WO2010070756A1 - Information processing device, authentication program, and authentication method - Google Patents

Information processing device, authentication program, and authentication method Download PDF

Info

Publication number
WO2010070756A1
WO2010070756A1 PCT/JP2008/073083 JP2008073083W WO2010070756A1 WO 2010070756 A1 WO2010070756 A1 WO 2010070756A1 JP 2008073083 W JP2008073083 W JP 2008073083W WO 2010070756 A1 WO2010070756 A1 WO 2010070756A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
authentication
fingerprint
user
identification
Prior art date
Application number
PCT/JP2008/073083
Other languages
French (fr)
Japanese (ja)
Inventor
琢磨 山田
悟 弥▲吉▼
Original Assignee
富士通株式会社
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 富士通株式会社 filed Critical 富士通株式会社
Priority to PCT/JP2008/073083 priority Critical patent/WO2010070756A1/en
Publication of WO2010070756A1 publication Critical patent/WO2010070756A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints

Definitions

  • the present invention relates to an information processing apparatus, an authentication program, and an authentication method, and more particularly, to an information processing apparatus, an authentication program, and an authentication method that perform authentication using a fingerprint.
  • the present invention has been made in view of such a point, and an object thereof is to provide an information processing apparatus, an authentication program, and an authentication method with high authentication accuracy by using fingerprint authentication and other authentication methods.
  • the disclosed information processing apparatus includes a fingerprint information acquisition unit that acquires fingerprint information, which is information acquired from the fingerprint of the user to authenticate the user, and information that is used to authenticate the user and the fingerprint information Is an identification information acquisition unit that acquires identification information that is different information, and information that is set in advance for use in authentication as to whether or not the user is legitimate, and compares the fingerprint information with the user.
  • a fingerprint authentication information storage unit for storing fingerprint authentication information for authenticating the information, and information set in advance for use in authenticating whether or not the user is valid, by comparing with the identification information Stored in the identification authentication information storage unit for storing the identification authentication information for authenticating the user, the fingerprint information acquired by the fingerprint information acquisition unit, and the fingerprint authentication information storage unit The fingerprint authentication information is compared with the first authentication, and the identification information acquired by the identification information acquisition unit is compared with the identification authentication information stored in the identification authentication information storage unit.
  • the authentication control unit authenticates the user as valid, and the authentication control unit authenticates the user. And a control unit that executes a process permitted by a legitimate user when it is authenticated.
  • fingerprint information is acquired by the fingerprint information acquisition unit.
  • Identification information is acquired by the identification information acquisition unit.
  • Fingerprint authentication information is stored by the fingerprint authentication information storage unit.
  • the identification / authentication information is stored by the identification / authentication information storage unit.
  • the authentication control unit compares the fingerprint information with the fingerprint authentication information to perform the first authentication, compares the identification information with the identification authentication information, performs the second authentication, and performs the first authentication and the first authentication. If the second authentication is successful, the user is authenticated as valid.
  • the control unit authenticates the user as valid by the authentication control unit, processing permitted to the valid user is executed.
  • the information processing apparatus can increase the accuracy of authentication by using fingerprint authentication and other authentication methods in combination.
  • FIG. 1 is a diagram showing an outline of the present embodiment.
  • the information processing apparatus 1 illustrated in FIG. 1 outputs a setting execution program for setting a password for the information processing apparatus 1.
  • the information processing apparatus 1 includes a control unit 1a, a fingerprint information acquisition unit 1b, an identification information acquisition unit 1c, an authentication control unit 1d, a fingerprint authentication information storage unit 1e, and an identification / authentication information storage unit 1f.
  • the control unit 1a receives a start instruction of the information processing apparatus 1 by the user or a login instruction for starting reception of a login, an application start instruction for instructing start of an application, or an application execution instruction for instructing execution of an application.
  • the control unit 1a performs the above process when the authentication control unit 1d authenticates the user as valid. Based on the instruction, the process authorized by the legitimate user is executed.
  • the fingerprint information acquisition unit 1b acquires fingerprint information which is information acquired from the user's fingerprint in order to authenticate the user.
  • This fingerprint information is information acquired for executing the above-described processing, and is information indicating the characteristics of the fingerprint of the legitimate user's finger.
  • a user who intends to cause the information processing apparatus 1 to execute the above-described processing is authenticated as valid, so that the fingerprint information acquisition unit of the information processing apparatus 1 has the fingerprint information of the user's previously registered finger. Let 1b read. Thereby, the fingerprint information of the user is acquired.
  • the identification information acquisition unit 1c acquires identification information that is information for authenticating the user and is different from the fingerprint information.
  • This identification information is information acquired for the execution of the above processing, and the user ID that uses the information processing apparatus 1, such as a user ID (Identification), is authorized to use other users and other users.
  • This information makes it possible to identify a person who does not have
  • the user ID is input by a keyboard, a button-type input device, or other input devices that the information processing apparatus 1 has.
  • the identification information can identify the user, for example, ID information stored in a device owned by the user and capable of storing information such as an IC card, biometric information other than fingerprints such as iris and palm print, etc. It ’s enough if it ’s information.
  • the authentication control unit 1d performs first authentication by comparing the fingerprint information acquired by the fingerprint information acquisition unit 1b with the fingerprint authentication information stored in the fingerprint authentication information storage unit 1e, and also by the identification information acquisition unit 1c.
  • the second authentication is performed by comparing the acquired identification information with the identification authentication information stored in the identification authentication information storage unit 1f, and if the first authentication and the second authentication are successful, the user is authorized. Authenticate that
  • the first authentication for comparing the fingerprint information with the fingerprint authentication information is performed by comparing the feature point extracted by reading the user's fingerprint indicated by the fingerprint information with the feature point indicated by the preset fingerprint authentication information. .
  • the second authentication for comparing the identification information and the identification authentication information the feature point indicated by the identification information acquired from the user to be authenticated is compared with the feature point indicated by the preset identification authentication information. Done.
  • the fingerprint authentication information storage unit 1e is information set in advance for use in authenticating whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information. .
  • This fingerprint authentication information is information that the information processing apparatus 1 has in advance, and is information indicating the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint.
  • the identification / authentication information storage unit 1f is information set in advance for use in authentication of whether or not the user is valid, and stores identification / authentication information for authenticating the user by comparing with the identification information.
  • This identification authentication information is information that the information processing apparatus 1 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 1 from other users and those who do not have a valid use authority other than the user. Information.
  • the identification authentication information is information that can be compared with the identification information.
  • fingerprint information is acquired by the fingerprint information acquisition unit 1b.
  • Identification information is acquired by the identification information acquisition unit 1c.
  • Fingerprint authentication information is stored in the fingerprint authentication information storage unit 1e.
  • Identification and authentication information is stored in the identification and authentication information storage unit 1f.
  • the authentication control unit 1d compares the fingerprint information with the fingerprint authentication information to perform the first authentication, compares the identification information with the identification authentication information, performs the second authentication, If the second authentication is successful, the user is authenticated as valid.
  • the control unit 1a authenticates that the user is valid in the authentication control unit 1d, a process permitted to the valid user is executed.
  • FIG. 2 is a diagram illustrating an appearance of the information processing apparatus.
  • An information processing apparatus 100 shown in FIG. 2 is a notebook type (laptop type) personal computer to which a security function based on password authentication is added.
  • the information processing apparatus 100 includes an electronic component such as a display unit 120 having an LCD (Liquid Crystal Display) 121, a keyboard 131, and a fingerprint authentication unit 141, a card reader 144, and other CPU (Central Processing Unit) 101 described later in FIG. It has a main body portion 130.
  • a one-touch operation unit 142 is disposed on the upper surface of the main body 130.
  • the LCD 121 is a display device having a display screen for displaying characters or images.
  • other thin display devices such as an organic EL (Electroluminescence) display may be used as the display device.
  • the keyboard 131 is an input device for inputting characters and performing other operations.
  • the one-touch operation unit 142 is an operation unit for the user to perform an input by a pressing operation.
  • the contact input unit 143 is an input device having a digitizer 143a for a user to input handwriting and the like, and a fingerprint reading unit 143b for reading fingerprints and inputting fingerprint information. is there.
  • the card reader 144 is a device for reading information stored in the IC card by communicating with the IC card.
  • the information processing apparatus 100 has been described with respect to the notebook type personal computer.
  • the information processing apparatus 100 is an example of the information processing apparatus, and the user authentication function according to the present embodiment can be performed using a mobile phone or PDA. (Personal Digital Assistant) and other mobile communication terminal devices, desktop type personal computers, information processing system terminal devices, and the like can be applied to information processing devices that perform user authentication.
  • PDA Personal Digital Assistant
  • FIG. 3 is a diagram showing a one-touch operation unit.
  • a one-touch operation unit 142 illustrated in FIG. 3 is an operation unit for a user to perform an input by a pressing operation.
  • the one-touch operation unit 142 includes a one-touch button 142a and a confirmation button 142b.
  • the one-touch button 142a is a button that receives an input such as an application activation instruction from the user, for example.
  • the one-touch operation unit 142 according to the present embodiment has four buttons with symbols “1” to “4” as the one-touch buttons 142a.
  • An application to be used by the user is assigned to each button, and an activation instruction for the assigned application is output by a pressing operation of the user.
  • the number of the one-touch buttons 142a and the attached codes are not limited to this, and can be freely set as necessary.
  • the confirmation button 142b is a button for confirming an input made by operating the one-touch button 142a.
  • a signal corresponding to the operation by the one-touch button 142a is transmitted to the input interface 105 described later with reference to FIG.
  • a signal corresponding to the operation of the one-touch button 142a may be transmitted without waiting for the operation of the confirm button 142b.
  • FIG. 4 is a diagram showing the contact input unit.
  • the contact input unit 143 shown in FIG. 4 is an input device having a digitizer 143a for a user to input handwriting and the like and a fingerprint reading unit 143b for inputting fingerprint information by reading a fingerprint.
  • the digitizer 143a acquires coordinates by detecting the contact of the user's fingertip or touch pen with the input surface by detecting a change in pressure or static electricity of the input surface provided on the surface.
  • the digitizer 143a can receive input by the user such as input of real-time (real-time) handwriting drawn by the user by continuously acquiring the coordinates.
  • the digitizer 143a acquires time information at the same time when acquiring the coordinates of the handwriting. Thereby, the coordinates of the handwriting and the time information are acquired in association with each other.
  • the fingerprint reading unit 143b has a fingerprint sensor that acquires fingerprint information by reading the fingerprint of the user's fingertip.
  • the fingerprint reading unit 143b reads the fingerprint
  • the user applies a predetermined fingertip of the fingertip (the side with the fingerprint) for causing the fingerprint reading unit 143b to read the fingerprint, and the arrow A in FIG. Slide in the direction. Accordingly, the fingerprint reading unit 143b can read the fingerprint of the user's finger.
  • the contact input unit 143 includes an LED (Light Emitting Diode) 143c.
  • the LED 143c is lit for a certain time each time one stroke is read when reading the handwriting of the digitizer 143a.
  • the user can input a figure while confirming that the handwriting has been read during handwriting authentication.
  • FIG. 5 is a diagram illustrating a hardware configuration of the information processing apparatus.
  • the information processing apparatus 100 shown in FIG. 5 is a notebook type personal computer as described above, and the entire apparatus is controlled by the CPU 101.
  • a RAM (Random Access Memory) 102, a hard disk drive (HDD: Hard Disk Drive) 103, a graphic processing device 104, an input interface 105, and a communication interface 106 are connected to the CPU 101 via a bus 107.
  • RAM Random Access Memory
  • HDD Hard Disk Drive
  • the RAM 102 temporarily stores at least a part of an OS (Operating System) program and application programs to be executed by the CPU 101.
  • the RAM 102 stores various data necessary for processing by the CPU 101.
  • the HDD 103 stores an OS and application programs.
  • a display device such as an LCD 121 is connected to the graphic processing device 104.
  • the graphic processing device 104 can display an image on a display screen of a display device such as the LCD 121 in accordance with a command from the CPU 101. Further, the graphic processing device 104 and the LCD 121 are connected by, for example, a serial communication cable, and control signals and image signals are alternately transmitted and received.
  • the input interface 105 is connected to input devices such as a keyboard 131 and a mouse 13.
  • the input interface 105 outputs a signal sent from an input device such as a keyboard 131 to the CPU 101 via the bus 107.
  • a fingerprint authentication unit 141, a contact input unit 143, and a card reader 144 are connected to the input interface 105.
  • a one-touch operation unit 142 is connected to the keyboard 131.
  • a signal output by operating the one-touch operation unit 142 is output to the input interface 105 through the keyboard 131 and the bus 107.
  • the communication interface 106 can be connected to a communication line such as a LAN (Local Area Network).
  • the communication interface 106 can send and receive data to and from other computers via a communication line.
  • the fingerprint authentication unit 141 accepts and authenticates input of user identification information different from fingerprint information, such as fingerprint information acquired from the user's fingerprint and, for example, handwriting information acquired based on the user's real-time handwriting. I do.
  • fingerprint information such as fingerprint information acquired from the user's fingerprint and, for example, handwriting information acquired based on the user's real-time handwriting. I do.
  • the information processing apparatus 100 executes predetermined processing of the information processing apparatus 100 such as starting a predetermined application.
  • the fingerprint authentication unit 141 includes a fingerprint authentication control unit 141a and an authentication information storage unit 141b. Further, a keyboard 131, a card reader 144, and a contact input unit 143 are connected to the fingerprint authentication unit 141, and information input by the user by each input device can be acquired by communicating with these. .
  • the fingerprint authentication control unit 141a controls authentication using fingerprint information and identification information.
  • the authentication information storage unit 141b stores fingerprint authentication information used for authentication performed by the fingerprint authentication unit 141 and identification authentication information which is an authentication method different from fingerprint authentication and is used for authentication performed by the information processing apparatus 100.
  • the authentication information storage unit 141b includes an EEPROM (Electronically Erasable and Programmable Read Only Memory).
  • the fingerprint authentication unit 141 can store fingerprint authentication information and identification authentication information used for authentication in the EEPROM included in the authentication information storage unit 141b, and is acquired by the authentication information stored in the EEPROM and the fingerprint reading unit 143b. Authentication is performed based on the fingerprint information and identification information acquired by another input device such as the digitizer 143a.
  • the identification authentication information is stored in the authentication information storage unit 141b together with the fingerprint authentication information.
  • the present invention is not limited to this, and may be stored separately from the fingerprint authentication information in another storage device.
  • the one-touch operation unit 142 is an operation unit for performing input of an application to be activated and other inputs by a user's pressing operation.
  • the card reader 144 can be electrically connected to an IC card (not shown) by wireless communication.
  • the card reader 144 can perform information communication with the connected IC card.
  • the information processing apparatus 100 can acquire information stored in the IC card, such as identification information, by wireless communication with the IC card by the card reader 144.
  • the card reader 144 of this embodiment can be electrically connected to the IC card by wireless communication.
  • the card reader 144 is not limited thereto, and is electrically connected by bringing terminals into contact with each other using a card slot or the like. Also good.
  • FIG. 6 is a block diagram illustrating a configuration of the information processing apparatus according to the first embodiment.
  • the information processing apparatus 100 illustrated in FIG. 6 includes a fingerprint authentication unit 141, an embedded controller 151, an operating system 160, and an application program 170.
  • the information processing apparatus 100 includes a keyboard 131, a digitizer 143a, and a fingerprint reading unit 143b at the lowest layer.
  • the information processing apparatus 100 includes an embedded controller 151 in the upper layer of the keyboard 131 and the digitizer 143a.
  • the information processing apparatus 100 includes a fingerprint authentication unit 141 in the upper layer of the fingerprint reading unit 143b.
  • An operating system 160 is provided on the upper layer of the fingerprint authentication unit 141 and the embedded controller 151 via the bus 107.
  • An application program 170 is provided in the upper layer of the operating system 160.
  • the fingerprint authentication unit 141 includes a fingerprint authentication control unit 141a and an authentication information storage unit 141b.
  • the fingerprint authentication control unit 141a and the authentication information storage unit 141b are mounted on the same chip.
  • a fingerprint reading unit 143b is connected to the fingerprint authentication unit 141.
  • the fingerprint authentication control unit 141a performs fingerprint authentication by comparing the fingerprint information acquired by the fingerprint authentication unit 141 and the fingerprint reading unit 143b with the fingerprint authentication information stored in the authentication information storage unit 141b.
  • the operating system 160 performs handwriting authentication by comparing the identification information (handwriting information) based on the handwriting of the graphic input by the digitizer 143a and the digitizer controller 151b with the identification authentication information stored in the authentication information storage unit 141b.
  • the operating system 160 authenticates the user as valid when the fingerprint authentication and the handwriting authentication are successful.
  • the fingerprint authentication control unit 141a and the operating system 160 function as an authentication control unit.
  • the fingerprint authentication unit 141 and the fingerprint reading unit 143b read the fingerprint of the user's finger. Based on the read user fingerprint, fingerprint information, which is information acquired from the user fingerprint to authenticate the user, is acquired. This fingerprint information is information obtained for use in fingerprint authentication for determining whether or not to execute the above-described processing such as execution of an application, and is information indicating the characteristics of the fingerprint of a legitimate user's finger. .
  • a user who intends to cause the information processing apparatus 100 to execute a process whose execution is restricted to other than the above-mentioned valid user is authenticated as the user's pre-registered finger fingerprint in order to be authenticated.
  • the fingerprint authentication unit 141 and the fingerprint reading unit 143b included in the processing apparatus 100 are caused to read.
  • the fingerprint information is generated by the fingerprint authentication library 162d extracting the characteristics of the fingerprint from the information acquired by the fingerprint reading unit 143b reading the fingerprint. Thereby, the fingerprint information of the user is acquired.
  • the fingerprint authentication unit 141, the fingerprint reading unit 143b, and the fingerprint authentication library 162d function as a fingerprint information acquisition unit.
  • the authentication information storage unit 141b is information set in advance for use in authenticating whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information.
  • This fingerprint authentication information is information that the information processing apparatus 100 has in advance, and is information that indicates the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint. The fingerprint authentication information is set for each user.
  • the authentication information storage unit 141b is information set in advance for use in authentication of whether or not the user is valid, and stores identification authentication information for authenticating the user by comparing with the identification information.
  • This identification authentication information is information that the information processing apparatus 100 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 100 from other users and those who do not have a valid use authority other than the user. Information.
  • the identification authentication information is information that can be compared with the identification information.
  • the identification authentication information is information based on the user's handwriting acquired in advance.
  • Fingerprint authentication is performed by comparing a feature point extracted by reading a user's fingerprint indicated by fingerprint information with a feature point indicated by preset fingerprint authentication information.
  • the handwriting authentication is performed by comparing the feature point indicated by the identification information extracted from the handwriting of the graphic input by the user who is authenticated with the feature point indicated by the identification authentication information extracted from the preset handwriting. Is called.
  • the digitizer 143a and the digitizer controller 151b accept the input of the graphic handwriting input by the user. Based on the accepted handwriting, identification information that is information for authenticating the user and information different from the fingerprint information is acquired. This identification information is information acquired for the execution of the above processing, and identifies the ID of the user who uses the information processing apparatus 100 from other users and those who do not have a valid use authority other than the user. It is information that makes it possible.
  • the digitizer 143a and the digitizer controller 151b function as a handwriting input unit that receives a handwriting input by the user and acquires the handwriting of the user. Based on the handwriting acquired by the digitizer 143a and the digitizer controller 151b, the graphic recognition driver 161c extracts the handwriting characteristics of the user and generates identification information.
  • the digitizer 143a, the digitizer controller 151b, and the figure recognition driver 161c function as an identification information acquisition unit.
  • the digitizer 143a is connected to the LED 143c.
  • the LED 143c is lit for a certain time each time one stroke is read when reading the handwriting of the digitizer 143a.
  • the user can input a figure while confirming that the handwriting has been read during handwriting authentication.
  • the embedded controller 151 has functions such as power management for the information processing apparatus 100, and also includes a keyboard controller 151a, a digitizer controller 151b, and an I / O (Input / Output) controller 151c.
  • the keyboard controller 151 a periodically monitors key press operations and release operations on the keyboard 131 and transmits information corresponding to the operations to the operating system 160 via the bus 107.
  • the digitizer controller 151b acquires the information input by the digitizer 143a and transmits the acquired information.
  • the I / O controller 151c transmits and receives information related to operations of the one-touch operation unit 142 (described above in FIG. 2) and the like. In addition, the I / O controller 151c receives a control signal transmitted from the fingerprint authentication unit 141 and indicating that the fingerprint authentication is successful.
  • Communication between the embedded controller 151 and the operating system 160 and communication between the fingerprint authentication unit 141 and the operating system 160 are performed via the bus 107.
  • the information transmitted from the keyboard controller 151a is transmitted to the keyboard driver 161a and keyboard library 162a of the operating system 160 via the bus 107.
  • Information transmitted from the digitizer controller 151b is transmitted to the digitizer driver 161b and the digitizer library 162b of the operating system 160 via the bus 107.
  • the operating system 160 is software that manages the entire information processing apparatus 100 by defining functions of each part of the information processing apparatus 100.
  • the operating system 160 includes a keyboard driver 161a, a digitizer driver 161b, a figure recognition driver 161c, a fingerprint authentication driver 161d, a keyboard library 162a, a digitizer library 162b, a figure recognition library 162c, and a fingerprint authentication library 162d.
  • the operating system 160 receives a start instruction for the information processing apparatus 100 by the user or a login instruction for instructing start of acceptance of login, an application start instruction for instructing start of the application, or an application execution instruction for instructing execution of the application.
  • the operating system 160 functions as a control unit.
  • the operating system 160 When the operating system 160 receives an instruction such as an application activation instruction from the user, if the process corresponding to the above instruction is a process whose execution is restricted to a user other than a valid user, the operating system 160 is based on the received instruction.
  • the fingerprint authentication control unit 141a performs fingerprint authentication, and the operating system 160 performs handwriting authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 141a and the handwriting authentication by the operating system 160, the process permitted to the authorized user, such as starting an application, based on the above instruction Execute.
  • the operating system 160 causes the digitizer 143a and the digitizer controller 151b to acquire the handwriting of the user, and generates handwriting information indicating the handwriting characteristic points based on the acquired handwriting. Execute handwriting authentication.
  • the application 171a that acquires the information input by the keyboard 131
  • the information that is input by the digitizer 143a is acquired, and the authentication is successfully performed by the information processing apparatus 100, the application 171b that processes the acquired information.
  • the fingerprint authentication unit 141 succeeds in authenticating the user's fingerprint
  • handwriting input is started via the I / O controller 151c from the fingerprint authentication unit 141 to the embedded controller 151 to which the digitizer 143a is connected.
  • a control signal instructing is transmitted.
  • the digitizer driver 161b starts transmitting input data from the digitizer 143a to the graphic recognition driver 161c.
  • a control signal may be transmitted from the fingerprint authentication driver 161d to the digitizer driver 161b, and the digitizer driver 161b may start transmitting input data from the digitizer 143a to the figure recognition driver 161c based on the control signal.
  • the fingerprint authentication information includes finger-specific fingerprint authentication information set for a plurality of fingerprints of different fingers of the same user, and an order indicating a predetermined order for the fingerprints of the plurality of fingers.
  • Information the fingerprint authentication executed by the fingerprint authentication control unit 141a is the fingerprint information based on the fingerprint read by the fingerprint reading unit 143b and the fingerprint authentication unit 141 for the fingerprint information obtained by the user's fingerprint a plurality of times.
  • the authentication information storage unit 141b may store a plurality of pieces of identification authentication information indicating the characteristics of the handwriting of the graphic input by the user.
  • the information processing apparatus 100 may include an application activation information storage unit (not shown) that stores application activation information that associates identification authentication information with an application activated by the operating system 160.
  • the operating system 160 may determine which identification / authentication information has succeeded in identification / authentication when handwriting authentication is executed. In this case, the operating system 160 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 141a and the operating system 160, and the determined application Can be started. Accordingly, the information processing apparatus 100 can start different applications based on the type of handwriting of the graphic input by the user, so that the user can select the application started by the graphic to be input. Become.
  • an application activation information storage unit that stores application activation information that associates fingerprints of a plurality of different fingers of the same user with applications activated by the operating system 160 may be provided.
  • the fingerprint authentication information may include finger-specific fingerprint authentication information set for each of a plurality of different fingerprints of the same user.
  • the operating system 160 may determine which fingerprint of the user has succeeded in fingerprint authentication when executing fingerprint authentication.
  • the operating system 160 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 141a and the operating system 160, and the determined application Can be started. Accordingly, the information processing apparatus 100 can start different applications based on the finger that the user has read the fingerprint, so the user can select the application that is started by the finger that reads the fingerprint. become.
  • the fingerprint authentication control unit 141a performs fingerprint authentication and the operating system 160 performs handwriting authentication.
  • the present invention is not limited to this, and the fingerprint authentication control unit 141a may perform fingerprint authentication and handwriting authentication.
  • the same control unit executes fingerprint authentication and handwriting authentication, so that the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
  • the fingerprint authentication control unit 141a and the authentication information storage unit 141b may be mounted on the same chip.
  • FIGS. 7 and 8 are flowcharts illustrating the authentication processing procedure according to the first embodiment.
  • the authentication process shown in FIGS. 7 and 8 is a process executed by the information processing apparatus 100 (described above in FIG. 2).
  • This authentication process is an authentication process executed when the information processing apparatus 100 receives an application activation instruction from the user and activates the application.
  • the authentication process is performed by the user using the keyboard 131 (described above in FIG. 2) or the one-touch operation unit 142. Execution is started based on the application activation operation by the operation (described above in FIG. 2).
  • Step S1 The operating system 160 (described above in FIG. 6) displays a fingerprint authentication message window 121a (described later in FIG. 15) on the display screen of the LCD 121 (described above in FIG. 2).
  • the embedded controller 151 accepts an input of a user ID using the keyboard 131 by the user. Based on this, the keyboard controller 151a (described above in FIG. 6) transmits the received user ID to the keyboard driver 161a. At this time, the keyboard controller 151a transmits the received user ID to the fingerprint authentication unit 141 (described above in FIG. 5) via the I / O controller 151 (described above in FIG. 6).
  • Step S3 The fingerprint authentication unit 141 starts reading the fingerprint of the user by the fingerprint reading unit 143b (described above in FIG. 6). At this time, the fingerprint authentication control unit 141a (described above in FIG. 5) requests the fingerprint reading unit 143b to transmit fingerprint information until it receives fingerprint information obtained as a result of fingerprint reading. The fingerprint authentication control unit 141a stops fingerprint authentication when there is no transmission of fingerprint information for a certain period of time.
  • Step S4 The fingerprint authentication control unit 141a reads out and acquires the fingerprint authentication information corresponding to the user ID transmitted in step S2 from the authentication information storage unit 141b (described above in FIG. 5).
  • Step S5 The fingerprint authentication control unit 141a performs authentication by comparing the fingerprint information acquired by the fingerprint reading unit 143b with the fingerprint information corresponding to the user ID acquired from the authentication information storage unit 141b. Determine whether or not. If the authentication is successful, the process proceeds to step S11 (FIG. 8). On the other hand, if the authentication fails, the process proceeds to step S17 (FIG. 8).
  • the operating system 160 displays a handwriting authentication message window 121b (described later in FIG. 16) on the display screen of the LCD 121.
  • the digitizer controller 151b controls the digitizer 143a (described above in FIG. 6) to accept the input of the handwriting by the user and acquire the handwriting.
  • the digitizer controller 151b continues to acquire until the number of strokes reaches the predetermined number.
  • the stroke is a handwriting written from a single pen-down to a pen-up at the time of handwriting input, that is, from when the user touches the digitizer 143a until the fingertip is released.
  • the figure recognition driver 161c (described above in FIG. 6) obtains handwriting information used for handwriting authentication by analyzing the handwriting characteristics of the figure input by the user. At this time, the figure recognition driver 161c generates handwriting information by disassembling the handwriting of the figure input by the user for each stroke and extracting the features of the decomposed stroke.
  • the graphic recognition library 162c (described above in FIG. 6) acquires handwriting authentication information corresponding to the user ID.
  • This handwriting authentication information is information included in the figure recognition library 162c, and is registered in advance by a user or an administrator.
  • Step S15 The graphic recognition library 162c performs handwriting authentication by comparing the handwriting information acquired in step S13 and the handwriting authentication information acquired in step S14, and determines whether or not the result of handwriting authentication is successful. If the result of handwriting authentication is successful, the process proceeds to step S16. On the other hand, if the result of handwriting authentication fails, the process proceeds to step S17.
  • Step S16 The operating system 160 activates the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
  • Step S ⁇ b> 17 The operating system 160 displays on the display screen of the LCD 121 an error related to the activation of the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
  • the authentication process according to the present embodiment is started when the information processing apparatus 100 detects an application activation instruction by the user, but is not limited to this, and displays, for example, a login screen (not shown). Execution may be started when the user logs in to the information processing apparatus 100 such as when an operation is performed (such as pressing the control key, Alt key, and Delete key of the keyboard 131 simultaneously).
  • step S5 if fingerprint authentication in step S5 fails or if handwriting authentication in step S15 fails, an error is displayed in step S17, but another attempt is made to read the fingerprint and acquire the handwriting again. May be.
  • FIG. 9 to 11 are sequence diagrams illustrating a procedure at the time of authentication according to the first embodiment.
  • the “user interface” in the figure is an input device operated by a user and an output device that performs screen display.
  • the “fingerprint authentication unit” in the figure is the fingerprint authentication unit 141 described above with reference to FIG. As described above, the fingerprint authentication unit 141 includes the fingerprint authentication control unit 141a and the authentication information storage unit 141b.
  • a “controller” in the figure is a control unit that controls input devices such as a keyboard 131, a one-touch operation unit 142 (described above in FIG. 3), a digitizer 143a, and the like.
  • operating system in the figure is the operating system 160 and the libraries and drivers included in the operating system 160 described above with reference to FIG.
  • Step S101 The one-touch button 142a or the keyboard 131 of the one-touch operation unit 142 accepts an application activation operation by the user.
  • Step S102 The keyboard controller 151a detects the activation operation of the application in step S101. Based on the detection of the application activation operation by the user, a signal based on the application activation instruction is transmitted.
  • Step S103 The operating system 160 executes processing for starting fingerprint authentication. Specifically, as will be described later, the fingerprint authentication unit 141 is activated by the fingerprint authentication driver 161d. Also, a fingerprint authentication message window 121a (described later in FIG. 15) is displayed on the graphic processing device 104.
  • the graphic processing device 104 causes the LCD 121 to display a fingerprint authentication message window 121a.
  • the keyboard 131 receives an input of a user ID by the user.
  • Step S106 The keyboard controller 151a detects the user ID input operation in step S105. Based on the detection of the user ID input operation by the user, the user ID is acquired, and information indicating the acquired user ID is transmitted to the fingerprint authentication unit 141 and the figure recognition driver 161c.
  • the fingerprint authentication control unit 141a activates the fingerprint reading unit 143b. As a result, the user's fingerprint can be read.
  • the fingerprint reading unit 143b reads the fingerprint of the user and acquires fingerprint information. The acquired fingerprint information is transmitted to the fingerprint authentication control unit 141a.
  • the fingerprint authentication control unit 141a reads the fingerprint authentication information corresponding to the user ID transmitted in step S106 from the authentication information storage unit 141b. Next, the fingerprint authentication control unit 141a compares the fingerprint information of the fingerprint read by the fingerprint reading unit 143b in step S108 with the fingerprint authentication information read from the authentication information storage unit 141b and collates them to authenticate the user's fingerprint. Do. Thereby, the legitimacy of the user who tries to start the application is determined based on the fingerprint.
  • the fingerprint authentication control unit 141a transmits a fingerprint authentication verification result, which is a verification result of fingerprint authentication, to the fingerprint authentication driver 161d.
  • the fingerprint authentication driver 161d that has received the fingerprint authentication verification result transmitted from the fingerprint authentication control unit 141a transmits the fingerprint authentication verification result to the fingerprint authentication library 162d.
  • the fingerprint authentication library 162d that has received the fingerprint authentication collation result transmitted from the fingerprint authentication driver 161d has succeeded in the fingerprint authentication of the user performed by the fingerprint authentication control unit 141a in step S121 based on the fingerprint authentication collation result. It is determined whether or not.
  • the fingerprint authentication library 162d transmits the fingerprint authentication determination result to the figure recognition library 162c.
  • Step S124 If the received determination result of the fingerprint authentication is successful, the operating system 160 executes processing for starting handwriting authentication. Specifically, as will be described later, the figure recognition library 162c causes the digitizer controller 151b to activate the digitizer 143a. Further, the graphic recognition library 162c ends the display of the fingerprint authentication message window 121a on the graphic processing device 104, and displays the handwriting authentication message window 121b (described later in FIG. 16). The graphic recognition library 162c activates the graphic recognition driver 161c.
  • the operating system 160 ends the display of the fingerprint authentication message window 121a and displays an error display on the display screen of the LCD 121 as described above with reference to FIG. End the authentication process.
  • the graphic processing device 104 ends the display of the fingerprint authentication message window 121a displayed on the display screen of the LCD 121.
  • the graphic processing device 104 displays a handwriting authentication message window 121b on the display screen of the LCD 121.
  • Step S127 The digitizer controller 151b is activated based on the control of the graphic recognition library 162c in step S124, and activates the digitizer 143a in the graphic recognition mode. With this figure recognition mode, the user's handwriting using the digitizer 143a can be acquired.
  • the digitizer 143a reads the handwriting input by the user and acquires information indicating the handwriting. Information indicating the acquired handwriting is transmitted to the digitizer controller 151b.
  • the digitizer controller 151b that has received the information indicating the handwriting transmits the information indicating the handwriting to the digitizer driver 161b.
  • the digitizer driver 161b that has received the information indicating the handwriting transmits the information indicating the handwriting to the graphic recognition driver 161c.
  • the graphic recognition driver 161c that has received the information indicating the handwriting processes the information indicating the handwriting to generate the handwriting information indicating the characteristics of the handwriting, and transmits the generated handwriting information to the graphic recognition library 162c.
  • Step S141 The graphic recognition library 162c reads the handwriting authentication information corresponding to the user ID transmitted in Step S106 among the handwriting authentication information held by itself. Next, the graphic recognition library 162c compares and compares the handwriting information transmitted in step S128 with the read handwriting authentication information, and authenticates the user's handwriting. Thereby, the legitimacy of the user who intends to start an application based on handwriting is determined.
  • Step S142 The graphic authentication library 162c determines whether or not the user's handwriting authentication in Step S141 is successful based on the handwriting authentication collation result. [Step S143] If the determination result of the handwriting authentication is successful, the operating system 160 performs display control when the user authentication is successful. Specifically, the graphic recognition library 162c ends the display of the handwriting authentication message window 121b for the graphic processing device 104.
  • the operating system 160 ends the display of the handwriting authentication message window 121b and displays an error display on the display screen of the LCD 121 as described above with reference to FIG. End the authentication process.
  • the graphic processing device 104 ends the display of the handwriting authentication message window 121b displayed on the display screen of the LCD 121.
  • the graphic recognition library 162c activates the application that is the target of the user's application activation operation.
  • FIG. 12 is a diagram illustrating decomposition of an input figure into handwriting in the determination of handwriting authentication according to the first embodiment.
  • FIG. 12A shows a figure (character) input in handwriting authentication.
  • FIG. 12B is a diagram illustrating decomposition of a figure input in handwriting authentication into strokes.
  • the handwriting of figures and characters input at the time of authentication is registered in advance.
  • authentication is performed by inputting a handwriting of a figure or a character registered by the user using the digitizer 143a and the like and comparing it with a handwriting registered in advance. Is called.
  • FIG. 12A shows “Water”, which is a Chinese character, as an example of a figure input by the user with the digitizer 143a (described above in FIG. 4) in order to cause the information processing apparatus 100 to start an application.
  • the handwriting information generated based on the graphic is compared with the handwriting authentication information stored in the information processing apparatus 100 to authenticate the user.
  • FIG. 12B shows an example in which the figure input by the user shown in FIG.
  • the figure input by the user is decomposed for each stroke, with the point at which the finger touches the digitizer 143a as the start point and the point at which the finger has moved away from the digitizer 143a (pen up) as the end point.
  • it is decomposed into three strokes 1, 2, and 3.
  • FIG. 13 is a diagram illustrating decomposition of handwriting into vectors in the determination of handwriting authentication according to the first embodiment.
  • FIG. 13A is a diagram illustrating disassembly of each handwriting at regular intervals in handwriting authentication.
  • FIG. 13B is a diagram illustrating decomposition of a figure that is input after being decomposed and input in a certain time in handwriting authentication into strokes (strokes).
  • FIG. 13A shows an example in which each stroke obtained by disassembling the graphic shown in FIG. 12B is divided at regular intervals based on time information when handwriting is acquired.
  • the points that divide the strokes at regular time intervals are indicated by circles.
  • the center of each circle indicates the point that divides the stroke. In this way, the stroke is divided at regular intervals.
  • FIG. 13B shows, with respect to the portion where the stroke shown in FIG. 13A is divided, a vector having each divided point (the center of the circle) as a start point and an end point. This vector indicates the movement speed (movement speed and movement direction) of the fingertip within a certain time when each part of the handwriting is input when the user inputs a figure.
  • FIG. 14 is a diagram illustrating a vector of each part obtained by dividing a vector in determination of handwriting authentication according to the first embodiment.
  • FIG. 14 shows the vectors obtained by dividing the strokes of the graphic input by the user shown in FIG. 13B at regular intervals, arranged for each stroke.
  • the vector obtained from each stroke particularly represents the feature of the shape of the figure input by the user. Thereby, the legitimacy of the user can be determined from the graphic input by the user using this vector.
  • this vector is considered to represent the characteristics of the moving speed of coordinates when each part of the stroke is input. Thereby, using this vector, the legitimacy of the user can be determined based on the feature of the movement of the user's coordinates from the movement speed of the coordinates when the user inputs the figure.
  • handwriting information having information indicating the size and direction of each vector acquired as described above is generated, and handwriting authentication is performed using the generated handwriting information. Furthermore, the handwriting authentication information acquired in advance corresponding to the user ID to be compared with the authentication is also acquired in the same manner, the user's handwriting at the time of inputting the figure, the stroke obtained by disassembling the user's handwriting, and It is information which has the information which shows the vector acquired from the user's handwriting.
  • the following is used as a standard for handwriting authentication.
  • 1. The stroke number of the handwriting of the inputted figure and the figure registered in advance as a comparison target is the same. 2.
  • the difference in the amount of movement between the corresponding strokes is within a certain range.
  • the difference between the direction and length of the vectors corresponding to each stroke must be within a certain range. For example, when all of the above 1, 2, and 3 are satisfied, or all items are converted into evaluation values. It can be assumed that handwriting authentication has succeeded when a certain standard is satisfied, and handwriting authentication has failed otherwise.
  • the user is authenticated by comprehensively evaluating the size and direction of the vector obtained by disassembling the figure as described above.
  • the handwriting authentication method described above is an example, and handwriting authentication may be performed by other methods.
  • FIG. 15 is a diagram illustrating a fingerprint authentication message window according to the first embodiment.
  • a fingerprint authentication message window 121a shown in FIG. 15 is an example of a window displayed on the display screen of the LCD 121 included in the information processing apparatus 100 (described above in FIG. 2).
  • the fingerprint authentication message window 121a a message and an image for guiding the user to input the user ID and read the fingerprint are displayed.
  • the fingerprint authentication message window 121a for example, a message “Enter your user ID and slide your finger against the sensor” and an image that guides the user ID input and fingerprint reading are displayed.
  • the fingerprint authentication message window 121a has a user ID input field 121a1 and a cancel button 121a2.
  • the user ID input field 121a1 is an input field for accepting input of a user ID.
  • the user can input a user ID in the user ID input field 121a1 by inputting characters using an input device such as the keyboard 131.
  • the cancel button 121a2 is a button for canceling the input of the user ID. By operating the cancel button 121a2, the user can cancel the input of the user ID and cancel the activation of the application without performing fingerprint authentication.
  • FIG. 16 is a diagram illustrating a handwriting authentication message window according to the first embodiment.
  • a handwriting authentication message window 121b illustrated in FIG. 16 is an example of a window displayed on the display screen of the LCD 121 included in the information processing apparatus 100 (described above in FIG. 2).
  • the handwriting authentication message window 121b a message and an image for guiding the user to input a figure using the digitizer 143a (described above in FIG. 2) are displayed.
  • the handwriting authentication message window 121b has a cancel button 121b2.
  • the cancel button 121b2 is a button for canceling the figure input. By operating the cancel button 121b2, the user can cancel the input of the figure and can stop the activation of the application.
  • FIG. 17 is a diagram illustrating an application window according to the first embodiment.
  • An application window 121c illustrated in FIG. 17 is an example of a window displayed on the display screen of the LCD 121 included in the information processing apparatus 100 (described above in FIG. 2).
  • the application window 121c is a screen related to the application that is the target of the user's activation operation.
  • the application window 121c is a screen related to the operation of the application, such as a screen for inputting search conditions for the database system.
  • the application window 121c is displayed when the user authentication is successful. On the other hand, if the user authentication fails, the application is not started and the application window 121c is not displayed.
  • the information processing apparatus 100 steals information to be protected by prohibiting activation of other than authorized users such as database systems and mail systems that need to be protected because personal information and trade secrets are included. Leakage, destruction, etc. can be prevented.
  • the accuracy of user authentication is increased, so that security is improved.
  • the fingerprint authentication process is concealed from the outside, so that cracks can be prevented and safety is improved.
  • the second embodiment is different from the first embodiment in that the user is identified by the user's one-touch button operation and the user's fingerprint authentication is performed using the fingerprint authentication information corresponding to the identified user. .
  • FIG. 18 is a block diagram illustrating a configuration of the information processing apparatus according to the second embodiment.
  • An information processing apparatus 200 illustrated in FIG. 18 includes a fingerprint authentication unit 241, an embedded controller 251, an operating system 260, and an application program 270.
  • the information processing apparatus 200 includes a keyboard 231, a one-touch operation unit 242, and a fingerprint reading unit 243 b at the lowest layer.
  • the information processing apparatus 200 includes an embedded controller 251 in the upper layer of the keyboard 231 and the one-touch operation unit 242.
