Information processing system, information processing method, and information processing device

The information processing system addresses high costs and security vulnerabilities in conventional authentication methods by enabling secure user authentication through NFC communication between mobile terminals and service execution devices, reducing the need for dedicated terminals and preventing identity theft.

JP7896311B2Active Publication Date: 2026-07-29OKI ELECTRIC INDUSTRY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
OKI ELECTRIC INDUSTRY CO LTD
Filing Date
2022-03-29
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Conventional user authentication methods require dedicated terminals for biometric data acquisition, incurring high introduction and maintenance costs, and are vulnerable to identity theft, especially in face authentication services using smartphones.

Method used

An information processing system comprising a mobile terminal, a service identification device, and a service execution device that facilitates user authentication through NFC communication, reducing the need for dedicated terminals and enhancing security by leveraging existing mobile devices for authentication processing.

Benefits of technology

This system reduces the costs associated with dedicated authentication terminals and prevents identity theft by utilizing mobile devices for secure user authentication, thereby improving operational efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007896311000001
    Figure 0007896311000001
  • Figure 0007896311000002
    Figure 0007896311000002
  • Figure 0007896311000003
    Figure 0007896311000003
Patent Text Reader

Abstract

To enable suppressing introduction cost or maintenance management cost of a dedicated terminal for authentication, and preventing masquerading as person in question.SOLUTION: An information processing system according to the present invention comprises: an application execution apparatus that is given service identification means having service identification information and executes an application using a service; a portable terminal that acquires service identification information from service identification means and performs processing corresponding to the service identification information; a service execution apparatus that performs a service corresponding to the service identification information; and an information processing apparatus that intermediates processing between a portable terminal which is a request source and a service execution apparatus which is a request destination on the basis of service request information including the service identification information from the portable terminal, and that gives a result obtained by the service execution apparatus which is the request destination to the portable terminal and the application execution apparatus.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, an information processing method, and an information processing apparatus.

Background Art

[0002] Conventionally, when authenticating the user himself / herself, for example, an identity document such as a driver's license, an insurance card, or a My Number card is used to confirm the user himself / herself. There is also a mechanism such as biometric authentication using the user's biometric information, such as the user's face feature data, fingerprint data, iris data, etc. Furthermore, recently, face authentication services that utilize functions installed in mobile terminals such as smartphones have become widespread. Some systems register the face feature data, which is the information source for personal authentication, by photographing the face or a driver's license with a camera.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the case of the above-described conventional methods, in order to acquire the user's biometric information, it is necessary for the side performing the confirmation to prepare a dedicated terminal for reading the user's face, fingerprint, iris, etc. There is a problem that burdens such as the introduction cost and maintenance cost of the dedicated terminal are imposed on the side performing the confirmation.

[0005] Also, regarding the face authentication service that uses the user's smartphone, since the operation is such that the user uses the smartphone to register face information, a driver's license, etc., there is also a problem that it is easy to impersonate the user himself / herself.

[0006] Therefore, there is a need for information processing systems, information processing methods, and information processing devices that can reduce the costs of introducing and maintaining dedicated authentication terminals, and prevent identity theft. [Means for solving the problem]

[0007] To solve the above problems, the first information processing system according to the present invention is characterized by comprising: an application execution device that is provided with service identification means having service identification information that identifies a service including user authentication processing, and performs an application using the service, and performs an operation according to the user's authentication result; a mobile terminal that acquires service identification information from the service identification means and performs processing corresponding to the service identification information, and acquires at least the user's authentication information; a service execution device that performs the authentication processing included in the service corresponding to the service identification information; and an information processing device that mediates processing between the requesting mobile terminal and the requesting service execution device based on service request information including service identification information from the mobile terminal, and when the service to be executed is the user authentication processing, provides the service execution device with information including the user's authentication information from the mobile terminal to perform the authentication processing, and provides the authentication result acquired from the service execution device to the mobile terminal and the application execution device. 。

[0008] The 2 The information processing method according to the present invention is characterized in that a mobile terminal obtains service identification information that identifies a service including user authentication processing from a service identification means attached to an application execution device, performs processing corresponding to the service identification information, obtains at least user authentication information, and the information processing device mediates processing between the requesting mobile terminal and the requesting service execution device based on service request information including the service identification information from the mobile terminal, and if the service to be executed is user authentication processing, provides the service execution device with information including the user authentication information from the mobile terminal to execute the authentication processing, and provides the authentication result obtained from the service execution device to the mobile terminal and the application execution device.

