Door unlocking system, terminal device, equipment control system, and door unlocking method
Patent Information
- Application Number
- JP2022085405
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-25
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2042-05-25
AI Technical Summary
【0011】 本発明によれば、人物照合処理により、利用者がドアの解錠を許可できる登録者であることを確認することができる。また、位置照合処理により、利用者がドアの近傍に滞在していることを確認することができる。これにより、利用者が所持する端末装置を利用することで、利用者が認証を受ける地点に認証専用の装置を必要とせず、簡易な構成でセキュリティ性の高い認証を実現することができる。
Smart Images

Figure 0007909216000001 
Figure 0007909216000002 
Figure 0007909216000003
Abstract
Description
Technical Field
[0001] The present invention relates to a door unlocking system and a door unlocking method for controlling door unlocking according to the result of user biometric authentication, a terminal device on which an operation related to user biometric authentication is performed, and a device control system for controlling a target device according to the result of user biometric authentication.
Background Art
[0002] In order to restrict entry to pre-registered persons, a system for managing the entry of persons using an IC card has been widely spread. Furthermore, in recent years, instead of card authentication using an IC card, biometric authentication using biometric information such as a person's face or iris has also been spreading. On the other hand, in recent years, since many people carry mobile terminals such as smartphones and tablet terminals, it is conceivable to enhance the security of authentication using a mobile terminal.
[0003] As such a system using a mobile terminal possessed by a user, conventionally, a user is identified by collating a face image obtained by photographing a user standing in front of a door with a camera with a face image of a registered person, and an authentication code including a door ID corresponding to the camera that photographed the user and an ID of the identified user is generated and transmitted to a mobile terminal possessed by the user. A technique for unlocking a door by causing a code reader installed near the door to read the authentication code displayed on the screen of the mobile terminal is known (see Patent Document 1).
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Conventional technologies allow for enhanced authentication security by utilizing mobile devices carried by users. However, these technologies require a camera to photograph the user as well as a code reader to read the authentication code, leading to a problem where the system becomes cumbersome as the number of authentication locations increases. Therefore, a simpler configuration that does not require dedicated authentication equipment at each authentication location is desired.
[0006] Therefore, the main objective of the present invention is to provide a door unlocking system, terminal device, equipment control system, and door unlocking method that utilize a terminal device owned by the user, thereby eliminating the need for a dedicated authentication device at the point where the user is authenticated, and enabling highly secure authentication with a simple configuration. [Means for solving the problem]
[0007] The present invention relates to a door unlocking system that controls the unlocking of a door according to the result of a person matching process based on the user's biometric information, comprising: a server device that remotely controls a locking device installed on the door; and a terminal device that is carried by the user, connected to the server device via a network, and has a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, wherein the server device acquires the user's biometric information acquired by the sensor and the location information of the terminal device acquired by the positioning unit from the terminal device, performs a person matching process that compares the user's biometric information with the registered person's biometric information, and also performs a location matching process that compares the location information of the terminal device with the location information of the door, A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the door, and a determination is made as to whether or not the door can be unlocked based on the results of the person matching process, the location matching process and the unique object matching process. This will be the structure.
[0008] Furthermore, the terminal device of the present invention is carried by the user and connected via a network to a server device that remotely controls a locking device installed on a door, and comprises a sensor that acquires the user's biometric information, a positioning unit that acquires the location information of the device itself, and a display input unit that displays a screen and accepts user operation input, and an authentication guidance screen that provides guidance regarding the acquisition of the user's biometric information, and the server device that acquires the user's biometric information、 Location information of the aforementioned self-device and the result of a unique object matching process that compares unique object information obtained based on at least one of the self-device and the user with unique object information registered in association with the door. The system is configured to display a result confirmation screen regarding the determination of whether or not the door can be unlocked, which is made based on the above, and a result confirmation screen.
[0009] Furthermore, the present invention relates to a device control system that controls a target device in accordance with the results of a person matching process based on the user's biometric information, comprising: a server device that remotely controls the target device; a terminal device possessed by the user, connected to the server device via a network, having a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, wherein the server device acquires the user's biometric information acquired by the sensor and the location information of the terminal device acquired by the positioning unit from the terminal device, performs a person matching process that compares the user's biometric information with the registered person's biometric information, and also performs a location matching process that compares the location information of the terminal device with the location information of the target device, A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the target device. The person matching process and the location matching process, The aforementioned unique object verification process Based on the results, the system is configured to determine whether or not the target device can be controlled.
[0010] Furthermore, the present invention is a door unlocking method in which a processor executes a process to control the unlocking of a door according to the result of a person matching process based on the user's biometric information, the process involves obtaining the user's biometric information obtained by the sensor and the location information of the terminal device obtained by the positioning unit from a terminal device possessed by the user and having a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, executing a person matching process that compares the user's biometric information with the registered person's biometric information, and executing a location matching process that compares the location information of the terminal device with the location information of the door. A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the door. The person matching process and the location matching process, The aforementioned unique object verification process Based on the results, the system determines whether or not the door can be unlocked, and remotely controls the locking device installed on the door according to the determination result. [Effects of the Invention]
[0011] According to the present invention, the person verification process can confirm that the user is a registered person authorized to unlock the door. Furthermore, the location verification process can confirm that the user is in the vicinity of the door. As a result, by utilizing a terminal device carried by the user, a dedicated authentication device is not required at the location where the user is authenticated, and highly secure authentication can be achieved with a simple configuration. [Brief explanation of the drawing]
[0012] [Figure 1] Overall configuration diagram of the door unlocking system according to the first embodiment [Figure 2] An explanatory diagram showing an overview of the door unlocking system according to the first embodiment. [Figure 3] Block diagram showing the schematic configuration of the authentication server, device management server, mobile terminal, and registration terminal according to the first embodiment. [Figure 4] Screen displayed on the registration terminal according to the first embodiment [Figure 5] Screen displayed on the registration terminal according to the first embodiment [Figure 6] This diagram illustrates the authentication information transmitted from the mobile terminal according to the first embodiment to the authentication server, and the registration information of the biometric information database managed by the authentication server. [Figure 7] This diagram illustrates the registration information of the target device database and control authority database managed by the device management server according to the first embodiment. [Figure 8] Diagram illustrating the screen displayed on a mobile terminal according to the first embodiment. [Figure 9] An explanatory diagram showing a screen displayed on a mobile terminal according to a modified example of the first embodiment. [Figure 10] Diagram illustrating the screen displayed on the mobile terminal according to the second embodiment. [Figure 11] An explanatory diagram showing an overview of the door unlocking system according to the third embodiment. [Figure 12] Diagram illustrating registration information in the target device database managed by the device management server according to the third embodiment. [Figure 13] Explanatory drawing showing a screen displayed on a mobile terminal according to the third embodiment [Figure 14] Explanatory drawing showing an overview of a door unlocking system according to the first modification of the third embodiment [Figure 15] Explanatory drawing showing an overview of a door unlocking system according to the second modification of the third embodiment [Figure 16] Explanatory drawing showing an overview of a door unlocking system according to the third modification of the third embodiment [Figure 17] [[ID=1十三]]Explanatory drawing showing an overview of a device control system according to the fourth embodiment [Figure 18] Explanatory drawing showing registration information of a target device database and a control authority database managed by a device management server according to the fourth embodiment [Figure 19] Explanatory drawing showing a screen displayed on a mobile terminal according to the fourth embodiment [Figure 20] Explanatory drawing showing an overview of a device control system according to the fifth embodiment [Figure 21] Explanatory drawing showing a screen displayed on a mobile terminal according to the fifth embodiment [Figure 22] Explanatory drawing showing a screen displayed on a mobile terminal according to the sixth embodiment [Figure 23] [[ID=3十一]]Explanatory drawing showing an overview of a device control system according to the seventh embodiment [Figure 24] Explanatory drawing showing a screen displayed on a mobile terminal according to the seventh embodiment [Figure 25] Explanatory drawing showing an overview of a payment system according to the eighth embodiment [Figure 26] Explanatory drawing showing a screen displayed on a mobile terminal according to the eighth embodiment
Modes for Carrying Out the Invention
[0013] The first invention made to solve the aforementioned problems is a door unlocking system that controls the unlocking of a door according to the result of a person matching process based on the user's biometric information, comprising: a server device that remotely controls a locking device installed on the door; and a terminal device that is possessed by the user, connected to the server device via a network, and has a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, wherein the server device acquires the user's biometric information acquired by the sensor and the location information of the terminal device acquired by the positioning unit from the terminal device, performs a person matching process that compares the user's biometric information with the registered person's biometric information, and also performs a location matching process that compares the location information of the terminal device with the location information of the door, A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the door, and a determination is made as to whether or not the door can be unlocked based on the results of the person matching process, the location matching process and the unique object matching process. This will be the structure.
