Server device, server device control method and program

JPWO2024161580A5Pending Publication Date: 2025-09-04
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024574173
Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-06-25
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Biometric authentication systems face challenges in updating facial data without increasing server load, as existing methods require frequent updates which can lead to authentication failures due to changes in facial features over time.

Method used

A server device and method that sets a predetermined biometric information storage period and updates registered biometric information using accumulated data within this period, reducing the frequency of updates and thus minimizing server load.

Benefits of technology

This approach maintains authentication accuracy by updating biometric information only when necessary, reducing server load and preventing resource overload while ensuring accurate biometric authentication.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present invention provides a server device with which biometric information can be updated while moderating increases in load. The server device comprises a storage means, an accumulation period control means, and an update control means. The storage means stores registered biometric information to be used for biometric authentication. The accumulation period control means sets, at a predetermined frequency, a biometric information accumulation period of predetermined length, which is a period for accumulating biometric information about a user. The update control means updates the registered biometric information using at least one piece of biometric information accumulated during the biometric information accumulation period.
Need to check novelty before this filing date? Find Prior Art

Description

Server device, server device control method and storage medium

[0001] The present invention relates to a server device, a control method for a server device, and a storage medium.

[0002] There are technologies related to updating face data used for biometric authentication.

[0003] For example, Patent Document 1 discloses a system capable of updating face data stored in a database in a simple manner. The control unit of the communication terminal in Patent Document 1 captures an image of an operator with an imaging unit to acquire face data, and then uses a face authentication unit to compare this face data with face data previously stored in an authentication data storage unit to determine whether the operator is legitimate or illegitimate. When the face authentication unit determines that the operator is legitimate, the control unit of the communication terminal repeatedly stores the face data acquired by the imaging unit in the authentication data storage unit as face data of a registrant, and transmits the face data determined to be legitimate to a management device as face data of a registrant. The face data sent to the management device is used to update the registrant face data stored in the registrant database of the management device.

[0004] JP 2016-224751 A

[0005] As described in Patent Document 1, biometric information (e.g., facial image) used for biometric authentication needs to be updated. For example, a facial image registered when a service is first used and a facial image acquired long after the service has been used may show different impressions (different facial features) even if the person is the same. If biometric authentication is performed using such a facial image, the authentication is likely to fail. Therefore, updating of the biometric information (facial image) is necessary, but performing this update process constantly is not appropriate because it increases the load on the server.

[0006] A primary object of the present invention is to provide a server device, a control method for a server device, and a storage medium that contribute to enabling updating of biometric information while suppressing an increase in load.

[0007] According to a first aspect of the present invention, there is provided a server device comprising: a storage means for storing registered biometric information used for biometric authentication; an accumulation period control means for setting a biometric information accumulation period having a predetermined length at a predetermined frequency, which is a period for accumulating a user's biometric information; and an update control means for updating the registered biometric information using at least one piece of biometric information accumulated within the biometric information accumulation period.

[0008] According to a second aspect of the present invention, there is provided a method for controlling a server device, in which a server device stores registered biometric information used for biometric authentication, sets a biometric information accumulation period having a predetermined length at a predetermined frequency, and updates the registered biometric information using at least one piece of biometric information accumulated within the biometric information accumulation period.

[0009] According to a third aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a server device to execute the following processes: storing registered biometric information used for biometric authentication; setting a biometric information storage period having a predetermined length at a predetermined frequency for storing a user's biometric information; and updating the registered biometric information using at least one piece of biometric information stored within the biometric information storage period.

[0010] According to each aspect of the present invention, a server device, a control method for a server device, and a storage medium are provided that contribute to enabling updating of biometric information while suppressing an increase in load. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.

[0011] FIG. 1 is a diagram for explaining an overview of an embodiment. FIG. 2 is a flowchart showing an operation of the embodiment. FIG. 3 is a diagram showing an example of a schematic configuration of an information processing system according to the first embodiment. FIG. 4 is a diagram for explaining the operation of the information processing system according to the first embodiment. FIG. 5 is a diagram for explaining a biometric information accumulation period according to the first embodiment. FIG. 6 is a diagram showing an example of a processing configuration of a server device according to the first embodiment. FIG. 7 is a diagram showing an example of a display of a terminal according to the first embodiment. FIG. 8 is a diagram showing an example of a user management database according to the first embodiment. FIG. 9 is a diagram showing an example of an accumulation period management database according to the first embodiment. FIG. 10 is a flowchart showing an example of an operation of an authentication control unit according to the first embodiment. FIG. 11 is a diagram showing an example of a biometric information management database according to the first embodiment. FIG. 12 is a diagram showing an example of a processing configuration of an authentication terminal according to the first embodiment. FIG. 13 is a sequence diagram showing an example of an operation of the information processing system according to the first embodiment. FIG. 14 is a diagram showing an example of a display of a terminal according to a modification of the first embodiment. FIG. 15 is a diagram showing an example of a display of a terminal according to a modification of the first embodiment. FIG. 16 is a diagram showing an example of a display of a terminal according to a modification of the first embodiment. Fig. 17 is a diagram illustrating an example of a display on a terminal according to a modification of Embodiment 1. Fig. 18 is a diagram illustrating an example of a hardware configuration of a server device according to the present disclosure.

[0012] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0013] A server device 100 according to one embodiment includes a storage unit 101, an accumulation period control unit 102, and an update control unit 103 (see FIG. 1). The storage unit 101 stores registered biometric information used for biometric authentication (step S1 in FIG. 2). The accumulation period control unit 102 sets a biometric information accumulation period of a predetermined length at a predetermined frequency, which is a period for storing a user's biometric information (step S2). The update control unit 103 updates the registered biometric information using at least one piece of biometric information accumulated during the biometric information accumulation period (step S3).

[0014] The server device 100 sets a biometric information storage period for storing biometric information necessary to update the registered biometric information, and updates the registered biometric information using the biometric information obtained during the biometric information storage period. The biometric information storage period is set at a predetermined frequency and for a predetermined length, and the server device 100 updates the registered biometric information, for example, after the end of the biometric information storage period. In other words, the server device 100 does not update the biometric information constantly (every time authentication is successful), so the increase in load on the server device 10 is limited. In other words, a server device 100 is provided that enables updating of biometric information while suppressing an increase in load.