[0009] The 3 The information processing device according to the present invention is equipped with service identification means having service identification information that identifies a service including user authentication processing, and is connected to a mobile terminal that acquires service identification information from the service identification means and performs processing corresponding to the service identification information, and a service execution device that performs authentication processing included in the service corresponding to the service identification information, and is an information processing device that mediates processing between the requesting mobile terminal and the requesting service execution device based on service request information including service identification information from the mobile terminal, and is characterized by comprising means for providing information including user authentication information from the mobile terminal to the service execution device and executing authentication processing when the service to be executed is user authentication processing, and means for providing information including user authentication information from the mobile terminal to the service execution device and having the authentication processing executed, and providing the authentication result obtained from the service execution device to the mobile terminal and the application execution device. [Effects of the Invention]

[0010] According to the present invention, the costs of introducing and maintaining dedicated authentication terminals can be reduced, and identity theft can be prevented. [Brief explanation of the drawing]

[0011] [Figure 1] This is an overall configuration diagram showing the overall configuration of the service provision system according to the embodiment. [Figure 2] This is an internal configuration diagram showing the internal configurations of the tag device, service provision device, corporate server, and mobile terminal according to the embodiment. [Figure 3] This is an internal configuration diagram showing the internal configuration of the management server according to the embodiment. [Figure 4] This is a configuration diagram showing an example of the configuration of history information recorded as history in the integrated database unit according to the embodiment. [Figure 5]It is an internal configuration diagram showing the internal configuration of the authentication institution server according to the embodiment. [Figure 6] It is an operation diagram showing the overall operation of the service providing system according to the embodiment. [Figure 7] It is a sequence diagram showing the operation of the authentication process according to the embodiment. [Figure 8] It is a sequence diagram showing the operation of the voice communication process according to the embodiment.

Mode for Carrying Out the Invention

[0012] (A) Embodiment Hereinafter, embodiments of the information processing system, information processing method, and information processing apparatus according to the present invention will be described in detail with reference to the drawings.

[0013] (A-1) Configuration of the Embodiment FIG. 1 is an overall configuration diagram showing the overall configuration of a service providing system (hereinafter, also referred to as an "information processing system") according to the embodiment.

[0014] In FIG. 1, the service providing system 9 of the embodiment includes a management server 1 as an information processing apparatus, a mobile terminal 2 of a user U, a corporate server 4 provided by the service provider side, a service providing apparatus 5 as an application execution apparatus, a tag apparatus 3 as a service identification means, one or more authentication institution servers 6 (6-1, 6-2,...), and a call center server 7.

[0015] Note that the authentication institution server 6 and the call center server 7 are examples of "service execution apparatuses".

[0016] When the user U holds the mobile terminal 2 near the tag device 3 and starts short-range wireless communication such as NFC (Near Field Communication) between the mobile terminal 2 and the tag device 3, the application software (hereinafter also referred to as "app") that performs processing corresponding to the tag information preset in the tag device 3 is launched on the mobile terminal 2, and services such as voice communication and identity authentication are provided to the user U via the management server 1.

[0017] A "service" is a service provided to the user in relation to the use of the service providing device (application execution device) 5 by the user U, including, for example, voice communication, authentication processing, payment processing, etc. These services can be performed using an app on the mobile terminal 2 that performs NFC communication with the tag device 3 for the user U.

[0018] [Tag device 3, service providing device 5, enterprise server 4] FIG. 2 is an internal configuration diagram showing the internal configurations of the tag device 3, service providing device 5, enterprise server 4, and mobile terminal 2 according to the embodiment.

[0019] The tag device 3 is, for example, a device equipped with NFC. The tag device 3 includes an IC chip device having a short-range wireless communication unit 31, a storage unit 32, and a control unit 33. The tag device 3 can be, for example, a contactless IC tag type, an IC card type, a stationary type, etc. The tag device 3 is provided in a form corresponding to the service provision scenario at the location where the user U receives the service or the device (such as the service providing device 5) handled by the user U.

[0020] For example, the tag device 3 may be provided for each service such as voice communication, biometric authentication, and payment, or alternatively, the tag device 3 may be capable of supporting a plurality of services such as voice communication, biometric authentication, and payment.

[0021] In the former case, that is, the tag device 3 provided for each service, stores in advance service identification information that uniquely identifies the corresponding service and tag information associated with the service. In the latter case, the tag device 3 stores the service identification information and tag information for each service, and the user U may be prompted to select which service to use on the mobile terminal 2 that receives the tag information.

[0022] Furthermore, the tag device 3 also stores usage identification information that identifies the purpose of the service provided, such as ATMs, car sharing, and call centers; an individual ID that identifies the tag device 3 itself; and a company ID that identifies the service provider (e.g., a company).

[0023] When the tag device 3 communicates with the mobile terminal 2 via NFC, it transmits tag information, including the aforementioned service identification information, usage identification information, individual ID, company ID, etc., to the mobile terminal 2. Note that the tag information is not limited to the information described above.

[0024] The service provider 5 is a device related to the services provided to user U. For example, an ATM (Auto Teller Machine) in financial transactions, or a car in the case of car sharing, would be considered the service provider 5. In this embodiment, the service provider 5 is to be handled by user U. The service provider 5 has a control unit 51 that manages the functions of the service provider 5 and a communication unit 52 that communicates with the corporate server 4.

[0025] The enterprise server 4 is a server that connects to the service provider 5 and controls the operation of the service provider 5. The enterprise server 4 can be an existing general-purpose server, for example, having a control unit 41, a storage unit 42, and a communication unit 43.

