Terminal, System, Method for Controlling Terminal, and Program

JPWO2024084713A5Inactive Publication Date: 2025-06-16
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024551200
Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-04-01
Publication Date
2025-06-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing biometric authentication systems for passenger boarding procedures at airports impose a significant information management burden on businesses, such as airport and airline companies, due to centralized data management, which increases security risks and operational costs.

Method used

A terminal and system that store and manage biometric information locally, obtaining user consent for external data sharing, and registering this information in an authentication server only when consent is provided, thereby decentralizing the data management and reducing the burden on central servers.

Benefits of technology

This approach minimizes the period of data retention, reduces security risks, and decreases the operational burden on businesses by allowing information to be activated only when necessary, while ensuring compliance with data protection regulations.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Provided is a terminal that contributes to realizing the reduction of burdens of business operators who provide services, using biometric authentication. The terminal comprises a storage means, a consent acquisition control means, and a registration control means. The storage means stores information for proceeding with boarding procedures at an airport by biometric authentication. The consent acquisition control means acquires the consent of a user to the provision of information for proceeding with boarding procedures at an airport by biometric authentication to the outside. The registration control means exercises control for registering, to an authentication server, information for proceeding with the boarding procedures for which consent to provision to the outside has been obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Terminal, system, terminal control method and storage medium

[0001] The present invention relates to a terminal, a system, a terminal control method, and a storage medium.

[0002] There is a technology that applies biometric authentication to the procedures for boarding passengers on aircraft and the like.

[0003] For example, Patent Document 1 describes that it is possible to provide an information processing device, an information processing method, and a recording medium that can promote the use of biometric authentication in passenger boarding procedures. The information processing device in Patent Document 1 includes an acquisition unit and an output unit. The acquisition unit acquires first history information indicating that passenger boarding procedures at an airport have been performed using biometric authentication and second history information indicating that the procedures have been performed by reading a medium. The output unit outputs the use status of biometric authentication in the procedures based on the first history information and the second history information.

[0004] International Publication No. 2021 / 029047

[0005] As disclosed in Patent Document 1, airport boarding procedures are performed using biometric authentication. In such biometric authentication, a server stores information necessary to authenticate the person to be authenticated. However, such a centralized management system of personal information by a server imposes a heavy information management burden on the business operator (e.g., an airport company or an airline) that operates the server.

[0006] The main object of the present invention is to provide a terminal, a system, a method for controlling a terminal, and a storage medium that contribute to reducing the burden on businesses that provide services using biometric authentication.

[0007] According to a first aspect of the present invention, there is provided a terminal comprising: a storage means for storing information for proceeding with boarding procedures at an airport through biometric authentication; a consent acquisition control means for acquiring a user's consent to providing the information for proceeding with boarding procedures through biometric authentication to an external party; and a registration control means for controlling the registration of the information for proceeding with boarding procedures through biometric authentication, for which consent to providing the information to an external party has been obtained, in an authentication server.

[0008] According to a second aspect of the present invention, there is provided a system including a terminal carried by a user and an authentication server that authenticates the person to be authenticated, wherein the terminal is equipped with: a storage means that stores information for proceeding with check-in procedures at an airport through biometric authentication; a consent acquisition control means that acquires the user's consent to providing the information for proceeding with check-in procedures through biometric authentication to an external party; and a registration control means that controls the registration of the information for proceeding with check-in procedures through biometric authentication, for which consent to providing the information to an external party has been obtained, in the authentication server.

[0009] According to a third aspect of the present invention, there is provided a method for controlling a terminal, which stores information for proceeding with check-in procedures at an airport using biometric authentication in the terminal, obtains consent from a user to provide the information for proceeding with check-in procedures using biometric authentication to an external party, and performs control to register the information for proceeding with check-in procedures using biometric authentication, for which consent to provision to an external party has been obtained, in an authentication server.

[0010] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a terminal to execute the following processes: storing information for proceeding with check-in procedures at an airport using biometric authentication; obtaining consent from a user for providing the information for proceeding with check-in procedures using biometric authentication to an external party; and controlling the registration of the information for proceeding with check-in procedures using biometric authentication, for which consent for provision to an external party has been obtained, in an authentication server.

[0011] According to each aspect of the present invention, a terminal, a system, a terminal control method, and a storage medium are provided that contribute to realizing a reduction in the burden on businesses and the like that provide services using biometric authentication. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.

[0012] FIG. 1 is a diagram illustrating an overview of an embodiment. FIG. 2 is a flowchart illustrating operation of an embodiment. FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to a first embodiment. FIG. 4 is a diagram illustrating an example of a configuration of an on-premise airport according to the first embodiment. FIG. 5 is a diagram illustrating an example of a configuration of a cloud-based airport according to the first embodiment. FIG. 6 is a diagram illustrating an example of a display on a terminal according to the first embodiment. FIG. 7 is a diagram illustrating operation of the information processing system according to the first embodiment. FIG. 8 is a diagram illustrating operation of the information processing system according to the first embodiment. FIG. 9 is a diagram illustrating an example of a processing configuration of a control server according to the first embodiment. FIG. 10 is a flowchart illustrating an example of operation of a system registration control unit according to the first embodiment. FIG. 11 is a diagram illustrating an example of a processing configuration of a dedicated server according to the first embodiment. FIG. 12 is a diagram illustrating an example of a token management database according to the first embodiment. FIG. 13 is a diagram illustrating an example of a processing configuration of a shared server according to the first embodiment. FIGS. 14A and 14B are diagrams illustrating an example of a token management database according to the first embodiment. FIG. 15 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment. FIG. 16 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment. FIG. 17 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. FIGS. 18A, 18B, and 18C are diagrams for explaining a terminal according to a modified example of the first embodiment. FIG. 19 is a diagram showing an example of a display of a terminal according to a modified example of the first embodiment. FIG. 20 is a diagram for explaining the operation of the information processing system according to the modified example of the first embodiment. FIG. 21 is a diagram for explaining the operation of the information processing system according to the second embodiment. FIG. 22 is a diagram showing an example of a token issuance history database according to the third embodiment. FIG. 23 is a diagram showing an example of the processing configuration of a dedicated server according to the third embodiment. FIG. 24 is a diagram showing an example of the processing configuration of a shared server according to the third embodiment. FIG. 25 is a diagram showing an example of the hardware configuration of a control server according to the present disclosure.

[0013] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0014] The terminal 100 according to one embodiment includes a storage unit 101, a consent acquisition control unit 102, and a registration control unit 103 (see FIG. 1 ). The storage unit 101 stores information for proceeding with the boarding procedure at the airport using biometric authentication (storing boarding procedure information; step S1 in FIG. 2 ). The consent acquisition control unit 102 acquires the user's consent for providing information for proceeding with the boarding procedure using biometric authentication to an external party (acquiring consent for information provision; step S2). The registration control unit 103 controls the registration of information for proceeding with the boarding procedure using biometric authentication, for which consent for provision to an external party has been obtained, in an authentication server (registering boarding procedure information; step S3).

[0015] Terminal 100 stores therein information (check-in information; for example, biometric information, passport information) required to proceed with airport check-in procedures using biometric authentication. That is, check-in information is not centrally managed (continuously managed) by a server, but is decentralized and managed by each user. As a result, the information management burden and security risks on the airport company or the like that operates the server are reduced. That is, check-in information is enabled only when it is needed, and is deleted when the server's use of the check-in information is terminated. This configuration minimizes the period during which the company or the like that operates the server handles the information (the period during which the information is retained).

[0016] Specific embodiments will be described in more detail below with reference to the drawings.

[0017] First Embodiment The first embodiment will be described in more detail with reference to the drawings.

[0018] [System Configuration] Fig. 3 is a diagram showing an example of the schematic configuration of an information processing system (airport management system, authentication system) according to the first embodiment. The information processing system shown in Fig. 3 includes a management center and multiple airports A to C.

[0019] The management center will provide each airport with an identity verification platform (Biometrics Hub) that utilizes biometric authentication. The management center will be operated by a voluntary organization, such as an airport company, a joint venture between multiple airport companies, a public institution such as a national or local government, or a private company commissioned by an airport company or public institution.

[0020] The management center includes a control server 10. The control server 10 is a device that realizes the main functions of the management center. The control server 10 may be installed within the facility of the management center, or may be installed in a cloud on a network.

[0021] The multiple airports A to C included in the information processing system are classified into two types.

[0022] An airport that belongs to the first type is an airport that manages and operates the devices and equipment necessary for users (passengers) to complete immigration procedures using biometric authentication. In the example of Figure 3, Airport A corresponds to an airport of the first type. In the following explanation, an airport that belongs to the first type will be referred to as an "on-premise airport."

[0023] An on-premise airport includes a dedicated server 30 that authenticates users who go through immigration procedures using biometric authentication, and an authentication terminal 40 (touch point) that serves as an interface when users go through immigration procedures using biometric authentication. The dedicated server 30 performs authentication processing at one airport. A more detailed configuration of an on-premise airport will be described later.

[0024] The second type of airport is an airport that shares a server with other airports, which is one of the devices required to process users through immigration procedures using biometric authentication. In the example of Figure 3, airports B and C correspond to the second type of airport. In the following explanation, airports that belong to the second type will be referred to as "cloud-based airports."

[0025] As described above, a cloud-based airport does not have a server that authenticates users. A cloud-based airport includes at least one authentication terminal 40 (touch point). In a cloud-based airport, a shared server 50 installed in the cloud authenticates users. The shared server 50 is shared by multiple airports as a server that performs authentication processing. A more detailed configuration of a cloud-based airport will be described later.

[0026] In the following description, the dedicated server 30 and the shared server 50 will be collectively referred to as "authentication servers."

[0027] As shown in Figure 3, the information processing system includes a DCS (Departure Control System) 20. The DCS 20 is a system that manages check-in processing, issuing boarding passes, accepting baggage, etc. The DCS 20 is made up of servers (airline hosts, DCS servers) for each airline. The DCS 20 is a collection of multiple DCS servers. The DCS servers for each airline are configured to be accessible from the control server 10, dedicated server 30, and shared server 50.

