WO2021192193A1 - 管理サーバ、システム、トークン発行方法及び記憶媒体 - Google Patents
管理サーバ、システム、トークン発行方法及び記憶媒体 Download PDFInfo
- Publication number
- WO2021192193A1 WO2021192193A1 PCT/JP2020/013892 JP2020013892W WO2021192193A1 WO 2021192193 A1 WO2021192193 A1 WO 2021192193A1 JP 2020013892 W JP2020013892 W JP 2020013892W WO 2021192193 A1 WO2021192193 A1 WO 2021192193A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- passport
- token
- management server
- terminal
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 136
- 230000004044 response Effects 0.000 claims description 16
- 230000005540 biological transmission Effects 0.000 claims description 6
- 238000012545 processing Methods 0.000 description 48
- 238000004891 communication Methods 0.000 description 33
- 230000006870 function Effects 0.000 description 15
- 238000010586 diagram Methods 0.000 description 11
- 239000000284 extract Substances 0.000 description 6
- 230000000694 effects Effects 0.000 description 5
- 238000012986 modification Methods 0.000 description 4
- 230000004048 modification Effects 0.000 description 4
- 238000013527 convolutional neural network Methods 0.000 description 2
- 238000000605 extraction Methods 0.000 description 2
- 230000001815 facial effect Effects 0.000 description 2
- 230000010365 information processing Effects 0.000 description 2
- 238000007689 inspection Methods 0.000 description 2
- 239000004065 semiconductor Substances 0.000 description 2
- 238000012795 verification Methods 0.000 description 2
- 230000002457 bidirectional effect Effects 0.000 description 1
- 238000004590 computer program Methods 0.000 description 1
- 238000000151 deposition Methods 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 239000004973 liquid crystal related substance Substances 0.000 description 1
- 238000010295 mobile communication Methods 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 230000001151 other effect Effects 0.000 description 1
- 230000001052 transient effect Effects 0.000 description 1
- 230000001960 triggered effect Effects 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/40—Business processes related to the transportation industry
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/02—Reservations, e.g. for tickets, services or events
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q50/00—Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
- G06Q50/10—Services
- G06Q50/26—Government or public services
- G06Q50/265—Personal security, identity or safety
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B15/00—Arrangements or apparatus for collecting fares, tolls or entrance fees at one or more control points
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/30—Individual registration on entry or exit not involving the use of a pass
- G07C9/32—Individual registration on entry or exit not involving the use of a pass in combination with an identity check
- G07C9/37—Individual registration on entry or exit not involving the use of a pass in combination with an identity check using biometric data, e.g. fingerprints, iris scans or voice recognition
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q2220/00—Business processing using cryptography
- G06Q2220/10—Usage protection of distributed data files
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/20—Individual registration on entry or exit involving the use of a pass
- G07C9/27—Individual registration on entry or exit involving the use of a pass with central registration
Definitions
- the present invention relates to a management server, a system, a token issuing method, and a storage medium.
- Patent Document 1 describes ticketless boarding, which uses passenger biometric information (face image) to perform various procedures by face recognition at multiple checkpoints (check-in lobby, security checkpoint, boarding gate, etc.) in the airport. The system is disclosed.
- Patent Document 1 only discloses the configuration for using face recognition for a specific business in the airport, and does not disclose the conditions for system registration for using face recognition.
- An object of the present invention is to provide a management server, a system, a token issuing method, and a storage medium that contribute to eliminating users who are not qualified to use a boarding procedure system using biometric authentication. ..
- the receiving unit that receives at least the boarding pass information written on the boarding pass and the token issuance request including the passport information written on the passport from the terminal, and the boarding pass information. It includes a generation unit that makes a first determination regarding the consistency of the passport information and generates a token for the user to use the boarding procedure using biometric information based on the result of the first determination.
- the management server is provided.
- the management server includes a terminal and a management server connected to the terminal, and the management server is described in at least the boarding pass information and the passport described in the boarding pass from the terminal.
- the receiving unit which receives the token issuance request including the passport information, makes a first determination regarding the consistency between the boarding pass information and the passport information, and based on the result of the first determination, the user is a living body.
- a system is provided that includes a generator that generates tokens for using information-based boarding procedures.
- the management server receives a token issuance request including at least the boarding pass information written on the boarding pass and the passport information written on the passport from the terminal, and the boarding pass information and the above-mentioned boarding pass information.
- a token issuing method for making a first determination regarding the integrity of the passport information and generating a token for the user to use the boarding procedure using biometric information based on the result of the first determination.
- a computer-readable storage medium is provided that stores a program for processing and executing.
- a management server, a system, a token issuing method and a storage medium that contribute to eliminating users who are not qualified to use a boarding procedure system using biometric authentication are provided. ..
- the effect of the present invention is not limited to the above. According to the present invention, other effects may be produced in place of or in combination with the effect.
- the management server 100 includes a receiving unit 101 and a generating unit 102 (see FIG. 1).
- the receiving unit 101 receives from the terminal a token issuance request including at least the boarding pass information written on the boarding pass and the passport information written on the passport.
- the generation unit 102 makes a first determination regarding the consistency between the boarding pass information and the passport information, and based on the result of the first determination, generates a token for the user to use the boarding procedure using the biometric information. ..
- BP Boarding Pass
- PP Passport
- BP Boarding Pass
- PP Passport
- BP Boarding Pass
- PP Passport
- Boarding procedures using biometrics are automated by computers (servers, terminals) and there is little room for human intervention. Therefore, if the name on the boarding pass and passport is spelled differently, part of the name is omitted, or the order of description (first name and last name) is different, it will be stated on the boarding pass and passport.
- the management server 100 confirms the consistency between the boarding pass and the passport acquired via the terminal. For example, the management server 100 transmits the acquired boarding pass information to a server managed by the airline company (airline company server 30 described later), and inquires about the passport information corresponding to the boarding pass information. If the passport information presented to the terminal matches the passport information obtained from the airline company, the management server 100 determines that the passport of the passenger who is permitted to board the aircraft has been presented to the terminal, and performs biometric authentication. Issue a token to receive the boarding procedure used.
- the management server 100 is a terminal of a third party (a user who is not qualified to use the boarding procedure using biometric authentication) who has not been issued a boarding pass. Judging that you are presenting your passport to, do not issue a token.
- the management server 100 stores the passport information held by the airline server (DCS; Departure Control System) that stores the reservation information that is the basis of the boarding pass information, and the passport information that the user has on the boarding date. Identity verification is performed by collating.
- DCS Departure Control System
- the token is not issued to a third party who is not qualified to use the boarding procedure system using biometric authentication, and the third party is excluded from the boarding procedure using biometric authentication.
- FIG. 2 is a diagram showing an example of a schematic configuration of the boarding procedure system according to the first embodiment.
- the boarding procedure system according to the first embodiment is a system that realizes a series of procedures (luggage deposit, security check, etc.) at the airport by biometric authentication.
- the boarding procedure system shown in FIG. 2 is operated by, for example, a public institution such as an immigration control bureau or a trustee who has been entrusted with business by the public institution.
- boarding procedure indicates a series of procedures performed from check-in to boarding an aircraft.
