System, server device, server device control method and program
Patent Information
- Application Number
- JP2024572782
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-04
AI Technical Summary
Users face a significant burden when updating biometric information in biometric information-independent systems, as they must individually comply with varying update requirements from multiple service providers, leading to increased complexity and risk of fraud.
A system where a first server stores biometric information and update requirements for each service, and when updated, it determines if the new biometric information meets the service provider's update requirements, allowing its use for authentication only if the requirements are satisfied, thereby centralizing the verification process.
This approach reduces the user's workload and minimizes the risk of fraud by ensuring that biometric information updates adhere to specific security policies, simplifying the update process and enhancing security across multiple services.
Abstract
Description
System, server device, server device control method and storage medium
[0001] The present invention relates to a system, a server device, a control method for a server device, and a storage medium.
[0002] 2. Description of the Related Art There are technologies for managing personnel information and the like in organizations such as companies.
[0003] For example, Patent Document 1 describes a system for centrally managing personnel information related to multiple companies, organizations, and employees. In the personnel information management system of Patent Document 1, each user terminal is connected to a personnel information management processing server via a network. The personnel information management processing server is equipped with a means for storing and managing information related to multiple companies in a database in a tree structure in which information related to each company's organization is sequentially linked under a parent organization. Upon receiving search criteria and a range specification for companies and organizations from the user terminal, the personnel information management processing server is equipped with a means for sequentially extracting target employees based on the range specification by referencing information related to the company and information related to each company's organization. The personnel information management processing server is equipped with a means for determining whether each extracted employee satisfies the search criteria and transmitting a list of employees matching the search criteria to the user terminal.
[0004] Japanese Patent Application Laid-Open No. 2003-022351
[0005] Among the system configurations that provide services using biometric authentication, there is a biometric information-independent type that centrally manages the biometric information required for authentication. In addition, service providers that provide services to users may have established rules for updating the biometric information used for authentication when providing their services. In a biometric information-independent system configuration, the biometric information used for authentication by each service provider is managed centrally. Therefore, when a user's biometric information is updated, the user must perform procedures in accordance with the update rules of each service provider. As the number of services increases, the burden on the user due to the above procedures increases.
[0006] However, this problem cannot be solved by applying the technology disclosed in Patent Document 1, because Patent Document 1 only discloses a technology for extracting employees who satisfy search conditions, etc.
[0007] The main object of the present invention is to provide a system, a server device, a control method for a server device, and a storage medium that contribute to reducing the burden on users who receive services using biometric authentication when updating registered biometric information.
[0008] According to a first aspect of the present invention, there is provided a system including a first server that stores, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the provided service in association with each other, and a second server operated by a service provider that requests identity authentication of a service recipient from the first server, wherein, when first biometric information stored in the first server is updated to second biometric information, the second server notifies the first server of update requirements based on the service policy of the service provider, and when the stored first biometric information is updated, the first server determines whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, uses the second biometric information for identity authentication when the service is provided.
[0009] According to a second aspect of the present invention, there is provided a server device comprising: a storage means for storing, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the provided service in association with each other; a receiving means for receiving update requirements based on a service policy of a service provider when first biometric information is updated to second biometric information; and an update control means for, when the stored first biometric information is updated, determining whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, using the second biometric information for identity authentication when the service is provided.
[0010] According to a third aspect of the present invention, there is provided a server control method in which, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the provided service are stored in association with each other, and when first biometric information is updated to second biometric information, update requirements based on the service policy of the service provider are received, and when the stored first biometric information is updated, it is determined whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, the second biometric information is used for identity authentication when the service is provided.
[0011] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a server device to execute the following processes: a process of storing, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the provided service in association with each other; a process of receiving update requirements based on a service policy of a service provider when first biometric information is updated to second biometric information; and a process of determining, when the stored first biometric information is updated, whether the second biometric information satisfies the update requirements, and, if the update requirements are satisfied, using the second biometric information for identity authentication when the service is provided.
[0012] According to each aspect of the present invention, a system, a server device, a control method for a server device, and a storage medium are provided that contribute to reducing the burden on users who receive services using biometric authentication when updating registered biometric information. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.
[0013] FIG. 1 is a diagram for explaining an overview of an embodiment. FIG. 2 is a flowchart showing an example of an operation of an embodiment. FIG. 3 is a diagram showing an example of a schematic configuration of an information processing system according to a first embodiment. FIG. 4 is a diagram showing an example of a processing configuration of a management server according to the first embodiment. FIG. 5 is a diagram showing an example of an internal configuration of a verification execution unit according to the first embodiment. FIG. 6 is a diagram showing an example of a processing configuration of a service server according to the first embodiment. FIG. 7 is a diagram showing an example of a display of a terminal according to the first embodiment. FIG. 8 is a diagram showing an example of a user management database according to the first embodiment. FIG. 9 is a diagram showing an example of an action item definition table according to the first embodiment. FIG. 10 is a diagram for explaining the operation of the information processing system according to the first embodiment. FIG. 11 is a diagram showing an example of a used original management database according to the first embodiment. FIG. 12 is a diagram showing an example of a verification content management database according to the first embodiment. FIG. 13 is a diagram for explaining the operation of the information processing system according to the first embodiment. FIG. 14 is a diagram showing an example of a user management database according to the first embodiment. FIG. 15 is a flowchart showing an example of an operation of the verification execution unit according to the first embodiment. FIG. 16 is a sequence diagram showing an example of an operation of the information processing system according to the first embodiment. FIG. 17 is a diagram illustrating an example of a hardware configuration of a management server according to the present disclosure.
[0014] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0015] A system according to one embodiment includes a first server 101 and a second server 102 (see FIG. 1 ). The first server 101 stores, for each of a plurality of users, a service to be provided and biometric information used for identity authentication for the provided service, in association with each other. When the first biometric information stored in the first server 101 is updated with second biometric information, the second server 102 notifies the first server 101 of update requirements based on the service policy of the service provider (step S1 in FIG. 2 ). When the stored first biometric information is updated, the first server 101 determines whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, uses the second biometric information for identity authentication when the service is provided (verification of the update requirements; step S2).
[0016] In recent years, advances in communication technology and information processing technology have led to the provision of a variety of services using biometric authentication. For example, companies are providing services that require personal authentication, such as employee attendance management, entrance / exit management, and in-house cashless payments. In addition, for personal use, services that require personal authentication, such as cashless payments, hotel reservations, and app logins, are being provided.
[0017] Conventionally, in services using biometric authentication, each service provider holds biometric information individually, and such a system configuration can be said to be "biometric information embedded type."
[0018] In this type of biometric information-incorporated system, the service provider holds the user's biometric information individually, which raises concerns that the risk of the user's biometric information being leaked increases as the number of services a user uses increases. Therefore, in response to users' growing awareness of the handling of personal information, a system configuration that manages biometric information independently from the service provider may be adopted. This type of system configuration is called a "biometric information-independent" system. In a biometric information-independent system, each service does not hold biometric information. When a service needs to verify a user's identity, it accesses a system or other system that centrally manages the user's biometric information to perform the authentication.
[0019] Here, a user's registered biometric information may need to be updated for some reason. For example, the quality of the registered face image is poor, causing personal authentication to fail or taking too long. Another example of a reason for updating the registered biometric information is when a registered fingerprint (finger) cannot be used for authentication due to an injury, and a user wants to register another finger as biometric information.
[0020] Next, among the services that service providers offer to users, there are some that are directly linked to the user's assets and some that require strict discrimination against non-users, and security levels are set individually for user identity verification. For example, services related to the user's assets, such as cashless payment services, and services related to entry and exit from the company where the user works, require stricter identity verification, so a high security level is set for identity verification and biometric information updates.
[0021] The same applies to registered biometric information (biometric information used for authentication). If biometric information is easily replaced, it could lead to fraud such as impersonation. Therefore, service providers set requirements for updating biometric information in accordance with their own security policies.
[0022] For example, in a service with a low security level, when updating biometric information, the old and new biometric information are compared and the update is permitted if it is confirmed that the person is the same (principal person). In contrast, in a service with a high security level, the service provider may require an identification document or approval from a third party as an update requirement in addition to the above-mentioned identity verification (confirmation using the identity rate). In this way, when updating registered biometric information, the requirements set by the service provider must be met.
[0023] As mentioned above, each service has its own security level based on its own security policy, and when updating biometric information, the requirements set by the service provider must be met.
[0024] In a biometric information-inclusive system configuration, the biometric information is contained within the service provider. Therefore, when biometric information is updated, it can be updated as long as the biometric information held by the service satisfies the update requirements of that service. However, in a biometric information-independent system configuration, the biometric information is managed uniquely and independently of the service, and various services with different security levels access this biometric information. In this case, when a user updates their biometric information, it affects all services (service providers) they use.
[0025] When biometric information is updated in a biometric information-independent system, the service provider cannot accept the update unless the update requirements in accordance with the company's security policy are met. Therefore, the service provider requests the user to carry out the procedures stipulated in the company's biometric information update requirements. The user must individually comply with the update requirements demanded by each service provider. This requires compliance for all services the user uses, which creates a significant burden.
[0026] For example, if a user receives services from three companies, Service A, Service B, and Service C, and each company requires the user to "present identification" in addition to verifying their identity with the old and new biometric information as a requirement for updating their biometric information, and the user is unable to smoothly verify their identity using the biometric information of Service A and updates their biometric information, the three service providers will require the user to "present identification" in addition to verifying their identity with the old and new biometric information. The user would have to "present identification" individually to each of the three service providers and have their biometric information updated.