[0028] A user possesses a terminal 60. The user uses the terminal 60 to carry out procedures related to the use of an aircraft. For example, the user operates the terminal 60 to purchase an airline ticket or to carry out check-in procedures. An application related to the use of an aircraft is installed on the terminal 60. In the following description, the application installed on the terminal 60 will be referred to as a "mobile app."

[0029] 3 (the control server 10, the dedicated server 30, the shared server 50, etc.) are configured to be able to communicate with each other via a network. For example, the control server 10 and the dedicated server 30 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0030] 3 is an example and is not intended to limit the configuration of the information providing system disclosed in the present application. For example, the management center may include two or more control servers 10. The number of airports included in the information processing system is not limited to three. The information processing system may include at least one on-premise airport and at least one cloud-based airport.

[0031] [Configuration of an On-Premises Airport] Fig. 4 is a diagram showing an example of the configuration of an on-premise airport. As shown in Fig. 4, the on-premise airport includes a dedicated server 30 and multiple touch points (authentication terminals 40; check-in terminals 41, baggage drop machines 42, passenger passage systems 43, gate devices 44, and boarding gate devices 45).

[0032] The user's check-in procedure is carried out at each touch point shown in Figure 4. Specifically, a series of procedures when the user departs the country is carried out sequentially at five touch points. The user can proceed with the check-in procedure using biometric authentication at the five touch points shown in Figure 4.

[0033] In order to proceed with boarding procedures (departure procedures) using biometric authentication, users must register the information required for biometric authentication in the system.

[0034] Note that the user can also proceed with the boarding procedure without relying on biometric authentication. In that case, the user will complete the procedure at a manned counter, booth, etc. Since boarding procedures without biometric authentication are not within the scope of the present disclosure, detailed explanation will be omitted.

[0035] To board an aircraft, a user performs check-in procedures. The user performs check-in procedures using check-in terminal 41. Specifically, the user presents an airline ticket and passport to check-in terminal 41. Once the check-in procedures are complete, check-in terminal 41 issues a boarding pass. The boarding pass includes both paper and electronic boarding passes.

[0036] After completing the check-in procedure, the user can register with the system (registering information required for biometric authentication in the system) using one of the touch points installed at the airport (for example, the check-in terminal 41 or the baggage drop machine 42).

[0037] When performing system registration, the touchpoint (authentication terminal 40) acquires information about the face image, passport, and boarding pass, as well as the user's consent to providing this information. The information acquired by the touchpoint is sent to the dedicated server 30, thereby completing system registration.

[0038] The user can also perform the check-in procedure using the terminal 60 (a mobile application installed on the terminal 60). The user can also perform the system registration using the terminal 60 (a mobile application). The check-in procedure and system registration using the terminal 60 will be described later.

[0039] The check-in terminal 41 is installed in the check-in lobby of the airport. The check-in terminal 41 is also called a CUSS (Common Use Self Service) terminal. After completing the check-in procedure, the user proceeds to the baggage drop-off area or security checkpoint.

[0040] The baggage drop machine 42 is installed in an area adjacent to the baggage counter (manned counter) in the airport or in an area near the check-in terminal 41. The baggage drop machine 42 is a self-service terminal that a user operates to carry on baggage that will not be carried on board the aircraft (baggage drop procedure). The baggage drop machine 42 is also called a CUBD (Common Use Bag Drop) terminal. After completing the baggage drop procedure, the user proceeds to the security checkpoint. Note that if the user does not check in any baggage, the baggage drop procedure is omitted.

[0041] The passenger passage system 43 is a gate device installed at the entrance to the security checkpoint in the airport. The passenger passage system 43 is also called a PRS (Passenger Reconciliation System), and is a system that determines whether or not a user can pass through at the entrance to the security checkpoint. After passing through the passenger passage system 43 and completing the security check procedure, the user moves to the departure inspection area.

[0042] The gate device 44 is installed at the departure inspection area in the airport. The gate device 44 is a device that automatically performs the departure inspection procedures for users. After completing the departure inspection procedures, the user moves to the departure area where duty-free shops and boarding gates are located.

[0043] The boarding gate device 45 is a traffic control device installed at each boarding gate in the departure area. The boarding gate device 45 is also called an ABG (Automated Boarding Gates) terminal. The boarding gate device 45 confirms that the user is a passenger on an aircraft that can board through the boarding gate. After passing through the boarding gate device 45, the user boards the aircraft and departs from the first country to the second country.

[0044] As shown in Figure 4, in principle, on-premise airports use biometric authentication for each procedure (departure procedures) within the airport. However, on-premise airports may use a procedure other than biometric authentication for some of the five procedures. For example, departure procedures may be performed by immigration officers in charge of departure procedures.

[0045] [Configuration of a Cloud-Based Airport] Fig. 5 is a diagram showing an example of the configuration of a cloud-based airport. As shown in Fig. 5, the cloud-based airport does not include a server equivalent to the dedicated server 30. Furthermore, the cloud-based airport is equipped with some of the five touchpoints (authentication terminals 40) required for users' departure procedures. The cloud-based airport selects an authentication terminal 40 that is appropriate for the number of passengers and size of the airport, and installs it within the airport.

[0046] 5, a baggage drop machine 42 and a passenger passage system 43 are installed at airport B, and a boarding gate device 45 is installed at airport C. An authentication terminal 40 (touch point) included in the cloud-based airport is connected to a shared server 50 via a network.

[0047] Even cloud-based airports may have the five touchpoints required for the above-mentioned departure procedures. Furthermore, even cloud-based airports require system registration to proceed with boarding procedures using biometric authentication.

[0048] Note that the configuration of the on-premise airport shown in FIG. 4 and the configuration of the cloud-based airport shown in FIG. 5 are examples and are not intended to limit the configuration of each airport. On-premise airports and cloud-based airports may be equipped with terminals and devices of different types from the authentication terminal 40 shown in the figure. For example, a device that determines whether a token has been issued (whether the procedure can be carried out using biometric authentication) may be installed within the airport. Alternatively, a guidance terminal (information signage) that provides users with details about boarding procedures and token issuance (system registration) may be installed within the airport. Alternatively, a terminal that determines whether users are allowed to enter lounges operated by airport companies or credit card information companies may be installed within the airport. Users may also register with the system using these terminals (the terminal that determines whether a token has been issued, the information signage, or the terminal installed in the lounge).

[0049] [Overall Operation of the System] Next, an overall operation of the information processing system will be described.

[0050] <Advance Preparation> The user makes advance preparations before reserving an aircraft (purchasing an airline ticket). The user makes advance preparations for using the aircraft using a mobile app installed on the terminal 60. Specifically, the user uses the mobile app to register biometric information and passport information in advance on the terminal 60.

[0051] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In this disclosure, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.

[0052] Passport information is all or part of the information printed on the face of a passport, including the user's facial image (hereinafter referred to as the passport facial image), name, date of birth, address, gender, passport number, etc.

[0053] To acquire biometric information, the user photographs his or her own face by operating the terminal 60. The terminal 60 acquires a facial image by taking a selfie.

[0054] To acquire passport information, the terminal 60 analyzes image data obtained by photographing the passport, or acquires passport information from an IC (Integrated Circuit) chip mounted on the passport.

[0055] Once biometric information (e.g., a facial image) and passport information are obtained, the terminal 60 (mobile application) performs identity verification using a facial image obtained by photographing the user (hereinafter referred to as a photographed facial image) and a passport facial image obtained from the passport.

[0056] Specifically, the terminal 60 performs one-to-one authentication using two facial images. If the one-to-one authentication is successful, the terminal 60 determines that the user's advance preparations are complete. In other words, if the one-to-one authentication is not successful (if the user's identity is not confirmed using a passport), the terminal 60 will not execute control related to system registration (information registration for proceeding with departure procedures using biometric authentication) using a mobile app, etc.

[0057] If the user's identity is successfully verified, the user purchases an airline ticket via the web page of a travel agency, airline, etc. The user who purchases the ticket is issued a paper ticket, a two-dimensional barcode containing boarding information, an e-ticket copy, etc. The airline's DCS server also stores the ticket purchaser's passport information and reservation information (ticket information) in association with each other.

[0058] The terminal 60 acquires airline ticket information (all or part of the information written on the airline ticket). For example, the terminal 60 acquires the airline ticket information by analyzing image data obtained by photographing the airline ticket. Alternatively, the terminal 60 acquires the airline ticket information from the two-dimensional barcode or e-ticket. The airline ticket information includes the departure airport, arrival airport, flight name (flight number), airline code of the airline operating the aircraft, etc.

[0059] A predetermined time (for example, 24 hours) before the departure of the reserved flight, the DCS server notifies the ticket purchaser about the check-in procedure. Specifically, the DCS server sends a "check-in request" to the ticket purchaser's email address, which has been registered in advance.

[0060] Upon receiving the check-in request, the user operates the terminal 60 to perform the check-in procedure. For example, the user performs the check-in procedure by following the instructions included in the email received from the DCS server. The check-in procedure may be performed using a mobile app or an application provided by the airline.

[0061] Once check-in is complete, the user is issued a boarding pass. The DCS server stores the passport and boarding pass of the user who has completed check-in in association with each other.

[0062] <Pre-registration> After check-in is complete, the user must pre-register (system registration) to proceed with the boarding procedure using biometric authentication. Specifically, the user must register the information required for the departure airport (on-premise airport or cloud-based airport) to perform biometric authentication in the system.

[0063] As described above, the user can register with the system from the authentication terminal 40 (touch point) installed at the airport, or from the user's own terminal 60. The user registers with the system to proceed with the boarding procedure corresponding to the boarding pass for which check-in has been completed, using biometric authentication.

[0064] When performing procedures related to system registration using terminal 60, the user operates terminal 60 to launch the mobile app. The user performs a predetermined operation in the mobile app (for example, pressing a system registration button). In response to the user's operation, terminal 60 obtains the user's consent to providing information necessary for performing the biometric authentication to an external party.

