Terminal device, identity verification support method, and program
Patent Information
- Application Number
- JP2024569686
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Priority Date
- 2023-01-10
- Filing Date
- 2023-01-10
- Publication Date
- 2025-09-11
AI Technical Summary
Existing identity verification methods, particularly those using face verification with official certificates, face challenges in accuracy due to image quality issues and risk impersonation through forged documents, especially when the face on the certificate is defaced or tampered with.
A terminal device and method that acquire and compare biometric information from the user's body or voice with stored biometric information and electronic certificates, ensuring authentication without relying on the condition of the official certificate's face image, thereby reducing impersonation risks.
The solution effectively verifies identities by using biometric data from the user's voice or body, enhancing accuracy and security by eliminating reliance on the quality of the official certificate's image and reducing the risk of impersonation.
Abstract
Description
Terminal device, identity verification support method, and computer-readable storage medium
[0001] The present disclosure relates to a technology for supporting identity verification in procedures via a network.
[0002] Services that allow consumers to complete procedures online are commonly provided in various industries, such as finance, insurance, real estate, retail, and infrastructure. A technology for verifying identity in such situations is disclosed.
[0003] Patent Documents 1 and 2 disclose methods for verifying the identity of a user when opening an account at a financial institution from a terminal owned by the user.
[0004] Specifically, the information processing device in Patent Document 1 photographs the user's face and the user's driver's license at a terminal, and then verifies the user's identity by comparing the photographed image of the user's face with the photographed image of the face on the driver's license and determining whether the user's actions correspond to predetermined actions.
[0005] The identity verification system of Patent Document 2 outputs a guide screen specifying the position of an object to be photographed together with the identity verification document, and then verifies the identity by comparing an identity verification image including the identity verification document photographed in accordance with the guide screen with a separately photographed verification image including the face of the holder of the identity verification document.
[0006] International Publication No. 2020 / 022014 Japanese Patent Application Laid-Open No. 2020-161191
[0007] When identity verification is performed by facial matching, a facial image taken by the user may be compared with an image taken from an official certificate on which the photograph of the user's face is affixed. However, there is a risk that accurate matching may not be possible depending on the condition of the face of the official certificate, the quality of the captured image, etc. Furthermore, there is a risk that a third party other than the legitimate user may pose as the legitimate user by using a forged identity verification document, etc.
[0008] The present disclosure has been made in consideration of the above-mentioned problems, and one of its objects is to provide a terminal device or the like that is capable of appropriately performing identity verification.
[0009] A terminal device according to one aspect of the present disclosure includes a first acquisition means for measuring a user's body or voice when authenticating the user and acquiring first biometric information, which is biometric information corresponding to the measurement result; a second acquisition means for acquiring second biometric information, which is biometric information corresponding to the person's body or voice and an electronic certificate indicating the authenticity of the person, which are stored in an information storage medium; an authentication means for authenticating the user by comparing the first biometric information with the second biometric information; and a transmission means for transmitting the acquired electronic certificate and the authentication result when the user is authenticated.
[0010] A method for supporting identity verification according to one aspect of the present disclosure measures the body or voice of a user when authenticating the user on a terminal operated by the user, acquires first biometric information that is biometric information corresponding to the results of the measurement, acquires second biometric information that is biometric information corresponding to the person's body or voice and an electronic certificate indicating the authenticity of the person, which are stored on an information storage medium, authenticates the user by comparing the first biometric information with the second biometric information, and if the user is authenticated, transmits the acquired electronic certificate and the authentication result.
[0011] A computer-readable storage medium according to one aspect of the present disclosure stores a program that executes the following processes: measuring a user's body or voice when authenticating the user on a terminal operated by the user, and acquiring first biometric information, which is biometric information corresponding to the measurement results; acquiring second biometric information, which is biometric information corresponding to the person's body or voice and an electronic certificate indicating the person's authenticity, which are stored in an information storage medium; authenticating the user by comparing the first biometric information with the second biometric information; and, if the user is authenticated, transmitting the acquired electronic certificate and the authentication result.
[0012] According to the present disclosure, identity verification can be performed appropriately.
[0013] FIG. 1 is a block diagram illustrating an example of a functional configuration of a terminal device according to a first embodiment of the present disclosure. FIG. 2 is a flowchart illustrating an example of an operation of a terminal device according to a first embodiment of the present disclosure. FIG. 3 is a diagram schematically illustrating an example of a configuration including an identity verification support system according to a second embodiment of the present disclosure. FIG. 4 is a block diagram illustrating an example of a functional configuration of an identity verification support system according to a second embodiment of the present disclosure. FIG. 5 is a diagram illustrating an example of a situation in which information is read from an information storage medium according to the second embodiment of the present disclosure. FIG. 6 is a flowchart illustrating a first example of an operation of a terminal device according to a second embodiment of the present disclosure. FIG. 7 is a flowchart illustrating a first example of an operation of an enterprise server according to the second embodiment of the present disclosure. FIG. 8 is a flowchart illustrating a second example of an operation of an enterprise server according to the second embodiment of the present disclosure. FIG. 9 is a block diagram illustrating an example of a functional configuration of an identity verification support system according to a third embodiment of the present disclosure. FIG. 10 is a flowchart illustrating an example of an operation of a terminal device according to the third embodiment of the present disclosure. FIG. 11 is a block diagram illustrating an example of a hardware configuration of a computer device that realizes the identity verification support systems according to the first, second, and third embodiments of the present disclosure.
[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0015] First Embodiment An overview of a terminal device according to the present disclosure will be described. The terminal device is used to verify the identity of a user. Specifically, a user uses the terminal device to perform a predetermined procedure with a business operator. The predetermined procedure may be, for example, a transaction with a financial institution, an insurance application, a product purchase, or the like. The predetermined procedure is not limited to this example. At this time, the user's identity is verified in the terminal device.
