User authentication system, authentication terminal, management server, and user authentication method using the user authentication system
The user authentication system addresses security and efficiency issues by using short-range wireless communication for local biometric verification and centralized management, ensuring secure and efficient service provision.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
- Filing Date
- 2023-02-28
- Publication Date
- 2026-05-29
Smart Images

Figure 0007867168000001 
Figure 0007867168000002 
Figure 0007867168000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a user authentication system, an authentication terminal, a management server, a business operator device, a user terminal for authenticating a user who uses a service, and a user authentication method by the user authentication system.
Background Art
[0002] Conventionally, as an authentication system using a mobile terminal, it includes a mobile terminal and a server connectable to the mobile terminal via a network. In the server, information regarding qualifications to be authenticated and face information of legitimate holders of the qualifications are registered in advance. The mobile terminal receives information regarding qualifications and face information from the server via the network, stores a face image of the person to be authenticated taken using the camera function, and performs collation processing within the terminal between the face information sent from the server and the taken face image (see Patent Document 1).
[0003] Also conventionally, as an authentication system, it includes at least one or more authentication terminals and a server that stores in advance by associating the ID of each of a plurality of users with biometric information. The authentication terminal holds an ID list that stores the IDs of at least one or more stayers staying in a predetermined area. When authentication of a person to be authenticated is required, it transmits an authentication request including the biometric information of the person to be authenticated and the ID list to the server. The server extracts the IDs included in the ID list from the IDs of each of the plurality of users, and performs biometric authentication using the biometric information corresponding to the extracted IDs and the biometric information included in the authentication request (see Patent Document 2).
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
[0005] In the prior art described in Patent Documents 1 and 2 above, biometric information such as facial information of all legitimate users (i.e., those who have legitimate rights regarding ownership of goods or use of services, etc.) is stored in advance on the server, so advanced security measures are required to prevent information leakage from the server.
[0006] Furthermore, in the prior art described in Patent Document 1 and Patent Document 2 above, as the number of registered legitimate users increases, a large amount of similar facial and biometric information will be stored on the server, which may make it difficult to maintain the accuracy and speed of the authentication process.
[0007] Therefore, the main purpose of this disclosure is to provide a user authentication system, authentication terminal, management server, business equipment, and a user authentication method using a user terminal and user authentication system that can easily ensure the security of registered users' biometric information while providing stable services to users. [Means for solving the problem]
[0008] The user authentication system of this disclosure is a user authentication system for authenticating users of services provided by a service provider, comprising: one or more authentication terminals that authenticate the user by performing short-range wireless communication with a user terminal carried by the user; a biometric information acquisition device that is located within the communication area of the short-range wireless communication and acquires biometric information for user authentication of the user present in the communication area; and a management server that manages the authentication terminals, wherein the management server transmits conditional information regarding the provision of services scheduled by the service provider to each of the authentication terminals, and each of the authentication terminals The system transmits a beacon signal based on the aforementioned short-range wireless communication, and upon receiving a response from the user terminal to the beacon signal, it requests the responding user terminal to transmit the registered biometric information of the user registered on the user terminal and authorization information indicating that the user has the right to use the service. Registered biometric information and, The aforementioned The authorization information is obtained from the user terminal via the aforementioned short-range wireless communication. If the service provider's electronic signature is attached to the authorization information, verify that the authorization information has not been tampered with based on the electronic signature.The system performs authentication by comparing the biometric information used for authentication with the registered biometric information, and determines whether the content of the service for which the user has access rights satisfies the conditions for providing the service based on the authorization information and the condition information. If both the authentication result and the determination result are normal, the system permits the provision of the service for which the user has access rights to the user.
[0009] The management server in this disclosure is a management server provided in the user authentication system, which is connected to a service provider's equipment managed by the service provider and is configured to transmit the authentication result and the determination result to the service provider's equipment.
[0010] The authentication terminal in this disclosure is the management server provided in the user authentication system, which is connected to a service provider's equipment managed by the service provider and is configured to transmit the authentication result and the determination result to the service provider's equipment.
[0012] The user authentication method of this disclosure is a user authentication method by a user authentication system that authenticates users of services provided by a service provider, the user authentication system comprising: one or more authentication terminals that authenticate the user by performing short-range wireless communication with a user terminal carried by the user; a biometric information acquisition device that is located within the communication area of the short-range wireless communication and acquires biometric information for user authentication that is present within the communication area; and a management server that manages the authentication terminals, the management server transmits conditional information regarding the provision of services scheduled by the service provider to each of the authentication terminals, and each of the authentication terminals The system transmits a beacon signal based on the aforementioned short-range wireless communication, and upon receiving a response from the user terminal to the beacon signal, it requests the responding user terminal to transmit the registered biometric information of the user registered on the user terminal and authorization information indicating that the user has the right to use the service. Registered biometric information and, The aforementioned The authorization information is obtained from the user terminal via the aforementioned short-range wireless communication. If the service provider's electronic signature is attached to the authorization information, verify that the authorization information has not been tampered with based on the electronic signature.The system performs authentication by comparing the biometric information used for authentication with the registered biometric information, and determines whether the content of the service for which the user has access rights satisfies the conditions for providing the service based on the authorization information and the condition information. If both the authentication result and the determination result are normal, the system permits the provision of the service for which the user has access rights. [Effects of the Invention]
[0013] This disclosure makes it possible to provide stable services to users while easily ensuring the security of registered users' biometric information. [Brief explanation of the drawing]
[0014] [Figure 1] Overall configuration diagram of the user authentication system according to the embodiment [Figure 2] Functional block diagram of the management server [Figure 3] Functional block diagram of the authentication terminal [Figure 4] User terminal functional block diagram [Figure 5] Functional block diagram of the service provider's server [Figure 6] Sequence diagram showing the initial registration process for service providers using the user authentication system. [Figure 7] An explanatory diagram showing an example of the conditional information used to determine service authorization ((A) Meeting room setting information, (B) Event schedule information). [Figure 8] An explanatory diagram showing an example of condition information assigned to an authentication terminal ((A) Use of a meeting room, (B) Event ticket reservation). [Figure 9] A sequence diagram showing part of the initial registration process for users of the user authentication system (the process of obtaining user consent in order to perform facial recognition). [Figure 10] Figure 9 is an explanatory diagram showing an example of a facial recognition service application screen in the process shown. [Figure 11]Sequence diagram showing the flow of part of the initial registration of a user using a user authentication system (completing user registration) [Figure 12] Explanatory diagram showing an example of user management information in the user registration process shown in FIG. 11 [Figure 13] Sequence diagram showing the flow of processing for linking the service provider's service and the face authentication service [Figure 14] Explanatory diagram showing an example of a service link application screen in the process shown in FIG. 13 [Figure 15] Sequence diagram showing the flow of processing for a user to obtain service authorization information [Figure 16] Explanatory diagram showing an example of authorization information used for service authorization determination ((A) Use of a meeting room, (B) Ticket reservation for an event) [Figure 17] Sequence diagram showing the first modification example of the process shown in FIG. 15 [Figure 18] Sequence diagram showing the flow of preparation processing for a user to perform face authentication on an authentication terminal [Figure 19] Explanatory diagram showing an example of authentication information in the process shown in FIG. 18 [Figure 20] Sequence diagram showing a modification example of the process shown in FIG. 18[[ID=X]] [[ID=Y]] [Figure 21] Sequence diagram showing the flow of processing for determining whether to provide a service based on face authentication [[ID=3I]] [Figure 22] Sequence diagram showing a modification example of the process shown in FIG. 20 [Figure 23] A modification example of the process shown in FIG. 15, showing the flow of preparation processing for a user to perform face authentication on an authentication terminal in order to obtain service authorization information [Figure 24] A modification example of the process shown in FIG. 15, showing the flow of processing for a user to obtain service authorization information
Mode for Carrying Out the Invention
[0015] Note: There seems to be a typo in the original text where '[[ID=X]]' and '[[ID=Y]]' are likely incorrect. They should probably be '' and '' respectively. Also, '[[ID=3I]]' should likely be ''. I've translated them as is but noted the potential errors.The first invention made to solve the aforementioned problem is a user authentication system for authenticating users of services provided by a service provider, comprising: one or more authentication terminals that authenticate the user by performing short-range wireless communication with a user terminal carried by the user; a biometric information acquisition device that is placed within the communication area of the short-range wireless communication and acquires biometric information for user authentication of the user present in the communication area; and a management server that manages the authentication terminals, wherein the management server transmits conditional information regarding the provision of services scheduled by the service provider to each of the authentication terminals, and each of the authentication terminals The system transmits a beacon signal based on the aforementioned short-range wireless communication, and upon receiving a response from the user terminal to the beacon signal, it requests the responding user terminal to transmit the registered biometric information of the user registered on the user terminal and authorization information indicating that the user has the right to use the service. Registered biometric information and, The aforementioned The authorization information is obtained from the user terminal via the aforementioned short-range wireless communication. If the service provider's electronic signature is attached to the authorization information, verify that the authorization information has not been tampered with based on the electronic signature. The system performs authentication by comparing the biometric information used for authentication with the registered biometric information, and determines whether the content of the service for which the user has access rights satisfies the conditions for providing the service based on the authorization information and the condition information. If both the authentication result and the determination result are normal, the system permits the provision of the service for which the user has access rights to the user.