- the boarding procedure system includes a check-in terminal 10, a baggage deposit machine 11, a passenger passage system 12, a gate device 13, a boarding gate device 14, a management server 20, and an airline server 30. ..
- the check-in terminal 10, the baggage deposit machine 11, the passenger passage system 12, the gate device 13, and the boarding gate device 14 are terminals (touch points) installed at the airport. These terminals are connected to the management server 20 via a network.
- the network shown in FIG. 2 is composed of a LAN (Local Area Network) including an airport premises communication network, a WAN (Wide Area Network), a mobile communication network, and the like.
- the connection method is not limited to the wired method and may be a wireless method.
- the management server 20 and the airline server 30 are also connected via a network.
- the management server 20 and the airline server 30 are installed in facilities such as an airport company and an airline company. Alternatively, these servers may be servers installed in the cloud on the network.
- the configuration shown in FIG. 2 is an example, and does not mean to limit the configuration of the boarding procedure system.
- the boarding procedure system may include terminals and the like (not shown).
- the user's boarding procedure is performed by each terminal shown in Fig. 2. Specifically, a series of procedures when a user leaves Japan is sequentially carried out at terminals installed at five locations.
- the boarding procedure of the user is realized by authentication using biometric information (biometric authentication).
- the check-in terminal 10 When a user (system user) who wishes to carry out boarding procedures by biometric authentication arrives at the airport, he / she operates the check-in terminal 10 to perform "check-in procedures".
- the system user presents a paper ticket, a two-dimensional bar code on which boarding information is written, a mobile terminal displaying a copy of the e-ticket, and the like to the check-in terminal 10.
- the check-in terminal 10 outputs a boarding pass when the check-in procedure is completed.
- the boarding pass includes a paper boarding pass and an electronic boarding pass.
- a system user who has completed the check-in procedure and wishes to carry out the boarding procedure by biometric authentication uses the check-in terminal 10 to register the system. Specifically, the system user loads the acquired boarding pass and passport into the check-in terminal 10. In addition, the check-in terminal 10 acquires biometric information (for example, a face image) of the system user.
- biometric information for example, a face image
- the check-in terminal 10 transmits information related to these (boarding pass, passport, biometric information) to the management server 20.
- the management server 20 confirms the validity of the information acquired from the check-in terminal 10. Specifically, the management server 20 determines the consistency between the boarding pass and the passport and the validity of the passport presented to the check-in terminal 10. When the management server 20 confirms the validity of the information acquired from the check-in terminal 10, the management server 20 registers the system user. Specifically, the management server 20 issues a token used for the boarding procedure of the user registered in the system.
- the issued token is identified by the token ID (Identifier).
- Information required for boarding procedures for example, biometric information, business information required for boarding procedures, etc.
- the token ID is associated via a token ID. That is, the "token” is issued together with the registration of the system user, and is the identification information for the registered system user to undergo the boarding procedure using the biometric information.
- the token token ID
- the system user can use the boarding procedure using biometric authentication.
- biometric information for example, a face image
- the terminal transmits an authentication request including a face image to the management server 20.
- the management server 20 specifies the token ID by a collation process (1 to N collation; N is a positive integer, the same applies hereinafter) using the biometric information acquired from the terminal and the biometric information registered in the system.
- the user's boarding procedure is carried out based on the business information associated with the specified token ID.
- the check-in terminal 10 is installed in the check-in lobby in the airport. As described above, the user performs system registration for realizing the boarding procedure using biometric authentication using the check-in terminal 10. In addition, the system user operates the check-in terminal 10 to perform the check-in procedure. That is, the check-in terminal 10 is also a self-terminal for performing a check-in procedure by being operated by the user.
- the check-in terminal 10 is also referred to as a CUSS (Common Use Self Service) terminal. After completing the check-in procedure, the user will move to the baggage deposit area or security checkpoint.
- CUSS Common Use Self Service
- the baggage deposit machine 11 is installed in an area adjacent to the baggage counter (manned counter) in the airport or in an area near the check-in terminal 10.
- the baggage deposit machine 11 is a self-terminal for performing a procedure (baggage deposit procedure) for depositing baggage that is not brought into the aircraft by being operated by the user.
- the baggage deposit machine 11 is also referred to as a CUBD (Common Use Bag Drop) terminal. After completing the baggage check-in procedure, the user will move to the security checkpoint. If the user does not check the baggage, the baggage check-in procedure is omitted.
- the passenger passage system 12 is a gate device installed at the entrance of the security checkpoint in the airport.
- the passenger passage system 12 also called a PRS (Passenger Reconciliation System) is a system for determining whether or not a user can pass through at the entrance of a security checkpoint.
- PRS Passenger Reconciliation System
- the gate device 13 is installed at the immigration checkpoint in the airport.
- the gate device 13 is a device that automatically performs the departure examination procedure of the user. After completing the departure examination procedure, the user will move to the departure area where duty-free shops and boarding gates are provided.
- the boarding gate device 14 is a traffic control device installed for each boarding gate in the departure area.
- the boarding gate device 14 is also referred to as an ABG (Automated Boarding Gates) terminal.
- the boarding gate device 14 confirms that the user is a passenger of an aircraft that can board from the boarding gate. After passing through the boarding gate device 14, the user boarded the aircraft and departed for a second country.
- the boarding procedure using biometric authentication by each device (check-in terminal 10, baggage deposit machine 11, passenger passage system 12, gate device 13, boarding gate device 14) shown in FIG. 2 is an example and is used for the procedure. It is not intended to limit the devices to be used. For example, a device different from the above device may be used for the boarding procedure, or some of the above devices may not be used for the procedure. For example, the gate device 13 may not be included in the check-in system.
- the management server 20 is a server device for supporting and managing the above boarding procedure.
- the management server 20 manages the token ID. Specifically, the management server 20 issues and invalidates the token ID.
- the management server 20 processes authentication requests from various terminals in the airport.
- the airline server 30 is a server device managed by the airline.
- the airline server 30 includes a database that stores airline ticket reservation information.
- the airline server 30 stores the information about the passport acquired at the time of booking the ticket and the reservation information of the ticket in association with each other.
- the airline server 30 is also referred to as a DCS (Departure Control System).
- the airline server 30 may store all the information described in the passport in association with the reservation information, or may store some information described in the passport in association with the reservation information. May be good.
- boarding pass information is all or part of the reservation information stored in the airline server 30. That is, the boarding pass shows all or part of the reservation information.
- the information written on the passport (part or all of the information written on the passport) will be referred to as "passport information”.
- the user who wishes to perform the boarding procedure using biometric authentication operates the check-in terminal 10 to register the system.
- the user loads the boarding pass and passport in possession into the check-in terminal 10.
- the check-in terminal 10 acquires the user's biological information (for example, a face image).
- the check-in terminal 10 generates a "token issuance request" including the three acquired information (boarding pass information, passport information, and biometric information).
- the check-in terminal 10 transmits the generated token issuance request to the management server 20.
- the management server 20 retrieves boarding pass information and passport information included in the token issuance request.
- the management server 20 determines the consistency between the boarding pass and the passport presented to the check-in terminal 10 using the two pieces of information. Specifically, the management server 20 determines whether or not the person who is permitted to board the aircraft for which the boarding pass has been issued matches the person who has been issued the passport presented at the check-in terminal 10. do.
- the management server 20 transmits the boarding pass information (all or part of the reservation information) acquired from the check-in terminal 10 to the airline server 30 in order to determine the consistency.
- the airline server 30 searches the database using the acquired boarding pass information as a key, and transmits the corresponding passport information to the management server 20.
- the management server 20 compares the passport information acquired from the check-in terminal 10 with the passport information acquired from the airline server 30, and determines whether or not these information match.
- the management server 20 determines that the boarding pass and the passport presented to the check-in terminal 10 are consistent.
- the management server 20 determines the validity of the passport presented to the check-in terminal 10. Specifically, the management server 20 determines whether or not the person who presented the passport to the check-in terminal 10 and the person who received the issuance of the passport are the same person. More specifically, the management server 20 determines whether or not the face image included in the passport information (hereinafter referred to as the passport face image) and the face image captured by the check-in terminal 10 substantially match.
- the passport face image included in the passport information
- the management server 20 determines that the system user has presented the correct passport to the check-in terminal 10 (the passport presented to the check-in terminal 10 is). Judge as legitimate).
- the management server 20 performs the boarding procedure. Generate a token to receive.
- the management server 20 adds an entry to each of the database that stores the detailed information of the generated token and the database that stores the business information.
- the management server 20 rejects (rejects) the token issuance request from the check-in terminal 10.
- check-in terminal 10 is a device that provides system users with operations related to check-in procedures and system registration.
- FIG. 3 is a diagram showing an example of a processing configuration (processing module) of the check-in terminal 10 according to the first embodiment.
- the check-in terminal 10 includes a communication control unit 201, a system registration unit 202, a token issuance request unit 203, a message output unit 204, a check-in execution unit 205, and a storage unit 206. include.
- the communication control unit 201 is a means for controlling communication with other devices. Specifically, the communication control unit 201 receives data (packets) from the management server 20 and the airline server 30. Further, the communication control unit 201 transmits data to the management server 20 and the airline server 30. The communication control unit 201 delivers the data received from the other device to the other processing module. The communication control unit 201 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 201. The communication control unit 201 functions as a transmission unit and a reception unit.
- the system registration unit 202 is a means for registering the system of a user who wishes to carry out boarding procedures by biometric authentication.
- the system registration unit 202 provides the user with a GUI (Graphical User Interface) for confirming whether or not the user desires "boarding procedure using a face image" after the check-in procedure is completed. (See Fig. 4).
- GUI Graphic User Interface
- the system registration unit 202 acquires the three pieces of information using the GUI for acquiring the three pieces of information (boarding pass information, passport information, and biometric information).
- the system registration unit 202 includes three submodules.
- FIG. 5 is a diagram showing an example of a processing configuration (processing module) of the system registration unit 202 according to the first embodiment. As shown in FIG. 5, the system registration unit 202 includes a boarding pass information acquisition unit 211, a passport information acquisition unit 212, and a biometric information acquisition unit 213.
- the boarding pass information acquisition unit 211 is a means for acquiring boarding pass information from the boarding pass possessed by the system user.
- the boarding pass information acquisition unit 211 controls a reader (not shown) such as a scanner to acquire the information (boarding pass information) written on the boarding pass.
- Boarding pass information includes name (last name, first name), airline code, flight number, boarding date, departure place (boarding airport), destination (arrival airport), seat number, boarding time, arrival time, etc.
- the passport information acquisition unit 212 is a means for acquiring passport information from the passport possessed by the system user.
- the passport information acquisition unit 212 controls a reader such as a scanner to acquire the information (passport information) written in the passport.
- Passport information includes passport face image, name, gender, nationality, passport number, passport issuing country, etc.
- the biometric information acquisition unit 213 is a means for acquiring the biometric information of the system user.
- the biological information acquisition unit 213 controls the camera and acquires a facial image of the system user. For example, when the biometric information acquisition unit 213 detects a face in an image to be constantly or periodically photographed, the biometric information acquisition unit 213 photographs the user's face and acquires the face image.
- the biological information acquisition unit 213 displays a guidance message regarding the acquisition of the face image via the message output unit 204 before photographing the face image.
- the biometric information acquisition unit 213 displays a message such as "The customer's face image is taken and registered in the system. The registered face image will be deleted from the system after boarding is completed.”
- the system registration unit 202 delivers the acquired three pieces of information (boarding pass information, passport information, and biometric information) to the token issuance request unit 203.
- the token issuance request unit 203 shown in FIG. 3 is a means for requesting the management server 20 to issue a token.
- the token issuance request unit 203 generates a token issuance request including boarding pass information, passport information, and biometric information (face image).
- the token issuance request unit 203 generates a token issuance request including an identifier of the own device (hereinafter referred to as a check-in terminal identifier), the boarding pass information, and the like (see FIG. 6).
- the check-in terminal identifier the MAC (Media Access Control) address or IP (Internet Protocol) address of the check-in terminal 10 can be used.
- the token issuance request unit 203 transmits the generated token issuance request to the management server 20.
- the token issuance request unit 203 delivers the response (response to the token issuance request) acquired from the management server 20 to the message output unit 204.
- the message output unit 204 is a means for outputting various messages. For example, the message output unit 204 outputs a message according to the response obtained from the management server 20.
- the message output unit 204 When a response (affirmative response) indicating that the token issuance was successful is received, the message output unit 204 outputs that fact. For example, the message output unit 204 outputs a message such as "Future procedures can be performed by face recognition".
- the message output unit 204 When receiving a response (negative response) to the effect that the token issuance failed, the message output unit 204 outputs that fact. For example, the message output unit 204 outputs a message such as "Sorry. The procedure by face recognition cannot be performed. Please go to the manned booth.”
- the check-in execution unit 205 is a means for performing the check-in procedure of the user.
- the check-in execution unit 205 executes a check-in procedure such as seat selection based on the ticket presented by the user.
- the check-in execution unit 205 transmits the information described in the ticket to the DCS (airline server 30) and acquires the information described in the boarding pass from the DCS. Since the operation of the check-in execution unit 205 can be the same as the operation of the existing check-in terminal, a more detailed description will be omitted.
- the storage unit 206 is a means for storing information necessary for the operation of the check-in terminal 10.
- FIG. 7 is a diagram showing an example of a processing configuration (processing module) of the baggage deposit machine 11 according to the first embodiment.
- the baggage deposit machine 11 includes a communication control unit 301, a biometric information acquisition unit 302, an authentication request unit 303, a function realization unit 304, and a storage unit 305.
- the communication control unit 301 is a means for controlling communication with other devices. Specifically, the communication control unit 301 receives data (packets) from the management server 20. Further, the communication control unit 301 transmits data to the management server 20. The communication control unit 301 delivers the data received from the other device to the other processing module. The communication control unit 301 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 301.
- the communication control unit 301 functions as a transmission unit and a reception unit.
- the biometric information acquisition unit 302 is a means for controlling a camera (not shown) and acquiring the biometric information of the user.
- the biological information acquisition unit 302 images the front of the own device at regular intervals or at a predetermined timing.
- the biological information acquisition unit 302 determines whether or not the acquired image includes a human face image, and if the acquired image includes a face image, extracts the face image from the acquired image data.
- the biological information acquisition unit 302 may extract a face image (face region) from the image data by using a learning model learned by CNN (Convolutional Neural Network).
- the biological information acquisition unit 302 may extract a face image by using a technique such as template matching.
- the biometric information acquisition unit 302 delivers the extracted face image to the authentication request unit 303.
- the authentication request unit 303 is a means for requesting the management server 20 to authenticate the user in front of him.
- the authentication request unit 303 generates an authentication request including the acquired face image and transmits it to the management server 20.
- the authentication request unit 303 receives a response from the management server 20 to the authentication request.
- the authentication request unit 303 notifies the visitor to that effect.
- the authentication request unit 303 If the authentication result is "authentication successful", the authentication request unit 303 notifies the function realization unit 304 to that effect. Further, the authentication request unit 303 delivers the "business information" acquired from the management server 20 to the function realization unit 304.
- the function realization unit 304 is a means for realizing the "baggage deposit" function of the baggage deposit machine 11.
- the function realization unit 304 identifies the boarding flight of the baggage deposited by the user from the acquired business information, and attaches a label or the like so that the baggage is accommodated in the boarding flight. Since the operation of the function realization unit 304 can be the same as the operation of the existing baggage deposit machine, detailed description thereof will be omitted.
- the storage unit 305 is a means for storing information necessary for the operation of the baggage deposit machine 11.
- Each terminal acquires the biometric information (face image) of the system user and requests the management server 20 to authenticate using the acquired biometric information. If the authentication is successful, the function assigned to each terminal is executed.
- FIG. 8 is a diagram showing an example of a processing configuration (processing module) of the management server 20 according to the first embodiment.
- the management server 20 includes a communication control unit 401, a token generation unit 402, a database management unit 403, an authentication request processing unit 404, and a storage unit 405.
- the communication control unit 401 is a means for controlling communication with other devices. Specifically, the communication control unit 401 receives data (packets) from the check-in terminal 10 or the like. In addition, the communication control unit 401 transmits data to the check-in terminal 10 and the like. The communication control unit 401 delivers the data received from the other device to the other processing module. The communication control unit 401 transmits the data acquired from the other processing module to the other device. In this way, the other processing module transmits / receives data to / from the other device via the communication control unit 401. The communication control unit 401 functions as a transmission unit and a reception unit.
- the token generation unit 402 is a means for generating tokens in response to a token generation request from the check-in terminal 10.
- the token generation unit 402 issues a token when the two determinations described above are successful.
- the first judgment is a judgment regarding the consistency between boarding pass information and passport information.
- the second determination is a determination regarding the validity of the passport presented to the check-in terminal 10.
- the token generation unit 402 makes the first determination.
- the token generation unit 402 determines whether or not the person who is permitted to board the aircraft for which the boarding pass has been issued matches the person who has been issued the passport presented to the check-in terminal 10. Specifically, the token generation unit 402 seems to have issued the passport presented to the check-in terminal 10 to the user B while the user A is registered as a passenger in the DCS (airline server 30). Make sure that no situation has occurred. That is, the token generation unit 402 confirms the identity of the passport that is the basis for issuing the boarding pass (airline ticket) and the passport presented at the time of system registration in the first determination.
- the token generation unit 402 transmits the boarding pass information acquired from the check-in terminal 10 to the airline server 30. Specifically, the token generation unit 402 transmits boarding pass information that can identify one of the plurality of reservation information stored in the airline server 30 to the airline server 30. For example, the token generation unit 402 transmits to the airline server 30 as boarding pass information such as an airline code, flight number, boarding date, and seat number.
- the airline server 30 searches the database and identifies the passport information corresponding to the acquired boarding pass information.
- the airline server 30 transmits (replies) the specified passport information to the management server 20.
- the token generation unit 402 compares the passport information acquired from the check-in terminal 10 with the passport information acquired from the airline server 30 and determines whether or not they match. At that time, the token generation unit 402 may confirm that all the information described in the passport matches, or may confirm that some of the information match.
- the token generator 402 determines whether or not the passport number and the issuing country included in the two passport information match. Since the name is not suitable for determining the identity, information different from the name (combination of passport number and issuing country) is used to determine whether or not the two passport information match. Is desirable.
- the token generation unit 402 determines that the boarding pass presented on the check-in terminal 10 and the passport are consistent. If the above two passport information does not match, the token generation unit 402 determines that the boarding pass presented to the check-in terminal 10 and the passport are not consistent.
- the token generation unit 402 makes a second determination.
- the token generation unit 402 determines whether or not the person who presented the passport to the check-in terminal 10 and the person who received the issuance of the passport are the same person. Specifically, the passport presented to the check-in terminal 10 was issued to the user C, but there is no situation in which the user standing in front of the check-in terminal 10 is the user D. Make sure that. That is, the check-in terminal 10 confirms that the system user has not presented the passport issued to another person to the check-in terminal 10.
- the token generation unit 402 extracts the face image (system user's face image) included in the token generation request and the passport face image included in the passport information. The token generation unit 402 determines whether or not these two face images substantially match.
- the token generation unit 402 executes collation (one-to-one collation) of the above two face images.
- the token generation unit 402 calculates a feature vector from each of the two images.
- the token generation unit 402 calculates the similarity (for example, Euclidean distance) between the two images, and determines whether or not the two images are facial images of the same person based on the result of the threshold processing for the calculated similarity. do. For example, if the similarity is greater than the predetermined value (if the distance is shorter than the predetermined value), the token generation unit 402 determines that the two face images are from the same person.
- the token generation unit 402 issues a token when the boarding pass and passport consistency determination (first determination) and the passport validity determination using biometric information (second determination) are successful. For example, the token generation unit 402 generates a unique value as the token ID based on the date and time at the time of processing, the sequence number, and the like.
- the token generation unit 402 When the token generation unit 402 generates a token (token ID), it sends an acknowledgment (token issuance) to the check-in terminal 10. When the token ID generation unit 402 fails to generate the token ID, the token generation unit 402 sends a negative response (token not issued) to the check-in terminal 10.
- the token ID generation unit 402 When the token ID generation unit 402 succeeds in generating (issuing) the token ID, it hands over the generated token ID, boarding pass information, passport information, and face image (face image of the system user) to the database management unit 403.
- the database management unit 403 is a means for managing various databases built on the management server 20.
- the management server 20 includes a token ID information database and a business information database.
- the token ID information database stores at least the token ID and the biometric information of the user in association with each other.
- FIG. 9 is a diagram showing an example of a token ID information database. Referring to FIG. 9, the token ID information database has fields for storing a token ID, a registered face image, a feature amount, a token issuing time, a token issuing device name, an invalid flag, an invalidation time, and the like.
- the token ID is a temporarily issued identifier.
- the token ID is invalidated. That is, the token ID is not an identifier that is used permanently, but a one-time ID that has a valid period (life cycle).
- the registered face image is the face image of the system user.
- the registered face image may be a user's face image captured by the check-in terminal 10 or a passport face image.
- the feature quantity is a feature vector generated from the face image.
- the token issuance time is the time when the management server 20 issues the token ID.
- the device name is the device name (check-in terminal 10) from which the registered face image was acquired, which triggered the issuance of the token ID.
- the invalid flag is flag information indicating whether or not the token ID is currently valid. The invalid flag is set to "1" if the token ID is valid, and cleared to "0" if it is invalid.
- the invalidation time is a time stamp when the token ID is invalidated.
- the business information database is a database that manages information (business information) necessary for performing boarding procedures for users.
- FIG. 10 is a diagram showing an example of a business information database.
- the business information database has fields for storing a token ID, a passenger name, a departure place, a destination, an airline code, a flight number, an operation date, and the like.
- the business information database may have fields for storing sheet numbers, nationalities, passport numbers, surnames, first names, dates of birth, gender, and the like.
- the business information database stores business information related to a predetermined business (procedure business performed at each touch point) for each token ID.
- the above information stored in the business information database is obtained from boarding pass information and passport information.
- the database management unit 403 When the database management unit 403 acquires the token ID from the token generation unit 402 (when the token ID is issued), the database management unit 403 adds a new entry to the above two databases.
- the database management unit 403 sets the set values in the fields of each database. For example, the database management unit 403 generates a feature amount from the registered face image and registers the generated feature amount in the token ID information database.
- the database management unit 403 may set an initial value (default value) for a field for which a set value cannot be set.
- the authentication request processing unit 404 is a means for processing the authentication request acquired from the terminal.
- the authentication request includes the biometric information of the person to be authenticated.
- the authentication request processing unit 404 executes a collation process (1 to N collation) using the biometric information included in the authentication request and the biometric information included in the token ID information database.
- the authentication request processing unit 404 generates a feature amount from the face image acquired from the terminal.
- the authentication request processing unit 404 extracts feature points from the face image. Since the existing technique can be used for the extraction process of the feature points, the detailed description thereof will be omitted. For example, the authentication request processing unit 404 extracts eyes, nose, mouth, and the like as feature points from the face image. After that, the authentication request processing unit 404 calculates the position of each feature point and the distance between each feature point as a feature quantity, and generates a feature vector composed of a plurality of feature quantities.
- the authentication request processing unit 404 sets the generated feature amount (feature vector) as the feature amount on the collation side and the feature amount registered in the token ID information database as the feature amount on the registration side.
- the authentication request processing unit 404 calculates the degree of similarity between the feature amount on the collation side and each of the plurality of feature amounts on the registration side. For the similarity, a chi-square distance, an Euclidean distance, or the like can be used. The farther the distance is, the lower the similarity is, and the shorter the distance is, the higher the similarity is.
- the authentication request processing unit 404 says that the authentication is successful if, among the plurality of features registered in the token ID information database, there is a feature whose similarity with the feature to be collated is equal to or higher than a predetermined value. to decide.
- the authentication request processing unit 404 identifies the token ID corresponding to the feature amount having the highest degree of similarity.
- the authentication request processing unit 404 searches the business information database using the specified token ID as a key, and identifies the corresponding business information (passenger name, departure place, etc.).
- the authentication request processing unit 404 transmits the authentication result to the terminal (responds to the authentication request). If the authentication is successful, the authentication request processing unit 404 transmits a response including that fact (authentication success) and business information to the terminal. If the authentication fails, the authentication request processing unit 404 sends a response including that fact (authentication failure) to the terminal.
- the storage unit 405 stores various information necessary for the operation of the management server 20.
- a token ID information database and a business information database are constructed in the storage unit 405.
- FIG. 11 is a sequence diagram showing an example of the operation of the boarding procedure system according to the first embodiment. The operation when registering the user's system will be described with reference to FIG.
- the check-in terminal 10 transmits a token issuance request to the management server 20 (step S01).
- the management server 20 Upon receiving the token issuance request, the management server 20 executes a determination regarding the consistency between the boarding pass information and the passport information (executes the first determination).
- the management server 20 transmits all or part of the boarding pass information acquired from the check-in terminal 10 to the airline server 30 (step S02).
- the airline server 30 searches the database and transmits all or part of the passport information corresponding to the acquired boarding pass information to the management server 20 (step S03).
- the management server 20 determines whether or not the passport information acquired from the check-in terminal 10 and the passport information acquired from the airline server 30 match (step S04). That is, the management server 20 determines whether or not the above two passport information is the information described in the same passport (information obtained from the same passport).
- step S04 If the two passport information does not match (step S04, No branch), the management server 20 rejects the token issuance request. In this case, the management server 20 transmits a negative response to the check-in terminal 10 (step S08).
- step S04 If the two passport information match (step S04, Yes branch), the management server 20 executes a determination regarding the validity of the passport (executes the second determination).
- the management server 20 determines whether or not the face image captured by the check-in terminal 10 matches the passport face image (step S05).
- step S05 If the two face images do not match (step S05, No branch), the management server 20 rejects the token issuance request. In this case, the management server 20 transmits a negative response to the check-in terminal 10 (step S08).
- step S05 If the two face images match (step S05, Yes branch), the management server 20 issues a token (step S06). In this case, the management server 20 transmits an acknowledgment to the check-in terminal 10 (step S07).
- the management server 20 receives a token issuance request including at least boarding pass information and passport information from the check-in terminal 10.
- the management server 20 makes a first determination regarding the consistency between the boarding pass information and the passport information.
- the management server 20 generates a token for the user to use the boarding procedure using biometric information based on the result of the first determination. More specifically, the management server 20 transmits the acquired boarding pass information to the airline server 30, and receives the passport information corresponding to the boarding pass information transmitted from the airline server 30.
- the management server 20 generates a token when the passport information included in the token issuance request matches the passport information received from the airline server 30 and the presented passport is valid.
- tokens for using the procedure will not be issued to users who are not eligible for the boarding procedure using biometric authentication. Therefore, users who are not qualified to use the boarding procedure using biometric authentication are excluded from the target of the boarding procedure using biometric authentication.
- the management server 20 excludes users who try to use the boarding procedure by using biometric authentication by using the passport of another person by executing the second determination regarding the validity of the passport.
- the passport passport information
- FIG. 12 is a diagram showing an example of the hardware configuration of the management server 20.
- the management server 20 can be configured by an information processing device (so-called computer), and includes the configuration illustrated in FIG.
- the management server 20 includes a processor 311, a memory 312, an input / output interface 313, a communication interface 314, and the like.
- the components such as the processor 311 are connected by an internal bus or the like so that they can communicate with each other.
- the configuration shown in FIG. 12 does not mean to limit the hardware configuration of the management server 20.
- the management server 20 may include hardware (not shown) or may not include an input / output interface 313 if necessary.
- the number of processors 311 and the like included in the management server 20 is not limited to the example shown in FIG. 12, and for example, a plurality of processors 311 may be included in the management server 20.
- the processor 311 is a programmable device such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), and a DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs including an operating system (OS).
- OS operating system
- the memory 312 is a RAM (RandomAccessMemory), a ROM (ReadOnlyMemory), an HDD (HardDiskDrive), an SSD (SolidStateDrive), or the like.
- the memory 312 stores an OS program, an application program, and various data.
- the input / output interface 313 is an interface of a display device or an input device (not shown).
- the display device is, for example, a liquid crystal display or the like.
- the input device is, for example, a device that accepts user operations such as a keyboard and a mouse.
- the communication interface 314 is a circuit, module, or the like that communicates with another device.
- the communication interface 314 includes a NIC (Network Interface Card) and the like.
- the function of the management server 20 is realized by various processing modules.
- the processing module is realized, for example, by the processor 311 executing a program stored in the memory 312.
- the program can also be recorded on a computer-readable storage medium.
- the storage medium may be a non-transient such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product.
- the program can be downloaded via a network or updated using a storage medium in which the program is stored.
- the processing module may be realized by a semiconductor chip.
- the check-in terminal 10, the airline server 30, and the like can also be configured by the information processing device in the same manner as the management server 20, and the basic hardware configuration is the same as that of the management server 20, so the description thereof will be omitted. ..
- the check-in terminal 10 or the like may be provided with a camera, a scanner, or the like.
- the management server 20 is equipped with a computer, and the function of the management server 20 can be realized by causing the computer to execute a program. Further, the management server 20 executes the token issuing method by the program.
- the management server 20 may receive the token issuance request including at least the boarding pass information and the passport information, and make the first determination.
- the system registration is performed after the user's check-in procedure, but the system registration may be performed before the check-in procedure.
- the management server 20 may check the consistency between the ticket and the passport instead of the boarding pass. That is, the check-in terminal 10 transmits the ticket information (all or part of the information described in the ticket) to the management server 20.
- the management server 20 transmits the airline ticket information to the airline server 30 and acquires the corresponding passport information.
- the management server 20 may execute the first determination by confirming that the two passport information match.
- system registration registration for realizing boarding procedure using biometric authentication
- the system registration may be performed by a device or terminal other than the check-in terminal 10.
- a device dedicated to system registration may be installed at the airport, or system registration may be performed at a terminal (touch point) such as a baggage deposit machine 11 or a passenger passage system 12.
- the system may be registered by the baggage deposit machine 11, and the procedures (security inspection, etc.) after the baggage deposit may be performed by biometric authentication.
- some of the series of boarding procedures may be carried out at a manned booth or the like.
- the management server 20 and the airline server 30 have been described as separate devices, but the functions of these devices may be realized by one device (server).
- the token ID information database and the business information database built on the management server 20 may be built on a database server different from the management server 20. That is, the boarding procedure system may include various means (for example, token generating means) described in the above embodiment.
- the authentication request may include a feature amount generated from the face image.
- the management server 20 may process the authentication request using the feature amount extracted from the authentication request and the feature amount registered in the token ID information database.
- the form of data transmission / reception between the check-in terminal 10 or the like and the management server 20 is not particularly limited, but the data transmitted / received between these devices may be encrypted.
- Boarding pass information and passport information include personal information, and in order to properly protect the personal information, it is desirable that encrypted data be sent and received.
- each embodiment may be used alone or in combination. For example, it is possible to replace a part of the configuration of the embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of the embodiment. Further, it is possible to add, delete, or replace a part of the configuration of the embodiment with another configuration.
- the present invention is suitably applicable to a boarding procedure system at an airport or the like.
- [Appendix 1] A receiver that receives at least a token issuance request containing the boarding pass information written on the boarding pass and the passport information written on the passport from the terminal. A first determination regarding the consistency between the boarding pass information and the passport information is performed, and based on the result of the first determination, a token for the user to use the boarding procedure using biometric information is generated. Department and A management server.
- the generation unit generates the token when the person who is permitted to board the aircraft for which the boarding pass is issued and the person who has been issued the passport presented to the terminal match. The management server listed.
- the generation unit transmits the boarding pass information included in the token issuance request to an airline server that stores the passport information acquired at the time of ticket reservation and the ticket reservation information in association with each other, and the airline company. Receive the passport information corresponding to the boarding pass information sent from the server, The management server according to Appendix 1 or 2, which generates the token when the passport information included in the token issuance request and the passport information received from the airline server match.
- the management server according to Appendix 3 The management server according to Appendix 3, wherein the generation unit uses information different from the name to determine whether or not the passport information included in the token issuance request matches the passport information received from the airline server. ..
- the generation unit determines whether or not the passport information included in the token issuance request and the passport information received from the airline server match based on the passport number and the issuing country, according to Appendix 3 or 4. Management server.
- the generator makes a second determination regarding the validity of the passport presented to the terminal, and generates the token based on the results of the first and second determinations, any one of Supplementary notes 1 to 5.
- the generation unit determines whether or not the person who presented the passport to the terminal and the person who received the issuance of the passport presented to the terminal are the same person.
- the management server according to Appendix 6, which determines the above.
- the token issuance request includes the biometric information of the user.
- the management server according to Appendix 6 or 7, wherein the generation unit makes the second determination by one-to-one collation using the biometric information included in the token issuance request and the biometric information described in the passport.
- the management server according to any one of Supplementary note 1 to 8, further comprising a transmission unit that transmits a response to the token issuance request to the terminal.
- the management server With the terminal The management server connected to the terminal and Including The management server A receiving unit that receives at least a token issuance request including the boarding pass information written on the boarding pass and the passport information written on the passport from the terminal.
- a first determination regarding the consistency between the boarding pass information and the passport information is performed, and based on the result of the first determination, a token for the user to use the boarding procedure using biometric information is generated.
- Department and The system. [Appendix 11]
- On the management server Receive a token issuance request from the terminal, including at least the boarding pass information on the boarding pass and the passport information on the passport.
Landscapes
- Business, Economics & Management (AREA)
- Engineering & Computer Science (AREA)
- Tourism & Hospitality (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Human Resources & Organizations (AREA)
- Economics (AREA)
- Marketing (AREA)
- Computer Security & Cryptography (AREA)
- Development Economics (AREA)
- Health & Medical Sciences (AREA)
- Primary Health Care (AREA)
- General Health & Medical Sciences (AREA)
- Operations Research (AREA)
- Quality & Reliability (AREA)
- Entrepreneurship & Innovation (AREA)
- Educational Administration (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Human Computer Interaction (AREA)
- Finance (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Devices For Checking Fares Or Tickets At Control Points (AREA)
Abstract
Description
第1の実施形態について、図面を用いてより詳細に説明する。
図2は、第1の実施形態に係る搭乗手続きシステムの概略構成の一例を示す図である。第1の実施形態に係る搭乗手続きシステムは、空港における一連の手続き(荷物預け入れ、セキュリティチェック等)を生体認証にて実現するシステムである。図2に示す搭乗手続きシステムは、例えば、入出国の管理局等の公的機関や当該公的機関から業務の委託を受けた受託者により運営される。
続いて、図2を参照しつつ、搭乗手続きシステムの概略動作について説明する。
上述のように、チェックイン端末10は、システム利用者に対して、チェックイン手続とシステム登録に関する操作を提供する装置である。
図7は、第1の実施形態に係る手荷物預け機11の処理構成(処理モジュール)の一例を示す図である。図7を参照すると、手荷物預け機11は、通信制御部301と、生体情報取得部302と、認証要求部303と、機能実現部304と、記憶部305と、を含む。
搭乗手続きシステムに含まれる他の端末(旅客通過システム12、ゲート装置13、搭乗ゲート装置14)の基本的な処理構成は、図7に示す手荷物預け機11の処理構成と同一とすることができるので詳細な説明を省略する。いずれの端末も、システム利用者の生体情報(顔画像)を取得し、当該取得した生体情報を用いた認証を管理サーバ20に要求する。認証に成功すると、各端末に割り当てられた機能が実行される。
図8は、第1の実施形態に係る管理サーバ20の処理構成(処理モジュール)の一例を示す図である。図8を参照すると、管理サーバ20は、通信制御部401と、トークン生成部402と、データベース管理部403と、認証要求処理部404と、記憶部405と、を含む。
続いて、第1の実施形態に係る搭乗手続きシステムの動作を説明する。図11は、第1の実施形態に係る搭乗手続きシステムの動作の一例を示すシーケンス図である。なお、図11を用いて利用者のシステム登録をする際の動作を説明する。
なお、上記実施形態にて説明した搭乗手続きシステムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
[付記1]
端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信する、受信部と、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する、生成部と、
を備える、管理サーバ。
[付記2]
前記生成部は、前記搭乗券が発行された航空機への搭乗が許可された人物と前記端末に提示されたパスポートの発行を受けた人物が一致する場合に、前記トークンを生成する、付記1に記載の管理サーバ。
[付記3]
前記生成部は、前記トークン発行要求に含まれる搭乗券情報を、航空券の予約時に取得したパスポートの情報と前記航空券の予約情報を対応付けて記憶する航空会社サーバに送信し、前記航空会社サーバから前記送信された搭乗券情報に対応したパスポート情報を受信し、
前記トークン発行要求に含まれるパスポート情報と前記航空会社サーバから受信したパスポート情報が一致する場合に、前記トークンを生成する、付記1又は2に記載の管理サーバ。
[付記4]
前記生成部は、氏名とは異なる情報を用いて、前記トークン発行要求に含まれるパスポート情報と前記航空会社サーバから受信したパスポート情報が一致するか否かを判定する、付記3に記載の管理サーバ。
[付記5]
前記生成部は、パスポート番号及び発行国に基づいて、前記トークン発行要求に含まれるパスポート情報と前記航空会社サーバから受信したパスポート情報が一致するか否かを判定する、付記3又は4に記載の管理サーバ。
[付記6]
前記生成部は、前記端末に提示されたパスポートの正当性に関する第2の判定を行い、前記第1及び第2の判定の結果に基づき、前記トークンを生成する、付記1乃至5のいずれか一に記載の管理サーバ。
[付記7]
前記生成部は、前記端末にパスポートを提示した人物と、前記端末に提示されたパスポートの発行を受けた人物と、が同一人物か否かを判定することで、前記パスポートの正当性に関する第2の判定を行う、付記6に記載の管理サーバ。
[付記8]
前記トークン発行要求には、前記利用者の生体情報が含まれ、
前記生成部は、前記トークン発行要求に含まれる生体情報とパスポートに記載された生体情報を用いた1対1照合により、前記第2の判定を行う、付記6又は7に記載の管理サーバ。
[付記9]
前記トークン発行要求に対する応答を、前記端末に送信する、送信部をさらに備える、付記1乃至8のいずれか一に記載の管理サーバ。
[付記10]
端末と、
前記端末と接続された管理サーバと、
を含み、
前記管理サーバは、
前記端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信する、受信部と、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する、生成部と、
を備える、システム。
[付記11]
管理サーバにおいて、
端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信し、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する、トークン発行方法。
[付記12]
管理サーバに搭載されたコンピュータに、
端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信する処理と、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
11 手荷物預け機
12 旅客通過システム
13 ゲート装置
14 搭乗ゲート装置
20、100 管理サーバ
30 航空会社サーバ
101 受信部
102 生成部
201、301、401 通信制御部
202 システム登録部
203 トークン発行要求部
204 メッセージ出力部
205 チェックイン実行部
206、305、405 記憶部
211 搭乗券情報取得部
212 パスポート情報取得部
213、302 生体情報取得部
303 認証要求部
304 機能実現部
311 プロセッサ
312 メモリ
313 入出力インターフェイス
314 通信インターフェイス
402 トークン生成部
403 データベース管理部
404 認証要求処理部
Claims (12)
- 端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信する、受信部と、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する、生成部と、
を備える、管理サーバ。 - 前記生成部は、前記搭乗券が発行された航空機への搭乗が許可された人物と前記端末に提示されたパスポートの発行を受けた人物が一致する場合に、前記トークンを生成する、請求項1に記載の管理サーバ。
- 前記生成部は、前記トークン発行要求に含まれる搭乗券情報を、航空券の予約時に取得したパスポートの情報と前記航空券の予約情報を対応付けて記憶する航空会社サーバに送信し、前記航空会社サーバから前記送信された搭乗券情報に対応したパスポート情報を受信し、
前記トークン発行要求に含まれるパスポート情報と前記航空会社サーバから受信したパスポート情報が一致する場合に、前記トークンを生成する、請求項1又は2に記載の管理サーバ。 - 前記生成部は、氏名とは異なる情報を用いて、前記トークン発行要求に含まれるパスポート情報と前記航空会社サーバから受信したパスポート情報が一致するか否かを判定する、請求項3に記載の管理サーバ。
- 前記生成部は、パスポート番号及び発行国に基づいて、前記トークン発行要求に含まれるパスポート情報と前記航空会社サーバから受信したパスポート情報が一致するか否かを判定する、請求項3又は4に記載の管理サーバ。
- 前記生成部は、前記端末に提示されたパスポートの正当性に関する第2の判定を行い、前記第1及び第2の判定の結果に基づき、前記トークンを生成する、請求項1乃至5のいずれか一項に記載の管理サーバ。
- 前記生成部は、前記端末にパスポートを提示した人物と、前記端末に提示されたパスポートの発行を受けた人物と、が同一人物か否かを判定することで、前記パスポートの正当性に関する第2の判定を行う、請求項6に記載の管理サーバ。
- 前記トークン発行要求には、前記利用者の生体情報が含まれ、
前記生成部は、前記トークン発行要求に含まれる生体情報とパスポートに記載された生体情報を用いた1対1照合により、前記第2の判定を行う、請求項6又は7に記載の管理サーバ。 - 前記トークン発行要求に対する応答を、前記端末に送信する、送信部をさらに備える、請求項1乃至8のいずれか一項に記載の管理サーバ。
- 端末と、
前記端末と接続された管理サーバと、
を含み、
前記管理サーバは、
前記端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信する、受信部と、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する、生成部と、
を備える、システム。 - 管理サーバにおいて、
端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信し、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する、トークン発行方法。 - 管理サーバに搭載されたコンピュータに、
端末から、少なくとも搭乗券に記載された搭乗券情報及びパスポートに記載されたパスポート情報を含むトークン発行要求を受信する処理と、
前記搭乗券情報と前記パスポート情報の整合性に関する第1の判定を行い、前記第1の判定の結果に基づき、利用者が生体情報を用いた搭乗手続きを利用するためのトークンを生成する処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
Priority Applications (6)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2021566962A JP7006865B1 (ja) | 2020-03-27 | 2020-03-27 | 管理サーバ、システム、トークン発行方法及びコンピュータプログラム |
EP20927998.3A EP4131135A4 (en) | 2020-03-27 | 2020-03-27 | MANAGEMENT SERVER, SYSTEM, TOKEN ISSUANCE METHOD AND STORAGE MEDIUM |
PCT/JP2020/013892 WO2021192193A1 (ja) | 2020-03-27 | 2020-03-27 | 管理サーバ、システム、トークン発行方法及び記憶媒体 |
CN202080073416.XA CN114586054A (zh) | 2020-03-27 | 2020-03-27 | 管理服务器、系统、令牌发放方法和存储介质 |
US17/766,803 US20240070557A1 (en) | 2020-03-27 | 2020-03-27 | Management server, token issuance method, and storage medium |
JP2022000444A JP7276523B2 (ja) | 2020-03-27 | 2022-01-05 | 管理サーバ、システム、トークン発行方法及びコンピュータプログラム |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/JP2020/013892 WO2021192193A1 (ja) | 2020-03-27 | 2020-03-27 | 管理サーバ、システム、トークン発行方法及び記憶媒体 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2021192193A1 true WO2021192193A1 (ja) | 2021-09-30 |
Family
ID=77891020
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/JP2020/013892 WO2021192193A1 (ja) | 2020-03-27 | 2020-03-27 | 管理サーバ、システム、トークン発行方法及び記憶媒体 |
Country Status (5)
Country | Link |
---|---|
US (1) | US20240070557A1 (ja) |
EP (1) | EP4131135A4 (ja) |
JP (1) | JP7006865B1 (ja) |
CN (1) | CN114586054A (ja) |
WO (1) | WO2021192193A1 (ja) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP7100819B1 (ja) * | 2022-01-26 | 2022-07-14 | 日本電気株式会社 | 端末、システム、端末の制御方法及びプログラム |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003178346A (ja) * | 2001-12-07 | 2003-06-27 | Hitachi Ltd | 出国受付システム、出国審査システム、出国審査方法、旅券発給対象者情報の管理方法、出国改札システムの配置構造、入国受付システム、入国改札システム、入国審査システム、入国審査方法、入国改札システムの配置構造、及び旅券 |
JP2006236213A (ja) * | 2005-02-28 | 2006-09-07 | Digitalact:Kk | 認証システム |
JP2018045340A (ja) * | 2016-09-13 | 2018-03-22 | 株式会社日立製作所 | 出入国審査システム及び方法 |
Family Cites Families (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20080313088A1 (en) * | 2007-06-12 | 2008-12-18 | Cahn Robert S | Identification verification system |
CN107992855A (zh) * | 2017-12-22 | 2018-05-04 | 中国科学院重庆绿色智能技术研究院 | 一种基于人脸识别的机场安检三重验证方法 |
CN109499894A (zh) * | 2018-02-24 | 2019-03-22 | 北京首都机场航空安保有限公司 | 一种行李分拣系统 |
JP7264166B2 (ja) * | 2018-07-31 | 2023-04-25 | 日本電気株式会社 | 情報処理装置、情報処理方法及び記録媒体及びプログラム |
-
2020
- 2020-03-27 JP JP2021566962A patent/JP7006865B1/ja active Active
- 2020-03-27 US US17/766,803 patent/US20240070557A1/en active Pending
- 2020-03-27 WO PCT/JP2020/013892 patent/WO2021192193A1/ja active Application Filing
- 2020-03-27 EP EP20927998.3A patent/EP4131135A4/en active Pending
- 2020-03-27 CN CN202080073416.XA patent/CN114586054A/zh active Pending
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003178346A (ja) * | 2001-12-07 | 2003-06-27 | Hitachi Ltd | 出国受付システム、出国審査システム、出国審査方法、旅券発給対象者情報の管理方法、出国改札システムの配置構造、入国受付システム、入国改札システム、入国審査システム、入国審査方法、入国改札システムの配置構造、及び旅券 |
JP2006236213A (ja) * | 2005-02-28 | 2006-09-07 | Digitalact:Kk | 認証システム |
JP2018045340A (ja) * | 2016-09-13 | 2018-03-22 | 株式会社日立製作所 | 出入国審査システム及び方法 |
Non-Patent Citations (2)
Title |
---|
See also references of EP4131135A4 * |
YUKI ATSUYA , KUNITAKE KANEKO , FUMO TERAOKA : "Yamata-no-Orochi: an authentication and authorization infrastructure for internet services", INFORMATION PROCESSING SOCIETY OF JAPAN , vol. 55, no. 2, 15 February 2014 (2014-02-15), pages 849 - 864, XP055941846, ISSN: 1882-7764 * |
Cited By (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP7100819B1 (ja) * | 2022-01-26 | 2022-07-14 | 日本電気株式会社 | 端末、システム、端末の制御方法及びプログラム |
WO2023144912A1 (ja) * | 2022-01-26 | 2023-08-03 | 日本電気株式会社 | 端末、システム、端末の制御方法及び記憶媒体 |
JP2023109132A (ja) * | 2022-01-26 | 2023-08-07 | 日本電気株式会社 | 端末、端末の制御方法及びプログラム |
JP7392771B2 (ja) | 2022-01-26 | 2023-12-06 | 日本電気株式会社 | 端末、端末の制御方法及びプログラム |
Also Published As
Publication number | Publication date |
---|---|
EP4131135A4 (en) | 2023-05-10 |
US20240070557A1 (en) | 2024-02-29 |
CN114586054A (zh) | 2022-06-03 |
JP7006865B1 (ja) | 2022-01-24 |
EP4131135A1 (en) | 2023-02-08 |
JPWO2021192193A1 (ja) | 2021-09-30 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
JP7298733B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7363981B2 (ja) | システム、サーバ装置、サーバ装置の制御方法及びプログラム | |
JP7028385B1 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7006865B1 (ja) | 管理サーバ、システム、トークン発行方法及びコンピュータプログラム | |
JP7298737B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7287512B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7010421B1 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7279772B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7276523B2 (ja) | 管理サーバ、システム、トークン発行方法及びコンピュータプログラム | |
JP7501723B2 (ja) | 管理サーバ、システム、方法及びコンピュータプログラム | |
JP7040690B1 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP7414167B1 (ja) | サーバ装置、サーバ装置の制御方法及びプログラム | |
JP7548376B2 (ja) | サーバ装置、サーバ装置の制御方法及びコンピュータプログラム | |
JP7036291B1 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
WO2023058225A1 (ja) | システム、出発管理サーバ、出発管理サーバの制御方法及び記憶媒体 | |
JP7283597B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
WO2024084713A1 (ja) | 端末、システム、端末の制御方法及び記憶媒体 | |
JP7533723B1 (ja) | サーバ装置、サーバ装置の制御方法及びプログラム | |
JP7004128B1 (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
WO2024057457A1 (ja) | 認証端末、システム、認証端末の制御方法及び記憶媒体 | |
JP2023115091A (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム | |
JP2023096020A (ja) | サーバ装置、システム、サーバ装置の制御方法及びコンピュータプログラム |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20927998 Country of ref document: EP Kind code of ref document: A1 |
|
ENP | Entry into the national phase |
Ref document number: 2021566962 Country of ref document: JP Kind code of ref document: A |
|
WWE | Wipo information: entry into national phase |
Ref document number: 17766803 Country of ref document: US |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2020927998 Country of ref document: EP |
|
ENP | Entry into the national phase |
Ref document number: 2020927998 Country of ref document: EP Effective date: 20221027 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |