Registration device, registration method, and program
Patent Information
- Application Number
- JP2022042615
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-17
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-03-17
AI Technical Summary
【0014】 本開示の一実施例によれば、認証用の第1の生体情報と第1の権限とが登録されている第1の人物と一緒に行動している第2の人物に対して、認証用の第2の生体情報と、第1の権限が登録されている人物と一緒に行動することを条件に所定の行動を行うことができる第2の権限と、が登録される。また、第2の人物に対して、所定の条件が満たされたことに応じて、第2の権限が第1の権限に更新される。このように、登録済みの第1の人物と一緒に行動している未登録の第2の人物の生体情報が、第1の人物等の人物と一緒に行動することを条件に所定の行動を行うことができる第2の権限とともに登録され、所定の条件が満たされたことに応じて制限が緩和されるように第2の権限が第1の権限に更新されるので、セキュリティと第2の人物の利便性との両立を図ることができる。
Smart Images

Figure 0007912191000001 
Figure 0007912191000002 
Figure 0007912191000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a registration device, a registration method, and a program.
Background Art
[0002] In various fields, personal authentication based on face image analysis (hereinafter referred to as face authentication) is used. Face authentication is performed by pre-registering (storing) a face image of a person to be registered (hereinafter also referred to as a face, face information, or face information), and then collating a face image of a person to be authenticated captured by a camera with the pre-registered face image. When the face image of the person to be authenticated matches the pre-registered face image, the identity of the person is confirmed (authentication succeeds).
[0003] Regarding registration of face images, for example, Patent Document 1 discloses an authentication device that additionally registers face information used for authentication.
[0004] This authentication device acquires an image, extracts a face from the acquired image, collates the extracted face information with the face information registered in the authentication information stored in a storage unit, and determines whether the extracted face is a face whose information is registered in the authentication information. Further, when a face determined to be a face whose information is registered in the authentication information and a face determined not to be a face whose information is registered in the authentication information are extracted from the acquired image, this authentication device registers, in the authentication information, information of a face extracted from the acquired image that is determined not to be a face whose information is registered in the authentication information.
Prior Art Literature
Patent Literature
[0005]
Patent Document 1
Summary of the Invention
Problem to be Solved by the Invention
[0006] In the conventional technology described above, a person appearing in a camera image with a face registered in the authentication information (the registrant) is granted the same privileges as the registrant (a person whose face is not determined to be registered in the authentication information; an additional registrant). Therefore, if strong privileges are granted to the registrant, strong privileges will also be granted to unregistered individuals, which poses a risk and security problem in offices and other places where visitor access needs to be restricted.
[0007] Furthermore, in recent years, solutions known as gateless entrances have been considered and are being implemented in offices and other locations, allowing for identity verification without stopping at entrance gates or security checks by security guards. In cases where authentication cameras installed near such gateless entrances capture a wide area and perform facial recognition on many people passing by, applying the conventional technology described above could result in registering the faces of incorrect individuals. In such cases, there is a risk of granting strong privileges to incorrect individuals, which poses a security problem.
[0008] On the other hand, if security is prioritized too much and the privileges of additional registrants who are authenticated remain restricted, it may be insufficient in terms of convenience for those authenticated.
[0009] Non-limiting embodiments of this disclosure contribute to the provision of a registration device, registration method, and program for registering information of certified persons, which can balance security and the convenience of certified persons. [Means for solving the problem]
[0010] A registration device according to one embodiment of the present disclosure includes: an estimation unit that estimates whether a first person and a second person are acting together based on an image captured by a camera; and a registration unit that, if first biometric information and first authority for authentication of the first person are registered, and second biometric information for authentication of the second person are not registered, registers the second biometric information included in the image and a second authority that allows the second person acting together with the first person to perform a predetermined action on the condition that the second person acts together with the person for whom the first authority is registered, based on the result of the estimation, and updates the second authority to the first authority when the predetermined conditions are met.
[0011] A registration method according to one embodiment of the present disclosure estimates whether a first person and a second person are acting together based on an image captured by a camera. If the first person has registered first biometric information and first authority for authentication, and the second person has not registered second biometric information for authentication, the method registers the second biometric information included in the image and a second authority that allows the second person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered, based on the result of the estimation. The method then updates the second authority to the first authority when the predetermined conditions are met.
[0012] A program according to one embodiment of the present disclosure causes a computer to perform a procedure that estimates whether a first person and a second person are acting together based on an image captured by a camera, and if the first person has registered first biometric information and first authority for authentication, and the second person has not registered second biometric information for authentication, then, based on the result of the estimation, registers the second biometric information contained in the image and a second authority that allows the second person acting together with the person for whom the first authority is registered to perform a predetermined action, and updates the second authority to the first authority when the predetermined conditions are met.
[0013] These comprehensive or specific embodiments may be implemented as systems, devices, methods, integrated circuits, computer programs, or recording media, or as any combination of systems, devices, methods, integrated circuits, computer programs, and recording media. [Effects of the Invention]
[0014] According to one embodiment of this disclosure, a second person acting together with a first person whose first biometric information and first authority for authentication are registered is registered with a second person for authentication, and a second authority that allows the second person to perform a predetermined action on the condition that they act together with the person whose first authority is registered. Furthermore, the second authority is updated to the first authority for the second person when the predetermined conditions are met. In this way, the biometric information of an unregistered second person acting together with a registered first person is registered along with a second authority that allows the second person to perform a predetermined action on the condition that they act together with the first person or other person, and the second authority is updated to the first authority in such a way that the restrictions are eased when the predetermined conditions are met, thus achieving a balance between security and convenience for the second person.
[0015] Further advantages and effects of one embodiment of this disclosure will be made apparent from the specification and drawings. Such advantages and / or effects are provided by several embodiments and features described in the specification and drawings, but not all of them are necessarily provided in order to obtain one or more identical features. [Brief explanation of the drawing]
[0016] [Figure 1] Block diagram showing an example configuration of a facial recognition and registration system according to an embodiment of this disclosure. [Figure 2] Block diagram showing an example configuration of an authentication and registration device according to an embodiment of this disclosure. [Figure 3] A flowchart illustrating an example of the operation of an authentication / registration device according to an embodiment of this disclosure. [Figure 4] Flowchart illustrating another operation example of the authentication and registration device according to an embodiment of the present disclosure [Figure 5] Flowchart illustrating still another operation example of the authentication and registration device according to an embodiment of the present disclosure [Figure 6] Diagram illustrating a hardware configuration example of a computer according to an embodiment of the present disclosure MODE FOR CARRYING OUT THE INVENTION
[0017] Hereinafter, embodiments of the present disclosure will be described in detail with appropriate reference to the drawings. However, overly detailed description may be omitted in some cases. For example, detailed description of already well-known matters and repeated description of substantially the same configuration may be omitted. This is to avoid unnecessary redundancy in the following description and to facilitate understanding for those skilled in the art.
[0018] The accompanying drawings and the following description are provided for those skilled in the art to fully understand the present disclosure, and are not intended to limit the subject matter recited in the claims thereby.
[0019] (Embodiment) <Configuration of Face Authentication and Registration System> FIG. 1 is a block diagram illustrating a configuration example of a face authentication and registration system 1 according to an embodiment of the present disclosure.
[0020] As illustrated in FIG. 1, the face authentication and registration system 1 includes a camera 10 and an authentication and registration device 20. The camera 10 and the authentication and registration device 20 are connected via a wired or wireless network 30.