[0065] The terminal 60 obtains the user's consent to the provision of the information in a manner and manner that complies with the rules and laws regarding the provision of personal information in the country where the user is located.

[0066] Specifically, the terminal 60 (mobile app) references the passport information and airline ticket information to generate a GUI (Graphical User Interface) as shown in Fig. 6. As shown in Fig. 6, the terminal 60 acquires the user's consent to the provision of information while clearly indicating the content of the information to be provided to the outside (biometric information, etc. in the example of Fig. 6) and the destination of the information (airport A in the example of Fig. 6). Once the user's consent to the provision of information is obtained, the terminal 60 (mobile app) generates "power outlet information" including the acquired consent content.

[0067] Note that the consent acquisition screen shown in FIG. 6 is an example, and the terminal 60 can acquire consent for information provision while presenting various information to the user. For example, the terminal 60 may display the purpose and use of personal information (biometric information) to be provided to an external party. Alternatively, if the biometric information to be provided to an external party is to be used for providing a service outside the airport, the terminal 60 may notify the user of this and allow the user to select a service they wish to receive (a service in collaboration with an airport company, etc.). In other words, the terminal 60 may acquire consent (user consent) for personal information such as biometric information to be used outside the airport (off-airport). Furthermore, if the biometric information, etc. is to be used outside the airport, the terminal 60 may present the user with terms of use regarding the use of the biometric information.

[0068] For example, the outlet information includes information about the airport to which the information is to be provided, information about the aircraft the user is scheduled to board (e.g., flight number), information about the airline operating the aircraft (e.g., airline code), personal information about the user (e.g., biometric information, etc.), etc. The outlet information is information about the user's consent to information including biometric information being provided to an external party (shared server 50, dedicated server 30) as viewed from terminal 60.

[0069] Thereafter, the terminal 60 (mobile app) transmits the biometric information, passport information, and power outlet information to the control server 10. Specifically, the terminal 60 transmits a "system registration request" including the biometric information, passport information, and power outlet information to the control server 10 (step S01 in FIG. 7).

[0070] Upon receiving the system registration request, the control server 10 transmits the passport information included in the system registration request to the DCS server. Specifically, the control server 10 identifies the airline operating the aircraft the user plans to board based on the outlet information included in the system registration request. The control server 10 then transmits a "boarding pass information request" including the passport information to the DCS server of the identified airline (step S02).

[0071] The DCS server attempts to identify a boarding pass corresponding to the acquired passport information. If a corresponding boarding pass exists, the DCS server sends a positive response including the boarding pass information to the control server 10 (step S03). If a boarding pass does not exist corresponding to the acquired passport information, the DCS server sends a negative response indicating this to the control server 10.

[0072] Upon acquiring the boarding pass information, the control server 10 requests the authentication server (dedicated server 30, shared server 50) to issue a token. Specifically, the control server 10 transmits four pieces of information required for token issuance (biometric information, passport information, boarding pass information, and power outlet information) to the authentication server (dedicated server 30, shared server 50). The control server 10 transmits a "token issuance request" including the above four pieces of information to the authentication server (step S04).

[0073] When transmitting the token issuance request to the authentication server, the control server 10 determines the destination (dedicated server 30 or shared server 50) of the token issuance request based on the outlet information or boarding pass information. Specifically, if the departure airport obtained from the outlet information or boarding pass information is an on-premise airport, the control server 10 transmits the token issuance request to the dedicated server 30 of the on-premise airport. If the departure airport obtained from the outlet information, etc. is a cloud-based airport, the control server 10 transmits the token issuance request to the shared server 50.

[0074] 3, when a user boards an aircraft from airport A, the biometric information, passport information, boarding pass information, and power outlet information are transmitted to the dedicated server 30 at airport A. On the other hand, when the user boards an aircraft from airport B or airport C, the above four pieces of information are transmitted to the shared server 50.

[0075] When system registration is performed from an authentication terminal 40 (touch point) installed in an airport, the authentication terminal 40 acquires the above four pieces of information (biometric information, passport information, boarding pass information, and outlet information).The authentication terminal 40 then transmits a token issuance request including the acquired four pieces of information and a terminal ID (described later) to the authentication server.

[0076] <Token Issuance> The authentication server (dedicated server 30, shared server 50) issues a token based on the four pieces of information acquired. The authentication server associates the biometric information, passport information, boarding pass information, and power outlet information and registers them in a token management database (issues a token). The shared server 50 manages tokens using a token management database prepared for each airport.

[0077] When the token issuance process is completed, the authentication server transmits a response (positive response or negative response) to the token issuance request to the control server 10 (step S05).

[0078] In response to receiving the response to the token issuance request, the control server 10 transmits a response (positive response or negative response) to the system registration request to the terminal 60 (step S06).

[0079] If a positive response (system registration successful, token issuance successful) is received, the terminal 60 notifies the user that it is possible to proceed with airport procedures using biometric authentication (so-called face pass).If a negative response (system registration unsuccessful, token issuance unsuccessful) is received, the terminal 60 notifies the user that system registration has failed.

[0080] <Boarding Procedures Using Biometric Authentication> After completing system registration, a user visits the airport on the day of boarding. All or part of the procedures within the airport are carried out using biometric authentication. In procedures that support biometric authentication, the user moves in front of the authentication terminal 40. The authentication terminal 40 acquires biometric information of the user (person to be authenticated) and sends an authentication request including the acquired biometric information (e.g., a facial image) to the authentication server (see FIG. 8).

[0081] 3, the authentication terminal 40 installed at airport A transmits an authentication request to the dedicated server 30. The authentication terminal 40 installed at airport B or airport C transmits an authentication request to the shared server 50.

[0082] The authentication server (dedicated server 30, shared server 50) identifies the corresponding user (entry, token) by performing a matching process using the acquired biometric information and the biometric information stored in the token management database. The authentication server authenticates the user using the passport information and boarding pass information in the identified token. The authentication server transmits the authentication result (authentication successful, authentication failed) to the authentication terminal 40. The authentication terminal 40 performs processing according to the authentication result (for example, allowing or denying the user passage through the gate).

[0083] <Token Deletion> The authentication server (dedicated server 30, shared server 50) deletes tokens related to passengers of a departing aircraft after a predetermined time has elapsed since the aircraft departed.

[0084] As described above, the information processing system according to the first embodiment includes a control server 10, a shared server 50 shared by multiple airports as a server that performs authentication processing, and a dedicated server 30 that performs authentication processing at a single airport. The control server 10 transmits information required for a user to proceed with check-in procedures using biometric authentication to the authentication servers (shared server 50, dedicated server 30). The control server 10 transmits the information required for proceeding with check-in procedures using biometric authentication to either the shared server 50 or the dedicated server 30, depending on the airport used by the user.

[0085] Furthermore, the authentication server (dedicated server 30, shared server 50) uses information acquired from terminal 60 via control server 10 to generate a token for the user to proceed with boarding procedures through biometric authentication, and stores the generated token. The authentication server deletes the token (such as the user's biometric information) used for authentication processing when the token is no longer needed. Specifically, the shared server 50 and dedicated server 30 delete the user's token a predetermined time after the departure of the aircraft on which the user boarded.

[0086] Next, details of each device included in the information processing system according to the first embodiment will be described.

[0087] 9 is a diagram showing an example of the processing configuration (processing modules) of the control server 10 according to the first embodiment. Referring to FIG. 9, the control server 10 includes a communication control unit 201, a system registration control unit 202, and a storage unit 203.

[0088] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the dedicated server 30. The communication control unit 201 also transmits data to the dedicated server 30. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0089] The system registration control unit 202 is a means for controlling the system registration of users. The system registration control unit 202 functions as a "determination unit" that determines the airport used by the user. Furthermore, the system registration control unit 202 functions as a "registration unit" that transmits information required for the user to proceed with boarding procedures using biometric authentication to either the shared server 50 or the dedicated server 30, depending on the airport used by the user. The system registration control unit 202 processes a system registration request received from the terminal 60 (mobile app). The operation of the system registration control unit 202 will be described with reference to FIG. 10 .

[0090] The system registration control unit 202 checks the outlet information included in the system registration request. The outlet information includes information about the airport where the provision of personal information is permitted, the aircraft to be boarded, the airline to be used, etc. The system registration control unit 202 references information about the airline (e.g., airline code) and identifies the airline to be used by the user.

[0091] The system registration control unit 202 transmits a boarding pass information provision request including the passport information obtained from the system registration request to the DCS server of the identified airline (step S101).

[0092] The system registration control unit 202 receives a response (positive or negative response) from the airline's DCS server. The positive response sent from the DCS server includes boarding pass information.

[0093] If a negative response is received (step S102, No branch), the system registration control unit 202 determines that the user's boarding pass is not registered in the DCS 20. In this case, the system registration control unit 202 transmits a negative response (system registration failed) to the terminal 60 as a response to the system registration request (step S103).

[0094] If a positive response is received (step S102, Yes branch), the system registration control unit 202 extracts the boarding pass information from the positive response. Then, the system registration control unit 202 determines the departure airport used by the user (step S104).

[0095] Specifically, the system registration control unit 202 determines whether the airport used by the user is an on-premise airport or a cloud-based airport based on information about the airport (e.g., airport code) included in the outlet information.

[0096] The system registration control unit 202 sends a token issuance request to the authentication server (dedicated server 30, shared server 50) of the identified airport.

[0097] Specifically, if the departure airport is an on-premise airport (step S105, Yes branch), the system registration control unit 202 sends a token issuance request to the dedicated server 30 of the departure airport (step S106).

[0098] If the departure airport is a cloud-based airport (step S105, No branch), the system registration control unit 202 transmits a token issuance request to the shared server 50 (step S107).

[0099] The token issuance request sent by the system registration control unit 202 includes four pieces of information (biometric information, passport information, boarding pass information, and power outlet information) required for the authentication server to issue a token.

[0100] The system registration control unit 202 receives a response (positive response, negative response) to the token issuance request.

[0101] If a negative response (token generation failure) is received (step S108, No branch), the system registration control unit 202 transmits a negative response indicating that system registration has failed to the terminal 60 (step S103).

