Terminal, system, terminal control method, and storage medium
By transmitting biometric information with validity certification from a reliable terminal to a server for authentication, the system ensures the legitimacy of the device and integrity of the biometric data, enhancing the reliability of identity verification.
Patent Information
- Application Number
- PCT/JP2024/026541
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-25
- Publication Date
- 2026-01-29
AI Technical Summary
Existing identity verification systems using biometric authentication are unreliable when the device acquiring biometric information is of uncertain legitimacy, leading to potentially fraudulent authentication results.
A terminal and system that acquire biometric information and transmit it along with validity certification information to a server for authentication, ensuring the legitimacy of the device and reliability of the authentication process.
Guarantees the reliability of authentication results by verifying the authenticity of the device and the integrity of the biometric information, preventing fraudulent activities.
Smart Images

Figure JP2024026541_29012026_PF_FP_ABST
Abstract
Description
Terminal, system, terminal control method and storage medium
[0001] The present invention relates to a terminal, a system, a terminal control method, and a storage medium.
[0002] There are identity verification systems that use biometric information.
[0003] For example, Patent Document 1 describes that identity verification is performed via a network while ensuring the reliability of biometric authentication. In the system of Patent Document 1, matching-related data with a double digital signature from the biometric authentication device and the secure medium is sent to an authentication server via a network in response to a matching result obtained by a biometric authentication method.
[0004] Japanese Patent Application Laid-Open No. 2003-143136
[0005] Biometric authentication is based on the premise that the device or equipment that acquires the biometric information of the person to be authenticated is legitimate. In other words, the authentication server or other device cannot perform biometric authentication using biometric information acquired by a device whose manufacturer is uncertain. This is because the results of biometric authentication using unreliable biometric information will also be unreliable.
[0006] A primary object of the present invention is to provide a terminal, a system, a terminal control method, and a storage medium that contribute to ensuring the reliability of authentication results.
[0007] According to a first aspect of the present invention, there is provided a terminal comprising: an acquisition means for acquiring biometric information of a person to be authenticated; and a control means for transmitting to a server device that performs biometric authentication, person to be authenticated information about the person to be authenticated, including the acquired biometric information, and validity certification information for proving the validity of the terminal, thereby requesting the server device to authenticate the person to be authenticated.
[0008] According to a second aspect of the present invention, there is provided a system including a server device and a terminal that perform biometric authentication, wherein the terminal is equipped with an acquisition means that acquires biometric information of a person to be authenticated, and a control means that requests the server device to authenticate the person to be authenticated by transmitting to the server device person-to-be-authenticated information regarding the person to be authenticated, including the acquired biometric information, and validity certification information for proving the validity of the terminal itself.
[0009] According to a third aspect of the present invention, there is provided a method for controlling a terminal, comprising: an acquisition step of acquiring biometric information of a person to be authenticated; and a control step of transmitting, to a server device that performs biometric authentication, person information about the person to be authenticated, including the acquired biometric information, and validity certification information for proving the validity of the terminal, thereby requesting the server device to authenticate the person to be authenticated.
[0010] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a terminal to execute an acquisition process for acquiring biometric information of a person to be authenticated, and a control process for requesting authentication of the person to be authenticated from a server device that performs biometric authentication by transmitting, to the server device, person information about the person to be authenticated, including the acquired biometric information, and validity certification information for proving the validity of the terminal.
[0011] According to each aspect of the present invention, a terminal, a system, a terminal control method, and a storage medium are provided that contribute to ensuring the reliability of authentication results. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.
[0012] FIG. 1 is a diagram illustrating an overview of an embodiment. FIG. 2 is a flowchart illustrating an operation of an embodiment. FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating an authentication terminal according to an embodiment of the present disclosure. FIG. 5 is a diagram illustrating an operation of the information processing system according to an embodiment of the present disclosure. FIG. 6 is a diagram illustrating an operation of the information processing system according to an embodiment of the present disclosure. FIG. 7 is a diagram illustrating an example of a processing configuration of an authentication terminal according to an embodiment of the present disclosure. FIG. 8 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. FIG. 9 is a flowchart illustrating an example of an operation of a pre-screening control unit according to an embodiment of the present disclosure. FIG. 10 is a diagram illustrating an example of a user management database according to an embodiment of the present disclosure. FIG. 11 is a diagram illustrating an example of a processing configuration of an authentication terminal according to an embodiment of the present disclosure. FIG. 12 is a sequence diagram illustrating an example of an operation of an information processing system according to an embodiment of the present disclosure. FIG. 13 is a diagram illustrating an example of a hardware configuration of an authentication terminal according to an embodiment of the present disclosure.
[0013] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0014] The terminal 100 according to one embodiment includes an acquisition unit 101 and a control unit 102 (see FIG. 1). The acquisition unit 101 acquires biometric information of the person to be authenticated (step S1 in FIG. 2). The control unit 102 transmits, to a server device that performs biometric authentication, user information about the person to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the terminal, thereby requesting the server device to authenticate the person to be authenticated (step S2).
[0015] The terminal 100 transmits not only the biometric information of the person to be authenticated but also validity proof information attesting to the validity of the terminal itself to the server device. The server device can verify the validity of the terminal 100 that acquired the biometric information using the validity proof information. The server device performs authentication processing using biometric information acquired by the correct terminal 100, thereby ensuring the reliability of the authentication result output by the server device. That is, in biometric authentication, it is important that the biometric information received by the server device is certainly the biometric information of the person in question and that the biometric information has not been tampered with. Therefore, biometric authentication requires the use of a device or apparatus that leaves no room for fraud, such as a so-called injection attack. The server device verifies the applications, etc., used on the terminal 100 using the validity information transmitted from the terminal 100, thereby confirming that the device leaves no room for such fraud.
[0016] Specific embodiments will be described in more detail below with reference to the drawings.
[0017] First Embodiment The first embodiment will be described in more detail with reference to the drawings.
[0018] [System Configuration] Fig. 3 is a diagram showing an example of a schematic configuration of an information processing system (authentication system) according to an embodiment of the present disclosure. The information processing system shown in Fig. 3 includes a server device 10, an authentication terminal 20-1, and an authentication terminal 20-2.
[0019] An information processing system according to a first embodiment provides an authentication service using biometric information. In the first embodiment, the configuration, operation, etc. of the information processing system will be described using an example of immigration inspection that is conducted in advance of entry into a second country for a user who plans to depart a first country from a port in the first country on a ship 30 and enter a second country from a port in a second country different from the first country. The information processing system according to the first embodiment conducts immigration inspection in advance for a user who plans to enter the second country before the user arrives in the second country.
[0020] The information processing system is operated, for example, by an agency of the second country, such as an immigration control bureau that manages immigration to the second country, or by a contractor entrusted with the work by that agency. Foreigners enter the second country from the first foreign country for various purposes, such as tourism and business. In the second country, nationals and foreign residents depart for the first foreign country for various purposes, such as tourism, business, or temporary return to their home country, and then the nationals and foreign residents who depart for the first country return and enter the country. Note that a foreigner is someone who does not have the nationality of the second country. The information processing system conducts immigration inspections in advance for users such as these who enter the second country.
[0021] For example, the information processing system is operated by an institution such as the Immigration Bureau of Japan, which is the second country, and remotely performs immigration inspections on users entering Japan from a first country, which is a foreign country such as the United States. The first country may be a specific country or may include multiple countries.
[0022] The server device 10 is a server that realizes the main function of the above-mentioned preclearance. The server device 10 is operated by any organization or the like. For example, the server device 10 is operated by a public institution such as a national or local government, or a private company commissioned by a public institution or the like. The server device 10 may be installed in a building of the public institution or the like, or may be installed in a cloud on a network.
[0023] The authentication terminal 20-1 is a terminal used for pre-screening of a user (departing passenger) who is boarding a ship 30 (e.g., a cruise ship) and intends to depart a first country. The authentication terminal 20-1 is a terminal used for pre-screening of a user who is leaving a first country and intends to enter a second country. The authentication terminal 20-1 is installed at the departure port of the first country (e.g., a terminal building at the port). Alternatively, the authentication terminal 20-1 is installed inside the ship 30 (e.g., a lounge).
[0024] The authentication terminal 20-1 is prepared and installed by a shipping company, a shipping agency, etc. The authentication terminal 20-1 is a portable terminal, and is installed at the departure port or inside the ship 30 depending on the on-site situation, etc.
[0025] A user who has passed the preliminary screening and been permitted to enter the second country boards the ship 30. The ship 30 departs from the departure port of the first country and arrives at the arrival port of the second country.
[0026] Staff from a shipping company or shipping agency are on board the ship 30. The staff carry an authentication terminal 20-2. The staff use the authentication terminal 20-2 to perform immigration inspection-related tasks for users (entrants) who disembark the ship 30 and attempt to enter a second country.
[0027] The user possesses a terminal 40. Various applications are installed on the terminal 40. For example, the user makes a reservation for boarding the ship 30 using the applications installed on the terminal 40.
[0028] 3 (server device 10, authentication terminal 20-1, etc.) are configured to be able to communicate with each other via a network. For example, the server device 10 and the authentication terminal 20-1 are connected by wired or wireless communication means and are configured to be able to communicate with each other.
[0029] 3 is an example and is not intended to limit the configuration of the information providing system disclosed herein. For example, the information processing system may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10. Furthermore, the information processing system may include at least one authentication terminal 20-1 and one authentication terminal 20-2.
[0030] [Overview of Operation] Next, the overview of the operation of the information processing system will be described.
[0031] <Preliminary screening before boarding> The authentication terminal 20-1 acquires information (hereinafter referred to as "person to be authenticated") necessary for the server device 10 to perform a preliminary screening of the user (person to be authenticated for the preliminary screening). Specifically, the authentication terminal 20-1 acquires passport information, biometric information (face image, fingerprint image), and a verification image obtained from the passport.
[0032] Passport information is all or part of the information printed on the face of a passport, including the user's facial image (hereinafter referred to as the passport facial image), name, date of birth, address, gender, passport number, etc.
[0033] The verification image is an image that enables verification as to whether or not fraud such as impersonation has occurred when the authentication terminal 20-1 acquires a face image or a fingerprint image.
[0034] The authentication terminal 20-1 acquires the passport information, biometric information, and verification image using devices such as a camera, a scanner, etc. Specifically, as shown in Fig. 4, the authentication terminal 20-1 includes a camera 21 for acquiring a facial image, a scanner 22 for acquiring passport information, a fingerprint scanner 23 for acquiring a fingerprint image, and a camera 24 for acquiring a verification image.
[0035] The authentication terminal 20-1 uses a GUI (Graphical User Interface) or the like to prompt the user to place the passport on the scanner 22. The authentication terminal 20-1 controls the scanner 22 to obtain passport information.
[0036] The authentication terminal 20-1 acquires a face image and a fingerprint image of the user before and after acquiring the passport information.
[0037] Specifically, the authentication terminal 20-1 uses a GUI or the like to instruct the user to place a finger on the fingerprint scanner 23. The authentication terminal 20-1 controls the fingerprint scanner 23 to obtain at least one fingerprint image.
[0038] The authentication terminal 20-1 controls the camera 21 to acquire a facial image of the user when the fingerprint scanner 23 starts operating or while the fingerprint scanner 23 is operating. Furthermore, when the fingerprint scanner 23 starts operating or while the fingerprint scanner 23 is operating, the authentication terminal 20-1 controls the camera 24 to acquire a verification image.
[0039] In the following description, a face image acquired by the camera 21 will be referred to as a "captured face image." Also, a fingerprint image acquired by the fingerprint scanner 23 will be referred to as a "captured fingerprint image."
[0040] The camera 24 for acquiring the verification image may be a 360-degree camera capable of capturing images in all directions with a single lens. Therefore, the image captured by the camera 24 captures a wide area in front of the authentication terminal 20-1. For example, the face and body (arms and fingers) of the user who places his / her finger on the fingerprint scanner 23 are included in the image data captured by the camera 24.
[0041] Here, the authentication terminal 20-1 generates "validity certification information" for certifying the validity of its own terminal (authentication terminal 20-1) at the time of startup or the like.
[0042] For example, the authentication terminal 20-1 generates validity proof information that includes at least one of information about the terminal itself (authentication terminal 20-1), information about the installer (operator) of the authentication terminal 20-1, and information about the location where the authentication terminal 20-1 is installed.
[0043] The information about the authentication terminal 20-1 (hereinafter referred to as terminal information) includes the product name, manufacturer name, hardware ID, and names and versions of applications installed on the authentication terminal 20-1.
[0044] Information about the installer of authentication terminal 20-1 (hereinafter referred to as installer information) includes the name and biometric information (for example, a facial image) of the person who installed authentication terminal 20-1. Note that the installer (operator) of authentication terminal 20-1 may include the person who installed an application in authentication terminal 20-1.
[0045] Information about the location where the authentication device 20 is installed (hereinafter referred to as installation location information) includes location information of the authentication terminal 20-1. For example, the authentication terminal 20-1 generates its current location (latitude and longitude) as installation location information using a GPS (Global Positioning System) signal.
[0046] The authentication terminal 20-1 affixes a digital signature to the acquired user information and the generated validity proof information. For example, the authentication terminal 20-1 affixes a digital signature to the user information and the validity proof information using the manufacturer's private key.
[0047] Upon acquiring the authentication-subject information, the authentication terminal 20-1 requests authentication of the authentication-subject (preliminary screening regarding whether the user is permitted to enter the second country) from the server device 10. Specifically, the authentication terminal 20-1 transmits a "preliminary screening request" including the signed authentication-subject information and validity proof information to the server device 10 (see FIG. 5).
[0048] The server device 10 verifies the digital signature attached to the authenticated user information and the validity certification information included in the preliminary screening request. If the verification of the signatures of the authenticated user information and the validity certification information is successful, the server device 10 verifies the validity of the authentication terminal 20-1 using the validity certification information.
[0049] For example, the server device 10 verifies the legitimacy from the viewpoint of whether the version of the application used in the authentication terminal 20-1 is correct, whether the person who installed the authentication terminal 20-1 is the person who was previously registered, and whether the location where the authentication terminal 20-1 is installed is correct.
[0050] If it is determined that authentication terminal 20-1 is valid, server device 10 uses the authentication-subject information to perform a preliminary examination of the user (person to be authenticated).
[0051] Specifically, the server device 10 verifies the identity of the person to be authenticated using the passport facial image included in the passport information and the photographed facial image obtained by photographing the person using the authentication terminal 20-1.
[0052] If the identity verification is successful, the server device 10 determines whether the person to be authenticated is a person on a blacklist who is prohibited from entering the second country. Specifically, the server device 10 uses a captured fingerprint image of the person to be authenticated to determine whether the person to be authenticated is a person on a blacklist who is a person on a blacklist.
[0053] If the person to be authenticated is not a suspect person, the server device 10 uses the verification image to determine whether or not fraud such as impersonation has occurred when the photographed face image and photographed fingerprint image were acquired. For example, the server device 10 determines that fraud such as impersonation has occurred when the verification image shows a situation in which a person other than the person standing in front of the authentication terminal 20-1 is placing his / her finger on the fingerprint scanner 23 from below the authentication terminal 20-1.
[0054] If the above three determinations are successful, the server device 10 determines that the person to be authenticated is permitted to enter the second country. In this case, the server device 10 transmits an affirmative response indicating successful preliminary inspection (permission to enter) to the authentication terminal 20-1.
[0055] If the authentication terminal 20-1 fails to verify the authenticity or if at least one of the above three determinations fails, the server device 10 determines that the person to be authenticated is not allowed to enter the second country. In this case, the server device 10 transmits a negative response indicating a failure of the preliminary inspection (not allowed to enter) to the authentication terminal 20-1.
[0056] The authentication terminal 20-1 notifies the staff or the like of the result of the preliminary inspection. If the staff is notified that the preliminary inspection is successful (entry permitted), they will allow the person to board the ship 30. If the staff is notified that the preliminary inspection is unsuccessful (entry not permitted), they will deny the person to board the ship 30.
[0057] After the preliminary screening, the server device 10 stores the passport information, biometric information (facial features generated from a facial image, and a fingerprint image) of the person to be authenticated, the verification image, and the preliminary screening results in a user management database. The details of the user management database will be described later.
[0058] <Immigration Inspection Upon Disembarking> When a user disembarks from the ship 30 (when the user enters a second country), staff on board the ship 30 will conduct immigration inspection of the user.
[0059] The staff operates the authentication terminal 20-2 to acquire biometric information of the user (person to be authenticated). Specifically, the authentication terminal 20-2 photographs the user to acquire biometric information (for example, a facial image). The authentication terminal 20-2 then requests the server device 10 to authenticate the user (determine whether the user is permitted to enter the country). Specifically, the authentication terminal 20-2 transmits an "authentication request" including the acquired biometric information to the server device 10 (see FIG. 6).
[0060] The server device 10 executes a matching process using the biometric information included in the authentication request and the biometric information stored in the user management database.
[0061] If the matching process fails, the server device 10 notifies the authentication terminal 20-2 of "authentication failed," indicating that the user (person to be authenticated) is not allowed to enter the second country. Specifically, the server device 10 transmits a negative response to that effect to the authentication terminal 20-2. Alternatively, if the pre-screening result stored in the entry identified by the matching process is "pre-screening failed," the server device 10 also notifies the authentication terminal 20-2 of the authentication failure.
[0062] If the matching process is successful and the pre-screening result stored in the entry identified by the matching process is "pre-screening successful," the server device 10 notifies the authentication terminal 20-2 of "authentication successful," indicating that the user (person to be authenticated) is permitted to enter the second country. Specifically, the server device 10 transmits an affirmative response to that effect to the authentication terminal 20-2.
[0063] The authentication terminal 20-2 notifies the staff or the like of the authentication result. If the staff is notified that the authentication is successful (entry permitted), they allow the person to disembark from the ship 30. If the staff is notified that the authentication is unsuccessful (entry not permitted), they deny the person to disembark from the ship 30.
[0064] In this way, the server device 10 will not perform a preliminary immigration inspection (remote inspection; preclearance) of the person to be authenticated unless it has successfully verified the authenticity of the authentication terminal 20-1, which is the authentication device. As a result, the reliability of the authentication result using the biometric information acquired by the authentication terminal 20-1 is guaranteed.
[0065] Next, details of each device included in the information processing system according to the first embodiment will be described.
[0066] [Authentication Terminal 20-1] Fig. 7 is a diagram showing an example of the processing configuration (processing module) of the authentication terminal 20-1 according to an embodiment of the present disclosure. Referring to Fig. 7, the authentication terminal 20-1 includes a communication control unit 201, a terminal information control unit 202, an authentication-subject information control unit 203, a preliminary examination control unit 204, and a storage unit 205.
[0067] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0068] The terminal information control unit 202 is a means for controlling the validity proof information of the authentication terminal 20-1.
[0069] The terminal information control unit 202 generates validity proof information at the time of startup or in response to an instruction from an operator. Specifically, the terminal information control unit 202 acquires (generates) all or part of the terminal information, installer information, and installation location information.
[0070] The terminal information control unit 202 acquires, as terminal information, the product name, manufacturer name, hardware ID, and names and versions of applications used by the authentication terminal 20-1. For example, the terminal information control unit 202 reads the product name, etc. of the authentication terminal 20-1 from a predetermined area in a read-only memory (ROM) or a hard disk drive (HDD). Alternatively, the terminal information control unit 202 acquires the names and versions of installed applications via an operating system (OS).
[0071] The terminal information control unit 202 acquires, as installer information, the name and biometric information (e.g., a facial image) of the installer (e.g., a staff member of a shipping company or the like who conducts a preliminary screening) at the time of startup, etc. The terminal information control unit 202 acquires the name of the installer using a GUI. The terminal information control unit 202 also controls the camera 21 to photograph the installer and acquire the biometric information (facial image).
[0072] The terminal information control unit 202 calculates the current location of the authentication terminal 20-1 as installation location information. The terminal information control unit 202 receives GPS signals from GPS (Global Positioning System) satellites to perform positioning and generates location information including the latitude and longitude of the authentication terminal 20-1. Alternatively, the terminal information control unit 202 may communicate with a wireless access point and treat the location of the wireless access point as the location of the terminal itself. Alternatively, the terminal information control unit 202 may generate location information based on the strength of radio waves received from the wireless access point.
[0073] The terminal information control unit 202 signs the generated validity proof information. For example, the terminal information control unit 202 signs the validity proof information using the private key of the manufacturer of the authentication terminal 20-1. The terminal information control unit 202 stores the validity proof information with the digital signature in the storage unit 205.
[0074] The authenticated person information control unit 203 is a means for controlling the authenticated person information of the authenticated person (a person leaving the first country). The authenticated person information control unit 203 acquires passport information, a photographed face image, a photographed fingerprint image, and a verification image as the authenticated person information.
[0075] Authentication-subject information control unit 203 acquires passport information relating to the passport held by the authentication-subject.
[0076] For example, the authenticated user information control unit 203 controls the scanner 22 shown in Fig. 4 to scan the face of a passport placed on the scanner 22. The authenticated user information control unit 203 extracts a facial area from the image data obtained by the scan and acquires a facial image (passport facial image). The authenticated user information control unit 203 also acquires the name and other information written on the face of the passport using OCR (Optical Character Recognition) technology.
[0077] Alternatively, the authenticated person information control unit 203 may read passport information from an IC (Integrated Circuit) chip mounted on the passport. When reading information from the IC chip, the authenticated person information control unit 203 reads MRZ information written in a Machine Readable Zone (MRZ) printed on the face of the passport. The MRZ information includes name, nationality, gender, date of birth, etc. The authenticated person information control unit 203 uses the acquired MRZ information as a password to read information such as a facial image and name from the IC chip.
[0078] When the passport information is acquired, the authentication-subjected user information control unit 203 acquires a face image and a fingerprint image of the authentication-subjected user. When acquiring the face image and the fingerprint image, the authentication-subjected user information control unit 203 also acquires a verification image.
[0079] Using a GUI or the like, authentication-subjected user information control unit 203 instructs the user to place a finger on fingerprint scanner 23. Authentication-subjected user information control unit 203 controls fingerprint scanner 23 to obtain at least one fingerprint image.
[0080] The authentication-subjected user information control unit 203 photographs the person to be authenticated while capturing a fingerprint image to obtain a face image. The authentication-subjected user information control unit 203 controls the camera 21 to obtain at least one face image while capturing a fingerprint image.
[0081] Furthermore, while acquiring the fingerprint image, the authentication-subjected user information control unit 203 controls the camera 24 (360-degree camera) to capture an image of the entire body of the authentication-subjected user, including the face and fingers. The authentication-subjected user information control unit 203 treats the captured image as a verification image.
[0082] Upon acquiring the authentication-subject information (passport information, photographed face image, photographed fingerprint image, and verification image), the authentication-subject information control unit 203 signs the authentication-subject information. For example, the authentication-subject information control unit 203 signs the authentication-subject information using the private key of the manufacturer of the authentication terminal 20-1. The authentication-subject information control unit 203 passes the authentication-subject information with the digital signature to the preliminary screening control unit 204.
[0083] In this way, the authentication-subjected person information control unit 203 has a function as an acquisition unit that acquires the biometric information of the authentication-subjected person, etc. Specifically, the authentication-subjected person information control unit 203 acquires passport information related to the passport held by the authentication-subjected person, a facial image of the authentication-subjected person, a fingerprint image of the authentication-subjected person, and a verification image that enables verification of whether or not fraud has occurred when the facial image and fingerprint image are acquired.