[0016] FIG. 1 is a block diagram showing an example of the functional configuration of a terminal device 100. The terminal device 100 is a terminal used by a user. The terminal device 100 is, for example, a portable terminal such as a smartphone or a tablet terminal. This example is not limiting, and the terminal device 100 may also be a personal computer. The terminal device 100 has a camera function. The terminal device 100 also has further input / output devices. Examples of input / output devices include a keyboard, a microphone, a display, a speaker, and an IC (Integrated Circuit) card reader.
[0017] The terminal device 100 includes a first acquisition unit 110 , a second acquisition unit 120 , an authentication unit 130 , and a transmission unit 140 .
[0018] The first acquisition unit 110 acquires biometric information of a user when authenticating a user. The biometric information is information corresponding to a biological body. An example of a biological body is a face, but the biological body is not limited to this example. The biological body may represent a person's body or voice. The first acquisition unit 110 acquires biometric information corresponding to the results of biological body measurement. An example of measurement is photography. For example, the terminal device 100 photographs the user's face. The first acquisition unit 110 may acquire a facial image of the user's face as the user's biometric information. Such biometric information corresponding to the results of biological body measurement is referred to as first biometric information.
[0019] In this way, the first acquisition unit 110 measures the user's body or voice when authenticating the user, and acquires first biometric information that is biometric information corresponding to the measurement result. The first acquisition unit 110 is an example of a first acquisition means.
[0020] The second acquisition unit 120 acquires information stored in an information storage medium. The information storage medium stores biometric information and an electronic certificate. The biometric information stored in the information storage medium is referred to as second biometric information. The second biometric information is biometric information corresponding to a person's biometrics. For example, the second biometric information is a facial image of the person. The electronic certificate is information indicating the authenticity of the person. The electronic certificate is issued, for example, by an external certification authority. The information storage medium is, for example, a public certificate equipped with an IC chip. The second biometric information is, for example, a facial image of the person indicated in the public certificate. In other words, the information storage medium stores the second biometric information of a specific person and an electronic certificate indicating the authenticity of the specific person.
[0021] In this case, the second biometric information and the digital certificate stored in the information storage medium are read by the IC card reader function of the terminal device 100. The second acquisition unit 120 may acquire the read second biometric information and the digital certificate. Note that the information storage medium may be a storage device installed in the terminal device 100.
[0022] In this manner, the second acquisition unit 120 acquires the second biometric information, which is biometric information corresponding to the body or voice of the person, and the digital certificate indicating the authenticity of the person, both of which are stored in the information storage medium. The second acquisition unit 120 is an example of a second acquisition means.
[0023] The authentication unit 130 authenticates the user. Specifically, the authentication unit 130 performs matching based on the first biometric information and the second biometric information. For example, the authentication unit 130 matches a facial feature extracted from the first biometric information with a facial feature extracted from the second biometric information. If the matching is successful, the authentication unit 130 authenticates the user. Note that the authentication method is not limited to this example. For example, the user may be authenticated by a method that calculates the similarity of the entire image, such as pattern matching.
[0024] In this way, the authentication unit 130 authenticates the user by matching the first biometric information with the second biometric information. The authentication unit 130 is an example of an authentication means.
[0025] The transmitting unit 140 transmits various information. Specifically, when the user is authenticated by the authentication unit 130, the transmitting unit 140 transmits the acquired electronic certificate and the authentication result. The authentication result includes information indicating whether the user has been authenticated. The transmitting unit 140 may transmit the electronic certificate and the authentication result to a business server. The business server may be a server operated by a business that is the target of the procedure that the user is performing. For example, suppose that a user is performing an online procedure to open an account at a financial institution. In this case, the business server is a server operated by the financial institution or an institution commissioned by the financial institution.
[0026] In this way, when the user is authenticated, the transmitting unit 140 transmits the acquired digital certificate and the authentication result. The transmitting unit 140 is an example of a transmitting means.
[0027] Next, an example of the operation of the terminal device 100 will be described with reference to Fig. 2. In this disclosure, each step in a flowchart will be expressed using a number assigned to each step, such as "S1".
[0028] 2 is a flowchart illustrating an example of the operation of the terminal device 100. The first acquisition unit 110 measures the user's body or voice when authenticating the user and acquires first biometric information, which is biometric information corresponding to the measurement results (S1). The second acquisition unit 120 acquires second biometric information, which is biometric information corresponding to the person's body or voice, and an electronic certificate indicating the person's authenticity, both of which are stored in an information storage medium (S2). The authentication unit 130 authenticates the user by comparing the first biometric information with the second biometric information (S3). If the user is authenticated, the transmission unit 140 transmits the acquired electronic certificate and the authentication result (S4).
[0029] In this way, when authenticating a user, the terminal device 100 of the first embodiment measures the user's body or voice, acquires first biometric information that is biometric information corresponding to the measurement results, and further acquires second biometric information that is biometric information corresponding to the person's body or voice and a digital certificate indicating the person's authenticity, both of which are stored in an information storage medium. Furthermore, the terminal device 100 authenticates the user by comparing the first biometric information with the second biometric information. Then, when the user is authenticated, the terminal device 100 transmits the acquired digital certificate and the authentication result.
[0030] When identity verification is performed using a photograph of an official certificate with a face photo affixed, there is a possibility that accurate identity verification will not be possible if the face of the official certificate is soiled. In contrast, the terminal device 100 of the first embodiment uses biometric information stored in an information storage medium that includes a digital certificate that indicates the authenticity of a person. Therefore, the terminal device 100 can verify identity without considering the condition of the face of the official certificate.
[0031] Furthermore, the terminal device 100 can perform authentication by possessing an information storage medium that stores the above-mentioned digital certificate, and authentication using biometric information stored in the information storage medium. Therefore, the terminal device 100 can reduce the risk of spoofing by forging an official certificate, etc. In other words, the terminal device 100 of the first embodiment can properly perform identity verification.
[0032] Second Embodiment Next, a description will be given of an identity verification support system including a terminal device according to a second embodiment. In the second embodiment, the terminal device 100 described in the first embodiment will be described in more detail. Note that some of the content overlapping with the content described in the first embodiment will not be described again.
