Authentication system

JP7919650B2Active Publication Date: 2026-09-14ミガロホールディングス株式会社 +1
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2025119053
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2026-09-14
Estimated Expiration
2040-02-18

AI Technical Summary

Benefits of technology

【0009】 本発明の認証システムによれば、複数の顔認証エンジンを用いた顔認証プラットフォームの利便性を向上させることができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007919650000001
    Figure 0007919650000001
  • Figure 0007919650000002
    Figure 0007919650000002
  • Figure 0007919650000003
    Figure 0007919650000003
Patent Text Reader

Abstract

To improve convenience of a face authentication platform using a plurality of face authentication engines.SOLUTION: An authentication system comprises: first photographing means that acquires and transmits face image data of a user for extracting a feature quantity used as a comparison reference; a plurality of face authentication devices that collate the face of the user with the comparison reference and determine whether a service requested from the user can be provided; and service registration means that registers a service used by the user from among services provided by using the face authentication devices. The first photographing means and the service registration means are provided by using a user terminal that is an information terminal carried by the user. The face authentication devices each have feature quantity extraction means that extracts the feature quantity from the face image data of the user, and a storage unit in which the feature quantity used as the comparison reference is registered.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system.

Background Art

[0002] Conventionally, as a face authentication system that performs authentication based on face data, a face authentication system that performs personal authentication by collating input face data with pre-registered registered face data is known (see, for example, Patent Documents 1 and 2).

[0003] In the face authentication system described in Patent Document 1, a target person is authenticated using an image of a face portion in a captured image captured by a camera. Further, in the face authentication system described in Patent Document 2, for example, when four face images are registered, two are used as face patterns for accuracy assurance, one is used as a face pattern for disturbance component absorption, and one is used as a face pattern for update target. Then, when newly registering a face pattern, among the four pre-registered face patterns, the update target face pattern having the second lowest similarity to the newly registered face pattern is deleted. That is, by leaving the face pattern for absorbing disturbance components which has the lowest similarity to the newly registered face pattern, face authentication is performed while adapting to environmental variations.

Prior Art Literature

Patent Literature

[0004]

Patent Literature 1

Patent Literature 2

Summary of Invention

Problem to be Solved by the Invention

[0005] While the use of facial recognition-based authentication engines is becoming widespread, the facial recognition systems described in Patent Documents 1 and 2 cannot perform facial recognition with an authentication engine that has not registered facial data. Therefore, in order to perform authentication with multiple authentication engines, users have to register their facial data with each of them, which is time-consuming and stressful.

[0006] This invention has been made with these points in mind, and aims to improve the convenience of a facial recognition platform that uses multiple facial recognition engines. [Means for solving the problem]

[0007] The present invention provides an authentication system comprising: a first shooting means for acquiring and transmitting user face image data for extracting feature quantities to be used as comparison criteria; a plurality of face recognition devices for comparing the user's face with the comparison criteria and determining whether or not to provide the service requested by the user; and a service registration means for registering the service to be used by the user from among the services provided using each of the face recognition devices. The first shooting means and the service registration means are provided using a user terminal, which is an information terminal owned by the user. Each of the face recognition devices includes a feature quantity extraction means for extracting feature quantities from the user's face image data and a storage device in which the feature quantities used as comparison criteria are registered.

[0008] Furthermore, the present invention provides an authentication system comprising: a first imaging means for acquiring and transmitting user face image data for extracting feature quantities to be used as comparison criteria; and a plurality of face authentication devices for comparing the user's face with the comparison criteria and determining whether or not the service requested by the user can be provided. Each of the face authentication devices comprises a feature extraction means for extracting feature quantities from the user's face image data and a storage device for registering the feature quantities used as comparison criteria. The gist of the invention is that the services include those that can be provided solely by user face authentication and those that require authentication by methods other than biometric authentication in addition to user face authentication. [Effects of the Invention]

[0009] According to the authentication system of the present invention, the convenience of a facial recognition platform using multiple facial recognition engines can be improved. [Brief explanation of the drawing]

[0010] [Figure 1] This figure schematically shows an example of a facial recognition system and an authentication engine to be deployed in each service provider according to an embodiment of the present invention. [Figure 2] Figure 1 is a flowchart showing the processes performed when registering a user's facial image using the facial recognition system. [Figure 3] Figure 1 is a flowchart illustrating an example of the processes performed when authenticating a user using the authentication engine and facial recognition system shown. [Figure 4] This figure schematically illustrates another example of a facial recognition system and an authentication engine deployed in each service provider according to an embodiment of the present invention. [Figure 5] Figure 4 is a flowchart showing the processes performed when registering a user's facial image using the facial recognition system. [Figure 6] Figure 4 is a flowchart illustrating an example of the processes performed when authenticating a user using the authentication engine and facial recognition system shown. [Figure 7] This figure schematically illustrates yet another example of a facial recognition system and an authentication engine deployed in each service provider according to an embodiment of the present invention. [Figure 8] Figure 7 is a flowchart showing the processes performed when registering a user's facial image using the facial recognition system. [Figure 9] Figure 7 is a flowchart illustrating an example of the processes performed when authenticating a user using the authentication engine and facial recognition system shown. [Figure 10] This diagram shows the initial screen displayed on the user's terminal. [Figure 11]Figure showing a registration screen displayed on a user terminal. [Figure 12] Figure showing a registration screen displayed on a user terminal. [Figure 13] Figure showing a service addition screen displayed on a user terminal. [Figure 14] Figure showing an authentication history screen displayed on a user terminal. [Figure 15] Figure showing a detailed screen of authentication history displayed on a user terminal. [Figure 16] Figure schematically showing still another example of a face authentication system according to an embodiment of the present invention and an authentication engine arranged at each company. [Mode for Carrying Out the Invention]

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIGS. 1 to 15 are diagrams showing a face authentication system according to the present embodiment and an authentication engine arranged at each service organization.

[0012] As shown in FIG. 1, authentication engines 30A, 30B, and 30C that authenticate users are arranged at each service organization such as restaurants, hotels, transportation facilities, office buildings, residential complex facilities, and convenience stores. Although three authentication engines 30A, 30B, and 30C are illustrated in FIG. 1, two or four or more authentication engines may be used. Further, a face authentication system 10 installed in a company different from each service organization is communicatively connected to each of the authentication engines 30A, 30B, and 30C via a network such as the Internet. In addition, a user terminal 20 such as a smartphone owned by a user is communicatively connected to the face authentication system 10 and each of the authentication engines 30A, 30B, and 30C via a network such as the Internet. Hereinafter, details of the face authentication system 10 and each of the authentication engines 30A, 30B, and 30C will be described.

