Server device, system, server device control method, and storage medium
The server device manages biometric authentication by storing user information in service-specific databases, addressing the complexity of service addition/removal and ensuring system availability.
Patent Information
- Application Number
- PCT/JP2024/021962
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-18
- Publication Date
- 2025-12-26
AI Technical Summary
Existing systems face difficulties in managing multiple services using biometric authentication, as adding or removing services becomes complex, and discontinuing a service can affect other services due to the integration of information in a single database.
A server device that acquires biometric information and business information from a token issuance request and stores them in a database specific to each service, allowing for easy addition or removal of services without affecting others.
This approach improves the availability of biometric authentication systems by simplifying the management of services, ensuring seamless operation even when services are discontinued.
Smart Images

Figure JP2024021962_26122025_PF_FP_ABST
Abstract
Description
Server device, system, server device control method and storage medium
[0001] The present invention relates to a server device, a system, a method for controlling a server device, and a storage medium.
[0002] In recent years, services using biometric authentication (face authentication) have begun to be provided.
[0003] For example, Patent Document 1 describes that a system that can provide services easily is provided. The service providing system of Patent Document 1 includes a face image acquisition means, a storage means, a face matching means, and an output means. The face image acquisition means acquires a face image of a target person. The storage means stores an authentication face image of a registrant and information about the registrant. The face matching means matches the face image with the authentication face image. The output means outputs information related to the service. When the face matching means determines that the target person is a registrant, the output means outputs information about the registrant as service-related information.
[0004] Japanese Patent Application Laid-Open No. 2017-224050
[0005] As services using biometric authentication become more widespread, a single server may store the information required to provide multiple services. In this case, if the information for each service is stored in a single database, it becomes difficult to add or remove services.
[0006] In particular, when a service is discontinued, it is necessary to extract information about the service to be discontinued from information about multiple services stored in a single entry. As a result, there is a possibility that services that are not to be discontinued may be affected by an incorrect operation of the database.
[0007] It should be noted that the above problem cannot be solved even if the technology disclosed in Patent Document 1 is applied. Patent Document 1 does not assume the provision of multiple services.
[0008] The main object of the present invention is to provide a server device, a system, a method for controlling a server device, and a storage medium that contribute to improving the availability of a system that provides services using biometric authentication.
[0009] According to a first aspect of the present invention, there is provided a server device comprising: an acquisition means for acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider providing the certain service to provide the certain service; and a control means for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0010] According to a second aspect of the present invention, there is provided a system including a terminal and a server device, wherein the server device is equipped with an acquisition means for acquiring from the terminal a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider providing the certain service to provide the certain service, and a control means for storing the biometric information and business information included in the token issuance request as a token in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0011] According to a third aspect of the present invention, there is provided a method for controlling a server device, comprising: an acquisition step of acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider providing the certain service to provide the certain service; and a control step of storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0012] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a server device to execute an acquisition process for acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider that provides the certain service to provide the certain service, and a control process for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases that correspond to each of a plurality of services.
[0013] According to each aspect of the present invention, a server device, a system, a method for controlling a server device, and a storage medium are provided that contribute to improving the availability of a system that provides services using biometric authentication. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.
[0014] FIG. 1 is a diagram illustrating an overview of an embodiment. FIG. 2 is a flowchart illustrating an operation of an embodiment. FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating an application installed on a terminal according to an embodiment of the present disclosure. FIG. 5 is a diagram illustrating an example of a display of a terminal according to an embodiment of the present disclosure. FIG. 6 is a diagram illustrating an example of a display of a terminal according to an embodiment of the present disclosure. FIG. 7 is a diagram illustrating an example of a display of a terminal according to an embodiment of the present disclosure. FIG. 8 is a diagram illustrating an operation of an information processing system according to an embodiment of the present disclosure. FIG. 9 is a diagram illustrating an example of a display of a terminal according to an embodiment of the present disclosure. FIG. 10 is a diagram illustrating an operation of an information processing system according to an embodiment of the present disclosure. FIG. 11 is a diagram illustrating an example of a processing configuration of a terminal according to an embodiment of the present disclosure. FIG. 12 is a flowchart illustrating an example of an operation of a token control unit according to an embodiment of the present disclosure. FIG. 13 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. FIG. 14 is a diagram illustrating an example of a user management database according to an embodiment of the present disclosure. FIG. 15 is a flowchart illustrating an example of an operation of a token control unit according to an embodiment of the present disclosure. FIGS. 16A and 16B are diagrams illustrating an example of a service management database according to an embodiment of the present disclosure. FIG. 17 is a flowchart showing an example of an operation of an authentication unit according to an embodiment of the present disclosure. FIG. 18 is a diagram showing an example of a processing configuration of an authentication terminal according to an embodiment of the present disclosure. FIG. 19 is a sequence diagram showing an example of an operation of an information processing system according to an embodiment of the present disclosure. FIG. 20 is a sequence diagram showing an example of an operation of an information processing system according to an embodiment of the present disclosure. FIG. 21 is a diagram showing an example of a display of a terminal according to an embodiment of the present disclosure. FIG. 22 is a diagram showing an example of a behavior history management database according to an embodiment of the present disclosure. FIG. 23 is a diagram showing an example of a processing configuration of a server device according to an embodiment of the present disclosure. FIG. 24 is a diagram showing an example of a hardware configuration of a terminal according to an embodiment of the present disclosure. FIG. 25 is a diagram showing an example of a display of a terminal according to a modified example of the present disclosure.
[0015] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0016] A server device 100 according to an embodiment includes an acquisition unit 101 and a control unit 102 (see FIG. 1 ). The acquisition unit 101 acquires, from an external device, a token issuance request including biometric information of a user who wishes to receive a service and business information required by a service provider to provide the service (step S1 in FIG. 2 ). The control unit 102 stores the biometric information and business information included in the token issuance request as a token in a database corresponding to one of a plurality of first databases corresponding to each of a plurality of services (storing the token; step S2).
[0017] The server device 100 stores tokens used by service providers when providing services in a database prepared for each service. When an existing service is discontinued, the server device 100 simply deletes the database corresponding to the service to be discontinued. In other words, the discontinuation of a service does not require complex control of the database. As a result, the availability of a system that provides services using biometric authentication is improved.
[0018] Specific embodiments will be described in more detail below with reference to the drawings.
[0019] First Embodiment The first embodiment will be described in more detail with reference to the drawings.
[0020] An information processing system (authentication system) according to a first embodiment provides various services to users who have been successfully authenticated. In the first embodiment, the configuration and operation of the information processing system will be described using an example of a user using an airport. In addition, in the first embodiment, the information processing system will be described using an example of a case in which biometric information is used to authenticate a user.
[0021] [System Configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. The information processing system shown in Fig. 3 includes a server device 10 and multiple authentication terminals 20-1 to 20-4.
[0022] In the following description, unless there is a particular reason to distinguish between the authentication terminals 20-1 to 20-4, they will simply be referred to as "authentication terminals 20."
[0023] The server device 10 is a server that controls authentication of users who receive services using biometric authentication. The server device 10 is operated by any organization, etc. For example, the server device 10 is operated by an airport company, an airline, a public institution such as a national or local government, or a private company commissioned by an airport company or a public institution, etc.
[0024] The server device 10 may be installed in an airport or in a cloud on a network.
[0025] The authentication terminal 20 is a terminal (touchpoint) that serves as an interface for users who receive services using biometric authentication. Businesses (service providers) that provide users with services using biometric authentication install authentication terminals 20 at various locations inside and outside the airport according to the services they provide. Users receive services using biometric authentication via the authentication terminal 20.
[0026] For example, the authentication terminal 20-1 is a POS (Point of Sale) terminal installed in a shop or the like. For example, an airport company installs the authentication terminal 20-1 (POS terminal) in a shop or the like. For example, the airport company provides a payment service using biometric authentication to its members (hereinafter also referred to as airport members) via the authentication terminal 20-1. For example, the authentication terminal 20-1 executes control related to facial payment, etc.
[0027] The authentication terminal 20-2 is, for example, a reception terminal installed in a lounge or the like. For example, an airport company installs the authentication terminal 20-2 (reception terminal) at the entrance / exit (reception) of the lounge. For example, the airport company permits its members (airport members) to use the lounge free of charge. For example, the authentication terminal 20-2 notifies an employee waiting at the lounge reception whether a user identified by biometric authentication is eligible to use the lounge free of charge.
[0028] The authentication terminal 20-3 is, for example, a boarding gate installed at each boarding gate. For example, an airline installs the authentication terminal 20-3 (boarding gate). If a user identified by biometric authentication does not have the qualifications to board an aircraft, the authentication terminal 20-3 denies the user passage.
[0029] The authentication terminal 20-4 is a ticket gate installed at the ticket gate of a railway line that enters the airport. For example, a railway company installs the authentication terminal 20-4 (ticket gate). If a user identified by biometric authentication is qualified to exit or enter a station, the authentication terminal 20-4 allows the user to pass. In the following explanation, members of a railway company who can purchase tickets online will be referred to as "railway members."
[0030] A user possesses a terminal 30. Various applications are installed on the terminal 30. For example, an airport application used by members of an airport company, an airline application used by members of an airline company, and a railway application used by members of a railway company are installed on the terminal 30.
[0031] Users use the airport application to enjoy various services and benefits provided by the airport company. For example, users use the airport application to make reservations at hotels affiliated with the airport company, check flight information, etc. Or, users use the airport application to register credit card information and the like in the airport company's system. Users can then use the registered credit card information to make purchases (e.g., online shopping).
[0032] Furthermore, the user uses the airline application to purchase an airline ticket, perform check-in procedures (mobile check-in), etc. For example, the user uses the airline application to manage boarding passes.
[0033] Furthermore, the user uses the railway application to purchase a ticket, etc. For example, the user uses the railway application to manage tickets.
[0034] Furthermore, the terminal 30 has a function for registering a token required to receive a service from a service provider. Specifically, the terminal 30 requests the server device 10 to issue a token for the user. Details regarding the token will be described later.
[0035] The devices (server device 10, authentication terminal 20, etc.) included in the information processing system shown in Fig. 3 are configured to be able to communicate with each other via a network. For example, the server device 10 and the authentication terminal 20 are connected by wired or wireless communication means and are configured to be able to communicate with each other.
[0036] 3 is an example and is not intended to limit the configuration of the information providing system disclosed herein. For example, the information processing system may include multiple server devices 10. The multiple server devices 10 may achieve load balancing and redundancy. Furthermore, the number of authentication terminals 20 included in the information processing system is not limited to four. The information processing system may include at least one authentication terminal 20.
[0037] 3 is merely an example and is not intended to limit the entity that installs the authentication terminal 20 or the purpose of installing the authentication terminal 20. Authentication terminals 20 that are used for purposes other than POS terminals, reception terminals, boarding gates, and ticket gates may be installed inside or outside the airport.
[0038] [Overall Operation of the System] Next, an overall operation of the information processing system will be described.
[0039] <Token Registration> As described above, the terminal 30 has a function related to token registration.
[0040] The token is information required when the server device 10 provides a service using biometric authentication to a user. Specifically, the token is composed of a combination of the user's biometric information and business information, and is stored in the database of the server device 10.
[0041] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In this disclosure, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.
[0042] Business information is information required by service providers (e.g., airport operators, airlines, and railway companies) when providing services to users. Business information varies depending on the service provider and the type of service provided by each service provider. Note that business information does not include biometric information.
[0043] For example, if a facial payment service is provided to an airport member, the airport company's member ID will be the business information. In the following explanation, the airport company's member ID will be referred to as the "airport member ID." Alternatively, if a free lounge access service is provided to an airport member, the airport member ID will also be the business information.
[0044] Alternatively, when a user passes through the authentication terminal 20-3 (boarding gate) and boards an aircraft, the airline member ID and boarding pass information become the business information. In the following explanation, the airline member ID will be referred to as the "airline member ID."
[0045] Alternatively, when a user passes through the authentication terminal 20-4 (ticket gate) to enter a station, the railway company's member ID and ticket information become the transaction information. In the following explanation, the railway company's member ID will be referred to as the "railway member ID."
[0046] Before receiving services using biometric authentication inside or outside the airport, the user must register the token in the system. Specifically, the user uses the terminal 30 they own to request the server device 10 to issue a token.
[0047] <Token Control Application> As described above, various applications are installed on the user's terminal 30. For example, the above-mentioned airport application, airline application, and railway application are installed on the terminal 30.
[0048] Furthermore, the user installs an application for managing and controlling the token (services linked to the token) on the terminal 30. For example, the user downloads the token control application from an application store or the like and installs it on the terminal 30.
[0049] 4, various applications such as a token control application, an airport application, and an airline application are installed on the terminal 30. The applications installed on the terminal 30 are configured to be able to send and receive data to and from each other.
[0050] The token-controlled application can cooperate with other applications, specifically, the token-controlled application can receive data from other applications and send data to other applications.
[0051] <Identity Verification> The token control application installed on the terminal 30 performs identity verification of the user when the application is started for the first time, for example.
[0052] Specifically, the token control application acquires biometric information of the user using a GUI (Graphical User Interface) etc. For example, the token control application photographs the user by taking a selfie and acquires a facial image of the user.
[0053] The token control application then acquires biometric information from the user's identification card, such as a passport, driver's license, or My Number card, by reading a facial image from an IC chip.
[0054] The token control application performs identity verification (one-to-one authentication) using two pieces of biometric information.
[0055] If the identity verification is successful, the token control application stores the user's biometric information (for example, a facial image obtained by photographing or a facial image read from an identification card). If the token control application obtains a facial image from a passport, it may also store the information written on the passport (information about the passport obtained from an IC chip; passport information).
[0056] If the identity verification using an identification document such as a passport is successful, the token control application can request the server device 10 to issue a token.
[0057] <Token Issuance> Here, an application installed on the terminal 30 stores and manages information necessary for executing the application. For example, an airport application manages and stores a user's airport membership ID. Or, an airline application stores and manages a user's airline membership ID, boarding pass information, etc. Similarly, a railroad application stores and manages a user's railroad membership ID, boarding pass information, etc.
[0058] When a user desires to receive a service using biometric authentication, the airline application or the like transmits business information corresponding to the desired service to the token control application.
[0059] For example, if a user wishes to purchase a product at an airport kiosk using facial payment, the airport application sends the airport member ID to the token control application as business information.
[0060] Alternatively, if there are services using biometric authentication that can be offered to the user, the airline application etc. will introduce the available services to the user. If the user wishes to receive the offered service, the airline application etc. will send business information corresponding to the desired service to the token control application.
[0061] For example, a user purchases an airline ticket using an airline application, and then uses the airline application to check in and receive a boarding pass.
[0062] The airline application proposes that users pass through the boarding gate using biometric authentication when they obtain a boarding pass from the airline's system. The airline application guides users to a service (boarding gate face pass service) that allows them to pass through the boarding gate and board an aircraft without presenting a document (medium) such as a boarding pass to airline staff.
[0063] For example, when a user receives a boarding pass (when the user's check-in is completed), the airline application displays a GUI such as that shown in FIG. 5 and suggests to the user that they use the face pass service at the boarding gate.
[0064] When the user accepts the offer (when the "Use" button shown in FIG. 5 is pressed), the airline application sends the airline member ID and boarding pass information to the token control application as business information.
[0065] Alternatively, if a user purchases a ticket with a departure or arrival station connected to an airport, the rail application may suggest that the user pass through a ticket gate at the station using biometric authentication. In this case, the rail application may display a GUI such as that shown in FIG. 6 and suggest the use of the face pass service at the ticket gate to the user.
[0066] If the user accepts the proposal, the railway application sends the railway member ID and ticket information to the token control application as business information.
[0067] When business information is acquired from another application (when a push notification is received from another application), the token control application obtains the user's consent to providing the biometric information and business information to an external party. For example, the token control application obtains the user's consent to providing personal information (biometric information and business information) to a third party using a GUI such as that shown in FIG.
[0068] FIG. 7 is a diagram showing an example of a GUI when the token control application acquires business information from the airline application and the user wishes to receive a face pass service at the boarding gate.
[0069] Once the user's consent to providing the biometric information and business information to a third party is obtained, the token control application sends a "token issuance request" including the user's biometric information, business information, and service ID to the server device 10 (see Figure 8).
[0070] The service ID is an ID for uniquely identifying a service that can be provided by the information processing system. For example, the service ID for the face pass service at the boarding gate is "0001," the service ID for the face pass service at the ticket gate is "0002," and the service ID for the face payment service within the airport is "0003."
[0071] The service ID is shared between the server device 10 and the terminal 30 by any method. For example, a system administrator determines a service ID and sets the determined service ID in the server device 10. The terminal 30 accesses the server device 10 and acquires the service ID when starting the token control application, etc.
[0072] Upon receiving a token issuance request, the server device 10 executes a matching process using the biometric information included in the token issuance request to determine whether or not the user has an account. Specifically, the server device 10 determines whether or not the user's biometric information is registered in a user management database that manages the token issuance status (status of services provided to the user) and the like.
[0073] If the user's account does not exist (if biometric information is not registered), the server device 10 generates an ID to identify the user. In the following description, the ID generated by the server device 10 will be referred to as a "common ID." When the common ID is generated, the server device 10 adds a new entry to the user management database. The server device 10 stores the common ID, biometric information, and information about the services provided to the user in the new entry added.
[0074] Specifically, the server device 10 identifies a service for which a token is to be issued based on the service ID included in the token issuance request, and stores an ID used by the service provider to identify the user in a field (a field in the user management database) corresponding to the identified service.
[0075] For example, if a user requests a face pass service at a boarding gate, the server device 10 stores the airline member ID included in the token issuance request as part of the business information in the user management database. Alternatively, if a user requests a face pass service at a ticket gate, the server device 10 stores the railway member ID in the user management database.
[0076] In the following explanation, the ID used by a service provider (e.g., an airport company, an airline company, or a railway company) to identify a user will be referred to as an “individual ID.” As described above, an airport member ID, an airline member ID, a railway member ID, etc., correspond to an individual ID.
[0077] If an account for the user exists (if biometric information is registered), the server device 10 assigns an individual ID to the account of the user identified by the matching process using the biometric information.
[0078] When information about the service for which a token is to be issued (an individual ID used by the service provider) is registered in the user management database, the server device 10 issues a token. Specifically, the server device 10 stores the user's biometric information and business information in a service management database prepared for each service.
[0079] The user management database and the service management database will be described in detail later.
[0080] The server device 10 notifies the terminal 30 of the processing result for the token issuance request. If the token issuance is successful, the server device 10 transmits a positive response indicating that to the terminal 30. If the token issuance fails, the server device 10 transmits a negative response indicating that to the terminal 30.
[0081] The terminal 30 (token control application) notifies the user of the result of the token issuance request.
[0082] The token control application also presents the token registration status to the user. For example, the token control application displays a screen such as that shown in Fig. 9 upon receiving a positive response from the server device 10. As shown in Fig. 9, the token control unit application may display icons and part of the business information corresponding to services for which tokens have been registered.
[0083] Furthermore, the token control application may display information about services for which tokens have already been registered. In the example of Fig. 9, when a token for a face pass service at a boarding gate is issued, information about the face pass service at a ticket gate for which a token has already been registered is displayed.
[0084] In this way, the terminal 30 acquires business information necessary for the user to receive services using biometric authentication from an application installed on the terminal 30. The terminal 30 then transmits a token issuance request including the acquired business information and the user's biometric information to the server device 10.
[0085] In response to receiving a token issuance request, the server device 10 updates a user management database that manages the token issuance status of each user. That is, the server device 10 manages services provided to users (services for which tokens have already been issued) using individual IDs. The server device 10 also uses a service management database prepared for each service to store and manage tokens (biometric information, business information) required when providing the service.
[0086] <Provision of Service> A user receives a service using biometric authentication via the authentication terminal 20. A user who wishes to receive a service using biometric authentication moves in front of the authentication terminal 20, for example.
[0087] The authentication terminal 20 acquires biometric information of a user (person to be authenticated) in response to an operation (instruction) by an employee of the service provider or the user. Alternatively, the authentication terminal 20 automatically acquires biometric information of a person to be authenticated who is in front of the terminal 20.
[0088] For example, when a user wishes to purchase a product using facial payment, the authentication terminal 20-1 (POS terminal) photographs the user and acquires a facial image in response to an operation by a store clerk or the user (product purchaser). Alternatively, when a user wishes to enter a lounge, the authentication terminal 20-2 (reception terminal) photographs the user and acquires a facial image in response to an operation by a staff member waiting at the lounge reception desk.
[0089] Alternatively, when the authentication terminal 20-3 (boarding gate) or the authentication terminal 20-4 (ticket gate) detects a user in front of the terminal, it photographs the user and obtains a facial image.
[0090] The authentication terminal 20 transmits an "authentication request" including the acquired biometric information and the terminal ID to the server device 10 (see FIG. 10).
[0091] The terminal ID is an ID for identifying the authentication terminal 20. The MAC (Media Access Control) address or IP (Internet Protocol) address of the authentication terminal 20 can be used as the terminal ID.
[0092] The terminal ID is shared by any method between the server device 10 and each authentication terminal 20. For example, a system administrator determines a terminal ID and sets the determined terminal ID in the server device 10. The system administrator also sets the determined terminal ID and information about the authentication terminal 20 (installation location, installation entity of the authentication terminal 20, type of authentication terminal 20, services provided, etc.) in each authentication terminal 20.
[0093] The server device 10, which has received the authentication request, identifies the service (type of service) to be provided to the user based on the terminal ID included in the authentication request. For example, when the server device 10 receives an authentication request from the authentication terminal 20-3 (boarding gate), the server device 10 identifies the service to be provided to the user as the boarding gate face pass service. Alternatively, when the server device 10 receives an authentication request from the authentication terminal 20-4 (ticket gate), the server device 10 identifies the service to be provided to the user as the ticket gate face pass service.
[0094] After identifying the service to be provided to the user, the server device 10 performs biometric authentication using the biometric information included in the authentication request and the biometric information registered in the service management database corresponding to the identified service. The server device 10 then performs a matching process (one-to-N matching, where N is a positive integer; the same applies below) using the biometric information to identify the person to be authenticated.
[0095] The server device 10 transmits the business information (all or part of the business information) of the person to be authenticated identified by the matching process to the authentication terminal 20 .
[0096] For example, when an authentication request is received from the authentication terminal 20-1 (POS terminal) or the authentication terminal 20-2 (reception terminal), the server device 10 notifies the authentication terminal 20-1 of the airport member ID of the airport company.
[0097] Alternatively, when an authentication request is received from authentication terminal 20-3 (boarding gate), server device 10 transmits the airline member ID and boarding pass information to authentication terminal 20-3. Alternatively, when an authentication request is received from authentication terminal 20-4 (ticket gate), server device 10 notifies authentication terminal 20-4 of the railway member ID and boarding pass information.
[0098] The server device 10 transmits a response to the authentication request to the authentication terminal 20 .
[0099] Specifically, if the matching process is successful, the server device 10 transmits an affirmative response to the authentication terminal 20. More specifically, the server device 10 transmits an affirmative response to the authentication terminal 20, the affirmative response including the business information of the person to be authenticated identified by the matching process.
[0100] If the matching process fails, the server device 10 transmits a negative response to the authentication terminal 20 .
[0101] If a negative response is received, the authentication terminal 20 notifies the user, staff, or the like that the authentication has failed.
[0102] If an affirmative response (business information) is received, the authentication terminal 20 provides a service to the user using the business information acquired from the server device 10 .
[0103] For example, the authentication terminal 20-1 (POS terminal) transmits to the airport company's system (not shown) the airport member ID and payment information (product name and purchase amount of the product purchased by the user) obtained from the server device 10. The airport company's system (a system that provides various services to its own members) identifies the product purchaser using the airport member ID, and performs payment processing using the credit card information and payment information of the identified product purchaser.
[0104] Alternatively, the authentication terminal 20-2 (reception terminal) transmits the airport member ID acquired from the server device 10 to the airport company system. The airport company system transmits the member information (e.g., the member's name, etc.) stored in association with the airport member ID to the authentication terminal 20-2. The authentication terminal 20-2 notifies staff or the like that the person to be authenticated is a member of the airport company, along with the acquired member information. The staff then authorizes the person to be authenticated to use the lounge free of charge.
[0105] Alternatively, the authentication terminal 20-3 (boarding gate) uses the boarding pass information acquired from the server device 10 to determine whether the user has the authority to board an aircraft parked beyond the authentication terminal 20-3. When the authentication terminal 20-3 acquires from the server device 10 the boarding pass information corresponding to the aircraft for which it is determining whether or not the user is permitted to board, it opens the gate and allows the user to pass. When the authentication terminal 20-3 cannot acquire from the server device 10 the boarding pass information corresponding to the aircraft for which it is determining whether or not the user is permitted to board, it closes the gate and denies the user passage.
[0106] Alternatively, the authentication terminal 20-4 (ticket gate) uses the ticket information obtained from the server device 10 to determine whether the user has the authority to pass through the ticket gate (authority to enter the station, authority to exit the station).
[0107] In this way, in response to a request from the authentication terminal 20 (in response to receiving an authentication request from the authentication terminal 20), the server device 10 transmits the business information of the person to be authenticated stored in the service management database to the authentication terminal 20.
[0108] <Adding or Discontinuing a Service> A system administrator or the like can instruct the server device 10 to add or discontinue a service. The server device 10 acquires information on a service to be added or discontinued from a predetermined website or the like.
[0109] The server device 10 generates a service management database corresponding to the service to be added, and deletes the service management database corresponding to the service to be discontinued.
[0110] Next, details of each device included in the information processing system according to the first embodiment will be described.
[0111] [Terminal] Examples of the terminal 30 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers), and the like.
[0112] 11 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 30 according to an embodiment of the present disclosure. Referring to FIG. 11, the terminal 30 includes a communication control unit 201, a token control unit 202, and a storage unit 203.
[0113] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0114] The token control unit 202 is a means for controlling token registration. Specifically, the token control unit 202 requests the server device 10 to register a token. The token control unit 202 is a module that realizes the above-mentioned token control application.
[0115] First, the token control unit 202 performs identity verification of the user when the token control application is launched for the first time, etc. Alternatively, the token control unit 202 performs identity verification of the user when detecting a predetermined operation by the user (for example, pressing an identity verification button).
[0116] The token control unit 202 acquires biometric information for identity verification. Specifically, the token control unit 202 acquires a facial image of the user by photographing the user.
[0117] Furthermore, the token control unit 202 acquires biometric information from an identification card held by the user. For example, the token control unit 202 acquires a facial image from an IC chip mounted on an identification card such as a passport, a driver's license, or a My Number card. The token control unit 202 communicates with the IC chip via near field communication (NFC) and acquires the facial image stored in the IC chip.
[0118] Thereafter, the token control unit 202 performs identity verification. Specifically, the token control unit 202 performs identity verification using a facial image obtained by photographing the user and a facial image read from the IC chip of the identification card. The token control unit 202 performs identity verification by determining whether the two sets of biometric information substantially match.
[0119] Specifically, the token control unit 202 generates feature amounts from each of the face image acquired by photography and the face image acquired from the identification card.
[0120] Since existing technology can be used for the process of generating features, a detailed description thereof will be omitted. For example, the token control unit 202 extracts the eyes, nose, mouth, etc. from a facial image as feature points. Then, the token control unit 202 calculates the positions of each feature point and the distances between each feature point as feature amounts (generating a feature vector consisting of multiple feature amounts).
[0121] Next, the token control unit 202 performs authentication processing (one-to-one authentication) using the two generated feature amounts. Specifically, the token control unit 202 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the token control unit 202 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0122] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the token control unit 202 determines that the identity verification is successful. If the similarity is equal to or less than the predetermined value, the token control unit 202 determines that the identity verification is unsuccessful.
[0123] The token control unit 202 may also perform "liveness authentication" to prove that a user is actually present. Specifically, after successfully authenticating (matching) a face image obtained by photographing with a face image read from an identification card, the token control unit 202 instructs the user to perform a predetermined action and determines whether the user (person to be authenticated) follows the instruction. For example, the token control unit 202 may give an instruction such as "close your right eye" and determine whether the user actually exists based on whether the user follows the instruction.
[0124] If the identity verification fails, the token control unit 202 notifies the user of this fact. The token control unit 202 repeats the identity verification process as necessary.
[0125] If the identity verification is successful, the token control unit 202 stores the user's biometric information (e.g., a facial image) in the storage unit 203. For example, the token control unit 202 stores a facial image obtained by photographing the user or a facial image obtained from a passport.
[0126] If the identity verification is successful, the token control unit 202 becomes able to request the server device 10 to issue a token.
[0127] 12 is a flowchart illustrating an example of the operation of the token control unit 202 according to an embodiment of the present disclosure. The operation of the token control unit 202 after identity verification is completed will be described with reference to FIG.
[0128] The token control unit 202 receives business information from another application (step S101). Specifically, the token control unit 202 acquires the business information through a push notification from the other application.
[0129] For example, the token control unit 202 acquires an airport member ID or the like from an airport application, an airline member ID or the like from an airline application, or a railroad member ID, ticket information, or the like from a railroad application.
[0130] The token control unit 202 acquires the business information using, for example, an inter-application linking technique called Deep Link. Alternatively, the token control unit 202 may acquire the business information using a predetermined API (Application Programming Interface). For example, the token control unit 202 receives the business information from another application using an API defined by the token control application.
[0131] At this time, the token control unit 202 may acquire information about the service that the user wishes to receive (for example, the name of the service and the service ID) along with business information from the airline application or the like.
[0132] When the business information is received, the token control unit 202 obtains the user's consent to the provision of personal information to a third party (step S102).
[0133] The token control unit 202 obtains the user's consent using a GUI that corresponds to the obtained business information, the name of the service desired by the user, etc. For example, the token control unit 202 obtains the user's consent regarding the provision of personal information to a third party using the GUI shown in FIG.
[0134] If consent to the provision of personal information (biometric information and business information) is not obtained (step S103, No branch), the token control unit 202 terminates the process for token registration. In this case, the token control unit 202 may notify the user that the token cannot be registered unless the user provides the personal information to a third party.
[0135] If consent to the provision of personal information is obtained (step S103, Yes branch), the token control unit 202 transmits a token issuance request to the server device 10 (step S104). The token control unit 202 transmits a "token issuance request" including the biometric information, business information, and service ID stored in the storage unit 203 to the server device 10.
[0136] The token control unit 202 receives a response (positive response or negative response) to the token issuance request (step S105).
[0137] The token control unit 202 executes processing in response to the token issuance request (step S106).
[0138] If a positive response (token issuance success) is received, the token control unit 202 notifies the user, for example, that the user can receive the service he or she desires.
[0139] If a negative response (token issuance failure) is received, the token control unit 202 notifies the user that token registration has failed, for example.
[0140] In this way, the token control unit 202 has a function as consent acquisition means that acquires the user's consent to providing the user's personal information (business information and biometric information) to a third party before transmitting a token issuance request to the server device 10. Furthermore, the token control unit 202 has a function as identity verification means that performs identity verification using biometric information acquired from the user and biometric information acquired from an identification card held by the user. After successfully verifying the identity of the user who wishes to register a token, the token control unit 202 transmits a token issuance request to the server device 10.
[0141] The storage unit 203 is a means for storing information necessary for the operation of the terminal 30 .
[0142] Note that detailed descriptions of processing modules for realizing the airport application, airline application, and railway application will be omitted, as details of applications other than the token control application are outside the scope of the present disclosure.
[0143] 13 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to an embodiment of the present disclosure. Referring to FIG. 13, the server device 10 includes a communication control unit 301, a token control unit 302, an authentication unit 303, a database management unit 304, and a storage unit 305.
[0144] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the authentication terminal 20. The communication control unit 301 also transmits data to the authentication terminal 20. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0145] The token control unit 302 is a unit that controls the issuance of tokens. The token control unit 302 processes a token issuance request received from the terminal 30.
[0146] Here, the biometric information of the user and the token issuance status are managed and stored using a user management database (see FIG. 14). As shown in FIG. 14, the user management database stores the biometric information of the user (e.g., features generated from a facial image) and the token issuance status for the user. In FIG. 14, a service for which an individual ID (e.g., airport member ID, airline member ID, or railway member ID) is set in the service field corresponds to a service for which a token has been issued.
[0147] Note that the user management database shown in Figure 14 is an example and is not intended to limit the items stored therein. Also, since the user management database stores a user's individual ID for each service, the same individual ID may be stored multiple times in the entry for the same user. For example, if an airport company provides service A and service B and the same user receives these two services, the same individual ID is set in the service fields for service A and service B.
[0148] 15 is a flowchart showing an example of the operation of the token control unit 302 according to an embodiment of the present disclosure. The operation of the token control unit 302 will be described with reference to FIG.
[0149] Upon receiving a token issuance request, the token control unit 302 determines whether the user who wishes to register a token has an account. Specifically, the token control unit 302 executes a matching process (one-to-N matching; N is a positive integer, the same applies hereinafter) using the biometric information included in the token issuance request and the biometric information stored in the user management database (step S201).
[0150] The token control unit 302 generates features from the facial image included in the token issuance request. The token control unit 302 sets the generated features (feature vector) as features on the matching side, and sets the features registered in the user management database as features on the registration side.
[0151] The token control unit 302 calculates the similarity between the feature on the matching side and each of the multiple feature on the registration side. If there is a feature among the multiple feature registered in the user management database whose similarity with the feature to be matched is equal to or greater than a predetermined value, the token control unit 302 determines that the matching process has been successful. If there is no such feature, the token control unit 302 determines that the matching process has failed.
[0152] If the matching process fails (step S202, No branch), the token control unit 302 adds a new entry to the user management database (step S203).
[0153] Thereafter, the token control unit 302 generates an ID (common ID) for identifying the user. The common ID may be any information that can uniquely identify the user. For example, the token control unit 302 may assign a unique value each time an entry is added as the common ID.
[0154] The token control unit 302 stores the common ID, the biometric information (feature amount), and information about the service provided to the user (information about the service for which the token is issued) in the added entry (step S204).
[0155] With regard to the information about the service, the token control unit 302 stores the individual ID included in the token issuance request in a service field corresponding to the service ID included in the request, among multiple service fields included in the user management database.
[0156] If the matching process is successful (step S202, Yes branch), the token control unit 302 stores the individual ID included in the token issuance request in the entry identified by the matching process (the entry storing the biometric information with the highest similarity) (step S205).
[0157] Once information about the service for which a token is to be issued is stored in the user management database (when index information about the service is created), the token control unit 302 issues a token (step S206).
[0158] Specifically, the token control unit 302 stores the user's biometric information and business information in a service management database prepared for each service (see FIGS. 16A and 16B). Note that FIG. 16A is a database related to the face pass service at the boarding gate. Also, FIG. 16B is a database related to the face pass service at the ticket gate. The service management databases shown in FIGS. 16A and 16B are examples and are not intended to limit the items to be stored.
[0159] After storing the business information in the service management database, the token control unit 302 notifies the sender of the token issuance request (terminal 30) of the success of the token issuance (step S207). Specifically, the token control unit 302 sends an affirmative response indicating the success of the token issuance to the sender of the token issuance request.
[0160] In addition, if the issuance of the token fails for reasons such as the image quality of the facial image included in the token issuance request being low, the token control unit 302 sends a negative response indicating failure to issue the token to the sender of the token issuance request.
[0161] The token control unit 302 also has a function of deleting business information stored in the service management database as necessary. The token control unit 302 accesses the service management database periodically or at a predetermined timing. The token control unit 302 deletes entries that have been registered for a predetermined time (e.g., 24 hours).
[0162] In this way, the token control unit 302 has a function as an acquisition unit and a function as a control unit.
[0163] The acquisition means acquires from an external device (e.g., terminal 30) a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by the service provider providing the certain service to provide the certain service.
[0164] The control means stores the biometric information and business information included in the token issuance request as a token in a database corresponding to one of a plurality of first databases (service management databases) corresponding to each of a plurality of services. After storing the token in the database corresponding to the one service, the control means notifies the external device that the token issuance was successful.
[0165] Furthermore, in response to receiving a token issuance request, the control means stores in a second database the biometric information of the user who wishes to receive the one service and an individual ID for identifying the one user by a service provider who provides the one service, in association with each other. The second database is a database that stores the token issuance status of each user, and corresponds to a user management database.
[0166] The authentication unit 303 is a means for authenticating a user (person to be authenticated) who wishes to receive a service via the authentication terminal 20. The authentication unit 303 processes authentication requests received from each authentication terminal 20 (touch point) installed inside and outside the airport.
[0167] The authentication unit 303 receives an authentication request including the biometric information and terminal ID of the person to be authenticated from the authentication terminal 20. The authentication unit 303 identifies the service that the person to be authenticated wishes to receive based on the terminal ID. The authentication unit 303 identifies the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and the biometric information stored in a service management database corresponding to the identified service among multiple service management databases. The authentication unit 303 transmits to the authentication terminal 20 the business information of the identified person to be authenticated, which is stored in the service management database corresponding to the identified service.
[0168] 17 is a flowchart showing an example of the operation of the authentication unit 303 according to an embodiment of the present disclosure. The operation of the authentication unit 303 will be described with reference to FIG.
[0169] The authentication request includes the biometric information of the person to be authenticated and the terminal ID.
[0170] The authentication unit 303 identifies the service that the user is trying to receive based on the terminal ID included in the authentication request (step S301).
[0171] For example, if the terminal ID indicates the authentication terminal 20-3 (boarding gate), the authentication unit 303 identifies the boarding gate face pass service as the service the user is attempting to receive. Alternatively, if the terminal ID indicates the authentication terminal 20-4 (ticket gate), the authentication unit 303 identifies the ticket gate face pass service as the service the user is attempting to receive.
[0172] Once the service is identified, the authentication unit 303 performs a matching process (one-to-N matching; N is a positive integer, the same applies below) using the biometric information included in the authentication request and the biometric information stored in the service management database corresponding to the identified service (step S302).
[0173] The matching process by the authentication unit 303 can be the same as the matching process by the token control unit 302, so a detailed description thereof will be omitted.
[0174] If the matching process fails (step S303, No branch), the authentication unit 303 transmits a negative response indicating that authentication of the authenticatee has failed to the authentication terminal 20 (step S304).
[0175] If the matching process is successful (step S303, Yes branch), the authentication unit 303 acquires the business information of the entry identified by the matching process from the service management database (step S305).
[0176] Thereafter, the authentication unit 303 transmits an affirmative response indicating that the authentication of the person to be authenticated has been successful to the authentication terminal 20 (step S306). At this time, the authentication unit 303 transmits an affirmative response including the business information read from the service management database to the authentication terminal 20.
[0177] The database management unit 304 is a means for controlling and managing the databases in the server device 10. In particular, the database management unit 304 manages the service management database.
[0178] When a system administrator or the like accesses the server device 10, the database management unit 304 provides an interface for adding or abolishing services on a predetermined website or the like.
[0179] For example, when a system administrator wishes to add a service, the database management unit 304 displays a GUI for inputting the service ID of the service to be added to the computer used by the system administrator, items of business information to be stored in the service management database, etc.
[0180] When information about the service to be added (service ID, business information items to be stored in the service management database) is acquired, the database management unit 304 generates a service management database according to the acquired information.
[0181] Alternatively, when the system administrator wishes to discontinue a service, the database management unit 304 displays a GUI on the computer used by the system administrator, etc., for inputting the service ID, etc., of the service to be discontinued.
[0182] When the service ID of the service to be discontinued is acquired, the database management unit 304 deletes the service management database corresponding to the acquired service ID. In this way, the database management unit 304 acquires information about the service to be discontinued and deletes the service management database corresponding to the service to be discontinued from among the multiple service management databases.
[0183] The storage unit 305 stores various information necessary for the operation of the server device 10. In the storage unit 305, a user management database and a plurality of service management databases are constructed.
[0184] 18 is a diagram showing an example of a processing configuration (processing module) of the authentication terminal 20 according to an embodiment of the present disclosure. Referring to Fig. 18, the authentication terminal 20 includes a communication control unit 401, a biometric information acquisition unit 402, an authentication request unit 403, a function realization unit 404, and a storage unit 405.
[0185] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the server device 10. The communication control unit 401 also transmits data to the server device 10. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0186] The biometric information acquisition unit 402 is a means for controlling a camera (not shown) and acquiring biometric information of a user. For example, the biometric information acquisition unit 402 takes an image of a user in front of the device in response to an operation by a store staff member or the like. Alternatively, the biometric information acquisition unit 402 takes an image of the area in front of the device periodically or at a predetermined timing. The biometric information acquisition unit 402 determines whether the acquired image includes a human face image, and if a face image is included, extracts the face image from the acquired image data.
[0187] Note that since existing technologies can be used for the facial image detection process and facial image extraction process by the biometric information acquisition unit 402, detailed description thereof will be omitted. For example, the biometric information acquisition unit 402 may extract a facial image (face region) from image data using a learning model trained by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 402 may extract a facial image using a technique such as template matching.
[0188] The biometric information acquisition unit 402 passes the extracted face image to the authentication request unit 403 .
[0189] The authentication request unit 403 is a means for requesting authentication of the user in front of the server device 10. The authentication request unit 403 generates an authentication request including the acquired face image and terminal ID, and transmits it to the server device 10.
[0190] The authentication request unit 403 receives a response (positive response, negative response) to the authentication request from the server device 10. The authentication request unit 403 passes the received response to the function implementation unit 404.
[0191] The function realization unit 404 is a means for realizing the functions assigned to each authentication terminal 20. A detailed description of the operation of the function realization unit 404 of each authentication terminal 20 will be omitted because the operation of each authentication terminal 20 differs from the gist of the present disclosure.
[0192] The storage unit 405 is a means for storing information necessary for the operation of the authentication terminal 20 .
[0193] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described. Fig. 19 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. With reference to Fig. 19, the operation of the information processing system when a token issuance request is transmitted from the terminal 30 will be described.
[0194] The terminal 30 acquires business information from an application installed on the terminal 30, and transmits a token issuance request including the acquired business information, etc. to the server device 10 (step S01).
[0195] In response to receiving the token issuance request, the server device 10 issues a token (step S02).
[0196] The server device 10 transmits the result of the token issuance process (token issuance success, token issuance failure) to the terminal 30 (step S03).
[0197] The terminal 30 executes processing according to the received result (token issuance success, token issuance failure) (step S04).
[0198] 20 is a sequence diagram illustrating an example of the operation of the information processing system according to the embodiment of the present disclosure, The operation of the information processing system when performing authentication processing will be described with reference to FIG.
[0199] The authentication terminal 20 acquires biometric information of the user and transmits an authentication request including the acquired biometric information to the server device 10 (step S11).
[0200] The server device 10 executes authentication processing using the biometric information included in the authentication request and the biometric information included in the service management database (step S12).
[0201] The server device 10 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 20 (step S13).
[0202] The authentication terminal 20 executes a process according to the received authentication result (authentication success, authentication failure) (step S14).
[0203] Next, a modification of the first embodiment will be described.
[0204] <Modification 1> In the first embodiment, a service management database is prepared for each service. However, a service management database may be prepared for each service and each service providing location.
[0205] For example, if a boarding gate face pass service is provided at airport A and airport B, the server device 10 may have a database for the boarding gate face pass service provided at airport A and a database for the boarding gate face pass service provided at airport B.
[0206] In this case, it is sufficient that a service ID is assigned to the service providing location and the service. In the above example, different values are set for the service ID of the boarding gate face pass service provided at airport A and the service ID of the boarding gate face pass service provided at airport B.
[0207] <Modification 2> In the above embodiment, the case where the biometric information of the user is registered in the user management database and the service management database has been described. However, the biometric information does not have to be stored in the service management database.
[0208] In this case, the authentication unit 303 executes a matching process using the biometric information included in the authentication request and the biometric information stored in the user management database. The authentication unit 303 acquires an individual ID of a service corresponding to the service identified by the terminal ID from among at least one individual ID set in the entry identified by the matching process.
[0209] The authentication unit 303 searches the service management database using the acquired individual ID as a key to identify a corresponding entry. The authentication unit 303 reads out business information from the identified entry and transmits the read business information to the authentication terminal 20.
[0210] <Modification 3> The server device 10 may store attribute information (for example, gender, age, approximate address, etc.) of each user in the user management database.
[0211] In this case, when the terminal 30 performs identity verification using an identification card, it acquires the attribute information from the identification card. The terminal 30 transmits a token issuance request including the acquired attribute information to the server device 10. For example, the terminal 30 transmits a token issuance request including attribute information such as gender = male, age = 30s, and address = Tokyo to the server device 10.
[0212] The server device 10 may store the received attribute information in the user management database together with the common ID, biometric information, etc. Alternatively, the server device 10 may store the user's attribute information using a database different from the user management database and the service management database. For example, the server device 10 may be provided with an attribute management database that manages the user's common ID and attribute information in association with each other.
[0213] <Modification 4> In the above embodiment, a case has been described in which a token issuance request is made from the terminal 30 possessed by the user. However, the token issuance request may be made from an apparatus or device other than the terminal 30.
[0214] For example, a token issuance request may be transmitted from a kiosk terminal installed in an airport, a train station, a hotel, etc. In this case, the kiosk terminal performs identity verification of the user, and if the identity verification is successful, acquires the service the user wishes to enjoy and business information necessary for providing the service. The kiosk terminal transmits a token issuance request including the user's biometric information, business information, and service ID to the server device 10.
[0215] Furthermore, the server device 10 may change the way it handles a token issued in response to a request from the terminal 30 and a token issued in response to a request from a kiosk terminal. For example, the server device 10 may handle a token issuance request received from the terminal 30 as a request to issue a temporary token. Specifically, the token control unit 302 sets the token issued in response to a request from the terminal 30 as a "temporary token" and stores it in the service management database.
[0216] The temporary token is validated when the user is authenticated at a kiosk terminal installed at an airport, etc. Specifically, when the user arrives at the airport, he or she goes in front of the kiosk terminal. The kiosk terminal acquires the user's biometric information and transmits it to the server device 10.
[0217] The server device 10 executes a matching process using the acquired biometric information and the biometric information stored in the user management database to identify the user. The server device 10 uses the individual ID of the identified user as a key to search the service management database corresponding to the service for which the token has been issued to the user.
[0218] If the entry identified by the search is a "temporary token," the server device 10 sets the temporary token as a normal token (real token).
[0219] For example, a user operates the terminal 30 at home to issue a temporary token for the face pass service at the boarding gate. When the user arrives at the airport, he or she moves to the kiosk terminal. When the user stands in front of the kiosk terminal, the temporary token for the face pass service at the boarding gate is validated.
[0220] As described above, the server device 10 according to the first embodiment includes a first database for each service that manages tokens required to provide a service, and a second database that manages the status of tokens issued to users (services that users can enjoy). Managing tokens using the service management database facilitates the addition or discontinuation of services provided to users in the information processing system. For example, when a new service is added, a service ID and service management database corresponding to the new service are simply set in the server device 10. Alternatively, when an existing service is discontinued, the service management database corresponding to the discontinued service is simply deleted from the server device 10. For example, consider a case where tokens related to multiple services are stored in a single database and a specific service is discontinued. In this case, information (fields, entries) for the discontinued service must be deleted from the single database, which may result in the erroneous deletion of information for other services. In contrast, the server device 10 according to the first embodiment has an independent service management database for each service, preventing the addition or discontinuation of a service from affecting other services. As a result, the availability of the information processing system is improved.
[0221] The server device 10 also uses a user management database to manage the biometric information and token issuance status of each user. By using the user management database, the server device 10 can quickly determine whether or not the user has an account when receiving a token issuance request.
[0222] Furthermore, the terminal 30 acquires business information necessary for receiving services using biometric authentication from an application installed on the terminal 30 itself (e.g., a smartphone). The terminal 30 transmits the acquired business information and the user's biometric information to the server device 10 and requests token registration. The information processing system according to the first embodiment registers business information stored in a distributed manner on the terminals 30 owned by individuals into the system (server device 10) via a token control application. Therefore, there is no need to transmit business information centrally managed by the service provider's system to the server device 10. As a result, system registration of information necessary for providing services using biometric authentication can be easily realized.
[0223] When a service provider provides various services using biometric authentication to users, a problem arises as to how to register business information (e.g., membership information) corresponding to each service into the system. To address this problem, in the information processing system according to the first embodiment, a token control application collects business information stored in a distributed manner across terminals 30 and registers the collected business information in the server device 10. By adopting such a configuration, the information processing system can easily launch new services using biometric authentication. In recent years, users have become increasingly aware of personal information, leading to a trend toward registering necessary information on smartphones and other devices. This trend is expected to continue. By acquiring business information necessary for services using biometric authentication from terminals 30 such as smartphones, it becomes possible to register the information necessary for biometric authentication into the system without implementing extensive system integration or the like.
[0224] Furthermore, the server device 10 according to the first embodiment stores information of each service provider (e.g., information such as a member ID) in a linked manner via a common user ID. That is, the member information (member ID) of each service provider is in a "loosely coupled" state, independent of but connected to each system. The server device 10 stores such member information (member ID) in a loosely coupled state, making it possible to easily manage the status of token issuance for each user.
[0225] Second Embodiment Next, a second embodiment will be described in detail with reference to the drawings.
[0226] In the first embodiment, a case where an application installed on a terminal 30 notifies (push-notifies) a token control application of business information is described. In the second embodiment, a case where a token control application requests another application to provide business information is described.
[0227] The configuration of the information processing system according to the second embodiment can be the same as that of the first embodiment, and therefore the description corresponding to Fig. 3 will be omitted. Also, the processing configuration of the server device 10 according to the second embodiment can be the same as that of the first embodiment, and therefore the description thereof will be omitted.
[0228] The following description will focus on the differences between the first and second embodiments.
[0229] The terminal 30 displays a list of services that can be provided to the user, and acquires the service that the user wishes to receive from the displayed list of services. The terminal 30 acquires business information necessary for providing the acquired service (the service selected by the user) from among the applications installed on the terminal 30.
[0230] Specifically, when a user performs a predetermined action, the token control unit 202 of the terminal 30 displays a list of services (services using biometric information) that can be provided to the user using business information obtained from an application installed on the device.
[0231] At this time, the token control unit 202 acquires information about the applications installed on the terminal 30. For example, the token control unit 202 acquires information such as the names and versions of the applications installed on the terminal 30 from the OS (Operating System).
[0232] Next, the token control unit 202 refers to table information that stores business information obtained from applications installed on the terminal 30 in association with services that can be provided to users. The token control unit 202 refers to the table information and generates a list of services that can be provided to users using business information obtained from other applications.
[0233] The token control unit 202 uses the generated list of services to display a GUI such as that shown in Fig. 21. The token control unit 202 uses the GUI to acquire information about the services that the user wishes to receive.
[0234] The token control unit 202 requests the provision of business information from an application that stores business information required for a service desired by the user. The token control unit 202 acquires the required business information from another application using Deep Link, an API, or the like.
[0235] After acquiring the business information, the token control unit 202 acquires the user's consent to the provision of personal information (biometric information and business information) to a third party. The token control unit 202 acquires the user's consent using a GUI similar to that shown in FIG. 7.
[0236] Once the user's consent is obtained, the token control unit 202 sends a token issuance request including the biometric information, business information, and service ID to the server device 10.
[0237] As described above, the terminal 30 according to the second embodiment presents a list of services that can be provided to the user based on business information that can be collected from applications installed on the terminal 30. The terminal 30 acquires business information corresponding to the service selected by the user from the application and transmits the acquired business information to the server device 10. In the second embodiment as well, system registration of information necessary for providing services using biometric authentication can be easily realized.
[0238] Third Embodiment Next, a third embodiment will be described in detail with reference to the drawings.
[0239] In the third embodiment, a case will be described in which the server device 10 provides the behavior history of the user to a service provider or the like.
[0240] The configuration of the information processing system according to the third embodiment can be the same as that of the first and second embodiments, and therefore a description corresponding to FIG. 3 will be omitted.
[0241] The following description will focus on the differences between the first to third embodiments.
[0242] The authentication unit 303 according to the third embodiment stores details of the authentication process executed in response to the reception of the authentication request in the behavior history management database. The authentication unit 303 generates a behavior history of the user by storing the details of the authentication process.
[0243] For example, the authentication unit 303 stores the date and time when the biometric authentication was successful, information about the authentication terminal 20 used by the person to be authenticated (for example, the installation location and type) in the behavior history management database (see Fig. 22). As shown in Fig. 22, the behavior history management database stores the user's common ID, individual ID, and behavior history in association with each other.
[0244] If the authentication unit 303 can acquire accompanying information such as payment information in addition to the biometric information from the authentication terminal 20, the authentication unit 303 may also store the accompanying information in the behavior history management database.
[0245] If the authentication unit 303 succeeds in authenticating the person to be authenticated, it searches the behavior history management database using the ID of the person to be authenticated stored in the service management database as a key. If the search is successful, the authentication unit 303 stores the behavior history in the entry identified by the search.
[0246] If the search fails, the authentication unit 303 adds a new entry to the behavior history management database. The authentication unit 303 stores the user's common ID and individual ID (e.g., airport member ID, airline member ID, railway member ID) in the added entry. Furthermore, the authentication unit 303 stores the user's behavior history in the added entry.
[0247] The authentication unit 303 generates a behavior history as shown in the behavior history management database of Fig. 22. Note that the behavior history management database shown in Fig. 22 is an example and is not intended to limit the items to be stored.
[0248] 23 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure. Referring to FIG. 23, an information provision control unit 306 is added to the configuration of the server device 10 according to the first embodiment.
[0249] The information provision control unit 306 is a means for providing information about user behavior based on requests from service providers participating in the system, etc. The information provision control unit 306 generates information to be provided using the behavior history stored in the behavior history management database, and outputs the generated information to be provided.
[0250] The information provision control unit 306 acquires a request for information provision from a service provider. For example, the information provision control unit 306 acquires a request for information provision from a service provider using a portal site or the like that can be accessed by a person in charge of the service provider.
[0251] The information provision control unit 306 acquires the IDs of users whose behavioral histories are to be obtained from the service provider. For example, an airport company inputs the IDs of its members whose behavioral histories are to be obtained (a list of airport member IDs) into a portal site.
[0252] The information provision control unit 306 searches the behavior history management database using the acquired ID (ID list) as a key, and identifies a corresponding entry. The information provision control unit 306 provides the behavior history stored in the behavior history field of the identified entry to the service provider.
[0253] Next, a modified example of the third embodiment will be described.
[0254] <Variation 1> The information provision control unit 306 may provide attribute information of each user together with their behavioral history to a service provider, etc. In this case, the terminal 30 transmits a token issuance request including attribute information obtained from the identification card used for identity verification to the server device 10. The server device 10 stores the acquired attribute information together with the common ID, etc. in the behavioral history management database.
[0255] As described above, when the server device 10 according to the third embodiment successfully authenticates a user, the server device 10 generates a behavioral history of the user using at least information related to the authentication terminal 20. The server device 10 associates the user's ID with the generated behavioral history and stores the association in the behavioral history management database. When the server device 10 acquires a user's ID from a service provider, the server device 10 reads the user's behavioral history corresponding to the acquired ID from the behavioral history management database (third database) and provides the read behavioral history to the service provider. As a result, behavioral histories involving multiple service providers can be easily collected. In other words, by utilizing the information provided by the server device 10 according to the third embodiment, data spanning multiple providers can be analyzed. For example, an airport company and a railway company can perform data analysis from the perspective of MaaS (Mobility as a Service). Note that the multiple providers may or may not cooperate with each other.
[0256] Next, the hardware of each device constituting the information processing system will be described. Fig. 24 is a diagram showing an example of the hardware configuration of the terminal 30.
[0257] The terminal 30 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 24. For example, the terminal 30 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0258] However, the configuration shown in Fig. 24 is not intended to limit the hardware configuration of the terminal 30. The terminal 30 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the terminal 30 is not intended to be limited to the example shown in Fig. 24, and for example, the terminal 30 may include multiple processors 311.
[0259] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0260] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0261] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations, such as a keyboard or a mouse.
[0262] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0263] The functions of the terminal 30 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by a semiconductor chip.
[0264] The server device 10 and the like can also be configured by an information processing device in the same way as the terminal 30, and the basic hardware configuration is no different from that of the terminal 30, so a description thereof will be omitted.
[0265] The terminal 30, which is an information processing device, is equipped with a computer, and the computer executes a program to realize the functions of the terminal 30. The terminal 30 also executes a control method for the terminal 30 by the program.
[0266] [Modification] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0267] In the above embodiment, an airline application or the like proposes (introduces) services to a user. However, the service information may be provided by other means. For example, the service information may be provided using a two-dimensional barcode attached to an airport facility or a railway. In this case, the user operates the terminal 30 to read the two-dimensional barcode attached to the railway or the like. The two-dimensional barcode includes a link to call up a predetermined address of the token control application. The terminal 30 follows the link and displays a screen that allows the user to select a service. For example, the terminal 30 displays a screen such as that shown in FIG. 21 .
[0268] The token control unit 202 (token control application) of the terminal 30 may have a function to suggest token registration to the user. For example, the token control unit 202 may suggest token registration for another service to the user on a screen notifying the user that a token has been issued. For example, if a token is successfully registered, the token control unit 202 may display a GUI such as that shown in FIG. 25 to suggest token registration for a service other than the service for which the token was registered. In FIG. 25, when the button labeled "Favorite Services" is pressed, the token control unit 202 acquires business information from an application corresponding to the service selected by the user. For example, when the "Ticket Gate Face Pass" button is pressed, the token control unit 202 acquires a railway member ID and ticket information from a railway application. Then, the token control unit 202 acquires the user's consent to the provision of personal information to a third party. After obtaining the user's consent, the token control unit 202 sends a token issuance request to the server device 10.
[0269] In the above embodiment, the operation of the information processing system disclosed herein has been described using an authentication system in an airport as an example. However, the information processing system disclosed herein may be used in facilities other than airports. For example, the information processing system may be used in an authentication system in a large station such as a terminal station. Alternatively, the information processing system may be used in an authentication system at an event venue or the like.
[0270] In the above embodiment, the information processing system disclosed herein has been described using an airport where domestic flights take off and land as an example. However, the information processing system disclosed herein may also be used for an airport where international flights take off and land. In this case, the user simply transmits business information, including passport information, stored in the terminal 30 to the server device 10.
[0271] In the above embodiment, an airport application and an airline application have been described as examples of applications other than the token control application. However, it is not intended to limit the applications installed on the terminal 30 to these applications. The token control application can acquire business information from any application installed on the terminal 30.
[0272] In the second embodiment, a list of services that can be provided using business information obtained from an application installed on the terminal 30 is provided to the user (see FIG. 21 ). However, the terminal 30 may generate a list of services (services using biometric authentication) that can be provided to the user as a system and display the list on a GUI. Furthermore, if the user selects a service that uses business information obtainable from an application not installed on the terminal 30, the terminal 30 may prompt the user to install the application that is not installed. For example, if a "boarding gate face pass service" using boarding information obtainable from an airline application is selected and the airline application is not installed on the terminal 30, the terminal 30 prompts the user to install the airline application.
[0273] Alternatively, if the version of the application installed on the terminal 30 is old and appropriate business information cannot be acquired, the terminal 30 may prompt the user to upgrade the application.
[0274] The quality check of the biometric information when the token is issued (when the token is registered) may be performed by the server device 10. The quality check may also be performed by the terminal 30.
[0275] In the third embodiment, the server device 10 manages the behavior history of a user using a behavior history management database. However, the server device 10 may manage the behavior history of a user using a user management database. Alternatively, the server device 10 may update the user management database and reflect the updated contents of the user management database in the behavior history management database when the user management database is updated. For example, when the server device 10 adds an entry to the user management database, the server device 10 also adds the entry to the behavior history management database.
[0276] In the above embodiment, a case has been described in which biometric information related to a facial image is transmitted and received between the server device 10 and the authentication terminal 20. However, features generated from a facial image may also be transmitted and received between the devices. In this case, the receiving server device 10 may use the received features and utilize the received features in subsequent processing. Alternatively, the biometric information stored in a user management database or the like may be features or a facial image. If a facial image is stored, features may be generated from the facial image as needed. Alternatively, both the facial image and features may be stored in a user management database or the like.
[0277] In the above embodiment, the case where the user management database and the service management database are configured inside the server device 10 has been described, but these databases may be configured on an external database server or the like. That is, some functions of the server device 10 or the like may be implemented on another server. More specifically, it is sufficient that the above-described "token control unit (token control means)" or the like is implemented in any of the devices included in the system.
[0278] The form of data transmission and reception between each device (server device 10, terminal 30, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect personal information, it is desirable to transmit and receive encrypted data.
[0279] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0280] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0281] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems that provide users with services using biometric authentication.
[0282] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.
[0283] [Supplementary Note 1] A server device comprising: an acquisition means for acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider who provides the certain service to provide the certain service; and a control means for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0284] [Supplementary Note 2] The server device according to Supplementary Note 1, wherein the control means notifies the external device of successful token issuance when the token is stored in a database corresponding to the one service.
[0285] [Supplementary Note 3] The server device according to Supplementary Note 2, wherein the control means, in response to receiving the token issuance request, stores the biometric information of the user who wishes to receive the one service in a second database that stores the issuance status of the token for each user, in association with an individual ID that a service provider that provides the one service uses to identify the one user.
[0286] [Supplementary Note 4] The server device according to Supplementary Note 3, further comprising a management unit that acquires information about a service to be discontinued, and deletes a database corresponding to the service to be discontinued from among the plurality of first databases.
[0287] [Supplementary Note 5] The server device according to any one of Supplementary Notes 1 to 4, further comprising an authentication means for receiving an authentication request from an authentication terminal, the authentication request including biometric information and a terminal ID of the person to be authenticated; identifying a service that the person to be authenticated wishes to receive based on the terminal ID; identifying the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and biometric information stored in a database corresponding to the identified service among the plurality of first databases; and transmitting business information of the identified person to the authentication terminal, the business information being stored in the database corresponding to the identified service.
[0288] [Appendix 6] The server device described in Appendix 5, wherein the authentication means, when biometric authentication of the person to be authenticated is successful, generates a behavioral history of the person to be authenticated using information about the authentication terminal obtained from at least the terminal ID, and associates the ID of the person to be authenticated with the generated behavioral history and stores it in a third database.
[0289] [Appendix 7] The server device according to Appendix 6, further comprising a providing means for, upon obtaining a user's ID from a business operator wishing to provide the behavioral history, reading out the behavioral history corresponding to the obtained ID from the third database and providing the read behavioral history to the business operator.
[0290] [Supplementary Note 8] A system including a terminal and a server device, wherein the server device comprises: an acquisition means for acquiring from the terminal a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider that provides the certain service to provide the certain service; and a control means for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0291] [Supplementary Note 9] The system according to Supplementary Note 8, wherein the control means notifies the terminal of successful token issuance when the token is stored in a database corresponding to the one service.
[0292] [Supplementary Note 10] The system described in Supplementary Note 9, wherein the control means, in response to receiving the token issuance request, stores the biometric information of the user who wishes to receive the one service in a second database that stores the issuance status of the token for each user, in association with an individual ID used by a service provider that provides the one service to identify the one user.
[0293] [Supplementary Note 11] The system according to Supplementary Note 10, further comprising a management unit that acquires information about a service to be discontinued, and deletes a database corresponding to the service to be discontinued from among the plurality of first databases.
[0294] [Supplementary Note 12] The system described in any one of Supplementary Notes 8 to 11 further comprises an authentication means that receives an authentication request including biometric information and a terminal ID of the person to be authenticated from the authentication terminal, identifies a service that the person to be authenticated wishes to receive based on the terminal ID, identifies the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and biometric information stored in a database corresponding to the identified service among the plurality of first databases, and transmits business information of the identified person to the authentication terminal that is stored in the database corresponding to the identified service.
[0295] [Appendix 13] The system described in Appendix 12, wherein the authentication means, when biometric authentication of the person to be authenticated is successful, generates a behavioral history of the person to be authenticated using information about the authentication terminal obtained from at least the terminal ID, and associates the ID of the person to be authenticated with the generated behavioral history and stores it in a third database.
[0296] [Appendix 14] The system described in Appendix 13 further comprises a providing means that, upon obtaining a user's ID from a business operator that wishes to provide the behavioral history, reads the behavioral history corresponding to the obtained ID from the third database and provides the read behavioral history to the business operator.
[0297] [Supplementary Note 15] A control method for a server device, comprising: an acquisition step of acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider who provides the certain service to provide the certain service; and a control step of storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0298] [Supplementary Note 16] The method for controlling a server device according to Supplementary Note 15, wherein the control step notifies the external device of successful token issuance when the token is stored in a database corresponding to the one service.
[0299] [Supplementary Note 17] The control method for a server device described in Supplementary Note 16, wherein the control step stores, in a second database that stores the issuance status of the token for each user, biometric information of the user who wishes to receive the one service in association with an individual ID that a service provider that provides the one service uses to identify the one user, in response to obtaining the token issuance request.
[0300] [Supplementary Note 18] The server device control method according to Supplementary Note 17, further comprising a management step of acquiring information about a service to be discontinued, and deleting a database corresponding to the service to be discontinued from among the plurality of first databases.
[0301] [Supplementary Note 19] A control method for a server device according to any one of Supplementary Notes 15 to 18, further comprising an authentication step of receiving an authentication request from an authentication terminal, the authentication request including biometric information and a terminal ID of the person to be authenticated; identifying a service that the person to be authenticated wishes to receive based on the terminal ID; identifying the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and biometric information stored in a database corresponding to the identified service among the plurality of first databases; and transmitting business information of the identified person to the authentication terminal, the business information stored in the database corresponding to the identified service.
[0302] [Appendix 20] The control method for a server device described in Appendix 19, wherein the authentication process, when biometric authentication of the person to be authenticated is successful, generates a behavioral history of the person to be authenticated using information about the authentication terminal obtained from at least the terminal ID, and associates the ID of the person to be authenticated with the generated behavioral history and stores them in a third database.
[0303] [Supplementary Note 21] The control method for a server device described in Supplementary Note 20, further comprising a providing step of, when a user's ID is obtained from a business operator wishing to provide the behavioral history, reading the behavioral history corresponding to the obtained ID from the third database and providing the read behavioral history to the business operator.
[0304] [Supplementary Note 22] A computer-readable storage medium storing a program for causing a computer mounted on a server device to execute the following operations: an acquisition process for acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider who provides the certain service to provide the certain service; and a control process for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
[0305] [Supplementary Note 23] The storage medium according to Supplementary Note 22, wherein the control process notifies the external device of successful token issuance when the token is stored in a database corresponding to the one service.
[0306] [Appendix 24] The storage medium according to Appendix 23, wherein the control process stores, in a second database that stores the issuance status of the token for each user, biometric information of the user who wishes to receive the one service in association with an individual ID that a service provider who provides the one service uses to identify the one user, in response to obtaining the token issuance request.
[0307] [Supplementary Note 25] The storage medium according to Supplementary Note 24, further executing a management process of acquiring information about a service to be discontinued, and deleting a database corresponding to the service to be discontinued from among the plurality of first databases.
[0308] [Supplementary Note 26] A storage medium according to any one of Supplementary Notes 22 to 25, further executing an authentication process, which includes receiving an authentication request from an authentication terminal, the authentication request including biometric information and a terminal ID of the person to be authenticated; identifying a service that the person to be authenticated wishes to receive based on the terminal ID; identifying the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and biometric information stored in a database corresponding to the identified service among the plurality of first databases; and transmitting business information of the identified person to the authentication terminal, the business information stored in the database corresponding to the identified service.
[0309] [Appendix 27] The storage medium described in Appendix 26, wherein the authentication process generates a behavioral history of the person to be authenticated using information about the authentication terminal obtained from at least the terminal ID when biometric authentication of the person to be authenticated is successful, and associates the ID of the person to be authenticated with the generated behavioral history and stores it in a third database.
[0310] [Appendix 28] The storage medium described in Appendix 27 further executes a provision process in which, when a user's ID is obtained from a business operator that wishes to provide the behavioral history, the behavioral history corresponding to the obtained ID is read from the third database and the read behavioral history is provided to the business operator.
[0311] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 7 that are dependent on Supplementary Note 1 above may also be dependent on Supplementary Notes 8, 15, and 22 in the same dependent relationship as Supplementary Notes 2 to 7. Furthermore, not limited to Supplementary Notes 1, 8, 15, and 22, some or all of the configurations described as Supplements may be made dependent on various hardware, software, various recording means for recording software, or systems, within the scope of each of the above-mentioned embodiments.
[0312] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.
[0313] 10 Server device 20 Authentication terminal 20-1 Authentication terminal 20-2 Authentication terminal 20-3 Authentication terminal 20-4 Authentication terminal 30 Terminal 100 Server device 101 Acquisition means 102 Control means 201 Communication control unit 202 Token control unit 203 Storage unit 301 Communication control unit 302 Token control unit 303 Authentication unit 304 Database management unit 305 Storage unit 306 Information provision control unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 401 Communication control unit 402 Biometric information acquisition unit 403 Authentication request unit 404 Function realization unit 405 Storage unit
Claims
1. A server device comprising: an acquisition means for acquiring, from an external device, a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider providing said service to provide said service; and a control means for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to said certain service among a plurality of first databases corresponding to each of a plurality of services.
2. The server device according to claim 1, wherein said control means notifies said external device of successful token issuance when said token is stored in a database corresponding to said one service.
3. The server device according to claim 2, wherein the control means, in response to receiving the token issuance request, stores in a second database that stores the issuance status of the token for each user, the biometric information of the user who wishes to receive the one service and an individual ID that is used by the service provider providing the one service to identify the one user, in association with each other.
4. The server device according to claim 3, further comprising a management means for acquiring information about a service to be discontinued and deleting a database corresponding to the service to be discontinued from among said plurality of first databases.
5. A server device according to any one of claims 1 to 4, further comprising an authentication means for receiving an authentication request from an authentication terminal, the authentication request including biometric information and a terminal ID of the person to be authenticated; identifying a service that the person to be authenticated wishes to receive based on the terminal ID; identifying the person to be authenticated by performing a matching process using the biometric information included in the received authentication request and biometric information stored in a database corresponding to the identified service among the plurality of first databases; and transmitting business information of the identified person to the authentication terminal, the business information stored in the database corresponding to the identified service.
6. The server device of claim 5, wherein the authentication means, upon successful biometric authentication of the person to be authenticated, generates a behavioral history of the person to be authenticated using information about the authentication terminal obtained from at least the terminal ID, and associates the ID of the person to be authenticated with the generated behavioral history and stores it in a third database.
7. The server device according to claim 6, further comprising a providing means for, upon obtaining a user's ID from a business operator wishing to provide the behavioral history, reading the behavioral history corresponding to the obtained ID from the third database and providing the read behavioral history to the business operator.
8. A system including a terminal and a server device, wherein the server device is equipped with: an acquisition means for acquiring from the terminal a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider providing the certain service to provide the certain service; and a control means for storing the biometric information and business information included in the token issuance request as a token in a database corresponding to the certain service among a plurality of first databases corresponding to each of a plurality of services.
9. A method for controlling a server device, comprising: an acquisition step of acquiring from an external device a token issuance request including biometric information of a user who wishes to receive a certain service and business information required by a service provider providing said service to provide said service; and a control step of storing the biometric information and business information included in the token issuance request as a token in a database corresponding to said certain service among a plurality of first databases corresponding to each of a plurality of services.
10. A computer-readable storage medium storing a program for causing a computer mounted on a server device to execute the following operations: an acquisition process for acquiring, from an external device, a token issuance request including biometric information of a user wishing to receive a certain service and business information required by a service provider providing said service to provide said service; and a control process for storing, as a token, the biometric information and business information included in the token issuance request in a database corresponding to said certain service among a plurality of first databases corresponding to each of a plurality of services.
Citation Information
Patent Citations
Authentication information management server device, authentication information management system, and authentication information management method
JP2020154750A
Audible Authentication
JP2022509837A
Authentication server, system, authentication server control method, and recording medium
WO2022118639A1
Information processing system, information processing method, and program
WO2023170902A1
Server device, system, server device control method, and storage medium
WO2024122003A1