[0033] In the second embodiment, an example will be described in which a user performs procedures with a financial institution online. More specifically, in the second embodiment, a user uses a terminal device to perform procedures to open an account with a financial institution. Note that the example of the procedure described in this embodiment is merely an example. The identity verification support system in the present disclosure can be applied to various procedures.
[0034] 3 is a diagram schematically illustrating an example of a configuration including an identity verification support system 1000. The identity verification support system 1000 includes a terminal device 100 and an enterprise server 200.
[0035] The terminal device 100 is communicably connected to the business operator server 200 and the verification server 300 via a network. The business operator server 200 is a server managed by the business operator. For example, the business operator server 200 is managed by a financial institution or an institution commissioned by a financial institution. The business operator server 200 accepts procedures performed by a user. In other words, the business operator server accepts an application to open an account.
[0036] The verification server 300 is a server that verifies the validity of a digital certificate. For example, the verification server 300 is a server managed by an organization such as an external certification authority that manages digital certificates.
[0037] For example, the user may start a dedicated application stored in the terminal device 100 to open an account. The processing of the terminal device 100 may be executed by the application. Alternatively, the user may start a browser on the terminal device 100 to access the website of the financial institution and open an account.
[0038] 4 is a block diagram showing an example of the functional configuration of the identity verification support system 1000. The terminal device 100 includes a first acquisition unit 110, a second acquisition unit 120, an authentication unit 130, and a transmission unit 140. The terminal device 100 further includes a document generation unit 150, an encryption unit 160, a reception unit 170, and an image capture unit 180.
[0039] The first acquisition unit 110 acquires first biometric information of the user. Specifically, the user's face is captured by the imaging unit 180 of the terminal device 100. The first acquisition unit 110 acquires, from the imaging unit 180, a captured image of the user's face.
[0040] The second acquisition unit 120 acquires information stored in an information storage medium. The information storage medium may be a public certificate. An example of an information storage medium is a My Number card. The My Number card is equipped with an IC chip. The IC chip stores a facial image and an electronic certificate of the owner of the My Number card. The IC chip also includes a public key. The electronic certificate includes a signature electronic certificate and a user authentication electronic certificate.
[0041] A signature electronic certificate is used when creating or sending document information over the Internet, etc. A signature electronic certificate is information that proves that the document information is authentic and created by the owner of the My Number card. A signature electronic certificate includes a private key for signing and four basic pieces of information about the owner. The private key corresponds to the public key contained in the IC chip. In other words, information encrypted with the private key is decrypted with the public key. The four basic pieces of information indicate name, address, date of birth, and gender. A user authentication electronic certificate is information that proves the user's identity. A user authentication electronic certificate includes a private key for user authentication.
[0042] The second acquisition unit 120 acquires at least a signature digital certificate and a face image of the owner stored in the IC chip of the Individual Number Card. The face image of the owner is an example of second biometric information. At this time, contactless communication is performed in the terminal device 100, and information is read from the Individual Number Card.
[0043] FIG. 5 is a diagram illustrating an example of a situation in which information is read from an information storage medium. The terminal device 100 reads information stored in the information storage medium through contactless communication. For example, the information is read using near-field communication (NFC) technology. The example of FIG. 5 illustrates an example in which the terminal device 100 reads information from a My Number card. At this time, the second acquisition unit 120 may output guidance information that guides the user through the operation of reading information from the information storage medium. In the example of FIG. 5 , the guidance information may include the message "Please hold your My Number card over the terminal device 100" displayed on the display of the terminal device 100. For example, the user holds their My Number card over the terminal device 100 in accordance with the guidance information displayed on the display. As a result, the terminal device 100 reads a facial image and a digital signature certificate from the My Number card. In this manner, the second acquisition unit 120 may acquire the facial image and the digital signature certificate by reading the facial image and the digital signature certificate from the information storage medium.
[0044] Furthermore, when an operation to read information is performed, the second acquisition unit 120 may prompt the user to enter a personal identification number. For example, after the user holds the My Number card over the terminal device 100, the second acquisition unit 120 accepts the user's input of a personal identification number. In this case, registration number information indicating the correct personal identification number is stored in an IC chip or a storage device (not shown) possessed by the terminal device 100. If the input personal identification number matches the registration number information, the second acquisition unit 120 may read information from the My Number card. If the input personal identification number does not match the registration number information, the second acquisition unit 120 may prompt the user to enter the personal identification number again, or may output information on the terminal device 100 indicating that the information could not be read. In this way, by using a personal identification number when retrieving information from an information storage medium, the terminal device 100 can further perform knowledge authentication.
[0045] Note that the method of acquiring information by the second acquisition unit 120 is not limited to this example. For example, the second acquisition unit 120 may acquire various pieces of information by contact-type communication being performed in the terminal device 100. In this case, information is read by contacting a terminal of a card reader communicatively connected to the terminal device 100 with the IC chip of the My Number card.
[0046] Furthermore, in the above example, the information storage medium is mainly an Individual Number Card, but the information storage medium does not have to be an Individual Number Card. The information storage medium may be a public certificate equipped with an IC chip that stores a facial image and an electronic certificate as described above. The second acquisition unit 120 may similarly acquire a public key from the information storage medium. If the information storage medium is an Individual Number Card, the second acquisition unit 120 may similarly acquire a user-authentication electronic certificate.
[0047] The authentication unit 130 authenticates the user based on the first biometric information acquired by the first acquisition unit 110 and the second biometric information acquired by the second acquisition unit 120. Specifically, the authentication unit 130 compares a captured image of the user's face with a facial image stored in an information storage medium. At this time, the authentication unit 130, for example, extracts facial features from the captured image (first biometric information). The authentication unit 130 also extracts facial features from the facial image (second biometric information). The authentication unit 130 then compares the extracted features. A match indicates that the user has been authenticated. A mismatch indicates that the user has not been authenticated. The authentication unit 130 generates an authentication result. A general facial comparison technique may be used as the user authentication method.