[0013] The facial recognition system 10 is composed of, for example, a computer, and includes a processor 12 such as a CPU, a memory 16, and a communication unit 18. The processor 12 includes a feature extraction means 14 that extracts the feature quantities of the user's facial image corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​based on facial image data received from the user terminal 20, and a registration means 13 that registers the extracted feature quantities of the user's facial image. The processor 12 executes a program stored in the memory 16, causing the feature extraction means 14 to extract the feature quantities of the user's facial image corresponding to each authentication engine 30A, 30B, and 30C as hash values. Specifically, the feature extraction means 14 extracts the hash value obtained from the received user's facial image data using a predetermined hash function as the feature quantity of the user's facial image. Note that even if the user's facial image data is the same, the feature quantities of the user's facial image may differ depending on the type of authentication engine 30A, 30B, and 30C. This is because the specifications of the authentication engines 30A, 30B, and 30C used by different service providers differ depending on the service provider. Therefore, the feature extraction means 14 extracts feature quantities from the user's face image for each authentication engine 30A, 30B, and 30C. In other words, from a single face image data, feature quantities from the face images of multiple users corresponding to each authentication engine 30A, 30B, and 30C are extracted. Furthermore, the processor 12 executes a program stored in memory 16 to store the feature quantities (specifically, hash values) of the user's face image for each authentication engine 30A, 30B, and 30C extracted by the feature extraction means 14 in memory 16, associated with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C, via the registration means 13. Note that the program executed by the processor 12 is not limited to those stored in memory 16. The processor 12 may execute a program transmitted to the facial recognition system 10 from an external device, or a program stored on a recording medium detachably attached to the facial recognition system 10, thereby performing processing in the feature extraction means 14 and the registration means 13, respectively.

[0014] As described above, the feature amounts (specifically, hash values) of the user's face image extracted by the feature amount extracting means 14 are stored in the memory 16 in association with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C. As described above, the feature amount of the user's face image extracted by the feature amount extracting means 14 may vary depending on the types of the authentication engines 30A, 30B, and 30C. Therefore, the feature amount extracting means 14 extracts the feature amount of the user's face image for each of the authentication engines 30A, 30B, and 30C. Accordingly, the feature amount of the user's face image extracted by the feature amount extracting means 14 also needs to be stored in the memory 16 in association with each of the authentication engines 30A, 30B, and 30C. In addition, the user's identification information and the service organization selected by the user are stored in the memory 16 in association with each other. Furthermore, as described above, the memory 16 stores programs for causing the processor 12 to perform various processes. The processor 12 transmits and receives signals to and from the authentication engines 30A, 30B, and 30C disposed at each service organization or the user terminal 20 via a network such as the Internet through the communication unit 18.

[0015] Each of the authentication engines 30A, 30B, and 30C deployed at each service organization is composed of, for example, a computer, and each authentication engine 30A, 30B, and 30C has a processor 32A, 32B, and 32C such as a CPU, memory 36A, 36B, and 36C, imaging units 38A, 38B, and 38C, processing units 40A, 40B, and 40C, and communication units 42A, 42B, and 42C. The processors 32A, 32B, and 32C have feature extraction means 34A, 34B, and 34C that extract feature quantities of the user's face image as hash values ​​based on the user's face image data captured by the imaging units 38A, 38B, and 38C, and authentication means 35A, 35B, and 35C. Processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C, causing feature extraction means 34A, 34B, and 34C to extract feature quantities of the user's face image as hash values. Specifically, feature extraction means 34A, 34B, and 34C extract hash values ​​obtained from the received user face image data using a predetermined hash function as feature quantities of the user's face image. Furthermore, processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C, causing authentication means 35A, 35B, and 35C to authenticate the user. Details of these processes will be described later. Note that the programs executed by processors 32A, 32B, and 32C are not limited to those stored in memories 36A, 36B, and 36C. The processors 32A, 32B, and 32C execute programs transmitted from an external device to the authentication engines 30A, 30B, and 30C, or programs stored on recording media detachably attached to the authentication engines 30A, 30B, and 30C, thereby performing various processes in the feature extraction means 34A, 34B, and 34C and the authentication means 35A, 35B, and 35C, respectively. Furthermore, each of the authentication engines 30A, 30B, and 30C is not limited to corresponding to a single service organization. For example, the authentication engine 30A may correspond to multiple service organizations.

[0016] Furthermore, memories 36A, 36B, and 36C store pre-registered user identification information and associated feature quantities of the user's facial image. Also, as mentioned above, memories 36A, 36B, and 36C store programs for causing processors 32A, 32B, and 32C to perform various processes. In addition, imaging units 38A, 38B, and 38C have, for example, cameras and acquire facial image data of the user by capturing images of the user.

[0017] Furthermore, processing units 40A, 40B, and 40C perform various processes for authenticated users. For example, if the authentication engines 30A, 30B, and 30C are located in office buildings or apartment complexes, the processing units 40A, 40B, and 40C will unlock doors located at entrances to these office buildings or apartment complexes once a user has been authenticated. Also, if the authentication engines 30A, 30B, and 30C are located in restaurants, hotels, transportation facilities, convenience stores, etc., they enable cashless payment when users pay for services at these service providers. In this case, payment information is transmitted from the authentication engines 30A, 30B, and 30C to the servers of financial institutions or credit card companies, so that the payment amount is automatically debited from the user's bank account or added to their credit card statement. In addition, the processors 32A, 32B, and 32C transmit and receive signals with the facial recognition system 10 or user terminal 20 via a network such as the internet using the communication units 42A, 42B, and 42C.

[0018] Furthermore, in each authentication engine 30A, 30B, and 30C, the user's face image is captured by the imaging unit 38A, 38B, and 38C, allowing the feature quantities of this user's face image to be registered in each authentication engine 30A, 30B, and 30C. Specifically, when registering the feature quantities of a user's face image in each authentication engine 30A, 30B, and 30C, once the user's face image is captured by the imaging unit 38A, 38B, and 38C, the processors 32A, 32B, and 32C extract the feature quantities of the user's face image as hash values ​​using the feature quantity extraction means 34A, 34B, and 34C based on the user's face image data captured by the imaging unit 38A, 38B, and 38C. These extracted feature quantities of the user's face image (specifically, hash values) are then stored in the memory 36A, 36B, and 36C. In this way, the feature quantities of the user's face image are registered in each authentication engine 30A, 30B, and 30C.

[0019] The user terminal 20 can install a facial recognition application via an online store or similar means. Once such a facial recognition application is installed, the user can register facial image data, register service providers using the service, etc., via the user terminal 20. The processing details of such a facial recognition application will be described later. Note that such a facial recognition application may be provided by the facial recognition system 10, or it may be provided by a system separate from the facial recognition system 10.

[0020] In this embodiment, the facial recognition system 10 and the authentication engines 30A, 30B, and 30C deployed in each service organization are connected via API (Application Programming Interface). This makes it easier to configure the systems of each authentication engine 30A, 30B, and 30C compared to configuring each system independently.

[0021] Next, the processing details for user authentication performed by the facial recognition system 10 and each authentication engine 30A, 30B, and 30C will be explained using Figures 2, 3, and 10 to 12.