[0014] According to this system, the person verification process confirms that the user is a registered person authorized to unlock the door. Furthermore, the location verification process confirms that the user is in the vicinity of the door. This allows for highly secure authentication with a simple configuration, without requiring a dedicated authentication device at the authentication location, by utilizing the user's own terminal device. Furthermore, because it is possible to confirm whether or not the user is staying near the door, it is possible to prevent the user's current location from being falsified by tampering with the location information provided from the terminal device to the server device. In other words, it is possible to falsify the information to make it appear as if the user is staying near the door when they are not.
[0015] Furthermore, the second invention is configured such that the server device acquires a facial image as biometric information of the user captured by the camera as a sensor from the terminal device, and in the person matching process, compares the facial image of the user with the facial image of the registered person.
[0016] According to this, it is possible to perform person matching processing in a simple and highly accurate manner.
[0017] Furthermore, the third invention is configured such that the server device acquires the location information obtained by the terminal device using a satellite positioning system from the terminal device.
[0018] According to this, location information with the required precision can be easily obtained.
[0021] Also, the 4 The invention is configured such that, as the unique object matching process, the server device compares code information obtained by taking a picture of a code image provided near the door in the terminal device with code information registered in association with the door.
[0022] According to this system, by successfully matching the code information obtained from a code image placed near the door, it is possible to properly confirm that a user is staying near the door.
[0023] Also, the 5 The invention is configured such that the server device, as part of the unique object matching process, compares the identification information of a telephone installed near the door and operated by a user with the identification information of a telephone registered in association with the door.
[0024] According to this, by having the user operate a telephone located near the door, it is possible to properly confirm that the user is staying near the door.
[0025] Also, the 6 The invention is configured such that the server device, as part of the unique object matching process, compares the identification information of a wireless network access point located near the door and used by the terminal device with the identification information of an access point registered in association with the door.
[0026] According to this, by having the terminal device utilize an access point installed near the door, it is possible to properly confirm that a user is staying near the door.
[0027] Also, the 7The invention comprises a sensor that is held by the user and connected via a network to a server device that remotely controls a locking device installed on a door, and which acquires the user's biometric information, a positioning unit that acquires the location information of the device itself, and a display input unit that displays a screen and accepts user operation input, an authentication guidance screen that provides guidance regarding the acquisition of the user's biometric information, and the server device that acquires the user's biometric information 、 Location information of the aforementioned self-device and the result of a unique object matching process that compares unique object information obtained based on at least one of the self-device and the user with unique object information registered in association with the door. The system is configured to display a result confirmation screen regarding the determination of whether or not the door can be unlocked, which is made based on the above, and a result confirmation screen.
[0028] According to this system, the authentication guidance screen allows users to recognize when their biometric information is being acquired. Furthermore, the results confirmation screen allows users to easily check whether or not the door can be unlocked.
[0029] Also, the 8 The invention relates to a device control system that controls a target device according to the result of a person matching process based on the user's biometric information, comprising: a server device that remotely controls the target device; a terminal device possessed by the user, connected to the server device via a network, having a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, wherein the server device acquires the user's biometric information acquired by the sensor and the location information of the terminal device acquired by the positioning unit from the terminal device, performs a person matching process that compares the user's biometric information with the registered person's biometric information, and also performs a location matching process that compares the location information of the terminal device with the location information of the target device, A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the target device. The person matching process and the location matching process, The aforementioned unique object verification process Based on the results, the system is configured to determine whether or not the target device can be controlled.
[0030] According to this system, the person verification process confirms that the user is a registered person authorized to control the target device. Furthermore, the location verification process confirms that the user is in the vicinity of the target device. This allows for highly secure authentication with a simple configuration, eliminating the need for dedicated authentication equipment at the authentication location, by utilizing the user's own terminal device. Target devices include doors equipped with electronic locks, entrance / exit gates with opening / closing mechanisms, control panels, vending machines, and cash handling terminals (ATMs, CDs, etc.).
[0031] Also, the 9 The invention is configured such that the server device transmits a device operation screen to the terminal device in which a user performs operations for controlling the target device, and controls the target device in accordance with the user's operations on the device operation screen.
[0032] According to this, users can properly perform operations to control the target device using a terminal device.
[0033] Also, the 10 The invention relates to a door unlocking method in which a processor executes a process to control the unlocking of a door according to the result of a person matching process based on the user's biometric information, wherein the invention relates to a terminal device possessed by the user and having a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, and the invention relates to a person matching process that compares the user's biometric information with the biometric information of a registered person, and also to a location matching process that compares the location information of the terminal device with the location information of the door, and A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the door. The person matching process and the location matching process, The aforementioned unique object verification process Based on the results, the system determines whether or not the door can be unlocked, and remotely controls the locking device installed on the door according to the determination result.
[0034] According to this, similar to the first invention, by utilizing a terminal device owned by the user, a dedicated authentication device is not required at the point where the user is authenticated, and highly secure authentication can be achieved with a simple configuration.
[0035] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0036] (First Embodiment) Figure 1 is an overall configuration diagram of the door unlocking system according to the first embodiment.
[0037] This system controls the unlocking of doors installed at the entrances and exits of a facility. The system comprises an authentication server 1 (server device), an equipment management server 2, a mobile terminal 3 (terminal device), a registration terminal 4, and an electronic lock 5 (locking device).
[0038] Mobile terminal 3 connects to authentication server 1 via a wireless network and the internet. Registration terminal 4 connects to authentication server 1 and device management server 2 via a wireless network and the internet. Authentication server 1 and device management server 2 are connected via a network.
[0039] The authentication server 1 obtains the user's biometric information from the mobile terminal 3 and performs biometric authentication of the user based on that information. If the authentication server 1 successfully authenticates the user's biometric information, it instructs the electronic lock 5 to unlock.
[0040] The device management server 2 manages location information for each target device (door) and information regarding the control authority (door unlocking authority) for each registered user.
[0041] Mobile device 3 (checker) is carried by the user. Mobile device 3 can be a smartphone or a tablet. An authentication application (checker application) is installed on mobile device 3. The authentication application performs biometric authentication processing for the user.
[0042] Registration terminal 4 (register) is operated by the administrator. Users may also operate it to input their own information. Registration terminal 4 can be a tablet or a PC. A registration application (register application) is installed on registration terminal 4. The registration application registers information managed by authentication server 1 and device management server 2.
[0043] The electronic lock 5 locks and unlocks the door. The electronic lock 5 is connected to the authentication server 1 via a network. The electronic lock 5 is remotely controlled by the authentication server 1 and performs an unlocking operation in response to an unlocking command from the authentication server 1.
[0044] The authentication server 1 and the device management server 2 can be configured to operate on-premises, i.e., within the premises of the facility where the target device (door) is installed, but they may also be operated in the cloud.
[0045] Furthermore, to prevent tailgating, that is, fraudulent activity in which a person other than the authenticated person follows the authenticated person through the entrance / exit, cameras may be installed to photograph people passing through the entrance / exit.
[0046] Furthermore, while this embodiment primarily describes facial recognition using the user's facial image as a form of biometric authentication, biometric authentication is not limited to facial recognition. For example, biometric authentication may also use the iris, fingerprints, palm, gestures (finger movements), and gait (walking style).
[0047] Next, an overview of the door unlocking system according to the first embodiment will be described. Figure 2 is an explanatory diagram showing an overview of the door unlocking system.
[0048] In this embodiment, the user stays near the authentication point, i.e., the target device, which is the door, and performs biometric authentication operations using the mobile terminal 3. The door is equipped with an electronic lock 5, which is remotely controlled by the authentication server 1. The authentication server 1 performs biometric authentication of the user, and if biometric authentication is successful, the door is unlocked.
[0049] The device management server 2 manages the target device database and the control authority database. The target device database registers the location information of each target device (door). The control authority database registers the control authority (door unlocking authority) for each registered user. The device management server 2 provides the registration information from the target device database and the control authority database to the authentication server 1.