[0048] The transmitting unit 140 transmits various types of information. When the user is authenticated by the authenticating unit 130, the transmitting unit 140 transmits the digital certificate acquired by the second acquiring unit 120 and the authentication result generated by the authenticating unit 130 to the business server 200. At this time, the transmitting unit 140 also transmits the public key and encrypted document information, which will be described later, to the business server 200.
[0049] Furthermore, the transmitting unit 140 transmits the digital certificate to the verification server 300. As a result, the validity of the digital certificate is confirmed in the verification server 300. When the user is authenticated and the validity of the digital certificate is confirmed, the transmitting unit 140 may transmit the authentication result and the digital certificate to the business server 200.
[0050] If the user is not authenticated by the authentication unit 130, the transmission unit 140 may transmit the first biometric information and the second biometric information to the business entity server 200. In this case, authentication processing is performed by the business entity server 200. The authentication processing by the business entity server will be described later.
[0051] The document generation unit 150 generates document information related to the procedure. The document generation unit 150 is an example of a document generation means. The document information indicates a document related to the procedure. If the procedure performed by the user is to open an account, the document information is an account opening application form. The document generation unit 150 accepts an input operation from the user and generates document information into which information corresponding to the input operation has been input.
[0052] The encryption unit 160 encrypts the document information. The encryption unit 160 is an example of an encryption means. Specifically, the encryption unit 160 encrypts the document information using a private key included in the electronic certificate acquired by the second acquisition unit 120. When the information storage medium is a My Number card, the encryption unit 160 encrypts the document information using a private key for signature.
[0053] The receiving unit 170 receives various types of information. The receiving unit 170 is an example of a receiving means. The receiving unit 170 receives implementation status information from the business entity server 200. The receiving unit 170 outputs the received implementation status information to the terminal device 100. The implementation status information will be described in detail later.
[0054] The receiving unit 170 also receives the result of checking the validity of the digital certificate from the check server 300 .
[0055] The business entity server 200 includes a reception unit 210, a notification unit 220, and an authentication unit 230. The reception unit 210 receives information transmitted from the terminal device 100. For example, the reception unit 210 receives an authentication result, encrypted document information, a digital certificate, and a public key from the terminal device 100. When the reception unit 210 receives the encrypted document information and the public key, the reception unit 210 decrypts the document information using the public key. This allows the business entity server 200 to receive the procedure. Note that a description of the examination of the procedure based on the contents of the document information will be omitted.
[0056] The receiving unit 210 may also receive the first biometric information and the second biometric information from the terminal device 100. In this case, the authentication unit 230 performs authentication processing.
[0057] The authentication unit 230 extracts facial features from each of the received first biometric information and second biometric information. The authentication unit 230 then performs authentication processing by comparing the extracted features. The authentication unit 230 generates an external authentication result indicating the result of the authentication processing.
[0058] The notification unit 220 provides various notifications to the terminal device 100. Specifically, the notification unit 220 transmits implementation status information to the terminal device 100. The implementation status information indicates the implementation status of a procedure based on the digital certificate and the authentication result. For example, the implementation status information may indicate that the procedure has been completed, or that the procedure could not be completed due to a defect.
[0059] Furthermore, the notification unit 220 may transmit the external authentication result to the terminal device 100 .
[0060] [Example of Operation of Identity Verification Support System 1000] An example of operation of the identity verification support system 1000 will be described. In this example of operation, the operations of the terminal device 100 and the business entity server 200 will be described.
[0061] 6A is a flowchart illustrating a first example of the operation of the terminal device 100. First, an application is started on the terminal device 100 by a user operation (S101). The application is, for example, an application for opening an account. The document generation unit 150 generates document information related to the procedure (S102). The document information is information entered in response to an input operation by the user.
[0062] Next, the terminal device 100 reads information from the information storage medium. Specifically, the user activates the information reading function. At this time, the second acquisition unit 120 outputs guidance information that guides the user through the information reading operation. The user holds the information storage medium over the terminal device 100 according to the guidance information. The second acquisition unit 120 accepts input of a personal identification number (S103). If the input personal identification number is correct ("Yes" in S104), the second acquisition unit 120 acquires various information from the information storage medium (S105). For example, the second acquisition unit 120 acquires a digital certificate, a facial image, and a public key. The facial image corresponds to second biometric information. If the input personal identification number is incorrect ("No" in S104), the second acquisition unit 120 may accept input of the personal identification number again. At this time, if the personal identification number is incorrect despite being entered a predetermined number of times, the second acquisition unit 120 may terminate the process.
[0063] After the process of S105, the transmitting unit 140 transmits the electronic certificate to the verification server 300 (S106). As a result, the validity of the electronic certificate is confirmed by the verification server 300. Then, the receiving unit 170 receives the confirmation result regarding the validity of the electronic certificate from the verification server 300. If the validity of the electronic certificate is not confirmed ("No" in S107), the terminal device 100 may end the process. If the validity of the electronic certificate is confirmed ("Yes" in S107), the photographing unit 180 photographs the user's face (S108).
[0064] The first acquisition unit 110 acquires the image captured by the imaging unit 180 as the first biometric information (S109). The authentication unit 130 performs authentication processing (S110). Specifically, the authentication unit 130 extracts facial features from each of the second biometric information acquired in the processing of S105 and the first biometric information acquired in the processing of S109. The authentication unit 130 then performs authentication processing by comparing the extracted features.
[0065] If the user is authenticated ("Yes" in S111), the authentication unit 130 generates an authentication result indicating that the user has been authenticated (S112). The encryption unit 160 encrypts the document information using the private key included in the digital certificate (S113).
[0066] The transmitting unit 140 transmits the digital certificate, the authentication result, the encrypted document information, and the public key to the business server 200 (S114). At this time, the transmitting unit 140 may transmit the encrypted document information and the document information before encryption.
[0067] The receiving unit 170 receives the implementation status information from the agent server 200 (S115).