[0022] First, we will explain the process by which a user registers facial image data with the facial recognition system 10 using the user terminal 20. Initially, the user installs a facial recognition application on the user terminal 20. The initial screen of such a facial recognition application displays the screen shown in Figure 10. The user then registers as a user using this facial recognition application on the user terminal 20. Specifically, pressing the account button on the screen shown in Figure 10 brings up the user registration screen shown in Figure 11. On this user registration screen, the user enters registration information such as name, date of birth, phone number, email address, and password, checks the box to agree to the terms of service, and then presses the register button, which brings up the facial image capture screen shown in Figure 12. When the user captures a facial image with the user terminal 20 on this capture screen, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the facial recognition system 10. In this way, the processor 12 of the facial recognition system 10 receives the facial image data from the user terminal 20 (STEP 1). Furthermore, the processor 12 of the facial recognition system 10 receives identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered into the user terminal 20. The processor 12 also issues a user ID as user identification information and stores this issued user ID in the memory 16.

[0023] Next, the processor 12 of the facial recognition system 10 extracts the facial image features corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​using the feature extraction means 14, based on the facial image data received from the user terminal 20 (STEP 2). At this time, the facial image features of the user extracted by the feature extraction means 14 may differ depending on the type of authentication engine 30A, 30B, and 30C. For this reason, the feature extraction means 14 extracts the facial image features of the user for each authentication engine 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the facial image features of the user corresponding to the authentication engine 30A, 30B, and 30C of the service organization that has been pre-selected by the user. For example, if a user has permitted the use of facial image data for a service organization where authentication engine 30A is installed, but has not permitted the use of facial image data for a service organization where authentication engine 30B is installed, the feature extraction means 14 extracts only the facial image features of the user corresponding to authentication engine 30A. As described above, the memory 16 stores the user's identification information and the service provider selected by the user in association. The processor 12 then uses the registration means 13 to store the facial image features corresponding to each authentication engine 30A, 30B, and 30C, extracted by the feature extraction means 14, in the memory 16 of the facial recognition system 10, associating them with the user ID (user's identification information) and the identification information of the authentication engines 30A, 30B, and 30C (STEP 3). In this way, the registration of the user's facial image captured by the user terminal 20 is completed. The information regarding the user's facial image features stored in the memory 16 is then transmitted from the facial recognition system 10 to the authentication engines 30A, 30B, and 30C of the service provider selected by the user (STEP 4). At this time, the user's facial image features corresponding to each authentication engine 30A, 30B, and 30C are transmitted to the authentication engines 30A, 30B, and 30C. The authentication engines 30A, 30B, and 30C store information related to the feature quantities of the user's facial image transmitted from the facial recognition system 10 in the memories 36A, 36B, and 36C, associating it with the user's identification information.

[0024] Next, the process of user authentication in each authentication engine 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each authentication engine 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C to image the user (STEP 11). In addition, in the authentication engines 30A, 30B, and 30C, the processors 32A, 32B, and 32C extract the features of the user's face image as hash values ​​using feature extraction means 34A, 34B, and 34C based on the acquired face image data (STEP 12). Then, processors 32A, 32B, and 32C authenticate the user by comparing the feature quantities (specifically, hash values) of the user's face image extracted by feature extraction means 34A, 34B, and 34C with the feature quantities (specifically, hash values) of the user's face image stored in memory 36A, 36B, and 36C (STEP 13). More specifically, if the matching rate between the feature quantities of the user's face image extracted by feature extraction means 34A, 34B, and 34C and the feature quantities of the user's face image stored in memory 36A, 36B, and 36C exceeds a predetermined threshold (for example, 80%), authentication means 35A, 35B, and 35C authenticate the user. As mentioned above, memory 36A, 36B, and 36C stores pre-registered user identification information and the feature quantities of this user's face image in association with each other.

[0025] Then, once the user is authenticated by the authentication means 35A, 35B, and 35C ("YES" in STEP 14), the processors 32A, 32B, and 32C enable the processing units 40A, 40B, and 40C to implement the services corresponding to the authentication engines 30A, 30B, and 30C (STEP 15). Specifically, as described above, if the authentication engines 30A, 30B, and 30C are located in office buildings or apartment complexes, the processing units 40A, 40B, and 40C will unlock the doors located at the entrances and exits of these office buildings and apartment complexes once the user has been authenticated. Furthermore, if the authentication engines 30A, 30B, and 30C are located in restaurants, hotels, transportation facilities, convenience stores, etc., they will enable cashless payment when making payments at these service providers. In addition, two-factor authentication may be implemented when cashless payment is made. Subsequently, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information regarding the service usage status to the facial recognition system 10 (STEP 17). As a result, the facial recognition system 10 stores information regarding the service usage status at each service provider in memory 16 for each user.

[0026] On the other hand, if the feature quantities of the user's face image extracted by the feature quantity extraction means 34A, 34B, and 34C do not substantially match the feature quantities of the user's face image stored in the memories 36A, 36B, and 36C, and the authentication means 35A, 35B, and 35C are unable to authenticate the user ("NO" in STEP 14), the processors 32A, 32B, and 32C will disable the service corresponding to this authentication engine 30A, 30B, and 30C through their respective processing units 40A, 40B, and 40C (STEP 16). In this case as well, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C will transmit information regarding the service usage status (specifically, information that the user attempted to authenticate with the authentication engines 30A, 30B, and 30C but was not authenticated and therefore could not use the service) to the face recognition system 10 (STEP 17).

[0027] With this authentication method, even if a user's facial image features are registered in the authentication engine of one service provider (e.g., authentication engine 30A) but not in the authentication engine of another service provider (e.g., authentication engine 30B), the facial recognition system 10's memory 16 and the memories 36A, 36B, and 36C of each authentication engine 30A, 30B, and 30C are stored in association with the identification information of the authentication engines 30A, 30B, and 30C. This allows the service provider whose facial image features are not registered to authenticate the user by capturing the user's facial image with the imaging unit. In this case, the user does not need to register facial image data with all of the multiple authentication engines, thus saving the user time and effort.

[0028] It should be noted that the facial recognition system 10 and facial recognition method according to this embodiment are not limited to those shown in Figures 1 to 3. Other examples of the facial recognition system 10 and facial recognition method according to this embodiment will be described using Figures 4 to 6. Note that for the facial recognition system 10 and each authentication engine 30A, 30B, and 30C shown in Figure 4, the same reference numerals are used for the same components as the facial recognition system 10 and each authentication engine 30A, 30B, and 30C shown in Figure 1, and their descriptions are omitted.

[0029] As shown in Figure 4, the processor 12 of the face recognition system 10 includes a feature extraction means 14 that extracts feature quantities of the user's face image corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​based on face image data received from the user terminal 20, a registration means 13 that registers the extracted feature quantities of the user's face image, and an authentication means 15 that authenticates the user based on the feature quantities (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each authentication engine 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 so that the registration means 13 stores the feature quantities (specifically, hash values) of the user's face image extracted by the feature extraction means 14 in the memory 16, associating them with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C. Furthermore, the processor 12 executes a program stored in the memory 16, thereby enabling the authentication means 15 to authenticate the user by comparing the feature quantities (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each authentication engine 30A, 30B, and 30C with the feature quantities (specifically, hash values) of the user's face image corresponding to each authentication engine 30A, 30B, and 30C stored in the memory 16. Note that the program executed by the processor 12 is not limited to those stored in the memory 16. The processor 12 may also execute a program transmitted to the face recognition system 10 from an external device or a program stored on a recording medium detachably attached to the face recognition system 10, thereby enabling processing in the feature quantity extraction means 14, the registration means 13, and the authentication means 15, respectively.