[0015] Specific embodiments will be described in more detail below with reference to the drawings.

[0016] First Embodiment The first embodiment will be described in more detail with reference to the drawings.

[0017] [System Configuration] As shown in FIG. 3, the information processing system (authentication system) according to the first embodiment includes a server device 10 and at least one authentication terminal 20.

[0018] The server device 10 and the authentication terminal 20 are managed and operated by a service provider that provides services to users using biometric authentication.

[0019] A service provider is any organization that provides a service using biometric authentication. Examples of service providers include businesses such as the user's employer, retail stores, hotels, airports, banks, hospitals, schools, and theme parks. Furthermore, a service provider may not be a private company, but may also be a public institution such as a local government.

[0020] The server device 10 stores information about users. The server device 10 stores the user's name, date of birth, biometric information, etc. The server device 10 provides services to users through biometric authentication using the biometric information. The server device 10 may be installed in the building of the service provider or on a network (cloud).

[0021] The authentication terminal 20 is a device that serves as an interface when providing services to users. The authentication terminal 20 is installed at a location where services are provided to users. As shown in Fig. 3, the first embodiment will be described using a gate-type authentication terminal 20 as an example.

[0022] However, the authentication terminal 20 is not limited to a gate-type terminal, and may be a tablet-type or signage-type terminal. Alternatively, the authentication terminal 20 may be a kiosk terminal. The authentication terminal 20 may be any apparatus or device equipped with a camera. The service provider may install a terminal or device suited to the type of business as the authentication terminal 20.

[0023] A user operates the terminal 30 to input information to the server device 10 or to obtain information from the server device 10 .

[0024] The devices shown in Fig. 3 are interconnected. Specifically, the server device 10 and the authentication terminal 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.

[0025] 3 is an example, and is not intended to limit the scope of the present invention. For example, the information processing system may include multiple server devices 10.

[0026] [Overall Operation] Next, an overall operation of the information processing system according to the first embodiment will be described.

[0027] <User Registration> A user who wishes to receive a service using biometric authentication must register in advance. The user operates the terminal 30 to access the server device 10. The user enters user information such as name, gender, date of birth, address, login information, email address, and biometric information on a website or the like provided by the server device 10.

[0028] Furthermore, the user inputs information necessary for the service to be provided to the server device 10. For example, a user who wishes to enter a workplace using biometric authentication inputs the department to which the user belongs to the server device 10. Alternatively, a user who wishes to make a payment using biometric authentication (face payment) inputs information such as a credit card account or bank account to the server device 10.

[0029] The biometric information of a user may be, for example, data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the biometric information of a user may be image data such as a face image or fingerprint image. The biometric information of a user may be any information that includes the user's physical characteristics. In the first embodiment, the biometric information is a person's face image or features generated from a face image.

[0030] When the server device 10 acquires the name, biometric information, etc. from the user, it generates a user ID for identifying the user. The server device 10 associates the generated user ID with the acquired user information and registers them in a user management database. The user management database will be described in detail later.

[0031] A user can also register another person as a user on their behalf. For example, a parent may enter the child's name, biometric information, etc. into the server device 10.

[0032] <Provision of Service> A user who wishes to receive a service from a service provider visits a location where the service is provided (e.g., a workplace or a retail store). The authentication terminal 20 acquires biometric information (e.g., a facial image) of the user in front of the user. The authentication terminal 20 transmits an authentication request including the acquired biometric information to the server device 10 (see FIG. 4).

[0033] The server device 10 performs biometric authentication using the biometric information included in the authentication request and the biometric information registered in the user management database. The server device 10 identifies the person to be authenticated by a matching process (authentication process) using the biometric information. The server device 10 authenticates the identified person to be authenticated. For example, if the person to be authenticated has the authority to enter the workplace, the server device 10 determines that the authentication is successful. If the person to be authenticated does not have the authority to enter the workplace, the server device 10 determines that the authentication is unsuccessful.

[0034] The server device 10 notifies the authentication terminal 20 of the authentication result (authentication success, authentication failure).

[0035] The authentication terminal 20 performs processing according to the authentication result. For example, if successful authentication is notified, the authentication terminal 20 opens the gate and allows the person to be authenticated to pass through the gate. If unsuccessful authentication is notified, the authentication terminal 20 closes the gate and denies the person to be authenticated from passing through the gate.

[0036] <Storage and Update of Biometric Information> Here, if the physical characteristics (e.g., facial features) of the person to be authenticated change over time, the authentication accuracy may decrease. In other words, biometric information for biometric authentication purposes needs to be maintained in an appropriate state. Taking this fact into consideration, the server device 10 updates the user's biometric information (biometric information registered in the server device 10; hereinafter referred to as registered biometric information).

[0037] Specifically, the server device 10 sets a period for storing registered biometric information for each user (hereinafter referred to as a "biometric information storage period" or "storage period").

[0038] The server device 10 sets a biometric information accumulation period of a predetermined length at a predetermined frequency. The server device 10 accumulates biometric information acquired during the biometric information accumulation period (biometric information acquired from the authentication terminal 20) that has been determined to be successfully authenticated. The server device 10 selects (extracts) biometric information suitable for biometric authentication purposes from the accumulated biometric information.

[0039] For example, the server device 10 sets a "biometric information accumulation period" for each user, such as once per year or once per three years, and a length (period) of "one week" or "one month." The server device 10 automatically updates the registered biometric information using biometric information acquired within the biometric information accumulation period. For example, if the frequency is once per year and the period is one week, the period indicated by the bold line in FIG. 5 corresponds to the biometric information accumulation period.

[0040] The server device 10 stores biometric information (e.g., facial images) that has been determined to be successfully authenticated within a biometric information storage period. At a predetermined timing (e.g., when the biometric information storage period ends), the server device 10 extracts (selects) biometric information that is most suitable for the registered biometric information from the stored biometric information.