[0068] If the user is not authenticated in the process of S111 ("No" in S111), the terminal device 100 performs the process shown in FIG. 6B. FIG. 6B is a flowchart illustrating a second example of the operation of the terminal device 100. At this time, the authentication unit 130 generates an authentication result indicating that the user has not been authenticated (S116). The transmission unit 140 transmits the first biometric information, the second biometric information, and the authentication result to the business entity server 200 (S117).
[0069] The receiving unit 170 receives the external authentication result from the business server 200 (S118). If the external authentication result indicates that the user has been authenticated ("Yes" in S119), the encryption unit 160 encrypts the document information using the private key included in the digital certificate (S120). The sending unit 140 sends the digital certificate, the authentication result, the encrypted document information, and the public key to the business server 200 (S121). The receiving unit 170 then receives implementation status information from the business server 200 (S122).
[0070] In the process of S119, if the external authentication result indicates that the user has not been authenticated ("No" in S119), the terminal device 100 may end the process.
[0071] In each case where the user is not authenticated, the document generating unit 150 may temporarily store the generated document information.
[0072] Next, an example of the operation of the business operator server 200 will be described. Fig. 7A is a flowchart illustrating a first example of the operation of the business operator server 200. Specifically, Fig. 7A shows the operation performed by the business operator server 200 after the terminal device 100 performs the process of S114.
[0073] The accepting unit 210 of the business entity server 200 accepts the digital certificate, the authentication result, the encrypted document information, and the public key from the terminal device 100 (S201). The accepting unit 210 decrypts the encrypted document information using the public key (S202). The notifying unit 220 generates implementation status information (S203). For example, if the business entity server 200 officially accepts the procedure, the notifying unit 220 generates implementation status information indicating that the procedure has been completed. Furthermore, for example, if there is a defect in the procedure, the notifying unit 220 generates implementation status information indicating that the procedure could not be completed. The notifying unit 220 then notifies the terminal device 100 of the implementation status information (S204). After this, the terminal device 100 performs the process of S115.
[0074] After the terminal device 100 performs the process of S121, the business entity server 200 performs the same process as that shown in FIG. 7A.
[0075] Next, a further example of the operation of the business operator server 200 will be described. Fig. 7B is a flowchart illustrating a second example of the operation of the business operator server 200. Specifically, Fig. 7B shows the operation performed by the business operator server 200 after the terminal device 100 performs the process of S117.
[0076] The accepting unit 210 of the business entity server 200 accepts the first biometric information, the second biometric information, and the authentication result from the terminal device 100 (S205). The authenticating unit 230 performs authentication processing based on the first biometric information and the second biometric information (S206). For example, the biometric authentication engine of the business entity server 200 may have better performance than the biometric authentication engine of the terminal device 100. Therefore, if authentication fails in the terminal device 100, the authentication processing may be performed in the business entity server 200.
[0077] Then, the authentication unit 230 generates an external authentication result indicating the authentication result (S207). The notification unit 220 notifies the terminal device 100 of the external authentication result (S208). After this, the terminal device 100 performs the process of S118.
[0078] Note that this operation example is merely an example, and the operation of the identity verification support system 1000 is not limited to the above-described operation. The order of the processes may be changed as appropriate. For example, the processes of S108 and S109 for acquiring the first biometric information may be performed earlier than in the above-described example. Furthermore, the processes of S103 to S111 may be performed before generating document information.
[0079] In addition, the above-described operation example has been described as an example of an operation for verifying the identity of a user when the user performs a predetermined procedure. Therefore, the operation example includes the generation and transmission / reception of document information related to the procedure. If the user only needs to verify the identity of the user when performing the procedure, the process for generating, transmitting, and receiving document information may not be performed.
[0080] In this way, when authenticating a user, the terminal device 100 of the second embodiment measures the user's body or voice, acquires first biometric information that is biometric information corresponding to the measurement results, and further acquires second biometric information that is biometric information corresponding to the person's body or voice and a digital certificate indicating the person's authenticity, both of which are stored in an information storage medium. The terminal device 100 also authenticates the user by comparing the first biometric information with the second biometric information. If the user is authenticated, the terminal device 100 transmits the acquired digital certificate and the authentication result.
[0081] When identity verification is performed using a photograph of an official certificate with a face photo affixed, there is a possibility that accurate identity verification will not be possible if the face of the official certificate is soiled. In contrast, the terminal device 100 of the second embodiment uses biometric information stored in an information storage medium that includes a digital certificate that indicates the authenticity of the person. Therefore, the terminal device 100 can verify the identity of the person without considering the condition of the face of the official certificate.
[0082] Furthermore, the terminal device 100 can perform authentication by possessing an information storage medium that stores the above-mentioned digital certificate, and authentication using biometric information stored in the information storage medium. Therefore, the terminal device 100 can reduce the risk of spoofing by forging an official certificate, etc. In other words, the terminal device 100 of the second embodiment can properly perform identity verification.
[0083] Furthermore, if the user is not authenticated, the terminal device 100 may transmit the first biometric information and the second biometric information to a server capable of performing authentication processing. Then, the terminal device 100 may receive information indicating a result of the authentication processing based on the first biometric information and the second biometric information, and if the received result indicates that the user is authenticated, may transmit a digital certificate.
[0084] There is a possibility that the authentication process will fail in the terminal device 100. On the other hand, an external server may have an authentication engine with better performance than the terminal device 100. In such a case, the terminal device 100 can have the external server perform the authentication process, thereby enabling more appropriate identity verification.
[0085] The terminal device 100 may also transmit the digital certificate and the authentication result to a server that accepts procedures performed by the user, and receive implementation status information indicating the implementation status of the procedures based on the transmitted digital certificate and the authentication result, thereby notifying the user of the implementation status of the procedures.