[0026] The enterprise server 4 is connected to the management server 1 via the network NT and instructs the corresponding service provider 5 to take action according to the authentication result of user U's identity authentication. In other words, the enterprise server 4 instructs the service provider 5 to take action when user U's authentication is successful or when authentication fails.

[0027] The actions that the corporate server 4 instructs the service provider 5 to perform upon successful authentication vary depending on the type and purpose of the service provider 5. For example, if the service provider 5 is an ATM, it may perform initial operations such as displaying a screen for PIN entry upon successful authentication. Alternatively, if the service provider 5 is a car-sharing vehicle, it may perform actions such as unlocking the vehicle's keys.

[0028] [Mobile device 2] Mobile terminal 2 is a device owned by user U, and can be, for example, a smartphone, tablet, or wearable device. In this embodiment, mobile terminal 2 is assumed to have NFC functionality. Furthermore, mobile terminal 2 is assumed to have an application installed that, when communicating with tag device 3 via NFC, activates processes such as voice communication and user authentication, and performs these processes through management server 1 (corresponding to the "NFC utilization processing unit 210" described later).

[0029] As illustrated in Figure 2, the mobile terminal 2 includes a control unit 21, a storage unit 22, a short-range wireless communication unit 23, a camera 24, a location information acquisition unit 25, a microphone 26, a speaker 27, a biosensor 28, and a communication unit 29.

[0030] The control unit 21 is responsible for the operation of the mobile terminal 2. The control unit 21 has an NFC utilization processing unit 210 that, triggered by the start of communication with the tag device 3, initiates processing corresponding to the service identification information of the tag information.

[0031] The NFC utilization processing unit 210 launches the corresponding application (e.g., voice communication, authentication processing, etc.) based on the service identification information contained in the tag information and performs processing through the management server 1. In other words, the NFC utilization processing unit 210 functions to coordinate the processing of applications with the management server 1.

[0032] Here, the application that is activated when communication with the tag device 3 is initiated is exemplified as voice communication and authentication processing to authenticate the user, but it is not limited to these, and may perform other processes such as payment processing. The applications such as the voice communication unit 211 and the authentication processing unit 212 may be independently installed on the mobile terminal 2 as a specified or standard application.

[0033] The voice communication unit 211 can apply IP (Internet Protocol) telephone functionality. The voice communication unit 211 sends call control information to the management server 1, specifying the destination number (for example, the telephone number of the call center server 7) included in the tag information as the destination. This enables communication between the mobile terminal 2 and the operator terminal of the call center server 7 through call control by the management server 1.

[0034] The authentication processing unit 212 performs authentication processes such as facial recognition, which involves comparing facial feature data extracted from a facial image with pre-registered facial feature data, or fingerprint authentication, which involves reading fingerprint feature data with a fingerprint sensor and authenticating by comparing it with pre-registered data. The authentication method is not limited to facial recognition or fingerprint authentication; other authentication processes can also be applied.

[0035] The service identification information included in the tag information also distinguishes the type of authentication method, and the authentication processing unit 212 operates the corresponding authentication method based on the service identification information.

[0036] Furthermore, if the authentication processing unit 212 obtains a successful authentication result from the authentication authority server 6 through the management server 1, it stores the authentication result cache 221 in the storage unit 22 so that the result of this successful authentication can be used when authentication is required for another service or the next service. As a result, user U can receive services using the authentication result cache 221, reducing the burden of repeatedly performing the same authentication process by the authentication authority server 6 each time a service is used. Note that the storage period or the number of uses for the authentication result cache 221 of successful authentications may be set in advance.

[0037] The storage unit 22 stores processing programs executed by the control unit 21 (for example, applications for the NFC utilization processing unit 210, voice communication programs, authentication processing programs, etc.), data necessary for processing, etc. The storage unit 22 also temporarily stores the authentication result cache 221.

[0038] The short-range wireless communication unit 23 performs NFC short-range wireless communication, and when it acquires tag information from the tag device 3 via NFC, it provides that tag information to the control unit 21.

[0039] Camera 24 captures an image of user U's face during facial recognition. Location information acquisition unit 25 acquires location information (latitude and longitude information) from, for example, GPS satellites.

[0040] The microphone and speaker 27 can be those installed in the mobile terminal 2 and are used when performing voice communication.

[0041] The biosensor 28 can be, for example, a fingerprint sensor that detects the user U's fingerprint during fingerprint authentication. The biosensor 28 may also be used for other biometric authentication processes.

[0042] [Management Server 1, Integrated Database Unit 10] Figure 3 is an internal configuration diagram showing the internal configuration of the management server 1 according to the embodiment.

[0043] In Figure 3, the management server 1 is connected to the integrated database unit 10 and includes a control unit 11, a communication unit 12, and a storage unit 13.

[0044] For the sake of explanation, the management server 1 is shown here as a single physical device, but it is not limited to this; the functions of the management server 1 may be implemented on servers that are distributed across multiple servers.

[0045] Furthermore, the management server 1 and the integrated database unit 10 may be implemented on a multi-tenant cloud platform.