[0041] For example, if the server device 10 successfully performs biometric authentication 10 times within the biometric information accumulation period, it selects one piece of biometric information from the 10 times (e.g., 10 facial images) that is most suitable for biometric authentication purposes.

[0042] The server device 10 updates the existing biometric information (registered biometric information) using the selected biometric information.

[0043] The server device 10 discards biometric information acquired outside the biometric information accumulation period and determined to have resulted in successful authentication. Since biometric information acquired outside the biometric information accumulation period is discarded, resources (memory, storage media, etc.) of the server device 10 are not strained. Note that biometric information determined to have resulted in unsuccessful authentication is discarded regardless of whether it is inside or outside the biometric information accumulation period.

[0044] Next, details of each device included in the information processing system according to the first embodiment will be described.

[0045] [Server Device] Fig. 6 is a diagram showing an example of a processing configuration (processing modules) of the server device 10 according to the first embodiment. Referring to Fig. 6, the server device 10 includes a communication control unit 201, a user management unit 202, an accumulation period control unit 203, an authentication control unit 204, an update control unit 205, and a storage unit 206.

[0046] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the authentication terminal 20. The communication control unit 201 also transmits data to the authentication terminal 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0047] The user management unit 202 is a means for managing users who receive the provision of services. For example, the user management unit 202 registers user information such as the user's name, gender, date of birth, address, email address, login information, and biometric information.

[0048] When a user operates the terminal 30 to access a predetermined website or the like provided by the server device 10, the user management unit 202 displays a GUI (Graphical User Interface) on the terminal 30 for user registration.

[0049] For example, the user management unit 202 acquires user information such as name, sex, date of birth, email address, and biometric information (for example, a face image) using a GUI such as that shown in FIG.

[0050] When a facial image is acquired as biometric information, the user management unit 202 generates feature quantities from the acquired facial image. The feature quantity generation process by the user management unit 202 can use existing technology, so a detailed description thereof will be omitted. For example, the user management unit 202 extracts the eyes, nose, mouth, etc. from the facial image as feature points. The user management unit 202 then calculates the positions of each feature point and the distances between each feature point as feature quantities (generating a feature vector consisting of multiple feature quantities).

[0051] Furthermore, upon acquiring user information of the user (or another person related to the user; for example, a child), the user management unit 202 generates a user ID for identifying the user. The user ID may be any information that can uniquely identify the user. For example, the user management unit 202 may assign a unique value each time a user is registered and use this as the user ID.

[0052] When the user ID is generated, the user management unit 202 generates an account for the user. Specifically, the user management unit 202 associates the generated user ID with the name, sex, date of birth, address, biometric information (features), email address, login information, etc., and registers them in the user management database (see FIG. 8).

[0053] The biometric information (e.g., feature values) registered in the user management database is biometric information used for biometric authentication and corresponds to the registered biometric information described above. Note that the user management database shown in FIG. 8 is an example and is not intended to limit the items to be stored. For example, a "face image" may be registered in the user management database.

[0054] When the user management unit 202 creates an account for a user (when it adds an entry to the user management database), it notifies the accumulation period control unit 203 of the user ID of the user.

[0055] The user management unit 202 also acquires information necessary for the services provided to the user (information specific to each individual service). For example, the user management unit 202 acquires the "department" as information necessary for entering the workplace. Alternatively, the user management unit 202 acquires account information (credit card information, bank account information) for biometric authentication payment. Note that a description of each individual service and the information necessary for providing each individual service is omitted here, as it is outside the scope of this disclosure.

[0056] The user management unit 202 also controls the suspension of service provision to a user and the cancellation of a service. When a user requests cancellation of a service on a portal site (a website to which the user logs in using login information), the user management unit 202 deletes the entry for that user (the entry in the user management database).

[0057] The accumulation period control unit 203 is a means for controlling the biometric information accumulation period set for each user. Specifically, the accumulation period control unit 203 is a period for accumulating the biometric information of the user, and sets the biometric information accumulation period having a predetermined length at a predetermined frequency.

[0058] When the user ID of a user who has completed account creation is acquired from the user management unit 202, the accumulation period control unit 203 determines a biometric information accumulation period for the user. For example, the accumulation period control unit 203 determines the biometric information accumulation period based on a predetermined rule (period setting rule) or a predetermined policy (period setting policy).

[0059] For example, the accumulation period control unit 203 determines the biometric information accumulation period based on rules regarding the "frequency" at which the biometric information accumulation period is set and the "length (period)" of the accumulation period. For example, the accumulation period control unit 203 determines the biometric information accumulation period of the user based on a rule (policy) such as "set the biometric information accumulation period to one week one year after the account creation date, and set the biometric information accumulation period in the same manner thereafter."

[0060] For example, if the account creation date is "January 20, 2023" and the above rule is adopted, the accumulation period control unit 203 sets the biometric information accumulation period to one week one year after the account creation date, from "January 20, 2024" to "January 27, 2024."

[0061] The accumulation period control unit 203 registers the determined biometric information accumulation period in an accumulation period management database (see FIG. 9). As shown in FIG. 9, the accumulation period management database stores the user ID, account creation date, rules (frequency, length) used to determine the biometric information accumulation period, status, and biometric information accumulation period. Note that the accumulation period management database shown in FIG. 9 is an example and is not intended to limit the items to be stored.

[0062] The accumulation period control unit 203 adds an entry to the accumulation period management database, sets the biometric information accumulation period, and then sets "updated" in the status field.

[0063] The accumulation period control unit 203 accesses the accumulation period management database periodically or at a predetermined timing, and extracts entries for which the biometric information accumulation period has elapsed. The accumulation period control unit 203 searches the user management database using the user ID of the extracted entry as a key, and determines whether or not a corresponding entry (user) exists.

[0064] If there is no corresponding entry (if the user has stopped or canceled the service), the accumulation period control unit 203 deletes the corresponding entry (user) from the accumulation period management database.

[0065] If a corresponding entry exists (if the service is being provided to the user continuously), the accumulation period control unit 203 determines a new biometric information accumulation period for the user and registers it in the accumulation period management database.