[0084] The pre-screening control unit 204 is a control means for controlling the pre-screening. The pre-screening control unit 204 requests the server device 10 to authenticate the person to be authenticated by transmitting to the server device 10, which performs biometric authentication, user information about the person to be authenticated, including biometric information, and validity certification information for verifying the validity of its own terminal (authentication terminal 20-1).
[0085] When the digitally signed user information is acquired from the user information control unit 203, the preliminary screening control unit 204 reads out the digitally signed validity proof information from the memory unit 205. The preliminary screening control unit 204 sends a "preliminary screening request" including the digitally signed user information and validity proof information to the server device 10.
[0086] The preliminary screening control unit 204 receives the result of the preliminary screening (preliminary screening success, preliminary screening failure) from the server device 10. The preliminary screening control unit 204 notifies staff or the like of the result of the preliminary screening.
[0087] Specifically, upon receiving a positive response (preliminary inspection successful, entry permitted), the preliminary inspection control unit 204 notifies the staff that the person to be authenticated is permitted to board the ship 30. Upon receiving a negative response (preliminary inspection unsuccessful, entry not permitted), the preliminary inspection control unit 204 notifies the staff that the person to be authenticated is not permitted to board the ship 30.
[0088] In this way, the preliminary screening control unit 204 transmits to the server device 10 validity certification information including at least one of the product name, manufacturer, hardware ID, application name, and application version. Alternatively, the preliminary screening control unit 204 transmits to the server device 10 validity certification information including at least one of the name and biometric information of the installer of its own terminal (authentication terminal 20-1). Alternatively, the preliminary screening control unit 204 transmits to the server device 10 validity certification information including location information of its own terminal (authentication terminal 20-1). Alternatively, the preliminary screening control unit 204 assigns a digital signature to each of the validity certification information and the authenticated party information, and transmits the validity certification information and the authenticated party information with the digital signature attached to them to the server device 10.
[0089] The storage unit 205 is a means for storing information necessary for the operation of the authentication terminal 20-1.
[0090] 8 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to an embodiment of the present disclosure. Referring to FIG. 8, the server device 10 includes a communication control unit 301, a preliminary screening control unit 302, an authentication control unit 303, and a storage unit 304.
[0091] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the authentication terminal 20-1. The communication control unit 301 also transmits data to the authentication terminal 20-1. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0092] The pre-screening control unit 302 is a means for controlling the pre-screening of the person to be authenticated (a person departing from the first country). The pre-screening control unit 302 processes the pre-screening request received from the authentication terminal 20-1.
[0093] 9 is a flowchart showing an example of the operation of the preliminary screening control unit 302 according to the embodiment of the present disclosure. The operation of the preliminary screening control unit 302 will be described with reference to FIG.
[0094] The preliminary examination control unit 302 receives a preliminary examination request from the authentication terminal 20-1 (step S101).
[0095] The preliminary examination control unit 302 verifies the digital signature attached to the acquired authentication target information and validity proof information.
[0096] If verification of at least one of the digital signatures attached to the two pieces of information fails (step S102, No branch), the pre-screening control unit 302 sets the pre-screening result to pre-screening failure (step S103).
[0097] If the verification of the digital signatures attached to the two pieces of information is successful (step S102, Yes branch), the preliminary screening control unit 302 verifies the authenticity of the authentication terminal 20-1.
[0098] Specifically, the preliminary screening control unit 302 verifies the validity of the authentication terminal 20-1 using the validity certification information. More specifically, the preliminary screening control unit 302 verifies the validity of the authentication terminal 20-1 using the validity certification information and information previously registered in the server device 10 by a system administrator or the like.
[0099] The system administrator registers in advance in the server device 10 the name of the authentication terminal 20-1 that can be used for the preliminary screening, the name of the manufacturer, the hardware ID, the name and version of the application that can be used for the preliminary screening, etc. The system administrator also obtains information about the staff in charge of the preliminary screening work (e.g., names and facial images) from the shipping company of the ship 30, etc., and registers the obtained information in the server device 10. The system administrator also registers in the server device 10 information about the location where the authentication terminal 20-1 can be installed (e.g., location information of the departure port).
[0100] If the validity proof information includes terminal information, the pre-screening control unit 302 determines whether the product name, manufacturer name, hardware ID, application name, application version, etc. of the authentication terminal 20-1 obtained from the information match the information registered in advance.
[0101] If the product name, etc. of the authentication terminal 20-1 matches the information registered in advance by the system administrator, etc., the pre-screening control unit 302 determines that the authentication terminal 20-1 is legitimate. If the product name, etc. of the authentication terminal 20-1 does not match the information registered in advance by the system administrator, etc., the pre-screening control unit 302 determines that the authentication terminal 20-1 is not legitimate.
[0102] If the authenticity proof information includes installer information, the pre-screening control unit 302 determines whether the name, facial image, etc. of the installer (operator) obtained from the information matches the information registered in advance.
[0103] If the name, facial image, etc. of the installer who installed authentication terminal 20-1 matches the information registered in advance by a system administrator, etc., the pre-screening control unit 302 determines that authentication terminal 20-1 is legitimate. If the name, facial image, etc. of the installer who installed authentication terminal 20-1 does not match the information registered in advance by a system administrator, etc., the pre-screening control unit 302 determines that authentication terminal 20-1 is not legitimate.
[0104] In addition, the preliminary screening control unit 302 can determine whether the installer of the authentication terminal 20-1 is a person who has been registered in advance by performing one-to-one authentication using the facial image contained in the installer information and a facial image that has been registered in advance.
[0105] If the authenticity proof information includes installation location information, the pre-examination control unit 302 determines whether the current location of the authentication terminal 20-1 has been pre-registered as a location where the authentication terminal 20-1 can be installed (the port of departure of the first country).
[0106] If the pre-screening control unit 302 determines, based on the location information of the authentication terminal 20-1, that the authentication terminal 20-1 is installed at a departure port previously registered by a system administrator, etc., the pre-screening control unit 302 determines that the authentication terminal 20-1 is legitimate. If the pre-screening control unit 302 determines, based on the location information of the authentication terminal 20-1, that the authentication terminal 20-1 is not installed at a departure port previously registered by a system administrator, etc., the pre-screening control unit 302 determines that the authentication terminal 20-1 is not legitimate.
[0107] In this way, the preliminary examination control unit 302 determines the legitimacy of the authentication terminal 20-1 using all or part of the information contained in the legitimacy proof information.
[0108] If the authentication terminal 20-1 is determined to be invalid (step S104, No branch), the pre-screening control unit 302 sets the pre-screening result to "pre-screening failure" (step S103).
[0109] If it is determined that the authentication terminal 20-1 is valid (step S104, Yes branch), the preliminary screening control unit 302 executes identity verification of the person to be authenticated using the authentication-subject information.
[0110] The pre-screening control unit 302 verifies the identity of the person by using the passport face image and the photographed face image included in the authentication subject information. The pre-screening control unit 302 verifies the identity of the person by determining whether the two sets of biometric information substantially match.
[0111] The preliminary screening control unit 302 generates feature amounts from each of the two facial images.
[0112] Since existing technology can be used for the feature generation process, a detailed description thereof will be omitted. For example, the pre-screening control unit 302 extracts the eyes, nose, mouth, etc. from the facial image as feature points. The pre-screening control unit 302 then calculates the positions of each feature point and the distances between each feature point as feature amounts (generating a feature vector consisting of multiple feature amounts).
[0113] Next, the preliminary screening control unit 302 performs a matching process (one-to-one matching) using the two generated feature amounts. Specifically, the preliminary screening control unit 302 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the preliminary screening control unit 302 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0114] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the pre-screening control unit 302 determines that the identity verification is successful. If the similarity is equal to or less than the predetermined value, the pre-screening control unit 302 determines that the identity verification is unsuccessful.
[0115] If the identity verification fails (step S105, No branch), the pre-screening control unit 302 sets the pre-screening result to pre-screening failure (step S103).
