Identity checking device, identity checking system, identity checking method, and recording medium
The biometric authentication system with a master ID management device addresses privacy and security concerns in identity verification by minimizing personal information disclosure and using one-time IDs, enhancing privacy and security in identity verification processes.
Patent Information
- Application Number
- PCT/JP2024/012372
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-10-02
AI Technical Summary
Existing identity verification systems require users to provide extensive personal information during registration and service access, compromising privacy and increasing the risk of impersonation and spoofing.
A biometric authentication system using a master ID management device that performs biometric verification and issues one-time IDs, eliminating the need to disclose personal information like email addresses or phone numbers to service providers, and reducing the risk of impersonation by using one-time identification information.
Reduces the amount of personal information required during registration, enhances user privacy by minimizing data exposure, and decreases the likelihood of impersonation and spoofing by utilizing biometric authentication and one-time IDs.
Smart Images

Figure JP2024012372_02102025_PF_FP_ABST
Abstract
Description
Personal identification device, personal identification system, personal identification method, and recording medium
[0001] The present invention relates to an identity verification device, an identity verification system, an identity verification method, and a recording medium.
[0002] In some cases, identity verification is performed when processing is performed to link a user to an individual. For example, Patent Literature 1 describes that an automated teller machine performs face authentication on a user who has forgotten their personal identification number, and discloses the personal identification number to the user if authentication is successful.
[0003] Japanese Patent Application Publication No. 5-314344
[0004] When a user registers for a plurality of services, it is preferable that the amount of personal information provided during registration be as small as possible.
[0005] An example of an object of the present invention is to provide an identity verification device, an identity verification system, an identity verification method, and a recording medium that can solve the above-mentioned problems.
[0006] According to a first aspect of the present invention, an identity verification device includes a biometric authentication means for performing biometric authentication of a user based on biometric information of the subject to be authenticated and biometric information linked to a master ID, which is identification information for identifying the user, and a master ID management means for notifying the device requesting identity verification of the result of the biometric authentication and the identification information issued by the device requesting identity verification.
[0007] According to a second aspect of the present invention, an identity verification system includes a user terminal device, an identity verification device, and a service providing device, and the identity verification device includes a biometric authentication means for performing biometric authentication of the user based on biometric information acquired from the user terminal device and biometric information linked to a master ID which is identification information for identifying the user, and a master ID management means for notifying the service providing device of the result of the biometric authentication and the identification information issued by the service providing device requesting identity verification.
[0008] According to a third aspect of the present invention, an identity verification method includes a computer performing biometric authentication of a user based on biometric information of an object to be authenticated and biometric information linked to a master ID, which is identification information that identifies the user, and notifying the device requesting identity verification of the result of the biometric authentication and identification information issued by the device requesting identity verification.
[0009] According to a fourth aspect of the present invention, the recording medium is a recording medium having recorded thereon a program that causes a computer to perform biometric authentication of a user based on biometric information of the subject to be authenticated and biometric information linked to a master ID, which is identification information that identifies the user, and to notify the device requesting identity verification of the result of the biometric authentication and the identification information issued by the device requesting identity verification.
[0010] FIG. 1 is a diagram showing an example of the configuration of an identity verification system according to at least one embodiment. FIG. 2 is a diagram showing an example of the configuration of a user terminal device according to at least one embodiment. FIG. 3 is a diagram showing an example of the configuration of a master ID management device according to at least one embodiment. FIG. 4 is a diagram showing an example of the configuration of a service providing device according to at least one embodiment. FIG. 5 is a diagram showing an example of the processing procedure in the identity verification system 1 when the master ID management device according to at least one embodiment issues a master ID. FIG. 6 is a diagram showing an example of the processing procedure in the identity verification system 1 when the service providing device according to at least one embodiment issues a service ID. FIG. 7 is a diagram showing an example of the processing procedure in the identity verification system when resetting a password for a Web service according to at least one embodiment. FIG. 8 is a diagram showing an example of the configuration of an identity verification device according to at least one embodiment. FIG. 9 is a diagram showing an example of the configuration of an identity verification system according to at least one embodiment. FIG. 10 is a diagram showing an example of the processing procedure in an identity verification method according to at least one embodiment. FIG. 11 is a schematic block diagram showing the configuration of a computer according to at least one embodiment.
[0011] The following describes embodiments of the present invention, but the following embodiments do not limit the scope of the invention as claimed. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0012] <First embodiment> Fig. 1 is a diagram showing an example of the configuration of an identity verification system according to at least one embodiment. In the configuration shown in Fig. 1, the identity verification system 1 includes a user terminal device 100, a master ID (identifier, identification information) management device 200, and a service providing device 300. The user terminal device 100 may be configured external to the identity verification system 1.