[0066] For example, the accumulation period control unit 203 determines a new biometric information accumulation period using the period setting rules (frequency and length of the biometric information accumulation period) stored in the accumulation period management database. In the above example, "January 20, 2025" to "January 27, 2025" is registered in the accumulation period management database as the new biometric information accumulation period.

[0067] Furthermore, when the accumulation period control unit 203 sets a new biometric information accumulation period in the accumulation period management database, it sets "not updated" in the status field of the corresponding entry.

[0068] The authentication control unit 204 is a means for controlling biometric authentication of the person to be authenticated. The authentication control unit 204 receives an authentication request including biometric information of the person to be authenticated from the authentication terminal 20, and executes authentication processing using the biometric information included in the authentication request and the registered biometric information stored in the user management database. The authentication control unit 204 also stores biometric information for which authentication is determined to be successful within a biometric information storage period, and discards biometric information for which authentication is determined to be successful outside the biometric information storage period.

[0069] 10 is a flowchart showing an example of the operation of the authentication control unit 204 according to the first embodiment. The operation of the authentication control unit 204 will be described with reference to FIG.

[0070] The authentication control unit 204 executes a matching process using the biometric information included in the authentication request and the biometric information stored in the user management database (step S101).

[0071] More specifically, the authentication control unit 204 generates features from the facial image included in the authentication request. The authentication control unit 204 sets the generated features as targets for matching and performs a matching process (one-to-N matching; N is a positive integer, the same applies hereinafter) with features stored in the user management database.

[0072] The authentication control unit 204 calculates the similarity between the feature to be matched and each of the multiple feature values ​​on the registration side. The similarity can be calculated using chi-square distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0073] The authentication control unit 204 determines that the matching process has failed if there is no feature among the multiple features stored in the user management database that has a similarity with the feature to be matched that is greater than or equal to a predetermined value.

[0074] The authentication control unit 204 determines that the matching process is successful if there is a feature among the multiple feature amounts stored in the user management database that has a similarity to the feature amount to be matched that is equal to or greater than a predetermined value. In this case, the user with the entry with the highest similarity is identified as the person to be authenticated.

[0075] If the matching process fails (step S102, No branch), the authentication control unit 204 sets the authentication result to authentication failure (step S103).

[0076] If the matching process is successful (step S102, Yes branch), the authentication control unit 204 determines whether or not to provide the service using the user information identified by the matching process (step S104).

[0077] For example, the authentication control unit 204 determines whether the person to be authenticated has the authority to enter the installation location (e.g., office) based on the department to which the person to be authenticated belongs and the installation location of the authentication terminal 20. If the person to be authenticated has the authority, the authentication control unit 204 determines that the service can be provided to the person to be authenticated (entry to the office is permitted). If the person to be authenticated does not have the authority, the authentication control unit 204 determines that the service cannot be provided to the person to be authenticated (entry to the office is prohibited).

[0078] If the service cannot be provided to the person to be authenticated (step S105, No branch), the authentication control unit 204 sets the authentication result to authentication failure (step S103).

[0079] If the service can be provided to the person to be authenticated (step S105, Yes branch), the authentication control unit 204 sets the authentication result to "authentication success" (step S106).

[0080] If the authentication is successful, the authentication control unit 204 determines whether the date of processing the authentication request is included in the biometric information accumulation period (determination of accumulation period; step S107).

[0081] The authentication control unit 204 searches the storage period management database using the user ID of the person to be authenticated identified by the matching process as a key, and identifies a corresponding entry. The authentication control unit 204 makes the above determination based on the setting value of the biometric information storage period field of the identified entry and the processing date of the authentication request.

[0082] If the date of processing the authentication request is outside the biometric information storage period (step S108, No branch), the authentication control unit 204 does not perform any particular operation.

[0083] If the processing date of the authentication request is within the biometric information storage period (step S108, Yes branch), the authentication control unit 204 stores the biometric information (face image) included in the authentication request (step S109).

[0084] Specifically, the authentication control unit 204 stores the user ID of the person to be authenticated, the authentication date and time, and the biometric information of the person who was successfully authenticated (for example, a facial image) in the biometric information management database (see Fig. 11). Note that the biometric information management database shown in Fig. 11 is an example and is not intended to limit the items to be stored.

[0085] The authentication control unit 204 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 20 (step S110).

[0086] The update control unit 205 is a means for controlling the update of biometric information of a user registered for biometric authentication (registered biometric information). The update control unit 205 updates the registered biometric information using at least one piece of biometric information accumulated within a biometric information accumulation period.

[0087] The update control unit 205 periodically or at a predetermined timing accesses the accumulation period management database, identifies entries whose status is set to "Not updated", searches the biometric information management database using the user ID of the identified entry as a key, and acquires biometric information (e.g., facial images) accumulated during the biometric information accumulation period.

[0088] The update control unit 205 calculates an index (referred to as an "appropriateness score" or simply as a "score") indicating the appropriateness of each piece of biometric information stored within the biometric information storage period as registered biometric information. In other words, the update control unit 205 calculates an appropriateness score indicating the appropriateness of each piece of biometric information stored within the biometric information storage period as biometric information for biometric authentication purposes.

[0089] For example, the update control unit 205 inputs biometric information (face image) into a learning model obtained by machine learning, and obtains an appropriateness score.

[0090] The learning model is obtained by machine learning using a large amount of training data in which labels (appropriateness scores) are assigned to image data (face images). Any algorithm, such as a support vector machine, boosting, or neural network, can be used to generate the learning model. Since known techniques can be used for the algorithms, such as the support vector machine, a description thereof will be omitted.

[0091] Training data is obtained by having experts with knowledge of biometric authentication assign scores to image data (face images). The experts assign scores to each image data piece, taking into account factors such as the orientation and state of the face in the image data (e.g., whether the eyes are open or closed), and the influence of the external environment (e.g., whether the image is too bright or too dark).

[0092] The update control unit 205 selects biometric information (e.g., a facial image) to be used to update already registered biometric information (registered biometric information) based on the calculated score. For example, the update control unit 205 selects the facial image with the highest score as the biometric information to be updated.

