WO2023032011A1 - Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium - Google Patents

Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium Download PDF

Info

Publication number
WO2023032011A1
WO2023032011A1 PCT/JP2021/031782 JP2021031782W WO2023032011A1 WO 2023032011 A1 WO2023032011 A1 WO 2023032011A1 JP 2021031782 W JP2021031782 W JP 2021031782W WO 2023032011 A1 WO2023032011 A1 WO 2023032011A1
Authority
WO
WIPO (PCT)
Prior art keywords
person
authenticated
tracking
unit
control unit
Prior art date
Application number
PCT/JP2021/031782
Other languages
French (fr)
Japanese (ja)
Inventor
統 坂口
智弘 波多江
麻衣 伊藤
Original Assignee
日本電気株式会社
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 日本電気株式会社 filed Critical 日本電気株式会社
Priority to PCT/JP2021/031782 priority Critical patent/WO2023032011A1/en
Priority to JP2023544816A priority patent/JPWO2023032011A5/en
Publication of WO2023032011A1 publication Critical patent/WO2023032011A1/en

Links

Images

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/30Individual registration on entry or exit not involving the use of a pass
    • G07C9/32Individual registration on entry or exit not involving the use of a pass in combination with an identity check
    • G07C9/37Individual registration on entry or exit not involving the use of a pass in combination with an identity check using biometric data, e.g. fingerprints, iris scans or voice recognition

Definitions

  • the present invention relates to a biometric authentication control unit, a system, a control method for the biometric authentication control unit, and a storage medium.
  • face recognition has started to be applied to various procedures (eg, check-in, luggage deposit, security check, etc.) at airports.
  • procedures eg, check-in, luggage deposit, security check, etc.
  • ticket gates compatible with face recognition is also underway.
  • biometric authentication is being developed.
  • Patent Document 1 For specific users of paid facilities, IC (Integrated Circuit) cards are used to reduce usage fees such as discounts and prevent unauthorized use by others.
  • the face authentication automatic ticket gate of Patent Literature 1 includes a storage unit, a card information reading unit, an imaging unit, and a fee discount determination unit.
  • the storage unit stores face verification data in which the face image of a specific user and the ID of the wireless card possessed by the user are associated with each other.
  • the card information reading unit reads information from the wireless card at the entrance of the toll facility.
  • the imaging unit captures an image of the face of the user entering the aisle.
  • the fee discount determination unit uses the ID read from the wireless card as a key to read out a face image having a matching ID from the face matching data stored in the storage unit and compares the face image with the photographed image. If the images match as a result of collation, the fee discount determination unit applies a fee discount according to the discount flag read from the wireless card.
  • Patent Document 2 states that it is possible to prevent unauthorized passage by unauthorized persons while maintaining the convenience of walk-through face authentication with a simple configuration.
  • the face authentication system disclosed in Patent Literature 2 authenticates the face of a person passing through an authentication area and determines whether the person is allowed to pass.
  • the system comprises image acquisition means, storage means, face matching means, and authorization means.
  • the image obtaining means sequentially obtains input images by photographing the authentication area.
  • the storage means stores a pre-registered registered face image of the user.
  • the face collation means collates the face image of the person extracted from the input image with the registered face image, and authenticates that the person is the user.
  • the authorization means permits passage of the authenticated person when the size of the area indicating the authenticated person in the input image is equal to or larger than a predetermined size. Even if an authorized user is authenticated by facial recognition, the system does not permit passage if the authenticated person is away from the camera. To give permission.
  • the information processing device of Patent Document 3 includes image processing means, distance estimation means, and matching means.
  • the image processing means extracts the feature amount of the object in the photographed image of the area before passing through the gate, and stores collation information relating to the collation of the object based on the feature amount.
  • the distance estimation means estimates the distance from the gate to the object in the captured image.
  • the collation means performs collation determination based on the estimated distance and the stored collation information of the target for which the distance was estimated.
  • Patent Documents 1 to 3 This problem cannot be solved by applying the techniques disclosed in Patent Documents 1 to 3. This is because these documents only disclose gate devices and the like using biometric authentication.
  • the main purpose of the present invention is to provide a biometric authentication control unit, a system, a biometric authentication control unit control method, and a storage medium that contribute to appropriately controlling the passage of users.
  • a person-to-be-authenticated detecting unit that detects a person to be authenticated; a requesting unit that transmits an authentication request including biometric information of the person to be authenticated to a server device; a tracking control unit that transmits a tracking start instruction including location information of the person to be authenticated to a tracking unit that tracks a person to be tracked using a tracking control unit that acquires a tracking result from the tracking unit; A notification unit that determines whether or not the person to be authenticated can pass through the gate device based on the result of the biometric authentication of the person to be authenticated and the result of the tracking by the tracking unit, and notifies the gate device of the determination result. and a biometric control unit.
  • a server device that stores biometric information of each of a plurality of users and performs biometric authentication
  • a gate device equipped with a biometric authentication control unit and a tracking unit
  • the biometric authentication control unit detects a person to be authenticated, transmits an authentication request including the detected biometric information of the person to be authenticated to the server device, and sends location information of the person to be authenticated to the tracking unit.
  • the tracking unit sets a person existing at a location corresponding to the position information included in the tracking start instruction as a person to be tracked, and tracks the person to be tracked using a range sensor.
  • a notification of entry of the person to be authenticated is transmitted to the biometric authentication control unit, and when the biometric authentication control unit receives the notification of entry of the person to be authenticated, the server device A system is provided that determines whether or not the person to be authenticated can pass through the gate device based on an authentication result, and notifies the gate device of the determination result.
  • the biometric authentication control unit detects a person to be authenticated, transmits an authentication request including the biometric information of the person to be authenticated to the server device, a tracking start instruction including the location information of the person to be authenticated is transmitted to a tracking unit that tracks the person, a tracking result is obtained from the tracking unit, and a biometric authentication result of the person to be authenticated by the server device; , the tracking result by the tracking unit, and whether or not the person to be authenticated can pass through the gate device, and notifies the gate device of the determination result.
  • a computer installed in a biometric authentication control unit performs processing for detecting a person to be authenticated and processing for transmitting an authentication request including the biometric information of the person to be authenticated to a server device.
  • a computer readable storage medium is provided that stores a program for executing and.
  • a biometric authentication control unit a system, a control method for the biometric authentication control unit, and a storage medium that contribute to appropriately controlling the passage of users are provided.
  • the effect of this invention is not limited above. Other effects may be achieved by the present invention instead of or in addition to this effect.
  • FIG. 1 is a diagram for explaining an overview of one embodiment.
  • FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment.
  • FIG. 3 is a diagram for explaining the operation of the authentication system according to the first embodiment.
  • 4 is a diagram illustrating an example of a processing configuration of a biometric authentication control unit according to the first embodiment;
  • FIG. 5 is a diagram showing an example of an authentication-subjected person information table according to the first embodiment.
  • FIG. 6 is a diagram showing an example of an authentication request according to the first embodiment.
  • 7 is a diagram illustrating an example of a processing configuration of a tracking unit according to the first embodiment;
  • FIG. 8A and 8B are diagrams for explaining the operation of the tracking unit according to the first embodiment.
  • FIG. 1 is a diagram for explaining an overview of one embodiment.
  • FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment.
  • FIG. 3 is a diagram for explaining the
  • FIG. 9 is a diagram illustrating an example of a processing configuration of the gate device according to the first embodiment
  • 10 is a sequence diagram illustrating an example of operations of the biometric authentication control unit and the gate device according to the first embodiment
  • FIG. FIG. 11 is a diagram illustrating an example of a processing configuration of the gate device according to the first embodiment
  • FIG. 12 is a diagram illustrating an example of a user information database according to the first embodiment
  • FIG. 13 is a diagram illustrating an example of an authentication status database according to the first embodiment
  • 14 is a flowchart illustrating an example of the operation of the server device according to the first embodiment
  • FIG. 15 is a sequence diagram illustrating an example of the operation of the authentication system according to the first embodiment
  • FIG. 16 is a diagram for explaining the operation of the authentication system according to the first embodiment
  • FIG. 17 is a diagram for explaining the operation of the authentication system according to the first embodiment
  • FIG. 18 is a diagram illustrating an example of a hardware configuration of a biometric authentication control unit disclosed in the present application
  • FIG. 19 is a diagram illustrating an example of a hardware configuration of a gate device according to the disclosure of the present application.
  • the biometric authentication control unit 100 includes an authentication subject detection unit 101, a request unit 102, a tracking control unit 103, and a notification unit 104 (see FIG. 1).
  • the to-be-authenticated person detection unit 101 detects the to-be-authenticated person.
  • the request unit 102 transmits an authentication request including the biometric information of the person to be authenticated to the server device.
  • the tracking control unit 103 transmits a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and acquires the tracking result from the tracking unit.
  • the notification unit 104 determines whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and notifies the gate device of the determination result. do.
  • the biometric authentication control unit 100 detects a user who is far from the gate device as a person to be authenticated.
  • the biometrics control unit 100 detects a person to be authenticated, it starts biometrics authentication and tracking of the person to be authenticated.
  • the biometrics control unit 100 requests the server device to biometrically authenticate the person to be authenticated, and requests (instructs) the tracking unit to track the person to be authenticated.
  • the biometrics control unit 100 confirms the authentication result of the person to be authenticated.
  • the biometrics control unit 100 permits the person to be authenticated to pass through the gate device when the biometrics authentication of the person to be authenticated whose tracking has been completed is successful.
  • a user who interrupts from the side of the person to be authenticated is not required to be biometrically authenticated by the server device, and tracking is not completed, so the user cannot pass through the gate device. Can not. That is, the traffic of users is appropriately controlled.
  • the biometric authentication control unit 100 solves the above problems by instructing a tracking unit that performs tracking using a distance measuring sensor (for example, a three-dimensional distance sensor; 3D LiDAR) to track the person to be authenticated.
  • a distance measuring sensor for example, a three-dimensional distance sensor; 3D LiDAR
  • the biometric authentication control unit 100 extracts the person to be authenticated from the image data, and causes the tracking unit that controls the range sensor to track the extracted person to be authenticated, thereby appropriately controlling the passage of the user. .
  • FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment.
  • the authentication system includes a plurality of gate devices 10-1 to 10-3 and a server device 20.
  • FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment.
  • the authentication system includes a plurality of gate devices 10-1 to 10-3 and a server device 20.
  • FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment.
  • the authentication system includes a plurality of gate devices 10-1 to 10-3 and a server device 20.
  • gate devices 10-1 to 10-3 are simply referred to as "gate device 10" unless there is a particular reason to distinguish them.
  • other configurations are represented by the symbols to the left of the hyphen.
  • the gate device 10 and the server device 20 are configured to be able to communicate with each other through wired or wireless communication means.
  • the server device 20 may be installed in the same building as the gate device 10, or may be installed on a network (cloud).
  • the gate device 10 is, for example, a device installed at airports and stations.
  • the gate device 10 controls passage of users.
  • the gate device 10 will be described as a ticket gate installed at a station. However, it is needless to say that the gate device 10 is not intended to be limited to ticket gates installed at stations.
  • the server device 20 is a device that controls the entire authentication system.
  • the server device 20 is a device that performs biometric authentication of a user who is going to pass through the gate device 10 . If the user is qualified (authorized) to pass through the gate device 10, the server device 20 permits the user to pass through. If the user is not qualified to pass through the gate device 10, the server device 20 denies the user passage.
  • the gate device 10 includes a camera 11 installed so as to capture a user walking towards the gate device 10 .
  • the gate device 10 also includes a detection sensor 12 for detecting a user who has entered the gate device 10, and a gate 13 for controlling the passage of the user.
  • the gate device 10 also includes a biometric authentication control unit 14 .
  • the biometric authentication control unit 14 is a unit that can be retrofitted (add-on) to the gate device 10 .
  • the gate device 10 and the biometric authentication control unit 14 are connected by a bus standard such as USB (Universal Serial Bus), PCI (Peripheral Component Interconnect), or Ethernet (registered trademark).
  • the biometric authentication control unit 14 is configured to be able to communicate with the camera 11 and the like, and controls (uses) these devices to realize the biometric authentication function of the gate device 10 .
  • the gate device 10 includes a tracking unit 15 .
  • the tracking unit 15 is also a unit that can be retrofitted (add-on) to the gate device 10 .
  • the tracking unit 15 is attached to the gate device 10 when adding a tracking function of the person to be authenticated to the gate device 10 .
  • the biometric authentication control unit 14 and the tracking unit 15 are connected by a bus standard such as USB or Ethernet (registered trademark), for example.
  • the tracking unit 15 is configured to be able to control a range sensor 16 capable of detecting an object, and uses this device to track the user.
  • biometric authentication control unit 14 and the tracking unit 15 are installed in the gate device 10 according to the first embodiment.
  • the ranging sensor 16 is a sensor that scans the distance to an object in space.
  • a stereo camera, a TOF (Time Of Flight) distance image sensor, a three-dimensional distance sensor (3D LiDAR), or the like can be used as the distance measurement sensor 16 .
  • the biometric authentication control unit 14 detects a person (user, passenger) present within a predetermined range in front of the gate device 10 . For example, the biometric control unit 14 detects a user who is closer to the gate device 10 than the position X1 in FIG. In other words, the biometrics control unit 14 does not detect users who are far from the gate device 10 .
  • the biometric authentication control unit 14 When the biometric authentication control unit 14 detects a user, it sets the user as an authentication target (authenticated person). For example, in the example of FIG. 3, user A1 is set as the person to be authenticated. User A2 is not set as a person to be authenticated because he is away from the gate device 10 .
  • the biometric authentication control unit 14 gives an ID (Identifier) to the person to be authenticated.
  • ID Identifier
  • ID_A1 is assigned to user A1.
  • an ID for identifying a person to be authenticated will be referred to as a "person to be authenticated ID”.
  • the biometric authentication control unit 14 requests the server device 20 to biometrically authenticate the detected user. Specifically, the biometric authentication control unit 14 transmits an “authentication request” including the biometric information of the user and the ID of the person to be authenticated to the server device 20 .