[0030] Each of the authentication engines 30A, 30B, and 30C deployed at each service organization is composed of, for example, a computer, and each authentication engine 30A, 30B, and 30C has a processor 32A, 32B, and 32C such as a CPU, memory 36A, 36B, and 36C, imaging units 38A, 38B, and 38C, processing units 40A, 40B, and 40C, and communication units 42A, 42B, and 42C. The processors 32A, 32B, and 32C have feature extraction means 34A, 34B, and 34C that extract feature quantities of the user's face image as hash values ​​based on the user's face image data captured by the imaging units 38A, 38B, and 38C. In the example shown in Figure 4, the processors 32A, 32B, and 32C do not have the authentication means 35A, 35B, and 35C as shown in Figure 1. Processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C, thereby enabling feature extraction means 34A, 34B, and 34C to extract features of the user's face image as hash values. Specifically, feature extraction means 34A, 34B, and 34C extract hash values ​​obtained from the received user face image data using a predetermined hash function as features of the user's face image. Note that the programs executed by processors 32A, 32B, and 32C are not limited to those stored in memories 36A, 36B, and 36C. Processors 32A, 32B, and 32C may execute programs transmitted from external devices to authentication engines 30A, 30B, and 30C, or programs stored on recording media detachably attached to authentication engines 30A, 30B, and 30C, thereby enabling various processes to be performed in feature extraction means 34A, 34B, and 34C. Furthermore, in the example shown in Figure 4, the user's facial image features are not stored in memories 36A, 36B, and 36C.

[0031] In the example shown in Figure 4, the facial recognition system 10 and the authentication engines 30A, 30B, and 30C deployed at each service provider are connected via API (Application Programming Interface). This makes it easier to configure the systems of each authentication engine 30A, 30B, and 30C compared to configuring each system independently.

[0032] Next, the processing details for user authentication performed by the facial recognition system 10 and each authentication engine 30A, 30B, and 30C, as shown in Figure 4, will be explained using Figures 5 and 6.

[0033] First, we will explain the process by which a user registers facial image data with the facial recognition system 10 using the user terminal 20. Note that the specific method by which the user captures facial images with the user terminal 20 has already been explained and will be omitted here. When a user first registers using such a facial recognition application on the user terminal 20, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the facial recognition system 10. In this way, the processor 12 of the facial recognition system 10 receives the facial image data from the user terminal 20 (STEP 21). The processor 12 of the facial recognition system 10 also receives the identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered on the user terminal 20. The processor 12 also issues a user ID as user identification information and stores this issued user ID in memory 16.

[0034] Next, the processor 12 of the facial recognition system 10 extracts the facial image features corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​using the feature extraction means 14 based on the facial image data received from the user terminal 20 (STEP 22). At this time, the facial image features of the user extracted by the feature extraction means 14 may differ depending on the type of authentication engine 30A, 30B, and 30C, and the feature extraction means 14 extracts the facial image features of the user for each authentication engine 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the facial image features of the user corresponding to the authentication engine 30A, 30B, and 30C of the service organization that has been pre-selected by the user. Then, the processor 12 stores the facial image features corresponding to each authentication engine 30A, 30B, and 30C extracted by the feature extraction means 14 in the memory 16 of the facial recognition system 10 using the registration means 13, associating them with the user ID (user identification information) and the identification information of the authentication engines 30A, 30B, and 30C (STEP 23). In this way, the registration of the user's facial image captured by the user terminal 20 is completed. Note that in the example shown in Figure 4, the information relating to the user's facial image features stored in the memory 16 is not transmitted from the facial recognition system 10 to the authentication engines 30A, 30B, and 30C of the service organization selected by the user.

[0035] Next, the process of user authentication in each authentication engine 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each authentication engine 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C to image the user (STEP 31). In addition, in the authentication engines 30A, 30B, and 30C, the processors 32A, 32B, and 32C extract the features of the user's face image as hash values ​​using feature extraction means 34A, 34B, and 34C based on the acquired face image data (STEP 32). Then, the processors 32A, 32B, and 32C transmit the features of the user's face image (specifically, the hash values) extracted by the feature extraction means 34A, 34B, and 34C to the processor 12 of the face authentication system 10 via communication units 42A, 42B, and 42C (STEP 33). Furthermore, when the processor 12 of the facial recognition system 10 receives information relating to the feature quantities of the user's facial image from the authentication engines 30A, 30B, and 30C, it receives information relating to the feature quantities of the user's facial image that has been transmitted only from the authentication engines 30A, 30B, and 30C of the service organization selected by the user, which is stored in the memory 16. Then, in the facial recognition system 10, the processor 12 authenticates the user by comparing the feature quantities of the user's facial image (specifically, hash values) received from the authentication engines 30A, 30B, and 30C with the feature quantities of the user's facial image (specifically, hash values) stored in the memory 16 using the authentication means 15 (STEP 34). More specifically, if the matching rate between the feature quantities of the user's facial image received from the authentication engines 30A, 30B, and 30C and the feature quantities of the user's facial image stored in the memory 16 exceeds a predetermined threshold (for example, 80%), the authentication means 15 authenticates the user. As mentioned above, the memory 16 stores pre-registered user identification information and identification information for authentication engines 30A, 30B, and 30C, along with the feature quantities of the user's facial image, in association with each other.

[0036] Then, when the user is authenticated by the authentication means 15 ("YES" in STEP 35), information relating to the authentication result is transmitted from the processor 12 of the facial recognition system 10 to the authentication engines 30A, 30B, and 30C via the communication unit 18 (STEP 36). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C enable the implementation of the service corresponding to these authentication engines 30A, 30B, and 30C via their respective processing units 40A, 40B, and 40C (STEP 37). Subsequently, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information relating to the service usage status to the facial recognition system 10. As a result, information relating to the service usage status at each service provider is stored in the memory 16 of the facial recognition system 10 for each user.

[0037] On the other hand, if the feature quantities of the user's face image received by the authentication engines 30A, 30B, and 30C do not substantially match the feature quantities of the user's face image stored in memory 16, and the authentication means 15 is unable to authenticate the user ("NO" in STEP 35), information relating to the authentication result is transmitted from the processor 12 of the face recognition system 10 to the authentication engines 30A, 30B, and 30C via the communication unit 18 (STEP 38). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C disable the service corresponding to this authentication engine 30A, 30B, and 30C via their respective processing units 40A, 40B, and 40C (STEP 39). In this case as well, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information regarding the service usage status (specifically, information that the user attempted to authenticate with the authentication engines 30A, 30B, and 30C but was not authenticated and therefore could not use the service) to the facial recognition system 10.

[0038] With this authentication method, even if the features of a user's face image are registered in the authentication engine of one service provider (e.g., authentication engine 30A) but not in the authentication engine of another service provider (e.g., authentication engine 30B), the user's face image features are stored in the memory 16 of the face recognition system 10 in association with the identification information of authentication engines 30A, 30B, and 30C. This allows the service provider whose face image features are not registered to authenticate the user by capturing the user's face image with the imaging unit. In this case, the user does not need to register face image data with all of the multiple authentication engines, thus saving the user time and effort.

[0039] Furthermore, other examples of the facial recognition system 10 and facial recognition method according to this embodiment will be described with reference to Figures 7 to 9. Note that for the facial recognition system 10 and each of the authentication engines 30A, 30B, and 30C shown in Figure 7, the same reference numerals are used for components that are the same as those shown in the facial recognition system 10 and each of the authentication engines 30A, 30B, and 30C in Figures 1 and 4, and their descriptions are omitted.

[0040] As shown in Figure 7, the processor 12 of the face recognition system 10 includes a feature extraction means 14 that extracts feature quantities of the user's face image corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​based on face image data received from the user terminal 20, a registration means 13 that registers the extracted feature quantities of the user's face image, and an authentication means 15 that authenticates the user based on the feature quantities (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each authentication engine 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 so that the registration means 13 stores the feature quantities (specifically, hash values) of the user's face image extracted by the feature extraction means 14 in the memory 16, associating them with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C. Furthermore, the processor 12 executes a program stored in the memory 16, thereby enabling the authentication means 15 to authenticate the user by comparing the feature quantities (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each authentication engine 30A, 30B, and 30C with the feature quantities (specifically, hash values) of the user's face image corresponding to each authentication engine 30A, 30B, and 30C stored in the memory 16. Note that the program executed by the processor 12 is not limited to those stored in the memory 16. The processor 12 may also execute a program transmitted to the face recognition system 10 from an external device or a program stored on a recording medium detachably attached to the face recognition system 10, thereby enabling processing in the feature quantity extraction means 14, the registration means 13, and the authentication means 15, respectively.

[0041] Each of the authentication engines 30A, 30B, and 30C deployed at each service organization is composed of, for example, a computer, and each authentication engine 30A, 30B, and 30C has a processor 32A, 32B, and 32C such as a CPU, memory 36A, 36B, and 36C, imaging units 38A, 38B, and 38C, processing units 40A, 40B, and 40C, and communication units 42A, 42B, and 42C. The processors 32A, 32B, and 32C have feature extraction means 34A, 34B, and 34C that extract feature quantities of the user's face image as hash values ​​based on the user's face image data captured by the imaging units 38A, 38B, and 38C. In the example shown in Figure 7, the processors 32A, 32B, and 32C do not have the feature extraction means 34A, 34B, and 34C and the authentication means 35A, 35B, and 35C as shown in Figure 1. Furthermore, in the example shown in Figure 7, the user's facial image features are not stored in memories 36A, 36B, and 36C.

[0042] In the example shown in Figure 7, the facial recognition system 10 and the authentication engines 30A, 30B, and 30C deployed at each service provider are connected via API (Application Programming Interface). This makes it easier to configure the systems of each authentication engine 30A, 30B, and 30C compared to configuring each system independently.

[0043] Next, the processing details for user authentication performed by the facial recognition system 10 and each authentication engine 30A, 30B, and 30C, as shown in Figure 7, will be explained using Figures 8 and 9.

[0044] First, we will explain the process by which a user registers facial image data with the facial recognition system 10 using the user terminal 20. Note that the specific method by which the user captures facial images with the user terminal 20 has already been explained and will be omitted here. When a user first registers using such a facial recognition application on the user terminal 20, various information entered on the user registration screen and the user's facial image data are sent from the user terminal 20 to the facial recognition system 10. In this way, the processor 12 of the facial recognition system 10 receives the facial image data from the user terminal 20 (STEP 41). The processor 12 of the facial recognition system 10 also receives the identification information of the user terminal 20, as well as registration information such as the user's name, date of birth, telephone number, email address, and password entered on the user terminal 20. The processor 12 also issues a user ID as the user's identification information and stores this issued user ID in memory 16.

[0045] Next, the processor 12 of the facial recognition system 10 extracts the facial image features corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​using the feature extraction means 14 based on the facial image data received from the user terminal 20 (STEP 42). At this time, the features of the user's facial image extracted by the feature extraction means 14 may differ depending on the type of authentication engine 30A, 30B, and 30C, and the feature extraction means 14 extracts the features of the user's facial image for each authentication engine 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the features of the user's facial image corresponding to the authentication engine 30A, 30B, and 30C of the service organization that has been pre-selected by the user. Then, the processor 12 stores the facial image features corresponding to each authentication engine 30A, 30B, and 30C extracted by the feature extraction means 14 in the memory 16 of the facial recognition system 10, associating them with the user ID (user identification information) and the identification information of the authentication engines 30A, 30B, and 30C (STEP 43) via the registration means 13. In this way, the registration of the user's facial image captured by the user terminal 20 is completed. Note that in the example shown in Figure 7, the information relating to the user's facial image features stored in the memory 16 is not transmitted from the facial recognition system 10 to the authentication engines 30A, 30B, and 30C of the service organization selected by the user.

[0046] Next, the process of user authentication performed by each authentication engine 30A, 30B, and 30C will be described. When user authentication is required at a service organization where each authentication engine 30A, 30B, and 30C is installed, first, the user's face image data is acquired by imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C to image the user (STEP 51). The processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit the user's face image data captured by the imaging units 38A, 38B, and 38C to the processor 12 of the face authentication system 10 via communication units 42A, 42B, and 42C (STEP 52). Furthermore, when the processor 12 of the facial recognition system 10 receives the user's facial image data from the authentication engines 30A, 30B, and 30C, it receives the user's facial image data transmitted only from the authentication engines 30A, 30B, and 30C of the service organization selected by the user, which is stored in the memory 16. Then, in the facial recognition system 10, the processor 12 uses the feature extraction means 14 to extract the features of the user's facial image as hash values ​​based on the facial image data received from the authentication engines 30A, 30B, and 30C (STEP 53). The processor 12 then uses the authentication means 15 to compare the features of the user's facial image extracted by the feature extraction means 14 (specifically, hash values) with the features of the user's facial image stored in the memory 16 (specifically, hash values) to authenticate the user (STEP 54). More specifically, if the matching rate between the features of the user's face image extracted by the feature extraction means 14 and the features of the user's face image stored in the memory 16 exceeds a predetermined threshold (for example, 80%), the authentication means 15 authenticates the user. As mentioned above, the memory 16 stores pre-registered user identification information and the identification information of the authentication engines 30A, 30B, and 30C, along with the features of the user's face image, in association with each other.

[0047] Then, when the user is authenticated by the authentication means 15 ("YES" in STEP 55), information relating to the authentication result is transmitted from the processor 12 of the facial recognition system 10 to the authentication engines 30A, 30B, and 30C via the communication unit 18 (STEP 56). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C enable the implementation of the service corresponding to these authentication engines 30A, 30B, and 30C via their respective processing units 40A, 40B, and 40C (STEP 57). Subsequently, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information relating to the service usage status to the facial recognition system 10. As a result, information relating to the service usage status at each service provider is stored in the memory 16 of the facial recognition system 10 for each user.

[0048] On the other hand, if the feature quantities of the user's face image received by the authentication engines 30A, 30B, and 30C do not substantially match the feature quantities of the user's face image stored in memory 16, and the authentication means 15 is unable to authenticate the user ("NO" in STEP 55), information relating to the authentication result is transmitted from the processor 12 of the face recognition system 10 to the authentication engines 30A, 30B, and 30C via the communication unit 18 (STEP 58). Upon receiving the information relating to the authentication result, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C disable the service corresponding to these authentication engines 30A, 30B, and 30C via their respective processing units 40A, 40B, and 40C (STEP 59). In this case as well, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information regarding the service usage status (specifically, information that the user attempted to authenticate with the authentication engines 30A, 30B, and 30C but was not authenticated and therefore could not use the service) to the facial recognition system 10.

[0049] With this authentication method, even if the features of a user's face image are registered in the authentication engine of one service provider (e.g., authentication engine 30A) but not in the authentication engine of another service provider (e.g., authentication engine 30B), the user's face image features are stored in the memory 16 of the face recognition system 10 in association with the identification information of authentication engines 30A, 30B, and 30C. This allows the service provider whose face image features are not registered to authenticate the user by capturing the user's face image with the imaging unit. In this case, the user does not need to register face image data with all of the multiple authentication engines, thus saving the user time and effort.

[0050] Next, we will explain the process when a user wants to add more service providers to the facial recognition system 10, as shown in Figures 1 to 9. After the user has completed the user registration described above, when the user presses the "Add Service" button on the initial screen of the user terminal 20, as shown in Figure 10, a list of service providers, as shown in Figure 13, is displayed. This list of service providers is pre-registered in the facial recognition system 10. On the screen shown in Figure 13, the icons for unregistered services and registered services are displayed in different colors, or the icons for unregistered services are displayed faintly, thus distinguishing them from the icons for registered services. When the user presses the icon for an unregistered service, the terms and conditions of the service to be added are displayed. When the user enters an instruction to agree to the terms and conditions of the service, the unregistered service becomes a registered service. At this time, the facial recognition system 10 stores the service provider associated with this registered service in memory 16, linked to the user ID (user identification information). Subsequently, the user terminal 20 displays a screen for capturing a facial image, as shown in Figure 12. When a user captures a facial image using the user terminal 20 on such an imaging screen, the user's facial image data is transmitted from the user terminal 20 to the facial recognition system 10. In this way, the processor 12 of the facial recognition system 10 receives the facial image data from the user terminal 20. The processor 12 then uses the feature extraction means 14 to extract the facial image features corresponding to the authentication engine of the new service provider as hash values ​​based on the facial image data received from the user terminal 20. The processor 12 stores the facial image features corresponding to the new authentication engine extracted by the feature extraction means 14 in the memory 16 of the facial recognition system 10, associating them with the user ID (user identification information) and the identification information of the new service provider's authentication engine, using the registration means 13. In this way, the registration of the new service provider is completed.Furthermore, as will be described later, if the user's face image data is stored in memory 16, when the user registers a new service provider using the user terminal 20, the user terminal 20 does not need to capture an image of the user's face. Instead, the feature extraction means 14 may extract the face image features corresponding to the authentication engine of the new service provider as hash values ​​based on the user's face image data stored in memory 16. In addition, the screen shown in Figure 13 may allow the user to delete registered services. In this case, the registered service becomes an unregistered service. Also, the information related to the user's face image features corresponding to the authentication engine of the service provider related to the deleted registered service, which is stored in memory 16, is deleted.

[0051] Furthermore, after the user has completed the user registration described above, when the user presses the "Authentication History" button on the initial screen of the user terminal 20 as shown in Figure 10, a list of past authentication history information (in other words, a list of information related to the user's usage of the service provider) will be displayed on the user terminal 20 as shown in Figure 14. More specifically, the memory 16 of the facial recognition system 10 stores the user's past authentication history information associated with the user's identification information. When the user presses the "Authentication History" button on the initial screen of the user terminal 20 as shown in Figure 10, the processor 12 of the facial recognition system 10 sends a signal from the user terminal 20 requesting the user's past authentication history information. When the processor 12 of the facial recognition system 10 receives the signal requesting the user's past authentication history information from the user terminal 20, it sends the past authentication history information corresponding to the user's identification information stored in the memory 16 to the user terminal 20 via the communication unit 18. As a result, the user terminal 20 will display a list of the user's past authentication history information. Furthermore, in the list of past authentication history information shown in Figure 14, when a user taps on a particular authentication history entry, the user terminal 20 will display the details of that authentication history, as shown in Figure 15.

[0052] Furthermore, in this embodiment, instead of the user registering the user's facial recognition features in the facial recognition system 10 using the user terminal 20, the user may register the user's facial recognition features in the facial recognition system 10 using certain authentication engines 30A, 30B, and 30C. Specifically, when the user inputs registration information into certain authentication engines 30A, 30B, and 30C, and the imaging units 38A, 38B, and 38C capture an image of the user's face, the input registration information and the user's facial image data are transmitted from the authentication engines 30A, 30B, and 30C to the facial recognition system 10. In this way, the processor 12 of the facial recognition system 10 receives the facial image data from the authentication engines 30A, 30B, and 30C. The processor 12 also issues a user ID as user identification information based on the registration information received from the authentication engines 30A, 30B, and 30C, and stores this issued user ID in the memory 16.

[0053] Next, the processor 12 of the facial recognition system 10 extracts the feature quantities of the facial images corresponding to each authentication engine 30A, 30B, and 30C as hash values ​​using the feature extraction means 14, based on the facial image data received from the authentication engines 30A, 30B, and 30C. In this process, the feature extraction means 14 extracts the feature quantities of the user's facial image for each authentication engine 30A, 30B, and 30C. Furthermore, the feature extraction means 14 extracts only the feature quantities of the user's facial image corresponding to the authentication engine 30A, 30B, and 30C of the service organization pre-selected by the user. For example, if a user has authorized the use of facial image data for the service organization where authentication engine 30A is installed, but has not authorized the use of facial image data for the service organization where authentication engine 30B is installed, the feature extraction means 14 extracts only the feature quantities of the user's facial image corresponding to authentication engine 30A. As described above, the memory 16 stores the user's identification information and the service organization selected by this user in association with each other. The processor 12 then stores the facial image features corresponding to each authentication engine 30A, 30B, and 30C extracted by the feature extraction means 14 in the memory 16 of the facial recognition system 10, associating them with the user ID (user identification information) and the identification information of the authentication engines 30A, 30B, and 30C, using the registration means 13. In this way, the registration of the user's facial image captured by the imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C is completed. In this configuration, the user can register the facial recognition features of the user in the facial recognition system 10 without using the user terminal 20.

[0054] According to the facial recognition method performed by the facial recognition system 10 of this embodiment, which has the configuration described above, the system receives the user's facial image data and user identification information, and extracts the feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's facial image data. Then, the information relating to the feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C that have been extracted is stored in the memory 16 in association with the received user identification information. With such a facial recognition method, facial recognition can be easily performed by multiple authentication engines 30A, 30B, and 30C.