[0013] In the identity verification system 1, the master ID management device 200 verifies the identity of the user when the user registers with the service providing device 300 and when the password is reset in the service providing device 300. In particular, in the identity verification system 1, the identity of the user can be verified without the need to notify the service providing device 300 of the master ID, which is identification information assigned to the user by the master ID management device 200. In this respect, in the identity verification system 1, when a user registers for multiple services separately for each service, the amount of personal information provided during registration can be relatively small. The master ID management device 200 is an example of an identity verification device.
[0014] The identity verification system 1 uses a one-time ID so that the identity of a user can be verified without the need to notify the service providing device 300 of the master ID. The one-time ID is identification information that is issued for each process and identifies the user. The service providing device 300 is an example of a device that requests identity verification.
[0015] Any of the user terminal device 100, the master ID management device 200, and the service providing device 300 may be configured using a computer. The number of service providing devices 300 may be one or more and is not limited to a specific number. The number of users who use the identity verification system 1 may be one or more and is not limited to a specific number. Therefore, the number of user terminal devices 100 that use the identity verification system 1 may be one or more and is not limited to a specific number.
[0016] Fig. 2 is a diagram showing an example of the configuration of the user terminal device 100. In the configuration shown in Fig. 2, the user terminal device 100 includes a first communication unit 110, a display unit 120, an operation input unit 130, a camera 140, a first memory unit 180, and a first control unit 190. The first control unit 190 includes a master ID request processing unit 191 and a service request processing unit 192.
[0017] The first communication unit 110 communicates with other devices. For example, the first communication unit 110 communicates various information related to the service provided by the service providing device 300, such as sending a user registration request to the service providing device 300 and receiving a one-time ID for user registration. The first communication unit 110 also communicates various information related to identity verification, such as receiving a request for identity verification data from the master ID management device 200 and transmitting facial image data for identity verification.
[0018] The display unit 120 has a display screen such as a liquid crystal panel or an LED (Light Emitting Diode) panel, and displays various images. For example, the display unit 120 displays various requests and various information in exchanges with the master ID management device 200 and the service providing device 300.
[0019] The operation input unit 130 includes input devices such as a keyboard and a mouse, and receives user inputs. For example, the operation input unit 130 receives various user inputs in interactions with the master ID management device 200 and the service providing device 300.
[0020] The camera 140 takes a photograph and generates image data. In particular, the camera 140 is used to generate face image data used for face authentication to verify the identity of a user.
[0021] The first storage unit 180 stores various data. For example, the first storage unit 180 stores various information necessary for communication with the master ID management device 200 and the service providing device 300, such as the communication address of the master ID management device 200 and the communication address of the service providing device 300. The first storage unit 180 is configured using a storage device provided in the user terminal device 100.
[0022] The first control unit 190 performs various processes by controlling each unit of the user terminal device 100. The functions of the first control unit 190 are executed by a CPU (Central Processing Unit) included in the user terminal device 100 reading and executing a program from the first storage unit 180.
[0023] The master ID request processing unit 191 performs various processes related to the master ID, such as a request to issue a master ID and a request for identity verification from the master ID management device 200. The service request processing unit 192 performs various processes related to the services provided by the service providing device 300, such as a request to issue a user ID for receiving a service from the service providing device 300, a request for service provision, and a request for password reset. A user ID for receiving a service is also called a service ID.
[0024] Fig. 3 is a diagram showing an example of the configuration of the master ID management device 200. In the configuration shown in Fig. 3, the master ID management device 200 includes a second communication unit 210, a second storage unit 280, and a second control unit 290. The second control unit 290 includes a biometric authentication unit 291 and a master ID processing unit 292.
[0025] The second communication unit 210 communicates with other devices. In particular, the second communication unit 210 transmits and receives various requests and information related to identity verification performed by the master ID management device 200. For example, the second communication unit 210 transmits a request for biometric information for identity verification to the user terminal device 100 and receives biometric information from the user terminal device 100.
[0026] The second storage unit 280 stores various data. For example, the second storage unit 280 stores a master ID and biometric information for comparison during identity verification in association with each other. The second storage unit 280 corresponds to an example of a storage means. The second storage unit 280 is configured using a storage device provided in the master ID management device 200.
[0027] The second control unit 290 performs various processes by controlling each unit of the master ID management device 200. The functions of the second control unit 290 are performed by the CPU included in the master ID management device 200 reading and executing a program from the second storage unit 280.
[0028] The biometric authentication unit 291 performs biometric authentication for identity verification. The biometric authentication unit 291 is an example of a biometric authentication means. In the following, an example will be described in which the biometric authentication unit 291 performs face authentication. However, the biometric authentication performed by the biometric authentication unit 291 is not limited to a specific type. For example, the biometric authentication unit 291 may perform iris authentication, fingerprint authentication, palm print authentication, or vein authentication. The biometric authentication unit 291 may perform multiple types of biometric authentication. Furthermore, the user terminal device 100 may perform the biometric authentication.