[0027] To solve the above-mentioned problems in a biometric information-independent system, in the system disclosed herein, a first server 101 stores and manages biometric information used for user authentication. The first server 101 stores the biometric information used for user authentication and update requirements for the biometric information for each service provided to the user. When a user updates their original biometric information, the first server 101 collectively verifies the update requirements for each service affected by the update. As a result, the user's work (work that the user had to perform) required for updating biometric information is reduced, reducing the burden on the user.
[0028] Specific embodiments will be described in more detail below with reference to the drawings.
[0029] First Embodiment The first embodiment will be described in more detail with reference to the drawings.
[0030] [System Configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an information processing system (authentication system) according to the first embodiment. As shown in Fig. 3, the information processing system includes a biometric information management service center (hereinafter referred to as a management center) and multiple service providers.
[0031] The information processing system according to the first embodiment is operated in a biometric information-independent system configuration. In the biometric information-independent system, the original biometric information used for identity verification when using a service is managed independently from the service provider. In the example of Fig. 3, a management center that is a separate organization from each service provider manages all biometric information collectively. When a service performs identity verification of a user, it obtains the necessary biometric information from the management center and compares it with the biometric information acquired by the service to verify the identity of the user.
[0032] In a biometric information-independent authentication system, users can select and use any service they like. When using a service, users register that their biometric information is stored in a management center, and the service obtains the original biometric information from the management center when authenticating the user. The user's identity is verified based on this information, and once the user's identity is confirmed, the user can use the service.
[0033] The management center includes a management server 10 .
[0034] The management server 10 is a server that realizes the main functions of the management center. The management server 10 stores and manages user account information (a unique number for identifying a user) and personal information (user information (such as name, address, and telephone number) and biometric information).
[0035] To register a user, a terminal 40 such as a smartphone is used. The user operates the terminal 40 to access the management server 10 or the like and registers the user's personal information.
[0036] The management server 10 also provides authentication services to service providers. In response to a request from a service provider, the management server 10 authenticates (authenticates or verifies) the identity of a service recipient who wishes to receive a service from the service provider.
[0037] Each service provider has a contract with the management center, and the management center provides authentication services to each service provider with which the contract has been concluded.
[0038] Each service provider has a service server 20 and an authentication terminal 30 .
[0039] The service server 20 is operated and managed by the service provider. The service server 20 is a server that realizes the main functions of the service provider. When a user accesses the service server 20, the service server 20 collects predetermined biometric information, queries the management center for personal authentication, and determines whether the user is allowed to use its own services based on the response from the management center.
[0040] The authentication terminal 30 is a device that serves as an interface for users who receive services. The authentication terminal 30 is installed at the service providing location of each service provider. For example, the authentication terminal 30 is installed in a location where users actually visit, such as an office or a retail store.
[0041] 3, the devices included in the information processing system (the management server 10, the service server 20, and the authentication terminal 30) are connected to each other so that they can communicate with each other. For example, the service server 20 and the authentication terminal 30 are connected by wired or wireless communication means.
[0042] 3 is merely an example and is not intended to limit the configuration of the information processing system disclosed in the present application. For example, the management center may include two or more management servers 10.
[0043] [System Operation] The operation of the information processing system according to the first embodiment can be divided into four phases.
[0044] The first phase is a phase in which the user registers their own information (personal information) with the management center. The registration operation performed in the first phase is referred to as "user registration" or "system registration." The user registers their user information and biometric information with the management server 10 on a portal site provided by the management center.
[0045] The second phase is composed of a phase in which the user registers the services he / she uses, and a phase in which the update requirements for biometric information set by the services are registered.
[0046] First, the user registers their usage permission with the service provider at any time. This registration process is referred to as "user registration." The service provider registers information about the user to whom the service is to be provided, information about the services provided to the user, and information about the method used for identity authentication, etc., with the management center.
[0047] Here, "user registration" allows a user to add and register multiple services at any time.
[0048] Next, update requirements in accordance with the security policy of the service are registered. This registration operation is referred to as “update requirement registration.” The service provider sets update requirements in accordance with its own security policy and requests the management server 10 to register this information as update requirements.
[0049] When the second phase is completed, the management server 10 registers information necessary for identity verification for the service used by the user and update requirements necessary when updating biometric information.
[0050] The third phase is when the service provider verifies the identity of the user with the management center when the user uses the service. When the user uses the service, identity verification is performed. The service sends the information required for identity verification to the management center and requests identity verification (identity authentication) from the management center. The service provider provides the service to users (authenticated persons) who have been successfully authenticated.
[0051] The fourth phase is when a user updates their biometric information, and a decision is made for each service the user uses as to whether or not the biometric information can be updated. The user updates the biometric information registered with the management center. When the user updates their biometric information, the management center checks and verifies the updated biometric information. The management center authenticates the service recipient using biometric information that has been successfully verified.
[0052] Next, a detailed description will be given of the configuration and operation of each device included in the information processing system according to the first embodiment. Below, an overview of the processing modules of each device will be given, and then the detailed operation of each processing module in each of the above four phases will be given.
[0053] [Management Server] Fig. 4 is a diagram showing an example of the processing configuration (processing modules) of the management server 10 according to the first embodiment. Referring to Fig. 4, the management server 10 includes a communication control unit 201, a user management unit 202, a service registration control unit 203, an identity authentication unit 204, an update control unit 205, a verification execution unit 206, and a storage unit 207.
[0054] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. The communication control unit 201 also transmits data to the service server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0055] The user management unit 202 is a means for managing information (user information, biometric information) of each user who uses the system.
[0056] The user information includes account information that is uniquely assigned to each user, as well as the user's name, address, date of birth, email address, telephone number, etc.
[0057] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as the face, fingerprints, ears, voiceprints, palms (veins), retinas, and iris patterns. Alternatively, biometric information may be image data such as face images and fingerprint images. The biometric information may be any information that includes the user's physical characteristics.
[0058] In the following description, the biometric information managed by the management server 10 will be referred to as “registered original biometric information” or simply as “original biometric information.” For example, the management server 10 manages and stores data such as a face image and a fingerprint image of a user as “registered original biometric information.”
[0059] The registered original biometric information is used as the original (master) of the user's biometric information when authenticating the user. The user can register any type of biometric information with the management center.
[0060] The user management unit 202 acquires and stores user information (personal information, such as name and address) and original biometric information (such as a face image or fingerprint image) from the user by any means. When registering for the first time, the user management unit 202 generates account information that is uniquely assigned to the user and registers it as user information.
[0061] The service registration control unit 203 is a means for controlling service registration by a service provider. The service registration control unit 203 receives a "service registration request" from the service server 20 and processes the request. The service registration control unit 203 also receives update requirement information for biometric information update from the service server 20, and performs correspondence between the service information used by the user, the original biometric information used by the service for identity verification, and the biometric information update requirements.
[0062] The personal authentication unit 204 is a means for authenticating (confirming the identity of) a user who wishes to receive a service from a service provider. Upon receiving an "authentication request" from the service server 20, the personal authentication unit 204 executes personal authentication (confirmation of the identity of the user).
[0063] More specifically, the personal authentication unit 204 obtains its own service information, account information for identifying the user, and biometric information collected on the service side (matching side biometric information: biometric information of the user visiting the service providing location) from the service server 20. Next, the personal authentication unit 204 identifies the registered original biometric information of the user based on the service information and account information, and performs personal authentication using the biometric information collected on the service side.
[0064] The update control unit 205 is a means for executing control related to updating of registered original biometric information. The update control unit 205 acquires updated original biometric information (new original biometric information) from the user via the user management unit 202. The update control unit 205 also controls verification of the new original biometric information itself and confirmation (identity verification, third-party verification) associated with the update of the original biometric information.
[0065] Here, each service provider defines biometric information update requirements (hereinafter referred to as original update requirements) in accordance with the security policy of the service it provides. The original update requirements are requirements for accepting new registered original biometric information (second biometric information) when the registered original biometric information (first biometric information) stored in the management server 10 is updated to the new registered original biometric information. The original update requirements are requirements specified for each service, or in other words, the original update requirements are requirements (conditions) for the service provider to permit updating of biometric information used for identity authentication of service recipients.
[0066] For example, if a "face" is used for identity authentication in a cashless payment service and the face image registered in the management center is updated, the original update requirement is a requirement for using the updated face image for identity authentication in the cashless payment service. For example, if a service provider sets the original update requirement as a similarity (matching degree) between the old and new face images being equal to or greater than a predetermined value, the update is permitted if the new face image is equal to or greater than the predetermined value.
[0067] In other words, even if a user updates the biometric information (original biometric information) registered with the management center, if the updated original biometric information does not satisfy the original update requirements set by the service provider, the updated original biometric information will not be used for identity authentication. In this case, the original biometric information used for identity authentication will be the original biometric information before the update.
[0068] The original data update requirement is composed of at least one verification item (implementation item, confirmation item). For example, a verification item may be a confirmation that the degree of match between the old and new original biometric information is equal to or greater than a predetermined value.
[0069] The management server 10 acquires and stores the original data update requirements defined by each service provider when registering a service. When a user updates their original biometric information, the update control unit 205 verifies the original data update requirements corresponding to the service provided to the user. Specifically, the update control unit 205 executes verification of at least one or more verification items constituting the original data update request.