[0086] Furthermore, the terminal device 100 may generate document information related to the procedure and, if the user is authenticated, further transmit the document information. At this time, the terminal device 100 may obtain a private key and a public key corresponding to the private key stored in an information storage medium and encrypt the document information based on the private key. Then, if the user is authenticated, the terminal device 100 may transmit the public key and the encrypted document information. This allows the terminal device 100 to be applied to a personal authentication service using a public key cryptosystem.
[0087] [Modification 1] When user authentication fails in the terminal device 100, the terminal device 100 may perform the authentication process a predetermined number of times.
[0088] For example, suppose the user is not authenticated in the process of S111. In this case, the terminal device 100 may return to the process of S108. That is, the photographing unit 180 photographs the user's face again. The first acquisition unit 110 acquires the photographed image again. In other words, the first acquisition unit 110 acquires biometric information different from the previously acquired first biometric information as the first biometric information again. Then, the authentication unit 130 may authenticate the user by comparing the reacquired first biometric information with the second biometric information.
[0089] If the number of times the user has not been authenticated (i.e., the number of times authentication has failed) exceeds a predetermined number, the terminal device 100 may proceed to the process of "No" in S111.
[0090] The authentication unit 130 may generate an authentication result including the number of authentication failures. This allows the business operator to be notified of the number of authentication failures. The business operator can take this information into consideration when carrying out the procedure.
[0091] In this way, if the user is not authenticated, the terminal device 100 of variant example 1 may re-acquire the user's first biometric information and authenticate the user by comparing the re-acquired first biometric information with the second biometric information.
[0092] [Modification 2] In the above-described embodiment, an example has been described in which a face image is used as biometric information. However, examples of biometric information are not limited to this example. The biometric information may be voice information, an iris image, a retina image, fingerprint information, etc. In other words, voiceprint authentication, iris authentication, retina authentication, fingerprint authentication, etc. may be performed as authentication processing.
[0093] For example, if the biometric information is voice information, the user's voice is measured by a microphone of the terminal device 100. The first acquisition unit 110 acquires voice information corresponding to the measured voice as the first biometric information. Furthermore, voice information indicating the user's voice is stored in advance in the information storage medium. The second acquisition unit 120 acquires the stored voice information as the second biometric information. Then, the authentication unit 130 performs voiceprint authentication based on the first biometric information and the second biometric information.
[0094] In this manner, various types of biometric authentication may be applied in the present disclosure.
[0095] [Modification 3] In the above-described embodiment, the information storage medium is mainly an official certificate such as a My Number card, etc. However, the information storage medium is not limited to this example.
[0096] For example, the information storage medium may be a storage medium included in the terminal device 100. That is, the terminal device 100 may have an electronic certificate and biometric information of the user. In other words, the terminal device 100 may be a device equipped with the function of a public certificate such as a My Number card.
[0097] [Variation 4] In the above embodiment, an example has been described in which the terminal device 100 verifies the validity of the digital certificate with the verification server 300. However, the present invention is not limited to this example, and the business entity server 200 may verify the validity with the verification server 300.
[0098] For example, after the processing of S201, the reception unit 210 of the business server 200 transmits the digital certificate to the verification server 300. Then, the reception unit 210 receives a verification result regarding the validity of the digital certificate from the verification server 300. If the validity of the digital certificate is verified, the business server 200 performs the processing from S202 onwards. If the validity of the digital certificate is not verified, the notification unit 220 notifies the terminal device 100 of implementation status information indicating that the procedure could not be completed.
[0099] In this case, the terminal device 100 does not need to perform the processes of S106 and S107.
[0100] [Modification 5] The method for acquiring the second biological information is not limited to the above-described example.
[0101] Specifically, biometric information does not need to be stored in the information storage medium. For example, a database of facial images of people is stored in advance in an external server. The external server operates a website where personal information including facial images can be accessed. The terminal device 100 logs in to the website using the digital certificate acquired from the information storage medium. Then, the second acquisition unit 120 may acquire facial images through the website.
[0102] <Third embodiment> Next, an identity verification support system according to a third embodiment will be described. In the third embodiment, an example of further functions of the identity verification support system will be described. Note that some of the content that overlaps with the content described in the first and second embodiments will not be described.
[0103] In this embodiment, an example will be described in which the biometric information is a face image, but as mentioned above, the biometric information is not limited to this example.
[0104] [Details of Identity Verification Support System 1001] Fig. 8 is a block diagram showing an example of the configuration of an identity verification support system 1001 according to the third embodiment. As shown in Fig. 8, the identity verification support system 1001 includes a terminal device 101 and an enterprise server 200.
[0105] The terminal device 101 includes a first acquisition unit 111, a second acquisition unit 120, an authentication unit 130, and a transmission unit 140. The terminal device 101 further includes a document generation unit 150, an encryption unit 160, a reception unit 170, and an image capture unit 181.
[0106] The first acquisition unit 111 may acquire biometric information of the user as appropriate. Specifically, the first acquisition unit 111 acquires the third biometric information at a timing different from the timing at which the first biometric information used for identity verification is acquired.
[0107] Specifically, the first acquisition unit 111 may acquire the third biometric information at a predetermined timing before acquiring the first biometric information. For example, assume that the first acquisition unit 111 acquires a face image as the first biometric information. Prior to that, the first acquisition unit 111 acquires a face image of the user operating the terminal device 101. In this case, the photographing unit 181 photographs the user's face before photographing the face image as the first biometric information. For example, the photographing unit 181 photographs the user's face when an application that performs a procedure on the terminal device 101 is launched. Then, the first acquisition unit 111 acquires the face image photographed by the photographing unit 181 as the third biometric information.
[0108] Similarly, the first acquisition unit 111 may acquire the third biometric information at a predetermined timing after acquiring the first biometric information. At this time, the image being captured by the imaging unit 181 may or may not be displayed on the terminal device 101. When the user is performing an operation related to a procedure, the image being captured may be displayed on a part of the display of the terminal device 101.
[0109] In this way, the first acquisition unit 111 may acquire the third biometric information of the user operating the terminal device 101 at a timing different from the timing at which the first biometric information is acquired.