[0021] Camera 10 is installed at various locations within a predetermined area, such as near the entrance of a building or facility, inside a room within a building or facility, on the side walls, ceiling, or columnar structures of a corridor in a building or facility. The predetermined area may be inside a building, such as an office building, shopping mall, underground shopping area, train station, airport, or public facility, or it may be outdoors, such as a park, sports field, or zoo. In the following explanation, we will assume a scenario in which the facial recognition and registration system 1 is used for gateless facial recognition applied to the gateless entrance of an office or the like, as an example, but the scenario in which the facial recognition and registration system 1 is used is not limited to the above. Camera 10 transmits the captured image (hereinafter referred to as "captured image") to the authentication and registration device 20 via the network 30. The captured image may be a still image or a moving image. Camera 10 only needs to have the ability to generate captured images with a resolution that allows the authentication and registration device 20 to recognize the faces of people present in the captured image. Camera 10 may also be referred to as a shooting device, imaging device, shooting unit, imaging unit, etc.
[0022] The authentication and registration device 20 registers (stores in the memory unit of the authentication and registration device 20) the unique identification information of a person (for example, each of all employees working in the office), the person's face, and the person's authority, which are entered by a user such as the administrator of the facial recognition and registration system 1. The authentication and registration device 20 is an example of a registration device, authentication device, information processing device, computer, etc. relating to this disclosure.
[0023] Here, a person's authority to act is broadly divided into individual authority and group authority. Group authority means the authority to act only when accompanied by a registered person who has individual authority (i.e., only when accompanied by a registered person who has individual authority). On the other hand, individual authority means the authority to act even when not accompanied by a registered person who has individual authority (i.e., alone). In this disclosure, a person whose identification information or face is registered (stored) in the authentication / registration device 20 is referred to as a registered person (or simply a registered person), and a person whose identification information or face is not registered in the authentication / registration device 20 is referred to as an unregistered person. Individual authority is an example of the "first authority" related to this disclosure, and group authority is an example of the "second authority which is more restricted than the first authority" related to this disclosure, and the "second authority which allows a person to take a prescribed action on the condition that they act together with a person who has registered first authority." Furthermore, "group action authority" may also be expressed as "the authority to perform a specified action on the condition that the action is performed together with all registered individuals who have recorded in the (described later) configuration information that they are scheduled to act together with a visitor (unregistered person)." Examples of actions that require this authority include entering and exiting a specific space, operating equipment, settling expenses, and various other actions.
[0024] The authentication and registration device 20 performs the following based on the images received from the camera 10: estimation of individuals acting together in a group (group estimation), identification of individuals to be authenticated (detection), and authentication of individuals to be authenticated. The authentication and registration device 20 further performs the following: registration of unregistered individuals to be authenticated (face, etc.), registration of the actions of individuals to be authenticated and updating of those actions when predetermined conditions are met (registration and updating may be collectively referred to as granting), and determination of violations of the actions of individuals to be authenticated. Estimation may also be referred to as determination, judgment, discrimination, estimation, calculation, etc.
[0025] The authentication and registration device 20 estimates whether multiple individuals are acting together as a group based on the images captured by the camera 10.
[0026] When an unregistered person who has been pre-configured to act together and a registered person with the authority to act alone are acting together as a group, the authentication / registration device 20 associates (matches or links) the face of the unregistered person and the identification information of the unregistered person, respectively, included in the image captured by the camera 10, and registers them.
[0027] During this registration process, the authentication and registration device 20 registers the action rights of unregistered individuals as group action rights, associated with the face of the unregistered individual and the identification information of the unregistered individual, and which can be updated when predetermined conditions are met.
[0028] As described above, unregistered individuals who are considered somewhat trustworthy because they are acting together with registered individuals who have individual action privileges are automatically registered with group action privileges. This ensures security because, at the time of automatic registration, the action privileges of individuals who were previously unregistered but considered somewhat trustworthy are restricted to group action privileges. Furthermore, since the action privileges granted at the time of automatic registration are restricted to group action privileges, the risk of incorrect registration is mitigated. In addition, the action privileges of individuals who were previously unregistered can be updated, for example, from group action privileges to individual action privileges, depending on the conditions that are met. In this case, the previously unregistered individual can, for example, act alone in an office, thereby improving convenience for the previously unregistered individual.
[0029] <Configuration of Authentication and Registration Device> Figure 2 is a block diagram showing an example configuration of the authentication and registration device 20.
[0030] The authentication and registration device 20 includes a person visitor information registration unit 201, a person visitor information storage unit 202, an image receiving unit 203, an image storage unit 204, a group estimation unit 205, an authentication and registration unit 206, a registered user information storage unit 207, and an action authority violation determination unit 208.
[0031] The Person Visitor Information Registration Unit 201 associates the unique identification information of a person visiting the office (an example of the "second person" in this disclosure), which is entered and set by the user of the facial recognition and registration system 1, with the date and time the person will visit the office and the identification information of a registered person accompanying the person (an example of the "first person" in this disclosure; for example, an employee working at the office who will escort the visiting person), and outputs (stores) this as person visitor information (which may also be called setting information) to the Person Visitor Information Storage Unit 202. This person visitor information is set and registered in advance and indicates that the visiting person and the registered person will act together. The person visitor information may or may not include the date and time of the visit. The person visitor information may also be called a visitor pattern or pattern. Furthermore, the second person may be multiple people. In this embodiment, it is not assumed that the facial information of the second person is not registered in advance. Therefore, if multiple second people visit simultaneously, other information is used to identify each second person in order to manage the authority of each person. In this case, for example, it is conceivable to identify each second person using a technique that estimates the attributes of the visiting person (such as gender and age).
[0032] The Person Visitor Information Registration Unit 201 stores information about people who have visited the area.
[0033] The image receiving unit 203 receives captured images from each camera 10 via the network 30. Along with the captured image, the image receiving unit 203 also receives unique identification information of the camera 10 that transmitted the image (for example, indicating that it is a camera 10 installed in an entrance, etc.). The image receiving unit 203 associates the received captured image, the identification information of the captured image, and the identification information of the camera 10 that transmitted the image, and outputs them to the image storage unit 204. The captured image includes the date and time the image was taken as metadata.
[0034] The image storage unit 204 stores the captured image along with the identification information of the captured image and the identification information of the camera 10 that transmitted the captured image.
[0035] The group estimation unit 205 estimates whether the people included in the captured images stored in the image storage unit 204 form a group, based on the captured images stored in the image storage unit 204 and existing group estimation techniques. For example, the group estimation unit 205 estimates a group using the distance between people and their movement paths in the captured images. A group refers to a group acting together.
[0036] More specifically, the group estimation unit 205 may estimate groups based on the movement paths of each person in the captured image. For example, the group estimation unit 205 may analyze the movement trajectory of each person and estimate that people with similar movement trajectories form the (same) group. Alternatively, the group estimation unit 205 may calculate the relative distance and relative velocity of all combinations of people from the time-dependent positions of the people in the captured image and determine whether the people in each combination form the (same) group. For example, the group estimation unit 205 may make a determination based on whether the relative distance remains below a certain threshold for a certain period of time or longer, or whether both the relative distance and relative velocity remain below a predetermined threshold in a certain time interval. In this case, the group estimation unit 205 may estimate that people form a group if the relative distance remains below a certain threshold for a certain period of time or longer, or if both the relative distance and relative velocity remain below a predetermined threshold in a certain time interval. Furthermore, the method for estimating groups is not limited to methods using movement trajectories, relative distances, relative velocities, etc., and various known methods may be used. For example, the group estimation unit 205 may estimate groups using the facial orientation information of people in the captured images.
[0037] Furthermore, the group estimation unit 205 detects and extracts human faces from the captured images stored in the image storage unit 204. For example, the group estimation unit 205 detects faces using a classifier that has been created in advance for face detection. As such a classifier, for example, a Haar-Like cascade classifier that has been created in advance for face detection in an open-source image processing library can be used. Alternatively, the group estimation unit 205 may detect faces by pattern matching. The group estimation unit 205 detects and extracts faces of both people who form a group and people who do not form a group.