[0070] If the update control unit 205 succeeds in verifying each verification item constituting the original update requirements defined by the service provider, it permits updating of the original biometric information used for identity authentication of the service provided by the service provider. That is, if the update control unit 205 succeeds in verifying each implementation content defined in the original update requirements, it updates the registered original biometric information (master information; for example, a face image or a fingerprint image) used for identity authentication when the service is provided.
[0071] The verification execution unit 206 is a means for executing the verification content of each verification item that constitutes the original document update requirements. The verification execution unit 206 includes a plurality of execution means (execution modules). Specifically, as shown in FIG. 5, the verification execution unit 206 includes execution units 206a to 206d. The specific processing of each of the execution units 206a to 206d will be described later.
[0072] The storage unit 207 is a means for storing information necessary for the operation of the management server 10 .
[0073] [Service Server] Fig. 6 is a diagram showing an example of the processing configuration (processing modules) of the service server 20 according to the first embodiment. Referring to Fig. 6, the service server 20 includes a communication control unit 301, an update requirement control unit 302, a service registration management unit 303, an authentication control unit 304, a service providing unit 305, and a storage unit 306.
[0074] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the management server 10. The communication control unit 301 also transmits data to the management server 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0075] The update requirement control unit 302 is a means for controlling the "original update requirement" that the service provider pre-registers in the management center. The update requirement control unit 302 creates the "original update requirement" based on the biometric information update information specified by the management center in accordance with its own security policy, and this information is registered in the management server 10 via the service registration management unit 303.
[0076] The service registration management unit 303 is a means for controlling and managing the registration of services provided to users.
[0077] When a user wishes to receive a service, the service registration management unit 303 registers the user information and biometric information registration destination information (account information and connection destination information) in its own (its own company's) service server 20. Next, the service registration control unit 303 accesses the management server 10 based on the previously registered biometric information registration destination information, and registers its own service in the management server 10.
[0078] Here, the user information, the service information itself, and the "original update requirements" created by the update requirement control unit 302 are registered. As a result, information about the service itself is registered in the management server 10.
[0079] The authentication control unit 304 is a means for controlling the personal authentication performed when a service is provided to a user. When a user accesses the company's service (when the user uses the company's service), the authentication control unit 304 requests personal authentication from the management center. Specifically, the authentication control unit 304 sends information that the management server 10 can use to perform biometric authentication (its own service information, account information, and biometric information acquired by its own service) and requests the management server 10 to verify the user's identity.
[0080] The authentication control unit 304 receives a response from the management server 10 and performs a biometric authentication determination.
[0081] The service providing unit 305 is a means for providing services to users. After the authentication control unit 304 determines that the user is the registered person, the service is provided. For example, the service providing unit 305 provides biometric authentication services such as cashless payment and entrance / exit management to users.
[0082] The storage unit 306 is a means for storing information necessary for the operation of the service server 20 .
[0083] [Authentication Terminal] The authentication terminal 30 is exemplified by a terminal such as a tablet equipped with a camera device. The configuration of the authentication terminal 30 is clear to those skilled in the art, so detailed description will be omitted. For example, the authentication terminal 30 photographs the user and acquires a facial image of the user. The authentication terminal 30 transmits the acquired biometric information (facial image) and the like to the service server 20. The authentication terminal 30 provides services to the user in accordance with instructions from the service server 20.
[0084] Here, since the authentication terminal 30 is operated in a manner that does not identify the user, when the user uses the authentication terminal 30, it has a means for registering (obtaining) the user's account information, and the account information and the obtained biometric information (facial image) are notified to the service server 20.
[0085] The authentication terminal 30 may not be in the form described above, but may be in the form of, for example, an app that is launched on an individual's smartphone. In this case, since the user of the app is limited to the individual himself / herself, account information may be registered in advance, and the biometric information (facial image) and account information obtained by the app may be notified to the service server 20.
[0086] [Terminal] Examples of the terminal 40 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers). The terminal 40 can be any equipment or device that can accept user operations and communicate with the management server 10, etc. Furthermore, the configuration of the terminal 40 is clear to those skilled in the art, so detailed explanation will be omitted.
[0087] <First Phase (System Registration Operation)> In the first phase, the user registers his / her own user information, biometric information, etc. with the management center.
[0088] Regarding the first phase, the information processing system according to the first embodiment is based on the following assumptions.
[0089] A user can access the management server 10 by operating a terminal 40 that the user owns. Here, the user can register and manage the user's biometric information from a portal site provided by the management server 10. The management server 10 can be accessed using authentication means such as single sign-on, but this is not the main subject of this specification and therefore will not be described here. The terminal 40 is equipped with means (camera, fingerprint sensor, etc.) for collecting and acquiring at least one type of biometric information such as face, fingerprint, and iris. A detailed description of the means for acquiring biometric information will be omitted.
[0090] The first phase will be described below using a specific example of a user (Yamada Taro) who registers his face image and fingerprint image in the management center.
[0091] First, the user (Yamada Taro) logs in to the portal site by operating the terminal 40. The user (Yamada Taro) performs procedures related to user registration (system registration) on the portal site.
[0092] The user management unit 202 of the management server 10 acquires user information (personal information) and biometric information of the user using a registration form, a GUI (Graphical User Interface), etc. For example, the user management unit 202 prompts the user to input user information and biometric information using a registration form such as that shown in FIG.
[0093] For example, a user (Yamada Taro) enters his / her name, email address, address, phone number, etc. into a registration form as user information. In addition, the user (Yamada Taro) registers a face image and a fingerprint image as biometric information, but selects not to register an iris image, ear image, etc.
[0094] When the user management unit 202 acquires user information and biometric information using a registration form or the like, it searches the user management database using all or part of the user information (for example, name or email address) as a key (see FIG. 8).
[0095] The user management database shown in Fig. 8 is a database for managing user information and original biometric information of users who have completed user registration (system registration). The user management database shown in Fig. 8 is an example and is not intended to limit the items to be stored.
[0096] If the acquired user information is registered in the user management database, the user management unit 202 determines that the user (Yamada Taro) has already completed user registration. In this case, the user management unit 202 notifies the user to that effect.
[0097] If the acquired user information is not registered in the user management database, the user management unit 202 executes a new user registration process.
[0098] Specifically, the user management unit 202 verifies the acquired biometric information. For example, if biometric information different from the biometric information selected by the user is registered, the user management unit 202 refuses to accept the acquired biometric information. For example, if a fingerprint image is registered as a face image, the user management unit 202 determines that there is a problem with the acquired biometric information and refuses to accept it.
[0099] The above determination can be made using a learning model obtained by machine learning. The learning model is obtained by machine learning using training data in which labels (face, fingerprint) are assigned to a large number of image data (face images and fingerprint images). Any algorithm such as a support vector machine, boosting, or neural network can be used to generate the learning model. Note that known techniques can be used for the algorithms such as the support vector machine, and therefore a description thereof will be omitted.
[0100] If no problem is found in the biometric information acquired from the user, the user management unit 202 generates account information that is uniquely assigned to the user, and adds a new entry to the user management database together with the account information.
[0101] At this time, the user management unit 202 assigns an ID (hereinafter referred to as an original ID) to each of at least one piece of biometric information (registered original biometric information) acquired from the user. For example, the user management unit 202 assigns an original ID every time it acquires original biometric information.
[0102] Furthermore, the user management unit 202 generates original information indicating the type and generation of the acquired registered original biometric information. The generation of the original biometric information acquired during user registration is the "first generation." If new original biometric information is subsequently added (updated), the generation of the original biometric information becomes the "second generation."
[0103] For example, when a face image is registered during user registration, the user management unit 202 generates "Face 1" as the original information. Similarly, when a fingerprint image is registered during user registration, the user management unit 202 generates "Fingerprint 1" as the original information.
[0104] The user management unit 202 registers the original ID, original information, etc. in the new entry added to the user management database.
[0105] In the above example, for the face image (registered face data), "ID1" is registered as the original ID and "Face 1" is registered as the original information. Also, for the fingerprint image (registered fingerprint data), "ID2" is registered as the original ID and "Fingerprint 1" is registered as the original information. Next, the user management unit 202 generates account information that is uniquely assigned to the user. The account information is registered in the account information field.
[0106] Once this information is registered in the user management database, the user management unit 202 notifies the user that user registration is complete. The user is then notified of their account information and the information required to connect to the management center. This information allows the user to connect to the management center when using a service.
[0107] Users can log in to the management center's portal site at any time and add or update their own user information and biometric information.
[0108] <Second Phase (Service Registration Operation)> The second phase consists of a "user registration phase" in which each service provider registers the services they use with the management center, and an "update requirement registration phase" in which they notify the biometric information update requirements set by the service.
[0109] First, the "user registration phase" will be explained.
[0110] Once the first phase (user registration, system registration) is complete, the user decides which service he or she wishes to use from among a plurality of services (various services).
[0111] The service provider performs an initial registration (service registration, service usage registration) regarding the service that the user wishes to receive.
[0112] Regarding the second phase, the information processing system according to the first embodiment is based on the following assumptions.
[0113] A user who wishes to receive a service will notify the service provider, and the service provider will obtain the information necessary to provide the service to the user.
[0114] The user registers personal information and registration information.