  • the information processing apparatus 200 includes a fingerprint authentication unit 241 in the upper layer of the fingerprint reading unit 243b.
  • the operating system 260 is provided on the upper layer of the fingerprint authentication unit 241 and the embedded controller 251 via the bus 207.
  • An application program 270 is provided in the upper layer of the operating system 260.
  • the fingerprint authentication unit 241 includes a fingerprint authentication control unit 241a and an authentication information storage unit 241b.
  • the fingerprint authentication control unit 241a and the authentication information storage unit 241b are mounted on the same chip.
  • a fingerprint reading unit 243 b is connected to the fingerprint authentication unit 241.
  • the fingerprint authentication control unit 241a performs fingerprint authentication by comparing the fingerprint information acquired by the fingerprint authentication unit 241 and the fingerprint reading unit 243b with the fingerprint authentication information stored in the authentication information storage unit 241b.
  • the one-touch operation unit 242 and the embedded controller 251 use, as identification information, a key code based on an operation of a one-touch button (see the one-touch button 142a described above in FIG. 3) included in the one-touch operation unit 242. Then, the I / O controller 251c transmits a key code to the fingerprint authentication unit 241.
  • the fingerprint authentication unit 241 that has received the key code performs one-touch button authentication by comparing the received key code with the identification authentication information stored in the authentication information storage unit 241b.
  • the operating system 260 authenticates the user as valid when the fingerprint authentication based on the fingerprint authentication information obtained by the one-touch button authentication is successful. That is, the fingerprint authentication control unit 241a and the operating system 260 accept the operation of the one-touch button and execute fingerprint authentication using the fingerprint authentication information corresponding to the operated one-touch button. The fingerprint authentication control unit 241a and the operating system 260 function as an authentication control unit.
  • the fingerprint authentication unit 241 and the fingerprint reading unit 243b read the fingerprint of the user's finger. Based on the read user fingerprint, fingerprint information, which is information acquired from the user fingerprint to authenticate the user, is acquired. This fingerprint information is information obtained for use in fingerprint authentication for determining whether or not to execute the above-described processing such as execution of an application, and is information indicating the characteristics of the fingerprint of a legitimate user's finger. .
  • a user who intends to cause the information processing apparatus 200 to execute a process whose execution is restricted to other than the above-mentioned authorized user is authenticated as the information of the user's pre-registered finger in order to be authenticated.
  • the fingerprint authentication unit 241 and the fingerprint reading unit 243b included in the processing apparatus 200 are read.
  • the fingerprint information is generated by the fingerprint authentication library 262d extracting the characteristics of the fingerprint from the information acquired by the fingerprint reading unit 243b reading the fingerprint. Thereby, the fingerprint information of the user is acquired.
  • the fingerprint authentication unit 241, the fingerprint reading unit 243b, and the fingerprint authentication library 262d function as a fingerprint information acquisition unit.
  • the authentication information storage unit 241b is information set in advance for use in authenticating whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information.
  • This fingerprint authentication information is information that the information processing apparatus 200 has in advance, and is information that indicates the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint.
  • the fingerprint authentication information is set for each user.
  • the authentication information storage unit 241b is information set in advance for use in authentication of whether or not the user is valid, and stores identification authentication information for authenticating the user by comparing with the identification information.
  • This identification authentication information is information that the information processing apparatus 200 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 200 from other users and those who do not have a valid use authority other than the user. Information.
  • the identification authentication information is information that can be compared with the identification information.
  • the identification authentication information is information that associates each key code corresponding to the one-touch button with the fingerprint authentication information of each user.
  • One-touch button authentication is performed by acquiring fingerprint authentication information associated with a key code that is identification information corresponding to a one-touch button operated by a user who is authenticated.
  • the key code of the one-touch button operated by the user and the fingerprint authentication information of each user are associated with each other by the identification authentication information.
  • the fingerprint authentication is performed by comparing the feature point extracted by reading the user's fingerprint indicated by the fingerprint information with the feature point indicated by the preset fingerprint authentication information.
  • the one-touch operation unit 242 and the built-in controller 251 accept a pressing operation of the one-touch button by the user. Based on the accepted operation of the one-touch button, a key code associated with each one-touch button is acquired as identification information that is information for authenticating the user and is different from the fingerprint information.
  • a plurality of one-touch buttons are provided in the information processing apparatus 200 and are assigned to each user who uses the information processing apparatus 200.
  • This identification information is information acquired for the execution of the above processing, and identifies the ID of the user who uses the information processing apparatus 200 from other users and those who do not have a valid use authority other than the user. It is information that makes it possible.
  • the one-touch operation unit 242 and the embedded controller 251 function as an identification information acquisition unit.
  • the one-touch operation unit 242 has a plurality of one-touch buttons that accept key code input as identification information.
  • the one-touch operation unit 242 receives a pressing operation of the one-touch button by the user, and acquires identification information based on the received operation.
  • the one-touch operation unit 242 of this embodiment has four buttons as one-touch buttons (not shown) (see the one-touch button 142a described above in FIG. 3). A user having a right to use the information processing apparatus 200 is assigned to each button. Each user performs one-touch button authentication by operating a one-touch button assigned to him / her when the application is activated. Not limited to this, the number and the corresponding characters can be freely set as necessary.
  • the embedded controller 251 has functions such as power management for the information processing apparatus 200, and also includes a keyboard controller 251a and an I / O controller 251c.
  • the keyboard controller 251 a periodically monitors key press operations and release operations on the keyboard 231, and transmits information corresponding to the operations to the operating system 260 via the bus 207.
  • the I / O controller 251c transmits and receives information related to the operation of the one-touch operation unit 242 and the like with the fingerprint authentication unit 241.
  • Communication between the embedded controller 251 and the operating system 260 and communication between the fingerprint authentication unit 241 and the operating system 260 are performed via the bus 207.
  • Information such as a key code transmitted from the keyboard controller 251a is transmitted to the keyboard driver 261a and keyboard library 262a of the operating system 260 via the bus 207.
  • the key code is further transmitted to the one-touch operation unit driver 261e and the one-touch operation unit library 262e via the keyboard driver 261a.
  • the operating system 260 is software that manages the entire information processing apparatus 200 by defining the functions of each part of the information processing apparatus 200.
  • the operating system 260 includes a keyboard driver 261a, a fingerprint authentication driver 261d, a one-touch operation unit driver 261e, a keyboard library 262a, a fingerprint authentication library 262d, and a one-touch operation unit library 262e.
  • the operating system 260 accepts a user's activation instruction for the information processing apparatus 200 or a login instruction for instructing the start of acceptance of login, an application activation instruction for instructing application activation, or an application execution instruction for instructing execution of the application.
  • the operating system 260 functions as a control unit.
  • the operating system 260 When the operating system 260 accepts an instruction such as an application activation instruction from the user, if the process corresponding to the above instruction is a process that is restricted to a user other than a valid user, the operating system 260 is based on the accepted instruction. Then, the operating system 260 performs one-touch button authentication, and then causes the fingerprint authentication control unit 241a to perform fingerprint authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 241a, the process authorized by the authorized user, such as starting an application, is executed based on the above instruction.
  • an instruction such as an application activation instruction from the user
  • the process corresponding to the above instruction is a process that is restricted to a user other than a valid user
  • the operating system 260 is based on the accepted instruction. Then, the operating system 260 performs one-touch button authentication, and then causes the fingerprint authentication control unit 241a to perform fingerprint authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 241
  • the operating system 260 acquires a key code (identification information) corresponding to the one-touch button of the one-touch operation unit 242 based on the operation of the one-touch operation unit 242 by the user as one-touch button authentication. Based on this key code, the fingerprint authentication control unit 241a acquires the fingerprint authentication information of the user associated with the acquired key code by the identification authentication information, and acquires the fingerprint acquired based on the one-touch button authentication as the fingerprint authentication. The authentication information is compared with the fingerprint information acquired by the fingerprint reading unit 243b. Thereby, the legitimacy of the user is determined.
  • the user may input a user ID or the like by operating the one-touch button a plurality of times, and authentication may be performed using the input user ID as identification information.
  • each one-touch button corresponds to “1” to “4”.
  • Each user can input the user ID by operating the buttons “1” to “4” in the order determined as the user ID. For example, when the user ID is defined as “3”, “1”, “2”, “4”, the user presses the one-touch button “3”, “1”, “2”, “4”. After operating in this order, operate the confirm button. Thereby, the input of the user ID by the user is accepted. Then, the fingerprint authentication information is determined based on the user ID input by the operating system 260. Then, authentication of the fingerprint authentication control unit 241a based on the fingerprint authentication information determined by the fingerprint authentication unit 241 is performed, and the legitimacy of the user is determined.
  • the application program 270 includes an application 271a that acquires information input through the keyboard 231 and an application 271c that is executed when authentication by the information processing apparatus 200 is successful.
  • the embedded controller 251 receives the key code based on the operation of the one-touch button, and transmits the received key code to the fingerprint authentication unit 241 via the I / O controller 251c.
  • the fingerprint authentication unit 241 that has received the key code reads the identification authentication information from the authentication information storage unit 241b.
  • the fingerprint authentication unit 241 reads the fingerprint authentication information associated with the key code by the identification authentication information from the authentication information storage unit 241b, and the fingerprint based on the read fingerprint authentication information and the fingerprint read by the fingerprint reading unit 243b. Fingerprint authentication is performed based on information.
  • the fingerprint authentication information includes finger-specific fingerprint authentication information set for a plurality of fingerprints of different fingers of the same user, and an order indicating a predetermined order for the fingerprints of the plurality of fingers. Information.
  • the fingerprint authentication executed by the fingerprint authentication control unit 241a is performed on the fingerprint information obtained by the fingerprint reading unit 243b and the fingerprint authentication unit 241 with respect to the fingerprint information obtained by the user's fingerprint a plurality of times.
  • the authentication information storage unit 241b may store a plurality of pieces of identification authentication information corresponding to the one-touch button operated by the user.
  • the information processing apparatus 200 may include an application activation information storage unit (not shown) that stores application activation information that associates identification authentication information with an application activated by the operating system 260.
  • the operating system 260 may determine which identification / authentication information has succeeded in identification / authentication when executing the one-touch button authentication. In this case, the operating system 260 determines the application to be activated based on the application activation information stored in the application activation information storage unit and the results of determination by the fingerprint authentication control unit 241a and the operating system 260, and the determined application Can be started.
  • the information processing apparatus 200 can start different applications based on the one-touch button operated by the user, so that the user can select an application to be started by operating the one-touch button.
  • an application activation information storage unit that stores application activation information that associates fingerprints of a plurality of different fingers of the same user with applications activated by the operating system 260 may be provided.
  • the fingerprint authentication information may include finger-specific fingerprint authentication information set for each of a plurality of different fingerprints of the same user.
  • the operating system 260 may determine which fingerprint of the user's finger is successful when executing the fingerprint authentication.
  • the operating system 260 determines the application to be activated based on the application activation information stored in the application activation information storage unit and the results of determination by the fingerprint authentication control unit 241a and the operating system 260, and the determined application Can be started.
  • the information processing apparatus 200 can start different applications based on the finger that the user has read the fingerprint, so the user can select the application that is started by the finger that reads the fingerprint. become.
  • the fingerprint authentication control unit 241a performs fingerprint authentication and one-touch button authentication. Normally, when different authentication methods are combined, such as fingerprint authentication and handwriting authentication, it is necessary to perform processing separately for each authentication device, so the time required to complete all authentication processing is prolonged. It will be. On the other hand, in the present embodiment, the same control unit executes fingerprint authentication and handwriting authentication, so that the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
  • the process of opening / closing and calling each driver and library in each application can be simplified, so that the process can be simplified.
  • FIG. 19 is a flowchart illustrating an authentication processing procedure according to the second embodiment.
  • the authentication process shown in FIG. 19 is a process executed by the information processing apparatus 200 (described above in FIG. 18).
  • This authentication process is a process for performing authentication performed when the information processing apparatus 200 accepts an application activation instruction from the user and activates the application, and is a one-touch operation unit 242 (described above in FIG. 18) by the user. Execution is started based on an application activation operation by operating a button (not shown).
  • the embedded controller 251 receives the operation of the one-touch operation unit 242 operated by the user.
  • the information processing apparatus 200 starts an authentication process for starting an application corresponding to the operated one-touch operation unit 242.
  • the keyboard controller 251a (described above in FIG. 18) transmits a key code corresponding to the one-touch operation unit 242 whose operation has been received by the embedded controller 251 to the keyboard driver 261a (described above in FIG. 18). At this time, the keyboard controller 251a transmits the received key code to the fingerprint authentication unit 241 (described above in FIG. 18) via the I / O controller 251c (described above in FIG. 18).
  • Step S22 The operating system 260 (described above in FIG. 18) displays a fingerprint authentication message window 221d (described later in FIG. 22) on the display screen of the LCD (not shown) of the information processing apparatus 200.
  • the fingerprint authentication unit 241 starts reading the fingerprint of the user by the fingerprint reading unit 243b (described above in FIG. 18). At this time, the fingerprint authentication control unit 241a (described above in FIG. 18) requests the fingerprint reading unit 243b to transmit the fingerprint information until it receives the fingerprint information obtained as a result of the fingerprint reading. Note that the fingerprint authentication control unit 241a stops fingerprint authentication when there is no transmission of fingerprint information for a certain period of time.
  • Step S24 The fingerprint authentication control unit 241a reads out and acquires the fingerprint authentication information corresponding to the key code transmitted in step S21 from the authentication information storage unit 241b (described above in FIG. 18).
  • Step S25 The fingerprint authentication control unit 241a performs authentication by comparing the fingerprint information acquired by the fingerprint reading unit 243b and the fingerprint information corresponding to the key code acquired from the authentication information storage unit 241b. Determine whether or not. If the authentication is successful, the process proceeds to step S26. On the other hand, if the authentication fails, the process proceeds to step S27.
  • Step S26 The operating system 260 activates the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
  • Step S27 The operating system 260 displays an error related to the activation of the application that is the target of the activation instruction by the user on the LCD display screen. Thereafter, the authentication process ends.
  • the authentication process according to the present embodiment is started when the information processing apparatus 200 detects an application activation instruction by an operation of the user's one-touch operation unit 242, but is not limited thereto. Execution may be started when the user logs in to the information processing apparatus 200 such as when the one-touch operation unit 242 is operated as an operation for displaying a login screen (not shown).
  • step S25 when the fingerprint authentication in step S25 fails, an error display is performed in step S27, but another fingerprint reading may be attempted.
  • 20 and 21 are sequence diagrams illustrating a procedure at the time of authentication according to the second embodiment.
  • “user interface” in the figure is an input device operated by the user and an output device for displaying a screen.
  • the “fingerprint authentication unit” in the figure is the fingerprint authentication unit 241 described above with reference to FIG. As described above, the fingerprint authentication unit 241 includes the fingerprint authentication control unit 241a and the authentication information storage unit 241b.
  • controller in the figure is a control unit that controls input devices such as the keyboard 231 and the one-touch operation unit 242, and includes the embedded controller 251, the keyboard controller 251a, the I / O controller 251c, and the like.
  • operating system in the figure is the operating system 260 and the libraries and drivers included in the operating system 260 described above with reference to FIG.
  • the one-touch operation unit 242 accepts a pressing operation of a one-touch button (not shown) by the user.
  • the keyboard controller 251a detects the pressing operation of the one-touch button in step S201.
  • the keyboard controller 251a transmits a key code corresponding to the operated one-touch button to the keyboard driver 261a based on the pressing operation of the one-touch button detected in Step S202. Further, the I / O controller 251c transmits a key code corresponding to the operated one-touch button to the fingerprint authentication unit 241.
  • the keyboard driver 261a further transmits the received key code to the one-touch operation unit driver 261e.
  • This key code is transmitted to the one-touch operation unit library 262e by the one-touch operation unit driver 261e.
  • the one-touch operation unit library 262e activates an application based on the received key code when fingerprint authentication described later is successful.
  • the fingerprint authentication unit 241 performs fingerprint authentication using fingerprint authentication information corresponding to the received key code.
  • the operating system 260 executes processing for starting fingerprint authentication. Specifically, as described later, the operating system 260 causes the fingerprint authentication driver 261d to activate the fingerprint authentication unit 241. Further, a fingerprint authentication message window 221d (described later in FIG. 22) is displayed on a graphic processing device (not shown) included in the information processing device 200.
  • the graphic processing apparatus displays a fingerprint authentication message window 221d on the LCD.
  • the fingerprint authentication control unit 241a activates the fingerprint reading unit 243b. As a result, the user's fingerprint can be read.
  • the fingerprint reading unit 243b reads the user's fingerprint and obtains fingerprint information.
  • the acquired fingerprint information is transmitted to the fingerprint authentication control unit 241a.
  • the fingerprint authentication control unit 241a reads fingerprint authentication information corresponding to the key code transmitted in step S203 from the authentication information storage unit 241b.
  • the fingerprint authentication control unit 241a compares and compares the fingerprint information of the fingerprint read by the fingerprint reading unit 243b in step S207 with the fingerprint authentication information read from the authentication information storage unit 241b, thereby authenticating the user's fingerprint. Do. Thereby, the legitimacy of the user who tries to start the application is determined based on the fingerprint.
  • the fingerprint authentication control unit 241a transmits a fingerprint authentication verification result, which is a verification result of fingerprint authentication, to the fingerprint authentication driver 261d.
  • the fingerprint authentication driver 261d that has received the fingerprint authentication verification result transmitted from the fingerprint authentication control unit 241a transmits the fingerprint authentication verification result to the fingerprint authentication library 262d.
  • the fingerprint authentication library 262d that has received the fingerprint authentication collation result transmitted from the fingerprint authentication driver 261d has succeeded in the fingerprint authentication of the user performed by the fingerprint authentication control unit 241a in step S221 based on the fingerprint authentication collation result. It is determined whether or not. Further, the fingerprint authentication library 262d transmits the fingerprint authentication determination result to the one-touch operation unit library 262e.
  • Step S224 If the determination result of the received fingerprint authentication is successful, the operating system 260 performs display control when the user is successfully authenticated. Specifically, as will be described later, the one-touch operation unit library 262e ends the display of the fingerprint authentication message window 221d on the graphic processing device.
  • the operating system 260 terminates the display of the fingerprint authentication message window 221d and displays an error display on the LCD display screen as described above with reference to FIG. End the authentication process.
  • the graphic processing device ends the display of the fingerprint authentication message window 221d displayed on the LCD display screen.
  • the one-touch operation unit library 262e activates the application that is the target of the activation operation of the user's application.
  • FIG. 22 is a diagram illustrating a fingerprint authentication message window according to the second embodiment.
  • a fingerprint authentication message window 221d shown in FIG. 22 is an example of a window displayed on the LCD display screen of the information processing apparatus 200 (described above in FIG. 18).
  • the fingerprint authentication message window 221d a message and an image for guiding the user to read the fingerprint are displayed.
  • the fingerprint authentication message window 221d for example, a message “Please slide your finger against the sensor” and an image for guiding fingerprint reading are displayed.
  • the fingerprint authentication message window 221d has a cancel button 221d2.
  • the cancel button 221d2 is a button for canceling fingerprint reading. By operating the cancel button 221d2, the user can cancel the fingerprint reading and cancel the activation of the application without performing fingerprint authentication.
  • the information processing apparatus 200 by using authentication with a one-touch button and fingerprint authentication together, the accuracy of user authentication is increased, so that security is improved.
  • the fingerprint authentication control unit 241a executes fingerprint authentication and handwriting authentication processing
  • the same processing unit continuously performs a plurality of authentication processes.
  • the process of exchanging data between processing units that perform authentication can be omitted, and the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
  • the fingerprint authentication unit 241 configured with a one-chip IC
  • the authentication process is concealed from the outside, so that cracks can be prevented. Yes, it increases safety.
  • a user is identified by reading ID information (identification information) stored in an IC card possessed by the user, and fingerprint authentication of the user is performed using fingerprint authentication information corresponding to the identified user.
  • ID information identification information
  • FIG. 23 is a block diagram illustrating a configuration of the information processing apparatus according to the third embodiment.
  • An information processing apparatus 300 illustrated in FIG. 23 includes a fingerprint authentication unit 341, an embedded controller 351, an operating system 360, and an application program 370.
  • the information processing apparatus 300 includes a fingerprint reading unit 343b and a card reader 344 at the lowest layer.
  • the information processing apparatus 300 includes an embedded controller 351 in the upper layer of the card reader 344.
  • the information processing apparatus 300 includes a fingerprint authentication unit 341 in the upper layer of the fingerprint reading unit 343b.
  • an operating system 360 is provided via a bus 307.
  • An application program 370 is provided in the upper layer of the operating system 360.
  • the fingerprint authentication unit 341 includes a fingerprint authentication control unit 341a and an authentication information storage unit 341b.
  • the fingerprint authentication control unit 341a and the authentication information storage unit 341b are mounted on the same chip.
  • a fingerprint reading unit 343 b is connected to the fingerprint authentication unit 341.
  • the fingerprint authentication control unit 341a performs fingerprint authentication by comparing the fingerprint information acquired by the fingerprint authentication unit 341 and the fingerprint reading unit 343b with the fingerprint authentication information stored in the authentication information storage unit 341b.
  • the card reader 344 and the embedded controller 351 use the ID information stored in the user's IC card (not shown) read by the card reader 344 as identification information. Then, the I / O controller 351c transmits the ID information to the fingerprint authentication unit 341.
  • the fingerprint authentication unit 341 that has received the ID information compares the received ID information with the identification authentication information stored in the authentication information storage unit 341b to perform card ID information authentication.
  • the operating system 360 authenticates the user as valid when the fingerprint authentication based on the fingerprint authentication information acquired by the card ID information authentication is successful.
  • the fingerprint authentication control unit 341a and the operating system 360 acquire the ID information stored in the IC card read by the card reader 344, and execute the fingerprint authentication using the fingerprint authentication information corresponding to the acquired ID information. To do.
  • the fingerprint authentication control unit 341a and the operating system 360 function as an authentication control unit.
  • the fingerprint authentication unit 341 and the fingerprint reading unit 343b read the fingerprint of the user's finger. Based on the read user fingerprint, fingerprint information, which is information acquired from the user fingerprint to authenticate the user, is acquired. This fingerprint information is information obtained for use in fingerprint authentication for determining whether or not to execute the above-described processing such as execution of an application, and is information indicating the characteristics of the fingerprint of a legitimate user's finger. .
  • a user who intends to cause the information processing apparatus 300 to execute a process whose execution is restricted by a person other than the above-mentioned authorized user is authenticated with the fingerprint of the user's pre-registered finger in order to be authenticated.
  • the fingerprint authentication unit 341 and the fingerprint reading unit 343b included in the processing device 300 are read.
  • the fingerprint information is generated by the fingerprint authentication library 362d extracting the characteristics of the fingerprint from the information acquired by the fingerprint reading unit 343b reading the fingerprint. Thereby, the fingerprint information of the user is acquired.
  • the fingerprint authentication unit 341, the fingerprint reading unit 343b, and the fingerprint authentication library 362d function as a fingerprint information acquisition unit.
  • the authentication information storage unit 341b is information set in advance for use in authentication of whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information.
  • This fingerprint authentication information is information that the information processing apparatus 300 has in advance, and is information that indicates the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint.
  • the fingerprint authentication information is set for each user.
  • the authentication information storage unit 341b stores identification authentication information that is set in advance for use in authentication of whether or not the user is valid and authenticates the user by comparing with the identification information.
  • the identification authentication information is information that the information processing apparatus 300 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 300 from other users and persons who do not have a valid use authority other than the user. Information.
  • the identification authentication information is information that can be compared with the identification information.
  • the identification authentication information is information that associates ID information stored in an IC card possessed by each user with fingerprint authentication information of each user.
  • Card ID information authentication is performed by acquiring fingerprint authentication information associated with ID information which is identification information stored in an IC card held by a user who is authenticated.
  • ID information which is identification information stored in an IC card held by a user who is authenticated.
  • the ID information of the one-touch button operated by the user and the fingerprint authentication information of each user are associated by the identification authentication information.
  • the fingerprint authentication is performed by comparing the feature point extracted by reading the user's fingerprint indicated by the fingerprint information with the feature point indicated by the preset fingerprint authentication information.
  • the card reader 344 acquires ID information stored in an IC card held by the user as identification information that is information for authenticating the user and is different from the fingerprint information.
  • the card reader 344 can be electrically connected to the IC card by wireless communication, and can read information such as ID information from the connected IC card.
  • the card reader 344 acquires ID information by wireless communication.
  • the present invention is not limited to this, contact communication connected by a cable, a terminal, or the like, reading of information recorded on a magnetic material, barcode Alternatively, it may be acquired by reading optically recorded information such as a QR code.
  • an IC card is used.
  • the present invention is not limited to this, and any medium capable of storing information such as a magnetic card, a small memory, and an optical disk is sufficient.
  • This identification information is information acquired for executing the above-described processing, and identifies the ID of the user who uses the information processing apparatus 300 from other users and those who do not have a valid use authority other than the user. It is information that makes it possible.
  • the card reader 344 and the embedded controller 351 function as an identification information acquisition unit.
  • the embedded controller 351 has functions such as power management for the information processing apparatus 300, and also includes a card reader controller 351f and an I / O controller 351c.
  • the card reader controller 351f periodically monitors the card reader 344 and transmits information acquired by the card reader 344 to the operating system 360 via the bus 307.
  • the I / O controller 351c transmits the ID information acquired by the card reader 344 to the fingerprint authentication unit 341.
  • ID information transmitted from the card reader controller 351f is transmitted to the card reader driver 361f and the card reader library 362f of the operating system 360 via the bus 307.
  • the ID information can also be transmitted to the fingerprint authentication driver 361d and the fingerprint authentication library 362d via the card reader driver 361f.
  • the operating system 360 is software that manages the entire information processing apparatus 300 by defining functions of each part of the information processing apparatus 300.
  • the operating system 360 includes a card reader driver 361f, a fingerprint authentication driver 361d, a card reader library 362f, and a fingerprint authentication library 362d.
  • the operating system 360 accepts a user's activation instruction for the information processing apparatus 300 or a login instruction for instructing to start accepting login, an application activation instruction for instructing application activation, or an application execution instruction for instructing execution of the application.
  • the operating system 360 functions as a control unit.
  • the operating system 360 When the operating system 360 accepts an instruction such as an application activation instruction from the user, if the process corresponding to the above instruction is a process that is restricted to a user other than a valid user, the operating system 360 is based on the accepted instruction. Then, the operating system 360 performs card ID information authentication, and then causes the fingerprint authentication control unit 341a to perform fingerprint authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 341a, based on the above instruction, processing authorized by the authorized user, such as activation of an application, is executed.
  • an instruction such as an application activation instruction from the user
  • the process corresponding to the above instruction is a process that is restricted to a user other than a valid user
  • the operating system 360 is based on the accepted instruction. Then, the operating system 360 performs card ID information authentication, and then causes the fingerprint authentication control unit 341a to perform fingerprint authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 341a, based on the
  • the operating system 360 acquires ID information (identification information) stored in the IC card based on reading of the IC card held by the user by the card reader 344 as card ID information authentication.
  • ID information ID information
  • the fingerprint authentication control unit 341a acquires the fingerprint authentication information of the user associated with the acquired ID information by the identification authentication information, and the fingerprint authentication acquired based on the card ID information authentication as the fingerprint authentication
  • the legitimacy of the user is determined by comparing the information with the fingerprint information acquired by the fingerprint reading unit 343b.
  • the application program 370 includes an application 371 f that acquires information input by the card reader 344 and an application 371 c that is executed when authentication by the information processing apparatus 300 is successful.
  • the embedded controller 351 when the embedded controller 351 receives ID information based on reading by the card reader 344, the embedded controller 351 transmits the received ID information to the fingerprint authentication unit 341 via the I / O controller 351c.
  • the fingerprint authentication unit 341 that has received the ID information reads the identification authentication information from the authentication information storage unit 341b.
  • the fingerprint authentication unit 341 reads fingerprint authentication information associated with the ID information by the identification authentication information from the authentication information storage unit 341b, and the fingerprint based on the read fingerprint authentication information and the fingerprint read by the fingerprint reading unit 343b. Fingerprint authentication is performed based on information.
  • the ID information may be transmitted to the fingerprint authentication unit 341 via the card reader controller 351f and the operating system 360.
  • the fingerprint authentication information includes finger-specific fingerprint authentication information set for a plurality of fingerprints of different fingers of the same user, and an order indicating a predetermined order for the fingerprints of the plurality of fingers. Information.
  • the fingerprint authentication executed by the fingerprint authentication control unit 341a is the fingerprint information based on the fingerprint read by the fingerprint reading unit 343b and the fingerprint authentication unit 341 for the fingerprint information obtained by the user's fingerprint a plurality of times.
  • the authentication information storage unit 341b may prepare a plurality of IC cards owned by the user for the user, and may further change the ID information stored in each IC card. A plurality of identification authentication information corresponding to each ID information may be stored.
  • the information processing apparatus 300 may include an application activation information storage unit (not shown) that stores application activation information that associates identification authentication information with an application activated by the operating system 360. Further, the operating system 360 may determine which identification / authentication information has succeeded in identification / authentication when executing card ID information authentication. In this case, the operating system 360 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 341a and the operating system 360, and the determined application Can be started. As a result, the information processing apparatus 300 can start different applications based on the ID information read from the user's IC card. Therefore, the user selects an application to be started by the read IC card. Is possible.
  • an application activation information storage unit that stores application activation information that associates fingerprints of a plurality of different fingers of the same user with applications activated by the operating system 360 may be provided.
  • the fingerprint authentication information may include finger-specific fingerprint authentication information set for each of a plurality of different fingerprints of the same user.
  • the operating system 360 may determine which fingerprint of the user's finger is successful when executing the fingerprint authentication.
  • the operating system 360 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 341a and the operating system 360, and the determined application Can be started.
  • the information processing apparatus 300 can start different applications based on the finger that the user has read the fingerprint, so the user can select the application that is started by the finger that reads the fingerprint. become.
  • the fingerprint authentication control unit 341a performs fingerprint authentication and card ID authentication. Normally, when different authentication methods are combined, such as fingerprint authentication and card ID authentication, it is necessary to perform processing separately for each authentication device, so the time required to complete all authentication processing is prolonged. Will do. On the other hand, in the present embodiment, the same control unit executes fingerprint authentication and card ID authentication, so that the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
  • the process of opening / closing and calling each driver and library in each application can be simplified, so that the process can be simplified.
  • FIG. 24 is a flowchart illustrating an authentication processing procedure according to the third embodiment.
  • the authentication process shown in FIG. 24 is a process executed by the information processing apparatus 300 (described above in FIG. 23).
  • This authentication process is a process of performing authentication when the information processing apparatus 300 receives an application activation instruction from the user and activates the application, and includes a one-touch button (not illustrated) included in a one-touch operation unit (not illustrated) by the user. Execution is started based on the application activation operation by the operation of (omitted).
  • the user operates the one-touch operation unit corresponding to the application to be activated, so that the embedded controller 351 (described above in FIG. 23) receives the operation of the one-touch operation unit operated by the user.
  • the information processing apparatus 300 starts an authentication process for starting an application corresponding to the operated one-touch operation unit.
  • the card reader controller 351f receives the ID information stored in the user's IC card (not shown) by the card reader 344 (described above in FIG. 23) via the embedded controller 351. By reading, the user's ID information is acquired. Next, the card reader controller 351f transmits the acquired ID information to the card reader driver 361f (described above in FIG. 23). At this time, the card reader controller 351f transmits the received ID information to the fingerprint authentication unit 341 (described above in FIG. 23) via the I / O controller 351c (described above in FIG. 23).
  • the operating system 360 displays a fingerprint authentication message window (not shown) including a display for guiding the user to read the fingerprint on the display screen of the LCD (not shown) of the information processing apparatus 300. indicate.
  • the fingerprint authentication unit 341 starts reading the fingerprint of the user by the fingerprint reading unit 343b (described above in FIG. 23). At this time, the fingerprint authentication control unit 341a (described above in FIG. 23) requests the fingerprint reading unit 343b to transmit the fingerprint information until receiving the fingerprint information obtained as a result of the fingerprint reading. Note that the fingerprint authentication control unit 341a stops the fingerprint authentication when there is no transmission of fingerprint information for a certain period of time.
  • Step S34 The fingerprint authentication control unit 341a reads out and acquires the fingerprint authentication information corresponding to the ID information transmitted in step S31 from the authentication information storage unit 341b (described above in FIG. 23).
  • Step S35 The fingerprint authentication control unit 341a compares the fingerprint information acquired by the fingerprint reading unit 343b and the fingerprint information corresponding to the ID information acquired from the authentication information storage unit 341b, and performs authentication. Determine whether or not. If the authentication is successful, the process proceeds to step S36. On the other hand, if the authentication fails, the process proceeds to step S37.
  • Step S36 The operating system 360 activates the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
  • Step S37 The operating system 360 displays on the LCD display screen an error regarding the activation of the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
  • the authentication process of the present embodiment is started when the information processing apparatus 300 detects an application activation instruction by a user operation, but is not limited to this. For example, a login screen (not shown) is displayed. Execution may be started when the user logs in to the information processing apparatus 300 when an operation to display is performed.
  • step S35 when the fingerprint authentication in step S35 fails, an error display is performed in step S37, but another fingerprint reading may be attempted.
  • 25 and 26 are sequence diagrams illustrating a procedure at the time of authentication according to the third embodiment.
  • “user interface” in the figure is an input device operated by the user and an output device for displaying a screen.
  • the “fingerprint authentication unit” in the figure is the fingerprint authentication unit 341 described above with reference to FIG. As described above, the fingerprint authentication unit 341 includes the fingerprint authentication control unit 341a and the authentication information storage unit 341b.
  • controller in the figure is a control unit that controls an input device such as a card reader 344, and includes an embedded controller 351, an I / O controller 351c, a card reader controller 351f, and the like.
  • operating system in the figure is the operating system 360 and the libraries and drivers of the operating system 360 described above with reference to FIG.
  • Step S301 The card reader 344 reads and acquires ID information from the user's IC card (not shown). This ID information is transmitted to the card reader controller 351f.
  • the card reader controller 351f detects the ID information of the IC card read in step S301.
  • the card reader controller 351f transmits the ID information of the IC card detected in step S302 to the card reader driver 361f. Also, the I / O controller 351c transmits the detected ID information of the IC card to the fingerprint authentication unit 341.
  • the card reader driver 361f further transmits the received ID information to the card reader library 362f. If the card reader library 362f succeeds in fingerprint authentication described later, the card reader library 362f activates the application based on the received ID information.
  • the fingerprint authentication unit 341 performs fingerprint authentication using fingerprint authentication information corresponding to the received ID information.
  • Step S304 The operating system 360 executes processing for starting fingerprint authentication. Specifically, as will be described later, the card reader driver 361f causes the fingerprint authentication driver 361d to activate the fingerprint authentication unit 341. Further, a fingerprint authentication message window (not shown) is displayed on a graphic processing device (not shown) included in the information processing apparatus 300.
  • Step S305 The graphic processing device displays a fingerprint authentication message window on the LCD.
  • Step S306 The fingerprint authentication control unit 341a activates the fingerprint reading unit 343b. As a result, the user's fingerprint can be read.
  • the fingerprint reading unit 343b reads the fingerprint of the user and acquires fingerprint information.
  • the acquired fingerprint information is transmitted to the fingerprint authentication control unit 341a.
  • the fingerprint authentication control unit 341a reads fingerprint authentication information corresponding to the ID information transmitted in step S303 from the authentication information storage unit 341b.
  • the fingerprint authentication control unit 341a compares the fingerprint information of the fingerprint read by the fingerprint reading unit 343b in step S307 with the fingerprint authentication information read from the authentication information storage unit 341b and collates them to authenticate the user's fingerprint. Do. Thereby, the legitimacy of the user who tries to start the application is determined based on the fingerprint.
  • the fingerprint authentication control unit 341a transmits a fingerprint authentication collation result, which is a fingerprint authentication collation result, to the fingerprint authentication driver 361d.
  • the fingerprint authentication driver 361d that has received the fingerprint authentication verification result transmitted from the fingerprint authentication control unit 341a transmits the fingerprint authentication verification result to the fingerprint authentication library 362d.
  • the fingerprint authentication library 362d that has received the fingerprint authentication collation result transmitted from the fingerprint authentication driver 361d has succeeded in the fingerprint authentication of the user performed by the fingerprint authentication control unit 341a in step S321 based on the fingerprint authentication collation result. It is determined whether or not.
  • Step S324 If the received determination result of the fingerprint authentication is successful, the operating system 360 performs display control when the user is successfully authenticated. Specifically, as will be described later, the fingerprint authentication library 362d ends the display of the fingerprint authentication message window on the graphic processing device.
  • the operating system 160 terminates the display of the fingerprint authentication message window and displays an error display on the LCD display screen as described above with reference to FIG. End the process.
  • the graphic processing device ends the display of the fingerprint authentication message window displayed on the LCD display screen.
  • the fingerprint authentication library 362d activates the application that is the target of the activation operation of the user's application.
  • the information processing apparatus 300 by using the authentication based on the ID information of the user's IC card and the fingerprint authentication together, the accuracy of the user authentication is increased, so that the security is improved. .
  • the fingerprint authentication control unit 341a executes fingerprint authentication and card ID authentication processing
  • the same processing unit continuously performs a plurality of authentication processes.
  • the process of exchanging data between processing units that perform authentication can be omitted, and the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
  • the fingerprint authentication unit 341 configured with a one-chip IC, cracking can be prevented by hiding the authentication process from the outside. Yes, it increases safety.
  • the information processing apparatus is an automatic transaction apparatus, and is an automatic teller machine (ATM: AutomatedTMTeller ⁇ ⁇ ⁇ ⁇ Machine) that accepts and pays out deposits such as banks.
  • ATM AutomatedTMTeller ⁇ ⁇ ⁇ ⁇ Machine
  • the form is different.
  • FIG. 27 is a diagram illustrating an appearance of the automatic transaction apparatus according to the fourth embodiment.
  • the automatic transaction apparatus 400 includes an operation screen 481, a bill input / output unit 482 a, a coin input / output unit 482 b, a passbook receiving unit 483, a receiving card receiving unit 484, a receipt issuing unit 485, a fingerprint reading unit 486 and a speaker 487.
  • the operation screen 481 has a display screen for displaying an image showing the contents of a transaction, an image including a message for guiding the user, and a touch panel for receiving user input.
  • the banknote deposit / withdrawal unit 482a deposits / withdraws banknotes for accepting user deposits and dispensing user deposits.
  • the coin deposit / withdrawal unit 482b deposits / withdraws coins for accepting the deposit of the user and paying out the deposit of the user.
  • the passbook accepting unit 483 accepts a passbook when accepting a user's deposit, when paying out a user's deposit, and when other users wish to book.
  • the card reception unit 484 receives a cash card or the like when the user uses it.
  • the receipt issuing unit 485 issues a receipt in which usage details are recorded when the user uses it.
  • the fingerprint reading unit 486 reads the user's fingerprint in order to perform fingerprint authentication of the user at the time of use.
  • the speaker 487 outputs voice guidance and warning sound for guiding the transaction status and operation to the
  • the fourth embodiment by performing authentication other than fingerprint authentication in the automatic transaction apparatus 400, the accuracy of user authentication for the user using the automatic transaction apparatus 400 is improved. Security increases because it increases.
  • the fingerprint authentication process is concealed from the outside, so that cracks can be prevented and safety is improved.
  • the above processing functions can be realized by a computer.
  • a program describing the processing contents of the functions that the information processing apparatuses 100, 200, 300 and the automatic transaction apparatus 400 should have is provided.
  • the above processing functions are realized on the computer.
  • the program describing the processing content can be recorded on a computer-readable recording medium.
  • the computer-readable recording medium include a magnetic recording device, an optical disk, a magneto-optical recording medium, and a semiconductor memory.
  • Magnetic recording devices include HDDs, flexible disks (FD), magnetic tapes (MT) and the like.
  • Optical discs include DVD (Digital Versatile Disc), DVD-RAM, CD-ROM (Compact Disc-Read Only Memory), CD-R (Recordable) / RW (ReWritable), and the like.
  • Magneto-optical recording media include MO (Magneto-Optical Disk).
  • a portable recording medium such as a DVD or CD-ROM in which the program is recorded is sold. It is also possible to store the program in a server computer and transfer the program from the server computer to another computer via a network.
  • the computer that executes the program stores, for example, the program recorded on the portable recording medium or the program transferred from the server computer in its own storage device. Then, the computer reads the program from its own storage device and executes processing according to the program. The computer can also read the program directly from the portable recording medium and execute processing according to the program. Further, each time the program is transferred from the server computer, the computer can sequentially execute processing according to the received program.
  • the disclosed information processing apparatus, authentication program, and authentication method have been described based on the illustrated embodiment, the configuration of each unit can be replaced with an arbitrary configuration having the same function.
  • any other component or process may be added to the disclosed technology.
  • the disclosed technique may be a combination of any two or more of the above-described embodiments.

Abstract

It is possible to improve the authentication accuracy by using a fingerprint authentication in combination with other authentication method. A control unit (1a) executes a process when a user is authenticated by an authentication control unit (1d). A fingerprint information acquisition unit (1b) acquires fingerprint information. An identification information acquisition unit (1c) acquires identification inforatmion. An authentication control unit (1d) compares the fingerprint information to the fingerprint authentication information to execute a first authentication and compares the identification information to the identification authentication information to execute a second authentication. If the first authentication and the second authentication are both successful, it is decided that the user is authorized. A fingerprint authentication information storage unit (1e) stores fingerprint authentication information. An identification authentication information storage unit (1f) stores the identification authentication information.

Description

情報処理装置、認証プログラムおよび認証方法Information processing apparatus, authentication program, and authentication method
 本発明は、情報処理装置、認証プログラムおよび認証方法に関し、特に、指紋を用いて認証を行う情報処理装置、認証プログラムおよび認証方法に関する。 The present invention relates to an information processing apparatus, an authentication program, and an authentication method, and more particularly, to an information processing apparatus, an authentication program, and an authentication method that perform authentication using a fingerprint.
 近年、情報処理装置および情報ネットワークの普及により、社会で多くの情報が利用されており、また、機密情報や個人情報の保護の要求も高まっている。これに対して、ノート型パーソナルコンピュータ(以下、ノートPCとする)等の携帯型の情報処理装置は、移動先や移動中に使用される機会が比較的多いため、セキュリティ対策が重視される。 In recent years, with the spread of information processing devices and information networks, a lot of information is used in society, and the demand for protection of confidential information and personal information is also increasing. On the other hand, since portable information processing apparatuses such as notebook personal computers (hereinafter referred to as notebook PCs) are relatively frequently used during movement destinations or during movement, security measures are emphasized.
 セキュリティ対策の1つとして、ノートPCの使用者を認証する個人認証がある。この個人認証のうち、使用者において生体的に固有である指紋等の生体情報によるバイオメトリクス認証が注目されている。この指紋認証に関して、以下の技術が知られている。
特開2000-293253号公報 特開2003-157140号公報 特開2006-172129号公報 特開2005-100063号公報 特開2006-24205号公報
As one of the security measures, there is personal authentication for authenticating the user of the notebook PC. Of these personal authentications, biometric authentication based on biometric information such as fingerprints that are biometrically unique to the user has attracted attention. The following techniques are known for this fingerprint authentication.
JP 2000-293253 A JP 2003-157140 A JP 2006-172129 A JP 2005-100063 A JP 2006-24205 A
 しかし、指紋認証等のバイオメトリクス認証の場合、一種類の生体情報だけでは、精度が不十分な場合があるという問題点がある。
 本件はこのような点に鑑みてなされたものであり、指紋認証と他の認証方法を利用することにより認証の精度が高い情報処理装置、認証プログラムおよび認証方法を提供することを目的とする。
However, in the case of biometric authentication such as fingerprint authentication, there is a problem that accuracy may be insufficient with only one type of biometric information.
The present invention has been made in view of such a point, and an object thereof is to provide an information processing apparatus, an authentication program, and an authentication method with high authentication accuracy by using fingerprint authentication and other authentication methods.
 開示の情報処理装置は、ユーザを認証するために前記ユーザの指紋から取得される情報である指紋情報を取得する指紋情報取得部と、前記ユーザを認証するための情報であると共に前記指紋情報とは異なる情報である識別情報を取得する識別情報取得部と、前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記指紋情報と比較することにより前記ユーザを認証するための指紋認証情報を記憶する指紋認証情報記憶部と、前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記識別情報と比較することにより前記ユーザを認証する識別認証情報を記憶する識別認証情報記憶部と、前記指紋情報取得部によって取得された前記指紋情報と前記指紋認証情報記憶部に記憶された前記指紋認証情報とを比較して第1の認証を実行すると共に、前記識別情報取得部によって取得された前記識別情報と前記識別認証情報記憶部に記憶された前記識別認証情報とを比較して第2の認証を実行し、前記第1の認証と前記第2の認証とに成功した場合に、前記ユーザを正当であると認証する認証制御部と、前記認証制御部によって前記ユーザが正当であると認証された場合に、正当なユーザに許可された処理を実行する制御部と、を有する。 The disclosed information processing apparatus includes a fingerprint information acquisition unit that acquires fingerprint information, which is information acquired from the fingerprint of the user to authenticate the user, and information that is used to authenticate the user and the fingerprint information Is an identification information acquisition unit that acquires identification information that is different information, and information that is set in advance for use in authentication as to whether or not the user is legitimate, and compares the fingerprint information with the user. A fingerprint authentication information storage unit for storing fingerprint authentication information for authenticating the information, and information set in advance for use in authenticating whether or not the user is valid, by comparing with the identification information Stored in the identification authentication information storage unit for storing the identification authentication information for authenticating the user, the fingerprint information acquired by the fingerprint information acquisition unit, and the fingerprint authentication information storage unit The fingerprint authentication information is compared with the first authentication, and the identification information acquired by the identification information acquisition unit is compared with the identification authentication information stored in the identification authentication information storage unit. When the second authentication is executed and the first authentication and the second authentication are successful, the authentication control unit authenticates the user as valid, and the authentication control unit authenticates the user. And a control unit that executes a process permitted by a legitimate user when it is authenticated.
 開示の情報処理装置によれば、指紋情報取得部により、指紋情報が取得される。識別情報取得部により、識別情報が取得される。指紋認証情報記憶部により、指紋認証情報が記憶される。識別認証情報記憶部により、識別認証情報が記憶される。認証制御部により、指紋情報と指紋認証情報とを比較して第1の認証が行われると共に、識別情報と識別認証情報とを比較して第2の認証が行われ、第1の認証と第2の認証とに成功した場合に、ユーザが正当であると認証される。制御部により、認証制御部においてユーザが正当であると認証された場合に、正当なユーザに許可された処理が実行される。 According to the disclosed information processing apparatus, fingerprint information is acquired by the fingerprint information acquisition unit. Identification information is acquired by the identification information acquisition unit. Fingerprint authentication information is stored by the fingerprint authentication information storage unit. The identification / authentication information is stored by the identification / authentication information storage unit. The authentication control unit compares the fingerprint information with the fingerprint authentication information to perform the first authentication, compares the identification information with the identification authentication information, performs the second authentication, and performs the first authentication and the first authentication. If the second authentication is successful, the user is authenticated as valid. When the control unit authenticates the user as valid by the authentication control unit, processing permitted to the valid user is executed.
 開示の情報処理装置、認証プログラムおよび認証方法によれば、情報処理装置が指紋認証および他の認証方法を併用することにより認証の精度を高めることが可能になる。
 本発明の上記および他の目的、特徴および利点は本発明の例として好ましい実施の形態を表す添付の図面と関連した以下の説明により明らかになるであろう。
According to the disclosed information processing apparatus, authentication program, and authentication method, the information processing apparatus can increase the accuracy of authentication by using fingerprint authentication and other authentication methods in combination.
These and other objects, features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings which illustrate preferred embodiments by way of example of the present invention.
本実施の形態の概要を示す図である。It is a figure which shows the outline | summary of this Embodiment. 情報処理装置の外観を示す図である。It is a figure which shows the external appearance of information processing apparatus. ワンタッチ操作部を示す図である。It is a figure which shows a one-touch operation part. 接触入力部を示す図である。It is a figure which shows a contact input part. 情報処理装置のハードウェア構成を示す図である。It is a figure which shows the hardware constitutions of information processing apparatus. 第1の実施の形態の情報処理装置の構成を示すブロック図である。It is a block diagram which shows the structure of the information processing apparatus of 1st Embodiment. 第1の実施の形態の認証処理の手順を示すフローチャートである。It is a flowchart which shows the procedure of the authentication process of 1st Embodiment. 第1の実施の形態の認証処理の手順を示すフローチャートである。It is a flowchart which shows the procedure of the authentication process of 1st Embodiment. 第1の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 1st Embodiment. 第1の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 1st Embodiment. 第1の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 1st Embodiment. 第1の実施の形態の筆跡認証の判定における入力された図形の筆跡への分解を示す図である。It is a figure which shows decomposition | disassembly into the handwriting of the figure input in determination of the handwriting authentication of 1st Embodiment. 第1の実施の形態の筆跡認証の判定における筆跡のベクトルへの分解を示す図である。It is a figure which shows decomposition | disassembly into the vector of handwriting in determination of handwriting authentication of 1st Embodiment. 第1の実施の形態の筆跡認証の判定におけるベクトルを区分した各部分のベクトルを示す図である。It is a figure which shows the vector of each part which divided the vector in determination of the handwriting authentication of 1st Embodiment. 第1の実施の形態の指紋認証メッセージウインドウを示す図である。It is a figure which shows the fingerprint authentication message window of 1st Embodiment. 第1の実施の形態の筆跡認証メッセージウインドウを示す図である。It is a figure which shows the handwriting authentication message window of 1st Embodiment. 第1の実施の形態のアプリケーションウインドウを示す図である。It is a figure which shows the application window of 1st Embodiment. 第2の実施の形態の情報処理装置の構成を示すブロック図である。It is a block diagram which shows the structure of the information processing apparatus of 2nd Embodiment. 第2の実施の形態の認証処理の手順を示すフローチャートである。It is a flowchart which shows the procedure of the authentication process of 2nd Embodiment. 第2の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 2nd Embodiment. 第2の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 2nd Embodiment. 第2の実施の形態の指紋認証メッセージウインドウを示す図である。It is a figure which shows the fingerprint authentication message window of 2nd Embodiment. 第3の実施の形態の情報処理装置の構成を示すブロック図である。It is a block diagram which shows the structure of the information processing apparatus of 3rd Embodiment. 第3の実施の形態の認証処理の手順を示すフローチャートである。It is a flowchart which shows the procedure of the authentication process of 3rd Embodiment. 第3の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 3rd Embodiment. 第3の実施の形態の認証時の手順を示すシーケンス図である。It is a sequence diagram which shows the procedure at the time of the authentication of 3rd Embodiment. 第4の実施の形態の自動取引装置の外観を示す図である。It is a figure which shows the external appearance of the automatic transaction apparatus of 4th Embodiment.
 以下、実施の形態について、図面を参照して説明する。
 図1は、本実施の形態の概要を示す図である。図1に示す情報処理装置1は、情報処理装置1のパスワードを設定するための設定実行プログラムを出力する。情報処理装置1は、制御部1a、指紋情報取得部1b、識別情報取得部1c、認証制御部1d、指紋認証情報記憶部1e、識別認証情報記憶部1fを有する。
Hereinafter, embodiments will be described with reference to the drawings.
FIG. 1 is a diagram showing an outline of the present embodiment. The information processing apparatus 1 illustrated in FIG. 1 outputs a setting execution program for setting a password for the information processing apparatus 1. The information processing apparatus 1 includes a control unit 1a, a fingerprint information acquisition unit 1b, an identification information acquisition unit 1c, an authentication control unit 1d, a fingerprint authentication information storage unit 1e, and an identification / authentication information storage unit 1f.
 制御部1aは、ユーザによる情報処理装置1の起動指示もしくはログインの受け付けを開始するログイン指示、またはアプリケーションの起動を指示するアプリケーション起動指示もしくはアプリケーションの実行を指示するアプリケーション実行指示を受け付ける。制御部1aは、上記の指示に対応する処理が正当なユーザ以外のユーザに対して実行が制限される処理であるときには、認証制御部1dによってユーザが正当であると認証された場合に、上記の指示に基づいて正当なユーザに許可された処理を実行する。 The control unit 1a receives a start instruction of the information processing apparatus 1 by the user or a login instruction for starting reception of a login, an application start instruction for instructing start of an application, or an application execution instruction for instructing execution of an application. When the process corresponding to the above instruction is a process whose execution is restricted for a user other than a valid user, the control unit 1a performs the above process when the authentication control unit 1d authenticates the user as valid. Based on the instruction, the process authorized by the legitimate user is executed.
 指紋情報取得部1bは、ユーザを認証するためにユーザの指紋から取得される情報である指紋情報を取得する。この指紋情報は、上記の処理の実行のために取得される情報であって、正当なユーザの指の指紋の特徴を示す情報である。上記の処理を情報処理装置1に実行させようとするユーザは、正当であると認証されるために、そのユーザの予め登録された指の指紋情報を、情報処理装置1が有する指紋情報取得部1bに読み取らせる。これにより、ユーザの指紋情報が取得される。 The fingerprint information acquisition unit 1b acquires fingerprint information which is information acquired from the user's fingerprint in order to authenticate the user. This fingerprint information is information acquired for executing the above-described processing, and is information indicating the characteristics of the fingerprint of the legitimate user's finger. A user who intends to cause the information processing apparatus 1 to execute the above-described processing is authenticated as valid, so that the fingerprint information acquisition unit of the information processing apparatus 1 has the fingerprint information of the user's previously registered finger. Let 1b read. Thereby, the fingerprint information of the user is acquired.
 識別情報取得部1cは、ユーザを認証するための情報であると共に指紋情報とは異なる情報である識別情報を取得する。この識別情報は、上記の処理の実行のために取得される情報であって、ユーザID(Identification)等、情報処理装置1を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。ユーザIDは、情報処理装置1が有するキーボード、ボタン型入力装置その他の入力装置によって入力が受け付けられる。なお、識別情報は、例えば、ユーザが所持する装置であってICカード等の情報を記憶可能な装置に記憶されたID情報、虹彩や掌紋等の指紋以外のバイオメトリクス情報等、ユーザを識別可能な情報であれば足りる。 The identification information acquisition unit 1c acquires identification information that is information for authenticating the user and is different from the fingerprint information. This identification information is information acquired for the execution of the above processing, and the user ID that uses the information processing apparatus 1, such as a user ID (Identification), is authorized to use other users and other users. This information makes it possible to identify a person who does not have The user ID is input by a keyboard, a button-type input device, or other input devices that the information processing apparatus 1 has. The identification information can identify the user, for example, ID information stored in a device owned by the user and capable of storing information such as an IC card, biometric information other than fingerprints such as iris and palm print, etc. It ’s enough if it ’s information.
 認証制御部1dは、指紋情報取得部1bによって取得された指紋情報と指紋認証情報記憶部1eに記憶された指紋認証情報とを比較して第1の認証を行うと共に、識別情報取得部1cによって取得された識別情報と識別認証情報記憶部1fに記憶された識別認証情報とを比較して第2の認証を行い、第1の認証と第2の認証とに成功した場合に、ユーザを正当であると認証する。 The authentication control unit 1d performs first authentication by comparing the fingerprint information acquired by the fingerprint information acquisition unit 1b with the fingerprint authentication information stored in the fingerprint authentication information storage unit 1e, and also by the identification information acquisition unit 1c. The second authentication is performed by comparing the acquired identification information with the identification authentication information stored in the identification authentication information storage unit 1f, and if the first authentication and the second authentication are successful, the user is authorized. Authenticate that
 指紋情報と指紋認証情報とを比較する第1の認証は、指紋情報が示すユーザの指紋を読み取って抽出した特徴点と、予め設定された指紋認証情報が示す特徴点とを比較して行われる。識別情報と識別認証情報とを比較する第2の認証も同様に、認証を受けるユーザから取得された識別情報が示す特徴点と、予め設定された識別認証情報が示す特徴点とを比較して行われる。 The first authentication for comparing the fingerprint information with the fingerprint authentication information is performed by comparing the feature point extracted by reading the user's fingerprint indicated by the fingerprint information with the feature point indicated by the preset fingerprint authentication information. . Similarly, in the second authentication for comparing the identification information and the identification authentication information, the feature point indicated by the identification information acquired from the user to be authenticated is compared with the feature point indicated by the preset identification authentication information. Done.
 指紋認証情報記憶部1eは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、指紋情報と比較することによりユーザを認証するための指紋認証情報を記憶する。この指紋認証情報は、予め情報処理装置1が有する情報であって、正当なユーザの指紋を読み取って抽出した指紋の特徴を示す情報である。 The fingerprint authentication information storage unit 1e is information set in advance for use in authenticating whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information. . This fingerprint authentication information is information that the information processing apparatus 1 has in advance, and is information indicating the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint.
 識別認証情報記憶部1fは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、識別情報と比較することによりユーザを認証する識別認証情報を記憶する。この識別認証情報は、予め情報処理装置1が有する情報であって、情報処理装置1を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。識別認証情報は、識別情報と比較可能な情報である。 The identification / authentication information storage unit 1f is information set in advance for use in authentication of whether or not the user is valid, and stores identification / authentication information for authenticating the user by comparing with the identification information. This identification authentication information is information that the information processing apparatus 1 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 1 from other users and those who do not have a valid use authority other than the user. Information. The identification authentication information is information that can be compared with the identification information.
 このような情報処理装置1によれば、指紋情報取得部1bにより、指紋情報が取得される。識別情報取得部1cにより、識別情報が取得される。指紋認証情報記憶部1eにより、指紋認証情報が記憶される。識別認証情報記憶部1fにより、識別認証情報が記憶される。認証制御部1dにより、指紋情報と指紋認証情報とを比較して第1の認証が行われると共に、識別情報と識別認証情報とを比較して第2の認証が行われ、第1の認証と第2の認証とに成功した場合に、ユーザが正当であると認証される。制御部1aにより、認証制御部1dにおいてユーザが正当であると認証された場合に、正当なユーザに許可された処理が実行される。 According to such an information processing apparatus 1, fingerprint information is acquired by the fingerprint information acquisition unit 1b. Identification information is acquired by the identification information acquisition unit 1c. Fingerprint authentication information is stored in the fingerprint authentication information storage unit 1e. Identification and authentication information is stored in the identification and authentication information storage unit 1f. The authentication control unit 1d compares the fingerprint information with the fingerprint authentication information to perform the first authentication, compares the identification information with the identification authentication information, performs the second authentication, If the second authentication is successful, the user is authenticated as valid. When the control unit 1a authenticates that the user is valid in the authentication control unit 1d, a process permitted to the valid user is executed.
 これによって、指紋認証と他の認証方法を利用することにより認証の精度を高めることが可能になると共に、効率的に処理を行うことで認証処理を実行する際の処理の負担を軽減することが可能になる。 This makes it possible to improve the accuracy of authentication by using fingerprint authentication and other authentication methods, and reduce the processing burden when executing the authentication process by efficiently performing the process. It becomes possible.
 [第1の実施の形態]
 以下、第1の実施の形態について図面を参照して詳細に説明する。
 図2は、情報処理装置の外観を示す図である。図2に示す情報処理装置100は、パスワード認証によるセキュリティ機能が付加された、ノートタイプ(ラップトップタイプ:laptop type)のパーソナルコンピュータである。情報処理装置100は、LCD(Liquid Crystal Display)121を有するディスプレイ部120、キーボード131ならびに図5において後述する指紋認証部141、カードリーダ144、その他のCPU(Central Processing Unit)101等の電子部品を有する本体部130を有する。また、本体部130の上面には、ワンタッチ操作部142が配置されている。
[First Embodiment]
Hereinafter, a first embodiment will be described in detail with reference to the drawings.
FIG. 2 is a diagram illustrating an appearance of the information processing apparatus. An information processing apparatus 100 shown in FIG. 2 is a notebook type (laptop type) personal computer to which a security function based on password authentication is added. The information processing apparatus 100 includes an electronic component such as a display unit 120 having an LCD (Liquid Crystal Display) 121, a keyboard 131, and a fingerprint authentication unit 141, a card reader 144, and other CPU (Central Processing Unit) 101 described later in FIG. It has a main body portion 130. A one-touch operation unit 142 is disposed on the upper surface of the main body 130.
 LCD121は、文字または画像を表示する表示画面を有する表示装置である。なお、表示装置としては、LCD以外にも、例えば有機EL(Electroluminescence)ディスプレイ等の他の薄型表示デバイスを用いてもよい。キーボード131は、文字の入力およびその他の操作を行うための入力装置である。 The LCD 121 is a display device having a display screen for displaying characters or images. In addition to the LCD, other thin display devices such as an organic EL (Electroluminescence) display may be used as the display device. The keyboard 131 is an input device for inputting characters and performing other operations.
 ワンタッチ操作部142は、詳しくは図3において後述するが、ユーザが押下操作による入力を行うための操作部である。
 接触入力部143は、詳しくは図4において後述するが、ユーザが筆跡入力など入力を行うためのデジタイザ143aおよび指紋を読み取らせて指紋情報の入力を行うための指紋読み取り部143bを有する入力装置である。
As will be described in detail later with reference to FIG. 3, the one-touch operation unit 142 is an operation unit for the user to perform an input by a pressing operation.
As will be described in detail later with reference to FIG. 4, the contact input unit 143 is an input device having a digitizer 143a for a user to input handwriting and the like, and a fingerprint reading unit 143b for reading fingerprints and inputting fingerprint information. is there.
 カードリーダ144は、詳しくは図5において後述するが、ICカードと通信することによりICカードに記憶されている情報を読み取るための装置である。
 なお、本実施の形態の情報処理装置100では、ノートタイプのパーソナルコンピュータについて説明したが、情報処理装置100は情報処理装置の一例であり、本実施の形態のユーザ認証機能は、携帯電話やPDA(Personal Digital Assistant)を初めとする移動通信用端末装置、デスクトップタイプ(desktop type)のパーソナルコンピュータ、情報処理システムの端末装置等のように、ユーザ認証を行う情報処理装置に適用することができる。
As will be described in detail later with reference to FIG. 5, the card reader 144 is a device for reading information stored in the IC card by communicating with the IC card.
Note that the information processing apparatus 100 according to the present embodiment has been described with respect to the notebook type personal computer. However, the information processing apparatus 100 is an example of the information processing apparatus, and the user authentication function according to the present embodiment can be performed using a mobile phone or PDA. (Personal Digital Assistant) and other mobile communication terminal devices, desktop type personal computers, information processing system terminal devices, and the like can be applied to information processing devices that perform user authentication.
 図3は、ワンタッチ操作部を示す図である。図3に示すワンタッチ操作部142は、ユーザが押下操作による入力を行うための操作部である。ワンタッチ操作部142は、ワンタッチボタン142aおよび確定ボタン142bを有する。 FIG. 3 is a diagram showing a one-touch operation unit. A one-touch operation unit 142 illustrated in FIG. 3 is an operation unit for a user to perform an input by a pressing operation. The one-touch operation unit 142 includes a one-touch button 142a and a confirmation button 142b.
 ワンタッチボタン142aは、例えば、ユーザによるアプリケーションの起動指示などの入力を受け付けるボタンである。
 本実施の形態のワンタッチ操作部142は、ワンタッチボタン142aとして、「1」~「4」の符号が付された4個のボタンを有する。各ボタンにはユーザが使用するアプリケーションが割り当てられており、ユーザの押下操作により、割り当てられたアプリケーションの起動指示が出力される。ワンタッチボタン142aの個数および付される符号は、これに限らず、必要に応じて自由に設定することができる。
The one-touch button 142a is a button that receives an input such as an application activation instruction from the user, for example.
The one-touch operation unit 142 according to the present embodiment has four buttons with symbols “1” to “4” as the one-touch buttons 142a. An application to be used by the user is assigned to each button, and an activation instruction for the assigned application is output by a pressing operation of the user. The number of the one-touch buttons 142a and the attached codes are not limited to this, and can be freely set as necessary.
 確定ボタン142bは、ワンタッチボタン142aを操作することによって行われた入力を確定させるボタンである。確定ボタン142bが操作されると、ワンタッチボタン142aによる操作に対応する信号が、図5において後述する入力インタフェース105に送信される。なお、ワンタッチボタン142aが操作された場合、確定ボタン142bの操作を待たずに、ワンタッチボタン142aの操作に対応する信号が送信されてもよい。 The confirmation button 142b is a button for confirming an input made by operating the one-touch button 142a. When the confirm button 142b is operated, a signal corresponding to the operation by the one-touch button 142a is transmitted to the input interface 105 described later with reference to FIG. When the one-touch button 142a is operated, a signal corresponding to the operation of the one-touch button 142a may be transmitted without waiting for the operation of the confirm button 142b.
 図4は、接触入力部を示す図である。図4に示す接触入力部143は、ユーザが筆跡入力など入力を行うためのデジタイザ143aおよび指紋を読み取らせて指紋情報の入力を行うための指紋読み取り部143bを有する入力装置である。 FIG. 4 is a diagram showing the contact input unit. The contact input unit 143 shown in FIG. 4 is an input device having a digitizer 143a for a user to input handwriting and the like and a fingerprint reading unit 143b for inputting fingerprint information by reading a fingerprint.
 デジタイザ143aは、表面に設けられた入力面の圧力または静電気の変化の検出によって、入力面に対するユーザの指先またはタッチペンの接触を検知することにより座標を取得する。デジタイザ143aは、この座標を連続的に取得することで、例えば、ユーザが描く実時間(リアルタイム)の筆跡の入力等の、ユーザによる入力を受け付けることができる。また、デジタイザ143aは、筆跡の座標を取得する際に、同時に時間情報を取得する。これにより、筆跡の座標および時間情報が対応付けて取得される。 The digitizer 143a acquires coordinates by detecting the contact of the user's fingertip or touch pen with the input surface by detecting a change in pressure or static electricity of the input surface provided on the surface. The digitizer 143a can receive input by the user such as input of real-time (real-time) handwriting drawn by the user by continuously acquiring the coordinates. Also, the digitizer 143a acquires time information at the same time when acquiring the coordinates of the handwriting. Thereby, the coordinates of the handwriting and the time information are acquired in association with each other.
 指紋読み取り部143bは、ユーザの指先の指紋を読み取ることによって指紋情報を取得する指紋センサを有している。指紋を指紋読み取り部143bに読み取らせる場合、ユーザは、指紋読み取り部143bに対して指紋を読み取らせるための予め定められた指の指先の腹(指紋のある側)を当て、図の矢印Aの向きに滑らせる。これにより、指紋読み取り部143bは、ユーザの指の指紋を読み取ることができる。 The fingerprint reading unit 143b has a fingerprint sensor that acquires fingerprint information by reading the fingerprint of the user's fingertip. When the fingerprint reading unit 143b reads the fingerprint, the user applies a predetermined fingertip of the fingertip (the side with the fingerprint) for causing the fingerprint reading unit 143b to read the fingerprint, and the arrow A in FIG. Slide in the direction. Accordingly, the fingerprint reading unit 143b can read the fingerprint of the user's finger.
 また、接触入力部143は、LED(Light Emitting Diode)143cを有する。LED143cは、デジタイザ143aの筆跡の読み取りの際、1ストローク読み取る毎に一定時間点灯する。これによりユーザは、筆跡認証の際、筆跡が読み取られたことを確認しながら図形を入力することができる。 The contact input unit 143 includes an LED (Light Emitting Diode) 143c. The LED 143c is lit for a certain time each time one stroke is read when reading the handwriting of the digitizer 143a. Thus, the user can input a figure while confirming that the handwriting has been read during handwriting authentication.
 図5は、情報処理装置のハードウェア構成を示す図である。図5に示す情報処理装置100は、前述のようにノートタイプのパーソナルコンピュータであり、CPU101によって装置全体が制御されている。CPU101には、バス107を介してRAM(Random Access Memory)102、ハードディスクドライブ(HDD:Hard Disk Drive)103、グラフィック処理装置104、入力インタフェース105および通信インタフェース106が接続されている。 FIG. 5 is a diagram illustrating a hardware configuration of the information processing apparatus. The information processing apparatus 100 shown in FIG. 5 is a notebook type personal computer as described above, and the entire apparatus is controlled by the CPU 101. A RAM (Random Access Memory) 102, a hard disk drive (HDD: Hard Disk Drive) 103, a graphic processing device 104, an input interface 105, and a communication interface 106 are connected to the CPU 101 via a bus 107.
 RAM102には、CPU101に実行させるOS(Operating System:オペレーティングシステム)のプログラムやアプリケーションプログラムの少なくとも一部が一時的に格納される。また、RAM102には、CPU101による処理に必要な各種データが格納される。HDD103には、OSやアプリケーションプログラムが格納される。 The RAM 102 temporarily stores at least a part of an OS (Operating System) program and application programs to be executed by the CPU 101. The RAM 102 stores various data necessary for processing by the CPU 101. The HDD 103 stores an OS and application programs.
 グラフィック処理装置104には、LCD121等の表示装置が接続されている。グラフィック処理装置104は、CPU101からの命令にしたがって、画像をLCD121等の表示装置の表示画面に表示させることができる。また、グラフィック処理装置104とLCD121とは、例えば、シリアル通信ケーブルで接続され制御信号と画像信号とが交互に送受信される。 A display device such as an LCD 121 is connected to the graphic processing device 104. The graphic processing device 104 can display an image on a display screen of a display device such as the LCD 121 in accordance with a command from the CPU 101. Further, the graphic processing device 104 and the LCD 121 are connected by, for example, a serial communication cable, and control signals and image signals are alternately transmitted and received.
 入力インタフェース105には、キーボード131、マウス13等の入力装置が接続されている。入力インタフェース105は、キーボード131等の入力装置から送られてくる信号を、バス107を介してCPU101に出力する。また、入力インタフェース105には、指紋認証部141、接触入力部143、カードリーダ144が接続されている。また、キーボード131には、ワンタッチ操作部142が接続されている。ワンタッチ操作部142を操作することによって出力される信号は、キーボード131を通じ、バス107を介して入力インタフェース105に出力される。 The input interface 105 is connected to input devices such as a keyboard 131 and a mouse 13. The input interface 105 outputs a signal sent from an input device such as a keyboard 131 to the CPU 101 via the bus 107. In addition, a fingerprint authentication unit 141, a contact input unit 143, and a card reader 144 are connected to the input interface 105. A one-touch operation unit 142 is connected to the keyboard 131. A signal output by operating the one-touch operation unit 142 is output to the input interface 105 through the keyboard 131 and the bus 107.
 通信インタフェース106は、LAN(Local Area Network)等の通信回線に接続可能である。通信インタフェース106は、通信回線を介して、他のコンピュータとの間でデータの送受信を行うことができる。 The communication interface 106 can be connected to a communication line such as a LAN (Local Area Network). The communication interface 106 can send and receive data to and from other computers via a communication line.
 指紋認証部141は、ユーザの指紋から取得された指紋情報および、例えば、ユーザのリアルタイムの筆跡に基づいて取得された筆跡情報等の、指紋情報とは異なるユーザの識別情報の入力を受け付けて認証を行う。指紋認証部141が認証に成功した場合、情報処理装置100において、例えば、所定のアプリケーションを起動する等、情報処理装置100の所定の処理が実行される。指紋認証部141は、指紋認証制御部141aおよび認証情報記憶部141bを有する。また、指紋認証部141には、キーボード131、カードリーダ144、接触入力部143が接続されており、これらと通信することにより各入力装置によってユーザにより入力された情報を取得することが可能である。 The fingerprint authentication unit 141 accepts and authenticates input of user identification information different from fingerprint information, such as fingerprint information acquired from the user's fingerprint and, for example, handwriting information acquired based on the user's real-time handwriting. I do. When the fingerprint authentication unit 141 succeeds in authentication, the information processing apparatus 100 executes predetermined processing of the information processing apparatus 100 such as starting a predetermined application. The fingerprint authentication unit 141 includes a fingerprint authentication control unit 141a and an authentication information storage unit 141b. Further, a keyboard 131, a card reader 144, and a contact input unit 143 are connected to the fingerprint authentication unit 141, and information input by the user by each input device can be acquired by communicating with these. .
 指紋認証制御部141aは、指紋情報および識別情報を用いた認証を制御する。認証情報記憶部141bは、指紋認証部141で行われる認証に用いられる指紋認証情報および指紋認証とは異なる認証方法であって情報処理装置100で行われる認証に用いられる情報である識別認証情報を記憶する。認証情報記憶部141bは、EEPROM(Electronically Erasable and Programmable Read Only Memory)を有する。指紋認証部141は、認証に使用する指紋認証情報および識別認証情報を、認証情報記憶部141bが有するEEPROMに記憶させることができ、EEPROMに記憶させた認証情報ならびに指紋読み取り部143bによって取得された指紋情報および例えば、デジタイザ143a等の他の入力装置によって取得された識別情報に基づいて認証を行う。 The fingerprint authentication control unit 141a controls authentication using fingerprint information and identification information. The authentication information storage unit 141b stores fingerprint authentication information used for authentication performed by the fingerprint authentication unit 141 and identification authentication information which is an authentication method different from fingerprint authentication and is used for authentication performed by the information processing apparatus 100. Remember. The authentication information storage unit 141b includes an EEPROM (Electronically Erasable and Programmable Read Only Memory). The fingerprint authentication unit 141 can store fingerprint authentication information and identification authentication information used for authentication in the EEPROM included in the authentication information storage unit 141b, and is acquired by the authentication information stored in the EEPROM and the fingerprint reading unit 143b. Authentication is performed based on the fingerprint information and identification information acquired by another input device such as the digitizer 143a.
 なお、本実施の形態では、識別認証情報を指紋認証情報と共に認証情報記憶部141bに記憶させるが、これに限らず、他の記憶装置において、指紋認証情報とは別に記憶させてもよい。 In this embodiment, the identification authentication information is stored in the authentication information storage unit 141b together with the fingerprint authentication information. However, the present invention is not limited to this, and may be stored separately from the fingerprint authentication information in another storage device.
 ワンタッチ操作部142は、図3において前述したように、ユーザが押下操作により、起動するアプリケーションの入力およびその他の入力を行うための操作部である。
 カードリーダ144は、無線通信によって図示しないICカードと電気的に接続可能である。カードリーダ144は、接続されたICカードとの間で情報通信を行うことができる。情報処理装置100は、このカードリーダ144によるICカードとの無線通信により、例えば、識別情報等の、ICカードに記憶されている情報を取得することができる。
As described above with reference to FIG. 3, the one-touch operation unit 142 is an operation unit for performing input of an application to be activated and other inputs by a user's pressing operation.
The card reader 144 can be electrically connected to an IC card (not shown) by wireless communication. The card reader 144 can perform information communication with the connected IC card. The information processing apparatus 100 can acquire information stored in the IC card, such as identification information, by wireless communication with the IC card by the card reader 144.
 なお、本実施の形態のカードリーダ144は、無線通信によってICカードと電気的に接続可能であるが、これに限らず、カードスロット等により、端子同士を接触させることにより電気的に接続してもよい。 Note that the card reader 144 of this embodiment can be electrically connected to the IC card by wireless communication. However, the card reader 144 is not limited thereto, and is electrically connected by bringing terminals into contact with each other using a card slot or the like. Also good.
 以上のようなハードウェア構成によって、本実施の形態の処理機能を実現することができる。
 図6は、第1の実施の形態の情報処理装置の構成を示すブロック図である。図6に示す情報処理装置100は、指紋認証部141、組み込みコントローラ151、オペレーティングシステム160、アプリケーションプログラム170を有する。
With the hardware configuration as described above, the processing functions of the present embodiment can be realized.
FIG. 6 is a block diagram illustrating a configuration of the information processing apparatus according to the first embodiment. The information processing apparatus 100 illustrated in FIG. 6 includes a fingerprint authentication unit 141, an embedded controller 151, an operating system 160, and an application program 170.
 情報処理装置100は、最下層にキーボード131、デジタイザ143a、指紋読み取り部143bを有する。また、情報処理装置100は、キーボード131、デジタイザ143aの上層に組み込みコントローラ151を有する。また、情報処理装置100は、指紋読み取り部143bの上層に指紋認証部141を有する。 The information processing apparatus 100 includes a keyboard 131, a digitizer 143a, and a fingerprint reading unit 143b at the lowest layer. In addition, the information processing apparatus 100 includes an embedded controller 151 in the upper layer of the keyboard 131 and the digitizer 143a. In addition, the information processing apparatus 100 includes a fingerprint authentication unit 141 in the upper layer of the fingerprint reading unit 143b.
 指紋認証部141、組み込みコントローラ151の上層には、バス107を介してオペレーティングシステム160を有する。このオペレーティングシステム160の上層には、アプリケーションプログラム170を有する。 An operating system 160 is provided on the upper layer of the fingerprint authentication unit 141 and the embedded controller 151 via the bus 107. An application program 170 is provided in the upper layer of the operating system 160.
 指紋認証部141は、指紋認証制御部141a、認証情報記憶部141bを有する。指紋認証制御部141aと認証情報記憶部141bとは、同一のチップに搭載されている。また、指紋認証部141には、指紋読み取り部143bが接続されている。 The fingerprint authentication unit 141 includes a fingerprint authentication control unit 141a and an authentication information storage unit 141b. The fingerprint authentication control unit 141a and the authentication information storage unit 141b are mounted on the same chip. In addition, a fingerprint reading unit 143b is connected to the fingerprint authentication unit 141.
 指紋認証制御部141aは、指紋認証部141および指紋読み取り部143bによって取得された指紋情報と認証情報記憶部141bに記憶された指紋認証情報とを比較して指紋認証を行う。オペレーティングシステム160は、デジタイザ143aおよびデジタイザコントローラ151bによって入力された図形の筆跡に基づく識別情報(筆跡情報)と認証情報記憶部141bに記憶された識別認証情報とを比較して筆跡認証を行う。オペレーティングシステム160は、指紋認証と筆跡認証とに成功した場合に、ユーザを正当であると認証する。指紋認証制御部141aおよびオペレーティングシステム160は、認証制御部として機能する。 The fingerprint authentication control unit 141a performs fingerprint authentication by comparing the fingerprint information acquired by the fingerprint authentication unit 141 and the fingerprint reading unit 143b with the fingerprint authentication information stored in the authentication information storage unit 141b. The operating system 160 performs handwriting authentication by comparing the identification information (handwriting information) based on the handwriting of the graphic input by the digitizer 143a and the digitizer controller 151b with the identification authentication information stored in the authentication information storage unit 141b. The operating system 160 authenticates the user as valid when the fingerprint authentication and the handwriting authentication are successful. The fingerprint authentication control unit 141a and the operating system 160 function as an authentication control unit.
 指紋認証部141および指紋読み取り部143bは、ユーザの指の指紋を読み取る。この読み取られたユーザの指紋に基づいて、ユーザを認証するためにユーザの指紋から取得される情報である指紋情報が取得される。この指紋情報は、アプリケーションの実行等の上記の処理を実行するか否かを判定する指紋認証に用いるために取得される情報であって、正当なユーザの指の指紋の特徴を示す情報である。 The fingerprint authentication unit 141 and the fingerprint reading unit 143b read the fingerprint of the user's finger. Based on the read user fingerprint, fingerprint information, which is information acquired from the user fingerprint to authenticate the user, is acquired. This fingerprint information is information obtained for use in fingerprint authentication for determining whether or not to execute the above-described processing such as execution of an application, and is information indicating the characteristics of the fingerprint of a legitimate user's finger. .
 上記の正当なユーザ以外に実行が制限される処理を情報処理装置100に実行させようとするユーザは、正当であると認証されるために、そのユーザの予め登録された指の指紋を、情報処理装置100が有する指紋認証部141および指紋読み取り部143bに読み取らせる。指紋情報は、指紋読み取り部143bが指紋を読み取ることにより取得した情報から、指紋認証ライブラリ162dが指紋の特徴を抽出することによって生成される。これにより、ユーザの指紋情報が取得される。指紋認証部141、指紋読み取り部143b、指紋認証ライブラリ162dは、指紋情報取得部として機能する。 A user who intends to cause the information processing apparatus 100 to execute a process whose execution is restricted to other than the above-mentioned valid user is authenticated as the user's pre-registered finger fingerprint in order to be authenticated. The fingerprint authentication unit 141 and the fingerprint reading unit 143b included in the processing apparatus 100 are caused to read. The fingerprint information is generated by the fingerprint authentication library 162d extracting the characteristics of the fingerprint from the information acquired by the fingerprint reading unit 143b reading the fingerprint. Thereby, the fingerprint information of the user is acquired. The fingerprint authentication unit 141, the fingerprint reading unit 143b, and the fingerprint authentication library 162d function as a fingerprint information acquisition unit.
 認証情報記憶部141bは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、指紋情報と比較することによりユーザを認証するための指紋認証情報を記憶する。この指紋認証情報は、予め情報処理装置100が有する情報であって、正当なユーザの指紋を読み取って抽出した指紋の特徴を示す情報である。指紋認証情報は、ユーザ毎に設定されている。 The authentication information storage unit 141b is information set in advance for use in authenticating whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information. This fingerprint authentication information is information that the information processing apparatus 100 has in advance, and is information that indicates the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint. The fingerprint authentication information is set for each user.
 また、認証情報記憶部141bは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、識別情報と比較することによりユーザを認証する識別認証情報を記憶する。この識別認証情報は、予め情報処理装置100が有する情報であって、情報処理装置100を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。識別認証情報は、識別情報と比較可能な情報である。識別認証情報は、予め取得されたユーザの筆跡に基づく情報である。 Also, the authentication information storage unit 141b is information set in advance for use in authentication of whether or not the user is valid, and stores identification authentication information for authenticating the user by comparing with the identification information. This identification authentication information is information that the information processing apparatus 100 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 100 from other users and those who do not have a valid use authority other than the user. Information. The identification authentication information is information that can be compared with the identification information. The identification authentication information is information based on the user's handwriting acquired in advance.
 指紋認証は、指紋情報が示すユーザの指紋を読み取って抽出した特徴点と、予め設定された指紋認証情報が示す特徴点とを比較して行われる。筆跡認証も同様に、認証を受けるユーザが入力した図形の筆跡から抽出された識別情報が示す特徴点と、予め設定された筆跡から抽出された識別認証情報が示す特徴点とを比較して行われる。 Fingerprint authentication is performed by comparing a feature point extracted by reading a user's fingerprint indicated by fingerprint information with a feature point indicated by preset fingerprint authentication information. Similarly, the handwriting authentication is performed by comparing the feature point indicated by the identification information extracted from the handwriting of the graphic input by the user who is authenticated with the feature point indicated by the identification authentication information extracted from the preset handwriting. Is called.
 デジタイザ143aおよびデジタイザコントローラ151bは、ユーザにより入力された図形の筆跡の入力を受け付ける。この受け付けられた筆跡に基づいて、ユーザを認証するための情報であると共に指紋情報とは異なる情報である識別情報が取得される。この識別情報は、上記の処理の実行のために取得される情報であって、情報処理装置100を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。 The digitizer 143a and the digitizer controller 151b accept the input of the graphic handwriting input by the user. Based on the accepted handwriting, identification information that is information for authenticating the user and information different from the fingerprint information is acquired. This identification information is information acquired for the execution of the above processing, and identifies the ID of the user who uses the information processing apparatus 100 from other users and those who do not have a valid use authority other than the user. It is information that makes it possible.
 デジタイザ143aおよびデジタイザコントローラ151bは、ユーザによる筆跡の入力を受け付けてユーザの筆跡を取得する筆跡入力部として機能する。このデジタイザ143aおよびデジタイザコントローラ151bが取得した筆跡に基づいて、図形認識ドライバ161cがユーザの筆跡の特徴を抽出して識別情報を生成する。デジタイザ143a、デジタイザコントローラ151b、図形認識ドライバ161cは、識別情報取得部として機能する。 The digitizer 143a and the digitizer controller 151b function as a handwriting input unit that receives a handwriting input by the user and acquires the handwriting of the user. Based on the handwriting acquired by the digitizer 143a and the digitizer controller 151b, the graphic recognition driver 161c extracts the handwriting characteristics of the user and generates identification information. The digitizer 143a, the digitizer controller 151b, and the figure recognition driver 161c function as an identification information acquisition unit.
 また、デジタイザ143aは、LED143cと接続されている。LED143cは、デジタイザ143aの筆跡の読み取りの際、1ストローク読み取る毎に一定時間点灯する。これによりユーザは、筆跡認証の際、筆跡が読み取られたことを確認しながら図形を入力することができる。 The digitizer 143a is connected to the LED 143c. The LED 143c is lit for a certain time each time one stroke is read when reading the handwriting of the digitizer 143a. Thus, the user can input a figure while confirming that the handwriting has been read during handwriting authentication.
 組み込みコントローラ151は、情報処理装置100の電源管理等の機能を有すると共に、キーボードコントローラ151a、デジタイザコントローラ151b、I/O(Input/Output)コントローラ151cを有する。 The embedded controller 151 has functions such as power management for the information processing apparatus 100, and also includes a keyboard controller 151a, a digitizer controller 151b, and an I / O (Input / Output) controller 151c.
 キーボードコントローラ151aは、キーボード131に対するキーの押下操作およびリリース操作を定期的に監視して、操作に応じた情報を、バス107を介してオペレーティングシステム160に送信する。デジタイザコントローラ151bは、デジタイザ143aによって入力された情報を取得し、取得した情報を送信する。I/Oコントローラ151cは、ワンタッチ操作部142(図2において前述)等の操作に関する情報の送受信を行う。また、I/Oコントローラ151cは、指紋認証部141から送信された指紋認証に成功した旨を示す制御信号を受信する。 The keyboard controller 151 a periodically monitors key press operations and release operations on the keyboard 131 and transmits information corresponding to the operations to the operating system 160 via the bus 107. The digitizer controller 151b acquires the information input by the digitizer 143a and transmits the acquired information. The I / O controller 151c transmits and receives information related to operations of the one-touch operation unit 142 (described above in FIG. 2) and the like. In addition, the I / O controller 151c receives a control signal transmitted from the fingerprint authentication unit 141 and indicating that the fingerprint authentication is successful.
 組み込みコントローラ151とオペレーティングシステム160との間の通信、および指紋認証部141とオペレーティングシステム160との間の通信は、バス107を介して行われる。 Communication between the embedded controller 151 and the operating system 160 and communication between the fingerprint authentication unit 141 and the operating system 160 are performed via the bus 107.
 キーボードコントローラ151aから送信された情報は、バス107を介してオペレーティングシステム160が有するキーボードドライバ161aおよびキーボードライブラリ162aに送信される。デジタイザコントローラ151bから送信された情報は、バス107を介してオペレーティングシステム160が有するデジタイザドライバ161bおよびデジタイザライブラリ162bに送信される。 The information transmitted from the keyboard controller 151a is transmitted to the keyboard driver 161a and keyboard library 162a of the operating system 160 via the bus 107. Information transmitted from the digitizer controller 151b is transmitted to the digitizer driver 161b and the digitizer library 162b of the operating system 160 via the bus 107.
 オペレーティングシステム160は、情報処理装置100の各部分の機能を定義することにより情報処理装置100の全体を管理するソフトウェアである。オペレーティングシステム160は、キーボードドライバ161a、デジタイザドライバ161b、図形認識ドライバ161c、指紋認証ドライバ161d、キーボードライブラリ162a、デジタイザライブラリ162b、図形認識ライブラリ162c、指紋認証ライブラリ162dを有する。 The operating system 160 is software that manages the entire information processing apparatus 100 by defining functions of each part of the information processing apparatus 100. The operating system 160 includes a keyboard driver 161a, a digitizer driver 161b, a figure recognition driver 161c, a fingerprint authentication driver 161d, a keyboard library 162a, a digitizer library 162b, a figure recognition library 162c, and a fingerprint authentication library 162d.
 オペレーティングシステム160は、ユーザによる情報処理装置100の起動指示もしくはログインの受け付けの開始を指示するログイン指示、またはアプリケーションの起動を指示するアプリケーション起動指示もしくはアプリケーションの実行を指示するアプリケーション実行指示を受け付ける。オペレーティングシステム160は、制御部として機能する。 The operating system 160 receives a start instruction for the information processing apparatus 100 by the user or a login instruction for instructing start of acceptance of login, an application start instruction for instructing start of the application, or an application execution instruction for instructing execution of the application. The operating system 160 functions as a control unit.
 オペレーティングシステム160は、ユーザによるアプリケーションの起動指示等の指示を受け付けると、上記の指示に対応する処理が正当なユーザ以外のユーザに対して実行が制限される処理であるときには、受け付けた指示に基づいて指紋認証制御部141aに指紋認証を行わせると共に、オペレーティングシステム160が筆跡認証を行う。そして、指紋認証制御部141aによる指紋認証およびオペレーティングシステム160による筆跡認証によってユーザが正当であると認証された場合に、上記の指示に基づいて、アプリケーションの起動等、正当なユーザに許可された処理を実行する。 When the operating system 160 receives an instruction such as an application activation instruction from the user, if the process corresponding to the above instruction is a process whose execution is restricted to a user other than a valid user, the operating system 160 is based on the received instruction. The fingerprint authentication control unit 141a performs fingerprint authentication, and the operating system 160 performs handwriting authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 141a and the handwriting authentication by the operating system 160, the process permitted to the authorized user, such as starting an application, based on the above instruction Execute.
 オペレーティングシステム160は、指紋認証制御部141aによる指紋認証に成功した後、デジタイザ143aおよびデジタイザコントローラ151bにユーザの筆跡を取得させ、取得された筆跡に基づいて筆跡の特徴点を示す筆跡情報を生成し、筆跡認証を実行する。 After the fingerprint authentication control unit 141a succeeds in fingerprint authentication, the operating system 160 causes the digitizer 143a and the digitizer controller 151b to acquire the handwriting of the user, and generates handwriting information indicating the handwriting characteristic points based on the acquired handwriting. Execute handwriting authentication.
 アプリケーションプログラム170には、キーボード131によって入力された情報を取得するアプリケーション171a、デジタイザ143aによって入力された情報を取得し、取得した情報を処理するアプリケーション171b、情報処理装置100による認証に成功した場合に実行されるアプリケーション171cがある。 In the application program 170, when the application 171a that acquires the information input by the keyboard 131, the information that is input by the digitizer 143a is acquired, and the authentication is successfully performed by the information processing apparatus 100, the application 171b that processes the acquired information. There is an application 171c to be executed.
 本実施の形態では、指紋認証部141がユーザの指紋の認証に成功すると、指紋認証部141からデジタイザ143aが接続された組み込みコントローラ151に対して、I/Oコントローラ151cを介して筆跡入力の開始を指示する制御信号が送信される。これに基づいて、組み込みコントローラ151からデジタイザドライバ161bに制御信号が転送されることで、デジタイザドライバ161bがデジタイザ143aからの入力データの図形認識ドライバ161cに対する送信を開始する。 In this embodiment, when the fingerprint authentication unit 141 succeeds in authenticating the user's fingerprint, handwriting input is started via the I / O controller 151c from the fingerprint authentication unit 141 to the embedded controller 151 to which the digitizer 143a is connected. A control signal instructing is transmitted. Based on this, when the control signal is transferred from the embedded controller 151 to the digitizer driver 161b, the digitizer driver 161b starts transmitting input data from the digitizer 143a to the graphic recognition driver 161c.
 なお、これに限らず、指紋認証ドライバ161dからデジタイザドライバ161bに制御信号が送信され、デジタイザドライバ161bがこれに基づいてデジタイザ143aからの入力データの図形認識ドライバ161cに対する送信を開始してもよい。 Note that the present invention is not limited thereto, and a control signal may be transmitted from the fingerprint authentication driver 161d to the digitizer driver 161b, and the digitizer driver 161b may start transmitting input data from the digitizer 143a to the figure recognition driver 161c based on the control signal.
 また、本実施の形態の指紋認証情報は、同一のユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報と、複数の指の指紋について予め定められた順序を示す順序情報とを有してもよい。そして、この場合、指紋認証制御部141aが実行する指紋認証は、ユーザの指紋を複数回取得した指紋情報について、指紋読み取り部143bおよび指紋認証部141によって読み取られた指紋に基づく指紋情報が、指紋認証情報が有する指別指紋認証情報とすべて一致すると共に、指紋情報が取得された順序が、指紋認証情報が有する順序情報が示す順序と一致した場合に、成功したと判定されるようにすることができる。これにより、情報処理装置100において、ユーザの複数の指の指紋について認証が実行されると共に、認証の対象であるユーザが指紋を読み取らせた順序も認証の判定の対象になるため、セキュリティを向上させることができる。 The fingerprint authentication information according to the present embodiment includes finger-specific fingerprint authentication information set for a plurality of fingerprints of different fingers of the same user, and an order indicating a predetermined order for the fingerprints of the plurality of fingers. Information. In this case, the fingerprint authentication executed by the fingerprint authentication control unit 141a is the fingerprint information based on the fingerprint read by the fingerprint reading unit 143b and the fingerprint authentication unit 141 for the fingerprint information obtained by the user's fingerprint a plurality of times. When all the finger-fingerprint authentication information included in the authentication information matches and the order in which the fingerprint information is acquired matches the order indicated by the order information included in the fingerprint authentication information, it is determined that the authentication is successful. Can do. As a result, in the information processing apparatus 100, authentication is performed on the fingerprints of the plurality of fingers of the user, and the order in which the user who is the subject of authentication reads the fingerprints is also subject to authentication determination, thus improving security. Can be made.
 また、認証情報記憶部141bは、ユーザが入力する図形の筆跡の特徴を示した識別認証情報を複数記憶してもよい。そして、情報処理装置100が、識別認証情報とオペレーティングシステム160により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶する図示しないアプリケーション起動情報記憶部を有するようにしてもよい。さらに、オペレーティングシステム160は、筆跡認証の実行時において、いずれの識別認証情報によって識別認証が成功したかを判断するようにしてもよい。この場合、オペレーティングシステム160は、アプリケーション起動情報記憶部に記憶されているアプリケーション起動情報と指紋認証制御部141aおよびオペレーティングシステム160による判断の結果とに基づいて、起動するアプリケーションを決定し、決定したアプリケーションを起動するようにすることができる。これにより、情報処理装置100は、ユーザが入力した図形の筆跡の種類に基づいて、異なるアプリケーションを起動することができるので、ユーザは、入力する図形によって起動されるアプリケーションを選択することが可能になる。 Further, the authentication information storage unit 141b may store a plurality of pieces of identification authentication information indicating the characteristics of the handwriting of the graphic input by the user. The information processing apparatus 100 may include an application activation information storage unit (not shown) that stores application activation information that associates identification authentication information with an application activated by the operating system 160. Furthermore, the operating system 160 may determine which identification / authentication information has succeeded in identification / authentication when handwriting authentication is executed. In this case, the operating system 160 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 141a and the operating system 160, and the determined application Can be started. Accordingly, the information processing apparatus 100 can start different applications based on the type of handwriting of the graphic input by the user, so that the user can select the application started by the graphic to be input. Become.
 また、同一のユーザの異なる複数の指の指紋とオペレーティングシステム160により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶するアプリケーション起動情報記憶部を有してもよい。そして、指紋認証情報は、同一のユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報を有してもよい。そして、オペレーティングシステム160は、指紋認証の実行時において、ユーザのいずれの指の指紋によって指紋認証が成功したかを判断するようにしてもよい。この場合、オペレーティングシステム160は、アプリケーション起動情報記憶部に記憶されているアプリケーション起動情報と指紋認証制御部141aおよびオペレーティングシステム160による判断の結果とに基づいて、起動するアプリケーションを決定し、決定したアプリケーションを起動するようにすることができる。これにより、情報処理装置100は、ユーザが指紋を読み取らせた指に基づいて、異なるアプリケーションを起動することができるので、ユーザは、指紋を読み取らせる指によって起動されるアプリケーションを選択することが可能になる。 Also, an application activation information storage unit that stores application activation information that associates fingerprints of a plurality of different fingers of the same user with applications activated by the operating system 160 may be provided. The fingerprint authentication information may include finger-specific fingerprint authentication information set for each of a plurality of different fingerprints of the same user. Then, the operating system 160 may determine which fingerprint of the user has succeeded in fingerprint authentication when executing fingerprint authentication. In this case, the operating system 160 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 141a and the operating system 160, and the determined application Can be started. Accordingly, the information processing apparatus 100 can start different applications based on the finger that the user has read the fingerprint, so the user can select the application that is started by the finger that reads the fingerprint. become.
 また、本実施の形態では指紋認証を指紋認証制御部141aが行い、筆跡認証をオペレーティングシステム160が行うが、これに限らず、指紋認証制御部141aが指紋認証および筆跡認証を行ってもよい。 In this embodiment, the fingerprint authentication control unit 141a performs fingerprint authentication and the operating system 160 performs handwriting authentication. However, the present invention is not limited to this, and the fingerprint authentication control unit 141a may perform fingerprint authentication and handwriting authentication.
 通常、指紋認証と筆跡認証のように、異なる認証方式を組み合わせた場合、それぞれの認証装置で別個に処理を行う必要が生じるために、すべての認証処理が終了するまでに要する時間が長期化することになる。これに対して、本実施の形態では、同一の制御部が指紋認証および筆跡認証を実行することにより、複数種類の認証処理を実行しても、認証に要する時間を短縮可能である。 Normally, when different authentication methods are combined, such as fingerprint authentication and handwriting authentication, it is necessary to perform processing separately for each authentication device, so the time required to complete all authentication processing is prolonged. It will be. On the other hand, in the present embodiment, the same control unit executes fingerprint authentication and handwriting authentication, so that the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
 また、この場合において、指紋認証制御部141aと認証情報記憶部141bとを同一のチップに搭載してもよい。
 以上により、本実施の形態では、各アプリケーションにおけるそれぞれのドライバおよびライブラリのオープン/クローズおよびコールの処理を簡略化することができるため、処理の簡易化が可能になる。
In this case, the fingerprint authentication control unit 141a and the authentication information storage unit 141b may be mounted on the same chip.
As described above, according to the present embodiment, it is possible to simplify the processing of the open / close and call of each driver and library in each application, so that the processing can be simplified.
 次に、本実施の形態で実行される処理について説明する。
 図7および図8は、第1の実施の形態の認証処理の手順を示すフローチャートである。図7および図8に示す認証処理は、情報処理装置100(図2において前述)により実行される処理である。この認証処理は、情報処理装置100がユーザによるアプリケーションの起動指示を受け付けてアプリケーションを起動する際に実行される認証を行う処理であり、ユーザによるキーボード131(図2において前述)またはワンタッチ操作部142(図2において前述)の操作によるアプリケーション起動操作に基づいて実行が開始される。
Next, processing executed in the present embodiment will be described.
7 and 8 are flowcharts illustrating the authentication processing procedure according to the first embodiment. The authentication process shown in FIGS. 7 and 8 is a process executed by the information processing apparatus 100 (described above in FIG. 2). This authentication process is an authentication process executed when the information processing apparatus 100 receives an application activation instruction from the user and activates the application. The authentication process is performed by the user using the keyboard 131 (described above in FIG. 2) or the one-touch operation unit 142. Execution is started based on the application activation operation by the operation (described above in FIG. 2).
 [ステップS1]オペレーティングシステム160(図6において前述)は、指紋認証メッセージウインドウ121a(図15において後述)をLCD121(図2において前述)の表示画面に表示する。 [Step S1] The operating system 160 (described above in FIG. 6) displays a fingerprint authentication message window 121a (described later in FIG. 15) on the display screen of the LCD 121 (described above in FIG. 2).
 [ステップS2]組み込みコントローラ151(図6において前述)は、ユーザによるキーボード131を用いたユーザIDの入力を受け付ける。これに基づいて、キーボードコントローラ151a(図6において前述)は、受け付けたユーザIDをキーボードドライバ161aに送信する。また、このときキーボードコントローラ151aは、I/Oコントローラ151(図6において前述)を介して指紋認証部141(図5において前述)に対して受信したユーザIDを送信する。 [Step S2] The embedded controller 151 (described above with reference to FIG. 6) accepts an input of a user ID using the keyboard 131 by the user. Based on this, the keyboard controller 151a (described above in FIG. 6) transmits the received user ID to the keyboard driver 161a. At this time, the keyboard controller 151a transmits the received user ID to the fingerprint authentication unit 141 (described above in FIG. 5) via the I / O controller 151 (described above in FIG. 6).
 [ステップS3]指紋認証部141は、指紋読み取り部143b(図6において前述)によるユーザの指紋の読み取りを開始する。このとき指紋認証制御部141a(図5において前述)は、指紋の読み取りの結果得られる指紋情報を受信するまで、指紋読み取り部143bに対して指紋情報の送信を要求する。なお、指紋認証制御部141aは、一定時間指紋情報の送信がない場合には、指紋認証を中止する。 [Step S3] The fingerprint authentication unit 141 starts reading the fingerprint of the user by the fingerprint reading unit 143b (described above in FIG. 6). At this time, the fingerprint authentication control unit 141a (described above in FIG. 5) requests the fingerprint reading unit 143b to transmit fingerprint information until it receives fingerprint information obtained as a result of fingerprint reading. The fingerprint authentication control unit 141a stops fingerprint authentication when there is no transmission of fingerprint information for a certain period of time.
 [ステップS4]指紋認証制御部141aは、認証情報記憶部141b(図5において前述)からステップS2で送信されたユーザIDに対応する指紋認証情報を読み出して取得する。 [Step S4] The fingerprint authentication control unit 141a reads out and acquires the fingerprint authentication information corresponding to the user ID transmitted in step S2 from the authentication information storage unit 141b (described above in FIG. 5).
 [ステップS5]指紋認証制御部141aは、指紋読み取り部143bにより取得された指紋情報および認証情報記憶部141bから取得したユーザIDに対応する指紋情報を比較して認証を行い、認証に成功したか否かを判定する。認証に成功すれば、処理がステップS11(図8)に進められる。一方、認証に失敗すれば、処理がステップS17(図8)に進められる。 [Step S5] The fingerprint authentication control unit 141a performs authentication by comparing the fingerprint information acquired by the fingerprint reading unit 143b with the fingerprint information corresponding to the user ID acquired from the authentication information storage unit 141b. Determine whether or not. If the authentication is successful, the process proceeds to step S11 (FIG. 8). On the other hand, if the authentication fails, the process proceeds to step S17 (FIG. 8).
 [ステップS11]オペレーティングシステム160は、筆跡認証メッセージウインドウ121b(図16において後述)をLCD121の表示画面に表示する。
 [ステップS12]デジタイザコントローラ151b(図6において前述)は、デジタイザ143a(図6において前述)を制御してユーザによる筆跡の入力を受け付けて筆跡を取得する。このとき、デジタイザコントローラ151bは、筆跡のストローク数が、例えば、ユーザによって登録されたストローク数等の所定数に不足する場合には、ストローク数が所定数に達するまで取得を継続する。ここで、ストロークとは、筆跡の入力時において一回のペンダウンからペンアップまで、すなわち、ユーザがデジタイザ143aに指先を接触させてから指先を離すまでに書かれた筆跡とする。
[Step S11] The operating system 160 displays a handwriting authentication message window 121b (described later in FIG. 16) on the display screen of the LCD 121.
[Step S12] The digitizer controller 151b (described above in FIG. 6) controls the digitizer 143a (described above in FIG. 6) to accept the input of the handwriting by the user and acquire the handwriting. At this time, when the number of strokes of the handwriting is insufficient for a predetermined number such as the number of strokes registered by the user, the digitizer controller 151b continues to acquire until the number of strokes reaches the predetermined number. Here, the stroke is a handwriting written from a single pen-down to a pen-up at the time of handwriting input, that is, from when the user touches the digitizer 143a until the fingertip is released.
 [ステップS13]図形認識ドライバ161c(図6において前述)は、ユーザが入力した図形の筆跡の特徴を解析することにより、筆跡認証に用いる筆跡情報を取得する。このとき、図形認識ドライバ161cは、ユーザにより入力された図形の筆跡をストローク毎に分解し、分解したストロークの特徴を抽出することにより、筆跡情報を生成する。 [Step S13] The figure recognition driver 161c (described above in FIG. 6) obtains handwriting information used for handwriting authentication by analyzing the handwriting characteristics of the figure input by the user. At this time, the figure recognition driver 161c generates handwriting information by disassembling the handwriting of the figure input by the user for each stroke and extracting the features of the decomposed stroke.
 [ステップS14]図形認識ライブラリ162c(図6において前述)は、ユーザIDに対応する筆跡認証情報を取得する。この筆跡認証情報は、図形認識ライブラリ162cに含まれている情報であり、ユーザや管理者によって予め登録されている。 [Step S14] The graphic recognition library 162c (described above in FIG. 6) acquires handwriting authentication information corresponding to the user ID. This handwriting authentication information is information included in the figure recognition library 162c, and is registered in advance by a user or an administrator.
 [ステップS15]図形認識ライブラリ162cは、ステップS13で取得した筆跡情報およびステップS14で取得した筆跡認証情報を比較して筆跡認証を行い、筆跡認証の結果が成功であるか否かを判定する。筆跡認証の結果が成功であれば、処理がステップS16に進められる。一方、筆跡認証の結果が失敗であれば、処理がステップS17に進められる。 [Step S15] The graphic recognition library 162c performs handwriting authentication by comparing the handwriting information acquired in step S13 and the handwriting authentication information acquired in step S14, and determines whether or not the result of handwriting authentication is successful. If the result of handwriting authentication is successful, the process proceeds to step S16. On the other hand, if the result of handwriting authentication fails, the process proceeds to step S17.
 [ステップS16]オペレーティングシステム160は、ユーザによる起動指示の対象となっているアプリケーションを起動させる。その後、認証処理は終了する。
 [ステップS17]オペレーティングシステム160は、LCD121の表示画面に、ユーザによる起動指示の対象となっているアプリケーションの起動に関するエラー表示を行う。その後、認証処理は終了する。
[Step S16] The operating system 160 activates the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
[Step S <b> 17] The operating system 160 displays on the display screen of the LCD 121 an error related to the activation of the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
 なお、本実施の形態の認証処理は、情報処理装置100において、ユーザによるアプリケーションの起動指示が検出された場合に実行が開始されるが、これに限らず、例えば、図示しないログイン画面を表示させる操作(キーボード131のコントロールキー、Altキー、Deleteキーが同時に押下等)が行われた場合等の情報処理装置100に対するユーザのログイン時に実行が開始されてもよい。 The authentication process according to the present embodiment is started when the information processing apparatus 100 detects an application activation instruction by the user, but is not limited to this, and displays, for example, a login screen (not shown). Execution may be started when the user logs in to the information processing apparatus 100 such as when an operation is performed (such as pressing the control key, Alt key, and Delete key of the keyboard 131 simultaneously).
 また、本実施の形態では、ステップS5の指紋認証に失敗した場合およびステップS15の筆跡認証に失敗した場合、ステップS17でエラー表示を行うが、再度の指紋の読み取り、再度の筆跡の取得を試みてもよい。 In the present embodiment, if fingerprint authentication in step S5 fails or if handwriting authentication in step S15 fails, an error is displayed in step S17, but another attempt is made to read the fingerprint and acquire the handwriting again. May be.
 図9から図11は、第1の実施の形態の認証時の手順を示すシーケンス図である。
 ここで、図中の“ユーザインタフェース”は、ユーザが操作する入力装置および画面表示を行う出力装置である。具体的には、図6において前述したキーボード131、デジタイザ143a、指紋読み取り部143b、図2において前述したLCD121等である。
9 to 11 are sequence diagrams illustrating a procedure at the time of authentication according to the first embodiment.
Here, the “user interface” in the figure is an input device operated by a user and an output device that performs screen display. Specifically, the keyboard 131, the digitizer 143a, the fingerprint reading unit 143b described above in FIG. 6, the LCD 121 described above in FIG.
 また、図中の“指紋認証部”は、図6において前述した指紋認証部141である。前述のように、指紋認証部141は、指紋認証制御部141a、認証情報記憶部141bを有する。 Also, the “fingerprint authentication unit” in the figure is the fingerprint authentication unit 141 described above with reference to FIG. As described above, the fingerprint authentication unit 141 includes the fingerprint authentication control unit 141a and the authentication information storage unit 141b.
 また、図中の“コントローラ”は、キーボード131、ワンタッチ操作部142(図3において前述)、デジタイザ143a等の入力装置を制御する制御部であり、組み込みコントローラ151、キーボードコントローラ151a、デジタイザコントローラ151b、I/Oコントローラ151c等である。 A “controller” in the figure is a control unit that controls input devices such as a keyboard 131, a one-touch operation unit 142 (described above in FIG. 3), a digitizer 143a, and the like. The embedded controller 151, keyboard controller 151a, digitizer controller 151b, An I / O controller 151c or the like.
 また、図中の“オペレーティングシステム”は、図6において前述したオペレーティングシステム160ならびにオペレーティングシステム160が有する各ライブラリおよび各ドライバである。 In addition, “operating system” in the figure is the operating system 160 and the libraries and drivers included in the operating system 160 described above with reference to FIG.
 以下に、情報処理装置100における認証時の手順を図に従って説明する。
 [ステップS101]ワンタッチ操作部142のワンタッチボタン142aまたはキーボード131は、ユーザによるアプリケーションの起動操作を受け付ける。
Hereinafter, a procedure at the time of authentication in the information processing apparatus 100 will be described with reference to the drawings.
[Step S101] The one-touch button 142a or the keyboard 131 of the one-touch operation unit 142 accepts an application activation operation by the user.
 [ステップS102]キーボードコントローラ151aは、ステップS101におけるアプリケーションの起動操作を検出する。このユーザによるアプリケーションの起動操作の検出に基づいて、アプリケーションの起動指示に基づく信号が送信される。 [Step S102] The keyboard controller 151a detects the activation operation of the application in step S101. Based on the detection of the application activation operation by the user, a signal based on the application activation instruction is transmitted.
 [ステップS103]オペレーティングシステム160は、指紋認証を開始する際の処理を実行させる。具体的には、後述するように、指紋認証ドライバ161dに対して指紋認証部141を起動させる。また、グラフィック処理装置104に対して指紋認証メッセージウインドウ121a(図15において後述)を表示させる。 [Step S103] The operating system 160 executes processing for starting fingerprint authentication. Specifically, as will be described later, the fingerprint authentication unit 141 is activated by the fingerprint authentication driver 161d. Also, a fingerprint authentication message window 121a (described later in FIG. 15) is displayed on the graphic processing device 104.
 [ステップS104]グラフィック処理装置104は、LCD121に指紋認証メッセージウインドウ121aを表示させる。
 [ステップS105]キーボード131は、ユーザによるユーザIDの入力を受け付ける。
[Step S104] The graphic processing device 104 causes the LCD 121 to display a fingerprint authentication message window 121a.
[Step S105] The keyboard 131 receives an input of a user ID by the user.
 [ステップS106]キーボードコントローラ151aは、ステップS105におけるユーザIDの入力操作を検出する。このユーザによるユーザIDの入力操作の検出に基づいて、ユーザIDが取得され、指紋認証部141および図形認識ドライバ161cに対して取得されたユーザIDを示す情報が送信される。 [Step S106] The keyboard controller 151a detects the user ID input operation in step S105. Based on the detection of the user ID input operation by the user, the user ID is acquired, and information indicating the acquired user ID is transmitted to the fingerprint authentication unit 141 and the figure recognition driver 161c.
 [ステップS107]指紋認証制御部141aは、指紋読み取り部143bを起動する。これにより、ユーザの指紋の読み取りが可能な状態になる。
 [ステップS108]指紋読み取り部143bは、ユーザの指紋の読み取りを行い、指紋情報を取得する。取得された指紋情報は、指紋認証制御部141aに送信される。
[Step S107] The fingerprint authentication control unit 141a activates the fingerprint reading unit 143b. As a result, the user's fingerprint can be read.
[Step S108] The fingerprint reading unit 143b reads the fingerprint of the user and acquires fingerprint information. The acquired fingerprint information is transmitted to the fingerprint authentication control unit 141a.
 [ステップS121]指紋認証制御部141aは、認証情報記憶部141bから、ステップS106で送信されたユーザIDに対応する指紋認証情報を読み出す。次に、指紋認証制御部141aは、ステップS108において指紋読み取り部143bによって読み取られた指紋の指紋情報および認証情報記憶部141bから読み出した指紋認証情報を比較して照合し、ユーザの指紋の認証を行う。これにより、指紋に基づいてアプリケーションを起動しようとするユーザの正当性が判定される。 [Step S121] The fingerprint authentication control unit 141a reads the fingerprint authentication information corresponding to the user ID transmitted in step S106 from the authentication information storage unit 141b. Next, the fingerprint authentication control unit 141a compares the fingerprint information of the fingerprint read by the fingerprint reading unit 143b in step S108 with the fingerprint authentication information read from the authentication information storage unit 141b and collates them to authenticate the user's fingerprint. Do. Thereby, the legitimacy of the user who tries to start the application is determined based on the fingerprint.
 [ステップS122]指紋認証制御部141aは、指紋の認証の照合結果である指紋認証照合結果を指紋認証ドライバ161dに送信する。
 [ステップS123]指紋認証制御部141aから送信された指紋認証照合結果を受信した指紋認証ドライバ161dは、指紋認証ライブラリ162dに指紋認証照合結果を送信する。さらに、指紋認証ドライバ161dから送信された指紋認証照合結果を受信した指紋認証ライブラリ162dは、指紋認証照合結果に基づいて、ステップS121において指紋認証制御部141aにより行われたユーザの指紋認証が成功したか否かを判定する。さらに、指紋認証ライブラリ162dは、指紋認証の判定結果を図形認識ライブラリ162cに送信する。
[Step S122] The fingerprint authentication control unit 141a transmits a fingerprint authentication verification result, which is a verification result of fingerprint authentication, to the fingerprint authentication driver 161d.
[Step S123] The fingerprint authentication driver 161d that has received the fingerprint authentication verification result transmitted from the fingerprint authentication control unit 141a transmits the fingerprint authentication verification result to the fingerprint authentication library 162d. Furthermore, the fingerprint authentication library 162d that has received the fingerprint authentication collation result transmitted from the fingerprint authentication driver 161d has succeeded in the fingerprint authentication of the user performed by the fingerprint authentication control unit 141a in step S121 based on the fingerprint authentication collation result. It is determined whether or not. Furthermore, the fingerprint authentication library 162d transmits the fingerprint authentication determination result to the figure recognition library 162c.
 [ステップS124]受信した指紋認証の判定結果が認証成功であれば、オペレーティングシステム160は、筆跡認証を開始する際の処理を実行させる。具体的には、図形認識ライブラリ162cは、後述するように、デジタイザコントローラ151bに対してデジタイザ143aを起動させる。また、図形認識ライブラリ162cは、グラフィック処理装置104に対して指紋認証メッセージウインドウ121aの表示を終了させ、筆跡認証メッセージウインドウ121b(図16において後述)を表示させる。また、図形認識ライブラリ162cは、図形認識ドライバ161cを起動させる。 [Step S124] If the received determination result of the fingerprint authentication is successful, the operating system 160 executes processing for starting handwriting authentication. Specifically, as will be described later, the figure recognition library 162c causes the digitizer controller 151b to activate the digitizer 143a. Further, the graphic recognition library 162c ends the display of the fingerprint authentication message window 121a on the graphic processing device 104, and displays the handwriting authentication message window 121b (described later in FIG. 16). The graphic recognition library 162c activates the graphic recognition driver 161c.
 なお、指紋認証の判定結果が認証失敗であれば、オペレーティングシステム160は、指紋認証メッセージウインドウ121aの表示を終了させると共に、図8において前述したように、LCD121の表示画面にエラー表示を表示させ、認証処理を終了させる。 If the determination result of the fingerprint authentication is an authentication failure, the operating system 160 ends the display of the fingerprint authentication message window 121a and displays an error display on the display screen of the LCD 121 as described above with reference to FIG. End the authentication process.
 [ステップS125]グラフィック処理装置104は、LCD121の表示画面に表示された、指紋認証メッセージウインドウ121aの表示を終了させる。
 [ステップS126]グラフィック処理装置104は、LCD121の表示画面に、筆跡認証メッセージウインドウ121bを表示させる。
[Step S125] The graphic processing device 104 ends the display of the fingerprint authentication message window 121a displayed on the display screen of the LCD 121.
[Step S126] The graphic processing device 104 displays a handwriting authentication message window 121b on the display screen of the LCD 121.
 [ステップS127]デジタイザコントローラ151bは、ステップS124における図形認識ライブラリ162cの制御に基づいて起動すると共に、デジタイザ143aを図形認識モードで起動させる。この図形認識モードにより、デジタイザ143aを用いたユーザの筆跡の取得が可能になる。 [Step S127] The digitizer controller 151b is activated based on the control of the graphic recognition library 162c in step S124, and activates the digitizer 143a in the graphic recognition mode. With this figure recognition mode, the user's handwriting using the digitizer 143a can be acquired.
 [ステップS128]デジタイザ143aは、ユーザが入力した筆跡の読み取りを行い、筆跡を示す情報を取得する。取得された筆跡を示す情報は、デジタイザコントローラ151bに送信される。筆跡を示す情報を受信したデジタイザコントローラ151bは、筆跡を示す情報をデジタイザドライバ161bに送信する。筆跡を示す情報を受信したデジタイザドライバ161bは、筆跡を示す情報を図形認識ドライバ161cに送信する。さらに、筆跡を示す情報を受信した図形認識ドライバ161cは、筆跡を示す情報を処理して筆跡の特徴を示す筆跡情報を生成し、生成した筆跡情報を図形認識ライブラリ162cに送信する。 [Step S128] The digitizer 143a reads the handwriting input by the user and acquires information indicating the handwriting. Information indicating the acquired handwriting is transmitted to the digitizer controller 151b. The digitizer controller 151b that has received the information indicating the handwriting transmits the information indicating the handwriting to the digitizer driver 161b. The digitizer driver 161b that has received the information indicating the handwriting transmits the information indicating the handwriting to the graphic recognition driver 161c. Further, the graphic recognition driver 161c that has received the information indicating the handwriting processes the information indicating the handwriting to generate the handwriting information indicating the characteristics of the handwriting, and transmits the generated handwriting information to the graphic recognition library 162c.
 [ステップS141]図形認識ライブラリ162cは、自己が有する筆跡認証情報のうち、ステップS106で送信されたユーザIDに対応する筆跡認証情報を読み出す。次に、図形認識ライブラリ162cは、ステップS128において送信された筆跡情報および読み出した筆跡認証情報を比較して照合し、ユーザの筆跡の認証を行う。これにより、筆跡に基づいてアプリケーションを起動しようとするユーザの正当性が判定される。 [Step S141] The graphic recognition library 162c reads the handwriting authentication information corresponding to the user ID transmitted in Step S106 among the handwriting authentication information held by itself. Next, the graphic recognition library 162c compares and compares the handwriting information transmitted in step S128 with the read handwriting authentication information, and authenticates the user's handwriting. Thereby, the legitimacy of the user who intends to start an application based on handwriting is determined.
 [ステップS142]図形認証ライブラリ162cは、筆跡認証照合結果に基づいて、ステップS141におけるユーザの筆跡認証が成功したか否かを判定する。
 [ステップS143]筆跡認証の判定結果が成功であれば、オペレーティングシステム160は、ユーザの認証に成功した際の表示制御を行う。具体的には、図形認識ライブラリ162cは、グラフィック処理装置104に対して筆跡認証メッセージウインドウ121bの表示を終了させる。
[Step S142] The graphic authentication library 162c determines whether or not the user's handwriting authentication in Step S141 is successful based on the handwriting authentication collation result.
[Step S143] If the determination result of the handwriting authentication is successful, the operating system 160 performs display control when the user authentication is successful. Specifically, the graphic recognition library 162c ends the display of the handwriting authentication message window 121b for the graphic processing device 104.
 なお、筆跡認証の判定結果が認証失敗であれば、オペレーティングシステム160は、筆跡認証メッセージウインドウ121bの表示を終了させると共に、図8において前述したように、LCD121の表示画面にエラー表示を表示させ、認証処理を終了させる。 If the determination result of the handwriting authentication is an authentication failure, the operating system 160 ends the display of the handwriting authentication message window 121b and displays an error display on the display screen of the LCD 121 as described above with reference to FIG. End the authentication process.
 [ステップS144]グラフィック処理装置104は、LCD121の表示画面に表示された、筆跡認証メッセージウインドウ121bの表示を終了させる。
 [ステップS145]図形認識ライブラリ162cは、ユーザのアプリケーションの起動操作の対象であるアプリケーションを起動させる。
[Step S144] The graphic processing device 104 ends the display of the handwriting authentication message window 121b displayed on the display screen of the LCD 121.
[Step S145] The graphic recognition library 162c activates the application that is the target of the user's application activation operation.
 次に、本実施の形態で行われる筆跡認証の判定について説明する。
 図12は、第1の実施の形態の筆跡認証の判定における入力された図形の筆跡への分解を示す図である。図12(A)は、筆跡認証において入力された図形(文字)を示す図である。図12(B)は、筆跡認証において入力された図形のストロークへの分解を示す図である。
Next, the handwriting authentication determination performed in the present embodiment will be described.
FIG. 12 is a diagram illustrating decomposition of an input figure into handwriting in the determination of handwriting authentication according to the first embodiment. FIG. 12A shows a figure (character) input in handwriting authentication. FIG. 12B is a diagram illustrating decomposition of a figure input in handwriting authentication into strokes.
 本実施の形態の筆跡認証では、認証時に入力する図形や文字の筆跡を事前に登録しておく。そして、アプリケーション起動時やログイン時等の認証が行われる際に、ユーザがデジタイザ143a等を用いて登録した図形や文字の筆跡を入力し、事前に登録された筆跡と比較することにより認証が行われる。 In the handwriting authentication according to the present embodiment, the handwriting of figures and characters input at the time of authentication is registered in advance. When authentication is performed at the time of application startup or login, authentication is performed by inputting a handwriting of a figure or a character registered by the user using the digitizer 143a and the like and comparing it with a handwriting registered in advance. Is called.
 図12(A)は、ユーザが情報処理装置100にアプリケーションを起動させるためにデジタイザ143a(図4において前述)で入力した図形の例として、漢字の文字である「水」を示す。この図形に基づいて生成される筆跡情報が、情報処理装置100に記憶されている筆跡認証情報と比較されることによりユーザの認証が行われる。 FIG. 12A shows “Water”, which is a Chinese character, as an example of a figure input by the user with the digitizer 143a (described above in FIG. 4) in order to cause the information processing apparatus 100 to start an application. The handwriting information generated based on the graphic is compared with the handwriting authentication information stored in the information processing apparatus 100 to authenticate the user.
 図12(B)は、図12(A)に示したユーザによって入力された図形をストローク毎に分解した例を示す。
 ユーザによって入力された図形は、デジタイザ143aに指が接触した点を始点とし、デジタイザ143aから指が離れた点(ペンアップ)を終点とすることにより、ストローク毎に分解される。図12(B)の例では、1,2,3の3個のストロークに分解される。
FIG. 12B shows an example in which the figure input by the user shown in FIG.
The figure input by the user is decomposed for each stroke, with the point at which the finger touches the digitizer 143a as the start point and the point at which the finger has moved away from the digitizer 143a (pen up) as the end point. In the example of FIG. 12B, it is decomposed into three strokes 1, 2, and 3.
 図13は、第1の実施の形態の筆跡認証の判定における筆跡のベクトルへの分解を示す図である。図13(A)は、筆跡認証において各筆跡の一定時間毎の分解を示す図である。図13(B)は、筆跡認証において一定時間に分解されて入力された図形の筆跡(ストローク)への分解を示す図である。 FIG. 13 is a diagram illustrating decomposition of handwriting into vectors in the determination of handwriting authentication according to the first embodiment. FIG. 13A is a diagram illustrating disassembly of each handwriting at regular intervals in handwriting authentication. FIG. 13B is a diagram illustrating decomposition of a figure that is input after being decomposed and input in a certain time in handwriting authentication into strokes (strokes).
 図13(A)は、図12(B)に示した図形を分解して得られた各ストロークについて、筆跡を取得した際の時間情報に基づいて、一定時間毎に区分した例を示す。
 図13(A)では、各ストロークをさらに一定時間毎に区分する点について円を用いて示す。各円の中心が、ストロークを区分する点を示す。このようにして、ストロークが一定時間毎に区分される。
FIG. 13A shows an example in which each stroke obtained by disassembling the graphic shown in FIG. 12B is divided at regular intervals based on time information when handwriting is acquired.
In FIG. 13 (A), the points that divide the strokes at regular time intervals are indicated by circles. The center of each circle indicates the point that divides the stroke. In this way, the stroke is divided at regular intervals.
 図13(B)は、図13(A)に示したストロークが区分された部分について、各区分した点(円の中心)を始点および終点とするベクトルによって示す。
 このベクトルにより、ユーザが図形を入力した際、筆跡の各部分を入力した時の、一定時間内における指先の移動速度(移動の速さおよび移動の向き)が示される。
FIG. 13B shows, with respect to the portion where the stroke shown in FIG. 13A is divided, a vector having each divided point (the center of the circle) as a start point and an end point.
This vector indicates the movement speed (movement speed and movement direction) of the fingertip within a certain time when each part of the handwriting is input when the user inputs a figure.
 図14は、第1の実施の形態の筆跡認証の判定におけるベクトルを区分した各部分のベクトルを示す図である。
 図14は、図13(B)に示したユーザにより入力された図形の各ストロークを一定時間毎に区分して得られたベクトルをストローク毎に並べて示す。
FIG. 14 is a diagram illustrating a vector of each part obtained by dividing a vector in determination of handwriting authentication according to the first embodiment.
FIG. 14 shows the vectors obtained by dividing the strokes of the graphic input by the user shown in FIG. 13B at regular intervals, arranged for each stroke.
 この各ストロークから得られたベクトルは、特に、ユーザによって入力された図形の形状の特徴を表していると考えられる。これにより、このベクトルを用いて、ユーザが入力した図形により、ユーザの正当性を判定することができる。 It is considered that the vector obtained from each stroke particularly represents the feature of the shape of the figure input by the user. Thereby, the legitimacy of the user can be determined from the graphic input by the user using this vector.
 また、このベクトルは、ストロークの各部分が入力された時の座標の移動速度の特徴を表していると考えられる。これにより、このベクトルを用いて、ユーザが図形を入力した時の座標の移動速度から、ユーザの座標の移動の特徴に基づいて、ユーザの正当性を判定することができる。 Also, this vector is considered to represent the characteristics of the moving speed of coordinates when each part of the stroke is input. Thereby, using this vector, the legitimacy of the user can be determined based on the feature of the movement of the user's coordinates from the movement speed of the coordinates when the user inputs the figure.
 本実施の形態では、以上のようにして取得された各ベクトルの大きさおよび向きを示す情報を有する筆跡情報を生成し、生成した筆跡情報を用いて筆跡認証を行う。さらに、認証の比較対象であるユーザIDに対応する予め取得された筆跡認証情報も、同様にして取得された、図形の入力時のユーザの筆跡、ユーザの筆跡を分解して得られたストロークおよびユーザの筆跡から取得されたベクトルを示す情報を有する情報である。 In the present embodiment, handwriting information having information indicating the size and direction of each vector acquired as described above is generated, and handwriting authentication is performed using the generated handwriting information. Furthermore, the handwriting authentication information acquired in advance corresponding to the user ID to be compared with the authentication is also acquired in the same manner, the user's handwriting at the time of inputting the figure, the stroke obtained by disassembling the user's handwriting, and It is information which has the information which shows the vector acquired from the user's handwriting.
 本実施の形態では、筆跡認証の基準として、以下を用いる。
 1.入力された図形および比較対象として予め登録された図形の筆跡のストローク数が同じであること
 2.対応する各ストローク同士の移動量(ストロークの始点から終点までの道のり)の差が一定の範囲内に収まること
 3.各ストロークの対応するベクトル同士の向きと長さの差が一定の範囲内に収まること
 例えば、以上の1,2,3をすべて満たす場合、またはすべての項目を評価値に換算し、評価値が一定基準を満たす場合に筆跡認証に成功したものとし、それ以外の場合を筆跡認証に失敗したものとすることができる。
In the present embodiment, the following is used as a standard for handwriting authentication.
1. 1. The stroke number of the handwriting of the inputted figure and the figure registered in advance as a comparison target is the same. 2. The difference in the amount of movement between the corresponding strokes (the distance from the start point to the end point of the stroke) is within a certain range. The difference between the direction and length of the vectors corresponding to each stroke must be within a certain range. For example, when all of the above 1, 2, and 3 are satisfied, or all items are converted into evaluation values. It can be assumed that handwriting authentication has succeeded when a certain standard is satisfied, and handwriting authentication has failed otherwise.
 本実施の形態の筆跡認証では、以上のようにして図形を分解して得られたベクトルの大きさおよび向きを総合して評価することにより、ユーザの認証を行う。なお、以上の筆跡認証の手法は一例であり、他の手法により筆跡認証を行ってもよい。 In the handwriting authentication of the present embodiment, the user is authenticated by comprehensively evaluating the size and direction of the vector obtained by disassembling the figure as described above. The handwriting authentication method described above is an example, and handwriting authentication may be performed by other methods.
 次に、本実施の形態で表示される表示画面について説明する。
 図15は、第1の実施の形態の指紋認証メッセージウインドウを示す図である。図15に示す指紋認証メッセージウインドウ121aは、情報処理装置100(図2において前述)が有するLCD121の表示画面に表示されるウインドウの一例である。指紋認証メッセージウインドウ121aには、ユーザにユーザIDの入力および指紋の読み取りを案内するメッセージおよび画像が表示される。
Next, a display screen displayed in the present embodiment will be described.
FIG. 15 is a diagram illustrating a fingerprint authentication message window according to the first embodiment. A fingerprint authentication message window 121a shown in FIG. 15 is an example of a window displayed on the display screen of the LCD 121 included in the information processing apparatus 100 (described above in FIG. 2). In the fingerprint authentication message window 121a, a message and an image for guiding the user to input the user ID and read the fingerprint are displayed.
 指紋認証メッセージウインドウ121aには、例えば、「ユーザIDを入力し、指をセンサに当ててスライドさせてください」というメッセージおよびユーザIDの入力および指紋の読み取りを案内する画像が表示される。また、指紋認証メッセージウインドウ121aは、ユーザID入力欄121a1、キャンセルボタン121a2を有する。 In the fingerprint authentication message window 121a, for example, a message “Enter your user ID and slide your finger against the sensor” and an image that guides the user ID input and fingerprint reading are displayed. The fingerprint authentication message window 121a has a user ID input field 121a1 and a cancel button 121a2.
 ユーザID入力欄121a1は、ユーザIDの入力を受け付ける入力欄である。ユーザは、このユーザID入力欄121a1に、キーボード131等の入力装置で文字を入力することにより、ユーザIDを入力することができる。 The user ID input field 121a1 is an input field for accepting input of a user ID. The user can input a user ID in the user ID input field 121a1 by inputting characters using an input device such as the keyboard 131.
 キャンセルボタン121a2は、ユーザIDの入力をキャンセルするボタンである。ユーザは、キャンセルボタン121a2を操作することにより、ユーザIDの入力をキャンセルすると共に指紋認証を行わず、アプリケーションの起動を中止することができる。 The cancel button 121a2 is a button for canceling the input of the user ID. By operating the cancel button 121a2, the user can cancel the input of the user ID and cancel the activation of the application without performing fingerprint authentication.
 図16は、第1の実施の形態の筆跡認証メッセージウインドウを示す図である。図16に示す筆跡認証メッセージウインドウ121bは、情報処理装置100(図2において前述)が有するLCD121の表示画面に表示されるウインドウの一例である。筆跡認証メッセージウインドウ121bには、ユーザにデジタイザ143a(図2において前述)を用いた図形の入力を案内するメッセージおよび画像が表示される。 FIG. 16 is a diagram illustrating a handwriting authentication message window according to the first embodiment. A handwriting authentication message window 121b illustrated in FIG. 16 is an example of a window displayed on the display screen of the LCD 121 included in the information processing apparatus 100 (described above in FIG. 2). In the handwriting authentication message window 121b, a message and an image for guiding the user to input a figure using the digitizer 143a (described above in FIG. 2) are displayed.
 指紋認証メッセージウインドウ121aには、例えば、「指をデジタイザに当てて動かし図形を入力してください」というメッセージおよびユーザによる図形の入力を案内する画像が表示される。また、筆跡認証メッセージウインドウ121bは、キャンセルボタン121b2を有する。 In the fingerprint authentication message window 121a, for example, a message “Please move your finger against the digitizer and input a graphic” and an image for guiding the user to input the graphic are displayed. The handwriting authentication message window 121b has a cancel button 121b2.
 キャンセルボタン121b2は、図形の入力をキャンセルするボタンである。ユーザは、キャンセルボタン121b2を操作することにより、図形の入力をキャンセルすると共に、アプリケーションの起動を中止することができる。 The cancel button 121b2 is a button for canceling the figure input. By operating the cancel button 121b2, the user can cancel the input of the figure and can stop the activation of the application.
 図17は、第1の実施の形態のアプリケーションウインドウを示す図である。図17に示すアプリケーションウインドウ121cは、情報処理装置100(図2において前述)が有するLCD121の表示画面に表示されるウインドウの一例である。アプリケーションウインドウ121cは、ユーザの起動操作の対象であるアプリケーションに関する画面である。 FIG. 17 is a diagram illustrating an application window according to the first embodiment. An application window 121c illustrated in FIG. 17 is an example of a window displayed on the display screen of the LCD 121 included in the information processing apparatus 100 (described above in FIG. 2). The application window 121c is a screen related to the application that is the target of the user's activation operation.
 アプリケーションウインドウ121cは、例えば、データベースシステムの検索条件を入力する画面等の、アプリケーションの動作に関する画面である。アプリケーションウインドウ121cは、ユーザの認証に成功した場合に表示される。一方、ユーザの認証に失敗した場合には、アプリケーションが起動されず、アプリケーションウインドウ121cも表示されない。 The application window 121c is a screen related to the operation of the application, such as a screen for inputting search conditions for the database system. The application window 121c is displayed when the user authentication is successful. On the other hand, if the user authentication fails, the application is not started and the application window 121c is not displayed.
 このように、情報処理装置100により、個人情報や営業秘密が含まれるために保護する必要のあるデータベースシステム、メールシステム等の正当なユーザ以外の起動を禁止することにより、保護すべき情報の盗用、漏えい、破壊等を防止することができる。 In this way, the information processing apparatus 100 steals information to be protected by prohibiting activation of other than authorized users such as database systems and mail systems that need to be protected because personal information and trade secrets are included. Leakage, destruction, etc. can be prevented.
 以上のように、第1の実施の形態によれば、情報処理装置100において、指紋認証および筆跡認証を行うことにより、ユーザ認証の精度が高まるのでセキュリティが向上する。 As described above, according to the first embodiment, by performing fingerprint authentication and handwriting authentication in the information processing apparatus 100, the accuracy of user authentication is increased, so that security is improved.
 また、指紋認証を、ワンチップICで構成された指紋認証部141で行うことにより、指紋認証の処理が外部から隠ぺいされるので、クラックを防止することができ、安全性が高まる。 In addition, by performing fingerprint authentication with the fingerprint authentication unit 141 configured with a one-chip IC, the fingerprint authentication process is concealed from the outside, so that cracks can be prevented and safety is improved.
 [第2の実施の形態]
 次に、第2の実施の形態について説明する。上記の第1の実施の形態との相違点を中心に説明し、同様の事項については同一の符号を用いると共に説明を省略する。
[Second Embodiment]
Next, a second embodiment will be described. Differences from the first embodiment will be mainly described, and the same reference numerals are used for the same matters, and descriptions thereof are omitted.
 第2の実施の形態は、ユーザによるワンタッチボタンの操作によりユーザを識別すると共に、識別したユーザに対応した指紋認証情報を用いてユーザの指紋認証を行う点で、第1の実施の形態と異なる。 The second embodiment is different from the first embodiment in that the user is identified by the user's one-touch button operation and the user's fingerprint authentication is performed using the fingerprint authentication information corresponding to the identified user. .
 図18は、第2の実施の形態の情報処理装置の構成を示すブロック図である。図18に示す情報処理装置200は、指紋認証部241、組み込みコントローラ251、オペレーティングシステム260、アプリケーションプログラム270を有する。 FIG. 18 is a block diagram illustrating a configuration of the information processing apparatus according to the second embodiment. An information processing apparatus 200 illustrated in FIG. 18 includes a fingerprint authentication unit 241, an embedded controller 251, an operating system 260, and an application program 270.
 情報処理装置200は、最下層にキーボード231、ワンタッチ操作部242、指紋読み取り部243bを有する。また、情報処理装置200は、キーボード231、ワンタッチ操作部242の上層に組み込みコントローラ251を有する。また、情報処理装置200は、指紋読み取り部243bの上層に指紋認証部241を有する。 The information processing apparatus 200 includes a keyboard 231, a one-touch operation unit 242, and a fingerprint reading unit 243 b at the lowest layer. In addition, the information processing apparatus 200 includes an embedded controller 251 in the upper layer of the keyboard 231 and the one-touch operation unit 242. In addition, the information processing apparatus 200 includes a fingerprint authentication unit 241 in the upper layer of the fingerprint reading unit 243b.
 指紋認証部241、組み込みコントローラ251の上層には、バス207を介してオペレーティングシステム260を有する。このオペレーティングシステム260の上層には、アプリケーションプログラム270を有する。 The operating system 260 is provided on the upper layer of the fingerprint authentication unit 241 and the embedded controller 251 via the bus 207. An application program 270 is provided in the upper layer of the operating system 260.
 指紋認証部241は、指紋認証制御部241a、認証情報記憶部241bを有する。指紋認証制御部241aと認証情報記憶部241bとは、同一のチップに搭載されている。また、指紋認証部241には、指紋読み取り部243bが接続されている。 The fingerprint authentication unit 241 includes a fingerprint authentication control unit 241a and an authentication information storage unit 241b. The fingerprint authentication control unit 241a and the authentication information storage unit 241b are mounted on the same chip. In addition, a fingerprint reading unit 243 b is connected to the fingerprint authentication unit 241.
 指紋認証制御部241aは、指紋認証部241および指紋読み取り部243bによって取得された指紋情報と認証情報記憶部241bに記憶された指紋認証情報とを比較して指紋認証を行う。ワンタッチ操作部242および組み込みコントローラ251は、ワンタッチ操作部242が有するワンタッチボタン(図3において前述したワンタッチボタン142a参照)の操作に基づくキーコードを識別情報とする。そして、I/Oコントローラ251cは、指紋認証部241にキーコードを送信する。キーコードを受信した指紋認証部241は、受信したキーコードと認証情報記憶部241bに記憶された識別認証情報とを比較してワンタッチボタン認証を行う。オペレーティングシステム260は、ワンタッチボタン認証により取得した指紋認証情報に基づく指紋認証に成功した場合に、ユーザを正当であると認証する。すなわち、指紋認証制御部241aおよびオペレーティングシステム260は、ワンタッチボタンの操作を受け付け、操作されたワンタッチボタンに対応する指紋認証情報を用いて指紋認証を実行する。指紋認証制御部241aおよびオペレーティングシステム260は、認証制御部として機能する。 The fingerprint authentication control unit 241a performs fingerprint authentication by comparing the fingerprint information acquired by the fingerprint authentication unit 241 and the fingerprint reading unit 243b with the fingerprint authentication information stored in the authentication information storage unit 241b. The one-touch operation unit 242 and the embedded controller 251 use, as identification information, a key code based on an operation of a one-touch button (see the one-touch button 142a described above in FIG. 3) included in the one-touch operation unit 242. Then, the I / O controller 251c transmits a key code to the fingerprint authentication unit 241. The fingerprint authentication unit 241 that has received the key code performs one-touch button authentication by comparing the received key code with the identification authentication information stored in the authentication information storage unit 241b. The operating system 260 authenticates the user as valid when the fingerprint authentication based on the fingerprint authentication information obtained by the one-touch button authentication is successful. That is, the fingerprint authentication control unit 241a and the operating system 260 accept the operation of the one-touch button and execute fingerprint authentication using the fingerprint authentication information corresponding to the operated one-touch button. The fingerprint authentication control unit 241a and the operating system 260 function as an authentication control unit.
 指紋認証部241および指紋読み取り部243bは、ユーザの指の指紋を読み取る。この読み取られたユーザの指紋に基づいて、ユーザを認証するためにユーザの指紋から取得される情報である指紋情報が取得される。この指紋情報は、アプリケーションの実行等の上記の処理を実行するか否かを判定する指紋認証に用いるために取得される情報であって、正当なユーザの指の指紋の特徴を示す情報である。 The fingerprint authentication unit 241 and the fingerprint reading unit 243b read the fingerprint of the user's finger. Based on the read user fingerprint, fingerprint information, which is information acquired from the user fingerprint to authenticate the user, is acquired. This fingerprint information is information obtained for use in fingerprint authentication for determining whether or not to execute the above-described processing such as execution of an application, and is information indicating the characteristics of the fingerprint of a legitimate user's finger. .
 上記の正当なユーザ以外に実行が制限される処理を情報処理装置200に実行させようとするユーザは、正当であると認証されるために、そのユーザの予め登録された指の指紋を、情報処理装置200が有する指紋認証部241および指紋読み取り部243bに読み取らせる。指紋情報は、指紋読み取り部243bが指紋を読み取ることにより取得した情報から、指紋認証ライブラリ262dが指紋の特徴を抽出することによって生成される。これにより、ユーザの指紋情報が取得される。指紋認証部241、指紋読み取り部243b、指紋認証ライブラリ262dは、指紋情報取得部として機能する。 A user who intends to cause the information processing apparatus 200 to execute a process whose execution is restricted to other than the above-mentioned authorized user is authenticated as the information of the user's pre-registered finger in order to be authenticated. The fingerprint authentication unit 241 and the fingerprint reading unit 243b included in the processing apparatus 200 are read. The fingerprint information is generated by the fingerprint authentication library 262d extracting the characteristics of the fingerprint from the information acquired by the fingerprint reading unit 243b reading the fingerprint. Thereby, the fingerprint information of the user is acquired. The fingerprint authentication unit 241, the fingerprint reading unit 243b, and the fingerprint authentication library 262d function as a fingerprint information acquisition unit.
 認証情報記憶部241bは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、指紋情報と比較することによりユーザを認証するための指紋認証情報を記憶する。この指紋認証情報は、予め情報処理装置200が有する情報であって、正当なユーザの指紋を読み取って抽出した指紋の特徴を示す情報である。指紋認証情報は、ユーザ毎に設定されている。 The authentication information storage unit 241b is information set in advance for use in authenticating whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information. This fingerprint authentication information is information that the information processing apparatus 200 has in advance, and is information that indicates the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint. The fingerprint authentication information is set for each user.
 また、認証情報記憶部241bは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、識別情報と比較することによりユーザを認証する識別認証情報を記憶する。この識別認証情報は、予め情報処理装置200が有する情報であって、情報処理装置200を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。識別認証情報は、識別情報と比較可能な情報である。識別認証情報は、ワンタッチボタンに対応する各キーコードと各ユーザの指紋認証情報とをそれぞれ関連付ける情報である。 Also, the authentication information storage unit 241b is information set in advance for use in authentication of whether or not the user is valid, and stores identification authentication information for authenticating the user by comparing with the identification information. This identification authentication information is information that the information processing apparatus 200 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 200 from other users and those who do not have a valid use authority other than the user. Information. The identification authentication information is information that can be compared with the identification information. The identification authentication information is information that associates each key code corresponding to the one-touch button with the fingerprint authentication information of each user.
 ワンタッチボタン認証は、認証を受けるユーザが操作したワンタッチボタンに対応する識別情報であるキーコードと関連付けられた指紋認証情報を取得することにより行われる。ここで、ユーザが操作したワンタッチボタンのキーコードと各ユーザの指紋認証情報とは、識別認証情報によって関連付けられている。 One-touch button authentication is performed by acquiring fingerprint authentication information associated with a key code that is identification information corresponding to a one-touch button operated by a user who is authenticated. Here, the key code of the one-touch button operated by the user and the fingerprint authentication information of each user are associated with each other by the identification authentication information.
 指紋認証は、指紋情報が示すユーザの指紋を読み取って抽出した特徴点と、予め設定された指紋認証情報が示す特徴点とを比較して行われる。
 ワンタッチ操作部242および組み込みコントローラ251は、ユーザによるワンタッチボタンの押下操作を受け付ける。この受け付けられたワンタッチボタンの操作に基づいて、ユーザを認証するための情報であると共に指紋情報とは異なる情報である識別情報として、ワンタッチボタンのそれぞれに対応付けられたキーコードが取得される。ここで、ワンタッチボタンは、情報処理装置200に複数設けられていると共に、情報処理装置200を使用するユーザのそれぞれに割り当てられている。この識別情報は、上記の処理の実行のために取得される情報であって、情報処理装置200を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。ワンタッチ操作部242、組み込みコントローラ251は、識別情報取得部として機能する。
The fingerprint authentication is performed by comparing the feature point extracted by reading the user's fingerprint indicated by the fingerprint information with the feature point indicated by the preset fingerprint authentication information.
The one-touch operation unit 242 and the built-in controller 251 accept a pressing operation of the one-touch button by the user. Based on the accepted operation of the one-touch button, a key code associated with each one-touch button is acquired as identification information that is information for authenticating the user and is different from the fingerprint information. Here, a plurality of one-touch buttons are provided in the information processing apparatus 200 and are assigned to each user who uses the information processing apparatus 200. This identification information is information acquired for the execution of the above processing, and identifies the ID of the user who uses the information processing apparatus 200 from other users and those who do not have a valid use authority other than the user. It is information that makes it possible. The one-touch operation unit 242 and the embedded controller 251 function as an identification information acquisition unit.
 ワンタッチ操作部242は、識別情報としてのキーコードの入力を受け付ける複数のワンタッチボタンを有する。ワンタッチ操作部242は、ユーザによるワンタッチボタンの押下操作を受け付け、受け付けた操作に基づいて識別情報を取得する。 The one-touch operation unit 242 has a plurality of one-touch buttons that accept key code input as identification information. The one-touch operation unit 242 receives a pressing operation of the one-touch button by the user, and acquires identification information based on the received operation.
 本実施の形態のワンタッチ操作部242は、図示しないワンタッチボタン(図3において前述したワンタッチボタン142aを参照)として4個のボタンを有する。この各ボタンに対して情報処理装置200の使用について正当な権限を有するユーザが割り当てられている。各ユーザは、アプリケーションの起動時等に、自分に割り当てられたワンタッチボタンを操作することにより、ワンタッチボタン認証が行われる。これに限らず、個数および対応する文字は、必要に応じて自由に設定することができる。 The one-touch operation unit 242 of this embodiment has four buttons as one-touch buttons (not shown) (see the one-touch button 142a described above in FIG. 3). A user having a right to use the information processing apparatus 200 is assigned to each button. Each user performs one-touch button authentication by operating a one-touch button assigned to him / her when the application is activated. Not limited to this, the number and the corresponding characters can be freely set as necessary.
 組み込みコントローラ251は、情報処理装置200の電源管理等の機能を有すると共に、キーボードコントローラ251a、I/Oコントローラ251cを有する。
 キーボードコントローラ251aは、キーボード231に対するキーの押下操作およびリリース操作を定期的に監視して、操作に応じた情報を、バス207を介してオペレーティングシステム260に送信する。I/Oコントローラ251cは、ワンタッチ操作部242等の操作に関する情報の指紋認証部241との間の送受信を行う。
The embedded controller 251 has functions such as power management for the information processing apparatus 200, and also includes a keyboard controller 251a and an I / O controller 251c.
The keyboard controller 251 a periodically monitors key press operations and release operations on the keyboard 231, and transmits information corresponding to the operations to the operating system 260 via the bus 207. The I / O controller 251c transmits and receives information related to the operation of the one-touch operation unit 242 and the like with the fingerprint authentication unit 241.
 組み込みコントローラ251とオペレーティングシステム260との間の通信、および指紋認証部241とオペレーティングシステム260との間の通信は、バス207を介して行われる。 Communication between the embedded controller 251 and the operating system 260 and communication between the fingerprint authentication unit 241 and the operating system 260 are performed via the bus 207.
 キーボードコントローラ251aから送信されたキーコード等の情報は、バス207を介してオペレーティングシステム260が有するキーボードドライバ261aおよびキーボードライブラリ262aに送信される。キーコードはさらに、キーボードドライバ261aを介してワンタッチ操作部ドライバ261eおよびワンタッチ操作部ライブラリ262eに送信される。 Information such as a key code transmitted from the keyboard controller 251a is transmitted to the keyboard driver 261a and keyboard library 262a of the operating system 260 via the bus 207. The key code is further transmitted to the one-touch operation unit driver 261e and the one-touch operation unit library 262e via the keyboard driver 261a.
 オペレーティングシステム260は、情報処理装置200の各部分の機能を定義することにより情報処理装置200の全体を管理するソフトウェアである。オペレーティングシステム260は、キーボードドライバ261a、指紋認証ドライバ261d、ワンタッチ操作部ドライバ261e、キーボードライブラリ262a、指紋認証ライブラリ262d、ワンタッチ操作部ライブラリ262eを有する。 The operating system 260 is software that manages the entire information processing apparatus 200 by defining the functions of each part of the information processing apparatus 200. The operating system 260 includes a keyboard driver 261a, a fingerprint authentication driver 261d, a one-touch operation unit driver 261e, a keyboard library 262a, a fingerprint authentication library 262d, and a one-touch operation unit library 262e.
 オペレーティングシステム260は、ユーザによる情報処理装置200の起動指示もしくはログインの受け付けの開始を指示するログイン指示、またはアプリケーションの起動を指示するアプリケーション起動指示もしくはアプリケーションの実行を指示するアプリケーション実行指示を受け付ける。オペレーティングシステム260は、制御部として機能する。 The operating system 260 accepts a user's activation instruction for the information processing apparatus 200 or a login instruction for instructing the start of acceptance of login, an application activation instruction for instructing application activation, or an application execution instruction for instructing execution of the application. The operating system 260 functions as a control unit.
 オペレーティングシステム260は、ユーザによるアプリケーションの起動指示等の指示を受け付けると、上記の指示に対応する処理が正当なユーザ以外のユーザに対して実行が制限される処理であるときには、受け付けた指示に基づいてオペレーティングシステム260がワンタッチボタン認証を行い、続いて指紋認証制御部241aに指紋認証を行わせる。そして、指紋認証制御部241aによる指紋認証によってユーザが正当であると認証された場合に、上記の指示に基づいて、アプリケーションの起動等、正当なユーザに許可された処理を実行する。 When the operating system 260 accepts an instruction such as an application activation instruction from the user, if the process corresponding to the above instruction is a process that is restricted to a user other than a valid user, the operating system 260 is based on the accepted instruction. Then, the operating system 260 performs one-touch button authentication, and then causes the fingerprint authentication control unit 241a to perform fingerprint authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 241a, the process authorized by the authorized user, such as starting an application, is executed based on the above instruction.
 オペレーティングシステム260は、ワンタッチボタン認証として、ユーザによるワンタッチ操作部242の操作に基づいて、ワンタッチ操作部242が有するワンタッチボタンに対応するキーコード(識別情報)を取得する。このキーコードに基づいて、指紋認証制御部241aは、取得したキーコードに対して識別認証情報によって関連付けられたユーザの指紋認証情報を取得し、指紋認証として、ワンタッチボタン認証に基づいて取得した指紋認証情報と指紋読み取り部243bによって取得された指紋情報とを比較する。これにより、ユーザの正当性が判断される。 The operating system 260 acquires a key code (identification information) corresponding to the one-touch button of the one-touch operation unit 242 based on the operation of the one-touch operation unit 242 by the user as one-touch button authentication. Based on this key code, the fingerprint authentication control unit 241a acquires the fingerprint authentication information of the user associated with the acquired key code by the identification authentication information, and acquires the fingerprint acquired based on the one-touch button authentication as the fingerprint authentication. The authentication information is compared with the fingerprint information acquired by the fingerprint reading unit 243b. Thereby, the legitimacy of the user is determined.
 なお、ワンタッチボタン認証に代えて、ユーザに対してワンタッチボタンを複数回操作することによりユーザID等を入力させ、入力させたユーザIDを識別情報として認証を行ってもよい。具体的には、各ワンタッチボタンに対して、それぞれが「1」~「4」に対応するものとする。各ユーザは、この「1」~「4」のボタンをユーザIDとして定められた順序で操作することにより、ユーザIDを入力することができる。例えば、ユーザIDが「3」、「1」、「2」、「4」と定められている場合には、ユーザは、ワンタッチボタンを「3」、「1」、「2」、「4」の順序で操作した後、確定ボタンを操作する。これにより、ユーザによるユーザIDの入力が受け付けられる。そして、オペレーティングシステム260により入力されたユーザIDに基づいて指紋認証情報が決定される。そして、指紋認証部241により決定された指紋認証情報に基づく指紋認証制御部241aの認証が行われ、ユーザの正当性が判断される。 Note that instead of the one-touch button authentication, the user may input a user ID or the like by operating the one-touch button a plurality of times, and authentication may be performed using the input user ID as identification information. Specifically, it is assumed that each one-touch button corresponds to “1” to “4”. Each user can input the user ID by operating the buttons “1” to “4” in the order determined as the user ID. For example, when the user ID is defined as “3”, “1”, “2”, “4”, the user presses the one-touch button “3”, “1”, “2”, “4”. After operating in this order, operate the confirm button. Thereby, the input of the user ID by the user is accepted. Then, the fingerprint authentication information is determined based on the user ID input by the operating system 260. Then, authentication of the fingerprint authentication control unit 241a based on the fingerprint authentication information determined by the fingerprint authentication unit 241 is performed, and the legitimacy of the user is determined.
 アプリケーションプログラム270には、キーボード231によって入力された情報を取得するアプリケーション271a、情報処理装置200による認証に成功した場合に実行されるアプリケーション271cがある。 The application program 270 includes an application 271a that acquires information input through the keyboard 231 and an application 271c that is executed when authentication by the information processing apparatus 200 is successful.
 本実施の形態では、組み込みコントローラ251は、ワンタッチボタンの操作に基づくキーコードを受信すると、受信したキーコードをI/Oコントローラ251cを介して指紋認証部241に送信する。 In this embodiment, the embedded controller 251 receives the key code based on the operation of the one-touch button, and transmits the received key code to the fingerprint authentication unit 241 via the I / O controller 251c.
 キーコードを受信した指紋認証部241は、認証情報記憶部241bから識別認証情報を読み出す。そして、指紋認証部241は、識別認証情報によりキーコードに対応付けられた指紋認証情報を認証情報記憶部241bから読み出して、読み出した指紋認証情報と指紋読み取り部243bで読み取られた指紋に基づく指紋情報とにより指紋認証を行う。 The fingerprint authentication unit 241 that has received the key code reads the identification authentication information from the authentication information storage unit 241b. The fingerprint authentication unit 241 reads the fingerprint authentication information associated with the key code by the identification authentication information from the authentication information storage unit 241b, and the fingerprint based on the read fingerprint authentication information and the fingerprint read by the fingerprint reading unit 243b. Fingerprint authentication is performed based on information.
 なお、これに限らず、キーコードはキーボードコントローラ251aおよびオペレーティングシステム260を介して指紋認証部241に送信されてもよい。
 また、本実施の形態の指紋認証情報は、同一のユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報と、複数の指の指紋について予め定められた順序を示す順序情報とを有してもよい。そして、この場合、指紋認証制御部241aが実行する指紋認証は、ユーザの指紋を複数回取得した指紋情報について、指紋読み取り部243bおよび指紋認証部241によって読み取られた指紋に基づく指紋情報が、指紋認証情報が有する指別指紋認証情報とすべて一致すると共に、指紋情報が取得された順序が、指紋認証情報が有する順序情報が示す順序と一致した場合に、成功したと判定されるようにすることができる。これにより、情報処理装置200において、ユーザの複数の指の指紋について認証が実行されると共に、認証の対象であるユーザが指紋を読み取らせた順序も認証の判定の対象になるため、セキュリティを向上させることができる。
However, the present invention is not limited thereto, and the key code may be transmitted to the fingerprint authentication unit 241 via the keyboard controller 251a and the operating system 260.
The fingerprint authentication information according to the present embodiment includes finger-specific fingerprint authentication information set for a plurality of fingerprints of different fingers of the same user, and an order indicating a predetermined order for the fingerprints of the plurality of fingers. Information. In this case, the fingerprint authentication executed by the fingerprint authentication control unit 241a is performed on the fingerprint information obtained by the fingerprint reading unit 243b and the fingerprint authentication unit 241 with respect to the fingerprint information obtained by the user's fingerprint a plurality of times. When all the finger-fingerprint authentication information included in the authentication information matches and the order in which the fingerprint information is acquired matches the order indicated by the order information included in the fingerprint authentication information, it is determined that the authentication is successful. Can do. As a result, in the information processing apparatus 200, authentication is performed on the fingerprints of a plurality of fingers of the user, and the order in which the user who is the subject of authentication reads the fingerprints is also subject to authentication determination, thus improving security. Can be made.
 また、認証情報記憶部241bは、ユーザが操作するワンタッチボタンに対応する識別認証情報を複数記憶してもよい。そして、情報処理装置200が、識別認証情報とオペレーティングシステム260により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶する図示しないアプリケーション起動情報記憶部を有するようにしてもよい。さらに、オペレーティングシステム260は、ワンタッチボタン認証の実行時において、いずれの識別認証情報によって識別認証が成功したかを判断するようにしてもよい。この場合、オペレーティングシステム260は、アプリケーション起動情報記憶部に記憶されているアプリケーション起動情報と指紋認証制御部241aおよびオペレーティングシステム260による判断の結果とに基づいて、起動するアプリケーションを決定し、決定したアプリケーションを起動するようにすることができる。これにより、情報処理装置200は、ユーザが操作したワンタッチボタンに基づいて、異なるアプリケーションを起動することができるので、ユーザは、ワンタッチボタンの操作によって起動されるアプリケーションを選択することが可能になる。 Further, the authentication information storage unit 241b may store a plurality of pieces of identification authentication information corresponding to the one-touch button operated by the user. Then, the information processing apparatus 200 may include an application activation information storage unit (not shown) that stores application activation information that associates identification authentication information with an application activated by the operating system 260. Furthermore, the operating system 260 may determine which identification / authentication information has succeeded in identification / authentication when executing the one-touch button authentication. In this case, the operating system 260 determines the application to be activated based on the application activation information stored in the application activation information storage unit and the results of determination by the fingerprint authentication control unit 241a and the operating system 260, and the determined application Can be started. As a result, the information processing apparatus 200 can start different applications based on the one-touch button operated by the user, so that the user can select an application to be started by operating the one-touch button.
 また、同一のユーザの異なる複数の指の指紋とオペレーティングシステム260により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶するアプリケーション起動情報記憶部を有してもよい。そして、指紋認証情報は、同一のユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報を有してもよい。そして、オペレーティングシステム260は、指紋認証の実行時において、ユーザのいずれの指の指紋によって指紋認証が成功したかを判断するようにしてもよい。この場合、オペレーティングシステム260は、アプリケーション起動情報記憶部に記憶されているアプリケーション起動情報と指紋認証制御部241aおよびオペレーティングシステム260による判断の結果とに基づいて、起動するアプリケーションを決定し、決定したアプリケーションを起動するようにすることができる。これにより、情報処理装置200は、ユーザが指紋を読み取らせた指に基づいて、異なるアプリケーションを起動することができるので、ユーザは、指紋を読み取らせる指によって起動されるアプリケーションを選択することが可能になる。 Also, an application activation information storage unit that stores application activation information that associates fingerprints of a plurality of different fingers of the same user with applications activated by the operating system 260 may be provided. The fingerprint authentication information may include finger-specific fingerprint authentication information set for each of a plurality of different fingerprints of the same user. Then, the operating system 260 may determine which fingerprint of the user's finger is successful when executing the fingerprint authentication. In this case, the operating system 260 determines the application to be activated based on the application activation information stored in the application activation information storage unit and the results of determination by the fingerprint authentication control unit 241a and the operating system 260, and the determined application Can be started. As a result, the information processing apparatus 200 can start different applications based on the finger that the user has read the fingerprint, so the user can select the application that is started by the finger that reads the fingerprint. become.
 また、本実施の形態では指紋認証制御部241aが指紋認証およびワンタッチボタン認証を行う。通常、指紋認証と筆跡認証のように、異なる認証方式を組み合わせた場合、それぞれの認証装置で別個に処理を行う必要が生じるために、すべての認証処理が終了するまでに要する時間が長期化することになる。これに対して、本実施の形態では、同一の制御部が指紋認証および筆跡認証を実行することにより、複数種類の認証処理を実行しても、認証に要する時間を短縮可能である。 In this embodiment, the fingerprint authentication control unit 241a performs fingerprint authentication and one-touch button authentication. Normally, when different authentication methods are combined, such as fingerprint authentication and handwriting authentication, it is necessary to perform processing separately for each authentication device, so the time required to complete all authentication processing is prolonged. It will be. On the other hand, in the present embodiment, the same control unit executes fingerprint authentication and handwriting authentication, so that the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
 以上により、本実施の形態では、各アプリケーションにおけるそれぞれのドライバおよびライブラリのオープン/クローズおよびコールの処理を簡略化することができるため、処理の簡易化が可能になる。 As described above, according to the present embodiment, the process of opening / closing and calling each driver and library in each application can be simplified, so that the process can be simplified.
 次に、本実施の形態で実行される処理について説明する。
 図19は、第2の実施の形態の認証処理の手順を示すフローチャートである。図19に示す認証処理は、情報処理装置200(図18において前述)により実行される処理である。この認証処理は、情報処理装置200がユーザによるアプリケーションの起動指示を受け付けてアプリケーションを起動する際に実行される認証を行う処理であり、ユーザによるワンタッチ操作部242(図18において前述)が有するワンタッチボタン(図示省略)の操作によるアプリケーション起動操作に基づいて実行が開始される。このときユーザは、起動させたいアプリケーションに対応するワンタッチ操作部242を操作することにより、組み込みコントローラ251(図18において前述)は、ユーザにより操作されたワンタッチ操作部242の操作を受け付ける。これにより、情報処理装置200は、操作されたワンタッチ操作部242に対応するアプリケーションを起動するための認証処理を開始する。
Next, processing executed in the present embodiment will be described.
FIG. 19 is a flowchart illustrating an authentication processing procedure according to the second embodiment. The authentication process shown in FIG. 19 is a process executed by the information processing apparatus 200 (described above in FIG. 18). This authentication process is a process for performing authentication performed when the information processing apparatus 200 accepts an application activation instruction from the user and activates the application, and is a one-touch operation unit 242 (described above in FIG. 18) by the user. Execution is started based on an application activation operation by operating a button (not shown). At this time, when the user operates the one-touch operation unit 242 corresponding to the application to be activated, the embedded controller 251 (described above in FIG. 18) receives the operation of the one-touch operation unit 242 operated by the user. As a result, the information processing apparatus 200 starts an authentication process for starting an application corresponding to the operated one-touch operation unit 242.
 [ステップS21]キーボードコントローラ251a(図18において前述)は、組み込みコントローラ251によって操作が受け付けられたワンタッチ操作部242に対応するキーコードをキーボードドライバ261a(図18において前述)に送信する。また、このときキーボードコントローラ251aは、I/Oコントローラ251c(図18において前述)を介して指紋認証部241(図18において前述)に対して受信したキーコードを送信する。 [Step S21] The keyboard controller 251a (described above in FIG. 18) transmits a key code corresponding to the one-touch operation unit 242 whose operation has been received by the embedded controller 251 to the keyboard driver 261a (described above in FIG. 18). At this time, the keyboard controller 251a transmits the received key code to the fingerprint authentication unit 241 (described above in FIG. 18) via the I / O controller 251c (described above in FIG. 18).
 [ステップS22]オペレーティングシステム260(図18において前述)は、指紋認証メッセージウインドウ221d(図22において後述)を情報処理装置200が有するLCD(図示省略)の表示画面に表示する。 [Step S22] The operating system 260 (described above in FIG. 18) displays a fingerprint authentication message window 221d (described later in FIG. 22) on the display screen of the LCD (not shown) of the information processing apparatus 200.
 [ステップS23]指紋認証部241は、指紋読み取り部243b(図18において前述)によるユーザの指紋の読み取りを開始する。このとき指紋認証制御部241a(図18において前述)は、指紋の読み取りの結果得られる指紋情報を受信するまで、指紋読み取り部243bに対して指紋情報の送信を要求する。なお、指紋認証制御部241aは、一定時間指紋情報の送信がない場合には、指紋認証を中止する。 [Step S23] The fingerprint authentication unit 241 starts reading the fingerprint of the user by the fingerprint reading unit 243b (described above in FIG. 18). At this time, the fingerprint authentication control unit 241a (described above in FIG. 18) requests the fingerprint reading unit 243b to transmit the fingerprint information until it receives the fingerprint information obtained as a result of the fingerprint reading. Note that the fingerprint authentication control unit 241a stops fingerprint authentication when there is no transmission of fingerprint information for a certain period of time.
 [ステップS24]指紋認証制御部241aは、認証情報記憶部241b(図18において前述)からステップS21で送信されたキーコードに対応する指紋認証情報を読み出して取得する。 [Step S24] The fingerprint authentication control unit 241a reads out and acquires the fingerprint authentication information corresponding to the key code transmitted in step S21 from the authentication information storage unit 241b (described above in FIG. 18).
 [ステップS25]指紋認証制御部241aは、指紋読み取り部243bにより取得された指紋情報および認証情報記憶部241bから取得したキーコードに対応する指紋情報を比較して認証を行い、認証に成功したか否かを判定する。認証に成功すれば、処理がステップS26に進められる。一方、認証に失敗すれば、処理がステップS27に進められる。 [Step S25] The fingerprint authentication control unit 241a performs authentication by comparing the fingerprint information acquired by the fingerprint reading unit 243b and the fingerprint information corresponding to the key code acquired from the authentication information storage unit 241b. Determine whether or not. If the authentication is successful, the process proceeds to step S26. On the other hand, if the authentication fails, the process proceeds to step S27.
 [ステップS26]オペレーティングシステム260は、ユーザによる起動指示の対象となっているアプリケーションを起動させる。その後、認証処理は終了する。
 [ステップS27]オペレーティングシステム260は、LCDの表示画面に、ユーザによる起動指示の対象となっているアプリケーションの起動に関するエラー表示を行う。その後、認証処理は終了する。
[Step S26] The operating system 260 activates the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
[Step S27] The operating system 260 displays an error related to the activation of the application that is the target of the activation instruction by the user on the LCD display screen. Thereafter, the authentication process ends.
 なお、本実施の形態の認証処理は、情報処理装置200において、ユーザのワンタッチ操作部242の操作によるアプリケーションの起動指示が検出された場合に実行が開始されるが、これに限らず、例えば、図示しないログイン画面を表示させる操作としてワンタッチ操作部242が操作された場合等の情報処理装置200に対するユーザのログイン時に実行が開始されてもよい。 The authentication process according to the present embodiment is started when the information processing apparatus 200 detects an application activation instruction by an operation of the user's one-touch operation unit 242, but is not limited thereto. Execution may be started when the user logs in to the information processing apparatus 200 such as when the one-touch operation unit 242 is operated as an operation for displaying a login screen (not shown).
 また、本実施の形態では、ステップS25の指紋認証に失敗した場合、ステップS27でエラー表示を行うが、再度の指紋の読み取りを試みてもよい。
 図20および図21は、第2の実施の形態の認証時の手順を示すシーケンス図である。
In the present embodiment, when the fingerprint authentication in step S25 fails, an error display is performed in step S27, but another fingerprint reading may be attempted.
20 and 21 are sequence diagrams illustrating a procedure at the time of authentication according to the second embodiment.
 ここで、図中の“ユーザインタフェース”は、ユーザが操作する入力装置および画面表示を行う出力装置である。具体的には、図18において前述したキーボード231、ワンタッチ操作部242、指紋読み取り部243b、情報処理装置200が有するLCD等である。 Here, “user interface” in the figure is an input device operated by the user and an output device for displaying a screen. Specifically, the keyboard 231, the one-touch operation unit 242, the fingerprint reading unit 243 b, the LCD included in the information processing apparatus 200 and the like described above with reference to FIG.
 また、図中の“指紋認証部”は、図18において前述した指紋認証部241である。前述のように、指紋認証部241は、指紋認証制御部241a、認証情報記憶部241bを有する。 Also, the “fingerprint authentication unit” in the figure is the fingerprint authentication unit 241 described above with reference to FIG. As described above, the fingerprint authentication unit 241 includes the fingerprint authentication control unit 241a and the authentication information storage unit 241b.
 また、図中の“コントローラ”は、キーボード231、ワンタッチ操作部242等の入力装置を制御する制御部であり、組み込みコントローラ251、キーボードコントローラ251a、I/Oコントローラ251c等である。 Further, “controller” in the figure is a control unit that controls input devices such as the keyboard 231 and the one-touch operation unit 242, and includes the embedded controller 251, the keyboard controller 251a, the I / O controller 251c, and the like.
 また、図中の“オペレーティングシステム”は、図18において前述したオペレーティングシステム260ならびにオペレーティングシステム260が有する各ライブラリおよび各ドライバである。 Further, “operating system” in the figure is the operating system 260 and the libraries and drivers included in the operating system 260 described above with reference to FIG.
 以下に、情報処理装置200における認証時の手順を図に従って説明する。
 [ステップS201]ワンタッチ操作部242は、ユーザによるワンタッチボタン(図示省略)の押下操作を受け付ける。
Hereinafter, a procedure at the time of authentication in the information processing apparatus 200 will be described with reference to the drawings.
[Step S201] The one-touch operation unit 242 accepts a pressing operation of a one-touch button (not shown) by the user.
 [ステップS202]キーボードコントローラ251aは、ステップS201におけるワンタッチボタンの押下操作を検出する。
 [ステップS203]キーボードコントローラ251aは、ステップS202において検出したワンタッチボタンの押下操作に基づいて、操作されたワンタッチボタンに対応するキーコードを、キーボードドライバ261aに対して送信する。また、I/Oコントローラ251cは、操作されたワンタッチボタンに対応するキーコードを、指紋認証部241に対して送信する。
[Step S202] The keyboard controller 251a detects the pressing operation of the one-touch button in step S201.
[Step S203] The keyboard controller 251a transmits a key code corresponding to the operated one-touch button to the keyboard driver 261a based on the pressing operation of the one-touch button detected in Step S202. Further, the I / O controller 251c transmits a key code corresponding to the operated one-touch button to the fingerprint authentication unit 241.
 ここで、キーボードドライバ261aは、受信したキーコードをさらにワンタッチ操作部ドライバ261eに対して送信する。このキーコードは、ワンタッチ操作部ドライバ261eによってワンタッチ操作部ライブラリ262eに送信される。ワンタッチ操作部ライブラリ262eは、後述する指紋認証に成功した場合、受信したキーコードに基づいてアプリケーションを起動する。また、指紋認証部241は、受信したキーコードに対応する指紋認証情報を用いて指紋認証を行う。 Here, the keyboard driver 261a further transmits the received key code to the one-touch operation unit driver 261e. This key code is transmitted to the one-touch operation unit library 262e by the one-touch operation unit driver 261e. The one-touch operation unit library 262e activates an application based on the received key code when fingerprint authentication described later is successful. The fingerprint authentication unit 241 performs fingerprint authentication using fingerprint authentication information corresponding to the received key code.
 [ステップS204]オペレーティングシステム260は、指紋認証を開始する際の処理を実行させる。具体的には、後述するように、オペレーティングシステム260は、指紋認証ドライバ261dに、指紋認証部241を起動させる。また、情報処理装置200が有するグラフィック処理装置(図示省略)に対して指紋認証メッセージウインドウ221d(図22において後述)を表示させる。 [Step S204] The operating system 260 executes processing for starting fingerprint authentication. Specifically, as described later, the operating system 260 causes the fingerprint authentication driver 261d to activate the fingerprint authentication unit 241. Further, a fingerprint authentication message window 221d (described later in FIG. 22) is displayed on a graphic processing device (not shown) included in the information processing device 200.
 [ステップS205]グラフィック処理装置は、LCDに指紋認証メッセージウインドウ221dを表示させる。
 [ステップS206]指紋認証制御部241aは、指紋読み取り部243bを起動する。これにより、ユーザの指紋の読み取りが可能な状態になる。
[Step S205] The graphic processing apparatus displays a fingerprint authentication message window 221d on the LCD.
[Step S206] The fingerprint authentication control unit 241a activates the fingerprint reading unit 243b. As a result, the user's fingerprint can be read.
 [ステップS207]指紋読み取り部243bは、ユーザの指紋の読み取りを行い、指紋情報を取得する。取得された指紋情報は、指紋認証制御部241aに送信される。
 [ステップS221]指紋認証制御部241aは、認証情報記憶部241bから、ステップS203で送信されたキーコードに対応する指紋認証情報を読み出す。次に、指紋認証制御部241aは、ステップS207において指紋読み取り部243bによって読み取られた指紋の指紋情報および認証情報記憶部241bから読み出した指紋認証情報を比較して照合し、ユーザの指紋の認証を行う。これにより、指紋に基づいてアプリケーションを起動しようとするユーザの正当性が判定される。
[Step S207] The fingerprint reading unit 243b reads the user's fingerprint and obtains fingerprint information. The acquired fingerprint information is transmitted to the fingerprint authentication control unit 241a.
[Step S221] The fingerprint authentication control unit 241a reads fingerprint authentication information corresponding to the key code transmitted in step S203 from the authentication information storage unit 241b. Next, the fingerprint authentication control unit 241a compares and compares the fingerprint information of the fingerprint read by the fingerprint reading unit 243b in step S207 with the fingerprint authentication information read from the authentication information storage unit 241b, thereby authenticating the user's fingerprint. Do. Thereby, the legitimacy of the user who tries to start the application is determined based on the fingerprint.
 [ステップS222]指紋認証制御部241aは、指紋の認証の照合結果である指紋認証照合結果を指紋認証ドライバ261dに送信する。
 [ステップS223]指紋認証制御部241aから送信された指紋認証照合結果を受信した指紋認証ドライバ261dは、指紋認証ライブラリ262dに指紋認証照合結果を送信する。さらに、指紋認証ドライバ261dから送信された指紋認証照合結果を受信した指紋認証ライブラリ262dは、指紋認証照合結果に基づいて、ステップS221において指紋認証制御部241aにより行われたユーザの指紋認証が成功したか否かを判定する。さらに、指紋認証ライブラリ262dは、指紋認証の判定結果をワンタッチ操作部ライブラリ262eに送信する。
[Step S222] The fingerprint authentication control unit 241a transmits a fingerprint authentication verification result, which is a verification result of fingerprint authentication, to the fingerprint authentication driver 261d.
[Step S223] The fingerprint authentication driver 261d that has received the fingerprint authentication verification result transmitted from the fingerprint authentication control unit 241a transmits the fingerprint authentication verification result to the fingerprint authentication library 262d. Furthermore, the fingerprint authentication library 262d that has received the fingerprint authentication collation result transmitted from the fingerprint authentication driver 261d has succeeded in the fingerprint authentication of the user performed by the fingerprint authentication control unit 241a in step S221 based on the fingerprint authentication collation result. It is determined whether or not. Further, the fingerprint authentication library 262d transmits the fingerprint authentication determination result to the one-touch operation unit library 262e.
 [ステップS224]受信した指紋認証の判定結果が認証成功であれば、オペレーティングシステム260は、ユーザの認証に成功した際の表示制御を行う。具体的には、後述するように、ワンタッチ操作部ライブラリ262eは、グラフィック処理装置に対して指紋認証メッセージウインドウ221dの表示を終了させる。 [Step S224] If the determination result of the received fingerprint authentication is successful, the operating system 260 performs display control when the user is successfully authenticated. Specifically, as will be described later, the one-touch operation unit library 262e ends the display of the fingerprint authentication message window 221d on the graphic processing device.
 なお、指紋認証の判定結果が認証失敗であれば、オペレーティングシステム260は、指紋認証メッセージウインドウ221dの表示を終了させると共に、図19において前述したように、LCDの表示画面にエラー表示を表示させ、認証処理を終了させる。 If the determination result of the fingerprint authentication is an authentication failure, the operating system 260 terminates the display of the fingerprint authentication message window 221d and displays an error display on the LCD display screen as described above with reference to FIG. End the authentication process.
 [ステップS225]グラフィック処理装置は、LCDの表示画面に表示された、指紋認証メッセージウインドウ221dの表示を終了させる。
 [ステップS226]ワンタッチ操作部ライブラリ262eは、ユーザのアプリケーションの起動操作の対象であるアプリケーションを起動させる。
[Step S225] The graphic processing device ends the display of the fingerprint authentication message window 221d displayed on the LCD display screen.
[Step S226] The one-touch operation unit library 262e activates the application that is the target of the activation operation of the user's application.
 次に、本実施の形態で表示される表示画面について説明する。
 図22は、第2の実施の形態の指紋認証メッセージウインドウを示す図である。図22に示す指紋認証メッセージウインドウ221dは、情報処理装置200(図18において前述)が有するLCDの表示画面に表示されるウインドウの一例である。指紋認証メッセージウインドウ221dには、ユーザに指紋の読み取りを案内するメッセージおよび画像が表示される。
Next, a display screen displayed in the present embodiment will be described.
FIG. 22 is a diagram illustrating a fingerprint authentication message window according to the second embodiment. A fingerprint authentication message window 221d shown in FIG. 22 is an example of a window displayed on the LCD display screen of the information processing apparatus 200 (described above in FIG. 18). In the fingerprint authentication message window 221d, a message and an image for guiding the user to read the fingerprint are displayed.
 指紋認証メッセージウインドウ221dには、例えば、「指をセンサに当ててスライドさせてください」というメッセージおよび指紋の読み取りを案内する画像が表示される。また、指紋認証メッセージウインドウ221dは、キャンセルボタン221d2を有する。 In the fingerprint authentication message window 221d, for example, a message “Please slide your finger against the sensor” and an image for guiding fingerprint reading are displayed. The fingerprint authentication message window 221d has a cancel button 221d2.
 キャンセルボタン221d2は、指紋の読み取りをキャンセルするボタンである。ユーザは、キャンセルボタン221d2を操作することにより、指紋の読み取りをキャンセルすると共に指紋認証を行わず、アプリケーションの起動を中止することができる。 The cancel button 221d2 is a button for canceling fingerprint reading. By operating the cancel button 221d2, the user can cancel the fingerprint reading and cancel the activation of the application without performing fingerprint authentication.
 以上のように、第2の実施の形態によれば、情報処理装置200において、ワンタッチボタンによる認証および指紋認証を併用することにより、ユーザ認証の精度が高まるのでセキュリティが向上する。 As described above, according to the second embodiment, in the information processing apparatus 200, by using authentication with a one-touch button and fingerprint authentication together, the accuracy of user authentication is increased, so that security is improved.
 また、指紋認証制御部241aが指紋認証および筆跡認証の処理を実行することにより、同一の処理部が複数の認証処理を連続して行う。これにより、認証を行う処理部間のデータをやり取りするプロセスが省略でき、複数種類の認証処理を実行しても認証に要する時間を短縮可能である。 Further, when the fingerprint authentication control unit 241a executes fingerprint authentication and handwriting authentication processing, the same processing unit continuously performs a plurality of authentication processes. As a result, the process of exchanging data between processing units that perform authentication can be omitted, and the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
 また、ワンタッチボタンに対応するキーコードの認証から指紋認証までを、ワンチップICで構成された指紋認証部241で行うことにより、認証の処理が外部から隠ぺいされるので、クラックを防止することができ、安全性が高まる。 In addition, by performing the authentication from the key code corresponding to the one-touch button to the fingerprint authentication by the fingerprint authentication unit 241 configured with a one-chip IC, the authentication process is concealed from the outside, so that cracks can be prevented. Yes, it increases safety.
 [第3の実施の形態]
 次に、第3の実施の形態について説明する。上記の第1の実施の形態との相違点を中心に説明し、同様の事項については同一の符号を用いると共に説明を省略する。
[Third Embodiment]
Next, a third embodiment will be described. Differences from the first embodiment will be mainly described, and the same reference numerals are used for the same matters, and descriptions thereof are omitted.
 第3の実施の形態は、ユーザが所持するICカードに記憶されたID情報(識別情報)を読み取ることによりユーザを識別すると共に、識別したユーザに対応した指紋認証情報を用いてユーザの指紋認証を行う点で、第1の実施の形態と異なる。 In the third embodiment, a user is identified by reading ID information (identification information) stored in an IC card possessed by the user, and fingerprint authentication of the user is performed using fingerprint authentication information corresponding to the identified user. This is different from the first embodiment in that
 図23は、第3の実施の形態の情報処理装置の構成を示すブロック図である。図23に示す情報処理装置300は、指紋認証部341、組み込みコントローラ351、オペレーティングシステム360、アプリケーションプログラム370を有する。 FIG. 23 is a block diagram illustrating a configuration of the information processing apparatus according to the third embodiment. An information processing apparatus 300 illustrated in FIG. 23 includes a fingerprint authentication unit 341, an embedded controller 351, an operating system 360, and an application program 370.
 情報処理装置300は、最下層に指紋読み取り部343b、カードリーダ344を有する。また、情報処理装置300は、カードリーダ344の上層に組み込みコントローラ351を有する。また、情報処理装置300は、指紋読み取り部343bの上層に指紋認証部341を有する。 The information processing apparatus 300 includes a fingerprint reading unit 343b and a card reader 344 at the lowest layer. The information processing apparatus 300 includes an embedded controller 351 in the upper layer of the card reader 344. In addition, the information processing apparatus 300 includes a fingerprint authentication unit 341 in the upper layer of the fingerprint reading unit 343b.
 指紋認証部341、組み込みコントローラ351の上層には、バス307を介してオペレーティングシステム360を有する。このオペレーティングシステム360の上層には、アプリケーションプログラム370を有する。 In the upper layer of the fingerprint authentication unit 341 and the embedded controller 351, an operating system 360 is provided via a bus 307. An application program 370 is provided in the upper layer of the operating system 360.
 指紋認証部341は、指紋認証制御部341a、認証情報記憶部341bを有する。指紋認証制御部341aと認証情報記憶部341bとは、同一のチップに搭載されている。また、指紋認証部341には、指紋読み取り部343bが接続されている。 The fingerprint authentication unit 341 includes a fingerprint authentication control unit 341a and an authentication information storage unit 341b. The fingerprint authentication control unit 341a and the authentication information storage unit 341b are mounted on the same chip. In addition, a fingerprint reading unit 343 b is connected to the fingerprint authentication unit 341.
 指紋認証制御部341aは、指紋認証部341および指紋読み取り部343bによって取得された指紋情報と認証情報記憶部341bに記憶された指紋認証情報とを比較して指紋認証を行う。カードリーダ344および組み込みコントローラ351は、カードリーダ344によって読み取られたユーザのICカード(図示省略)に記憶されているID情報を識別情報とする。そして、I/Oコントローラ351cは、指紋認証部341にID情報を送信する。ID情報を受信した指紋認証部341は、受信したID情報と認証情報記憶部341bに記憶された識別認証情報とを比較してカードID情報認証を行う。オペレーティングシステム360は、カードID情報認証により取得した指紋認証情報に基づく指紋認証に成功した場合に、ユーザを正当であると認証する。すなわち、指紋認証制御部341aおよびオペレーティングシステム360は、カードリーダ344によって読み取られたICカードに記憶されたID情報を取得し、取得されたID情報に対応する指紋認証情報を用いて指紋認証を実行する。指紋認証制御部341aおよびオペレーティングシステム360は、認証制御部として機能する。 The fingerprint authentication control unit 341a performs fingerprint authentication by comparing the fingerprint information acquired by the fingerprint authentication unit 341 and the fingerprint reading unit 343b with the fingerprint authentication information stored in the authentication information storage unit 341b. The card reader 344 and the embedded controller 351 use the ID information stored in the user's IC card (not shown) read by the card reader 344 as identification information. Then, the I / O controller 351c transmits the ID information to the fingerprint authentication unit 341. The fingerprint authentication unit 341 that has received the ID information compares the received ID information with the identification authentication information stored in the authentication information storage unit 341b to perform card ID information authentication. The operating system 360 authenticates the user as valid when the fingerprint authentication based on the fingerprint authentication information acquired by the card ID information authentication is successful. That is, the fingerprint authentication control unit 341a and the operating system 360 acquire the ID information stored in the IC card read by the card reader 344, and execute the fingerprint authentication using the fingerprint authentication information corresponding to the acquired ID information. To do. The fingerprint authentication control unit 341a and the operating system 360 function as an authentication control unit.
 指紋認証部341および指紋読み取り部343bは、ユーザの指の指紋を読み取る。この読み取られたユーザの指紋に基づいて、ユーザを認証するためにユーザの指紋から取得される情報である指紋情報が取得される。この指紋情報は、アプリケーションの実行等の上記の処理を実行するか否かを判定する指紋認証に用いるために取得される情報であって、正当なユーザの指の指紋の特徴を示す情報である。 The fingerprint authentication unit 341 and the fingerprint reading unit 343b read the fingerprint of the user's finger. Based on the read user fingerprint, fingerprint information, which is information acquired from the user fingerprint to authenticate the user, is acquired. This fingerprint information is information obtained for use in fingerprint authentication for determining whether or not to execute the above-described processing such as execution of an application, and is information indicating the characteristics of the fingerprint of a legitimate user's finger. .
 上記の正当なユーザ以外に実行が制限される処理を情報処理装置300に実行させようとするユーザは、正当であると認証されるために、そのユーザの予め登録された指の指紋を、情報処理装置300が有する指紋認証部341および指紋読み取り部343bに読み取らせる。指紋情報は、指紋読み取り部343bが指紋を読み取ることにより取得した情報から、指紋認証ライブラリ362dが指紋の特徴を抽出することによって生成される。これにより、ユーザの指紋情報が取得される。指紋認証部341、指紋読み取り部343b、指紋認証ライブラリ362dは、指紋情報取得部として機能する。 A user who intends to cause the information processing apparatus 300 to execute a process whose execution is restricted by a person other than the above-mentioned authorized user is authenticated with the fingerprint of the user's pre-registered finger in order to be authenticated. The fingerprint authentication unit 341 and the fingerprint reading unit 343b included in the processing device 300 are read. The fingerprint information is generated by the fingerprint authentication library 362d extracting the characteristics of the fingerprint from the information acquired by the fingerprint reading unit 343b reading the fingerprint. Thereby, the fingerprint information of the user is acquired. The fingerprint authentication unit 341, the fingerprint reading unit 343b, and the fingerprint authentication library 362d function as a fingerprint information acquisition unit.
 認証情報記憶部341bは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、指紋情報と比較することによりユーザを認証するための指紋認証情報を記憶する。この指紋認証情報は、予め情報処理装置300が有する情報であって、正当なユーザの指紋を読み取って抽出した指紋の特徴を示す情報である。指紋認証情報は、ユーザ毎に設定されている。 The authentication information storage unit 341b is information set in advance for use in authentication of whether or not the user is valid, and stores fingerprint authentication information for authenticating the user by comparing with the fingerprint information. This fingerprint authentication information is information that the information processing apparatus 300 has in advance, and is information that indicates the characteristics of a fingerprint extracted by reading a legitimate user's fingerprint. The fingerprint authentication information is set for each user.
 また、認証情報記憶部341bは、ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、識別情報と比較することによりユーザを認証する識別認証情報を記憶する。この識別認証情報は、予め情報処理装置300が有する情報であって、情報処理装置300を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。識別認証情報は、識別情報と比較可能な情報である。識別認証情報は、各ユーザが有するICカードに記憶されたID情報と各ユーザの指紋認証情報とをそれぞれ関連付ける情報である。 Further, the authentication information storage unit 341b stores identification authentication information that is set in advance for use in authentication of whether or not the user is valid and authenticates the user by comparing with the identification information. The identification authentication information is information that the information processing apparatus 300 has in advance, and makes it possible to identify the ID of the user who uses the information processing apparatus 300 from other users and persons who do not have a valid use authority other than the user. Information. The identification authentication information is information that can be compared with the identification information. The identification authentication information is information that associates ID information stored in an IC card possessed by each user with fingerprint authentication information of each user.
 カードID情報認証は、認証を受けるユーザが有するICカードに記憶された識別情報であるID情報と関連付けられた指紋認証情報を取得することにより行われる。ここで、ユーザが操作したワンタッチボタンのID情報と各ユーザの指紋認証情報とは、識別認証情報によって関連付けられている。 Card ID information authentication is performed by acquiring fingerprint authentication information associated with ID information which is identification information stored in an IC card held by a user who is authenticated. Here, the ID information of the one-touch button operated by the user and the fingerprint authentication information of each user are associated by the identification authentication information.
 指紋認証は、指紋情報が示すユーザの指紋を読み取って抽出した特徴点と、予め設定された指紋認証情報が示す特徴点とを比較して行われる。
 カードリーダ344は、ユーザが有するICカードに記憶されたID情報を、ユーザを認証するための情報であると共に指紋情報とは異なる情報である識別情報として取得する。カードリーダ344は、ICカードと無線通信により電気的に接続可能であると共に、接続されたICカードからID情報等の情報を読み取ることができる。なお、本実施の形態では、カードリーダ344は無線通信によってID情報を取得するが、これに限らず、ケーブルや端子等で接続された接触通信、磁性体に記録された情報の読み取り、バーコード、QRコード等の光学的に記録された情報の読み取り等で取得してもよい。また、本実施の形態では、ICカードを用いるが、これに限らず、磁気カード、小型メモリ、光ディスク等の情報を記憶可能な媒体であれば足りる。
The fingerprint authentication is performed by comparing the feature point extracted by reading the user's fingerprint indicated by the fingerprint information with the feature point indicated by the preset fingerprint authentication information.
The card reader 344 acquires ID information stored in an IC card held by the user as identification information that is information for authenticating the user and is different from the fingerprint information. The card reader 344 can be electrically connected to the IC card by wireless communication, and can read information such as ID information from the connected IC card. In this embodiment, the card reader 344 acquires ID information by wireless communication. However, the present invention is not limited to this, contact communication connected by a cable, a terminal, or the like, reading of information recorded on a magnetic material, barcode Alternatively, it may be acquired by reading optically recorded information such as a QR code. In this embodiment, an IC card is used. However, the present invention is not limited to this, and any medium capable of storing information such as a magnetic card, a small memory, and an optical disk is sufficient.
 この識別情報は、上記の処理の実行のために取得される情報であって、情報処理装置300を使用するユーザのIDを他のユーザおよびユーザ以外の正当な使用権限を有さない者と識別可能にする情報である。カードリーダ344、組み込みコントローラ351は、識別情報取得部として機能する。 This identification information is information acquired for executing the above-described processing, and identifies the ID of the user who uses the information processing apparatus 300 from other users and those who do not have a valid use authority other than the user. It is information that makes it possible. The card reader 344 and the embedded controller 351 function as an identification information acquisition unit.
 組み込みコントローラ351は、情報処理装置300の電源管理等の機能を有すると共に、カードリーダコントローラ351f、I/Oコントローラ351cを有する。
 カードリーダコントローラ351fは、カードリーダ344を定期的に監視して、カードリーダ344により取得された情報を、バス307を介してオペレーティングシステム360に送信する。I/Oコントローラ351cは、カードリーダ344によって取得されたID情報を、指紋認証部341に送信する。
The embedded controller 351 has functions such as power management for the information processing apparatus 300, and also includes a card reader controller 351f and an I / O controller 351c.
The card reader controller 351f periodically monitors the card reader 344 and transmits information acquired by the card reader 344 to the operating system 360 via the bus 307. The I / O controller 351c transmits the ID information acquired by the card reader 344 to the fingerprint authentication unit 341.
 組み込みコントローラ351とオペレーティングシステム360との間の通信、および指紋認証部341とオペレーティングシステム360との間の通信は、バス307を介して行われる。 Communication between the embedded controller 351 and the operating system 360 and communication between the fingerprint authentication unit 341 and the operating system 360 are performed via the bus 307.
 カードリーダコントローラ351fから送信されたID情報等の情報は、バス307を介してオペレーティングシステム360が有するカードリーダドライバ361fおよびカードリーダライブラリ362fに送信される。ID情報はさらに、カードリーダドライバ361fを介して指紋認証ドライバ361dおよび指紋認証ライブラリ362dに送信することもできる。 Information such as ID information transmitted from the card reader controller 351f is transmitted to the card reader driver 361f and the card reader library 362f of the operating system 360 via the bus 307. The ID information can also be transmitted to the fingerprint authentication driver 361d and the fingerprint authentication library 362d via the card reader driver 361f.
 オペレーティングシステム360は、情報処理装置300の各部分の機能を定義することにより情報処理装置300の全体を管理するソフトウェアである。オペレーティングシステム360は、カードリーダドライバ361f、指紋認証ドライバ361d、カードリーダライブラリ362f、指紋認証ライブラリ362dを有する。 The operating system 360 is software that manages the entire information processing apparatus 300 by defining functions of each part of the information processing apparatus 300. The operating system 360 includes a card reader driver 361f, a fingerprint authentication driver 361d, a card reader library 362f, and a fingerprint authentication library 362d.
 オペレーティングシステム360は、ユーザによる情報処理装置300の起動指示もしくはログインの受け付けの開始を指示するログイン指示、またはアプリケーションの起動を指示するアプリケーション起動指示もしくはアプリケーションの実行を指示するアプリケーション実行指示を受け付ける。オペレーティングシステム360は、制御部として機能する。 The operating system 360 accepts a user's activation instruction for the information processing apparatus 300 or a login instruction for instructing to start accepting login, an application activation instruction for instructing application activation, or an application execution instruction for instructing execution of the application. The operating system 360 functions as a control unit.
 オペレーティングシステム360は、ユーザによるアプリケーションの起動指示等の指示を受け付けると、上記の指示に対応する処理が正当なユーザ以外のユーザに対して実行が制限される処理であるときには、受け付けた指示に基づいてオペレーティングシステム360がカードID情報認証を行い、続いて指紋認証制御部341aに指紋認証を行わせる。そして、指紋認証制御部341aによる指紋認証によってユーザが正当であると認証された場合に、上記の指示に基づいて、アプリケーションの起動等、正当なユーザに許可された処理を実行する。 When the operating system 360 accepts an instruction such as an application activation instruction from the user, if the process corresponding to the above instruction is a process that is restricted to a user other than a valid user, the operating system 360 is based on the accepted instruction. Then, the operating system 360 performs card ID information authentication, and then causes the fingerprint authentication control unit 341a to perform fingerprint authentication. Then, when the user is authenticated by the fingerprint authentication by the fingerprint authentication control unit 341a, based on the above instruction, processing authorized by the authorized user, such as activation of an application, is executed.
 オペレーティングシステム360は、カードID情報認証として、カードリーダ344によるユーザが有するICカードの読み取りに基づいて、ICカードに記憶されたID情報(識別情報)を取得する。このID情報は、指紋認証制御部341aは、取得したID情報に対して識別認証情報によって関連付けられたユーザの指紋認証情報を取得し、指紋認証として、カードID情報認証に基づいて取得した指紋認証情報と指紋読み取り部343bによって取得された指紋情報とを比較することにより、ユーザの正当性が判断される。 The operating system 360 acquires ID information (identification information) stored in the IC card based on reading of the IC card held by the user by the card reader 344 as card ID information authentication. As for this ID information, the fingerprint authentication control unit 341a acquires the fingerprint authentication information of the user associated with the acquired ID information by the identification authentication information, and the fingerprint authentication acquired based on the card ID information authentication as the fingerprint authentication The legitimacy of the user is determined by comparing the information with the fingerprint information acquired by the fingerprint reading unit 343b.
 アプリケーションプログラム370には、カードリーダ344によって入力された情報を取得するアプリケーション371f、情報処理装置300による認証に成功した場合に実行されるアプリケーション371cがある。 The application program 370 includes an application 371 f that acquires information input by the card reader 344 and an application 371 c that is executed when authentication by the information processing apparatus 300 is successful.
 本実施の形態では、組み込みコントローラ351は、カードリーダ344の読み取りに基づくID情報を受信すると、受信したID情報をI/Oコントローラ351cを介して指紋認証部341に送信する。 In the present embodiment, when the embedded controller 351 receives ID information based on reading by the card reader 344, the embedded controller 351 transmits the received ID information to the fingerprint authentication unit 341 via the I / O controller 351c.
 ID情報を受信した指紋認証部341は、認証情報記憶部341bから識別認証情報を読み出す。そして、指紋認証部341は、識別認証情報によりID情報に対応付けられた指紋認証情報を認証情報記憶部341bから読み出して、読み出した指紋認証情報と指紋読み取り部343bで読み取られた指紋に基づく指紋情報とにより指紋認証を行う。 The fingerprint authentication unit 341 that has received the ID information reads the identification authentication information from the authentication information storage unit 341b. The fingerprint authentication unit 341 reads fingerprint authentication information associated with the ID information by the identification authentication information from the authentication information storage unit 341b, and the fingerprint based on the read fingerprint authentication information and the fingerprint read by the fingerprint reading unit 343b. Fingerprint authentication is performed based on information.
 なお、これに限らず、ID情報はカードリーダコントローラ351fおよびオペレーティングシステム360を介して指紋認証部341に送信されてもよい。
 また、本実施の形態の指紋認証情報は、同一のユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報と、複数の指の指紋について予め定められた順序を示す順序情報とを有してもよい。そして、この場合、指紋認証制御部341aが実行する指紋認証は、ユーザの指紋を複数回取得した指紋情報について、指紋読み取り部343bおよび指紋認証部341によって読み取られた指紋に基づく指紋情報が、指紋認証情報が有する指別指紋認証情報とすべて一致すると共に、指紋情報が取得された順序が、指紋認証情報が有する順序情報が示す順序と一致した場合に、成功したと判定されるようにすることができる。これにより、情報処理装置300において、ユーザの複数の指の指紋について認証が実行されると共に、認証の対象であるユーザが指紋を読み取らせた順序も認証の判定の対象になるため、セキュリティを向上させることができる。
The ID information may be transmitted to the fingerprint authentication unit 341 via the card reader controller 351f and the operating system 360.
The fingerprint authentication information according to the present embodiment includes finger-specific fingerprint authentication information set for a plurality of fingerprints of different fingers of the same user, and an order indicating a predetermined order for the fingerprints of the plurality of fingers. Information. In this case, the fingerprint authentication executed by the fingerprint authentication control unit 341a is the fingerprint information based on the fingerprint read by the fingerprint reading unit 343b and the fingerprint authentication unit 341 for the fingerprint information obtained by the user's fingerprint a plurality of times. When all the finger-fingerprint authentication information included in the authentication information matches and the order in which the fingerprint information is acquired matches the order indicated by the order information included in the fingerprint authentication information, it is determined that the authentication is successful. Can do. As a result, in the information processing apparatus 300, authentication is performed on the fingerprints of a plurality of fingers of the user, and the order in which the user who is the authentication target reads the fingerprints is also subject to authentication determination, thus improving security. Can be made.
 また、認証情報記憶部341bは、ユーザが有するICカードをユーザに対して複数用意し、さらにそれぞれのICカードに記憶されたID情報を異ならせてもよい。そして、それぞれのID情報に対応する識別認証情報を複数記憶してもよい。そして、情報処理装置300が、識別認証情報とオペレーティングシステム360により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶する図示しないアプリケーション起動情報記憶部を有するようにしてもよい。さらに、オペレーティングシステム360は、カードID情報認証の実行時において、いずれの識別認証情報によって識別認証が成功したかを判断するようにしてもよい。この場合、オペレーティングシステム360は、アプリケーション起動情報記憶部に記憶されているアプリケーション起動情報と指紋認証制御部341aおよびオペレーティングシステム360による判断の結果とに基づいて、起動するアプリケーションを決定し、決定したアプリケーションを起動するようにすることができる。これにより、情報処理装置300は、ユーザのICカードから読み出したID情報に基づいて、異なるアプリケーションを起動することができるので、ユーザは、読みとらせたICカードによって起動されるアプリケーションを選択することが可能になる。 Further, the authentication information storage unit 341b may prepare a plurality of IC cards owned by the user for the user, and may further change the ID information stored in each IC card. A plurality of identification authentication information corresponding to each ID information may be stored. The information processing apparatus 300 may include an application activation information storage unit (not shown) that stores application activation information that associates identification authentication information with an application activated by the operating system 360. Further, the operating system 360 may determine which identification / authentication information has succeeded in identification / authentication when executing card ID information authentication. In this case, the operating system 360 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 341a and the operating system 360, and the determined application Can be started. As a result, the information processing apparatus 300 can start different applications based on the ID information read from the user's IC card. Therefore, the user selects an application to be started by the read IC card. Is possible.
 また、同一のユーザの異なる複数の指の指紋とオペレーティングシステム360により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶するアプリケーション起動情報記憶部を有してもよい。そして、指紋認証情報は、同一のユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報を有してもよい。そして、オペレーティングシステム360は、指紋認証の実行時において、ユーザのいずれの指の指紋によって指紋認証が成功したかを判断するようにしてもよい。この場合、オペレーティングシステム360は、アプリケーション起動情報記憶部に記憶されているアプリケーション起動情報と指紋認証制御部341aおよびオペレーティングシステム360による判断の結果とに基づいて、起動するアプリケーションを決定し、決定したアプリケーションを起動するようにすることができる。これにより、情報処理装置300は、ユーザが指紋を読み取らせた指に基づいて、異なるアプリケーションを起動することができるので、ユーザは、指紋を読み取らせる指によって起動されるアプリケーションを選択することが可能になる。 Also, an application activation information storage unit that stores application activation information that associates fingerprints of a plurality of different fingers of the same user with applications activated by the operating system 360 may be provided. The fingerprint authentication information may include finger-specific fingerprint authentication information set for each of a plurality of different fingerprints of the same user. Then, the operating system 360 may determine which fingerprint of the user's finger is successful when executing the fingerprint authentication. In this case, the operating system 360 determines an application to be activated based on the application activation information stored in the application activation information storage unit and the determination result by the fingerprint authentication control unit 341a and the operating system 360, and the determined application Can be started. As a result, the information processing apparatus 300 can start different applications based on the finger that the user has read the fingerprint, so the user can select the application that is started by the finger that reads the fingerprint. become.
 また、本実施の形態では指紋認証制御部341aが指紋認証およびカードID認証を行う。通常、指紋認証とカードID認証のように、異なる認証方式を組み合わせた場合、それぞれの認証装置で別個に処理を行う必要が生じるために、すべての認証処理が終了するまでに要する時間が長期化することになる。これに対して、本実施の形態では、同一の制御部が指紋認証およびカードID認証を実行することにより、複数種類の認証処理を実行しても、認証に要する時間を短縮可能である。 In this embodiment, the fingerprint authentication control unit 341a performs fingerprint authentication and card ID authentication. Normally, when different authentication methods are combined, such as fingerprint authentication and card ID authentication, it is necessary to perform processing separately for each authentication device, so the time required to complete all authentication processing is prolonged. Will do. On the other hand, in the present embodiment, the same control unit executes fingerprint authentication and card ID authentication, so that the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
 以上により、本実施の形態では、各アプリケーションにおけるそれぞれのドライバおよびライブラリのオープン/クローズおよびコールの処理を簡略化することができるため、処理の簡易化が可能になる。 As described above, according to the present embodiment, the process of opening / closing and calling each driver and library in each application can be simplified, so that the process can be simplified.
 次に、本実施の形態で実行される処理について説明する。
 図24は、第3の実施の形態の認証処理の手順を示すフローチャートである。図24に示す認証処理は、情報処理装置300(図23において前述)により実行される処理である。この認証処理は、情報処理装置300がユーザによるアプリケーションの起動指示を受け付けてアプリケーションを起動する際に実行される認証を行う処理であり、ユーザによるワンタッチ操作部(図示省略)が有するワンタッチボタン(図示省略)の操作によるアプリケーション起動操作に基づいて実行が開始される。このときユーザは、起動させたいアプリケーションに対応するワンタッチ操作部を操作することにより、組み込みコントローラ351(図23において前述)は、ユーザにより操作されたワンタッチ操作部の操作を受け付ける。これにより、情報処理装置300は、操作されたワンタッチ操作部に対応するアプリケーションを起動するための認証処理を開始する。
Next, processing executed in the present embodiment will be described.
FIG. 24 is a flowchart illustrating an authentication processing procedure according to the third embodiment. The authentication process shown in FIG. 24 is a process executed by the information processing apparatus 300 (described above in FIG. 23). This authentication process is a process of performing authentication when the information processing apparatus 300 receives an application activation instruction from the user and activates the application, and includes a one-touch button (not illustrated) included in a one-touch operation unit (not illustrated) by the user. Execution is started based on the application activation operation by the operation of (omitted). At this time, the user operates the one-touch operation unit corresponding to the application to be activated, so that the embedded controller 351 (described above in FIG. 23) receives the operation of the one-touch operation unit operated by the user. As a result, the information processing apparatus 300 starts an authentication process for starting an application corresponding to the operated one-touch operation unit.
 [ステップS31]カードリーダコントローラ351f(図23において前述)は、組み込みコントローラ351を介して、カードリーダ344(図23において前述)により、ユーザのICカード(図示省略)に記憶されているID情報を読み取ることにより、ユーザのID情報を取得する。次に、カードリーダコントローラ351fは、取得したID情報をカードリーダドライバ361f(図23において前述)に送信する。また、このときカードリーダコントローラ351fは、I/Oコントローラ351c(図23において前述)を介して指紋認証部341(図23において前述)に対して受信したID情報を送信する。 [Step S31] The card reader controller 351f (described above in FIG. 23) receives the ID information stored in the user's IC card (not shown) by the card reader 344 (described above in FIG. 23) via the embedded controller 351. By reading, the user's ID information is acquired. Next, the card reader controller 351f transmits the acquired ID information to the card reader driver 361f (described above in FIG. 23). At this time, the card reader controller 351f transmits the received ID information to the fingerprint authentication unit 341 (described above in FIG. 23) via the I / O controller 351c (described above in FIG. 23).
 [ステップS32]オペレーティングシステム360(図23において前述)は、ユーザに指紋の読み取りを案内する表示を含む指紋認証メッセージウインドウ(図示省略)を情報処理装置300が有するLCD(図示省略)の表示画面に表示する。 [Step S32] The operating system 360 (described above in FIG. 23) displays a fingerprint authentication message window (not shown) including a display for guiding the user to read the fingerprint on the display screen of the LCD (not shown) of the information processing apparatus 300. indicate.
 [ステップS33]指紋認証部341は、指紋読み取り部343b(図23において前述)によるユーザの指紋の読み取りを開始する。このとき指紋認証制御部341a(図23において前述)は、指紋の読み取りの結果得られる指紋情報を受信するまで、指紋読み取り部343bに対して指紋情報の送信を要求する。なお、指紋認証制御部341aは、一定時間指紋情報の送信がない場合には、指紋認証を中止する。 [Step S33] The fingerprint authentication unit 341 starts reading the fingerprint of the user by the fingerprint reading unit 343b (described above in FIG. 23). At this time, the fingerprint authentication control unit 341a (described above in FIG. 23) requests the fingerprint reading unit 343b to transmit the fingerprint information until receiving the fingerprint information obtained as a result of the fingerprint reading. Note that the fingerprint authentication control unit 341a stops the fingerprint authentication when there is no transmission of fingerprint information for a certain period of time.
 [ステップS34]指紋認証制御部341aは、認証情報記憶部341b(図23において前述)からステップS31で送信されたID情報に対応する指紋認証情報を読み出して取得する。 [Step S34] The fingerprint authentication control unit 341a reads out and acquires the fingerprint authentication information corresponding to the ID information transmitted in step S31 from the authentication information storage unit 341b (described above in FIG. 23).
 [ステップS35]指紋認証制御部341aは、指紋読み取り部343bにより取得された指紋情報および認証情報記憶部341bから取得したID情報に対応する指紋情報を比較して認証を行い、認証に成功したか否かを判定する。認証に成功すれば、処理がステップS36に進められる。一方、認証に失敗すれば、処理がステップS37に進められる。 [Step S35] The fingerprint authentication control unit 341a compares the fingerprint information acquired by the fingerprint reading unit 343b and the fingerprint information corresponding to the ID information acquired from the authentication information storage unit 341b, and performs authentication. Determine whether or not. If the authentication is successful, the process proceeds to step S36. On the other hand, if the authentication fails, the process proceeds to step S37.
 [ステップS36]オペレーティングシステム360は、ユーザによる起動指示の対象となっているアプリケーションを起動させる。その後、認証処理は終了する。
 [ステップS37]オペレーティングシステム360は、LCDの表示画面に、ユーザによる起動指示の対象となっているアプリケーションの起動に関するエラー表示を行う。その後、認証処理は終了する。
[Step S36] The operating system 360 activates the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
[Step S37] The operating system 360 displays on the LCD display screen an error regarding the activation of the application that is the target of the activation instruction by the user. Thereafter, the authentication process ends.
 なお、本実施の形態の認証処理は、情報処理装置300において、ユーザの操作によるアプリケーションの起動指示が検出された場合に実行が開始されるが、これに限らず、例えば、図示しないログイン画面を表示させる操作が行われた場合等の情報処理装置300に対するユーザのログイン時に実行が開始されてもよい。 The authentication process of the present embodiment is started when the information processing apparatus 300 detects an application activation instruction by a user operation, but is not limited to this. For example, a login screen (not shown) is displayed. Execution may be started when the user logs in to the information processing apparatus 300 when an operation to display is performed.
 また、本実施の形態では、ステップS35の指紋認証に失敗した場合、ステップS37でエラー表示を行うが、再度の指紋の読み取りを試みてもよい。
 図25および図26は、第3の実施の形態の認証時の手順を示すシーケンス図である。
In this embodiment, when the fingerprint authentication in step S35 fails, an error display is performed in step S37, but another fingerprint reading may be attempted.
25 and 26 are sequence diagrams illustrating a procedure at the time of authentication according to the third embodiment.
 ここで、図中の“ユーザインタフェース”は、ユーザが操作する入力装置および画面表示を行う出力装置である。具体的には、図23において前述した指紋読み取り部343b、カードリーダ344、情報処理装置300が有するLCD等である。 Here, “user interface” in the figure is an input device operated by the user and an output device for displaying a screen. Specifically, the fingerprint reading unit 343b, the card reader 344, the LCD included in the information processing apparatus 300 described above with reference to FIG.
 また、図中の“指紋認証部”は、図23において前述した指紋認証部341である。前述のように、指紋認証部341は、指紋認証制御部341a、認証情報記憶部341bを有する。 Also, the “fingerprint authentication unit” in the figure is the fingerprint authentication unit 341 described above with reference to FIG. As described above, the fingerprint authentication unit 341 includes the fingerprint authentication control unit 341a and the authentication information storage unit 341b.
 また、図中の“コントローラ”は、カードリーダ344等の入力装置を制御する制御部であり、組み込みコントローラ351、I/Oコントローラ351c、カードリーダコントローラ351f等である。 Further, “controller” in the figure is a control unit that controls an input device such as a card reader 344, and includes an embedded controller 351, an I / O controller 351c, a card reader controller 351f, and the like.
 また、図中の“オペレーティングシステム”は、図23において前述したオペレーティングシステム360ならびにオペレーティングシステム360が有する各ライブラリおよび各ドライバである。 Also, “operating system” in the figure is the operating system 360 and the libraries and drivers of the operating system 360 described above with reference to FIG.
 以下に、情報処理装置300における認証時の手順を図に従って説明する。
 [ステップS301]カードリーダ344は、ユーザのICカード(図示省略)からID情報を読み取って取得する。このID情報は、カードリーダコントローラ351fに送信される。
Hereinafter, a procedure at the time of authentication in the information processing apparatus 300 will be described with reference to the drawings.
[Step S301] The card reader 344 reads and acquires ID information from the user's IC card (not shown). This ID information is transmitted to the card reader controller 351f.
 [ステップS302]カードリーダコントローラ351fは、ステップS301において読み取られたICカードのID情報を検出する。
 [ステップS303]カードリーダコントローラ351fは、ステップS302において検出したICカードのID情報を、カードリーダドライバ361fに対して送信する。また、I/Oコントローラ351cは、検出したICカードのID情報を、指紋認証部341に対して送信する。
[Step S302] The card reader controller 351f detects the ID information of the IC card read in step S301.
[Step S303] The card reader controller 351f transmits the ID information of the IC card detected in step S302 to the card reader driver 361f. Also, the I / O controller 351c transmits the detected ID information of the IC card to the fingerprint authentication unit 341.
 ここで、カードリーダドライバ361fは、受信したID情報をさらにカードリーダライブラリ362fに送信する。カードリーダライブラリ362fは、後述する指紋認証に成功した場合、受信したID情報に基づいてアプリケーションを起動する。また、指紋認証部341は、受信したID情報に対応する指紋認証情報を用いて指紋認証を行う。 Here, the card reader driver 361f further transmits the received ID information to the card reader library 362f. If the card reader library 362f succeeds in fingerprint authentication described later, the card reader library 362f activates the application based on the received ID information. The fingerprint authentication unit 341 performs fingerprint authentication using fingerprint authentication information corresponding to the received ID information.
 [ステップS304]オペレーティングシステム360は、指紋認証を開始する際の処理を実行させる。具体的には、後述するように、カードリーダドライバ361fは、指紋認証ドライバ361dに、指紋認証部341を起動させる。また、情報処理装置300が有するグラフィック処理装置(図示省略)に対して指紋認証メッセージウインドウ(図示省略)を表示させる。 [Step S304] The operating system 360 executes processing for starting fingerprint authentication. Specifically, as will be described later, the card reader driver 361f causes the fingerprint authentication driver 361d to activate the fingerprint authentication unit 341. Further, a fingerprint authentication message window (not shown) is displayed on a graphic processing device (not shown) included in the information processing apparatus 300.
 [ステップS305]グラフィック処理装置は、LCDに指紋認証メッセージウインドウを表示させる。
 [ステップS306]指紋認証制御部341aは、指紋読み取り部343bを起動する。これにより、ユーザの指紋の読み取りが可能な状態になる。
[Step S305] The graphic processing device displays a fingerprint authentication message window on the LCD.
[Step S306] The fingerprint authentication control unit 341a activates the fingerprint reading unit 343b. As a result, the user's fingerprint can be read.
 [ステップS307]指紋読み取り部343bは、ユーザの指紋の読み取りを行い、指紋情報を取得する。取得された指紋情報は、指紋認証制御部341aに送信される。
 [ステップS321]指紋認証制御部341aは、認証情報記憶部341bから、ステップS303で送信されたID情報に対応する指紋認証情報を読み出す。次に、指紋認証制御部341aは、ステップS307において指紋読み取り部343bによって読み取られた指紋の指紋情報および認証情報記憶部341bから読み出した指紋認証情報を比較して照合し、ユーザの指紋の認証を行う。これにより、指紋に基づいてアプリケーションを起動しようとするユーザの正当性が判定される。
[Step S307] The fingerprint reading unit 343b reads the fingerprint of the user and acquires fingerprint information. The acquired fingerprint information is transmitted to the fingerprint authentication control unit 341a.
[Step S321] The fingerprint authentication control unit 341a reads fingerprint authentication information corresponding to the ID information transmitted in step S303 from the authentication information storage unit 341b. Next, the fingerprint authentication control unit 341a compares the fingerprint information of the fingerprint read by the fingerprint reading unit 343b in step S307 with the fingerprint authentication information read from the authentication information storage unit 341b and collates them to authenticate the user's fingerprint. Do. Thereby, the legitimacy of the user who tries to start the application is determined based on the fingerprint.
 [ステップS322]指紋認証制御部341aは、指紋の認証の照合結果である指紋認証照合結果を指紋認証ドライバ361dに送信する。
 [ステップS323]指紋認証制御部341aから送信された指紋認証照合結果を受信した指紋認証ドライバ361dは、指紋認証ライブラリ362dに指紋認証照合結果を送信する。さらに、指紋認証ドライバ361dから送信された指紋認証照合結果を受信した指紋認証ライブラリ362dは、指紋認証照合結果に基づいて、ステップS321において指紋認証制御部341aにより行われたユーザの指紋認証が成功したか否かを判定する。
[Step S322] The fingerprint authentication control unit 341a transmits a fingerprint authentication collation result, which is a fingerprint authentication collation result, to the fingerprint authentication driver 361d.
[Step S323] The fingerprint authentication driver 361d that has received the fingerprint authentication verification result transmitted from the fingerprint authentication control unit 341a transmits the fingerprint authentication verification result to the fingerprint authentication library 362d. Furthermore, the fingerprint authentication library 362d that has received the fingerprint authentication collation result transmitted from the fingerprint authentication driver 361d has succeeded in the fingerprint authentication of the user performed by the fingerprint authentication control unit 341a in step S321 based on the fingerprint authentication collation result. It is determined whether or not.
 [ステップS324]受信した指紋認証の判定結果が認証成功であれば、オペレーティングシステム360は、ユーザの認証に成功した際の表示制御を行う。具体的には、後述するように、指紋認証ライブラリ362dは、グラフィック処理装置に対して指紋認証メッセージウインドウの表示を終了させる。 [Step S324] If the received determination result of the fingerprint authentication is successful, the operating system 360 performs display control when the user is successfully authenticated. Specifically, as will be described later, the fingerprint authentication library 362d ends the display of the fingerprint authentication message window on the graphic processing device.
 なお、指紋認証の判定結果が認証失敗であれば、オペレーティングシステム160は、指紋認証メッセージウインドウの表示を終了させると共に、図24において前述したように、LCDの表示画面にエラー表示を表示させ、認証処理を終了させる。 If the fingerprint authentication determination result is authentication failure, the operating system 160 terminates the display of the fingerprint authentication message window and displays an error display on the LCD display screen as described above with reference to FIG. End the process.
 [ステップS325]グラフィック処理装置は、LCDの表示画面に表示された、指紋認証メッセージウインドウの表示を終了させる。
 [ステップS326]指紋認証ライブラリ362dは、ユーザのアプリケーションの起動操作の対象であるアプリケーションを起動させる。
[Step S325] The graphic processing device ends the display of the fingerprint authentication message window displayed on the LCD display screen.
[Step S326] The fingerprint authentication library 362d activates the application that is the target of the activation operation of the user's application.
 以上のように、第3の実施の形態によれば、情報処理装置300において、ユーザのICカードのID情報による認証および指紋認証を併用することにより、ユーザ認証の精度が高まるのでセキュリティが向上する。 As described above, according to the third embodiment, in the information processing apparatus 300, by using the authentication based on the ID information of the user's IC card and the fingerprint authentication together, the accuracy of the user authentication is increased, so that the security is improved. .
 また、指紋認証制御部341aが指紋認証およびカードID認証の処理を実行することにより、同一の処理部が複数の認証処理を連続して行う。これにより、認証を行う処理部間のデータをやり取りするプロセスが省略でき、複数種類の認証処理を実行しても認証に要する時間を短縮可能である。 Further, when the fingerprint authentication control unit 341a executes fingerprint authentication and card ID authentication processing, the same processing unit continuously performs a plurality of authentication processes. As a result, the process of exchanging data between processing units that perform authentication can be omitted, and the time required for authentication can be shortened even when a plurality of types of authentication processes are executed.
 また、ICカードから読み取ったID情報の認証から指紋認証までを、ワンチップICで構成された指紋認証部341で行うので、認証の処理が外部から隠ぺいされることにより、クラックを防止することができ、安全性が高まる。 Further, since the authentication from the ID information read from the IC card to the fingerprint authentication is performed by the fingerprint authentication unit 341 configured with a one-chip IC, cracking can be prevented by hiding the authentication process from the outside. Yes, it increases safety.
 [第4の実施の形態]
 次に、第4の実施の形態について説明する。上記の第1の実施の形態との相違点を中心に説明し、同様の事項については同一の符号を用いると共に説明を省略する。
[Fourth Embodiment]
Next, a fourth embodiment will be described. Differences from the first embodiment will be mainly described, and the same reference numerals are used for the same matters, and descriptions thereof are omitted.
 第4の実施の形態は、情報処理装置が、自動取引装置であり、銀行等の預金の受け入れおよび払い出しを行う現金自動預け払い機(ATM:Automated Teller Machine)である点で、第1の実施の形態と異なる。 In the fourth embodiment, the information processing apparatus is an automatic transaction apparatus, and is an automatic teller machine (ATM: AutomatedTMTeller 受 け 入 れ Machine) that accepts and pays out deposits such as banks. The form is different.
 図27は、第4の実施の形態の自動取引装置の外観を示す図である。自動取引装置400は、操作画面481、紙幣入出部482a、硬貨入出部482b、通帳受付部483、受け付けるカード受付部484、レシート発行部485、指紋読み取り部486、スピーカ487を有する。 FIG. 27 is a diagram illustrating an appearance of the automatic transaction apparatus according to the fourth embodiment. The automatic transaction apparatus 400 includes an operation screen 481, a bill input / output unit 482 a, a coin input / output unit 482 b, a passbook receiving unit 483, a receiving card receiving unit 484, a receipt issuing unit 485, a fingerprint reading unit 486 and a speaker 487.
 操作画面481は、取引の内容を示す画像や利用者を案内するメッセージを含む画像等を表示する表示画面および利用者の入力を受け付けるタッチパネルを有する。紙幣入出部482aは、利用者の預金の受け入れおよび利用者の預金の払い出しのために紙幣を入出金する。硬貨入出部482bは、利用者の預金の受け入れおよび利用者の預金の払い出しのために硬貨を入出金する。通帳受付部483は、利用者の預金の受け入れ時、利用者の預金の払い出し時およびその他利用者の記帳希望時に通帳を受け付ける。カード受付部484は、利用者の利用時にキャッシュカード等を受け付ける。レシート発行部485は、利用者の利用時に利用内容等を記録したレシートを発行する。指紋読み取り部486は、利用時に利用者を指紋認証するために、利用者の指紋を読み取る。スピーカ487は、利用者に取引の状況や操作を案内する音声案内や警告音を出力する。 The operation screen 481 has a display screen for displaying an image showing the contents of a transaction, an image including a message for guiding the user, and a touch panel for receiving user input. The banknote deposit / withdrawal unit 482a deposits / withdraws banknotes for accepting user deposits and dispensing user deposits. The coin deposit / withdrawal unit 482b deposits / withdraws coins for accepting the deposit of the user and paying out the deposit of the user. The passbook accepting unit 483 accepts a passbook when accepting a user's deposit, when paying out a user's deposit, and when other users wish to book. The card reception unit 484 receives a cash card or the like when the user uses it. The receipt issuing unit 485 issues a receipt in which usage details are recorded when the user uses it. The fingerprint reading unit 486 reads the user's fingerprint in order to perform fingerprint authentication of the user at the time of use. The speaker 487 outputs voice guidance and warning sound for guiding the transaction status and operation to the user.
 以上のように、第4の実施の形態によれば、自動取引装置400において、指紋認証に加えて指紋認証以外の認証を行うことにより、自動取引装置400を利用するユーザに対するユーザ認証の精度が高まるのでセキュリティが向上する。 As described above, according to the fourth embodiment, by performing authentication other than fingerprint authentication in the automatic transaction apparatus 400, the accuracy of user authentication for the user using the automatic transaction apparatus 400 is improved. Security increases because it increases.
 また、指紋認証を、ワンチップICで構成された指紋認証部(図示省略)で行うことにより、指紋認証の処理が外部から隠ぺいされるので、クラックを防止することができ、安全性が高まる。 Also, by performing fingerprint authentication with a fingerprint authentication unit (not shown) configured with a one-chip IC, the fingerprint authentication process is concealed from the outside, so that cracks can be prevented and safety is improved.
 なお、上記の処理機能は、コンピュータによって実現することができる。その場合、情報処理装置100,200,300および自動取引装置400が有すべき機能の処理内容を記述したプログラムが提供される。そのプログラムをコンピュータで実行することにより、上記処理機能がコンピュータ上で実現される。 Note that the above processing functions can be realized by a computer. In that case, a program describing the processing contents of the functions that the information processing apparatuses 100, 200, 300 and the automatic transaction apparatus 400 should have is provided. By executing the program on a computer, the above processing functions are realized on the computer.
 処理内容を記述したプログラムは、コンピュータで読み取り可能な記録媒体に記録しておくことができる。コンピュータで読み取り可能な記録媒体には、磁気記録装置、光ディスク、光磁気記録媒体、半導体メモリ等がある。磁気記録装置には、HDD、フレキシブルディスク(FD)、磁気テープ(MT)等がある。光ディスクには、DVD(Digital Versatile Disc)、DVD-RAM、CD-ROM(Compact Disc - Read Only Memory)、CD-R(Recordable)/RW(ReWritable)等がある。光磁気記録媒体には、MO(Magneto - Optical disk)等がある。 The program describing the processing content can be recorded on a computer-readable recording medium. Examples of the computer-readable recording medium include a magnetic recording device, an optical disk, a magneto-optical recording medium, and a semiconductor memory. Magnetic recording devices include HDDs, flexible disks (FD), magnetic tapes (MT) and the like. Optical discs include DVD (Digital Versatile Disc), DVD-RAM, CD-ROM (Compact Disc-Read Only Memory), CD-R (Recordable) / RW (ReWritable), and the like. Magneto-optical recording media include MO (Magneto-Optical Disk).
 上記プログラムを流通させる場合には、例えば、そのプログラムが記録されたDVD、CD-ROM等の可搬型記録媒体が販売される。また、プログラムをサーバコンピュータに格納しておき、ネットワークを通じて、サーバコンピュータから他のコンピュータにそのプログラムを転送することもできる。 When distributing the above program, for example, a portable recording medium such as a DVD or CD-ROM in which the program is recorded is sold. It is also possible to store the program in a server computer and transfer the program from the server computer to another computer via a network.
 上記プログラムを実行するコンピュータは、例えば、可搬型記録媒体に記録されたプログラムまたはサーバコンピュータから転送されたプログラムを、自己の記憶装置に格納する。そして、コンピュータは、自己の記憶装置からプログラムを読み取り、プログラムに従った処理を実行する。なお、コンピュータは、可搬型記録媒体から直接プログラムを読み取り、そのプログラムに従った処理を実行することもできる。また、コンピュータは、サーバコンピュータからプログラムが転送されるごとに、逐次、受け取ったプログラムに従った処理を実行することもできる。 The computer that executes the program stores, for example, the program recorded on the portable recording medium or the program transferred from the server computer in its own storage device. Then, the computer reads the program from its own storage device and executes processing according to the program. The computer can also read the program directly from the portable recording medium and execute processing according to the program. Further, each time the program is transferred from the server computer, the computer can sequentially execute processing according to the received program.
 以上、開示の情報処理装置、認証プログラムおよび認証方法を、図示の実施の形態に基づいて説明したが、各部の構成は同様の機能を有する任意の構成のものに置換することができる。また、開示の技術に他の任意の構成物や工程が付加されてもよい。また、開示の技術は前述した実施の形態のうちの任意の2以上の構成を組み合わせたものであってもよい。 Although the disclosed information processing apparatus, authentication program, and authentication method have been described based on the illustrated embodiment, the configuration of each unit can be replaced with an arbitrary configuration having the same function. In addition, any other component or process may be added to the disclosed technology. Further, the disclosed technique may be a combination of any two or more of the above-described embodiments.
 上記については単に本発明の原理を示すものである。さらに、多数の変形、変更が当業者にとって可能であり、開示の技術は上記に示し、説明した正確な構成および応用例に限定されるものではなく、対応するすべての変形例および均等物は、添付の請求項およびその均等物による本発明の範囲とみなされる。 The above merely shows the principle of the present invention. In addition, many variations and modifications can be made by those skilled in the art, and the disclosed technology is not limited to the exact configurations and applications shown and described above, and all corresponding variations and equivalents are The scope of the invention is to be determined by the appended claims and their equivalents.
符号の説明Explanation of symbols
 1 情報処理装置
 1a 制御部
 1b 指紋情報取得部
 1c 識別情報取得部
 1d 認証制御部
 1e 指紋認証情報記憶部
 1f 識別認証情報記憶部
DESCRIPTION OF SYMBOLS 1 Information processing apparatus 1a Control part 1b Fingerprint information acquisition part 1c Identification information acquisition part 1d Authentication control part 1e Fingerprint authentication information storage part 1f Identification authentication information storage part

Claims (15)

  1.  ユーザを認証するために前記ユーザの指紋から取得される情報である指紋情報を取得する指紋情報取得部と、
     前記ユーザを認証するための情報であると共に前記指紋情報とは異なる情報である識別情報を取得する識別情報取得部と、
     前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記指紋情報と比較することにより前記ユーザを認証するための指紋認証情報を記憶する指紋認証情報記憶部と、
     前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記識別情報と比較することにより前記ユーザを認証する識別認証情報を記憶する識別認証情報記憶部と、
     前記指紋情報取得部によって取得された前記指紋情報と前記指紋認証情報記憶部に記憶された前記指紋認証情報とを比較して第1の認証を実行すると共に、前記識別情報取得部によって取得された前記識別情報と前記識別認証情報記憶部に記憶された前記識別認証情報とを比較して第2の認証を実行し、前記第1の認証と前記第2の認証とに成功した場合に、前記ユーザを正当であると認証する認証制御部と、
     前記認証制御部によって前記ユーザが正当であると認証された場合に、正当なユーザに許可された処理を実行する制御部と、
     を有することを特徴とする情報処理装置。
    A fingerprint information acquisition unit that acquires fingerprint information that is information acquired from the fingerprint of the user to authenticate the user;
    An identification information acquisition unit that acquires identification information that is information for authenticating the user and is different from the fingerprint information;
    A fingerprint authentication information storage unit for storing fingerprint authentication information to be used for authentication of whether or not the user is legitimate and to authenticate the user by comparing with the fingerprint information When,
    An identification authentication information storage unit for storing identification authentication information for authenticating the user by comparison with the identification information, which is information set in advance for use in authentication of whether or not the user is valid;
    The fingerprint information acquired by the fingerprint information acquisition unit is compared with the fingerprint authentication information stored in the fingerprint authentication information storage unit to perform a first authentication and acquired by the identification information acquisition unit When the second authentication is performed by comparing the identification information with the identification authentication information stored in the identification authentication information storage unit, and the first authentication and the second authentication are successful, An authentication control unit that authenticates the user as valid;
    A control unit that executes processing permitted to a legitimate user when the user is authorized by the authentication control unit;
    An information processing apparatus comprising:
  2.  前記識別認証情報は、予め取得された前記ユーザの筆跡に基づく情報であり、
     前記識別情報取得部は、前記ユーザによる前記筆跡の入力を受け付けて前記ユーザの前記筆跡を取得する筆跡入力部を有すると共に、前記筆跡入力部によって前記ユーザの前記筆跡を取得し、取得した前記筆跡に基づいて前記識別情報を取得することを特徴とする請求の範囲第1項記載の情報処理装置。
    The identification authentication information is information based on the user's handwriting acquired in advance,
    The identification information acquisition unit includes a handwriting input unit that receives the handwriting input by the user and acquires the handwriting of the user, acquires the handwriting of the user by the handwriting input unit, and acquires the handwriting The information processing apparatus according to claim 1, wherein the identification information is acquired based on the information.
  3.  前記識別情報取得部は、前記識別情報の入力を受け付ける識別情報入力部を有すると共に、前記識別情報入力部によって前記ユーザによって入力された前記識別情報を取得することを特徴とする請求の範囲第1項記載の情報処理装置。 The identification information acquisition unit includes an identification information input unit that receives an input of the identification information, and acquires the identification information input by the user by the identification information input unit. Information processing apparatus according to item.
  4.  前記識別情報は、識別情報記憶装置に予め記憶され、
     前記識別情報取得部は、前記識別情報記憶装置と電気的に接続される前記識別情報記憶装置接続部を有すると共に、前記識別情報記憶装置接続部によって接続された前記識別情報記憶装置から前記識別情報を取得することを特徴とする請求の範囲第1項記載の情報処理装置。
    The identification information is stored in advance in an identification information storage device,
    The identification information acquisition unit includes the identification information storage device connection unit electrically connected to the identification information storage device, and the identification information from the identification information storage device connected by the identification information storage device connection unit. The information processing apparatus according to claim 1, wherein:
  5.  前記認証制御部と前記指紋認証情報記憶部とは、同一のチップに搭載されていることを特徴とする請求の範囲第1項記載の情報処理装置。 The information processing apparatus according to claim 1, wherein the authentication control unit and the fingerprint authentication information storage unit are mounted on the same chip.
  6.  前記指紋認証情報記憶部と前記識別情報記憶部とは、同一のチップに搭載されていることを特徴とする請求の範囲第1項記載の情報処理装置。 The information processing apparatus according to claim 1, wherein the fingerprint authentication information storage unit and the identification information storage unit are mounted on the same chip.
  7.  前記認証制御部は、前記第1の認証に成功した後、前記指紋情報取得部に前記指紋情報の取得を実行させ、前記識別情報取得部によって取得された前記識別情報に基づいて前記第2の認証を実行することを特徴とする請求の範囲第2項記載の情報処理装置。 The authentication control unit, after succeeding in the first authentication, causes the fingerprint information acquisition unit to acquire the fingerprint information, and based on the identification information acquired by the identification information acquisition unit 3. The information processing apparatus according to claim 2, wherein authentication is executed.
  8.  前記指紋認証情報は、前記ユーザ毎に設定され、
     前記識別情報入力部は、複数の操作部を有し、
     前記識別情報は、前記操作部のそれぞれに対応付けられた情報であり、
     前記識別認証情報は、各前記識別情報と各前記ユーザの前記指紋認証情報とをそれぞれ関連付ける情報であり、
     前記認証制御部は、前記第2の認証として、前記ユーザによる前記操作部の操作に基づいて前記操作部に対応する前記識別情報を取得し、取得した前記識別情報に対して前記識別認証情報によって関連付けられた前記ユーザの前記指紋認証情報を取得し、前記第1の認証として、前記第2の認証に基づいて取得した前記指紋認証情報と前記指紋情報取得部によって取得された前記指紋情報とを比較することを特徴とする請求の範囲第3項記載の情報処理装置。
    The fingerprint authentication information is set for each user,
    The identification information input unit has a plurality of operation units,
    The identification information is information associated with each of the operation units,
    The identification authentication information is information that associates each identification information with the fingerprint authentication information of each user,
    The authentication control unit acquires the identification information corresponding to the operation unit based on the operation of the operation unit by the user as the second authentication, and uses the identification authentication information for the acquired identification information. The fingerprint authentication information of the associated user is acquired, and as the first authentication, the fingerprint authentication information acquired based on the second authentication and the fingerprint information acquired by the fingerprint information acquisition unit The information processing apparatus according to claim 3, wherein comparison is made.
  9.  前記識別情報入力部は、複数の操作部を有すると共に、前記ユーザによる前記操作部の操作による前記識別情報の入力を受け付けることによって前記識別情報を取得し、
     前記識別認証情報は、各前記識別情報と各前記ユーザの前記指紋認証情報とをそれぞれ関連付ける情報であり、
     前記認証制御部は、前記第2の認証として、前記識別情報取得部によって取得された前記識別情報に対して前記識別認証情報によって関連付けられた前記ユーザの前記指紋認証情報を取得し、前記第1の認証として、前記第2の認証に基づいて取得した前記指紋認証情報と前記指紋情報取得部によって取得された前記指紋情報とを比較することを特徴とする請求の範囲第3項記載の情報処理装置。
    The identification information input unit has a plurality of operation units, and acquires the identification information by receiving input of the identification information by operation of the operation unit by the user,
    The identification authentication information is information that associates each identification information with the fingerprint authentication information of each user,
    The authentication control unit acquires the fingerprint authentication information of the user associated by the identification authentication information with respect to the identification information acquired by the identification information acquisition unit as the second authentication, and the first authentication 4. The information processing according to claim 3, wherein the authentication is performed by comparing the fingerprint authentication information acquired based on the second authentication with the fingerprint information acquired by the fingerprint information acquisition unit. apparatus.
  10.  前記制御部は、前記ユーザによる前記アプリケーションの起動指示を受け付け、受け付けた前記起動指示に基づいて前記認証制御部に前記第1の認証と前記第2の認証とを実行させると共に、前記認証制御部によって前記ユーザが正当であると認証された場合に、前記アプリケーションを起動することを特徴とする請求の範囲第1項記載の情報処理装置。 The control unit receives an activation instruction of the application by the user, causes the authentication control unit to execute the first authentication and the second authentication based on the received activation instruction, and the authentication control unit The information processing apparatus according to claim 1, wherein the application is activated when the user is authenticated as valid.
  11.  前記指紋認証情報は、同一の前記ユーザの異なる複数の指の指紋に対してそれぞれ設定された指別指紋認証情報と、複数の前記指の前記指紋について予め定められた順序を示す順序情報とを有し、
     前記指紋認証は、前記ユーザの指紋を複数回取得した前記指紋情報について、前記指紋情報取得部によって取得された前記指紋情報が、前記指紋認証情報が有する前記指別指紋認証情報とすべて一致すると共に、前記指紋情報が取得された順序が、前記指紋認証情報が有する前記順序情報が示す順序と一致した場合に、成功したと判定されることを特徴とする請求の範囲第1項記載の情報処理装置。
    The fingerprint authentication information includes finger-specific fingerprint authentication information set for fingerprints of a plurality of different fingers of the same user, and order information indicating a predetermined order for the fingerprints of the plurality of fingers. Have
    In the fingerprint authentication, the fingerprint information acquired by the fingerprint information acquisition unit for the fingerprint information acquired a plurality of times for the user's fingerprint matches all the fingerprint authentication information included in the fingerprint authentication information. 2. The information processing according to claim 1, wherein when the order in which the fingerprint information is acquired matches the order indicated by the order information included in the fingerprint authentication information, the information processing is determined to be successful. apparatus.
  12.  前記識別認証情報記憶部は、前記識別認証情報を複数記憶し、
     前記識別認証情報と前記制御部により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶するアプリケーション起動情報記憶部を有し、
     前記認証制御部は、前記識別認証の実行時において、いずれの前記識別認証情報によって前記識別認証が成功したかを判断し、
     前記制御部は、前記アプリケーション起動情報記憶部に記憶されている前記アプリケーション起動情報と前記認証制御部による前記判断の結果とに基づいて、起動する前記アプリケーションを決定し、決定した前記アプリケーションを起動することを特徴とする請求の範囲第1項記載の情報処理装置。
    The identification authentication information storage unit stores a plurality of the identification authentication information,
    An application activation information storage unit that stores application activation information that associates the identification and authentication information with an application activated by the control unit;
    The authentication control unit determines whether the identification authentication is successful with which identification authentication information at the time of execution of the identification authentication,
    The control unit determines the application to be activated based on the application activation information stored in the application activation information storage unit and the result of the determination by the authentication control unit, and activates the determined application The information processing apparatus according to claim 1, wherein:
  13.  同一の前記ユーザの異なる複数の指の指紋と前記制御部により起動されるアプリケーションとを関連付けるアプリケーション起動情報を記憶するアプリケーション起動情報記憶部を有し、
     前記指紋認証情報は、同一の前記ユーザの異なる複数の前記指の前記指紋に対してそれぞれ設定された指別指紋認証情報を有し、
     前記認証制御部は、前記指紋認証の実行時において、前記ユーザのいずれの前記指の指紋によって前記指紋認証が成功したかを判断し、
     前記制御部は、前記アプリケーション起動情報記憶部に記憶されている前記アプリケーション起動情報と前記認証制御部による前記判断の結果とに基づいて、起動する前記アプリケーションを決定し、決定した前記アプリケーションを起動することを特徴とする請求の範囲第1項記載の情報処理装置。
    An application activation information storage unit that stores application activation information that associates fingerprints of different fingers of the same user with applications activated by the control unit;
    The fingerprint authentication information has finger fingerprint authentication information set for each of the fingerprints of the plurality of different fingers of the same user,
    The authentication control unit determines whether the fingerprint authentication is successful by the fingerprint of which finger of the user at the time of executing the fingerprint authentication,
    The control unit determines the application to be activated based on the application activation information stored in the application activation information storage unit and the result of the determination by the authentication control unit, and activates the determined application The information processing apparatus according to claim 1, wherein:
  14.  コンピュータを、
     ユーザを認証するために前記ユーザの指紋から取得される情報である指紋情報を取得する指紋情報取得部、
     前記ユーザを認証するための情報であると共に前記指紋情報とは異なる情報である識別情報を取得する識別情報取得部、
     前記指紋情報取得部によって取得された前記指紋情報と、指紋認証情報記憶部に記憶された前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記指紋情報と比較することにより前記ユーザを認証するための指紋認証情報とを比較して第1の認証を実行すると共に、前記識別情報取得部によって取得された前記識別情報と、識別認証情報記憶部に記憶された前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記識別情報と比較することにより前記ユーザを認証する識別認証情報とを比較して第2の認証を実行し、前記第1の認証と前記第2の認証とに成功した場合に、前記ユーザを正当であると認証する認証制御部、
     前記認証制御部によって前記ユーザが正当であると認証された場合に、正当なユーザに許可された処理を実行する制御部、
     として機能させることを特徴とする認証プログラム。
    Computer
    A fingerprint information acquisition unit for acquiring fingerprint information, which is information acquired from the fingerprint of the user to authenticate the user;
    An identification information acquisition unit for acquiring identification information that is information for authenticating the user and is different from the fingerprint information;
    The fingerprint information acquired by the fingerprint information acquisition unit and the information stored in advance in the fingerprint authentication information storage unit and used for authentication as to whether or not the user is valid, the fingerprint information Is compared with fingerprint authentication information for authenticating the user to execute first authentication, and the identification information acquired by the identification information acquisition unit and stored in the identification authentication information storage unit Information set in advance for use in authenticating whether the user is valid or not, and compared with the identification authentication information for authenticating the user by comparing with the identification information. An authentication control unit that executes authentication and authenticates the user as valid when the first authentication and the second authentication are successful;
    A control unit that executes processing permitted to a legitimate user when the user is authenticated by the authentication control unit;
    An authentication program characterized by causing it to function as
  15.  コンピュータがユーザを認証する認証方法であって、
     指紋情報取得部が、ユーザを認証するために前記ユーザの指紋から取得される情報である指紋情報を取得し、
     識別情報取得部が、前記ユーザを認証するための情報であると共に前記指紋情報とは異なる情報である識別情報を取得し、
     認証制御部が、前記指紋情報取得部によって取得された前記指紋情報と、指紋認証情報記憶部に記憶された前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記指紋情報と比較することにより前記ユーザを認証するための指紋認証情報とを比較して第1の認証を実行すると共に、前記識別情報取得部によって取得された前記識別情報と、識別認証情報記憶部に記憶された前記ユーザが正当であるか否かの認証に用いるために予め設定される情報であって、前記識別情報と比較することにより前記ユーザを認証する識別認証情報とを比較して第2の認証を実行し、前記第1の認証と前記第2の認証とに成功した場合に、前記ユーザを正当であると認証し、
     制御部が、前記認証制御部によって前記ユーザが正当であると認証された場合に、正当なユーザに許可された処理を実行することを特徴とする認証方法。
    An authentication method in which a computer authenticates a user,
    A fingerprint information acquisition unit acquires fingerprint information that is information acquired from the user's fingerprint to authenticate the user,
    An identification information acquisition unit acquires identification information that is information for authenticating the user and is different from the fingerprint information;
    The authentication control unit is information set in advance for use in authentication of the fingerprint information acquired by the fingerprint information acquisition unit and whether the user stored in the fingerprint authentication information storage unit is valid. And comparing the fingerprint information with the fingerprint authentication information for authenticating the user to execute the first authentication, and the identification information acquired by the identification information acquisition unit and the identification authentication Compared with identification authentication information for authenticating the user by comparing with the identification information, which is set in advance for use in authentication whether the user stored in the information storage unit is valid or not The second authentication is performed, and when the first authentication and the second authentication are successful, the user is authenticated as valid,
    An authentication method, wherein a control unit executes a process permitted to a valid user when the authentication control unit authenticates the user as valid.
PCT/JP2008/073083 2008-12-18 2008-12-18 Information processing device, authentication program, and authentication method WO2010070756A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/JP2008/073083 WO2010070756A1 (en) 2008-12-18 2008-12-18 Information processing device, authentication program, and authentication method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2008/073083 WO2010070756A1 (en) 2008-12-18 2008-12-18 Information processing device, authentication program, and authentication method

Publications (1)

Publication Number Publication Date
WO2010070756A1 true WO2010070756A1 (en) 2010-06-24

Family

ID=42268446

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2008/073083 WO2010070756A1 (en) 2008-12-18 2008-12-18 Information processing device, authentication program, and authentication method

Country Status (1)

Country Link
WO (1) WO2010070756A1 (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103761464A (en) * 2014-01-26 2014-04-30 金硕澳门离岸商业服务有限公司 Touch device and touch control method
CN104091105A (en) * 2014-07-03 2014-10-08 浪潮(山东)电子信息有限公司 User identity authentication method based on self-service banking system
JP2017167621A (en) * 2016-03-14 2017-09-21 株式会社リコー Information processing apparatus, information processing system, information processing method, and information processing program
USRE49669E1 (en) 2011-02-09 2023-09-26 Maxell, Ltd. Information processing apparatus

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006172180A (en) * 2004-12-16 2006-06-29 Konica Minolta Business Technologies Inc Authentication device and image forming device
JP2007164423A (en) * 2005-12-13 2007-06-28 Oki Electric Ind Co Ltd Personal identification system and personal identification method
JP2007172508A (en) * 2005-12-26 2007-07-05 Sony Corp Detachable storage device and authentication method
JP2008250934A (en) * 2007-03-30 2008-10-16 Toshiba Corp Information processor

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006172180A (en) * 2004-12-16 2006-06-29 Konica Minolta Business Technologies Inc Authentication device and image forming device
JP2007164423A (en) * 2005-12-13 2007-06-28 Oki Electric Ind Co Ltd Personal identification system and personal identification method
JP2007172508A (en) * 2005-12-26 2007-07-05 Sony Corp Detachable storage device and authentication method
JP2008250934A (en) * 2007-03-30 2008-10-16 Toshiba Corp Information processor

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
USRE49669E1 (en) 2011-02-09 2023-09-26 Maxell, Ltd. Information processing apparatus
CN103761464A (en) * 2014-01-26 2014-04-30 金硕澳门离岸商业服务有限公司 Touch device and touch control method
CN104091105A (en) * 2014-07-03 2014-10-08 浪潮(山东)电子信息有限公司 User identity authentication method based on self-service banking system
JP2017167621A (en) * 2016-03-14 2017-09-21 株式会社リコー Information processing apparatus, information processing system, information processing method, and information processing program

Similar Documents

Publication Publication Date Title
EP3497621B1 (en) Identifying one or more users based on typing pattern and/or behaviour
US9817965B2 (en) System and method for authentication with a computer stylus
Jansen Authenticating users on handheld devices
US7239728B1 (en) Fingerprint recognizing display and operating method thereof
Frank et al. Touchalytics: On the applicability of touchscreen input as a behavioral biometric for continuous authentication
JP4240502B2 (en) Technology for authenticating an object based on features extracted from the object
US20140029811A1 (en) User-authenticating, digital data recording pen
EP3388963B1 (en) Segment-based handwritten signature authentication system and method
KR20120080220A (en) Enhancing biometric security of a system
US20080172733A1 (en) Identification and verification method and system for use in a secure workstation
JP2007156790A (en) Authentication technique for authentication using a plurality of types of biometric information
CN103714457A (en) Method for validating a transaction
WO2010070756A1 (en) Information processing device, authentication program, and authentication method
JP2007164423A (en) Personal identification system and personal identification method
KR20110002968A (en) Method and system for providing financial trading service by using biometrics and portable memory unit therefor
JP5282477B2 (en) Authentication method, program, and authentication apparatus
JP4802670B2 (en) Cardless authentication system, cardless authentication method used in the system, and cardless authentication program
JP2003223421A (en) Information processing apparatus
JP2006277396A (en) Personal identification device
JP5028231B2 (en) Transaction authentication method
JP2003132032A (en) Personal authentication system, authentication device, personal authentication method, program and recording medium
Rahman et al. Movement pattern based authentication for smart mobile devices
JP2000003337A (en) Controller
JP2011107956A (en) Computer system
JP2006053820A (en) Automatic teller machine and online system equipped with the same

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08878924

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 08878924

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: JP