[0050] Mobile terminal 3 acquires the user's biometric information (e.g., facial image). Mobile terminal 3 also acquires location information of its own device, which represents the user's current location. Mobile terminal 3 sends authentication information to authentication server 1 requesting authentication. The authentication information includes the user's biometric information, location information of its own device, and time information (timestamp) regarding the time when the biometric information and location information were acquired.
[0051] Authentication server 1 manages the biometric information database. The biometric information database contains biometric information for each registered user. Authentication server 1 obtains registration information from the target device database and the control authority database from device management server 2.
[0052] Authentication server 1 identifies the user to be authenticated by comparing the user's biometric information with the biometric information for each registered user registered in the biometric information database (person matching process). Authentication server 1 also compares the location information of mobile terminal 3 with the location information for each target device (door) registered in the target device database to identify the target device (door) corresponding to the user's current location and confirm that the user is in the vicinity of the target device (door) (location matching process). Furthermore, authentication server 1 uses the registration information in the control authority database to determine whether the user has control authority (door unlocking authority) for the target device based on the user identified in the person matching process and the target device (door) identified in the location matching process (authority determination process). Finally, if the user is identified through the person matching process, the target device (door) corresponding to the user's current location is identified through the location matching process, and the user has control authority (door unlocking authority) for the target device, control of the target device (door unlocking) is permitted. At this time, the authentication server 1 transmits a contact signal as an unlocking command to a contact converter (not shown) located near the electronic lock 5 of the door. The electronic lock 5 receives the unlocking signal output from the contact converter and performs a remote unlocking operation.
[0053] In this embodiment, the person matching process confirms that the user is a registered person authorized to unlock the door. The location matching process confirms that the user is in the vicinity of the door. If the user is a person who has been given prior authority to unlock the door, the door is unlocked. This enables highly secure authentication with a simple configuration and prevents fraudulent actions such as unlocking the door when the user is not in the vicinity of the door.
[0054] Next, the schematic configuration of the authentication server 1, device management server 2, mobile terminal 3, and registration terminal 4 according to the first embodiment will be described. Figure 3 is a block diagram showing the schematic configuration of the authentication server 1, device management server 2, mobile terminal 3, and registration terminal 4.
[0055] The mobile terminal 3 comprises a sensor 31, a positioning unit 32, a display input unit 33, a communication unit 34, a storage unit 35, and a processor 36.
[0056] Sensor 31 (biometric information acquisition unit) acquires the user's biometric information. Sensor 31 is, for example, a camera, and by photographing the user's upper body, it extracts and acquires a facial image as biometric information of the user.
[0057] The positioning unit 32 (location information acquisition unit) acquires location information regarding the current location of the mobile terminal 3 using a satellite positioning system such as GPS (outdoor positioning system), that is, a system that performs positioning based on positioning signals transmitted from positioning satellites. The positioning unit 32 also acquires location information regarding the current location of the mobile terminal 3 using an indoor positioning system, that is, a system that performs positioning based on positioning signals (beacon signals) transmitted from beacon transmitters. It is desirable that the location information of the mobile terminal 3 also include information such as the floor and number of floors.
[0058] The display input unit 33 consists of a touch panel display or the like. The display input unit 33 displays information on the screen and also accepts user input.
[0059] The communication unit 34 communicates with the authentication server 1.
[0060] The memory unit 35 stores programs and other data that are executed by the processor 36.
[0061] The processor 36 performs various processes by executing programs (authentication applications, device operation applications) stored in the memory unit 35. In this embodiment, the processor 36 performs authentication information generation processing and display input control processing, etc.
[0062] In the authentication information generation process, the processor 36 generates authentication information to request authentication from the authentication server 1. The authentication information includes biometric information (face image) acquired by the sensor 31 and location information acquired by the positioning unit 32. The authentication information is transmitted to the authentication server 1.
[0063] During the display input control process, the processor 36 displays an authentication guidance screen (see Figures 8(A) and (B)) on the display input unit 33. Additionally, during the display input control process, the processor 36 displays a result confirmation screen (see Figures 8(C) to (F)) on the display input unit 33.
[0064] The screen displayed in the display input unit 33 of the mobile terminal 3 may be generated by the authentication server 1 and transmitted to the mobile terminal 3, or it may be generated and displayed by the mobile terminal 3 based on the information received from the authentication server 1.
[0065] The authentication server 1 comprises a communication unit 11, a storage unit 12, and a processor 13.
[0066] The communication unit 11 communicates with the mobile terminal 3, the device management server 2, the registration terminal 4, and the electronic lock 5.
[0067] The memory unit 12 stores programs and other data executed by the processor 13. The memory unit 12 also stores registration information for the biometric information database (see Figure 6(B)).
[0068] The processor 13 performs various processes by executing programs stored in the memory unit 12. In this embodiment, the processor 13 performs registration processing, registration information acquisition processing, person matching processing, location matching processing, authority determination processing, target device control processing, and result notification processing.
[0069] During the registration process, the processor 13 assigns a biometric ID (person ID) to the biometric information of the registrant provided by the registration terminal 4, and registers the registrant's biometric information and biometric ID in the biometric information database (see Figure 6(B)).
[0070] The registration information acquisition process involves the processor 13 acquiring registration information (see Figure 7) from the device management server 2 in the target device database and the control authority database.
[0071] In the person matching process, the processor 13 matches the user's biometric information included in the authentication information obtained from the mobile terminal 3 with the biometric information for each registered user registered in the biometric information database to identify the user to be authenticated. The biometric information is, for example, a facial image, and the facial image (facial features) of the user obtained from the mobile terminal 3 is matched with the facial image (facial features) for each registered user registered in the biometric information database (facial matching).
[0072] In the location matching process, the processor 13 compares the location information of the mobile terminal 3, which is included in the authentication information obtained from the mobile terminal 3, with the location information for each target device (door) registered in the target device database to identify the target device corresponding to the user's current location. Furthermore, the processor 13 can confirm that the user is staying near the door if the location matching process is successful.
[0073] In the authorization determination process, the processor 13 uses the registration information in the control authorization database to determine whether the user has control authorization (door unlocking authorization) for the target device, based on the user's biometric ID identified in the person matching process and the target device identified in the location matching process.
[0074] In the target device control process, the processor 13 determines whether or not to control the target device (unlock the door) based on the results of the person verification process, location verification process, and authority determination process. Specifically, if the user is identified by the person verification process, the target device (door) corresponding to the user's current location is identified by the location verification process, and the user has the authority to control the target device (authority to unlock the door), then control of the target device (unlock the door) is permitted. When unlocking the door is permitted, a contact signal is sent to the electronic lock 5 as an unlock command.
[0075] In the result notification process, processor 13 notifies mobile terminal 3 of the results of the person matching process, location matching process, and authorization determination process. Specifically, it transmits the display information of the result confirmation screen (see Figures 8(C) to (F)) to mobile terminal 3.
[0076] The device management server 2 comprises a communication unit 21, a storage unit 22, and a processor 23.
[0077] The communication unit 21 communicates with the authentication server 1 and the registered terminal 4.
[0078] The storage unit 22 stores programs and other data executed by the processor 23. The storage unit 22 also stores registration information for the target device database and the control authority database (see Figure 6(B)).
[0079] The processor 23 performs various processes by executing programs stored in the memory unit 22. In this embodiment, the processor 23 performs registration processing and the like.
[0080] During the registration process, the processor 23 registers information about the target equipment in the target equipment database (see Figure 7(A)) in response to the administrator's input operations regarding the target equipment performed at the registration terminal 4. Specifically, for each target equipment (door), it registers the location information of the installation site, the equipment name (door name), and the equipment ID (door ID).
[0081] Furthermore, during the registration process, the processor 23 registers information regarding control privileges in the control privilege database (see Figure 7(B)) in response to the administrator's input operations regarding control privileges performed at the registration terminal 4. Specifically, for each registrant, this information includes their biometric ID, name, and whether or not they have permission to unlock doors (unlocking privileges). The biometric ID is obtained from the authentication server 1.
[0082] The registration terminal 4 includes a sensor 41, a display input unit 42, a communication unit 43, a storage unit 44, and a processor 45.
[0083] Sensor 41 (biometric information acquisition unit) acquires the biometric information of the registered person. Sensor 41 is, for example, a camera, and by photographing the upper body of the registered person, it extracts and acquires a facial image as biometric information of the registered person.