[0046] The communication unit 12 communicates with the mobile terminal 2 and the corporate server 4 via the network NT. The communication unit 12 also communicates with the certification authority server 6 and the call center server 7 via the network NT.

[0047] The memory unit 13 stores the processing program (for example, an information processing program) from the control unit 11, and the data necessary for executing the processing program.

[0048] The control unit 11 is responsible for the functions of the management server 1. The control unit 11 includes a management control unit 110 that, triggered by communication with the tag device 3, mediates the processing requested by the mobile terminal 2 between the call center server 7 or the authentication authority server 6.

[0049] When the management control unit 110 receives a login request from the mobile terminal 2, it compares the registered data with the login data, sends the result of the login process back to the mobile terminal 2, and further records the login data history in the integrated database unit 10.

[0050] The management control unit 110 includes a voice communication control unit 111 that controls the call between the mobile terminal 2 and the call center server 7 when it receives a voice communication outgoing request from the mobile terminal 2, and an authentication control unit 112 that makes an authentication request to the authentication authority server 6 that performs the corresponding type of authentication process when it receives an authentication request from the mobile terminal 2.

[0051] The voice communication control unit 111 controls calls between the mobile terminal 2 and the call center server 7. Furthermore, when a call between the mobile terminal 2 and the operator terminal on the call center server 7 ends, the voice communication control unit 111 records data related to the voice communication in the integrated database unit 10.

[0052] The voice communication control unit 111 may be equipped with a function to translate between global IP addresses and private IP addresses (so-called NAT traversal) to solve the problem of not being able to make calls across networks when establishing network connections between multiple hosts using NAT equipment. For example, as a technology to perform NAT traversal for the voice communication control unit 111 of the management server 1, address resolution can be performed using STUN (Simple Traversal of UDP Through NAT), ICE (Interactive Connectivity Establishment), etc., thereby configuring a B2BUA (Back-To-Back User Agent) and ensuring voice communication and security between different networks.

[0053] When the authentication control unit 112 receives an authentication request from the mobile terminal 2, it ensures secure information communication both between the mobile terminal 2 and the management server 1, and between the management server 1 and the authentication authority server 6, in order to improve information security. Furthermore, after ensuring secure information communication, the authentication control unit 112 relays authentication-related information (for example, information including information that identifies user U, tag information, location information, facial feature data, or fingerprint feature data) between the mobile terminal 2 and the authentication authority server 6.

[0054] Furthermore, the authentication control unit 112 records information related to the authentication being relayed, information related to the authentication result from the authentication authority server 6, etc., in the integrated database unit 10.

[0055] Furthermore, when the authentication control unit 112 receives the authentication result from the authentication authority server 6, it sends the authentication result to both the corporate server 4 and the mobile terminal 2 in order to cause the service provider device 5 to take action according to the authentication result. The destination information of the corporate server 4 (e.g., IP address, MAC address, etc.) can be set in advance, for example, in the tag information.

[0056] Here, we illustrate the case where the authentication control unit 112 sends the authentication result to the corporate server 4. However, if the service provider 5 can perform actions according to the authentication result, the authentication result may be sent directly to the service provider 5. In that case, this can be achieved by including the communication address of the service provider 5 in the tag information in advance.

[0057] The integrated database unit 10 stores information related to the processing of requests made by the mobile terminal 2, triggered by communication with the tag device 3.

[0058] Figure 4 is a configuration diagram showing an example of the configuration of history information recorded as history in the integrated database unit 10 according to the embodiment.

[0059] In Figure 4, for example, the integrated database unit 10 includes the following items: "Communication ID," "Tag Information," "Location Information," "Time Information," "OS / Model Type," "Dedicated Application (AP) ID," "User ID," and "Authentication Result." Furthermore, the item "Tag Information" includes the following items: "Service Identification Information," "Purpose Identification Information," "Individual ID," and "Company ID."

[0060] Furthermore, the items included in "tag information" are not limited to those shown in Figure 4; they may also include "call center's outgoing telephone number," "identification information of the service provider 5 to which the tag device 3 is attached," "communication destination information of the authentication authority server 6 (e.g., IP address)," "communication destination information of the corporate server 4 (e.g., IP address)," etc. In addition, the history information recorded as history in the integrated database unit 10 is not limited to the items shown in Figure 4; it may also include, if the service is voice communication, "call duration from the start to the end of the call path," if the service is biometric authentication, "type of facial recognition or fingerprint authentication," "feature data" used for authentication, etc.

[0061] [Certification Authority Server 6] Figure 5 is an internal configuration diagram showing the internal configuration of the certification authority server 6 according to the embodiment.

[0062] The authentication authority server 6 is connected to a customer database unit 60 that stores pre-registered information necessary for biometric authentication of user U for each user U, and performs specific types of authentication processing by referring to the customer database unit 60.

[0063] As shown in Figure 5, the authentication authority server 6 includes a control unit 61, a communication unit 62 that communicates with the management server 1 via the network NT, and a storage unit 63 that stores processing programs executed by the control unit 61 (for example, authentication execution programs, etc.) and data necessary for processing.