[0115] As the first type of personal information, user information (personal information; for example, name, address, email address, telephone number, etc.) is registered, and this information is stored in the service server 20.
[0116] The second piece of registration information is information for connecting to the location where the user's biometric information is registered. In this case, since the user's biometric information is registered at the management center, connection information to the management center (connection information to the management center and account information for identifying the user) is registered.
[0117] The registration destination information enables the service provider (service server 20) to connect to the location where the biometric information is registered when verifying the identity of the user.
[0118] Here, with regard to connection to the management center, the service server 20 connects to the management server 10 based on the registration destination information. When connecting to the management server 10, the service server 20 transmits an ID and a password to the management server 10 as in a single sign-on system, and performs connection authentication, but a detailed description of the authentication etc. will be omitted.
[0119] Next, the "update requirement registration phase" will be explained.
[0120] In this phase, after the completion of the "user registration phase," the service provider connects to the management center and registers update requirements in accordance with their own security policy when updating biometric information.
[0121] When a user's original biometric information is updated, the service provider defines original update requirements for accepting the update. In the present disclosure, when updating biometric information, the means for implementing the original update requirements (original update implementation means), which was previously implemented on the service side, is provided on the management center side (the original update requirements are implemented on the management center side). For this reason, the management center has several original update implementation means that were previously implemented by the service provider, and these provide information to each service provider as "actionable item" information. Each service creates update requirements based on the "actionable item" information disclosed by the management center and its own security policy, and registers the update requirements when the service updates biometric information with the management center.
[0122] Items that can be implemented by the management center (hereinafter simply referred to as implementation items) are stored in an implementation item definition table (see FIG. 9).
[0123] Specifically, each service provider is provided with an action item definition table such as that shown in Fig. 9. In other words, the information described in the action item definition table is shared between the management center and the service provider.
[0124] The action item definition table shown in FIG. 9 is composed of an action item ID for identifying an action item, an outline of the action item, and parameters (parameters required when executing each action item).
[0125] For example, the content of an action item (verification item) with an action item ID of "A" is "verify the identity ratio between the registered original and the updated original." When executing this action item, the management center checks the match ratio between the registered original biometric information and the new original biometric information (biometric information to be updated). In this action item, a threshold value for the match ratio is set as a parameter. In this case, if the match ratio between the registered original biometric information and the new original biometric information exceeds the threshold, the verification for action item A (the action item with action item ID "A," the same applies hereinafter) is determined to be successful.
[0126] The content of the action item with the action item ID "B" is "approval confirmation by a third party." When executing this action item, the management center requests approval for updating the original biometric information from a third party other than the user (for example, the user's boss). In action item B (the action item with the action item ID "B," the same applies below), the contact email address of the third party who will give approval is set as a parameter.
[0127] The content of the action item with action item ID "C" is "identity verification using identification card." When this action item is executed, the management center requests the user to present an identification card when updating the original biometric information. In action item C (the action item with action item ID "C," the same applies below), the type of identification card that the user is required to present is set as a parameter.
[0128] The action item with the action item ID "D" is "identity verification by email." When this action item is executed, the management center will verify the identity of the user using the user's email address. In action item D (the action item with the action item ID "D," the same applies below), the email address to which the inquiry email will be sent is set as a parameter.
[0129] Note that the action item definition table shown in FIG. 9 is an example and is not intended to limit the contents thereof. The management center may check and verify contents different from those shown in FIG. 9. For example, verification and confirmation of the quality of new biometric information (updated biometric information) may be performed. For example, verification of the size (face size) and brightness of the facial image may be performed. The management center can perform any action item (verification item). Furthermore, the contents of the action item definition table can be modified or added as appropriate.
[0130] In addition, in Fig. 9, the action items to be performed when updating the original biometric information are expressed using parameters, but the action items may be expressed in other formats. Note that in Fig. 9, the parameters are specifically described, such as "passport," for ease of understanding.
[0131] The update requirement control unit 302 of the service server 20 obtains an action item definition table such as that shown in Fig. 9 from the management center by any means. For example, a person in charge of the service provider receives a USB (Universal Serial Bus) memory storing the action item definition table from the management center and connects the USB memory to the service server 20. The update requirement control unit 302 obtains the action item definition table from the USB memory.
[0132] The update requirement control unit 302 presents the acquired action item definition table (list information of candidates and details of action items that can be set in the original update request) to a security officer or the like of the service provider.
[0133] The security officer determines the original document update requirements for each service provided by his / her company based on the presented information (table information as shown in Figure 9) and his / her company's security policy. The security officer refers to the action item definition table disclosed by the management center and determines the original document update requirements in accordance with his / her company's security policy.
[0134] For example, if a service provider can provide four services, services A to D, to a user, the security officer determines the original document update requirements for each of services A to D.
[0135] The update requirement control unit 302 acquires the original update requirements determined by the security officer by any means. For example, the update requirement control unit 302 provides the security officer with a GUI or the like for inputting the original update requirements.
[0136] For example, a security officer selects three action items (e.g., action items A, B, and D) from four possible action items disclosed by the management center as original document update requirements for a cashless payment service.
[0137] The security officer also determines the parameters for each action item. For example, the security officer determines "80" as the parameter (threshold information) for action item A, the email address of the user's boss as the parameter for action item B, and the email address of the user himself as the parameter for action item D.
[0138] The original update requirements generated by the update requirement control unit 302 are notified to the management center when the service is registered.
[0139] The second phase will be explained below, assuming that a user (Taro Yamada) uses cashless payment to make payments for work-related expenses. As mentioned above, the original document update requirements for the cashless payment service have already been determined by the security officer. In addition, the authentication method for identity verification for the cashless payment service has been determined to be facial recognition.
[0140] First, the "user registration phase" will be described. When the service registration management unit 303 receives an offer from a user to receive a service, it controls and manages the service registration of the user. When it receives information necessary for providing a service to the user, the service registration management unit 303 accesses the management server 10.
[0141] Specifically, the service registration management unit 303 notifies the management server 10 of service information (service ID) related to the service provided to the user, user information (account information), and the type of biometric information (authentication method) used for personal authentication.
[0142] The service information (service ID) is information that allows a service provider to identify its own service. Hereinafter, the service ID of the cashless payment service will be referred to as "Service A."
[0143] The service registration management unit 303 transmits a service registration request including service information, user information, and an authentication method to the management server 10 (see FIG. 10 ). In the above example, a service registration request including the cashless payment service "Service A," the user information "Account Information," and the biometric authentication type "Face" is transmitted to the management server 10.
[0144] The management server 10 receives the service registration request. The service registration control unit 203 of the management server 10 processes the received service registration request. Upon receiving the service registration request, the service registration control unit 203 searches the user management database using the account information of the user information included in the request as a key.
[0145] If the search result shows that the account information of the user information acquired from the service provider is not registered in the user management database, the service registration control unit 203 notifies the service provider that the service registration has failed. Specifically, the service registration control unit 203 sends a negative response to the service server 20 indicating that the service registration for the user has failed.
[0146] If the account information of the user information is registered in the user management database, the service registration control unit 203 determines whether the type of biometric authentication corresponding to the authentication method (type of biometric information used to authenticate the user) included in the system registration request is registered in the user management database.
[0147] Specifically, the service registration control unit 203 checks whether the notified type of biometric authentication is registered in the original ID of the user management database of FIG.
[0148] If the type of biometric authentication is not registered, the service registration control unit 203 transmits a negative response indicating that the service registration has failed to the service server 20 .
[0149] If the type of biometric authentication is registered, the service registration control unit 203 associates and manages the service selected by the user (service A enjoyed by the user: cashless payment service) with the type of biometric authentication used in that service.
[0150] Specifically, the service registration control unit 203 uses a usage original data management database to manage services provided to users and the biometric authentication types used in those services (see FIG. 11). Note that the usage original data management database shown in FIG. 11 is an example and is not intended to limit the items to be stored. Furthermore, a usage original data management database is prepared for each user. The usage original data management database shown in FIG. 11 is a database prepared for a user (Yamada Taro).
[0151] The service registration control unit 203 sets "Initial setting in progress" in the status field of Fig. 11, and then sets the service information (service ID) notified by the service provider in the used service field. Furthermore, the service registration control unit 203 confirms (obtains) the ID number from the original ID field of Fig. 8 regarding the biometric authentication type, and sets the ID number in the used original field.
[0152] In this example, if the user is "Yamada Taro" and the authentication method is "face authentication," "ID1" is set in the used original field. Note that the status field can be set to initial setting, in operation, original update in progress, etc.
[0153] When the service ID and the original ID are registered in the original document usage management database, the service registration control unit 203 transmits an affirmative response to the service server 20 indicating that the service registration for the user has been successful.
[0154] At this point, nothing is set in the verification item field or check result field of the original document used management database. These will be set after the "update requirement registration phase" is completed.
[0155] In this way, the management server 10 processes the service registration request received from the service server 20 and transmits a response to the request to the service server 20 (see FIG. 10).
[0156] The service server 20 receives a response to the service registration request from the management server 10. More specifically, the service registration management unit 303 of the service server 20 receives the response (positive response, negative response) to the service registration request.
[0157] When a negative response (service registration failure) is received, the service registration management unit 303 notifies the user (Yamada Taro) that the service registration has failed.
