WO2019124103A1 - 端末機器、本人認証システムおよび本人認証方法 - Google Patents
端末機器、本人認証システムおよび本人認証方法 Download PDFInfo
- Publication number
- WO2019124103A1 WO2019124103A1 PCT/JP2018/044998 JP2018044998W WO2019124103A1 WO 2019124103 A1 WO2019124103 A1 WO 2019124103A1 JP 2018044998 W JP2018044998 W JP 2018044998W WO 2019124103 A1 WO2019124103 A1 WO 2019124103A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- information
- movement history
- terminal device
- unit
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/63—Location-dependent; Proximity-dependent
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/42—User authentication using separate channels for security data
- G06F21/43—User authentication using separate channels for security data wireless channels
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/322—Aspects of commerce using mobile devices [M-devices]
- G06Q20/3224—Transactions dependent on location of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/389—Keeping log of transactions for guaranteeing non-repudiation of a transaction
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4015—Transaction verification using location information
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4016—Transaction verification involving fraud or risk level assessment in transaction processing
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
- G06Q20/4093—Monitoring of device authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0853—Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/107—Network architectures or network communication protocols for network security for controlling access to devices or network resources wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/37—Managing security policies for mobile devices or for controlling mobile applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/40—Security arrangements using identity modules
- H04W12/47—Security arrangements using identity modules using near field communication [NFC] or radio frequency identification [RFID] modules
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/30—Services specially adapted for particular environments, situations or purposes
- H04W4/38—Services specially adapted for particular environments, situations or purposes for collecting sensor information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/60—Subscription-based services using application servers or record carriers, e.g. SIM application toolkits
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W64/00—Locating users or terminals or network equipment for network management purposes, e.g. mobility management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2111—Location-sensitive, e.g. geographical location, GPS
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2117—User registration
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3821—Electronic credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/02—Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
- H04W8/08—Mobility data transfer
Definitions
- the present invention relates to a person authentication technology.
- the present invention relates to a technique for authenticating a person using history information related to a user collected by a user-owned terminal.
- Patent Document 1 There is a person authentication technology using position information that can be acquired by a portable terminal.
- the present position information of the portable communication device is received from the portable communication device of the user, and information on the movement history of the portable communication device is collected. The contents of the response received from the user and the history are compared, and if the consistency between the two is confirmed, it is determined that the user is the person (abstract extract). .
- Patent Document 1 in order to confirm whether the movement history information acquired from the terminal is that of the user, the system side creates a question and employs a method in which the user answers. Convenience and security are high as the credentials used for authentication are automatically changed. However, when selecting an answer option, it is necessary to operate a button, which is time-consuming for the user.
- the present invention has been made in view of the above circumstances, and it is an object of the present invention to provide a technique with high security and high convenience in personal authentication via a portable terminal.
- the present invention is a terminal device, which measures the position of the terminal device at predetermined time intervals and stores the position information as position information, and movement using the position information of a predetermined period
- a movement history generation unit that generates a history and stores it as movement history information
- a registration processing unit that transmits the movement history information to the person authentication apparatus for registration, and after the registration processing unit transmits the person authentication apparatus
- a certification request unit for making a certification request to the personal identification device using the movement history information.
- the present invention is a person authentication system comprising a terminal device, an authentication interface device, and a person authentication device, wherein the terminal device measures the position of the terminal device at predetermined time intervals, and uses it as position information.
- the movement history generation unit generates a movement history by using the positioning unit to be stored, the position information for a predetermined period, and stores the movement history information as movement history information, and transmits the movement history information to the person authentication apparatus for registration.
- a registration processing unit; and an authentication request unit that makes an authentication request to the personal authentication device via the authentication interface device using the movement history information that the registration processing unit has sent to the personal authentication device.
- the personal authentication device is a storage processing unit for storing the movement history information transmitted from the terminal device; and the authentication interface device from the terminal device. The authentication unit performs authentication by determining whether the movement history included in the authentication request is stored by the storage processing unit when the request is received, and an authentication unit that returns an authentication result.
- the present invention is a person authentication method in a person authentication system including a terminal device, an authentication interface device, and a person authentication device, wherein movement history information is stored in the terminal device, and the movement history information is stored in the person authentication device. Is transmitted in the personal authentication device and stored as authentication information in the personal authentication device, and the movement history information is transmitted as the authentication request to the personal authentication device via the authentication interface device, and the authentication information in the personal authentication device. And an authentication step for receiving authentication using the authentication information, and newly generated movement history information is transmitted to the user authentication device via the authentication interface device, and the authentication information stored in the person authentication device is used as the movement history. And d) replacing the authentication information with information. To provide an authentication method.
- (A) is explanatory drawing for demonstrating the shop authentication process of 1st embodiment
- (b) is respectively an authentication information update process of 1st embodiment.
- (A) is a flowchart of the process registration process of the first embodiment
- (b) is a flowchart of the shop authentication process and the authentication information update process of the first embodiment, respectively.
- (A)-(c) is an explanatory view for explaining the flow of data of initial registration processing of the first embodiment, store authentication processing and authentication information update processing, respectively.
- (A) to (d) are explanatory diagrams for explaining the person authentication process of the first embodiment.
- (A) is the terminal ID of the first embodiment
- (b) is the movement history of the first embodiment
- (c) is the data configuration of the biological information of the first embodiment
- (A) to (d) are explanatory diagrams for explaining a movement history generation process using feature information according to the first embodiment.
- (A) And (b) is a flowchart and timing chart of movement history generation processing of a first embodiment, respectively. It is a whole block diagram of the user authentication system of 2nd embodiment.
- (A) And (b) is a functional block and hardware block diagram of a personal identification device of a second embodiment, respectively. It is an explanatory view for explaining a flow of data at the time of attestation of a 2nd embodiment.
- (A) is a functional block diagram of the terminal device of the third embodiment
- (b) is a functional block diagram of the personal identification device of the third embodiment.
- (A) is explanatory drawing for demonstrating the reference
- (b) is each an authentication process. It is a flowchart of the authentication process of 3rd embodiment.
- ⁇ First Embodiment A first embodiment of the present invention will be described.
- personal identification is performed using information of terminal devices such as mobile terminals and wearable terminals held by the user. Specifically, position information of the user is collected for a predetermined period, movement history information (hereinafter simply referred to as movement history) is generated from the collected information, and is shared with the person authentication apparatus (server). Then, this shared movement history is used for authentication as authentication information. At this time, the movement history is generated from the position information acquired while the authorized user holds the terminal device. Also, the authentication information is updated at a predetermined timing.
- movement history information hereinafter simply referred to as movement history
- FIG. 1 is an overall configuration diagram of a person authentication system 100 of the present embodiment.
- the person authentication system 100 includes a terminal device 200 and a provider system 300.
- the provider system 300 includes an identity authentication device 310 possessed by a provider or the like, a store device 330 provided in each store, and an internal network (N / W) 320 for transmitting and receiving data between the identity identification device 310 and the store device 330. And.
- a settlement server or the like may be provided.
- FIG. 1 illustrates the case where the shop device 330 includes two of the shop device 331 and the shop device 332, the number of the shop device 330 is not limited to this. Also, hereinafter, in the present specification, each shop device 331, 332 is represented by the shop device 330 when it is not necessary to distinguish.
- the terminal device 200 and the personal identification device 310 can transmit and receive data directly via the network 101.
- the terminal device 200 includes a central processing unit (CPU) 201, a system bus 202, a storage device 210, a communicator 220, an expansion I / F 227, an operation device 230, and a video processor 240. , An audio processor 250, and a sensor 260.
- CPU central processing unit
- the CPU 201 is a microprocessor unit that controls the entire terminal device 200.
- a system bus 202 is a data communication path for transmitting and receiving data between the CPU 201 and each operation block in the terminal device 200.
- the storage device 210 includes a read only memory (ROM) 211, a random access memory (RAM) 212, and an external memory interface (I / F) 213.
- ROM read only memory
- RAM random access memory
- I / F external memory interface
- the ROM 211 is a memory in which a basic operation program such as an operating system or the like and other operation programs are stored.
- a rewritable ROM such as an EEPROM (Electrically Erasable and Programmable Read Only Memory) or a flash ROM is used.
- operation setting values of the above-described program, and various programs and data necessary to realize each function of the present embodiment are also stored.
- the external memory I / F 213 is an interface that connects a memory card or another memory medium to transmit and receive data.
- the RAM 212 is a work area when executing a basic operation program and other operation programs.
- the ROM 211 and the RAM 212 may be integrated with the CPU 201.
- Each operation program stored in the ROM 211 can be updated and function expanded by, for example, download processing from each distribution server on the network.
- the communication device 220 includes a LAN (Local Area Network) communication device 221, a telephone network communication device 222, and an inter-terminal communication device 223.
- LAN Local Area Network
- the LAN communication device 221 is connected to the network 101 via an access point (AP) device by wireless connection by Wi-Fi (registered trademark) or the like, and transmits / receives data to / from other devices on the network 101.
- AP access point
- the telephone network communication unit 222 transmits and receives calls and data by wireless communication with a base station of a mobile telephone communication network.
- the inter-terminal communicator 223 is an I / F that implements communication between the terminal device 200 and the shop device 330.
- Examples of communication methods used include near field communication (NFC (Near Field Communication)), Bluetooth (registered trademark), and the like.
- NFC realizes two-way communication between devices equipped with an NFC chip in an extremely short distance of several centimeters to about one meter. For example, it corresponds to a service using a non-contact IC chip such as electronic money mounted on the terminal device 200.
- Bluetooth registered trademark
- the LAN communication unit 221, the telephone network communication unit 222, and the inter-terminal communication unit 223 each include a coding circuit, a decoding circuit, an antenna, and the like.
- the communication device 220 may further include a communication device that realizes infrared communication, and other communication devices.
- the expansion I / F 227 is an interface group for expanding the function of the terminal device 200.
- a video / audio I / F a USB (Universal Serial Bus) I / F, and the like are provided.
- the video / audio I / F performs input of a video signal / audio signal from an external video / audio output device, output of a video signal / audio signal to an external video / audio input device, and the like.
- the USB I / F is connected to another device such as a PC (Personal Computer) to transmit and receive data. Also, a keyboard or other USB device may be connected.
- the controller 230 receives an input of an operation instruction to the terminal device 200.
- a touch panel disposed overlapping the display 241 and an operation key in which button switches are arranged are provided. Note that only one of them may be used.
- the terminal device 200 may be operated using a keyboard or the like connected to the expansion I / F 227. Further, the terminal device 200 may be operated using a separate device connected by wired communication or wireless communication. Further, the touch panel function may be provided to the display 241.
- the video processor 240 includes a display 241, an image signal processor 242, and a camera 243.
- the display 241 is, for example, a display device such as a liquid crystal panel, displays the image data processed by the image signal processor 242, and provides the image data to the user of the terminal device 200.
- the image signal processor 242 includes a video RAM (not shown), and the display 241 is driven based on the image data input to the video RAM. Further, the image signal processor 242 performs format conversion, superimposing processing of a menu or other OSD (On-Screen Display) signal, and the like as necessary.
- the camera 243 acquires surroundings or an object as image data by converting light input from the lens into an electrical signal using an electronic device such as a CCD (Charge-Coupled Device) or a CMOS (Complementary Metal Oxide Semiconductor) sensor. Image capture device.
- CCD Charge-Coupled Device
- CMOS Complementary Metal Oxide Semiconductor
- the audio processor 250 includes a speaker 251, an audio signal processor 252, and a microphone 253.
- the speaker 251 provides the user of the terminal device 200 with the audio signal processed by the audio signal processor 252.
- the microphone 253 converts a user's voice or the like into voice data and inputs the voice data.
- the sensor 260 is a sensor group for detecting the state of the terminal device 200.
- a GPS (Global Positioning System) receiver 261 for example, a GPS (Global Positioning System) receiver 261, a gyro sensor 262, a geomagnetic sensor 263, an acceleration sensor 264, an illuminance sensor 265, a proximity sensor 266, and a biological information sensor 267 Prepare.
- GPS Global Positioning System
- the GPS receiver 261 receives signals from positioning satellites such as GPS satellites, and calculates position information.
- the acceleration sensor 264 detects the acceleration of the terminal device 200. In the present embodiment, the acceleration in the x, y, z axial directions of the device coordinate system set in the terminal device 200 is detected. The unit of the detected value is “G” (1.0 G is approximately 9.8 m / s 2 ) with reference to the gravitational acceleration.
- the biological information sensor 267 detects, for example, biological information of the user 209 such as a pulse wave and a heart rate.
- the position, inclination, direction, movement, and ambient brightness of the terminal device 200, the biological information of the user 209, and the like are detected by these sensors.
- the terminal device 200 may further include a pressure sensor or other sensor such as a pressure sensor.
- the position information is acquired by the GPS receiver 261.
- it may be acquired using the position information of the Wi-Fi AP device by the LAN communication device 221, and similarly, the position information of the base station and the telephone by the telephone network communication device 222 You may acquire by the positional information acquisition method using the propagation delay of a communication electromagnetic wave.
- these sensor groups do not necessarily have to be all.
- the configuration example of the terminal device 200 shown in FIG. 2 includes many configurations that are not essential to the present embodiment, the effects of the present embodiment are not impaired even if these configurations are not provided. . Further, a configuration not shown, such as a digital broadcast reception function and an electronic money settlement function, may be further added.
- FIG. 3 is a functional block diagram of the terminal device 200 of the present embodiment.
- the terminal device 200 includes a positioning unit 271, a movement history generation unit 272, a collation unit 273, a feature information collection unit 274, a communication unit 275, a registration processing unit 276, and an authentication request unit 279. Equipped with In addition, a position information storage unit 281, a movement history storage unit 282, a reference feature information storage unit 283, and a terminal, which are used by these units to execute processing and store data obtained as a result of the processing. And an ID storage unit 284.
- the positioning unit 271 processes a signal from the sensor 260 and calculates position information of the terminal device 200.
- the calculated position information is stored in the position information storage unit 281.
- the position information is stored, for example, in association with the time when the signal from the sensor 260 is acquired.
- position information received from the GPS receiver 261 is stored in the position information storage unit 281 as it is. Storage of position information is performed at predetermined time intervals.
- the feature information collecting unit 274 collects the signal from the sensor 260 as the feature information of the user 209 and passes it to the matching unit 273. Further, as initial processing to be described later, feature information is collected for a predetermined period according to an instruction from the user 209, and is stored in the reference feature information storage unit 283 as reference feature information at the time of matching. In the present embodiment, for example, information calculated from the acceleration detected by the acceleration sensor 264 is used as the feature information. In addition, a pulse wave, a heart rate, or the like detected by the biological information sensor 267 may be used.
- the verification unit 273 receives the feature information from the feature information collection unit 274, the verification unit 273 verifies the feature information with the reference feature information storage unit 283, and outputs the verification result to the movement history generation unit 272.
- the movement history generation unit 272 generates a movement history using the position information stored in the position information storage unit 281.
- the movement history information is generated in synchronization with the timing at which the result indicating the collation success is received from the collation unit 273. Details of the generation will be described later.
- the generated movement history is stored in the movement history storage unit 282.
- the communication unit 275 transmits and receives data to and from an external device via the communication device 220.
- a set of the movement history stored in the movement history storage unit 282 and the terminal identification information (terminal ID) stored in the terminal ID storage unit 284 is transmitted as authentication information. Also, information such as an authentication result is received from the outside.
- the terminal ID is identification information that uniquely identifies each terminal device 200, and is assigned to each terminal device 200 in advance.
- the authentication information may be transmitted for registration in the personal identification device 310 or may be transmitted for authentication.
- the registration processing unit 276 notifies the communication unit 275 to that effect.
- the communication unit 275 receives the notification, and in the case of transmission for registration, generates header information and adds it to transmission data so that it can be determined that transmission for registration is performed.
- the authentication information transmitted for registration is called registration authentication information.
- the registration processing unit 276 determines whether transmission for registration is performed according to transmission timing or according to an instruction from the user 209 via the operation device 230 or the display 241.
- the registration processing unit 276 may notify the communication unit 275 to that effect or may not notify anything. .
- the authentication request unit 279 uses the movement history stored in the movement history storage unit 282 to issue an authentication request to the personal identification device 310 via the shop device 330.
- the authentication request is executed, for example, when communication between the shop device 330 and the terminal is performed.
- the CPU 201 loading a program stored in advance in the ROM 211 into the RAM 212 and executing it.
- the position information storage unit 281, the movement history storage unit 282, the reference feature information storage unit 283, and the terminal ID storage unit 284 are provided in, for example, the ROM 211 or an external memory.
- data necessary for each function to execute, intermediate data generated during execution, and data generated as a result of execution are also stored in the ROM 211 or an external memory or the like.
- FIG. 4A is a functional block diagram of the personal identification device 310.
- the personal identification device 310 includes a communication unit 311, a storage processing unit 312, and an authentication unit 313.
- the authentication information storage unit 314 further stores authentication information.
- FIG. 4B is a hardware configuration diagram of the personal identification device 310.
- the personal identification device 310 is an information processing device including a CPU 321, a memory 322, a storage device 323, and a communication device 324.
- a communication unit 324 for example, a LAN communication unit 325 is provided.
- the LAN communication unit 325 realizes communication via the internal network 320 and the network 101.
- the communication unit 311 controls transmission and reception of data with an external device via the communication unit 324. Further, in the present embodiment, it is determined whether the received authentication information is registration authentication information. The determination is performed based on header information of the received data. Then, if it is determined that it is registration authentication information, it is delivered to the storage processing unit 312. In other cases, it passes to the authentication unit 313.
- the storage processing unit 312 stores registered authentication information, that is, a combination of a movement history and a terminal ID, transmitted from each terminal device 200 in the authentication information storage unit 314 as authentication information.
- the authentication unit 313 When the authentication unit 313 receives an authentication request from the shop device 330 via the communication unit 311, the authentication unit 313 performs authentication, and sends the authentication result back to the shop device 330 as the request source.
- the authentication request a pair of the movement history and the terminal ID is received from the shop device 330.
- the authentication unit 313 performs authentication by collating the set of the received movement history and terminal ID with the authentication information stored in the authentication information storage unit 314. If the two match, the authentication is determined to be successful. If the two do not match, the authentication is determined to be unsuccessful.
- Each function of person authentication apparatus 310 is realized by CPU 321 loading a program stored in storage device 323 into memory 322 and executing it. Further, the authentication information storage unit 314 is provided, for example, in the storage device 323 or the like.
- the store device 330 provided in the store of the present embodiment will be described.
- the shop device 330 of the present embodiment transmits the authentication information to the user authentication device 310 and receives authentication.
- the store device 330 is configured by an information processing apparatus including a CPU 341, a memory 342, a storage device 343, and a communicator 344.
- the communication unit 344 includes a LAN communication unit 345 and an inter-terminal communication unit 346.
- the LAN communication unit 340 realizes communication with the user authentication device 310 via the internal network 320. Also, the inter-terminal communicator 346 realizes transmission and reception of data with the terminal device 200.
- FIG. 5A is a schematic view of the flow of the person authentication process of the present embodiment.
- step S1001 an initial registration process is performed (step S1001), and then authentication is performed as a shop authentication process (step S1002) via the shop device 330 in a shop or the like.
- step S1003 when the authentication is successful (step S1003; Yes), authentication information update processing for updating authentication information is performed (step S1004). If the authentication fails in step S1003, for example, the terminal device 200 notifies the user 209 to that effect, and ends the process. The details of each process will be described below.
- the initial registration process is a process of registering authentication information from the terminal device 200 in the personal identification device 310, as shown in FIG. 5 (b).
- the initial registration process is performed before performing the authentication process.
- the movement history generation unit 272 generates the movement history 5a from the position information 4a stored in the position information storage unit 281.
- the generated combination of the movement history 5a and the terminal ID 1a is transmitted as the registration authentication information to the principal authenticating device 310 via the network 101.
- the storage processing unit 312 associates the movement history 5a and the terminal ID 1a with the authentication information storage unit 314, and registers them as authentication information.
- the positioning unit 271 continues collecting position information unless the user 209 instructs to cancel the instruction.
- the user 209 receives the authentication in the store device 330 (331) provided in the store or the like.
- the user 209 requests authentication by holding the terminal device 200, for which the initial registration process has been performed in advance, over the store device 331 or the like.
- the authentication request unit 279 transmits the movement history 5a and the terminal ID 1a to the store device 331 as authentication information. Transmission is performed using, for example, inter-terminal communication such as near field communication.
- the communication device 344 of the store device 331 When the communication device 344 of the store device 331 receives the authentication information, the communication device 344 transfers the authentication information to the user authentication device 310 via the internal network 320. Then, in the personal identification device 310, the authentication unit 313 performs authentication using the authentication information registered in the authentication information storage unit 314, and returns the result to the store device 331. In addition, the shop device 331 sends the authentication result back to the terminal device 200 of the transmission source.
- the authentication information update process is a process of updating the authentication information stored in the person authentication apparatus 310 when the authentication through the shop device 331 is successful.
- a new movement history 5b is generated using the position information 4b collected so far. Then, together with the terminal ID 1a, the authentication information is transmitted as the new registered authentication information to the person authentication apparatus 310 through the shop device 331.
- the movement history generation unit 272 generates the movement history 5b from the position information 4b stored in the position information storage unit 281. Then, in accordance with an instruction from the registration processing unit 276, the set of the generated movement history 5b and the terminal ID 1a is transmitted to the shop device 331 as new registration authentication information. Transmission is performed by, for example, inter-terminal communication.
- the registration processing unit 276 determines that the transmission is for transmission and notifies the communication unit 275.
- the store apparatus 331 transmits the received new registration authentication information to the person authentication apparatus 310 via the internal network 320.
- the storage processing unit 312 updates the authentication information by registering the movement history 5b and the terminal ID 1a in the authentication information storage unit 314 as authentication information. .
- FIG. 7 (a) The process flow of the initial registration process is shown in FIG. 7 (a).
- the positioning unit 271 collects the position information 4a for a predetermined period (step S1101), and stores the position information 4a in the position information storage unit 281.
- the movement history generation unit 272 generates the movement history 5a from the generated position information 4a (step S1102), and stores the movement history 5a in the movement history storage unit 282.
- the registration processing unit 276 causes the communication unit 275 to transmit the movement history 5a together with the terminal ID 1a as the registration authentication information to the principal authenticating device 310 (step S1103).
- the communication unit 275 adds, to the transmission data, header information indicating that it is registration authentication information.
- the storage processing unit 312 stores the received registered authentication information (the movement history 5a and the terminal ID 1a) in the authentication information storage unit 314 (step S1201).
- FIG. 7 (b) A processing flow of the store authentication process and the authentication information update process is shown in FIG. 7 (b).
- the positioning unit 271 continues collecting the position information 4b (step S1301).
- the authentication request unit 279 sends the authentication information (the movement history 5a and the terminal ID 1a) to the store device 330 from the terminal device 200 to the store device 330. It transmits (step S1302).
- the movement history 5a to be transmitted is data stored in the movement history storage unit 282 at the time of initial registration. Also, transmission is performed using, for example, the inter-terminal communicator 223.
- the shop equipment 330 receives the authentication information (the movement history 5a and the terminal ID 1a) via the inter-terminal communicator 346, and transmits it to the principal authenticating device 310 via the LAN communication unit 345 (step S1401). Transmission from the store device 330 to the personal identification device 310 is performed, for example, via the internal network 320.
- the authentication unit 313 checks the authentication information stored in the authentication information storage unit 314 for authentication. (Step S1502).
- the transmitted authentication result is either authentication success or authentication failure.
- the shop device 330 transmits the authentication result to the terminal device (step S1402).
- the terminal device 200 receives the authentication result (step S1303).
- the authentication is successful, for example, the process proceeds to payment processing and the like.
- the user is notified to that effect.
- the notification to the user is performed, for example, by displaying a message on the display 241.
- the movement history generation unit 272 when the result received in step S1303 is authentication success, the movement history generation unit 272 generates the movement history 5b using the position information 4b collected up to that point (steps) S1304). Then, the movement history storage unit 282 stores the newly generated movement history 5b in the movement history storage unit 282 and transmits the movement history 5b to the shop device 330 (step S1305). The movement history 5 b is transmitted to the shop device 330 as new registration authentication information together with the terminal ID 1 a. The transmission is performed via the inter-terminal communicator 223, 246.
- the store device 330 transmits the received new registration authentication information (the movement history 5b and the terminal ID 1a) to the personal identification device 310 (step S1404).
- the storage processing unit 312 updates the authentication information stored in the authentication information storage unit 314 with the newly received registration authentication information (step S1504). At this time, the storage processing unit 312 extracts the authentication information having the same terminal ID 1 a and replaces (overwrites) the newly transmitted authentication information.
- the terminal device 200 returns to step S1301, and continues collecting position information.
- registration authentication information (the movement history 5a and the terminal ID 1a) is directly transmitted to the principal authenticating device 310.
- authentication information (the movement history 5a and the terminal ID 1a) or registration authentication Information (the movement history 5 b and the terminal ID 1 a) is transmitted to the person authentication apparatus 310 via the shop device 330.
- the user 209 performs initial registration processing before the user authentication processing of the present embodiment is performed in a store or the like.
- the initial registration process is performed, for example, at the home of the user 209 or the like.
- the user 209 carries the terminal device 200 subjected to the initial registration process, and goes to the store. Then, the terminal device 200 is held over the store device 331 or the like. Thereby, the terminal device 200 transmits the movement history 5a stored therein and the terminal ID 1a as the authentication information to the shop device 331, and requests authentication.
- the user 209 continues collecting location information while reaching a store to be authenticated.
- the store device 331 transmits authentication information to the personal identification device 310 and receives authentication.
- the terminal device 200 When the authentication is successful, as shown in FIG. 9C, the terminal device 200 generates a new movement history 5b from the position information accumulated after the generation of the movement history. Then, the new movement history 5b is stored in its own movement history storage unit 282, and is transmitted to the store device 331 as registration authentication information together with the terminal ID 1a.
- the store device 331 transfers the new registration authentication information (the movement history 5 b and the terminal ID 1 a) to the personal identification device 310. Then, in the personal identification device 310, the authentication information registered in association with the terminal ID 1a is updated.
- the store device 332 of the store uses the movement history 5b newly stored in the movement history storage unit 282, as shown in FIG. Perform authentication request, update authentication information, etc.
- the authentication request unit 279 may perform processing to confirm the legitimacy of the user 209 before the store authentication processing. That is, the terminal device 200 further includes an identification section, and the identification section confirms whether or not the user 209 is the user 209 registered in advance, and after confirming the identification, performs store authentication processing. .
- personal identification by the personal identification unit may use, for example, biometric information such as a fingerprint. Also, knowledge information such as a password may be used.
- the terminal device 200 is described to generate the movement history after receiving the authentication result, but the timing of movement history generation is not limited to this.
- the movement history may be generated independently of the authentication process. For example, as described later, each time position information is collected, its correctness may be determined, and if it is correct, it may be stored as movement information.
- the movement history storage unit can be distinguished from the movement history already registered in the user authentication device 310 and the movement history (newly used movement history) newly generated and registered next. It memorizes to 282.
- the terminal ID 1a includes type name information 411 for specifying the type of the terminal, and a serial number 412.
- the terminal ID 1a is not limited to this. It may be information that can uniquely identify each terminal device 200. Also, the terminal ID 1a may be inserted into transmission data as header information, for example.
- the movement history 5a is, for example, time-series data of position information measured in a predetermined period. That is, the movement history 5a includes a predetermined number of position information. As shown in the figure, the movement history 5a includes, for each piece of position information, a number 421 specifying the position information, a date and time 422 when the position information is acquired, and position information 423.
- the movement history 5a is not limited to this.
- a hash value of each piece of position information may be calculated, and may be time-series data of the hash value.
- the order of the transition of the measured position information may be rearranged based on a predetermined rule and used as the movement history.
- the movement history generation unit 272 generates a movement history from the position information collected by the positioning unit 271 for a predetermined period. At this time, in the present embodiment, only the position information collected while holding the terminal device 200 is adopted for generation of movement history by the valid user 209 of the terminal device 200.
- whether or not the user is a valid user 209 is determined using feature information of the user 209 registered in advance.
- the feature information for example, information on walking such as the user's pace frequency, stride, walking speed, and the like is used. These pieces of information are calculated from, for example, acceleration information of a predetermined period acquired by the acceleration sensor 264.
- the pace is estimated from the change in the acceleration waveform when the user 209 walks. Also, the stride is estimated by combining the estimated pace and the position information acquired by the positioning unit 271.
- the feature information collection unit 274 collects predetermined feature information, and stores the reference feature information as reference feature information 50a at the time of collation. Register in section 283.
- the reference feature information 50a includes, for example, a pace frequency 431, a stride 432, and a walking speed 433.
- the reference feature information 50a may be, for example, waveform data itself.
- the movement history generation unit 272 After registering the reference feature information 50a, the movement history generation unit 272 generates a movement history using the position information acquired while the valid user 209 is possessed.
- the feature information collection unit 274 acquires feature information at predetermined time intervals. Then, the matching unit 273 matches the acquired feature information with the reference feature information 50a stored in the reference feature information storage unit 283, and determines the presence or absence of the consistency.
- the movement history generation unit 272 calculates a movement history using the collation result of the collation unit 273.
- FIG. 12A is a process flow of the movement history generation process of the present embodiment.
- the present process is performed at a predetermined time interval ⁇ t.
- the positioning unit 271 collects position information at time intervals shorter than ⁇ t, and stores the position information in the position information storage unit 281 in association with the collection time.
- the feature information collection unit 274 collects feature information (step S1601).
- the collation unit 273 collates the collected feature information with the reference feature information 50a stored in the reference feature information storage unit 283 (step S1602).
- the matching unit 273 determines that the valid user 209 is possessed. And it compares with the last collation result, and it is discriminate
- the movement history generation unit 272 reverses the generation of the movement history and the non-generation state (step S1605), stores the present collation result, and ends the processing. That is, if the movement history is generated, generation of the movement history is stopped, and if generation of the movement history is stopped, generation of the movement history is started.
- the movement history generation unit 272 is next determined that the valid user 209 is not possessed. Continue moving history generation until. Also, once it is determined that the valid user 209 is not possessed, generation of movement history is suspended until it is subsequently determined that the valid user 209 is possessed. That is, as described in step S1605, the generation history of the movement history and the non-generation state are reversed according to the reversal of the comparison result.
- FIG. 12B is a timing chart showing changes in the verification timing (matching, non-matching) by the matching unit 273, the matching result (matching, non-matching), and movement history generation / non-generation state.
- the collation unit 273 collates the acquired feature information with the reference feature information at a predetermined time interval ⁇ t. Then, when there is a change in the collation result, the movement history generation unit 272 is notified.
- the collation unit 273 does not notify the movement history generation unit 272 of the collation result.
- the movement history generation unit 272 continues the state as it is because there is no notification. For example, if a movement history is being generated, generation continues. On the other hand, when generation of movement history is stopped, the stopped state is continued as it is.
- the matching result indicates non-coincidence.
- the matching unit 273 since the matching result has changed from the matching result of the second match, the matching unit 273 notifies the movement history generating unit 272.
- the movement history generation unit 272 receives the notification and reverses the state. That is, in this case, while the movement history has been generated up to now, the generation of the movement history is stopped.
- the verification unit 273 notifies the movement history generation unit 272.
- the movement history generation unit 272 receives the notification and determines the state. That is, in this case, the generation of the movement history is started while the generation of the movement history is stopped until now.
- the movement history generation unit 272 of the present embodiment generates a movement history from the position information only during a period when it is determined that the valid user 209 is possessed. For this reason, the movement history of the person who is the valid user 209 can be collected with high accuracy.
- the feature information is not limited to this.
- the terminal device 200 when the terminal device 200 is a watch-type device, as shown in FIG. 11D, it may be, for example, a pulse wave signal.
- the pulse wave signal includes, for example, a pulse wave sensor as a biological information sensor 267, and is acquired by the pulse wave sensor.
- the movement history itself generated from the position information, which is registered in advance by the user 209, is used for the user authentication of the user 209. For this reason, personal identification can be performed using unique information of the terminal holder.
- the burden on the personal identification device 310 is also small, and the burden and labor of the user 209 operating the terminal device 200 are also small.
- the movement history is registered in the personal identification device 310 in association with the identification information (terminal ID) of the terminal device 200. Therefore, for example, even if only movement history information is copied and transmitted from another terminal, authentication does not succeed. Therefore, the safety is high.
- the movement history is generated using position information collected during a period in which the terminal device 200 is determined to be possessed by the valid user 209. Therefore, the reliability of the movement history used for personal identification is high.
- the movement history is continuously generated, and the movement history registered as authentication information in the personal identification device 310 is updated at a predetermined timing. Therefore, it is possible to provide a system that is resistant to leakage of authentication information.
- the update of the authentication information is performed in the shop device 330 after the authentication. Therefore, transmission and reception of data at the time of update is performed by communication between terminals. Communication between terminals is more secure than transmission and reception via a general network. Since the authentication information is updated using such highly secure communication, the security of the entire system is also high.
- the user authentication is performed using the movement history generated from the highly accurate position information of the user.
- the movement history is registered in advance in the personal identification device 310 together with information for specifying the terminal device 200. Further, the authentication information is updated at a predetermined timing.
- the movement history is updated using the store device 330 after the person authentication in the store is performed, but the present invention is not limited to this.
- the authentication information may be transmitted to the principal authenticating apparatus 310 via the network 101 at a predetermined timing, and may be updated.
- the predetermined timing is, for example, a predetermined time interval, or every time a predetermined amount of movement history is generated. In this case, at the time of transmission, predetermined security measures such as encryption are taken.
- the movement history may be generated each time a predetermined amount of position information (valid position information) obtained while the valid user 209 holds is stored. In this case, only the latest movement history may be stored as the update movement history.
- a predetermined amount of legal position information including the position information used at the time of the previous movement history generation May be secured. For example, this is a case where the period after the previous movement history generation is short and a sufficient amount of valid position information is not accumulated.
- a sufficient amount of valid position information is not stored, a new movement history may not be generated, and the movement history in the authentication information stored in the personal identification device 310 may not be updated.
- the terminal ID is transmitted as the authentication information together with the movement history, and the terminal ID 1a is also stored by the personal identification device 310.
- the authentication information storage unit 314 of the person authentication apparatus 310 may store only the movement history. In this case, the authentication unit 313 determines that the authentication is successful if the transmitted movement history is stored in the authentication information storage unit 314 regardless of the terminal device 200 of the transmission source.
- Second Embodiment a second embodiment of the present invention will be described.
- an individual authentication device is provided independently of each store.
- a personal identification device is provided for each store or store group. Then, the authentication information used for the personal authentication is distributed and shared among a plurality of personal authentication devices.
- the personal identification system 102 of the present embodiment will be described focusing on a configuration different from the first embodiment.
- the overall configuration of the person authentication system 102 of this embodiment is shown in FIG.
- the person authentication system 102 of this embodiment includes a terminal device 200 and a provider system 302. And the provider system 302 is equipped with the person-identifying apparatus 350 (351, 352, 353) arrange
- the individual authentication devices 350 are connected by an internal network 320. If there is no need to distinguish the individual authentication devices 351, 352, 353, in particular, the individual authentication device 350 will be represented.
- the terminal device 200 according to the present embodiment basically has the same configuration as the terminal device 200 according to the first embodiment, and thus the description thereof is omitted here.
- FIG. 14A is a functional block diagram of the personal identification device 350 of this embodiment. Further, FIG. 14B is a hardware configuration diagram of the personal identification device 350 of the present embodiment.
- the personal identification device 350 of this embodiment includes an inter-terminal communicator 326 in addition to the configuration of the personal identification device 310 of the first embodiment.
- the inter-terminal communicator 326 has the same configuration as the device of the same name provided in the terminal device 200. In this embodiment, it is used to transmit and receive data with the terminal device 200 in a store.
- the person authentication apparatus 350 of the present embodiment includes a sharing processing unit 315 in addition to the functional configuration similar to that of the first embodiment.
- a plurality of personal identification devices 350 are provided. Then, authentication information is shared among all the user authentication devices 350. Further, in the present embodiment, authentication for one authentication request is performed by the plurality of person authentication devices 350. When it is determined that the authentication is successful by a predetermined percentage or more, for example, a half or more of the user authentication devices 350, the entire system is determined to be a authentication success.
- the sharing processing unit 315 determines the transmission source after the communication unit 311 determines whether the received authentication information is registered authentication information.
- Whether the transmission source is the terminal device 200 or the other person authentication apparatus 350 is determined based on, for example, header information of transmission / reception data.
- the transmission source of the received authentication information or registration authentication information is the terminal device 200
- the communication unit 311 is instructed to transmit information or registration authentication information.
- the transmission source of the received authentication information or registration authentication information is the other person authentication apparatus 350
- the storage processing unit according to the determination result of whether or not it is registration authentication information as in the first embodiment. 312 or to the authentication unit 313.
- the sharing processing unit 315 causes the authentication unit 313 to perform authentication and causes the communication unit 311 to transmit the authentication result to the person authentication apparatus 350 of the transmission source.
- the authentication result of the authentication unit 313 of the own apparatus is added, and whether or not the authentication is successful by half or more of the person authentication apparatus 350 Determine. Then, if the authentication is successful with half or more, it is determined that the authentication is successful, and the communication unit 311 causes the terminal device 200 of the transmission source to transmit. On the other hand, when the authentication result of the authentication success is smaller than half, it is determined that the authentication fails, and the communication unit 311 causes the terminal device 200 of the transmission source to transmit.
- the terminal device 200 performs an initial registration process of registering authentication information in the personal identification device 350.
- the initial registration process is performed by transmitting registration authentication information to any one of the principal authentication devices 350 via the network 101 as in the first embodiment.
- the personal identification device 350 that has received the registration authentication information not only stores the received authentication information (the movement history 5a and the terminal ID 1a) in its own authentication information storage unit 314, but also sends it to another personal identification device 350. Send. Then, in the other person authentication apparatus 350, the received registration authentication information is stored in the authentication information storage unit 314.
- the registration authentication information (the movement history 5a and the terminal ID 1a) of the terminal device 200 is shared among all of the person authentication devices 350.
- the personal identification device 352 transmits the authentication information (the movement history 5a and the terminal ID 1a) to the other personal identification devices 351 and 353 via the internal network 320.
- the other personal authentication devices 351 and 353 respectively perform authentication, and return the authentication result to the transmission source personal authentication device 352 via the internal network 320.
- the personal authentication device 352 determines the final authentication result using the own authentication result and the authentication results received from the other personal authentication devices 351 and 353, and sends the final authentication result back to the request source terminal device 200.
- the initial registration process may be performed using terminal-to-terminal communication in a specific store having the user authentication device 350.
- authentication information at the time of initial registration processing is transmitted and received by inter-terminal communication. This further enhances the safety.
- a plurality of personal authentication devices 350 having the same configuration as the first embodiment are provided. For this reason, according to this embodiment, the same effect as that of the first embodiment can be obtained. Furthermore, in the present embodiment, a plurality of personal authentication devices 350 are provided to share authentication information. In this way, at the time of authentication, consensus is established between multiple devices, and mutual verification is performed. Therefore, the reliability is improved.
- the ratio of the person authentication apparatus 350 that succeeded in authentication when determining that the authentication is successful is not limited to this, and can be set freely. For example, it may be configured to determine that the authentication is successful only when all the authentication devices 350 have succeeded.
- the personal identification device 350 is disposed for each store has been described as an example in the above embodiment, the present invention is not limited to this configuration.
- the personal identification device 350 may be disposed, for example, for each of several store groups.
- position information of the base station 105 of the mobile phone network is used as position information of the third party.
- the present embodiment will be described focusing on a configuration different from the first embodiment.
- the overall configuration of the user authentication system 100 of the present embodiment is basically the same as that of the first embodiment. Also, the hardware configuration and functional blocks of each component are basically the same as in the first embodiment.
- the terminal device 200 has a configuration for acquiring position information of a third party. Further, the personal identification device 310 is configured to determine the legitimacy of the third party's position information.
- FIG. 16A is a functional block of the terminal device 203 of this embodiment.
- the terminal device 203 of this embodiment is provided with the reference
- the reference information acquisition unit 277 acquires reference position information at timing when the positioning unit 271 acquires position information and stores the position information in the position information storage unit 281. And it matches with the positional information which the positioning part 271 acquired at the same timing, and memorize
- the reference position information acquired by the reference information acquisition unit 277 is, for example, the information of the base station 105 as described above.
- the reference information acquisition unit 277 acquires, as reference position information, information of the base station 105 used at the time of communication via the telephone network communication unit 222 in the communication unit 220.
- the reference position information to be acquired may be, for example, the position information of the base station 105 itself or identification information (base station ID) for specifying the base station.
- the reference information acquisition unit 277 stores a set of the position information 2a acquired at the same timing and the reference position information 40a in the reference information storage unit 285 as the reference information 500a.
- the reference information 500 repeats generation at a predetermined timing. Therefore, a plurality of reference information 500 including the position information 2 and the reference position information 40 is generated and stored in the reference information storage unit 285.
- reference information 500a (40a, 2a), reference information 500b (40b, 2b), and reference information 500c (40c, 2c) are registered is exemplified.
- the authentication request unit 279 adds the reference information 500 to the shop equipment in addition to the authentication information (the movement history 5a and the terminal ID 1a) of the first embodiment. Send to 330 Then, the shop device 330 transmits the received authentication information and the reference information 500 to the person authentication apparatus 310.
- the person authentication apparatus 319 further includes a reference information verification unit 316, as shown in FIG.
- the reference information verification unit 316 verifies the legitimacy of the reference information 500.
- the reference information verification unit 316 verifies whether the relationship between the position information 2 in the received reference information 500 and the reference position information 40 registered in association with each other is reasonable. For example, when the reference position information 40a is position information of the base station 105, it is verified whether the position information 2a is within the coverage area of the base station 105 specified by the reference position information 40a.
- the reference position information 40a is the base station ID of the base station 105, it is verified whether it is within the coverage area of the base station 105 specified by the ID.
- the correspondence information between the position information of each base station 105 and / or the base station ID and the like and the cover area is made available to the person authentication apparatus 310.
- the authentication unit 313 collates the received authentication information with the authentication information stored in the authentication information storage unit 314 (step S3101).
- step S3106 information indicating the authentication failure is sent back to the terminal device 200 of the transmission source (step S3106), and the process is ended.
- the reference information verification unit 316 analyzes each reference information 500 and verifies its legitimacy (step S3103). Here, it is determined whether or not the position information 2 is within the coverage area of the base station 105 specified by the reference position information 40 as described above. Then, if all the reference information 500 is in the cover area, it is determined that the information is valid (step S3104).
- step S3104 If it is determined in step S3104 that the information is valid, information indicating success in authentication is sent back to the transmission source terminal device 200 (step S3105), and the process ends.
- the position information of the base station 105 of the mobile phone is used as the reference information, but the reference information is not limited to this. It may be information that can be acquired by the terminal device 200, such as position information of other landmarks, and can be identified by the personal identification device 310 as the legitimacy of the information.
- each of the terminal device 200 and the personal identification device 310 has the same configuration as that of the first embodiment. Therefore, the same effect as the first embodiment can be obtained. Furthermore, the terminal device 200 according to the present embodiment collects reference information, and transmits the reference information and the authentication information to the person authentication apparatus 310. Then, the personal identification device 310 also determines the legitimacy of the reference information. For example, position information of a third party is used as the reference information.
- the present embodiment it can be determined whether the movement history transmitted from the terminal device 200 is actually obtained by the movement of the user 209 or not fake. Therefore, the reliability can be further improved.
- the authentication information is generated from the position information acquired by the positioning unit 271 in the above embodiment, the authentication information is not limited to this.
- a purchase history may be used.
- the purchase history may include, for example, purchase store information, purchase item information, purchase price information, and the like.
- the present invention is not limited to the embodiments described above, but includes various modifications.
- the above-described embodiment is for describing the present invention in an easy-to-understand manner, and is not necessarily limited to one having all the described configurations.
- part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment.
- each of the configurations, functions, processing units, processing means, etc. described above may be realized by hardware, for example, by designing part or all of them with an integrated circuit.
- control lines and information lines indicate what is considered to be necessary for the description, and not all control lines and information lines in the product are necessarily shown. In practice, almost all configurations may be considered to be mutually connected.
- Identity authentication system 101 Network 102: Identity authentication system 105: Base station 200: terminal device, 201: CPU, 202: system bus, 203: terminal device, 208: invalid user, 209: valid user, 210: storage device, 211: ROM, 212: RAM, 213: external memory I / F, 220: communicator, 221: LAN communicator, 222: telephone network communicator, 223: inter-terminal communicator, 227: extended I / F, 230: controller, 240: video processor, 241: display, 242: Image signal processor 243: camera 246: inter-terminal communication device 250: audio processor 251: speaker 252: audio signal processor 253: microphone 260: sensor 261: GPS receiver 262: gy
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Accounting & Taxation (AREA)
- Software Systems (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Computing Systems (AREA)
- Finance (AREA)
- Power Engineering (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
- Telephone Function (AREA)
Abstract
携帯端末を介した本人認証において、安全性が高く、さらに利便性の高い技術を提供する。本発明の端末機器200は、所定の時間間隔で端末機器200の位置を測位し、位置情報として蓄積する測位部271と、所定期間の位置情報を用いて移動履歴を生成し、移動履歴情報として記憶する移動履歴生成部272と、移動履歴情報を、本人認証装置に登録のために送信する登録処理部276と、登録処理部276が本人認証装置310に送信後の移動履歴情報を用いて、本人認証装置310に対して認証要求を行う認証要求部279と、を備える。
Description
本発明は、本人認証技術に関する。特に、ユーザ保有の端末で収集したユーザに係わる履歴情報を用いて本人認証を行う技術に関する。
携帯端末で取得できる位置情報を用いた本人認証技術がある。例えば、特許文献1には、「ユーザの携帯通信機器から、その携帯通信機器の現在位置情報を受信し、その携帯通信機器の移動履歴に関する情報を収集する。そして、この履歴の内容に関する質問を生成し、ユーザに提示する。ユーザから受け取った回答と履歴の内容を比較し、両者間の整合性が確認された場合、本人であると決定する(要約抜粋)。」技術が開示されている。
特許文献1に開示の技術では、端末から取得した移動履歴情報がユーザ本人のものかを確認するために、システム側が質問を作成し、ユーザが回答する方法を採用している。認証に用いるクレデンシャルが自動的に変更されるため、利便性も安全性も高い。しかし、答えの選択肢を選ぶ際にボタン操作を行う必要があり、ユーザにとって、手間がかかる。
本発明は、上記事情に鑑みてなされたもので、携帯端末を介した本人認証において、安全性が高く、さらに利便性の高い技術を提供することを目的とする。
上記課題を解決するため、本発明は、端末機器であって、所定の時間間隔で前記端末機器の位置を測位し、位置情報として蓄積する測位部と、所定期間の前記位置情報を用いて移動履歴を生成し、移動履歴情報として記憶する移動履歴生成部と、前記移動履歴情報を、本人認証装置に登録のために送信する登録処理部と、前記登録処理部が前記本人認証装置に送信後の前記移動履歴情報を用いて、前記本人認証装置に対して認証要求を行う認証要求部と、を備えることを特徴とする端末機器を提供する。
また、本発明は、端末機器と、認証インタフェース装置と、本人認証装置とを備える本人認証システムであって、前記端末機器は、所定の時間間隔で前記端末機器の位置を測位し、位置情報として蓄積する測位部と、所定期間の前記位置情報を用いて移動履歴を生成し、移動履歴情報として記憶する移動履歴生成部と、前記移動履歴情報を、前記本人認証装置に登録のために送信する登録処理部と、前記登録処理部が前記本人認証装置に送信後の前記移動履歴情報を用いて、前記認証インタフェース装置を介して前記本人認証装置に対して認証要求を行う認証要求部と、を備え、前記本人認証装置は、前記端末機器から送信された前記移動履歴情報を、保管する保管処理部と、前記端末機器から前記認証インタフェース装置を介して前記認証要求を受信した際、当該認証要求に含まれる前記移動履歴が前記保管処理部により保管されているか否かを判別することにより、認証を行い、認証結果を返す認証部と、を備えることを特徴とする本人認証システムを提供する。
本発明は、端末機器と、認証インタフェース装置と、本人認証装置とを備える本人認証システムにおける本人認証方法であって、端末機器において移動履歴情報を記憶するとともに、前記本人認証装置に当該移動履歴情報を送信し、当該本人認証装置において認証情報として保管する初期登録ステップと、前記認証インタフェース装置を介して前記移動履歴情報を認証要求として前記本人認証装置に送信し、前記本人認証装置において前記認証情報を用いて認証を受ける認証ステップと、新たに生成した移動履歴情報を、前記認証インタフェース装置を介して前記本人認証装置に送信し、前記本人認証装置において保管されている前記認証情報を当該移動履歴情報によって置き換える認証情報更新ステップと、を備えることを特徴とする本人認証方法を提供する。
本発明によれば、携帯端末を介した本人認証において、安全性が高く、さらに利便性の高い技術を提供できる。上記した以外の課題、構成および効果は、以下の実施形態の説明により明らかにされる。
以下、図面を参照しながら本発明の実施形態について説明する。以下、本明細書において、同一機能を有するものは、特に断らない限り、同一の符号を付し、繰り返しの説明は省略する。
<<第一の実施形態>>
本発明の第一の実施形態を説明する。本実施形態の本人認証システムでは、ユーザが保持するモバイル端末やウェアラブル端末などの端末機器の情報を用いて本人認証を行う。具体的には、所定期間、ユーザの位置情報を収集し、収集した情報から移動履歴情報(以下、単に移動履歴と呼ぶ。)を生成し、本人認証装置(サーバ)と共有する。そして、この共有する移動履歴を認証情報として認証に用いる。このとき、この移動履歴は、正当なユーザが端末機器を保持している間に取得した位置情報から生成される。また、認証情報は、所定のタイミングで、更新する。
本発明の第一の実施形態を説明する。本実施形態の本人認証システムでは、ユーザが保持するモバイル端末やウェアラブル端末などの端末機器の情報を用いて本人認証を行う。具体的には、所定期間、ユーザの位置情報を収集し、収集した情報から移動履歴情報(以下、単に移動履歴と呼ぶ。)を生成し、本人認証装置(サーバ)と共有する。そして、この共有する移動履歴を認証情報として認証に用いる。このとき、この移動履歴は、正当なユーザが端末機器を保持している間に取得した位置情報から生成される。また、認証情報は、所定のタイミングで、更新する。
まず、本実施形態の本人認証システム100の全体構成を説明する。図1は、本実施形態の本人認証システム100の全体構成図である。本人認証システム100は、端末機器200と、プロバイダシステム300と、を備える。
プロバイダシステム300は、プロバイダ等が有する本人認証装置310と、各店舗に備えられる店舗機器330と、本人認証装置310と店舗機器330との間でデータ送受信を行う内部ネットワーク(N/W)320と、を備える。なお、その他、図示はしないが、決済サーバ等を備えていてもよい。
図1では、店舗機器330は、店舗機器331と店舗機器332との2つを備える場合を例示するが、店舗機器330の数はこれに限定されない。また、以下、本明細書で、特に区別する必要がない場合は、各店舗機器331、332を、店舗機器330で代表する。
端末機器200と、本人認証装置310と、は、ネットワーク101で直接データを送受信できる。
[端末機器のハードウェア構成]
まず、端末機器200について説明する。端末機器200のハードウェア構成を図2に示す。本図に示すように、端末機器200は、CPU(Central Processing Unit)201と、システムバス202と、記憶装置210と、通信器220と、拡張I/F227と、操作器230と、ビデオプロセッサ240と、オーディオプロセッサ250と、センサ260とを備える。
まず、端末機器200について説明する。端末機器200のハードウェア構成を図2に示す。本図に示すように、端末機器200は、CPU(Central Processing Unit)201と、システムバス202と、記憶装置210と、通信器220と、拡張I/F227と、操作器230と、ビデオプロセッサ240と、オーディオプロセッサ250と、センサ260とを備える。
CPU201は、端末機器200全体を制御するマイクロプロセッサユニットである。システムバス202はCPU201と端末機器200内の各動作ブロックとの間でデータ送受信を行うためのデータ通信路である。
記憶装置210は、ROM(Read Only Memory)211と、RAM(Random Access Memory)212と、外部メモリインタフェース(I/F)213と、を備える。
ROM211は、オペレーティングシステムなどの基本動作プログラムやその他の動作プログラムが格納されるメモリである。ROM211として、例えば、EEPROM(Electrically Erasable and Programmable Read Only Memory)やフラッシュROMのような書き換え可能なROMが用いられる。また、上記プログラムの動作設定値、本実施形態の各機能を実現するために必要な各種のプログラムやデータも記憶される。
外部メモリI/F213は、メモリカードやその他のメモリ媒体を接続してデータの送受信を行うインタフェースである。
RAM212は、基本動作プログラムやその他の動作プログラム実行時のワークエリアである。
ROM211及びRAM212は、CPU201と一体構成であっても良い。
なお、ROM211に記憶された各動作プログラムは、例えば、ネットワーク上の各配信サーバからのダウンロード処理により更新及び機能拡張することができる。
通信器220は、LAN(Local Area Network)通信器221と、電話網通信器222と、端末間通信器223と、を備える。
LAN通信器221はWi-Fi(登録商標)等による無線接続によりアクセスポイント(AP)装置を介してネットワーク101に接続され、ネットワーク101上の他の装置とデータの送受信を行う。
電話網通信器222は移動体電話通信網の基地局との無線通信により、通話及びデータの送受信を行う。
端末間通信器223は、端末機器200と、店舗機器330との間の通信を実現するI/Fである。用いられる通信方式には、例えば、近距離無線通信(NFC(Near Field Communication))、Bluetooth(登録商標)等がある。NFCは、数センチからおよそ1メートル程度の極短距離で、NFCチップを搭載した機器間の双方向通信を実現する。例えば、端末機器200に搭載される電子マネーなどの非接触ICチップを利用したサービスに対応する。Bluetooth(登録商標)は、数mから数十m程度の距離の情報機器間で、電波を使い簡易な情報のやりとりを実現する。
LAN通信器221と、電話網通信器222と、端末間通信器223と、は、それぞれ、符号回路や復号回路、アンテナ等を備える。また、通信器220は、赤外線通信を実現する通信器や、その他の通信器を更に備えていても良い。
拡張I/F227は、端末機器200の機能を拡張するためのインタフェース群である。本実施形態では、映像/音声I/F、USB(Universal Serial Bus)I/F等を備える。映像/音声I/Fは、外部映像/音声出力機器からの映像信号/音声信号の入力、外部映像/音声入力機器への映像信号/音声信号の出力、等を行う。USBI/Fは、PC(Personal Computer)等の他の装置と接続してデータの送受信を行う。また、キーボードやその他のUSB機器の接続を行っても良い。
操作器230は、端末機器200に対する操作指示の入力を受け付ける。本実施形態では、ディスプレイ241に重ねて配置したタッチパネルおよびボタンスイッチを並べた操作キーを備える。なお、そのいずれか一方のみであっても良い。また、拡張I/F227に接続したキーボード等を用いて端末機器200の操作を行っても良い。また、有線通信又は無線通信により接続された別体の機器を用いて端末機器200の操作を行っても良い。また、タッチパネル機能はディスプレイ241が備えていてもよい。
ビデオプロセッサ240は、ディスプレイ241と、画像信号プロセッサ242と、カメラ243と、を備える。
ディスプレイ241は、例えば液晶パネル等の表示デバイスであり、画像信号プロセッサ242で処理した画像データを表示し、端末機器200のユーザに提供する。画像信号プロセッサ242は図示を省略したビデオRAMを備え、ビデオRAMに入力された画像データに基づいてディスプレイ241が駆動される。また、画像信号プロセッサ242は、必要に応じてフォーマット変換、メニューやその他のOSD(On-Screen Display)信号の重畳処理等を行う。カメラ243は、CCD(Charge-Coupled Device)やCMOS(Complementary Metal Oxide Semiconductor)センサ等の電子デバイスを用いてレンズから入力した光を電気信号に変換することにより、周囲や対象物を画像データとして取得する撮影装置である。
オーディオプロセッサ250は、スピーカ251と、音声信号プロセッサ252と、マイク253と、を備える。スピーカ251は、音声信号プロセッサ252で処理した音声信号を端末機器200のユーザに提供する。マイク253は、ユーザの声などを音声データに変換して入力する。
センサ260は、端末機器200の状態を検出するためのセンサ群である。本実施形態では、例えば、GPS(Global Positioning System)受信器261と、ジャイロセンサ262と、地磁気センサ263と、加速度センサ264と、照度センサ265と、近接センサ266と、生体情報センサ267と、を備える。
GPS受信器261は、GPS衛星等の測位衛星からの信号を受信し、位置情報を算出する。加速度センサ264は、端末機器200の加速度を検出する。本実施形態では、端末機器200に設定された機器座標系のx、y、z各軸方向の加速度を検出する。検出される値の単位は、重力加速度を基準とした「G」(1.0Gは約9.8m/s2)である。生体情報センサ267は、例えば、脈波、心拍数等のユーザ209の生体情報を検出する。
これらのセンサ群により、端末機器200の位置、傾き、方角、動き、及び周囲の明るさ、ユーザ209の生体情報等を検出する。また、端末機器200が、気圧センサ等、圧力センサ他のセンサを更に備えていても良い。なお、上述のように、位置情報は、GPS受信器261により取得する。しかし、GPS電波が入りにくい場所等では、LAN通信器221によりWi-FiのAP装置の位置情報を用いて取得してもよいし、同様に電話網通信器222により基地局の位置情報及び電話通信電波の伝搬遅延を用いた位置情報取得方法により取得してもよい。また、これらのセンサ群は、必ずしも全てを備えていなくてもよい。
なお、図2に示す端末機器200の構成例は、本実施形態に必須ではない構成も多数含んでいるが、これらが備えられていない構成であっても本実施形態の効果を損なうことはない。また、デジタル放送受信機能や電子マネー決済機能等、図示していない構成が更に加えられていても良い。
[端末機器の機能構成]
次に、本実施形態の端末機器200の機能構成について説明する。ここでは、本実施形態の本人認証処理に関する機能に主眼をおいて説明する。
次に、本実施形態の端末機器200の機能構成について説明する。ここでは、本実施形態の本人認証処理に関する機能に主眼をおいて説明する。
図3は、本実施形態の端末機器200の機能ブロック図である。本実施形態の端末機器200は、測位部271と、移動履歴生成部272と、照合部273と、特徴情報収集部274と、通信部275と、登録処理部276と、認証要求部279と、を備える。また、これらの各部が処理を実行するために用いたり、処理の結果得られるデータを格納したりする、位置情報記憶部281と、移動履歴記憶部282と、参照特徴情報記憶部283と、端末ID記憶部284と、を備える。
測位部271は、センサ260からの信号を処理し、端末機器200の位置情報を算出する。算出した位置情報は、位置情報記憶部281に記憶する。位置情報は、例えば、センサ260からの信号を取得した時刻に対応づけて記憶される。本実施形態では、例えば、センサ260として、GPS受信器261から受信する位置情報を、そのまま位置情報記憶部281に記憶する。位置情報の記憶は、所定の時間間隔で行う。
特徴情報収集部274は、センサ260からの信号を、ユーザ209の特徴情報として収集し、照合部273に受け渡す。また、後述する初期処理として、ユーザ209からの指示に従って、所定期間、特徴情報を収集し、照合時の参照特徴情報として、参照特徴情報記憶部283に記憶する。本実施形態では、特徴情報として、例えば、加速度センサ264が検出した加速度から算出した情報を用いる。また、生体情報センサ267で検出した、脈波、心拍数等を用いてもよい。
照合部273は、特徴情報収集部274から特徴情報を受信すると、参照特徴情報記憶部283と照合し、照合結果を移動履歴生成部272に出力する。
移動履歴生成部272は、位置情報記憶部281に記憶された位置情報を用いて、移動履歴を生成する。移動履歴情報は、照合部273から照合成功を意味する結果を受信したタイミングに同期して生成する。生成の詳細は、後述する。生成した移動履歴は、移動履歴記憶部282に記憶される。
通信部275は、通信器220を介した外部装置とのデータの送受信を行う。本実施形態では、所定のタイミングで、移動履歴記憶部282に記憶される移動履歴と、端末ID記憶部284に記憶される端末識別情報(端末ID)との組を、認証情報として送信する。また、認証結果等の情報を外部から受信する。なお、端末IDは、各端末機器200を一意に識別する識別情報であり、予め各端末機器200に付与される。
本実施形態では、認証情報は、本人認証装置310に登録するために送信される場合と、認証のために送信される場合とがある。登録処理部276は、送信する認証情報が、登録のために送信される場合、その旨、通信部275に通知する。
通信部275は、通知を受け、登録のための送信の場合、登録のための送信であることが判別可能なように、ヘッダ情報を生成し、送信データに付加する。以後、登録のために送信される認証情報を登録認証情報と呼ぶ。なお、登録処理部276は、送信タイミングにより、または、操作器230やディスプレイ241を介したユーザ209からの指示により、登録のための送信であるか否かを判別する。
なお、登録処理部276は、登録のための送信でない場合、すなわち、認証のための送信である場合は、通信部275にその旨、通知してもよいし、何も通知しなくてもよい。
認証要求部279は、移動履歴記憶部282に記憶される移動履歴を用いて、店舗機器330を介して本人認証装置310に対して認証要求を行う。認証要求は、例えば、店舗機器330と、端末間通信を行うことを契機に実行される。
これらの各機能は、CPU201が、ROM211に予め保存したプログラムを、RAM212にロードして実行することにより実現される。また、位置情報記憶部281と、移動履歴記憶部282と、参照特徴情報記憶部283と、端末ID記憶部284は、例えば、ROM211、または、外部メモリ等に設けられる。また、各機能が実行するために必要なデータ、実行中に生成される中間データ、実行の結果生成されるデータも、ROM211、または、外部メモリ等に格納される。
[本人認証装置]
次に、本人認証装置310のハードウェア構成および機能ブロックを説明する。
次に、本人認証装置310のハードウェア構成および機能ブロックを説明する。
図4(a)は、本人認証装置310の機能ブロック図である。本図に示すように、本人認証装置310は、通信部311と、保管処理部312と、認証部313と、を備える。また、認証情報を保管する認証情報保管部314をさらに備える。
図4(b)は、本人認証装置310のハードウェア構成図である。本人認証装置310は、CPU321と、メモリ322と、記憶装置323と、通信器324と、を備える情報処理装置である。本実施形態では、通信器324として、例えば、LAN通信器325を備える。LAN通信器325は、内部ネットワーク320およびネットワーク101を介した通信を実現する。
通信部311は、通信器324を介した外部装置とのデータの送受信を制御する。また、本実施形態では、受信した認証情報が、登録認証情報であるか否かを判別する。判別は、受信データのヘッダ情報により行う。そして、登録認証情報と判別された場合、保管処理部312に受け渡す。また、その他の場合、認証部313に受け渡す。
保管処理部312は、各端末機器200から送信される、登録認証情報、すなわち、移動履歴と端末IDとの組を、認証情報として認証情報保管部314に保管する。
認証部313は、通信部311を介して店舗機器330から認証要求を受信すると、認証を行い、要求元の店舗機器330に認証結果を返信する。本実施形態では、認証要求として、店舗機器330から、移動履歴と端末IDとの組を受信する。認証部313は、受信した移動履歴と端末IDとの組と、認証情報保管部314に保管される認証情報と照合し、認証を行う。両者が一致した場合、認証成功とし、不一致の場合、認証失敗とする。
本人認証装置310の各機能は、CPU321が、記憶装置323に格納されたプログラムを、メモリ322にロードして実行することにより実現される。また、認証情報保管部314は、例えば、記憶装置323等に設けられる。
[店舗機器]
次に、本実施形態の店舗に備えられる店舗機器330について説明する。本実施形態の店舗機器330は、端末機器200から認証要求として、認証情報を受け取ると、本人認証装置310に送信し、認証を受ける。店舗機器330は、図4(c)に示すように、CPU341と、メモリ342と、記憶装置343と、通信器344とを備える情報処理装置で構成される。通信器344は、LAN通信器345と、端末間通信器346と、を備える。
次に、本実施形態の店舗に備えられる店舗機器330について説明する。本実施形態の店舗機器330は、端末機器200から認証要求として、認証情報を受け取ると、本人認証装置310に送信し、認証を受ける。店舗機器330は、図4(c)に示すように、CPU341と、メモリ342と、記憶装置343と、通信器344とを備える情報処理装置で構成される。通信器344は、LAN通信器345と、端末間通信器346と、を備える。
LAN通信器340は、本人認証装置310との、内部ネットワーク320を介した通信を実現する。また、端末間通信器346は、端末機器200との間のデータの送受信を実現する。
[本人認証処理]
次に、本実施形態の本人認証処理の流れを説明する。図5(a)は、本実施形態の本人認証処理の流れの概略図である。
次に、本実施形態の本人認証処理の流れを説明する。図5(a)は、本実施形態の本人認証処理の流れの概略図である。
本図に示すように、本人認証処理では、初期登録処理を行い(ステップS1001)、その後、店舗等で店舗機器330を介して店舗認証処理(ステップS1002)として、認証を受ける。店舗認証処理において、認証が成功した場合(ステップS1003;Yes)、認証情報を更新する認証情報更新処理を行う(ステップS1004)。なお、ステップS1003で認証が失敗した場合は、例えば、端末機器200は、ユーザ209にその旨通知し、処理を終了する。以下、各処理について、詳細を説明する。
初期登録処理は、図5(b)に示すように、端末機器200から認証情報を本人認証装置310に登録する処理である。初期登録処理は、認証処理を行う前に実行される。本図に示すように、まず、端末機器200において、移動履歴生成部272が、位置情報記憶部281に記憶される位置情報4aから移動履歴5aを生成する。そして、登録処理部276の指示により、生成した移動履歴5aと端末ID1aとの組を、登録認証情報として、ネットワーク101を介して、本人認証装置310に送信する。
登録認証情報を受信した本人認証装置310では、保管処理部312が、認証情報保管部314に、移動履歴5aと端末ID1aとを対応づけて、認証情報として登録する。
なお、初期登録完了後、ユーザ209が、指示を中止の指示をしない限り、測位部271は、位置情報の収集を継続する。
店舗認証処理は、図6(a)に示すように、ユーザ209が、店舗等に備えられる店舗機器330(331)において、認証を受ける処理である。ユーザ209は、事前に初期登録処理を行った端末機器200を店舗機器331等にかざすことにより、認証を要求する。ここでは、認証要求部279は、移動履歴5aと、端末ID1aとを、認証情報として店舗機器331に送信する。送信は、例えば、近距離無線通信等の端末間通信を用いて行う。
店舗機器331の通信器344は、認証情報を受信すると、内部ネットワーク320を介して本人認証装置310に転送する。そして、本人認証装置310では、認証部313が、認証情報保管部314に登録されている認証情報を用いて認証を行い、結果を店舗機器331に返す。また、店舗機器331は、認証結果を送信元の端末機器200に返信する。
認証情報更新処理は、店舗機器331を介した認証が成功した場合、本人認証装置310内に保管される認証情報を更新する処理である。ここでは、それまでに収集した位置情報4bを用いて、新たな移動履歴5bを生成する。そして、端末ID1aとともに、店舗機器331を介して、新たな登録認証情報として、本人認証装置310に送信し、認証情報を更新する。
図6(b)に示すように、まず、端末機器200において、移動履歴生成部272が、位置情報記憶部281に記憶される位置情報4bから移動履歴5bを生成する。そして、登録処理部276の指示により、生成した移動履歴5bと端末ID1aとの組を、新たな登録認証情報として、店舗機器331に送信する。送信は、例えば、端末間通信により行う。
なお、登録処理部276は、このように、認証成功後、同じ店舗機器330を介して、新たな移動履歴5bを送信する場合、登録のための送信と判断し、通信部275に通知する。
店舗機器331は、受信した新たな登録認証情報を、内部ネットワーク320を介して本人認証装置310に送信する。
登録認証情報を受信した本人認証装置310では、保管処理部312が、認証情報保管部314に、移動履歴5bと端末ID1aとを対応づけて、認証情報として登録することにより、認証情報を更新する。保管処理部312は、例えば、同じ端末ID1aに対応づけて登録されている認証情報を抽出し、新たに送信された認証情報で、抽出した認証情報を置き換える。
初期登録処理の処理フローを、図7(a)に示す。
測位部271は、所定期間、位置情報4aを収集し(ステップS1101)、位置情報記憶部281に記憶する。
そして、移動履歴生成部272は、生成した位置情報4aから移動履歴5aを生成し(ステップS1102)、移動履歴記憶部282に記憶する。
ユーザ209からの指示に従って、登録処理部276は、通信部275に、移動履歴5aを、端末ID1aとともに、登録認証情報として、本人認証装置310へ送信させる(ステップS1103)。このとき、通信部275は、送信データに、登録認証情報であることを示すヘッダ情報を付加する。
本人認証装置310では、保管処理部312が、受信した登録認証情報(移動履歴5aおよび端末ID1a)を、認証情報保管部314に格納する(ステップS1201)。
店舗認証処理と、認証情報更新処理との、処理フローを図7(b)に示す。
上述のように、測位部271は、位置情報4bの収集を継続する(ステップS1301)。
位置情報4bの収集とは独立し、ユーザ209が店舗に到着すると、認証要求部279は、端末機器200から、店舗機器330へ、認証情報(移動履歴5aおよび端末ID1a)を、店舗機器330へ送信する(ステップS1302)。ここで、送信される移動履歴5aは、初期登録時に、移動履歴記憶部282に記憶されているデータである。また、送信は、例えば、端末間通信器223を用いて行う。
店舗機器330では、端末間通信器346を介して、認証情報(移動履歴5aおよび端末ID1a)を受け取り、LAN通信器345を介して、本人認証装置310へ送信する(ステップS1401)。店舗機器330から本人認証装置310への送信は、例えば、内部ネットワーク320を介して行われる。
店舗機器330から認証情報(移動履歴5aおよび端末ID1a)を受け取ると(ステップS1501)、本人認証装置310では、認証部313が、認証情報保管部314に保管されている認証情報と照合し、認証を行う(ステップS1502)。
そして、通信部311を介して、認証結果を店舗機器330に送信する(ステップS1503)。送信される認証結果は、認証成功または認証失敗のいずれかである。
認証結果を受信すると、店舗機器330では、認証結果を端末機器に送信する(ステップS1402)。
端末機器200は、認証結果を受信する(ステップS1303)。ここで、認証成功であれば、例えば、決済処理等に移行する。一方、認証失敗であれば、その旨をユーザに通知する。ユーザへの通知は、例えば、メッセージをディスプレイ241に表示するなどにより行う。
次に、端末機器200では、ステップS1303で受信した結果が、認証成功の場合、移動履歴生成部272は、その時点までに収集された位置情報4bを用いて、移動履歴5bを生成する(ステップS1304)。そして、新たに生成した移動履歴5bを、移動履歴記憶部282に記憶するとともに、店舗機器330へ送信する(ステップS1305)。移動履歴5bは、端末ID1aとともに、新たな登録認証情報として店舗機器330へ送信される。送信は、端末間通信器223、246を介して行われる。
店舗機器330では、受信した新たな登録認証情報(移動履歴5bおよび端末ID1a)を、本人認証装置310へ送信する(ステップS1404)。
本人認証装置310では、保管処理部312が、認証情報保管部314に保管されている認証情報を、新たに受信した登録認証情報で更新する(ステップS1504)。このとき、保管処理部312は、同じ端末ID1aを有する認証情報を抽出し、新たに送信された認証情報に置き換える(上書きする)。
その後、端末機器200は、ステップS1301へ戻り、位置情報の収集を継続する。
上記の初期登録処理と、店舗認証処理と、認証情報更新処理との、データの流れを、図8(a)~図8(c)に示す。
図8(a)に示すように、初期登録処理では、登録認証情報(移動履歴5aおよび端末ID1a)が、直接、本人認証装置310に送信される。
初期登録処理以降の処理、すなわち、店舗認証処理および認証情報更新処理では、図8(b)および図8(c)に示すように、認証情報(移動履歴5aおよび端末ID1a)、または、登録認証情報(移動履歴5bおよび端末ID1a)が、店舗機器330を介して、本人認証装置310に送信される。
本実施形態の本人認証処理を、ユーザ209の動きに沿って、図9(a)~図9(d)を用いて説明する。各店舗が、店舗機器331、332、333、334を備えるものとする。
まず、ユーザ209は、図9(a)に示すように、店舗等で本実施形態の本人認証処理を行う前に、初期登録処理を行う。初期登録処理は、例えば、ユーザ209の自宅等で行われる。
初期登録処理を終えると、ユーザ209は、図9(b)に示すように、初期登録処理を行った端末機器200を携帯し、店舗に向かう。そして、端末機器200を、店舗機器331にかざすなどする。これにより、端末機器200は、自身に記憶される移動履歴5aと、端末ID1aとを、認証情報として店舗機器331に送信し、認証を要求する。
なお、図9(b)に示すように、ユーザ209は、認証を受ける店舗に到る間も、位置情報の収集を継続する。
店舗機器331は、認証情報を本人認証装置310に送信し、認証を受ける。認証に成功すると、端末機器200は、図9(c)に示すように、先に移動履歴を生成後に蓄積した位置情報から、新たな移動履歴5bを生成する。そして、新たな移動履歴5bを自身の移動履歴記憶部282に記憶するとともに、端末ID1aとともに、登録認証情報として、店舗機器331に送信する。
店舗機器331は、新たな登録認証情報(移動履歴5bおよび端末ID1a)を、本人認証装置310に転送する。そして、本人認証装置310では、端末ID1aに対応づけて登録されている認証情報を更新する。
その後、ユーザ209は、別の店舗に行った場合、その店舗の店舗機器332において、図9(d)に示すように、新たに移動履歴記憶部282に記憶された移動履歴5bを用いて、認証要求、認証情報の更新等を行う。
なお、店舗認証処理の前に、認証要求部279は、ユーザ209の正当性を確認する処理を行ってもよい。すなわち、端末機器200が、本人確認部をさらに備え、本人確認部において、ユーザ209が予め登録されたユーザ209本人であるか否かを確認し、本人と確認された後、店舗認証処理を行う。
この場合の本人確認部による本人確認は、例えば、指紋等の生体情報を活用してもよい。また、パスワード等、知識情報を活用してもよい。
また、上記例では、端末機器200は、認証結果を受信後に移動履歴を生成するよう記載したが、移動履歴生成のタイミングは、これに限定されない。移動履歴の生成は、認証処理とは、独立して行ってもよい。例えば、後述するよう、位置情報を収集する毎に、その正当性を判別し、正当であれば、移動情報として蓄積するよう構成してもよい。
この場合、認証情報として、本人認証装置310へ登録済みの移動履歴と、新たに生成し、次に登録予定の移動履歴(更新用移動履歴)とは、区別可能な態様で、移動履歴記憶部282に記憶する。
[データ構成]
ここで、端末機器200から本人認証装置310、店舗機器330に送信されるデータの構成を説明する。
ここで、端末機器200から本人認証装置310、店舗機器330に送信されるデータの構成を説明する。
端末ID1aのデータ構成例を図10(a)に示す。本図に示すように、端末ID1aは、端末の型式を特定する型名情報411と、シリアル番号412と、を備える。なお、端末ID1aは、これに限定されない。各端末機器200を、一意に特定可能な情報であればよい。また、端末ID1aは、例えば、ヘッダ情報として送信データに挿入されてもよい。
移動履歴5aのデータ構成例を図10(b)に示す。移動履歴5aは、例えば、所定期間に測位された位置情報の時系列データとする。すなわち、移動履歴5aは、所定数の位置情報を備える。本図に示すように、移動履歴5aは、各位置情報について、それぞれ、位置情報を特定する番号421と、当該位置情報を取得した日時422と、位置情報423と、を備える。
なお、移動履歴5aは、これに限定されない。例えば、各位置情報のハッシュ値を計算し、そのハッシュ値の時系列データであってもよい。また、プライバシー保護の観点から、所定のルールのもと、測位された位置情報の遷移の順番を並び替えて移動履歴としてもよい。
[移動履歴生成処理]
ここで、本実施形態の移動履歴生成処理を説明する。本実施形態では、測位部271が所定期間収集した位置情報から、移動履歴生成部272が、移動履歴を生成する。このとき、本実施形態では、端末機器200の正当なユーザ209が、当該端末機器200を所持している間に収集された位置情報のみを、移動履歴生成に採用する。
ここで、本実施形態の移動履歴生成処理を説明する。本実施形態では、測位部271が所定期間収集した位置情報から、移動履歴生成部272が、移動履歴を生成する。このとき、本実施形態では、端末機器200の正当なユーザ209が、当該端末機器200を所持している間に収集された位置情報のみを、移動履歴生成に採用する。
本実施形態では、正当なユーザ209であるか否かを、予め登録された、ユーザ209の特徴情報を用いて判別する。本実施形態では、特徴情報として、例えば、ユーザの歩調周波数、歩幅、歩行速度等、歩行に関する情報を用いる。これらの情報は、例えば、加速度センサ264で取得した、所定期間の加速度情報から算出する。
歩調は、ユーザ209の歩行時の加速度波形の変化から推定する。また、歩幅は、推定した歩調と測位部271が取得した位置情報とを組み合わせて推定する。
本実施形態の、特徴情報を用いた移動履歴生成処理の概略を図11(a)~図11(c)を用いて説明する。
本実施形態では、図11(a)に示すように、まず、初期処理として、特徴情報収集部274が、予め定めた特徴情報を収集し、照合時の参照特徴情報50aとして、参照特徴情報記憶部283に登録する。
ここで、登録される参照特徴情報50aのデータ構成を、図10(c)に示す。本図に示すように、参照特徴情報50aは、例えば、歩調周波数431と、歩幅432と、歩行速度433と、を備える。なお、参照特徴情報50aは、例えば、波形データそのものであってもよい。
参照特徴情報50aを登録後、移動履歴生成部272は、正当なユーザ209が所持している間に取得された位置情報を用いて移動履歴を生成する。
図11(b)、図11(c)に示すように、特徴情報収集部274は、所定の時間間隔で、特徴情報を取得する。そして、照合部273は、取得した特徴情報を、参照特徴情報記憶部283に記憶される参照特徴情報50aと照合し、整合性の有無を判別する。
すなわち、整合性があれば、正当なユーザ209がこの端末機器200を保持していると判別し、整合性が無ければ、正当ではないユーザ208がこの端末機器200を保持していると判別する。
移動履歴生成部272は、照合部273の照合結果を用いて、移動履歴を算出する。
以下、本実施形態の移動履歴生成処理の流れを説明する。図12(a)は、本実施形態の移動履歴生成処理の処理フローである。本処理は、所定の時間間隔Δtで実行される。なお、この間、測位部271は、Δtより短い時間間隔で、位置情報を収集し、位置情報記憶部281に収集時刻に対応づけて、記憶する。
まず、特徴情報収集部274は、特徴情報を収集する(ステップS1601)。そして、照合部273は、収集した特徴情報と、参照特徴情報記憶部283に格納される参照特徴情報50aとを照合する(ステップS1602)。
収集した特徴情報と参照特徴情報50aとが略一致し、整合性が有る場合、照合部273は、正当なユーザ209が所持していると判別する。そして、前回の照合結果と比較し、照合結果が変化したか否かを判別する(ステップS1603)。前回の照合結果から変化した場合、移動履歴生成部272に通知する(ステップS1604)。
照合結果の変化の通知を受け取ると、移動履歴生成部272は、移動履歴の生成、非生成の状態を反転させ(ステップS1605)、今回の照合結果を、記憶し、処理を終了する。すなわち、移動履歴を生成していれば、移動履歴の生成を停止し、移動履歴の生成を停止している状態であれば、移動履歴の生成を開始する。
このように、本実施形態では、移動履歴生成部272は、一度、正当なユーザ209が所持していると判別された場合は、次に、正当なユーザ209が所持していないと判別されるまでは、移動履歴生成を継続する。また、一旦、正当なユーザ209が所持していないと判別された場合は、次に、正当なユーザ209が所持していると判別されるまでは、移動履歴の生成を停止する。すなわち、上記ステップS1605で説明したように、照合結果の反転に応じて、移動履歴の生成、非生成の状態を反転させる。
このような、上記の移動履歴の生成、非生成状態の反転を、具体的なタイミングチャートで説明する。図12(b)は、照合部273による照合タイミング(照合実施、照合不実施)と、照合結果(一致、不一致)と、移動履歴生成、非生成状態の変化の様子を示すタイミングチャートである。
上述のように、照合部273は、所定の時間間隔Δtで、取得した特徴情報と、参照用特徴情報との照合を実施する。そして、照合結果に変化があった場合、移動履歴生成部272に通知する。
図12(b)の例では、1回目および2回目の照合結果は、一致を示し、それぞれ、前回の照合結果から変化はない。このため、照合部273は、照合結果を移動履歴生成部272に通知しない。移動履歴生成部272は、通知がないため、そのまま、その状態を継続する。例えば、移動履歴を生成している場合は、そのまま生成を続ける。一方、移動履歴の生成を停止している場合は、そのまま停止状態を継続する。
ここで、3回目の照合時、照合結果が不一致を示す。この場合、一致である2回目の照合結果から、照合結果が変化したため、照合部273は、移動履歴生成部272に通知する。移動履歴生成部272は、通知を受け、状態を反転させる。すなわち、この場合は、今まで移動履歴を生成していたところ、移動履歴の生成を停止する。
4回目の照合時は、照合結果が一致を示す。この場合、不一致である3回目の照合結果から、照合結果が変化したため、照合部273は、移動履歴生成部272に通知する。移動履歴生成部272は、通知を受け、状態を判定させる。すなわち、この場合は、今まで移動履歴の生成を停止していたところ、移動履歴の生成を開始する。
図12(b)の例では、3回目の照合の直前までは、正当なユーザ209が保持しているものと判別され、3回目の照合時から4回目の照合の直前までは、正当なユーザ209に所持されていないものと判別される。
本実施形態の移動履歴生成部272は、このように、正当なユーザ209が所持していると判別された期間のみ、位置情報から移動履歴を生成する。このため、正当なユーザ209である本人による移動履歴を高い精度で収集できる。
なお、上記実施形態では、特徴情報として、加速度センサ264の出力から算出される情報を用いたが、特徴情報は、これに限定されない。例えば、端末機器200が、腕時計型機器である場合、図11(d)に示すように、例えば、脈波信号であってもよい。脈波信号は、例えば、生体情報センサ267として、脈波センサを備え、この脈波センサで取得する。
以上説明したように、本実施形態によれば、位置情報から生成された移動履歴であって、ユーザ209が予め登録した移動履歴そのものを、ユーザ209の本人認証に用いる。このため、端末保持者の固有情報を用いて、本人認証を行うことができる。また、質問を生成したり、質問に答えたりといった処理がないため、本人認証装置310側の負担も少なく、端末機器200を操作するユーザ209の負担や手間も少ない。
また、この移動履歴は、端末機器200の識別情報(端末ID)に対応づけて、本人認証装置310に登録される。このため、例えば、移動履歴情報のみがコピーされ、他の端末から送信されたとしても、認証は成功しない。このため、安全性が高い。
また、移動履歴は、端末機器200を、正当なユーザ209が所持していると判断された期間に収集された位置情報を用いて生成される。従って、本人認証に用いる移動履歴の信頼性が高い。
また、移動履歴の生成を継続的に行い、所定のタイミングで、本人認証装置310に認証情報として登録される移動履歴を更新する。このため、認証情報の漏えいに強いシステムを提供できる。
また、上記実施形態では、特に、この認証情報の更新を、店舗機器330において、認証後に行う。従って、更新時のデータの送受信は、端末間通信で行われる。一般のネットワークを介した送受信に比べ、端末間通信は、安全性が高い。このような安全性の高い通信を用いて、認証情報の更新を行うため、システム全体としての安全性も高い。
このように、本実施形態では、本人である確度の高い位置情報から生成された移動履歴を用いて、本人認証を行う。また、その移動履歴は、事前に本人認証装置310に、端末機器200を特定する情報とともに登録しておく。さらに、所定のタイミングで認証情報を更新する。これらにより、本実施形態によれば、安全性と利便性とを両立させたシステムを実現できる。
なお、本実施形態では、移動履歴の更新を、店舗で本人認証を行った後、店舗機器330を用いて行うよう構成されているが、これに限定されない。例えば、所定のタイミングで、ネットワーク101を介して、本人認証装置310に認証情報を送信し、更新するよう構成してもよい。所定のタイミングは、例えば、予め定めた時間間隔や、所定量の移動履歴が生成される毎、等とする。この場合、送信時は、暗号化するなど、所定のセキュリティ対策を施す。
また、移動履歴は、正当なユーザ209が保持している間に得られた位置情報(正当な位置情報)が、所定量蓄積される毎に生成してもよい。この場合、最新の移動履歴のみ、更新用移動履歴として記憶しておいてもよい。
また、上述のように、店舗機器330と端末間通信が可能な時に、不定期に移動履歴を生成する場合、前回の移動履歴生成時に用いた位置情報も含めて、所定量の正当な位置情報を確保してもよい。例えば、前回の移動履歴生成時以降の期間が短く、十分な量の正当な位置情報が蓄積されていない場合場などである。また、十分な量の正当な位置情報が蓄積されていない場合は、新たな移動履歴を生成せず、本人認証装置310に保管される認証情報内の移動履歴を更新しなくてもよい。
また、上記実施形態では、認証情報として、移動履歴とともに、端末IDを送信し、端末ID1aも、本人認証装置310で保管しているが、これに限定されない。本人認証装置310の認証情報保管部314では、移動履歴のみを保管してもよい。この場合は、認証部313は、送信元の端末機器200によらず、送信された移動履歴が、認証情報保管部314に保管されていれば、認証成功とする。
<<第二の実施形態>>
次に、本発明の第二の実施形態を説明する。第一の実施形態は、各店舗とは独立して、本人認証装置を備える。これに対し、本実施形態では、各店舗、あるいは、店舗グループ毎に、本人認証装置を備える。そして、本人認証に用いる認証情報を、複数の本人認証装置間で分散共有する。
次に、本発明の第二の実施形態を説明する。第一の実施形態は、各店舗とは独立して、本人認証装置を備える。これに対し、本実施形態では、各店舗、あるいは、店舗グループ毎に、本人認証装置を備える。そして、本人認証に用いる認証情報を、複数の本人認証装置間で分散共有する。
以下、本実施形態の本人認証システム102について、第一の実施形態と異なる構成に主眼をおいて説明する。
本実施形態の本人認証システム102の全体構成を図13に示す。本実施形態の本人認証システム102は、端末機器200と、プロバイダシステム302と、を備える。そして、プロバイダシステム302は、店舗毎に配置される本人認証装置350(351、352、353)を備える。各本人認証装置350間は、内部ネットワーク320で接続される。なお、各本人認証装置351、352、353を特に区別する必要がない場合は、本人認証装置350で代表する。
本実施形態の端末機器200は、基本的に第一の実施形態の端末機器200と同様の構成を有するため、ここでは、説明を省略する。
図14(a)は、本実施形態の本人認証装置350の機能ブロック図である。また、図14(b)は、本実施形態の本人認証装置350のハードウェア構成図である。
図14(b)に示すように、本実施形態の本人認証装置350は、第一の実施形態の本人認証装置310の構成に加え、端末間通信器326を備える。端末間通信器326は、端末機器200が備える同名の装置と同様の構成を有する。本実施形態では、店舗において、端末機器200とデータの送受信を行うために用いられる。
また、本実施形態の本人認証装置350は、図14(a)に示すように、第一の実施形態と同様の機能構成に加え、共有処理部315を備える。
本実施形態では、上述のように、本人認証装置350を複数備える。そして、全ての本人認証装置350間で、認証情報を共有する。また、本実施形態では、1つの認証要求に対する認証を、複数の本人認証装置350で行う。そして、所定割合以上、例えば、半数以上の本人認証装置350で認証成功と判別された場合、システム全体として認証成功と判断する。
これを実現するため、共有処理部315は、通信部311が、受信した認証情報が登録認証情報であるか否かを判別した後、その送信元を判別する。ここでは、送信元が、端末機器200であるか、他の本人認証装置350であるかを判別する。送信元が端末機器200であるか、他の本人認証装置350であるかは、例えば、送受信データのヘッダ情報等により判別する。
そして、受信した認証情報または登録認証情報の送信元が端末機器200である場合、保管処理部312または認証部313に受け渡すだけでなく、他の全ての本人認証装置350にも、受信した認証情報または登録認証情報を送信するよう通信部311に指示を行う。一方、受信した認証情報または登録認証情報の送信元が他の本人認証装置350である場合は、第一の実施形態同様、登録認証情報であるか否かの判別結果に応じて、保管処理部312または認証部313に受け渡す。
さらに、認証情報を他の本人認証装置350から受け取った場合、共有処理部315は、認証部313に認証させるとともに、通信部311に、認証結果を送信元の本人認証装置350に送信させる。
また、通信部311を介して、他の本人認証装置350から認証結果を受け取ると、自装置の認証部313の認証結果を加え、半数以上の本人認証装置350で認証成功であるか否かを判別する。そして、半数以上で認証成功であれば、認証成功とし、通信部311から送信元の端末機器200に送信させる。一方、認証成功との認証結果が半数より少ない場合は、認証失敗とし、通信部311から送信元の端末機器200に送信させる。
以下、本実施形態の本人認証処理の流れを説明する。
なお、本実施形態においても、第一の実施形態同様、まず、端末機器200は、本人認証装置350に対し、認証情報を登録する初期登録処理を行う。初期登録処理は、第一の実施形態同様、ネットワーク101を介して、いずれかの本人認証装置350に対して登録認証情報を送信することにより行う。
このとき、登録認証情報を受信した本人認証装置350は、受信した認証情報(移動履歴5aおよび端末ID1a)を、自身の認証情報保管部314に保管するだけでなく、他の本人認証装置350へ送信する。そして、他の本人認証装置350においても、受信した登録認証情報を、認証情報保管部314に保管する。
これにより、当該端末機器200の登録認証情報(移動履歴5aおよび端末ID1a)が、全ての本人認証装置350間で共有される。
図15を用いて、本実施形態の認証時のデータの流れを説明する。本図に示すように、端末機器200を保持したユーザ209が、特定の店舗に行き、本人認証装置352に対して認証を要求した場合、すなわち、端末機器200から認証要求を受けた場合、本人認証装置352は、自装置内で認証を行う。
また、本人認証装置352は、内部ネットワーク320を介して、認証情報(移動履歴5aおよび端末ID1a)を、他の本人認証装置351、353に送信する。他の本人認証装置351、353では、それぞれ、認証を行い、認証結果を、内部ネットワーク320を介して、送信元の本人認証装置352に返信する。
本人認証装置352では、自身の認証結果と、他の本人認証装置351、353から受信した認証結果とを用い、最終的な認証結果を決定し、要求元の端末機器200に返信する。
なお、本実施形態では、初期登録処理を、本人認証装置350を有する特定の店舗で、端末間通信を用いて行ってもよい。このように構成することで、初期登録処理時の認証情報が端末間通信で送受信される。これにより、さらに安全性が高くなる。
本実施形態によれば、第一の実施形態と同様の構成を有する本人認証装置350を、複数有する。このため、本実施形態によれば、第一の実施形態と同様の効果が得られる。さらに、本実施形態では、本人認証装置350を複数備え、認証情報を共有する。これにより、認証時に複数装置の合意形成を図り、相互検証を行う。従って、信頼性が向上する。
なお、本実施形態では、半数以上の本人認証装置350が認証成功であった場合、認証成功と判別している。しかしながら、認証成功と判別する際の、認証に成功した本人認証装置350の割合は、これに限定されず、自由に設定可能である。例えば、全ての本人認証装置350で認証成功の場合のみ、認証成功と判別するよう構成してもよい。
また、上記実施形態では、本人認証装置350が、店舗毎に配置される場合を例にあげて説明したが、本構成に限定されない。本人認証装置350は、例えば、いくつかの店舗グループ毎に配置されてもよい。
また、本実施形態においても、第一の実施形態の各種の変形例が適用可能である。
<<第三の実施形態>>
次に、本発明の第三の実施形態を説明する。本実施形態では、移動履歴の正当性を検証するために、第三者の位置情報を用いる。
次に、本発明の第三の実施形態を説明する。本実施形態では、移動履歴の正当性を検証するために、第三者の位置情報を用いる。
本実施形態では、第三者の位置情報として、例えば、携帯電話網の基地局105の位置情報を用いる。以下、本実施形態について、第一の実施形態と異なる構成に主眼をおいて説明する。
本実施形態の本人認証システム100の全体構成は、第一の実施形態と基本的に同じである。また、各構成要素のハードウェア構成、機能ブロックも、基本的に第一の実施形態と同じである。ただし、端末機器200は、第三者の位置情報を取得する構成を備える。また、本人認証装置310は、第三者の位置情報の正当性を判別する構成を備える。
図16(a)は、本実施形態の端末機器203の機能ブロックである。本図に示すように、本実施形態の端末機器203は、第一の実施形態の構成に加え、基準情報取得部277を備える。基準情報取得部277は、測位部271が位置情報を取得し、位置情報記憶部281に格納するタイミングで、基準位置情報を取得する。そして、測位部271が同じタイミングで取得した位置情報に対応づけて、基準情報として、基準情報記憶部285に記憶する。
基準情報取得部277が取得する基準位置情報は、本実施形態では、例えば、上述のように、基地局105の情報とする。
基準情報取得部277は、通信器220のうち、電話網通信器222を介して、通信時に用いる基地局105の情報を、基準位置情報として取得する。取得する基準位置情報は、例えば、基地局105の位置情報そのものであってもよいし、基地局を特定する識別情報(基地局ID)であってもよい。
図17(a)に示すように、基準情報取得部277は、同じタイミングで取得した位置情報2aと、基準位置情報40aとの組を、基準情報500aとして基準情報記憶部285に記憶する。
なお、基準情報500は、所定のタイミングでの生成を繰り返す。従って、位置情報2と基準位置情報40とを備える基準情報500が、複数生成され、基準情報記憶部285に記憶される。ここでは、基準情報500a(40a、2a)、基準情報500b(40b、2b)、基準情報500c(40c、2c)、が登録されている場合を例示する。
本実施形態では、認証時、図17(b)に示すように、認証要求部279は、第一の実施形態の認証情報(移動履歴5aおよび端末ID1a)に加え、基準情報500を、店舗機器330に送信する。そして、店舗機器330は、受信した認証情報と基準情報500とを、本人認証装置310に送信する。
また、本実施形態の本人認証装置319は、図16(b)に示すように、第一の実施形態の構成に加え、さらに、基準情報検証部316を備える。基準情報検証部316は、基準情報500の正当性を検証する。
すなわち、基準情報検証部316は、受信した基準情報500内の位置情報2と、対応づけて登録されている基準位置情報40との関係が、合理的なものであるかを検証する。例えば、基準位置情報40aが、基地局105の位置情報である場合、位置情報2aが、基準位置情報40aで特定される基地局105のカバーエリア内であるかを検証する。
なお、基準位置情報40aが基地局105の基地局IDである場合、当該IDで特定される基地局105のカバーエリア内であるかを検証する。
なお、各基地局105の位置情報および/または基地局ID等と、カバーエリアとの対応情報は、本人認証装置310で入手可能とする。
そして、基準情報検証結果がカバーエリア内であると判別された場合のみ、本人認証成功とする。
本実施形態の本人認証装置310における、認証処理の流れを図18に沿って説明する。
まず、第一の実施形態と同様に、認証部313が、受信した認証情報と、認証情報保管部314に保管される認証情報とを照合する(ステップS3101)。
そして、一致しない場合、認証失敗とし、認証失敗を意味する情報を送信元の端末機器200に返信し(ステップS3106)、処理を終了する。
一方一致した場合、基準情報検証部316は、各基準情報500を解析し、その正当性を検証する(ステップS3103)。ここでは、位置情報2が上述のように、基準位置情報40で特定される基地局105のカバーエリア内であるか否かを判別する。そして、全ての基準情報500が、カバーエリア内であれば、正当と判別する(ステップS3104)。
ステップS3104で正当と判別された場合、認証成功を意味する情報を、送信元の端末機器200に返信し(ステップS3105)、処理を終了する。
一方、正当と判別されない場合は、ステップS3106へ移行する。
なお、本実施形態では、基準情報として、携帯電話の基地局105の位置情報を用いたが、基準情報は、これに限定されない。その他のランドマークの位置情報等、端末機器200で取得でき、かつ、本人認証装置310で、当該情報の正当性を判別できる情報であればよい。
本実施形態は、端末機器200および本人認証装置310は、それぞれ、第一の実施形態と同様の構成を有する。このため、第一の実施形態と同様の効果が得られる。さらに、本実施形態の端末機器200は、基準情報を収集し、認証情報とともに、本人認証装置310に送信する。そして、本人認証装置310では、基準情報の正当性も判別する。この基準情報には、例えば、第三者の位置情報を用いる。
このため、本実施形態によれば、端末機器200から送信される移動履歴が、実際にユーザ209の移動により得られたものであるか、偽物でないか、を判別できる。従って、より信頼性を向上できる。
また、本実施形態においても、第一の実施形態の各種の変形例が適用可能である。
上記実施形態では、測位部271が取得した位置情報から認証情報を生成しているが、認証情報は、これに限定されない。例えば、購買履歴等を用いてもよい。購買履歴は、例えば、購買店舗情報、購買商品情報、購買金額情報等を含んでいてもよい。
本発明は上記の実施形態に限定されるものではなく、様々な変形例が含まれる。例えば、上記した実施形態は、本発明を分かりやすく説明するためのものであり、必ずしも説明した全ての構成を備えるものに限定されるものではない。また、ある実施形態の構成の一部を他の実施形態の構成に置き換えることが可能であり、また、ある実施形態の構成に他の実施形態の構成を加えることも可能である。また、各実施形態の構成の一部について、他の構成の追加・削除・置換をすることが可能である。
また、上記の各構成、機能、処理部、処理手段等は、それらの一部または全部を、例えば集積回路で設計する等によりハードウェアで実現してもよい。
また、制御線や情報線は説明上必要と考えられるものを示しており、製品上必ずしも全ての制御線や情報線を示しているとは限らない。実際には殆ど全ての構成が相互に接続されていると考えてもよい。
1a:端末ID、2:位置情報、2a:位置情報、4a:位置情報、4b:位置情報、5a:移動履歴、5b:移動履歴、40:基準位置情報、40a:基準位置情報、50a:参照特徴情報、
100:本人認証システム、101:ネットワーク、102:本人認証システム、105:基地局、
200:端末機器、201:CPU、202:システムバス、203:端末機器、208:正当でないユーザ、209:正当なユーザ、210:記憶装置、211:ROM、212:RAM、213:外部メモリI/F、220:通信器、221:LAN通信器、222:電話網通信器、223:端末間通信器、227:拡張I/F、230:操作器、240:ビデオプロセッサ、241:ディスプレイ、242:画像信号プロセッサ、243:カメラ、246:端末間通信器、250:オーディオプロセッサ、251:スピーカ、252:音声信号プロセッサ、253:マイク、260:センサ、261:GPS受信器、262:ジャイロセンサ、263:地磁気センサ、264:加速度センサ、265:照度センサ、266:近接センサ、267:生体情報センサ、271:測位部、272:移動履歴生成部、273:照合部、274:特徴情報収集部、275:通信部、276:登録処理部、277:基準情報取得部、279:認証要求部、281:位置情報記憶部、282:移動履歴記憶部、283:参照特徴情報記憶部、284:端末ID記憶部、285:基準情報記憶部、
300:プロバイダシステム、302:プロバイダシステム、310:本人認証装置、311:通信部、312:保管処理部、313:認証部、314:認証情報保管部、315:共有処理部、316:基準情報検証部、319:本人認証装置、320:内部ネットワーク、321:CPU、322:メモリ、323:記憶装置、324:通信器、325:LAN通信器、326:端末間通信器、330:店舗機器、331:店舗機器、332:店舗機器、333:店舗機器、334:店舗機器、340:LAN通信器、341:CPU、342:メモリ、343:記憶装置、344:通信器、345:LAN通信器、346:端末間通信器、350:本人認証装置、351:本人認証装置、352:本人認証装置、353:本人認証装置、
411:型名情報、412:シリアル番号、422:日時、423:位置情報、431:歩調周波数、432:歩幅、433:歩行速度、
500:基準情報、500a:基準情報、500b:基準情報、500c:基準情報
100:本人認証システム、101:ネットワーク、102:本人認証システム、105:基地局、
200:端末機器、201:CPU、202:システムバス、203:端末機器、208:正当でないユーザ、209:正当なユーザ、210:記憶装置、211:ROM、212:RAM、213:外部メモリI/F、220:通信器、221:LAN通信器、222:電話網通信器、223:端末間通信器、227:拡張I/F、230:操作器、240:ビデオプロセッサ、241:ディスプレイ、242:画像信号プロセッサ、243:カメラ、246:端末間通信器、250:オーディオプロセッサ、251:スピーカ、252:音声信号プロセッサ、253:マイク、260:センサ、261:GPS受信器、262:ジャイロセンサ、263:地磁気センサ、264:加速度センサ、265:照度センサ、266:近接センサ、267:生体情報センサ、271:測位部、272:移動履歴生成部、273:照合部、274:特徴情報収集部、275:通信部、276:登録処理部、277:基準情報取得部、279:認証要求部、281:位置情報記憶部、282:移動履歴記憶部、283:参照特徴情報記憶部、284:端末ID記憶部、285:基準情報記憶部、
300:プロバイダシステム、302:プロバイダシステム、310:本人認証装置、311:通信部、312:保管処理部、313:認証部、314:認証情報保管部、315:共有処理部、316:基準情報検証部、319:本人認証装置、320:内部ネットワーク、321:CPU、322:メモリ、323:記憶装置、324:通信器、325:LAN通信器、326:端末間通信器、330:店舗機器、331:店舗機器、332:店舗機器、333:店舗機器、334:店舗機器、340:LAN通信器、341:CPU、342:メモリ、343:記憶装置、344:通信器、345:LAN通信器、346:端末間通信器、350:本人認証装置、351:本人認証装置、352:本人認証装置、353:本人認証装置、
411:型名情報、412:シリアル番号、422:日時、423:位置情報、431:歩調周波数、432:歩幅、433:歩行速度、
500:基準情報、500a:基準情報、500b:基準情報、500c:基準情報
Claims (14)
- 端末機器であって、
所定の時間間隔で前記端末機器の位置を測位し、位置情報として蓄積する測位部と、
所定期間の前記位置情報を用いて移動履歴を生成し、移動履歴情報として記憶する移動履歴生成部と、
前記移動履歴情報を、本人認証装置に登録のために送信する登録処理部と、
前記登録処理部が前記本人認証装置に送信後の前記移動履歴情報を用いて、前記本人認証装置に対して認証要求を行う認証要求部と、を備えること
を特徴とする端末機器。 - 請求項1記載の端末機器であって、
前記登録処理部は、前記移動履歴情報とともに、当該端末機器を一意に特定する端末識別情報を、前記本人認証装置に送信し、
前記認証要求部は、前記認証要求に、前記端末識別情報と前記移動履歴情報とを含めること
を特徴とする端末機器。 - 請求項1記載の端末機器であって、
当該端末機器のユーザの特徴を示す特徴情報を収集する特徴情報収集部と、
収集した前記特徴情報を、予め保持する正当なユーザの特徴情報である参照特徴情報と照合し、照合結果を出力する照合部と、をさらに備え、
前記移動履歴生成部は、前記照合部が前記照合結果として前記特徴情報と前記参照特徴情報とが一致したことを意味する情報を出力している間に測位された位置情報を用いて、前記移動履歴を生成すること
を特徴とする端末機器。 - 請求項1記載の端末機器であって、
前記登録処理部は、前記認証要求部の前記認証要求に応じて認証された後、最新の前記移動履歴情報を前記本人認証装置に送信すること
を特徴とする端末機器。 - 請求項1記載の端末機器であって、
第三者の位置情報を、基準情報として取得する基準情報取得部をさらに備え、
前記認証要求部は、前記認証要求に、前記基準情報もさらに含めること
を特徴とする端末機器。 - 請求項1記載の端末機器であって、
前記認証要求は、近距離無線通信を用いて行うこと
を特徴とする端末機器。 - 端末機器と、認証インタフェース装置と、本人認証装置とを備える本人認証システムであって、
前記端末機器は、
所定の時間間隔で前記端末機器の位置を測位し、位置情報として蓄積する測位部と、
所定期間の前記位置情報を用いて移動履歴を生成し、移動履歴情報として記憶する移動履歴生成部と、
前記移動履歴情報を、前記本人認証装置に登録のために送信する登録処理部と、
前記登録処理部が前記本人認証装置に送信後の前記移動履歴情報を用いて、前記認証インタフェース装置を介して前記本人認証装置に対して認証要求を行う認証要求部と、を備え、
前記本人認証装置は、
前記端末機器から送信された前記移動履歴情報を、保管する保管処理部と、
前記端末機器から前記認証インタフェース装置を介して前記認証要求を受信した際、当該認証要求に含まれる前記移動履歴が前記保管処理部により保管されているか否かを判別することにより、認証を行い、認証結果を返す認証部と、を備えること
を特徴とする本人認証システム。 - 請求項7記載の本人認証システムであって、
前記保管処理部は、前記端末機器から新たな移動履歴情報を受信する毎に、最新の前記移動履歴情報で、保管されている前記移動履歴情報を上書きすること
を特徴とする本人認証システム。 - 請求項7記載の本人認証システムであって、
前記本人認証装置を複数備え、
各前記本人認証装置は、共有処理部を備え、
前記共有処理部は、前記端末機器から送信された前記移動履歴情報および前記認証要求を、他の本人認証装置に送信するとともに、前記他の本人認証装置それぞれから前記認証要求に対する認証結果を受信し、受信した当該認証結果と自身の前記認証部による認証結果とに応じて認証の成否を決定すること
を特徴とする本人認証システム。 - 端末機器と、認証インタフェース装置と、本人認証装置とを備える本人認証システムにおける本人認証方法であって、
端末機器において移動履歴情報を記憶するとともに、前記本人認証装置に当該移動履歴情報を送信し、当該本人認証装置において認証情報として保管する初期登録ステップと、
前記認証インタフェース装置を介して前記移動履歴情報を認証要求として前記本人認証装置に送信し、前記本人認証装置において前記認証情報を用いて認証を受ける認証ステップと、
新たに生成した移動履歴情報を、前記認証インタフェース装置を介して前記本人認証装置に送信し、前記本人認証装置において保管されている前記認証情報を当該移動履歴情報によって置き換える認証情報更新ステップと、を備えること
を特徴とする本人認証方法。 - 請求項10記載の本人認証方法であって、
前記端末機器から前記認証インタフェース装置および前記本人認証装置のいずれかに前記移動履歴情報を送信する前に、当該移動履歴情報を生成する移動履歴情報生成ステップを備え、
前記移動履歴情報生成ステップは、
前記端末機器の位置情報を取得する位置情報取得ステップと、
前記端末機器のユーザの正当性を判別する正当性判別ステップと、
前記正当性判別ステップにおいて正当と判別された際に取得された位置情報を前記移動履歴情報に採用する採用移動履歴決定ステップと、を備えること
を特徴とする本人認証方法。 - 請求項10記載の本人認証方法であって、
前記認証情報は、送信元の前記端末機器の識別情報である端末識別情報をさらに備え、
前記認証ステップでは、前記認証要求に、当該認証要求の送信元の前記端末機器の前記端末識別情報を含めること
を特徴とする本人認証方法。 - 請求項3記載の端末機器であって、
当該端末機器の加速度を検出する加速度センサをさらに備え、
前記特徴情報として、所定期間の前記加速度センサの出力を用いること
を特徴とする端末機器。 - 請求項3記載の端末機器であって、
前記ユーザの脈波を検出する脈波センサをさらに備え、
前記特徴情報として、所定期間の前記脈波センサの出力を用いること
を特徴とする端末機器。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/769,610 US11483713B2 (en) | 2017-12-20 | 2018-12-06 | Terminal device, personal authentication system and personal authentication method |
| CN201880071903.5A CN111316264B (zh) | 2017-12-20 | 2018-12-06 | 终端设备、本人认证系统和本人认证方法 |
| US17/945,513 US11871239B2 (en) | 2017-12-20 | 2022-09-15 | Terminal device, personal authentication system and personal authentication method |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2017-244152 | 2017-12-20 | ||
| JP2017244152A JP7007177B2 (ja) | 2017-12-20 | 2017-12-20 | 端末機器、本人認証システムおよび本人認証方法 |
Related Child Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/769,610 A-371-Of-International US11483713B2 (en) | 2017-12-20 | 2018-12-06 | Terminal device, personal authentication system and personal authentication method |
| US17/945,513 Continuation US11871239B2 (en) | 2017-12-20 | 2022-09-15 | Terminal device, personal authentication system and personal authentication method |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2019124103A1 true WO2019124103A1 (ja) | 2019-06-27 |
Family
ID=66993501
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2018/044998 Ceased WO2019124103A1 (ja) | 2017-12-20 | 2018-12-06 | 端末機器、本人認証システムおよび本人認証方法 |
Country Status (4)
| Country | Link |
|---|---|
| US (2) | US11483713B2 (ja) |
| JP (1) | JP7007177B2 (ja) |
| CN (1) | CN111316264B (ja) |
| WO (1) | WO2019124103A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPWO2022018833A1 (ja) * | 2020-07-21 | 2022-01-27 |
Families Citing this family (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7299972B2 (ja) | 2019-04-24 | 2023-06-28 | 真旭 徳山 | 情報処理システム、情報処理方法、及びプログラム |
| JP7299973B2 (ja) | 2019-04-26 | 2023-06-28 | 真旭 徳山 | リモコン装置、情報処理方法及びプログラム |
| WO2021019807A1 (ja) * | 2019-07-31 | 2021-02-04 | 真旭 徳山 | 端末装置、情報処理方法、及びプログラム |
| JP7399727B2 (ja) * | 2020-01-30 | 2023-12-18 | 株式会社東芝 | 認証デバイスおよび認証システム |
| US20230153405A1 (en) * | 2020-03-26 | 2023-05-18 | Nec Corporation | Information processing device, information processing system, information processing method, and recording medium |
| JP2022122498A (ja) * | 2021-02-10 | 2022-08-23 | 富士通株式会社 | 移動履歴変更方法及び移動履歴変更プログラム |
| WO2022254654A1 (ja) * | 2021-06-03 | 2022-12-08 | 富士通株式会社 | 記憶制御方法、情報処理装置、記憶制御システム、及び記憶制御プログラム |
| JP7803116B2 (ja) * | 2021-12-22 | 2026-01-21 | トヨタ自動車株式会社 | 情報処理システム、情報処理方法、及びプログラム |
| US20250156511A1 (en) * | 2022-02-24 | 2025-05-15 | Sony Group Corporation | Information processing apparatus, information processing method, and program |
| CN116261138A (zh) * | 2023-03-14 | 2023-06-13 | 展讯半导体(成都)有限公司 | 网络鉴权方法、装置、终端设备及基站 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2004258845A (ja) * | 2003-02-25 | 2004-09-16 | Ntt Data Systems Corp | 本人認証装置、行動記録方法、交通費精算方法 |
| JP2010277190A (ja) * | 2009-05-26 | 2010-12-09 | Nippon Telegr & Teleph Corp <Ntt> | 滞在地コンテキスト抽出装置、滞在地コンテキスト抽出方法およびプログラム |
| JP2012133526A (ja) * | 2010-12-21 | 2012-07-12 | Panasonic Corp | 位置履歴認証システム、サーバ装置及びプログラム |
| WO2013073120A1 (ja) * | 2011-11-15 | 2013-05-23 | パナソニック株式会社 | 携帯端末装置、認証システム、認証方法、プログラムおよび集積回路 |
| JP2016099684A (ja) * | 2014-11-18 | 2016-05-30 | インターマン株式会社 | ライフログを利用した本人確認方法および本人確認装置 |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2011059837A (ja) * | 2009-09-08 | 2011-03-24 | Hitachi Ltd | 行動履歴情報活用個人認証システム及び方法 |
| JP2012134795A (ja) * | 2010-12-22 | 2012-07-12 | Nec Access Technica Ltd | 位置検索システム、携帯情報端末、及び位置検索方法 |
| US10373160B2 (en) * | 2011-02-10 | 2019-08-06 | Paypal, Inc. | Fraud alerting using mobile phone location |
| US9344414B2 (en) | 2013-02-01 | 2016-05-17 | Interman Corporation | User similarity provision method |
| US9122853B2 (en) * | 2013-06-24 | 2015-09-01 | A10 Networks, Inc. | Location determination for user authentication |
| JP2015065592A (ja) * | 2013-09-25 | 2015-04-09 | Necプラットフォームズ株式会社 | ユーザー認証機能付き複合装置、方法、及び、プログラム |
| KR20150118813A (ko) * | 2014-04-15 | 2015-10-23 | 삼성전자주식회사 | 햅틱 정보 운용 방법 및 이를 지원하는 전자 장치 |
| US20150310434A1 (en) * | 2014-04-29 | 2015-10-29 | Dennis Takchi Cheung | Systems and methods for implementing authentication based on location history |
| JP6461516B2 (ja) | 2014-08-25 | 2019-01-30 | 国立大学法人 東京大学 | 認証システム及び方法 |
-
2017
- 2017-12-20 JP JP2017244152A patent/JP7007177B2/ja active Active
-
2018
- 2018-12-06 WO PCT/JP2018/044998 patent/WO2019124103A1/ja not_active Ceased
- 2018-12-06 US US16/769,610 patent/US11483713B2/en active Active
- 2018-12-06 CN CN201880071903.5A patent/CN111316264B/zh active Active
-
2022
- 2022-09-15 US US17/945,513 patent/US11871239B2/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2004258845A (ja) * | 2003-02-25 | 2004-09-16 | Ntt Data Systems Corp | 本人認証装置、行動記録方法、交通費精算方法 |
| JP2010277190A (ja) * | 2009-05-26 | 2010-12-09 | Nippon Telegr & Teleph Corp <Ntt> | 滞在地コンテキスト抽出装置、滞在地コンテキスト抽出方法およびプログラム |
| JP2012133526A (ja) * | 2010-12-21 | 2012-07-12 | Panasonic Corp | 位置履歴認証システム、サーバ装置及びプログラム |
| WO2013073120A1 (ja) * | 2011-11-15 | 2013-05-23 | パナソニック株式会社 | 携帯端末装置、認証システム、認証方法、プログラムおよび集積回路 |
| JP2016099684A (ja) * | 2014-11-18 | 2016-05-30 | インターマン株式会社 | ライフログを利用した本人確認方法および本人確認装置 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPWO2022018833A1 (ja) * | 2020-07-21 | 2022-01-27 | ||
| WO2022018833A1 (ja) * | 2020-07-21 | 2022-01-27 | 日本電気株式会社 | 人検知システム、サーバ装置、人検知方法、コンピュータ可読媒体、及びマスク |
| JP7533586B2 (ja) | 2020-07-21 | 2024-08-14 | 日本電気株式会社 | 人検知システム、サーバ装置、人検知方法、及びプログラム |
Also Published As
| Publication number | Publication date |
|---|---|
| US11483713B2 (en) | 2022-10-25 |
| JP2019109858A (ja) | 2019-07-04 |
| CN111316264B (zh) | 2026-04-07 |
| US11871239B2 (en) | 2024-01-09 |
| JP7007177B2 (ja) | 2022-01-24 |
| US20230021132A1 (en) | 2023-01-19 |
| CN111316264A (zh) | 2020-06-19 |
| US20200322792A1 (en) | 2020-10-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7007177B2 (ja) | 端末機器、本人認証システムおよび本人認証方法 | |
| US12261839B2 (en) | User authentication system and portable terminal | |
| US12625932B2 (en) | Identity authentication using biometrics | |
| JP6186087B2 (ja) | 操作権限付与方法、操作権限付与装置、プログラム及び記録媒体 | |
| EP2610708B1 (en) | Communication apparatus | |
| US20190026722A1 (en) | Payment processing using a wearable device | |
| JP2009135688A (ja) | 認証方法、認証システムおよび車載装置 | |
| US20200134602A1 (en) | Method and apparatus for determining device for payment in multiple electronic devices | |
| KR20140121514A (ko) | 체크인 처리 방법 | |
| JP6108904B2 (ja) | サーバ装置、携帯端末、および決済端末 | |
| KR20170039463A (ko) | 사용자 장치, 비콘, 서비스 제공 장치, 그를 포함하는 결제 시스템, 그의 제어 방법 및 컴퓨터 프로그램이 기록된 기록매체 | |
| CN111062712B (zh) | 用于激活便携式非接触支付对象的方法和系统 | |
| JP2023126410A (ja) | 使用者認証システムおよび携帯端末 | |
| KR20160070080A (ko) | 이동 데이터 단말기용 인증 시스템 | |
| JP2018148341A (ja) | センサネットワークシステム、センサ接続端末、データ収集方法、およびセンサ接続方法 | |
| KR101794832B1 (ko) | 무인단말기와 휴대통신기기의 네트워크 형성 시스템 및 그 방법 | |
| JP6820667B2 (ja) | マイグレーション方法、マイグレーションプログラム、サービス提供サーバ及びサービス提供システム | |
| KR101780566B1 (ko) | 이동 단말기 및 그의 동작 방법 | |
| JP2006236119A (ja) | 情報端末、認証装置及び認証システム | |
| KR102163676B1 (ko) | 동적 분할 코드를 이용한 다중 인증 방법 | |
| CN109448140B (zh) | 一种基于nfc终端的电子票务系统及其工作方法 | |
| JP7077089B2 (ja) | 携帯型端末、プログラム、クレジットカード、及びクレジットカード端末 | |
| KR20260058345A (ko) | 인증을 통한 안전한 오더 알선 시스템 | |
| JP2022156519A (ja) | プログラム | |
| JP2023050398A (ja) | 情報処理装置及びプログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18890615 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18890615 Country of ref document: EP Kind code of ref document: A1 |