Server device, server device control method and program
Patent Information
- Application Number
- JP2025519276
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Priority Date
- 2023-05-11
- Filing Date
- 2023-05-11
- Publication Date
- 2026-01-22
AI Technical Summary
Existing network services lack the ability to selectively choose the optimal supervision method for users based on the specific circumstances and relationships between parties involved, such as adult-child or parent-young child scenarios, in managing online activities.
A server device and method that allow users to generate accounts and set access rights, enabling multi-access scenarios where one user can supervise or manage another's account activities, with options to set access rights or create proxy accounts based on the user's needs and relationships.
Enables tailored supervision methods for different user relationships, allowing for effective management of online activities and ensuring secure, authorized access, thereby enhancing user control and trust in network services.
Abstract
Description
Server device, server device control method and storage medium
[0001] The present invention relates to a server device, a control method for a server device, and a storage medium.
[0002] There are technologies that limit the services provided to users online (on a network).
[0003] For example, Patent Document 1 discloses an electronic shopping system that allows a user to supervise and restrict the overall Internet shopping activities of another user. The electronic shopping system of Patent Document 1 includes a customer profile database, a product database, and a transaction database. The electronic shopping system uses data records and ID numbers to facilitate the supervision of Internet shopping. A first user establishes shopping criteria and predetermines which items or categories, and in what quantities or frequency, a second user may purchase. The first user reviews the second user's selections before the purchase transaction is completed. Operations are performed on the data records to reduce the time and energy required to supervise the shopping selections. The electronic shopping system uses email and date and time information to notify users of activities being carried out in the system.
[0004] Japanese Patent Application Laid-Open No. 2004-078924
[0005] As described in Patent Literature 1, in services such as internet shopping, there is a need for other users to supervise the activities of a certain user on a network. Various methods are conceivable for realizing supervision of the activities of other users. Furthermore, the various methods for realizing such supervision vary depending on the circumstances and relationships of the parties involved. For example, the optimal method differs between an adult child supervising the activities of an elderly parent and a parent supervising the activities of a young child.
[0006] The main object of the present invention is to provide a server device, a control method for a server device, and a storage medium that contribute to enabling the selection of the most appropriate supervision method for services provided over a network, taking into account the circumstances of the parties involved, etc.
[0007] According to a first aspect of the present invention, a server device is provided, comprising: an account generation means for generating an account for a first user; and an access right setting means for setting access rights to the first user's account for a second user when the first user wishes the second user to be given access rights to an account in the name of the first user.
[0008] According to a second aspect of the present invention, there is provided a control method for a server device, in which an account for a first user is created in the server device, and when the first user wishes a second user to be granted access rights to an account in the name of the first user, the control method grants access rights to the first user's account to the second user.
[0009] According to a third aspect of the present invention, a computer-readable storage medium is provided that stores a program for causing a computer installed in a server device to execute the following processes: a process for generating an account for a first user; and a process for granting a second user access rights to the first user's account when the first user wishes the second user to have access rights to an account in the name of the first user.
[0010] According to each aspect of the present invention, a server device, a control method for a server device, and a storage medium are provided that contribute to enabling selection of an optimal supervision method for services provided over a network, taking into account the circumstances of the parties involved, etc. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.
[0011] FIG. 1 is a diagram illustrating an overview of an embodiment. FIG. 2 is a flowchart illustrating an overview of an operation of an embodiment. FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to a first embodiment. FIG. 4 is a diagram illustrating an operation of the information processing system according to the first embodiment. FIG. 5 is a diagram illustrating an example of a processing configuration of a server device according to the first embodiment. FIG. 6 is a diagram illustrating an example of a user management database according to the first embodiment. FIG. 7 is a diagram illustrating an example of a display of a terminal according to the first embodiment. FIG. 8 is a diagram illustrating an example of a display of a terminal according to the first embodiment. FIG. 9 is a diagram illustrating an example of a user management database according to the first embodiment. FIG. 10 is a flowchart illustrating an example of an operation of a service providing unit according to the first embodiment. FIG. 11 is a diagram illustrating an example of a hardware configuration of a server device according to the present disclosure.
[0012] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0013] A server device 100 according to one embodiment includes an account generation unit 101 and an access right setting unit 102 (see FIG. 1). The account generation unit 101 generates an account for a first user (step S1 in FIG. 2). When the first user requests a second user to have access rights to an account in the first user's name set for the second user, the access right setting unit 102 sets the second user the access rights to the first user's account (step S2).
[0014] When a user wishes to grant access rights to another person, the server device 100 grants the other person access rights to the user's account from among various methods that enable the user to supervise the activities of other users. For example, when an elderly parent entrusts the management of assets, etc. to a child, this access right setting is selected. Alternatively, the server device 100 may enable a user to create an account in another person's name on their behalf. When a user wishes to create an account in another person's name, the server device 100 may create the account in the other person's name. For example, this method is selected when a parent creates an account for their young child (e.g., an account related to electronic money). In this way, the server device 100 makes it possible to select the supervision method that is optimal for the circumstances of the parties (parent, child) regarding services provided on the network.
[0015] Specific embodiments will be described in more detail below with reference to the drawings.
[0016] First Embodiment The first embodiment will be described in more detail with reference to the drawings.
[0017] 3 is a diagram showing an example of a schematic configuration of an information processing system according to the first embodiment. The information processing system according to the first embodiment includes a plurality of server devices 10.
[0018] The server device 10 is managed and operated by a business operator (hereinafter referred to as a service provider) that provides various services to users. The service provider may be a private company or a public institution such as a local government. For example, a bank, a securities company, a credit card company, an EC (electronic commerce) business operator, a public health center, or a local government that manages My Number cards, etc., corresponds to the service provider.
[0019] A user carries a terminal 20. The user operates the terminal 20 to perform online shopping, for example.
[0020] 3 are connected to a network. Specifically, the server device 10 and the terminal 20 are connected to the network by wired or wireless communication means.
[0021] The configuration of the information processing system shown in Fig. 3 is an example and is not intended to be limiting. For example, although three server devices 10 are illustrated in Fig. 3, the system may include at least one server device 10 (service provider).
[0022] [Overall Operation] Next, an overall operation of the information processing system according to the first embodiment will be described.
[0023] <Creating an Account> By creating an account with a service provider, a user can receive various services from the service provider.
[0024] To create an account, the user operates the terminal 20 that the user owns to access the server device 10. In response to the access from the terminal 20, the server device 10 displays a WEB page or the like for creating an account.
[0025] The user creates an account on the web page. At that time, the server device 10 acquires information necessary for the user's account creation. Specifically, the server device 10 acquires login information (ID, password), name, date of birth, contact information, account information, biometric information, etc.
[0026] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes an individual's physical characteristics. In the present disclosure, biometric information is defined as a person's face image or features generated from a face image.
[0027] When the login information, biometric information, name, etc. are acquired, the server device 10 generates a user ID (identifier) for uniquely identifying the user.
[0028] The server device 10 stores the generated user ID, login information, name, date of birth, contact information, biometric information, etc. in association with each other. The server device 10 stores this information in a "user management database." The user management database will be described in detail later.
[0029] By creating an account on the server device 10, for example, the user can receive services from a service provider.
[0030] For example, a user can access the server device 10 provided by a credit card company to change (set) a monthly credit limit, or check a usage history (transaction history) in an account with the credit card company, or apply for various administrative procedures online in an account for administrative procedures.
[0031] <Multiple Access> Here, it goes without saying that an account holder can use (access) their own account. Furthermore, the server device 10 allows others to use the account. For example, a child can access (log in to) an account in their parent's name. Conversely, a parent can access an account in their child's name. In other words, the server device 10 allows "multiple access," in which multiple people access one account.
[0032] There are two ways to achieve multi-access.
[0033] The first method is to set access rights for a third party who accesses another person's account. For example, if the account holder is a parent, the child becomes the "access right grantee" who receives the access rights.
[0034] The second method is to create an account on behalf of another person. For example, a parent who creates an account in the name of a child is the "proxy account creator." In this case, the account created on behalf of the child (hereinafter referred to as the proxy account) is held in that child's name. The account holder is also referred to as the "proxy account holder."
[0035] <Setting Access Rights> First, a case where an account holder sets access rights for other people will be described.
[0036] To achieve multi-access, the account holder can set access rights to their account for others. For example, if an elderly parent entrusts their child with the management of their assets, access rights are set for the child.
[0037] In this case, the parent sets access rights for the child for each of their own accounts. For example, if a parent has accounts with service providers A, B, and C, the parent can set access rights for the child for each account. Of course, the parent does not have to set access rights for accounts that do not require access rights for the child.
[0038] The account holder (e.g., a parent) logs in to their account and registers information about the person (e.g., a child) for whom they want to set access rights. For example, the login information and biometric information (e.g., a facial image of the child) for the person are registered in the account.
[0039] The person to whom access rights have been granted can log in to the account to which access rights have been granted using the login information provided by the account holder.
[0040] Additionally, account holders can restrict the actions of those granted access rights on their accounts.
[0041] For example, in a credit card company account, the account holder may grant the access right holder the authority to check the usage history. Alternatively, the account holder may grant the access right holder the authority to change the credit limit. In this way, the account holder can grant the access right holder the authority (scope of authority) for actions on their account.
[0042] Alternatively, the server device 10 may automatically determine the scope of authority of the access right grantee based on the attributes (e.g., age) or condition (e.g., death of the account holder or illness suffered by the account holder) of the account holder or the access right grantee. For example, the server device 10 may automatically determine the scope of authority of the access right grantee when the account holder suffers from an illness such as dementia that makes them anxious or worried about making decisions on their own.
[0043] For example, if the account holder (e.g., a parent) is older than a predetermined age, the server device 10 grants all privileges to the access right grantee (e.g., a child). Alternatively, when the account holder dies, the server device 10 may grant all privileges to the access right grantee. That is, when the account holder dies, the server device 10 may disclose all information in the account of the account holder to the access right grantee. Alternatively, when the account holder becomes ill (e.g., suffers from dementia), the server device 10 may grant all privileges to the access right grantee.
[0044] In this way, the server device 10 may determine the scope of authority of the access right grantee depending on the age, death, illness, etc. of the account holder.
[0045] <Proxy Account Creation> Next, a case where a user creates an account for another person on their behalf will be described.
[0046] To achieve multi-access, an account holder can create an account in the name of another person on their behalf. Specifically, the account holder creates a proxy account by following a prescribed procedure in their own account.
[0047] The proxy account creator (e.g., a parent) registers the login information (ID, password), name, age, biometric information (e.g., a facial image), etc. used by the account holder (e.g., a child) in the server device 10. The server device 10 uses the acquired information to create a proxy account.
[0048] For example, a parent may create an account for a young child on their behalf, for example, the parent may create a proxy account for the child with an electronic money company account.
[0049] In this case, the proxy account creator has full authority over the proxy account holder's account. More specifically, the proxy account creator (e.g., parent) has a range of authority equal to or greater than that of the proxy account holder (e.g., child).
[0050] For example, a parent can check the usage status (history) of electronic money (prepaid electronic money) by their child and charge the electronic money through an account with an electronic money company.
[0051] By utilizing a proxy account, for example, it becomes possible for the account holder (child) to make deferred payment for services received from a service provider.
[0052] For example, consider a case where a child pays for something at a retail store, hospital, etc. When the user (child) requests deferred payment, the payment terminal 30 at the retail store, etc., sends a "deferred payment availability determination request" including the user's biometric information (e.g., a facial image) to the server device 10 (see FIG. 4). For example, the payment terminal 30 sends the deferred payment availability determination request to the server device 10 of an electronic money company.
[0053] When the server device 10 receives the request to determine whether or not deferred payment is possible, the server device 10 identifies the user (child) using the acquired biometric information. The server device 10 determines whether or not the account of the identified user is a proxy account created by the parent on their behalf. If it is a proxy account, the server device 10 determines that "deferred payment is possible." If it is not a proxy account, the server device 10 determines that "deferred payment is not possible."
[0054] The server device 10 transmits the determination result (post-payment possible, post-payment not possible) to the payment terminal 30.
[0055] When the notice of deferred payment is received, the settlement terminal 30 provides a service in which the payment for the child can be charged to the parent even if the charge amount for the user (child) is insufficient.
[0056] In this case, the payment terminal 30 notifies the server device 10 of the amount to be charged to the user (child). The server device 10 settles the notified amount at a predetermined timing (for example, at the end of the month) using the electronic money of the proxy account holder (for example, the child). Alternatively, if the server device 10 cannot settle the amount using the electronic money of the proxy account holder, it settles the amount using the electronic money or credit card of the creator of the proxy account (parent).
[0057] When notified that deferred payment is not possible, the payment terminal 30 requests the user (child) to pay in cash or the like (deferred payment is not permitted).
[0058] In this way, if a child has a proxy account created by a parent, the account has a certain level of trust, and the service provider can allow the service user to pay later.
[0059] The account holder, access right grantee, proxy account creator, and proxy account holder explained above will now be explained again.
[0060] An account holder is a user who creates a new account in their own name. An access right grantee is a user who can access another person's account and to whom the account holder grants access rights. For example, if the account holder is an elderly parent, the access right grantee is their adult child.
[0061] A proxy account creator is a user who already has an account and creates an account in someone else's name. A proxy account holder is the holder of an account created by someone else. For example, if the proxy account creator is a parent, the proxy account holder is a young child (minor child). Note that because an account holder can create a proxy account, the proxy account creator is also an account holder.
[0062] Next, details of each device included in the information processing system according to the first embodiment will be described.
[0063] [Server Device] Fig. 5 is a diagram showing an example of a processing configuration (processing module) of the server device 10 according to the first embodiment. Referring to Fig. 5, the server device 10 includes a communication control unit 201, an account creation unit 202, an access right setting unit 203, an authority range control unit 204, a proxy account creation unit 205, a service providing unit 206, and a storage unit 207.
[0064] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the terminal 20. The communication control unit 201 also transmits data to the terminal 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0065] The account generation unit 202 is a means for generating a user account. The account generation unit 202 acquires login information (e.g., ID and password), biometric information (e.g., face image), name, date of birth, contact information, etc. from the user's terminal 20 using a GUI (Graphical User Interface) or the like.
[0066] When the account generation unit 202 acquires a facial image of the user, it generates a feature amount from the acquired facial image.