  • the server device 20 Upon receiving the authentication request, the server device 20 identifies the user through verification processing (authentication processing) using pre-registered biometric information. The server device 20 determines whether or not the specified user is qualified to pass through the gate device 10 . For example, the server device 20 confirms the pre-registered user's charge amount and the like, and determines whether or not the person to be authenticated can pass. The server device 20 may make an inquiry to an external server or the like when determining whether or not the person to be authenticated can pass. Whether or not to inquire of an external server or the like depends on the specifications, design, etc. of the system, and is different from the gist of the present disclosure, so a description of the system configuration including the external server will be omitted.
  • the server device 20 transmits a response (authentication result) to the authentication request to the biometric authentication control unit 14, which is the source of the request. Specifically, the server device 20 notifies the biometric authentication control unit 14 of “successful authentication” when it is determined that “passage is permitted”. If it is determined that the passage is not allowed, the server device 20 notifies the biometric authentication control unit 14 of the "authentication failure".
  • the server device 20 notifies the gate device 10 of the ID of the person to be authenticated along with the result of the biometric authentication (authentication success, authentication failure).
  • the authentication target ID “ID_A1” is notified to the gate device 10 together with the authentication result of the user A1.
  • the gate device 10 starts tracking the user (person to be authenticated detected at position X1) at substantially the same timing as the transmission of the authentication request (start of authentication). Specifically, the biometric control unit 14 instructs the tracking unit 15 to start tracking the person to be authenticated.
  • the biometric authentication control unit 14 estimates the position (coordinates; X coordinate, Y coordinate) of the user whose face image was extracted. For example, the biometric authentication control unit 14 estimates the position (X coordinate, Y coordinate) of the person corresponding to the face from the position and size of the face included in the image data. For example, the biometric authentication control unit 14 estimates the position of each user whose facial image is extracted (user's ID to be authenticated), such as "ID_A: X1, Y1".
  • the biometric authentication control unit 14 notifies the tracking unit 15 of the location information and the ID of the person to be authenticated whose face image has been extracted. Specifically, the biometrics control unit 14 transmits to the tracking unit 15 a “tracking start instruction” including the location information of the person to be authenticated and the ID of the person to be authenticated. In this way, the biometric authentication control unit 14 sets the tracking unit 15 that the user (object) present at the position (coordinates) where the face image is extracted is the tracking target.
  • the tracking unit 15 uses the ranging sensor 16 to detect objects existing around the gate device 10 . After that, the tracking unit 15 associates and manages the object (an object presumed to be a person) detected at substantially the same position as the position notified from the biometrics control unit 14 and the person-to-be-authenticated ID.
  • the tracking unit 15 tracks the person associated with the person-to-be-authenticated ID.
  • the tracking unit 15 is notified of the position (X1, Y1) of the user A1 and the ID of the person to be authenticated "ID_A1", and the tracking unit 15 starts tracking the user A1.
  • the biometric authentication control unit 14 detects the person to be authenticated within a predetermined range, it instructs the tracking unit 15 to track the person to be authenticated at substantially the same timing as the authentication request to the server device 20 .
  • the person to be authenticated moves toward the gate device 10.
  • the biometric authentication control unit 14 receives a response to the authentication request from the server device 20 at the timing when the person to be authenticated moves to the location X2.
  • the biometric authentication control unit 14 Even if the biometric authentication control unit 14 receives the authentication result from the server device 20, it does not instruct the gate device 10 to open or close the gate 13 at that timing.
  • the person to be authenticated further approaches the gate device 10 and enters its interior (the person to be authenticated reaches position X3).
  • the tracking unit 15 notifies the biometric control unit 14 of the subject ID of the tracked person.
  • the tracking unit 15 notifies the biometric authentication control unit 14 of a “person to be authenticated entrance notification” including the to-be-authenticated person ID of the person to be tracked who has entered the inside of the gate device 10 .
  • the tracking unit 15 notifies the biometric authentication control unit 14 of the user A1's ID "ID_A1".
  • the biometrics control unit 14 stores the ID of the person to be authenticated notified from the tracking unit 15.
  • the biometric authentication control unit 14 determines whether or not the person to be authenticated whose ID notified from the server device 20 matches the ID of the person to be authenticated notified from the tracking unit 15 can pass through the gate device 10 . Specifically, if the authentication result of the person to be authenticated whose tracking has been completed is "successful authentication", the biometric authentication control unit 14 determines that the user can pass through the gate device 10, and notifies the gate device of that fact. Notify 10. More specifically, the biometric authentication control unit 14 transmits a “notice of permission to pass” to the gate device 10 .
  • the biometrics control unit 14 does not take any particular action if the authentication result of the person to be authenticated whose tracking has been completed is other than "authentication success" (authentication failure or no authentication result).
  • the user proceeds further inside from the entrance of the gate device 10 .
  • the gate device 10 detects the person to be authenticated based on the detection signal from the detection sensor 12 installed in the middle of the device itself.
  • the gate device 10 If the gate device 10 receives the "passage permission notification" at the timing when the user is detected, the gate device 10 keeps the gate 13 open and permits the user to pass through the gate.
  • the gate device 10 closes the gate 13 and restricts the passage of the user if the "passage permission notification" is not received at the timing when the user is detected.
  • the tracking unit 15 detects that a person to be authenticated who is set as a tracking target has entered the gate device 10, the tracking unit 15 notifies the biometrics control unit 14 of the ID of the person to be authenticated who has entered. .
  • the biometric authentication control unit 14 confirms the authentication result of the corresponding person to be authenticated, and permits passage if the authentication is successful.
  • the user's biometric information includes, for example, data (feature amounts) calculated from physical features unique to an individual, such as a face or iris pattern (pattern).
  • the user's biometric information may be image data such as a face image or an iris image.
  • a user's biometric information should just contain a user's physical characteristic as information.
  • a facial image of a person or a feature amount generated from the facial image is used as biometric information.
  • the authentication system may include at least one or more gate devices 10 .
  • Each gate device 10 may be installed in the same place (for example, the same station), or may be installed in different places.
  • biometric authentication control unit 14, tracking unit 15, gate device 10, and server device 20 included in the authentication system according to the first embodiment will be described.
  • FIG. 4 is a diagram showing an example of a processing configuration (processing modules) of the biometric authentication control unit 14 according to the first embodiment.
  • the biometric authentication control unit 14 includes a communication control unit 201, a person-to-be-authenticated detection unit 202, an authentication request unit 203, a tracking control unit 204, a passage permission notification unit 205, and a table management unit 206. , a message output unit 207 and a storage unit 208 .
  • the communication control unit 201 is means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 20 . Also, the communication control unit 201 transmits data to the server device 20 . The communication control unit 201 transfers data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 201 .
  • the communication control unit 201 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the authenticated person detection unit 202 is means for detecting an authenticated person.
  • the person-to-be-authenticated detection unit 202 detects a person within a predetermined range from the gate device 10 as a person to be authenticated. More specifically, the person-to-be-authenticated detection unit 202 determines whether a person exists within a predetermined range from the gate device 10 (for example, a position closer to the gate device 10 than the position X1; within the range from X1 to X3). to detect
  • the range in which the person-to-be-authenticated detection unit 202 detects the person to be authenticated is defined in the X-axis direction. ⁇ Y2) are also considered.
  • the person-to-be-authenticated detection unit 202 acquires image data from the camera 11 periodically or at a predetermined timing.
  • the person-to-be-authenticated detection unit 202 attempts to extract a face image from the acquired image data.
  • the person-to-be-authenticated detection unit 202 may extract a face image (face region) from image data using a learning model learned by a CNN (Convolutional Neural Network).
  • the person-to-be-authenticated detection unit 202 may extract a face image using a technique such as template matching.
  • the person-to-be-authenticated detection unit 202 calculates the inter-eye distance from the face image. Specifically, the person-to-be-authenticated detection unit 202 extracts left and right eyes from the face image, and calculates the length (the number of pixels) of the straight line connecting the extracted eyes.
  • the to-be-authenticated person detection unit 202 performs threshold processing on the calculated inter-eye distance, and determines whether or not the to-be-authenticated person exists within the predetermined range according to the result. Specifically, if the distance between the eyes is longer than the threshold, the person-to-be-authenticated detection unit 202 determines that the person-to-be-authenticated has been detected within the predetermined range. If the distance between the eyes is equal to or less than the threshold, the person-to-be-authenticated detection unit 202 determines that the person-to-be-authenticated does not exist within the predetermined range.
  • the authenticated person detection unit 202 When an authenticated person is detected within a predetermined range, the authenticated person detection unit 202 adds an entry to the authenticated person information table.
  • the to-be-authenticated person detection unit 202 numbers the to-be-authenticated person ID for identifying the to-be-authenticated person, and stores the ID of the to-be-authenticated person in a new entry.
  • the authentication-subjected person detection unit 202 also stores the time when the authentication-subjected person is registered in the authentication-subjected person information table (the time when a new entry is added) in the authentication-subjected person information table.
  • FIG. 5 is a diagram showing an example of an authentication-subjected person information table according to the first embodiment.
  • the authenticated person information table is constructed on the memory of the biometric authentication control unit 14 .
  • the person-to-be-authenticated detection unit 202 detects a person at the position X1, it adds an entry to the person-to-be-authenticated information table and sets the detected person as the person to be authenticated. do. Note that nothing is set in the authentication status field and the tracking status field when the entry is added.
  • the authentication status field is a field for managing the biometric authentication status of the authenticated person.
  • the tracking status field is a field for managing the tracking status of the person to be authenticated.
  • the authentication-subjected person information table shown in FIG. 5 is an example, and is not meant to limit the items to be stored.
  • the biometric information (face image, feature amount) of the person to be authenticated may be registered in the person-to-be-authenticated information table.
  • the authentication-subject detection unit 202 may prevent a user who has already been registered as an authentication-subject from being registered again in the authentication-subject information table using the biometric information. If the face image (feature amount) extracted from the image data substantially matches the face image (feature amount) registered in the authentication-subjected person information table, the authentication-subjected person detection unit 202 detects the face image (feature amount) from the image data. The person corresponding to the extracted face image is not set as the person to be authenticated.
  • the person-to-be-authenticated detection unit 202 passes the ID of the person-to-be-authenticated and the image data (image data and face image obtained from the camera 11) at the time of detection of the person-to-be-authenticated to the authentication requesting unit 203. .
  • the person-to-be-authenticated detection unit 202 estimates the position (coordinates; X coordinate, Y coordinate) of the user whose face image is extracted. For example, the person-to-be-authenticated detection unit 202 estimates the position (X coordinate, Y coordinate) of the person corresponding to the face from the position and size of the face included in the image data.
  • the person-to-be-authenticated detection unit 202 may estimate the position using a learning model. Specifically, the person-to-be-authenticated detection unit 202 estimates a position using a learning model generated by machine learning using teacher data in which labels (X coordinates, Y coordinates) are assigned to images. good.
  • Arbitrary algorithms such as a support vector machine, a boosting, and a neural network, can be used for the production
  • the to-be-authenticated person detection unit 202 estimates the position of each user (user's to-be-authenticated person ID) whose face image is extracted, for example, "ID_A: X1, Y1".
  • the to-be-authenticated person detection unit 202 passes the to-be-authenticated person ID and the user's position (X coordinate, Y coordinate) to the tracking control unit 204 .
  • the authentication request unit 203 is means for requesting the server device 20 to authenticate the person to be authenticated detected by the person-to-be-authenticated detection unit 202 . After acquiring the face image of the person to be authenticated, the authentication requesting unit 203 generates a feature amount (a feature vector composed of a plurality of feature amounts) from the acquired face image.
  • the authentication requesting unit 203 extracts the eyes, nose, mouth, etc. from the face image as feature points. After that, the authentication requesting unit 203 calculates the position of each feature point and the distance between each feature point as a feature amount, and generates a feature vector (vector information that characterizes the face image) composed of a plurality of feature amounts.
  • a feature vector vector information that characterizes the face image
  • the authentication requesting unit 203 generates an authentication request including the generated feature amount (biometric information), the ID of the person to be authenticated, and the gate ID, and transmits it to the server device 20 (see FIG. 6).
  • the gate ID is identification information for identifying the gate device 10 .
  • the MAC (Media Access Control) address or IP (Internet Protocol) address of the gate device 10 can be used as the gate ID.
  • the gate ID may be system-specific identification information (identification ID). By holding the identification ID as a master also on the server device 20 side, it can be determined that the transmitted authentication request is from the permitted gate device 10 .
  • the authentication requesting unit 203 sets "authenticating" in the authentication status field of the corresponding entry (entries with the same authentication-subject ID) in the authentication-subject information table (see FIG. 5). See the second entry from the bottom).
  • the authentication requesting unit 203 receives a response (including the authentication result) from the server device 20 to the authentication request.
  • the authentication requesting unit 203 extracts the ID of the person to be authenticated from the received response.
  • the authentication request unit 203 identifies the person to be authenticated based on the extracted person-to-be-authenticated ID, and registers the authentication result in the corresponding entry of the person-to-be-authenticated information table (the first and second entries from the top in FIG. 5). reference). In this way, upon receiving the biometric authentication result from the server device 20 , the authentication requesting unit 203 sets the received biometric authentication result in the authentication status field of the entry added by the authentication-subject detecting unit 202 .
  • the tracking control unit 204 is means for controlling tracking of the person-to-be-authenticated detected by the person-to-be-authenticated detection unit 202 .
  • the tracking control unit 204 transmits a tracking start instruction including the position information of the person to be authenticated to the tracking unit 15 that tracks the person to be tracked using the distance measuring sensor 16 .
  • the tracking control section 204 acquires tracking results from the tracking unit 15 .
  • the tracking control unit 204 acquires the authenticated person ID and the authenticated person's location information (X coordinate, Y coordinate) from the authenticated person detection unit 202 . After that, the tracking control section 204 transmits a “tracking start instruction” including the location information of the person to be authenticated (estimated location of the person to be authenticated) and the ID of the person to be authenticated to the tracking unit 15 .
  • the tracking control unit 204 sets the tracking status of the authenticated person who sent the tracking start instruction to "tracking" and updates the authenticated person information table (see the third entry from the bottom in FIG. 5).
  • the tracking control unit 204 receives the "notification of entry of the person to be authenticated" from the tracking unit 15. Upon receiving the notification, the tracking control unit 204 determines that tracking of the person to be authenticated has been completed. The tracking control unit 204 updates the tracking status of the corresponding authenticated person using the authenticated person ID included in the notification. Specifically, the tracking control unit 204 sets "tracking completed" in the tracking status field of the corresponding entry in the authenticated person information table (see the topmost entry in FIG. 5).