[0038] Furthermore, the group estimation unit 205 performs face tracking based on the captured images stored in the image storage unit 204. For example, the group estimation unit 205 determines the identity of a person based on the relationship between the captured images of the face positions obtained as a result of face detection, and tracks the faces of the same person.
[0039] The group estimation unit 205 outputs the estimation result (whether or not a group is formed), the identification information of the captured image used as the basis for estimation, the detected and extracted faces, the identification information of the captured image from which the faces were detected and extracted, and the tracking result to the authentication / registration unit 206 and the action authority violation determination unit 208.
[0040] The authentication and registration unit 206 associates the unique identification information of a person (for example, an employee working in an office), the person's face, and the person's authority (which may also be called authority or authority information), as entered by the user of the facial recognition and registration system 1, and registers them as registrant information (stored in the registrant information storage unit 207).
[0041] Furthermore, the authentication / registration unit 206 performs identity verification (authentication) by comparing the face input from the group estimation unit 205 with the faces of already registered individuals stored in the registrant information storage unit 207. If a face that matches the face input from the group estimation unit 205 is stored in the registrant information storage unit 207 (i.e., authentication is successful), the authentication / registration unit 206 takes no action. More specifically, the authentication / registration unit 206 may perform authentication based on the similarity between the face input from the group estimation unit 205 and the faces stored in the registrant information storage unit 207. For example, the higher the similarity between the face and the face stored in the registrant information storage unit 207, the higher the similarity information (hereinafter referred to as the "authentication score") may be set. Then, for example, if the authentication score is above a threshold, the authentication / registration unit 206 may determine that the face input from the group estimation unit 205 matches the face stored in the registrant information storage unit 207. Conversely, the authentication / registration unit 206 may determine, for example, that if the authentication score is below a threshold, the face input from the group estimation unit 205 does not match the face stored in the registrant information storage unit 207.
[0042] If no face matching the face input from the group estimation unit 205 is stored in the registrant information storage unit 207 (for example, if the authentication score is below a threshold), the authentication / registration unit 206 first identifies the already registered person with independent action authority, as indicated by the setting information stored in the person visitor information storage unit 202, who forms a group obtained from the estimation results input from the group estimation unit 205 in the captured image. Next, if the person whose face was input from the group estimation unit 205 but is not stored in the registrant information storage unit 207 forms the group, the authentication / registration unit 206 associates the identification information of the visitor (unregistered person) accompanying the above-mentioned already registered person, as indicated by the setting information, with the person's face and the group action authority as that person's action authority, and registers them as registrant information (stored in the registrant information storage unit 207). During this registration, the authentication / registration unit 206 also registers the identification information of the already registered person with independent action authority, as indicated by the setting information, along with the group action authority, as registrant information. This means that this visitor cannot act without being accompanied by this registered person. In this way, in order to register an unregistered person, prior configuration information indicating that the unregistered person will act together with a registered person is required, thus guaranteeing that the unregistered person is a trustworthy individual to some extent and ensuring security.
[0043] Furthermore, if no face matching the face input from the group estimation unit 205 is stored in the registrant information storage unit 207, and the person whose face was input from the group estimation unit 205 does not form a group with an already registered person who has independent action authority (authentication fails), the authentication / registration unit 206 transmits a signal indicating authentication failure, along with the face input from the group estimation unit 205, to a terminal or the like held by the security guard, via the communication interface (not shown) of the authentication / registration device 20.
[0044] Furthermore, the authentication / registration unit 206 updates the activity privileges stored in the registrant information storage unit 207 based on images taken by cameras 10 other than the camera 10 installed near the entrance, which are stored in the image storage unit 204, when predetermined conditions are met. For example, based on images taken by camera 10 while moving within the office building, images taken by camera 10 from entering to leaving a room in the office building, etc., the authentication / registration unit 206 updates the activity privileges of a person with group activity privileges to individual activity privileges when the condition that "a certain number (threshold; e.g., 5 people) or more of already registered persons with individual activity privileges join the above group and act together for a certain period of time (threshold; e.g., 1 minute) or longer" is met. Note that the predetermined conditions are not limited to those mentioned above. Thus, since a person with group action privileges acts with a registered individual with independent action privileges who is considered trustworthy for at least a certain period of time, the person with group action privileges can be considered trustworthy, and as a result, their privileges are updated to independent action privileges, thereby improving their convenience. Furthermore, since a person with group action privileges acts with a certain number of registered individuals with independent action privileges who are considered trustworthy, the person with group action privileges can be considered more trustworthy, and as a result, their privileges are updated to independent action privileges, thereby improving their convenience. In other words, if there are few people with independent action privileges, they may collude with a person with group action privileges to fraudulently update their group action privileges to independent action privileges, but by making accompanying a larger number of people with independent action privileges a condition for updating privileges, such fraudulent activity can be deterred.
[0045] In addition, a registered person in relation to this disclosure refers to a person whose face or identification information is stored in the registered person information storage unit 207, while an unregistered person in relation to this disclosure refers to a person whose face or identification information is not stored in the registered person information storage unit 207.
[0046] The Action Authority Violation Determination Unit 208 determines, based on the estimation results input from the Group Estimation Unit 205 and the captured images stored in the Image Storage Unit 204, such as those taken by cameras 10 other than the camera 10 installed near the entrance, whether the person indicated by the registered user information stored in the Registered User Information Storage Unit 207 is violating the action authority indicated by the registered user information. If the person indicated by the registered user information is violating the action authority indicated by the registered user information, the Action Authority Violation Determination Unit 208 transmits a signal indicating the violation, along with the face input from the Group Estimation Unit 205, to a terminal held by the security guard via the communication interface of the authentication / registration device 20. For example, if the person indicated by the registered user information has group action authority indicated by the registered user information, the Action Authority Violation Determination Unit 208 determines, based on the estimation results input from the Group Estimation Unit 205 and the captured images stored in the Image Storage Unit 204, whether the person is acting together with an already registered person who has individual action authority. If the person in question is not acting with a registered person who has the authority to act alone (for example, for a predetermined period of time), the action authority violation determination unit 208 transmits a signal indicating that the person is in violation of group action authority, along with the person's face, to a terminal held by the security guard via the communication interface of the authentication / registration device 20.
[0047] The group estimation unit 205 is an example of an estimation unit relating to this disclosure. The authentication / registration unit 206 is an example of a registration unit relating to this disclosure. The person visitor information registration unit 201, the group estimation unit 205, the authentication / registration unit 206, and the action authority violation determination unit 208 may be referred to as a control unit, processing unit, etc. That is, the person visitor information registration unit 201, the group estimation unit 205, the authentication / registration unit 206, and the action authority violation determination unit 208 may constitute a control unit, processing unit, etc. The control unit, processing unit, etc. may be implemented by a processor, controller, etc. The person visitor information storage unit 202, the image storage unit 204, and the registrant information storage unit 207 may be referred to as a storage unit. That is, the person visitor information storage unit 202, the image storage unit 204, and the registrant information storage unit 207 may constitute a storage unit. The image receiving unit 203 and the communication interface may be referred to as a communication unit. That is, the image receiving unit 203 and the communication interface may constitute a communication unit.
[0048] The functional units described above may be further divided into functional units, or two or more functional units may be integrated into a single functional unit. For example, the authentication / registration unit 206 may be divided into a determination unit that determines whether predetermined conditions for determining whether or not to update the action rights have been met, and a functional unit that performs processing other than this determination, and this functional unit may be further divided into sub-functional units depending on the function to be performed. Alternatively, for example, the authentication / registration unit 206 and the action rights violation determination unit 208 may be implemented as a single functional unit.
[0049] The authentication and registration device 20 may be implemented as a single device having all of the above-described functional units, or as multiple devices in which the above-described functional units are distributed. When the authentication and registration device 20 is implemented as multiple devices, the functions of the authentication and registration device 20 can be realized by the cooperation of the multiple devices via a network.
[0050] In summary, since the actions granted during automatic registration are limited to group actions, security can be ensured, and the risk of incorrect registration can be mitigated. Furthermore, the group actions a person possesses can be upgraded to individual actions when certain conditions are met, thereby improving the convenience for that person.
[0051] <Operation of Authentication / Registration Device> Figure 3 is a flowchart showing an example of the operation of the authentication and registration device 20 according to an embodiment of this disclosure. The process shown in Figure 3 relates to the pre-registration of visitors.
[0052] In step S301, the person visit information registration unit 201 pre-registers person visit information by storing the person visit information entered and set by the user in the person visit information storage unit 202. As described above, person visit information may also be called a visit pattern. After step S301, the flow ends. Note that each time the user enters and sets person visit information, the process shown in Figure 3 may be executed.
[0053] Figure 4 is a flowchart showing another example of operation of the authentication and registration device 20 according to an embodiment of the present disclosure. The process shown in Figure 4 relates to group estimation, authentication, and automatic registration based on images captured by a camera 10 installed near the entrance.
[0054] In step S401, the group estimation unit 205 estimates the group based on images captured by the camera 10 installed near the entrance. This estimation also includes face detection and face tracking by the group estimation unit 205.
[0055] In step S402, the authentication and registration unit 206 performs facial recognition processing based on the images captured by the camera 10 installed near the entrance, for the number of faces detected in step S401. In this facial recognition processing, registered visitors, unregistered visitors accompanied by registered visitors with independent travel privileges, and unregistered visitors not accompanied by registered visitors with independent travel privileges are identified.
[0056] Next, step S403 is performed at least as many times as the number of groups estimated in step S401.
[0057] Specifically, in step S403, the authentication / registration unit 206 determines whether the estimated group matches the visit pattern. The authentication / registration unit 206 may perform this determination on the condition that at least one, a predetermined number, or all of the captured images used to estimate the group were taken within a predetermined range including the date and time of the visit (for example, 30 minutes before and after the date and time of the visit).
[0058] If the estimated group does not match the visitor pattern (No in step S403), the flow returns to step S403 (if there are still unprocessed groups remaining) or terminates (if there are no unprocessed groups remaining).
[0059] On the other hand, if the estimated group matches the visitor pattern (Yes in step S403), in step S404, the authentication / registration unit 206 registers the unregistered person (or their face) by storing the unregistered person's face, etc., in the registrant information storage unit 207. At this time, the authentication / registration unit 206 grants the unregistered person group action authority by storing the group action authority in association with the unregistered person. The flow then returns to step S403 (if there are still unprocessed groups remaining) or terminates (if there are no unprocessed groups remaining).
[0060] The flow terminates after step S403 has been executed at least as many times as the number of groups estimated in step S401.
[0061] Although not shown in the diagram, during the process shown in Figure 4, for any authenticated individuals who were not automatically registered (individuals whose authentication failed), the authentication / registration unit 206 transmits a signal indicating that authentication failed, along with the face of the authenticated individual, to a terminal or other device held by the security guard.
[0062] Figure 5 is a flowchart showing yet another example of operation of the authentication and registration device 20 according to an embodiment of the present disclosure. The process shown in Figure 5 relates to group estimation, authentication, and activity authority updating based on images captured by cameras 10 other than the camera 10 installed near the entrance. For example, the process shown in Figure 5 may be performed after the process shown in Figure 4, while an unregistered visitor is moving around and staying in the room after being automatically registered, or it may be performed while the visitor is moving around and staying in the room after they visit on a later date and are successfully authenticated at the entrance as a registered person.
[0063] Step S501 is the same as step S401 described above, except that the camera 10 that took the captured image used for estimation is different.
[0064] Step S502 is the same as step S402 described above, except that the camera 10 that captured the image used for facial recognition processing is different. In this facial recognition processing, registered individuals with individual action authority and registered individuals with group action authority (and in some cases, unregistered individuals) are identified.
[0065] Next, step S503 is performed at least as many times as the number of groups estimated in step S501.
[0066] Specifically, in step S503, the authentication / registration unit 206 determines whether or not there is a person with group action authority in the captured image.
[0067] If no person with group action authority is present in the captured image (No in step S503), the flow returns to step S503 (if there are still unprocessed groups remaining) or terminates (if there are no unprocessed groups remaining).
[0068] On the other hand, if there is a person with group action authority in the captured image (Yes in step S503), in step S504, the authentication / registration unit 206 determines whether the number of people with individual action authority within the group is equal to or greater than a threshold.
[0069] If the number of individuals with independent action authority within the group is not equal to or greater than the threshold (No in step S504), the flow returns to step S503 (if there are still groups remaining to process) or terminates (if there are no groups remaining to process).
[0070] On the other hand, if the number of individuals with independent action authority within the group is greater than or equal to a threshold (Yes in step S504), in step S505, the authentication and registration unit 206 determines, for example, based on the results of group estimation by the group estimation unit 205, whether the time spent by individuals with group action authority acting together with individuals with independent action authority is greater than or equal to a threshold.
[0071] If the time spent by the group is not equal to or greater than the threshold (No in step S505), the flow returns to step S503 (if there are still groups that need processing) or terminates (if there are no groups that need processing).
[0072] On the other hand, if the time spent acting as a group exceeds a threshold (Yes in step S505), in step S506, the authentication / registration unit 206 grants individual action privileges to the person with group action privileges by updating their action privileges to individual action privileges. The flow then returns to step S503 (if there are still unprocessed groups) or terminates (if there are no unprocessed groups).
[0073] The flow terminates after step S503 has been executed at least as many times as the number of groups estimated in step S501.
[0074] Although not shown in the diagram, during the process shown in Figure 5, if a registered person violates their access rights, the access rights violation determination unit 208 transmits the face of that registered person along with a signal indicating the violation to a terminal held by the security guard. Also, although not shown in the diagram, during the process shown in Figure 5, if an unregistered person is found, the authentication / registration unit 206 transmits the face of that person along with a signal indicating authentication failure to a terminal held by the security guard.
[0075] <Variation> [Settings Information] The above describes an example in which pre-configured information (person visitor information) is registered by being entered and configured by the user, but this disclosure is not limited to this example. For example, the configuration information may be registered in the facial recognition and registration system 1 by copying the corresponding information from another system (e.g., an access control system), or the person visitor information registration unit 201 may refer to the corresponding information in another system. In this way, the need for the user to register (remember) the same content in two systems can be reduced or eliminated, thereby reducing the burden on the user.
[0076] [Authority to act] The above describes an example where action permissions are broadly divided into group action permissions and individual action permissions. However, this disclosure is not limited to this example, and more detailed action permissions may be established.
[0077] The above describes an example where a person with independent action authority can accompany (act with) an unregistered person, but this disclosure is not limited to this example. For example, the authority to accompany an unregistered person may be granted in conjunction with independent action authority. In other words, it may be the case that only a person who has both independent action authority and the authority to accompany an unregistered person can accompany an unregistered person. Furthermore, there may be multiple levels of authority to accompany an unregistered person, depending on the number of unregistered people that can be accompanied. For example, there may be authority to accompany one unregistered person, authority to accompany two to five unregistered people, authority to accompany six or more unregistered people, etc. The number of unregistered people that can be accompanied may be set according to the role and trustworthiness of the person with independent action authority. For example, employees in sales or heads of organizations are likely to have more opportunities to accompany many unregistered people, so they may be permitted to accompany more unregistered people than other people. Also, a person who has had independent action authority for a long period of time is likely to be considered more trustworthy than a person who has just been granted independent action authority, so they may be permitted to accompany more unregistered people.
[0078] The above describes an example where a person with group activity privileges can only be accompanied by a person with individual activity privileges as indicated by the configuration information. In other words, even if there are multiple people with individual activity privileges, the above describes an example where a person with individual activity privileges can only be accompanied by a person with individual activity privileges who is configured to be part of the same group as the person with group activity privileges as indicated by the configuration information. In this way, the above describes a system that controls the access of a person with group activity privileges so that they are only permitted to be accompanied by an individual with individual activity privileges who invited them. In other words, it prevents fraudulent activity where a person with group activity privileges tries to expand their permitted range of activities by accompanying someone with individual activity privileges who has not invited them (for example, another employee in the office).
[0079] However, this disclosure is not limited to this example. For example, the number of individuals with unilateral authority, as indicated by the configuration information, may be one person or multiple people. Furthermore, if there are multiple individuals with unilateral authority, the actions of individuals with group authority may be restricted to those accompanied by all of them. This prevents collusion between individuals with unilateral authority and individuals with group authority to engage in fraudulent activities.
[0080] Furthermore, if a person with group action authority is accompanied by any one of the individuals with individual action authority, the system may be controlled to allow the individual with group action authority to act. This allows for the accompaniment of a person with group action authority to be passed between multiple individuals, for example, a security guard accompanying the individual from the entrance to the building, and then an employee accompanying them from the building to the room. In this case, if it is detected that a person with group action authority is not accompanied by any of the individuals with individual action authority, the system may be controlled to reduce the trustworthiness of that person.
[0081] Furthermore, for example, a person with group action authority may be allowed to accompany any person with individual action authority. In this way, the actions of a person with group action authority are permitted as long as any person with individual action authority is accompanying them. This allows for control so that even if a person with individual action authority suddenly becomes unable to respond (accompany), the actions of the person with group action authority are not restricted.
[0082] Furthermore, for example, a person with group authority may travel with any person with individual authority, but only if they are accompanied by a number of people exceeding the threshold for individual authority. This would deter individuals with individual authority from colluding with a person with group authority to improperly authorize the actions of that person.
[0083] Furthermore, for example, if a person with group action privileges is indicated by configuration information as having multiple individuals with individual action privileges who may accompany them, that person may be allowed to accompany any one or more of these individuals. In this way, a person with group action privileges is granted the authority to act as long as they are accompanied by any of the multiple individuals, so even when a response is handed over among pre-configured individuals or when one of the individuals suddenly becomes unable to respond, the actions of the person with group action privileges are not unnecessarily restricted. In this case, if it is detected that the person with group action privileges is not accompanied by any of the individuals indicated by the configuration information, the trustworthiness of the person with group action privileges may be reduced.
[0084] The above describes examples where individuals with group activity privileges and individuals with individual activity privileges can act without time restrictions, but this disclosure is not limited to these examples. For example, individuals with group activity privileges and individuals with individual activity privileges may only be able to act at specific times. For example, the authentication and registration unit 206 may grant individual activity privileges to individuals who frequently visit during the morning hours (e.g., "from 10 a.m. to 11 a.m."), allowing them to act alone only during those hours.
[0085] Although the above explanation used gateless entrances as an example, the same concept can be applied to gates that have doors to restrict the movement of people. In this case, the opening and closing of the doors can be controlled to restrict passage through the gate by individuals who violate group behavioral rights.
[0086] The above explanation uses facial recognition as an example, but the same concept can be applied to other biometric authentication methods. In the above example, a situation is assumed where multiple users constituting a group can be recognized, such as in a gateless entrance, so the use of a contactless authentication method that does not require the user to stop and operate (e.g., iris, voice, or gait recognition) is convenient. However, if multiple devices are installed to acquire biometric information, it is also possible to estimate the group from the time of operation, etc., so the above concept can also be realized using other biometric authentication methods that require the user to stop for a certain period of time or to make contact (e.g., vein or fingerprint recognition).
[0087] The above variations may be combined in any way as long as they do not contradict each other.
[0088] [Refreshing access permissions] In the above, we described an example in which the action authority is updated from group action authority to individual action authority when the conditions are met, namely when the number of individuals with individual action authority within the group is greater than or equal to a fixed number, and the time spent acting as a group is greater than or equal to a fixed time. However, this disclosure is not limited to this example, and more detailed conditions may be set. For example, the update conditions may be changed depending on the number of individuals with individual action authority within the group. For example, if there are many individuals with individual action authority within the group, the authentication / registration unit 206 may grant individual action authority in a short time. More specifically, for example, if there are 5 individuals with individual action authority within the group, the authentication / registration unit 206 may grant individual action authority to individuals with group action authority if the time spent acting as a group is 1 minute or more. If there are 10 individuals with individual action authority within the group, the authentication / registration unit 206 may grant individual action authority to individuals with group action authority if the time spent acting as a group is 10 seconds or more. In other words, the threshold (a predetermined time) mentioned above, in relation to the time spent acting as a group, may be set shorter the more individuals with individual authority to act independently who are acting together with the individual with group authority. In this way, because the individual with group authority is acting together with more individuals with individual authority who are considered trustworthy, the individual with group authority can be considered trustworthy more quickly, and as a result, their authority can be updated to individual authority more quickly, thus improving their convenience. On the other hand, if there are few individuals with individual authority to act independently acting together, the time until their authority is updated to individual authority will be longer, making it more difficult for individuals with individual authority to act independently to collude with individuals with group authority to update their authority.
[0089] The above describes an example where access privileges are updated from group access privileges to individual access privileges (updated to relax restrictions). However, this disclosure is not limited to this example, and access privileges may be updated to tighten restrictions depending on the conditions met. For example, if a person with individual access privileges enters or attempts to enter an area where entry is prohibited (a restricted area), or if a person with individual access privileges takes a predetermined action that reduces their trustworthiness, such as false authentication or impersonation, the authentication / registration unit 206 may update that person's access privileges from individual access privileges to group access privileges. In this way, security can be further ensured when a person with individual access privileges has their trustworthiness reduced, for example, by taking a predetermined action that reduces their trustworthiness. Furthermore, if trustworthiness decreases before group access privileges are updated to individual access privileges, the authentication / registration unit 206 may tighten the conditions required for updating from group access privileges to individual access privileges. Specifically, the authentication and registration unit 206 may change the threshold for the number of individuals with independent action privileges accompanying the individual, or the threshold for group action time, to a higher threshold than when the level of trust has not decreased. Furthermore, if the cumulative time spent acting with an individual with independent action privileges is used as a condition for updating from group action privileges to independent action privileges, the accumulated time count may be reset or reduced if the level of trust has decreased. Since individuals may unintentionally take actions that decrease their level of trust, the system may prevent the level from decreasing until the number of such actions exceeds a predetermined threshold, or prevent the update of privileges until the level of trust falls below a predetermined value.
[0090] The above describes an example where, without location restrictions, individuals with group action authority can only act in groups, while individuals with solitary action authority can act alone. However, this disclosure is not limited to this example. For example, the authentication / registration device 20 may manage action authority by dividing it into areas. For example, for individuals granted solitary action authority, their action authority may be switched between solitary action authority and group action authority depending on the area, such that they can act alone in some areas (e.g., an area for visitors) but only in groups in other areas (e.g., an area exclusively for employees). Also, for example, for individuals granted group action authority, their action authority may be updated from group action authority to solitary action authority if they are in an area where they have previously acted as part of a group, and then updated again from solitary action authority to group action authority if they leave that area. Thus, the action authority may be switched between solitary action authority and group action authority depending on the area. In this way, the authentication / registration unit 206 may switch between solitary action authority and group action authority for an individual depending on the area in which that individual is located. In this way, for example, the permissions of the second person are switched depending on whether the area where the person is located is a restricted area or not, or whether it is an area where the group is acting, thus making it possible to better balance security with the convenience of the second person.
[0091] Furthermore, when updating access permissions, time such as the time of arrival and the time spent in the office may be taken into consideration. For example, if a visitor with group access permissions or a first-time visitor arrives after office hours (e.g., 5 PM), regardless of the number of individuals with individual access permissions within the group and / or the time spent acting as a group, the visitor's access permissions may remain as group access permissions, without being updated to individual access permissions. Similarly, if a visitor with group access permissions or a first-time visitor arrives before 5 PM, and the number of individuals with individual access permissions within the group and / or the time spent acting as a group does not exceed a threshold before 5 PM, then regardless of the number of individuals with individual access permissions within the group and / or the time spent acting as a group after 5 PM, the visitor's access permissions may remain as group access permissions, without being updated to individual access permissions. By doing this, for example, during nighttime hours, the activity privileges of a person with group activity privileges will not be updated to individual activity privileges. This means that the person's activity privileges will be restricted during times when there are fewer people around, thus enhancing security. In these cases, instead of controlling the update of group activity privileges to individual activity privileges, it may be better to control the update to make it more difficult. Specifically, group activity privileges may be set so that they are not updated to individual activity privileges unless the person is acting in a group with more people with individual activity privileges for a longer period of time than during normal times (for example, before 5 PM).
[0092] Furthermore, for individuals whose office hours are known in advance, such as cleaning staff, their activity permissions could be set to allow them to act independently only during those hours, and in a group at other times. This ensures greater security by preventing them from being granted independent activity during times when their purpose for visiting does not require it.
[0093] Thus, the authentication and registration unit 206 may decide whether or not to update group action privileges to individual action privileges depending on the time of day, or it may switch between individual action privileges and group action privileges depending on the time of day. For example, during the time when a person is working, their action privileges are updated to individual action privileges, and during the time when the person is not working, their action privileges are updated to group action privileges, thereby better balancing security and the convenience of the person.
[0094] Furthermore, when updating access permissions, information about the individuals involved, such as their job titles, may be considered. For example, if a visitor with group access permissions or a first-time visitor is acting with a specific individual (e.g., a manager or higher, or the person in charge of the office), regardless of the number of individuals with individual access permissions within the group, the visitor's access permissions may be updated from group access permissions to individual access permissions in a shorter time (second time) than the threshold (first time) mentioned above, based on the time spent acting as a group (the first and second times are collectively referred to as "predetermined time"). In other words, the predetermined time may differ depending on whether the individual with individual access permissions who is acting with the visitor is a specific individual. In this way, because an individual with group access permissions is acting with a more specific individual who is considered more trustworthy, the individual with group access permissions can be considered trustworthy sooner, and as a result, their access permissions can be updated to individual access permissions sooner, thus improving their convenience.
[0095] Furthermore, when updating access rights, attributes such as the age of the automatically registered person may be taken into consideration. For example, if the automatically registered person is a minor, their access rights do not need to be updated from group access rights to individual access rights; they may remain as group access rights. In this way, the authentication and registration unit 206 may decide whether or not to update group access rights to individual access rights according to the attributes of the automatically registered person.
[0096] Furthermore, individuals who have been granted independent action privileges after their group action privileges have been updated (such as visitors) may be treated differently from individuals who have had independent action privileges from the beginning (such as full-time employees). For example, individuals who have been granted independent action privileges after their group action privileges have been updated may have their independent action privileges updated back to group action privileges depending on the number of times they have taken actions that reduce their trustworthiness, while individuals who have had independent action privileges from the beginning may not have their privileges updated. In addition, the conditions for permitting the actions of individuals with group action privileges, or for updating group action privileges to independent action privileges, may require them to be accompanied not only by individuals who have been granted independent action privileges after their group action privileges have been updated, but also by individuals who have had independent action privileges from the beginning. In this way, the scope of individuals with independent action privileges can be limited to the scope that individuals who have had independent action privileges from the beginning can recognize. This prevents individuals with independent action privileges from spreading to areas that are not known to full-time employees, etc.
[0097] Although the above explanation used an office as an example, the above ideas can be applied to other facilities. For example, they could be applied to schools, banks, etc.
[0098] The above modifications can be combined in any way as long as they do not contradict each other. Furthermore, a judgment block for determining the conditions related to the above modifications may be appropriately incorporated into the loop processing shown in Figure 5.
[0099] As described above, embodiments of this disclosure have been described in detail with reference to the drawings, but the functions of the authentication and registration device 20 described above may be implemented by a computer program.
[0100] Figure 6 shows the hardware configuration of the computer 1000 that implements the functions of the authentication and registration device 20 through a program. This computer 1000 includes input devices 1001 such as a keyboard, mouse, and touchpad; output devices 1002 such as a display and speakers; a CPU (Central Processing Unit) 1003; a GPU (Graphics Processing Unit) 1004; a ROM (Read Only Memory) 1005; a RAM (Random Access Memory) 1006; a storage device 1007 such as a hard disk drive and an SSD (Solid State Drive); a reader 1008 that reads information from recording media such as a DVD-ROM (Digital Versatile Disk Read Only Memory) and a USB (Universal Serial Bus) memory; and a transceiver 1009 that communicates via a network. These devices 1001 to 1009 are connected by a bus 1010.
[0101] The reader 1008 then reads the program for realizing the functions of the authentication / registration device 20 from the recording medium containing the program and stores it in the storage device 1007. Alternatively, the transceiver 1009 communicates with a server device connected to the network and stores the program for realizing the functions of the authentication / registration device 20 downloaded from the server device in the storage device 1007.
[0102] Then, the CPU 1003 copies the program stored in the memory device 1007 to the RAM 1006, and sequentially reads and executes the instructions contained in that program from the RAM 1006, thereby realizing the functions of the authentication and registration device 20.
[0103] <Effects of the Embodiment> The group estimation unit 205 of the authentication and registration device 20 estimates whether the first person and the second person are acting together based on the captured image taken by the camera 10. If the first biometric information (face, iris, etc.) and independent action authority for the first person (registered person) for authentication are registered, and the second biometric information (face, iris, etc.) for the second person (unregistered person) for authentication are not registered, the authentication and registration unit 206 of the authentication and registration device 20 registers the second biometric information and group action authority included in the captured image for the unregistered person acting together with the registered person, based on the estimation result by the group estimation unit 205, and updates the group action authority to independent action authority if predetermined conditions are met.
[0104] With the above configuration, the biometric information of unregistered individuals acting together with (belonging to the same group as) already registered individuals is registered along with group action privileges that are more restricted than the individual action privileges of the already registered individuals, and that allow them to perform certain actions on the condition that they act together with a person who has registered individual action privileges. Furthermore, when the specified conditions are met, the group action privileges are updated to individual action privileges so that the restrictions are eased. Thus, it is possible to achieve both security and convenience for authenticated individuals.
[0105] (Summary of the embodiments) A registration device (authentication / registration device 20) according to one embodiment of the present disclosure includes: an estimation unit (group estimation unit 205) that estimates whether a first person and a second person are acting together based on an image (captured image) captured by a camera (camera 10); and a registration unit (authentication / registration unit 206) that, if the first person (already registered) has registered first biometric information (face, iris, etc.) and first authority (independent action authority) for authentication, and the second person (unregistered) has not registered second biometric information (face, iris, etc.) for authentication, based on the estimation result, registers the second biometric information included in the image and a second authority (group action authority) that allows the second person acting together with the first person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered, and updates the second authority to the first authority when the predetermined conditions are met.