[0093] The update control unit 205 generates features from the selected biometric information (face image). The update control unit 205 accesses the user management database and updates the features set in the registered biometric information field of the corresponding user with the generated features (replaces the features, overwrites the features).

[0094] The update control unit 205 sets "updated" in the status field of the corresponding entry in the accumulation period management database (the entry corresponding to the user whose biometric information has been updated).

[0095] The storage unit 206 is a means for storing information necessary for the operation of the server device 10. The storage unit 206 stores registered biometric information used for biometric authentication.

[0096] [Authentication Terminal] Fig. 12 is a diagram showing an example of the processing configuration (processing module) of the authentication terminal 20 according to the first embodiment. Referring to Fig. 12, the authentication terminal 20 includes a communication control unit 301, a biometric information acquisition unit 302, an authentication request unit 303, and a storage unit 304.

[0097] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the server device 10. The communication control unit 301 also transmits data to the server device 10. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0098] The biometric information acquisition unit 302 is a means for controlling the camera and acquiring biometric information (e.g., a facial image) of a user. The biometric information acquisition unit 302 periodically or at a predetermined timing captures an image of the area in front of the device. The biometric information acquisition unit 302 determines whether the acquired image contains a human facial image, and if a facial image is included, extracts the facial image from the acquired image data.

[0099] Note that since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 302, detailed description thereof will be omitted. For example, the biometric information acquisition unit 302 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 302 may extract a facial image using a technique such as template matching.

[0100] The biometric information acquisition unit 302 passes the extracted face image to the authentication request unit 303 .

[0101] The authentication request unit 303 is a means for requesting authentication of the person to be authenticated from the server device 10. When authentication of the person to be authenticated becomes necessary, the authentication request unit 303 transmits an authentication request including biometric information of the person to be authenticated (the user in front of the authentication terminal 20) to the server device 10.

[0102] The authentication request unit 303 receives the authentication result (authentication success, authentication failure) from the server device 10. The authentication request unit 303 performs an operation according to the received authentication result.

[0103] For example, if the response from the server device 10 is a "negative response" (if the authentication has failed), the authentication request unit 303 closes the gate and denies the person to be authenticated entry into the office. At this time, the authentication request unit 303 may notify the person to be authenticated that he or she cannot pass through the gate.

[0104] If the response from the server device 10 is an "affirmative response" (if the authentication is successful), the authentication request unit 303 opens the gate and allows the person to be authenticated to enter the office.

[0105] The storage unit 304 is a means for storing information necessary for the operation of the authentication terminal 20 .

[0106] [Terminal] Examples of the terminal 30 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers). The terminal 30 can be any equipment or device that can accept user operations and communicate with the server device 10, etc. Furthermore, the configuration of the terminal 30 is clear to those skilled in the art, and therefore a detailed description thereof will be omitted.

[0107] [System Operation] Next, the operation of the authentication system according to the first embodiment will be described.

[0108] 13 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. The operation of the information processing system according to the first embodiment will be described with reference to FIG.

[0109] The authentication terminal 20 transmits an authentication request including biometric information of the person to be authenticated to the server device 10 (step S01).

[0110] The server device 10 performs biometric authentication using the acquired biometric information and the biometric information stored in the user management database (step S02).

[0111] If the biometric authentication is successful and the authentication date (authentication date and time) is within the biometric information storage period, the server device 10 stores the biometric information (e.g., a facial image) acquired from the authentication terminal 20. The server device 10 stores the biometric information for which authentication is determined to be successful within the biometric information storage period.

[0112] The server device 10 transmits a successful authentication to the authentication terminal 20 (step S04).

[0113] The authentication terminal 20 provides the service assigned to itself (step S05). For example, the authentication terminal 20 opens the gate and allows the person to be authenticated to pass through the gate.

[0114] During the biometric information storage period, the authentication terminal 20 and the server device 10 repeat the operations of steps S01 to S05.

[0115] When the biometric information storage period has elapsed, the server device 10 selects the biometric information (face image) that is most suitable as the biometric information for registration from the stored biometric information, and updates the registered biometric information using the selected biometric information (step S06).

[0116] Next, a modification of the first embodiment will be described.

[0117] <Variation 1> The server device 10 may notify a user that the service provision date for the user falls within the biometric information storage period. For example, if the authentication control unit 204 of the server device 10 successfully authenticates the authenticatee during the biometric information storage period, the authentication control unit 204 notifies the user via the authentication terminal 20 that the biometric information storage period is in progress. In this case, the authentication control unit 204 may notify the authentication terminal 20 that the authentication is successful and that the biometric information storage period is in progress. Alternatively, the authentication control unit 204 may notify the email address of the user identified by the matching process (the terminal 30 owned by the user) that the service provision date falls within the biometric information storage period. In this case, the terminal 30 may display a pop-up message as shown in FIG. 14 to notify the user that the biometric information storage period is scheduled to be set before the biometric information storage period is actually set. For example, the server device 10 may notify the user that the biometric information storage period is scheduled to be set a predetermined period before the set biometric information storage period (e.g., one week or one month before).

[0118] 14 is an example and is not intended to limit the manner in which the user is notified that the service provision date falls within the biometric information storage period. For example, the terminal 30 may notify the user that the service provision date falls within the biometric information storage period by changing the background color or layout. For example, the terminal 30 may notify the user that the service provision date falls within the biometric information storage period by, for example, changing a white background to a yellow background. In this way, the terminal 30 may notify the user that the service provision date falls within the biometric information storage period not only by using text (message) but also by using the color scheme, layout, etc. of the screen.

[0119] <Variation 2> The server device 10 may obtain consent from the user when updating the biometric information. For example, when the update control unit 205 of the server device 10 selects biometric information (e.g., a facial image) to be used to update the registered biometric information, the update control unit 205 transmits an "update inquiry" including the selected facial image to the user's terminal 30. Upon receiving the update inquiry, the terminal 30 displays a GUI such as that shown in FIG. 15 and obtains whether the registered facial image (registered biometric information) should be updated with the facial image selected by the server device 10. The terminal 30 notifies the server device 10 of the user's intention (agree to update, reject update). When the user agrees to update the biometric information (facial image), the update control unit 205 updates the registered biometric information using the facial image.