[0016] According to this system, biometric information registered on the user terminal (i.e., biometric information used for verification against authentication biometric information acquired when providing the service) will only be acquired and temporarily stored by the authentication terminal if the authentication terminal is located in a position where short-range wireless communication with the user terminal is possible. Furthermore, the provision of the service to the user will only be permitted if both the authentication result regarding the biometric information and the result of the determination of whether or not the service can be used are normal. Therefore, it becomes possible to provide services to users stably while easily ensuring the security of registered user biometric information.
[0017] Furthermore, the second invention is configured such that the authentication terminal sends a notification to the user terminal indicating that it cannot provide the service if there is an abnormality in at least one of the authentication result and the determination result.
[0018] According to this, users can quickly and easily recognize when an authentication error occurs and they are not allowed to use the service.
[0019] Furthermore, the third invention is configured such that the authentication terminal has a display device and displays at least one of the authentication result and the determination result on the display device.
[0020] According to this, users can quickly and easily understand the results of authentication or determination regarding the use of the service.
[0023] Also, the 4 The invention is configured such that the authentication terminal has a storage device in which the registered biometric information is stored, and after performing the authentication, the registered biometric information in the storage device is erased.
[0024] This allows for more reliable security of registered biometric information. Furthermore, because the target of the matching process is easily identified (i.e., unnecessary registered biometric information is deleted), the authentication process is simplified, reducing the processing load. The authentication terminal can also similarly delete authentication biometric information acquired by the biometric information acquisition device from its storage device.
[0027] Also, the 5 The invention is configured such that the management server extracts services related to each authentication terminal from among a plurality of services scheduled to be provided by the service provider, and transmits the condition information relating to the extracted services to each corresponding authentication terminal.
[0028] According to this, each authentication terminal can obtain only the conditional information relevant to its own device, thus reducing the processing load for authentication.
[0029] Also, the 6The invention relates to a management server provided in the user authentication system, which is communicatively connected to a service provider's equipment managed by the service provider, and is configured to transmit the authentication result and the determination result to the service provider's equipment.
[0030] This makes it easy to ensure the security of registered users' biometric information. Furthermore, service providers can easily understand the authentication and judgment results.
[0031] Also, the 7 The present invention relates to an authentication terminal provided in the user authentication system, which is connected to an external device in a communicative manner, and is configured to transmit a predetermined control signal to the external device when both the authentication result and the determination result are normal.
[0032] This makes it easy to ensure the security of registered users' biometric information. Furthermore, by controlling external devices based on the authentication results and judgment results (i.e., predetermined control signals), services can be provided to users quickly and reliably.
[0043] Also, the 8 The invention relates to a user authentication method using a user authentication system that authenticates users of services provided by a service provider, the user authentication system comprising: one or more authentication terminals that authenticate the user by performing short-range wireless communication with a user terminal carried by the user; a biometric information acquisition device that is placed within the communication area of the short-range wireless communication and acquires biometric information for user authentication of the user present in the communication area; and a management server that manages the authentication terminals, the management server transmits conditional information regarding the provision of services scheduled by the service provider to each of the authentication terminals, and each of the authentication terminals The system transmits a beacon signal based on the aforementioned short-range wireless communication, and upon receiving a response from the user terminal to the beacon signal, it requests the responding user terminal to transmit the registered biometric information of the user registered on the user terminal and authorization information indicating that the user has the right to use the service. Registered biometric information and, The aforementioned The authorization information is obtained from the user terminal via the aforementioned short-range wireless communication. If the service provider's electronic signature is attached to the authorization information, verify that the authorization information has not been tampered with based on the electronic signature.The system performs authentication by comparing the biometric information used for authentication with the registered biometric information, and determines whether the content of the service for which the user has access rights satisfies the conditions for providing the service based on the authorization information and the condition information. If both the authentication result and the determination result are normal, the system permits the provision of the service for which the user has access rights.
[0044] According to this system, biometric information registered on the user terminal (i.e., biometric information used for verification against authentication biometric information acquired when providing the service) will only be acquired and temporarily stored by the authentication terminal if the authentication terminal is located in a position where short-range wireless communication with the user terminal is possible. Furthermore, the provision of the service to the user will only be permitted if both the authentication result regarding the biometric information and the result of the determination of whether or not the service can be used are normal. Therefore, it becomes possible to provide services to users stably while easily ensuring the security of registered user biometric information.
[0045] The embodiments of this disclosure will be described below with reference to the drawings.
[0046] As shown in Figure 1, the user authentication system 1 comprises an authentication terminal 2 that performs user authentication processing, a management server 3 that manages the authentication terminal 2, a service provider server 4 (an example of a service provider device) managed by a service provider that provides services to the user (for example, an individual, corporation, or organization that provides services to the user), and a user terminal 5 carried by the user. The authentication terminal 2, management server 3, service provider server 4, and user terminal 5 are connected to each other so that they can communicate with one another via a communication network 6 consisting of the Internet or a LAN (Local Area Network), etc.
[0047] The user authentication system 1 only needs to include at least an authentication terminal 2 and a management server 3. In other words, the administrator of the user authentication system 1 can manage at least the authentication terminal 2 and the management server 3. In that case, the service provider server 4 and the user terminal 5 may be provided as appropriate devices that can cooperate with the user authentication system 1.