[0067] Since existing technology can be used for the feature generation process by the account generation unit 202, a detailed description thereof will be omitted. For example, the account generation unit 202 extracts the eyes, nose, mouth, etc. from a facial image as feature points. The account generation unit 202 then calculates the positions of the feature points and the distances between the feature points as feature amounts (generating a feature vector consisting of multiple feature amounts).
[0068] Furthermore, the account generation unit 202 generates a user ID for identifying the user. For example, the account generation unit 202 assigns a unique number each time a user registers with the system, and uses the assigned number as the user ID.
[0069] The account creation unit 202 sets the account type of the created account to "normal." The account creation unit 202 sets the user type of the account creator to "account holder." The account creation unit 202 sets the status (health condition, etc.) of the account holder to "healthy." The account creation unit 202 sets the authority scope of the account holder to "full range."
[0070] The account generation unit 202 stores the user ID, login information, biometric information (feature amount), name, date of birth, status, scope of authority, etc. in the user management database (see FIG. 6). As shown in FIG. 6, the account generation unit 202 stores the information of the account holder in the user management database as "account holder information."
[0071] The user management database shown in FIG. 6 is merely an example, and is not intended to limit the items stored therein.
[0072] The access right setting unit 203 is a means for setting an access right to a third party different from the account holder. When a first user (e.g., an elderly parent) requests a second user (e.g., a child) to set an access right to the account held in the name of the first user, the access right setting unit 203 sets the second user an access right to the account of the first user.
[0073] When a user who has logged in to an account performs a predetermined operation, the access right setting unit 203 acquires information necessary to set access rights for a third party other than the account holder. For example, the access right setting unit 203 displays a GUI such as that shown in FIG. 7 on the terminal 20. In FIG. 7, when "Authority Range: All Range" is selected, it indicates that all authorities in the account are granted to the access right grantee. When "Check Credit Limit" is selected, it indicates that the access right grantee can check the credit limit for credit card usage by the account holder. When "Check Usage History" is selected, it indicates that the access right grantee can check the credit card usage history of the account holder.
[0074] The access right setting unit 203 acquires information about the access right grantee from the account holder, such as login information, name, date of birth, biometric information (e.g., face image), contact information (e.g., email address), and scope of authority for the access right grantee.
[0075] The access right setting unit 203 generates features from a facial image of the access right grantee. The access right setting unit 203 generates a user ID of the access right grantee. The access right setting unit 203 sets the user type of the access right grantee to "access right grantee."
[0076] The access right setting unit 203 stores information about the person to whom the access right is to be set in the account of the account holder as "access right set person information."
[0077] The authority range control unit 204 is a means for controlling the authority range of the account holder and the person to whom the access right is set.
[0078] The authority range control unit 204 determines the authority range of the account holder or access right grantee depending on the attributes (for example, age) and condition (death, dementia, etc.) of the account holder or access right grantee.
[0079] The authority range control unit 204 accesses the user management database periodically or at a predetermined timing. The authority range control unit 204 references the account holder information of each entry. For example, if the age of the account holder (e.g., parent) is equal to or greater than a predetermined value, the authority range control unit 204 grants all authority to the access right grantee (e.g., child) regarding actions on the account. Alternatively, the authority range control unit 204 may expand the authority range of the access right grantee as the account holder's age increases.
[0080] Alternatively, when the account holder dies, the authority scope control unit 204 may grant all authority to the access right grantee. In this case, the authority scope control unit 204 obtains a death notification of the account holder from the access right grantee (e.g., a child) using a GUI or the like. The authority scope control unit 204 obtains the name of the deceased from the obtained death notification, and if the name matches the account holder's name, the account holder is considered to be deceased.
[0081] Alternatively, if the account holder suffers from a specific illness (for example, dementia), the authority scope control unit 204 may grant all authority to the access right grantee. In this case, the authority scope control unit 204 obtains a medical certificate regarding the account holder from the access right grantee (for example, a child) using a GUI or the like. The authority scope control unit 204 obtains the account holder's name and the name of the illness from the obtained medical certificate. The authority scope control unit 204 uses the obtained name of the illness to understand the account holder's condition (whether the account holder has a specific illness).
[0082] In this way, the authority range control unit 204 may determine the authority range of a second user (e.g., a child) in an account in the name of a first user (e.g., a parent) depending on the attributes or status of the first user. Alternatively, the authority range control unit 204 may determine the authority range of a first user in an account in the name of the first user depending on the attributes or status of the first user.
[0083] Alternatively, if the age of the access right grantee is equal to or greater than a predetermined value, the authority range control unit 204 may grant the access right grantee all authority over the account. Alternatively, the authority range control unit 204 may expand the authority range of the access right grantee as the access right grantee's age increases.
[0084] The proxy account generation unit 205 is a means for generating an account in the name of another person on behalf of the other person.
[0085] When a first user (e.g., a parent) wishes to create an account for a second user (e.g., a child) on their behalf, the proxy account creation unit 205 creates an account in the name of the second user. In this case, the proxy account creation unit 205 sets the first user (e.g., a parent) with authority equal to or greater than that of the second user (e.g., a child) in the proxy account.