[0120] Alternatively, the server device 10 may obtain consent from the user to start storing biometric information for update. For example, the server device 10 transmits a "storage period start inquiry" including the registered biometric information to the user's terminal 30 immediately before the start of the biometric information storage period. Upon receiving the inquiry, the terminal 30 displays a GUI such as that shown in FIG. 16 and obtains consent or denial of the storage of biometric information to update the registered biometric information. The terminal 30 notifies the server device 10 of the user's intention (agree to storage, reject storage). If the user consents to the storage of biometric information (facial image), the server device 10 starts storing the biometric information during the biometric information storage period. In this manner, the server device 10 obtains from the user consent or denial of the setting of a biometric information storage period in which the initially captured facial image is deleted (updated).

[0121] <Variation 3> The accumulation period control unit 203 of the server device 10 may set the biometric information accumulation period based on the user's attribute information (e.g., age, gender). For example, the accumulation period control unit 203 may determine the frequency of setting the biometric information accumulation period according to the user's age. For example, the biometric information accumulation period may be set at frequencies such as "under 5 years old: once every three months," "5 to 10 years old: once every six months," "10 to 15 years old: once a year," "15 to 20 years old: once every two years," and "20 years old or older: once every five years." That is, the accumulation period control unit 203 may determine the biometric information accumulation period for each user based on the period setting rule (period setting policy) described above. Note that there may be a rule such as "no update required" for users over a certain age. For example, the accumulation period control unit 203 may determine the biometric information accumulation period based on a rule such as "60 years old or older: no update required." In this case, the accumulation period control unit 203 may set the biometric information accumulation period to a period far exceeding a human lifespan. In this way, the server device 10 may determine the frequency of the biometric information accumulation period according to age, taking into account that children's faces change easily. When setting a new biometric information accumulation period, the server device 10 may set the biometric information accumulation period based on the user's age. Alternatively, the server device 10 may determine the length of the biometric information accumulation period based on the user's attribute information (e.g., age, gender). For example, taking into account that the younger the user, the more easily the face (physiognomy) changes, the server device 10 sets a longer biometric information accumulation period for younger users and a shorter biometric information accumulation period for older users.

[0122] <Variation 4> The server device 10 may determine the frequency and length of the biometric information storage period based on the number of successful authentication attempts that are considered to be authentication failures. For example, the server device 10 stores, for each user, the number of times authentication is determined to be successful near the lower limit of the threshold for determining authentication success (the number of pseudo-errors). As the number of pseudo-errors increases, the server device 10 shortens the setting frequency of the biometric information storage period. For example, the server device 10 changes the period setting frequency from once a year to once every six months. Alternatively, as the number of pseudo-errors increases, the server device 10 lengthens the biometric information storage period. For example, the server device 10 changes the period setting frequency from once a week to three weeks. Alternatively, as the number of pseudo-errors increases, the server device 10 may increase the number of times required for authentication to be determined to be successful within the biometric information storage period (e.g., from 10 times to 15 times). On the other hand, if the number of pseudo-errors is low, the server device 10 may lengthen the setting frequency of the storage period for biometric information updates. For example, the server device 10 may change the update frequency from once a year to once every three years. Alternatively, if the number of pseudo errors is low, the server device 10 may shorten the biometric information accumulation period (e.g., from one week to three days) or reduce the number of required authentications (e.g., from 10 to five).

[0123] <Variation 5> The accumulation period control unit 203 of the server device 10 may determine the length of the biometric information accumulation period based on the user's authentication history. In this case, the server device 10 generates and stores an authentication history for each user, including the date, time, and location of successful authentication. The accumulation period control unit 203 calculates the user's authentication frequency (the number of successful authentications within a predetermined period). The accumulation period control unit 203 sets a shorter biometric information accumulation period for users with a high authentication frequency. Conversely, the accumulation period control unit 203 sets a longer biometric information accumulation period for users with a low authentication frequency. For example, the accumulation period control unit 203 calculates the user's authentication frequency over the past month. Furthermore, the standard length of the biometric information accumulation period (the default value of the accumulation period) is set to "1 week." In this case, for users with a high authentication frequency, the accumulation period control unit 203 sets the biometric information accumulation period to "3 days," which is shorter than the default value. Conversely, for users with a low authentication frequency, the accumulation period control unit 203 sets the biometric information accumulation period to "2 weeks," which is longer than the default value. A high authentication frequency indicates that a large amount of biometric information is acquired during the biometric information accumulation period. Therefore, even if the biometric information accumulation period is set short, a sufficient number of facial images are accumulated to select facial images for updating. On the other hand, a low authentication frequency indicates that a small amount of biometric information is acquired during the biometric information accumulation period. Therefore, unless the biometric information accumulation period is set long, a sufficient number of facial images are not accumulated to select facial images for updating. Taking these circumstances into consideration, the server device 10 determines the length of the biometric information accumulation period according to the authentication frequency (frequency of service use) of each user, and enables the acquisition of biometric information suitable for updating (biometric information with a sufficiently high appropriateness score).

[0124] <Variation 6> Alternatively, the server device 10 (storage period control unit 203) may extend the biometric information storage period if the number of successful authentication attempts during the biometric information storage period does not reach a predetermined value. For example, if a rule such as "10 successful authentication attempts are required" is defined, the server device 10 extends the biometric information storage period until 10 successful authentication attempts are confirmed during the biometric information storage period (until 10 pieces of biometric information are accumulated). In this case, the storage period control unit 203 references the biometric information storage period field in the storage period management database and extracts entries whose end date for the biometric information storage period has arrived. The storage period control unit 203 references the biometric information management database and obtains the number of pieces of biometric information of the user corresponding to the user ID of the extracted entry. If the number of pieces of biometric information obtained (the number of pieces of biometric information accumulated during the biometric information storage period) has not reached a predetermined value (10 in the above example), the storage period control unit 203 extends the end date of the biometric information storage period in the storage period management database.

