Information processing system, information processing device, information processing method, and storage medium
The system uses biometric eye information for accurate user identification and verification in virtual spaces, integrating iris authentication with visual confirmation to enhance security and control access effectively.
Patent Information
- Application Number
- PCT/JP2024/010489
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-18
- Publication Date
- 2025-09-25
AI Technical Summary
Existing systems for access control in virtual spaces with high security levels lack robust biometric authentication methods that ensure accurate user identification and verification, often relying solely on ID and password combinations or visual confirmation by security personnel.
An information processing system that utilizes biometric information from a user's eyes, such as iris features, to perform authentication, outputs relevant information to a security terminal, and receives permission to access a virtual space based on successful authentication, incorporating additional visual confirmation by security personnel.
Enhances security by ensuring accurate user identification through biometric authentication, allowing or denying access to virtual spaces based on thorough verification processes, reducing the risk of unauthorized entry.
Smart Images

Figure JP2024010489_25092025_PF_FP_ABST
Abstract
Description
Information processing system, information processing device, information processing method, and recording medium
[0001] The present disclosure relates to the technical fields of an information processing system, an information processing device, an information processing method, and a recording medium.
[0002] As an example of this type of system, a system has been proposed that uses an image of the facial area that can be observed by an inward-facing camera of a wearable device worn by a user whose facial expression cannot be determined from the outside to represent the facial expression of the user's avatar (see Patent Document 1).
[0003] Japanese Patent Application Laid-Open No. 2023-096152
[0004] An object of this disclosure is to provide an information processing system, an information processing device, an information processing method, and a recording medium that aim to improve the technology related to the above-mentioned prior art documents.
[0005] One aspect of the information processing system comprises an acquisition means for acquiring biometric information including information relating to the eyes of a subject wearing a wearable device, an authentication means for performing biometric authentication of the subject using the biometric information, an output means for outputting subject information relating to the subject to a security terminal if the biometric authentication by the authentication means is successful, and a receiving means for receiving permission information from the security terminal indicating whether the subject can log in to a virtual space based on the subject information.
[0006] One aspect of the information processing device comprises an acquisition means for acquiring biometric information including information relating to the eyes of a subject wearing a wearable device, an authentication means for performing biometric authentication of the subject using the biometric information, an output means for outputting subject information relating to the subject to a security terminal if the biometric authentication by the authentication means is successful, and a receiving means for receiving permission information from the security terminal indicating whether the subject can log in to a virtual space based on the subject information.
[0007] One aspect of the information processing method involves acquiring biometric information including information related to the eyes of a subject wearing a wearable device, performing biometric authentication of the subject using the biometric information, and if the biometric authentication is successful, outputting subject information related to the subject to a security terminal, and receiving permission information from the security terminal indicating whether the subject can log in to a virtual space based on the subject information.
[0008] One aspect of the recording medium has a computer program recorded on it that causes a computer to execute an information processing method that acquires biometric information including information related to the eyes of a subject wearing a wearable device, performs biometric authentication of the subject using the biometric information, and if the biometric authentication is successful, outputs subject information related to the subject to a security terminal, and receives permission information from the security terminal that indicates whether the subject can log in to a virtual space based on the subject information.
[0009] 1 is a diagram illustrating an example of a configuration of an information processing system according to an embodiment. FIG. 2 is a flowchart illustrating an example of an operation of the information processing system according to an embodiment. FIG. 3 is a diagram illustrating another example of a configuration of an information processing system according to an embodiment. FIG. 4 is a block diagram illustrating an example of a configuration of a terminal device according to an embodiment. FIG. 5 is a diagram illustrating an example of a configuration of a wearable device according to an embodiment. FIG. 6 is a block diagram illustrating an example of a configuration of an authentication server according to an embodiment. FIG. 7 is a block diagram illustrating an example of a configuration of a arithmetic device of an authentication server according to an embodiment. FIG. 8 is a conceptual diagram illustrating the concept of image synthesis. FIG. 9 is a diagram illustrating another example of a configuration of an information processing system according to an embodiment. FIG. 10 is a block diagram illustrating an example of a configuration of a virtual world server according to an embodiment. FIG. 11 is a block diagram illustrating an example of a configuration of a arithmetic device of a virtual world server according to an embodiment. FIG. 12 is a block diagram illustrating another example of a configuration of an information processing system according to an embodiment. FIG. 13 is a block diagram illustrating another example of a configuration of an authentication server according to an embodiment. FIG. 14 is a block diagram illustrating another example of a configuration of a arithmetic device of a terminal device according to an embodiment. FIG. 15 is a block diagram illustrating another example of a configuration of an authentication server according to an embodiment.
[0010] First Embodiment A first embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described with reference to Fig. 1 and Fig. 2. Hereinafter, the first embodiment of the information processing system, the information processing device, the information processing method, and the recording medium will be described using an information processing system 1.
[0011] 1, the information processing system 1 includes an acquisition device 11, an authentication device 12, an output device 13, and a receiving device 14. The acquisition device 11 acquires biometric information including information related to the eyes of a subject wearing a wearable device (e.g., a head-mounted display (HMD)). The information related to the eyes of the subject may be, for example, an eye image including the subject's eyes, or feature amounts extracted from the eye image. Note that the feature amounts extracted from the eye image may be feature amounts related to the subject's iris.
[0012] The wearable device may be, for example, an immersive head-mounted display, a video see-through head-mounted display, or an optical see-through head-mounted display (so-called Augmented Reality (AR) glasses). The acquisition device 11 may be provided in the wearable device. That is, the acquisition device 11 may constitute a part of the wearable device. Alternatively, the acquisition device 11 may be an external device to the wearable device. That is, the acquisition device 11 does not have to constitute a part of the wearable device.
[0013] The authentication device 12 performs biometric authentication of a target using biometric information. As described above, the biometric information includes information related to the target's eyes. Therefore, the authentication device 12 may perform iris authentication as biometric authentication. The authentication device 12 may be provided in a wearable device. That is, the authentication device 12 may constitute a part of the wearable device. Alternatively, the authentication device 12 may be a device external to the wearable device. That is, the authentication device 12 does not have to constitute a part of the wearable device.
[0014] When biometric authentication by the authentication device 12 is successful, the output device 13 outputs target information about the target to the security terminal. Here, "biometric authentication is successful" may mean that the target is identified as one of the pre-registered registrants. Note that "biometric authentication is unsuccessful" may mean that the target does not correspond to any of the pre-registered registrants. The target information may include, for example, at least one of information for identifying the target (such as name, identification number, affiliation, etc.) and information indicating the target's status (such as audio and images). Note that "security terminal" refers to a terminal device used for security work. In other words, in this embodiment, a terminal device used for security work is referred to as a "security terminal." The terminal device serving as a security terminal may be a dedicated device with a configuration specialized for security work, or may be a general-purpose device. The security terminal may be, for example, at least one of a personal computer, a tablet terminal, and a smartphone. Note that the security terminal may be equipped with AI (artificial intelligence) specialized for security work. In this case, the security terminal may be a security robot.
[0015] The receiving device 14 receives permission information from the security terminal indicating whether or not a user is permitted to log in to the target virtual space based on the target information. The "virtual space" may refer to a three-dimensional virtual space constructed on at least one of a network and a computer. The "virtual space" may be, for example, a virtual space that can be used jointly by multiple users.
[0016] The acquisition device 11, authentication device 12, output device 13, and receiving device 14 may be provided in a single device. The single device may be, for example, a server device. In this case, the server device including the acquisition device 11, authentication device 12, output device 13, and receiving device 14 corresponds to the information processing device according to this embodiment. For example, a wearable device may include the acquisition device 11, authentication device 12, output device 13, and receiving device 14. In this case, the wearable device corresponds to the information processing device according to this embodiment. The acquisition device 11, authentication device 12, output device 13, and receiving device 14 may be devices independent of each other.
[0017] The operation of the information processing system 1 will be described with reference to the flowchart of Fig. 2. In Fig. 2, the acquisition device 11 acquires biometric information including information related to the eyes of a subject wearing a wearable device (e.g., an HMD) (step S101). The authentication device 12 performs biometric authentication of the subject using the biometric information acquired in the processing of step S101 (step S102).
[0018] If the biometric authentication of the target is successful, the authentication device 12 may transmit information indicating the success of the biometric authentication to the output device 13. Upon receiving the information indicating the success of the biometric authentication, the output device 13 outputs target information regarding the target to the security terminal (step S103). The receiving device 14 receives permission information indicating whether the target is allowed to log in to the virtual space based on the target information from the security terminal (step S104).
[0019] If the target biometric authentication fails in the process of step S102, the operation shown in Fig. 2 may be ended. In this case, the processes from step S103 onward may not be performed.
[0020] In this way, the information processing system 1 may perform an information processing method in which it acquires biometric information including information related to the eyes of the subject wearing the wearable device, performs biometric authentication of the subject using the biometric information, and if the biometric authentication is successful, outputs target information related to the subject to a security terminal, and receives permission information from the security terminal indicating whether the subject can log in to the virtual space based on the target information.
[0021] For example, a single device (e.g., a server device or a wearable device) including the acquisition device 11, the authentication device 12, the output device 13, and the receiving device 14 may be realized by a computer constituting the single device reading a computer program recorded on a recording medium. In this case, the recording medium may have recorded thereon a computer program for causing the computer to execute an information processing method for acquiring biometric information including information related to the eyes of a subject wearing the wearable device, performing biometric authentication of the subject using the biometric information, and, if the biometric authentication is successful, outputting subject information related to the subject to a security terminal, and receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
[0022] (Technical Effect) In the real world, in access control for areas with a relatively high security level, in addition to identity verification using, for example, a security card or biometric authentication, visual confirmation by at least one of a security guard and a guard is often performed. As the use of virtual spaces becomes more widespread, virtual spaces with a relatively high security level may be created. Access control for virtual spaces with a relatively high security level may require identity verification using an ID and password or biometric authentication, as in the real world, and confirmation of the user (corresponding to the above-mentioned target) by at least one of a security guard and a guard. An example of a virtual space with a relatively high security level is an office built in a virtual space (i.e., a virtual office).
[0023] In the information processing system 1, when the biometric authentication of a target by the authentication device 12 is successful, target information is output to the security terminal. Therefore, an operator of the security terminal (e.g., a security guard or a security guard) can confirm the target based on the target information. Therefore, according to the information processing system 1, in addition to identity confirmation by biometric authentication, the operator of the security terminal can confirm the target.
[0024] If the permission information indicates that the target is permitted to log in to the virtual space, the target may log in to the virtual space. On the other hand, if the permission information indicates that the target is not permitted to log in to the virtual space, the target cannot log in to the virtual space.
[0025] Second Embodiment A second embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described with reference to Figures 3 to 8. Below, the second embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described using an information processing system 2. Note that, for the second embodiment, descriptions that overlap with the description of the first embodiment will be omitted as appropriate.
[0026] (Overview of Information Processing System 2) In Figure 3, the information processing system 2 comprises a terminal device 100, an authentication server 200, a security terminal 300, and a virtual world server 400. The terminal device 100, the authentication server 200, the security terminal 300, and the virtual world server 400 are configured to be able to communicate with each other via a network such as the Internet. The virtual world server 400 is a server for realizing a virtual space. The security terminal 300 corresponds to the security terminal in the first embodiment.
[0027] When user U uses terminal device 100 to log in to a virtual space realized by virtual world server 400, information processing system 2 may perform the following operations. First, when user U wearing wearable device 151 uses terminal device 100 to access virtual world server 400 (e.g., a homepage related to the virtual space provided by virtual world server 400), virtual world server 400 may transmit information for authentication to terminal device 100. Having received the information for authentication, terminal device 100 may automatically access authentication server 200 based on the information for authentication. Note that the information for authentication may be, for example, information for accessing authentication server 200 (e.g., the URL of an authentication page related to authentication server 200).
[0028] The authentication server 200 may acquire biometric information of the user U from the terminal device 100. The authentication server 200 may perform biometric authentication of the user U using the biometric information. If the biometric authentication is successful, the authentication server 200 may output user information about the user U to the security terminal 300. The operator O of the security terminal 300 may determine whether or not the user U can log in to the virtual space based on the user information. The operator O of the security terminal 300 may be a person performing security duties. An example of a person performing security duties is at least one of a security guard and a security guard. The operator O may also be a person who operates the security terminal 300 in accordance with the instructions of a person performing security duties. In other words, the operator O may be a person who indirectly performs security duties.
[0029] The operator O may use the security terminal 300 to transmit permission information (in other words, the result of the operator O's judgment) indicating whether or not the user U is permitted to log in to the virtual space to the authentication server 200. As a result, the authentication server 200 may receive the permission information indicating whether or not the user U is permitted to log in to the virtual space. The authentication server 200 may transmit the permission information to the terminal device 100.