[0055] Specifically, while it is common practice to use facial recognition engines, conventional facial recognition systems could not perform facial recognition if the facial data was not registered in the authentication engine. Therefore, in order to perform authentication with multiple authentication engines, users had to register their facial data with each of them, which was time-consuming and stressful. In contrast, in this embodiment, even if the feature quantities of a user's facial image are registered in one service provider's authentication engine (e.g., authentication engine 30A) but not in another service provider's authentication engine (e.g., authentication engine 30B), the feature quantities of this user's facial image are stored in the memory 16 of the facial recognition system 10 for each of the authentication engines 30A, 30B, and 30C. As a result, even if the user's facial image feature quantities are not registered in the authentication engines 30A, 30B, and 30C of a service provider, the user can be authenticated by capturing the user's facial image with the imaging units 38A, 38B, and 38C. In this case, users will no longer need to register their facial image data with all of the authentication engines 30A, 30B, and 30C, thus saving them time and effort. This will encourage users who previously avoided using various services that use authentication engines that do not require facial image data registration, as they found the process cumbersome, to easily utilize these services.

[0056] Furthermore, when extracting features of the user's face image, such as hash values, and storing them in memory 16, the amount of data stored in memory 16 can be significantly reduced compared to when the user's face image data itself is stored in memory 16. This is because the amount of data for the features of the user's face image is smaller compared to the amount of data for the user's face image data itself. Also, in this case, since the user's face image data itself is not stored in memory 16, the user's privacy can be protected even more reliably. In addition, when sending information related to the features of the user's face image between the face recognition system 10 and each authentication engine 30A, 30B, and 30C, the amount of data communication can be significantly reduced compared to when the user's face image data is sent between the face recognition system 10 and each authentication engine 30A, 30B, and 30C.

[0057] Furthermore, in the face recognition method of this embodiment, as described above, when extracting the feature quantities of the user's face image based on the received user's face image data, the feature quantities of the user's face image are extracted for each of the multiple authentication engines 30A, 30B, and 30C, and the extracted feature quantities of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C are stored in memory in association with the user's identification information by the registration means 13. At this time, it is possible to handle cases where the feature quantities of the user's face image extracted by the feature quantity extraction means 14 differ depending on the type of authentication engine 30A, 30B, and 30C. Note that if the same program is used for the multiple authentication engines 30A, 30B, and 30C, and the feature quantities of the user's face image extracted by the feature quantity extraction means 14 are common to all of the authentication engines 30A, 30B, and 30C, it is not necessary to extract the feature quantities of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C.

[0058] Furthermore, in the facial recognition method of this embodiment, as described above, the memory 16 stores information related to the service provider selected by the user, associated with the user's identification information. In the process of extracting the feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's facial image data, the feature quantity extraction means 14 extracts the feature quantities of the user's facial image corresponding only to the authentication engine of the service provider selected by the user, which are stored in the memory 16. In this case, the feature quantities of the user's facial image corresponding to the authentication engines 30A, 30B, and 30C of service providers not selected by the user are not stored in the memory 16, thus improving security and reassuring the user. In addition, companies and others that participate in the group of authentication engines managed comprehensively by the facial recognition system 10 can appeal to customers with improved customer convenience, as they can be authenticated by multiple authentication engines simply by registering facial image data on the user terminal 20, etc.

[0059] Furthermore, in the face recognition method of this embodiment, as described above, the feature extraction means 14 extracts a hash value obtained from the received user's face image data using a predetermined hash function, as a feature of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C. In this case, since the hash value is stored in the memory 16 as a feature of the user's face image, the amount of data stored in the memory 16 can be reduced compared to the case where the face image data itself is stored in the memory 16. In addition, it is difficult to reconstruct or infer the face image data from the hash value, and since the face recognition system 10 stores only the hash value, the privacy and security of the user can be enhanced.

[0060] In this embodiment, the feature extraction means 14 is not limited to extracting the features of the user's face image as hash values ​​for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's face image data. The feature extraction means 14 may also extract the features of the user's face image as a value of a different type than the hash value for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's face image data. For example, the relative position, size, and shape of each part of the face (eyes, nose, ears, etc.) may be extracted as features of the user's face image. Even in this case, if the amount of data of a value of a different type than the hash value is less than the amount of data of the face image itself, the amount of data stored in the memory 16 can be reduced.

[0061] Furthermore, in the face recognition method of this embodiment, as described above, in the step of extracting the feature quantities of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's face image data, the feature quantities of the user's face image are extracted by the feature quantities of the multiple authentication engines 30A, 30B, and 30C based on the user's face image data transmitted from the user terminal 20 held by the user. Alternatively, in the step of extracting the feature quantities of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's face image data, the feature quantities of the user's face image may be extracted by the feature quantities of the multiple authentication engines 30A, 30B, and 30C based on the user's face image data transmitted from one of the multiple authentication engines 30A, 30B, and 30C.

[0062] Furthermore, in this embodiment, a program for performing a facial recognition method by the facial recognition system 10, which is executed by the processor 12, and a recording medium on which this program is stored are used. When the processor 12 executes the program, it receives the user's facial image data and the user's identification information, and extracts the feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C based on the received facial image data. Then, the information relating to the extracted feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C is stored in the memory 16 in association with the received user's identification information. With such a program and recording medium, facial recognition can be easily performed by multiple authentication engines 30A, 30B, and 30C.

[0063] Furthermore, in this embodiment, a facial recognition system 10 equipped with a processor 12 is used. In such a facial recognition system 10, the processor 12 receives the user's facial image data and user identification information by executing a program, and extracts the feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C based on the received facial image data. Then, the information relating to the extracted feature quantities of the user's facial image for each of the multiple authentication engines 30A, 30B, and 30C is stored in the memory 16 in association with the received user identification information. With such a facial recognition system 10, facial recognition can be easily performed using multiple authentication engines 30A, 30B, and 30C.

[0064] Furthermore, the facial recognition method and facial recognition system according to the present invention are not limited to the embodiments described above, and can be modified in various ways.

[0065] For example, a facial recognition system like the one shown in Figure 16 may be used. The facial recognition system 50 shown in Figure 16 includes a processor 52, a first server 56, a second server 58, and a third server 60. Here, each server 56, 58, and 60 corresponds to each authentication engine 30A, 30B, and 30C. Specifically, the first server 56 corresponds to authentication engine 30A, the second server 58 corresponds to authentication engine 30B, and the third server 60 corresponds to authentication engine 30C. Although three authentication engines 30A, 30B, and 30C are shown in Figure 16, if two or more authentication engines are used, a server corresponding to each authentication engine will be provided in the facial recognition system 10. The processor 52 also includes a server management means 52a, a feature extraction means 54, a registration means 53, and an authentication means 55. The feature extraction means 54, registration means 53, and authentication means 55 of the processor 52 have substantially the same functions as the feature extraction means 14, registration means 13, and authentication means 15 of the processor 12 of the facial recognition system 10 shown in Figures 1, 4, and 7. The server management means 52a is configured to manage each of the servers 56, 58, and 60.