[0102] If an affirmative response (token generation success) is received (step S108, branch Yes), the system registration control unit 202 transmits an affirmative response indicating that system registration has been successful to the terminal 60 (step S109).

[0103] As described above, the outlet information includes information about the airport used by the user and information about the airline operating the aircraft the user is scheduled to board. The control server 10 obtains boarding pass information about the boarding pass issued to the user by transmitting passport information to a DCS server of the airline corresponding to the information about the airline included in the outlet information. The control server 10 also determines a destination to which to send a token issuance request based on the information about the airport included in the outlet information. The control server 10 transmits a token issuance request including the user's biometric information, passport information about the user's passport, boarding pass information about the boarding pass issued to the user, and the outlet information to the determined destination (authentication server).

[0104] The storage unit 203 stores information necessary for the operation of the control server 10. For example, the storage unit 203 stores the type of each airport (on-premise airport, cloud airport), the address of each authentication server, the address of each airline's DCS server, etc.

[0105] [DCS (DCS Server)] A detailed description of the DCS 20 will be omitted. The DCS server included in the DCS 20 holds reservation information related to passengers of the airline company and issues boarding passes to users who have completed check-in procedures. The DCS server also processes requests for boarding pass information received from the control server 10. If the DCS server has stored a boarding pass corresponding to the passport information included in the received boarding pass information request, it transmits an affirmative response including the boarding pass information of the boarding pass to the control server 10.

[0106] 11 is a diagram showing an example of a processing configuration (processing module) of the dedicated server 30 according to the first embodiment. Referring to FIG. 11 , the dedicated server 30 includes a communication control unit 301, a token control unit 302, an authentication unit 303, and a storage unit 304.

[0107] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the control server 10. The communication control unit 301 also transmits data to the control server 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0108] The token control unit 302 is a means for controlling the tokens of users who proceed with the boarding procedure by biometric authentication. The token control unit 302 receives a token issuance request from the authentication terminal 40 or the control server 10.

[0109] In response to receiving the token issuance request, the token control unit 302 issues a token. Specifically, the token control unit 302 generates a unique value as a token ID based on the date and time of processing, a sequence number, etc.

[0110] Furthermore, the token control unit 302 generates a feature amount from the biometric information (face image) included in the token issuance request.

[0111] Since existing technology can be used for the process of generating features, a detailed description thereof will be omitted. For example, the token control unit 302 extracts the eyes, nose, mouth, etc. from a facial image as feature points. Then, the token control unit 302 calculates the positions of each feature point and the distances between each feature point as feature amounts (generating a feature vector consisting of multiple feature amounts).

[0112] Once the features are generated, the token control unit 302 stores the token ID, biometric information (features), passport information, boarding pass information, and power outlet information in association with each other in the token management database (see FIG. 12). Note that the token management database shown in FIG. 12 is an example and is not intended to limit the items to be stored. For example, a "face image" may be registered in the token management database as biometric information.

[0113] Once the token is generated (the four pieces of information are registered in the database), the token control unit 302 sends a positive response (token issuance successful) to the sender of the token issuance request (authentication terminal 40, control server 10). If the token control unit 302 fails to generate a token ID, it sends a negative response (token issuance failed) to the sender of the token issuance request.

[0114] The token control unit 302 accesses the token management database periodically or at a predetermined timing. The token control unit 302 references the boarding pass information of each entry (token) in the database and deletes entries for which a predetermined time (e.g., 24 hours) has elapsed since the aircraft departed. Alternatively, the token control unit 302 may obtain information about the departed aircraft from the DCS 20.

[0115] The authentication unit 303 is a means for authenticating a user (person to be authenticated) who proceeds with the boarding procedure by biometric authentication. The authentication unit 303 processes authentication requests received from each authentication terminal 40 (touch point) installed in the airport.

[0116] The authentication request includes the biometric information of the person to be authenticated and a terminal ID. The terminal ID is an ID for identifying the authentication terminal 40 installed at the airport. The terminal ID can be the MAC (Media Access Control) address or IP (Internet Protocol) address of the authentication terminal 40.

[0117] The terminal ID is shared by any method between the authentication server and the authentication terminal 40. For example, a system administrator determines a terminal ID and sets the determined terminal ID and detailed information about the authentication terminal 40 (e.g., information about the type of authentication terminal 40, the airport where it is installed, the airline that manages the authentication terminal 40, etc.) in the authentication server. The system administrator also sets the determined terminal ID in the authentication terminal 40.

[0118] The authentication unit 303 uses the terminal ID to identify the type of authentication terminal 40 that sent the authentication request (check-in terminal 41, baggage drop machine 42, passenger passage system 43, gate device 44, boarding gate device 45).

[0119] The authentication unit 303 executes a matching process (one-to-N matching; N is a positive integer, the same applies below) using the biometric information included in the authentication request and the biometric information stored in the token management database.

[0120] The authentication unit 303 generates features from the face image acquired from the authentication terminal 40. The authentication unit 303 sets the generated features (feature vector) as features on the matching side, and sets the features registered in the token management database as features on the registration side.

[0121] The authentication unit 303 calculates the similarity between the feature on the matching side and each of the multiple feature on the registration side. Note that the similarity can be calculated using chi-square distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0122] The authentication unit 303 determines that the matching process has been successful if there is a feature among the multiple feature amounts registered in the token management database that has a similarity with the feature amount to be matched that is equal to or greater than a predetermined value. If there is no such feature amount, the authentication unit 303 determines that the matching process has failed.

[0123] If the matching process fails, the authentication unit 303 transmits a negative response to the authentication terminal 40 indicating that the authentication of the person to be authenticated has failed.

[0124] If the matching process is successful, the authentication unit 303 authenticates the person to be authenticated using the passport information and boarding pass information of the entry corresponding to the feature quantity with the highest similarity. At this time, the authentication unit 303 authenticates the person to be authenticated by executing a process according to the type of authentication terminal 40 identified from the terminal ID.

[0125] For example, when an authentication request is received from the boarding gate device 45 (ABG), the authentication unit 303 determines that the authentication is successful if the person to be authenticated is qualified to board an aircraft parked beyond the boarding gate. If the person to be authenticated is not qualified to board the aircraft, the authentication unit 303 determines that the authentication is unsuccessful.

[0126] A detailed description of the authentication process for each authentication terminal 40 will be omitted, as the authentication process for each individual authentication terminal 40 is different from the gist of the present disclosure and would be obvious to a person skilled in the art.

[0127] The authentication unit 303 transmits the authentication result to the authentication terminal 40 (responds to the authentication request). If the authentication is successful, the authentication unit 303 transmits a positive response (a response indicating successful authentication) to the authentication terminal 40. If the authentication is unsuccessful, the authentication unit 303 transmits a negative response to that effect (authentication failure) to the authentication terminal 40.

[0128] The storage unit 304 stores various information necessary for the operation of the dedicated server 30. In the storage unit 304, a token management database is created.

[0129] 13 is a diagram showing an example of the processing configuration (processing modules) of the shared server 50 according to the first embodiment. Referring to FIG. 13, the shared server 50 includes a communication control unit 401, a token control unit 402, an authentication unit 403, and a storage unit 404.

[0130] The main functions of the shared server 50 can be the same as those of the dedicated server 30. Therefore, the differences between the shared server 50 and the dedicated server 30 will be explained.

[0131] The token control unit 402 of the shared server 50 stores the generated tokens in a database for each airport. For example, the token of a user boarding an aircraft from Airport B is stored in a token management database prepared for Airport B (see FIG. 14A). Also, the token of a user boarding an aircraft from Airport C is stored in a token management database prepared for Airport C (see FIG. 14B).

[0132] When processing an authentication request, authentication unit 403 of shared server 50 authenticates the person to be authenticated using a token management database corresponding to the airport where authentication terminal 40 that sent the authentication request is installed.

[0133] For example, when an authentication request is received from the authentication terminal 40 installed in airport B, the authentication unit 403 performs the authentication process using the biometric information in the token management database shown in Fig. 14A. When an authentication request is received from the authentication terminal 40 installed in airport C, the authentication unit 403 performs the authentication process using the biometric information in the token management database shown in Fig. 14B.

[0134] The authentication unit 403 may refer to table information that stores terminal IDs and airports where the terminals are installed in association with each other, and identify the airport where the authentication terminal 40 is installed.

[0135] 15 is a diagram showing an example of the processing configuration (processing modules) of the authentication terminal 40 according to the first embodiment. Referring to Fig. 15, the authentication terminal 40 includes a communication control unit 501, a biometric information acquisition unit 502, an authentication request unit 503, a function realization unit 504, and a storage unit 505.

[0136] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the dedicated server 30. The communication control unit 501 also transmits data to the dedicated server 30. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0137] The biometric information acquisition unit 502 is a means for controlling a camera (not shown) and acquiring biometric information of a user. The biometric information acquisition unit 502 periodically or at a predetermined timing captures an image of the area in front of the device. The biometric information acquisition unit 502 determines whether the acquired image contains a human face image, and if a face image is included, extracts the face image from the acquired image data.

[0138] Note that since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 502, detailed description thereof will be omitted. For example, the biometric information acquisition unit 502 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 502 may extract a facial image using a technique such as template matching.

[0139] The biometric information acquisition unit 502 passes the extracted face image to the authentication request unit 503 .

[0140] The authentication request unit 503 is a unit that requests the authentication server to authenticate the user in front of the authentication server. The authentication request unit 503 generates an authentication request including the acquired face image and terminal ID, and transmits the request to the authentication server.

[0141] The authentication request unit 503 of the authentication terminal 40 installed in the on-premise airport transmits an authentication request to the corresponding dedicated server 30. The authentication request unit 503 of the authentication terminal 40 installed in the cloud-based airport transmits an authentication request to the shared server 50.

[0142] The authentication request unit 503 receives a response (positive response, negative response) to the authentication request from the authentication server, and passes the received response to the function implementation unit 504.