[0125] <Variation 7> Alternatively, the server device 10 (authentication control unit 204) may notify the user of the accumulation status of biometric information (the number of successful authentications) during the biometric information accumulation period. That is, the server device 10 may notify the user of the progress status regarding the accumulation of biometric information required to complete the biometric information accumulation period. In the above example, the number of successful authentications required to complete the biometric information accumulation period is "10," and the number of successful authentications at the time of successful authentication (e.g., seven successful biometric authentications) may be notified to the user. For example, the authentication control unit 204 may notify the terminal 30 of the user identified by the matching process of the accumulation status of biometric information (e.g., the number of required authentications, the current number of authentications). In this case, the terminal 30 may display a pop-up as shown in FIG. 17 to notify the user of the accumulation status of biometric information.

[0126] <Variation 8> The server device 10 may generate update biometric information from multiple pieces of biometric information accumulated during the biometric information accumulation period. For example, the update control unit 205 may combine multiple facial images obtained during the biometric information accumulation period to generate a single facial image. The update control unit 205 may generate features from the generated facial image and register the generated features as update biometric information in the user management database. Alternatively, the update control unit 205 may generate features from each facial image obtained during the biometric information accumulation period and calculate an average value of the generated features. The update control unit 205 may register the calculated average value of the features as update biometric information in the user management database.

[0127] As described above, the server device 10 according to the first embodiment sets a biometric information accumulation period for accumulating biometric information necessary to update the registered biometric information. The server device 10 selects biometric information suitable for updating the registered biometric information from the biometric information obtained during the biometric information accumulation period, and updates the registered biometric information using the selected biometric information. The biometric information accumulation period is set at a predetermined frequency and for a predetermined length, and the server device 10 updates the registered biometric information, for example, after the end of the biometric information accumulation period. With this configuration, the server device 10 does not need to update the biometric information every time a user is successfully authenticated, thereby suppressing an increase in the load on the server device 10.

[0128] Here, if the facial features of the person to be authenticated change, the authentication accuracy will deteriorate. Children, in particular, grow quickly and their faces change quickly. Therefore, frequent updates of biometric information are required for children. On the other hand, the facial changes of adults are gradual, and frequent updates of biometric information are often unnecessary. The server device 10 takes these circumstances into consideration and sets an appropriate biometric information accumulation period according to the user's attributes (e.g., age). For example, the server device 10 sets the biometric information accumulation period for children so that biometric information is updated frequently. On the other hand, the server device 10 sets the biometric information accumulation period for adults so that biometric information is not updated frequently. As a result, it is possible to improve (maintain) authentication accuracy while suppressing an increase in the load on the server device 10.

[0129] Furthermore, the server device 10 can reliably acquire biometric information to be used for updating the registered biometric information by appropriately selecting the length of the biometric information accumulation period. Also, the server device 10 verifies the quality of the biometric information to be used for updating, thereby preventing a deterioration in the accuracy of biometric authentication using the updated biometric information.

[0130] Next, the hardware of each device constituting the information processing system will be described. Fig. 18 is a diagram showing an example of the hardware configuration of the server device 10.

[0131] The server device 10 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 18. For example, the server device 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0132] However, the configuration shown in Fig. 18 is not intended to limit the hardware configuration of the server device 10. The server device 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the server device 10 is not intended to be limited to the example shown in Fig. 18, and for example, the server device 10 may include multiple processors 311.

[0133] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0134] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0135] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations, such as a keyboard or a mouse.

[0136] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0137] The functions of the server device 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by semiconductor chips.

[0138] The authentication terminal 20 can also be configured by an information processing device, similar to the server device 10, and its basic hardware configuration is not different from that of the server device 10, so a description thereof will be omitted. For example, the authentication terminal 20 may be provided with a camera device for photographing the person to be authenticated.

[0139] The server device 10, which is an information processing device, is equipped with a computer, and the functions of the server device 10 can be realized by having the computer execute a program. The server device 10 also executes a control method for the server device 10 using the program. Similarly, the authentication terminal 20 is equipped with a computer, and the functions of the authentication terminal 20 can be realized by having the computer execute a program. The authentication terminal 20 also executes a control method for the authentication terminal 20 using the program.

[0140] [Modification] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0141] The user management unit 202 of the server device 10 may calculate an appropriateness score for the biometric information acquired from the user at the time of initial registration of the biometric information. If the calculated appropriateness score is lower than a threshold, the user management unit 202 may request the user to re-register different biometric information (e.g., a face image).

[0142] The server device 10 may select biometric information to be used for updating the registered biometric information based on the similarity between the registered biometric information and the accumulated biometric information. For example, the server device 10 may select, as the biometric information for update, the biometric information that has the greatest similarity to the registered biometric information among the biometric information acquired during the biometric information accumulation period.

[0143] When registering a user, the user's identity may be verified. The user management unit 202 of the server device 10 acquires the user's name, biometric information, etc., as well as an identification document (e.g., a passport, a driver's license, etc.) containing the biometric information. The user management unit 202 performs one-to-one matching using the biometric information on the identification document and the biometric information acquired from the user. If the matching is successful, the user management unit 202 may register the user (create an account).

[0144] The accumulation period control unit 203 may set the biometric information accumulation period using attribute information obtained from an identification document instead of attribute information (age, gender) acquired from the user. Alternatively, the accumulation period control unit 203 may infer the user's attribute information from the user's registered biometric information (e.g., a face image).

[0145] The update control unit 205 may perform statistical processing on the appropriateness scores of the biometric information obtained during the biometric information accumulation period, and select biometric information to update the registered biometric information according to the results of the statistical processing. For example, the update control unit 205 may calculate a representative value representing the accumulated biometric information, such as the average, median, or mode of the appropriateness scores. The update control unit 205 may select biometric information having an appropriateness score that matches (is closest to) the representative value as the biometric information to be updated.

[0146] Alternatively, the update control unit 205 may select biometric information for updating the registered biometric information from the biometric information remaining after excluding the biometric information with the best and worst appropriateness scores. Alternatively, the update control unit 205 may calculate the representative value by excluding the biometric information with the best and worst appropriateness scores.