[0110] The authentication unit 131 authenticates the user by matching the first biometric information with the third biometric information. That is, the authentication unit 131 may perform an authentication process separate from the authentication based on the first biometric information and the second biometric information. The authentication based on the first biometric information and the second biometric information is for confirming whether the user is the person shown on the information storage medium. On the other hand, the authentication based on the first biometric information and the third biometric information is for confirming whether the user currently operating the device is the same.
[0111] Here, authentication based on the first biometric information and the second biometric information is referred to as first authentication, and authentication based on the first biometric information and the third biometric information is referred to as second authentication.
[0112] The first acquisition unit 111 may acquire the third biometric information multiple times, and the authentication unit 131 may perform the second authentication in response to the acquisition of the third biometric information.
[0113] [Example of Operation of Identity Verification Support System 1001] An example of operation of the identity verification support system 1001 will be described. In this example of operation, the operations of the terminal device 101 and the business entity server 200 will be described. Also, some of the explanations of processes similar to those in the second embodiment will be omitted.
[0114] 9 is a flowchart illustrating an example of the operation of the terminal device 101. First, an application is launched in the terminal device 101 by a user's operation (S101). Then, the image capturing unit 181 captures an image of the user's face (S301). The first acquisition unit 110 acquires the image captured by the image capturing unit 180 as third biometric information (S302). The processes from S102 to S109 are the same as those in the example of FIG. 6A.
[0115] The authentication unit 130 performs authentication processing (S303). Specifically, the authentication unit 130 performs first authentication based on the first biometric information and the second biometric information, and second authentication based on the first biometric information and the second biometric information.
[0116] If the user is not authenticated in the second authentication ("No" in S304), the terminal device 101 may end the processing. If the user is authenticated in the second authentication ("Yes" in S304) and the user is authenticated in the first authentication ("Yes" in S305), the terminal device 101 may perform the processing from S112 onwards. If the user is not authenticated in the first authentication ("No" in S305), the terminal device 101 may perform the operation of FIG. 6B.
[0117] In this way, the terminal device 101 of the third embodiment may measure the body or voice of the user operating the device at a timing different from the timing at which the first biometric information was acquired, and acquire the third biometric information, which is biometric information corresponding to the measurement results. Then, the terminal device 101 may authenticate the user by comparing the first biometric information with the third biometric information.
[0118] There is a possibility that a third party other than the legitimate user may switch places during a procedure and pose as the legitimate user. In contrast, authentication based on the first biometric information and the third biometric information verifies whether the user performing the operation is the same. Therefore, the terminal device 101 of the third embodiment can prevent such user spoofing.
[0119] <Example of Hardware Configuration of Identity Verification Support System> The hardware constituting the identity verification support systems of the first, second, and third embodiments described above will be described. FIG. 10 is a block diagram showing an example of the hardware configuration of a computer device that realizes the identity verification support system in each embodiment. The identity verification support system and identity verification support method described in each embodiment and each modified example are realized in a computer device 90. More specifically, the identity verification support system and identity verification support method described in each embodiment and each modified example are realized in a computer device 90. For example, each of the terminal devices and business entity servers described in each embodiment and each modified example may have the hardware configuration shown in FIG. 10 .
[0120] 10 , a computer device 90 includes a processor 91, a RAM (Random Access Memory) 92, a ROM (Read Only Memory) 93, a storage device 94, an input / output interface 95, a bus 96, and a drive device 97. Note that the terminal device and the business server may be realized by a plurality of electric circuits.
[0121] The storage device 94 stores a program (computer program) 98. The processor 91 executes the program 98 of the identity verification support system using the RAM 92. Specifically, for example, the program 98 includes a program that causes a computer to execute the processes shown in FIGS. 6A, 6B, 7A, 7B, and 9. The processor 91 executes the program 98 to realize the functions of each component of the identity verification support system. The program 98 may be stored in the ROM 93. The program 98 may also be recorded in the storage medium 80 and read out using the drive device 97, or may be transmitted to the computer device 90 from an external device (not shown) via a network (not shown).
[0122] The input / output interface 95 exchanges data with peripheral devices (such as a keyboard, a mouse, and a display device) 99. The input / output interface 95 functions as a means for acquiring or outputting data. The bus 96 connects the various components.
[0123] There are various variations in the method for realizing the identity verification support system. For example, the identity verification support system can be realized as a dedicated device. Furthermore, the identity verification support system, terminal device, and business server can be realized based on a combination of multiple devices.
[0124] The scope of each embodiment also includes a processing method in which a program for realizing each component of the function of each embodiment is recorded on a storage medium, the program recorded on the storage medium is read as code, and the program is executed on a computer. In other words, a computer-readable storage medium is also included in the scope of each embodiment. Furthermore, the storage medium on which the above-mentioned program is recorded and the program itself are also included in each embodiment.
[0125] The storage medium may be, but is not limited to, a floppy disk, a hard disk, an optical disk, a magneto-optical disk, a compact disc (CD)-ROM, a magnetic tape, a non-volatile memory card, or a ROM. The programs recorded on the storage medium are not limited to standalone programs that execute processes, but also include programs that run on an operating system (OS) in cooperation with other software or functions of an expansion board.
[0126] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0127] The above-described embodiments and modifications can be combined as appropriate.
[0128] Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0129] <Additional Notes>
[0130] [Supplementary Note 1] A terminal device comprising: a first acquisition means for measuring a user's body or voice when authenticating the user and acquiring first biometric information which is biometric information corresponding to the measurement result; a second acquisition means for acquiring second biometric information which is biometric information corresponding to the person's body or voice and an electronic certificate indicating the authenticity of the person, both of which are stored in an information storage medium; an authentication means for authenticating the user by comparing the first biometric information with the second biometric information; and a transmission means for transmitting the acquired electronic certificate and an authentication result when the user is authenticated.
[0131] [Supplementary Note 2] The terminal device according to Supplementary Note 1, further comprising a receiving means, wherein the transmitting means transmits the first biometric information and the second biometric information to a server capable of performing authentication processing if the user is not authenticated, the receiving means receives information indicating a result of the authentication processing based on the first biometric information and the second biometric information, and if the received result indicates that the user is authenticated, the transmitting means transmits the electronic certificate.
[0132] [Supplementary Note 3] The terminal device according to Supplementary Note 1 or 2, wherein the first acquisition means measures the body or voice of the user operating the device at a timing different from the timing at which the first biometric information is acquired, and acquires third biometric information which is biometric information according to the results of the measurement, and the authentication means authenticates the user by comparing the first biometric information with the third biometric information.
[0133] [Supplementary Note 4] A terminal device as described in any of Supplementary Notes 1 to 3, further comprising a receiving means, wherein the transmitting means transmits the electronic certificate and the authentication result to a server that accepts procedures performed by the user, and the receiving means receives implementation status information indicating the implementation status of the procedures based on the transmitted electronic certificate and the authentication result.
[0134] [Supplementary Note 5] The terminal device according to any one of Supplementary Notes 1 to 4, further comprising a document generation unit that generates document information relating to a procedure, wherein the transmission unit further transmits the document information when the user is authenticated.
[0135] [Appendix 6] The terminal device described in Appendix 5 further comprises an encryption means for encrypting the document information, wherein the second acquisition means acquires a private key and a public key corresponding to the private key stored in the information storage medium, the encryption means encrypts the document information based on the private key, and the transmission means transmits the public key and the encrypted document information when the user is authenticated.
[0136] [Supplementary Note 7] The terminal device according to Supplementary Note 5 or 6, wherein the document generation means temporarily stores the generated document information if the user is not authenticated.
[0137] [Supplementary Note 8] A method for assisting in personal identification, comprising: in a terminal operated by a user, measuring the user's body or voice when authenticating the user, and acquiring first biometric information that is biometric information corresponding to the measurement result; acquiring second biometric information that is biometric information corresponding to the person's body or voice and an electronic certificate indicating the authenticity of the person, both of which are stored in an information storage medium; authenticating the user by comparing the first biometric information with the second biometric information; and, if the user is authenticated, transmitting the acquired electronic certificate and the authentication result.
[0138] [Supplementary Note 9] A computer-readable storage medium storing a program that executes the following processes in a terminal operated by a user: measuring the user's body or voice when authenticating the user, and acquiring first biometric information that is biometric information corresponding to the measurement result; acquiring second biometric information that is biometric information corresponding to the person's body or voice, and an electronic certificate indicating the authenticity of the person, which are stored in an information storage medium; authenticating the user by comparing the first biometric information with the second biometric information; and transmitting the acquired electronic certificate and the authentication result when the user is authenticated.
[0139] REFERENCE SIGNS LIST 100, 101 Terminal device 110, 111 First acquisition unit 120 Second acquisition unit 130, 131 Authentication unit 140 Transmission unit 150 Document generation unit 160 Encryption unit 170 Reception unit 180, 181 Photography unit 200 Business operator server 210 Reception unit 220 Notification unit 230 Authentication unit 300 Verification server 1000, 1001 Personal identification support system
Claims
1. a first acquisition means for measuring a body or voice of the user when authenticating the user and acquiring first biometric information corresponding to a result of the measurement; a second acquisition means for acquiring second biometric information, which is biometric information corresponding to the person's body or voice, and an electronic certificate indicating the authenticity of the person, both of which are stored in an information storage medium; an authentication means for authenticating the user by matching the first biometric information with the second biometric information; a transmitting means for transmitting the acquired digital certificate and an authentication result when the user is authenticated; Terminal device.
2. Further comprising receiving means, the transmitting means transmits the first biometric information and the second biometric information to a server capable of performing authentication processing if the user is not authenticated; the receiving means receives information indicating a result of an authentication process based on the first biometric information and the second biometric information; If the received result indicates that the user has been authenticated, the transmitting means transmits the digital certificate. The terminal device according to claim 1 .
3. the first acquisition means measures a body or voice of the user operating the device at a timing different from a timing at which the first biometric information was acquired, and acquires third biometric information that is biometric information corresponding to a result of the measurement; the authentication means authenticates the user by matching the first biometric information with the third biometric information. The terminal device according to claim 1 .
4. Further comprising receiving means, the transmitting means transmits the digital certificate and the authentication result to a server that accepts procedures performed by the user; the receiving means receives implementation status information indicating the implementation status of the procedure based on the transmitted digital certificate and the authentication result. The terminal device according to claim 1 .
5. further comprising a document generation means for generating document information relating to a procedure; the transmitting means further transmits the document information if the user is authenticated. The terminal device according to claim 1 .
6. further comprising an encryption means for encrypting the document information; the second acquisition means acquires a private key and a public key corresponding to the private key, which are stored in the information storage medium; the encryption means encrypts the document information based on the private key; the transmitting means transmits the public key and the encrypted document information if the user is authenticated. The terminal device according to claim 5.
7. the document generation means temporarily stores the generated document information if the user is not authenticated; 7. The terminal device according to claim 5 or 6.
8. On the terminal operated by the user, measuring a body or voice of the user when authenticating the user, and acquiring first biometric information corresponding to a result of the measurement; Acquire second biometric information, which is biometric information corresponding to the person's body or voice, and an electronic certificate indicating the authenticity of the person, both of which are stored in an information storage medium; authenticating the user by matching the first biometric information with the second biometric information; If the user is authenticated, the acquired digital certificate and the authentication result are transmitted. Identity verification assistance methods.
9. On the terminal operated by the user, a process of measuring the user's body or voice when authenticating the user and acquiring first biometric information corresponding to the measurement result; A process of acquiring second biometric information, which is biometric information corresponding to the person's body or voice, and an electronic certificate indicating the authenticity of the person, both of which are stored in an information storage medium; a process of authenticating the user by matching the first biometric information with the second biometric information; If the user is authenticated, the program executes a process of transmitting the acquired electronic certificate and the authentication result.