[0143] The function realization unit 504 is a means for realizing the functions assigned to each authentication terminal 40. For example, if the authentication of the person to be authenticated is successful, the function realization unit 504 of the boarding gate device 45 opens the gate and allows the person to pass through. On the other hand, if the authentication of the person to be authenticated is unsuccessful, the function realization unit 504 of the boarding gate device 45 closes the gate and denies the person to be authenticated from passing through.

[0144] A detailed description of the operation of the function realization unit 504 of each authentication terminal 40 will be omitted because the operation of each authentication terminal 40 is obvious to those skilled in the art and is different from the gist of the disclosure of this application.

[0145] The storage unit 505 is a means for storing information necessary for the operation of the authentication terminal 40 .

[0146] The processing modules of the authentication terminal 40 related to the user's system registration (token issuance) are omitted from Fig. 15. The authentication terminal 40 simply executes the procedure for system registration, similar to the terminal 60. The authentication terminal 40 simply transmits a token issuance request including four pieces of information necessary for token issuance to the authentication server.

[0147] [Terminal] Examples of the terminal 60 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, notebook computers), and the like.

[0148] 16 is a diagram showing an example of a processing configuration (processing module) of the terminal 60 according to the first embodiment. Referring to Fig. 16, the terminal 60 includes a communication control unit 601, a biometric information acquisition unit 602, a passport information acquisition unit 603, a personal identification unit 604, an airline ticket information acquisition unit 605, a consent acquisition control unit 606, a system registration control unit 607, and a storage unit 608.

[0149] The communication control unit 601 is a means for controlling communication with other devices. For example, the communication control unit 601 receives data (packets) from the control server 10. The communication control unit 601 also transmits data to the control server 10. The communication control unit 601 passes data received from other devices to other processing modules. The communication control unit 601 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 601. The communication control unit 601 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0150] The biometric information acquisition unit 602, passport information acquisition unit 603, personal identification unit 604, airline ticket information acquisition unit 605, consent acquisition control unit 606, and system registration control unit 607 are processing modules that make up the mobile application.

[0151] The biometric information acquisition unit 602 is a means for acquiring biometric information (e.g., a facial image) of a user. When the biometric information acquisition unit 602 detects a predetermined operation by the user (e.g., pressing a pre-preparation button), the biometric information acquisition unit 602 acquires the biometric information (e.g., a facial image) of the user using a GUI or the like.

[0152] When acquiring a facial image, the biometric information acquisition unit 602 may utilize a technique for acquiring a facial image suitable for biometric authentication. For example, the biometric information acquisition unit 602 may use a frontal face photographing technique for acquiring a frontal face image or a liveness photographing technique for preventing fraud using photographs, etc.

[0153] When the facial image is acquired, the biometric information acquisition unit 602 notifies the passport information acquisition unit 603 of the fact.

[0154] The passport information acquisition unit 603 is a means for acquiring passport information from a passport held by a user. Upon receiving a notification that acquisition of a facial image has been completed, the passport information acquisition unit 603 acquires the passport information using a GUI or the like.

[0155] For example, a user operates the terminal 60 to photograph the face of the passport. The passport information acquisition unit 603 extracts a facial area from the image data obtained by photographing the face of the passport and acquires a facial image (passport face image). The passport information acquisition unit 603 also acquires the name and other information written on the face of the passport using OCR (Optical Character Recognition) technology.

[0156] Alternatively, the passport information acquisition unit 603 may read passport information from an IC (Integrated Circuit) chip mounted on the passport. When reading information from the IC chip, the passport information acquisition unit 603 reads MRZ information written in a Machine Readable Zone (MRZ) printed on the face of the passport. The MRZ information includes name, nationality, gender, date of birth, etc. The passport information acquisition unit 603 uses the acquired MRZ information as a password to read information such as a facial image and name from the IC chip.

[0157] When the passport information is acquired, the passport information acquisition unit 603 notifies the personal identification unit 604 of that fact. Of course, the terminal 60 may acquire biometric information (facial image) after acquiring the passport information. In this case, after the passport information acquisition unit 603 acquires the passport information, the biometric information acquisition unit 602 acquires the facial image (biometric information).

[0158] The identity verification unit 604 is a means for verifying the identity of a user. When biometric information and passport information are acquired, the identity verification unit 604 performs identity verification using a facial image obtained by photographing the user (photographed facial image) and a facial image read from the passport (passport facial image).

[0159] The personal identification unit 604 performs one-to-one authentication using the two facial images. The personal identification unit 604 determines whether the two facial images substantially match and performs personal identification.

[0160] Specifically, the identity verification unit 604 generates feature amounts from each of the two images. The identity verification unit 604 calculates the similarity between the two feature amounts. If the similarity between the two feature amounts is greater than a predetermined value, the identity verification unit 604 determines that the two facial images are of the same person (determines identity verification as successful). If the similarity is equal to or less than the predetermined value, the identity verification unit 604 determines that the two facial images are not of the same person (determines identity verification as unsuccessful).

[0161] Once identity verification (one-to-one authentication) is complete, users can use each function of the mobile app.

[0162] The air ticket information acquisition unit 605 is a means for acquiring air ticket information from an air ticket purchased by a user. When the air ticket information acquisition unit 605 detects a predetermined action by the user (for example, pressing the air ticket registration button), it displays a GUI or the like for acquiring air ticket information.

[0163] The airline ticket information acquisition unit 605 acquires airline ticket information from image data obtained by photographing an airline ticket, similar to the acquisition of passport information. Alternatively, the airline ticket information acquisition unit 605 may acquire airline ticket information from a web page (a server that provides a web page) or the like where the user purchased the airline ticket.

[0164] The consent acquisition control unit 606 is a means for acquiring the user's consent to providing personal information including biometric information to an external party. More specifically, the consent acquisition control unit 606 acquires the user's consent to providing information (e.g., biometric information, passport information) for proceeding with the boarding procedure by biometric authentication to the boarding airport. After successful identity verification, the consent acquisition control unit 606 acquires the user's consent to providing the information to the boarding airport.

[0165] When the check-in procedure for the purchased airline ticket is completed, the user presses the "System Registration" button on the mobile app. In response to the pressing of the system registration button, the consent acquisition control unit 606 acquires the user's consent to providing personal information required for system registration to an external party.

[0166] For example, the consent acquisition control unit 606 acquires the user's consent to the provision of information using a GUI such as that shown in Fig. 6. When the user's consent to the provision of information is obtained, the consent acquisition control unit 606 generates "consent information" including the acquired consent details. When the consent information is generated, the consent acquisition control unit 606 notifies the system registration control unit 607 of the generation of the consent information.

[0167] The system registration control unit 607 is a means for controlling the system registration of users. The system registration control unit 607 controls the registration of information (information for proceeding with boarding procedures using biometric authentication) that has been consented to be provided to an external party (boarding airport) in the authentication server.

[0168] Once the user's consent to providing information is obtained (the power outlet information is generated), the system registration control unit 607 sends a "system registration request" including biometric information (facial image), passport information, and power outlet information to the control server 10.

[0169] The system registration control unit 607 receives a response (positive response, negative response) to the system registration request from the control server 10. Depending on the received response, the system registration control unit 607 notifies the user whether system registration is possible (whether or not boarding procedures can be carried out using biometric authentication).

[0170] In this way, the system registration control unit 607 transmits a system registration request including the biometric information, passport information, and outlet information to the control server 10. The control server 10 is a server connected to the authentication server, and transmits the passport information to a DCS server of the airline that corresponds to the information about the airline included in the outlet information, thereby acquiring boarding pass information related to the boarding pass issued to the user. Furthermore, in order to enable the control server 10 to acquire the boarding pass information, the consent acquisition control unit 606 generates outlet information including at least information about the airline operating the aircraft on which the user plans to board, when consent to the provision of information is obtained from the user.

[0171] The storage unit 608 is a means for storing information necessary for the operation of the terminal 60. The storage unit 608 stores information for proceeding with the boarding procedure at the airport using biometric authentication. For example, the storage unit 608 stores the user's biometric information, passport information, power outlet information, etc.

[0172] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described. Fig. 17 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. The operation related to the system registration of a user will be described with reference to Fig. 17.

[0173] In response to an operation by the user, the terminal 60 obtains the user's consent to providing personal information such as biometric information to an external party (step S11).

[0174] After obtaining the user's consent (generating the outlet information), the terminal 60 transmits a system registration request including the biometric information, passport information, and outlet information to the control server 10 (step S12).

[0175] In response to receiving the system registration request, the control server 10 transmits the passport information to the DCS 20 to obtain the corresponding boarding pass information (step S13).

[0176] When the boarding pass information is acquired, the control server 10 transmits a token issuance request including the biometric information, passport information, boarding pass information, and power outlet information to the authentication server (step S14). If the user uses an on-premise airport, the control server 10 transmits the token issuance request to the dedicated server 30. If the user uses a cloud-based airport, the control server 10 transmits the token issuance request to the shared server 50.

[0177] The authentication server issues a token by registering the received four pieces of information in a token management database (step S15). In particular, the shared server 50 issues a token to the user in response to the token issuance request received from the control server 10, and stores the issued token in a token management database prepared for each of the multiple airports.

[0178] Next, a modification of the first embodiment will be described.

[0179] <First Modification of First Embodiment> In the above-described first embodiment, the case where the control server 10 acquires boarding pass information from the DCS 20 has been described. However, the terminal 60 may acquire boarding pass information from the DCS 20. Specifically, the system registration control unit 607 of the terminal 60 may acquire boarding pass information by transmitting passport information to the DCS server of the airline company obtained from the airline ticket information.

[0180] In this case, the system registration control unit 607 sends a system registration request including biometric information, passport information, boarding pass information, and power outlet information to the control server 10. The control server 10 identifies the airport used by the user based on the power outlet information or boarding pass information. The control server 10 then sends a token issuance request to the authentication server (dedicated server 30, shared server 50) according to the identified airport.

[0181] Alternatively, the terminal 60 (mobile app) may acquire boarding pass information by photographing a boarding pass issued by the check-in terminal 41 or the like. In this case, once the user's consent to providing information is obtained, the system registration control unit 607 photographs the boarding pass in response to the user's operation. The system registration control unit 607 generates (extracts) boarding pass information from image data obtained by photographing the boarding pass. The system registration control unit 607 then transmits a system registration request to the control server 10, including biometric information, passport information, boarding pass information, and power outlet information. Alternatively, the terminal 60 may acquire boarding pass information from a two-dimensional barcode printed on the boarding pass. That is, the terminal 60 may have a function for reading the barcode printed on the boarding pass.

[0182] Alternatively, boarding pass information acquired by an application other than the mobile app may be transmitted to the control server 10 .

[0183] For example, as shown in FIG. 18A , the mobile app (system registration control unit 607) may obtain boarding pass information from an airline app provided to the user by an airline. The user completes the check-in procedure using the airline app. Upon completion of the check-in procedure, the airline app obtains the boarding pass information from the DCS server. The airline app passes the obtained boarding pass information to the mobile app. The system registration control unit 607 of the terminal 60 sends a system registration request including the obtained boarding pass information to the control server 10.

[0184] Alternatively, the airline app may have the functionality of a mobile app implemented in it, as shown in Fig. 18B . In this case, the system registration control unit 607 also sends a system registration request including the acquired boarding pass information to the control server 10.

[0185] 18C , the mobile app may obtain boarding pass information from a wallet app that manages credit cards, transportation IC cards, concert tickets, etc. In this way, the mobile app may obtain boarding pass information in cooperation with another company's application.

[0186] In this way, the system registration control unit 607 may obtain boarding pass information by transmitting passport information to the DCS server of the airline operating the aircraft the user will board. In this case, the system registration control unit 607 may transmit a system registration request including biometric information, passport information, boarding pass information, and power outlet information to the control server 10 connected to the authentication server.

[0187] <Modification 2 of First Embodiment> In the first embodiment, it is assumed that consent is obtained from the user only for providing information about the boarding procedure corresponding to one boarding pass for which check-in procedures have been completed. However, depending on the timing of boarding the aircraft, consent may be obtained for boarding procedures corresponding to multiple boarding passes.

[0188] For example, both the boarding procedures when traveling from a first country to a second country and the boarding procedures when traveling from the second country to a third country may be subject to system registration (information provision to airports, etc.). In this case, the consent acquisition control unit 606 of the terminal 60 may display multiple boarding procedures (air tickets) that are subject to consent acquisition, allowing the user to select the procedure for which consent is to be given.

[0189] For example, the consent acquisition control unit 606 may display a list of procedures (air tickets) for which consent is to be acquired, as shown in Figure 19, and allow the user to select from the listed air tickets the one for which consent to information provision is to be given.

[0190] The consent acquisition control unit 606 acquires the procedure for which consent is to be acquired using a GUI such as that shown in Fig. 19. The consent acquisition control unit 606 acquires the user's consent for the acquired procedure using a GUI such as that shown in Fig. 6. The system registration control unit 607 may request the control server 10 to register the system for the airline ticket (boarding procedure) selected by the user.

[0191] With this configuration of terminal 60, the user can individually decide whether or not to provide personal information, taking into consideration the details of the flight (airports to which information will be provided and airlines used.) For example, in Figure 19, if the user has concerns about the information management of airport A3 used for the flight in the lower row, the user can choose to refuse to provide information about that flight.

[0192] <Third Modification of First Embodiment> The management center (control server 10) may receive a system registration request from another management center in addition to receiving a system registration request from the user's terminal 60. Alternatively, the management center (control server 10) may transmit a system registration request received from the user's terminal 60 to another management center.

[0193] For example, as shown in FIG. 20, a system registration request may be sent from the control server 10-1 of the first personal identification platform (Biometrics Hub) to the control server 10-2 of the second personal identification platform.

[0194] In this case, if the system registration control unit 202 of the control server 10-1 determines that the system registration request received from the terminal 60 is not addressed to an airport managed by its own system, it sends (transfers) the system registration request to another control server 10-2 connected to its own system.

[0195] When the system registration control unit 202 receives a system registration request from another control server 10, if it determines that the system registration request is addressed to an airport included in its own system, it sends the token issuance request described above to the authentication server.

[0196] In this way, when the control server 10 receives a system registration request (a request including the four pieces of information necessary for token generation) from another system, the control server 10 may transmit a token issuance request to an authentication server of an airport managed by the control server 10. In other words, the control server 10 may transmit a token issuance request to the shared server 50 or the dedicated server 30 in response to a system registration request received from another system.

[0197] <Fourth Modification of the First Embodiment> Rules, laws, etc. regarding the provision of personal information to an external party differ from country to country. In principle, laws, etc. regarding the provision of information are determined by the country in which the user is located. For example, if the user is located in country A, the laws that apply when information is provided to an external party from terminal 60 are the laws of country A. In other words, if a user staying in country B uses an airport in country A, the laws that apply to the provision of information by the user staying in country B are the laws of country B.

[0198] Here, if laws in Country B regarding the provision of personal information prohibit the provision of personal information to other countries, the terminal 60 of a user staying in Country B cannot provide the user's personal information to the outside, and the control server 10 cannot obtain the user's personal information.

[0199] Therefore, the terminal 60 (mobile application) and / or the control server 10 performs control to comply with the laws of the country where the user is located.

[0200] Specifically, the consent acquisition control unit 606 of the terminal 60 acquires location information of the terminal itself using a GPS (Global Positioning System) or the like. If the country in which the airport used by the user is located is different from the country in which the user is located, the consent acquisition control unit 606 notifies the user that system registration is not possible (that information for biometric authentication cannot be provided).

[0201] Alternatively, the consent acquisition control unit 606 may store information on whether or not personal information can be provided to the outside for each country, and if it determines that system registration (external provision of personal information) would violate the laws of the country in which the user is located, it may notify the user that the system registration is not possible.

[0202] In this way, the consent acquisition control unit 606 of the terminal 60 (mobile app) does not acquire the user's consent to providing information for proceeding with boarding procedures using biometric authentication to an external party if the user's country of residence is different from the country in which the airport used by the user is located.

[0203] The system registration control unit 202 of the control server 10 may also determine the country in which the user is located based on the IP address of the terminal 60. If it is determined that the user is staying in a country different from the country in which the airport used is located, the system registration control unit 202 may reject the user's system registration request. Alternatively, the system registration control unit 202 may use a list that lists whether or not a system registration request can be accepted for each country.

[0204] By updating the list of countries as necessary, or by updating the mobile app version, it will be possible to achieve both compliance with the law regarding the provision of personal information and improved user convenience.

[0205] As described above, the terminal 60 according to the first embodiment acquires and internally stores biometric information, passport information, and power outlet information, which are information necessary to issue a token (information necessary to proceed with boarding procedures using biometric authentication). The terminal 60 transmits the information to the control server 10 before boarding at the airport. The control server 10 acquires boarding pass information based on the passport information and power outlet information. The control server 10 transmits the biometric information, passport information, boarding pass information, and power outlet information to the authentication server. The authentication server (dedicated server 30, shared server 50) generates a token using these four pieces of information and stores it in a token management database. Once the user's boarding procedures are complete (the aircraft departs), the shared server 50 deletes the token consisting of the above four pieces of information. As a result, the authentication server only needs to store the user's biometric information, passport information, etc. for the minimum necessary period, thereby reducing the burden of managing personal information. In other words, personal information such as biometric information is valid only for the period during which the personal information is used and is deleted when the use of the information ceases. In other words, when the system does not need personal information (such as biometric information), the personal information is not stored in the central server (authentication server). Furthermore, by storing the authorization information, the authentication server can store personal information such as biometric information with the user's explicit consent. Furthermore, the number of entries (tokens) in the token management database built on the authentication server is reduced, improving authentication accuracy.

[0206] Furthermore, by using the mobile app installed on the terminal 60, the user can perform various operations and procedures related to the aircraft passenger. By registering the necessary information in the terminal 60 in advance, the user can register the information for boarding procedures (boarding procedure information) in the system with simple operations on the day of flight travel. The mobile app has a function to acquire and manage tokens (biometric information, passport information, power outlet information, etc.) required for biometric authentication procedures. The mobile app has a biometric information management function, a passport information management function, a boarding pass information (airline ticket information) management function, a power outlet information management function, etc.

[0207] Furthermore, the control server 10 transmits the information required to generate the token (facial image, passport information, boarding pass information, and power outlet information) to the authentication server (dedicated server 30, shared server 50). Even if an airport is unable to provide its own server (dedicated server 30) for biometric authentication, the airport can utilize the shared server 50 to provide users with a boarding procedure using biometric authentication. Airport companies can easily and inexpensively build a biometric authentication system simply by installing an authentication terminal 40 that meets their needs within the airport. Furthermore, if the system includes an airport that already supports a biometric authentication system, the control server 10 transmits the information required to generate the token to the dedicated server 30 of that airport. The control server 10 can change the destination of the information required to generate the token depending on the airport the user is using, allowing airports that already support a biometric authentication system and airports that will newly support a biometric authentication system to coexist.

[0208] Second Embodiment Next, a second embodiment will be described in detail with reference to the drawings.

[0209] In the second embodiment, we will explain how to update a token when a user registers with the system using a mobile app and then changes their seat at the departure airport (when boarding pass information changes).

[0210] The configuration of the information processing system according to the second embodiment can be the same as that of the first embodiment, and therefore a description corresponding to FIG. 3 will be omitted.

[0211] The following description will focus on the differences between the first and second embodiments.

[0212] When a user is informed by an airline employee that a seat change has been made to the aircraft that the user is about to board, the user operates terminal 60 to update the token (information registered in the system).

[0213] For example, the user performs a predetermined operation on the mobile app (e.g., pressing the seat change button). In response to the operation, the system registration control unit 607 of the terminal 60 transmits a "system re-registration request" including at least the passport information and outlet information transmitted immediately before to the control server 10 (see FIG. 21).

[0214] When a system re-registration request is received, the system registration control unit 202 of the control server 10 obtains boarding pass information by transmitting the passport information included in the system re-registration request to the DCS server of the airline used by the user.

