Information processing device, information processing method, and recording medium

The information processing apparatus effectively associates biometric information with affiliated groups and authentication devices, enhancing user access control and security by ensuring only relevant authentication results are accessible to authorized administrators.

WO2026069547A1PCT designated stage Publication Date: 2026-04-02NEC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing technologies for managing authentication devices at the edge and in the cloud do not effectively associate biometric information with affiliated groups and manage authentication results, leading to inefficiencies in user access control and security.

Method used

An information processing apparatus and method that stores biometric information in association with affiliated groups and authentication devices, allowing for the output of authentication results specific to user groups, while preventing unauthorized access to non-relevant information.

Benefits of technology

Enhances user access control by ensuring only relevant authentication results are visible to authorized administrators, improving security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024034508_02042026_PF_FP_ABST
    Figure JP2024034508_02042026_PF_FP_ABST
Patent Text Reader

Abstract

This information processing device comprises: a first storage means that stores registered biometric information of a person to be authenticated in association with at least one affiliation group to which the person to be authenticated belongs; and a second storage means that stores a result of biometric authentication based on biometric information of the person to be authenticated and the registered biometric information in association with information indicating an authentication device that has performed the biometric authentication. Each of at least one authentication device is associated with the at least one affiliation group, and comprises: an acquisition means that acquires identification information of a user; and an output means that outputs a result of biometric authentication of the person to be authenticated belonging to a user affiliation group, the biometric authentication having been performed in the at least one authentication device associated with the user affiliation group corresponding to the identification information of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Information Processing Apparatus, Information Processing Method, and Recording Medium

[0001] This disclosure relates to the technical field of information processing apparatuses, information processing methods, and recording media.

[0002] Technologies for managing authentication devices at the edge and master information in the cloud are known. For example, Patent Document 1 discloses managing feature data in units of authentication groups in the cloud.

[0003] Japanese Patent Application Laid-Open No. 2020-126340

[0004] An object of this disclosure is to provide an information processing apparatus, an information processing method, and a recording medium for improving the related technologies described above.

[0005] One aspect of the information processing apparatus of this disclosure includes: a first storage means for storing registered biometric information of an authentication target person in association with at least one affiliated group to which the authentication target person belongs; and a second storage means for storing the result of biometric authentication based on the biometric information of the authentication target person and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication. Each of at least one authentication device is associated with at least one of the affiliated groups, and includes an acquisition means for acquiring identification information of a user, and an output means for outputting the result of biometric authentication of an authentication target person belonging to the user affiliated group, which is the biometric authentication performed in the at least one authentication device associated with the user affiliated group corresponding to the identification information of the user.

[0006] One aspect of the information processing method of this disclosure includes storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs, and storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups, and includes obtaining user identification information, and outputting the result of biometric authentication performed at the at least one authentication device associated with the user's group to which the user's identification information belongs, and of a person to be authenticated belonging to the user's group, and is executed by a computer.

[0007] One aspect of the recording medium of this disclosure includes storing registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs, and storing the result of biometric authentication based on the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups, and records a computer program that causes a computer to execute an information processing method which includes acquiring user identification information and outputting the result of biometric authentication performed at the at least one authentication device associated with the user's group to which the user belongs, and which is a biometric authentication of a person to be authenticated who belongs to the user's group.

[0008] This is a block diagram illustrating an example of the configuration of the information processing device related to this disclosure. This is a flowchart illustrating an example of the flow of information processing operations in the information processing device related to this disclosure. This is a block diagram illustrating an example of the configuration of the information processing device related to this disclosure. This is a block diagram illustrating an example of a scenario in which the information processing device related to this disclosure is applied. This is a flowchart illustrating an example of the flow of information processing operations in the information processing device related to this disclosure. This is a diagram illustrating an example of information processing operations in the information processing device related to this disclosure. This is a diagram illustrating an example of information processing operations in the information processing device related to this disclosure. This is a diagram illustrating an example of information processing operations in the information processing device related to this disclosure. This is a block diagram illustrating an example of the configuration of the information processing device related to this disclosure. This is a diagram illustrating an example of information processing operations in the information processing device related to this disclosure. This is a block diagram illustrating an example of information processing operations in the information processing device related to this disclosure. This is a block diagram illustrating an example of the configuration of the information processing device related to this disclosure.

[0009] The following describes embodiments of the information processing apparatus, information processing method, and recording medium with reference to the drawings. [1: First Embodiment]

[0010] A first embodiment relating to an information processing device, an information processing method, and a recording medium will be described with reference to Figures 1 and 2. In the following description, the first embodiment relating to an information processing device, an information processing method, and a recording medium will be described using the information processing device 10.

[0011] As shown in Figure 1, the information processing device 10 comprises a first storage unit 11, a second storage unit 12, an acquisition unit 13, and an output unit 14. The operations performed by the information processing device 10 will be explained with reference to the flowchart in Figure 2.

[0012] As shown in Figure 2, the first storage unit 11 stores the biometric information of the person to be authenticated, associating it with at least one group to which the person belongs (step S11). The biometric information stored by the first storage unit 11 is referred to as "registered biometric information".

[0013] The person being authenticated may be the person subject to biometric authentication. Biometric authentication may include a process of verifying biometric information.

[0014] Biometric information refers to information about the physical characteristics of the person being authenticated. Examples of biometric information include facial images of the person being authenticated, iris images of the person's iris, fingerprint images of the person's fingerprints, palm print images of the person's palm prints, vein images of the person's fingers and palms, and at least one of these, as well as voice information including the person's voice.

[0015] The person being authenticated must belong to at least one group. The person being authenticated may belong to one or more groups.

[0016] Biometric authentication of the person to be authenticated is performed by at least one authentication device. Each of the at least one authentication device is associated with at least one affiliated group. In other words, the authentication device that performs biometric authentication of a person to be authenticated who belongs to a certain affiliated group is predetermined. A person to be authenticated who belongs to a certain affiliated group may be biometrically authenticated by at least one authentication device that is pre-associated with that affiliated group. The affiliated group associated with an authentication device may be called the authenticated group.

[0017] The second storage unit 12 stores the results of the biometric authentication of the person to be authenticated, in association with information indicating the authentication device that performed the biometric authentication (step S12). Biometric authentication is performed based on the biometric information of the person to be authenticated and the registered biometric information.

[0018] The acquisition unit 13 acquires the user's identification information (step S13). The user may be, for example, a person who manages the authenticated persons belonging to the group to which the user belongs. The user may also be a person who has the authority to view the biometric authentication results of authenticated persons in order to manage the authenticated persons belonging to the group to which they belong.

[0019] The output unit 14 outputs the biometric authentication results of the person to be authenticated who belongs to the group corresponding to the user's identification information (step S14). The group corresponding to the user's identification information is referred to as the "user group." The biometric authentication results output by the output unit 14 are the results of biometric authentication performed at at least one authentication device associated with the user group. In other words, the output unit 14 outputs the biometric authentication results performed at at least one authentication device associated with the user group, and also the biometric authentication results of the person to be authenticated who belongs to the user group.

[0020] Thus, the information processing device 10 includes storing the registered biometric information of the person to be authenticated in association with at least one group to which the person to be authenticated belongs, and storing the result of biometric authentication based on the person to be authenticated's biometric information and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication. Each of the at least one authentication device is associated with at least one group to which the person to be authenticated belongs, and the information processing method includes obtaining the user's identification information and outputting the result of biometric authentication performed on at least one authentication device associated with the user's group to which the user belongs, and of the person to be authenticated belonging to the user's group.

[0021] The information processing device 10 described above may be implemented by a computer reading a computer program recorded on a recording medium. In this case, the computer program includes storing the registered biometric information of the person to be authenticated in association with at least one group to which the person to be authenticated belongs, and storing the result of biometric authentication based on the person to be authenticated's biometric information and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, and each of the at least one authentication device is associated with at least one group to which the person to be authenticated belongs, and may be made to execute an information processing method that includes acquiring the user's identification information and outputting the result of biometric authentication of the person to be authenticated who belongs to the user's group, which was performed at at least one authentication device associated with the user's group to which the user's identification information belongs. [Technical Effects] The information processing device 10 according to this disclosure can be configured so that a user can confirm the result of biometric authentication of a person to be authenticated who is associated with the user, but cannot confirm the result of biometric authentication of a person to be authenticated who is not associated with the user. [2: Second Embodiment]

[0022] A second embodiment relating to the information processing device, information processing method, and recording medium will be described with reference to Figures 3 to 10. Hereinafter, the second embodiment relating to the information processing device, information processing method, and recording medium will be described using the information processing device 20. Note that from the second embodiment onward, the description will be based on the case where the biometric information is a facial image and the biometric authentication is facial authentication. Furthermore, in the second embodiment, explanations that overlap with the description of the first embodiment described above will be omitted as appropriate. [2-1: Configuration of the Information Processing Device 20]

[0023] The configuration of the information processing device 20 will be explained with reference to Figure 3. Figure 3 is a block diagram showing the configuration of the information processing device 20.

[0024] As shown in Figure 3, the information processing device 20 comprises an arithmetic unit 21 and a storage device 22. Furthermore, the information processing device 20 may also include a communication device 23, an input device 24, and an output device 25. However, the information processing device 20 does not have to include the communication device 23 and at least one of the input device 24 and the output device 25. The arithmetic unit 21, the storage device 22, the communication device 23, the input device 24, and the output device 25 may be connected via a data bus 26.

[0025] The arithmetic unit 21 includes at least one processor (i.e., one or more processors) as hardware. The processor may include, for example, a processor conforming to a von Neumann computer architecture. A processor conforming to a von Neumann computer architecture may include at least one of a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit). The processor may also include, for example, a processor conforming to a non-von Neumann computer architecture. A processor conforming to a non-von Neumann computer architecture may include at least one of an FPGA (Field Programmable Gate Array) and an ASIC (Application Specific Circuit).

[0026] The arithmetic unit 21 reads a computer program 220 which includes at least one of computer program code and computer program instructions. For example, the arithmetic unit 21 may read a computer program 220 stored in a storage device 22. For example, the arithmetic unit 21 may read a computer program 220 stored in a computer-readable and non-temporary recording medium using a recording medium reader (not shown) provided in the information processing device 20. The computer program 220 read from the recording medium may be stored in the storage device 22. The arithmetic unit 21 may obtain (i.e., download or read) a computer program 220 from a device (not shown) located outside the information processing device 20 via a communication device 23 (or other communication device). The downloaded computer program 220 may be stored in the storage device 22.

[0027] The arithmetic unit 21 executes the loaded computer program 220. As a result, logical functional blocks for executing the information processing that the information processing device 20 should perform are realized within the arithmetic unit 21. In other words, the arithmetic unit 21, together with the storage device 22 on which the computer program 220 is recorded (in other words, together with the storage device 22 and the computer program 220 recorded in the storage device 22), can function as a controller or computer for realizing logical functional blocks for executing the processing that the information processing device 20 should perform. That is, together with at least one processor in the arithmetic unit 21, the memory (recording medium) in the storage device 22 and the computer program 220 are configured so that the information processing device 20 performs the information processing that the information processing device 20 should perform.

[0028] Furthermore, the recording medium for recording the computer program 220 executed by the arithmetic unit 21 may include at least one of the following: optical discs such as CD-ROM, CD-R, CD-RW, flexible disk, MO, DVD-ROM, DVD-RAM, DVD-R, DVD+R, DVD-RW, DVD+RW, and Blu-ray (registered trademark); magnetic media such as magnetic tape; magneto-optical disks; semiconductor memory such as USB memory; and any other medium capable of storing a program. The recording medium may also include equipment capable of recording computer programs (for example, general-purpose or dedicated equipment on which the computer program 220 is implemented in an executable state in at least one form such as software and firmware). Furthermore, each process and function included in the computer program 220 may be implemented by logical processing blocks realized within the arithmetic unit 21 (i.e., the processor) when the arithmetic unit 21 executes the computer program 220, or by hardware such as a predetermined gate array (FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit)) provided by the arithmetic unit 21, or in a form in which logical processing blocks and partial hardware modules that realize some elements of the hardware are mixed.

[0029] The storage device 22 includes at least one memory capable of storing desired data. In other words, the storage device 22 includes at least one memory containing desired data. For example, the storage device 22 may store a computer program 220 executed by the arithmetic unit 21. In this case, the storage device 22 (memory) may be used as the recording medium described above for recording the computer program 220 executed by the arithmetic unit 21. The storage device 22 may temporarily store data that the arithmetic unit 21 temporarily uses when the arithmetic unit 21 is executing the computer program 220. The storage device 22 may store data that the information processing device 20 stores long-term. The storage device 22 may include at least one of RAM (Random Access Memory), ROM (Read Only Memory), hard disk drive, magneto-optical disk drive, SSD (Solid State Drive), and disk array drive. In other words, the storage device 22 may include a recording medium that is not temporary.

[0030] The first storage unit 221 and the second storage unit 222 may be implemented within the storage device 22. However, the first storage unit 221 and the second storage unit 222 may be implemented in a storage device other than the storage device 22. For example, the first storage unit 221 and the second storage unit 222 may be implemented in a storage device provided by an external device of the information processing device 20. The following describes the case where the first storage unit 221 and the second storage unit 222 are implemented within the storage device 22.

[0031] The communication device 23 may be capable of communicating with devices outside the information processing device 20. The communication device 23 may use either wired or wireless communication.

[0032] The input device 24 is a device capable of receiving information input to the information processing device 20 from an external source. The input device 24 may include an operating device (e.g., a keyboard, mouse, touch panel, etc.) that can be operated by the user of the information processing device 20. The input device 24 may include a recording medium reader capable of reading information recorded on a recording medium that can be attached to and detached from the information processing device 20, such as a USB (Universal Serial Bus) memory. When information is input to the information processing device 20 via the communication device 23 (in other words, when the information processing device 20 acquires information via the communication device 23), the communication device 23 may function as an input device.

[0033] The output device 25 is a device capable of outputting information to the outside of the information processing device 20. The output device 25 may output visual information such as characters and images, auditory information such as sounds, or tactile information such as vibrations. The output device 25 may include, for example, at least one of a display, a speaker, a printer, and a vibration motor. The output device 25 may also be capable of outputting information to a recording medium that can be attached to or detached from the information processing device 20, such as a USB memory stick. When the information processing device 20 outputs information via the communication device 23, the communication device 23 may function as an output device.

[0034] Figure 3 shows an example of a logical functional block implemented within the arithmetic unit 21 to perform facial recognition. As shown in Figure 3, the arithmetic unit 21 may also implement an acquisition unit 213, an output unit 214, and a reception unit 215. The "first storage unit 221" is a component corresponding to the "first storage unit 11" in the first embodiment described above, the "second storage unit 222" is a component corresponding to the "second storage unit 12" in the first embodiment described above, the "acquisition unit 213" is a component corresponding to the "acquisition unit 13" in the first embodiment described above, and the "output unit 214" is a component corresponding to the "output unit 14" in the first embodiment described above. Note that if the information processing device 20 is configured on a cloud (IaaS), etc., "hardware" may be "virtual hardware". [2-2: Overview of scenarios in which the information processing device 20 is applied]

[0035] In this embodiment, the person to be authenticated may be permitted to enter and exit a predetermined area, for example, by facial recognition. In this embodiment, facial recognition may be rephrased as being performed to determine whether or not to permit the person to enter and exit the predetermined area by matching facial images. For example, in this embodiment, if facial recognition of the person to be authenticated is successful, it may be determined that the person to enter and exit the predetermined area is permitted. Also, in this embodiment, if facial recognition of the person to be authenticated fails, it may be determined that the person to enter and exit the predetermined area is not permitted.

[0036] For example, this embodiment may be applied to managing entry and exit to an office building where a company with multiple business divisions is located. In this case, as illustrated in Figure 4, the entire interior of the office building may be designated as the first predetermined area 1000. Alternatively, the area used by business division A may be designated as the second predetermined area 100A. Furthermore, the area used by business division B may be designated as the second predetermined area 100B.

[0037] Each of the designated areas may be associated with an authentication device. Hereinafter, an authentication device associated with a designated area will be referred to as an "edge device". As illustrated in Figure 4, an edge device 100 may be provided at the entrance 100C of the first designated area 1000. The edge device 100 may determine, by facial recognition, whether a person attempting to enter the first designated area 1000 is a person who is permitted to enter the first designated area 1000. The persons whom the edge device 100 determines to be permitted to enter the first designated area 1000 may be predetermined. The edge device 100 may determine that persons belonging to the group associated with the edge device 100 (i.e., the authentication target group described above) are persons who are permitted to enter the first designated area 1000. In other words, the edge device 100 may determine, by facial recognition, whether a person is within the management scope of the edge device 100. Alternatively, the edge device 100 may be described as allowing persons within the management range of the edge device 100 to enter and exit the first predetermined area 1000 by facial recognition.

[0038] In this embodiment, a group may be a group of individuals whose entry and exit to a predetermined area are managed by the same administrator. In other words, individuals belonging to the same group may have their entry and exit to a predetermined area managed by the same administrator. Furthermore, an administrator may be associated with a group. The administrator may manage the entry and exit to a predetermined area for individuals belonging to the associated group. That is, the user described above may be an administrator associated with a group.

[0039] An edge device 10A may be provided at the entrance / exit of the second designated area 100A. The edge device 10A may determine, by facial recognition, whether a person attempting to enter the second designated area 100A is permitted to enter the second designated area 100A. The persons that the edge device 10A determines to be permitted to enter the second designated area 100A may be predetermined. The edge device 10A may determine that individuals belonging to the group associated with the edge device 10A are permitted to enter the second designated area 100A. In other words, the edge device 10A may determine, by facial recognition, whether a person is within the management scope of the edge device 10A. Alternatively, the edge device 10A may permit individuals within the management scope of the edge device 10A to enter or exit the second designated area 100A by facial recognition.

[0040] The group associated with edge device 10A may be a group of individuals belonging to business unit A. The group of individuals belonging to business unit A will be referred to as "Group A". Authenticated individuals belonging to Group A may have their entry and exit from the second designated area 100A managed by administrator A. Group A can be rephrased as a group of authenticated individuals managed by administrator A. Administrator A may be associated with Group A. Furthermore, the group of authenticated individuals associated with edge device 10A may be Group A.

[0041] Similarly, edge devices 10B may be provided at the entrance and exit of the second designated area 100B. The edge device 10B may determine, by facial recognition, whether a person attempting to enter the second designated area 100B is permitted to enter the second designated area 100B. The persons that the edge device 10B determines to be permitted to enter the second designated area 100B may be predetermined. The edge device 10B may determine that individuals belonging to the group associated with the edge device 10B are permitted to enter the second designated area 100B. In other words, the edge device 10B may determine, by facial recognition, whether a person is within the management scope of the edge device 10B. Alternatively, the edge device 10B may permit individuals within the management scope of the edge device 10B to enter and exit the second designated area 100B by facial recognition.

[0042] The group associated with edge device 10B may be a group of individuals belonging to business unit B. The group of individuals belonging to business unit B will be referred to as "Group B". Authenticated individuals belonging to Group B may have their entry and exit to the second designated area 100B managed by administrator B. Group B can also be described as a group of authenticated individuals managed by administrator B. Administrator B may be associated with Group B. Furthermore, the group of authenticated individuals associated with edge device 10B may be Group B.

[0043] In the case illustrated in FIG. 4, the first predetermined area 1000 includes the second predetermined area 100A and the second predetermined area 100B. Therefore, an authentication target person belonging to the affiliated group A permitted to enter and exit the second predetermined area 100A may be permitted to enter and exit the first predetermined area 1000. Similarly, an authentication target person belonging to the affiliated group B permitted to enter and exit the second predetermined area 100B may be permitted to enter and exit the first predetermined area 1000. Therefore, the authentication target group associated with the edge device 100 associated with the first predetermined area 1000 may be the affiliated group A and the affiliated group B. The authentication target person belonging to the affiliated group A may be managed by the administrator A for entering and exiting the first predetermined area 1000. Similarly, the authentication target person belonging to the affiliated group B may be managed by the administrator B for entering and exiting the first predetermined area 1000. The information processing device 20 may be a device for presenting the face authentication result of the authentication target person belonging to the affiliated group corresponding to the administrator to the administrator. [2-3: Information Processing Method Executed by the Information Processing Device 20]

[0044] Referring to FIGS. 5 to 10, the information processing method executed by the information processing device 20 will be described. FIG. 5 is a flowchart showing an example of the flow of the information processing method executed by the information processing device 20. FIGS. 6 to 10 are diagrams for explaining the information processing method executed by the information processing device 20.

[0045] As shown in FIG. 5, the reception unit 215 receives the setting of the affiliated group (step S21). The reception unit 215 may receive the setting of the affiliated group from, for example, the person in charge of the office building. The reception unit 215 may receive the setting of the affiliated group via the input device 24. The reception unit 215 may store the received setting of the affiliated group in, for example, the storage device 22.

[0046] The reception unit 215 receives information indicating the assignment of an administrator to the affiliated group (step S22). The reception unit 215 may receive information indicating the assignment of an administrator to the affiliated group from, for example, the person in charge of the office building. The reception unit 215 may receive information indicating the assignment of an administrator to the affiliated group via the input device 24. The reception unit 215 may store the received information indicating the assignment of an administrator to the affiliated group in, for example, the storage device 22. FIG. 6 illustrates a case where administrator A is assigned to affiliated group A and administrator B is assigned to affiliated group B.

[0047] The reception unit 215 receives information indicating the association between the edge device and the affiliated group (step S23). The reception unit 215 may receive information indicating the association between the edge device and the affiliated group from, for example, the person in charge of the office building. The reception unit 215 may receive information indicating the association between the edge device and the affiliated group via the input device 24. The reception unit 215 may store the received information indicating the association between the edge device and the affiliated group in, for example, the storage device 22.

[0048] In the case illustrated in FIG. 4, the edge device 100 may be associated with affiliated group A and affiliated group B. Also, the edge device 10A may be associated with affiliated group A. Also, the edge device 10B may be associated with affiliated group B.

[0049] The reception unit 215 receives the face image of the authentication target person in association with information indicating at least one affiliated group to which the authentication target person belongs. The first storage unit 221 stores the face image of the authentication target person received by the reception unit 215 as a registered face image in association with at least one affiliated group to which the authentication target person belongs (step S24).

[0050] Figure 7 illustrates a case where the registered facial images of authenticated person X and authenticated person Y are stored in association with their respective group A, and the registered facial images of authenticated person Y and authenticated person Z are stored in association with their respective group B. In other words, Figure 7 illustrates a case where authenticated person X belongs to group A, authenticated person Y belongs to both group A and group B, and authenticated person Z belongs to group B.

[0051] The edge device performs facial recognition of a person attempting to enter or exit a designated area corresponding to the edge device. The edge device may perform facial recognition by acquiring the face image of the person to be recognized and comparing the face image of the person to be recognized with a registered face image associated with the group of people to be recognized on the edge device. The edge device may identify who the person to be recognized is through facial recognition and identify the group to which the person to be recognized belongs from at least one group associated with the registered face image.

[0052] The second storage unit 222 stores the results of face authentication based on the face image of the person to be authenticated and the registered face image, in association with information indicating the edge device that performed the face authentication (step S25). The second storage unit 222 may also store the results of face authentication based on the face image of the person to be authenticated and the registered face image for each edge device.

[0053] If facial recognition is successful, the second storage unit 222 may store the identified person to be authenticated and the identified group to which they belong, in association with information indicating the edge device that performed the facial recognition. In other words, the second storage unit 222 stores information indicating which group to which person to be authenticated was successfully authenticated on a given edge device.

[0054] Figure 8 shows an example of information stored in the second storage unit 222. As illustrated in Figure 8, the second storage unit 222 may store a record number that identifies facial recognition, information that identifies the edge device, information that indicates the authentication target group of the edge device, information that indicates the facial recognition result, information that identifies the identified authentication target person, and information that identifies the group to which the identified authentication target person belongs. The second storage unit 222 may store information other than the information illustrated in Figure 8. For example, the second storage unit 222 may store information indicating the date and time when facial recognition was performed. The second storage unit 222 may also store information that can distinguish whether the authentication target person is about to enter or leave. In this embodiment, the case in which the information processing device 20 is applied to the management of entry into and exit from a predetermined area is described, but the information processing device 20 may be applied only to the management of entry into a predetermined area, or the information processing device 20 may be applied only to the management of exit from a predetermined area.

[0055] Figure 8 illustrates the record when authenticated persons X, Y, and Z successfully undergo facial recognition by the edge device 100 and enter the first predetermined area 1000. Figure 8 also illustrates the record when authenticated persons X and Y successfully undergo facial recognition by the edge device 10A and enter the second predetermined area 100A. Figure 8 also illustrates the record when authenticated person Z successfully undergoes facial recognition by the edge device 10B and enters the second predetermined area 100B. Figure 8 also illustrates the record when authenticated person Y further successfully undergoes facial recognition by the edge device 10B and enters the second predetermined area 100B.

[0056] The acquisition unit 213 acquires the administrator's identification information (step S26). The administrator's identification information may be, for example, an image of the administrator's face. The administrator's identification information may also be stored on a storage medium carried by the administrator. In this case, the acquisition unit 213 may acquire the identification information stored on the storage medium using a reader for the storage medium.

[0057] The output unit 214 outputs the results of facial recognition performed on at least one edge device associated with the administrator's group, and the results of facial recognition of the person to be authenticated who belongs to the administrator's group (step S27). The output unit 214 may output only the results of facial recognition performed on at least one edge device associated with the administrator's group, and the results of facial recognition of the person to be authenticated who belongs to the administrator's group. In this case, when the acquisition unit 213 acquires the identification information of administrator A, the output unit 214 may output only the results of facial recognition performed on edge devices 100 and 10A associated with group A, and the results of facial recognition of the person to be authenticated who belongs to group A. For example, when the acquisition unit 213 acquires the identification information of administrator A, as illustrated in Figure 9, the output unit 214 may cause the output device 25 to output information 25A of record numbers "1", "2", "4", and "5" as illustrated in Figure 8. Furthermore, if the acquisition unit 213 acquires the identification information of administrator B, the output unit 214 may output the information 25B of record numbers "2", "3", "6", and "7" as illustrated in Figure 8 to the output device 25, as illustrated in Figure 9.

[0058] Alternatively, the output unit 214 may output all facial recognition results, with all information except for the facial recognition results of the person being authenticated who belongs to the administrator's group, which were performed on at least one edge device associated with the administrator's group. In this case, for example, when the acquisition unit 213 acquires the identification information of administrator A, the output unit 214 may output information 25A to the output device 25, with all information except for the record numbers "1", "2", "4", and "5" illustrated in Figure 8 blacked out, as illustrated in Figure 10. Also, when the acquisition unit 213 acquires the identification information of administrator B, the output unit 214 may output information 25B to the output device 25, with all information except for the record numbers "2", "3", "6", and "7" illustrated in Figure 8 blacked out, as illustrated in Figure 10.

[0059] Each of at least one affiliated group may be associated with the identification information of an administrator who can view the facial recognition results of the authenticated individuals belonging to at least one affiliated group. The output unit 214 may output facial recognition results that can be viewed by the administrator based on the administrator's identification information. [2-4: Technical Effects]

[0060] The information processing device 20 disclosed herein allows the administrator to check the results of facial recognition of authenticated individuals under the administrator's management, but prevents the administrator from checking the results of facial recognition of authenticated individuals outside of the administrator's management. [3: Third Embodiment]

[0061] A third embodiment relating to an information processing device, an information processing method, and a recording medium will be described with reference to Figures 11 to 13. In the following description, the third embodiment relating to an information processing device, an information processing method, and a recording medium will be described using the information processing device 30. In the third embodiment, explanations that overlap with the descriptions of the first and second embodiments described above will be omitted as appropriate. In the drawings, parts common to the first and second embodiments will be denoted by the same reference numerals.

[0062] As shown in Figure 11, the arithmetic unit 21 of the information processing device 30 includes, as logical functional blocks, an acquisition unit 213, an output unit 314, and a reception unit 215.

[0063] In this embodiment, if facial recognition fails, the second storage unit 322 may store the facial image used for facial recognition in association with information indicating the edge device that performed the facial recognition. Figure 12 shows an example of information stored in the second storage unit 322. As illustrated in Figure 12, if facial recognition fails (NG), the person to be authenticated cannot be identified, so the second storage unit 322 may store the facial image itself as information to identify the person to be authenticated. Also, if facial recognition fails (NG), the person to be authenticated cannot be identified, so the group to which they belong becomes unknown.

[0064] Figure 12 illustrates a case where facial recognition using "face image 1" at the edge device 100 failed (NG), and therefore a record of facial recognition identified by record number "4," which associates the edge device 100 with "face image 1," is stored in the second storage unit 322. Figure 12 also illustrates a case where facial recognition using "face image 1" at the edge device 100 failed (NG), and therefore a record of facial recognition identified by record number "7," which associates the edge device 100 with "face image 1," is stored in the second storage unit 322. Facial recognition identified by different record numbers represents different facial recognition. In other words, Figure 12 illustrates that the person in "face image 1" has failed facial recognition twice at the edge device 100.

[0065] Furthermore, Figure 12 illustrates a record of the case when authentication target X, authentication target Y, and authentication target Z successfully undergo facial recognition by edge device 100 and enter the first predetermined area 1000. Also, Figure 12 illustrates a record of the case when authentication target X and authentication target Y successfully undergo facial recognition by edge device 10A and enter the second predetermined area 100A. Also, Figure 12 illustrates a record of the case when authentication target Z successfully undergoes facial recognition by edge device 10B and enters the second predetermined area 100B. Also, Figure 12 illustrates a record of the case when authentication target Y further successfully undergoes facial recognition by edge device 10B and enters the second predetermined area 100B.

[0066] In this embodiment, the output unit 314 may output information regarding successful facial recognition of an authenticated person belonging to the administrator's group, as well as information regarding the failure of facial recognition on the at least one edge device associated with the administrator's group. For example, if the acquisition unit 213 acquires the identification information of administrator A, the output unit 314 may output information 25A of record numbers "1", "2", "4", "5", "6", and "7" as illustrated in Figure 12 to the output device 25, as illustrated in Figure 13. Also, if the acquisition unit 213 acquires the identification information of administrator B, the output unit 314 may output information 25B of record numbers "2", "3", "4", "7", "8", and "9" as illustrated in Figure 12 to the output device 25, as illustrated in Figure 13. Alternatively, similar to the second embodiment, the output unit 314 may output all facial recognition results, while concealing information other than information regarding the success of facial recognition of an authenticated person belonging to the administrator's group, and information other than information regarding the failure of facial recognition on the at least one edge device associated with the administrator's group. [Technical Effects]

[0067] The information processing device 30 disclosed herein can notify the administrator of information regarding the failure of facial recognition on an edge device that performs facial recognition on an authenticated person under the administrator's management. [4: Fourth Embodiment]

[0068] A fourth embodiment relating to an information processing device, an information processing method, and a recording medium will be described with reference to Figure 14. In the following description, the fourth embodiment relating to an information processing device, an information processing method, and a recording medium will be described using the information processing device 40. In the fourth embodiment, explanations that overlap with the descriptions of the first to third embodiments described above will be omitted as appropriate. In the drawings, parts common to the first to third embodiments will be denoted by the same reference numerals.

[0069] As shown in Figure 12, the arithmetic unit 21 of the information processing device 40 includes, as logical functional blocks, an acquisition unit 213, an output unit 214, a reception unit 215, and a registration unit 416.

[0070] The registration unit 416 registers a face image in the attention list if the number of face images stored in the second storage unit 322 that are the same as a face image used in a failed face recognition attempt (a face image used in a failed face recognition attempt is referred to as a "failed face image") exceeds a predetermined number. A face image that is the same as a failed face image may be a face image whose similarity to a failed face image exceeds a predetermined value.

[0071] The watchlist could be, for example, a list viewed by the security personnel in charge of office building security. Furthermore, each edge device may notify the office building security personnel if it successfully performs facial recognition against any of the registered facial images on the watchlist. [Technical Effects]

[0072] The information processing device 40 related to this disclosure can manage a person who may have malicious intent. [5: Note]

[0073] The embodiments described above may also be described as follows, but are not limited thereto. [Note 1] An information processing apparatus comprising: a first storage means for storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs; a second storage means for storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups; an acquisition means for acquiring user identification information; and an output means for outputting the result of biometric authentication performed on the at least one authentication device associated with the user's group to which the user's group to which the user belongs, and the result of biometric authentication of a person to be authenticated belonging to the user's group. [Note 2] The information processing apparatus according to Note 1, wherein, if the biometric authentication is successful, the second storage means stores the result of biometric authentication in association with at least one group to which the registered biometric information belongs and information indicating the authentication device that performed the biometric authentication. [Note 3] The information processing apparatus according to Note 2, wherein the second storage means stores, in the event that the biometric authentication fails, the biometric information used for the biometric authentication and information indicating the authentication device that performed the biometric authentication in association with each other. [Note 4] The information processing apparatus according to Note 3, wherein the output means outputs information regarding the success of biometric authentication of an authenticated person belonging to the user group, and information regarding the failure of biometric authentication at the at least one authentication device associated with the user group, for biometric authentication performed at the at least one authentication device associated with the user group. [Note 5] The information processing apparatus according to Note 3, further comprising a registration means for registering the failed biometric information in a caution list when the number of biometric pieces of information stored in the second storage means that are the same as the failed biometric information used for the failed biometric authentication exceeds a predetermined number.[Note 6] Each of the at least one membership group is associated with user identification information of a user who can view the biometric authentication results of an authenticated person belonging to the at least one membership group, and the output means outputs the biometric authentication results that can be viewed by the user based on the user identification information, as described in Note 1 or 2. [Note 7] The output means is a biometric authentication performed in the at least one authentication device associated with the user membership group, and the information processing device according to Note 1 or 2 outputs only the biometric authentication results of an authenticated person belonging to the user membership group. [Note 8] The output means is a biometric authentication performed in the at least one authentication device associated with the user membership group, and the information processing device according to Note 1 or 2 outputs all biometric authentication results while concealing everything except the biometric authentication results of an authenticated person belonging to the user membership group. [Note 9] A computer-based information processing method comprising: storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs; storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups; acquiring user identification information; and outputting the result of biometric authentication performed on the at least one authentication device associated with the user's group to which the user's identification information belongs, for a person to be authenticated who belongs to the user's group.[Note 10] A recording medium on which a computer program is recorded that causes a computer to execute an information processing method which includes storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs, and storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups, and the method includes obtaining user identification information and outputting the result of biometric authentication performed on the at least one authentication device associated with the user's group to which the user's identification information belongs, and of a person to be authenticated belonging to the user's group.

[0074] This disclosure may be modified as appropriate, insofar as it does not contradict the gist or idea of ​​the invention as can be inferred from the claims and the specification as a whole, and information processing devices, information processing methods, and recording media with such modifications are also included in the technical idea of ​​this disclosure.

[0075] 10, 20, 30, 40 Information processing device 11, 221 First storage unit 12, 222, 322 Second storage unit 13, 213 Acquisition unit 14, 214, 314 Output unit 215 Reception unit 416 Registration unit

Claims

1. An information processing device comprising: a first storage means for storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs; a second storage means for storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups; an acquisition means for acquiring user identification information; and an output means for outputting the result of biometric authentication performed on the at least one authentication device associated with the user's group to which the user's group to which the user belongs, and which is a result of biometric authentication of a person to be authenticated belonging to the user's group.

2. The information processing apparatus according to claim 1, wherein, if the biometric authentication is successful, the second storage means stores the result of the biometric authentication in association with information indicating at least one group to which the registered biometric information belongs, and information indicating the authentication device that performed the biometric authentication.

3. The information processing apparatus according to claim 2, wherein, in the event that the biometric authentication fails, the second storage means stores in association the biometric information used for the biometric authentication and information indicating the authentication device that performed the biometric authentication.

4. The information processing apparatus according to claim 3, wherein the output means outputs biometric authentication performed in the at least one authentication device associated with the user group, and outputs information regarding the success of biometric authentication of an authenticated person belonging to the user group, and information regarding the failure of biometric authentication in the at least one authentication device associated with the user group.

5. The information processing apparatus according to claim 3, further comprising a registration means for registering failed biometric information in a caution list when the number of failed biometric information entries stored in the second storage means that are the same as the failed biometric information entries used in the failed biometric authentication exceeds a predetermined number.

6. The information processing apparatus according to claim 1 or 2, wherein each of the at least one membership group is associated with user identification information of a user who can view the biometric authentication results of an authenticated person belonging to the at least one membership group, and the output means outputs the biometric authentication results that can be viewed by the user based on the user identification information.

7. The information processing apparatus according to claim 1 or 2, wherein the output means is biometric authentication performed in the at least one authentication device associated with the user group, and outputs only the results of biometric authentication of the person to be authenticated who belongs to the user group.

8. The information processing apparatus according to claim 1 or 2, wherein the output means is biometric authentication performed in the at least one authentication device associated with the user group, and outputs all biometric authentication results while concealing all results except those of the authenticated person belonging to the user group.

9. A computer-based information processing method comprising: storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs; storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups; acquiring user identification information; and outputting the result of biometric authentication performed on the at least one authentication device associated with the user's group to which the user's identification information belongs, for a person to be authenticated who belongs to the user's group.

10. A recording medium on which a computer program is recorded that causes a computer to execute an information processing method, which includes storing the registered biometric information of a person to be authenticated in association with at least one group to which the person to be authenticated belongs, and storing the result of biometric authentication based on the biometric information of the person to be authenticated and the registered biometric information in association with information indicating the authentication device that performed the biometric authentication, wherein each of the at least one authentication device is associated with at least one of the aforementioned groups, and the method includes obtaining user identification information and outputting the result of biometric authentication performed on the at least one authentication device associated with the user's group to which the user's identification information belongs, for a person to be authenticated who belongs to the user's group.

Citation Information

Patent Citations

  • Security system, authentication server, authentication method and program

    JP2006145835A

  • Biometric matching system and biometric matching method

    JP2010287124A

  • Face authentication system, face authentication management device, face authentication management method, and face authentication management program

    JP2020126340A