[0086] When a user who has logged in to an account performs a predetermined operation, the proxy account creation unit 205 acquires information necessary to create an account for a third party different from the account holder. For example, the access right setting unit 203 displays a GUI such as that shown in FIG. 8 on the terminal 20.
[0087] The proxy account generation unit 205 acquires information about the proxy account holder from the account holder, such as login information, name, date of birth, contact information, and biometric information (e.g., a facial image) for the proxy account holder.
[0088] The proxy account generation unit 205 generates features from the facial image of the proxy account holder. The proxy account generation unit 205 generates a user ID for the proxy account holder. The proxy account generation unit 205 sets the type of the generated account to "proxy account."
[0089] The proxy account generation unit 205 stores the proxy account holder's information (user ID, login information, name, date of birth, etc.) in the user management database as "account holder information" (see FIG. 9). Note that the proxy account generation unit 205 may set the proxy account holder's status to "healthy" or the like, or may not set a status. The proxy account generation unit 205 may also set the proxy account holder's scope of authority to "all range," or may limit the proxy account holder's scope of authority to some authority.
[0090] The proxy account generation unit 205 stores information about the user (e.g., parent) who generated the proxy account in the user management database as “proxy account generator information.” For example, the proxy account generation unit 205 stores information such as the user ID, login information, name, and date of birth of the proxy account generator in the user management database as the proxy account generator information.
[0091] At this time, the proxy account generation unit 205 sets the scope of authority of the proxy account creator to “all range.” In other words, the proxy account generation unit 205 sets authority to the proxy account creator that is greater than or equal to that of the proxy account holder.
[0092] 6 and the user management database shown in FIG. 9 may be the same database. That is, the account holder information, access right grantee information, and proxy account creator information may be stored in the same database. Alternatively, the databases that store the account holder information, etc. may be separate depending on the account type (normal account, proxy account).
[0093] The access right setting unit 203 and the proxy account generating unit 205 execute control so that duplication of login information between users does not occur.
[0094] The service providing unit 206 is a means for providing services to users. The service providing unit 206 provides the first and second users with services according to the authority ranges set for the first and second users.
[0095] The service providing unit 206 provides services according to the type and business of the service provider. For example, if the service provider is a credit card company, the service providing unit 206 provides information such as the usage history of users who log in to their accounts.
[0096] When a user logs in to an account, the service providing unit 206 searches the user management database using the login information (ID, password). Through the search, the service providing unit 206 identifies the type of user (account holder, access right grantee, proxy account holder, proxy account creator).
[0097] If the login information is set in the account holder information (account holder information field) of the normal account, the service providing unit 206 determines that the logged-in user is the "account holder."
[0098] If the login information is set in the access right grantee information of the normal account, the service providing unit 206 determines that the logged-in user is an "access right grantee."
[0099] If the login information is set in the account holder information of the proxy account, the service providing unit 206 determines that the logged-in user is the "proxy account holder."
[0100] If the login information is set in the proxy account creator information of the proxy account, the service providing unit 206 determines that the logged-in user is the "proxy account creator."
[0101] The service providing unit 206 provides services to users based on the scope of authority of the user type identified according to the login information. For example, the person to whom the access right is set supervises (monitors) the actions of the account holder. Alternatively, the proxy account creator supervises the actions of the proxy account holder.
[0102] As described above, the server device 10 realizes deferred payment by the proxy account holder. The service providing unit 206 realizes the deferred payment function.
[0103] 10 is a flowchart showing an example of the operation of the service providing unit 206 according to the first embodiment. The deferred payment function of the service providing unit 206 will be described with reference to FIG.
[0104] The service providing unit 206 receives a request for determining whether or not payment is possible from the payment terminal 30 installed at a storefront such as a retail store (step S101).
[0105] The service providing unit 206 executes a matching process using the biometric information included in the deferred payment availability determination request and the biometric information stored in the user management database (step S102).
[0106] More specifically, the service providing unit 206 generates features from the facial image included in the deferred payment availability determination request. The service providing unit 206 sets the generated features as a comparison target and performs a comparison process (one-to-N comparison; N is a positive integer, the same applies hereinafter) with the features stored in the user management database.
[0107] The service providing unit 206 calculates the similarity between the feature to be matched and each of the multiple feature values on the registration side. The similarity can be calculated using chi-square distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0108] If there is no feature among the multiple features stored in the user management database whose similarity with the feature to be matched is equal to or greater than a predetermined value, the service providing unit 206 determines that the matching process has failed.
[0109] The service providing unit 206 determines that the matching process is successful if there is a feature among the multiple feature amounts stored in the user management database that has a similarity to the feature amount to be matched that is equal to or greater than a predetermined value. In this case, the user with the entry with the highest similarity is identified as a user who wishes to pay later.
[0110] If the matching process fails (step S103, No branch), the service providing unit 206 sets the determination result to "post-payment not possible" (step S104).
[0111] If the matching process is successful (step S103, Yes branch), the service providing unit 206 determines whether the user identified by the matching process is the proxy account holder (e.g., a child) (holder determination; step S105).
[0112] Specifically, if the account type of the identified user is a "proxy account" and the user type of the identified user is an "account holder," the service providing unit 206 determines that the identified user is a proxy account holder.
[0113] If the user is not the proxy account holder (step S106, No branch), the service providing unit 206 sets the determination result to "Deferred payment not available" (step S104).
[0114] If the user is a proxy account holder (step S106, Yes branch), the service providing unit 206 sets the determination result to "Deferred payment available" (step S107).
[0115] The service providing unit 206 transmits the determination result (post-payment possible, post-payment not possible) to the payment terminal 30 (step S108).
[0116] In this way, the service providing unit 206 receives a deferred payment availability determination request including biometric information of a user (e.g., a child) who wishes to pay later from the payment terminal 30. The service providing unit 206 identifies the user who wishes to pay later by performing a matching process using the biometric information included in the deferred payment availability determination request and the biometric information stored in the user management database. If the account of the identified user is a proxy account, the service providing unit 206 notifies the payment terminal 30 that deferred payment is available.
[0117] Note that detailed description of the service providing unit 206 relating to services other than the deferred payment service (services according to each service provider) will be omitted because detailed description of the provision of individual services is outside the scope of the present disclosure.
[0118] The storage unit 207 is a means for storing information necessary for the operation of the server device 10. The storage unit 207 uses a user management database to store at least the account type and the biometric information of the account holder in association with each other.
[0119] [Terminal] Examples of the terminal 20 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers). The terminal 20 can be any equipment or device that can accept user operations and communicate with the server device 10, etc. The configuration of the terminal 20 is clear to those skilled in the art, so detailed description thereof will be omitted.
[0120] [Payment Terminal] The payment terminal 30 is a so-called POS (Point of Sale) terminal. When a user requests deferred payment, the payment terminal 30 acquires the user's biometric information (e.g., a facial image). The payment terminal 30 transmits a deferred payment availability determination request, including the acquired biometric information, to a predetermined server device 10. The payment terminal 30 notifies a store clerk or the like of the determination result (deferred payment available, deferred payment unavailable). Note that a detailed description of the configuration and operation of the payment terminal 30 will be omitted, as the configuration and other aspects of the payment terminal 30 will be apparent to those skilled in the art.
[0121] Next, a modification of the first embodiment will be described.
[0122] <Modification 1> In the above embodiment, when an access right is set for an account holder, the server device 10 acquires information about the access right holder using a GUI such as that shown in Fig. 7. The access right setting unit 203 of the server device 10 may link (link) an existing account of the access right holder with the account of the account holder.
[0123] Specifically, the access right setting unit 203 acquires the login ID of the access right grantee (e.g., a child) from the account holder (e.g., an elderly parent). The access right setting unit 203 may register information such as the name stored in association with the acquired login ID in the user management database as access right grantee information.
[0124] <Modification 2> The server device 10 may have a function of supervising the actions of the account holder and the proxy account holder.
[0125] For example, the server device 10 (service providing unit 206) of a credit card company may notify the person to whom the access right is to be set when the amount of a single payment made by the account holder exceeds a predetermined amount. Alternatively, the server device 10 of a bank may notify the person to whom the access right is to be set when the account holder transfers more than a predetermined amount (or registers a transfer application).
[0126] Such a function of the server device 10 can protect the account holder from sudden behavior or fraud caused by the account holder suffering from dementia or the like.
[0127] <Modification 3> The server device 10 may realize the transfer of electronic money or points between the account holder and the person to whom the access right is set, or between the proxy account holder and the proxy account creator. For example, the server device 10 may grant points or electronic money to the proxy account holder in response to an instruction from the proxy account creator.
[0128] As described above, the server device 10 according to the first embodiment allows a user (e.g., a parent) to set access rights for another person (e.g., a child). For example, a child can use an account in the parent's name within the scope of the set access rights. The child can monitor the parent's activities on the network to prevent the parent from being defrauded, etc. Alternatively, the server device 10 allows a user (e.g., a parent) to create an account for another person (e.g., a child) on their behalf. The parent has full authority over the child's account. Furthermore, if the child requests deferred payment, the server device 10 allows the deferred payment if the child is the proxy account holder. In this way, the server device 10 provides the user (parent, child) with multi-access capabilities suited to their situation and condition.
[0129] Next, the hardware of each device constituting the information processing system will be described. Fig. 10 is a diagram showing an example of the hardware configuration of the server device 10.
[0130] The server device 10 can be configured by an information processing device (so-called computer), and has the configuration shown in Fig. 10. For example, the server device 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0131] However, the configuration shown in Fig. 10 is not intended to limit the hardware configuration of the server device 10. The server device 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the server device 10 is not intended to be limited to the example shown in Fig. 10, and for example, the server device 10 may include multiple processors 311.
[0132] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0133] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0134] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a keyboard, a mouse, a touch panel, or the like that accepts user operations.
[0135] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0136] The functions of the server device 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by semiconductor chips.
[0137] The terminal 20, the payment terminal 30, etc. can also be configured by an information processing device in the same way as the server device 10, and their basic hardware configurations are no different from those of the server device 10, so a description thereof will be omitted.
[0138] The server device 10 is equipped with a computer, and the computer executes a program to realize the functions of the server device 10. The server device 10 also executes a control method for the server device 10 by the program.
[0139] [Modifications] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0140] In the above embodiment, the multi-access target is described as a parent and a child. However, it is obvious that the multi-access target is not limited to a parent and a child. For example, the multi-access target may be a grandparent and a grandchild, or an acquaintance or a friend.
[0141] In the above embodiment, the server device 10 has been described as using login information to identify a user logging in to the server device 10. The server device 10 may also use biometric authentication to identify a user logging in. In this case, if a user identified by biometric authentication has multiple user types (e.g., account holder or proxy account creator), the server device 10 may obtain from the user which user type the user will log in as.
[0142] In the above embodiment, the server device 10 identifies a user who wishes to pay later by performing a matching process using biometric information. However, the server device 10 may identify a user who wishes to pay later by other methods. For example, the server device 10 may identify the user by obtaining a user ID or login ID from the user. For example, the payment terminal 30 may obtain a user ID or the like from the user when transmitting a request to determine whether or not payment is possible. For example, the user may present a two-dimensional barcode converted from the user ID or login ID issued by the server device 10 to the payment terminal 30, enter the user ID into the payment terminal 30, or have the payment terminal 30 read a card on which the user ID is stored.
[0143] The access right setting unit 203 of the server device 10 may obtain information about the access right grantee from the access right grantee rather than from the account holder. For example, the access right setting unit 203 obtains contact information for the access right grantee from the account holder. The access right setting unit 203 transmits an URL (Uniform Resource Locator) of an information acquisition page such as that shown in FIG. 7 to the obtained contact information. The access right setting unit 203 obtains the name, etc., of the access right grantee from the terminal 20. Note that the access right setting unit 203 may obtain the authority range of the access right grantee from the account holder.
[0144] When setting an access right grantee, the server device 10 may set the access right grantee after obtaining consent from the access right grantee. Specifically, the access right setting unit 203 acquires contact information for the access right grantee from the account holder. The access right setting unit 203 inquires of the acquired contact information (email address) whether or not the access right should be granted (whether or not the access right is granted). If the access right grantee agrees to the access right setting, the access right setting unit 203 acquires information about the access right grantee using a GUI similar to that shown in FIG. 7 .
[0145] Alternatively, the server device 10 may set an access right grantee in response to an application (request) from the access right grantee. For example, when an "access right setting request" including information identifying the account holder (e.g., a login ID, a name, etc.) is received from the child's terminal 20, the access right setting unit 203 inquires of the account holder whether or not to agree to the setting of the access right. If the account holder agrees to the setting of the access right, the access right setting unit 203 acquires information about the access right grantee.
[0146] When changing the authority of a user (the authority range of the account holder, the authority range of the access right grantee), the authority range control unit 204 of the server device 10 may obtain consent from the parties regarding the change in the authority range. Alternatively, the authority range control unit 204 may obtain consent when the authority range is either narrowed or expanded. For example, when the authority of an account holder (e.g., an elderly parent) is reduced, the authority range control unit 204 may obtain consent regarding the reduction in authority from the account holder.
[0147] The authority range control unit 204 of the server device 10 may change (reduce) the authority range of the proxy account creator depending on the attributes (e.g., age) of the proxy account holder. Alternatively, the authority range control unit 204 may revoke the authority of the proxy account creator when the proxy account holder reaches a predetermined age. For example, the authority range control unit 204 may revoke the supervisory authority of the proxy account creator when the proxy account holder reaches adulthood. Alternatively, the authority range control unit 204 may obtain the consent of the parties involved when changing the authority range of the proxy account creator.
[0148] The server device 10 may perform identity verification of a user when creating an account. For example, the server device 10 acquires biometric information (facial image) from an identification card such as a passport held by the user. For example, the server device 10 performs identity verification using biometric information (facial image) obtained by photographing the user and biometric information obtained from the identification card. The server device 10 performs identity verification by determining whether the two sets of biometric information substantially match.
[0149] In the above embodiment, the explanation was mainly given using examples of the account holder, the access right grantee, the proxy account creator, and the proxy account holder parent and child. However, the relationship between the account holder and the access right grantee, and the relationship between the proxy account creator and the proxy account holder, can also be established between users who are not related by blood. For example, if the account holder is a retiring employee (company employee), the access right grantee can also be an employee who takes over the employee's work.
[0150] In the above embodiment, the case where the user management database is configured inside the server device 10 has been described, but the database may also be configured on an external database server or the like. That is, some of the functions of the server device 10 may be implemented in another device. More specifically, it is sufficient that the above-described "access right setting unit (access right setting means)" and the like are implemented in any of the devices included in the system.
[0151] The form of data transmission between each device (e.g., server device 10, payment terminal 30) is not particularly limited, but the data transmitted between these devices may be encrypted. Biometric information of users and other data are transmitted between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.
[0152] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0153] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0154] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems including service providers that provide services to users over a network.
[0155] Some or all of the above embodiments may be described as, but are not limited to, the following supplementary notes. [Supplementary Note 1] A server device comprising: account generation means for generating an account for a first user; and access right setting means for setting access rights to the first user's account for a second user when the first user requests that the second user be given access rights to the account in the first user's name. [Supplementary Note 2] The server device according to Supplementary Note 1, further comprising proxy account generation means for generating an account in the name of the second user when the first user requests that an account for the second user be created on their behalf. [Supplementary Note 3] The server device according to Supplementary Note 2, wherein the proxy account generation means sets the first user with authority equal to or greater than that of the second user in the account in the second user's name. [Supplementary Note 4] The server device according to Supplementary Note 3, further comprising authority range control means for determining the authority range of the second user in the name of the first user according to the attributes or status of the first user. [Supplementary Note 5] The server device according to Supplementary Note 4, wherein the authority scope control means determines the authority scope of the first user for the account in the name of the first user according to the attributes or status of the first user. [Supplementary Note 6] The server device according to Supplementary Note 5, further comprising service providing means for providing services to the first and second users according to the authority scopes set for the first and second users. [Supplementary Note 7] The server device according to Supplementary Note 6, further comprising storage means for storing an account type and biometric information of the account holder in association with each other, wherein the service providing means receives from a payment terminal a deferred payment availability determination request including biometric information of a user who wishes to pay later, identifies the user who wishes to pay later by performing a matching process using the biometric information included in the deferred payment availability determination request and the stored biometric information, and if the account of the identified user is a proxy account, notifies the payment terminal that deferred payment is available. [Supplementary Note 8] The server device according to Supplementary Note 7, wherein the biometric information is a facial image or a feature generated from the facial image.[Supplementary Note 9] A control method for a server device, in which a server device generates an account for a first user, and when the first user requests a second user to have access rights to an account in the name of the first user, sets the second user the right to access the account of the first user. [Supplementary Note 10] A computer-readable storage medium storing a program for causing a computer installed in the server device to execute the following processes: a process for generating an account for a first user, and a process for setting the second user the right to access the account of the first user, when the first user requests the second user to have access rights to the account in the name of the first user.
[0156] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.
[0157] 10 Server device 20 Terminal 30 Payment terminal 100 Server device 101 Account generation means 102 Access right setting means 201 Communication control unit 202 Account generation unit 203 Access right setting unit 204 Authority range control unit 205 Proxy account generation unit 206 Service provision unit 207 Storage unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface
Claims
1. an account creation means for creating an account for the first user; an access right setting means for setting an access right to the account of the first user to a second user when the first user requests the second user to set an access right to the account in the name of the first user; A server device comprising:
2. The server device according to claim 1, further comprising a proxy account generation means for generating an account in the name of the second user when the first user wishes to generate an account for the second user on his / her behalf.
3. 3. The server device according to claim 2, wherein the proxy account generation means sets authority for the first user equal to or greater than that of the second user in an account in the name of the second user.
4. 4. The server device according to claim 3, further comprising an authority range control means for determining an authority range of the second user under the name of the first user according to an attribute or status of the first user.
5. 5. The server device according to claim 4, wherein the authority scope control means determines the authority scope of the first user in the account in the name of the first user according to the attributes or status of the first user.
6. 6. The server device according to claim 5, further comprising a service providing unit that provides the first and second users with services according to the authority ranges set for the first and second users.
7. The system further comprises a storage means for storing the account type and the biometric information of the account holder in association with each other, The service providing means receives, from the payment terminal, a request for determining whether or not deferred payment is possible, the request including biometric information of a user who wishes to defer payment; Identifying a user who wishes to pay later by performing a matching process using the biometric information included in the request for determining whether or not the payment is possible and the stored biometric information; The server device according to claim 6 , wherein if the identified user's account is a proxy account, the server device notifies the payment terminal that deferred payment is possible.
8. The server device according to claim 7 , wherein the biometric information is a face image or a feature amount generated from the face image.
9. In the server device, Creating an account for the first user; A control method for a server device, which, when a first user requests a second user to be granted access rights to an account in the name of the first user, grants the second user access rights to the first user's account.
10. The computer installed in the server device creating an account for a first user; a process of granting access rights to the account of the first user to the second user when the first user requests the second user to grant access rights to the account in the name of the first user; A program to execute.