[0215] The acquired boarding pass information reflects the seat change that has already been made. The control server 10 sends a "token update request" including at least the reacquired boarding pass information and passport information to the authentication server.

[0216] The token control unit 302 of the dedicated server 30 or the token control unit 402 of the shared server 50 identifies the person (entry, token) whose token is to be updated from the passport information included in the token update request. The token control unit 302 or the like replaces the boarding pass information of the identified token with the boarding pass information included in the token update request.

[0217] In this way, when a boarding pass issued to a user is changed, the system registration control unit 607 of the terminal 60 sends a system re-registration request including passport information and power outlet information to the control server 10. The control server 10 obtains boarding pass information related to the changed boarding pass by sending the passport information included in the system re-registration request to the DCS server of the airline corresponding to the information about the airline included in the power outlet information. The control server 10 then sends a token update request to the authentication server including the obtained changed boarding pass information and passport information.

[0218] <Modification of Second Embodiment> When a seat change is performed, the DCS server may transmit the boarding pass (boarding pass information) and passport information after the seat change to the control server 10 and the authentication server.

[0219] Specifically, the DCS server may transmit a token update request including the boarding pass information and passport information after the seat change to the control server 10. In this case, the control server 10 identifies the authentication server (dedicated server 30, shared server 50) that holds the token to be updated based on the boarding pass information. The control server 10 may transmit a token update request including the changed boarding pass information and passport information to the identified authentication server.

[0220] Alternatively, the DCS server may send a token update request including the boarding pass information and passport information after the seat change directly to the authentication server.

[0221] In this way, the token on the authentication server may be updated by DCS20 sending boarding pass information after a seat change to the authentication server, or the token may be updated by the user performing the token reissue (token update) procedure using a mobile app.

[0222] As described above, the information processing system according to the second embodiment accommodates seat changes implemented by airlines. By accommodating seat changes, users can continue to proceed with boarding procedures using biometric authentication.

[0223] Third Embodiment Next, a third embodiment will be described in detail with reference to the drawings.

[0224] In the third embodiment, a case will be described in which an authentication server stores a history of token issuance, and the token issuance history is provided to an airline or the like.

[0225] The configuration of the information processing system according to the third embodiment can be the same as that of the first embodiment, and therefore a description corresponding to FIG. 3 will be omitted.

[0226] The following description will focus on the differences between the first to third embodiments.

[0227] When the control server 10 according to the third embodiment sends a token generation request to an authentication server, it notifies the authentication server that the sending of the token generation request is due to receiving a system registration request from a mobile app.

[0228] For example, the control server 10 (system registration control unit 202) treats a mobile app as a virtual touchpoint and assigns a virtual ID to the mobile app. Specifically, the system registration control unit 202 sends a token issuance request including the virtual ID (hereinafter referred to as a virtual terminal ID) assigned to the mobile app together with the four pieces of information included in the received system registration request to the authentication server.

[0229] Note that a virtual terminal ID is set for each airline. For example, even when system registration requests are received from the mobile app of the same terminal 60, the virtual terminal ID included in the token issuance request addressed to airline A and the virtual terminal ID included in the token issuance request addressed to airline B are different.

[0230] As mentioned above, the user can also register with the system from the authentication terminal 40 (touch point). At this time, the authentication terminal 40 transmits the terminal ID along with the four pieces of information required for issuing a token (biometric information, passport information, boarding pass information, and outlet information) to the authentication server.

[0231] The authentication server can identify the airline issuing the token using the ID (terminal ID, virtual terminal ID) included in the token issuance request.

[0232] When the token control unit 302 of the dedicated server 30 or the token control unit 402 of the shared server 50 issues a token in response to a received token issuance request, the token control unit 302 stores a history of the token issuance in a database.

[0233] Specifically, the token control unit 302, etc., identifies the airline for which the token issuance has been requested and the sender of the token issuance request (touchpoint, mobile app that sent the system registration request) based on the ID (terminal ID, virtual terminal ID) included in the token issuance request.

[0234] The token control unit 302 stores the date and time when the token was issued, the specified airline, and the sender in a token issuance history database (see FIG. 22). Note that the token issuance history database shown in FIG. 22 is an example and is not intended to limit the items to be stored.

[0235] Fig. 23 is a diagram showing an example of a processing configuration (processing module) of the dedicated server 30 according to the third embodiment. Referring to Fig. 23, an information provision control unit 305 is added to the configuration of the dedicated server 30 according to the first embodiment.

[0236] Fig. 24 is a diagram showing an example of the processing configuration (processing module) of the shared server 50 according to the third embodiment. Referring to Fig. 24, an information provision control unit 405 is added to the configuration of the shared server 50 according to the first embodiment.

[0237] The information provision control unit 305 and the information provision control unit 405 can operate in the same manner. The information provision control unit 305 and the like are means for controlling the provision of information from the authentication server to the outside.

[0238] For example, the information provision control unit 305 etc. provides information on token issuance history in response to a request from an airline employee etc. For example, in the example of Fig. 22, when a request is made to provide the token issuance history of airline A1, the information provision control unit 305 extracts the entries in the first and third to fifth rows of the token issuance history database shown in Fig. 22 and provides the extracted entries to airline A1.

[0239] The airline that receives the information can calculate the token issuance rate from touch points installed at airports, the token issuance rate from mobile apps, etc. For example, in the above example, the token issuance rate from mobile apps is calculated to be 75% (3 / 4).

[0240] The information provision control unit 305 may provide an interface to an airline or the like that allows the airline to input information required by the airline. For example, the information provision control unit 305 may prepare an interface that allows an airline employee or the like to specify a period for extracting the token issuance history. The information provision control unit 305 may also transmit the token issuance history to a server of the airline or to a terminal operated by the employee.

[0241] In this way, each of the shared server 50 and the dedicated server 30 issues a token in response to receiving a token issuance request from a touch point installed in the airport. The token issuance request transmitted from the touch point includes a terminal ID that identifies the touch point. Furthermore, upon receiving a system registration request from the terminal 60, the control server 10 assigns a virtual terminal ID to the terminal 60 (mobile terminal) and transmits a token issuance request including the virtual terminal ID to the shared server 50 or the dedicated server 30. The shared server 50 or the dedicated server 30 generates a token issuance history including the sender of the token issuance request based on the terminal ID and the virtual terminal ID. The shared server 50 or the dedicated server 30 provides information regarding the generated token issuance history.

[0242] <Variation 1 according to the third embodiment> The authentication server may store attribute information (e.g., age, gender, nationality, etc.) of users who have requested token issuance in a token issuance history database shown in Fig. 22. Furthermore, the information provision control unit 305 may generate information to be provided to airlines, etc., using the attribute information of users stored in the token issuance history database. For example, the information provision control unit 305 may calculate the token issuance rate using a mobile app for each attribute (age, gender, nationality, etc.).

[0243] <Modification 2 of Third Embodiment> The information provision control unit 305 and the like may enable information obtained from the token management database to be viewed by airport company staff, etc. In other words, the information provision control unit 305 may provide a dashboard function to the airport company.

[0244] <Variation 3 of the Third Embodiment> In order to improve the token generation rate by the mobile app, a special benefit may be given to users who register with the system using the mobile app. For example, a predetermined number of mileage points may be given to users who register with the system using the mobile app. As a result, system registration using the mobile app is promoted, and the number of check-in terminals 41 and the like installed can be reduced. In other words, increasing the number of users who use the mobile app can reduce costs for airlines and the like.

[0245] As described above, the information processing system according to the third embodiment provides information related to token generation. In particular, the authentication server provides information about the source of the token issuance request (touchpoint, mobile app) to airlines and the like. Airlines and the like are considering more proactive use of biometric authentication. However, airlines and the like are hesitant to install numerous token generation devices at airports due to the cost. Therefore, airlines wish to register a system using a mobile app and consider initiatives to improve the token generation rate (biometric authentication utilization rate) using the mobile app. To understand the results of these initiatives, airlines need to understand the token generation rate using the mobile app. The control server 10 sets a virtual terminal ID in the token generation request from the mobile app, thereby enabling identification of the source of the token issuance request and calculation of the token generation rate using the mobile app.

[0246] Next, the hardware of each device constituting the information processing system will be described. Fig. 25 is a diagram showing an example of the hardware configuration of the control server 10.

[0247] The control server 10 can be configured using an information processing device (a so-called computer), and has the configuration shown in Fig. 25. For example, the control server 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0248] However, the configuration shown in Fig. 25 is not intended to limit the hardware configuration of the control server 10. The control server 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the control server 10 is not intended to be limited to the example shown in Fig. 25; for example, the control server 10 may include multiple processors 311.

[0249] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0250] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0251] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0252] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0253] The functions of the control server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by semiconductor chips.

[0254] The dedicated server 30, authentication terminal 40, etc. can also be configured using information processing devices, just like the control server 10, and their basic hardware configurations are no different from that of the control server 10, so a description thereof will be omitted.

[0255] The control server 10, which is an information processing device, is equipped with a computer, and the functions of the control server 10 can be realized by causing the computer to execute a program. The control server 10 also executes the control method of the control server 10 by the program.

[0256] [Modification] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0257] In the above embodiment, the terminal 60 acquires the airline ticket information and automatically displays the information for which consent is obtained from the user (for example, the name of the airport to which the information will be provided and the airline to be used). However, the terminal 60 may provide the user with a GUI or the like for acquiring the name of the airport to which the information will be provided and the airline to be used. That is, instead of acquiring the airline ticket information, the terminal 60 may provide the user with an interface for the user to input the airport to which the information will be provided and the airline to be used.

[0258] The token generated by the authentication server may be used not only for boarding procedures but also for immigration procedures, such as customs procedures, immigration inspection, and quarantine procedures.

[0259] The management center (control server 10) may have a management function and a counting function for system usage fees. The control server 10 may manage the number of tokens generated by the mobile app and other systems, and may request each airline to pay a fee according to the number of tokens generated.

[0260] In the above embodiment, the control server 10 and the shared server 50 are described as different devices. However, the control server 10 may have the functions of the shared server 50. In other words, the control server 10 and the shared server 50 may be servers built on a cloud.

[0261] In the above embodiment, the case where the authentication server determines whether or not a user is permitted to pass through the gate has been described. However, the authentication terminal 40 may perform this determination. For example, the authentication server transmits the passport information and boarding pass information of the entry identified by the matching process to the authentication terminal 40. The authentication terminal 40 may use the acquired passport information and boarding pass information to determine whether or not the authenticated person is permitted to pass through the gate.

[0262] In the above embodiment, a case has been described in which biometric information related to a facial image is transmitted and received between the authentication server and the authentication terminal 40. However, features generated from a facial image may also be transmitted and received between the above devices. In this case, the receiving authentication server may use the received features for subsequent processing. Alternatively, the biometric information stored in the token management database may be features or a facial image. If a facial image is stored, features may be generated from the facial image as needed. Alternatively, both the facial image and features may be stored in the token management database.

[0263] In the above embodiment, the token management database is configured inside the control server 10. However, the token management database may be configured in an external database server or the like. That is, some functions of the control server 10 or the like may be implemented in another server. More specifically, the above-described "system registration control unit (system registration control means)" or the like may be implemented in any of the devices included in the system.

[0264] The form of data transmission between each device (control server 10, terminal 60, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Passport information and the like is transmitted and received between these devices, and in order to appropriately protect personal information, it is desirable to transmit and receive encrypted data.

[0265] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0266] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0267] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems for users of aircraft and the like.

[0268] Some or all of the above embodiments may be described as, but are not limited to, the following supplementary notes. [Supplementary Note 1] A terminal comprising: a storage means for storing information for proceeding with a check-in procedure at an airport using biometric authentication; a consent acquisition control means for acquiring consent from a user to providing the information for proceeding with the check-in procedure using biometric authentication to an external party; and a registration control means for controlling registration of the information for proceeding with the check-in procedure using biometric authentication, for which consent to provision to an external party has been obtained, in an authentication server. [Supplementary Note 2] The terminal according to Supplementary Note 1, further comprising a biometric information acquisition means for acquiring biometric information of the user. [Supplementary Note 3] The terminal according to Supplementary Note 2, further comprising a passport information acquisition means for acquiring passport information from the user's passport. [Supplementary Note 4] The terminal according to Supplementary Note 3, further comprising: the biometric information acquisition means for acquiring a photographed facial image by photographing the user; the passport information acquisition means for acquiring a passport facial image from the passport; and an identity verification means for verifying the user's identity using the photographed facial image and the passport facial image. [Supplementary Note 5] The terminal according to Supplementary Note 4, wherein the consent acquisition control means acquires the user's consent to providing information to the outside after the identity verification is successful. [Supplementary Note 6] The terminal according to Supplementary Note 5, wherein the consent acquisition control means, when consent to providing information for proceeding with the boarding procedure using biometric authentication to an airport used by the user, generates outlet information including at least information about the airline operating the aircraft that the user plans to board, and the registration control means transmits a system registration request including the biometric information, the passport information, and the outlet information to a control server that is connected to the authentication server and that acquires boarding pass information related to a boarding pass issued to the user by transmitting the passport information to a DCS (Departure Control System) server of an airline that corresponds to the information about the airline included in the outlet information.[Supplementary Note 7] The terminal according to Supplementary Note 6, wherein the registration control means, when a boarding pass issued to the user is changed, sends a system re-registration request including the passport information and the outlet information to the control server, and the control server acquires the boarding pass information related to the changed boarding pass by sending the passport information included in the system re-registration request to a DCS server of an airline that corresponds to the information about the airline included in the outlet information. [Supplementary Note 8] The terminal according to Supplementary Note 5, wherein the registration control means acquires boarding pass information by sending the passport information to a DCS (Departure Control System) server of the airline operating the aircraft on which the user will board, and sends a system registration request including the biometric information, the passport information, the boarding pass information, and the outlet information to a control server connected to the authentication server. [Supplementary Note 9] The terminal according to any one of Supplements 1 to 8, wherein the consent acquisition control means does not acquire user consent to providing to an external party information for proceeding with the boarding procedure using biometric authentication if the country in which the user is located is different from the country in which the airport used by the user is located. [Supplementary Note 10] A system including a terminal carried by a user and an authentication server that authenticates an authenticatee, wherein the terminal comprises: a storage means that stores information for proceeding with airport check-in procedures through biometric authentication, a consent acquisition control means that acquires consent from the user to providing the information for proceeding with the check-in procedures through biometric authentication to an external party, and a registration control means that controls registration of the information for proceeding with the check-in procedures through biometric authentication, for which consent to provision to an external party has been obtained, to the authentication server. [Supplementary Note 11] The system described in Supplementary Note 10, wherein the authentication server uses information acquired from the terminal to generate a token for the user to proceed with the check-in procedures through biometric authentication, and stores the generated token in a token management database. [Supplementary Note 12] The system described in Supplementary Note 11, wherein the authentication server deletes the user's token after a predetermined time has elapsed since the departure of the aircraft on which the user boarded.[Supplementary Note 13] The system according to any one of Supplementary Notes 10 to 12, wherein the biometric information is a facial image or a feature amount generated from the facial image. [Supplementary Note 14] A method for controlling a terminal, comprising: storing, in a terminal, information for proceeding with check-in procedures at an airport through biometric authentication, obtaining consent from a user to provide the information for proceeding with check-in procedures through biometric authentication to an external party, and performing control to register, in an authentication server, the information for proceeding with check-in procedures through biometric authentication, for which consent to provision to an external party has been obtained. [Supplementary Note 15] A computer-readable storage medium storing, in a computer mounted on the terminal, a program for causing: a process for storing information for proceeding with check-in procedures at an airport through biometric authentication, a process for obtaining consent from a user to provide the information for proceeding with check-in procedures through biometric authentication to an external party, and a process for controlling registration, in an authentication server, of the information for proceeding with check-in procedures through biometric authentication, for which consent to provision to an external party has been obtained.

[0269] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.

[0270] 10 Control server 10-1 Control server 10-2 Control server 20 DCS 30 Dedicated server 40 Authentication terminal 41 Check-in terminal 42 Baggage drop machine 43 Passenger passage system 44 Gate device 45 Boarding gate device 50 Shared server 60 Terminal 100 Terminal 101 Storage means 102 Consent acquisition control means 103 Registration control means 201 Communication control unit 202 System registration control unit 203 Storage unit 301 Communication control unit 302 Token control unit 303 Authentication unit 304 Storage unit 305 Information provision control unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 401 Communication control unit 402 Token control unit 403 Authentication unit 404 Storage unit 405 Information provision control unit 501 Communication control unit 502 Biometric information acquisition unit 503 Authentication request unit 504 Function realization unit 505 Storage unit 601 Communication control unit 602 Biometric information acquisition unit 603 Passport information acquisition unit 604 Personal identification unit 605 Airline ticket information acquisition unit 606 Consent acquisition control unit 607 System registration control unit 608 Storage unit

Claims

1. a storage means for storing information for carrying out a boarding procedure at an airport through biometric authentication; a consent acquisition control means for acquiring a consent of a user for providing information for carrying out the boarding procedure by biometric authentication to an external party; a registration control means for controlling the registration in an authentication server of the information for proceeding with the boarding procedure by biometric authentication, the information for which the consent to providing to the outside has been obtained; A terminal comprising:

2. The terminal according to claim 1 , further comprising a biometric information acquiring means for acquiring biometric information of the user.

3. 3. The terminal according to claim 2, further comprising a passport information acquisition means for acquiring passport information from the user's passport.

4. the biometric information acquisition means acquires a photographed face image by photographing the user; The passport information acquisition means acquires a passport face image from the passport, The terminal according to claim 3 , further comprising an identity verification unit that performs identity verification using the photographed face image and the passport face image.

5. The terminal according to claim 4 , wherein the consent acquisition control means acquires the user's consent to providing information to the outside after the identity verification has been successful.

6. the consent acquisition control means, when consent is obtained for providing information for proceeding with the boarding procedure by biometric authentication to the airport used by the user, generates consent information including at least information about the airline operating the aircraft on which the user is scheduled to board; The terminal described in claim 5, wherein the registration control means transmits a system registration request including the biometric information, the passport information, and the outlet information to a control server that is connected to the authentication server and obtains boarding pass information regarding the boarding pass issued to the user by transmitting the passport information to a DCS (Departure Control System) server of an airline corresponding to the information regarding the airline included in the outlet information.

7. the registration control means transmits a system re-registration request including the passport information and the outlet information to the control server when a boarding pass issued to the user is changed; The terminal of claim 6, wherein the control server obtains the boarding pass information related to the changed boarding pass by transmitting passport information included in the system re-registration request to a DCS server of an airline corresponding to the airline information included in the outlet information.

8. A terminal owned by a user; an authentication server that authenticates an authentication subject; Including, The terminal includes: a storage means for storing information for carrying out a boarding procedure at an airport through biometric authentication; a consent acquisition control means for acquiring a consent of a user for providing information for carrying out the boarding procedure by biometric authentication to an external party; a registration control means for controlling the registration of the information for proceeding with the boarding procedure by the biometric authentication, the information for which the consent to providing it to the outside has been obtained, in the authentication server; A system comprising:

9. On the terminal, storing information for proceeding with boarding procedures at airports through biometric authentication; Obtaining the user's consent to providing information to an external party for carrying out the boarding procedure by biometric authentication; A method for controlling a terminal, which performs control for registering, in an authentication server, information for proceeding with the boarding procedure through biometric authentication, for which consent to providing the information to an external party has been obtained.

10. The computer installed in the terminal A process of storing information for proceeding with the boarding procedure at the airport by biometric authentication; A process of obtaining consent from the user for providing information for carrying out the boarding procedure by biometric authentication to an external party; A process of controlling the registration in an authentication server of the information for proceeding with the boarding procedure by biometric authentication, the information for which consent to the provision to the outside has been obtained; A program for executing the above.