[0116] If the identity verification is successful (step S105, Yes branch), the preliminary screening control unit 302 determines whether the person to be authenticated is a suspicious person.
[0117] The preliminary screening control unit 302 determines whether the person to be authenticated is a suspicious person by using the captured fingerprint image included in the person-to-be-authentication information. Specifically, the preliminary screening control unit 302 determines whether the person to be authenticated is a suspicious person based on whether the captured fingerprint image is included in a blacklist consisting of fingerprint images of multiple suspicious people.
[0118] The blacklist (fingerprint images of suspicious persons) is input in advance into the server device 10 by a system administrator or the like.
[0119] The pre-screening control unit 302 sets the captured fingerprint image as the target for matching and performs one-to-many matching with multiple fingerprint images registered on the blacklist (at least one fingerprint image of multiple suspect individuals). The pre-screening control unit 302 calculates a score (similarity) between the captured fingerprint image to be matched and each of the multiple fingerprint images on the registration side.
[0120] The preliminary screening control unit 302 extracts minutiae (end points, bifurcation points) from each of the fingerprint images on the matching side and the registration side. The preliminary screening control unit 302 calculates a score indicating the similarity between the two fingerprint images based on the extracted minutiae, etc. Specifically, the preliminary screening control unit 302 matches the core regions (central regions of the fingerprint) of the two fingerprint images and calculates the score based on the positions and number of minutiae as seen from the core regions, the number of core lines existing between the minutiae, etc. The higher the score, the higher the similarity between the two fingerprint images.
[0121] The process of extracting minutiae from a fingerprint image and the process of calculating a score from minutiae can be performed using existing technology and will be clear to those skilled in the art, so further explanation will be omitted.
[0122] The preliminary screening control unit 302 determines whether there is at least one fingerprint image among the multiple fingerprint images registered on the blacklist that has a score with the fingerprint image to be compared that is equal to or greater than a predetermined value.
[0123] If a fingerprint image with the above score equal to or greater than a predetermined value is present on the blacklist, the pre-screening control unit 302 determines that the person to be authenticated is a person requiring suspicion. If a fingerprint image with the above score equal to or greater than a predetermined value is not present on the blacklist, the pre-screening control unit 302 determines that the person to be authenticated is not a person requiring suspicion.
[0124] Alternatively, the preliminary screening control unit 302 may send a fingerprint image (photographed fingerprint image) of the person to be authenticated to an external server that holds a blacklist and request a determination as to whether the person to be authenticated is a person to be suspicious of.
[0125] If the person to be authenticated is a suspicious person (step S106, Yes branch), the pre-screening control unit 302 sets the result of the pre-screening to "pre-screening failure" (step S103).
[0126] If the person to be authenticated is not a suspect person (step S106, No branch), the preliminary screening control unit 302 determines whether or not fraud such as impersonation has occurred (determines whether or not fraud has occurred).
[0127] Specifically, the preliminary screening control unit 302 determines whether fraud such as impersonation has occurred by using the verification image included in the authenticated person information. For example, the preliminary screening control unit 302 can obtain a determination result (whether fraud has occurred or not) by inputting the verification image into a learning model.
[0128] The learning model is obtained by machine learning using a large amount of training data in which labels (determination results; for example, whether there is fraud or not) are assigned to image data (image data showing the situation when the face and fingerprint were photographed). Any algorithm such as a support vector machine, boosting, or neural network can be used to generate the learning model. Note that known techniques can be used for the algorithms such as the support vector machine, and therefore a description thereof will be omitted.
[0129] If fraud is detected (step S107, Yes branch), the pre-screening control unit 302 sets the pre-screening result to pre-screening failure (step S103).
[0130] If no fraud is detected (step S107, No branch), the pre-screening control unit 302 sets the result of the pre-screening to pre-screening success (step S108).
[0131] The preliminary screening control unit 302 transmits the screening result (preliminary screening successful, preliminary screening failed) to the authentication terminal 20-1 (step S109).
[0132] Specifically, if the pre-screening is successful (entry into the second country is permitted), the pre-screening control unit 302 sends a positive response indicating this to the authentication terminal 20-1. If the pre-screening is unsuccessful (entry into the second country is not permitted), the pre-screening control unit 302 sends a negative response indicating this to the authentication terminal 20-1.
[0133] The pre-screening control unit 302 stores the information of the person to be authenticated and the results of the pre-screening in the user management database (step S110). Specifically, the pre-screening control unit 302 stores the passport information, biometric information (facial features generated from a facial image, fingerprint image), verification image, and the results of the pre-screening in the user management database (see FIG. 10).
[0134] 10 is an example and is not intended to limit the items to be stored in the user management database. For example, a "face image" may be registered in the user management database as biometric information.
[0135] The authentication control unit 303 is a means for executing control relating to the authentication of the person to be authenticated (a person entering the second country).
[0136] The authentication control unit 303 processes the authentication request received from the authentication terminal 20-2.
[0137] The authentication control unit 303 performs a matching process using the biometric information (face image) included in the authentication request and the biometric information (feature amount) stored in the user management database.
[0138] Specifically, the authentication control unit 303 generates features from the facial image included in the authentication request. The authentication control unit 303 sets the generated features as targets for matching and performs a matching process (one-to-N matching; N is a positive integer, the same applies hereinafter) with features registered in the user management database.
[0139] The authentication control unit 303 calculates the similarity between the feature to be matched and each of the multiple feature values on the registration side. The similarity can be calculated using chi-square distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0140] The authentication control unit 303 determines that the matching process has failed if there is no feature among the multiple features registered in the user management database that has a similarity with the feature to be matched that is equal to or greater than a predetermined value.
[0141] The authentication control unit 303 determines that the matching process is successful if, among the multiple features registered in the user management database, there is a feature whose similarity with the feature to be matched is equal to or greater than a predetermined value. If the matching process is successful, the entry with the feature that has the highest similarity among the multiple entries registered in the user management database is identified as the entry of the person to be authenticated.
[0142] If the matching process fails, the authentication control unit 303 sets the authentication result to "authentication failure."
[0143] If the matching process is successful, the authentication control unit 303 reads the screening result from the pre-screening result field of the entry identified by the matching process.
[0144] If the result of the pre-screening is "pre-screening failed", the authentication control unit 303 sets the authentication result to "authentication failed". If the result of the pre-screening is "pre-screening successful", the authentication control unit 303 sets the authentication result to "authentication successful".
[0145] The authentication control unit 303 transmits the authentication result (authentication success, authentication failure) to the authentication terminal 20-2. Specifically, if the authentication result is authentication success, the authentication control unit 303 transmits an affirmative response indicating that to the authentication terminal 20-2. If the authentication result is authentication failure, the authentication control unit 303 transmits a negative response indicating that to the authentication terminal 20-2.
[0146] The storage unit 304 is a means for storing information necessary for the operation of the server device 10 .
[0147] 11 is a diagram showing an example of the processing configuration (processing module) of the authentication terminal 20-2 according to an embodiment of the present disclosure. Referring to FIG. 11, the authentication terminal 20-2 includes a communication control unit 401, a biometric information acquisition unit 402, an authentication control unit 403, and a storage unit 404.
[0148] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the server device 10. The communication control unit 401 also transmits data to the server device 10. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0149] The biometric information acquisition unit 402 is a means for controlling a camera (not shown) and acquiring biometric information of the person to be authenticated. The biometric information acquisition unit 402 captures an image in front of the terminal automatically or in response to an operation by a staff member or the like. The biometric information acquisition unit 402 passes the image data obtained by capturing the image to the authentication control unit 403 as biometric information (facial image) of the person to be authenticated.
[0150] The authentication control unit 403 is a means for executing control related to authentication of a user (person to be authenticated). The authentication control unit 403 transmits an “authentication request” including the biometric information acquired from the biometric information acquisition unit 402 to the server device 10.
[0151] The authentication control unit 403 receives a response (positive response, negative response) to the authentication request from the server device 10. The authentication control unit 403 notifies a staff member or the like of the authentication result (authentication success, authentication failure) obtained from the received response.
[0152] The storage unit 404 stores various information necessary for the operation of the authentication terminal 20-2.
[0153] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described. Fig. 12 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system will be described with reference to Fig. 12.
[0154] The authentication terminal 20-1 acquires the information of the person to be authenticated (step S01). The authentication terminal 20-1 controls the camera 21 and the like to acquire passport information, biometric information (face image, fingerprint image), and a verification image.
[0155] The authentication terminal 20-1 transmits a "preliminary examination request" including the acquired authentication-subject information and the validity proof information generated in advance to the server device 10 (step S02).
[0156] The server device 10 verifies the authenticity of the authentication terminal 20-1 using the acquired authenticity proof information (step S03).
[0157] If authentication terminal 20-1 is valid, server device 10 performs a preliminary examination of the person to be authenticated using the person to be authenticated (step S04).
[0158] The server device 10 notifies the authentication terminal 20-1 of the result of the preliminary examination (step S05).
[0159] The authentication terminal 20-1 notifies the staff or the like of the results of the preliminary examination (step S06).
[0160] Next, a modification of the first embodiment will be described.
[0161] <Modification 1> In the above embodiment, a case has been described in which a facial image of a user (person to be authenticated) is acquired when disembarking from the ship 30, and authentication is performed using the facial image. However, other biometric information may be used to authenticate the person to be authenticated instead of or in addition to a facial image.
[0162] For example, the authentication terminal 20-2 may acquire a face image and a fingerprint image of a user (entering the second country). The authentication terminal 20-2 may transmit an authentication request including the face image and fingerprint image of the person to be authenticated to the server device 10.
[0163] In this case, the server device 10 may determine that the authentication is successful if the fingerprint image (photographed fingerprint image) stored in the entry identified by the matching process using the facial image substantially matches the fingerprint image of the person to be authenticated.
[0164] The authentication control unit 303 of the server device 10 may set the threshold value used for the determination using the fingerprint image (the threshold value used for threshold processing of the score) lower than the threshold value used for the preliminary screening, because the person to be authenticated has already been identified by authentication using a face image.
[0165] <Modification 2> In the above embodiment, a case has been described in which a face image and a fingerprint image of a user (person to be authenticated) are acquired when boarding the vessel 30, and the face image and the fingerprint image are transmitted as part of the person to be authenticated to the server device 10. However, other biometric information may be transmitted to the server device 10 instead of or in addition to the face image and the fingerprint image.
[0166] For example, authentication terminal 20-1 may acquire an iris image in addition to a face image and a fingerprint image, and transmit to server device 10 information about the person to be authenticated that includes the acquired iris image.
[0167] When the server device 10 has successfully pre-authenticate the person to be authenticated, it stores the iris feature amount in addition to the facial feature amount and fingerprint image in the user management database.
[0168] When iris features are registered in the user management database, the authentication terminal 20-2 may acquire an iris image of the user disembarking the ship 30, and transmit an authentication request including the acquired iris image to the server device 10. For example, the authentication terminal 20-2 may transmit an authentication request including a face image and an iris image to the server device 10.
[0169] The authentication control unit 303 of the server device 10 performs one-to-N authentication using the facial image included in the authentication request and the facial feature amounts stored in the user management database. The authentication control unit 303 performs one-to-one authentication using the iris feature amounts of the entry identified by the one-to-N authentication (one-to-N matching) and the iris image included in the authentication request. The authentication control unit 303 may determine that authentication of the person to be authenticated has been successful if one-to-one authentication using iris information is successful.
[0170] Alternatively, the authentication control unit 303 may perform one-to-many authentication using iris feature amounts, and one-to-one authentication using facial feature amounts.
[0171] <Modification 3> The authentication terminal 20-1 may add a timestamp when passport information or biometric information is acquired to the authentication subject information. The server device 10 may verify the authenticity of the authentication terminal 20-1 using the timestamp. For example, the server device 10 may determine that the authentication terminal 20-1 is not authentic if the time when the biometric information was acquired is unnaturally earlier than the time of authentication.
[0172] <Modification 4> In the above embodiment, the case where the authenticated person information (passport information, face image, fingerprint image, verification image) is acquired when departing from a first country has been described. However, the authenticated person information may also be acquired after the ship 30 enters the territorial waters of a second country. For example, the authentication terminal 20-1 may be configured to acquire the authenticated person information when it determines that the terminal has entered the territorial waters of a second country by positioning using a GPS signal or the like.
[0173] As described above, the authentication terminal 20-1 according to the first embodiment transmits not only the biometric information of the person to be authenticated but also validity proof information that proves the validity of the terminal itself to the server device 10. The server device 10 can verify the validity of the authentication terminal 20-1 that acquired the biometric information (authentication information, person to be authenticated) using the validity proof information. Since the server device 10 performs the authentication process using the biometric information acquired by the correct authentication terminal 20-1, the reliability of the authentication result output by the server device 10 is guaranteed.
[0174] Here, preclearance (preliminary inspection before entry) for departing persons may also be performed at airports. At airports, immigration officers operate authentication devices. In contrast, preclearance for users boarding ships 30 such as cruise ships is often performed by shipping companies, shipping agents, etc. Therefore, the authentication devices used at airports and those used at ports or inside ships 30 require different security levels. Taking these circumstances into consideration, authentication terminal 20-1 provides server device 10 with validity certification information indicating the validity of its own terminal. By performing preclearance using the validity certification information, the user's entry inspection into a second country can be completed in a short time. As a result, convenience for users is improved.
[0175] Next, the hardware of each device constituting the information processing system will be described. Fig. 13 is a diagram showing an example of the hardware configuration of the authentication terminal 20-1.
[0176] The authentication terminal 20-1 can be configured as an information processing device (a so-called computer), and has the configuration shown in Fig. 13. For example, the authentication terminal 20-1 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0177] However, the configuration shown in Fig. 13 is not intended to limit the hardware configuration of the authentication terminal 20-1. The authentication terminal 20-1 may include hardware not shown, and may not have the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the authentication terminal 20-1 is not intended to be limited to the example shown in Fig. 13; for example, the authentication terminal 20-1 may include multiple processors 311.
[0178] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0179] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0180] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations, such as a keyboard or a mouse.
[0181] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0182] The functions of the authentication terminal 20-1 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing modules can be realized by a semiconductor chip.
[0183] The server device 10, authentication terminal 20-2, etc. can also be configured by information processing devices in the same way as authentication terminal 20-1, and their basic hardware configurations are no different from those of authentication terminal 20-1, so a description thereof will be omitted.
[0184] The authentication terminal 20-1, which is an information processing device, is equipped with a computer, and the functions of the authentication terminal 20-1 can be realized by causing the computer to execute a program. Also, the authentication terminal 20-1 executes a control method for the authentication terminal 20-1 by the program.
[0185] [Modification] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0186] In the above embodiment, a case has been described in which the authentication terminal 20-1 used for the preliminary inspection (remote inspection; preclearance) of a user boarding the ship 30 and entering a second country transmits the validity proof information to the server device 10. However, the authentication terminal 20-2 used for the immigration inspection when the user lands in the second country may also transmit the validity proof information to the server device 10. The server device 10 may execute the user authentication process when the validity verification of the authentication terminal 20-2 is successful.
[0187] Furthermore, an authentication terminal used for any application, not limited to pre-screening or immigration screening, can transmit its own validity certification information to the server device 10. For example, an authentication terminal used for check-in at a hotel or the like, or an authentication terminal used for biometric authentication payment may transmit validity certification information to the server device 10.
[0188] The authentication terminal 20-1 may affix a digital signature to a single file that combines the authenticated user information and the validity proof information. Alternatively, the authentication terminal 20-1 may affix a digital signature to either the authenticated user information or the validity proof information. Alternatively, the authentication terminal 20-1 may not affix a digital signature to either the authenticated user information or the validity proof information.
[0189] The authentication terminal 20-1 does not have to transmit the validity proof information to the server device 10 together with the authenticatee information. The authentication terminal 20-1 may write the validity proof information to the blockchain at startup or the like. Furthermore, the server device 10 may acquire the validity proof information from the blockchain in response to receiving a pre-screening request from the authentication terminal 20-1. Alternatively, the authentication terminal 20-1 may write the validity proof information to the blockchain as a credential certificate (VC; Verifiable Credentials).
[0190] In the above embodiment, a case has been described in which a fingerprint image (a photographed fingerprint image) is used to determine whether or not a person to be authenticated is a blacklist. That is, a case has been described in which a fingerprint image is included in a blacklist as information on blacklisted persons. However, the blacklist may also include passport numbers and the like of passports issued to blacklisted persons.
[0191] The preclearance described in the above embodiment may be applied to a user entering a second country from a first country by airplane.
[0192] The server device 10 may verify the authenticity of the authentication terminal 20-1 based on a combination of the product name of the authentication terminal 20-1 and the application used. If the combination is correct, the server device 10 may determine that the authentication terminal 20-1 is authentic.
[0193] The server device 10 may verify the authenticity of the authentication subject information. For example, if the server device 10 finds any suspicious features in the acquired fingerprint image, the server device 10 may instruct the authentication terminal 20-1 to reacquire the fingerprint image. Note that any suspicious features in the fingerprint image may be detected using a learning model.
[0194] In the above embodiment, a case has been described in which biometric information related to a facial image is transmitted and received between the server device 10 and the authentication terminal 20-1. However, feature amounts generated from a facial image may also be transmitted and received between the devices. In this case, the receiving server device 10 may use the received feature amounts and utilize the received feature amounts in subsequent processing. Alternatively, the biometric information stored in the user management database may be feature amounts or facial images. If a facial image is stored, feature amounts may be generated from the facial image as needed. Alternatively, both facial images and feature amounts may be stored in the user management database.
[0195] In the above embodiment, the case where the result of the preliminary screening is notified to the authentication terminal 20-1 has been described. However, the result of the preliminary screening does not have to be notified to the authentication terminal 20-1. In other words, the result of the preliminary screening may be stored in the user management database, and an authenticated person who fails the preliminary screening may be allowed to board the ship 30. In this case, disembarkation (entry into the second country) of a user who fails the preliminary screening is denied at the immigration screening (screening using the result of the preliminary screening) conducted when passengers disembark.
[0196] The preliminary inspection conducted when the user departs from a first country and the immigration inspection conducted when the user enters a second country may be conducted by the user himself / herself, rather than by staff of a shipping company, etc. In other words, the authentication terminal 20-1 and / or the authentication terminal 20-2 may be a self-service terminal operated by the user himself / herself.
[0197] In the above embodiment, the case where the server device 10 installed on the network performs the preliminary inspection has been described. However, it is conceivable that it may be difficult for the authentication terminal 20-1 to access the server device 10 on the network from inside the ship 30. In this regard, a device equivalent to the server device 10 that contains a blacklist may be installed inside the ship 30, and the authentication terminal 20-1 may request the preliminary inspection from that device.
[0198] The server device 10 may authenticate the shipping company when verifying the validity information received from the authentication terminal 20-1. Specifically, the server device 10 obtains information (file) from the shipping company that is information about the staff in charge of the preliminary screening work and that has the shipping company's digital signature attached. The server device 10 may authenticate the shipping company by verifying the digital signature.
[0199] In the above embodiment, a case has been described in which the facial image (photographed facial image) used for the preliminary screening and the verification image are acquired by different cameras. However, the facial image (photographed facial image) for the preliminary screening may be generated from the verification image. For example, the authentication terminal 20-1 may extract a facial image after applying a predetermined transformation (transformation or correction to remove distortion from an image captured by a 360-degree camera) to the verification image, and then treat the extracted facial image as the photographed facial image.
[0200] In the above embodiment, a case where the user management database is configured inside the server device 10 has been described, but the user management database may also be constructed on an external database server, etc. In other words, some functions of the server device 10, etc. may be implemented on another server. More specifically, the above-described "pre-screening control unit (pre-screening control means)" etc. may be implemented on any of the devices included in the system.
[0201] The format of data transmission between each device (server device 10, authentication terminal 20-1, etc.) is not particularly limited, but data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect personal information, it is desirable to transmit and receive encrypted data.
[0202] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0203] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0204] From the above explanation, it is clear that the present invention has industrial applicability, and the present invention can be suitably applied to information processing systems that provide users with services using biometric authentication.
[0205] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.
[0206] [Supplementary Note 1] A terminal comprising: an acquisition means for acquiring biometric information of a person to be authenticated; and a control means for transmitting, to a server device that performs biometric authentication, user information about the person to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the terminal, thereby requesting the server device to authenticate the person to be authenticated.
[0207] [Supplementary Note 2] The terminal according to Supplementary Note 1, wherein the control means transmits the validity certification information including at least one of a product name, a manufacturer, a hardware ID, a name of an application, and a version of the application to the server device.
[0208] [Supplementary Note 3] The terminal according to Supplementary Note 1, wherein the control means transmits the validity proof information including at least one of a name and biometric information of an installer of the terminal to the server device.
[0209] [Supplementary Note 4] The terminal according to Supplementary Note 1, wherein the control means transmits the validity proof information including location information of the terminal to the server device.
[0210] [Supplementary Note 5] The terminal according to any one of Supplementary Notes 1 to 4, wherein the control means assigns a digital signature to each of the validity proof information and the authenticated user information, and transmits the validity proof information and the authenticated user information with the digital signature attached to the server device.
[0211] [Supplementary Note 6] The terminal described in any one of Supplementary Notes 1 to 4, wherein the acquisition means acquires passport information regarding a passport held by the person to be authenticated, a facial image of the person to be authenticated, a fingerprint image of the person to be authenticated, and a verification image that enables verification of whether or not any fraud has occurred when the facial image and the fingerprint image are acquired, and the control means transmits the person to be authenticated information including the passport information, the facial image, the fingerprint image, and the verification image to the server device.
[0212] [Supplementary Note 7] The terminal described in Supplementary Note 1, wherein the acquisition means acquires biometric information of the person to be authenticated who is leaving a first country and attempting to enter a second country, and the control means transmits the validity proof information including location information of the terminal acquired within the territorial waters of the second country to the server device.
[0213] [Supplementary Note 8] A system including a server device and a terminal that perform biometric authentication, wherein the terminal comprises: an acquisition means that acquires biometric information of a person to be authenticated; and a control means that requests the server device to authenticate the person to be authenticated by transmitting to the server device person-to-be-authenticated information related to the person to be authenticated, including the acquired biometric information, and validity certification information for proving the validity of the terminal itself.
[0214] [Supplementary Note 9] The system according to Supplementary Note 8, wherein the control means transmits the validity proof information to the server device, the validity proof information including at least one of a product name, a manufacturer, a hardware ID, a name of an application, and a version of the application.
[0215] [Supplementary Note 10] The system according to Supplementary Note 8, wherein the control means transmits the validity proof information including at least one of the name and biometric information of an installer of the terminal to the server device.
[0216] [Supplementary Note 11] The system according to Supplementary Note 8, wherein the control means transmits the validity proof information including location information of the terminal itself to the server device.
[0217] [Appendix 12] The system described in any one of Appendices 8 to 11, wherein the control means assigns a digital signature to each of the validity proof information and the authenticated user information, and transmits the validity proof information and the authenticated user information with the digital signature attached to the server device.
[0218] [Supplementary Note 13] The system described in any one of Supplementary Notes 8 to 11, wherein the acquisition means acquires passport information regarding a passport held by the person to be authenticated, a facial image of the person to be authenticated, a fingerprint image of the person to be authenticated, and a verification image that enables verification of whether or not any fraud has occurred when the facial image and the fingerprint image are acquired, and the control means transmits the person to be authenticated information including the passport information, the facial image, the fingerprint image, and the verification image to the server device.
[0219] [Appendix 14] The system described in Appendix 8, wherein the acquisition means acquires biometric information of the person to be authenticated who is leaving a first country and attempting to enter a second country, and the control means transmits the validity proof information including location information of the device acquired within the territorial waters of the second country to the server device.
[0220] [Supplementary Note 15] A method for controlling a terminal, comprising: an acquisition step of acquiring biometric information of a person to be authenticated; and a control step of transmitting, to a server device that performs biometric authentication, person information about the person to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the terminal, thereby requesting the server device to authenticate the person to be authenticated.
[0221] [Supplementary Note 16] The terminal control method according to Supplementary Note 15, wherein the control step transmits the validity proof information including at least one of a product name, a manufacturer, a hardware ID, a name of an application, and a version of the application to the server device.
[0222] [Supplementary Note 17] The method for controlling a terminal according to Supplementary Note 15, wherein the control step transmits the validity proof information including at least one of a name and biometric information of an installer of the terminal to the server device.
[0223] [Supplementary Note 18] The method for controlling a terminal according to Supplementary Note 15, wherein the control step transmits the validity proof information including location information of the terminal to the server device.
[0224] [Supplementary Note 19] The method for controlling a terminal according to any one of Supplementary Notes 15 to 18, wherein the control step includes attaching a digital signature to each of the validity proof information and the authenticated user information, and transmitting the validity proof information and the authenticated user information with the digital signature attached to the server device.
[0225] [Supplementary Note 20] A control method for a terminal described in any one of Supplementary Notes 15 to 18, wherein the acquisition step acquires passport information related to a passport held by the person to be authenticated, a facial image of the person to be authenticated, a fingerprint image of the person to be authenticated, and a verification image that enables verification of whether or not fraud has occurred when the facial image and the fingerprint image are acquired, and the control step transmits the person to be authenticated information including the passport information, the facial image, the fingerprint image, and the verification image to the server device.
[0226] [Supplementary Note 21] The method for controlling a terminal described in Supplementary Note 15, wherein the acquisition step acquires biometric information of the person to be authenticated who is leaving a first country and attempting to enter a second country, and the control step transmits the validity proof information including location information of the terminal acquired within the territorial waters of the second country to the server device.
[0227] [Supplementary Note 22] A computer-readable storage medium storing a program for causing a computer mounted on a terminal to execute: an acquisition process for acquiring biometric information of a person to be authenticated; and a control process for requesting a server device that performs biometric authentication to authenticate the person to be authenticated by transmitting, to the server device, person to be authenticated information regarding the person to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the terminal.
[0228] [Supplementary Note 23] The storage medium according to Supplementary Note 22, wherein the control process transmits the validity proof information including at least one of a product name, a manufacturer, a hardware ID, a name of an application, and a version of the application to the server device.
[0229] [Supplementary Note 24] The storage medium according to Supplementary Note 22, wherein the control process transmits the validity proof information including at least one of the name and biometric information of an installer of the terminal to the server device.
[0230] [Supplementary Note 25] The storage medium according to Supplementary Note 22, wherein the control process transmits the validity proof information including location information of the terminal to the server device.
[0231] [Appendix 26] The storage medium according to any one of Appendices 22 to 25, wherein the control process adds a digital signature to each of the validity proof information and the authenticated user information, and transmits the validity proof information and the authenticated user information with the digital signature attached to the server device.
[0232] [Appendix 27] The storage medium described in any one of Appendices 22 to 25, wherein the acquisition process acquires passport information related to a passport held by the person to be authenticated, a facial image of the person to be authenticated, a fingerprint image of the person to be authenticated, and a verification image that enables verification of whether or not fraud has occurred when the facial image and the fingerprint image are acquired, and the control process transmits the person to be authenticated information including the passport information, the facial image, the fingerprint image, and the verification image to the server device.
[0233] [Appendix 28] The storage medium described in Appendix 22, wherein the acquisition process acquires biometric information of the person to be authenticated who is leaving a first country and attempting to enter a second country, and the control process transmits the validity proof information including location information of the person's own terminal acquired within the territorial waters of the second country to the server device.
[0234] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 7 that are dependent on Supplementary Note 1 above may also be dependent on Supplementary Notes 8, 15, and 22 in the same dependent relationship as Supplementary Notes 2 to 7. Furthermore, not limited to Supplementary Notes 1, 8, 15, and 22, some or all of the configurations described as Supplements may be made dependent on various hardware, software, various recording means for recording software, or systems, within the scope of each of the above-mentioned embodiments.
[0235] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.
[0236] 10 Server device 20 Authentication device 20-1 Authentication terminal 20-2 Authentication terminal 21 Camera 22 Scanner 23 Fingerprint scanner 24 Camera 30 Ship 40 Terminal 100 Terminal 101 Acquisition means 102 Control means 201 Communication control unit 202 Terminal information control unit 203 Authenticated person information control unit 204 Preliminary examination control unit 205 Storage unit 301 Communication control unit 302 Preliminary examination control unit 303 Authentication control unit 304 Storage unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 401 Communication control unit 402 Biometric information acquisition unit 403 Authentication control unit 404 Storage unit
Claims
an acquisition means for acquiring biometric information of a person to be authenticated; a control means for transmitting to a server device that performs biometric authentication, user information regarding the user to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the user's own terminal, thereby requesting the server device to authenticate the user to be authenticated; A terminal comprising:
2. The terminal according to claim 1, wherein the control means transmits the validity certification information to the server device, the validity certification information including at least one of a product name, a manufacturer, a hardware ID, an application name, and a version of the application.
2. The terminal according to claim 1, wherein the control means transmits the validity proof information including at least one of the name and biometric information of an installer of the terminal to the server device. The terminal according to claim 1 , wherein the control means transmits the validity proof information including location information of the terminal to the server device.
5. The terminal according to claim 1, wherein the control means assigns a digital signature to each of the validity proof information and the authenticated user information, and transmits the validity proof information and the authenticated user information with the digital signature attached to the server device. the acquiring means acquires passport information relating to a passport held by the person to be authenticated, a face image of the person to be authenticated, a fingerprint image of the person to be authenticated, and a verification image that enables verification of whether or not fraud has occurred when the face image and the fingerprint image are acquired; 5. The terminal according to claim 1, wherein the control means transmits the user information including the passport information, the face image, the fingerprint image, and the verification image to the server device. the acquiring means acquires biometric information of the person to be authenticated who is leaving a first country and intends to enter a second country; The terminal according to claim 1 , wherein the control means transmits the validity proof information including location information of the terminal acquired within the territorial waters of the second country to the server device. a server device that performs biometric authentication; A terminal and Including, The terminal an acquisition means for acquiring biometric information of a person to be authenticated; a control means for transmitting to the server device user information relating to the user to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the user's own terminal, thereby requesting the server device to authenticate the user to be authenticated; A system comprising: an acquisition step of acquiring biometric information of the person to be authenticated; a control step of transmitting to a server device that performs biometric authentication, user information regarding the user to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the user's own terminal, thereby requesting the server device to authenticate the user to be authenticated; A method for controlling a terminal, comprising: The computer installed in the device an acquisition process for acquiring biometric information of the person to be authenticated; a control process of transmitting to a server device that performs biometric authentication, user information regarding the user to be authenticated, including the acquired biometric information, and validity certification information for verifying the validity of the user's own terminal, thereby requesting the server device to authenticate the user to be authenticated; A computer-readable storage medium that stores a program for executing the above.
Citation Information
Patent Citations
Identification system and apparatus
JP2003143136A
A handheld portable device for verifying travel documents and personal documents, reading biometric data, and verifying the identity of the document holder.
JP2012528379A
Methods of enrolling and authenticating user in authentication system, facial authentication system, and methods of authenticating user in authentication system
JP2016051482A
Applicant authentication device and authentication method, and security authentication system using the method
JP2017102684A