[0066] Each server 56, 58, and 60 stores the feature quantities of the user's facial image data corresponding to each authentication engine 30A, 30B, and 30C, associated with the user's identification information. Furthermore, each server 56, 58, and 60 is communicably connected to the corresponding authentication engines 30A, 30B, and 30C via a network such as the Internet. Each server 56, 58, and 60 is configured to be centrally managed via an API (Application Programming Interface) by the server management means 52a. This makes it easier to configure the systems (programs) of each server 56, 58, and 60 compared to configuring each server independently. Additionally, the server management means 52a and the service organizations where each authentication engine 30A, 30B, and 30C are installed are linked via API. For example, by opening the platform of the server management means 52a to each service organization and allowing each service organization to use the same platform as the server management means 52a, systems for providing services at each service organization can be easily constructed.

[0067] A facial recognition system 50 having such a processor 52 and servers 56, 58, and 60 can perform the same processing as a facial recognition system 10 having a processor 12. That is, according to the facial recognition method performed by the facial recognition system 50 shown in Figure 16, the processor 52 extracts the feature quantities of the user's facial image based on the received user's facial image data using a feature quantity extraction means 54 for each authentication engine 30A, 30B, and 30C, and stores the extracted feature quantities of the user's facial image in each server 56, 58, and 60 in association with the user's identification information and the authentication engines 30A, 30B, and 30C using a registration means 53.

[0068] Furthermore, information relating to the feature quantities of the user's face image stored in each server 56, 58, and 60 is transmitted from each server 56, 58, and 60 to the corresponding authentication engines 30A, 30B, and 30C. As a result, when each authentication engine 30A, 30B, and 30C performs user authentication, the imaging units 38A, 38B, and 38C capture images of the user to acquire the user's face image data, and the feature quantity extraction means 34A, 34B, and 34C extract the feature quantities of the user's face image based on the acquired face image data, thereby enabling each authentication engine 30A, 30B, and 30C to perform user authentication. Subsequently, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information relating to the service usage status to the face recognition system 10. As a result, information relating to the service usage status at each service provider is stored in each server 56, 58, and 60 for each user in the face recognition system 50.

[0069] As another method of user authentication, when each authentication engine 30A, 30B, and 30C authenticates a user, the imaging units 38A, 38B, and 38C capture images of the user to acquire facial image data, and the feature extraction means 34A, 34B, and 34C extract the features of the user's facial image based on the acquired facial image data. Then, each authentication engine 30A, 30B, and 30C transmits information related to the features of the user's facial image to the facial recognition system 50. This enables the authentication means 55 to authenticate the user. Subsequently, the user authentication result is transmitted from the facial recognition system 50 to the original authentication engines 30A, 30B, and 30C.

[0070] As yet another method of user authentication, when each authentication engine 30A, 30B, and 30C performs user authentication, the imaging units 38A, 38B, and 38C capture images of the user to acquire user face image data. Then, each authentication engine 30A, 30B, and 30C transmits the user's face image data to the face recognition system 50. The processor 52 then uses the feature extraction means 54 to extract the feature quantities of the user's face image based on the user's face image data transmitted to each server 56, 58, and 60, and the authentication means 55 compares the extracted feature quantities of the user's face image with the feature quantities of the user's face image stored in each server 56, 58, and 60. This enables the authentication means 55 to authenticate the user. Subsequently, the user authentication result is transmitted from the face recognition system 50 to the original authentication engines 30A, 30B, and 30C.

[0071] These facial recognition methods make it easy to perform facial recognition using multiple authentication engines 30A, 30B, and 30C.

[0072] Furthermore, in a facial recognition system 10 as shown in Figures 1, 4, and 7, the processor 12 may store the user's facial image data itself, transmitted from the user terminal 20 and each of the authentication engines 30A, 30B, and 30C, in the memory 16.

[0073] Furthermore, although the above example shows a configuration in which the facial recognition systems 10 and 50 are installed separately from the authentication engines 30A, 30B, and 30C installed at each service organization, one of the authentication engines 30A, 30B, and 30C installed at each service organization may also perform the functions of the facial recognition systems 10 and 50. That is, the processor of one of the authentication engines 30A, 30B, and 30C installed at each service organization may have feature extraction means, registration means, and authentication means that have the same functions as the feature extraction means 14, registration means 13, and authentication means 15 in the processor 12 of the facial recognition system 10 shown in Figures 1, 4, and 7. [Explanation of symbols]

[0074] 10. Facial Recognition System 12 processors 13. Registration Method 14. Feature extraction method 15 Authentication methods 16 memory 18 Communications Department 20 User Terminals 30A, 30B, 30C certification engine 32A, 32B, 32C processors 34A, 34B, 34C Feature extraction means 35A, 35B, 35C Authentication methods 36A, 36B, 36C memory 38A, 38B, 38C Imaging Unit 40A, 40B, 40C Processing Unit 42A, 42B, 42C Communication Department 50 Facial Recognition Systems 52 processors 52a Server Management Means 53. Registration methods 54 Feature Extraction Method 55 Authentication methods 56 Server 1 58 Second Server 60 Third Server

Claims

1. A first shooting means for acquiring and transmitting user face image data for extracting feature quantities to be used as a comparison criterion, Multiple facial recognition devices that compare feature quantities extracted from captured user facial image data with the aforementioned comparison criteria, and provide services requested by the user when facial recognition of the user is successful, The system includes a service registration means for registering the services that a user will use from among the services provided using each of the aforementioned facial recognition devices, The first imaging means and the service registration means are provided using a user terminal, which is an information terminal owned by the user. Each of the aforementioned facial recognition devices includes a feature extraction means for extracting feature quantities from the user's facial image data, and a storage device in which the feature quantities used as the comparison criteria are registered. Authentication system.

2. Each of the aforementioned facial recognition devices operates differently depending on the device, including the equipment and processing performed when successful facial recognition of a user. The authentication system according to claim 1.

3. Each of the aforementioned facial recognition devices is installed in a service organization, which is a facility where services are provided using these facial recognition devices. The authentication system according to claim 1.

4. Each of the aforementioned facial recognition devices independently determines whether or not it is possible to provide the service requested by the user. The authentication system according to claim 1.

5. Each of the aforementioned facial recognition devices has a different specification for extracting features from facial image data. The authentication system according to claim 1.

6. The aforementioned facial recognition devices do not have a server device that aggregates the authentication means of each device and performs unified user identity verification. The authentication system according to claim 1.

7. At least one of the facial recognition devices can generate and register feature quantities to be used as comparison criteria even from a facial image acquired by the imaging means provided by the facial recognition device. The authentication system according to claim 1.

8. At least one of the aforementioned facial recognition devices is The facial recognition device includes a second shooting means, It has an authentication server connected to the second imaging means via the internet, The authentication server has means for extracting features from facial image data and means for authenticating the user. The second imaging means transmits the acquired user's facial image data to the authentication server. The authentication system according to claim 1.

9. Each of the aforementioned facial recognition devices has a second shooting means for capturing the user's face. The authentication system according to claim 1.

Citation Information

Patent Citations

  • Personal authentication system

    JP2006072540A

  • Intercom, and ringtone control method of intercom

    JP2007184839A

  • Position authentication device, terminal, position authentication method and program

    JP2016025386A

  • Id provider recommendation apparatus, id recommendation system, and id provider recommendation method

    JP2016045633A

  • Service system and robot

    JP2017209769A