  • the tracking control unit 204 receives from the tracking unit 15 an authentication-subjected person entry notification indicating that the tracked person has entered the gate device 10 .
  • the tracking control unit 204 sets the tracking result (fact that tracking of the person to be authenticated has been completed) obtained from the tracking unit 15 in the tracking status field of the entry added by the person to be authenticated detection unit 202 .
  • the tracking control unit 204 When the tracking control unit 204 reflects the subject entry notification from the tracking unit 15 in the authentication subject information table, the tracking control unit 204 notifies the passage permission notification unit 205 to that effect.
  • the passage permission notification unit 205 is means for notifying the gate device 10 whether or not the person to be authenticated (user) is permitted to pass through the gate device 10 .
  • the passage permission notification unit 205 determines whether or not the person to be authenticated can pass through the gate device 10 based on the result of biometric authentication of the person to be authenticated by the server device 20 and the tracking result of the person to be authenticated by the tracking unit 15. and notifies the gate device 10 of the determination result.
  • the pass permission notification unit 205 accesses the authenticated person information table at the timing when the tracking of the authenticated person is completed (when the tracking control unit 204 acquires the fact that the tracking has been completed).
  • the passage permission notification unit 205 checks the authentication status field and tracking status field of each entry included in the authentication subject information table. If there is an entry in which the set value of the authentication status field is "authentication successful" and the set value of the tracking status field is "tracking completed", the passage permission notification unit 205 allows the person to be authenticated to pass through the gate device 10. allow Specifically, if there is an entry that satisfies the above two conditions, the passage permission notification unit 205 notifies the gate device 10 that the user can pass through the gate device 10 . The passage permission notification unit 205 transmits a “passage permission notification” to the gate device 10 .
  • the passage permission notification unit 205 transmits a "passage permission notice" to the gate device 10.
  • the passage permission notification unit 205 When the passage permission notification unit 205 permits the user (person to be authenticated) to pass through the gate, it deletes the entry that serves as the basis for the permission. In the example of FIG. 5, the passage permission notification unit 205 deletes the topmost entry.
  • the passage permission notification unit 205 determines whether or not the person to be authenticated can pass through the gate device 10 in response to the receipt of the entry notification of the person to be authenticated by the tracking control unit 204 . That is, the biometrics control unit 14 determines whether or not the person to be authenticated can pass through the gate device 10 based on the authentication result by the server device 20 when receiving the notification of the entry of the person to be authenticated.
  • the passage permission notification unit 205 may receive a "gate closed notification" from the gate device 10. Upon receiving the notification, the passage permission notification unit 205 continues to access the authentication subject information table for a predetermined period of time, and checks whether an entry satisfying the above two conditions appears (exists). If an entry that satisfies the above two conditions appears during the predetermined period, the passage permission notification unit 205 permits the person to be authenticated (user) to pass through the gate. Specifically, when an entry that satisfies the above two conditions appears, the passage permission notifying unit 205 transmits a “passage permission notification” to the gate device 10 .
  • the above phenomenon occurs. can happen.
  • the above phenomenon may occur when the person to be authenticated tries to run through the gate device 10 .
  • the passage permission notification unit 205 notifies the station staff (the terminal used by the station staff) that a problem has occurred.
  • the pass permission notification unit 205 may prompt the person to be authenticated to go to the station staff via the message output unit 207 .
  • the table management unit 206 is means for managing the authenticated person information table.
  • the table management unit 206 accesses the authentication-subjected person information table periodically or at a predetermined timing, and deletes unnecessary entries.
  • the table management unit 206 checks the registration time field of each entry, and deletes entries for which a predetermined period has passed since the entry was added to the authentication-subjected person information table. That is, the table management unit 206 deletes an entry that does not satisfy the above two conditions (authentication success, tracking completion) even after a predetermined period of time has passed since the entry was registered.
  • the table management unit 206 may notify the server device 20 and the tracking unit 15 to that effect.
  • the table management unit 206 may transmit the ID of the person to be authenticated to the server device 20 and cancel the authentication of the corresponding person to be authenticated.
  • the table management section 206 may also transmit the ID of the person to be authenticated to the tracking unit 15 and instruct it to exclude the person to be tracked corresponding to the ID of the person to be authenticated from being tracked.
  • the message output unit 207 is means for outputting a message or the like to be notified to the user.
  • the message output unit 207 notifies the user of necessary messages using a display (not shown), a speaker (not shown), or the like.
  • the message output unit 207 outputs a message to that effect and a countermeasure (for example, contact the station staff).
  • the storage unit 208 is means for storing information necessary for the operation of the biometrics control unit 14 .
  • FIG. 7 is a diagram showing an example of a processing configuration (processing modules) of the tracking unit 15 according to the first embodiment.
  • tracking unit 15 includes communication control section 301 , tracking section 302 , and storage section 303 .
  • the communication control unit 301 is means for controlling communication with other apparatuses (devices). For example, the communication control section 301 receives data (packets) from the biometric authentication control unit 14 . The communication control section 301 also transmits data to the biometric authentication control unit 14 . The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301 .
  • the communication control unit 301 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the tracking unit 302 is means for tracking the person to be authenticated.
  • the tracking unit 302 receives a “tracking start instruction” from the biometric control unit 14 .
  • the tracking unit 302 controls the distance measuring sensor 16 and scans all around the gate device 10 (especially in front of the gate device 10).
  • the tracking unit 302 detects objects existing around the gate device 10 through the scanning.
  • the tracking unit 302 acquires a countless set of points (point group).
  • the tracking unit 302 obtains a cluster (a set of points forming an object) by clustering the points included in the obtained point group for each object.
  • the tracking unit 302 detects objects by assigning meanings (for example, floors, walls, people) to the obtained clusters.
  • the tracking unit 302 detects an object (person, etc.) by image recognition based on machine learning (image recognition of a laser image obtained by reflecting a laser off an object).
  • the tracking unit 302 performs object detection using the technique disclosed in Reference 1 below. ⁇ Reference 1> JP 2021-099698 A
  • the tracking unit 302 When the tracking unit 302 detects at least one person, it calculates the position (coordinates) of the detected person. For example, as shown in FIG. 3, when scanning is performed in a situation where user A1 stands at position (X1, Y1) and user A2 stands at position (X0, Y0), as shown in FIG. 8A Two persons are detected in the positional relationship. When two persons are detected, the tracking unit 302 calculates the center position of each person as the position (X coordinate, Y coordinate) of the person.
  • the tracking unit 302 sets a person who exists substantially at the same location as the position information included in the tracking start instruction as a tracking target. In the examples of FIGS. 3 and 8A, the tracking unit 302 sets user A1 as a tracking target.
  • the tracking unit 302 associates and manages the position of the tracked target and the ID of the person to be authenticated.
  • the user A1 is set as a tracking target, so the tracking unit 302 makes a correspondence such as (ID_A1; X1, Y1).
  • the tracking unit 302 controls the distance measuring sensor 16 periodically or at a predetermined timing to detect an object. For example, when object detection is performed at the timing when user A1 moves to position (X2, Y1) in FIG. 3, tracking unit 302 detects two persons in a positional relationship as shown in FIG. 8B.
  • the tracking unit 302 identifies the tracking target from among the people detected by the current scan by comparing the shape of the person obtained by the previous scan with the shape of the person obtained by the current scan.
  • the tracking unit 302 updates the identified position (X coordinate, Y coordinate) of the tracked object. In the above example, the position of the tracked user A1 is updated to (X2, Y1).
  • the tracking unit 302 confirms the updated position of the tracked object and determines whether the tracked object has entered the inside of the gate device 10 . For example, in the example of FIG. 3, the tracking unit 302 determines that the user A1 has entered the gate device 10 if the X coordinate of the user A1 is closer to the gate device 10 than the position X3. The tracking unit 302 determines that the user A1 has not entered the gate device 10 if the X coordinate of the user A1 is farther from the gate device 10 than the position X3.
  • the tracking unit 302 determines that the tracked person has entered the inside of the gate device 10
  • the tracking unit 302 transmits to the biometrics control unit 14 a "person to be authenticated entrance notification" including the ID of the person to be tracked.
  • the tracking unit 302 transmits to the biometric authentication control unit 14 a notification of entry of the person to be authenticated indicating that the person to be tracked has entered the gate device 10 .
  • the tracking unit 15 (tracking unit 302) manages the position of the tracked person in association with the ID of the person to be authenticated, and completes tracking when the tracked person enters the gate device 10.
  • the tracking unit 302 notifies the biometric authentication control unit 14 of the subject ID of the person to be tracked who has completed the tracking.
  • the tracking unit 302 may delete the information (authenticated person ID and location) of the person to be tracked who has not completed tracking even after a predetermined time has elapsed since the start of tracking. Alternatively, the tracking unit 302 also deletes the information of the tracked person when the tracked person leaves the predetermined range (for example, when the tracked person does not go to the gate device 10 but heads to another place). may
  • the storage unit 303 is means for storing information necessary for the operation of the tracking unit 15.
  • FIG. 9 is a diagram showing an example of a processing configuration (processing modules) of the gate device 10 according to the first embodiment.
  • the gate device 10 includes a communication control section 401 , an intruder detection section 402 , a gate control section 403 and a storage section 404 .
  • the communication control unit 401 is means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the biometric authentication control unit 14 . Also, the communication control unit 401 transmits data to the biometric authentication control unit 14 . The communication control unit 401 transfers data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 401 .
  • the communication control unit 401 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the intruder detection unit 402 is a means for detecting an intruder into its own device (gate device 10). More specifically, the intruder detection unit 402 uses the detection signal from the detection sensor 12 to detect the user who has reached the intermediate point of the gate device 10 (position X4 in FIG. 3). When the intruder detection unit 402 detects the user at the position X4, the intruder detection unit 402 notifies the gate control unit 403 to that effect.
  • the gate control unit 403 is means for controlling the gate 13 provided in the gate device 10 .
  • the gate control unit 403 performs opening/closing control of the gate 13 at the timing when the user reaches a predetermined position (position X4 in FIG. 3) of the gate device 10 .
  • the gate control unit 403 keeps the gate 13 open if it has already received the "passage permission notification" from the biometric authentication control unit 14 when the user reaches the position X4. On the other hand, the gate control unit 403 closes the gate 13 when the "passage permission notification" is not received from the biometrics control unit 14 at the timing.
  • the gate control section 403 When the gate 13 is closed, the gate control section 403 notifies the biometric authentication control unit 14 to that effect. Specifically, the gate control unit 403 transmits a “gate closed notification” to the biometric authentication control unit 14 . The gate control unit 403 opens the gate 13 when receiving the “passage permission for the user” within a predetermined period of time after transmitting the gate closing notification.
  • the gate control unit 403 notifies the server device 20 via the biometric authentication control unit 14 of the fact that the person to be authenticated has passed through the gate 13 . Specifically, when the gate control unit 403 permits the user to pass through the gate because the user is detected at the position X4 and the pass permission notice is received from the biometric authentication control unit 14, The biometric authentication control unit 14 is notified to that effect.
  • the pass permission notification unit 205 of the biometric authentication control unit 14 receives the authenticated person ID described in the entry (the entry of the authenticated person information table) that is the basis for transmitting the pass permission notification and the gate ID of the gate device 10. to the server device 20. That is, the gate device 10 (biometric authentication control unit 14 ) transmits to the server device 20 a “gate passage notification” including the subject ID of the person to be authenticated who has passed through the gate 13 and the gate ID.
  • the storage unit 404 is means for storing information necessary for the operation of the gate device 10 .
  • FIG. 10 is a sequence diagram showing an example of operations of the biometric authentication control unit 14 and the gate device 10 according to the first embodiment.
  • the biometric authentication control unit 14 attempts to detect the person to be authenticated within a predetermined range in front of the gate device 10 (step S101). If the person to be authenticated is not detected (step S101, No branch), the biometric authentication control unit 14 repeats the process of step S101.
  • the biometrics control unit 14 requests the server device 20 to request authentication of the person to be authenticated (step S102).
  • the biometrics control unit 14 starts tracking the person to be authenticated substantially at the same time as sending the authentication request.
  • the biometrics control unit 14 sends a tracking start instruction including the location of the person to be authenticated and the ID of the person to be authenticated to the tracking unit 15 (step S103).
  • the biometric authentication control unit 14 receives the authentication result from the server device 20 (step S104).
  • the biometric authentication control unit 14 reflects the authentication result in the authenticated person information table.
  • the tracking unit 15 tracks the person-to-be-authenticated, and when the person-to-be-authenticated arrives at the entrance of the gate device 10, it sends a notification of entry of the person-to-be-authenticated to the biometrics control unit 14.
  • the biometric control unit 14 receives the entry notification of the person to be authenticated from the tracking unit 15 (step S105).
  • the biometric authentication control unit 14 reflects the tracking result by the tracking unit 15 in the authentication subject information table.
  • the biometrics control unit 14 transmits a notice of permission to pass to the gate device 10 (step S106).
  • the gate device 10 determines whether or not the person to be authenticated has reached a predetermined position on the gate device 10 (step S201). If the person to be authenticated has not reached the predetermined position (step S201, No branch), the gate device 10 repeats the process of step S201.
  • the gate device 10 When the person to be authenticated has reached the predetermined position (step S201, Yes branch), the gate device 10 performs opening/closing control of the gate 13 (step S202).
  • the gate device 10 permits the person-to-be-authenticated to pass if the notification of passage permission is received. In other words, the gate device 10 closes the gate 13 to let the user Block traffic.
  • the gate device 10 When the gate device 10 permits the person to be authenticated to pass, the gate device 10 notifies the server device 20 of this fact.
  • the biometric authentication control unit 14 detects a person to be authenticated and transmits an authentication request including the detected biometric information of the person to be authenticated to the server device 20 . Also, the biometrics control unit 14 transmits a tracking start instruction including the location information of the person to be authenticated to the tracking unit 15 . The biometric authentication control unit 14 notifies the tracking unit 15 of the location information of the person to be authenticated, thereby setting the person to be tracked in the tracking unit 15 . The tracking unit 15 sets a person existing at a location corresponding to the position information included in the tracking start instruction as a person to be tracked, and uses the distance measurement sensor 16 to track the person to be tracked.