[0084] The display input unit 42 consists of a touch panel display or the like. The display input unit 42 displays a screen and accepts user input.
[0085] The communication unit 43 communicates with the authentication server 1 and the device management server 2.
[0086] The memory unit 44 stores programs and other data executed by the processor 45.
[0087] The processor 45 performs various processes by executing programs (registered applications) stored in the memory unit 44. In this embodiment, the processor 45 performs display input control processing, etc.
[0088] In the display input control process, the processor 45 displays the biometric information registration screen (see Figure 4) on the display input unit 42. In addition, during the display input control process, the processor 45 displays the target device registration screen (see Figures 5(A) and (B)) and the control authority registration screen (see Figures 5(C) and (D)) on the display input unit 42, and acquires the administrator's input operation information regarding the target device and control authority. The administrator's input operation information is sent to the device management server 2.
[0089] Next, the screen displayed on the registration terminal 4 according to the first embodiment will be described. Figures 4 and 5 are explanatory diagrams showing the screen displayed on the registration terminal 4.
[0090] This section describes the case where the registrant registers their biometric information themselves, but the administrator may also register the biometric information by loading a pre-taken image of the registrant into the registration terminal 4. On the registration terminal 4, the registration application is launched, and the initial screen shown in Figure 4(A) is displayed as the biometric information registration screen. When the start button 62 is operated, the face capture screen shown in Figure 4(B) is displayed. On the face capture screen, the live image of the registrant captured by the sensor 41 (camera) of the registration terminal 4 is displayed on the display unit 61, following the guidance, "Please take a picture of your face from the front." Next, the capture button 63 is operated, and after confirming that a still image including the registrant's face image has been properly captured, the register button 64 is operated. As a result, the registrant's face image is extracted and sent to the authentication server 1, where the biometric information (face features) registration process is executed.
[0091] Furthermore, on registration terminal 4, the list screen shown in Figure 5(A) is first displayed as the target device registration screen. The list screen includes a list table 71. The list table 71 displays information about the target devices, specifically, for each target device (door), the location information of the installation site, the device name (door name), and the device ID (door ID). When the administrator selects a row in the list table 71 and operates the start button 72 on the list screen, the system transitions to the editing screen shown in Figure 5(B). The editing screen includes an editing field 73. In the editing field 73, the administrator can edit (input, change, delete) the information regarding the location information of the installation site, the device name (door name), and the device ID (door ID). When the administrator operates the register button 74 on the editing screen, the system returns to the list screen shown in Figure 5(A), and the edited information about the target devices is registered in the target device database (see Figure 7(A)).
[0092] Furthermore, on registration terminal 4, the list screen shown in Figure 5(C) is first displayed as the control authority registration screen. The list screen includes a list table 75. The list table 75 displays information regarding control authority, specifically, for each registrant, information such as biometric ID, name, and whether or not they have permission to unlock doors (unlocking permission). When the administrator selects a row in the list table 75 and operates the start button 76 on the list screen, the system transitions to the editing screen shown in Figure 5(D). The editing screen includes an editing field 77. In the editing field 77, the administrator can edit (input, change, delete) information regarding biometric ID, name, and whether or not they have permission to unlock doors (unlocking permission). When the administrator operates the register button 78 on the editing screen, the system returns to the list screen shown in Figure 5(C), and the edited information regarding control authority is registered in the control authority database (see Figure 7(B)).
[0093] Next, the authentication information transmitted from the mobile terminal 3 to the authentication server 1 according to the first embodiment, and the biometric information database managed by the authentication server 1 will be described. Figure 6 is an explanatory diagram showing the authentication information and the registered information in the biometric information database.
[0094] Mobile terminal 3 sends authentication information to authentication server 1 requesting authentication. As shown in Figure 6(A), the authentication information includes the user's biometric information and the location information of mobile terminal 3, which represents the user's current location.
[0095] Furthermore, it is desirable to add time information (timestamp) regarding the time when each piece of information was acquired to the user's biometric information and the location information of the mobile terminal 3. This allows the system to determine that the user's biometric information and the location information of the mobile terminal 3 were acquired at the same time, thereby preventing unauthorized unlocking of the door. To further enhance security, the acquisition of authentication information may be restricted to mobile terminals 3 that have been assigned specific identification information (such as a MAC address).
[0096] Furthermore, the authentication server 1 manages the biometric information database. As shown in Figure 6(B), the biometric information database registers the biometric information and biometric ID (identification information of the registrant) for each registrant. In addition, the authentication server 1 extracts facial features from the facial image, which is the biometric information of the registrant obtained from the mobile terminal 3, and assigns a biometric ID (person ID) to the registrant's biometric information. The registrant's facial image and biometric ID are then registered in the biometric information database.
[0097] The biometric information registered in the biometric database is used in the person verification process performed by the authentication server 1. In the person verification process, the biometric information of the user obtained from the mobile terminal 3 is compared with the biometric information for each registered user registered in the biometric database to identify the user to be authenticated.
[0098] In this case, if the biometric information is a facial image, the facial features extracted from the facial image become the matching target, and the facial features of the facial image are registered in the biometric information database. Furthermore, the biometric information is not limited to facial images; it can also be the iris, fingerprints, palm, gestures (finger movements), and gait (walking style). If the biometric information is the iris, fingerprints, or palm, those biometric features are registered, and if it is gestures (finger movements) or gait (walking style), a pattern video is registered.
[0099] Next, the target device database and control authority database managed by the device management server 2 according to the first embodiment will be described. Figure 7 is an explanatory diagram showing the registration information of the target device database and control authority database.
[0100] The device management server 2 manages the target device database. As shown in Figure 7(A), the target device database registers the location information of the installation site, the device name (door name), and the device ID (door ID) for each target device (door).
[0101] The registration information in the target device database is used for location verification processing performed by the authentication server 1. In the location verification processing, the target device (door) corresponding to the user's current location is identified based on the location information of the mobile terminal 3, which is obtained from the mobile terminal 3 and represents the user's current location.
[0102] Furthermore, the device management server 2 manages the control authority database. As shown in Figure 7(B), the control authority database registers information for each registrant, including their biometric ID, name, and whether or not they have permission to unlock doors (unlocking permission). Unlocking permission as a control authority is registered for each door. In this example, the registration status of unlocking permission for the target device with device ID "000C" is shown.
[0103] The registration information in the control authority database is used in the authority determination process performed by the authentication server 1. In the authority determination process, it is determined whether the user has control authority over the target device (door unlocking authority) based on the user's biometric ID identified in the person matching process and the target device (door) identified in the location matching process.
[0104] Next, the screen displayed on the mobile terminal 3 according to the first embodiment will be described. Figure 8 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0105] On the mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 8(A) is displayed first, followed by the face capture screen shown in Figure 8(B). At this time, when the mobile terminal 3 detects the user's face from the live image from the sensor 31 (camera), it generates a face image as biometric information and sends authentication information including that face image to the authentication server 1. When the authentication server 1 receives the authentication information from the mobile terminal 3, it performs person matching processing, location matching processing, and authorization determination processing.
[0106] Next, mobile terminal 3 displays one of the result confirmation screens shown in Figures 8(C) to 8(F), depending on the person verification result and the authorization determination result.
[0107] The result confirmation screen shown in Figure 8(C) represents the case where person verification (face recognition) is successful and control of the target device is permitted. In this case, the first display unit 81 displays text indicating that unlocking door #1 is the target of control. The second display unit 82 displays text indicating that person verification (face recognition) was successful as a result of person verification, and text indicating that the door has been unlocked as a result of device control.
[0108] The result confirmation screen shown in Figure 8(D) is for the case where person matching (face recognition) fails and control of the target device is not permitted. In this case, the second display unit 82 displays text indicating that person matching (face recognition) failed, and text prompting the user to try person matching (face recognition) again. In this case, the user returns to the face capture screen shown in Figure 8(B), and can retake the photo of their face.
[0109] The result confirmation screen shown in Figure 8(E) represents the case where person verification (face recognition) was successful, but control of the target device was not permitted because the user was not granted control authority. In this case, the second display unit 82 displays the results of person verification, including the message that person verification (face recognition) was successful and the message that control of the target device (unlocking the door) was not possible.
[0110] The result confirmation screen shown in Figure 8(F) is for the case where person matching (face matching) was successful, but operation to control the target device was not permitted due to invalid location information. Here, invalid location information means that the location information of the mobile terminal 3 obtained from the mobile terminal 3 does not match the location information of the target device (door) registered in the target device database, that is, there is no target device corresponding to the user's current location. In this case, the second display unit 82 displays text indicating that person matching (face matching) was successful, and text prompting the user to move to an appropriate location, i.e., near the target device (door), as the person matching result.
[0111] (Modified version of the first embodiment) Next, a modified version of the first embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment. Figure 9 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0112] In the first embodiment, an authentication application is launched on the mobile terminal 3, and after the user's face is captured, authentication information including the user's biometric facial image and the location information of the mobile terminal 3 representing the user's current location is sent to the authentication server 1. On the other hand, in this modified example, the location information of the mobile terminal 3 is sent to the authentication server 1 when the authentication application is launched. The authentication server 1 identifies the target device (door) based on the location information of the mobile terminal 3. This allows the target device (door) to be presented to the user before biometric authentication (facial recognition) is performed.
[0113] When the authentication application is launched on the mobile terminal 3, the initial screen shown in Figure 9(A) is displayed first as an authentication guidance screen, followed by the face capture screen shown in Figure 9(B). On both the initial screen and the face capture screen, the first display unit 81 displays the message that door #1 is the control target.
[0114] Next, the mobile terminal 3 displays one of the result confirmation screens shown in Figure 9(C), depending on the person verification result and the authorization determination result. This result confirmation screen is the same as in the first embodiment (see Figures 8(C) to (F)).
[0115] (Second Embodiment) Next, a second embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment.
[0116] In facial recognition (face-based identity matching), fraud is possible by having the sensor 31 (camera) of the mobile terminal 3 capture an image of another person's face, specifically a photo sheet with another person's face printed on it, or a screen displaying another person's face.
[0117] Therefore, in this embodiment, in order to prevent impersonation, the user's face is photographed multiple times from different angles, and person matching is performed using the multiple facial images obtained. Specifically, the user's face is photographed from the front, from the left, and from the right, and person matching is performed using the acquired frontal, left, and right-facing facial images.
[0118] In this case, person matching is performed using only one of multiple facial images. Alternatively, person matching may be performed using a combination of two of the multiple facial images. Furthermore, person matching may be performed using all of the multiple facial images. In addition, if person matching is performed using a portion of the multiple facial images, the facial images used for person matching may be randomly selected.
[0119] Furthermore, in this embodiment, it is a condition that the multiple facial images used for person matching are captured within a predetermined time. In addition, in this embodiment, location information at the time of capture is added to each of the multiple facial images, and it is a condition that the location information at the time of capture of each of the multiple facial images matches each other and also matches the location information of the mobile terminal 3. As a result, the time for capturing the user's face is short and limited, making it difficult to capture multiple facial images of other people with the sensor 31 (camera) of the mobile terminal 3 within the limited time, thus preventing impersonation using facial images of other people.
[0120] Furthermore, in this embodiment, similar to the first embodiment (see Figure 4), the registration application displays a biometric information registration screen on the registration terminal 4, and an operation is performed to photograph the registrant's face on a face photography screen similar to the example shown in Figure 4(B). On the other hand, in this embodiment, since matching is performed on multiple face images with different shooting directions, the face photography screen similar to the example shown in Figure 4(B) is repeatedly displayed on the registration terminal 4 with a different shooting direction, and the registrant's face is repeatedly photographed with a different shooting direction. As a result, multiple face images with different shooting directions are acquired.
[0121] Next, we will describe the screen displayed on the mobile terminal 3 according to the second embodiment. Figure 10 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0122] On mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 10(A) is displayed first, followed by the face capture screens shown in Figures 10(B), (C), and (D) in order. These face capture screens capture the user's face from multiple directions. Specifically, the face capture screen shown in Figure 10(B) captures the face from the front, and a front-facing face image is obtained. The face capture screen shown in Figure 10(C) captures the face facing left, and a left-facing face image is obtained. The face capture screen shown in Figure 10(D) captures the face facing right, and a right-facing face image is obtained.
[0123] Next, the mobile terminal 3 displays one of the result confirmation screens shown in Figure 10(E), depending on the person verification result and the authorization determination result. This result confirmation screen is the same as in the first embodiment (see Figures 8(C) to (F)).
[0124] In this example, the face is photographed facing forward, to the left, and to the right, but the direction in which the face is photographed is not limited to these three directions. For example, in addition to the face facing forward, only one of the left-facing or right-facing faces may be photographed.
[0125] (Third embodiment) Next, a third embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment. Figure 11 is an explanatory diagram showing an overview of the door unlocking system.
[0126] By tampering with the location information included in the authentication information transmitted from the mobile terminal 3 to the authentication server 1, it is possible to falsely represent that the user is at the authentication location even though the user is not. If such falsification of the user's current location is permitted, security problems such as unauthorized operation of the target device may occur.
[0127] Therefore, in this embodiment, a unique object of the location where the user is authenticated (authentication point) is captured by the sensor 31 (camera) of the mobile terminal 3. In particular, in this embodiment, a two-dimensional code image 6 installed at the authentication point is captured as the unique object of the authentication point. In the example shown in Figure 11, a panel with the two-dimensional code image 6 is attached to the wall surface near the door.
[0128] Mobile terminal 3 transmits location spoofing prevention information, including information (unique object information) obtained by photographing a unique object with sensor 31 (camera), to authentication server 1. The unique object information is code information obtained by reading the captured 2D code image 6. Alternatively, the unique object information may be a captured image of the unique object (2D code image 6). The location spoofing prevention information is accompanied by location information of the acquisition point (photography point), that is, the location information of mobile terminal 3 when the unique object was photographed, and time information (timestamp) related to the acquisition time (photography time).
[0129] Furthermore, the mobile terminal 3, similar to the first embodiment, transmits authentication information to the authentication server 1 requesting authentication. The authentication information includes the user's biometric information (facial image) and the location information of the mobile terminal 3.
[0130] Authentication server 1 compares the unique object information (code information) obtained from mobile terminal 3 with the unique object information (code information) registered in the target device database (unique object verification process). If the unique object information verification fails, it is determined to be location spoofing and control of the target device (unlocking the door) is not permitted.
[0131] Furthermore, the authentication server 1 compares the location information contained in the location spoofing prevention information obtained from the mobile terminal 3 with the location information of the unique device registered in the target device database. In addition, the authentication server 1 compares the location information contained in the authentication information with the location information contained in the location spoofing prevention information. If these location information comparisons fail, the server determines that location spoofing has occurred and does not permit control of the target device (unlocking the door).
[0132] Furthermore, the authentication server 1 is required to have obtained the unique object information included in the location spoofing prevention information and the biometric information included in the authentication information within a predetermined time. Specifically, the requirement is that the information from the 2D code image 6 included in the location spoofing prevention information and the facial image included in the authentication information are captured within a predetermined time.
[0133] In this embodiment, the mobile terminal 3 captures a unique object (2D code image 6) that can only be photographed at the authentication point using the sensor 31 (camera). The authentication server 1 then compares the unique object information (code information) obtained from the mobile terminal 3 with the unique object information (code information) registered in the target device database. This comparison allows the server to confirm that the user is currently at the authentication point, thus preventing the user from falsifying their current location.
[0134] Next, we will describe the target device database managed by the device management server 2 according to the third embodiment. Figure 12 is an explanatory diagram showing the registration information of the target device database.
[0135] In the first embodiment (see Figure 7(A)), the target equipment database registered location information of the installation site, equipment name (door name), and equipment ID (door ID) for each target equipment (door). In this embodiment, however, code information corresponding to a 2D code image 6 provided near the door, which is the target equipment, is also registered as unique object information.
[0136] Next, the screen displayed on the mobile terminal 3 according to the third embodiment will be described. Figure 13 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0137] On the mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 13(A) is displayed first, followed by the unique object capture screen shown in Figure 13(B). On the unique object capture screen, text prompting the user to capture the unique object (the 2D code image 6 near the door) is displayed. At this point, the user captures the unique object (the 2D code image 6 near the door) with the sensor 31 (camera) of the mobile terminal 3.
[0138] Next, the mobile terminal 3 displays the face capture screen shown in Figure 13(C). Then, depending on the person matching result and the authorization determination result, the mobile terminal 3 displays one of the result confirmation screens shown in Figure 13(D). This result confirmation screen is the same as in the first embodiment (see Figures 8(C) to (F)). If the unique object matching fails, the system transitions to the result confirmation screen shown in Figure 13(E). This result confirmation screen displays text prompting the user to take another picture of the unique object (the 2D code image 6 near the door).
[0139] (First modified example of the third embodiment) Next, a first modified example of the third embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment. Figure 14 is an explanatory diagram showing an overview of the door unlocking system.
[0140] In this modified version, as a unique feature of the authentication point, landmarks 7 (indicators) located around the authentication point are photographed by the sensor 31 (camera) of the mobile terminal 3. Landmarks 7 include buildings and structures such as doors and walls inside buildings.
[0141] In this case, the unique object information registered in the target device database is either a photograph of the landmark or features extracted from the photograph of the landmark. Authentication server 1 compares the unique object information (features of landmark 7) obtained from mobile terminal 3 with the unique object information (landmark feature information) corresponding to the authentication point (user's current location) registered in the target device database (unique object matching process). If the matching of unique object information fails, it is determined to be location spoofing, and control of the target device (unlocking the door) is not permitted.
[0142] (Second modified example of the third embodiment) Next, a second modification of the third embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment. Figure 15 is an explanatory diagram showing an overview of the door unlocking system.
[0143] In this modified version, the unique object of the authentication location is a fixed device that can only be operated by the user at the authentication location, specifically a fixed telephone 8 installed at the authentication location. The authentication server 1 detects when the user operates the fixed telephone 8 installed at the authentication location and confirms that the user is at the authentication location.
[0144] Specifically, the authentication server 1 controls a call made on a fixed telephone 8 installed at the authentication location, and when the user picks up the receiver of the fixed telephone 8, it is confirmed that the user is at the authentication location. In this case, it may be required that an off-hook state be detected within a predetermined time after the call.
[0145] Furthermore, the authentication server 1 controls the mobile terminal 3 to prompt the user to pick up the receiver of the fixed telephone 8 installed at the authentication location. When the user picks up the receiver of the fixed telephone 8, it is confirmed that the user is at the authentication location. In this case, it may be required that an off-hook state be detected within a predetermined time after the prompt is given.
[0146] Furthermore, the user may be required to operate the buttons instructed by the voice guidance on the landline telephone 8. Alternatively, the user may be required to enter the authentication code instructed by the voice guidance on the landline telephone 8 into the mobile terminal 3.
[0147] In this modified example, the unique item information registered in the target device database is the identification information of the landline telephone 8. The authentication server 1 compares the identification information (unique item information) of the landline telephone 8 operated by the user with the identification information (unique item information) of the landline telephone 8 corresponding to the authentication point (user's current location) registered in the target device database (unique item matching process). If the matching of unique item information fails, it is determined to be location spoofing, and control of the target device (unlocking the door) is not permitted.
[0148] (Third modified example of the third embodiment) Next, a third modification of the third embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment. Figure 16 is an explanatory diagram showing an overview of the door unlocking system.
[0149] In this modified example, the unique object of the authentication point becomes the access point 9 installed near the authentication point. Since communication between the mobile terminal 3 and the authentication server 1 takes place via the access point 9 installed near the mobile terminal 3, the access point 9 installed near the mobile terminal 3 becomes a unique object that can only be used by the user's mobile terminal 3 at the authentication point. The access point 9 is a device that serves as a base station for a wireless network, specifically a wireless LAN such as Wi-Fi (registered trademark).
[0150] In this case, the unique information registered in the target device database is the identification information of access point 9. The authentication server 1 compares the identification information (unique information) of access point 9 obtained through communication with the mobile terminal 3 with the identification information (unique information) of access point 9 corresponding to the authentication point (user's current location) registered in the target device database (unique information matching process). If the matching of unique information fails, it is determined to be location spoofing, and control of the target device (unlocking the door) is not permitted.
[0151] Furthermore, when authentication information is transmitted from the mobile terminal 3 to the authentication server 1 via the access point 9, the access point 9 adds its own device identification information to the authentication information, allowing the authentication server 1 to obtain the access point 9's identification information.
[0152] (Fourth Embodiment) Next, a fourth embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiments. Figure 17 is an explanatory diagram showing an overview of the equipment control system according to the fourth embodiment.
[0153] In this embodiment, the target device is the control panel 101. The control panel 101 controls the voltage of the power supply and the opening degree of valves installed in the equipment to be controlled.
[0154] Similar to the first embodiment, the mobile terminal 3 has an authentication application installed, but in this embodiment, the mobile terminal 3 also has a device operation application installed. Similar to the first embodiment, the mobile terminal 3 displays an authentication guidance screen via the authentication application to obtain the user's biometric information (facial image) used for biometric authentication (facial recognition). Furthermore, if biometric authentication is successful, the device operation application is launched on the mobile terminal 3, and the user transitions to the device operation screen. On the device operation screen, the user can operate the control panel 101.
[0155] Furthermore, in this embodiment, if the user's identity verification is successful and the user has the authority to unlock the door of the control panel 101, the door of the control panel 101 is unlocked. This allows the user (worker) to open the door of the control panel 101 and visually inspect the instruments and other components inside the control panel 101.
[0156] Thus, in this embodiment, a user (worker) can operate the control panel 101 using the mobile terminal 3 without directly touching the operating levers or other components inside the control panel 101.
[0157] In this example, the door to the control panel 101 is unlocked in order to visually inspect the instruments on the control panel 101, but the door to the control room may also be unlocked in order to enter the room.
[0158] Next, the target device database and control authority database managed by the device management server 2 according to the fourth embodiment will be described. Figure 18 is an explanatory diagram showing the registration information of the target device database and control authority database.
[0159] The equipment management server 2 manages the target equipment database. As shown in Figure 18(A), the target equipment database registers the location information of the installation site, the equipment name (control panel name), and the equipment ID (control panel ID) for each target equipment (control panel 101).
[0160] Furthermore, the equipment management server 2 manages the control authority database. As shown in Figure 18(B), the control authority database registers information for each registrant, including their biometric ID, name, whether or not they have the authority to unlock the door of the target equipment (control panel 101) (unlocking authority), and whether or not they have the authority to operate the target equipment (control panel 101) (operation authority). In this example, the registration status of unlocking authority and operation authority for the target equipment with equipment ID "000C" is shown.
[0161] In some cases, only unlocking the door of the control panel 101 may be permitted, and operation of the control panel 101 using the mobile terminal 3 may not be permitted. In this case, the user (worker) will not be able to operate the control panel 101 using the mobile terminal 3, but will be able to open the door of the control panel 101 and visually inspect the instruments and other components inside the control panel 101.
[0162] Next, the screen displayed on the mobile terminal 3 according to the fourth embodiment will be described. Figure 19 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0163] On mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 19(A) is displayed first, followed by the face capture screen shown in Figure 19(B). If person matching (face recognition) is successful and control of the target device is permitted, the system transitions to the result confirmation screen shown in Figure 19(C). In other cases, such as when person matching (face recognition) fails and control of the target device is not permitted, the process is the same as in the first embodiment (see Figures 8(D) to (F)).
[0164] In the result confirmation screen shown in Figure 19(C), the first display unit 81 displays text indicating that the control panel 101 is the controlled object. The second display unit 82 displays text indicating that the person verification (face verification) was successful as a person verification result, and text indicating that the control panel 101 can be operated as equipment control content. At this time, if the user has the authority to unlock the door of the control panel 101, the door of the control panel 101 is unlocked, and the user can open the door and check the instruments and other equipment inside the control panel 101.
[0165] Next, the mobile terminal 3 launches the device operation application and transitions to the device operation screen shown in Figures 19(D) to (F). The device operation screen is equipped with a button 83 for adjusting the setting value and a "Settings" button 84. In the device operation screen (voltage operation screen) shown in Figure 19(D), the user can set the power supply voltage by operating button 83, and when the "Settings" button 84 is operated, the power supply is controlled to reach the set voltage. In the device operation screens (valve operation screens) shown in Figures 19(E) and (F), the user can set the valve opening degree by operating button 83, and when the "Settings" button 84 is operated, the valve is controlled to reach the set opening degree.
[0166] (Fifth embodiment) Next, a fifth embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiments. Figure 20 is an explanatory diagram showing an overview of the equipment control system according to the fifth embodiment.
[0167] In this embodiment, the target device is a vending machine 102, and the user is granted control authority to perform operations related to the maintenance of the vending machine 102. Specifically, the user is permitted to perform operations to check maintenance information, such as checking the remaining number of products stored in the vending machine 102.
[0168] Users (workers) can perform maintenance operations on the vending machine 102 using the mobile terminal 3, without directly touching the vending machine 102.
[0169] In this embodiment, the user can perform maintenance operations on the vending machine 102 using the mobile terminal 3, but the user may also perform maintenance operations on other equipment, such as checking the remaining amount in a gas tank at a gas station.
[0170] Next, we will describe the screen displayed on the mobile terminal 3 according to the fifth embodiment. Figure 21 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0171] On mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 21(A) is displayed first, followed by the face capture screen shown in Figure 21(B). If person matching (face recognition) is successful and control of the target device is permitted, the system transitions to the result confirmation screen shown in Figure 21(C). In other cases, such as when person matching (face recognition) fails and control of the target device is not permitted, the process is the same as in the first embodiment (see Figures 8(D) to (F)).
[0172] In the results confirmation screen shown in Figure 21(C), the first display unit 81 displays text indicating that the vending machine 102 is the target of control. The second display unit 82 displays text indicating that the person verification (face verification) was successful as a result of person verification, and text indicating that maintenance is possible as part of the equipment control content.
[0173] Next, the mobile terminal 3 launches the equipment operation application and transitions to the equipment confirmation screen shown in Figures 21(D) to (F). In this example, maintenance information, specifically the remaining quantity of each product stored in the vending machine 102, is displayed on the equipment confirmation screen. If any product has a remaining quantity lower than a predetermined value, the user (worker) performs the task of replenishing the product.
[0174] (Sixth Embodiment) Next, a sixth embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiments.
[0175] In this embodiment, similar to the fifth embodiment (see Figure 20), the target device is a vending machine 102, but here, the user is granted control authority to select and purchase items from the vending machine 102. The user (customer) can select and purchase items from the vending machine 102 using the mobile terminal 3 without directly touching the vending machine 102. Furthermore, payment (settlement) for the goods is made using the biometric authentication result.
[0176] Next, we will describe the screen displayed on the mobile terminal 3 according to the sixth embodiment. Figure 22 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0177] On mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 22(A) is displayed first, followed by the face capture screen shown in Figure 22(B). If person matching (face recognition) is successful and control of the target device is permitted, the system transitions to the result confirmation screen shown in Figure 22(C). In other cases, such as when person matching (face recognition) fails and control of the target device is not permitted, the process is the same as in the first embodiment (see Figures 8(D) to (F)).
[0178] In the result confirmation screen shown in Figure 22(C), the first display unit 81 displays text indicating that the vending machine 102 is the control target. The second display unit 82 displays text indicating that the person verification (face verification) was successful as a person verification result, and text indicating that the product can be purchased as a device control result.
[0179] Next, the mobile terminal 3 launches the device operation application and transitions to the device operation screen shown in Figures 22(D) to (F). In this example, a different device operation screen is displayed for each product. The device operation screen displays text representing the name of the product. When the user operates the "Purchase" button 85, the vending machine 102 performs a product dispensing operation, and the product is ejected to the dispensing slot, allowing the user to receive the product.
[0180] (Seventh Embodiment) Next, a seventh embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiment. Figure 23 is an explanatory diagram showing an overview of the equipment control system.
[0181] In this embodiment, the target device is a cash handling terminal 103 such as an ATM (Automated Teller Machine) or CD (Automated Cash Dispenser). When a user stands in front of the cash handling terminal 103 and activates the authentication application on the mobile terminal 3 to perform biometric authentication and refund operations, cash is dispensed from the cash dispenser of the cash handling terminal 103, and the user can receive the cash.
[0182] In this example, withdrawals (refunds) are made at the cash handling terminal 103, but deposits (deposits, transfers, etc.) may also be made at the cash handling terminal 103. In this case, the user can make a deposit by performing the deposit operation on the device operation screen displayed on the mobile terminal 3 and inserting cash into the cash slot.
[0183] Furthermore, in this embodiment, since control authority is granted to each user for each cash handling terminal 103, users can only use a specific cash handling terminal 103, thus allowing the use of cash handling terminals 103 to be restricted according to the user.
[0184] Next, the screen displayed on the mobile terminal 3 according to the seventh embodiment will be described. Figure 24 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0185] On mobile terminal 3, the authentication application is launched, and as an authentication guidance screen, the initial screen shown in Figure 24(A) is displayed first, followed by the face capture screen shown in Figure 24(B). If person matching (face recognition) is successful and control of the target device is permitted, the system transitions to the result confirmation screen shown in Figure 24(C). In other cases, such as when person matching (face recognition) fails and control of the target device is not permitted, the process is the same as in the first embodiment (see Figures 8(D) to (F)).
[0186] In the result confirmation screen shown in Figure 24(C), the first display unit 81 displays text indicating that the cash handling terminal 103 (ATM) is the control target. The second display unit 82 displays text indicating that the person verification (facial recognition) was successful as the person verification result, and text indicating that a refund is possible as the device control content.
[0187] Next, the mobile terminal 3 launches the device operation application and transitions to the device operation screen shown in Figures 24(D) to (F). In this example, a different device operation screen is displayed for each refund amount. The device operation screen displays text representing the refund amount. When the user operates the "Refund" button 86, cash is dispensed into the cash dispenser, and the user can receive the cash.
[0188] (Eighth embodiment) Next, an eighth embodiment will be described. Points not specifically mentioned here are the same as in the previous embodiments. Figure 25 is an explanatory diagram showing an overview of the payment system according to the eighth embodiment.
[0189] In this embodiment, the location information of the mobile terminal 3 is used to detect when users board or alight from public transportation (trains, taxis, buses, etc.), and the travel section (boarding station, alighting station) is identified. In addition, biometric authentication (facial recognition) is performed when boarding, and if biometric authentication is successful, boarding is permitted. Furthermore, payment of the fare (settlement) is made for the user identified through biometric authentication.
[0190] Furthermore, since the authentication application running continuously on the mobile terminal 3 periodically transmits the location information of the mobile terminal 3, it is possible to detect when a user boards or alights, thereby preventing fare evasion.
[0191] Next, the screen displayed on the mobile terminal 3 according to the eighth embodiment will be described. Figure 26 is an explanatory diagram showing the screen displayed on the mobile terminal 3.
[0192] This example assumes that a passenger boards a train at Station A and alights at Station B.
[0193] First, the user launches the authentication application on the mobile terminal 3 before reaching the ticket gate at Station A. On the mobile terminal 3, the initial screen shown in Figure 26(A) is displayed as an authentication guidance screen, followed by the face-capture screen shown in Figure 26(B). On the face-capture screen, the first display unit 81 shows text indicating that authentication will be performed for boarding at Station A.
[0194] Next, if person verification (facial recognition) is successful, the mobile terminal 3 displays the boarding permission screen shown in Figure 26(C). On the boarding permission screen, the first display unit 81 displays text indicating that boarding is permitted. The second display unit 82 also displays text indicating that person verification (facial recognition) was successful, as well as text prompting the user to board the train at the boarding station (Station A). At this time, the mobile terminal 3 detects that the user is at Station A based on its own location information.
[0195] After a user boards a train at station A, their departure point, the train arrives at station B, their destination, and the user disembarks at station B. At this time, mobile terminal 3 detects that the user is at station B based on its own location information. Furthermore, mobile terminal 3 detects that the user has disembarked at station B after a predetermined period of time has passed. As a result, mobile terminal 3 displays the disembarkation confirmation screen shown in Figure 26(D). On the disembarkation confirmation screen, the first display unit 81 displays text indicating that disembarkation is permitted. The second display unit 82 displays text indicating that the user has disembarked, text indicating that fare payment has been completed, and text representing the fare amount.
[0196] In this example, facial recognition is performed upon boarding and fare payment is made upon alighting, but it is also possible for facial recognition to be performed and fare payment to be made upon alighting.
[0197] Furthermore, it is conceivable that users may present the boarding permission screen (see Figure 26(C)) displayed on the mobile terminal 3 to the driver, conductor, or other crew members when boarding, during the ride, or when alighting. In this case, for example, in the case of one-man operation such as a route bus, the driver cannot carefully check the contents of the boarding permission screen displayed on the mobile terminal 3. Therefore, the background color of the boarding permission screen may be changed depending on the day of the week or time of day. This would allow the driver to immediately check the contents of the boarding permission screen by its background color, and would also prevent fraudulent use of previously displayed boarding permission screens by users.
[0198] If the background color of the boarding permission screen changes depending on the day of the week, for example, the background color would be set to light blue on Mondays, Wednesdays, and Fridays; orange on Tuesdays and Thursdays; blue on Saturdays; and yellow on Sundays. Furthermore, if the background color of the boarding permission screen changes depending on the time of day, for example, light blue in the morning and yellow in the evenings, the crew could immediately detect if a passenger is attempting to board fraudulently using the previous boarding permission screen. In the event of a failed authentication, the background color should be changed to a different color from the boarding permission screen, such as red.
[0199] By the way, in the above embodiment, a system for controlling the unlocking of doors installed at the entrance and exit of a facility was described, but it may also be a system for controlling gates installed at the entrance and exit of a facility (the entrance and exit may be separate), that is, a system that controls the opening of the gate when authentication is successful and entry or exit to the facility is permitted. Specifically, it may be a system for controlling gates installed at the ticket gates of a train station, or gates installed at the entrance of an exhibition, museum, amusement park, etc. It may also be a system for controlling gates installed at the entrance and exit of a bicycle parking area or parking lot.
[0200] Furthermore, even in systems where authentication is performed at the entrance and exit of a facility, the gates may not be controlled. Specifically, once authentication is successful and entry or exit is permitted, the system may provide information regarding entry and exit to the facility, or process payment of usage fees. For example, in the case of bicycle parking areas or car parks, once authentication is successful and entry or exit is permitted, parking permission and guidance to parking spaces may be provided, or parking fees may be processed.
[0201] Furthermore, in the above embodiment, operations related to the control of the target equipment are performed using a mobile terminal 3 held by the user, but a robot capable of self-propelled movement within the facility may also be equipped with the functions of the mobile terminal 3 (checker). In this case, for example, the robot would wait at the facility's reception desk, perform actions necessary for biometric authentication of visitors (for example, taking a picture of the visitor's face), and once biometric authentication is complete, guide the visitor to the conference room and unlock the conference room door.
[0202] Furthermore, in the above embodiment, the control panel 101, vending machine 102, and cash handling terminal 103, which are the target devices, are remotely controlled by the authentication server 1. However, the alcohol detector held by the user may also be remotely controlled by the authentication server 1. This would enable alcohol checks using an alcohol detector during remote roll calls by transportation companies and the like. In this case, the use of the alcohol detector is permitted by biometric authentication using the mobile terminal 3, and when alcohol is detected by the alcohol detector, the detection result is notified to the administrator terminal via the authentication server 1 or the like.
[0203] As described above, embodiments have been explained as examples of the technology disclosed in this application. However, the technology in this disclosure is not limited to these embodiments and can be applied to embodiments that have been modified, replaced, added, or omitted. Furthermore, it is possible to create new embodiments by combining the components described in the above embodiments. [Industrial applicability]
[0204] The door unlocking system, terminal device, equipment control system, and door unlocking method according to the present invention have the effect of achieving highly secure authentication with a simple configuration, without requiring a dedicated authentication device at the point where the user is authenticated, by utilizing a terminal device possessed by the user. They are useful as a door unlocking system and door unlocking method that controls the unlocking of a door according to the result of the user's biometric authentication, a terminal device on which operations related to the user's biometric authentication are performed, and an equipment control system that controls a target device according to the result of the user's biometric authentication. [Explanation of Symbols]
[0205] 1. Authentication Server (Server Device) 2. Device Management Server 3. Mobile terminal (terminal device) 4. Registered terminals 5. Electronic lock (locking device) 11 Communications Department 12 Storage section 13 processors 31 Sensors 32 Positioning Unit 33 Display Input Section 34 Communications Department 35 Storage section 36 processors
Claims
1. A door unlocking system that controls the unlocking of a door according to the result of a person matching process based on the user's biometric information, A server device that remotely controls the locking mechanism installed on the door, The system comprises a terminal device possessed by the user, connected to the server device via a network, having a sensor that acquires the user's biometric information, and a positioning unit that acquires the location information of the device itself. The server device is The user's biometric information acquired by the aforementioned sensor and the location information of the terminal device acquired by the positioning unit are obtained from the terminal device. The system performs a person matching process that compares the biometric information of the user with the biometric information of the registered person, A location matching process is performed to compare the location information of the terminal device with the location information of the door. A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the door. A door unlocking system characterized by determining whether or not the door can be unlocked based on the results of the person matching process, the location matching process, and the unique object matching process.
2. The server device is The terminal device acquires a facial image of the user as biometric information captured by the camera, which is the aforementioned sensor. The door unlocking system according to claim 1, characterized in that the person matching process compares the user's facial image with the registered person's facial image.
3. The server device is The door unlocking system according to claim 1, characterized in that the terminal device acquires the location information obtained using a satellite positioning system from the terminal device.
4. The server device is The door unlocking system according to claim 1, characterized in that, as the unique object verification process, the terminal device compares code information obtained by taking a picture of a code image provided near the door with code information registered in association with the door.
5. The server device is The door unlocking system according to claim 1, characterized in that, as the unique object matching process, it matches the identification information of a telephone installed near the door and operated by a user with the identification information of a telephone registered in association with the door.
6. The server device is The door unlocking system according to claim 1, characterized in that, as the unique object matching process, the identification information of a wireless network access point provided near the door and used by the terminal device is compared with the identification information of an access point registered in association with the door.
7. Possessed by the user, A server device that remotely controls the locking mechanism installed on the door is connected via a network. A sensor that acquires the user's biometric information, A positioning unit that acquires the location information of the device, It includes a display input unit that displays a screen and accepts user input, A terminal device characterized by displaying an authentication guidance screen that provides guidance on acquiring the user's biometric information, and a result confirmation screen regarding the determination result of whether or not the door can be unlocked, which is performed based on the result of a unique object matching process in which the server device compares the user's biometric information, the location information of the device itself, and unique object information acquired based on at least one of the device itself and the user with unique object information registered in association with the door.
8. A device control system that controls target devices according to the results of a person matching process based on the user's biometric information, A server device for remotely controlling the target equipment, The system comprises a terminal device possessed by the user, connected to the server device via a network, having a sensor that acquires the user's biometric information, and a positioning unit that acquires the location information of the device itself. The server device is The user's biometric information acquired by the aforementioned sensor and the location information of the terminal device acquired by the positioning unit are obtained from the terminal device. The system performs a person matching process that compares the biometric information of the user with the biometric information of the registered person, A location matching process is performed to compare the location information of the terminal device with the location information of the target device. A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the target device. A device control system characterized by determining whether or not the target device can be controlled based on the results of the person matching process, the location matching process, and the unique object matching process.
9. The server device is The terminal device is transmitted a device operation screen in which the user performs operations to control the aforementioned target device. The device control system according to claim 8, characterized in that it controls the target device in response to user operations on the device operation screen.
10. A door unlocking method in which a processor executes a process to control the unlocking of a door according to the result of a person matching process based on the user's biometric information, From a terminal device possessed by a user and having a sensor that acquires the user's biometric information and a positioning unit that acquires the location information of the device itself, the system acquires the user's biometric information acquired by the sensor and the location information of the terminal device acquired by the positioning unit. The system performs a person matching process that compares the biometric information of the user with the biometric information of the registered person, A location matching process is performed to compare the location information of the terminal device with the location information of the door. A unique object matching process is performed to compare unique object information obtained based on at least one of the terminal device and the user with unique object information registered in association with the door. A door unlocking method characterized by determining whether the door can be unlocked based on the results of the person matching process, the location matching process, and the unique object matching process, and remotely controlling a locking device installed on the door according to the result of the determination.
Citation Information
Patent Citations
Intelligent article storage cabinet for performing face recognition by using mobile phone terminal
CN109671202A
Entrance and exit control system
JP2006172286A
Access management apparatus, access management method, and program
JP2015064722A
Room entry / exit management system
JP2020042374A
Composite system, biometric authentication system, method for controlling composite system, and program
JP2021135975A