[0106] With the above configuration, a second person acting together with a first person who has registered first biometric information and first authority for authentication is registered, and a second authority that allows the second person to perform a predetermined action on the condition that they act together with the person who has registered first authority. Furthermore, for the second person, the second authority is updated to the first authority when the predetermined conditions are met. In this way, the biometric information of an unregistered second person acting together with a registered first person is registered along with a second authority that allows them to perform a predetermined action on the condition that they act together with a person such as the first person who is considered trustworthy, and the second authority is updated to the first authority in a way that eases restrictions when the predetermined conditions are met, thus achieving a balance between security and convenience for the second person.
[0107] In this registration device, the second authority is the authority to perform a predetermined action on the condition that the first person acts together with the second person, as recorded in the prior configuration information as having plans to act together with the second person.
[0108] With the above configuration, in order to grant the second authority, it is necessary to record in the prior configuration information that the second person and the first person will act together. This ensures that the second person is a trustworthy individual to a certain extent, thereby further enhancing security.
[0109] In this registration device, the pre-configuration information records multiple first persons who are scheduled to act together with the second person, and the second authority is the authority to perform a predetermined action on the condition that the first person acts together with all of the first persons who are scheduled to act together with the second person as recorded in the configuration information.
[0110] The above configuration prevents either of the first persons with the first authority and the second person with the second authority from colluding to carry out illegal activities.
[0111] In this registration device, the predetermined conditions include the second person acting together with the person to whom the first authority is registered for a predetermined period of time or longer.
[0112] With the above configuration, since the second person is acting with a person considered trustworthy for a predetermined amount of time or longer, the second person can be considered trustworthy, and as a result, the second person's authority is updated to independent action authority, thereby improving the second person's convenience.
[0113] In this registration device, the predetermined conditions include the second person acting together with the first person, for a predetermined amount of time or longer, as recorded in the prior setting information, which indicates that the second person is scheduled to act together with the first person.
[0114] With the above configuration, in order to grant the second authority, it is necessary that the prior configuration information records that the second person and the first person will act together. Since the second person has been acting with a person considered trustworthy for a specified period of time or longer, the second person can be considered more trustworthy, and as a result, the second person's authority is updated to independent action authority, thereby improving the convenience of the second person.
[0115] In this registration device, the predetermined time is set to be shorter the more people the second person acts with and who have the first authority registered.
[0116] With the above configuration, the second person can be considered trustworthy more quickly because they are acting together with more people who are considered trustworthy. This allows the second person's authority to be updated to independent authority more quickly, thus improving the second person's convenience.
[0117] In this registration device, the predetermined time varies depending on whether the person who acts together with the second person and whose first authority is registered is a specific person.
[0118] With the above configuration, if the second person is acting together with a more specific person who is considered more trustworthy, for example, the second person can be considered trustworthy more quickly, and thereby the second person's authority can be updated to independent authority more quickly, thus improving the second person's convenience.
[0119] In this registration device, the predetermined condition is that if the number of people with registered first privileges who act together with the second person is less than the predetermined number, the second person's second privilege will not be updated to the first privilege, regardless of the amount of time the second person and the people with registered first privileges act together.
[0120] With the above configuration, if the second person is acting with fewer than a specified number of people considered trustworthy, the second person will not be considered trustworthy, thus providing greater security.
[0121] In this registration device, the predetermined condition is that even if the time spent by the second person acting together with the person whose second authority has been updated to the first authority exceeds the predetermined time, the second person's second authority will not be updated to the first authority.
[0122] With the above configuration, the scope of the person with the first authority can be limited from the outset to the scope that the person with the first authority can perceive. Therefore, it is possible to prevent the person with the first authority from expanding beyond the necessary scope.
[0123] In this registration device, the registration unit updates the first authority to the second authority when the second person whose authority has been updated takes a predetermined action.
[0124] With the above configuration, security can be further ensured if the trustworthiness of the second person decreases, for example, by taking a predetermined action that reduces trustworthiness.
[0125] In this registration device, if the second person takes a predetermined action before the first authority is updated, the conditions for updating the second person's second authority to the first authority are made stricter than when the second person does not take the predetermined action.
[0126] With the above configuration, if the second person's trustworthiness decreases, for example, by taking certain actions that reduce trustworthiness, the conditions for updating the second person's authority to the first person's authority become stricter, thus ensuring greater security.
[0127] In this registration device, the registration unit switches between the first and second privileges for the second person depending on the area where the second person is located.
[0128] With the above configuration, for example, the second person's permissions will switch depending on whether the area where the second person is located is a restricted area or not, thus better balancing security and the convenience of the second person.
[0129] In this registration device, the registration unit determines whether or not to update the second authority to the first authority depending on the time period.
[0130] With the above configuration, for example, during nighttime hours, the privileges of the second person are not updated to those of the first person. The second person's privileges remain restricted during off-peak hours, thus enhancing security.
[0131] In this registration device, the registration unit switches between the first and second privileges for the second person depending on the time of day.
[0132] With the above configuration, for example, the permissions of the second person will switch depending on the time of day they are working, thus better balancing security with the convenience of the second person.
[0133] A registration method according to one embodiment of the present disclosure estimates whether a first person and a second person are acting together based on an image (captured image) captured by a camera (camera 10). If the first person (already registered) has registered first biometric information (face, iris, etc.) and first authority (independent action authority) for authentication, and the second person (unregistered) has not registered second biometric information (face, iris, etc.) for authentication, then, based on the estimation result, the second person acting together with the first person is registered with the second biometric information included in the image and a second authority (group action authority) that allows the second person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered. The second authority is then updated to the first authority when the predetermined conditions are met.
[0134] With the above configuration, a second person acting together with a first person who has registered first biometric information and first authority for authentication is registered, and a second authority that allows the second person to perform a predetermined action on the condition that they act together with the person who has registered first authority. Furthermore, for the second person, the second authority is updated to the first authority when the predetermined conditions are met. In this way, the biometric information of an unregistered second person acting together with a registered first person is registered along with a second authority that allows them to perform a predetermined action on the condition that they act together with a person such as the first person who is considered trustworthy, and the second authority is updated to the first authority in a way that eases restrictions when the predetermined conditions are met, thus achieving a balance between security and convenience for the second person.
[0135] A program according to one embodiment of the present disclosure causes a computer (authentication / registration device 20, computer 1000) to estimate whether a first person and a second person are acting together based on an image (captured image) taken by a camera (camera 10). If the first person (registered person) has registered first biometric information (face, iris, etc.) and first authority (independent action authority) for authentication, and the second person (unregistered person) does not have registered second biometric information (face, iris, etc.) for authentication, the program, based on the estimation result, registers the second biometric information included in the image and a second authority (group action authority) that allows the second person acting together with the first person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered, and then updates the second authority to the first authority when the predetermined conditions are met.
[0136] With the above configuration, a second person acting together with a first person who has registered first biometric information and first authority for authentication is registered, and a second authority that allows the second person to perform a predetermined action on the condition that they act together with the person who has registered first authority. Furthermore, for the second person, the second authority is updated to the first authority when the predetermined conditions are met. In this way, the biometric information of an unregistered second person acting together with a registered first person is registered along with a second authority that allows them to perform a predetermined action on the condition that they act together with a person such as the first person who is considered trustworthy, and the second authority is updated to the first authority in a way that eases restrictions when the predetermined conditions are met, thus achieving a balance between security and convenience for the second person.
