Hands-free personal authentication application and authentication method for service use within closed SIM communication network
The hands-free authentication system in closed SIM networks uses terminal identification and biometric data to enhance security and verify qualifications, addressing authentication challenges and ensuring only authorized users access the network.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- MATSUNAGA CHIKARA
- Filing Date
- 2026-01-17
- Publication Date
- 2026-07-23
AI Technical Summary
Existing closed SIM networks lack effective participant authentication methods, particularly in verifying user identity and qualifications, leading to security risks and inconvenience, as they rely on password-based or device authentication that can be easily compromised.
A hands-free authentication system using a combination of terminal identification numbers and biometric data, specifically facial recognition, to ensure secure and reliable user authentication, with integrated qualification verification processes.
Provides high-security, convenient user authentication and qualification verification, reducing the risk of impersonation and ensuring only authorized and qualified individuals can access closed SIM network services.
Smart Images

Figure JP2026001360_23072026_PF_FP_ABST
Abstract
Description
Hands-free Service Usage Personal Authentication Application and Authentication Method within a Closed SIM Communication Network
[0001] The present invention relates to a service usage personal authentication application and authentication method within a closed SIM communication network that involves personal authentication for controlling the availability of specific services by participants within a closed SIM communication network constructed within a specific range without going through the Internet.
[0002] One that has attracted attention as a closed network is the closed SIM communication network using SIM. Briefly speaking, the closed SIM communication network is a mobile network that can communicate between specific SIM cards without going through the Internet. Since it does not go through the Internet, it leads to a reduction in risks such as information theft and communication eavesdropping, and it is expected to become more popular in the future in organizations that handle confidential information and personal information.
[0003] Assuming a closed SIM network, since those other than the relevant parties cannot participate in the closed SIM network, high security can be ensured with stable communication quality. Furthermore, if it involves a personal authentication process to determine whether a person has the qualification to use the services provided within the closed SIM communication network, advanced operation regarding service usage becomes possible.
[0004] The closed SIM network can be roughly classified into a dedicated line and a VPN. The dedicated line is a communication network provided by a specific mobile network operator (MNO), such as the mobile communication networks provided by operators such as NTT Docomo, au (KDDI), SoftBank, and Rakuten. A VPN (Virtual Private Network) is provided by a Mobile Virtual Network Operator (MVNO) by virtually constructing a dedicated network on the network (closed network) provided by an MNO communication operator. There are many MVNO operators, for example, IIJmio, BIGLOBE Mobile, Nuro Mobile, OCN Mobile ONE, etc.
[0005] In any case, a closed SIM network is characterized by being built separately from the internet and utilizing a closed network area. Routers installed in a closed SIM network are configured to exchange information necessary for packet delivery only between routers within the closed SIM network, rather than via the internet.
[0006] Because services provided via data communication over a closed SIM network are isolated from the internet, security is extremely high and communication quality is stable. Due to these advantages, the construction of systems using closed SIM networks is expected to be popular in facilities such as corporate offices and hospitals.
[0007] Japanese Patent Publication No. 6476533, WO2023 / 286134, WO2021 / 234901, Japanese Unexamined Patent Publication No. 2023-163583, Japanese Unexamined Patent Publication No. 2018-166845, WO2024-154223, US2020-0186352. Miho Ichinohe, Hands-free facial recognition system, Toshiba Technical Publications Vol. 20-43, Toshiba Corporation, 2002.09.30
[0008] As mentioned above, closed SIM networks can be operated in isolation from the internet, and their advantages such as high security and stable communication quality are attracting considerable attention. However, the inventor noticed two problems that needed to be solved.
[0009] The first challenge is that while closed SIM networks limit participants, they do not authenticate the participants themselves during the participation process. This is a significant issue. For example, while knowledge authentication such as passwords or device authentication using the SIM card are envisioned for participation in closed SIM networks, both the former and the latter have their own challenges.
[0010] The former method, knowledge-based authentication, carries the risk of being compromised by malicious actors through the leakage or theft of passwords. If passwords are compromised, the malicious actor can enter those passwords, allowing an imposter to bypass knowledge-based authentication and participate in the closed SIM network.
[0011] The latter method, terminal authentication for the user's device, is merely terminal authentication and does not verify whether the user is truly the person they claim to be. The ID number verification on the user's SIM card has a problem: if the user's device is temporarily stolen or taken away, terminal authentication can be easily bypassed, allowing an imposter to join the closed SIM network.
[0012] As a measure to prevent cybercrime, so-called two-factor authentication or two-step authentication is attracting attention as a promising method of identity verification. While this two-factor authentication or two-step authentication can be expected to improve security against cyberattacks to some extent, it is basically set up when the user logs into the system, and once identity verification is successful and the service can be provided or enjoyed, identity verification is basically not required thereafter. In other words, once identity verification is successful at the start of service use and service use is possible, it is only presumed that only the legitimate person used the service for the entire period of service use until the end of service use.
[0013] In the prior art, only Japanese Patent No. 6476533 discloses a system that achieves a high level of security by requiring and verifying user authentication both when opening the user authentication file at the start of service use and when closing the user authentication file at the end of service use. Figure 9 is a diagram that briefly illustrates the configuration of the application disclosed in Japanese Patent No. 6476533.
[0014] However, performing identity verification is often inconvenient for users. While a genuine user is naturally aware of their own identity, and understands that they must tolerate the necessary identity verification procedures to prevent fraudulent use, having to perform these procedures according to the requirements and operating procedures of the service provider application is extremely troublesome. In particular, having to take out the user's device and perform some operation, or having to perform complex operations or data entry on some device, is extremely inconvenient.
[0015] The second challenge is that while closed SIM networks limit participants, it's impossible to verify whether participants possess the required qualifications. Currently, conventional technologies rely on analog methods to verify whether participants are qualified. This often involves relying solely on verbal self-declaration or verification of copies of qualification certificates. Qualification verification is necessary for those involved in medical procedures, such as doctors and nurses. Furthermore, construction-related work has a wide variety of qualifications and training requirements, including, for example, completion of rigging skills training, special training in scaffolding assembly, small mobile crane operation skills training, aerial work platform operation skills training (over 10m), and special training in aerial work platform operation (under 10m). There are many other tasks requiring specific qualifications or training completion. It is illegal for individuals without the necessary qualifications to engage in construction work at a construction site. In other words, it is important for a closed SIM network to verify the qualifications of its participants and the services they intend to provide within the closed SIM network.