[0064] The control unit 61 is responsible for various functions of the authentication authority server 6. The control unit 61 has an authentication execution unit 611 that performs specific types of biometric authentication processing.

[0065] The authentication execution unit 611 performs specific types of authentication processes, such as facial recognition, fingerprint recognition, and iris recognition. For example, in the case of facial recognition, the authentication execution unit 611 obtains the facial feature data of user U through the communication unit 62. It then compares the obtained facial feature data with the facial feature data registration information of user U that is pre-registered in the customer database unit 60. If the feature data matches, authentication is considered successful; otherwise, authentication is considered a failure.

[0066] The customer database unit 60 stores customer data (e.g., user ID, user name, gender, address, etc.), registration data of biometric information used for biometric authentication matching (e.g., facial feature registration data, fingerprint feature registration data), biometric information used for authentication (e.g., facial feature data, fingerprint feature data), and authentication results.

[0067] [Call center server 7] The call center server 7 connects to multiple operator terminals and manages calls between operators and users U. The call center server 7 can widely adapt to various existing systems.

[0068] (A-2) Operation of the embodiment Figure 6 is an operation diagram showing the overall operation of the service provision system 9 according to the embodiment.

[0069] In the following section, the service provision method (information processing method) in the service provision system 9 according to the embodiment will be described with reference to the drawings.

[0070] The following operation description uses the following usage environment as an example. Of course, it is not limited to this environment.

[0071] For example, suppose a tag device 3 is attached to the ATM, which serves as the service provider 5, or is located near the ATM. User U can authenticate themselves using NFC between their mobile terminal 2 and the tag device 3, and then use the ATM. Another example is when, for example, user U needs to contact the call center when using the ATM, and the NFC between the mobile terminal 2 and the tag device 3 enables them to make a call to the call center.

[0072] (A-2-1) Authentication process Figure 7 is a sequence diagram showing the operation of the authentication process according to the embodiment.

[0073] First, it is assumed that the mobile terminal 2 has an NFC utilization processing unit 210 installed, which is application software that, upon communicating with the tag device 3 via NFC, initiates processes such as voice communication and user authentication, and performs these processes through the management server 1.

[0074] Furthermore, it is assumed that registered facial data, from which feature data has been extracted from the facial information of user U, is pre-registered in the authentication authority server 6 (S330).

[0075] In the situation described above, user U will hold their mobile terminal 2 over the tag device 3, authenticate themselves using user U's biometric information, and then use the ATM.

[0076] In this example, for instance, the tag information of tag device 3 might be: "Service identification information: Biometric authentication (e.g., "facial recognition")", "Usage identification information: ATM", "Individual ID: A54321", "Company ID: XYZ-01", etc.

[0077] User U holds their mobile device 2 over the tag device 3. When NFC communication begins between the mobile device 2 and the tag device 3, this triggers the activation of the NFC utilization processing unit 210.

[0078] Since the NFC utilization processing unit 210 operates effectively on the mobile terminal 2, user U must complete the login to the management server 1. The method of login is not particularly limited, but for example, the following method can be applied.

[0079] User U enters their ID and password into the mobile terminal 2 for login (S101). The NFC utilization processing unit 210 on the mobile terminal 2 sends a login request to the management control unit 110 of the management server 1 (S102), and the management control unit 110 compares the entered login data with the registration data previously registered in the integrated database unit 10 (S103).

[0080] As a result, if the data verification is successful (S104), the authentication result is sent back to the management control unit 110 (S105), the management control unit 110 sends a message to the NFC utilization processing unit 210 indicating that the login is successful (S106), and the NFC utilization processing unit 210 indicates to user U that the login is complete (S107).

[0081] Furthermore, the management control unit 110, upon receiving the authentication result, records the user U's authentication result in the integrated database unit 10 (S108). In this way, the NFC utilization processing unit 210 operates effectively on the mobile terminal 2.

[0082] The tag information includes service identification information that identifies the biometric authentication to be performed as a service. When the mobile terminal 2 receives the tag information from the tag device 3 via NFC, the authentication processing unit 212 corresponding to the service identification information contained in the tag information is activated (S300).

[0083] Here, for example, if the biometric authentication is facial recognition, camera 24 is activated to obtain the facial information of user U, and camera 24 captures an image of user U's face (S301). The authentication processing unit 212 then analyzes the facial image from camera 24 and extracts the facial feature data of user U.

[0084] At this time, for example, a message confirming transmission to the authentication authority is displayed on the display of the mobile terminal 2, and when user U selects OK to transmit, the authentication processing unit 212 encrypts the extracted facial feature data for information security (S302). Also, in the mobile terminal 2, for example, the location information acquisition unit 25, which functions as a GPS, is activated, and location information such as latitude and longitude information is provided to the authentication processing unit 212 (S303).

[0085] In order to transmit information to the authentication authority server 6 via the management server 1, the authentication processing unit 212 encrypts data such as tag information obtained from the tag device 3, facial feature data as biometric information of user U, location information, and OS / model information of the mobile terminal 2 (S304).

[0086] Furthermore, time information may be included as information transmitted to the certification authority server 6. In other words, the time information may be the time recorded in the integrated database unit 10 of the management server 1, or it may be the time information on the mobile terminal 2.

[0087] When transmitting to the certification authority server 6, in order to ensure the security of the information being transmitted, the management control unit 110 of the management server 1 obtains the address information of the certification authority server 6 (e.g., IP address) included in the tag information from the authentication processing unit 212 of the mobile terminal 2 and negotiates to ensure secure communication.

[0088] For example, the management control unit 110 ensures a secure bidirectional tunnel for information communication between the authentication processing unit 212 of the mobile terminal 2 and the authentication control unit 112 of the management server 1, and between the authentication execution unit 611 of the authentication authority server 6 and the authentication control unit 112 of the management server 1 (S305, S306).

[0089] Then, the authentication processing unit 212 of the mobile terminal 2 sends information (encrypted data) destined for the authentication authority server 6, including tag information, facial feature data, location information, OS / model information, etc., to the management server 1 (S307). The management server 1 also forwards the information from the authentication processing unit 212 of the mobile terminal 2 destined for the authentication authority server 6 to the authentication authority server 6 (S308).

[0090] Here, in the management server 1, the authentication control unit 112 decrypts the information (encrypted data) received from the authentication processing unit 212 of the mobile terminal 2 (S309), and the authentication control unit 112 records the decrypted information, including tag information and location information, in the integrated database unit 10 (S310).

[0091] In this case, the authentication processing unit 212 decrypts the information recorded in the integrated database unit 10. Therefore, although it is explained that the authentication processing unit 212 decrypts information such as tag information, location information, and OS / model information, if it is necessary to record the user U's facial feature data itself in the integrated database unit 10, the facial feature data may also be decrypted. However, in this embodiment, from the viewpoint of ensuring security, an example is given in which facial feature data is not recorded and not decrypted.

[0092] When the authentication authority server 6 receives information from the mobile terminal 2 via the management server 1, the authentication execution unit 611 decrypts the received information and decrypts the user U's facial feature data (S311).

[0093] Then, the authentication execution unit 611 searches the customer database unit 60 for the registered face data of user U based on the user ID included in the received information, and the authentication execution unit 611 performs a comparison (matching) of the received face feature data with the registered face data (S312).

[0094] In this example, assuming that the authentication was successful (authentication OK), the authentication authority server 6 sends the authentication result from the authentication execution unit 611 to the management server 1 (S313).

[0095] On the management server 1, the authentication control unit 121 transmits the authentication result of user U's facial recognition by the authentication authority server 6 to both the mobile terminal 2 and the corporate server 4 (S314, S315).

[0096] As a result, the authentication processing unit 212 in the mobile terminal 2 can display the authentication result on a display or the like to inform the user U (S316). The authentication processing unit 212 also stores the successful authentication result as an authentication result cache 221 in the storage unit 22.

[0097] On the other hand, the enterprise server 4 instructs the service provider 5 to perform an action according to the authentication result (S317), and the service provider 5 performs an action according to the authentication result (S318).

[0098] In this way, the authentication control unit 121 transmits the authentication result to both the mobile terminal 2 and the corporate server 4, not only informing the user U of the authentication result via the mobile terminal 2, but also causing the service provider 5 to perform actions according to the authentication result.

[0099] For example, if authentication is successful (authentication OK), the ATM, as the service provider 5, will consider that user U's identity has been authenticated and will permit user U to conduct financial transactions, for example, by displaying a transaction menu screen or by allowing the user to enter a PIN to start a transaction.

[0100] Thus, according to this embodiment, when the legitimacy (authenticity) of user U is obtained through biometric authentication or the like, the service provision device 5 handled by user U can be operated according to the result. From user U's perspective, they can use the service provision device 5 in conjunction with their own legitimacy, which provides a sense of security. From the service provider's perspective, they can allow user U to use the service provision device 5 based on the trust derived from user U's legitimacy.

[0101] Although the example shown illustrates the operation of the service provider 5 via the corporate server 4, it is sufficient for the service provider 5 to operate according to the authentication result of user U. Therefore, the management server 1 may directly send the authentication result to the service provider 5 without going through the corporate server 4, and the service provider 5 may operate according to the authentication result.

[0102] Furthermore, while this embodiment illustrates a case where the legitimacy (authenticity) of user U is proven by biometric authentication, other authentication methods may be applied instead of biometric authentication.

[0103] The management server 1 records the authentication results received from the authentication authority server 6 in the integrated database unit 10 (S319).

[0104] For example, the management server 1 may record the billing information related to the authentication process requested from the authentication authority server 6 in the integrated database unit 10.

[0105] Subsequently, the management control unit 110 of the management server 1 terminates both the bidirectional tunnels between the authentication processing unit 212 of the mobile terminal 2 and the authentication control unit 112 of the management server 1, and between the authentication execution unit 611 of the authentication authority server 6 and the authentication control unit 112 of the management server 1 (S321, S322).