[0048] User authentication system 1 authenticates users who use multiple services. These services may be provided to the user by multiple different service providers. Services provided to the user include, for example, the rental and access control of buildings and parts thereof (e.g., rooms for holding events or meetings), the use of tools and equipment, the rental of vehicles (e.g., vehicle rental for car-sharing services), reservations for train cars and seats, sales of goods and tickets, use of various facilities including transportation (e.g., stadiums), medical examinations and treatments at hospitals, login to devices such as personal computers, and use of stations and parcel lockers.
[0049] Figure 1 shows only one service provider server 4 managed by one service provider. However, the number of service providers using the user authentication system 1 may be changed as appropriate. If there are multiple service providers, multiple service provider servers will be provided, each managed by a different service provider.
[0050] Similarly, although Figure 1 shows only one user terminal 5, the user authentication system 1 may include more user terminals 5. In other words, the user authentication system 1 can be used by multiple users. Also, although Figure 1 shows only one authentication terminal 2, the user authentication system 1 may include more authentication terminals 2.
[0051] As shown in Figure 2, the management server 3 includes a communication unit 11, a control unit 12, and a storage unit 13.
[0052] The communication unit 11 communicates wirelessly or via wired connection with other devices (in this case, the authentication terminal 2, the service provider server 4, and the user terminal 5, etc.) via the communication network 6 in accordance with a known communication protocol.
[0053] In the control unit 12, the service provider management unit 21 executes a service provider registration process to register each service provider that uses the user authentication system 1, and manages those service providers. Service providers can use the service provider server 4 to perform the process of registering with the user authentication system 1. Registered service providers can use biometric authentication of users (for example, the facial recognition service described later) by the user authentication system 1 when providing services to users.
[0054] Information about service providers obtained through the service provider registration process is stored in the storage unit 13 as service provider management information 31. Service provider management information 31 includes, for example, information such as the name or title of the service provider, contact information, and contract information regarding the use of the user authentication system 1.
[0055] Furthermore, the service provider management unit 21 obtains condition information 32 regarding the provision of services scheduled to be provided by each service provider from the service provider (in this case, the service provider server 4). The obtained condition information 32 is stored in the storage unit 13. As will be described in detail later, the condition information 32 is used to determine whether the content of the service that a user has reserved meets the service provision conditions set by the service provider when the user uses that service. For example, the condition information 32 includes information regarding the provision time (or provision time period, provision period) and provision location (including location, name, identification code, etc.) for each service that the service provider is scheduled to provide.
[0056] The user management unit 22 manages each user who receives services from each service provider. The user management unit 22 obtains information necessary for user management from each user (in this case, user terminal 5) and service providers (in this case, service provider server 4) and stores it in the storage unit 13 as user management information 33. User management information 33 may include, for example, individual identification information of user terminal 5, identification information related to communications performed by user terminal 5, and identification information (authentication ID described later) attached to the biometric information of the user registered in user terminal 5. In addition, user management information 33 may include user identification information such as user ID, user's name, address, email address, and information about attributes such as age and gender.
[0057] The Service Integration Management Unit 23 manages the integration between service providers who provide services and users who receive those services (hereinafter referred to as "service integration"). Managing such service integration may include obtaining user consent for facial recognition (i.e., using the user's facial information) when providing services to the user. The Service Integration Management Unit 23 can perform the process of obtaining user consent in cooperation with the facial recognition application 81 (see Figure 4) that runs on the user terminal 5.
[0058] Furthermore, service integration management may include relaying various types of information exchanged between the service provider server 4 and the user terminal 5, and managing (recording) such information. In addition, service integration management may also include transmitting information related to user authentication and determination performed by the authentication terminal 2 (e.g., the results of authentication and determination) to the service provider server 4 and the user terminal 5. Information related to service integration management is stored in the storage unit 13 as service integration management information 34.
[0059] The authentication terminal management unit 24 manages the authentication terminal 2. Management of the authentication terminal 2 includes, for example, providing information necessary for the authentication process performed on the authentication terminal 2, and issuing control commands regarding the operation of the authentication terminal 2. If multiple authentication terminals 2 exist, the authentication terminal management unit 24 performs management according to the service corresponding to each authentication terminal 2. Information regarding the management of the authentication terminal 2 is stored in the storage unit 13 as authentication terminal management information 35.
[0060] The management server 3 includes a computer capable of performing the above-described processes. The management server 3 may be equipped with known hardware such as a processor (CPU, MPU, etc.), memory, display, input devices, network interface, and storage.
[0061] The communication unit 11 may include a communication device equipped with an antenna, a communication circuit, and the like.
[0062] At least some of the functions of each part 21-24 in the control unit 12 can be realized by the processor executing a predetermined control program. Furthermore, the control unit 12 can comprehensively control the operation of the management server 3.
[0063] The memory unit 13 may include a storage device such as a storage unit for storing data and information necessary for processing the management server 3.
[0064] Furthermore, in the user authentication system 1, at least a portion of the functions of the management server 3 described above may be realized through the cooperation of multiple computers.
[0065] The authentication terminal 2 may be placed in locations where users visit to make reservations for services or to receive services (such as stores or facilities). As shown in Figure 3, the authentication terminal 2 includes a network communication unit 41, a short-range communication unit 42, a sensor unit 43, an operation input unit 44, a display unit 45, a control unit 46, and a storage unit 47.
[0066] The network communication unit 41 communicates with other devices (in this case, the management server 3 and the service provider server 4, etc.) via the communication network 6, similar to the communication unit 11 described above.
[0067] The short-range communication unit 42 performs short-range wireless communication with other devices (in this case, user terminal 5, etc.) located around the authentication terminal 2, in accordance with a known communication protocol. The short-range communication unit 42 communicates with other devices based on Bluetooth®, but is not limited to this and may perform communication based on other communication standards (such as Wi-Fi).
[0068] The sensor unit 43 includes a sensor (an example of a biometric information acquisition device) for acquiring the user's biometric information. In this embodiment, facial information (i.e., the user's facial image or facial features extracted from that facial image) is used as the user's biometric information, and the sensor unit 43 is equipped with a camera as a sensor for acquiring the user's facial image. However, the user's biometric information available to the user authentication system 1 is not limited to facial information, but may also include information about other physical characteristics (for example, information about fingerprints, irises, and veins).
[0069] In addition, the sensor unit 43 may be omitted in the authentication terminal 2. In that case, a sensor having the same function as the sensor unit 43 (another example of a biometric information acquisition device) can be provided externally (for example, provided near the authentication terminal 2 as a separate unit), and the authentication terminal 2 can obtain the user's biometric information from its external sensor.
[0070] The operation input unit 44 includes known input devices such as a touch panel or input buttons that can be used by the user.
[0071] The display unit 45 includes known display devices such as liquid crystal displays. However, a touch panel used as an input device may also function as a display device.
[0072] In the control unit 46, the condition information acquisition unit 51 acquires condition information 32 regarding the provision of services scheduled by the service provider. The acquired condition information 32 is stored in the storage unit 47.
[0073] The biometric information acquisition unit 52 executes a biometric information acquisition process to acquire biometric information of a user approaching the authentication terminal 2 (or a user operating the authentication terminal 2) using the sensor unit 43. In the biometric information acquisition process according to this embodiment, a face image is acquired by capturing the user's face with a camera, and further, facial features are extracted from the face image. These facial features are stored in the storage unit 47 as biometric information 62 for authentication, together with (or without) the corresponding face image.