[0137] In the above-described embodiment, the notation "...part" used for each component may be replaced with other notations such as "...circuitry", "...assembly", "...device", "...unit", or "...module".
[0138] While embodiments have been described above with reference to the drawings, this disclosure is not limited to such examples. It will be apparent to those skilled in the art that various modifications or alterations can be conceived within the scope of the claims. Such modifications or alterations are also understood to fall within the technical scope of this disclosure. Furthermore, the components in the embodiments may be combined in any way without departing from the spirit of this disclosure.
[0139] This disclosure can be implemented in software, hardware, or software in conjunction with hardware. Each functional block used in the description of the above embodiments may be implemented in part or in whole as an integrated circuit (LSI), and each process described in the above embodiments may be controlled in part or in whole by a single LSI or a combination of LSIs. An LSI may consist of individual chips, or it may consist of a single chip that includes some or all of the functional blocks. An LSI may have data inputs and outputs. Depending on the degree of integration, LSIs may be referred to as ICs, system LSIs, super LSIs, or ultra LSIs.
[0140] The method of integration is not limited to LSIs; it may also be implemented using dedicated circuits, general-purpose processors, or dedicated processors. Furthermore, FPGAs (Field Programmable Gate Arrays) that can be programmed after LSI manufacturing, or reconfigurable processors that allow for the reconfiguration of the connections and settings of circuit cells within the LSI, may also be used. This disclosure may be implemented as digital or analog processing.
[0141] Furthermore, if advancements in semiconductor technology or related technologies lead to the emergence of integrated circuit technologies that replace LSIs, then naturally, these technologies can be used to integrate functional blocks. The application of biotechnology, for example, is a possible possibility.
[0142] This disclosure is applicable to all types of devices, systems, and equipment with communication capabilities (collectively referred to as communication equipment). Non-exclusive examples of communication equipment include telephones (mobile phones, smartphones, etc.), tablets, personal computers (PCs) (laptops, desktops, notebooks, etc.), cameras (digital still / video cameras, etc.), digital players (digital audio / video players, etc.), wearable devices (wearable cameras, smartwatches, tracking devices, etc.), game consoles, digital book readers, telehealth / telemedicine devices, vehicles or mobile transport with communication capabilities (automobiles, airplanes, ships, etc.), and combinations of the above-mentioned equipment.
[0143] Communication devices are not limited to portable or movable devices, but also include all kinds of non-portable or fixed devices, devices, and systems, such as smart home devices (appliances, lighting equipment, smart meters or measuring instruments, control panels, etc.), vending machines, and any other "things" that may exist on an IoT (Internet of Things) network.
[0144] Communication includes data communication via cellular systems, wireless LAN systems, and communication satellite systems, as well as data communication using combinations of these.
[0145] Furthermore, the communication device also includes devices such as controllers and sensors that are connected to or linked to a communication device that performs the communication functions described in this disclosure. For example, this includes controllers and sensors that generate control signals and data signals used by the communication device that performs the communication functions of the communication device.
[0146] Furthermore, communication equipment includes infrastructure facilities such as base stations, access points, and any other devices, devices, and systems that communicate with or control the aforementioned non-limited types of equipment. [Industrial applicability]
[0147] This disclosure is useful for technologies that register faces for use in facial recognition. [Explanation of Symbols]
[0148] 1. Facial Recognition and Registration System 10 Cameras 20 Authentication and Registration Devices 30 Networks 201 Person Visitor Information Registration Department 202 Person Visitor Information Storage Unit 203 Image receiving unit 204 Image storage unit 205 Group Estimation Department 206 Authentication and Registration Department 207 Registered User Information Storage Unit 208 Action Authority Violation Determination Unit
Claims
1. An estimation unit that estimates whether the first person and the second person are acting together based on images captured by the camera, If the first biometric information and first authority for authentication of the first person are registered, and the second biometric information for authentication of the second person are not registered, a registration unit registers the second biometric information included in the image and a second authority that allows the second person acting together with the first person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered, based on the result of the estimation, and updates the second authority to the first authority when the predetermined conditions are met. Equipped with, The second authority is the authority to perform a predetermined action on the condition that the first person acts together with the second person, as recorded in the prior configuration information as being scheduled to act together with the second person. Registration device.
2. The aforementioned pre-configuration information includes records of multiple first persons who are scheduled to act together with the second person. The second authority is the authority to perform a predetermined action on the condition that the first person acts together with all of the first person who is recorded in the configuration information as having plans to act together with the second person. The registration device according to claim 1.
3. The aforementioned predetermined conditions include the second person acting together with the person to whom the first authority is registered for a predetermined period of time or longer. The registration device according to claim 1.
4. The aforementioned predetermined conditions include the second person acting together with the first person, for a predetermined amount of time or longer, as recorded in the pre-configured information, where it is stated that the second person is scheduled to act together with the first person. The registration device according to claim 3.
5. The predetermined time is set to be shorter the more people the second person acts with and the number of people who have the first authority registered is greater. The registration device according to claim 3.
6. The predetermined time varies depending on whether the person who acts together with the second person and who is registered with the first authority is a specific person. The registration device according to claim 3.
7. The aforementioned predetermined condition is that, if the number of persons with registered first authority who act together with the second person is less than a predetermined number, the second authority of the second person will not be updated to the first authority, regardless of the amount of time the second person and the persons with registered first authority act together. The registration device according to claim 3.
8. The aforementioned predetermined condition is that even if the time spent by the second person acting together with the person whose second authority has been updated to the first authority exceeds the aforementioned predetermined time, the second person's second authority will not be updated to the first authority. The registration device according to claim 3.
9. The registration unit updates the first authority to the second authority when the second person whose authority has been updated takes a predetermined action. The registration device according to claim 1.
10. The registration unit, if the second person takes a predetermined action before the second person's authority is updated to the first authority, makes the conditions for updating the second person's second authority to the first authority stricter than if the second person did not take the predetermined action. The registration device according to claim 1.
11. The registration unit switches between the first and second privileges for the second person depending on the area where the second person is located. The registration device according to claim 1.
12. The registration unit determines whether or not to update the second authority to the first authority depending on the time period. The registration device according to claim 1.
13. The registration unit switches between the first and second privileges for the second person depending on the time of day. The registration device according to claim 1.
14. The registration device is Based on the images captured by the camera, it is estimated whether the first person and the second person are acting together. If the first biometric information and first authority for authentication of the first person are registered, and the second biometric information for authentication of the second person are not registered, then, based on the estimation result, the second biometric information included in the image and the second authority that allows the second person acting together with the first person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered are registered. Depending on whether the specified conditions are met, the second authority is renewed to the first authority. The second authority is the authority to perform a predetermined action on the condition that the first person acts together with the second person, as recorded in the prior configuration information as being scheduled to act together with the second person. How to register.
15. On the computer, Based on the images captured by the camera, it is estimated whether the first person and the second person are acting together. If the first biometric information and first authority for authentication of the first person are registered, and the second biometric information for authentication of the second person are not registered, then, based on the estimation result, the second biometric information included in the image and the second authority that allows the second person acting together with the first person to perform a predetermined action on the condition that they act together with the person for whom the first authority is registered are registered. Depending on whether the specified conditions are met, the second authority is renewed to the first authority. The second authority is the authority to perform a predetermined action on the condition that the first person acts together with the second person, as recorded in the prior configuration information as being scheduled to act together with the second person. A program that executes a procedure.
Citation Information
Patent Citations
Security device
JP2006188853A
Entry management device
JP2010026733A
Authentication program, authentication device and authentication method
JP2013114304A
Information processing apparatus, information processing method, and information processing program
JP2019003339A
Device for personal authentication registration, method for personal authentication registration, and program for personal authentication registration
WO2009101671A1