[0016] Furthermore, it is necessary to prevent illegal employment by foreign workers. In order for foreign workers to engage in specific services, it is necessary to confirm that they possess the appropriate residence status (work permit). Foreign workers must not only be qualified for the work but also possess the necessary residence status, and it is important to confirm what kind of services they intend to provide within the closed SIM network.
[0017] Therefore, in view of the above problems, the present invention aims to perform user authentication itself, rather than knowledge authentication or terminal authentication, when starting or stopping service use within a closed SIM network, and to perform reliable user authentication processing in a convenient hands-free manner. Furthermore, it aims to perform user authentication processing that can reliably confirm whether a person participating in a closed SIM network possesses the prescribed qualifications.
[0018] To achieve the above objective, the present invention provides an authentication application that enables the use of a predetermined service within a closed SIM communication network constructed within a predetermined range by establishing authentication using a registered open authentication code and a registered closed authentication code set for each user, wherein the open authentication code is the terminal identification number of the user terminal, the closed authentication code is the user's biometric information, and within the closed SIM communication network, there are open authentication code input spots where a wireless open authentication code input device is installed and closed authentication code input spots where a closed authentication code input device is installed, and the authentication application communicates to a computer system the open authentication code from the user terminal that has entered the open authentication code input spot. The application comprises: a hands-free open PIN acquisition process that wirelessly acquires the terminal identification number via a PIN input device; a hands-free closed PIN acquisition process that acquires the user's biometric information from the user who has entered a closed PIN input spot via a closed PIN input device; an identity authentication process that performs a comparison process between the registered open PIN and the registered closed PIN registered in the identity authentication application and the user registration information database, and the open PIN and the closed PIN entered hands-free; and a hands-free closed SIM communication network service user authentication application that, upon successful completion of the comparison process, permits the use of services within the closed SIM communication network.
[0019] With the above configuration, when a user enters an open PIN code input spot at a site, a wireless open PIN code acquisition process is executed at the site. Furthermore, at a closed PIN code input spot, a camera captures the user's facial image. This performs terminal device authentication on the user's own device and facial image-based identity authentication, eliminating impersonation in a simple, hands-free manner. This is not merely biometric authentication in conventional technology. While biometric authentication in conventional technology is only one step in a set of multiple authentications for login, this invention involves pinpoint facial image capture and identity authentication of the user's facial image, triggered by the acquisition of the open PIN code, so terminal device authentication and identity authentication are executed simultaneously.
[0020] Here, the authentication process using the input open PIN and the registered open PIN is actually terminal device authentication using the terminal identification number. Furthermore, the authentication process using the input closed PIN and the registered closed PIN is actually personal authentication using biometric information, particularly facial image data. In other words, although the terminology uses "open processing" for the authentication performed first and "closed processing" for the authentication performed next, regardless of the name, in reality, "open processing" refers to terminal device authentication using the terminal identification number held by the user on the user's terminal, and "closed processing," regardless of the name, is actually personal authentication using the user's facial image data. It should be noted that personal authentication using the user's facial image data is said to have an authentication accuracy of approximately 99.99% as of the time of this application, meaning that it is possible to recognize one person out of 10,000. However, by combining this personal authentication using facial image data with terminal device authentication that is performed virtually simultaneously at the time of entry and exit, it is expected that the authentication accuracy will be dramatically improved.
[0021] Next, in the configuration of the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the open PIN code input device is a wireless reader, the terminal identification number of the user terminal is the MAC address number or IMEI number of the user terminal and hands-free wireless input is possible, and the closed PIN code input device is a camera, the biometric information is the user's facial image and hands-free input is possible. These terminal identification numbers are assigned as unique numbers to smartphones, tablets, etc., so that the user terminal can be uniquely identified and authentication can be made as to whether or not the user terminal is authorized to participate in the closed SIM communication network. Hands-free acquisition of the open PIN code and the closed PIN code is possible.
[0022] Next, in the configuration of the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the construction of the closed SIM network is a multi-carrier platform constructed by selecting one or a combination thereof of multiple communication carriers, such as communication networks provided by a Mobile Network Operator, Wi-Fi communication networks, and SXGP communication networks. Communication environments are affected by location and time, and even if the communication environment of a particular carrier is good at a certain time in a certain place, the communication environment of the normally used carrier may suddenly become poor at a different time, or even in the same area, the communication environment of a carrier may change if the location or direction is slightly different. It is important to be able to dynamically select the carrier that provides the best environment when constructing the closed SIM communication network, prioritizing the stability of service provision and enjoyment. In order to adopt a multi-carrier platform, it is sufficient for the user terminal or router to be physically equipped with multiple SIM card slots, and for eSIMs, it is sufficient if they are configured to allow the use of multiple profiles. The criteria for selecting a communication carrier in a multi-carrier platform may be to dynamically select a good carrier prioritizing communication speed, or to dynamically select an inexpensive carrier prioritizing communication charges.
[0023] Next, in the configuration of the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the closed SIM communication network is constructed within a building, the open PIN code input spot and the closed PIN code input spot are provided near the entrances and exits of the building, and users passing through the entrances and exits are restricted from entering the open PIN code input spot, and if there are multiple entrances and exits of the building, the open PIN code input spot and the closed PIN code input spot are provided at each of them.
[0024] In particular, it is preferable that the user authentication process, which involves obtaining a hands-free open PIN and a hands-free closed PIN, is performed when the user enters the building, and that the user authentication process, which involves obtaining a hands-free open PIN and a hands-free closed PIN, is also performed when the user leaves the building. With the above configuration, user authentication can be reliably performed when entering and leaving the closed SIM communication network established within the building.
[0025] In the above configuration, it is preferable that a closed PIN code input spot is provided adjacent to the open PIN code input spot along the user's movement path as they pass through the entrance / exit, and that when the user enters the closed SIM communication network from the entrance / exit, the closed PIN code acquisition process executes an entry-time face capture image synchronization process that links the capture of the user's face image by the camera, provided that the terminal identification number is obtained from the user's terminal in the open PIN code acquisition process, and when the user exits the closed SIM communication network from the exit / exit, the closed PIN code acquisition process executes an exit-time face capture image synchronization process that links the capture of the user's face image by the camera, provided that the terminal identification number is obtained from the user's terminal in the open PIN code acquisition process. With the above configuration, it is preferable that the open PIN code and closed PIN code can be reliably obtained from the user and the user's terminal along the user's movement path when entering and exiting the closed SIM communication network constructed within the building, thereby ensuring reliable authentication of the user's identity. Furthermore, the user's identity verification process involves pinpoint facial image capture, triggered by the acquisition of an open PIN code, and the terminal device authentication and identity verification processes are performed simultaneously.
[0026] In the configuration of the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the service is a data communication service established within the closed SIM communication network within the building, and that the configuration enables data communication between user terminals of users who have successfully authenticated themselves, as well as data communication with computer network resources installed within the closed SIM communication network. With the above configuration, only users who have successfully completed the authentication process will be able to access the company's internal network system established within the building and the computer systems established within the company.
[0027] Next, in the configuration of the closed-network SIM communication network service provision authentication system of the present invention described above, it is preferable that three or more access points capable of calculating the distance from the user terminal are arranged within the predetermined range, and that the location authentication process is a process of determining the location by wireless communication between the user terminal and the access points. For example, if the distance between the user terminal and multiple access points can be calculated, the location of the user terminal, that is, the location of the user, can be determined by so-called three-point measurement calculation. Depending on the arrangement of the access points, the vertical and horizontal positions can also be roughly determined. For example, in the case of an office building, it is possible to detect which floor and approximately where the user is.
[0028] Next, in the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the system is configured to include a qualification authentication processing module that, when a predetermined qualification is required for the provision or enjoyment of the service, confirms and authenticates that the user possesses said qualification at the time of user login or when using the service. It is important that it can be confirmed that persons who participate in the use of the closed SIM communication network service of the present invention and provide or enjoy the service are qualified.
[0029] For example, if the area where the closed SIM communication network is constructed is within a medical facility, the service is a medical service, the qualifications are medical-related qualifications including a physician's license, a nurse's license, and a medical equipment operator's license required for providing the medical service, and the qualification authentication processing module is configured to include a qualification information access module that accesses a national qualification information database, then it becomes possible to authenticate that the service provider holds the medical-related qualifications based on the registered information in the national qualification information database.
[0030] For example, if the area where the closed SIM communication network is constructed is within a medical facility, the service is a universal health insurance service, the eligibility is one of the social insurance qualifications required to receive the medical service, including health insurance eligibility, national health insurance eligibility, mutual aid association membership eligibility, seamen's insurance eligibility, or late-stage elderly medical insurance eligibility, and the eligibility authentication processing module is configured to include an insurance eligibility information access module that accesses an insurance eligibility information database operated by the national or local government based on a My Number insurance card or eligibility confirmation certificate, then it becomes possible to authenticate that the user of the service holds the social insurance qualification based on the registered information in the insurance eligibility information database.
[0031] For example, a configuration is preferred in which the area where the closed SIM communication network is constructed is within a medical facility, the service is a medical service, at least a portion of the medical devices used by the user are IoT medical devices, a medical device ID information reader device is provided that can acquire ID information identifying the IoT medical devices via wireless communication in a predetermined manner, and a medical device authentication processing module is provided that authenticates whether the IoT medical devices used for providing the service are devices intended to be used for providing the service. The ID information identifying the IoT medical devices can be IMEI number information, as many medical devices these days are computer-controlled. With the above configuration, records can be kept not only of the doctors, nurses, and other medical personnel involved in the medical procedure, but also of the main medical devices used.
[0032] Next, in the configuration of the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the area where the closed SIM communication network is constructed is within the office of a building, the service is an attendance management service for employees within the office, the qualification is an employee qualification that permits activity within the office, the qualification authentication processing module comprises a qualification information access module that accesses the employee database of the office, and authenticates that the person entering the closed SIM communication network is a person who holds the employee qualification based on the information in the employee database, and comprises an attendance record processing module that takes records of entry and exit to the closed SIM communication network constructed in the office. In the case of a typical office, the qualifications that a person who can participate in using the closed SIM communication network service of the present invention can be confirmed as being an employee, or, in the case of equipment where specific confidentiality management is implemented, whether or not the person has the access rights qualification set by the company.
[0033] Next, in the configuration of the closed SIM communication network service provision authentication system of the present invention described above, it is preferable that the area where the closed SIM communication network is constructed is a construction site, the service is construction work performed by workers engaged at the construction site, the qualification is a construction-related qualification required for the construction work, and the qualification authentication processing module is equipped with a qualification information access module that accesses the CCUS database of the construction-related qualifications. It is also preferable to have a configuration in which an entry / exit record processing module is provided that can authenticate that a person entering the construction site is a person who holds the construction-related qualification based on the information in the CCUS database, and records the person's entry and exit from the closed SIM communication network constructed at the construction site.
[0034] Furthermore, in the case of a construction site, it is preferable that the qualifications include the residence status required when the construction worker is a foreign national, and that the qualification authentication processing module is configured to include a qualification information access module that accesses the work qualification database. Based on the information in the work qualification database, it is also possible to authenticate that the person entering the construction site is a person who holds the residence status. The present invention with the above configuration can be provided not only as a service provision authentication system within a closed SIM communication network, but also as a service provision authentication program within a closed network, and as a service provision authentication method within a closed network.
[0035] This figure shows the basic configuration of the closed SIM communication network service provision authentication system upon entry. This is a simplified diagram (1) showing the data flow of the basic configuration of the closed SIM communication network service provision authentication system. This is a simplified diagram (2) showing the data flow of the basic configuration of the closed SIM communication network service provision authentication system. This is a simplified diagram (3) showing the data flow of the basic configuration of the closed SIM communication network service provision authentication system. This figure shows the basic configuration of the closed SIM communication network service provision authentication system upon exit. This figure shows an example configuration when the closed SIM communication network service provision authentication system according to Example 2 is applied to a hospital facility. This figure shows an example configuration that includes a medical device authentication process 150 that authenticates whether an IoT medical device used for medical treatment is a planned medical device. This figure shows an example configuration when the closed SIM communication network service provision authentication system according to Example 3 is applied to a construction site. This figure briefly explains the configuration of the application disclosed in Japanese Patent Publication No. 6476533.
[0036] The best mode for carrying out the present invention will be described in detail below with reference to examples. However, the present invention is not limited to these examples. Example 1 will briefly describe the basic configuration and data flow when the closed SIM communication network service provision authentication system is applied to an office space in a typical building. Example 2 will briefly describe the basic configuration and data flow when the closed SIM communication network service provision authentication system is applied to a medical facility. Example 3 will briefly describe the basic configuration and data flow when the closed SIM communication network service provision authentication system is applied to a construction site.
[0037] As Example 1, we will briefly describe the basic configuration and data flow when the closed-network service provision authentication system of the present invention is applied to an office space in a typical building. Figure 1 is a diagram showing the basic configuration of the closed-network service provision authentication system. Figures 2 to 4 are diagrams (part 1, part 2, and part 3) that briefly show the data flow of the basic configuration of the closed-network service provision authentication system.
[0038] As shown in Figure 1, the basic configuration of the closed-network service provision authentication system 1 consists of a closed-network service user authentication application 100, a closed-network SIM communication network 200, a user registration information database 300, and a user terminal 400. Although not shown, an office management control system and the like also exist. In this example, there are two levels of security: the first level of security is the entrance 500 to the office building, and the second level of security is the security gate 550 installed inside the office building. Although not shown, this example also includes an exit from the office building, which, like the entrance 500, is equipped with an open PIN code input spot and a wireless reader device, as well as a closed PIN code input spot and a camera as a biometric information input device. The services that companies manage and operate are diverse, and the instructions for providing those services are also diverse, but here we will explain one example.
[0039] The user authentication application 100 works in conjunction with the computer resources 210 within the closed SIM communication network 200 to authenticate the user when the user starts using a service (for example, when entering the closed SIM communication network 200). User authentication is performed immediately and with high security using an open authentication code and a closed authentication code set for each user, enabling the use of specified services within the closed SIM communication network 200. In other words, when entering from the entrance 500 of the office building, those who have successfully authenticated themselves using the open authentication code and the closed authentication code are invited in, and by passing through the security gate 550, they are able to use data communication within the closed SIM communication network 200 and use corporate business systems, etc. The user authentication application 100 of Embodiment 1 is configured to include at least an open PIN code acquisition processing module 110, a closed PIN code acquisition module 120, and an open PIN code and closed PIN code matching processing module 130. It also includes a control processing module (not shown) that cooperates with computer resources 210 within a closed SIM communication network.
[0040] At the entrance 500 of the office building, an open PIN code input spot 510 is provided along the user's path, and adjacent to it, a closed PIN code input spot 520 is provided. Depending on the structure of the entrance and the flow of movement, these spots are positioned at appropriate locations and angles that users passing through cannot avoid.
[0041] An open PIN code input device 511 is installed at the open PIN code input spot 510. The open PIN code input device 511 is a device that forcibly obtains a terminal identification number from the user terminal 400 in a hands-free manner via wireless communication. For example, it is a wireless reader device that can wirelessly obtain the MAC address number or IMEI number of the user terminal 400 as the terminal identification number of the user terminal 400. The open PIN code acquisition processing module 110 obtains a terminal identification number such as the MAC address number or IMEI number via wireless communication from the user terminal 400 of a user who has entered the open PIN code input spot 510, in a hands-free manner via the open PIN code input device 511.
[0042] A closed PIN code input device 521 is installed at the closed PIN code input spot 520. The closed PIN code input device 521 is a device that forcibly acquires the user's biometric information hands-free, such as a camera. It is adjusted to an angle that captures the user's face image, allowing for hands-free acquisition of the user's face image. While the closed PIN code can be any biometric information, a face image is suitable for biometric information that can be easily acquired hands-free from passing users, and here, the biometric information is a face image. The closed PIN code acquisition processing module 120 acquires the user's face image hands-free from users passing through the closed PIN code input spot 520.
[0043] Here, we will describe the arrangement and coordination of the open PIN code input spot 510 and the closed PIN code input spot 520. As shown in Figure 1, both are arranged along the flow of users entering and exiting the office building, with the closed PIN code input spot 520 located adjacent to the open PIN code input spot 510. The system is designed so that users who enter the open PIN code input spot 510 will immediately enter the closed PIN code input spot 520. Here, regarding the order of the arrangement of the open PIN code input spot 510 and the closed PIN code input spot 520, the basic configuration is shown with the open PIN code input spot 510 at the beginning of the flow and the closed PIN code input spot 520 at the end, but the order of the arrangement can be reversed, and an arrangement where the closed PIN code input spot 520 is at the beginning of the flow and the open PIN code input spot 510 is at the end is also possible. It is preferable to limit the wireless communication area to some extent. For example, it is preferable to limit the communication area of wireless communication equipment to a radius of 10m. Furthermore, the range can be wider or narrower. It can be adjusted according to the environment and purpose of the facility to which this invention is applied. In other words, it is possible to adjust it to a radius narrower than 10m, for example, a radius of 7m, 5m, 3m, 2m, or 1m. Conversely, it is also possible to have a distance wider than 10m. The communication range can be controlled by modifying the output of the wireless communication equipment or surrounding it with radio wave shielding materials. In addition, when a user obtains an open PIN code, which is a terminal identification number, at the open PIN code input spot 510 through the open PIN code acquisition process 110, the closed PIN code acquisition process 120 will synchronize with the capture of the user's face image by the camera at the closed PIN code input spot 520. Here, this is called the "entry-time face image capture synchronization process". Similarly, when a user exits the closed SIM communication network 200, if the open PIN code acquisition process 110 acquires an open PIN code, which is a terminal identification number, the closed PIN code acquisition process 120 will then synchronize with the camera at the closed PIN code input spot 520 to capture an image of the user's face.Here, it is called "processing linked to capturing face images at the time of leaving the premises". In the flow of movement of users when entering and leaving the closed area SIM communication network 200 constructed within the building, it is possible to reliably obtain the open authentication code and the closed authentication code from the users and user terminals, and to reliably perform personal authentication.
[0044] The matching processing module 130 is a module that executes a matching process between the registered open authentication code and the registered closed authentication code registered in the personal authentication application 100 and the user registration information database 300, and the open authentication code and the closed authentication code input hands-free from the user entering from the entrance 500. In this example, it is an example in which the registered open authentication code and the registered closed authentication code are registered in the user registration information database 300. As an important feature, the registered open authentication code and the registered closed authentication code form a pair, and the face image of the corresponding user is determined for the terminal identification number that is the registered open authentication code. By the matching processing module 130 performing matching processing on the open authentication code and the closed authentication code obtained from the user who entered from the entrance 510, two authentications of "terminal device authentication" and "user personal authentication" are executed, and high security is ensured.
[0045] If the matching process of the matching processing module 130 is successful, assuming that the device authentication and the personal authentication are determined, the use of services within the closed area SIM communication network 200 is permitted. Here, data communication, voice calls, etc. between the user terminals 400 of the users (employees) participating in the closed area SIM communication network 200, and the use of the in-house business system constructed by the computer resources in the closed area SIM communication network 200 are assumed.
[0046] The closed SIM communication network 200 is designed so that a fixed private IP address is assigned to a specific SIM card, and data communication is performed in a closed area based on this private IP address. Because secure communication is possible without using the internet, it is a closed communication network that can only be accessed by authorized personnel. The closed SIM communication network 200 is a communication network built using a closed dedicated line or VPN connection provided by an MNO (Mobile Network Operator). Dedicated lines are mobile communication networks provided by operators such as NTT Docomo, au (KDDI), SoftBank, and Rakuten. VPN (Virtual Private Network) is a virtual dedicated network built on the network (closed network) provided by an MNO communication operator, and is provided by an MVNO (Mobile Virtual Network Operator). There are many such MVNO operators, but examples include IIJmio, BIGLOBE Mobile, NURO Mobile, and OCN Mobile ONE. While a closed SIM communication network 200 is not limited to a physically enclosed space and can be established even for remote connections from homes, cafes, or co-working spaces, this example will describe its establishment in a specific physical location such as a particular office building, medical facility, or construction site.
[0047] In the example shown in Figure 1, the closed SIM communication network 200 has multiple routers 220a, 220b, and 220c, as well as computer resources 210 within the SIM communication network and service applications 230. The routers 220 located in the closed SIM communication network 200 perform data transmission and reception using only the fixed private IP address assigned to a specific SIM card as a valid address.
[0048] Here, as a contrivance, the closed-domain SIM communication network 200 is constructed on a multi-carrier platform. With a multi-carrier platform, it becomes possible to connect to the networks of multiple mobile phone carriers, and without being affected by the quality of the communication environment, the carrier with the best conditions at that time and place can be selected. As the carrier, any one of the communication networks provided by MNO (Mobile Network Operator), a Wi-Fi communication network, an SXGP communication network, or a combination thereof can be selected and constructed. Technically, it can be realized in multiple ways. For example, it is sufficient if the user terminal 400 is a terminal equipped with multiple SIM slots. Also, for example, even if the SIM slot of the user terminal 400 has only one, as long as the inserted SIM card itself is a multi-carrier SIM. That is, a plurality of profiles are stored in the multi-carrier SIM, and an appropriate line can be automatically selected.
[0049] In addition, while the above-described components described with reference to FIG. 1 are described as being equipped at one entrance of the building, it is assumed that the same components are also equipped at the exit. Also, when there are multiple entrances and exits, it is assumed that open password input spots 510 and closed password input spots 520 are provided at each location.
[0050] The computer resources 210 within the closed-domain SIM communication network can be a variety of computer resources. It can include all computer resources such as servers, clients, networks, databases, personal computers, and storage devices within an enterprise. The service application 230 is not particularly limited, and there can be a variety of service applications depending on the constructed closed-domain SIM communication network. It can include a variety of things according to the business of the enterprise, such as the enterprise's business system, business application, mail system, CAD system, employee information, medical record, and patient information.
[0051] Next, we will explain a mechanism for detecting the location of a user who has joined the closed SIM communication network 200. In large buildings such as office buildings, or in offices with free-address seating where employees do not have assigned seats, or in jobs where employees move around the premises, there may be a need to confirm the location of users participating in the closed SIM communication network 200. This invention assumes that the user has a specific user terminal, and if there are three or more access points that can communicate with the user terminal, the approximate location can be determined by so-called three-point distance calculation. In other words, user location authentication is also possible. Although access points are not shown in Figure 1, if there are three or more access points equipped as computer resources 210 within the SIM communication network, and the specifications allow for distance calculation from them, user location authentication becomes possible.
[0052] Next, it is also possible to provide an entry / exit record processing system that records entry and exit records for users who have joined the closed SIM communication network 200. For example, the service application 230 of the closed SIM communication network 200 may perform this entry / exit record processing. Although not shown in Figure 1, the system may also include an entry / exit management processing module 160 as shown in Figure 8 of Embodiment 3, which will be described later.
[0053] The above is a brief explanation of each component shown in Figure 1. Below, with reference to Figures 2 to 4, the basic data flow of the user authentication application for services within a closed SIM communication network shown in Figure 1 is briefly explained. <User Entry> Figure 2 is a diagram (part 1) that briefly shows the data flow of the basic configuration of the authentication system for providing services within a closed SIM communication network. As shown in Figure 2, user A enters the office building through the entrance 510 hands-free while holding user terminal A1. An open PIN code input spot 510 is provided directly below the entrance 510 of the office building, and a wireless reader device 511 is installed. User terminal A1 responds to the wireless reader device 511 and transmits a terminal identification number (step S1). For example, MAC address information is transmitted here. The wireless reader device 511 is controlled by the open PIN code acquisition process 110, and the MAC address information acquired by the open PIN code acquisition process 110 (step S2) is passed to the matching processing module 130 as an open PIN code (step S3). Adjacent to the open PIN code input spot 510 at the entrance 510 of the office building, a closed PIN code input spot 520 is provided, equipped with a biometric information input device (camera) 512. In reality, the two spots may overlap. Upon acquisition of the open PIN code, the camera is used to perform a linked process of capturing a facial image upon entry. In other words, a facial image is captured at that specific location by pinpoint image capture (step S4). The closed PIN code acquisition process 120 acquires the user's facial image data obtained from the capture, or edited data obtained from the facial image, as the closed PIN code (step S5), and passes it to the matching processing module 130 (step S6).
[0054] <Terminal device authentication and user authentication> Figure 3 is a simplified diagram (part 2) showing the data flow of the basic configuration of the authentication system for providing services within a closed SIM communication network. The matching processing module 130 compares the registered open PIN and registered close PIN registered in the user registration information database 300 based on the acquired input open PIN and input close PIN (step S7). Here, as shown in Figure 3, the set of registered open PIN and registered close PIN in the database is compared with the input open PIN and input close PIN, and terminal device authentication processing and user authentication processing are performed simultaneously. If both matches are successful, the matching is considered successful (step S7: Yes). If either or both matches are unsuccessful (step S7: No), entry is denied as unauthorized entry. In this case, the security gate 550 is not unlocked.
[0055] <Participation in a Closed SIM Communication Network> Figure 4 is a simplified diagram (part 3) showing the data flow of the basic configuration of the service provision authentication system within the closed SIM communication network. The matching processing module 130 notifies the control device (not shown) of the computer resource 210 within the SIM communication network of the successful completion of the terminal device authentication process and the user authentication process, along with the private IP address information of the user terminal, and the security gate 550 can be unlocked. User A is granted entry and can use user terminal A1 to perform data communication within the closed SIM communication network 200, and can use the computer resource 210 within the SIM communication network (step S8).
[0056] The above explanation focuses on the user's commencement (participation) in the closed SIM communication network 200, but the same considerations apply to the user's termination (departure) from the closed SIM communication network 200. Specifically, at the building exit, a closed PIN code input spot 520 is provided adjacent to the open PIN code input spot 510. When a user intending to exit passes through the open PIN code input spot 510, the wireless reader device 511 obtains the terminal device number from the user terminal 400. Subsequently, when the user passes through the closed PIN code input spot 520, the biometric information input device (camera) 521 obtains a facial image, and the open PIN code / closed PIN code matching process 130 performs the user authentication process to ensure the user is indeed the one leaving the building.
[0057] The basic configuration shown in Figure 1 and the data flow in Figures 2 to 4 above primarily describe the process when entering the closed SIM communication network 200. While the basic configuration and data flow when exiting the closed SIM communication network 200 can be considered in essentially the same way, Figure 5 shows the basic configuration of the authentication system for providing services within the closed SIM communication network when exiting. As shown in Figure 5, the basic configuration upon exit is the same as the basic configuration shown in Figure 1 upon entry. However, the user exits the closed SIM communication network 200 hands-free while holding the user terminal 400. A wireless reader device 511 is positioned along the path of movement when passing through the exit so that the user first passes through the open PIN code input spot 510. The open PIN code acquisition processing module 110 acquires the terminal identification number of the user terminal 400, such as the MAC address number and IMEI number, hands-free. A biometric information input device (camera) 521 is then positioned so that the user continues to pass through the adjacent (essentially the same spot) closed PIN code input spot 520. The closed PIN code acquisition processing module 120 captures the user's face image, and the face image data is acquired hands-free. The open PIN code and closed PIN code matching processing module 130 matches the open PIN code and closed PIN code obtained from the user exiting through the exit, thereby performing two authentication processes: "terminal device authentication" and "user authentication," ensuring a high level of security. Although the following examples 2, 3, and 4 mainly describe the process upon entry, the exit process is also performed in these examples.
[0058] As Example 2, the basic configuration and data flow when the closed-network service provision authentication system of the present invention is applied to a medical facility will be briefly described. Figure 6 is a diagram showing an example configuration when the closed-network service provision authentication system according to Example 2 is applied to a hospital facility. Figure 7 is a diagram showing an example configuration that includes a medical device authentication process 150 that authenticates whether an IoT medical device used for medical treatment is a designated medical device. Among the components shown in Figures 6 and 7, explanations of components that are the same as those described in Example 1 will be omitted as appropriate. Also, the user registration information database 300 is shown in a simplified form compared to Figure 1.
[0059] As shown in Figure 6, in the closed SIM communication network service provision authentication system according to Embodiment 2, a credential authentication processing module 140 is added to the components shown in Figure 1. Although not shown, the access control processing module 160 shown in Embodiment 3 may also be included. The credential verification processing module 140 performs credential authentication processing to confirm and authenticate that the user possesses the required qualifications when logging in or when providing a service within the closed SIM communication network, when such qualifications are required for the provision or enjoyment of a service. Embodiment 2 assumes that the area within which the closed SIM communication network is constructed is within a medical facility and the service is a medical service. Under these circumstances, the required qualifications include medical-related qualifications such as a physician's license, a nurse's license, and a license to operate medical equipment such as X-ray machines, which are necessary for providing medical services. These are national qualifications and the National Qualification Information Database 700 is available for use.
[0060] Furthermore, from the perspective of accessing medical services, the services that patients utilize include the national health insurance service. The qualifications required to access medical services include health insurance qualifications, national health insurance qualifications, mutual aid association membership qualifications, seamen's insurance qualifications, or social insurance qualifications including late-stage elderly medical insurance qualifications. The qualification verification processing module 140 has a qualification information access processing function that accesses the national qualification information database 700 in these qualification authentication processes, and authenticates that the service provider (closed SIM communication network user) holds medical-related qualifications based on the registration information in the national qualification information database 700.
[0061] Furthermore, the qualification authentication processing module 140 is equipped with an insurance qualification information access processing function that accesses an insurance qualification information database operated by the national or local government based on the My Number Insurance Card or qualification confirmation certificate, and authenticates that the service user (patient) holds social insurance qualifications based on the registered information in the insurance qualification information database.
[0062] While it is possible for the identity verification application 100's qualification verification processing module 140 to directly access the registered information in the national qualification information database 700 to obtain qualification information, using a website called the qualification authentication portal system 600 is also very convenient and has many advantages. From the perspective of protecting personal information, it may be problematic for the identity verification application 100, which is based on the premise of using a closed SIM communication network built within private medical facilities, to directly access the national qualification information database 700. It is also conceivable to collect qualification information in advance and generate and utilize a unique qualification information database within the identity verification application 100, but since qualifications can be lost or revoked due to the actions of the qualified person, and have expiration dates that are renewed, qualification information from only a single point in the past cannot be used, and it is necessary to always obtain the most recent and latest qualification information. It is difficult for private medical facilities to overcome these problems. Therefore, a system called the qualification authentication portal system 600, operated by an organization that overcomes the above problems and provides personal information protection and the latest qualification information, has been conceived. In the example shown in Figure 6, the system allows for the use of the qualification authentication portal system 600 and the utilization of the national qualification information database 700 through the qualification authentication portal system 600.
[0063] From the perspective of providing medical services, it is important that appropriate medical devices are used in medical procedures and are in a properly maintained state. Therefore, a configuration in which the medical devices used are IoT medical devices and a medical device ID information reader device is provided that can acquire ID information (terminal device number) that identifies these IoT medical devices via wireless communication in a predetermined manner is preferable. In the configuration shown in Figure 7, a medical device authentication process 150 is provided to authenticate whether the IoT medical device to be used for medical treatment is the intended medical device.
[0064] As Example 3, we will briefly explain the basic configuration and data flow when the closed-network SIM communication network service provision authentication system is applied to a construction site. In Example 3, the service provided is construction work performed by workers engaged at the construction site, and the qualifications are construction-related qualifications required for construction work. Figure 8 is a diagram showing an example configuration when the closed-network SIM communication network service provision authentication system according to Example 3 is applied to a construction site. Among the components shown in Figure 8, explanations of components that are the same as those explained in Example 1 will be omitted as appropriate. In the configuration example shown in Figure 8, the user registration information database 300 is illustrated in a simplified manner compared to the configuration in Figure 1.
[0065] As shown in Figure 8, in the closed SIM communication network service provision authentication system according to Embodiment 3, a credential authentication processing module 140 and an access control processing module 160 are added to the components shown in Figure 1. Furthermore, the databases accessible by the credential authentication portal system 600 used by the credential authentication processing 140 described in Embodiment 2 include the credential information database 700 and the residence status / work status information database 800.
[0066] The CCUS database is an example of the construction-related qualification information database 700. For example, the qualification authentication process 140 is equipped with a qualification information access processing function that accesses the CCUS database to obtain information. By using the CCUS database, it is possible to authenticate what construction-related qualifications a construction worker entering a construction site holds. In recent years, the number of foreign nationals working in construction has been increasing. Therefore, the qualifications that the qualification authentication processing module 140 should authenticate are not only qualifications related to construction work, but also, in the case of construction workers of foreign nationality, whether they hold a valid residence status. The qualification authentication processing module 140 is equipped with a qualification information access processing function that accesses the residence status / work qualification database 800. Based on the information in the residence status / work qualification database 800, it is possible to authenticate that users entering a construction site hold a valid residence status or work qualification.
[0067] Next, the access control processing module 160 is equipped with an access record processing function that records entry and exit to the closed SIM communication network established at the construction site. It is desirable to properly record entry and exit to construction sites in order to eliminate excessive work and ensure a proper working environment.
[0068] 100 User authentication application for services within a closed SIM communication network 200 Closed SIM communication network 300 User registration information database 400 User terminal 500 Entrance (exit) of office building 550 Security gate 600 Qualification authentication portal system 700 Qualification information database 800 Residence status / work qualification information database
Claims
1. An authentication application that enables the use of a predetermined service within a closed SIM communication network established within a predetermined range by establishing identity authentication using a registered open authentication code and a registered closed authentication code set for each user, wherein the open authentication code is the terminal identification number of the user's terminal, and the closed authentication code is the user's biometric information, and within the closed SIM communication network, there are defined open authentication code input spots where a wireless open authentication code input device is installed and closed authentication code input spots where a closed authentication code input device is installed, and the authentication application provides a computer system with: a hands-free input open authentication code acquisition process that wirelessly acquires the terminal identification number from the user's terminal via the open authentication code input device when the user enters the open authentication code input spot; and a hands-free input closed authentication code acquisition process that acquires the user's biometric information from the user via the closed authentication code input device when the user enters the closed authentication code input spot. An authentication process that performs a comparison process between the registered open PIN and the registered closed PIN and the input open PIN and the input closed PIN entered hands-free; and a hands-free closed SIM communication network service user authentication application that, upon successful completion of the comparison process, permits the use of services within the closed SIM communication network.
2. The hands-free closed SIM communication network service user authentication application according to claim 1, wherein the authentication process using the input open PIN and the registered open PIN is terminal device authentication using the terminal identification number, and the authentication process using the input closed PIN and the registered closed PIN is personal authentication using facial image data.
3. The hands-free user authentication application for a closed SIM communication network service according to claim 2, wherein the open PIN code input device is a wireless reader, the terminal identification number of the user terminal is the MAC address number or IMEI number of the user terminal and wireless hands-free input is possible, and the closed PIN code input device is a camera, the biometric information is the user's facial image and hands-free input is possible.
4. The hands-free application for user authentication of a service within a closed SIM communication network according to claim 3, wherein the service is a data communication service established within the closed SIM communication network, and enables data communication between user terminals of the user who has successfully authenticated the user, and data communication with computer network resources installed within the closed SIM communication network.
5. The closed SIM communication network service provision authentication system according to claim 4, characterized in that the closed SIM communication network is constructed by selecting one or a combination thereof of multiple communication carriers, including communication networks provided by Mobile Network Operators, Wi-Fi communication networks, and SXGP communication networks, and is a multi-carrier platform.
6. The hands-free application for user authentication of a service within a closed SIM communication network according to claim 1, characterized in that the closed SIM communication network is constructed within a building, the open PIN code input spot and the closed PIN code input spot are provided near the entrances and exits of the building, users passing through the entrances and exits are restricted from entering the open PIN code input spot, and if there are multiple entrances and exits of the building, the open PIN code input spot and the closed PIN code input spot are provided at each of them.
7. The hands-free user authentication application for use of a closed SIM communication network service according to claim 6, characterized in that the user authentication process using the hands-free open PIN acquisition process and the hands-free closed PIN acquisition process is performed when the user enters the building, and the user authentication process using the hands-free open PIN acquisition process and the hands-free closed PIN acquisition process is performed when the user leaves the building.
8. A hands-free application for authenticating a user of a service within a closed SIM communication network, as described in 7, characterized in that, when the user enters the closed SIM communication network from the entrance of the entrance, the closed SIM acquisition process executes an entry-time face capture synchronization process, which is triggered by the acquisition of the terminal identification number from the user terminal in the open SIM acquisition process, and the closed SIM acquisition process executes an exit-time face capture synchronization process, which is triggered by the acquisition of the terminal identification number from the user terminal in the open SIM acquisition process, and the close SIM acquisition process executes an exit-time face capture synchronization process, which is triggered by the acquisition of the terminal identification number from the user terminal in the open SIM acquisition process, and the closed SIM acquisition process executes an exit-time face capture synchronization process, which is triggered by the acquisition of the camera, and the closed SIM acquisition process executes an exit-time face capture synchronization process, which is triggered by the acquisition of the terminal identification number from the user terminal in the open SIM acquisition process.
9. A hands-free application for authenticating the user of a service within a closed SIM communication network, according to claim 1, wherein three or more access points capable of wireless communication with the user terminal are located within the closed SIM communication network, and a location authentication process is performed to authenticate the user's location by measuring the distance between the user terminal and the access points.
10. A hands-free application for authenticating the user of a service within a closed SIM communication network, according to any one of 1 to 9, characterized in that, when the provision or enjoyment of the service requires a predetermined qualification, the application performs a qualification authentication process to confirm and authenticate that the user possesses the said qualification at the time of login or use of the service.
11. A hands-free application for authenticating the user of a service within a closed SIM communication network according to claim 10, wherein the area within which the closed SIM communication network is constructed is within a medical facility, the service is a medical service, the qualification is a medical-related qualification including a physician's license, a nurse's license, and a medical equipment operator's license required for providing the medical service, and the qualification authentication process includes a qualification information access process that accesses a national qualification information database, and authenticates that the service provider holds the medical-related qualification based on the registered information in the national qualification information database.
12. The hands-free application for user authentication of a service within a closed SIM communication network according to claim 10, wherein the service is a national health insurance service, the qualification is one of the social insurance qualifications including health insurance qualification, national health insurance qualification, mutual aid association membership qualification, seamen's insurance qualification, or late-stage elderly medical insurance qualification required to enjoy the medical service, and the qualification authentication process includes an insurance qualification information access process that accesses an insurance qualification information database operated by the national or local government based on a My Number insurance card or qualification confirmation certificate, and authenticates that the user of the service holds the social insurance qualification based on the registered information in the insurance qualification information database.
13. The hands-free application for user authentication of a service within a closed SIM communication network according to 11, characterized in that the service is a medical service, at least a portion of the medical devices used by the user are IoT medical devices, the application comprises a medical device ID information reader device capable of obtaining ID information that identifies the IoT medical devices via wireless communication in a predetermined manner, and the application comprises a medical device authentication process that authenticates whether the IoT medical devices used for providing the service are devices intended to be used for providing the service.
14. The hands-free application for user authentication of a service within a closed SIM communication network according to 10, characterized in that the area where the closed SIM communication network is constructed is within the company office of a building, the service is an employee attendance management service for employees within the office, the qualification is an employee qualification that permits activity within the office, the qualification authentication process includes a qualification information access process that accesses the employee database of the office, and authenticates that the person entering the closed SIM communication network is a person who holds the employee qualification based on the information in the employee database, and includes an attendance record process that takes records of entry and exit to the closed SIM communication network constructed in the office.
15. The hands-free application for user authentication of a service within a closed SIM communication network according to 10, characterized in that the area where the closed SIM communication network is constructed is a construction site, the service is construction work performed by workers engaged at the construction site, the qualification is a construction-related qualification required for the construction work, the qualification authentication process includes a qualification information access process that accesses a CCUS database of construction-related qualifications, and authenticates that the user entering the construction site is a person who holds the construction-related qualification based on the information in the CCUS database, and includes an entry / exit record process that takes records of entry and exit to the closed SIM communication network constructed at the construction site.
16. The hands-free application for user authentication of a service within a closed SIM communication network according to claim 15, wherein the qualifications include the status of residence required when the construction worker is a foreign national, and the qualification authentication process includes a qualification information access process that accesses a work qualification database, and further authenticates that the user entering the construction site is a person who holds the status of residence based on the information in the work qualification database.
17. A personal authentication method that enables the use of a predetermined service within a closed SIM communication network constructed within a predetermined range by establishing personal authentication using a registered open authentication code and a registered closed authentication code set for each user, wherein the open PIN code is the terminal identification number of the user's terminal, the closed PIN code is the user's biometric information, the closed SIM communication network is defined as having open PIN code input spots where open PIN code input devices are installed and closed PIN code input spots where closed PIN code input devices are installed, a hands-free open PIN code acquisition process that acquires the terminal identification number wirelessly via the open PIN code input device from the user's terminal that has entered the open PIN code input spot, a hands-free closed PIN code acquisition process that acquires the user's biometric information via the closed PIN code input device from the user that has entered the closed PIN code input spot, and a personal authentication process that performs a comparison process between the registered open PIN code and the registered closed PIN code and the open PIN code and the closed PIN code that were entered hands-free. A hands-free method for authenticating the user of a service within a closed SIM communication network, which permits the use of the service within the closed SIM communication network upon successful completion of the aforementioned verification process.