[0147] In the above embodiment, a case has been described in which user information, biometric information accumulation periods, and biometric information determined to be successfully authenticated are managed using three databases (user management database, accumulation period management database, and biometric information management database). However, the user information, biometric information accumulation periods, etc. may be managed by a single database. In other words, the above three databases may be integrated and user information, etc. may be managed by a single database.

[0148] In the above embodiment, the user management database stores the user's feature values ​​as registered biometric information. However, the user management database may store the user's facial image as registered biometric information. In this case, the authentication control unit 204 generates feature values ​​from the registered biometric information (facial image) each time authentication processing is performed.

[0149] In the above embodiment, a case where a user management database and the like are configured inside the server device 10 has been described, but these databases may also be configured on an external database server or the like. That is, some of the functions of the server device 10 may be implemented on another server. More specifically, the above-described "accumulation period control unit (accumulation period control means)," "update control unit (update control means)," and the like may be implemented on any of the devices included in the system.

[0150] The form of data transmission and reception between the devices (server device 10, authentication terminal 20) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.

[0151] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0152] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0153] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems that provide users with services using biometric authentication.

[0154] Some or all of the above embodiments may be described as, but are not limited to, the following supplementary notes. [Supplementary Note 1] A server device comprising: a storage means for storing registered biometric information used for biometric authentication; a storage period control means for setting a biometric information storage period of a predetermined length at a predetermined frequency, which is a period for storing a user's biometric information; and an update control means for updating the registered biometric information using at least one piece of biometric information stored within the biometric information storage period. [Supplementary Note 2] The server device according to Supplementary Note 1 further comprises an authentication control means for receiving an authentication request including biometric information of a person to be authenticated from an authentication terminal, and performing authentication processing using the biometric information included in the authentication request and the stored registered biometric information, wherein the authentication control means stores biometric information determined to be successful for authentication within the biometric information storage period, and discards biometric information determined to be successful for authentication outside the biometric information storage period. [Supplementary Note 3] The server device according to Supplementary Note 2, wherein the update control means calculates a score indicating the suitability of at least one piece of biometric information accumulated during the biometric information accumulation period as biometric information for biometric authentication purposes, and selects biometric information to be used to update the registered biometric information based on the calculated score. [Supplementary Note 4] The server device according to any one of Supplements 1 to 3, wherein the accumulation period control means sets the biometric information accumulation period based on attribute information of the user. [Supplementary Note 5] The server device according to Supplementary Note 4, wherein the accumulation period control means determines a frequency at which the biometric information accumulation period is set according to the age of the user. [Supplementary Note 6] The server device according to Supplementary Note 5, wherein the accumulation period control means determines a length of the biometric information accumulation period based on the authentication history of the user. [Supplementary Note 7] The server device according to Supplementary Note 6, wherein the biometric information is a facial image or a feature generated from the facial image. [Supplementary Note 8] A control method for a server device, the method comprising: storing registered biometric information used for biometric authentication in the server device; setting a biometric information accumulation period having a predetermined length, which is a period for accumulating a user's biometric information, at a predetermined frequency; and updating the registered biometric information using at least one piece of biometric information accumulated within the biometric information accumulation period.[Supplementary Note 9] A computer-readable storage medium storing a program for causing a computer mounted on a server device to execute the following processes: a process of storing registered biometric information used for biometric authentication; a process of setting a biometric information accumulation period having a predetermined length at a predetermined frequency, which is a period for accumulating a user's biometric information; and a process of updating the registered biometric information using at least one piece of biometric information accumulated within the biometric information accumulation period.

[0155] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.

[0156] REFERENCE SIGNS LIST 10 Server device 20 Authentication terminal 30 Terminal 100 Server device 101 Storage means 102 Accumulation period control means 103 Update control means 201 Communication control unit 202 User management unit 203 Accumulation period control unit 204 Authentication control unit 205 Update control unit 206 Storage unit 301 Communication control unit 302 Biometric information acquisition unit 303 Authentication request unit 304 Storage unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface

Claims

1. a storage means for storing registered biometric information used for biometric authentication; an accumulation period control means for setting a predetermined length of biometric information accumulation period at a predetermined frequency, the biometric information being a period for accumulating biometric information of a user; an update control means for updating the registered biometric information using at least one piece of biometric information stored during the biometric information storage period; A server device comprising:

2. further comprising an authentication control means for receiving an authentication request including biometric information of a person to be authenticated from an authentication terminal, and performing authentication processing using the biometric information included in the authentication request and the stored registered biometric information; 2. The server device according to claim 1, wherein the authentication control means stores biometric information determined to be successfully authenticated within the biometric information storage period, and discards biometric information determined to be successfully authenticated outside the biometric information storage period.

3. 3. The server device according to claim 2, wherein the update control means calculates a score indicating the suitability of the biometric information for biometric authentication purposes for each of at least one piece of biometric information accumulated during the biometric information accumulation period, and selects the biometric information to be used to update the registered biometric information based on the calculated score.

4. The server device according to claim 1 , wherein the storage period control means sets the biometric information storage period based on attribute information of the user.

5. 5. The server device according to claim 4, wherein the storage period control means determines a frequency at which the biometric information storage period is set depending on an age of the user.

6. 6. The server device according to claim 5, wherein the storage period control means determines the length of the biometric information storage period based on an authentication history of the user.

7. The server device according to claim 6 , wherein the biometric information is a facial image or a feature amount generated from the facial image.

8. In the server device, Stores registered biometric information used for biometric authentication, setting a biometric information storage period having a predetermined length at a predetermined frequency, the biometric information storage period being a period for storing the biometric information of the user; A control method for a server device, the method comprising: updating the registered biometric information using at least one piece of biometric information stored within the biometric information storage period.

9. The computer installed in the server device A process of storing registered biometric information used for biometric authentication; a process of setting a biometric information storage period having a predetermined length at a predetermined frequency, the biometric information storage period being a period for storing biometric information of a user; updating the registered biometric information using at least one piece of biometric information accumulated during the biometric information accumulation period; A program to execute.