[0074] The user terminal detection unit 53 detects user terminals 5 located in the vicinity of the authentication terminal 2 through short-range wireless communication with the user terminals 5. More specifically, the user terminal detection unit 53 detects user terminals 5 located within the communication area of the short-range wireless communication (i.e., user terminals 5 located within a distance range where short-range wireless communication with the authentication terminal 2 is possible). For example, a user terminal 5 can communicate with the authentication terminal 2 by being located within a range of approximately 10 to 100 meters from the authentication terminal 2 (i.e., approaching it).
[0075] The service authorization unit 54 performs user authentication (i.e., biometric authentication). This user authentication is performed by comparing the biometric information of the user (i.e., the user present near the authentication terminal 2) obtained by the biometric information acquisition unit 52 with the user's registered biometric information previously obtained from the user terminal 5 as authentication information 63. The service authorization unit 54 also determines whether the content of the service provided to the user (i.e., the service reserved by the user) meets the conditions for service provision planned by the service provider.
[0076] Furthermore, the service authorization unit 54 authorizes the provision of services to the user if both the user authentication result and the result of the service provision condition determination are normal. On the other hand, the service authorization unit 54 refuses to provide services to the user if there is an abnormality in at least one of those results. The authentication result, the condition determination result, and information regarding whether the service provision has been authorized (or denied) by the service authorization unit 54 are stored in the storage unit 47 as service authorization information 64. The service authorization unit 54 can also display this information on the display unit 75 so that the user can recognize it.
[0077] The authentication terminal 2 may be connected to an external device 55 involved in providing services to the user in a communicative manner. When the service authorization unit 54 authorizes the provision of services to the user, it can transmit a predetermined control signal to the external device 55. For example, if the service provided to the user is the use of a stadium (e.g., participation in an event held at the stadium), the service authorization unit 54 can transmit a control signal (a signal instructing the gate to open) to a gate device, which is an external device 55 installed at the entrance of the stadium. Alternatively, if the service provided to the user is the use of a conference room, the service authorization unit 54 can transmit a control signal (a signal instructing the door lock device to unlock) to a door lock device, which is an external device 55 installed on the door of the conference room. The authentication terminal 2 may be provided as part of the external device 55 (i.e., integrated with the external device 55).
[0078] Authentication terminal 2 includes a computer capable of performing the above-described processes. Authentication terminal 2 may be equipped with known hardware such as a processor (CPU, MPU, etc.), memory, display, input devices, network interface, and storage.
[0079] The network communication unit 41 and the short-range communication unit 42 may each include communication devices equipped with antennas, communication circuits, etc.
[0080] At least some of the functions of each of the parts 51-54 in the control unit 46 can be realized by the processor executing a predetermined control program. Furthermore, the control unit 46 can comprehensively control the operation of the authentication terminal 2.
[0081] The memory unit 47 may include a storage device such as a storage unit for storing data and information necessary for processing the authentication terminal 2.
[0082] User terminal 5 includes information devices with communication capabilities, such as smartphones, tablet devices, or PCs, carried by each user. User terminal 5 may be equipped with known hardware such as a processor (CPU, MPU, etc.), memory, a touch panel display, a network interface, and storage. Each user can use their own user terminal 5 to perform procedures such as registering biometric authentication information performed on authentication terminal 2, or applying to use services provided by service providers.
[0083] As shown in Figure 4, the user terminal 5 has a network communication unit 71, a short-range communication unit 72, a sensor unit 73, an operation input unit 74, a display unit 75, a control unit 76, and a storage unit 77. The network communication unit 71, the short-range communication unit 72, the sensor unit 73, the operation input unit 74, and the display unit 75 have the same functions and configurations as the network communication unit 41, the short-range communication unit 42, the sensor unit 43, the operation input unit 44, and the display unit 45 described above, respectively.
[0084] The user terminal 5 has an application installed (in this case, a facial recognition application 81) for performing biometric authentication (in this case, facial recognition) in the user authentication system 1.
[0085] The control unit 76 has a processor and is capable of performing various processes for user facial recognition based on the facial recognition application 81 stored in the storage unit 77. Such processes include, for example, processes related to the user's application for facial recognition and processes related to the registration of the user's facial information used for facial recognition. The user's facial information registered in the user terminal 5 is stored in the storage unit 77 as registered biometric information 82. The storage unit 77 also stores an authentication ID 83 for other devices (in this case, the management server 3 and the service provider server 4) to identify the registered biometric information 82.
[0086] Furthermore, the control unit 76 can execute processes for using services provided by a service provider based on a predetermined control program (not shown) stored in the storage unit 77. Such processes include, for example, processes related to applying for a user ID to the service provider and processes related to applying for the use of a service. When the application for the use of a service is successfully executed, the user terminal 5 obtains authorization information 84 from the service provider server 4 indicating that the service has been reserved by the user, and stores it in the storage unit 77. The authorization information 84 is stored in association with registered biometric information 82 (in this case, registered facial features).
[0087] The control unit 76 can comprehensively control the operation of the user terminal 5. When various processes are executed by the control unit 76, the user can perform necessary input operations via the operation input unit 74.
[0088] The memory unit 77 may include a storage device or other storage device for storing data and information necessary for processing the user terminal 5. The memory unit 77 stores terminal information 85, including the Bluetooth® device address (BD address) of the user terminal 5 and application identification information (UUID).
[0089] As shown in Figure 5, the service provider server 4 has a communication unit 91, a control unit 92, and a storage unit 93.
[0090] The communication unit 91 communicates wirelessly or via wired connection with other devices (in this case, the authentication terminal 2, the management server 3, and the user terminal 5, etc.) via the communication network 6 in accordance with a known communication protocol.
[0091] In the control unit 92, the registration unit 101 can submit a registration application to the management server 3 for service providers to use the user authentication system 1. Information about the service provider used in the registration application (including the service provider's name and other information, as well as contact information) is stored in the storage unit 93 as service provider information 111. The registration unit 101 can also accept registration applications from users who wish to receive services. Information about the user used in the registration application (including the user's name and contact information) is stored in the storage unit 93 as user information 112.
[0092] The condition information setting unit 102 sets condition information 32 regarding the provision of services planned by the service provider and stores it in the storage unit 93.
[0093] The Authentication Information Linking Reception Unit 103 performs processing related to the linking of information for user facial recognition when a service provider provides services to a user. For example, the Authentication Information Linking Reception Unit 103 performs processing to obtain the user's consent to perform facial recognition (i.e., to use the facial recognition service provided by User Authentication System 1) in relation to the services provided to the user.
[0094] The authorization information setting unit 104 receives a reservation for the provision of a service from the user (usually the user terminal 5), sets authorization information 84 indicating that it is the reserved service, and stores it in the storage unit 93. The set authorization information 84 is then transmitted to the user terminal 5.
[0095] The service information management unit 105 manages the history of services provided by service providers to users. Information regarding such service history is stored in the storage unit 93 as service history information 113.
[0096] The service provider server 4 includes a computer capable of performing the above-described processes and may be equipped with publicly known hardware, similar to the management server 3.
[0097] The communication unit 91 may include a communication device equipped with an antenna, communication circuits, etc.
[0098] At least some of the functions of each part 101-105 in the control unit 92 can be realized by the processor executing a predetermined control program. Furthermore, the control unit 92 can comprehensively control the operation of the service provider server 4.
[0099] The memory unit 93 may include a storage device or other storage device for storing data and information necessary for processing the service provider server 4.
[0100] Next, with reference to Figures 6, 7, and 8, we will explain the initial registration process for service providers using User Authentication System 1.
[0101] First, prior to a user using the user authentication system 1, the service provider sends a service provider registration application from the service provider server 4 to the management server 3 (1001). This service provider registration application includes contract information regarding system usage, service provider information 111, and information about the services provided by the service provider, which are sent to the management server 3. The service information includes information about the services that the service provider can provide to the user.
[0102] When the management server 3 receives the business registration application, it executes the business registration process for the service provider (1002). At this time, the management server 3 assigns identification information (hereinafter referred to as the business ID) to the target service provider and can store this business ID, along with the corresponding contract information, business information, and service information, as service provider management information 31 in the storage unit 13. Subsequently, the management server 3 notifies the service provider server 4 of the registration permission (1003). This registration permission notification may include information on how to use the user authentication system 1 for users who receive services from the service provider.
[0103] Once the service provider server 4 has completed registering the service provider with the management server 3, it sends a request to the management server 3 to set up an authorization determination for the service (1004). This authorization determination setting causes the authentication terminal 2 to determine whether the content of the service meets the service provision conditions when a user receives the reserved service.
[0104] Subsequently, when the service provider server 4 receives a notification from the management server 3 indicating permission to set the authorization determination (1005), it sets the condition information 32 used for determining the authorization of the service via the authentication terminal 2 (1006). Furthermore, the service provider server 4 notifies the management server 3 of the assignment request for the authentication terminal based on the set condition information 32 (1007).
[0105] For example, if the service provided to the user is the rental of a part of a building (in this case, the use of a meeting room), then conditional information for managing entry and exit for each meeting room is set, as shown in Figure 7(A). Such conditional information includes, for example, the floor on which the rented room is located (e.g., the 6th floor) and the room number (e.g., room XXX).
[0106] For example, if the service provided to the user is ticket booking (sale) for an event, then condition information 32 is set to manage the user's entry to each venue where each event is held, as shown in Figure 7(B). Such condition information may include, for example, the name of each venue (e.g., Arena A, Arena B, Arena C), the event name (e.g., Event α, β, γ, Event α1, β1), or the time or period during which entry to the venue is permitted (e.g., from 18:00 on October 1, 2023).
[0107] When the management server 3 receives a request to assign an authentication terminal, it extracts the authentication terminal 2 to be assigned from among the multiple authentication terminals 2 under its management (1008). At this time, the management server 3 can extract the authentication terminal 2 to be assigned by extracting the service related to each authentication terminal 2 from among the multiple services included in the condition information 32 (i.e., multiple services that the service provider is scheduled to provide). For example, if an authentication terminal 2 is installed for room XXX on the 6th floor of a building in relation to a service that rents out conference rooms, the management server 3 can extract the information corresponding to the installation location of the authentication terminal 2 (in this case, room XXX on the 6th floor) from the floor number and room number information of the conference room included in the condition information 32 and assign it to the authentication terminal 2.
[0108] For example, regarding a ticket reservation (sales) service for an event, if authentication terminal 2 is installed at the entrance of Arena A, which is the event venue, the management server 3 can extract information corresponding to the installation location of authentication terminal 2 (for example, Arena A, Event α, October 1, 2023, 10:00-11:00; Arena A, Event β, October 1, 2023, 12:00-14:00; Arena A, Event γ, October 1, 2023, 17:00-19:00) from the information of the event venue, event name, and the time or period when entry is permitted, which is included in the condition information 32, and assign it to authentication terminal 2.
[0109] Subsequently, the management server 3 sends a request to save the corresponding condition information to the authentication terminal 2 from which the assignment condition information has been extracted (1009). Although only one authentication terminal 2 is shown in Figure 6, the management server 3 can send requests to save the corresponding condition information to multiple authentication terminals.
[0110] When authentication terminal 2 receives a request to save condition information, it saves the received condition information 32 to storage unit 47 (1010). For example, as shown in Figure 8(A), the condition information saved to authentication terminal 2 installed for room XXX on the 6th floor includes information corresponding to the installation location (here, room XXX on the 6th floor). Also, for example, as shown in Figure 8(B), the condition information saved to authentication terminal 2 installed for Arena A includes information such as the event venue (here, Arena A), the event name (e.g., Event α), and the time or period during which entry is permitted (e.g., October 1, 2023, 10:00-11:00). In addition, although not shown, the condition information saved to authentication terminal 2 installed for Arena B includes the condition information shown in Figure 7(B) (Arena B, Event α1, October 5, 2023, 9:00-10:00). Furthermore, the condition information stored in the authentication terminal 2 installed for Arena C includes the condition information shown in Figure 7(B) (Arena C, Event β1, October 1, 2023, 11:00-14:00).
[0111] Note that the process for setting the authorization determination for the service (steps 1004-1010) does not need to be executed together with the process for registering the service provider (steps 1001-1004). After the service provider registration is complete, the service provider server 4 can perform the same process as in steps 1004-1010 as needed.
[0112] Next, with reference to Figures 9, 10, and 11, we will explain the initial registration process for users utilizing the user authentication system.
[0113] Figure 9 illustrates the process of obtaining user consent in order to perform facial recognition (i.e., provide a facial recognition service).
[0114] The user can pre-install the facial recognition application 81 on the user terminal 5 (1101). For example, when the user applies for user registration with the service provider, the user can obtain the facial recognition application 81 based on the user guidance information distributed to the user terminal 5 from the service provider server 4.
[0115] Once the installation of the facial recognition application 81 is complete, the display unit 75 of the user terminal 5 displays a screen 120 (hereinafter referred to as the "facial recognition service application screen") related to the user's application for and consent to use facial recognition (1102). The facial recognition service application screen 120 includes, for example, as shown in Figure 10, consent input areas 121 for the user to input their consent to use the facial recognition service and their consent to the handling of personal information (in this case, Terms of Service A and Privacy Policy A).
[0116] On the facial recognition service application screen 120, when the user enters information in the consent input area 121 and then presses the consent button 122 (1103), an application for the use of the facial recognition service is sent from the user terminal 5 to the management server 3 (1104). This application for the use of the service may include user information (such as the user's name and contact information).
[0117] When the management server 3 receives an application to use the facial recognition service, it performs application acceptance processing (for example, saving necessary information) (1105). Once the application acceptance processing is successfully completed, the management server 3 sends a notification to the user terminal 5 indicating that the application has been approved (1106).
[0118] Figure 11 illustrates the process by which a service provider sends an authentication ID and terminal information from the user terminal 5 to the service provider server 4 to complete user registration when providing a service from the service provider to the user. The process shown in Figure 10 may be executed after the process shown in Figure 8.
[0119] The user terminal 5 acquires a facial image captured by the camera of the sensor unit 73 as the user's biometric information (1201), and further acquires facial features extracted from the facial image (1202). Subsequently, the user terminal 5 assigns an authentication ID 83 to the facial image and facial features (1203), and then stores them in the storage unit 77 as registered biometric information 82 (1204).
[0120] Next, user terminal 5 sends a user registration request, including authentication ID 83 and terminal information 85, to management server 3 (1205).
[0121] When the management server 3 receives the user registration request, it executes the user registration process (1206). At this time, the management server 3 stores the user management information 33 in the storage unit 13. The user management information 33 includes, for example, the authentication ID 83 and the associated terminal information 85 (in this case, the BD address and UUID), as shown in Figure 12. When the user registration process is successfully completed, the management server 3 sends a notification to the user terminal 5 indicating that user registration has been permitted (1207).
[0122] Next, referring to Figures 13 and 14, we will explain the processing flow for linking the service provider (service provider server 4) with the facial recognition service.
[0123] First, the user terminal 5 sends a service request to the service provider server 4 in order to receive services from the service provider (1301). This service request can be made, for example, by the user accessing the service provider's website using a browser pre-installed on the user terminal 5.
[0124] When the service provider server 4 receives a service usage application, it executes the application acceptance process (1302). At this time, the accessing user is assigned a user ID to identify the user. Next, the service provider server 4 requests an authentication ID corresponding to the user from the management server 3 (1303). As a result, the service provider server 4 obtains the corresponding authentication ID from the management server 3 (1304) and registers (saves) the authentication ID in association with the user ID (1305). Subsequently, a consent screen is displayed on the website asking the user to consent to using the facial recognition service (1306). At the same time, the service provider server 4 sends a service provider ID to the user terminal 5 to identify the service provider offering the service (1307).
[0125] Subsequently, when the user terminal 5 performs a consent operation (in this case, by pressing the confirmation button) on the consent screen displayed on the website (1308), an application for linking the service provider's service provision with the facial recognition service (hereinafter referred to as the "linking application") is launched in the browser (1309). At this time, the user terminal 5 reads the authentication ID 83 from the storage unit 77 (1310).
[0126] Upon launching the linked application, the display unit 75 of the user terminal 5 displays a screen 130 (hereinafter referred to as the "service linkage application screen") for obtaining the user's consent regarding the linkage between the service provider's service provision and the facial recognition service. The service linkage application screen 130 includes a consent input area 131 for the user to input their consent to the linkage between the desired service and the facial recognition service, as shown in Figure 14, for example. In the consent input area 131, the user can appropriately select a desired service provider and the desired service provided by them from among multiple service providers and the various services they offer.
[0127] On the service integration application screen 130, when the user enters information in the consent input area 131 and then presses the consent button 132 (1311), a notification regarding that consent is sent from the user terminal 5 to the management server 3 along with the authentication ID 83 (1312).
[0128] When the service provider server 4 receives the notification regarding the consent, it determines whether or not to permit the service integration application (1313). If the service integration application is permitted, the service provider server 4 sends a notification to the user terminal 5 indicating that the application has been permitted (1314).
[0129] When user terminal 5 receives the notification, it sends a notification regarding the results of the service integration to management server 3 (1315). This notification includes information regarding authentication ID 83 and business ID.
[0130] When the management server 3 receives the notification, it registers the information including the authentication ID 83 and the business ID (i.e., stores it in the storage unit 13 as service linkage management information 34) (1316).
[0131] Next, with reference to Figures 15 and 16, we will explain the process flow for a user to obtain service authorization information (i.e., reserve a service).
[0132] First, on user terminal 5, the user makes a login request by accessing the service provider's website using a browser (1401). In this login request, the user ID entered by the user on user terminal 5 is sent to the service provider server 4.
[0133] When the service provider server 4 receives the login request, it executes the login process and reads the authentication ID (1402). At this time, the service provider server 4 can read the authentication ID associated with the user ID (see step 1305 in Figure 13) based on the user ID. If the login process is completed successfully, the service provider server 4 sends a notification to the user terminal 5 indicating that the login was successful (1403).
[0134] Next, at the user terminal 5, the user applies for service use (i.e., reserves a service) on the service provider's website (1404). In response, the service provider server 4 performs the service use acceptance process (1405) and stores information about the reserved service along with the user information in the storage unit 93 (1406).
[0135] Next, the service provider server 4 sets authorization information for the reserved service (1407) and sends it to the management server 3 along with the authentication ID (1408). This authorization information includes, for example, information about the time and location of provision of the corresponding service, similar to the condition information 32 described above.
[0136] The authorization information includes, for example, as shown in Figure 16(A), information such as the floor on which the reserved room is located (e.g., 6th floor) and the room number (e.g., Room XXX) if the service used by the user is the use of a meeting room.
[0137] For example, as shown in Figure 16(B), if the service used by the user is ticket reservations for an event, the information will include the event name, the time or period during which entry to the venue will be possible (e.g., from 18:00 on October 1, 2023), and the name of the venue (e.g., Arena A).
[0138] However, the information regarding the time and location of service provision included in the authorization information may satisfy multiple conditional information 32 (i.e., service provision conditions) assigned to multiple different authentication terminals 2. For example, if the service is ticket reservation (sale) for an event, the authorization information may satisfy multiple conditional information 32 assigned to authentication terminals 2, each corresponding to one of the multiple gates that allow entry to the venue. This allows the user to enter the venue through their preferred gate among the multiple gates.
[0139] When the management server 3 receives the authorization information, it searches for terminal information using the corresponding authentication ID and selects the user terminal 5 to which it will send the authorization information (1409). Subsequently, the management server 3 transfers the authorization information to the selected user terminal 5 (1410). Furthermore, the management server 3 stores the acquired authorization information as service linkage management information 34 in the storage unit 13 (1411). Note that in step 1408, the authorization information may be sent directly from the service provider server 4 to the user terminal 5 without going through the management server 3.
[0140] When user terminal 5 receives authorization information from management server 3, it associates this information with registered facial features and stores it in storage unit 77 (1412).
[0141] Next, with reference to Figure 17, we will describe the first modification of the process shown in Figure 15. Unless otherwise specified below, the process is the same as that shown in Figure 15.
[0142] In the first modified example, the service provider server 4 affixes an electronic signature to the authorization information set in step 1407 (1420). This electronically signs the authorization information, preventing tampering with the authorization information transmitted to the management server 3 and the user terminal 5.
[0143] Next, referring to Figure 18, we will explain the flow of the preparation process for performing user facial recognition on authentication terminal 2 (i.e., the process of obtaining authorization information and registered facial features).
[0144] The authentication terminal 2 transmits a beacon signal via its short-range communication unit 42 to detect user terminals 5 located in the vicinity of its device (i.e., within the communication area of short-range wireless communication) (1601).
[0145] When user terminal 5, located near authentication terminal 2, receives its beacon signal (1602), it transmits a response to that beacon signal (1603). This response includes information about the BD address used by the user terminal 5's short-range communication unit 72.
[0146] Authentication terminal 2 detects user terminal 5 upon receiving a response from user terminal 5 (1604). Subsequently, authentication terminal 2 requests the detected user terminal 5 to send registered facial features (1605). In response, user terminal 5 sends a response to the request to authentication terminal 2 (1606). At this time, authorization information is added to the transmitted registered facial features.
[0147] Next, the authentication terminal 2 stores the registered facial features and authorization information received from the user terminal 5 in the storage unit 47 as authentication information 63 (1607). The stored authentication information 63 may include, for example, the BD address, application ID, registered facial features, and authorization information, as shown in Figure 19. Subsequently, the authentication terminal 2 sends a notification to the user terminal 5 indicating that it is ready to perform facial authentication of the user (1608).
[0148] Furthermore, if the authentication terminal 2 detects multiple user terminals 5 in step 1604, the processes in steps 1605-1608 are executed with each user terminal 5, and as shown in Figure 19, the application ID, registered facial features, and authorization information are linked to each BD address and stored in the storage unit 47 (1607).
[0149] Next, with reference to Figure 20, a modified version of the process shown in Figure 18 will be described. Unless otherwise specified below, the process is the same as that shown in Figure 18.
[0150] In the modified version, in step 1606, the authorization information transmitted from the user terminal 5 is digitally signed. Furthermore, before step 1607, a process is performed to determine the validity of the digital signature (1610), and the authentication information 63 is saved only if the digital signature is valid. This prevents tampering with the authorization information transmitted to the authentication terminal 2. Such digital signature processing can be performed based on digital signature verification techniques using known public-key cryptography schemes.
[0151] Next, referring to Figure 21, we will explain the process flow for determining whether or not to provide the service based on facial recognition.
[0152] Before the process shown in Figure 20 is executed, the authentication terminal 2 obtains registered facial features and authorization information from the user terminal 5 in the preparation process for performing user facial recognition shown in Figure 17. In other words, such preparation processing is performed within the communication area of short-range wireless communication before the user terminal 5 approaches the authentication terminal 2 (for example, at a distance of several tens of meters from the authentication terminal 2).
[0153] Subsequently, when a user approaches the authentication terminal 2 to receive the service, the authentication terminal 2 acquires a facial image of the user who has approached it (for example, standing in front of the authentication terminal 2) using the camera of the sensor unit 43 (1701), and obtains facial features extracted from the facial image (1702).
[0154] Next, the authentication terminal 2 reads the authentication information 63 and the condition information 32 from the storage unit 47, respectively (1703, 1704). The authentication information 63 includes the registered facial features and authorization information obtained in the above preparation process from the user terminal 5 located within the communication area of the short-range wireless communication with the authentication terminal 2.
[0155] Next, the authentication terminal 2 performs face authentication by comparing the face features obtained in step 1702 with the registered face features read in step 1703 (1705).
[0156] Furthermore, the authentication terminal 2 performs the authorization determination process (1706). In this authorization determination, it is determined whether the authorization information included in the authentication information 63 in step 1703 satisfies the condition information in step 1704. For example, as shown in Figure 8(A), if the condition information set for the authentication terminal 2 for conference room XXX on the 6th floor indicates "conference room XXX on the 6th floor," then if the authorization information includes "conference room XXX on the 6th floor" as shown in Figure 16(A), then it is determined that the condition information is satisfied. Also, for example, as shown in Figure 8(B), if the condition information set for the authentication terminal 2 for Arena A indicates the date and time and event name of each event held in Arena A, then if the authorization information includes "Arena A, event α, date and time" as shown in Figure 16(B), then it is determined that the condition information is satisfied.
[0157] If there is an abnormality in at least one of the results of facial recognition in step 1705 and the authorization determination in step 1706, the authentication terminal 2 sends a notification to the user terminal 5 indicating that authentication has failed (i.e., the service cannot be provided) (1707). In addition, if facial recognition in step 1705 is not performed, the authentication terminal 2 can send a notification to the user terminal 5 indicating that facial recognition was not performed. Furthermore, if facial recognition is not performed, or if there is an abnormality in at least one of the results of facial recognition in step 1705 and the authorization determination in step 1706, the authentication terminal 2 can display a message such as "Please check with staff" on the display unit 45 for the user and send a similar message to the user terminal 5.
[0158] Furthermore, the authentication terminal 2 displays the results of the facial recognition and authorization determination on the display unit 45 (1708). If both the facial recognition and authorization determination results are normal, the provision of the reserved service to the user is permitted. At this time, for example, the authentication terminal 2 can transmit a predetermined control signal to the external device 55.
[0159] Furthermore, the authentication terminal 2 transmits the facial recognition result and the authorization decision result, along with terminal information, to the management server 3 (1709). Upon receiving the authentication result, the management server 3 searches for the authentication ID based on the acquired terminal information (1710). The management server 3 then forwards the authentication result to the service provider server 4 (1711).
[0160] When the service provider server 4 receives the results of facial recognition and authorization, it updates the service history information 113 stored in the memory unit 93 based on the information contained therein (1712).
[0161] After step 1708, the authentication terminal 2, using the short-range communication unit 42, performs a process to detect user terminals 5 present in the vicinity of its device (i.e., within the communication area of short-range wireless communication), similar to steps 1601-1604 in Figure 17 above (1713). If no user terminals 5 that could be subject to facial recognition and authorization determination exist, the authentication terminal 2 erases the corresponding authentication information 63 stored in the storage unit 47 (1714). However, the authentication terminal 2 only needs to erase the user's facial information (i.e., facial image and facial features). Once the erasure of the authentication information 63 is complete, the authentication terminal 2 sends a notification to the user terminal 5 indicating that the facial information has been erased (1715).
[0162] Next, with reference to Figure 22, a modified version of the process shown in Figure 20 will be described. Unless otherwise specified below, the process is the same as that shown in Figure 20.
[0163] In the modified version, the authorization information read in step 1703 is electronically signed. Furthermore, before performing the facial recognition process in step 1705, a process is performed to determine the validity of the electronic signature (1720).
[0164] For determining the validity of the digital signature in the user authentication system 1, publicly known methods can be used. For example, a digital signature is information in which the hash value obtained by hashing the authorization information is encrypted with the service provider's private key. The authentication terminal 2 can verify the authenticity (that it has not been tampered with) of the digitally signed authorization information by determining whether the hash value of the read authorization information (plaintext) matches the information obtained by decrypting the digital signature with the service provider's public key (which may be sent from the service provider server 4 to the authentication terminal 2 along with the authorization information, or may be obtained through another route). If it is found that the digital signature has been tampered with, it means that incorrect authorization information has been presented by the user, and the authentication terminal 2 interrupts the subsequent processing and displays a message such as "This is incorrect usage reservation information, please contact the service provider" to notify the user that the service is unavailable. This prevents tampering with the authorization information stored in the storage unit 47.
[0165] Next, with reference to Figures 23 and 24, other embodiments of the process shown in Figure 15 will be described. Unless otherwise specified below, the process is the same as that shown in Figure 15.
[0166] In other embodiments, the authentication terminal 2 executes a user's application for service use (i.e., a service reservation). In this case, before the process shown in Figure 24 is executed, a process similar to the preparation process shown in Figure 18 is executed, as shown in Figure 23. However, the process shown in Figure 23 differs from the process shown in Figure 18 in that, in step 1606, an authentication ID is sent from the user terminal 5 to the authentication terminal 2 instead of authorization information, and in step 1607, the registered facial features and authentication ID are stored in the storage unit 47 as authentication information 63.
[0167] As shown in Figure 24, when the authentication terminal 2 receives a service application from a user (1801), it acquires a facial image of the user using the camera of the sensor unit 43 (1802), and obtains facial features extracted from the facial image (1803).
[0168] Next, the authentication terminal 2 performs face authentication by comparing the face features obtained in step 1503 with the registered face features obtained from the user terminal 5 in step 1616 in Figure 23 (1804). The result of the face authentication is displayed on the display unit 45 of the authentication terminal 2 (1805).
[0169] Once facial recognition is successfully completed, the authentication terminal 2 sends a notification regarding the facial recognition result to the service provider server 4 (1806). This notification regarding the facial recognition result includes user information, information regarding the application for service use, and the authentication ID.
[0170] When the service provider server 4 receives a notification regarding the result of facial recognition, it stores information related to the authentication result (including user information, information related to the application for service use, and the authentication ID) in the storage unit 13 (1807).
[0171] Next, the service provider server 4 sets authorization information for the reserved service based on the service information (1808) and sends this to the management server 3 along with the authentication ID (1809). This authorization information includes, for example, information about the time and location of provision of the corresponding service, similar to the condition information 32 described above.
[0172] When the management server 3 receives the authorization information, it searches for terminal information using the corresponding authentication ID and selects the user terminal 5 to which it will send the authorization information (1810). Subsequently, the management server 3 transfers the authorization information to the selected user terminal 5 (1811). Furthermore, the management server 3 stores the acquired authorization information as service linkage management information 34 in the storage unit 13 (1812). Note that in step 1408, the authorization information may be sent directly from the service provider server 4 to the user terminal 5 without going through the management server 3.
[0173] When the user terminal 5 receives authorization information from the service provider server 4, it associates this information with registered facial features and stores it in the memory unit 77 (1813).
[0174] As described above, embodiments have been explained as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these embodiments and can be applied to embodiments that have been modified, replaced, added, or omitted. Furthermore, it is possible to create new embodiments by combining the components described in the above embodiments.
[0175] For example, if there are multiple service providers (i.e., service provider servers 4), each service provider can add incentives to the services it provides based on the results (or planned results) of services provided by other service providers. Alternatively, the management server 3 may assign a common ID to the same user using the user authentication system 1, and each service provider server 4 may use this common ID to identify the user. [Industrial applicability]
[0176] The user authentication system, authentication terminal, management server, operator equipment, user terminal, and user authentication method provided by the user authentication system relating to this disclosure have the effect of easily ensuring the security of registered users' biometric information while providing stable services to users, and are useful as a user authentication system, authentication terminal, management server, operator equipment, user terminal, and user authentication method provided by the user authentication system for authenticating users who use the service. [Explanation of Symbols]
[0177] 1: User authentication system 2: Authentication terminal 3: Management Server 4: Service provider server 5: User terminal 6: Communication Networks 11: Communications Department 12: Control Unit 13: Storage section 21: Service Provider Management Department 22: User Management Department 23: Service Integration Management Department 24: Authentication Terminal Management Department 31: Service Provider Management Information 32: Condition Information 33: User Management Information 34: Service Integration Management Information 35: Authentication terminal management information 41: Network Communications Department 42: Near field communication department 43: Sensor Unit 44: Operation Input Section 45: Display section 46: Control Unit 47: Storage section 51: Condition information acquisition section 52: Biological Information Acquisition Unit 53: User terminal detection unit 54: Service Licensing Department 55: External device 62: Biometric Information 63: Authentication Information 64: Service authorization information 71: Network Communications Department 72: Near field communication department 73: Sensor Unit 74: Operation Input Section 75:Display section 76: Control Unit 77: Storage section 81: Facial recognition application 82: Biological Information 84:Authorization information 85: Terminal Information 91: Communications Department 92: Control Unit 93: Storage section 101: Registration Department 102: Condition Information Setting Section 103: Authentication Information Linking Reception Department 104: Authorization Information Setting Department 105: Service Information Management Department 111: Business information 112: User Information 113: Service History Information
Claims
1. A user authentication system that authenticates users who use services provided by a service provider, One or more authentication terminals that authenticate the user by performing short-range wireless communication with a user terminal carried by the user, A biometric information acquisition device is placed within the communication area of the aforementioned short-range wireless communication and acquires biometric information for authentication of the user present within the communication area. A management server that manages the aforementioned authentication terminals, Equipped with, The aforementioned management server The conditions information regarding the provision of the service scheduled by the service provider is transmitted to each authentication terminal. Each of the aforementioned authentication terminals is: The system transmits a beacon signal based on the aforementioned short-range wireless communication, and upon receiving a response from the user terminal to the beacon signal, it requests the responding user terminal to transmit the registered biometric information of the user registered on the user terminal and authorization information indicating that the user has the right to use the service. The registered biometric information and the authorization information are obtained from the user terminal via short-range wireless communication. If the service provider's electronic signature is attached to the authorization information, the authorization information will be verified based on the electronic signature to ensure that it has not been tampered with. Authentication is performed by comparing the aforementioned biometric information for authentication with the aforementioned registered biometric information. Based on the authorization information and the condition information, it is determined whether the content of the service for which the user has access rights satisfies the conditions for providing the service. A user authentication system that, when both the authentication result and the determination result are normal, permits the provision of services to the user for which the user has the right to use.
2. The user authentication system according to claim 1, wherein the authentication terminal sends a notification to the user terminal indicating that it cannot provide the service if there is an abnormality in at least one of the authentication result and the determination result.
3. The user authentication system according to claim 1, wherein the authentication terminal has a display device and displays at least one of the authentication result and the determination result on the display device.
4. The user authentication system according to claim 1, wherein the authentication terminal has a storage device on which the registered biometric information is stored, and after performing the authentication, the registered biometric information in the storage device is erased.
5. The management server extracts the services related to each authentication terminal from among the multiple services that the service provider is scheduled to provide, The user authentication system according to claim 1, wherein the condition information relating to the extracted service is transmitted to each of the corresponding authentication terminals.
6. The management server provided in the user authentication system described in claim 1, It is connected to the service provider's equipment managed by the aforementioned service provider in a manner that enables communication, A management server that transmits the results of the authentication and the results of the determination to the operator's device.
7. The authentication terminal provided in the user authentication system described in claim 1, It is connected to an external device in a way that allows it to communicate with it. An authentication terminal that transmits a predetermined control signal to the external device if both the authentication result and the determination result are normal.
8. A user authentication method using a user authentication system that authenticates users who use services provided by a service provider, The user authentication system is, One or more authentication terminals that authenticate the user by performing short-range wireless communication with a user terminal carried by the user, A biometric information acquisition device is placed within the communication area of the aforementioned short-range wireless communication and acquires biometric information for authentication of the user present within the communication area. A management server that manages the aforementioned authentication terminals, Equipped with, The aforementioned management server The conditions information regarding the provision of the service scheduled by the service provider is transmitted to each authentication terminal. Each of the aforementioned authentication terminals is: The system transmits a beacon signal based on the aforementioned short-range wireless communication, and upon receiving a response from the user terminal to the beacon signal, it requests the responding user terminal to transmit the registered biometric information of the user registered on the user terminal and authorization information indicating that the user has the right to use the service. The registered biometric information and the authorization information are obtained from the user terminal via short-range wireless communication. If the service provider's electronic signature is attached to the authorization information, the authorization information will be verified based on the electronic signature to ensure that it has not been tampered with. Authentication is performed by comparing the aforementioned biometric information for authentication with the aforementioned registered biometric information. Based on the authorization information and the condition information, it is determined whether the content of the service for which the user has access rights satisfies the conditions for providing the service. A user authentication method that, if both the authentication result and the determination result are normal, permits the provision of services for which the user has access rights.