[0029] The master ID processing unit 292 performs various processes related to the master ID, such as registering the master ID and verifying the identity of the user whose master ID is registered, etc. The master ID processing unit 292 is an example of a master ID management unit.
[0030] Fig. 4 is a diagram showing an example of the configuration of the service providing device 300. In the configuration shown in Fig. 4, the service providing device 300 includes a third communication unit 310, a third storage unit 380, and a third control unit 390. The third control unit 390 includes a service ID processing unit 391 and a web service processing unit 392.
[0031] The third communication unit 310 communicates with other devices. In particular, the third communication unit 310 transmits and receives various requests and information related to the provision of services by the service providing device 300. For example, the third communication unit 310 receives a request to issue a service ID from the user terminal device 100 and transmits a one-time ID to the user terminal device 100. The third communication unit 310 also receives, from the master ID management device 200, the identity verification result of the user requesting the issuance of a service ID. The third communication unit 310 also transmits the service ID to the user terminal device 100.
[0032] The third storage unit 380 stores various data. For example, the third storage unit 380 stores a service ID and a password in association with each other. The third storage unit 380 is configured using a storage device included in the service providing device 300.
[0033] The third control unit 390 performs various processes by controlling each unit of the service providing device 300. The functions of the third control unit 390 are executed by the CPU included in the service providing device 300 reading and executing a program from the third storage unit 380.
[0034] The service ID processing unit 391 performs various processes related to the service ID, such as issuing a service ID and resetting a password, etc. The web service processing unit 392 performs various processes related to the provision of a service.
[0035] 5 is a diagram showing an example of a processing procedure in the identity verification system 1 when the master ID management device 200 issues a master ID. In the processing of FIG. 5, the user terminal device 100 transmits a master ID issuance request to the master ID management device 200 (step S101). Specifically, the master ID request processing unit 191 generates a master ID issuance request based on a user operation, the master ID request processing unit 191 including information for identity verification by eKYC (Electronic Know Your Customer) and the user's biometric information. Then, the master ID request processing unit transmits the master ID issuance request to the master ID management device 200 via the first communication unit 110.
[0036] Next, the master ID management device 200 issues a master ID (step S102). Specifically, if the user's identity can be confirmed by the eKYC, the master ID processing unit 292 generates a master ID. Then, the master ID processing unit 292 associates the generated master ID with the biometric information included in the master ID issuance request and stores them in the second storage unit 280. The master ID processing unit 292 also transmits the master ID to the user terminal device 100 via the second communication unit 210.
[0037] 6 is a diagram showing an example of the processing procedure in the identity verification system 1 when the service providing device 300 issues a service ID. In the processing of FIG. 6, the user terminal device 100 transmits a service ID issuance request to the service providing device 300 (step S201). Specifically, the service request processing unit 192 generates a service ID issuance request in accordance with a user operation. Then, the service request processing unit 192 transmits the service ID issuance request to the service providing device 300 via the first communication unit 110.
[0038] Next, the service providing device 300 issues a one-time ID (step S202). Specifically, the service ID processing unit 391 generates a one-time ID including a one-time token, identification information of the service providing device 300, and the provisionally issued service ID. The one-time token here is identification information issued for each process.
[0039] Here, the one-time token is not essential. Even if the service ID processing unit 391 generates information including the identification information of the service providing device 300 and the provisionally issued service ID, the service providing device 300 can issue a service ID and reset a password. On the other hand, if the service ID processing unit 391 generates a one-time ID including a one-time token, the possibility of spoofing can be reduced.
[0040] In addition, the service ID processing unit 391 includes identification information of the service providing device 300 in the one-time ID, such as the communication address of the service providing device 300, so that the user terminal device 100 and the master ID management device 200 can communicate with the service providing device 300.
[0041] The service ID processing unit 391 then temporarily stores the one-time ID in the third storage unit 380. The service ID processing unit 391 also transmits the one-time ID via the third communication unit 310 to the user terminal device 100 that has requested the issuance of the service ID.
[0042] Upon receiving the one-time ID, the user terminal device 100 transmits the master ID and the received one-time ID to the master ID management device 200 to request identity verification (step S203). Specifically, the master ID request processing unit 191 generates an identity verification request including the received one-time ID and the master ID issued by the master ID management device 200. The master ID request processing unit 191 then transmits the identity verification request to the master ID management device 200 via the first communication unit 110.
[0043] The master ID management device 200 records the one-time ID received from the user terminal device (step S204). Specifically, the master ID processing unit 292 associates the one-time ID with the master ID and stores them in the second storage unit 280. As a result, the second storage unit 280 stores a service ID for each service providing device and for each master ID. The identification information of the service providing device 300 and the service ID in the one-time ID are used later when resetting a password.
[0044] Next, the master ID management device 200 sends a matching data request to the user terminal device 100 (step S205). Specifically, the master ID processing unit 292 generates a matching data request including the one-time ID. The matching data request here is a request for biometric information for identity verification. The master ID processing unit 292 then transmits the matching data request to the user terminal device 100 that has requested identity verification via the second communication unit 210.
[0045] Upon receiving the matching data request, the user terminal device 100 transmits the matching data to the master ID management device 200 (step S206). Specifically, the master ID request processing unit 191 displays a message requesting a facial image to be taken on the display unit 120. When the user who has referred to the message takes a facial image of the user using the camera 140, the master ID request processing unit 191 generates matching data including facial image data and a one-time ID. The matching data here is data including biometric information for identity verification.
[0046] Then, the master ID request processing unit 191 transmits the matching data to the master ID management device 200 via the first communication unit 110. Alternatively, the master ID request processing unit 191 may also transmit the matching data to the master ID management device 200 when making the identity verification request in step S203.
[0047] Upon receiving the matching data, the master ID management device 200 performs identity verification using the received matching data and transmits the matching result and the one-time ID to the service providing device 300 (step S207). Specifically, the biometric authentication unit 291 performs identity verification through biometric authentication using the biometric information included in the matching data and the biometric information stored in the second storage unit 280 in association with the master ID. The master ID processing unit 292 then transmits the result of the identity verification and the one-time ID to the service providing device 300 indicated by the identification information included in the one-time ID. The result of identity verification here is also referred to as a matching result.
[0048] The service providing device 300, which has received the collation result and the one-time ID, issues a service ID (step S208). Specifically, if the collation result indicates that the user who requested the issuance of the service ID is the actual user, the service ID processing unit 391 associates the service ID indicated in the one-time ID with the password as a formal service ID and stores it in the third storage unit 380. The service ID processing unit 391 also transmits the service ID to the user terminal device 100 that requested the issuance of the service ID via the third communication unit 310. If the service request processing unit 192 issues a password, the service request processing unit 192 transmits the service ID and password to the user terminal device 100 that requested the issuance of the service ID.
[0049] 7 is a diagram showing an example of the processing procedure in the identity verification system 1 when resetting a password for a web service. In the processing of FIG. 7, the user terminal device 100 transmits a password reset request to the service providing device 300 (step S301). Specifically, the service request processing unit 192 generates a password reset request including a service ID. The service request processing unit 192 then transmits the password reset request to the service providing device 300 via the first communication unit 110.
[0050] Upon receiving the password reset request, the service providing device 300 issues a one-time ID (step S302). Specifically, the service ID processing unit 391 generates a one-time ID including a one-time token, identification information of the service providing device 300, and a service ID. The service ID processing unit 391 then temporarily stores the one-time ID in the third storage unit 380. The service ID processing unit 391 also transmits the one-time ID via the third communication unit 310 to the user terminal device 100 that issued the password reset request.
[0051] Upon receiving the one-time ID, the user terminal device 100 transmits the master ID and the received one-time ID to the master ID management device 200 to request identity verification (step S303). Specifically, the master ID request processing unit 191 generates an identity verification request including the received one-time ID and the master ID issued by the master ID management device 200. The master ID request processing unit 191 then transmits the identity verification request to the master ID management device 200 via the first communication unit 110.
[0052] The master ID management device 200 compares the one-time ID received from the user terminal device with the information stored in the second storage unit 280 (step S204). Specifically, the master ID processing unit 292 compares the one-time ID received from the user terminal device with the information stored in the second storage unit 280 (information included in the one-time ID when requesting issuance of a service ID).
[0053] As a result, the master ID processing unit 292 checks whether the service ID and the service providing device 300 for which the password is to be reset match the service ID and the service providing device 300 when the service ID was registered.
[0054] If it is determined that the service ID and service providing device 300 targeted for the password reset do not match the service ID and service providing device 300 at the time of service ID registration, the master ID processing unit 292 transmits a matching result indicating that the identity of the user who has requested the password reset could not be confirmed to the user terminal device 100. In this case, the identity verification system 1 stops the processing of FIG.
[0055] Next, the master ID management device 200 sends a matching data request to the user terminal device 100 (step S305). Specifically, the master ID processing unit 292 generates a matching data request including the one-time ID. The master ID processing unit 292 then transmits the matching data request via the second communication unit 210 to the user terminal device 100 that has requested the identity verification.
[0056] Upon receiving the matching data request, the user terminal device 100 transmits the matching data to the master ID management device 200 (step S306). Specifically, the master ID request processing unit 191 displays a message requesting that a facial image be taken on the display unit 120. When a user who has referred to the message takes a facial image of themselves using the camera 140, the master ID request processing unit 191 generates matching data including facial image data and a one-time ID.
[0057] Then, the master ID request processing unit 191 transmits the matching data to the master ID management device 200 via the first communication unit 110. Alternatively, the master ID request processing unit 191 may also transmit the matching data to the master ID management device 200 when making the identity verification request in step S303.
[0058] Upon receiving the matching data, the master ID management device 200 performs identity verification using the received matching data and transmits the matching result and the one-time ID to the service providing device 300 (step S307). Specifically, the biometric authentication unit 291 performs identity verification by biometric authentication using the biometric information included in the matching data and the biometric information stored in the second storage unit 280 in association with the master ID. The master ID processing unit 292 then transmits the result of the identity verification and the one-time ID to the service providing device 300 identified by the identification information included in the one-time ID.
[0059] Upon receiving the collation result and the one-time ID, the service providing device 300 issues a new password (step S308). Specifically, if the collation result indicates that the user who made the password reset request is the same person, the service ID processing unit 391 generates a new password, associates it with the service ID, and stores it in the third storage unit 380. The service ID processing unit 391 also transmits the new password to the user terminal device 100 that made the password reset request via the third communication unit 310. Alternatively, the service ID processing unit 391 may adopt the new password transmitted from the user terminal device 100, associate it with the service ID, and store it in the third storage unit 380.
[0060] As described above, the biometric authentication unit 291 performs biometric authentication of a user based on the biometric information of the authentication target and the biometric information linked to a master ID, which is identification information for identifying the user. The master ID processing unit 292 notifies the service providing device 300 requesting identity verification of the result of the biometric authentication and the identification information issued by the service providing device 300.
[0061] When a user registers for multiple services separately for each service, the amount of personal information provided at the time of registration can be relatively small, according to master ID management device 200. In particular, when a user registers for a service ID, master ID management device 200 eliminates the need to notify service providing device 300 of the master ID.
[0062] Furthermore, because the master ID management device performs identity verification, there is no need to disclose information such as the user's email address or telephone number to service providing device 300. In this way, with master ID management device 200, there is no need to provide personal information for each service, and in this respect, the user's privacy can be protected.
[0063] Furthermore, the service providing device 300 does not need to manage personal information such as the user's email address, telephone number, or biometric information, which reduces the burden on the service providing device of managing personal information.
[0064] Furthermore, unlike ID federation among ID providers, the master ID management device 200 does not require the ID provider to pass service usage history information to the service providing device 300. In this respect, the service providing device 300 can protect the privacy of users.
[0065] Furthermore, the master ID management device 200 can reduce the possibility of impersonation by using biometric authentication to verify the identity of the user.
[0066] Here, consider a case where information that can identify a user, such as the user's email address, telephone number, or master ID, is provided to the service providing device 300. If the information that can identify a user is misused, the service usage status of the same user can be associated across multiple services, which may result in a violation of the user's privacy.
[0067] In contrast, with the master ID management device 200, when verifying the identity of a user, it is not necessary to provide information that can identify the user to the service providing device 300. In this respect, the master ID management device 200 can protect the privacy of the user.
[0068] Furthermore, the identification information issued by the service providing device 300 requesting identity verification is one-time identification information, which reduces the possibility of spoofing.
[0069] Furthermore, the second storage unit 280 stores, for each service providing device 300 and for each master ID, a service ID, which is identification information used by the service providing device 300 to identify a user. When the second storage unit 280 does not store the service ID of the service providing device 300 requesting identity verification, the master ID processing unit 292 stores the service ID issued by the service providing device 300 requesting identity verification in the second storage unit 280. An example of this case is when a service ID is issued. On the other hand, when the second storage unit 280 stores the user ID of the service providing device 300 requesting identity verification, the master ID processing unit 292 determines whether the service ID issued by the service providing device 300 requesting identity verification matches the user ID stored in the second storage unit 280. An example of this case is when a password is reset.
[0070] Master ID management device 200 can also verify the identity of a user when resetting a password, thereby protecting the user's privacy. Master ID management device 200 also determines whether the service ID used when registering the service ID matches the service ID used when resetting a password, thereby reducing the possibility of spoofing, in which a user other than the one who registered the service ID requests a password reset.
[0071] Second Embodiment Fig. 8 is a diagram showing an example of the configuration of an identity verification device according to at least one embodiment. In the configuration shown in Fig. 8, an identity verification device 610 includes a biometric authentication unit 611 and a master ID management unit 612.
[0072] In this configuration, the biometric authentication unit 611 performs biometric authentication of the user based on the biometric information of the authentication target and the biometric information linked to a master ID, which is identification information that identifies the user. The master ID management unit 612 notifies the device requesting identity verification of the result of the biometric authentication and the identification information issued by the device requesting identity verification. The biometric authentication unit 611 is an example of a biometric authentication means. The master ID management unit 612 is an example of a master ID management means.
[0073] When a user registers for multiple services, the amount of personal information provided at the time of registration can be relatively small, according to the identity verification device 610. In particular, when the user receives a user ID for receiving a service, the identity verification device 610 eliminates the need to notify the device providing the service (the device requesting identity verification) of the master ID.
[0074] Third Embodiment Fig. 9 is a diagram showing an example of the configuration of an identity verification system according to at least one embodiment. In the configuration shown in Fig. 9, an identity verification system 620 includes a user terminal device 621, an identity verification device 622, and a service providing device 625. The identity verification device 622 includes a biometric authentication unit 623 and a master ID management unit 624.
[0075] With this configuration, the biometric authentication unit 623 performs biometric authentication of the user based on the biometric information acquired from the user terminal device 621 and the biometric information linked to a master ID, which is identification information for identifying the user. The master ID management unit 624 notifies the service providing device 625 requesting identity verification of the result of the biometric authentication and the identification information issued by the service providing device 625. The biometric authentication unit 623 is an example of a biometric authentication means. The master ID management unit 624 is an example of a master ID management means.
[0076] When a user registers for multiple services, the amount of personal information provided at the time of registration can be relatively small, according to the identity verification system 620. In particular, when the user receives a user ID for receiving a service, the identity verification system 620 eliminates the need to notify the master ID to the service providing device 625 requesting identity verification.
[0077] <Fourth Embodiment> Fig. 10 is a diagram showing an example of a processing procedure in an identity verification method according to at least one embodiment. The identity verification method shown in Fig. 10 includes performing biometric authentication (step S611) and performing identity verification processing (step S612). In performing biometric authentication (step S611), a computer performs biometric authentication of a user based on biometric information of an authentication target and biometric information linked to a master ID, which is identification information that identifies the user. In performing identity verification processing (step S612), the computer notifies the device requesting identity verification of the results of the biometric authentication and the identification information issued by the device requesting identity verification.
[0078] According to the identity verification method shown in Fig. 10, when a user registers for multiple services, the amount of personal information provided at the time of registration can be relatively small. In particular, according to the identity verification method shown in Fig. 10, when a user is issued a user ID for receiving services, there is no need to notify the device requesting identity verification of the master ID.
[0079] 11 is a schematic block diagram illustrating the configuration of a computer according to at least one embodiment. In the configuration shown in FIG. 11, a computer 700 includes a CPU (Central Processing Unit) 710, a main memory device 720, an auxiliary memory device 730, and an interface 740.
[0080] One or more of the above-described user terminal device 100, master ID management device 200, service providing device 300, identity verification device 610, user terminal device 621, identity verification device 622, and service providing device 625, or a portion thereof, may be implemented in computer 700. In this case, the operation of each of the above-described processing units is stored in the auxiliary storage device 730 in the form of a program. CPU 710 reads the program from the auxiliary storage device 730, loads it into main storage device 720, and executes the above-described processing in accordance with the program. Furthermore, CPU 710 allocates storage areas in main storage device 720 corresponding to each of the above-described storage units in accordance with the program. Communication between each device and other devices is executed by an interface 740 having a communication function and communicating under the control of CPU 710.
[0081] When the user terminal device 100 is implemented in a computer 700, the operations of the first control unit 190 and each of its units are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.
[0082] Furthermore, the CPU 710 allocates a storage area for the first storage unit 180 in the main storage device 720 in accordance with the program. Communication with other devices by the first communication unit 110 is implemented by the interface 740 having a communication function and operating under the control of the CPU 710. Display of images by the display unit 120 is implemented by the interface 740 being equipped with a display device and displaying various images under the control of the CPU 710. Reception of user operations by the operation input unit 130 is implemented by the interface 740 being equipped with an input device and receiving the user operations under the control of the CPU 710. Photography by the camera 140 is implemented by the interface 740 being equipped with a camera and performing photography under the control of the CPU 710.
[0083] When the master ID management device 200 is implemented in a computer 700, the operations of the second control unit 290 and each of its units are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.
[0084] Furthermore, the CPU 710 allocates a storage area for the second storage unit 280 in the main storage device 720 in accordance with the program. Communication with other devices by the second communication unit 210 is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the master ID management device 200 and a user is performed by the interface 740, which has a display device and an input device, displaying various images under the control of the CPU 710 and accepting user operations.
[0085] When the service providing device 300 is implemented in the computer 700, the operations of the third control unit 390 and each of its units are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.
[0086] Furthermore, the CPU 710 allocates a storage area for the third storage unit 380 in the main storage device 720 in accordance with the program. Communication with other devices by the third communication unit 310 is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the service providing device 300 and a user is performed by the interface 740, which has a display device and an input device, displaying various images under the control of the CPU 710 and accepting user operations.
[0087] When the personal identification device 610 is implemented in the computer 700, the operations of the biometric authentication unit 611 and the master ID management unit 612 are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-mentioned processing in accordance with the program.
[0088] Furthermore, the CPU 710, in accordance with the program, reserves a storage area in the main storage device 720 for the personal identification device 610 to perform processing. Communication between the personal identification device 610 and other devices is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the personal identification device 610 and a user is performed by the interface 740, which has a display device and an input device, displaying various images under the control of the CPU 710 and accepting user operations.
[0089] When the user terminal device 621 is implemented in the computer 700, its operation is stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.
[0090] Furthermore, the CPU 710 allocates a storage area in the main memory device 720 for the user terminal device 621 to perform processing in accordance with the program. Communication between the user terminal device 621 and other devices is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the user terminal device 621 and a user is performed by the interface 740, which has a display device and an input device, displaying various images under the control of the CPU 710 and accepting user operations.
[0091] When the personal identification device 622 is implemented in the computer 700, the operations of the biometric authentication unit 623 and the master ID management unit 624 are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-mentioned processing in accordance with the program.
[0092] Furthermore, the CPU 710, in accordance with the program, allocates a storage area in the main storage device 720 for the personal identification device 622 to perform processing. Communication between the personal identification device 622 and other devices is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the personal identification device 622 and a user is performed by the interface 740, which has a display device and an input device, displaying various images under the control of the CPU 710 and accepting user operations.
[0093] When the service providing device 625 is implemented in the computer 700, its operation is stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.
[0094] Furthermore, the CPU 710 allocates a storage area in the main storage device 720 for the service providing device 625 to perform processing in accordance with the program. Communication between the service providing device 625 and other devices is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the service providing device 625 and a user is performed by the interface 740, which has a display device and an input device, displaying various images under the control of the CPU 710 and accepting user operations.
[0095] One or more of the above-described programs may be recorded on nonvolatile recording medium 750. In this case, interface 740 may read the programs from nonvolatile recording medium 750. Then, CPU 710 may directly execute the programs read by interface 740, or may temporarily store the programs in main storage device 720 or auxiliary storage device 730 and then execute them.
[0096] In addition, programs for executing all or part of the processing performed by user terminal device 100, master ID management device 200, service provider device 300, identity verification device 610, user terminal device 621, identity verification device 622, and service provider device 625 may be recorded on a computer-readable recording medium, and the programs recorded on the recording medium may be loaded into a computer system and executed to perform the processing of each unit. Note that the term "computer system" here includes hardware such as an operating system (OS) and peripheral devices. Furthermore, the term "computer-readable recording medium" refers to portable media such as floppy disks, optical magnetic disks, read-only memories (ROMs), and compact disc read-only memories (CD-ROMs), as well as storage devices such as hard disks built into the computer system. The programs may be programs for implementing part of the functions described above, or may be programs that can realize the functions described above in combination with programs already recorded on the computer system.
[0097] Although the embodiments of the present invention have been described above in detail with reference to the drawings, the specific configuration is not limited to these embodiments and includes designs within the scope of the present invention. Furthermore, the above-described embodiments may be combined with other embodiments as appropriate.
[0098] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes.
[0099] (Supplementary Note 1) An identity verification device comprising: a biometric authentication means for performing biometric authentication of a user based on biometric information of an object to be authenticated and biometric information linked to a master ID, which is identification information for identifying the user; and a master ID management means for notifying a device requesting identity verification of the result of the biometric authentication and the identification information issued by the device requesting identity verification.
[0100] (Supplementary Note 2) The personal identification device according to Supplementary Note 1, wherein the identification information issued by the device requesting personal identification is one-time identification information.
[0101] (Supplementary Note 3) An identity verification device as described in Supplementary Note 1 or Supplementary Note 2, comprising a storage means for storing, for each device and for each master ID, a user ID which is identification information by which the device identifies a user, and when the storage means does not store the user ID of the device requesting identity verification, the master ID management means stores the user ID issued by the device requesting identity verification in the storage means, and when the storage means stores the user ID of the device requesting identity verification, determines whether the user ID issued by the device requesting identity verification matches the user ID stored in the storage means.
[0102] (Supplementary Note 4) An identity verification system comprising a user terminal device, an identity verification device, and a service providing device, wherein the identity verification device comprises: a biometric authentication means for performing biometric authentication of the user based on biometric information acquired from the user terminal device and biometric information linked to a master ID which is identification information for identifying the user; and a master ID management means for notifying the service providing device of the result of the biometric authentication and the identification information issued by the service providing device requesting identity verification.
[0103] (Supplementary Note 5) The identity verification system according to Supplementary Note 4, wherein the identification information issued by the service providing device requesting the identity verification is one-time identification information.
[0104] (Supplementary Note 6) The identity verification system described in Supplementary Note 4 or Supplementary Note 5, wherein the identity verification device comprises a storage means for storing, for each service providing device and for each master ID, a service ID which is identification information by which the service providing device identifies a user, and the master ID management means, when the storage means does not store a user ID of the service providing device requesting the identity verification, stores a user ID issued by the service providing device requesting the identity verification in the storage means, and when the storage means stores a user ID of the service providing device requesting the identity verification, determines whether the user ID issued by the service providing device requesting the identity verification matches the user ID stored in the storage means.
[0105] (Supplementary Note 7) A method of identity verification, comprising: a computer performing biometric authentication of a user based on biometric information of the subject to be authenticated and biometric information linked to a master ID, which is identification information for identifying the user; and notifying the device requesting identity verification of the result of the biometric authentication and the identification information issued by the device requesting identity verification.
[0106] (Supplementary Note 8) The identity verification method according to Supplementary Note 7, wherein the identification information issued by the device requesting identity verification is one-time identification information.
[0107] (Supplementary Note 9) The identity verification method according to Supplementary Note 7 or Supplementary Note 8, wherein the computer comprises: a storage means for storing, for each device and for each master ID, a user ID, which is identification information by which the device identifies a user; when the storage means does not store the user ID of the device requesting identity verification, the storage means stores the user ID issued by the device requesting identity verification; and when the storage means stores the user ID of the device requesting identity verification, the storage means determines whether the user ID issued by the device requesting identity verification matches the user ID stored in the storage means.
[0108] (Supplementary Note 10) A recording medium having recorded thereon a program that causes a computer to perform the following: performing biometric authentication of a user based on biometric information of the subject to be authenticated and biometric information linked to a master ID, which is identification information that identifies the user; and notifying a device requesting identity verification of the results of the biometric authentication and the identification information issued by the device requesting identity verification.
[0109] (Supplementary Note 11) The recording medium according to Supplementary Note 10, wherein the identification information issued by the device requesting the identity verification is one-time identification information.
[0110] (Supplementary Note 12) The program causes the computer, which is provided with a storage means for storing, for each device and for each master ID, a user ID that is identification information by which the device identifies a user, to execute the following: when the storage means does not store the user ID of the device requesting identity verification, store the user ID issued by the device requesting identity verification in the storage means; and when the storage means stores the user ID of the device requesting identity verification, determine whether the user ID issued by the device requesting identity verification matches the user ID stored in the storage means.
[0111] The present invention may be applied to an identity verification device, an identity verification system, an identity verification method, and a recording medium.
[0112] 1, 620 Personal identification system 100, 621 User terminal device 110 First communication unit 120 Display unit 130 Operation input unit 140 Camera 180 First memory unit 190 First control unit 191 Master ID request processing unit 192 Service request processing unit 200 Master ID management device 210 Second communication unit 280 Second memory unit 290 Second control unit 291, 611, 623 Biometric authentication unit 292 Master ID processing unit 300, 625 Service providing device 310 Third communication unit 380 Third memory unit 390 Third control unit 391 Service ID processing unit 392 Web service processing unit 610, 622 Personal identification device 612, 624 Master ID management unit
Claims
1. An identity verification device comprising: a biometric authentication means for performing biometric authentication of a user based on biometric information of the subject to be authenticated and biometric information linked to a master ID, which is identification information for identifying the user; and a master ID management means for notifying the device requesting identity verification of the results of the biometric authentication and the identification information issued by the device requesting identity verification.
2. The personal identification device according to claim 1, wherein the identification information issued by the device requesting personal identification is one-time identification information.
3. An identity verification device as described in claim 1 or claim 2, comprising a storage means for storing, for each device and for each master ID, a user ID which is identification information by which the device identifies the user, and wherein the master ID management means, when the storage means does not store the user ID of the device requesting identity verification, stores the user ID issued by the device requesting identity verification in the storage means, and when the storage means stores the user ID of the device requesting identity verification, determines whether the user ID issued by the device requesting identity verification matches the user ID stored in the storage means.
4. An identity verification system comprising a user terminal device, an identity verification device, and a service providing device, wherein the identity verification device comprises: a biometric authentication means for performing biometric authentication of the user based on biometric information acquired from the user terminal device and biometric information linked to a master ID which is identification information for identifying the user; and a master ID management means for notifying the service providing device of the results of the biometric authentication and the identification information issued by the service providing device requesting identity verification.
5. A method of identity verification, comprising: a computer performing biometric authentication of a user based on the biometric information of the subject to authentication and biometric information linked to a master ID, which is identification information that identifies the user; and notifying the device requesting identity verification of the results of the biometric authentication and the identification information issued by the device requesting identity verification.
6. A recording medium having recorded thereon a program that causes a computer to perform the following: performing biometric authentication of a user based on the biometric information of the subject to be authenticated and biometric information linked to a master ID, which is identification information that identifies the user; and notifying the device requesting identity verification of the results of the biometric authentication and the identification information issued by the device requesting identity verification.
Citation Information
Patent Citations
Identification system, identification method, application providing device, identification device, and identification program
WO2020070807A1
Input control device, input system, input control method, and non-transitory computer-readable medium
WO2022059081A1