Server, use eligibility determination system, use eligibility determination method, and program

WO2026196466A1PCT designated stage Publication Date: 2026-09-24NEC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/010655
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2026-09-24

Smart Images

  • Figure JP2025010655_24092026_PF_FP_ABST
    Figure JP2025010655_24092026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention enables the use of a shared thing without identifying personal information while saving time and effort for managing personal information. A server according to the present disclosure determines whether or not a person is eligible to use a shared thing that is used in common by a group. The server is provided with: an authentication face image generation unit that generates an authentication face image on the basis of a composite face image obtained by compositing face images of a plurality of users included in the group; and a determination unit that determines whether or not the person is eligible to use the shared thing on the basis of a result of verifying a face image of the person with the authentication face image.
Need to check novelty before this filing date? Find Prior Art

Description

Server, availability determination system, availability determination method and program

[0001] The present disclosure relates to a server, an availability determination system, an availability determination method, and a program.

[0002] Patent Document 1 discloses a face matching system. In the face matching system disclosed in Patent Document 1, a composite face template is generated based on face image data of a plurality of monitored persons in a template generation apparatus. Then, in a primary processing apparatus, input face image data is subjected to matching processing with the composite face template, and input face image data having a matching rate equal to or higher than a predetermined value is transmitted to a secondary processing apparatus. Then, in the secondary processing apparatus, individual identification is performed by comparing the input face image data with stored face templates, that is, individual face data, and specifying identification information.

[0003] Japanese Patent Application Laid-Open No. 2012-133411

[0004] In the face matching system disclosed in Patent Document 1, individual face data is stored, and strict management of personal information is required. On the other hand, when a plurality of users share a shared object including objects and facilities, each user does not want their personal information to be identified.

[0005] In view of the above-mentioned problems, an object of the present disclosure is to provide a server, an availability determination system, an availability determination method, and a program that allow a shared object to be used without identification of personal information while omitting the trouble of managing personal information.

[0006] A server according to the present disclosure is a server that determines whether a subject can use a shared object that is shared and used by a group, and includes: an authentication face image generation unit that generates an authentication face image based on a composite face image obtained by combining face images of a plurality of users included in the group; and a determination unit that determines whether the subject can use the shared object based on a matching result between the subject's face image and the authentication face image.

[0007] The availability determination system relating to this disclosure comprises a server and a face image acquisition device, and is a availability determination system for determining whether a target person is available for use by a group of users to be shared, wherein the face image acquisition device acquires the face image of the target person and transmits the face image of the target person to the server, the server generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determines whether the target person is available for use by the group of users based on the result of comparing the face image of the target person received from the face image acquisition device with the authentication face image.

[0008] The method for determining eligibility to use a shared user entity shared by a group is a method for determining whether a target person is eligible to use a shared user entity shared by a group, and the computer performs a process that generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determines whether the target person is eligible to use the shared user entity based on the result of matching the target person's face image with the authentication face image.

[0009] The program relating to this disclosure is a program for determining whether a target person is eligible to use a shared user entity that is shared and used by a group, and causes a computer to perform the following processing: generating an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determining whether the target person is eligible to use the shared user entity based on the result of matching the target person's face image with the authentication face image.

[0010] This disclosure makes it possible to provide a server, an accessibility determination system, an accessibility determination method, and a program that allow users to access shared resources without identifying their personal information, while reducing the effort required for managing personal information.

[0011] This is a block diagram illustrating the server related to this disclosure. This is a flowchart showing the method for determining whether or not the information can be used related to this disclosure. This is a block diagram illustrating the server related to this disclosure. This is an explanatory diagram of a composite face image. This is a flowchart showing the method for determining whether or not the information can be used related to this disclosure. This is a flowchart showing the method for determining whether or not the information can be used related to this disclosure. This is an explanatory diagram for explaining the matching process. This is an explanatory diagram of an adversarial image. This is a flowchart showing the method for determining whether or not the information can be used related to this disclosure. This is an explanatory diagram for explaining the matching process. This is a block diagram illustrating the system for determining whether or not the information can be used related to this disclosure. This is a flowchart showing the method for determining whether or not the information can be used related to this disclosure. This is a block diagram showing an example of the server configuration related to this disclosure.

[0012] The present disclosure will be described below through embodiments, but the disclosure relating to the claims is not limited to the embodiments described below. Furthermore, not all of the configurations described in the embodiments are necessarily essential as means of solving the problem. In each drawing, the same elements are denoted by the same reference numerals, and redundant explanations are omitted where necessary.

[0013] <Embodiment 1> <Server> The configuration of the server according to this disclosure will be described below with reference to Figure 1. Figure 1 is a block diagram illustrating the server according to this disclosure. As shown in Figure 1, the server 10 includes an authentication face image generation unit 11 and a determination unit 12.

[0014] Server 10 is a server that determines whether a person is allowed to use a shared user. A shared user is a facility or object that is shared by a group of people, such as a fitness facility, an office, or a personal computer.

[0015] The authentication face image generation unit 11 generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group. The composite face image is, for example, an image obtained by averaging multiple face images, an image obtained by montaging multiple face images, or an image obtained by morphing multiple face images. The authentication face image is the image used for matching with the face image of the target person.

[0016] The determination unit 12 determines whether the subject is eligible to use the shared user based on the result of matching the subject's face image with the authentication face image. Specifically, the determination unit 12 determines that the subject is included in the group and is eligible to use the shared user if the subject's face image and the authentication face image match. Conversely, the determination unit 12 determines that the subject is not included in the group and is not eligible to use the shared user if the subject's face image and the authentication face image do not match.

[0017] Matching between the subject's face image and the authentication face image indicates that the matching rate between the two images is within a predetermined range. Conversely, failure to match between the subject's face image and the authentication face image indicates that the matching rate between the two images is outside a predetermined range. The predetermined range for the matching rate can be set arbitrarily.

[0018] In typical facial recognition systems, facial recognition is performed by comparing the facial image of the subject, which is captured by taking a photograph, with the facial image of a user that has been registered in advance. In contrast, the server 10 related to this disclosure does not require the storage (registration) of the user's facial image, thus reducing the effort required for managing personal information.

[0019] Furthermore, in the server 10 related to this disclosure, the matching of the authentication face image with the face image of the subject only determines whether or not the subject belongs to the group, and therefore the subject's personal information is not identified.

[0020] Therefore, with the server 10 related to this disclosure, the effort required for managing personal information is reduced, and the target user can use the shared user without their personal information being identified.

[0021] <Method for Determining Availability> Next, we will explain the method for determining availability related to this disclosure. Figure 2 is a flowchart showing the method for determining availability related to this disclosure. In Figure 2, the symbols shown in Figure 1 will be used as appropriate to explain the process.

[0022] First, the authentication face image generation unit 11 generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group (step ST1).

[0023] Next, the determination unit 12 determines whether the subject can use the shared user based on the result of matching the subject's face image with the authentication face image (step ST2).

[0024] By adopting this configuration, the method for determining whether or not to use the information related to this disclosure can reduce the effort required for managing personal information, while allowing the target user to use the shared information without their personal information being identified.

[0025] <Embodiment 2> <Server> The configuration of the server according to this disclosure will be described below with reference to Figure 3. Figure 3 is a block diagram illustrating the server according to this disclosure. As shown in Figure 3, the server 20 includes an authentication face image generation unit 21, a registration unit 22, and a determination unit 23. The following description will be given as an example when the authentication face image is a composite face image.

[0026] The authentication face image generation unit 21 and the determination unit 23 are the same as those in the server 10 shown in Figure 1. Here, the registration unit 22 will be described.

[0027] <Registration of Authentication Face Images> The registration unit 22 registers the authentication face images generated by the authentication face image generation unit 21. Typically, the registration unit 22 registers the images in a storage unit within the server 10. However, it is not limited to this configuration, and the registration unit 22 may also be configured to register the images in a storage unit (not shown in Figure 3) located outside the server 10.

[0028] <Synthetic Face Image> A synthetic face image is an image in which a person cannot recognize multiple users included in a group when viewed visually. This will be explained in detail with reference to Figure 4. Figure 4 is an explanatory diagram of a synthetic face image. As shown in Figure 4, the male image IG1 and the female image IG2 are the original images of the synthetic face image M1.

[0029] The composite face image M1 is, for example, an image obtained by averaging a male image IG1 and a female image IG2, an image obtained by montaging a male image IG1 and a female image IG2, or an image obtained by morphing a male image IG1 and a female image IG2.

[0030] The composite face image M1 shown in Figure 4 is an image that, when viewed visually, cannot be recognized as the male in image IG1. Similarly, the composite face image M1 shown in Figure 4 is an image that, when viewed visually, cannot be recognized as the female in image IG2.

[0031] Thus, the synthesized face image M1 is an image that, when viewed visually by a person, cannot be identified (recognized) as the original images IG1 and IG2. Details of the matching using the synthesized face image M1 shown in Figure 4 will be described later.

[0032] <Method for Determining Availability> Next, we will explain the method for determining availability related to this disclosure. Figures 5 to 7 are flowcharts showing the method for determining availability related to this disclosure. In Figures 5 to 7, the symbols shown in Figure 1 will be used as appropriate to explain the process.

[0033] <Generating Authentication Face Images> The process of generating authentication face images will be explained with reference to Figure 5. Here, we will explain using the case where the authentication face image is a composite face image as an example. As shown in Figure 5, the face images of multiple users included in the group are input to the server 10 (step ST21).

[0034] Next, as shown in Figure 5, the authentication face image generation unit 21 generates a composite face image by combining the face images (original images) of multiple users included in the group (step ST22). For example, the authentication face image generation unit 21 generates parameters to align the feature points of the original images and creates a morphed image by deforming the images based on the parameters. The authentication face image generation unit 21 may generate the composite face image using known techniques.

[0035] Next, as shown in Figure 5, the authentication face image generation unit 21 determines whether each of the matching values ​​indicating the difference between the face images of the users included in the group and the composite face image falls within a predetermined range (step ST23). For example, if there are three face images of users included in the group, the unit determines whether all of the matching values ​​(three matching values) between each image and the composite face image fall within a predetermined range. In other words, in step ST23, the authentication face image generation unit 21 compares each original image with the composite face image and determines whether any of the original images match the composite face image.

[0036] Next, as shown in Figure 5, the authentication face image generation unit 21 adjusts the parameters (step ST24) if each of the matching values ​​is not within a predetermined range (step 23NO). The authentication face image generation unit 21 repeats steps ST22 to ST24 until each of the matching values ​​is within a predetermined range.

[0037] On the other hand, as shown in Figure 5, the authentication face image generation unit 21 terminates processing if each of the matching values ​​is within a predetermined range (step 23 YES).

[0038] <Registration of Composite Face Image> The process of registering a composite face image will be explained with reference to Figure 6. As shown in Figure 6, a composite face image (authentication face image) is input to the registration unit 22 (step ST31). Next, as shown in Figure 6, the registration unit 22 detects the face in the composite face image (step ST32). The registration unit 22 detects, for example, the position of the face and the facial features of the composite face image.

[0039] Next, as shown in Figure 6, the registration unit 22 extracts feature quantities and metadata from the synthesized face image (step ST33). The registration unit 22 also associates the extracted feature quantities and metadata with the synthesized face image and registers them in the server 10 (step ST33).

[0040] As described above, the registration unit 22 registers a composite face image and does not register the face image of each user included in the group. Therefore, since the server 10 does not hold personal information in the first place, the use of the server 10 can suppress the leakage of personal information. In other words, it can be said that the use of the server 10 can save the labor of managing personal information.

[0041] In addition, the registration unit 22 does not register each of the face images of a plurality of users, but registers the composite face image, so that the capacity of the storage unit can be reduced. For example, when registering one composite face image, the capacity of the storage unit can be halved compared to registering each of the two face images of two users. Thereby, the cost of the hardware constituting the storage unit can be reduced.

[0042] <Determination of Availability> With reference to FIG. 7, a process of determining whether a target person can use a shared object will be described. As shown in FIG. 7, the face image of the target person is input to the determination unit 23 (step ST41). For example, the face image of the target person obtained by photographing is input to the determination unit 23.

[0043] Next, as shown in FIG. 7, the determination unit 23 detects the face in the face image of the target person (step ST42). The determination unit 23 detects, for example, the face position and face parts in the face image of the target person. Next, as shown in FIG. 6, the determination unit 23 extracts a feature amount and meta information from the face image of the target person (step ST43).

[0044] Next, as shown in FIG. 7, the determination unit 23 collates the face image of the target person with the composite face image (authentication face image) (step ST44). For example, the determination unit 23 collates the feature amount and meta information of the composite face image with the feature amount and meta information of the target person's face image.

[0045] Next, the determination unit 23 determines whether or not the target person's face image matches the composite face image (authentication face image) (step ST45). Here, with reference to FIG. 8, the collation process performed by the determination unit 23 will be described more specifically. FIG. 8 is an explanatory diagram for explaining the collation process.

[0046] In FIG. 8, a synthesized face image M1, a male face image IG1, and a male face image IG3 are shown. As described with reference to FIG. 4, the male face image IG1 shown in FIG. 8 is the original image of the synthesized face image M1 shown in FIG. 8. On the other hand, the male face image IG3 shown in FIG. 8 is not the original image of the synthesized face image M1 shown in FIG. 8.

[0047] The upper row of FIG. 8 shows an example of matching processing when the subject is the male of the face image IG1. In the upper row of FIG. 8, the determination unit 23 determines that the face image IG1 matches the synthesized face image M1. Therefore, as shown in FIG. 7, when the face image of the subject matches the synthesized face image, the determination unit 23 determines that the subject is included in the group and the shared-use object is available for use (step ST46).

[0048] As described above, the synthesized face image M1 shown in FIG. 4 and FIG. 8 is an image in which the original image IG1 cannot be identified when visually observed by a person. Further, as shown in the upper row of FIG. 8, when the subject is the male of the face image IG1, the determination unit 23 performs processing by matching the face image IG1 and the synthesized face image M1 as matching. With such a configuration, the subject can use the shared-use object without their personal information being identified.

[0049] The lower row of FIG. 8 shows an example of matching processing when the subject is the male of the face image IG3. In the lower row of FIG. 8, the determination unit 23 determines that the face image IG3 does not match the synthesized face image M1. This is because the male face image IG3 is not the original image of the synthesized face image M1.

[0050] Therefore, as shown in Figure 7, the determination unit 23 determines that if the subject's face image and the synthesized face image do not match, the subject is not included in the group and therefore cannot use the shared user (step ST47). By having this configuration, the server 10 can suppress unauthorized use of the shared user. In addition, the server 10 may be configured to notify a predetermined device that an attempt has been made to use the shared user illegally in step ST47. <Embodiment 3> <Server> The server according to this disclosure will now be described. The block diagram of the server according to this disclosure is the same as in Figure 3. In the server according to this disclosure, the authentication face image is an image that has been processed so that a person cannot see the synthesized face image. In the following, an adversarial image will be used as an example of an image that has been processed so that a person cannot see the synthesized face image.

[0051] <Adversarial Images> Adversarial images will be explained with reference to Figure 9. Figure 9 is an explanatory diagram of adversarial images. The composite face image M1, the male image IG1, and the female image IG2 shown in Figure 9 are the same as those shown in Figure 4. The adversarial image M3 shown in Figure 9 is an image created by overlaying the composite face image M1 as a guide image onto the source image M2. The source image M2 is any face image other than the composite face image M1, and is a dummy face image.

[0052] The adversarial image M3 shown in Figure 9 is recognized as the source image M2 when viewed by a human, making it impossible to distinguish between the original images IG1 and IG2. On the other hand, when the adversarial image M3 shown in Figure 9 is compared with the subject's face image, it is recognized as the composite face image M1.

[0053] In other words, the adversarial image M3 is an image created by processing the composite face image M1 so that it cannot be seen by the human eye, and in the case of face recognition matching, it is recognized as the composite face image M1. In Figure 9, the adversarial image M3 is shown with a dotted line representing the composite face image IG1 and a solid line representing the source image M2. Details of matching using the adversarial image M3 shown in Figure 9 will be described later.

[0054] <Method for Determining Usability> Next, we will explain the method for determining usability using adversarial images, referring to Figure 10. Figure 10 is a flowchart showing the method for determining usability related to this disclosure. Figure 10 is a flowchart showing the process for generating adversarial images.

[0055] Here, regarding the generation process of adversarial images, the registration process of adversarial images, and the determination process of whether the target can use the shared user's data, explanations will be omitted where they are the same as in Figure 7, and the differences will be explained.

[0056] <Generation of Adversarial Images> The process for generating authentication face images (adversarial images) will be explained with reference to Figure 10. As shown in Figure 10, steps ST21 to ST24 related to the synthesized face image are the same as in Figure 5, so the explanation will be omitted.

[0057] As shown in Figure 10, the authentication face image generation unit generates an authentication face image (adversarial image) based on the composite face image (step ST54). Specifically, the authentication face image generation unit generates an adversarial image by superimposing the composite face image as a guide image onto a source image, which is any face image other than the composite face image.

[0058] Next, as shown in Figure 10, the authentication face image generation unit determines whether each of the matching values ​​indicating the discrepancy between the face images of users included in the group and the adversarial image falls within a predetermined range (step ST55). For example, if there are three face images of users included in the group, the unit determines whether all of the matching values ​​(three matching values) between each image and the adversarial image fall within a predetermined range. In other words, the authentication face image generation unit 21 compares each original image with the synthesized face image and determines whether any of the original images are matched.

[0059] Next, as shown in Figure 10, the authentication face image generation unit adjusts the parameters (step ST56) if each of the matching values ​​is not within a predetermined range (step 55NO). The authentication face image generation unit 21 repeats steps ST54 to ST56 until each of the matching values ​​is within a predetermined range.

[0060] Furthermore, the authentication face image generation unit may determine the noise level of the composite face image, which is a guide image, so that each of the matching values ​​falls within a predetermined range. The greater the noise level of the composite face image, the easier it is for adversarial images to be recognized as composite face images when face authentication matching is performed.

[0061] On the other hand, as shown in Figure 10, the authentication face image generation unit terminates processing if each of the matching values ​​is within a predetermined range (step 55 YES).

[0062] <Registration of Adversarial Images> Next, we will explain the registration process for adversarial images. The registration process for adversarial images is basically the same as the registration process shown in Figure 6. The difference in this registration process compared to the registration process shown in Figure 6 is that the target of registration is adversarial images. In other words, the registration unit registers adversarial images and does not register the face images or composite face images of each user included in the group.

[0063] Therefore, since server 10 does not possess any personal information in the first place, using server 10 can suppress the leakage of personal information. Furthermore, even if adversarial images are leaked, it is not possible to visually identify each user's face image or a composite face image from the adversarial images, so there is no risk of personal information being identified. In other words, using server 10 can reduce the effort required to manage personal information.

[0064] <Determination of Availability> Next, we will explain the process for determining whether the shared user body of the target person can be used using adversarial images. The process for determining availability is basically the same as the determination process shown in Figure 7. In this determination process, the difference from the determination process shown in Figure 7 is that in step ST44 shown in Figure 7, the adversarial image is compared with the face image of the target person. We will explain this in detail with reference to Figure 11.

[0065] Figure 11 is an explanatory diagram illustrating the matching process. Figure 11 shows adversarial image M3, male face image IG1, and male face image IG3. As explained in Figure 9, male face image IG1 shown in Figure 11 is the original image of adversarial image M3 shown in Figure 11. On the other hand, male face image IG3 shown in Figure 11 is not the original image of adversarial image M3 shown in Figure 11.

[0066] The upper part of Figure 11 shows an example of the matching process when the subject is a male, represented by face image IG1. In the upper part of Figure 11, the determination unit determines that face image IG1 and adversarial image M3 are a match. More specifically, face image IG1 matches with the composite face image M1, which is a guide image for adversarial image M3. Therefore, the determination unit determines that face image IG1 and adversarial image M3 are a match. Consequently, the process of step ST46 shown in Figure 7 is executed.

[0067] As described above, the adversarial image M3 shown in Figures 9 and 11 is an image created by processing the composite face image IG1 so that it cannot be seen by a human eye. Furthermore, as shown in the upper part of Figure 11, if the subject is the male in face image IG1, the determination unit 23 processes the face image IG1 and the adversarial image M3 by comparing them. With this configuration, the subject can use the shared user with less identification of their personal information.

[0068] The lower part of Figure 11 shows an example of the matching process when the subject is a male, as shown in face image IG3. In the lower part of Figure 11, the determination unit 23 determines that face image IG3 and adversarial image M3 do not match. More specifically, face image IG3 and composite face image M1, which is a guide image for adversarial image M3, do not match. This is because the male face image IG3 is not the original image of composite face image M1. Therefore, the determination unit determines that face image IG3 and adversarial image M3 do not match. For this reason, the process of step ST47 shown in Figure 7 is executed. By using this configuration, the server 10 can suppress the unauthorized use of the shared user. <Embodiment 4> <Usability Determination System> The configuration of the usability determination system according to this disclosure will now be described. Figure 12 is a block diagram illustrating the usability determination system according to this disclosure. As shown in Figure 12, the usability determination system 100 includes a server 70 and a face image acquisition device 80.

[0069] <Face Image Acquisition Device> As shown in Figure 12, the face image acquisition device 80 includes a shooting unit 81. The shooting unit 81 captures a face image of the subject. The shooting unit 81 is, for example, a camera. The face image acquisition device 80 uses the shooting unit 81 to capture and acquire a face image of the subject. The face image acquisition device 80 transmits the face image of the subject to the server 70.

[0070] <Server> The server 70 includes an authentication face image generation unit 71, a determination unit 72, and a control unit 73. The authentication face image generation unit 71 and the determination unit 72 are the same as in Embodiments 1 to 3, so their description will be omitted. Here, the control unit 73 will be described.

[0071] <Detection of facial image for authentication> When the control unit 73 receives an authentication facial image from the facial image acquisition device as the facial image of the subject, it controls the determination unit 72 so as not to execute the determination process of whether the subject can use the shared user.

[0072] The authentication facial image received from the facial image acquisition device refers to an authentication facial image based on a composite facial image created by combining the facial images of multiple users included in a group. The authentication facial image received from the facial image acquisition device is, for example, the composite facial image or adversarial image described in Embodiment 2 and Embodiment 3.

[0073] The control unit will be explained in more detail with reference to Figure 13. Figure 13 is a flowchart showing the method for determining whether or not a user can use the device according to this disclosure. Figure 13 is a flowchart showing the process for determining whether or not a user can use the shared device of the target user.

[0074] In Figure 13, the processes other than step ST71 are the same as in Figure 7, so the explanation is omitted. As shown in Figure 13, when the subject's face image is input to the determination unit 23 (step ST41), the control unit 73 determines whether or not the input subject's face image is an authentication face image (step ST71).

[0075] If the input subject's face image is an authentication face image (step ST71 YES), the control unit 73 controls the determination unit 72 so as not to execute the processes from step ST42 onwards. On the other hand, if the input subject's face image is not an authentication face image (step ST71 NO), the control unit 73 controls the determination unit 72 so as to execute the processes from step ST42 onwards.

[0076] This configuration helps to suppress cases where a user fraudulently uses the authentication facial image to access the shared user. A specific case is as follows: The user holds the authentication facial image up to the facial image acquisition device. The facial image acquisition device 80 captures and acquires the authentication facial image. The facial image acquisition device 80 then transmits the authentication facial image to the server 70 as the user's facial image. In this case, if the process in step ST71 is not performed, the server 70 will determine that the user can access the shared user. Therefore, even if the user does not belong to the group, they may be able to access the shared user. Thus, by performing the process shown in step ST71, the server 70 can suppress the user from fraudulently accessing the shared user.

[0077] In Figure 13, an example is shown in which a server 70 and a face image acquisition device 80 are provided, and when the server 70 receives an authentication face image from the face image acquisition device 80, the control unit 73 controls the determination unit 72 so as not to execute the determination process for determining whether the subject's shared user is usable. However, this control process is not limited to when the server 70 receives an authentication face image from the face image acquisition device 80. For example, the server 70 may be configured to not execute the determination process for determining whether the determination unit is usable if the face image of the subject used for verification is an authentication face image, regardless of whether or not an authentication face image has been received.

[0078] <Distributed Processing> The availability determination system 100 has been described above. The processing of each functional block of the server 70 is not limited to being executed on the server 70, but may be configured so that each process is distributed between the server 70 and the face image acquisition device 80. In addition, the processing of each functional block of the server 70 may be distributed by multiple servers or devices.

[0079] <Configuration Example> Figure 14 is a block diagram showing an example of the configuration of a server relating to this disclosure. Figure 14 is a block diagram showing an example of the configuration of the servers 10, 20, 70 and the face image acquisition device 80 (hereinafter referred to as server 10, etc.) described above.

[0080] Referring to Figure 14, the server 10 includes a network interface 1201, a processor 1202, and memory 1203. The network interface 1201 may be used to communicate with network nodes. The network interface 1201 may include, for example, a network interface card (NIC) compliant with the IEEE 802.3 series. IEEE stands for Institute of Electrical and Electronics Engineers.

[0081] The processor 1202 reads and executes software (computer programs) from the memory 1203 to perform the processing of the server 10, etc., as described using a flowchart in the above embodiment. The processor 1202 may be, for example, a microprocessor, an MPU, or a CPU. The processor 1202 may include multiple processors.

[0082] Memory 1203 is composed of a combination of volatile and non-volatile memory. Memory 1203 may include storage located away from the processor 1202. In this case, the processor 1202 may access memory 1203 via an I / O (Input / Output) interface, which is not shown.

[0083] In the example shown in Figure 14, memory 1203 is used to store a group of software modules. The processor 1202 can read these software modules from memory 1203 and execute them, thereby enabling the server 10 and other processes described in the above embodiment.

[0084] As explained using Figure 14, each processor in the server 10, etc., executes one or more programs that include a set of instructions for causing the computer to perform the algorithm described in the diagram.

[0085] In the examples described above, the program includes a set of instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more of the functions described in the embodiments. The program may be stored on a non-temporary computer-readable medium or a physical storage medium. Examples, but not limited to, include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray® disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may be transmitted over a temporary computer-readable medium or a communication medium. The program may also be included in a program product. Examples, but not limited to, include temporary computer-readable medium or a communication medium that includes electrically, optically, acoustically or otherwise propagating signals.

[0086] Although the present disclosure has been described in accordance with the above embodiments, the present disclosure is not limited to the configuration of the above embodiments, and of course includes various modifications, alterations, and combinations that a person skilled in the art could make within the scope of the claims of the present patent application.

[0087] Each drawing is merely illustrative to illustrate one or more embodiments. Each drawing may be associated with one or more other embodiments, rather than being associated with only one specific embodiment. As those skilled in the art will understand, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings, for example, to create embodiments not explicitly shown or described. Not all features or steps shown in any one drawing to illustrate an exemplary embodiment are necessarily required, and some features or steps may be omitted. The order of steps described in any of the drawings may be changed as appropriate.

[0088] Some or all of the above embodiments may also be described as follows, but are not limited to the following: (Note 1) A server for determining whether a target person can use a shared user body shared by a group, comprising: an authentication face image generation unit that generates an authentication face image based on a composite face image obtained by combining the face images of a plurality of users included in the group; and a determination unit that determines whether the target person can use the shared user body based on the result of matching the face image of the target person with the authentication face image. (Note 2) The server according to Note 1, wherein the authentication face image is the composite face image which, when viewed by a person, cannot recognize the plurality of users included in the group. (Note 3) The server according to Note 1 or 2, wherein the authentication face image is an image obtained by processing the composite face image so that it cannot be viewed by a person. (Note 4) The authentication face image is an image obtained by superimposing the composite face image as a guide image onto a source image which is any face image other than the composite face image, so that the composite face image is recognized when compared with the face image of the subject. (Note 5) The server according to Note 1 or 2, further comprising a control unit that controls the determination process for whether or not the determination unit can be used when the face image of the subject used for matching is the authentication face image. (Note 6) The authentication face image is an image in which the matching values ​​indicating the difference between the face image of the user included in the group and the authentication face image are within a predetermined range. (Note 7) The amount of noise in the composite face image which is the guide image is determined so that the matching values ​​indicating the difference between the face image of the user included in the group and the authentication face image are within a predetermined range. (Note 8) The determination unit determines, when the face image of the subject matches the authentication face image, that the subject is included in the group and can use the shared user, and when the face image of the subject does not match the authentication face image, that the subject is not included in the group and cannot use the shared user, as described in Note 1 or 2.(Note 9) A system for determining whether a person can be used as a shared user for a group, comprising a server and a face image acquisition device, wherein the face image acquisition device acquires a face image of the person and transmits the face image of the person to the server, the server generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determines whether the person can be used as a shared user based on the result of matching the face image of the person received from the face image acquisition device with the authentication face image. (Note 10) The system for determining whether a person can be used as a shared user according to Note 9, wherein the server is controlled not to execute the process for determining whether the person can be used as a shared user when it receives the authentication face image from the face image acquisition device as the face image of the person. (Note 11) A method for determining whether a person is eligible to use a shared user object used by a group, wherein a computer performs the following steps: generate an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determine whether the person is eligible to use the shared user object based on the result of matching the face image of the person with the authentication face image. (Note 12) A program for determining whether a person is eligible to use a shared user object used by a group, wherein a computer performs the following steps: generate an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determine whether the person is eligible to use the shared user object based on the result of matching the face image of the person with the authentication face image.

[0089] Some or all of the elements (e.g., configuration and function) described in Appendices 2 to 8 that are dependent on Appendice 1 may also be dependent on Appendices 9, 11, and 12 in the same way as those described in Appendices 2 to 8. Some or all of the elements described in any appendice may be applied to various hardware, software, recording means, systems, and methods for recording software.

[0090] IG1, IG2, IG3 Face image M1 Composite face image M2 Source image M3 Adversarial image 10, 20, 70 Server 11, 21, 71 Authentication face image generation unit 12, 23, 72 Judgment unit 22 Registration unit 73 Control unit 80 Face image acquisition device 81 Shooting unit 100 Availability determination system 1201 Network interface 1202 Processor 1203 Memory

Claims

1. A server for determining whether a person is eligible to use a shared user object shared by a group, comprising: an authentication face image generation unit that generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group; and a determination unit that determines whether the person is eligible to use the shared user object based on the result of matching the face image of the person with the authentication face image.

2. The authentication face image is the composite face image, which, when viewed by a person, does not allow for the recognition of the multiple users included in the group, as described in claim 1.

3. The server according to claim 1 or 2, wherein the authentication face image is an image obtained by processing the composite face image so that it cannot be seen by a human eye.

4. The server according to claim 3, wherein the authentication face image is an image obtained by superimposing the composite face image as a guide image onto a source image which is any face image other than the composite face image, so that the composite face image is recognized when compared with the face image of the subject.

5. The server according to claim 1 or 2, further comprising a control unit that controls the determination unit not to execute the determination process for determining whether it is usable or not when the facial image of the subject used for matching is the authentication facial image.

6. The server according to claim 2, wherein the authentication face image is an image in which the matching values ​​indicating the discrepancy between the face image of the user included in the group and the authentication face image are within a predetermined range.

7. The amount of noise in the composite face image, which is the guide image, is determined such that the matching values ​​indicating the discrepancy between the face image of the user included in the group and the authentication face image are within a predetermined range, as described in claim 4.

8. The server according to claim 1 or 2, wherein the determination unit determines that if the face image of the subject matches the authentication face image, the subject is included in the group and can use the shared user, and if the face image of the subject does not match the authentication face image, the subject is not included in the group and cannot use the shared user.

9. A system for determining whether a person is eligible to use a shared user for a group, comprising a server and a face image acquisition device, wherein the face image acquisition device acquires a face image of the person and transmits the face image of the person to the server, the server generates an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and the system for determining whether the person is eligible to use the shared user for a group, based on the result of comparing the face image of the person received from the face image acquisition device with the authentication face image.

10. The availability determination system according to claim 9, wherein the server, when it receives the authentication face image from the face image acquisition device as the face image of the subject, controls the server not to perform the process of determining whether the subject can use the shared user.

11. A method for determining whether a person is eligible to use a shared user object used by a group, the method comprising: generating an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group; and determining whether the person is eligible to use the shared user object based on the result of matching the face image of the person with the authentication face image, the process being performed by a computer.

12. A program for determining whether a person is eligible to use a shared user object used by a group, the program causing a computer to perform the following steps: generate an authentication face image based on a composite face image obtained by combining the face images of multiple users included in the group, and determine whether the person is eligible to use the shared user object based on the result of matching the face image of the person with the authentication face image.