[0158] Next, the "update requirement registration phase" will be described. After the "user registration phase" is completed, the service registration management unit 303 notifies the management center of the original update requirements determined by the security officer. In the above example, the combination of action items A, B, and D determined by the security officer and the corresponding parameters is notified to the management center as the "original update requirements."
[0159] More specifically, the service registration management unit 303 sends an "update requirement setting request" including a combination of the implementation item ID and corresponding parameters of each implementation item as the original update requirement, along with the user's account information as the update requirement setting to the management server 10 (see Figure 10).
[0160] The management server 10 receives the update requirement setting request, and the service registration control unit 203 of the management server 10 processes the update requirement setting request.
[0161] When an update requirement setting request is received, the service registration control unit 203 determines whether the original update requirements included in the request conform to the conditions (format) defined by the management center. Specifically, the service registration control unit 203 determines whether each action item included in the original update requirements acquired from the service provider conforms to (is consistent with) the contents described in the action item definition table shown in FIG.
[0162] If the original document update requirements include an action item that does not conform to the contents of the action item definition table, the service registration control unit 203 notifies the service provider that the management center cannot comply with the original document update requirements notified by the service provider. Specifically, the service registration control unit 203 sends a negative response to the service server 20 indicating that the setting of the original document update requirements has failed.
[0163] For example, if the parameter combined with the action content of the original document update requirement is not written in the action item definition table, the service registration control unit 203 sends the above-mentioned negative response to the service server 20 .
[0164] If each action item constituting the original document update requirements matches the contents of the action item definition table, the service registration control unit 203 identifies the user based on the received account information and stores the specific verification content determined from each action item and its parameters in the verification content management database (FIG. 12). Note that the verification content management database shown in FIG. 12 is an example and is not intended to limit the items to be stored.
[0165] Specifically, the service registration control unit 203 creates the verification content management database shown in Fig. 12 based on the received action item ID information and parameter information. The service registration control unit 203 first checks whether the received action item ID information and parameter information have already been registered in the verification content management database.
[0166] If the received action item ID information and parameter information are not registered, the service registration control unit 203 creates a unique verification item ID and sets it in the verification item ID field. At this time, if the same action item has different parameters, a different verification item ID is assigned. Next, the service registration control unit 203 sets the received action item ID information in the action item ID field. The service registration control unit 203 sets the received parameter information in the parameter field.
[0167] If the received action item ID information and parameter information have been registered, the service registration control unit 203 determines that the information has already been registered and does nothing.
[0168] Here, the service registration control unit 203 sets the checked verification item ID in the verification item field of FIG. 11, and then sets "check OK" in the check result field.
[0169] Next, the service registration control unit 203 performs settings for all verification item IDs acquired from the service provider. If all check result fields show "Check OK," the necessary settings for the corresponding service have been completed, and the service registration control unit 203 sets "In operation" in the status field of the original usage management database. The service registration control unit 203 performs this operation for all services registered in the service usage field.
[0170] As a result of the above, the second phase, the ``user registration phase'' and the ``update requirement registration phase'', have been completed, and the service registration control unit 203 sends a positive response to the service server 20 indicating that the original update requirements have been successfully set.
[0171] The service server 20 receives a response (positive response or negative response) to the update requirement setting request. The service registration management unit 303 of the service server 20 performs processing according to the received result.
[0172] For example, if a positive response (setting of the update requirements has been successful) is received, the service registration management unit 303 notifies the user, the security officer of the service provider, etc. Alternatively, if a negative response (setting of the update requirements has failed) is received, the service registration management unit 303 notifies the user, the security officer of the service provider, etc.
[0173] The operation of service registration in the information processing system according to the first embodiment is as described above. The above operation is executed every time a user adds (selects) a service. Note that the user can add the service at any time.
[0174] For example, when a user (Yamada Taro) adds services B to D, the original document usage management database will be in the state shown in FIG.
[0175] In this way, the service server 20 (second server) notifies the management server 10 (first server) of the original update requirements for the service recipient before the service provider provides the service to the service recipient. By each service provider making such a notification, when the original biometric information is updated, the management center can process the update requirements (update requirements for each service) determined by each service provider in a lump sum. In other words, the user does not need to individually perform the verification items determined by each service provider.
[0176] <Third Phase (Service Provision)> In the third phase, the service provider provides the service to the user. In the third phase, when the user uses the service (receives the service from the service provider), the service provider requests the management center to authenticate the user.
[0177] Regarding the third phase, the information processing system according to the first embodiment is based on the following assumptions.
[0178] The service server 20 connects to the management server 10 when authenticating the user. When connecting to the management server 10, the service server 20 transmits an ID and a password to the management server 10, as in a single sign-on system. The management server 10 authenticates the service server 20 using the ID and password. Note that a detailed description of the authentication will be omitted.
[0179] The management server 10 compares the biometric information received from the service provider with the original biometric information registered in advance to perform identity authentication. The management center notifies the service provider of the authentication result (authentication success or authentication failure).
[0180] A user receives a service from a service provider via the authentication terminal 30. The authentication terminal 30 acquires biometric information of the user who wishes to receive the service. The user also presents account information (information uniquely assigned to the user registered with the management center) as their own user information to the service provider (authentication terminal 30). The authentication terminal 30 transmits the acquired biometric information and user information to the service server 20. The service server 20 transmits the acquired biometric information, user information, etc. to the management server 10 to request identity authentication. When the management server 10 successfully authenticates the user's identity, the service server 20 provides the user with a service via the authentication terminal 30.
[0181] A service provider can provide any service using biometric authentication to a user. Detailed explanations of individual services will be omitted here because the realization of individual services is outside the scope of the present disclosure.
[0182] The following describes a case where a user (Yamada Taro) receives a cashless payment service (service A) from a service provider. The biometric information used in the cashless payment service is a face image.
[0183] The authentication control unit 304 of the service server 20 controls the authentication of the user.
[0184] When the face image of the user is acquired via the authentication terminal 30, the authentication control unit 304 generates features from the acquired face image (the face image is converted into feature data).
[0185] The authentication control unit 304 generates identity verification data from a combination of feature data, service information (service ID of the service provided to the user; service A in the above example), user information (account information), and identity rate threshold.
[0186] The identity rate threshold is a value that is set in advance in the service server 20 by a security officer or the like of the service provider. The security officer determines a threshold value for the match rate (similarity) required for determining that a user is the “identity” and sets it in the service server 20.
[0187] The authentication control unit 304 transmits an authentication request including the personal identification data to the management server 10 (see FIG. 13).
[0188] The management server 10 receives the personal authentication request, and the personal authentication unit 204 of the management server 10 processes the personal authentication request.
[0189] When receiving a personal authentication request from a service provider, the personal authentication unit 204 refers to the user management database using the user information (account information) included in the request as a key, and identifies the corresponding user.
[0190] If the user corresponding to the user information is not registered in the user management database, the personal authentication unit 204 notifies the service provider that personal authentication has failed. Specifically, the personal authentication unit 204 sends a negative response indicating that personal authentication has failed to the service server 20.
[0191] Furthermore, the authentication unit 204 uses the service ID and user information included in the authentication request to identify the original document management database used by the corresponding user.
[0192] Even if the user information is registered in the user management database, if the service information (service ID) acquired from the service provider is not registered in the original usage management database, the personal authentication unit 204 notifies the service provider that personal authentication has failed. Specifically, the personal authentication unit 204 transmits a negative response indicating that personal authentication has failed to the service server 20.
[0193] If the user information and service ID are registered in the database, the identity authentication unit 204 reads out the original ID set in the used original field of the entry in the used original management database that corresponds to the service ID acquired from the service provider. In the above example, the identity authentication unit 204 reads out "ID1" from the used original field.
[0194] Thereafter, the identity authentication unit 204 refers to the user management table using the read original ID, and reads the original biometric information corresponding to the read original ID from the original information field. In the above example, the identity authentication unit 204 reads the face image data (face image data corresponding to face 1) as the original biometric information.
[0195] The identity authentication unit 204 performs identity authentication using the read original biometric information. For example, the identity authentication unit 204 calculates feature data from the read original biometric information. The identity authentication unit 204 performs a matching process (one-to-one matching) using the feature data calculated from the original biometric information and the feature data acquired from the service provider. The identity authentication unit 204 calculates the similarity (matching degree) between the two feature data as the "identity rate."
[0196] The personal authentication unit 204 compares the calculated personal identity rate with the personal identity rate threshold received from the service provider, and determines that personal authentication is successful if the personal identity rate is equal to or greater than the personal identity verification threshold. If the personal identity rate is smaller than the personal identity verification threshold, the personal authentication unit 204 determines that personal authentication is unsuccessful.
[0197] The personal authentication unit 204 notifies the service provider of the authentication result (personal authentication success, personal authentication failure). If personal authentication is successful, the personal authentication unit 204 sends a positive response indicating that to the service server 20. If personal authentication is unsuccessful, the personal authentication unit 204 sends a negative response indicating that to the service server 20.
[0198] The service server 20 receives the response to the personal authentication request (see FIG. 13). The service providing unit 305 of the service server 20 performs processing according to the authentication result.
[0199] If the personal authentication is successful (a positive response is received), the service providing unit 305 provides a service to the user via the authentication terminal 30. In the above example, the service providing unit 305 provides a cashless payment service to the user (Yamada Taro).
[0200] If the personal authentication fails (a negative response is received), the service providing unit 305 notifies the user via the authentication terminal 30 that the service cannot be provided.