[0106] (A-2-2) Variation (a) In the explanation of operation using Figure 7 described above, the case where the authentication result by the certification authority server 6 is successful is shown as an example. If authentication fails, the process is repeated, returning to S301 in Figure 7, and an authentication request is sent to the certification authority server 6 through the management server 1. In other words, authentication to the certification authority server 6 can be retried. Even in that case, the management server 1 records the information regarding the process exchanged between the mobile terminal 1 and the certification authority server 6 as history in the integrated database unit 10.

[0107] Furthermore, if the number of retries exceeds a threshold, the user can contact an operator, for example, by using the voice communication processing described later in (A-2-3).

[0108] (b) In the explanation of operation using Figure 7, the example given is that the tag device 3 is installed in an ATM. However, it is not limited to this, and for example, in the case of car sharing, the tag device 3 can be installed in a car which serves as the service provision device 5, and the car's key can be unlocked upon successful authentication (S318 in Figure 7).

[0109] In that case, if user U does not use the vehicle (service provision device 5) within a predetermined time (for example, 5 minutes) after unlocking the vehicle, the system may be configured to re-lock the vehicle.

[0110] (c) When using the authentication result cache 221 after successful authentication, the NFC utilization processing unit 210 is activated on the mobile terminal 2 via NFC with the tag device 3. After this, for example, the processes S101 to S108 in Figure 7 may be performed, and when a login request is made in S102, the NFC utilization processing unit 210 may send the tag information to the management server 1 at the same time as the login request. This allows the integrated database unit 10 to record history information including tag information even when using the authentication result cache 221.

[0111] (A-2-3) Voice communication processing Figure 8 is a sequence diagram showing the operation of the voice communication processing according to the embodiment.

[0112] Since the NFC utilization processing unit 210 operates effectively on the mobile terminal 2, user U must complete the login to the management server 1.

[0113] For example, when user U uses the ATM as a service provider 5, user U holds their mobile terminal 2 over the tag device 3 and makes an inquiry to the operator using their mobile terminal 2.

[0114] In this example, for instance, the tag information of tag device 3 might be "Service identification information: Voice communication", "Purpose identification information: Call center", "Individual ID: OP9087", and "Company ID: HII-02".

[0115] The processes S101 to S108 in Figure 8 are basically the same as those described in Figure 7, but the activated NFC utilization processing unit 210 may receive tag information from the tag device 3 via NFC and notify the management control unit 110 of the tag information in step S102. This allows log information including tag information to be recorded in the integrated database unit 10 in advance.

[0116] User U, who wishes to contact a call center operator, holds their mobile device 2 over the tag device 3. When NFC communication begins between the mobile device 2 and the tag device 3, this triggers the activation of the NFC utilization processing unit 210.

[0117] The tag information includes service identification information that identifies voice communication. When the mobile terminal 2 receives the tag information from the tag device 3 via NFC, the voice communication unit 211 corresponding to the service identification information contained in the tag information is activated (S200).

[0118] The tag information of the tagging device 3 is pre-configured with destination information for calls to the call center (e.g., phone number, IP address, etc.).

[0119] The NFC utilization processing unit 210 displays the phone number of the call center server 7 contained in the tag information on the display of the mobile terminal 2, allowing user U to operate the mobile terminal 2 and make a call to the call center server 7 (S201).

[0120] The voice communication unit 211 of the mobile terminal 2 transmits a call control signal (recipient call signal) to the management server 1, with the address of the call center server 7 as the destination (S202). At this time, the voice communication unit 211 of the mobile terminal 2 displays "Call center calling in progress" on the display of the mobile terminal 2 (S203).

[0121] When the voice communication control unit 111 in the management server 1 receives a call control signal (calling signal to the other party) from the mobile terminal 2, it forwards the call control signal (calling signal) to the call center server 7 (S204).

[0122] The call center server 7, which has multiple operator terminals connected to it, calls an operator to one of the operator terminals (S205), and when the operator responds (S206), it sends a response signal (call center response) back to the management server 1 (S207). Note that a wide variety of methods can be applied to the selection of operator terminals in the call center and the processing related to call connections with operator terminals.

[0123] When the voice communication control unit 111 in the management server 1 receives a response signal (call center response) from the call center server 7, it forwards the response signal to the mobile terminal 2 (S208).

[0124] Here, for example, some conventional call centers connected to ATMs belong to a private network depending on their operation. In that case, a NAT traversal problem may occur, potentially preventing a call connection between the mobile terminal 2 and the call center operator's terminal.

[0125] Therefore, the voice communication control unit 111 of the management server 1 may be equipped with an address resolution function that enables conversion between global addresses and private addresses. For example, the voice communication control unit 111 performs address and port resolution negotiation with the NFC utilization processing unit 210 of the mobile terminal 2 and the call center server 7, and performs address and port resolution (S209, S210).

[0126] Subsequently, a call (call path) is established between the mobile terminal 2 and the call center operator's terminal, and user U and the operator communicate (S211).

[0127] When the call ends (S212), the voice communication unit 211 of the mobile terminal 2 sends a control signal indicating the end of the call to the voice communication control unit 111 of the management server 1 (S213), and the call (call path) is disconnected (S214).

[0128] Then, the voice communication control unit 111 sends a control signal to the call center server 7 indicating the end of the call (S215), and the call ends (S216).

[0129] In the management server 1, the voice communication control unit 111 records call-related information (for example, call duration, call history, call-related billing information, etc.) in the integrated database unit 10 (S217).

[0130] (A-3) Effects of the Embodiment As described above, this embodiment allows businesses to reduce the cost of introducing dedicated devices and communication costs by providing a tag device that performs near-field communication (NFC) and a management server that controls the system. Furthermore, since the registration and management of facial information are handled by an authentication body, conventional measures against identity theft can be implemented.

[0131] (B) Other embodiments Although various modified embodiments have been mentioned in the embodiments described above, the present invention can also be applied to the following modified embodiments.

[0132] (B-1) In the description of the operation of the above embodiment, two cases, authentication processing and voice communication processing, were given as examples, but it is also possible to combine these operations. In other words, during ATM operation, authentication processing and voice communication processing may be performed using NFC with the tag device 3.

[0133] (B-2) In the embodiments described above, facial recognition using a camera was explained, but biometric authentication may also be performed using a fingerprint authentication device installed in recent smartphones, in addition to iris recognition using a camera.

[0134] Furthermore, the tagging device can also use QR codes (registered trademark) or similar as an identification method for a dedicated app, and the objects controlled based on the matching results can be broadly applied to applications other than automobiles, such as ATMs, access control systems, and counter services where identity verification is required. [Explanation of Symbols]

[0135] 1...Management server, 10...Integrated database unit, 11...Control unit, 110...Management control unit, 111...Voice communication control unit, 112...Authentication control unit, 121...Authentication control unit, 12...Communication unit, 13...Storage unit, 2...Mobile terminal, 21...Control unit, 210...NFC utilization processing unit, 211...Voice communication unit, 212...Authentication processing unit, 221...Authentication result cache, 22...Storage unit, 23...Short-range wireless communication unit, 24...Camera, 25...Location information acquisition unit, 26...Microphone, 27...Speaker, 28...Biometric sensor, 29...Communication unit, 3...Tag device, 31...Short-range wireless communication unit, 32...Storage unit, 33...Control unit, 4...Corporate server, 41...Control unit, 42...Storage unit, 43...Communication unit, 5...Service provision device, 51...Control unit, 52...Communication unit, 6...Certification authority server, 60...Customer database unit, 61...Control unit, 611...Certification execution unit, 62...Communication unit, 63...Storage unit, 7...Call center server, 9...Service delivery system.

Claims

1. A service execution device is provided with service identification means having service identification information that identifies a service including user authentication processing, and which performs an application using the said service, and which performs an operation according to the user authentication result, A mobile terminal that obtains the service identification information from the service identification means and performs processing corresponding to the service identification information, and obtains at least the user's authentication information, A service execution device that executes the authentication process included in the service corresponding to the aforementioned service identification information, An information processing device that mediates processing between the requesting mobile terminal and the requesting service execution device based on service request information including the service identification information from the mobile terminal, and when the service to be executed is user authentication processing, provides the service execution device with information including the user's authentication information from the mobile terminal to perform the authentication processing, and provides the authentication result obtained from the service execution device to the mobile terminal and the application execution device. An information processing system characterized by comprising the following features.

2. The information processing system according to claim 1, characterized in that the information processing device includes information storage means for storing information relating to processing performed between the mobile terminal and the service execution device.

3. The mobile terminal obtains service identification information from the service identification means attached to the application execution device, which identifies a service including user authentication processing, performs processing corresponding to the service identification information, and obtains at least the user authentication information. Information processing device, Based on the service request information including the service identification information from the mobile terminal, the mobile terminal, which is the requesting party, mediates the processing between the mobile terminal, which is the requesting party, and the service execution device, which is the requesting party, and if the service to be executed is the user authentication process, the mobile terminal provides the service execution device with information including the user's authentication information to cause the authentication process to be executed. The authentication result obtained from the service execution device is provided to the mobile terminal and the application execution device. An information processing method characterized by the following:

4. A service execution device is provided with service identification means having service identification information that identifies a service including user authentication processing, and which performs an application using the said service, and which performs an operation according to the user authentication result, A mobile terminal that obtains the service identification information from the service identification means and performs processing corresponding to the service identification information, A service execution device that executes the authentication process included in the service corresponding to the aforementioned service identification information. An information processing device that connects to, Based on the service request information including the service identification information from the mobile terminal, the means mediates the processing between the requesting mobile terminal and the requesting service execution device, and when the service to be executed is the user authentication process, the means provides the service execution device with information including the user authentication information from the mobile terminal to execute the authentication process. Means for providing the authentication result obtained from the service execution device to the mobile terminal and the application execution device. An information processing device characterized by comprising: