Information processing device, information processing method, and recording medium

A two-step authentication system using biometric and user information verification at a distance addresses user reluctance and ensures secure service provision by confirming user identity continuously, reducing the need for on-site actions.

WO2026105233A1PCT designated stage Publication Date: 2026-05-21NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NEC CORP
Filing Date
2024-11-13
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing biometric authentication systems in services like ATMs require users to perform additional actions at the terminal, leading to reluctance and potential misuse due to user changes post-authentication.

Method used

A two-step authentication process involving biometric and user information verification at a distance, allowing the first authentication process to authenticate users and subsequent authentication processes using user terminals, followed by a second authentication using user information processes using the results of biometric authentication using a smartphone, and issuing authentication using a smartphone, and issuing authentication using a second authentication process using a smartphone, and issuing authentication using a second authentication using terminal and issuing authentication using a second terminal.

Benefits of technology

Enhances user convenience by reducing the need for on-site actions and ensures secure service provision by confirming user identity through continuous authentication, preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024040330_21052026_PF_FP_ABST
    Figure JP2024040330_21052026_PF_FP_ABST
Patent Text Reader

Abstract

This information processing device comprises: a first authentication instruction means that transmits, to a first terminal, first instruction information for instructing execution of first authentication processing using first biological information of a user acquired by the first terminal and second biological information of a registered user; a second authentication instruction means that transmits, to the first terminal, second instruction information for instructing execution of second authentication processing using user information pertaining to the user, if the user has been authenticated as a registered user; a first acquisition means that acquires, from the first terminal, authentication results of the second authentication processing each time the second authentication processing is executed; an issuing means that issues, to the first terminal, input information to be input into a second terminal if the user has been authenticated as a registered user; a second acquisition means that acquires, from the second terminal, input results of the input information; and an output means that outputs, to the first terminal and / or the second terminal, service information pertaining to a service used by the user, on the basis of the acquisition results of the first acquisition means and the acquisition results of the second acquisition means.
Need to check novelty before this filing date? Find Prior Art

Description

Information Processing Apparatus, Information Processing Method, and Recording Medium

[0001] This disclosure relates to the technical field of information processing apparatuses, information processing methods, and recording media.

[0002] Technologies for providing various services using the results of biometric authentication are known. For example, Patent Document 1 discloses a technique for executing withdrawal and transfer services in an ATM (Automated Teller Machine) based on the results of biometric authentication using a smartphone.

[0003] JP 2019-046044

[0004] This disclosure aims to provide an information processing apparatus, an information processing method, and a recording medium for improving the technologies disclosed in prior art documents.

[0005] One aspect of the information processing apparatus of this disclosure is a first authentication instruction means for transmitting first instruction information for instructing execution of a first authentication process using first biometric information of a user acquired by a first terminal and second biometric information of a registered user registered in advance to the first terminal; a second authentication instruction means for transmitting second instruction information for instructing execution of a second authentication process using user information regarding the user to the first terminal when the user is authenticated as the registered user by the first authentication process; a first acquisition means for acquiring the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; an issuance means for issuing input information to be input to a second terminal to the first terminal when the user is authenticated as the registered user by the first authentication process; a second acquisition means for acquiring the input result of the input information from the second terminal; and an output means for outputting service information regarding a service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0006] One aspect of the information processing method disclosed herein involves at least one computer transmitting first instruction information to the first terminal, instructing it to execute a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; transmitting second instruction information to the first terminal, instructing it to execute a second authentication process using user information relating to the user, when the user is authenticated as the registered user by the first authentication process; obtaining the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; issuing input information to the first terminal to be input to the second terminal when the user is authenticated as the registered user by the first authentication process; obtaining the input result of the input information from the second terminal; and outputting service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0007] One aspect of the recording medium of this disclosure includes a computer program that causes at least one computer to execute an information processing method, which involves transmitting to the first terminal first instruction information instructing the execution of a first authentication process using first biometric information of a user acquired by a first terminal and second biometric information of a registered user that has been registered in advance; transmitting to the first terminal second instruction information instructing the execution of a second authentication process using user information relating to the user when the user is authenticated as the registered user by the first authentication process; obtaining the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; issuing input information to the first terminal to be input to the second terminal when the user is authenticated as the registered user by the first authentication process; obtaining the input result of the input information from the second terminal; and outputting service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0008] This is a block diagram showing the hardware configuration of the first information processing device. This is a block diagram showing the functional configuration of the first information processing device. This is a flowchart showing the operation flow of the first information processing device. This is a table showing a specific example of the second authentication process. This is a flowchart showing an example of operation up to the issuance of a two-dimensional code by the first information device and each terminal. This is a flowchart showing an example of operation up to the issuance of a ticket by the first information processing device and each terminal. This is a flowchart showing the operation flow of the second information processing device. This is a flowchart showing the operation flow of the third information processing device. This is a schematic diagram showing an example of the order in which the second authentication process is executed in the fourth information processing device. This is a schematic diagram showing the relationship between the user position in the fifth information processing device and the type of second authentication process executed. This is a schematic diagram showing the relationship between the user position in the sixth information processing device and the type of second authentication process executed.

[0009] The following describes embodiments of the information processing device, information processing method, and recording medium with reference to the drawings.

[0010] <First Embodiment> The first information processing device will be described with reference to Figures 1 to 6.

[0011] (Hardware Configuration) First, the hardware configuration of the first information processing device will be described with reference to Figure 1. Figure 1 is a block diagram showing the hardware configuration of the first information processing device.

[0012] As shown in Figure 1, the first information processing device 10 includes a processor 11, a RAM (Random Access Memory) 12, a ROM (Read Only Memory) 13, a storage device 14, an input device 15, an output device 16, and a communication device 18. The processor 11, RAM 12, ROM 13, storage device 14, input device 15, output device 16, and communication device 18 are all connected via a data bus 17. Note that the data bus 17 may be an interface other than a data bus (for example, LAN or USB).

[0013] The processor 11 reads a computer program. For example, the processor 11 is configured to read a computer program stored in at least one of the RAM 12, ROM 13, and storage device 14. Alternatively, the processor 11 may read a computer program stored in a computer-readable storage medium using a storage medium reading device (not shown). The processor 11 may also obtain (i.e., read) a computer program from a device (not shown) located outside the first information processing device 10 via a network interface. The processor 11 performs various processes by executing the read computer program. When the processor 11 executes the read computer program, a functional block related to the processing performed by the first information processing device 10 is realized within the processor 11. That is, the processor 11 may function as a controller that performs various controls in the first information processing device 10.

[0014] The processor 11 may be configured as, for example, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (field-programmable gate array), a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), or a quantum processor. The processor 11 may consist of one of these, or it may be configured to use multiple of them in parallel.

[0015] RAM 12 temporarily stores computer programs executed by processor 11. RAM 12 also temporarily stores data that processor 11 uses temporarily while executing computer programs. RAM 12 may be, for example, D-RAM (Dynamic Random Access Memory) or SRAM (Static Random Access Memory). Alternatively, other types of volatile memory may be used instead of RAM 12.

[0016] ROM 13 stores computer programs executed by processor 11. ROM 13 may also store other static data. ROM 13 may be, for example, P-ROM (Programmable Read Only Memory) or EPROM (Erasable Read Only Memory). Alternatively, other types of non-volatile memory may be used instead of ROM 13.

[0017] The storage device 14 stores data that the first information processing device 10 stores long-term. The storage device 14 may also operate as a temporary storage device for the processor 11. The storage device 14 may store computer programs executed by the processor 11. The storage device 14 may include, for example, at least one of a hard disk drive, a magneto-optical disk drive, an SSD (Solid State Drive), and a disk array device.

[0018] The input device 15 is a device that receives input instructions from the user of the first information processing device 10. The input device 15 may include, for example, at least one of a keyboard, mouse, touch panel, and stylus. The input device 15 may also be a device capable of voice input, for example, including a microphone.

[0019] The output device 16 is a device that outputs information related to the first information processing device 10 to the outside. For example, the output device 16 may be a display device (e.g., a display or monitor) capable of displaying information related to the first information processing device 10. Alternatively, the output device 16 may be a speaker or the like capable of outputting audio information related to the information processing device 10.

[0020] The communication device 18 is a device that communicates with the first information processing device 10 and external devices or terminals. The communication device 18 transmits and receives various types of information by communicating with the outside world via wired or wireless communication.

[0021] The first information processing device 10 may be configured to include some of the components described in Figure 1. For example, the first information processing device 10 may be configured to include only the processor 11, RAM 12, and ROM 13 from the components described above. In this case, the storage device 14, input device 15, output device 16, and communication device 18 may be provided as external devices to the first information processing device 10. Furthermore, some of the arithmetic functions of the first information processing device 10 may be implemented by an external server or cloud.

[0022] (Functional Configuration) Next, the functional configuration of the first information processing device 10 will be described with reference to Figure 2. Figure 2 is a block diagram showing the functional configuration of the first information processing device.

[0023] In Figure 2, the first information processing device 10 is configured as a device for providing various services to users. The first information processing device is configured, for example, as a server for a service center that manages the provision of services. The first information processing device 10 is configured to communicate with user terminals 20 and kiosk terminals 30, for example, by the communication device 18 (see Figure 1) described above. The user terminal 20 is a terminal owned by the user and may be, for example, a smartphone or tablet. The kiosk terminal 30 is a terminal installed in a facility that provides services and may be, for example, an ATM terminal at a financial institution, a multimedia terminal at a convenience store, a payment terminal at a store, or a check-in terminal at an airport.

[0024] The first information processing device 10 is configured to include, as components for realizing its functions, a first authentication instruction unit 110, a second authentication instruction unit 120, a first acquisition unit 130, an issuance unit 140, a second acquisition unit 150, and an output unit 160. Note that each of the first authentication instruction unit 110, the second authentication instruction unit 120, the first acquisition unit 130, the issuance unit 140, the second acquisition unit 150, and the output unit 160 may be a processing block realized by the processor 11 (see Figure 1) described above.

[0025] The first authentication instruction unit 110 is configured to output first instruction information to the user terminal 20 instructing it to execute the first authentication process. The first authentication process is an authentication process that uses the user's biometric information acquired by the user terminal 20 (hereinafter referred to as "first biometric information" as appropriate) and the biometric information of a registered user that has been registered in advance (hereinafter referred to as "second biometric information" as appropriate). The first authentication process may, for example, compare the first biometric information and the second biometric information to calculate the similarity, output an authentication result indicating that the user matches a registered user if the similarity is greater than or equal to a predetermined value, and output an authentication result indicating that the user does not match a registered user if the similarity is less than the predetermined value. The first authentication process may be a 1:1 authentication that compares the acquired first biometric information with one second biometric information, or a 1:N authentication that compares the acquired first biometric information with multiple second biometric information. The type of biometric information is not particularly limited, but examples include face, iris, fingerprint, palm print, etc. Furthermore, the first authentication process may be multimodal authentication using multiple types of biometric information. The first authentication process may be performed on the user terminal 20 that acquires the first biometric information. For example, the first authentication process may be performed by acquiring the first biometric information from an image of the user taken by a camera mounted on the user terminal 20. However, the user terminal 20 may be configured to transmit the acquired first biometric information to an external device and obtain the authentication result of the first authentication process performed on the external device. In this case, the first authentication process may be performed by the first information processing device 10. That is, the first information processing device 10 may be configured to include a first authentication unit that performs the first authentication process.

[0026] The second authentication instruction unit 120 is configured to output second instruction information to the user terminal 20 instructing it to perform a second authentication process. The second authentication instruction unit 120 outputs second instruction information to the user terminal 20 when the user is authenticated as a registered user by the first authentication process performed by the first authentication instruction (i.e., when the first authentication process is successful). The second authentication process is an authentication process that uses user information about the user. User information may be information indicating at least one of the user's location, user's actions, or user's state. The second authentication process may be a process that uses information indicating at least one of the user's location, user's actions, or user's state to confirm that the user who owns the user terminal 20 has not changed from the user authenticated as a registered user in the first authentication process. The second authentication process may be performed on the user terminal 20. In this case, the user information may be obtained by the user terminal 20. Alternatively, the second authentication process may be performed on an external terminal other than the user terminal 20. For example, if user information is obtained by an external terminal, the second authentication process may be performed on the external terminal that obtained the user information. In this case, the user terminal 20 only needs to obtain the authentication result of the second authentication process from the external terminal that performed the second authentication process. Alternatively, the second authentication process may be performed by the first information processing device 10. That is, the first information processing device 10 may be configured to include a second authentication unit that performs the second authentication process. Note that the second authentication process may be performed multiple times. In this case, the second authentication instruction unit 120 should output the second instruction information multiple times at the timing to execute the second authentication process. More specific examples of the second authentication process will be explained in detail later.

[0027] The first acquisition unit 130 is configured to acquire the authentication result of the second authentication process executed by the second authentication instruction from the user terminal 20. If the second authentication process is executed multiple times, the first acquisition unit 130 acquires the authentication result of the second authentication process each time it is executed. If the second authentication process is executed multiple times, the first acquisition unit 130 may be configured to store the results of past authentication processes (i.e., the progression of authentication results).

[0028] The issuing unit 140 is configured to issue input information to the user terminal 20 for input into the kiosk terminal 30. The issuing unit 140 issues input information to the user terminal 20 when the user is authenticated as a registered user by a first authentication process executed by a first authentication instruction (i.e., when the first authentication process is successful). The input information includes information about the service used by the user. The input information may be, for example, a two-dimensional code. In this case, the input information can be input into the kiosk terminal 30 by holding the user terminal 20 displaying the two-dimensional code over the camera mounted on the kiosk terminal 30. Alternatively, the input information may be information that can be transmitted by contactless communication. In this case, the input information can be input into the kiosk terminal 30 by holding the user terminal 20 on which the input information has been issued over the reader on the kiosk terminal 30.

[0029] The second acquisition unit 150 is configured to acquire the input results of the input information issued from the kiosk terminal 30 to the user terminal 20. The second acquisition unit 150 may acquire the input information entered into the kiosk terminal 30 as is. Alternatively, the second acquisition unit 150 may acquire the processing results using the input information entered into the kiosk terminal 30.

[0030] The output unit 160 is configured to output service information related to the services used by the user. The output unit 160 outputs service information based on the acquisition results of the first acquisition unit 130 (i.e., the authentication results of the second authentication process) and the acquisition results of the second acquisition unit 150 (i.e., the input results of the input information). For example, the output unit 160 outputs service information corresponding to the input results of the input information when the second authentication process is successfully completed. More specifically, the output unit 160 outputs information to permit the user to use the service when the second authentication process determines that there has been no change in the user (i.e., the user who entered the input information is the same user authenticated as a registered user by the first authentication process). The service information only needs to be output to at least one of the user terminal 20 and the kiosk terminal 30. Service information may include, for example, information instructing an ATM terminal at a financial institution to execute a withdrawal transaction, information instructing a multimedia terminal at a convenience store to issue a ticket, information instructing a payment terminal at a store to execute a payment transaction, or information instructing a check-in terminal at an airport to execute a check-in procedure.

[0031] (Operation Flow) Next, the operation flow of the first information processing device 10 will be explained with reference to Figure 3. Figure 3 is a flowchart showing the operation flow of the first information processing device.

[0032] As shown in Figure 3, when the operation of the first information processing device 10 starts, the first authentication instruction unit 110 first outputs first instruction information to the user terminal 20 instructing it to execute the first authentication process (step S101). This causes the first authentication process to be executed using the first biometric information obtained from the user. The location where the first authentication process is executed is not particularly limited. For example, the first authentication process may be executed at a location away from the kiosk terminal 30 (for example, the user's home). If the first authentication process fails (step S102: NO), the subsequent processes may be omitted. In this case, the first biometric information may be reacquired and the process may be restarted from step S101.

[0033] If the first authentication process is successful (step S102: YES), the issuing unit 140 issues input information to the user terminal 20 (step S103). The issuing unit 140 may automatically issue input information if the first authentication process is successful. Alternatively, the issuing unit 140 may issue input information in response to user operations after the first authentication process is successful. For example, the issuing unit 140 may issue input information in response to user operations just before the user enters the input information into the kiosk terminal 30. In this case, the issuance of input information will be performed after the second authentication process. Note that if the second authentication process has already failed at the stage when the issuing unit attempts to issue input information (i.e., if there is a possibility that the user has changed), the issuing unit 140 may refrain from issuing input information.

[0034] If the first authentication process is successful, the second authentication instruction unit 120 outputs second instruction information to the user terminal 20 instructing it to execute the second authentication process (step S104). This causes the second authentication process using the user information to be executed. Once the second authentication process is executed, the first acquisition unit 130 acquires the authentication result of the second authentication process (step S105). If the second authentication process is to be executed multiple times, steps S104 and S105 should be repeated until the input information is entered into the kiosk terminal 30.

[0035] When input information is entered into the kiosk terminal 30, the second acquisition unit 150 acquires the input result of the input information from the kiosk terminal 30 (step S106). Subsequently, the output unit 160 outputs service information to at least one of the user terminal 20 and the kiosk terminal 30 based on the acquisition result by the first acquisition unit 130 and the input result by the second acquisition unit 150 (step S107). The output unit 160 may choose not to output service information if it determines that it should not output service information (for example, if it can be determined from the authentication result of the second authentication process that there is a high possibility that the user has been replaced).

[0036] (Specific Example of the Second Authentication Process) Next, a specific example of the second authentication process will be explained with reference to Figure 4. Figure 4 is a table showing a specific example of the second authentication process.

[0037] As shown in Figure 4, the second authentication process may be route authentication using the route taken by the user authenticated in the first authentication process to reach the kiosk terminal 30. In route authentication, the user's current location is periodically obtained, for example, by a GPS (Global Positioning System) installed in the user terminal 20. Based on the obtained user location, it is determined whether the user heading to the kiosk terminal 30 is following a pre-specified route. The specified route may be automatically determined if the first authentication process is successful. Alternatively, the user may set it themselves if the first authentication process is successful. If the user is following the specified route, it can be determined that the user holding the user terminal 20 has not changed (i.e., it is still the user authenticated in the first authentication process). On the other hand, if the user has deviated from the specified route, it can be determined that the user holding the user terminal 20 may have changed (i.e., it is now held by a different user than the one authenticated in the first authentication process).

[0038] The second authentication process may be ear acoustic authentication using the ear acoustic information of the user authenticated in the first authentication process. In ear acoustic authentication, ear acoustic information (for example, information obtained as a result of the sound transmitted by the earphones reflecting off the user's ear canal) is periodically acquired from the earphones worn by the user. Based on the acquired ear acoustic information, it is determined whether or not the user is continuously wearing the earphones. Ear acoustic authentication may be performed on the user terminal 20 that receives the ear acoustic information from the earphones. Alternatively, ear acoustic authentication may be performed on the earphones, and the authentication result may be output to the user terminal 20. If the user is continuously wearing the earphones, it can be determined that the user who owns the user terminal 20 has not changed (i.e., it is still the user authenticated in the first authentication process). On the other hand, if the user is not continuously wearing the earphones, it can be determined that the user who owns the user terminal 20 may have changed (i.e., it is owned by a different user than the one authenticated in the first authentication process). In authentication processing using ear acoustic information, it is possible to identify the user by matching the ear acoustic information. However, in ear acoustic authentication in this embodiment, as described above, it is sufficient to determine whether or not the user is continuously wearing the earphones. However, it is also possible to improve the reliability of the second authentication process by identifying the user through ear acoustic authentication.

[0039] The second authentication process may be pulse authentication using the pulse information of the user authenticated in the first authentication process. In pulse authentication, pulse information (for example, information on pulse rate) is periodically acquired from the wearable device worn by the user. Based on the acquired pulse information, it is determined whether or not the user is continuously wearing the wearable device. Pulse authentication may be performed on the user terminal 20 that receives the pulse information from the wearable device. Alternatively, ear acoustic authentication may be performed on the wearable device, and the authentication result may be output to the user terminal 20. If the user is continuously wearing the wearable device, it can be determined that the user who possesses the user terminal 20 has not changed (i.e., it remains the same user authenticated in the first authentication process). On the other hand, if the user is not continuously wearing the wearable device, it can be determined that the user who possesses the user terminal 20 may have changed (i.e., it is now possessed by a different user than the one authenticated in the first authentication process).

[0040] The first information processing device 1 may be configured to instruct a second authentication process that includes all of the above-mentioned root authentication, ear acoustic authentication, and pulse authentication. That is, there may be multiple types of second authentication processes that are executed by the second instruction information. In this case, the user may be able to select the type of second authentication process to be executed. Alternatively, the type of second authentication process to be executed may be automatically determined based on predetermined conditions.

[0041] The above-mentioned root authentication, ear acoustic authentication, and pulse authentication are merely examples of processes that can be used in the second authentication process. In other words, the second authentication process may include authentication processes other than root authentication, ear acoustic authentication, and pulse authentication. However, it is preferable that the second authentication process does not require the user to perform actions to acquire biometric information (for example, taking a picture of themselves with a camera, or performing actions for liveness determination), unlike the first authentication process.

[0042] (Specific operation example) Next, a specific operation example of the first information processing apparatus 10 will be described while referring to FIGS. 5 and 6. FIG. 5 is a flowchart showing an operation example up to two-dimensional code issuance by the first information apparatus and each terminal. FIG. 6 is a flowchart showing an operation example up to ticket issuance by the first information processing apparatus and each terminal. Hereinafter, an example will be described in which a user using the ticket issuance service inputs a two-dimensional code, which is a specific example of input information, to the kiosk terminal 30.

[0043] As shown in FIG. 5, a user who intends to use the ticket issuance service first performs a registration operation for the service using the user terminal 20. By this operation, a service registration request is transmitted from the user terminal 20 to the first information processing apparatus 10 installed in the service center (step S11).

[0044] The first information processing apparatus 10 that has received the service registration request transmits a personal confirmation request to the user who intends to use the ticket issuance service (step S12). Specifically, the first authentication instruction unit 110 in the first information processing apparatus 10 outputs a first authentication instruction so as to execute the first authentication process.

[0045] The user who has received the personal confirmation request performs the first authentication process using the user terminal 20 and outputs the authentication result to the first information processing apparatus 10 (step S13). In addition, the user who has performed the first authentication process registers the method of the second authentication process to be performed thereafter (step S14). That is, the user selects the second authentication process to be actually executed from among a plurality of executable second authentication processes. For example, the user selects at least one authentication from the route authentication, ear acoustic authentication, and pulse authentication described in FIG. 4.

[0046] When the user is authenticated as a registered user by the first authentication process, the first information processing apparatus 10 issues a two-dimensional code to the user terminal 20 (step S15). Thereafter, until the user arrives at the kiosk terminal 30, the second authentication process selected by the user is appropriately executed.

[0047] As shown in FIG. 6, the user who has arrived at the kiosk terminal 30 starts operating the kiosk terminal 30 (step S21). That is, the user performs an operation to start using the ticket issuance service.

[0048] The kiosk terminal 30 requests the user who is operating it to present a two-dimensional code (step S22). Then, the user performs an operation to allow the kiosk terminal 30 to read the two-dimensional code issued to the user terminal 20 (step S23).

[0049] Based on the result of reading the two-dimensional code, the kiosk terminal 30 makes an inquiry to the service center (step S24). Specifically, the kiosk terminal 30 outputs the input result of the two-dimensional code to the first information processing device 10. As a result, the second acquisition unit 150 in the first information processing device 10 acquires the input result based on the input information. In addition, the kiosk terminal 30 also outputs the authentication result of the second authentication process to the first information processing device 10. The result of the second authentication process may be output separately from the two-dimensional code, or may be output as information attached to the two-dimensional code (for example, an expiration date updated according to the authentication result of the second authentication process). As a result, the first acquisition unit 130 in the first information processing device 10 acquires the authentication result of the second authentication process.

[0050] Based on the acquired information, the first information processing device 10 confirms the content of the service that the user intends to use and determines whether the user has changed (that is, whether the second authentication process has been continuously successful). Then, when the first authentication processing device determines that the user has not changed, it outputs service information corresponding to the content of the service that the user intends to use. Specifically, the first information processing device 10 outputs an instruction to issue a ticket to the kiosk terminal 30.

[0051] Upon receiving a ticket issuance instruction from the first information processing device 10, the kiosk terminal 30 issues a ticket to the user. For example, the kiosk terminal 30 may issue a paper ticket using the printing function installed in the kiosk terminal 30. Alternatively, the kiosk terminal 30 may display ticket information (such as a serial number) on the display installed in the kiosk terminal 30. Or, the kiosk terminal 30 may transmit the ticket information to the user terminal 20.

[0052] (Technical Effects) Next, the technical effects obtained by the first information processing device 10 will be explained.

[0053] As explained in Figures 1 to 6, in the first information processing device 10, a user attempting to use the service is authenticated by a first authentication process using biometric information. Then, the user authenticated in the first authentication process is authenticated by a second authentication process until they arrive at the kiosk terminal 30. In this way, users can be properly authenticated and services can be provided. For example, users do not have to perform the actions required for biometric authentication in front of the kiosk terminal 30. Therefore, they are freed from the reluctance to perform specific actions in public. In addition, it is possible to prevent queues from forming behind them (i.e., increasing the waiting time for other users) due to the user struggling with unfamiliar actions.

[0054] Furthermore, in the second authentication process in the first information processing device 10, information indicating at least one of the user's location, user's actions, or user's state may be used to confirm that the user holding the user terminal 20 has not changed from the user authenticated as a registered user in the first authentication process. This makes it possible to avoid inconveniences caused by user changes. For example, if such a second authentication process is not performed, and the person holding the user terminal 30 changes after the first authentication process is successful, there is a risk that the service may be mistakenly provided to someone who should not be receiving the service. However, in this embodiment, the second authentication process performed after the first authentication process makes it possible to guarantee that the person operating the kiosk terminal 30 is the registered user. Therefore, inconveniences that may occur if the user terminal 20 is lost or stolen can be appropriately avoided.

[0055] <Second Embodiment> The second information processing device 10 will be described with reference to Figure 7. The second information processing device 10 differs from the first information processing device 10 described above in some operations, but other parts may be the same as the first information processing device 10. For this reason, the parts that differ from the first embodiment will be explained in detail below, and explanations of other overlapping parts will be omitted as appropriate.

[0056] (Operation Flow) First, the operation flow of the second information processing device 10 will be explained with reference to Figure 7. Figure 7 is a flowchart showing the operation flow of the second information processing device. Note that in Figure 7, the same reference numerals are used for the same processes as those explained in Figure 3.

[0057] As shown in Figure 7, when the operation of the second information processing device 10 begins, the first authentication instruction unit 110 first outputs first instruction information to the user terminal 20 instructing it to execute the first authentication process (step S101). This causes the first authentication process to be executed using the first biometric information obtained from the user. If the first authentication process fails (step S102: NO), the subsequent processes may be omitted.

[0058] If the first authentication process is successful (step S102: YES), the issuing unit 140 issues input information to the user terminal 20 (step S103). The second authentication instruction unit 120 also outputs second instruction information to the user terminal 20 instructing it to execute the second authentication process (step S104). As a result, the second authentication process using the user information is executed. Once the second authentication process is executed, the first acquisition unit 130 acquires the authentication result of the second authentication process (step S105).

[0059] Subsequently, the second authentication instruction unit 120 determines whether the user has moved a predetermined distance and / or whether a predetermined time has elapsed since the previous output of the second instruction information (step S201). Note that it is sufficient for at least one of the following to be determined: whether the user has moved a predetermined distance and / or whether a predetermined time has elapsed. That is, the second authentication instruction unit 120 may determine only whether the user has moved a predetermined distance, or only whether a predetermined time has elapsed, or it may determine both whether the user has moved a predetermined distance and / or whether a predetermined time has elapsed.

[0060] If it is determined that the user has moved a predetermined distance or that a predetermined time has elapsed since the output of the second instruction information (step S201: YES), the second authentication instruction unit 120 outputs the second instruction information again. That is, if it is determined that the user has moved a predetermined distance or that a predetermined time has elapsed, the process from step S104 is repeated. As a result, the second authentication process is executed each time the user moves a predetermined distance or each time a predetermined time has elapsed.

[0061] The "predetermined distance" and "predetermined time" here are values ​​that are pre-set to determine the interval at which the second authentication process is executed. The predetermined distance and predetermined time may be set according to the type of second authentication process, for example. For example, route authentication shown in Figure 4 does not need to be performed while the user is walking on a road without forks in the road. Therefore, when using route authentication, the predetermined distance and predetermined time may be set to be relatively long. On the other hand, ear acoustic authentication and pulse authentication shown in Figure 4 are preferably performed at relatively short intervals in order to detect changes in the user. Therefore, when using ear acoustic authentication or pulse authentication, the predetermined distance and predetermined time may be set to be relatively short.

[0062] On the other hand, if it is determined that the user has not moved a predetermined distance since the output of the second instruction information, or if it is determined that a predetermined time has not elapsed (step S201: YES), the second authentication instruction unit 120 determines whether the second acquisition unit 150 has acquired the input result of the input information from the kiosk terminal 30 (step S202). If the input result of the input information has not been acquired from the kiosk terminal 30 (step S202: NO), the second authentication instruction unit 120 restarts the process of step S201. For this reason, until the input result of the input information is acquired from the kiosk terminal 30, the second authentication instruction unit 120 outputs a second authentication instruction according to the predetermined distance or predetermined time.

[0063] If input results are obtained from the kiosk terminal 30 (step S202: YES), the output unit 160 outputs service information to at least one of the user terminal 20 and the kiosk terminal 30 based on the results obtained by the first acquisition unit 130 and the input results obtained by the second acquisition unit 150 (step S107).

[0064] (Technical Effects) Next, the technical effects obtained by the second information processing device 10 will be explained.

[0065] As explained in Figure 7, the second information processing device 10 outputs a second authentication instruction each time the user moves a predetermined distance or each time a predetermined amount of time has elapsed. In this way, the second authentication process is executed at appropriate intervals, making it possible to appropriately determine if the user has changed after the first authentication process.

[0066] <Third Embodiment> The third information processing device 10 will be described with reference to Figure 8. Note that the third information processing device 10 differs in some operations from the first and second information processing devices 10 described above, but other parts may be the same as those of the first and second information processing devices 10. For this reason, the parts that differ from the embodiments already described will be explained in detail below, and other overlapping parts will be omitted as appropriate.

[0067] (Operation Flow) First, the operation flow of the third information processing device 10 will be explained with reference to Figure 8. Figure 8 is a flowchart showing the operation flow of the third information processing device. Note that in Figure 8, the same reference numerals are used for the same processes as shown in Figure 7.

[0068] As shown in Figure 7, when the operation of the third information processing device 10 begins, the first authentication instruction unit 110 first outputs first instruction information to the user terminal 20 instructing it to execute the first authentication process (step S101). This causes the first authentication process to be executed using the first biometric information obtained from the user. If the first authentication process fails (step S102: NO), the subsequent processes may be omitted.

[0069] If the first authentication process is successful (step S102: YES), the issuing unit 140 issues input information to the user terminal 20 with an expiration date (step S301). Input information that has not expired is treated as valid information when entered into the kiosk terminal 30. On the other hand, input information that has expired is treated as invalid information when entered into the kiosk terminal 30. For example, in the case of input information with an expiration date of 10 minutes, if it is entered into the kiosk terminal 30 within 10 minutes of issuance, service information will be output, but if it is entered into the kiosk terminal 30 more than 10 minutes later, service information will not be output. The length of the expiration date assigned may be a predetermined value. Alternatively, the length of the expiration date may change depending on the type of first authentication process. For example, the length of the expiration date may change depending on the reliability of the first authentication process. More specifically, the expiration date may be 10 minutes if fingerprint authentication is performed as the first authentication process, and 20 minutes if facial recognition is performed.

[0070] If the first authentication process is successful, the second authentication instruction unit 120 further outputs second instruction information to the user terminal 20 instructing it to execute the second authentication process (step S104). This results in the execution of the second authentication process using user information. Once the second authentication process is executed, the first acquisition unit 130 acquires the authentication result of the second authentication process (step S105).

[0071] Once the authentication result of the second authentication process is obtained, the issuing unit 140 determines whether the second authentication process was successful or not (step S302). If the second authentication process is successful (step S302: YES), the issuing unit 140 updates the expiration date of the input information (step S303). In other words, the issuing unit 140 extends the expiration date when the second authentication process is successful. As a result, the expiration date of the input information also functions as an indicator that the second authentication process is continuing to be successful. On the other hand, if the second authentication process is unsuccessful (step S302: NO), the process in step S303 described above is omitted. In other words, the issuing unit 140 does not update the expiration date of the input information.

[0072] When renewing the expiration date, the issuing unit 140 may renew it by adding a predetermined extension period to the expiration date at that time. For example, if the remaining time until expiration is 3 minutes and the predetermined extension period is 5 minutes, the issuing unit 140 may renew it so that the expiration date becomes 8 minutes. Alternatively, the issuing unit 140 may reset the expiration date to its initial value or a predetermined value, regardless of the current expiration date, and renew it. For example, if the initial value of the expiration date is 10 minutes, the issuing unit 140 may renew it so that the new expiration date becomes 10 minutes, regardless of whether the remaining time until expiration is 3 minutes or 5 minutes.

[0073] When updating the expiration date, the issuing unit 140 can simply reissue the input information with the updated expiration date. Alternatively, the issuing unit 140 may output the updated expiration date to the user terminal 20, and the user terminal 20 may re-apply the expiration date to the input information.

[0074] Furthermore, when renewing the expiration date, the issuing unit 140 may change the extension period depending on the type of second authentication process. For example, the issuing unit 140 may change the extension period depending on the reliability of the second authentication process. More specifically, if the second authentication process is root authentication, the issuing unit 140 may renew the expiration date to extend it by 5 minutes. If the second authentication process is ear acoustic authentication, the issuing unit 140 may renew the expiration date to extend it by 10 minutes.

[0075] Subsequently, the second authentication instruction unit 120 determines whether the user has moved a predetermined distance and / or whether a predetermined time has elapsed since the previous output of the second instruction information (step S201). If it is determined that the user has moved a predetermined distance or a predetermined time has elapsed since the output of the second instruction information (step S201: YES), the second authentication instruction unit 120 outputs the second instruction information again.

[0076] On the other hand, if it is determined that the user has not moved a predetermined distance since the output of the second instruction information, or that a predetermined time has not elapsed (step S201: YES), the second authentication instruction unit 120 determines whether the second acquisition unit 150 has acquired the input result of the input information from the kiosk terminal 30 (step S202). If the input result of the input information has not been acquired from the kiosk terminal 30 (step S202: NO), the second authentication instruction unit 120 restarts the process of step S201.

[0077] If input results are obtained from the kiosk terminal 30 (step S202: YES), the output unit 160 outputs service information to at least one of the user terminal 20 and the kiosk terminal 30 based on the results obtained by the first acquisition unit 130 and the input results obtained by the second acquisition unit 150 (step S107).

[0078] (Technical Effects) Next, the technical effects obtained by the third information processing device 10 will be explained.

[0079] As explained in Figure 8, in the third information processing device 10, if the second authentication process is successful, the expiration date attached to the input information is updated. In this way, the expiration date is extended as long as the second authentication process is successful, thus preventing situations where legitimate users are unable to receive service information due to expiration. In addition, the third information processing device 10 may update the expiration date for an extension period that depends on the type of second authentication process. In this way, it becomes possible to appropriately extend the expiration date according to the type of second authentication process (for example, reliability that depends on the authentication method).

[0080] <Fourth Embodiment> The fourth information processing device 10 will be described with reference to Figure 9. The fourth information processing device 10 differs in some operations from the first to third information processing devices 10 described above, but other parts may be the same as those of the first to third information processing devices 10. For this reason, the parts that differ from the embodiments already described will be explained in detail below, and other overlapping parts will be omitted as appropriate.

[0081] (Order of the second authentication process) First, the second authentication process executed in the fourth information processing device 10 will be explained in detail with reference to Figure 9. Figure 9 is a schematic diagram showing an example of the order in which the second authentication process is executed in the fourth information processing device.

[0082] As shown in Figure 9, the fourth information processing device 10 performs root authentication, ear acoustic authentication, and pulse authentication as the second authentication process. Therefore, the user is required to be in a state where all of root authentication, ear acoustic authentication, and pulse authentication can be performed. Specifically, the user is required to turn on the GPS of the user terminal 20 so that root authentication can be performed, wear earphones so that ear acoustic authentication can be performed, and wear a wearable device so that pulse authentication can be performed.

[0083] According to the fourth information processing device 10, after the first authentication process is successful, root authentication is performed as the first second authentication process. Then, ear acoustic authentication is performed as the second second authentication process. After that, pulse authentication is performed as the third second authentication process. In other words, multiple types of second authentication processes are executed sequentially in a predetermined order. Note that for the fourth second authentication process, the process returns to the beginning and root authentication is performed, and thereafter each authentication process may be executed in the same order in a loop.

[0084] The order in which each authentication process is executed may be predetermined, randomly determined after the first authentication process is completed, or determined by the user. If the user does not determine the order, the user does not need to be informed of the order in which the authentication processes are executed. Furthermore, the order in which each authentication process is executed may be changed midway through (for example, after a predetermined number of loops). In this case as well, the user does not need to be informed of the changed order.

[0085] (Technical Effects) Next, the technical effects obtained by the fourth information processing device 10 will be explained.

[0086] As explained in Figure 9, the fourth information processing device 10 executes multiple types of second authentication processes in a predetermined order. This allows for more accurate detection of user changes compared to continuously executing only one type of second authentication process.

[0087] <Fifth Embodiment> The fifth information processing device 10 will be described with reference to Figure 10. Note that the fifth information processing device 10 differs in some operations from the first to fourth information processing devices 10 described above, but other parts may be the same as those of the first to fourth information processing devices 10. For this reason, the parts that differ from each embodiment already described will be explained in detail below, and other overlapping parts will be omitted as appropriate.

[0088] (Second Authentication Process Based on User Location) First, the second authentication process performed in the fifth information processing device 10 will be explained in detail with reference to Figure 10. Figure 10 is a schematic diagram showing the relationship between the user location in the fifth information processing device and the type of second authentication process performed.

[0089] As shown in Figure 10, in the fifth information processing device 10, similar to the fourth embodiment described above, root authentication, ear acoustic authentication, and pulse authentication are performed as the second authentication process. In particular, in the fifth information processing device 10, the type of second authentication process performed is changed according to the user's location.

[0090] Specifically, if the first authentication process is performed at home, ear acoustic authentication is performed as the second authentication process in the vicinity of home. Subsequently, route authentication is performed in the vicinity of a point midway between home and kiosk terminal 30. After that, pulse authentication is performed in the vicinity of kiosk terminal 30.

[0091] The location at which authentication process is performed may be determined according to the characteristics of each authentication process. For example, in the vicinity of the user's home, where the first authentication process was successful, the effectiveness of route authentication may be low because there are still few route branches. For this reason, ear acoustic authentication may be performed instead of route authentication in the vicinity of the user's home. On the other hand, after the user has been moving for some time, the range of route options widens, and the effectiveness of route authentication increases. For this reason, route authentication may be performed around intermediate points. Also, there is a possibility that there will be many people around the kiosk terminal 30. For this reason, considering users who have an aversion to certain actions, pulse authentication that does not require any action (simply walking is sufficient) may be performed.

[0092] (Technical Effects) Next, the technical effects obtained by the fifth information processing device 10 will be explained.

[0093] As explained in Figure 10, the fifth information processing device 10 uses multiple types of second authentication processes depending on the user's location. In this way, the appropriate second authentication process can be executed according to the user's status from the completion of the first authentication process until they reach the kiosk terminal 30.

[0094] <Sixth Embodiment> The sixth information processing device 10 will be described with reference to Figure 11. Note that the sixth information processing device 10 differs in some operations from the first to fifth information processing devices 10 described above, but other parts may be the same as the first to fifth information processing devices 10. For this reason, the parts that differ from each embodiment already described will be explained in detail below, and other overlapping parts will be omitted as appropriate.

[0095] (Simultaneous execution of the second authentication process) First, the second authentication process executed in the sixth information processing device 10 will be explained in detail with reference to Figure 11. Figure 11 is a schematic diagram showing the relationship between the user position in the sixth information processing device and the type of second authentication process executed.

[0096] As shown in Figure 11, in the sixth information processing device 10, similar to the fifth embodiment described above, root authentication, ear acoustic authentication, and pulse authentication are performed as second authentication processes. In particular, in the sixth information processing device 10, two types of second authentication processes are executed simultaneously in parallel.

[0097] Specifically, if the first authentication process is performed at home, then ear acoustic authentication and pulse authentication are performed as the second authentication process in the vicinity of home. Subsequently, around a point midway between home and kiosk terminal 30, route authentication and ear acoustic authentication are performed. After that, around kiosk terminal 30, pulse authentication and route authentication are performed.

[0098] The combination of authentication processes can be pre-configured, taking into account the characteristics of each authentication process. For example, a low-reliability authentication process and a high-reliability authentication process can be combined and executed simultaneously. Alternatively, low-reliability authentication processes can be combined and executed simultaneously, or high-reliability authentication processes can be combined and executed simultaneously.

[0099] When two types of authentication processes are executed in parallel and simultaneously, the success criteria may be modified depending on the combination. For example, when combining ear acoustic authentication and pulse authentication, if either authentication process is successful, the system may be considered successful even if the other fails. Similarly, when combining root authentication and ear acoustic authentication, if either authentication process is successful, the system may be considered a failure if the other fails. The criteria for such success determination may be determined, for example, based on the reliability of each authentication process.

[0100] In the example above, we described a configuration that performs two types of authentication processes simultaneously, but it is also possible to perform three or more types of authentication processes simultaneously.

[0101] (Technical Effects) Next, the technical effects obtained by the sixth information processing device 10 will be explained.

[0102] As explained in Figure 11, the sixth information processing device 10 executes multiple types of second authentication processes simultaneously and in parallel. This allows for more accurate detection of user changes compared to the case where only one type of second authentication process is executed.

[0103] The processing method of recording a program that operates the configuration of each embodiment in order to realize the functions of each embodiment described above on a recording medium, reading the program recorded on the recording medium as code, and executing it on a computer is also included in the scope of each embodiment. In other words, a computer-readable recording medium is also included in the scope of each embodiment. Furthermore, not only the recording medium on which the above-mentioned program is recorded, but also the program itself is included in each embodiment.

[0104] Examples of recording media that can be used include floppy disks (registered trademark), hard disks, optical disks, magneto-optical disks, CD-ROMs, magnetic tapes, non-volatile memory cards, and ROMs. Furthermore, the scope of each embodiment is not limited to programs that perform processing on the recording media alone, but also includes programs that operate on the OS and perform processing in cooperation with other software and the functions of expansion boards. In addition, the program itself may be stored on a server, and part or all of the program may be made available for download from the server to the user terminal. The program may be provided to the user in, for example, SaaS (Software as a Service) format.

[0105] <Note> The embodiments described above may also be described in the following way, but are not limited to the following.

[0106] (Note 1) The information processing device described in Note 1 is an information processing device comprising: a first authentication instruction means that transmits to the first terminal first instruction information that instructs the execution of a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; a second authentication instruction means that transmits to the first terminal second instruction information that instructs the execution of a second authentication process using user information relating to the user when the user is authenticated as the registered user by the first authentication process; a first acquisition means that acquires the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; an issuing means that issues to the first terminal input information to be input to the second terminal when the user is authenticated as the registered user by the first authentication process; a second acquisition means that acquires the input result of the input information from the second terminal; and an output means that outputs service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0107] (Note 2) The information processing device described in Note 2 is the information processing device described in Note 1, wherein the user information is information indicating at least one of the user's location, the user's actions, and the user's state, and the second authentication process is a process that uses the user information to confirm that the user who possesses the first terminal has not changed from the user authenticated as the registered user by the first authentication process.

[0108] (Note 3) The information processing device described in Note 3 is the information processing device described in Note 1 or 2, wherein the second authentication instruction means transmits the second instruction information to the first terminal each time the user moves a predetermined distance and / or each time a predetermined amount of time has elapsed.

[0109] (Note 4) The information processing device described in Note 4 is the information processing device described in any one of Notes 1 to 3, wherein the issuing means issues the input information with an expiration date, and updates the expiration date each time an authentication result indicating the success of the second authentication process is obtained.

[0110] (Note 5) The information processing device described in Note 5 is the information processing device described in Note 4, wherein there are multiple types of second authentication processes, and the issuance means updates the expiration date for an extension period corresponding to the type of successful second authentication process.

[0111] (Note 6) The information processing device described in Note 6 is the information processing device described in any one of Notes 1 to 5, wherein the second authentication process has multiple types, and the second authentication instruction means transmits the second instruction information so that each of the multiple second authentication processes is executed in a predetermined order.

[0112] (Note 7) The information processing device described in Note 7 is the information processing device described in any one of Notes 1 to 5, wherein the second authentication process has multiple types, and the second authentication instruction means transmits the second instruction information to execute one of the multiple second authentication processes according to the user's location.

[0113] (Note 8) The information processing device described in Note 8 is the information processing device described in any one of Notes 1 to 5, wherein the second authentication process has multiple types, and the second authentication instruction means transmits the second instruction information to execute at least two of the multiple second authentication processes in parallel.

[0114] (Note 9) The information processing method described in Note 9 is an information processing method in which at least one computer transmits to the first terminal first instruction information instructing the execution of a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; when the user is authenticated as the registered user by the first authentication process, transmits to the first terminal second instruction information instructing the execution of a second authentication process using user information relating to the user; obtains the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; when the user is authenticated as the registered user by the first authentication process, issues input information to be input to the second terminal to the first terminal; obtains the input result of the input information from the second terminal; and outputs service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0115] (Note 10) The recording medium described in Note 10 is a recording medium on which a computer program is recorded that causes at least one computer to execute an information processing method which involves transmitting to the first terminal first instruction information instructing the first terminal to execute a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; transmitting to the first terminal second instruction information instructing the first terminal to execute a second authentication process using user information relating to the user when the first authentication process authenticates the user as the registered user; obtaining the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; issuing input information to the first terminal to be input to the second terminal when the first authentication process authenticates the user as the registered user; obtaining the input result of the input information from the second terminal; and outputting service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0116] (Note 11) The computer program described in Note 11 is a computer program that causes at least one computer to execute an information processing method which involves sending first instruction information to the first terminal instructing it to execute a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; sending second instruction information to the first terminal instructing it to execute a second authentication process using user information relating to the user when the user is authenticated as the registered user by the first authentication process; obtaining the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; issuing input information to the first terminal to be input to the second terminal when the user is authenticated as the registered user by the first authentication process; obtaining the input result of the input information from the second terminal; and outputting service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

[0117] This disclosure may be modified as appropriate, insofar as it does not contradict the gist or idea of ​​the invention as can be inferred from the claims and the specification as a whole, and information processing devices, information processing methods, and recording media with such modifications are also included in the technical idea of ​​this disclosure.

[0118] 10 Information processing device 11 Processor 12 RAM 13 ROM 14 Storage device 15 Input device 16 Output device 17 Data bus 18 Communication device 20 User terminal 30 Kiosk terminal 110 First authentication instruction unit 120 Second authentication instruction unit 130 First acquisition unit 140 Issuance unit 150 Second acquisition unit 160 Output unit

Claims

1. Information processing device comprising: a first authentication instruction means that transmits to the first terminal first instruction information that instructs the execution of a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; a second authentication instruction means that transmits to the first terminal second instruction information that instructs the execution of a second authentication process using user information relating to the user when the user is authenticated as the registered user by the first authentication process; a first acquisition means that acquires the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; an issuing means that issues to the first terminal input information to be input to the second terminal when the user is authenticated as the registered user by the first authentication process; a second acquisition means that acquires the input result of the input information from the second terminal; and an output means that outputs service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

2. The information processing apparatus according to claim 1, wherein the user information is information indicating at least one of the user's location, the user's actions, and the user's state, and the second authentication process is a process that uses the user information to confirm that the user possessing the first terminal has not changed from the user authenticated as the registered user by the first authentication process.

3. The information processing apparatus according to claim 1 or 2, wherein the second authentication instruction means transmits the second instruction information to the first terminal each time the user moves a predetermined distance and / or each time a predetermined amount of time has elapsed.

4. The information processing apparatus according to claim 1 or 2, wherein the issuing means issues the input information with an expiration date, and updates the expiration date each time an authentication result indicating the success of the second authentication process is obtained.

5. The information processing apparatus according to claim 4, wherein there are multiple types of the second authentication process, and the issuing means updates the expiration date for an extension period corresponding to the type of successful second authentication process.

6. The information processing apparatus according to claim 1 or 2, wherein there are multiple types of second authentication processes, and the second authentication instruction means transmits the second instruction information to execute each of the multiple second authentication processes in a predetermined order.

7. The information processing apparatus according to claim 1 or 2, wherein there are multiple types of second authentication processes, and the second authentication instruction means transmits the second instruction information to execute a process corresponding to the user's location from among the multiple second authentication processes.

8. The information processing apparatus according to claim 1 or 2, wherein there are multiple types of second authentication processes, and the second authentication instruction means transmits the second instruction information to execute at least two of the multiple second authentication processes in parallel.

9. An information processing method comprising: transmitting first instruction information to the first terminal, instructing the first terminal to execute a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; transmitting second instruction information to the first terminal, instructing the first terminal to execute a second authentication process using user information relating to the user, when the first authentication process authenticates the user as the registered user; obtaining the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; issuing input information to the first terminal to be input to the second terminal when the first authentication process authenticates the user as the registered user; obtaining the input result of the input information from the second terminal; and outputting service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.

10. A recording medium on which a computer program is recorded that causes at least one computer to execute an information processing method, which involves: transmitting to the first terminal first instruction information instructing the first terminal to execute a first authentication process using first biometric information of a user acquired by the first terminal and second biometric information of a registered user that has been registered in advance; transmitting to the first terminal second instruction information instructing the first terminal to execute a second authentication process using user information relating to the user when the first authentication process authenticates the user as the registered user; obtaining the authentication result of the second authentication process from the first terminal each time the second authentication process is executed; issuing input information to the first terminal to be input to the second terminal when the first authentication process authenticates the user as the registered user; obtaining the input result of the input information from the second terminal; and outputting service information relating to the service used by the user to at least one of the first terminal and the second terminal based on the acquisition result of the first acquisition means and the acquisition result of the second acquisition means.