[0201] <Fourth Phase (Update Operation)> In the fourth phase, when a user updates his / her biometric information, the management center (management server 10) determines whether or not to update the biometric information for all services that use the updated biometric information. The fourth phase consists of an "update determination phase" in which a determination is made as to whether or not to update the biometric information, and an "update requirement implementation phase" in which update requirements set in accordance with the security policy of the service being used are implemented.
[0202] First, let me explain the "Update Decision Phase"
[0203] When a user updates his / her biometric information, the user management unit 202 in FIG. 4 notifies the update control unit 205 of the user information and the updated biometric information.
[0204] The update control unit 205 checks the type of updated biometric information, identifies all services for which the user uses the corresponding biometric information, and checks the biometric information update requirements for each service. Specifically, the update control unit 205 identifies the information in the implementation item ID field registered in Figure 12 based on the information registered in the verification item field in Figure 11, and executes the original update implementation means.
[0205] Here, the execution of the original update requirement execution means is performed by the verification execution unit 206. Details will be explained in the "Update requirement execution phase".
[0206] The update control unit 205 receives the answer (response) from the verification execution unit 206, stores the results of the update requirements set by the service in the check result field of Figure 11, and checks whether all update requirements have been met (checks whether there are any problems with everything registered in the verification item field).
[0207] If all the conditions are met, the update control unit 205 updates the biometric information of the corresponding service to the newly registered biometric information. If all the conditions are not met, the update control unit 205 does not change the biometric information of the corresponding service.
[0208] The update control unit 205 checks the update requirements for all services that the user is using.
[0209] Next, the "update requirement implementation phase" will be explained.
[0210] The verification execution unit 206 is composed of several execution units 206a to 206d as shown in FIG.
[0211] The execution units 206a to 206d are the original update implementation means described in the above-mentioned "Update Requirement Registration Phase," and perform, for example, "verification of the identity of the registered original and the updated original" and "verification of approval by a third party."
[0212] The update control unit 205 sends an execution request to the verification execution unit 206 along with the action item ID information and parameter information. The verification execution unit 206 identifies the execution unit to be executed from among the execution units 206a to 206d based on the action item ID information, and executes any execution unit (execution means) along with the parameter information. The execution results of the execution units 206a to 206d are notified to the update control unit 205 via the verification execution unit 206.
[0213] The update control unit 205 registers the execution result in the check result field of Fig. 11. Here, if the execution result is successful, "check OK" is registered. If the execution result is unsuccessful, "check NG" is registered. In cases where the execution result cannot be reflected immediately (for example, when "approval confirmation by a third party" is performed), "checking" is stored.
[0214] Regarding the fourth phase, the information processing system according to the first embodiment is premised on the following for ease of explanation.
[0215] First, in the "update requirement execution phase," the execution units 206a to 206d are set as follows.
[0216] The execution unit 206a is an original data update execution means that executes action item A in the action item field in Fig. 9. The execution unit 206a calculates the identity rate between the registered original biometric information and new original biometric information (original biometric information of the update candidate), and compares the calculated identity rate with a threshold based on the parameter information received from the update control unit 205. If the identity rate is equal to or greater than the threshold, the execution unit 206a determines that the verification of action item A has been successful and notifies the user that the "check result is OK." On the other hand, if the identity rate is smaller than the threshold, the execution unit 206a determines that the verification of action item A has failed and notifies the user that the "check result is NG."
[0217] The execution unit 206b is an original data update execution means that executes action item B in the action item field in Fig. 9. The execution unit 206b notifies the registered contact email address based on the parameter information received from the update control unit 205 that the original biometric information of the user has been updated. The execution unit 206b sends an email to the contact email address inquiring whether the original biometric information can be updated. If the person who received the email gives permission (agreement) to update the original biometric information, the execution unit 206b determines that the verification of action item B has been successful and notifies the user that "check result OK". If the person who received the email refuses to update the original biometric information, the execution unit 206b determines that the verification of action item B has failed and notifies the user that "check result NG". If there is no reply from the contact email address for a certain period of time, the execution unit 206b notifies the user that "checking" is in progress.
[0218] The execution unit 206c is an original data update execution means that executes action item C in the action item field in Fig. 9. The execution unit 206c requests the user (the user who wishes to update the original biometric information) to present an identification card (for example, a passport or a driver's license) registered based on the parameter information received from the update control unit 205. If the execution unit 206c is successful in identifying the user using the presented identification card, it determines that the verification of action item C has been successful and notifies the user that "check result OK". If the execution unit 206c is unsuccessful in identifying the user using the presented identification card, or if the user does not present an identification card, it determines that the verification of action item C has failed and notifies the user that "check result NG". If there is no response for a certain period of time, the execution unit 206c notifies the user that "checking".
[0219] The execution unit 206d is an original data update execution means that executes action item D in the action item field in Fig. 9 . The execution unit 206d notifies the registered email address (user's email address) based on the parameter information received from the update control unit 205 that the original biometric information has been updated. The execution unit 206d sends an email to the user's email address inquiring whether the original biometric information can be updated. When the execution unit 206d receives a notification from the email destination that the update of the original biometric information is permitted, the execution unit 206d determines that the verification of action item D has been successful and notifies the user that "check result OK". When the execution unit 206d receives a notification from the email destination that the update of the original biometric information is rejected, or when no notification is received, the execution unit 206d determines that the verification of action item D has failed and notifies the user that "check result NG". When there is no reply from the contact email address for a certain period of time, the execution unit 206d notifies the user that "checking" is in progress.
[0220] There are various possible methods for executing (implementing) the above action items A to D. Therefore, a detailed explanation of the verification methods for each of these individual conditions will be omitted. For example, with regard to identity verification using an ID card, the execution unit 206b determines that identity verification is successful if it is determined that the facial image obtained from the ID card and the facial image obtained by photographing the user are the facial images of the same person.
[0221] Next, a user (Yamada Taro) has registered his biometric information, including his face and fingerprint information, in the management server 10. He is currently using services A, B, C, and D, and has registered information in the management server 10 to verify his identity through biometric authentication. Here, services A, B, and D perform identity authentication using face information as biometric information, while service C performs identity authentication using fingerprints.
[0222] Here, a user (Yamada Taro) was using the cashless payment service of Service A, but had recently experienced frequent failures in personal authentication, so he logged into the management center's portal site and updated his original biometric information about his face. The following explanation will be given assuming this situation.
[0223] The specific operation is as follows.
[0224] The user management unit 202 of the management server 10 refers to the user management database using the account information to identify the user who wishes to update the original biometric information. In the above example, "Yamada Taro" is identified.
[0225] When the user updates the face information, the user management unit 202 adds an entry to the user management database for adding new original biometric information of the user (Yamada Taro).
[0226] 8, since ID1: Face 1 is already registered as face information and ID2: Fingerprint 1 is already registered as fingerprint information, the user management unit 202 adds an original ID (ID3) and new original information (Face 2) as new biometric information. As a result, the user management database becomes as shown in FIG. 14.
[0227] Next, the user management unit 202 notifies the update control unit 205 of the fact that the original biometric information of the user (Yamada Taro) has been updated and the details thereof.
[0228] Specifically, the user management unit 202 notifies the update control unit 205 of the original ID of original biometric information of the same type as the new original biometric information, which is the original ID immediately before the update, and the original ID of the updated original biometric information. In the above example, since the updated original biometric information is "face," the update control unit 205 is notified of "ID1," which is the original ID immediately before the update, and "ID3," which is the original ID of the new original biometric information.
[0229] The operation of the update control unit 205 will be described below with reference to the drawings. Fig. 15 is a flowchart showing an example of the operation of the update control unit 205 according to the first embodiment.
[0230] When the update control unit 205 receives the information that the original biometric information has been updated, it searches the original usage management database (FIG. 8) of the corresponding user to identify services that use the same type of biometric information as the updated biometric information (original biometric information) (step S101). In the above example, the update control unit 205 identifies services that use the original biometric information corresponding to "ID1" for personal authentication. In the example of FIG. 11, services A, B, and D are identified.
[0231] The update control unit 205 sets "master update in progress" in the status field of each identified service in the master use management database (update status; step S102). In the above example, the statuses of services A, B, and D related to the user (Yamada Taro) are updated.
[0232] Furthermore, the update control unit 205 sets "checking" in the check result field corresponding to each verification item of each identified service (updating the check result; step S103). In the above example, the information in the check result fields for services A, B, and D related to the user (Yamada Taro) is updated.
[0233] Furthermore, when the information in the status and check result fields is changed, the update control unit 205 notifies the service providers of services A, B, and D, respectively, of the fact that the original biometric information has been updated (notifying original update; step S104). The management server 10 notifies the service server 20 that the original biometric information (first biometric information) has been updated to new original biometric information (second biometric information), and therefore the original update requirements will be verified.
[0234] Next, the update control unit 205 requests the verification execution unit 206 to verify the original document update requirements for each of services A, B, and D enjoyed by the user (Yamada Taro) (step S105). Specifically, the update control unit 205 requests the verification execution unit 206 to execute the verification items based on the information in the verification item field registered in the used original document management database shown in Fig. 11 (specific verification content of each implementation item constituting the original document update requirements for services A, B, and D).
[0235] For service A, the implementation of each verification item whose verification item ID in the verification item field is "001," "002," and "003" is requested. For service B, the implementation of each verification item whose verification item ID in the verification item field is "001," "002," "004," and "003" is requested. For service D, the implementation of each verification item whose verification item ID in the verification item field is "003" is requested.
[0236] At this time, the update control unit 205 requests verification of the original document update requirements (implementation items) for the services in the order registered in the original document usage management database. In the example of Fig. 11, verification is first performed on the original document update requirements for service A.
[0237] Specifically, the update control unit 205 requests the verification execution unit 206 to verify each verification item (verification item ID=001, 002, 003) that constitutes the original update requirements for service A. The update control unit 205 refers to the verification content management database shown in Fig. 12 and confirms the implementation item ID (A) and parameter (threshold value=80) that correspond to the verification item ID "001".
[0238] The update control unit 205 determines the execution unit (execution unit 206a) that will execute the execution item ID (A), and sends an execution request to the execution unit 206a along with the parameter information.
[0239] The same process is performed for the verification item IDs "002" and "003", and the update control unit 205 determines the execution units (execution units 206b and 206d) and issues an execution request to the execution units along with the parameter information.
[0240] The update control unit 205 acquires the verification result (verification failed, verification successful) from the verification execution unit 206. The update control unit 205 reflects the acquired verification result in the check result field of the used original document management database (step S106).
[0241] If the verification result is "verification successful", the update control unit 205 sets "check OK" in the check result field of the entry corresponding to the verification target. If the verification result is "verification failed", the update control unit 205 sets "check NG" in the check result field of the corresponding entry. Furthermore, if there is no response regarding the verification result after waiting for a certain period of time, the update control unit 205 sets "checking" in the check result field of the corresponding entry.
[0242] After checking the original update requirements for the first service, the update control unit 205 verifies the original update requirements for the next service. In the above example, after service A, the original update requirements for service B are verified. This is because the original ID of the original biometric information used for personal authentication for service B is "ID1", and the same type of biometric information (face information) as the original biometric information updated by the user (Yamada Taro) is used for personal authentication for service B.
[0243] Here, the update control unit 205 verifies the original update requirements for the second and subsequent services (services to be used), but omits verification of verification items that have already been verified. In other words, the update control unit 205 does not request the verification execution unit 206 to verify a verification item that has already been successfully verified, among at least one or more verification items that make up the original update requirements.
[0244] In the above example, if the verification of verification items with verification item IDs "001", "002", "0003", and "0004" that make up the original update requirements for service B has already been successful, verification of these verification items will not be performed.
[0245] In other words, among the four verification items that constitute the original document update requirements for service B, the verification item with the verification item ID "004" is requested to be verified.
[0246] In addition, the check result field of the verification item for which verification has been omitted is set to "check OK" because the verification has already been completed.
[0247] In this way, when the original update requirements are composed of at least one or more verification items (implementation items), the management server 10 determines that the new original biometric information satisfies the update requirements if the verification results of each verification item that composes the original update requirements are successful. In this case, the management server 10 omits verification of verification items with the same content as the verification items that were determined to be successful in the verification of the original update requirements of the first service when verifying the original update requirements of the second service.
[0248] Furthermore, the update control unit 205 periodically or at a predetermined timing checks the check result information in the check result field and the status information in the status field regarding the original biometric information update requirements of each service provided to the user (Yamada Taro). The update control unit 205 determines whether or not to update the original biometric information for each service according to the set values of the check result information and the status information (step S107).
[0249] For a verification item registered in one of the services in the original document usage management database, if the status is "original document update in progress" and all check results in the check result fields are "check OK", the update control unit 205 determines that the original document update requirements set by the service provider that provides the service have been met and approves the update of the original biometric information related to the service.
[0250] In this case, the original data field to be used is updated to the new biometric information. Specifically, after confirming that all check results for each verification item of service A are "check OK" and the status is "original data update in progress", the update control unit 205 changes the original data field to be used for service A from "ID1" to "ID3".
[0251] Furthermore, if the status is "original update in progress" and the check results in the check result fields are not all "check OK," the update control unit 205 determines that the original update requirements set by the service provider that provides the service in question have not been met, and does not allow the update of the original biometric information related to the service in question.
[0252] In this case, the setting of the used original field is maintained. Specifically, if the status of service B is "original update in progress" and the check results for each verification item include one or more "check NG" or "checking," the update control unit 205 will maintain "ID1" in the used original field of service B.
[0253] Finally, change the status.
[0254] For items that do not have "Checking" in the check result field, the update control unit 205 changes the status from "Original update in progress" to "In operation." Also, for items that have "Checking" in the check result field, the status is maintained as "Original update in progress."
[0255] In this way, when the stored original biometric information is updated, the management server 10 determines whether the new original biometric information satisfies the original update requirements, and if the new original biometric information satisfies the original update requirements, uses the new original biometric information for identity authentication when providing a service. In other words, if the new original biometric information does not satisfy the original update requirements, the management server 10 uses the previously stored original biometric information (original biometric information for which verification of each update requirement has been successfully completed) for identity authentication when providing a service. In other words, if the management server 10 does not determine that each verification item (implementation item) constituting the original update request corresponding to the service of the updated original biometric information is verified successfully, it uses the original biometric information before the update for identity authentication when providing a service.
[0256] The update control unit 205 notifies the service provider of the verification result of the original update requirements (notification of verification result; step S108).
[0257] The update control unit 205 notifies the service provider whose information in the used original field has been updated that the original has been successfully updated. The update control unit 205 notifies the service server 20 that verification of the original update requirements predetermined by the service provider has been successfully completed.
[0258] If there is a service for which some of the check results show "Check NG", the update control unit 205 notifies the service provider that provides the service that the update of the original biometric information has failed. The update control unit 205 notifies the service server 20 of the fact that the service provider has failed to verify the original update requirements set in advance.
[0259] If there is a service for which some of the check results include "checking," the update control unit 205 does not take any special action. Alternatively, the update control unit 205 may notify the service provider of the service that verification of the original update requirements is continuing.
[0260] Some of the original document update requirements (verification items) require time for verification. Therefore, the update control unit 205 may refer to the check results of the used original document management database periodically or at a predetermined timing, and report the verification status of the original biometric information to the service provider.
[0261] The update control unit 205 may notify the corresponding service provider of the verification result (update of the original biometric information completed successfully, update of the original biometric information failed) when "Checking" disappears from the check result. That is, the management server 10 may notify the service server 20 of the verification status of the original update requirement that started in response to updating the stored biometric information to new biometric information.
[0262] The service server 20 performs processing according to the verification result (verification result of the original update requirements) notified by the management server 10. For example, when a verification failure is notified, the service registration management unit 303 notifies a security officer or the like of that fact. The service registration management unit 303 transmits information about the user who failed to verify the original update requirements to a terminal or the like held by the security officer.
[0263] When the successful verification is notified, the service registration management unit 303 does not take any special action. Alternatively, the service registration management unit 303 may notify a security officer or the like of information about the user whose original biometric information has been successfully updated.
[0264] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described. Note that a description of the system operation relating to user registration, service registration, service provision, etc. will be omitted. Fig. 16 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment.
[0265] The management server 10 acquires the original biometric information to be updated from the user (step S01).
[0266] The management server 10 notifies the service server 20 of the update of the original biometric information (step S02). At that time, the management server 10 may notify the service server 20 of the user who updated the original biometric information and the service information (service ID) affected by the update of the original biometric information.
[0267] The management server 10 verifies the original data update requirements for the service that uses the updated original biometric information for personal authentication (step S03).
[0268] The management server 10 notifies the service server 20 of the verification result (verification success, verification failure) (step S04).
[0269] The service server 20 executes a process according to the verification result (step S05). For example, if the service server 20 fails to verify the original document update requirements, it notifies a security officer or the like to that effect.
[0270] As described above, in the information processing system according to the first embodiment, the biometric information (registered original biometric information) used for user authentication is managed by the management server 10. The management server 10 stores the original biometric information used for user authentication and the update requirements for the original biometric information for each service provided to the user. When the user updates the original biometric information, the management server 10 collectively verifies the original update requirements for each service affected by the update. At this time, redundant verification content is omitted. As a result, the user's work (work that the user had to perform) required for updating the original biometric information is reduced, reducing the burden on the user.
[0271] Furthermore, there are services that require a long time to verify the original update requirements (execute the verification content). For example, in an access control service for special areas such as a nuclear power plant, when biometric information is updated, the user's superior or a responsible person is required to individually verify the updated biometric information and grant permission. Obtaining such permission takes a relatively long time, resulting in a time lag between updating the biometric information and accepting the update. In this regard, the information processing system disclosed in the present application allows updates of biometric information for services for which verification has been completed, so that updates of biometric information used in other services are not delayed due to the update requirements that require time for verification.
[0272] Next, the hardware of each device constituting the authentication system will be described. Fig. 17 is a diagram showing an example of the hardware configuration of the management server 10.
[0273] The management server 10 can be configured using an information processing device (a so-called computer), and has the configuration shown in Fig. 17. For example, the management server 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0274] 17 is not intended to limit the hardware configuration of the management server 10. The management server 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the management server 10 is not intended to be limited to the example shown in FIG. 17, and the management server 10 may include multiple processors 311, for example.
[0275] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0276] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0277] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations, such as a keyboard or a mouse.
[0278] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0279] The functions of the management server 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by semiconductor chips.
[0280] The service server 20 and the like can also be configured using information processing devices, similar to the management server 10, and the basic hardware configuration is the same as that of the management server 10, so a description thereof will be omitted.
[0281] The management server 10, which is an information processing device, is equipped with a computer, and can realize the functions of the management server 10 by causing the computer to execute a program. The management server 10 also executes a control method for the management server 10 using the program. Similarly, the service server 20, which is an information processing device, is equipped with a computer, and can realize the functions of the service server 20 by causing the computer to execute a program. The service server 20 also executes the control method for the service server 20 using the program.
[0282] [Modification] The configuration, operation, etc. of the authentication system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0283] In the above embodiment, the case where the service server 20 transmits the service registration request and the update requirement setting request to the management server 10 at different times has been described. The service server 20 may transmit the information included in these requests to the management server 10 at the same time.
[0284] In the above embodiment, the management server 10 performs one-to-one matching (one-to-one authentication) during identity authentication. The management server 10 may also perform one-to-N matching (one-to-N authentication; N is a positive integer, the same applies below) during identity authentication. Specifically, the service server 20 transmits biometric information of the person to be authenticated, who is the recipient of the service, to the management server 10. The management server 10 sets the acquired biometric information as the matching side and the original biometric information as the registration side, and performs one-to-N authentication. The management server 10 transmits user information of the user identified by the one-to-N authentication to the service server 20. If there is no contradiction between the user information acquired from the management server 10 and the user information acquired from the person to be authenticated, the service server 20 provides the service to the person to be authenticated.
[0285] The management server 10 may provide the service provider with an interface that allows the service provider to add or change items in the action item definition table. In this case, the service provider sends the action item (action content and parameters) they wish to add to the management server 10 via the service server 20 and applies for the addition of the item. The management center (e.g., a management center staff member) conducts a predetermined review of the requested action item and determines whether the item can be accepted. If the action item can be accepted, the management center may notify (disclose) the accepted action item to other service providers. Alternatively, if a disclosure scope is set for the action item requested to be added, the management center may notify service providers within the set scope of the new action item. The service provider may use the notified action item to generate original update requirements to be set and registered in the management center.
[0286] In the above embodiment, the management server 10 performs verification of different verification items (verification item IDs) when updating original biometric information. However, the management server 10 may omit the execution of two verification items even if the verification items constituting the original update requirements are different. For example, if the verification of a verification item with an identity verification threshold set to 90% is successful, the management server 10 may not perform a verification item with an identity verification threshold set to 80%.
[0287] A plurality of parameters may be set for the action item. For example, in the verification of confirmation item C, a passport and a driver's license may be requested as identification documents in the same procedure.
[0288] In the above embodiment, a case where a user management database and the like are configured inside the management server 10 has been described, but the database may also be constructed on an external database server or the like. That is, some of the functions of the management server 10 may be implemented on another server. More specifically, the above-described "update control unit (update control means)" and the like may be implemented on any of the devices included in the system.
[0289] The management server 10 may verify the identity of a user when registering the user. Specifically, the management server 10 acquires the user's login information, etc., as well as an identification document (e.g., a passport, a driver's license, etc.) bearing biometric information and the biometric information. The management server 10 performs one-to-one matching using the biometric information on the identification document and the biometric information acquired from the user. If the matching is successful, the management server 10 may register the user whose identity has been successfully verified (system registration).
[0290] The form of data transmission and reception between the devices (management server 10, service server 20, authentication terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.
[0291] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0292] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0293] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems that provide biometric authentication services.
[0294] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes: [Supplementary Note 1] A system including: a first server that stores, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the provided service in association with each other; and a second server operated by a service provider that requests identity authentication of a service recipient from the first server, wherein, when first biometric information stored in the first server is updated with second biometric information, the second server notifies the first server of update requirements based on a service policy of the service provider, and when the stored first biometric information is updated, the first server determines whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, uses the second biometric information for identity authentication when the service is provided. [Supplementary Note 2] The system according to Supplementary Note 1, wherein, when the second biometric information does not satisfy the update requirements, the first server uses the first biometric information for identity authentication when the service is provided. [Supplementary Note 3] The system according to Supplementary Note 2, wherein the second server notifies the first server of the update requirements related to the service recipient before providing the service to the service recipient. [Supplementary Note 4] The system according to Supplementary Note 3, wherein the first server notifies the second server that verification of the update requirements will be performed in response to the first biometric information being updated to the second biometric information. [Supplementary Note 5] The system according to Supplementary Note 4, wherein the first server notifies the second server of a verification status of the update requirements that has started in response to the first biometric information being updated to the second biometric information. [Supplementary Note 6] The system according to any one of Supplements 1 to 5, wherein the update requirements are composed of at least one or more verification items, and the first server determines that the second biometric information satisfies the update requirements if the verification results of each verification item constituting the update requirements are successful. [Supplementary Note 7] The system described in Supplementary Note 6, wherein the first server omits verification of verification items having the same content as verification items that were determined to be successfully verified in the verification of the update requirements of the first service when verifying the update requirements of the second service.[Supplementary Note 8] The system according to Supplementary Note 7, wherein the verification item is any one of identity verification using a match rate between the first biometric information and the second biometric information, identity verification using an email, identity verification using an identification card, and third-party verification using an email. [Supplementary Note 9] The system according to Supplementary Note 8, wherein the update requirement is determined based on a security policy of the provided service. [Supplementary Note 10] A server device comprising: a storage means for storing, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the provided service in association with each other; a receiving means for receiving update requirements based on a service policy of a service provider when the first biometric information is updated to second biometric information; and an update control means for, when the stored first biometric information is updated, determining whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, using the second biometric information for identity authentication when the service is provided. [Supplementary Note 11] A server control method comprising: in a server device, for each of a plurality of users, storing a service to be provided and biometric information used for identity authentication of the provided service in association with each other, when first biometric information is updated to second biometric information, receiving update requirements based on a service policy of a service provider when the stored first biometric information is updated, determining whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, using the second biometric information for identity authentication when the service is provided. [Supplementary Note 12] A computer-readable storage medium storing a program for causing a computer mounted on the server device to execute the following processes: storing a service to be provided and biometric information used for identity authentication of the provided service in association with each other, when first biometric information is updated to second biometric information, receiving update requirements based on the service policy of a service provider when the first biometric information is updated, and determining whether the second biometric information satisfies the update requirements, and if the update requirements are satisfied, using the second biometric information for identity authentication when the service is provided.
[0295] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.
[0296] 10 Management server 20 Service server 30 Authentication terminal 40 Terminal 101 First server 102 Second server 201 Communication control unit 202 User management unit 203 Service registration control unit 204 Personal authentication unit 205 Update control unit 206 Verification execution unit 206a Execution unit 206b Execution unit 206c Execution unit 206d Execution unit 207 Storage unit 301 Communication control unit 302 Update requirement control unit 303 Service registration management unit 304 Authentication control unit 305 Service providing unit 306 Storage unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface
Claims
1. a first server that stores, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the service to be provided in association with each other; a second server operated by a service provider and requesting the first server to authenticate the identity of a service recipient; Including, when the first biometric information stored in the first server is updated to the second biometric information, the second server notifies the first server of an update requirement based on a service policy of the service provider; When the stored first biometric information is updated, the first server determines whether the second biometric information satisfies the update requirements, and if the update requirements are met, uses the second biometric information for identity authentication when providing services.
2. The system according to claim 1 , wherein the first server uses the first biometric information for personal authentication when providing a service if the second biometric information does not satisfy the update requirement.
3. The system of claim 2 , wherein the second server notifies the first server of the update requirements for the service recipient before providing the service to the service recipient.
4. The system according to claim 3 , wherein the first server notifies the second server that the update requirement is to be verified in response to the first biometric information being updated to the second biometric information.
5. The system according to claim 4 , wherein the first server notifies the second server of a verification status of the update requirement that is initiated in response to the first biometric information being updated to the second biometric information.
6. The update requirements consist of at least one verification item, The system according to claim 1 , wherein the first server determines that the second biometric information satisfies the update requirement when a verification result of each verification item constituting the update requirement is successful.
7. The system described in claim 6, wherein the first server omits verification of verification items having the same content as verification items that were determined to be successfully verified in the verification of the update requirements of the first service when verifying the update requirements of the second service.
8. a storage means for storing, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the service to be provided in association with each other; a receiving means for receiving an update requirement based on a service policy of a service provider when the first biometric information is updated to the second biometric information; an update control means for determining whether the second biometric information satisfies the update requirement when the stored first biometric information is updated, and for using the second biometric information for personal authentication when a service is provided if the second biometric information satisfies the update requirement; A server device comprising:
9. In the server device, storing, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the service to be provided in association with each other; receiving an update requirement based on a service policy of a service provider when the first biometric information is updated to the second biometric information; A server control method for determining whether the second biometric information satisfies the update requirements when the stored first biometric information is updated, and if the update requirements are met, using the second biometric information for identity authentication when providing a service.
10. The computer installed in the server device a process of storing, for each of a plurality of users, a service to be provided and biometric information used for identity authentication of the service to be provided in association with each other; receiving an update requirement based on a service policy of a service provider when the first biometric information is updated to the second biometric information; When the stored first biometric information is updated, determining whether the second biometric information satisfies the update requirement, and if the second biometric information satisfies the update requirement, using the second biometric information for identity authentication when providing a service; A program to execute.