[0030] If the permission information indicates that user U is permitted to log in to the virtual space, the terminal device 100 may transmit the permission information to the virtual world server 400. As a result, user U may log in to the virtual space. On the other hand, if the permission information indicates that user U is not permitted to log in to the virtual space, the terminal device 100 may, for example, notify user U that he or she cannot log in to the virtual space. Note that "user U" corresponds to "target" in the first embodiment.
[0031] (Configuration of Terminal Device 100) The configuration of the terminal device 100 will be described with reference to Fig. 4. In Fig. 4, the terminal device 100 includes a calculation device 110, a storage device 120, a communication device 130, an input device 140, an output device 150, and a camera 170. The calculation device 110, the storage device 120, the communication device 130, the input device 140, the output device 150, and the camera 170 may be connected via a data bus 160. The camera 170 may be a camera for capturing an image of the appearance of the user U. The camera 170 may be positioned so as to be able to capture an image of at least the head of the user U, for example. The camera 170 may be a visible light camera sensitive to the visible light wavelength range.
[0032] The arithmetic device 110 may include a processor 1101. The arithmetic device 110 may include other processors in addition to the processor 1101. That is, the arithmetic device 110 may include one or more processors. The processor 1101 may be a multi-core processor. When the arithmetic device 110 includes a single processor 1101 that is a multi-core processor, it can be said that the arithmetic device 110 logically includes multiple processors.
[0033] The processor 1101 may be, for example, at least one of a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field Programmable Gate Array), a TPU (Tensor Processing Unit), and a quantum processor.
[0034] The storage device 120 may include a memory 1201. The storage device 120 may include other memories in addition to the memory 1201. That is, the storage device 120 may include one or more memories. The memory 1201 may be, for example, at least one of a RAM (Random Access Memory), a ROM (Read Only Memory), a hard disk device, a magneto-optical disk device, an SSD (Solid State Drive), and an optical disk array. Therefore, the storage device 120 may include the memory 1201 as a non-transitory recording medium.
[0035] The storage device 120 can store desired data. A computer program 1201a to be executed by the arithmetic device 110 may be stored in the memory 1201 of the storage device 120. The storage device 120 may temporarily store data that is temporarily used by the arithmetic device 110 when the arithmetic device 110 is executing the computer program 1201a.
[0036] The computer program 1201a may be recorded on a computer-readable, non-transitory recording medium. In this case, the computer program 1201a may be stored in the memory 1201 by reading the recording medium using a recording medium reading device (not shown) included in the terminal device 100. The recording medium may be at least one of an optical disk, a magnetic medium, a magneto-optical disk, a semiconductor memory, and any other medium capable of storing a program. The computer program 1201a may be acquired (in other words, downloaded) from a device (not shown) external to the terminal device 100 via the communication device 130. The acquired computer program 1201a may be stored in the memory 1201.
[0037] The communication device 130 may be capable of communicating with devices external to the terminal device 100 (e.g., the authentication server 200 and the virtual world server 400). The communication device 130 may perform wired communication or wireless communication.
[0038] The input device 140 is a device capable of accepting information input to the terminal device 100 from outside. The input device 140 may include an operation device (e.g., a keyboard, a mouse, a touch panel, etc.) that can be operated by a user of the terminal device 100. The input device 140 may include a recording medium reading device that can read information recorded on a recording medium that is detachable from the terminal device 100, such as a USB (Universal Serial Bus) memory. Note that when information is input to the terminal device 100 via the communication device 130 (in other words, when the terminal device 100 acquires information via the communication device 130), the communication device 130 may function as an input device.
[0039] The output device 150 is a device capable of outputting information to the outside of the terminal device 100. The output device 150 may output visual information such as text or images, auditory information such as sound, or tactile information such as vibration, as the information. The output device 150 may include, for example, at least one of a display, a speaker, a printer, and a vibration motor. The output device 150 may be capable of outputting information to a recording medium detachable from the terminal device 100, such as a USB memory. Note that when the terminal device 100 outputs information via the communication device 130, the communication device 130 may function as the output device. In particular, in this embodiment, the output device 150 includes a wearable device 151.
[0040] The processor 1101 of the arithmetic device 110, together with the memory 1201 of the storage device 120 in which the computer program 1201a is stored (in other words, together with the memory 1201 and the computer program 1201a stored in the memory 1201), may execute the processing to be performed by the terminal device 100. For example, the processor 1101 may execute the computer program 1201a, thereby realizing a logical functional block in the arithmetic device 110 (for example, in the processor 1101) for executing the processing to be performed by the terminal device 100.
[0041] The wearable device 151 will be described with reference to Fig. 5. Here, a video see-through head-mounted display is taken as the wearable device 151. Note that the wearable device 151 is not limited to a video see-through head-mounted display, and may be, for example, an immersive head-mounted display or an optical see-through head-mounted display.
[0042] The head-mounted display as an example of the wearable device 151 may be a PC-connected head-mounted display that is connected to a personal computer as an example of the terminal device 100. Note that the head-mounted display as an example of the wearable device 151 may be a standalone head-mounted display. Alternatively, the head-mounted display as an example of the wearable device 151 may be a hybrid head-mounted display (i.e., a head-mounted display that can operate as both a standalone type and a PC-connected type).
[0043] 5, wearable device 151 has a display 1511, a lens 1512L for the left eye, a lens 1512R for the right eye, and a plurality of light sources 1513#1, 1513#2, 1513#3, and 1513#4 that emit near-infrared light. Light sources 1513#1 and 1513#2 may be arranged around lens 1512L. Light sources 1513#3 and 1513#4 may be arranged around lens 1512R. Lenses 1512L and 1512R may be referred to as VR lenses.
[0044] The wearable device 151 further includes cameras 1514L and 1514R and cameras 1515L and 1515R. The camera 1514L may be positioned so as to capture an image of the left eye of the user U. The camera 1514R may be positioned so as to capture an image of the right eye of the user U. The cameras 1514L and 1514R may be near-infrared cameras sensitive to the near-infrared wavelength range. The cameras 1514L and 1514R may have a filter that transmits near-infrared wavelengths while cutting visible light wavelengths. The cameras 1514L and 1514R may be referred to as in-cameras. The cameras 1515L and 1515R may be positioned so as to capture an image of the surroundings of the wearable device 151. The cameras 1515L and 1515R may be visible light cameras sensitive to the visible light wavelength range. Cameras 1515L and 1515R may be referred to as out-cameras.
[0045] The wearable device 151 may have a display for the left eye and a display for the right eye instead of the display 1511. The number of light sources that emit near-infrared light is not limited to four, and may be five or more, or three or less.
[0046] (Configuration of authentication server 200) The configuration of the authentication server 200 will be described with reference to Fig. 6. In Fig. 6, the authentication server 200 includes a calculation device 210, a storage device 220, a communication device 230, an input device 240, and an output device 250. The calculation device 210, the storage device 220, the communication device 230, the input device 240, and the output device 250 may be connected via a data bus 260.
[0047] The arithmetic device 210 may include a processor 2101. The arithmetic device 210 may include other processors in addition to the processor 2101. That is, the arithmetic device 210 may include one or more processors. The processor 2101 may be a multi-core processor. When the arithmetic device 210 includes a single processor 2101 that is a multi-core processor, it can be said that the arithmetic device 210 logically includes multiple processors. The processor 2101 may be, for example, at least one of a CPU, a GPU, an FPGA, a TPU, and a quantum processor.
[0048] The storage device 220 may include a memory 2201. The storage device 220 may include other memories in addition to the memory 2201. That is, the storage device 220 may include one or more memories. The memory 2201 may be, for example, at least one of a RAM, a ROM, a hard disk device, a magneto-optical disk device, an SSD, and an optical disk array. Therefore, the storage device 220 may include the memory 2201 as a non-transitory recording medium.
[0049] The storage device 220 can store desired data. A computer program 2201a executed by the arithmetic device 210 may be stored in the memory 2201 of the storage device 220. The storage device 220 may temporarily store data that is temporarily used by the arithmetic device 210 when the arithmetic device 210 is executing the computer program 2201a. The storage device 220 may store a database related to biometric authentication. The database may include at least one of registered images and registered feature amounts used for biometric authentication.
[0050] The computer program 2201a may be recorded on a computer-readable, non-transitory recording medium. In this case, the computer program 2201a may be stored in the memory 2201 by reading the recording medium using a recording medium reading device (not shown) included in the authentication server 200. The recording medium may be at least one of an optical disk, a magnetic medium, a magneto-optical disk, a semiconductor memory, and any other medium capable of storing a program. The computer program 2201a may be acquired (in other words, downloaded) from a device (not shown) external to the authentication server 200 via the communication device 230. The acquired computer program 2201a may be stored in the memory 2201.
[0051] The communication device 230 may be capable of communicating with devices external to the authentication server 200 (e.g., the terminal device 100 and the security terminal 300). The communication device 230 may perform wired communication or wireless communication.
[0052] The input device 240 is a device capable of accepting information input to the authentication server 200 from outside. The input device 240 may include an operation device (e.g., a keyboard, a mouse, a touch panel, etc.) that can be operated by a user of the authentication server 200. The input device 240 may include a recording medium reading device that can read information recorded on a recording medium that is detachable from the authentication server 200, such as a USB memory. Note that when information is input to the authentication server 200 via the communication device 230 (in other words, when the authentication server 200 acquires information via the communication device 230), the communication device 230 may function as an input device.
[0053] The output device 250 is a device capable of outputting information to the outside of the authentication server 200. The output device 250 may output visual information such as text or images, auditory information such as sound, or tactile information such as vibration, as the information. The output device 250 may include, for example, at least one of a display, a speaker, a printer, and a vibration motor. The output device 250 may be capable of outputting information to a recording medium that is detachable from the authentication server 200, such as a USB memory. Note that when the authentication server 200 outputs information via the communication device 230, the communication device 230 may function as the output device.
[0054] The processor 2101 of the arithmetic device 210, together with the memory 2201 of the storage device 220 in which the computer program 2201a is stored (in other words, together with the memory 2201 and the computer program 2201a stored in the memory 2201), may execute the processing to be performed by the authentication server 200. For example, the processor 2101 may execute the computer program 2201a, thereby realizing a logical function block in the arithmetic device 210 (for example, in the processor 2101) for executing the processing to be performed by the authentication server 200.
[0055] 7, the arithmetic device 210 may have, as logically realized functional blocks or physically realized processing circuits, an acquisition unit 211, an authentication unit 212, and an output unit 213. Note that at least one of the acquisition unit 211, the authentication unit 212, and the output unit 213 may be realized in a form in which a logical functional block and a physical processing circuit (i.e., hardware) are mixed.
[0056] When the acquisition unit 211, the authentication unit 212, and the output unit 213 are realized as functional blocks, the acquisition unit 211, the authentication unit 212, and the output unit 213 may be realized by a single processor (for example, the processor 2101). Alternatively, the acquisition unit 211, the authentication unit 212, and the output unit 213 may be realized by different processors. Alternatively, parts of the acquisition unit 211, the authentication unit 212, and the output unit 213 may be realized by a single processor, and the remaining parts of the acquisition unit 211, the authentication unit 212, and the output unit 213 may be realized by one or more processors different from the single processor.
[0057] The "acquisition unit 211," "authentication unit 212," and "output unit 213" are components corresponding to the "acquisition device 11," "authentication device 12," and "output device 13" in the first embodiment, respectively. The "communication device 230" is a component corresponding to the "reception device 14" in the first embodiment. The authentication server 200 corresponds to the information processing device according to this embodiment.
[0058] (Operation of Information Processing System 2) The acquisition unit 211 acquires biometric information including information related to the eyes of the user U wearing the wearable device 151. Here, the biometric information may be at least one of an eye image of the left eye generated by the camera 1514L of the wearable device 151 capturing an image of the left eye of the user U and an eye image of the right eye generated by the camera 1514R capturing an image of the right eye of the user U. Note that the calculation unit 110 of the terminal device 100 may extract features (e.g., features related to the iris) from at least one of the eye images of the left eye and the right eye. The acquisition unit 211 of the authentication server 200 may acquire the extracted features as biometric information.
[0059] The authentication unit 212 performs biometric authentication of the user U using the biometric information acquired by the acquisition unit 211. For example, when the biometric information is an eye image (i.e., at least one of an eye image of the left eye and an eye image of the right eye) and a registered image (e.g., an eye image) is registered in a database, the authentication unit 212 may perform the following process. The authentication unit 212 may extract features from the eye image as biometric information. The authentication unit 212 may extract features from the registered image. The authentication unit 212 may calculate a matching score by matching the features extracted from the eye image as biometric information with the features extracted from the registered image. The authentication unit 212 may compare the matching score with a predetermined threshold. If the matching score is equal to or greater than the predetermined threshold, the authentication unit 212 may determine that the user U is a person associated with the registered image. On the other hand, if the matching score is smaller than the predetermined threshold, the authentication unit 212 may determine that the user U is not a person associated with the registered image.
[0060] Here, the authentication unit 212 may perform 1:N authentication as the biometric authentication. If the maximum value of the matching score is equal to or greater than a predetermined threshold, the authentication unit 212 may determine that the user U is the person associated with the registered image with the maximum matching score. In this case, the authentication unit 212 may determine that the authentication is successful. On the other hand, if the maximum value of the matching score is smaller than the predetermined threshold, the authentication unit 212 may determine that the authentication is unsuccessful. Note that the authentication unit 212 may perform 1:1 authentication as the biometric authentication.
[0061] For example, when the biometric information is an eye image (i.e., at least one of an eye image of the left eye and an eye image of the right eye) and registered features (e.g., features related to the iris) are registered in the database, the authentication unit 212 may perform the following process: The authentication unit 212 may extract the features from the eye image as biometric information. The authentication unit 212 may calculate a matching score by matching the features extracted from the eye image as biometric information with the registered features.
[0062] For example, when the biometric information is a feature (i.e., a feature extracted from at least one of the left eye image and the right eye image) and a registered image (e.g., an eye image) is registered in the database, the authentication unit 212 may perform the following process: The authentication unit 212 may extract the feature from the registered image. The authentication unit 212 may calculate a matching score by matching the feature as the biometric information with the feature extracted from the registered image.
[0063] For example, when the biometric information is a feature (i.e., a feature extracted from at least one of the left eye image and the right eye image) and a registered feature (e.g., a feature related to the iris) is registered in the database, the authentication unit 212 may perform the following process: The authentication unit 212 may calculate a matching score by matching the feature as the biometric information with the registered feature.
[0064] If the biometric authentication fails, the arithmetic unit 210 of the authentication server 200 may transmit information indicating that the biometric authentication has failed to the terminal device 100 via the communication device 230. The arithmetic unit 110 of the terminal device 100 that has received the information indicating that the biometric authentication has failed may control the output device 150 to notify the terminal device 100 that the biometric authentication has failed. In this case, for example, at least one of characters, figures, and images indicating that the biometric authentication has failed may be displayed on the display 1511 of the wearable device 151. Furthermore, at least one of a voice and a sound effect may be emitted to indicate that the biometric authentication has failed.
[0065] If the biometric authentication is successful, the output unit 213 of the authentication server 200 transmits user information about the user U to the security terminal 300 via the communication device 230. The user information may include, for example, information for identifying the user U (such as name, identification number, affiliation, etc.). Note that the information for identifying the user U may be obtained, for example, from a database related to biometric authentication.
[0066] The user information may include, for example, information for an operator O of the security terminal 300 to chat, make a voice call, or make a video call with a user U. For example, when the operator O and the user U chat, make a voice call, or make a video call via the authentication server 200, the information for the chat, make a voice call, or make a video call may be information (e.g., a URL, an ID, and a password) for the operator O and the user U to access a predetermined page provided by the authentication server 200. When the security terminal 300 and the terminal device 100 are connected in a peer-to-peer manner and the operator O and the user U chat, make a voice call, or make a video call, the information for the chat, make a voice call, or make a video call may be information (e.g., an IP address) for the security terminal 300 to access the terminal device 100.
[0067] The operator O of the security terminal 300 may determine whether or not user U can log in to the virtual space by chatting or making a voice or video call with the user U, in addition to information for identifying the user U (such as name, identification number, affiliation, etc.) included in the user information. In this case, the security terminal 300 may output at least one of text data input by the user U and the voice of the user U. The output device 150 (e.g., the wearable device 151) of the terminal device 100 may output at least one of text data input by the operator O and the voice of the operator O. Note that a voice or video call can be used to check the liveness of the user U, which is useful, for example, as a countermeasure against impersonation. For example, the operator O may check the status of the user U by chatting or making a call with the user U. If there is no suspicious activity regarding the user U, the operator O may decide to allow the user U to log in to the virtual space. On the other hand, if there is any suspicious activity regarding the user U, the operator O may continue chatting or making a call with the user U until the suspicious activity is resolved. If the suspicious points are not resolved, the operator O may decide not to allow the user U to log in to the virtual space.
[0068] For example, when an operator O and a user U make a video call, the following problem occurs: In an image generated by the camera 170 of the terminal device 100 capturing an image of the user U wearing the wearable device 151, the area around the eyes of the user U is hidden by the wearable device 151, as in the image Img1 shown in FIG. 8 . When the image Img1 is displayed during the video call, it becomes difficult for the operator O to determine whether the user U is the real person.
[0069] Therefore, the arithmetic unit 110 of the terminal device 100 may generate, for example, image Img2 shown in FIG. 8 by combining a left eye image generated by capturing the left eye of user U with the camera 1514L of the wearable device 151 and a right eye image generated by capturing the right eye of user U with the camera 1514R. The arithmetic unit 110 may further generate image Img3 by combining image Img1 and image Img2. The arithmetic unit 110 may transmit image Img3 to at least one of the security terminal 300 and the authentication server 200 via the communication device 130. For example, if image Img3 is displayed during a video call, the operator O can appropriately determine whether user U is the person in question. Note that, for example, a pre-registered facial image may be displayed on the display device of the security terminal 300 in addition to image Img3. This configuration allows the operator O to relatively easily determine whether user U is the person in question. As described above, cameras 1514L and 1514R may be near-infrared cameras. In this case, image Img2 may be a near-infrared image. On the other hand, camera 170 may be a visible light camera. In this case, Img1 may be a visible light image. If image Img3 is generated by combining visible light image Img1 and near-infrared image Img2 and displayed on security terminal 300, operator O may feel uncomfortable. Therefore, calculation device 110 may perform color correction on image Img2, for example, based on the color tone of image Img1. This configuration can prevent operator O from feeling uncomfortable when image Img3 is displayed on security terminal 300.
[0070] If the operator O finds the user U suspicious, the operator O may request, for example, an image generated by at least one of the cameras 1515L and 1515R of the wearable device 151 capturing an image of the area around the wearable device 151 (in other words, the area around the user U). For example, the operator O can learn about the user U's surroundings from the image. For example, if the user U is in a location that is unsafe from a security standpoint, the operator O may determine not to allow the user U to log in to the virtual space. If the user U does not respond to a video call, or if the user U responds to a video call but the camera is turned off, the operator O may determine not to allow the user U to log in to the virtual space. If a person other than the user U is displayed in addition to the user U on the screen related to the video call, the operator O may determine not to allow the user U to log in to the virtual space. For example, if the operator O determines that the user U is being threatened by a person other than the user U, the operator O may report the incident to the police. Note that a signal to notify an emergency may be agreed upon between the user U and the operator O in advance. For example, if the user U signals an emergency, the operator O may call the police. Note that the user information may include a matching score for biometric authentication. For example, the operator O may change the way the operator handles the user U by referring to the matching score. Depending on a predetermined threshold for biometric authentication, even if the matching score is equal to or greater than the predetermined threshold, an unregistered person (i.e., a stranger) may be mistaken for a registered person. If the matching score is significantly greater than the predetermined threshold, the possibility of misidentification is negligible. On the other hand, if the matching score is slightly greater than the predetermined threshold, the possibility of misidentification cannot be ignored. For example, if the matching score is slightly greater than the predetermined threshold, the operator O may check the user U more carefully. Such behavior by the operator O is also effective as a countermeasure against impersonation. In other words, including the matching score in the user information can be used to prevent impersonation.
[0071] The operator O uses the security terminal 300 to transmit permission information indicating whether the user U is permitted to log in to the virtual space to the authentication server 200. As a result, the communication device 230 of the authentication server 200 may receive the permission information. The calculation device 210 of the authentication server 200, which has acquired the permission information, transmits the permission information to the terminal device 100 via the communication device 230.
[0072] If the permission information indicates that user U is permitted to log in to the virtual space, the arithmetic device 110 of the terminal device 100 may transmit the permission information to the virtual world server 400 via the communication device 130. As a result, user U may log in to the virtual space. On the other hand, if the permission information indicates that user U is not permitted to log in to the virtual space, the arithmetic device 110 of the terminal device 100 may, for example, control the output device 150 to notify user U that he or she cannot log in to the virtual space.
[0073] (Technical effect) According to the information processing system 2 of the second embodiment, similar to the information processing system 1 of the first embodiment described above, in addition to identity verification through biometric authentication, user U can be confirmed by an operator O of the security terminal 300.
[0074] 9 to 11, a third embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described. Hereinafter, the third embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described using an information processing system 3. Note that, for the third embodiment, descriptions that overlap with the descriptions for the first and second embodiments will be omitted as appropriate.
[0075] 9, the information processing system 3 includes a terminal device 100, a security terminal 300, and a virtual world server 400. In this embodiment, the virtual world server 400 has the functions related to the authentication server 200 in the second embodiment.
[0076] When user U uses terminal device 100 to log in to a virtual space realized by virtual world server 400, information processing system 3 may perform the following operations. First, when user U wearing wearable device 151 accesses virtual world server 400 using terminal device 100, virtual world server 400 may acquire biometric information of user U from terminal device 100. Virtual world server 400 may perform biometric authentication of user U using the biometric information.
[0077] If the biometric authentication is successful, the virtual world server 400 may output user information about the user U to the security terminal 300. An operator O (e.g., a security guard or a security guard) of the security terminal 300 may determine whether or not the user U is permitted to log in to the virtual space based on the user information. The operator O may use the security terminal 300 to send permission information indicating whether or not the user U is permitted to log in to the virtual space (in other words, the result of the operator O's determination) to the virtual world server 400. As a result, the virtual world server 400 may receive the permission information indicating whether or not the user U is permitted to log in to the virtual space.
[0078] If the permission information indicates that user U is permitted to log in to the virtual space, the virtual world server 400 may permit user U to log in to the virtual space. As a result, user U may log in to the virtual space. On the other hand, if the permission information indicates that user U is not permitted to log in to the virtual space, the virtual world server 400 may, for example, transmit information to the terminal device 100 indicating that user U cannot log in to the virtual space. As a result, the terminal device 100 may, for example, notify user U that he or she cannot log in to the virtual space.
[0079] (Configuration of Virtual World Server 400) The configuration of the virtual world server 400 will be described with reference to Fig. 10. In Fig. 10, the virtual world server 400 includes a computing device 410, a storage device 420, a communication device 430, an input device 440, and an output device 450. The computing device 410, the storage device 420, the communication device 430, the input device 440, and the output device 450 may be connected via a data bus 460.
[0080] The arithmetic device 410 may include a processor 4101. The arithmetic device 410 may include other processors in addition to the processor 4101. That is, the arithmetic device 410 may include one or more processors. The processor 4101 may be a multi-core processor. When the arithmetic device 410 includes a single processor 4101 that is a multi-core processor, it can be said that the arithmetic device 410 logically includes multiple processors. The processor 4101 may be, for example, at least one of a CPU, a GPU, an FPGA, a TPU, and a quantum processor.
[0081] The storage device 420 may include a memory 4201. The storage device 420 may include other memories in addition to the memory 4201. That is, the storage device 420 may include one or more memories. The memory 4201 may be, for example, at least one of a RAM, a ROM, a hard disk device, a magneto-optical disk device, an SSD, and an optical disk array. Therefore, the storage device 420 may include the memory 4201 as a non-transitory recording medium.
[0082] The storage device 420 can store desired data. A computer program 4201a executed by the arithmetic device 410 may be stored in the memory 4201 of the storage device 420. The storage device 420 may temporarily store data that is temporarily used by the arithmetic device 410 when the arithmetic device 410 is executing the computer program 4201a. The storage device 420 may store a database related to biometric authentication. The database may include at least one of registered images and registered feature amounts used for biometric authentication.
[0083] The computer program 4201a may be recorded on a computer-readable, non-transitory recording medium. In this case, the computer program 4201a may be stored in the memory 4201 by reading the recording medium using a recording medium reading device (not shown) provided in the virtual world server 400. The recording medium may be at least one of an optical disk, a magnetic medium, a magneto-optical disk, a semiconductor memory, and any other medium capable of storing a program. The computer program 4201a may be acquired (in other words, downloaded) from a device (not shown) external to the virtual world server 400 via the communication device 430. The acquired computer program 4201a may be stored in the memory 4201.
[0084] The communication device 430 may be capable of communicating with devices (e.g., the terminal device 100 and the security terminal 300) external to the virtual world server 400. The communication device 430 may perform wired communication or wireless communication.
[0085] The input device 440 is a device capable of accepting information input to the virtual world server 400 from outside. The input device 440 may include an operation device (e.g., a keyboard, a mouse, a touch panel, etc.) that can be operated by a user of the virtual world server 400. The input device 440 may include a recording medium reading device that can read information recorded on a recording medium that is detachable from the virtual world server 400, such as a USB memory. Note that when information is input to the virtual world server 400 via the communication device 430 (in other words, when the virtual world server 400 obtains information via the communication device 430), the communication device 430 may function as an input device.
[0086] The output device 450 is a device capable of outputting information to the outside of the virtual world server 400. The output device 450 may output visual information such as text or images, auditory information such as sound, or tactile information such as vibration, as the information. The output device 450 may include, for example, at least one of a display, a speaker, a printer, and a vibration motor. The output device 450 may be capable of outputting information to a recording medium that is detachable from the virtual world server 400, such as a USB memory. Note that when the virtual world server 400 outputs information via the communication device 430, the communication device 430 may function as an output device.
[0087] The processor 4101 of the arithmetic device 410, together with the memory 4201 of the storage device 420 in which the computer program 4201a is stored (in other words, together with the memory 4201 and the computer program 4201a stored in the memory 4201), may execute the processing to be performed by the virtual world server 400. For example, the processor 4101 may execute the computer program 4201a, thereby realizing logical functional blocks in the arithmetic device 410 (e.g., in the processor 4101) for executing the processing to be performed by the virtual world server 400.
[0088] 11 , the arithmetic device 410 may have, as logically realized functional blocks or physically realized processing circuits, an acquisition unit 411, an authentication unit 412, and an output unit 413. Note that at least one of the acquisition unit 411, the authentication unit 412, and the output unit 413 may be realized in a form in which a logical functional block and a physical processing circuit (i.e., hardware) are mixed.
[0089] When the acquisition unit 411, the authentication unit 412, and the output unit 413 are realized as functional blocks, the acquisition unit 411, the authentication unit 412, and the output unit 413 may be realized by a single processor (for example, the processor 4101). Alternatively, the acquisition unit 411, the authentication unit 412, and the output unit 413 may be realized by different processors. Alternatively, parts of the acquisition unit 411, the authentication unit 412, and the output unit 413 may be realized by a single processor, and the remaining parts of the acquisition unit 411, the authentication unit 412, and the output unit 413 may be realized by one or more processors different from the single processor.
[0090] The "acquisition unit 411," "authentication unit 412," and "output unit 413" are components corresponding to the "acquisition device 11," "authentication device 12," and "output device 13" in the first embodiment, respectively. The "communication device 430" is a component corresponding to the "reception device 14" in the first embodiment. The virtual world server 400 corresponds to the information processing device in this embodiment.
[0091] (Operation of information processing system 3) The acquisition unit 411 acquires biometric information including information related to the eyes of the user U wearing the wearable device 151. The authentication unit 412 performs biometric authentication of the user U using the biometric information acquired by the acquisition unit 411. If the biometric authentication fails, the arithmetic unit 410 of the virtual world server 400 may transmit information indicating that the biometric authentication has failed to the terminal device 100 via the communication device 430. The arithmetic unit 110 of the terminal device 100 that has received the information indicating that the biometric authentication has failed may control the output device 150 to notify the user that the biometric authentication has failed.
[0092] If the biometric authentication is successful, the output unit 413 of the virtual world server 400 transmits user information about the user U to the security terminal 300 via the communication device 430. The operator O uses the security terminal 300 to transmit permission information indicating whether or not the user U is permitted to log in to the virtual space to the virtual world server 400. As a result, the communication device 430 of the virtual world server 400 may receive the permission information.
[0093] If the permission information indicates that user U is permitted to log in to the virtual space, the virtual world server 400 may permit user U to log in to the virtual space. As a result, user U may log in to the virtual space. On the other hand, if the permission information indicates that user U is not permitted to log in to the virtual space, the calculation device 410 of the virtual world server 400 may transmit, for example, information indicating that user U cannot log in to the virtual space to the terminal device 100 via the communication device 430. As a result, the calculation device 110 of the terminal device 100 may control the output device 150, for example, to notify user U that he or she cannot log in to the virtual space.
[0094] (Technical effect) According to the information processing system 3 of the third embodiment, similar to the information processing system 2 of the second embodiment described above, in addition to confirming the identity of the user U through biometric authentication, the operator O of the security terminal 300 can confirm the identity of the user U.
[0095] Fourth Embodiment An information processing system, an information processing device, an information processing method, and a recording medium according to a fourth embodiment will be described with reference to Fig. 12 and Fig. 13. Hereinafter, the information processing system, the information processing device, the information processing method, and the recording medium according to the fourth embodiment will be described using an information processing system 4. Note that, with regard to the fourth embodiment, descriptions that overlap with the descriptions of the first to third embodiments will be omitted as appropriate.
[0096] 11, the information processing system 4 includes a terminal device 100, a security terminal 300, and a virtual world server 400. In this embodiment, the terminal device 100 has the functions related to the authentication server 200 in the second embodiment.
[0097] When user U uses terminal device 100 to log in to a virtual space realized by virtual world server 400, information processing system 4 may perform the following operations: First, when user U wearing wearable device 151 uses terminal device 100 to access virtual world server 400 (e.g., a homepage related to the virtual space provided by virtual world server 400), virtual world server 400 may request terminal device 100 to authenticate user U.
[0098] When requested to authenticate user U, the terminal device 100 may acquire biometric information of user U. The terminal device 100 may perform biometric authentication of user U using the biometric information. If the biometric authentication is successful, the terminal device 100 may output user information about user U to the security terminal 300. An operator O of the security terminal 300 (e.g., at least one of a security guard and a security guard) may determine whether or not user U is allowed to log in to the virtual space based on the user information.
[0099] The operator O may use the security terminal 300 to transmit permission information indicating whether or not the user U is permitted to log in to the virtual space (in other words, the result of the operator O's judgment) to the terminal device 100. As a result, the terminal device 100 may receive the permission information indicating whether or not the user U is permitted to log in to the virtual space.
[0100] If the permission information indicates that user U is permitted to log in to the virtual space, the terminal device 100 may transmit the permission information to the virtual world server 400. As a result, user U may log in to the virtual space. On the other hand, if the permission information indicates that user U is not permitted to log in to the virtual space, the terminal device 100 may, for example, notify user U that he or she cannot log in to the virtual space.
[0101] 13 , the arithmetic device 110 of the terminal device 100 according to the fourth embodiment may have, as logically realized functional blocks or physically realized processing circuits, an acquisition unit 111, an authentication unit 112, and an output unit 113. Note that at least one of the acquisition unit 111, the authentication unit 112, and the output unit 113 may be realized in a form in which a logical functional block and a physical processing circuit (i.e., hardware) are mixed.
[0102] When the acquisition unit 111, the authentication unit 112, and the output unit 113 are realized as functional blocks, the acquisition unit 111, the authentication unit 112, and the output unit 113 may be realized by a single processor (for example, the processor 1101). Alternatively, the acquisition unit 111, the authentication unit 112, and the output unit 113 may be realized by different processors. Alternatively, parts of the acquisition unit 111, the authentication unit 112, and the output unit 113 may be realized by a single processor, and the remaining parts of the acquisition unit 111, the authentication unit 112, and the output unit 113 may be realized by one or more processors different from the single processor.
[0103] The "acquisition unit 111," "authentication unit 112," and "output unit 113" are components corresponding to the "acquisition device 11," "authentication device 12," and "output device 13" in the first embodiment, respectively. The "communication device 130" is a component corresponding to the "reception device 14" in the first embodiment. The terminal device 100 corresponds to the information processing device according to this embodiment.
[0104] (Operation of information processing system 4) The acquisition unit 111 acquires biometric information including information related to the eyes of the user U wearing the wearable device 151. The authentication unit 112 performs biometric authentication of the user U using the biometric information acquired by the acquisition unit 111. The authentication unit 112 may perform 1:1 authentication as the biometric authentication. However, the authentication unit 112 may also perform 1:N authentication as the biometric authentication. If the biometric authentication fails, the calculation device 110 may control the output device 150 to notify the user that the biometric authentication has failed.
[0105] If the biometric authentication is successful, the output unit 113 transmits user information about the user U to the security terminal 300 via the communication device 130. The operator O uses the security terminal 300 to transmit permission information indicating whether or not the user U is permitted to log in to the virtual space to the terminal device 100. As a result, the communication device 130 of the terminal device 100 may receive the permission information.
[0106] If the permission information indicates that user U is permitted to log in to the virtual space, the arithmetic device 110 of the terminal device 100 may transmit the permission information to the virtual world server 400 via the communication device 130. As a result, user U may log in to the virtual space. On the other hand, if the permission information indicates that user U is not permitted to log in to the virtual space, the arithmetic device 110 of the terminal device 100 may, for example, control the output device 150 to notify user U that he or she cannot log in to the virtual space.
[0107] (Technical effect) According to the information processing system 4 of the fourth embodiment, similar to the information processing system 2 of the second embodiment described above, in addition to identity verification through biometric authentication, user U can be confirmed by an operator O of the security terminal 300.
[0108] Fifth Embodiment An information processing system, an information processing device, an information processing method, and a recording medium according to a fifth embodiment will be described with reference to Fig. 14 and Fig. 15. Hereinafter, the information processing system, the information processing device, the information processing method, and the recording medium according to the fifth embodiment will be described using an information processing system 5. Note that, with regard to the fifth embodiment, descriptions that overlap with the descriptions of the first to fourth embodiments will be omitted as appropriate.
[0109] In the first to fourth embodiments described above, a case where one user U (the "target" in the first embodiment) logs in to a virtual space is described. In the fifth embodiment, a case where multiple users log in to one virtual space is described. In the fifth embodiment, multiple users can log in to one virtual space only if the multiple users satisfy predetermined authentication conditions.
[0110] 14, the information processing system 5 includes a plurality of terminal devices 100#1, 100#2, and 100#3, an authentication server 200, a security terminal 300, and a virtual world server 400. The plurality of terminal devices 100#1, 100#2, and 100#3, the authentication server 200, the security terminal 300, and the virtual world server 400 are configured to be able to communicate with each other via a network such as the Internet. Note that the information processing system 5 may include only two terminal devices, or may include four or more terminal devices.
[0111] Terminal device 100#1 is a terminal device used by user U#1. Terminal device 100#2 is a terminal device used by user U#2. Terminal device 100#3 is a terminal device used by user U#3. The configuration of each of the multiple terminal devices 100#1, 100#2, and 100#3 may be the same as that of the terminal device 100 in the second embodiment. Therefore, a description of the configuration of each of the multiple terminal devices 100#1, 100#2, and 100#3 will be omitted. Note that user U#1 is assumed to be wearing a wearable device provided in terminal device 100#1. User U#2 is assumed to be wearing a wearable device provided in terminal device 100#2. User U#3 is assumed to be wearing a wearable device provided in terminal device 100#3. Note that the wearable devices of each of the multiple terminal devices 100#1, 100#2, and 100#3 correspond to wearable device 151 in the second embodiment.
[0112] The information processing system 5 may perform the following operations. When a user U#1 wearing a wearable device accesses the virtual world server 400 (e.g., a homepage related to a virtual space provided by the virtual world server 400) using the terminal device 100#1, the virtual world server 400 may transmit information for authentication to the terminal device 100#1. The terminal device 100#1, which has received the information for authentication, may automatically access the authentication server 200 based on the information for authentication. The authentication server 200 may acquire biometric information of the user U#1 from the terminal device 100#1. The authentication server 200 may perform biometric authentication of the user U#1 using the biometric information.
[0113] Similarly, when user U#2 wearing a wearable device accesses the virtual world server 400 using terminal device 100#2, the virtual world server 400 may transmit information for authentication to terminal device 100#2. Upon receiving the information for authentication, terminal device 100#2 may automatically access the authentication server 200 based on the information for authentication. The authentication server 200 may acquire biometric information of user U#2 from terminal device 100#2. The authentication server 200 may perform biometric authentication of user U#2 using the biometric information.
[0114] Similarly, when user U#3 wearing a wearable device accesses the virtual world server 400 using terminal device 100#3, the virtual world server 400 may transmit information for authentication to terminal device 100#2. Upon receiving the information for authentication, terminal device 100#3 may automatically access the authentication server 200 based on the information for authentication. The authentication server 200 may acquire biometric information of user U#3 from terminal device 100#3. The authentication server 200 may perform biometric authentication of user U#3 using the biometric information.
[0115] If the biometric authentication of each of the multiple users U#1, U#2, and U#3 is successful, the authentication server 200 may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on user information about user U#1, user information about user U#2, and user information about user U#3. If the biometric authentication of at least one of the multiple users U#1, U#2, and U#3 fails, the authentication server 200 may not allow the multiple users U#1, U#2, and U#3 to log in to one virtual space. If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the authentication server 200 may not allow the multiple users U#1, U#2, and U#3 to log in to one virtual space.
[0116] If it is determined that multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions, authentication server 200 may output user information about user U#1, user information about user U#2, and user information about user U#3 to security terminal 300. Operator O of security terminal 300 may determine whether multiple users U#1, U#2, and U#3 can log in to one virtual space based on the user information about user U#1, user information about user U#2, and user information about user U#3. Note that operator O is prohibited from making a decision to allow only a portion of multiple users U#1, U#2, and U#3 to log in to one virtual space (in other words, not allowing only a portion of multiple users U#1, U#2, and U#3 to log in to one virtual space).
[0117] The operator O may use the security terminal 300 to transmit permission information (in other words, the operator O's judgment result) indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to the authentication server 200. As a result, the authentication server 200 may receive permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space. The authentication server 200 may transmit the permission information to multiple terminal devices 100#1, 100#2, and 100#3.
[0118] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space, each of the terminal devices 100#1, 100#2, and 100#3 may transmit the permission information to the virtual world server 400. As a result, the multiple users U#1, U#2, and U#3 may log in to the one virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the one virtual space, the terminal devices 100#1, 100#2, and 100#3 may, for example, notify the users that they cannot log in to the one virtual space.
[0119] (Configuration of authentication server 200) The authentication server 200 may include a computing device 210a instead of the computing device 210. The computing device 210a may have one or more processors, similar to the computing device 210. As shown in Fig. 15, the computing device 210a may have an acquisition unit 211, a personal authentication unit 212a, an output unit 213, and a group authentication unit 214 as logically realized functional blocks or as physically realized processing circuits. Note that at least one of the acquisition unit 211, the personal authentication unit 212a, the output unit 213, and the group authentication unit 214 may be realized in a format in which a logical functional block and a physical processing circuit (i.e., hardware) are mixed.
[0120] When the acquisition unit 211, the personal authentication unit 212a, the output unit 213, and the group authentication unit 214 are realized as functional blocks, the acquisition unit 211, the personal authentication unit 212a, the output unit 213, and the group authentication unit 214 may be realized by a single processor. Alternatively, the acquisition unit 211, the personal authentication unit 212a, the output unit 213, and the group authentication unit 214 may be realized by different processors. Alternatively, some of the acquisition unit 211, the personal authentication unit 212a, the output unit 213, and the group authentication unit 214 may be realized by a single processor, and the remaining parts of the acquisition unit 211, the personal authentication unit 212a, the output unit 213, and the group authentication unit 214 may be realized by one or more processors different from the single processor.
[0121] The "personal authentication unit 212a" is a component corresponding to the "authentication unit 212" in the second embodiment. The authentication server 200 corresponds to the information processing device according to this embodiment. The personal authentication unit 212a and the group authentication unit 214 may be configured as an integrated unit.
[0122] (Operation of information processing system 5) The acquisition unit 211 acquires biometric information including information related to the eyes of user U#1 wearing the wearable device. The biometric information may be at least one of an image of the left eye and an image of the right eye of user U#1. The biometric information may also be feature amounts extracted from at least one of the image of the left eye and an image of the right eye of user U#1. The personal authentication unit 212a performs biometric authentication of user U#1 using the biometric information of user U#1 acquired by the acquisition unit 211.
[0123] Similarly, the acquisition unit 211 acquires biometric information including information related to the eyes of user U#2 wearing the wearable device. The personal authentication unit 212a performs biometric authentication of user U#2 using the biometric information of user U#2 acquired by the acquisition unit 211. Similarly, the acquisition unit 211 acquires biometric information including information related to the eyes of user U#3 wearing the wearable device. The personal authentication unit 212a performs biometric authentication of user U#3 using the biometric information of user U#3 acquired by the acquisition unit 211.
[0124] If biometric authentication of at least one of users U#1, U#2, and U#3 fails, the calculation device 210a of the authentication server 200 may transmit information indicating the failure of biometric authentication to a terminal device used by the at least one user (i.e., at least one of the multiple terminal devices 100#1, 100#2, and 100#3) via the communication device 230. The calculation device 110 of the terminal device used by the at least one user, which has received the information indicating the failure of biometric authentication, may control the output device 150 to notify the user that the biometric authentication has failed.
[0125] In this case, the calculation device 210a of the authentication server 200 may transmit information indicating that login to the one virtual space is not permitted to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 230. The calculation device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 that has received the information indicating that login to the one virtual space is not permitted may control the output device 150 to notify that login to the one virtual space is not permitted.
[0126] When the biometric authentication of each of the multiple users U#1, U#2, and U#3 is successful, the personal authentication unit 212a of the authentication server 200 may transmit user information about user U#1, user information about user U#2, and user information about user U#3 to the group authentication unit 214. At this time, the personal authentication unit 212a may transmit a group authentication query to the group authentication unit 214. Having received the group authentication query, the group authentication unit 214 may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0127] The predetermined authentication conditions may include, for example, at least one of the following: a user who is registered as a member of a group and has a predetermined job title is included; a combination of users satisfies a predetermined combination; and the elapsed time since the group authentication query was received does not exceed a predetermined time. In other words, the predetermined authentication conditions may include at least one of a condition that multiple users must satisfy and a time limit condition. By specifying the conditions that multiple users must satisfy, it is possible to relatively easily determine, for example, whether multiple users can log in to a single virtual space. By specifying the time limit condition, it is possible to terminate processing, for example, if some kind of malfunction occurs in at least one of the multiple users.
[0128] If it is determined that multiple users U#1, U#2, and U#3 do not satisfy predetermined authentication conditions, the calculation device 210a may transmit information indicating that login to the one virtual space is not permitted to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 230. The calculation device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 that has received the information indicating that login to the one virtual space is not permitted may control the output device 150 to notify that login to the one virtual space is not permitted.
[0129] If it is determined that multiple users U#1, U#2, and U#3 satisfy specified authentication conditions, the output unit 213 of the authentication server 200 may output user information regarding user U#1, user information regarding user U#2, and user information regarding user U#3 to the security terminal 300 via the communication device 230.
[0130] An operator O of the security terminal 300 may determine whether or not multiple users U#1, U#2, and U#3 can log in to a virtual space by, for example, chatting or making voice or video calls with multiple users U#1, U#2, and U#3, in addition to the information for identifying the user contained in each user information (name, identification number, affiliation, etc.).
[0131] For example, the security terminal 300 may display multiple images (e.g., an image corresponding to image Img3 shown in FIG. 8 ) corresponding to multiple users U#1, U#2, and U#3, respectively. This configuration allows the operator O to be provided with more information about the users. The operator O of the security terminal 300 may simultaneously chat, make voice calls, or video calls with multiple users U#1, U#2, and U#3. In this case, the wearable devices of the multiple terminal devices 100#1, 100#2, and 100#3 may also display multiple images corresponding to the multiple users U#1, U#2, and U#3, respectively.
[0132] For example, an operator O may check the status of each of the multiple users U#1, U#2, and U#3 by chatting or calling with the multiple users U#1, U#2, and U#3. For example, the operator O may check the status of each of the multiple users U#1, U#2, and U#3 by having the users chat or call with each other. At this time, each of the multiple users U#1, U#2, and U#3 may check the status of the other users by referring to the content of the chat or call. For example, if one of the multiple users U#1, U#2, and U#3 feels that another user is suspicious, the one user may inform the operator O that the other user is suspicious. With this configuration, not only the operator O but also the multiple users U#1, U#2, and U#3 can check with each other.
[0133] If there is no suspicious activity among the multiple users U#1, U#2, and U#3, the operator O may decide to allow the multiple users U#1, U#2, and U#3 to log in to one virtual space. On the other hand, if the suspicious activity among at least one of the multiple users U#1, U#2, and U#3 is not resolved, the operator O may decide not to allow the multiple users U#1, U#2, and U#3 to log in to one virtual space.
[0134] The operator O may use the security terminal 300 to transmit permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to the authentication server 200. As a result, the communication device 230 of the authentication server 200 may receive the permission information. The calculation device 210 of the authentication server 200, which has acquired the permission information, may transmit the permission information to multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 230.
[0135] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to a virtual space, the computing device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 may transmit the permission information to the virtual world server 400 via the communication device 130. As a result, the multiple users U#1, U#2, and U#3 may log in to the virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the virtual space, the computing device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 may control the output device 150 to notify the users that they cannot log in to the virtual space.
[0136] (Technical effect) According to the information processing system 5 of the fifth embodiment, when multiple users log in to a single virtual space, in addition to verifying the identity of each user through biometric authentication, the multiple users can be verified by an operator O of the security terminal 300.
[0137] Sixth Embodiment An information processing system, an information processing device, an information processing method, and a recording medium according to a sixth embodiment will be described with reference to Figs. 16 and 17 in addition to Fig. 14. Hereinafter, the sixth embodiment of the information processing system, the information processing device, the information processing method, and the recording medium will be described using an information processing system 5. In the sixth embodiment, similar to the fifth embodiment, a case in which multiple users log in to one virtual space will be described. Note that, for the sixth embodiment, descriptions that overlap with the descriptions for the first to fifth embodiments will be omitted as appropriate.
[0138] (Overview of Information Processing System 5) The information processing system 5 may perform the following operations. When a user U#1 wearing a wearable device uses a terminal device 100#1 to access a virtual world server 400 (e.g., a homepage related to a virtual space provided by the virtual world server 400), the virtual world server 400 may request that the terminal device 100#1 authenticate the user U#1. The terminal device 100#1 that has been requested to authenticate the user U#1 may acquire biometric information of the user U#1. The terminal device 100#1 may perform biometric authentication of the user U#1 using the biometric information. If the biometric authentication is successful, the terminal device 100#1 may transmit user information related to the user U#1 to the authentication server 200.
[0139] Similarly, when user U#2 wearing a wearable device accesses the virtual world server 400 using terminal device 100#2, the virtual world server 400 may request terminal device 100#2 to authenticate user U#2. When requested to authenticate user U#2, terminal device 100#2 may acquire biometric information of user U#2. Terminal device 100#2 may perform biometric authentication of user U#2 using the biometric information. If the biometric authentication is successful, terminal device 100#2 may transmit user information about user U#2 to the authentication server 200.
[0140] Similarly, when user U#3 wearing a wearable device accesses the virtual world server 400 using terminal device 100#3, the virtual world server 400 may request terminal device 100#3 to authenticate user U#3. Terminal device 100#3 that has been requested to authenticate user U#3 may acquire biometric information of user U#3. Terminal device 100#3 may perform biometric authentication of user U#3 using the biometric information. If biometric authentication is successful, terminal device 100#3 may transmit user information about user U#3 to the authentication server 200.
[0141] The authentication server 200, which has received user information about user U#1, user information about user U#2, and user information about user U#3, may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on the user information about user U#1, user information about user U#2, and user information about user U#3. If the authentication server 200 does not receive user information about at least one of the multiple users U#1, U#2, and U#3 within a predetermined period due to a biometric authentication failure for at least one of the multiple users U#1, U#2, and U#3, the authentication server 200 may not permit the multiple users U#1, U#2, and U#3 to log in to one virtual space. If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the authentication server 200 may not permit the multiple users U#1, U#2, and U#3 to log in to one virtual space.
[0142] If it is determined that multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions, authentication server 200 may output user information about user U#1, user information about user U#2, and user information about user U#3 to security terminal 300. Operator O of security terminal 300 may determine whether multiple users U#1, U#2, and U#3 are allowed to log in to one virtual space based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0143] The operator O may use the security terminal 300 to transmit permission information (in other words, the operator O's judgment result) indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to the authentication server 200. As a result, the authentication server 200 may receive permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space. The authentication server 200 may transmit the permission information to multiple terminal devices 100#1, 100#2, and 100#3.
[0144] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space, each of the terminal devices 100#1, 100#2, and 100#3 may transmit the permission information to the virtual world server 400. As a result, the multiple users U#1, U#2, and U#3 may log in to the one virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the one virtual space, the terminal devices 100#1, 100#2, and 100#3 may, for example, notify the users that they cannot log in to the one virtual space.
[0145] (Configuration of each of terminal devices 100#1, 100#2, and 100#3) Each of terminal devices 100#1, 100#2, and 100#3 may be provided with a calculation device 110a instead of the calculation device 110. The calculation device 110a may have one or more processors, similar to the calculation device 110. As shown in FIG. 16, the calculation device 110a may have an acquisition unit 111, a personal authentication unit 112a, and an output unit 113 as logically realized functional blocks or as physically realized processing circuits. Note that the "personal authentication unit 112a" is a component corresponding to the "authentication unit 112" in the fourth embodiment.
[0146] (Configuration of authentication server 200) The authentication server 200 may include a computing device 210b instead of the computing device 210 or 210a. The computing device 210b may have one or more processors, similar to the computing device 210. As shown in Fig. 17 , the computing device 210b may include an acquisition unit 211, an output unit 213, and a group authentication unit 214 as logically realized functional blocks or as physically realized processing circuits.
[0147] (Operation of Information Processing System 5) The acquisition unit 111 of the terminal device 100#1 may acquire biometric information including information related to the eyes of the user U#1 wearing the wearable device. The personal authentication unit 112a of the terminal device 100#1 may perform biometric authentication of the user U#1 using the biometric information acquired by the acquisition unit 111. If the biometric authentication is successful, the output unit 113 of the terminal device 100#1 may transmit user information related to the user U#1 to the authentication server 200 via the communication device 130 of the terminal device 100#1. Note that if the biometric authentication fails, the calculation device 110a of the terminal device 100#1 may control the output device 150 of the terminal device 100#1 to notify the user that the biometric authentication has failed.
[0148] The acquisition unit 111 of the terminal device 100#2 may acquire biometric information including information related to the eyes of the user U#2 wearing the wearable device. The personal authentication unit 112a of the terminal device 100#2 may perform biometric authentication of the user U#2 using the biometric information acquired by the acquisition unit 111. If the biometric authentication is successful, the output unit 113 of the terminal device 100#2 may transmit user information related to the user U#2 to the authentication server 200 via the communication device 130 of the terminal device 100#2. Note that if the biometric authentication fails, the calculation device 110a of the terminal device 100#2 may control the output device 150 of the terminal device 100#2 to notify the user that the biometric authentication has failed.
[0149] The acquisition unit 111 of the terminal device 100#3 may acquire biometric information including information related to the eyes of the user U#3 wearing the wearable device. The personal authentication unit 112a of the terminal device 100#3 may perform biometric authentication of the user U#3 using the biometric information acquired by the acquisition unit 111. If the biometric authentication is successful, the output unit 113 of the terminal device 100#3 may transmit user information related to the user U#3 to the authentication server 200 via the communication device 130 of the terminal device 100#3. Note that if the biometric authentication fails, the calculation device 110a of the terminal device 100#3 may control the output device 150 of the terminal device 100#3 to notify the user that the biometric authentication has failed.
[0150] The acquisition unit 211 of the authentication server 200 may acquire user information about user U#1, user information about user U#2, and user information about user U#3 transmitted from each of the multiple terminal devices 100#1, 100#2, and 100#3. Here, when at least one of the multiple terminal devices 100#1, 100#2, and 100#3 transmits user information to the authentication server 200, it may also transmit a group authentication query to the authentication server 200. Upon receiving the group authentication query, the group authentication unit 214 of the authentication server 200 may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0151] If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the calculation device 210b may transmit information indicating that login to the one virtual space is not permitted to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 230. The calculation device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 that has received the information indicating that login to the one virtual space is not permitted may control the output device 150 to notify that login to the one virtual space is not permitted.
[0152] If it is determined that multiple users U#1, U#2, and U#3 satisfy specified authentication conditions, the output unit 213 of the authentication server 200 may output user information regarding user U#1, user information regarding user U#2, and user information regarding user U#3 to the security terminal 300 via the communication device 230.
[0153] The operator O may use the security terminal 300 to transmit permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to the authentication server 200. As a result, the communication device 230 of the authentication server 200 may receive the permission information. The calculation device 210 of the authentication server 200, which has acquired the permission information, may transmit the permission information to multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 230.
[0154] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to a virtual space, the computing device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 may transmit the permission information to the virtual world server 400 via the communication device 130. As a result, the multiple users U#1, U#2, and U#3 may log in to the virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the virtual space, the computing device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 may control the output device 150 to notify the users that they cannot log in to the virtual space.
[0155] (Technical effect) According to the information processing system 5 of the sixth embodiment, similar to the information processing system 5 of the fifth embodiment described above, when multiple users log in to a single virtual space, in addition to verifying the identity of each user through biometric authentication, the multiple users can be verified by an operator O of the security terminal 300.
[0156] Seventh Embodiment A seventh embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described with reference to Figs. 18 and 19. Below, the seventh embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described using an information processing system 6. In the seventh embodiment, similar to the fifth embodiment, a case where multiple users log in to one virtual space will be described. Note that, for the seventh embodiment, descriptions that overlap with the descriptions for the first to sixth embodiments will be omitted as appropriate.
[0157] 18, the information processing system 6 includes a plurality of terminal devices 100#1, 100#2, and 100#3, a security terminal 300, and a virtual world server 400. The plurality of terminal devices 100#1, 100#2, and 100#3, the security terminal 300, and the virtual world server 400 are configured to be able to communicate with each other via a network such as the Internet. Note that the information processing system 6 may include only two terminal devices, or may include four or more terminal devices.
[0158] The information processing system 6 may perform the following operations: When a user U#1 wearing a wearable device accesses the virtual world server 400 using the terminal device 100#1, the virtual world server 400 may acquire biometric information of the user U#1 from the terminal device 100#1. The virtual world server 400 may perform biometric authentication of the user U#1 using the biometric information.
[0159] Similarly, when user U#2 wearing a wearable device accesses the virtual world server 400 using terminal device 100#2, the virtual world server 400 may acquire biometric information of user U#2 from terminal device 100#2. The virtual world server 400 may perform biometric authentication of user U#2 using the biometric information.
[0160] Similarly, when user U#3 wearing a wearable device accesses the virtual world server 400 using terminal device 100#3, the virtual world server 400 may acquire biometric information of user U#3 from terminal device 100#3. The virtual world server 400 may use the biometric information to perform biometric authentication of user U#3.
[0161] If biometric authentication of each of the multiple users U#1, U#2, and U#3 is successful, the virtual world server 400 may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on user information about user U#1, user information about user U#2, and user information about user U#3. If biometric authentication of at least one of the multiple users U#1, U#2, and U#3 fails, the virtual world server 400 may not allow the multiple users U#1, U#2, and U#3 to log in to one virtual space. If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the virtual world server 400 may not allow the multiple users U#1, U#2, and U#3 to log in to one virtual space.
[0162] If it is determined that multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions, virtual world server 400 may output user information about user U#1, user information about user U#2, and user information about user U#3 to security terminal 300. Operator O of security terminal 300 may determine whether multiple users U#1, U#2, and U#3 are allowed to log in to one virtual space based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0163] Operator O may use security terminal 300 to transmit permission information (in other words, the result of operator O's judgment) indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to virtual world server 400. As a result, virtual world server 400 may receive permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space.
[0164] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to a virtual space, the virtual world server 400 may permit the multiple users U#1, U#2, and U#3 to log in to the virtual space. As a result, the multiple users U#1, U#2, and U#3 may log in to the virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the virtual space, the virtual world server 400 may, for example, transmit information indicating that they cannot log in to the virtual space to the multiple terminal devices 100#1, 100#2, and 100#3. As a result, the terminal devices 100#1, 100#2, and 100#3 may, for example, notify them that they cannot log in to the virtual space.
[0165] (Configuration of Virtual World Server 400) The virtual world server 400 may include a computing device 410a instead of the computing device 410. The computing device 410a may have one or more processors, similar to the computing device 410. As shown in FIG. 19 , the computing device 410a may have an acquisition unit 411, a personal authentication unit 412a, an output unit 413, and a group authentication unit 414, either as logically realized functional blocks or as physically realized processing circuits. Note that at least one of the acquisition unit 411, the personal authentication unit 412a, the output unit 413, and the group authentication unit 414 may be realized in a form in which a logical functional block and a physical processing circuit (i.e., hardware) are mixed.
[0166] When the acquisition unit 411, the personal authentication unit 412a, the output unit 413, and the group authentication unit 414 are realized as functional blocks, the acquisition unit 411, the personal authentication unit 412a, the output unit 413, and the group authentication unit 414 may be realized by a single processor. Alternatively, the acquisition unit 411, the personal authentication unit 412a, the output unit 413, and the group authentication unit 414 may be realized by different processors. Alternatively, some of the acquisition unit 411, the personal authentication unit 412a, the output unit 413, and the group authentication unit 414 may be realized by a single processor, and the remaining parts of the acquisition unit 411, the personal authentication unit 412a, the output unit 413, and the group authentication unit 414 may be realized by one or more processors different from the single processor.
[0167] The "personal authentication unit 412a" is a component corresponding to the "authentication unit 412" in the third embodiment. The virtual world server 400 corresponds to the information processing device according to this embodiment. The personal authentication unit 412a and the group authentication unit 414 may be configured as an integrated unit.
[0168] (Operation of information processing system 6) The acquisition unit 411 acquires biometric information including information related to the eyes of user U#1 wearing the wearable device. The biometric information may be at least one of an image of the left eye and an image of the right eye of user U#1. The biometric information may also be feature amounts extracted from at least one of the image of the left eye and an image of the right eye of user U#1. The personal authentication unit 412a performs biometric authentication of user U#1 using the biometric information of user U#1 acquired by the acquisition unit 411.
[0169] Similarly, the acquisition unit 411 acquires biometric information including information related to the eyes of user U#2 wearing the wearable device. The personal authentication unit 412a performs biometric authentication of user U#2 using the biometric information of user U#2 acquired by the acquisition unit 411. Similarly, the acquisition unit 411 acquires biometric information including information related to the eyes of user U#3 wearing the wearable device. The personal authentication unit 412a performs biometric authentication of user U#3 using the biometric information of user U#3 acquired by the acquisition unit 411.
[0170] If biometric authentication of at least one of users U#1, U#2, and U#3 fails, the calculation device 410a of the virtual world server 400 may transmit information indicating that the biometric authentication has failed to a terminal device used by the at least one user (i.e., at least one of the multiple terminal devices 100#1, 100#2, and 100#3) via the communication device 430. The calculation device 110 of the terminal device used by the at least one user, which has received the information indicating that the biometric authentication has failed, may control the output device 150 to notify the user that the biometric authentication has failed.
[0171] In this case, the computing device 410a of the virtual world server 400 may transmit information indicating that login to the one virtual space is not permitted to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 430. The computing device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 that has received the information indicating that login to the one virtual space is not permitted may control the output device 150 to notify that login to the one virtual space is not permitted.
[0172] If the biometric authentication of each of the multiple users U#1, U#2, and U#3 is successful, the personal authentication unit 412a of the virtual world server 400 may send user information about user U#1, user information about user U#2, and user information about user U#3 to the group authentication unit 414. At this time, the personal authentication unit 412a may send a group authentication query to the group authentication unit 414. Having received the group authentication query, the group authentication unit 414 may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0173] If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the calculation device 410a may transmit information indicating that login to the one virtual space is not permitted to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 430. The calculation device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 that has received the information indicating that login to the one virtual space is not permitted may control the output device 150 to notify that login to the one virtual space is not permitted.
[0174] If it is determined that multiple users U#1, U#2, and U#3 satisfy specified authentication conditions, the output unit 413 of the virtual world server 400 may output user information regarding user U#1, user information regarding user U#2, and user information regarding user U#3 to the security terminal 300 via the communication device 430.
[0175] Operator O may use security terminal 300 to transmit permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to virtual world server 400. As a result, communication device 430 of virtual world server 400 may receive the permission information.
[0176] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to a virtual space, the virtual world server 400 may permit the multiple users U#1, U#2, and U#3 to log in to the virtual space. As a result, the multiple users U#1, U#2, and U#3 may log in to the virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the virtual space, the computing device 410 of the virtual world server 400 may transmit, for example, information indicating that they cannot log in to the virtual space to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 420. As a result, the computing device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 may control the output device 150 to notify them that they cannot log in to the virtual space.
[0177] (Technical effect) According to the information processing system 6 of the seventh embodiment, similar to the information processing system 5 of the fifth embodiment described above, when multiple users log in to one virtual space, in addition to verifying the identity of each user through biometric authentication, the multiple users can be verified by an operator O of the security terminal 300.
[0178] Eighth Embodiment An eighth embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described with reference to Fig. 16 and Fig. 20 in addition to Fig. 18. Below, the eighth embodiment of an information processing system, an information processing device, an information processing method, and a recording medium will be described using an information processing system 6. In the eighth embodiment, as in the seventh embodiment, a case where multiple users log in to one virtual space will be described. Note that, for the eighth embodiment, descriptions that overlap with the descriptions of the first to seventh embodiments will be omitted as appropriate.
[0179] (Overview of Information Processing System 6) The information processing system 6 may perform the following operations. When a user U#1 wearing a wearable device uses a terminal device 100#1 to access a virtual world server 400 (e.g., a homepage related to a virtual space provided by the virtual world server 400), the virtual world server 400 may request authentication of the user U#1 from the terminal device 100#1. When requested to authenticate the user U#1, the terminal device 100#1 may acquire biometric information of the user U#1. The terminal device 100#1 may perform biometric authentication of the user U#1 using the biometric information. If the biometric authentication is successful, the terminal device 100#1 may transmit user information about the user U#1 to the virtual world server 400.
[0180] Similarly, when user U#2 wearing a wearable device accesses the virtual world server 400 using terminal device 100#2, the virtual world server 400 may request terminal device 100#2 to authenticate user U#2. When requested to authenticate user U#2, terminal device 100#2 may acquire biometric information of user U#2. Terminal device 100#2 may perform biometric authentication of user U#2 using the biometric information. If the biometric authentication is successful, terminal device 100#2 may transmit user information about user U#2 to the virtual world server 400.
[0181] Similarly, when user U#3 wearing a wearable device accesses the virtual world server 400 using terminal device 100#3, the virtual world server 400 may request terminal device 100#3 to authenticate user U#3. When requested to authenticate user U#3, terminal device 100#3 may acquire biometric information of user U#3. Terminal device 100#3 may perform biometric authentication of user U#3 using the biometric information. If the biometric authentication is successful, terminal device 100#3 may transmit user information about user U#3 to the virtual world server 400.
[0182] The virtual world server 400, which has received the user information about user U#1, user U#2, and user U#3, may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on the user information about user U#1, user U#2, and user U#3. If the virtual world server 400 does not receive user information about at least one of the multiple users U#1, U#2, and U#3 within a predetermined period due to a biometric authentication failure for the at least one user, the virtual world server 400 may not permit the multiple users U#1, U#2, and U#3 to log in to one virtual space. If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the virtual world server 400 may not permit the multiple users U#1, U#2, and U#3 to log in to one virtual space.
[0183] If it is determined that multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions, virtual world server 400 may output user information about user U#1, user information about user U#2, and user information about user U#3 to security terminal 300. Operator O of security terminal 300 may determine whether multiple users U#1, U#2, and U#3 are allowed to log in to one virtual space based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0184] Operator O may use security terminal 300 to transmit permission information (in other words, the result of operator O's judgment) indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to virtual world server 400. As a result, virtual world server 400 may receive permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space.
[0185] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to a virtual space, the virtual world server 400 may permit the multiple users U#1, U#2, and U#3 to log in to the virtual space. As a result, the multiple users U#1, U#2, and U#3 may log in to the virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the virtual space, the virtual world server 400 may, for example, transmit information indicating that they cannot log in to the virtual space to the multiple terminal devices 100#1, 100#2, and 100#3. As a result, the terminal devices 100#1, 100#2, and 100#3 may, for example, notify them that they cannot log in to the virtual space.
[0186] (Configuration of Each of the Terminal Devices 100#1, 100#2, and 100#3) Each of the terminal devices 100#1, 100#2, and 100#3 may include a calculation device 110a shown in FIG.
[0187] (Configuration of virtual world server 400) The virtual world server 400 may include a computing device 410b instead of the computing device 410 or 410a. The computing device 410b may have one or more processors, similar to the computing device 410. As shown in Fig. 20 , the computing device 410b may include an acquisition unit 411, an output unit 413, and a group authentication unit 414 as logically realized functional blocks or as physically realized processing circuits.
[0188] (Operation of Information Processing System 6) The acquisition unit 111 of the terminal device 100#1 may acquire biometric information including information related to the eyes of the user U#1 wearing the wearable device. The personal authentication unit 112a of the terminal device 100#1 may perform biometric authentication of the user U#1 using the biometric information acquired by the acquisition unit 111. If the biometric authentication is successful, the output unit 113 of the terminal device 100#1 may transmit user information related to the user U#1 to the virtual world server 400 via the communication device 130 of the terminal device 100#1. Note that if the biometric authentication fails, the calculation device 110a of the terminal device 100#1 may control the output device 150 of the terminal device 100#1 to notify the user that the biometric authentication has failed.
[0189] The acquisition unit 111 of the terminal device 100#2 may acquire biometric information including information related to the eyes of the user U#2 wearing the wearable device. The personal authentication unit 112a of the terminal device 100#2 may perform biometric authentication of the user U#2 using the biometric information acquired by the acquisition unit 111. If the biometric authentication is successful, the output unit 113 of the terminal device 100#2 may transmit user information related to the user U#2 to the virtual world server 400 via the communication device 130 of the terminal device 100#2. Note that if the biometric authentication fails, the calculation device 110a of the terminal device 100#2 may control the output device 150 of the terminal device 100#2 to notify the user that the biometric authentication has failed.
[0190] The acquisition unit 111 of the terminal device 100#3 may acquire biometric information including information related to the eyes of the user U#3 wearing the wearable device. The personal authentication unit 112a of the terminal device 100#3 may perform biometric authentication of the user U#3 using the biometric information acquired by the acquisition unit 111. If the biometric authentication is successful, the output unit 113 of the terminal device 100#3 may transmit user information related to the user U#3 to the virtual world server 400 via the communication device 130 of the terminal device 100#3. Note that if the biometric authentication fails, the calculation device 110a of the terminal device 100#3 may control the output device 150 of the terminal device 100#3 to notify the user that the biometric authentication has failed.
[0191] The acquisition unit 411 of the virtual world server 400 may acquire user information about user U#1, user information about user U#2, and user information about user U#3 transmitted from each of the multiple terminal devices 100#1, 100#2, and 100#3. Here, when at least one of the multiple terminal devices 100#1, 100#2, and 100#3 transmits user information to the virtual world server 400, it may also transmit a group authentication query to the virtual world server 400. The group authentication unit 414 of the virtual world server 400 that receives the group authentication query may determine whether the multiple users U#1, U#2, and U#3 satisfy predetermined authentication conditions based on the user information about user U#1, user information about user U#2, and user information about user U#3.
[0192] If it is determined that the multiple users U#1, U#2, and U#3 do not satisfy the predetermined authentication conditions, the calculation device 410b may transmit information indicating that login to the one virtual space is not permitted to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 430. The calculation device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 that has received the information indicating that login to the one virtual space is not permitted may control the output device 150 to notify that login to the one virtual space is not permitted.
[0193] If it is determined that multiple users U#1, U#2, and U#3 satisfy specified authentication conditions, the output unit 413 of the virtual world server 400 may output user information regarding user U#1, user information regarding user U#2, and user information regarding user U#3 to the security terminal 300 via the communication device 430.
[0194] Operator O may use security terminal 300 to transmit permission information indicating whether or not multiple users U#1, U#2, and U#3 are permitted to log in to one virtual space to virtual world server 400. As a result, communication device 430 of virtual world server 400 may receive the permission information.
[0195] If the permission information indicates that multiple users U#1, U#2, and U#3 are permitted to log in to a virtual space, the virtual world server 400 may permit the multiple users U#1, U#2, and U#3 to log in to the virtual space. As a result, the multiple users U#1, U#2, and U#3 may log in to the virtual space. On the other hand, if the permission information indicates that multiple users U#1, U#2, and U#3 are not permitted to log in to the virtual space, the calculation device 410b of the virtual world server 400 may transmit, for example, information indicating that they cannot log in to the virtual space to the multiple terminal devices 100#1, 100#2, and 100#3 via the communication device 420. As a result, the calculation device 110 of each of the multiple terminal devices 100#1, 100#2, and 100#3 may control the output device 150 to notify them that they cannot log in to the virtual space.
[0196] (Technical effect) According to the information processing system 6 of the eighth embodiment, similar to the information processing system 6 of the seventh embodiment described above, when multiple users log in to a single virtual space, in addition to verifying the identity of each user through biometric authentication, the multiple users can be verified by an operator O of the security terminal 300.
[0197] <Modifications> Modifications common to the first to eighth embodiments will be described with reference to Figures 21 and 22. Note that descriptions that overlap with the descriptions of the first to eighth embodiments will be omitted as appropriate.
[0198] (Configuration of security terminal 300) The configuration of security terminal 300 will be described with reference to Fig. 21. In Fig. 21, security terminal 300 comprises a calculation device 310, a storage device 320, a communication device 330, an input device 340, and an output device 350. The calculation device 310, the storage device 320, the communication device 330, the input device 340, and the output device 350 may be connected via a data bus 360.
[0199] The arithmetic device 310 may include a processor 3101. The arithmetic device 310 may include other processors in addition to the processor 3101. That is, the arithmetic device 310 may include one or more processors. The processor 3101 may be a multi-core processor. When the arithmetic device 310 includes a single processor 3101 that is a multi-core processor, it can be said that the arithmetic device 310 logically includes multiple processors. The processor 3101 may be, for example, at least one of a CPU, a GPU, an FPGA, a TPU, and a quantum processor.
[0200] The storage device 320 may include a memory 3201. The storage device 320 may include other memories in addition to the memory 3201. That is, the storage device 320 may include one or more memories. The memory 3201 may be, for example, at least one of a RAM, a ROM, a hard disk device, a magneto-optical disk device, an SSD, and an optical disk array. Therefore, the storage device 320 may include the memory 3201 as a non-transitory recording medium.
[0201] The storage device 320 can store desired data. A computer program 3201a executed by the arithmetic device 310 may be stored in the memory 3201 of the storage device 320. The storage device 320 may temporarily store data that is temporarily used by the arithmetic device 310 when the arithmetic device 310 is executing the computer program 3201a. The storage device 320 may store a database related to biometric authentication. The database may include at least one of registered images and registered feature amounts used for biometric authentication.
[0202] The computer program 3201a may be recorded on a computer-readable, non-transitory recording medium. In this case, the computer program 3201a may be stored in the memory 3201 by reading the recording medium using a recording medium reading device (not shown) included in the security terminal 300. The recording medium may be at least one of an optical disk, a magnetic medium, a magneto-optical disk, a semiconductor memory, and any other medium capable of storing a program. The computer program 3201a may be acquired (in other words, downloaded) from a device (not shown) external to the security terminal 300 via the communication device 330. The acquired computer program 3201a may be stored in the memory 3201.
[0203] The communication device 330 may be capable of communicating with devices external to the security terminal 300. The communication device 330 may perform wired communication or wireless communication.
[0204] The input device 340 is a device capable of accepting information input to the security terminal 300 from outside. The input device 340 may include an operating device (e.g., a keyboard, a mouse, a touch panel, etc.) that can be operated by an operator O of the security terminal 300. The input device 340 may include a recording medium reading device that can read information recorded on a recording medium that is detachable from the security terminal 300, such as a USB memory. Note that when information is input to the security terminal 300 via the communication device 330 (in other words, when the security terminal 300 acquires information via the communication device 330), the communication device 330 may function as an input device.
[0205] The output device 350 is a device capable of outputting information to the outside of the security terminal 300. The output device 350 may output visual information such as text or images, auditory information such as sound, or tactile information such as vibration. The output device 350 may include, for example, at least one of a display, a speaker, a printer, and a vibration motor. The output device 350 may also be capable of outputting information to a recording medium that is detachable from the security terminal 300, such as a USB memory. Note that when the security terminal 300 outputs information via the communication device 330, the communication device 330 may function as the output device.
[0206] The processor 3101 of the computing device 310, together with the memory 3201 of the storage device 320 in which the computer program 3201a is stored (in other words, together with the memory 3201 and the computer program 3201a stored in the memory 3201), may execute the processing to be performed by the security terminal 300. For example, by the processor 3101 executing the computer program 3201a, a logical function block for executing the processing to be performed by the security terminal 300 may be realized within the computing device 310 (e.g., within the processor 3101).
[0207] 22, the arithmetic device 310 may have, as logically realized functional blocks or physically realized processing circuits, an acquisition unit 311, an authentication unit 312, and an alarm unit 313. Note that at least one of the acquisition unit 311, the authentication unit 312, and the alarm unit 313 may be realized in a form in which a logical functional block and a physical processing circuit (i.e., hardware) are mixed.
[0208] When the acquisition unit 311, authentication unit 312, and alarm unit 313 are realized as functional blocks, the acquisition unit 311, authentication unit 312, and alarm unit 313 may be realized by a single processor (for example, processor 3101). Alternatively, the acquisition unit 311, authentication unit 312, and alarm unit 313 may be realized by different processors. Alternatively, parts of the acquisition unit 311, authentication unit 312, and alarm unit 313 may be realized by a single processor, and the remaining parts of the acquisition unit 311, authentication unit 312, and alarm unit 313 may be realized by one or more processors different from the single processor.
[0209] (Operation of security terminal 300) The acquisition unit 311 may acquire biometric information of the operator O. The authentication unit 312 may perform biometric authentication of the operator O using the biometric information acquired by the acquisition unit 311. Note that the authentication unit 312 may perform at least one of the following biometric authentication methods, for example: face authentication, iris authentication, fingerprint authentication, palm print authentication, vein authentication, voice print authentication, ear acoustic authentication, and multimodal biometric authentication.
[0210] The biometric authentication of the operator O may be performed, for example, at least one of when the operator O logs in to the security terminal 300 and when the operator O transmits the above-mentioned permission information. This configuration can prevent, for example, a person conspiring with a person attempting to log in to the virtual space by fraudulent means from operating the security terminal 300. If the biometric authentication of the operator O fails, the alarm unit 313 may control the output device 350 to issue an alarm.
[0211] For example, as described in the second embodiment, if a person other than the user U is displayed in addition to the user U on the screen related to the video call between the operator O and the user U, and the operator O determines that the user U is being threatened or the like by a person other than the user U, the operator O may call the police. For example, if the user U makes a signal to notify an emergency, the operator O may call the police.
[0212] In this modification, for example, the arithmetic device 310 may automatically determine whether the user U is being threatened or the like, based on a screen related to a video call. If it is determined that the user U is being threatened or the like, the alarm unit 313 may control the output device 350 to issue an alarm. For example, the arithmetic device 310 may determine whether the user U has given a signal indicating an emergency. If it is determined that the user U has given a signal indicating an emergency, the alarm unit 313 may control the output device 350 to issue an alarm. Note that the signal indicating an emergency may be emergency information transmitted from the terminal device 100 indicating that an emergency has occurred. Upon receiving the emergency information, the arithmetic device 310 of the security terminal 300 may determine that the user U has given a signal indicating an emergency. As a result, the alarm unit 313 may control the output device 350 to issue an alarm. This configuration can prevent the operator O from missing the user U's help signal.
[0213] <Supplementary Notes> A part or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0214] (Supplementary Note 1) An information processing system comprising: an acquisition means for acquiring biometric information including information relating to the eyes of a subject wearing a wearable device; an authentication means for performing biometric authentication of the subject using the biometric information; an output means for outputting subject information relating to the subject to a security terminal if the biometric authentication by the authentication means is successful; and a receiving means for receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
[0215] (Supplementary Note 2) An information processing device comprising: an acquisition means for acquiring biometric information including information relating to the eyes of a subject wearing a wearable device; an authentication means for performing biometric authentication of the subject using the biometric information; an output means for outputting subject information relating to the subject to a security terminal if the biometric authentication by the authentication means is successful; and a receiving means for receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
[0216] (Supplementary Note 3) The information processing device described in Supplementary Note 2, wherein the acquisition means acquires a plurality of pieces of biometric information each including information relating to the eyes of a plurality of subjects each wearing a wearable device; the authentication means performs biometric authentication of the plurality of subjects using the plurality of pieces of biometric information; the authentication means determines whether the plurality of subjects satisfy predetermined authentication conditions; the output means outputs a plurality of pieces of target information relating to each of the plurality of subjects to the security terminal when biometric authentication of each of the plurality of subjects is successful and it is determined that the plurality of subjects satisfy the predetermined authentication conditions; and the receiving means receives the permission information from the security terminal indicating whether the plurality of subjects are allowed to log in to the virtual space based on the plurality of pieces of target information.
[0217] (Supplementary Note 4) The information processing device according to Supplementary Note 2 or 3, wherein the target information includes an image showing an appearance of the target.
[0218] (Supplementary Note 5) The information processing device according to any one of Supplementary Notes 2 to 4, wherein the target information includes an image showing a surrounding area of the target.
[0219] The information processing device according to any one of appendices 2 to 5, wherein the target information includes a matching score calculated by the authentication means in the biometric authentication.
[0220] (Supplementary Note 7) The information processing device according to Supplementary Note 3, wherein the predetermined authentication condition includes at least one of a condition to be satisfied by the plurality of targets and a time limit condition.
[0221] (Appendix 8) The information processing device described in Appendix 4, wherein the image showing the appearance of the subject is a composite image of an image including the face of the subject wearing the wearable device and an image including the subject's eyes covered by the wearable device.
[0222] (Supplementary Note 9) The information processing device according to Supplementary Note 7, wherein the conditions to be satisfied by the plurality of targets include a condition regarding a combination of the plurality of targets.
[0223] (Supplementary Note 10) The information processing system described in Supplementary Note 1, wherein the acquisition means acquires a plurality of pieces of biometric information each including information relating to the eyes of a plurality of subjects each wearing a wearable device; the authentication means performs biometric authentication of the plurality of subjects using the plurality of pieces of biometric information; the authentication means determines whether the plurality of subjects satisfy predetermined authentication conditions; the output means outputs a plurality of pieces of target information relating to each of the plurality of subjects to the security terminal when biometric authentication of each of the plurality of subjects is successful and it is determined that the plurality of subjects satisfy the predetermined authentication conditions; and the receiving means receives the permission information from the security terminal indicating whether the plurality of subjects are allowed to log in to the virtual space based on the plurality of pieces of target information.
[0224] (Appendix 11) The information processing system described in Appendix 1 or 10, wherein the security terminal outputs at least one of text data input by the subject and the subject's voice, and the wearable device outputs at least one of text data input by an operator of the security terminal and the operator's voice.
[0225] (Supplementary Note 12) The information processing system according to Supplementary Note 1, 10 or 11, wherein the target information includes an image showing the appearance of the target, and the security terminal displays the image showing the appearance of the target.
[0226] (Supplementary Note 13) The information processing system described in any one of Supplementary Notes 1 and 10 to 12, wherein the target information includes an image showing the surroundings of the target, and the security terminal displays the image showing the surroundings of the target.
[0227] (Supplementary Note 14) The information processing system described in any one of Supplementary Notes 1 and 10 to 13, wherein the target information includes a matching score calculated by the authentication means in the biometric authentication, and the security terminal displays the matching score.
[0228] (Supplementary Note 15) The information processing system according to Supplementary Note 10, wherein the plurality of pieces of target information include a plurality of images respectively showing the appearances of the plurality of targets, and the security terminal displays the plurality of images.
[0229] (Supplementary Note 16) The information processing system according to any one of Supplementary Notes 1 and 10 to 15, wherein the security terminal transmits the permission information when biometric authentication of the operator of the security terminal is successful.
[0230] (Supplementary Note 17) The information processing system according to any one of Supplementary Notes 1 and 10 to 16, wherein the security terminal issues an alert in response to emergency information issued by the target.
[0231] (Supplementary Note 18) The information processing system according to Supplementary Note 16, wherein the operator is a person who performs security work.
[0232] (Supplementary Note 19) An information processing method comprising: acquiring biometric information including information relating to the eyes of a subject wearing a wearable device; performing biometric authentication of the subject using the biometric information; if the biometric authentication is successful, outputting subject information relating to the subject to a security terminal; and receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
[0233] (Appendix 20) A recording medium having recorded thereon a computer program for causing a computer to execute an information processing method, which includes acquiring biometric information including information relating to the eyes of a subject wearing a wearable device, performing biometric authentication of the subject using the biometric information, outputting subject information relating to the subject to a security terminal if the biometric authentication is successful, and receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
[0234] Furthermore, some or all of the configurations described in Supplementary Notes 10 to 18, which are dependent on Supplementary Note 1, may also be dependent on Supplementary Note 19 in the same dependent relationship as Supplementary Note 10 to 18. Some or all of the configurations described in Supplementary Notes 3 to 9, which are dependent on Supplementary Note 2, may also be dependent on Supplementary Note 19 and Supplementary Note 20 in the same dependent relationship as Supplementary Note 3 to 9. Furthermore, not limited to Supplementary Note 1, Supplementary Note 2, Supplementary Note 19, and Supplementary Note 20, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems, within the scope of the above-described embodiments.
[0235] This disclosure may be modified as appropriate within the scope that does not contradict the gist or idea of the invention that can be read from the claims and the entire specification, and information processing systems, information processing devices, information processing methods, and recording media that involve such modifications are also included in the technical idea of this disclosure.
[0236] 1, 2, 3, 4, 5, 6 Information processing system 100 Terminal device 200 Authentication server 300 Security terminal 400 Virtual world server
Claims
1. An information processing system comprising: an acquisition means for acquiring biometric information including information relating to the eyes of a subject wearing a wearable device; an authentication means for performing biometric authentication of the subject using the biometric information; an output means for outputting subject information relating to the subject to a security terminal if the biometric authentication by the authentication means is successful; and a receiving means for receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
2. An information processing device comprising: an acquisition means for acquiring biometric information including information relating to the eyes of a subject wearing a wearable device; an authentication means for performing biometric authentication of the subject using the biometric information; an output means for outputting subject information relating to the subject to a security terminal if the biometric authentication by the authentication means is successful; and a receiving means for receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
3. The information processing device according to claim 2, wherein the acquisition means acquires a plurality of pieces of biometric information each including information relating to the eyes of a plurality of subjects each wearing a wearable device; the authentication means performs biometric authentication of the plurality of subjects using the plurality of pieces of biometric information; the authentication means determines whether the plurality of subjects satisfy predetermined authentication conditions; the output means outputs a plurality of pieces of target information relating to each of the plurality of subjects to the security terminal when biometric authentication of each of the plurality of subjects is successful and it is determined that the plurality of subjects satisfy the predetermined authentication conditions; and the receiving means receives from the security terminal the permission information indicating whether the plurality of subjects are allowed to log in to the virtual space based on the plurality of pieces of target information.
4. The information processing device according to claim 2, wherein the object information includes an image showing the appearance of the object.
5. The information processing device according to claim 2, wherein the target information includes an image showing the surroundings of the target.
6. The information processing device according to claim 2, wherein the target information includes a matching score calculated by the authentication means in the biometric authentication.
7. The information processing device according to claim 3, wherein the predetermined authentication conditions include at least one of a condition that must be satisfied by the plurality of targets and a time limit condition.
8. The information processing device described in claim 4, wherein the image showing the appearance of the subject is a composite image of an image including the face of the subject wearing the wearable device and an image including the eyes of the subject covered by the wearable device.
9. The information processing device according to claim 7, wherein the conditions to be satisfied by the plurality of objects include a condition regarding a combination of the plurality of objects.
10. The information processing system of claim 1, wherein the acquisition means acquires a plurality of pieces of biometric information each including information relating to the eyes of a plurality of subjects each wearing a wearable device; the authentication means performs biometric authentication of the plurality of subjects using the plurality of pieces of biometric information; the authentication means determines whether the plurality of subjects satisfy predetermined authentication conditions; the output means outputs a plurality of pieces of target information relating to each of the plurality of subjects to the security terminal when biometric authentication of each of the plurality of subjects is successful and it is determined that the plurality of subjects satisfy the predetermined authentication conditions; and the receiving means receives from the security terminal the permission information indicating whether the plurality of subjects are allowed to log in to the virtual space based on the plurality of pieces of target information.
11. The information processing system described in claim 1, wherein the security terminal outputs at least one of text data input by the subject and the subject's voice, and the wearable device outputs at least one of text data input by an operator of the security terminal and the operator's voice.
12. The information processing system according to claim 1, wherein the target information includes an image showing the appearance of the target, and the security terminal displays the image showing the appearance of the target.
13. The information processing system according to claim 1, wherein the target information includes an image showing the surroundings of the target, and the security terminal displays the image showing the surroundings of the target.
14. An information processing system as described in claim 1, wherein the target information includes a matching score calculated by the authentication means in the biometric authentication, and the security terminal displays the matching score.
15. An information processing system as described in claim 10, wherein the target information includes a plurality of images each showing the appearance of the target, and the security terminal displays the images.
16. The information processing system according to claim 1, wherein the security terminal transmits the permission information when biometric authentication of the operator of the security terminal is successful.
17. The information processing system according to claim 1, wherein the security terminal issues an alert in response to emergency information issued by the target.
18. The information processing system according to claim 16, wherein the operator is a person who performs security duties.
19. An information processing method comprising: acquiring biometric information including information relating to the eyes of a subject wearing a wearable device; performing biometric authentication of the subject using the biometric information; if the biometric authentication is successful, outputting subject information relating to the subject to a security terminal; and receiving permission information from the security terminal indicating whether the subject is allowed to log in to a virtual space based on the subject information.
20. A recording medium having recorded thereon a computer program for causing a computer to execute an information processing method, which comprises acquiring biometric information including information relating to the eyes of a subject wearing a wearable device, performing biometric authentication of the subject using the biometric information, outputting subject information relating to the subject to a security terminal if the biometric authentication is successful, and receiving permission information from the security terminal indicating whether the subject is permitted to log in to a virtual space based on the subject information.
Citation Information
Patent Citations
Information presentation system
JP2007006393A
Display device
JP2022007212A
Information processing device, information processing method, and computer-readable storage medium
WO2023032170A1