  • the tracking unit 15 When the person to be tracked enters the gate device 10 , the tracking unit 15 notifies that the person to be authenticated has arrived at the gate device 10 by transmitting a notification of entry of the person to be authenticated to the biometric authentication control unit 14 .
  • the biometrics control unit 14 determines whether or not the person to be authenticated can pass through the gate device 10 based on the authentication result by the server device 20 .
  • the biometric authentication control unit 14 determines that the person to be authenticated can pass through the gate device 10 if the person to be authenticated is qualified to pass through the gate device 10 (if the authentication is successful).
  • FIG. 11 is a diagram showing an example of a processing configuration (processing modules) of the server device 20 according to the first embodiment.
  • server device 20 includes communication control section 501 , user registration section 502 , authentication section 503 , gate passage notification processing section 504 , and storage section 505 .
  • the communication control unit 501 is means for controlling communication with other devices.
  • the communication control section 501 receives data (packets) from the biometrics control unit 14 .
  • the communication control unit 501 transmits data to the biometric authentication control unit 14 .
  • the communication control unit 501 passes data received from other devices to other processing modules.
  • the communication control unit 501 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 501 .
  • the communication control unit 501 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the user registration unit 502 is means for system registration of users who can pass through the gate device 10 .
  • the user registration unit 502 acquires biometric information (for example, facial images) of users who can pass through the gate device 10 using arbitrary means.
  • a system user inputs biometric information and personal information (name, address, etc.) into the server device 20 using a web page of a railway company or a kiosk terminal installed at a station.
  • a user registration unit 502 When the user registration unit 502 acquires a face image, it calculates a feature amount from the face image.
  • a user registration unit 502 stores a user ID that identifies a system user (biometric information registrant) and a user's biometric information (for example, a feature amount calculated from a face image) in a "user information database”. Register (see FIG. 12).
  • the user registration unit 502 registers information (business information) required for user authentication processing in the user information database as necessary. For example, when the server device 20 processes an authentication request from a ticket gate (gate device 10) installed at a station, the user registration unit 502 associates information such as the charge amount with biometric information to identify the user. Store in an information database.
  • the user information database shown in FIG. 12 is an example, and other items may be stored in association with biometric information (feature amounts). For example, the user's name and face image may be registered in the user information database.
  • the authentication unit 503 is means for processing an authentication request received from the biometric authentication control unit 14 (gate device 10). Upon receiving the authentication request, the authentication unit 503 extracts the gate ID and the person-to-be-authenticated ID from the authentication request. The authentication unit 503 adds a new entry to the authentication status database and stores the extracted gate ID and authenticated person ID (see FIG. 13). Also, the authentication unit 503 sets the processing status of the added entry to “processing”. In FIG. 13, for ease of understanding, the gate device 10 is used as the gate ID.
  • the authentication unit 503 sets the biometric information (feature amount) included in the authentication request as a matching target, and performs matching processing with the biometric information registered in the user information database. conduct.
  • the authentication unit 503 sets the feature amount extracted from the authentication request as a matching object, and performs one-to-N (N is a positive (integer, same below) perform matching.
  • the authentication unit 503 calculates the degree of similarity between the feature amount (feature vector) to be matched and each of the plurality of feature amounts on the registration side. Chi-square distance, Euclidean distance, or the like can be used for the degree of similarity. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
  • the authentication unit 503 sets "authentication failure" as the authentication result.
  • the authentication unit 503 determines whether or not the user specified by the collation process is qualified to pass through the gate device 10. .
  • the authentication unit 503 determines whether the specified user's charge amount is equal to or greater than the initial fare. If the balance of the charge amount is equal to or less than the initial fare, the authentication unit 503 determines that the specified user is not qualified to pass through the gate device 10 . If the balance of the charged amount is greater than the initial fare, the authentication unit 503 determines that the identified user is qualified to pass through the gate device 10 .
  • the authentication unit 503 determines whether the boarding station is set for the specified user. If the boarding station is not set, the authentication unit 503 determines that the specified user is not qualified to pass through the gate device 10 . If the boarding station is set, the authentication unit 503 calculates the fare according to the route of the user (the route between the boarding station and the alighting station). If the calculated fare exceeds the charged amount, the authentication unit 503 determines that the user is not qualified to pass through the gate device 10 . If the calculated fare is equal to or less than the charged amount, the authentication unit 503 determines that the specified user is qualified to pass through the gate device 10 .
  • the authentication unit 503 sets "authentication failure" to the authentication result.
  • the authentication unit 503 sets "authentication success" to the authentication result.
  • the authentication unit 503 notifies the biometric authentication control unit 14 (gate device 10) of the person-to-be-authenticated ID of the person to be authenticated (person to be authenticated) and the authentication result (authentication success, authentication failure). In the case of successful authentication, the authentication section 503 transmits an affirmative response indicating successful authentication to the biometrics control unit 14 . At that time, the authentication unit 503 transmits to the biometric authentication control unit 14 an affirmative response including the user ID of the user to be authenticated.
  • the authentication unit 503 sends a negative response indicating authentication failure to the biometric authentication control unit 14.
  • the authentication section 503 may also notify the biometric authentication control unit 14 of the cause of authentication failure.
  • the authentication unit 503 may transmit to the biometric authentication control unit 14 factors related to authentication failure, such as biometric information not being registered in the system, insufficient charging amount, and boarding station not being set.
  • the authentication unit 503 transmits a negative response including the authenticated person ID of the user to be authenticated to the biometric authentication control unit 14 .
  • the authentication unit 503 After sending a response to the authentication request to the gate device 10, the authentication unit 503 sets "responded" to the corresponding entry in the authentication status database. Also, when notifying the gate device 10 of successful authentication, the authentication unit 503 sets the user ID of the successful authentication person (the user determined to have been successfully authenticated) to the user ID of the corresponding entry.
  • the gate passage notification processing unit 504 is means for processing gate passage notifications received from the gate device 10 (biometric authentication control unit 14).
  • the gate passage notification processing unit 504 extracts the gate ID and the person-to-be-authenticated ID from the received notification.
  • the gate-passing notification processing unit 504 searches the authentication status database using the gate ID and the person-to-be-authenticated ID as keys to identify the corresponding entry.
  • the gate passage notification processing unit 504 reads the user ID from the user ID field of the identified entry.
  • the gate passage notification processing unit 504 searches the user information database using the read user ID as a key to identify the corresponding entry.
  • the gate passage notification processing unit 504 executes processing associated with the user passing through the gate for the specified entry.
  • the gate passage notification processing unit 504 sets the station where the gate device 10 is installed as the boarding station of the specified entry. .
  • the gate passage notification processing unit 504 calculates the user's fare and subtracts the fare from the charge amount. In addition, the gate passage notification processing unit 504 clears the setting value of the boarding station field.
  • the storage unit 505 stores various information necessary for the operation of the server device 20 .
  • a user information database and an authentication status database are constructed in the storage unit 505 .
  • FIG. 14 is a flow chart showing an example of the operation of the server device 20 according to the first embodiment.
  • the server device 20 receives an authentication request from the biometric authentication control unit 14 (step S301).
  • the server device 20 executes matching processing using the biometric information included in the authentication request and the biometric information registered in the user information database (step S302).
  • the server device 20 determines whether or not there is an entry with a degree of similarity between biometric information equal to or greater than a predetermined value (step S303).
  • step S303 If such an entry does not exist (step S303, No branch), the server device 20 sets the authentication result to authentication failure (step S304).
  • step S303 If such an entry exists (step S303, Yes branch), the server device 20 determines whether the person to be authenticated is qualified to pass through the gate device 10 (step S305).
  • step S305 If the person to be authenticated is not qualified to pass through the gate device 10 (step S305, No branch), the server device 20 sets the authentication result to authentication failure (step S304).
  • the server device 20 sets the authentication result to authentication success (step S306).
  • the server device 20 transmits the authentication result (authentication success, authentication failure) to the biometric authentication control unit 14 (step S307).
  • FIG. 15 is a sequence diagram illustrating an example of the operation of the authentication system according to the first embodiment; FIG. It is assumed that system users have already been registered prior to the operation of FIG. Also, in FIG. 15, the biometric authentication control unit 14 and the tracking unit 15 are assumed to be integrated with the gate device 10, and the operation of the system will be described.
  • the gate device 10 detects a person to be authenticated within a predetermined range set in front of itself (step S01).
  • the gate device 10 acquires the biometric information of the person to be authenticated, and transmits an authentication request including the biometric information to the server device 20 (step S02).
  • the gate device 10 starts tracking the person to be authenticated (step S03).
  • the server device 20 executes authentication processing and transmits the result to the gate device 10 (steps S11 and S12).
  • the gate device 10 receives the authentication result and reflects the authentication result in the authentication subject information table (reflection of the authentication result; step S04).
  • the gate device 10 completes tracking of the person to be authenticated (step S05).
  • the gate device 10 When the person to be authenticated reaches the predetermined position of the gate device 10, the gate device 10 performs gate control (step S06). Specifically, the gate device 10 permits passage of the person to be authenticated for whom authentication is successful and tracking is completed.
  • the gate device 10 After permitting the person to be authenticated to pass through, the gate device 10 transmits a gate passage notification to the server device 20 (step S07).
  • the server device 20 Upon receiving the gate passage notification, the server device 20 updates the information of the person who passed through the gate (authenticated person; person to be authenticated who was determined to be authenticated successfully) (step S13). Specifically, the server device 20 updates the entry in the user information database corresponding to the gate passer.
  • user 30 is set as a person to be authenticated, and user 31 is a user who is not to be authenticated.
  • the person to be authenticated is shown in gray, and the user who is not to be authenticated is shown in white.
  • User 31 is not a person to be authenticated because it is not detected as a person to be authenticated at position X1. Therefore, there is no entry for user 31 in the authenticated person information table.
  • the user 30 walks toward the gate device 10.
  • the user 31 moves so as to enter the inside of the gate device 10 from the side of the user 30 .
  • the positional relationship between the two becomes as shown in the lower part of FIG. 16 as time elapses.
  • gate 13 closes when user 31 reaches position X4. Further, even if a predetermined period of time has passed since the gate 13 was closed, the authentication result of the user 31 is not registered in the authenticated person information table, so the gate 13 is not opened.
  • the person to be authenticated passes another person to be authenticated walking in front.
  • the person to be authenticated the person in gray because the biometric information is acquired at the position X1 and the tracking is started.
  • the user 33 walking behind moves as shown in the dashed line in the upper part of FIG. 17 and overtakes the user 32 in front. In this case, the positional relationship between the two becomes as shown in the lower part of FIG. 17 as time elapses.
  • Entries for the user 32 and the user 33 are registered in the authenticated person information table. , the gate 13 remains open. Further, even if the user 32 arrives at the position X4 following the user 33, the gate 13 is not closed.
  • the user whose biometric information is acquired at the position X1 and who is set as the person to be authenticated can be processed normally even if they do not reach (enter) the gate device 10 in the set order. That is, the user can pass through the gate device 10 even if the user does not reach the gate device 10 in the order in which the person to be authenticated was registered due to a difference in the walking speed of the person to be authenticated.
  • the authentication system according to the first embodiment also allows irregular situations, so the throughput of the system is improved.
  • the tracking unit 15 sends to the biometrics control unit 14 the subject entry notification including the subject ID of the tracked person when tracking is completed.
  • the biometrics control unit 14 may periodically inquire of the tracking unit 15 whether or not tracking of the person to be authenticated (tracked person) has ended.
  • the tracking control unit 204 of the biometric authentication control unit 14 after transmitting a tracking start instruction to the tracking unit 15, the tracking control unit 204 of the biometric authentication control unit 14 periodically transmits a "location inquiry" including the ID of the person to be authenticated to the tracking unit 15. .
  • the tracking unit 302 of the tracking unit 15 transmits the position information (X coordinate, Y coordinate) of the ID of the person to be authenticated included in the inquiry to the biometrics control unit 14 .
  • the tracking control unit 204 determines whether or not the person to be authenticated (person to be tracked) has entered the gate device 10 using the acquired position information. When the tracking control unit 204 determines that the person to be authenticated has entered the gate device 10 from the acquired position information, the tracking control unit 204 sets the tracking status of the corresponding entry in the information table of the person to be authenticated to "tracking completed". When tracking completion is set in the entry, the tracking control unit 204 notifies the passage permission notification unit 205 to that effect.
  • the passage permission notification unit 205 determines whether or not the person to be authenticated can pass through the gate device 10 according to the notification. That is, when the tracked person's position information acquired by the tracking control unit 204 indicates that the tracked person has entered the gate device 10 , the passage permission notification unit 205 determines whether the person to be authenticated can pass through the gate device 10 . Determine whether or not.
  • the gate device 10 detects the person to be authenticated.
  • the gate device 10 detects the person to be authenticated, the gate device 10 starts authentication and tracking of the person to be authenticated at substantially the same timing. Since the server device 20 can start the authentication process from a place away from the gate device 10, it is possible to secure the execution time of the biometric authentication. Also, the gate device 10 starts tracking the person to be authenticated from the remote location. At that time, the gate device 10 performs tracking using the ranging sensor 16 .
  • the gate device 10 can grasp the accurate current position of the person to be authenticated by tracking the person to be authenticated using the distance measuring sensor 16, the entry into the gate device 10 by the person to be authenticated can be reliably recognized. In other words, even if a user who is not the person to be authenticated interrupts the gate device 10, the gate device 10 can block the passage of the interrupting user.
  • FIG. 18 is a diagram showing an example of the hardware configuration of the biometrics control unit 14. As shown in FIG.
  • the biometric authentication control unit 14 includes a processor 311, a memory 312, a communication interface 313, and the like. Components such as the processor 311 are connected by an internal bus or the like and configured to be able to communicate with each other.
  • the configuration shown in FIG. 18 is not intended to limit the hardware configuration of the biometric authentication control unit 14.
  • the biometrics control unit 14 may include hardware (not shown). Also, the number of processors 311 and the like included in the biometrics control unit 14 is not limited to the example shown in FIG.
  • the processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), DSP (Digital Signal Processor). Alternatively, processor 311 may be a device such as FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or the like. The processor 311 executes various programs including an operating system (OS).
  • OS operating system
  • the memory 312 is RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), or the like.
  • the memory 312 stores an OS program, application programs, and various data.
  • the communication interface 313 is a circuit, module, etc. that communicates with other devices.
  • the communication interface 313 includes a NIC (Network Interface Card) or the like.
  • the functions of the biometric authentication control unit 14 are realized by various processing modules.
  • the processing module is implemented by the processor 311 executing a program stored in the memory 312, for example.
  • the program can be recorded in a computer-readable storage medium.
  • the storage medium can be non-transitory such as semiconductor memory, hard disk, magnetic recording medium, optical recording medium, and the like. That is, the present invention can also be embodied as a computer program product.
  • the program can be downloaded via a network or updated using a storage medium storing the program.
  • the processing module may be realized by a semiconductor chip.
  • the biometric authentication control unit 14 is equipped with a computer, and the functions of the biometric authentication control unit 14 can be realized by causing the computer to execute a program. Moreover, the biometrics control unit 14 performs the control method of the biometrics control unit 14 by the said program.
  • the hardware configuration of the tracking unit 15 can be the same as the hardware configuration of the biometrics control unit 14, so the description is omitted.
  • the gate device 10 includes the camera 11, the detection sensor 12 and the gate 13 as described above (see FIG. 19).
  • the gate device 10 has hardware such as a processor, a memory, and a communication interface in the same manner as the biometric authentication control unit 14, but illustrations and descriptions of these configurations are omitted.
  • the camera 11 is a camera device capable of acquiring visible light images.
  • the gate device 10 has been described as having one camera 11, but this is not intended to limit the number or installation of the cameras 11.
  • FIG. For example, multiple cameras 11 may be installed in the gate device 10 .
  • the person to be authenticated may be detected by other means instead of the camera 11 for detecting the person to be authenticated.
  • a human sensor or the like may be used to detect a person at a predetermined distance from the gate device 10 .
  • the camera 11 may acquire image data when a human sensor detects a person, and the person to be authenticated may be detected.
  • the detection sensor 12 is a sensor that detects people.
  • a sensor composed of a light transmitting device and a light receiving device can be used.
  • an optical transmission device and an optical reception device are installed so as to face each other (two devices are installed on the inner wall of the main body).
  • a transmitting device constantly transmits light and a receiving device receives the transmitted light.
  • the gate device 10 determines that a person is detected when the receiving device fails to receive the light. Note that FIG. 3 shows one of the two devices that constitute the detection sensor 12 .
  • the gate 13 is a device that controls the passage of users.
  • the method of the gate 13 is not particularly limited, and may be, for example, a flapper gate that opens and closes with flappers provided from one or both sides of the passage, a turnstile gate that rotates three bars, or the like.
  • the functions of the biometric authentication control unit 14 and the tracking unit 15 may be implemented by a CPU or the like that controls the gate device 10 as a whole. Conversely, the functions of the gate device 10 may be realized by the processor 311 included in the biometrics control unit 14. FIG.
  • the functions of the tracking unit 15 may be realized by the biometric control unit 14.
  • the functionality of tracking unit 15 may be incorporated in ranging sensor 16 . That is, the distance measurement sensor 16 having the function of the tracking unit 15 and the biometric control unit 14 may be connected.
  • the server device 20 can be configured by an information processing device. As with the biometric authentication control unit 14, the server device 20 only needs to include a processor, a memory, a communication interface, and the like.
  • the gate device 10 is explained as a ticket gate installed at the station. However, it is of course not intended to limit the gate device 10 to a ticket gate.
  • the gate device 10 may be a device that is installed in an airport, an event site, an office, or the like, and controls the passage of users.
  • the server device 20 has a user information database
  • the database may be constructed in a database server different from the server device 20 .
  • the authentication system may include various means (authentication request unit 203, tracking control unit 204, etc.) described in the above embodiment.
  • the authentication process performed by the server device 20 may be performed by the gate device 10 (biometric authentication control unit 14).
  • a part or all of the functions of the server device 20 may be realized by the gate device 10 .
  • the biometric information related to the feature amount generated from the face image is transmitted from the biometric authentication control unit 14 to the server device 20 .
  • the “face image” itself may be transmitted from the biometric authentication control unit 14 to the server device 20 as the biometric information.
  • the server device 20 may generate a feature amount from the acquired face image and perform authentication processing (one-to-N matching).
  • the authenticated person detection unit 202 estimates the position (X coordinate, Y coordinate) of the authenticated person.
  • the estimation of the location of the person to be authenticated may be performed by the tracking control unit 204 .
  • the person-to-be-authenticated detection unit 202 may pass the person-to-be-authenticated ID and the image data to the tracking control unit 204 .
  • the tracking control unit 204 may estimate the position (X coordinate, Y coordinate) of the person to be authenticated using the acquired image data.
  • the camera 11 is assumed to be a monocular camera, but the camera 11 may be a depth camera (stereo camera) capable of measuring the depth direction.
  • the biometric authentication control unit 14 may detect the person to be authenticated at a predetermined distance from the gate device 10 using an image obtained from a stereo camera instead of thresholding the distance between the eyes. Specifically, the biometrics control unit 14 analyzes two images obtained from the stereo camera (analysis using parallax), and calculates the user's position with respect to the gate device 10 . If the calculated position is included in the predetermined location, the biometric authentication control unit 14 sets the user as a person to be authenticated.
  • the form of data transmission/reception between the biometric authentication control unit 14 and the server device 20 is not particularly limited, but the data transmitted/received between these devices may be encrypted.
  • a face image and a feature amount calculated from the face image are personal information, and in order to appropriately protect the personal information, it is desirable to transmit and receive encrypted data.
  • the gate device 10 the biometrics control unit 14, and the tracking unit 15 are separated has been described.
  • these devices may be integrated. That is, the biometrics control unit 14 and the tracking unit 15 may be integrated with the gate device 10 .
  • the gate device 10 includes, in addition to the configuration shown in FIG. It is sufficient if the tracking section 302 of the unit 15 is provided.
  • the information about the person to be authenticated is stored and managed using the information table for the person to be authenticated.
  • the information about the person to be authenticated may be stored and managed using a database (person to be authenticated information database).
  • each embodiment may be used alone or in combination.
  • additions, deletions, and replacements of other configurations are possible for some of the configurations of the embodiments.
  • the industrial applicability of the present invention is clear, and the present invention can be suitably applied to authentication systems installed at airports, stations, and the like.
  • an authenticated person detection unit for detecting an authenticated person; a request unit that transmits an authentication request including the biometric information of the person to be authenticated to a server device; a tracking control unit that transmits a tracking start instruction including position information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtains a tracking result from the tracking unit; determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device notifying, a notification unit; A biometric control unit.
  • the tracking control unit receives from the tracking unit an authentication-subjected person entry notification indicating that the tracked person has entered the gate device, The biometric authentication control unit according to supplementary note 1, wherein the notification unit determines whether or not the person to be authenticated can pass through a gate device in response to receiving the notification of entry of the person to be authenticated.
  • the tracking control unit after transmitting the tracking start instruction, transmitting a location inquiry including the subject ID to the tracking unit, obtaining location information of the tracked person corresponding to the subject ID from the tracking unit; Supplementary Note 1: The notification unit determines whether the person-to-be-authenticated can pass through the gate device when the acquired position information of the tracked person indicates that the tracked person has entered the gate device.
  • the biometric authentication control unit according to .
  • the authentication-subject detection unit detects the authentication-subject, the authentication-subject detection unit adds an entry to an authentication-subject information table,
  • the request unit receives the biometric authentication result from the server device, the request unit sets the received biometric authentication result in an authentication status field of the added entry,
  • the tracking control unit sets the tracking result in a tracking status field of the added entry; 4.
  • the notification unit according to any one of appendices 1 to 3, wherein the notification unit determines whether or not the person to be authenticated can pass through the gate device based on the set value of the authentication status field and the set value of the tracking status field.
  • a biometric control unit as described.
  • the biometric authentication control unit according to appendix 4, further comprising a table management unit that deletes an entry that has passed a predetermined period of time after being added to the authentication-subjected person information table.
  • Appendix 6 6.
  • the biometric authentication control unit according to any one of appendices 1 to 5, wherein the biometric information is a facial image or a feature amount generated from the facial image.
  • a server device that stores biometric information of each of a plurality of users and performs biometric authentication; a gate device equipped with a biometric control unit and a tracking unit; including The biometric control unit, A person to be authenticated is detected, an authentication request including biometric information of the detected person to be authenticated is transmitted to the server device, and a tracking start instruction including location information of the person to be authenticated is transmitted to the tracking unit. death,
  • the tracking unit is A person existing at a location corresponding to the position information included in the tracking start instruction is set as a person to be tracked, the person to be tracked is tracked using a range sensor, and the person to be tracked enters the gate device.
  • the biometric control unit transmitting the tracking start instruction including the location information of the subject and the subject ID of the subject to the tracking unit;
  • the tracking unit is When the position of the tracked person and the ID of the person to be authenticated are associated and managed, and when the tracking is completed in response to the entry of the tracked person into the gate device, the target of the tracked person who has completed the tracking is managed.
  • an authenticator ID is communicated to the biometric control unit.
  • the biometric control unit transmitting an authentication request including the detected biometric information of the person to be authenticated and the ID of the person to be authenticated to the server device; The system according to appendix 8, wherein the server device notifies the biometric authentication control unit of the authenticated person ID of the person to be authenticated.
  • the biometric authentication control unit determines whether or not a person to be authenticated whose ID of the person to be authenticated notified from the server device matches the ID of the person to be authenticated notified from the tracking unit can pass through the gate device. , Supplement 9. [Appendix 11] 11.
  • biometric control unit detect the subject, transmitting an authentication request including the biometric information of the person to be authenticated to a server device; sending a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtaining a tracking result from the tracking unit; determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device A method of controlling a biometrics control unit to notify.

Landscapes

  • Engineering & Computer Science (AREA)
  • Human Computer Interaction (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Collating Specific Patterns (AREA)

Abstract

Provided is a biometric authentication control unit that suitably controls the passage of users. The biometric authentication control unit comprises an authentication subject detection unit, a request unit, a tracking control unit, and a notification unit. The authentication subject detection unit detects an authentication subject. The request units transmits an authentication request including biometric information from the authentication subject to a server device. The tracking control unit transmits a tracking start instruction including location information for the authentication subject to a tracking unit which tracks a tracking subject using a distance measurement sensor. The tracking control unit also acquires a tracking result from the tracking unit. The notification unit uses the result of biometric authentication of the authentication subject by the server device and the tracking result of the tracking unit as a basis to determine whether the authentication subject can pass through a gate device and transmits the determination result to the gate device.

Description

生体認証制御ユニット、システム、生体認証制御ユニットの制御方法及び記憶媒体Biometric authentication control unit, system, control method of biometric authentication control unit, and storage medium
 本発明は、生体認証制御ユニット、システム、生体認証制御ユニットの制御方法及び記憶媒体に関する。 The present invention relates to a biometric authentication control unit, a system, a control method for the biometric authentication control unit, and a storage medium.
 顔認証を用いたサービスの普及が始まっている。例えば、空港における各種手続き(例えば、チェックイン、荷物預け入れ、セキュリティチェック等)に顔認証の適用が始まっている。あるいは、顔認証に対応した改札機の開発も進められている。生体認証に関する種々の技術開発が行われている。 The spread of services using face recognition has begun. For example, face recognition has started to be applied to various procedures (eg, check-in, luggage deposit, security check, etc.) at airports. Alternatively, the development of ticket gates compatible with face recognition is also underway. Various techniques related to biometric authentication are being developed.
 例えば、特許文献1には、有料施設を利用する特定の利用者に対して、IC(Integrated Circuit)カードにより割引などの利用料金の減免措置を行うとともに他者の不正利用行為を防止する、と記載されている。特許文献1の顔認証自動改札機は、記憶部と、カード情報読取部と、撮像部と、料金割引判定部と、を備える。記憶部は、特定の利用者の顔の画像と利用者が所持する無線カードのIDとを対応させた顔照合用データを記憶する。カード情報読取部は、有料施設入口の通路で無線カードから情報を読み取る。撮像部は、通路に進入する利用者の顔の画像を撮像する。料金割引判定部は、無線カードから読み取られたIDをキーにして記憶部に記憶されている顔照合用データの中からIDが一致する顔の画像を読み出して撮影画像と照合する。料金割引判定部は、照合の結果、画像が合致した場合、無線カードから読み取った割引フラグに従って料金割引を行う。 For example, in Patent Document 1, for specific users of paid facilities, IC (Integrated Circuit) cards are used to reduce usage fees such as discounts and prevent unauthorized use by others. Are listed. The face authentication automatic ticket gate of Patent Literature 1 includes a storage unit, a card information reading unit, an imaging unit, and a fee discount determination unit. The storage unit stores face verification data in which the face image of a specific user and the ID of the wireless card possessed by the user are associated with each other. The card information reading unit reads information from the wireless card at the entrance of the toll facility. The imaging unit captures an image of the face of the user entering the aisle. The fee discount determination unit uses the ID read from the wireless card as a key to read out a face image having a matching ID from the face matching data stored in the storage unit and compares the face image with the photographed image. If the images match as a result of collation, the fee discount determination unit applies a fee discount according to the discount flag read from the wireless card.
 特許文献2には、簡易な構成で、ウォークスルー顔認証の利便性を維持しながら、未認証者の不正通行を防止可能とする、と記載されている。特許文献2の顔認証システムは、認証領域を通行する人物を顔認証して当該人物の通行許否を判定する。当該システムは、画像取得手段と、記憶手段と、顔照合手段と、認可手段と、を備える。画像取得手段は、認証領域を撮影して入力画像を順次取得する。記憶手段は、予め登録された利用者の登録顔画像を記憶する。顔照合手段は、入力画像から抽出された人物の顔画像と登録顔画像とを照合し、当該人物が前記利用者であることを認証する。認可手段は、入力画像における認証された人物を示す領域の大きさが所定以上のとき、当該人物の通行を許可する。当該システムは、顔認証により正規利用者と認証されたとしても、その認証者がカメラから離れた位置にいる場合は通行許可せず、認証者のカメラ側への接近を検出した時点で通行を許可する。 Patent Document 2 states that it is possible to prevent unauthorized passage by unauthorized persons while maintaining the convenience of walk-through face authentication with a simple configuration. The face authentication system disclosed in Patent Literature 2 authenticates the face of a person passing through an authentication area and determines whether the person is allowed to pass. The system comprises image acquisition means, storage means, face matching means, and authorization means. The image obtaining means sequentially obtains input images by photographing the authentication area. The storage means stores a pre-registered registered face image of the user. The face collation means collates the face image of the person extracted from the input image with the registered face image, and authenticates that the person is the user. The authorization means permits passage of the authenticated person when the size of the area indicating the authenticated person in the input image is equal to or larger than a predetermined size. Even if an authorized user is authenticated by facial recognition, the system does not permit passage if the authenticated person is away from the camera. To give permission.
 特許文献3の情報処理装置は、画像処理手段と、距離推定手段と、照合手段と、を備える。画像処理手段は、ゲートの通過前領域を撮影した撮影画像内の対象の特徴量を抽出して、当該特徴量に基づく対象の照合に関する照合情報を記憶させる。距離推定手段は、ゲートから撮影画像内の対象までの距離を推定する。照合手段は、推定した距離と、当該距離を推定した対象の記憶されている照合情報と、に基づいて照合判定を行う。 The information processing device of Patent Document 3 includes image processing means, distance estimation means, and matching means. The image processing means extracts the feature amount of the object in the photographed image of the area before passing through the gate, and stores collation information relating to the collation of the object based on the feature amount. The distance estimation means estimates the distance from the gate to the object in the captured image. The collation means performs collation determination based on the estimated distance and the stored collation information of the target for which the distance was estimated.
特開2010-097272号公報JP 2010-097272 A 特開2015-001790号公報JP 2015-001790 A 特開2019-133364号公報JP 2019-133364 A
 駅に設置された改札機のように多くの利用者により利用されるゲート装置に生体認証を適用する場合、問題が生じることがある。具体的には、ゲート装置の前に位置する人物の認証を開始したが、当該人物の前に他人が割り込んできた場合に問題が生じ得る。この場合、認証をしていない人物の通過を許す可能性がある。 Problems can arise when biometric authentication is applied to gate devices that are used by many users, such as ticket gates installed at stations. Specifically, a problem may arise if authentication of a person positioned in front of a gate device is initiated, but another person interrupts in front of the person. In this case, there is a possibility of allowing an unauthenticated person to pass through.
 なお、当該問題点は、特許文献1乃至特許文献3に開示された技術を適用しても解決することができない。これらの文献は、生体認証を用いたゲート装置等を開示することに留まるためである。 This problem cannot be solved by applying the techniques disclosed in Patent Documents 1 to 3. This is because these documents only disclose gate devices and the like using biometric authentication.
 本発明は、利用者の通行を適切に制御することに寄与する、生体認証制御ユニット、システム、生体認証制御ユニットの制御方法及び記憶媒体を提供することを主たる目的とする。 The main purpose of the present invention is to provide a biometric authentication control unit, a system, a biometric authentication control unit control method, and a storage medium that contribute to appropriately controlling the passage of users.
 本発明の第1の視点によれば、被認証者を検出する、被認証者検出部と、前記被認証者の生体情報を含む認証要求をサーバ装置に送信する、要求部と、測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得する追跡制御部と、前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、通知部と、を備える、生体認証制御ユニットが提供される。 According to a first aspect of the present invention, a person-to-be-authenticated detecting unit that detects a person to be authenticated; a requesting unit that transmits an authentication request including biometric information of the person to be authenticated to a server device; a tracking control unit that transmits a tracking start instruction including location information of the person to be authenticated to a tracking unit that tracks a person to be tracked using a tracking control unit that acquires a tracking result from the tracking unit; A notification unit that determines whether or not the person to be authenticated can pass through the gate device based on the result of the biometric authentication of the person to be authenticated and the result of the tracking by the tracking unit, and notifies the gate device of the determination result. and a biometric control unit.
 本発明の第2の視点によれば、複数の利用者それぞれの生体情報を記憶し、生体認証を行うサーバ装置と、生体認証制御ユニット及び追跡ユニットが搭載されたゲート装置と、を含み、前記生体認証制御ユニットは、被認証者を検出し、前記検出された被認証者の生体情報を含む認証要求を前記サーバ装置に送信すると共に、前記追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信し、前記追跡ユニットは、前記追跡開始指示に含まれる位置情報に対応する場所に存在する人を追跡対象者に設定し、測距センサを用いて前記追跡対象者の追跡を行い、前記追跡対象者が前記ゲート装置に進入すると被認証者進入通知を前記生体認証制御ユニットに送信し、前記生体認証制御ユニットは、前記被認証者進入通知を受信すると、前記サーバ装置による認証結果に基づいて前記被認証者が前記ゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、システムが提供される。 According to a second aspect of the present invention, including a server device that stores biometric information of each of a plurality of users and performs biometric authentication, and a gate device equipped with a biometric authentication control unit and a tracking unit, The biometric authentication control unit detects a person to be authenticated, transmits an authentication request including the detected biometric information of the person to be authenticated to the server device, and sends location information of the person to be authenticated to the tracking unit. and the tracking unit sets a person existing at a location corresponding to the position information included in the tracking start instruction as a person to be tracked, and tracks the person to be tracked using a range sensor. and when the tracked person enters the gate device, a notification of entry of the person to be authenticated is transmitted to the biometric authentication control unit, and when the biometric authentication control unit receives the notification of entry of the person to be authenticated, the server device A system is provided that determines whether or not the person to be authenticated can pass through the gate device based on an authentication result, and notifies the gate device of the determination result.
 本発明の第3の視点によれば、生体認証制御ユニットにおいて、被認証者を検出し、前記被認証者の生体情報を含む認証要求をサーバ装置に送信し、測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得し、前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、生体認証制御ユニットの制御方法が提供される。 According to a third aspect of the present invention, the biometric authentication control unit detects a person to be authenticated, transmits an authentication request including the biometric information of the person to be authenticated to the server device, a tracking start instruction including the location information of the person to be authenticated is transmitted to a tracking unit that tracks the person, a tracking result is obtained from the tracking unit, and a biometric authentication result of the person to be authenticated by the server device; , the tracking result by the tracking unit, and whether or not the person to be authenticated can pass through the gate device, and notifies the gate device of the determination result. .
 本発明の第4の視点によれば、生体認証制御ユニットに搭載されたコンピュータに、被認証者を検出する処理と、前記被認証者の生体情報を含む認証要求をサーバ装置に送信する処理と、測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得する処理と、前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する処理と、を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体が提供される。 According to a fourth aspect of the present invention, a computer installed in a biometric authentication control unit performs processing for detecting a person to be authenticated and processing for transmitting an authentication request including the biometric information of the person to be authenticated to a server device. a process of transmitting a tracking start instruction including location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtaining a tracking result from the tracking unit; determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated and the tracking result by the tracking unit, and notifying the gate device of the determination result A computer readable storage medium is provided that stores a program for executing and.
 本発明の各視点によれば、利用者の通行を適切に制御することに寄与する、生体認証制御ユニット、システム、生体認証制御ユニットの制御方法及び記憶媒体が提供される。なお、本発明の効果は上記に限定されない。本発明により、当該効果の代わりに、又は当該効果と共に、他の効果が奏されてもよい。 According to each aspect of the present invention, a biometric authentication control unit, a system, a control method for the biometric authentication control unit, and a storage medium that contribute to appropriately controlling the passage of users are provided. In addition, the effect of this invention is not limited above. Other effects may be achieved by the present invention instead of or in addition to this effect.
図1は、一実施形態の概要を説明するための図である。FIG. 1 is a diagram for explaining an overview of one embodiment. 図2は、第1の実施形態に係る認証システムの概略構成の一例を示す図である。FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment. 図3は、第1の実施形態に係る認証システムの動作を説明するための図である。FIG. 3 is a diagram for explaining the operation of the authentication system according to the first embodiment. 図4は、第1の実施形態に係る生体認証制御ユニットの処理構成の一例を示す図である。4 is a diagram illustrating an example of a processing configuration of a biometric authentication control unit according to the first embodiment; FIG. 図5は、第1の実施形態に係る被認証者情報テーブルの一例を示す図である。FIG. 5 is a diagram showing an example of an authentication-subjected person information table according to the first embodiment. 図6は、第1の実施形態に係る認証要求の一例を示す図である。FIG. 6 is a diagram showing an example of an authentication request according to the first embodiment. 図7は、第1の実施形態に係る追跡ユニットの処理構成の一例を示す図である。7 is a diagram illustrating an example of a processing configuration of a tracking unit according to the first embodiment; FIG. 図8A及び図8Bは、第1の実施形態に係る追跡部の動作を説明するための図である。8A and 8B are diagrams for explaining the operation of the tracking unit according to the first embodiment. 図9は、第1の実施形態に係るゲート装置の処理構成の一例を示す図である。FIG. 9 is a diagram illustrating an example of a processing configuration of the gate device according to the first embodiment; 図10は、第1の実施形態に係る生体認証制御ユニット及びゲート装置の動作の一例を示すシーケンス図である。10 is a sequence diagram illustrating an example of operations of the biometric authentication control unit and the gate device according to the first embodiment; FIG. 図11は、第1の実施形態に係るゲート装置の処理構成の一例を示す図である。FIG. 11 is a diagram illustrating an example of a processing configuration of the gate device according to the first embodiment; 図12は、第1の実施形態に係る利用者情報データベースの一例を示す図である。FIG. 12 is a diagram illustrating an example of a user information database according to the first embodiment; 図13は、第1の実施形態に係る認証状況データベースの一例を示す図である。FIG. 13 is a diagram illustrating an example of an authentication status database according to the first embodiment; 図14は、第1の実施形態に係るサーバ装置の動作の一例を示すフローチャートである。14 is a flowchart illustrating an example of the operation of the server device according to the first embodiment; FIG. 図15は、第1の実施形態に係る認証システムの動作の一例を示すシーケンス図である。15 is a sequence diagram illustrating an example of the operation of the authentication system according to the first embodiment; FIG. 図16は、第1の実施形態に係る認証システムの動作を説明するための図である。FIG. 16 is a diagram for explaining the operation of the authentication system according to the first embodiment; 図17は、第1の実施形態に係る認証システムの動作を説明するための図である。FIG. 17 is a diagram for explaining the operation of the authentication system according to the first embodiment; 図18は、本願開示に係る生体認証制御ユニットのハードウェア構成の一例を示す図である。FIG. 18 is a diagram illustrating an example of a hardware configuration of a biometric authentication control unit disclosed in the present application; 図19は、本願開示に係るゲート装置のハードウェア構成の一例を示す図である。FIG. 19 is a diagram illustrating an example of a hardware configuration of a gate device according to the disclosure of the present application.
 はじめに、一実施形態の概要について説明する。なお、この概要に付記した図面参照符号は、理解を助けるための一例として各要素に便宜上付記したものであり、この概要の記載はなんらの限定を意図するものではない。また、特段の釈明がない場合には、各図面に記載されたブロックはハードウェア単位の構成ではなく、機能単位の構成を表す。各図におけるブロック間の接続線は、双方向及び単方向の双方を含む。一方向矢印については、主たる信号(データ)の流れを模式的に示すものであり、双方向性を排除するものではない。なお、本明細書及び図面において、同様に説明されることが可能な要素については、同一の符号を付することにより重複説明が省略され得る。 First, an outline of one embodiment will be described. It should be noted that the drawing reference numerals added to this outline are added to each element for convenience as an example to aid understanding, and the description of this outline does not intend any limitation. Also, unless otherwise specified, the blocks shown in each drawing represent the configuration of each function rather than the configuration of each hardware unit. Connecting lines between blocks in each figure include both bi-directional and uni-directional. The unidirectional arrows schematically show the flow of main signals (data) and do not exclude bidirectionality. In addition, in the present specification and drawings, elements that can be described in the same manner can be omitted from redundant description by assigning the same reference numerals.
 一実施形態に係る生体認証制御ユニット100は、被認証者検出部101と、要求部102と、追跡制御部103と、通知部104と、を備える(図1参照)。被認証者検出部101は、被認証者を検出する。要求部102は、被認証者の生体情報を含む認証要求をサーバ装置に送信する。追跡制御部103は、測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、被認証者の位置情報を含む追跡開始指示を送信すると共に、追跡ユニットから追跡結果を取得する。通知部104は、サーバ装置による被認証者の生体認証の結果と、追跡ユニットによる追跡結果と、に基づいて被認証者がゲート装置を通行できるか否か判定し、判定結果をゲート装置に通知する。 The biometric authentication control unit 100 according to one embodiment includes an authentication subject detection unit 101, a request unit 102, a tracking control unit 103, and a notification unit 104 (see FIG. 1). The to-be-authenticated person detection unit 101 detects the to-be-authenticated person. The request unit 102 transmits an authentication request including the biometric information of the person to be authenticated to the server device. The tracking control unit 103 transmits a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and acquires the tracking result from the tracking unit. The notification unit 104 determines whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and notifies the gate device of the determination result. do.
 生体認証制御ユニット100は、ゲート装置から離れた位置の利用者を被認証者として検出する。生体認証制御ユニット100は、被認証者を検出すると、当該被認証者の生体認証と追跡(トラッキング)を開始する。具体的には、生体認証制御ユニット100は、サーバ装置に被認証者の生体認証を依頼し、追跡ユニットに当該被認証者の追跡を依頼(指示)する。生体認証制御ユニット100は、被認証者の追跡が完了すると(例えば、被認証者がゲート装置に進入した事実を追跡ユニットから取得すると)、被認証者の認証結果を確認する。生体認証制御ユニット100は、追跡の完了した被認証者の生体認証が成功していると、当該被認証者がゲート装置を通行することを許可する。換言すれば、被認証者の横から割り込んできた利用者に関しては、生体認証がサーバ装置に要求されず、且つ、追跡が完了することもないので、当該利用者はゲート装置を通過することができない。即ち、利用者の通行は適切に制御される。 The biometric authentication control unit 100 detects a user who is far from the gate device as a person to be authenticated. When the biometrics control unit 100 detects a person to be authenticated, it starts biometrics authentication and tracking of the person to be authenticated. Specifically, the biometrics control unit 100 requests the server device to biometrically authenticate the person to be authenticated, and requests (instructs) the tracking unit to track the person to be authenticated. When the tracking of the person to be authenticated is completed (for example, the fact that the person to be authenticated has entered the gate device is obtained from the tracking unit), the biometrics control unit 100 confirms the authentication result of the person to be authenticated. The biometrics control unit 100 permits the person to be authenticated to pass through the gate device when the biometrics authentication of the person to be authenticated whose tracking has been completed is successful. In other words, a user who interrupts from the side of the person to be authenticated is not required to be biometrically authenticated by the server device, and tracking is not completed, so the user cannot pass through the gate device. Can not. That is, the traffic of users is appropriately controlled.
 ここで、被認証者の追跡に関し、被認証者が写る画像データを用いることが考えられる。しかし、発明者らが鋭意検討した結果、画像データを用いた被認証者の追跡では十分な追跡精度が得られないことが判明した。具体的には、画像データを用いた追跡では、画像内の位置に基づいて追跡対象者を決定するため、利用者が重なった場合等に正確な追跡が行なえないことが分かった。生体認証制御ユニット100は、測距センサ(例えば、3次元距離センサ;3D LiDAR)を用いた追跡を行う追跡ユニットに被認証者の追跡を指示することで、上記のような問題を解決する。即ち、測距センサを使った被認証者の追跡により当該被認証者の正確な現在位置が把握されるので、被認証者が重なった場合等であっても、ゲート装置を通過する権限のない利用者は確実に排除される。生体認証制御ユニット100は、画像データから被認証者を抽出し、当該抽出した被認証者の追跡を、測距センサを制御する追跡ユニットに行わせることで、利用者の通行を適切に制御する。 Here, it is conceivable to use image data showing the person to be authenticated for tracking the person to be authenticated. However, as a result of intensive studies by the inventors, it has been found that sufficient tracking accuracy cannot be obtained by tracking a person to be authenticated using image data. Specifically, in tracking using image data, it was found that accurate tracking cannot be performed when users overlap because the tracking target is determined based on the position in the image. The biometric authentication control unit 100 solves the above problems by instructing a tracking unit that performs tracking using a distance measuring sensor (for example, a three-dimensional distance sensor; 3D LiDAR) to track the person to be authenticated. That is, since the accurate current position of the person to be authenticated is grasped by tracking the person to be authenticated using the distance measuring sensor, even if the person to be authenticated overlaps with the person to be authenticated, there is no right to pass through the gate device. Users will definitely be excluded. The biometric authentication control unit 100 extracts the person to be authenticated from the image data, and causes the tracking unit that controls the range sensor to track the extracted person to be authenticated, thereby appropriately controlling the passage of the user. .
 以下に具体的な実施形態について、図面を参照してさらに詳しく説明する。 Specific embodiments will be described in more detail below with reference to the drawings.
[第1の実施形態]
 第1の実施形態について、図面を用いてより詳細に説明する。
[First Embodiment]
The first embodiment will be described in more detail with reference to the drawings.
[システム構成]
 図2は、第1の実施形態に係る認証システムの概略構成の一例を示す図である。図2を参照すると、認証システムは、複数のゲート装置10-1~10-3と、サーバ装置20と、を含む。
[System configuration]
FIG. 2 is a diagram showing an example of a schematic configuration of an authentication system according to the first embodiment. Referring to FIG. 2, the authentication system includes a plurality of gate devices 10-1 to 10-3 and a server device 20. FIG.
 以降の説明において、ゲート装置10-1~10-3を区別する特段の理由がない場合には、単に「ゲート装置10」と表記する。他の構成についても同様に、ハイフンより左側の符号にて当該構成を代表して表記する。 In the following description, the gate devices 10-1 to 10-3 are simply referred to as "gate device 10" unless there is a particular reason to distinguish them. Similarly, other configurations are represented by the symbols to the left of the hyphen.
 ゲート装置10とサーバ装置20は、有線又は無線の通信手段により通信が可能に構成されている。サーバ装置20は、ゲート装置10と同じ建物内に設置されていてもよいし、ネットワーク(クラウド)上に設置されていてもよい。 The gate device 10 and the server device 20 are configured to be able to communicate with each other through wired or wireless communication means. The server device 20 may be installed in the same building as the gate device 10, or may be installed on a network (cloud).
 ゲート装置10は、例えば、空港や駅に設置される装置である。ゲート装置10は、利用者の通行を制御する。第1の実施形態では、ゲート装置10は、駅に設置される改札機として説明を行う。ただし、ゲート装置10を駅に設置された改札機に限定する趣旨ではないことは勿論である。 The gate device 10 is, for example, a device installed at airports and stations. The gate device 10 controls passage of users. In the first embodiment, the gate device 10 will be described as a ticket gate installed at a station. However, it is needless to say that the gate device 10 is not intended to be limited to ticket gates installed at stations.
 サーバ装置20は、認証システムの全体を制御する装置である。サーバ装置20は、ゲート装置10を通過しようとする利用者の生体認証を行う装置である。サーバ装置20は、利用者がゲート装置10を通過する資格(権限)を備えていれば、当該利用者の通行を許可する。サーバ装置20は、利用者がゲート装置10を通過する資格を備えていなければ、当該利用者の通行を拒否する。 The server device 20 is a device that controls the entire authentication system. The server device 20 is a device that performs biometric authentication of a user who is going to pass through the gate device 10 . If the user is qualified (authorized) to pass through the gate device 10, the server device 20 permits the user to pass through. If the user is not qualified to pass through the gate device 10, the server device 20 denies the user passage.
[システムの動作概略]
 続いて、図面を参照しつつ、第1の実施形態に係る認証システムの動作概略を説明する。
[Overview of system operation]
Next, an outline of operation of the authentication system according to the first embodiment will be described with reference to the drawings.
 図3に示すように、ゲート装置10は、ゲート装置10に向かって歩いてくる利用者を撮影可能に設置されたカメラ11を備える。また、ゲート装置10は、自装置内に進入した利用者を検出するための検出センサ12と、利用者の通行を制御するためのゲート13と、を備える。 As shown in FIG. 3, the gate device 10 includes a camera 11 installed so as to capture a user walking towards the gate device 10 . The gate device 10 also includes a detection sensor 12 for detecting a user who has entered the gate device 10, and a gate 13 for controlling the passage of the user.
 また、ゲート装置10は、生体認証制御ユニット14を備える。生体認証制御ユニット14は、ゲート装置10に後付け(アドオン)可能なユニットである。ゲート装置10と生体認証制御ユニット14は、例えば、USB(Universal Serial Bus)、PCI(Peripheral Component Interconnect)又はイーサネット(登録商標)等のバス規格で接続される。また、生体認証制御ユニット14は、カメラ11等と通信可能に構成されており、これらのデバイスを制御(使用)してゲート装置10の生体認証機能を実現する。 The gate device 10 also includes a biometric authentication control unit 14 . The biometric authentication control unit 14 is a unit that can be retrofitted (add-on) to the gate device 10 . The gate device 10 and the biometric authentication control unit 14 are connected by a bus standard such as USB (Universal Serial Bus), PCI (Peripheral Component Interconnect), or Ethernet (registered trademark). Also, the biometric authentication control unit 14 is configured to be able to communicate with the camera 11 and the like, and controls (uses) these devices to realize the biometric authentication function of the gate device 10 .
 さらに、ゲート装置10は、追跡ユニット15を備える。追跡ユニット15も、ゲート装置10に後付け(アドオン)可能なユニットである。被認証者の追跡機能をゲート装置10に追加する場合に、追跡ユニット15はゲート装置10に取り付けられる。生体認証制御ユニット14と追跡ユニット15は、例えば、USB、イーサネット(登録商標)等のバス規格で接続される。また、追跡ユニット15は、物体の検出が可能な測距センサ16を制御可能に構成されており、当該デバイスを使用して利用者の追跡を実現する。 Furthermore, the gate device 10 includes a tracking unit 15 . The tracking unit 15 is also a unit that can be retrofitted (add-on) to the gate device 10 . The tracking unit 15 is attached to the gate device 10 when adding a tracking function of the person to be authenticated to the gate device 10 . The biometric authentication control unit 14 and the tracking unit 15 are connected by a bus standard such as USB or Ethernet (registered trademark), for example. Also, the tracking unit 15 is configured to be able to control a range sensor 16 capable of detecting an object, and uses this device to track the user.
 このように、第1の実施形態に係るゲート装置10には、生体認証制御ユニット14と追跡ユニット15が搭載されている。 In this way, the biometric authentication control unit 14 and the tracking unit 15 are installed in the gate device 10 according to the first embodiment.
 測距センサ16は、空間中の物体までの距離をスキャンするセンサである。測距センサ16には、ステレオカメラ、TOF(Time Of Flight)方式の距離画像センサ、3次元距離センサ(3D LiDAR)等を用いることができる。 The ranging sensor 16 is a sensor that scans the distance to an object in space. A stereo camera, a TOF (Time Of Flight) distance image sensor, a three-dimensional distance sensor (3D LiDAR), or the like can be used as the distance measurement sensor 16 .
 生体認証制御ユニット14は、ゲート装置10からみて前方の所定範囲内に存在する人物(利用者、乗客)を検出する。例えば、生体認証制御ユニット14は、図3の位置X1よりもゲート装置10に近くに存在する利用者を検出する。換言すれば、生体認証制御ユニット14は、ゲート装置10から遠くに存在する利用者を検出しない。 The biometric authentication control unit 14 detects a person (user, passenger) present within a predetermined range in front of the gate device 10 . For example, the biometric control unit 14 detects a user who is closer to the gate device 10 than the position X1 in FIG. In other words, the biometrics control unit 14 does not detect users who are far from the gate device 10 .
 生体認証制御ユニット14は、利用者を検出すると、当該利用者を認証対象(被認証者)に設定する。例えば、図3の例では、利用者A1が被認証者に設定される。利用者A2は、ゲート装置10から離れているため、被認証者に設定されない。 When the biometric authentication control unit 14 detects a user, it sets the user as an authentication target (authenticated person). For example, in the example of FIG. 3, user A1 is set as the person to be authenticated. User A2 is not set as a person to be authenticated because he is away from the gate device 10 .
 生体認証制御ユニット14は、被認証者にID(IDentifier)を付与する。例えば、図3の例では、利用者A1に「ID_A1」が付与される。以降の説明において、被認証者を識別するためのIDを「被認証者ID」と表記する。 The biometric authentication control unit 14 gives an ID (Identifier) to the person to be authenticated. For example, in the example of FIG. 3, "ID_A1" is assigned to user A1. In the following description, an ID for identifying a person to be authenticated will be referred to as a "person to be authenticated ID".
 例えば、ゲート装置10に近い位置(例えば、位置X1)で利用者が検出されると、生体認証制御ユニット14は、サーバ装置20に対して当該検出された利用者の生体認証を要求する。具体的には、生体認証制御ユニット14は、利用者の生体情報及び被認証者IDを含む「認証要求」をサーバ装置20に送信する。 For example, when a user is detected at a position (for example, position X1) near the gate device 10, the biometric authentication control unit 14 requests the server device 20 to biometrically authenticate the detected user. Specifically, the biometric authentication control unit 14 transmits an “authentication request” including the biometric information of the user and the ID of the person to be authenticated to the server device 20 .
 認証要求を受信したサーバ装置20は、事前に登録された生体情報を用いた照合処理(認証処理)により、利用者を特定する。サーバ装置20は、当該特定された利用者がゲート装置10を通行する資格を備えているか否か判定する。例えば、サーバ装置20は、事前登録された利用者のチャージ金額等を確認し、被認証者の通行可否を判定する。なお、サーバ装置20は、被認証者の通行可否の判定をする際、外部のサーバ等に問合せをする場合もある。外部サーバ等に問合わせるか否かはシステムの仕様、設計等に依存し、且つ、本願開示の趣旨とも異なるので当該外部サーバを含むシステムの構成に関する説明を省略する。 Upon receiving the authentication request, the server device 20 identifies the user through verification processing (authentication processing) using pre-registered biometric information. The server device 20 determines whether or not the specified user is qualified to pass through the gate device 10 . For example, the server device 20 confirms the pre-registered user's charge amount and the like, and determines whether or not the person to be authenticated can pass. The server device 20 may make an inquiry to an external server or the like when determining whether or not the person to be authenticated can pass. Whether or not to inquire of an external server or the like depends on the specifications, design, etc. of the system, and is different from the gist of the present disclosure, so a description of the system configuration including the external server will be omitted.
 サーバ装置20は、認証要求に対する応答(認証結果)を当該要求の送信元である生体認証制御ユニット14に送信する。具体的には、サーバ装置20は、「通行可」と判定された場合には、「認証成功」を生体認証制御ユニット14に通知する。「通行不可」と判定された場合には、サーバ装置20は、「認証失敗」を生体認証制御ユニット14に通知する。 The server device 20 transmits a response (authentication result) to the authentication request to the biometric authentication control unit 14, which is the source of the request. Specifically, the server device 20 notifies the biometric authentication control unit 14 of “successful authentication” when it is determined that “passage is permitted”. If it is determined that the passage is not allowed, the server device 20 notifies the biometric authentication control unit 14 of the "authentication failure".
 サーバ装置20は、生体認証の結果(認証成功、認証失敗)と共に、被認証者IDをゲート装置10に通知する。上記の例では、利用者A1の認証結果と共に、被認証者ID「ID_A1」がゲート装置10に通知される。 The server device 20 notifies the gate device 10 of the ID of the person to be authenticated along with the result of the biometric authentication (authentication success, authentication failure). In the above example, the authentication target ID “ID_A1” is notified to the gate device 10 together with the authentication result of the user A1.
 また、ゲート装置10は、認証要求の送信(認証の開始)と実質的に同じタイミングで、上記利用者(位置X1で検出された被認証者)の追跡(トラッキング)を開始する。具体的には、生体認証制御ユニット14は、追跡ユニット15に対して被認証者の追跡開始を指示する。 Also, the gate device 10 starts tracking the user (person to be authenticated detected at position X1) at substantially the same timing as the transmission of the authentication request (start of authentication). Specifically, the biometric control unit 14 instructs the tracking unit 15 to start tracking the person to be authenticated.
 その際、生体認証制御ユニット14は、顔画像が抽出された利用者の位置(座標;X座標、Y座標)を推定する。例えば、生体認証制御ユニット14は、画像データに含まれる顔の位置、大きさから当該顔に対応する人物の位置(X座標、Y座標)を推定する。例えば、生体認証制御ユニット14は、「ID_A:X1、Y1」のように、顔画像が抽出された利用者(利用者の被認証者ID)ごとにその位置を推定する。 At that time, the biometric authentication control unit 14 estimates the position (coordinates; X coordinate, Y coordinate) of the user whose face image was extracted. For example, the biometric authentication control unit 14 estimates the position (X coordinate, Y coordinate) of the person corresponding to the face from the position and size of the face included in the image data. For example, the biometric authentication control unit 14 estimates the position of each user whose facial image is extracted (user's ID to be authenticated), such as "ID_A: X1, Y1".
 生体認証制御ユニット14は、顔画像が抽出された被認証者の位置情報と被認証者IDを追跡ユニット15に通知する。具体的には、生体認証制御ユニット14は、被認証者の位置情報と被認証者IDを含む「追跡開始指示」を追跡ユニット15に送信する。このように、生体認証制御ユニット14は、顔画像が抽出された位置(座標)に存在する利用者(対象物)が追跡対象であることを追跡ユニット15に設定する。 The biometric authentication control unit 14 notifies the tracking unit 15 of the location information and the ID of the person to be authenticated whose face image has been extracted. Specifically, the biometrics control unit 14 transmits to the tracking unit 15 a “tracking start instruction” including the location information of the person to be authenticated and the ID of the person to be authenticated. In this way, the biometric authentication control unit 14 sets the tracking unit 15 that the user (object) present at the position (coordinates) where the face image is extracted is the tracking target.
 追跡ユニット15は、測距センサ16を用いてゲート装置10の周辺に存在する対象物を検出する。その後、追跡ユニット15は、生体認証制御ユニット14から通知された位置と実質的に同じ位置で検出された対象物(人と推定される物体)と被認証者IDを対応付けて管理する。 The tracking unit 15 uses the ranging sensor 16 to detect objects existing around the gate device 10 . After that, the tracking unit 15 associates and manages the object (an object presumed to be a person) detected at substantially the same position as the position notified from the biometrics control unit 14 and the person-to-be-authenticated ID.
 追跡ユニット15は、被認証者IDと対応付けられた人物を追跡する。図3の例では、利用者A1の位置(X1、Y1)と被認証者ID「ID_A1」が追跡ユニット15に通知され、追跡ユニット15は、利用者A1の追跡を開始する。 The tracking unit 15 tracks the person associated with the person-to-be-authenticated ID. In the example of FIG. 3, the tracking unit 15 is notified of the position (X1, Y1) of the user A1 and the ID of the person to be authenticated "ID_A1", and the tracking unit 15 starts tracking the user A1.
 このように、生体認証制御ユニット14は、所定範囲内で被認証者を検出すると、サーバ装置20に対する認証要求と実質的に同じタイミングで、追跡ユニット15に被認証者の追跡を指示する。 In this way, when the biometric authentication control unit 14 detects the person to be authenticated within a predetermined range, it instructs the tracking unit 15 to track the person to be authenticated at substantially the same timing as the authentication request to the server device 20 .
 サーバ装置20が認証要求を処理している間、被認証者(例えば、位置X1で撮影された利用者A1)はゲート装置10に向かって移動する。例えば、被認証者が位置X2の場所まで移動したタイミングで、生体認証制御ユニット14は、サーバ装置20から認証要求の応答を受信する。 While the server device 20 is processing the authentication request, the person to be authenticated (for example, the user A1 photographed at the position X1) moves toward the gate device 10. For example, the biometric authentication control unit 14 receives a response to the authentication request from the server device 20 at the timing when the person to be authenticated moves to the location X2.
 生体認証制御ユニット14は、サーバ装置20から認証結果を受信しても当該タイミングではゲート13の開閉をゲート装置10に指示しない。 Even if the biometric authentication control unit 14 receives the authentication result from the server device 20, it does not instruct the gate device 10 to open or close the gate 13 at that timing.
 被認証者は、さらにゲート装置10に近づき、その内部に進入する(被認証者は、位置X3に到達する)。追跡ユニット15は、追跡対象者がゲート装置10に進入すると、当該追跡対象者の被認証者IDを生体認証制御ユニット14に通知する。具体的には、追跡ユニット15は、ゲート装置10の内部に進入した追跡対象者の被認証者IDを含む「被認証者進入通知」を生体認証制御ユニット14に通知する。例えば、図3の例では、追跡ユニット15は、利用者A1の被認証者ID「ID_A1」を生体認証制御ユニット14に通知する。 The person to be authenticated further approaches the gate device 10 and enters its interior (the person to be authenticated reaches position X3). When a tracked person enters the gate device 10, the tracking unit 15 notifies the biometric control unit 14 of the subject ID of the tracked person. Specifically, the tracking unit 15 notifies the biometric authentication control unit 14 of a “person to be authenticated entrance notification” including the to-be-authenticated person ID of the person to be tracked who has entered the inside of the gate device 10 . For example, in the example of FIG. 3, the tracking unit 15 notifies the biometric authentication control unit 14 of the user A1's ID "ID_A1".
 生体認証制御ユニット14は、追跡ユニット15から通知された被認証者IDを記憶する。生体認証制御ユニット14は、サーバ装置20から通知された被認証者IDと追跡ユニット15から通知された被認証者IDが一致する被認証者についてゲート装置10を通行できるか否か判定する。具体的には、生体認証制御ユニット14は、追跡が完了した被認証者の認証結果が「認証成功」であれば、当該利用者はゲート装置10を通行できると判断し、その旨をゲート装置10に通知する。より具体的には、生体認証制御ユニット14は、「通行許可通知」をゲート装置10に送信する。 The biometrics control unit 14 stores the ID of the person to be authenticated notified from the tracking unit 15. The biometric authentication control unit 14 determines whether or not the person to be authenticated whose ID notified from the server device 20 matches the ID of the person to be authenticated notified from the tracking unit 15 can pass through the gate device 10 . Specifically, if the authentication result of the person to be authenticated whose tracking has been completed is "successful authentication", the biometric authentication control unit 14 determines that the user can pass through the gate device 10, and notifies the gate device of that fact. Notify 10. More specifically, the biometric authentication control unit 14 transmits a “notice of permission to pass” to the gate device 10 .
 対して、生体認証制御ユニット14は、追跡が完了した被認証者の認証結果が「認証成功」以外(認証失敗、又は認証結果が不存在)であれば、特段の対応をしない。 On the other hand, the biometrics control unit 14 does not take any particular action if the authentication result of the person to be authenticated whose tracking has been completed is other than "authentication success" (authentication failure or no authentication result).
 利用者(被認証者)は、ゲート装置10の入り口からさらに内部に進む。利用者がゲート装置10の所定位置(位置X4)まで進むと、ゲート装置10は、自装置の中間に設置された検出センサ12からの検出信号に基づき当該被認証者を検出する。 The user (person to be authenticated) proceeds further inside from the entrance of the gate device 10 . When the user advances to a predetermined position (position X4) of the gate device 10, the gate device 10 detects the person to be authenticated based on the detection signal from the detection sensor 12 installed in the middle of the device itself.
 ゲート装置10は、利用者が検出されたタイミングで、「通行許可通知」を受信していれば、ゲート13の開状態を維持して利用者のゲート通行を許可する。 If the gate device 10 receives the "passage permission notification" at the timing when the user is detected, the gate device 10 keeps the gate 13 open and permits the user to pass through the gate.
 対して、ゲート装置10は、利用者が検出されたタイミングで「通行許可通知」を受信していない場合、ゲート13を閉じて利用者の通行を制限する。 On the other hand, the gate device 10 closes the gate 13 and restricts the passage of the user if the "passage permission notification" is not received at the timing when the user is detected.
 このように、追跡ユニット15は、追跡対象として設定された被認証者がゲート装置10に進入したことを検知すると、当該進入した被認証者の被認証者IDを生体認証制御ユニット14に通知する。当該通知(プッシュ通知)に応じて、生体認証制御ユニット14は、対応する被認証者の認証結果を確認し、認証成功であれば通行を許可する。 In this way, when the tracking unit 15 detects that a person to be authenticated who is set as a tracking target has entered the gate device 10, the tracking unit 15 notifies the biometrics control unit 14 of the ID of the person to be authenticated who has entered. . In response to the notification (push notification), the biometric authentication control unit 14 confirms the authentication result of the corresponding person to be authenticated, and permits passage if the authentication is successful.
 なお、利用者の生体情報には、例えば、顔、虹彩の模様(パターン)といった個人に固有な身体的特徴から計算されるデータ(特徴量)が例示される。あるいは、利用者の生体情報は、顔画像、虹彩画像等の画像データであってもよい。利用者の生体情報は、利用者の身体的特徴を情報として含むものであればよい。第1の実施形態では、人の顔画像又は当該顔画像から生成された特徴量を生体情報として用いて説明を行う。 The user's biometric information includes, for example, data (feature amounts) calculated from physical features unique to an individual, such as a face or iris pattern (pattern). Alternatively, the user's biometric information may be image data such as a face image or an iris image. A user's biometric information should just contain a user's physical characteristic as information. In the first embodiment, a facial image of a person or a feature amount generated from the facial image is used as biometric information.
 図2等に示す構成は例示であって、システムの構成を限定する趣旨ではない。例えば、認証システムには少なくとも1台以上のゲート装置10が含まれていればよい。各ゲート装置10は同じ場所(例えば、同じ駅)に設置されていてもよいし、異なる場所に設置されていてもよい。 The configuration shown in FIG. 2, etc. is an example and is not intended to limit the configuration of the system. For example, the authentication system may include at least one or more gate devices 10 . Each gate device 10 may be installed in the same place (for example, the same station), or may be installed in different places.
 続いて、第1の実施形態に係る認証システムに含まれる生体認証制御ユニット14、追跡ユニット15、ゲート装置10及びサーバ装置20の詳細について説明する。 Next, details of the biometric authentication control unit 14, tracking unit 15, gate device 10, and server device 20 included in the authentication system according to the first embodiment will be described.
[生体認証制御ユニット]
 図4は、第1の実施形態に係る生体認証制御ユニット14の処理構成(処理モジュール)の一例を示す図である。図4を参照すると、生体認証制御ユニット14は、通信制御部201と、被認証者検出部202と、認証要求部203と、追跡制御部204と、通行許可通知部205と、テーブル管理部206と、メッセージ出力部207、記憶部208と、を含む。
[Biometric authentication control unit]
FIG. 4 is a diagram showing an example of a processing configuration (processing modules) of the biometric authentication control unit 14 according to the first embodiment. Referring to FIG. 4, the biometric authentication control unit 14 includes a communication control unit 201, a person-to-be-authenticated detection unit 202, an authentication request unit 203, a tracking control unit 204, a passage permission notification unit 205, and a table management unit 206. , a message output unit 207 and a storage unit 208 .
 通信制御部201は、他の装置との間の通信を制御する手段である。例えば、通信制御部201は、サーバ装置20からデータ(パケット)を受信する。また、通信制御部201は、サーバ装置20に向けてデータを送信する。通信制御部201は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部201は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部201を介して他の装置とデータの送受信を行う。通信制御部201は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 201 is means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 20 . Also, the communication control unit 201 transmits data to the server device 20 . The communication control unit 201 transfers data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 201 . The communication control unit 201 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 被認証者検出部202は、被認証者を検出する手段である。被認証者検出部202は、ゲート装置10から所定範囲内の人物を被認証者として検出する。より具体的には、被認証者検出部202は、ゲート装置10から所定範囲内(例えば、位置X1よりもゲート装置10に近い位置;X1からX3までの範囲内)に人が存在するか否か検出する。 The authenticated person detection unit 202 is means for detecting an authenticated person. The person-to-be-authenticated detection unit 202 detects a person within a predetermined range from the gate device 10 as a person to be authenticated. More specifically, the person-to-be-authenticated detection unit 202 determines whether a person exists within a predetermined range from the gate device 10 (for example, a position closer to the gate device 10 than the position X1; within the range from X1 to X3). to detect
 なお、以降の説明において、理解の容易のため、被認証者検出部202が被認証者を検出する範囲をX軸方向で規定しているが、実際にはY軸方向の範囲(例えば、Y0~Y2の範囲)も考慮される。 In the following description, for ease of understanding, the range in which the person-to-be-authenticated detection unit 202 detects the person to be authenticated is defined in the X-axis direction. ~ Y2) are also considered.
 被認証者検出部202は、定期的又は所定のタイミングでカメラ11から画像データを取得する。被認証者検出部202は、取得した画像データから顔画像の抽出を試みる。 The person-to-be-authenticated detection unit 202 acquires image data from the camera 11 periodically or at a predetermined timing. The person-to-be-authenticated detection unit 202 attempts to extract a face image from the acquired image data.
 被認証者検出部202による顔画像の抽出処理には、既存の技術を用いることができるので詳細な説明を省略する。例えば、被認証者検出部202は、CNN(Convolutional Neural Network)により学習された学習モデルを用いて、画像データの中から顔画像(顔領域)を抽出してもよい。あるいは、被認証者検出部202は、テンプレートマッチング等の手法を用いて顔画像を抽出してもよい。 Since existing technology can be used for face image extraction processing by the person-to-be-authenticated detection unit 202, detailed description thereof will be omitted. For example, the person-to-be-authenticated detection unit 202 may extract a face image (face region) from image data using a learning model learned by a CNN (Convolutional Neural Network). Alternatively, the person-to-be-authenticated detection unit 202 may extract a face image using a technique such as template matching.
 顔画像が抽出されると、被認証者検出部202は、顔画像から目間距離を計算する。具体的には、被認証者検出部202は、顔画像から左右の目を抽出し、当該抽出された両目を結ぶ直線の長さ(画素数)を計算する。 When the face image is extracted, the person-to-be-authenticated detection unit 202 calculates the inter-eye distance from the face image. Specifically, the person-to-be-authenticated detection unit 202 extracts left and right eyes from the face image, and calculates the length (the number of pixels) of the straight line connecting the extracted eyes.
 被認証者検出部202は、計算した目間距離に対して閾値処理を実行し、その結果に応じて被認証者が上記所定範囲内に存在するか否か判定する。具体的には、目間距離が閾値よりも長ければ、被認証者検出部202は、所定範囲内にて被認証者を検出したと判定する。目間距離が閾値以下であれば、被認証者検出部202は、当該所定範囲内には被認証者は存在しないと判定する。 The to-be-authenticated person detection unit 202 performs threshold processing on the calculated inter-eye distance, and determines whether or not the to-be-authenticated person exists within the predetermined range according to the result. Specifically, if the distance between the eyes is longer than the threshold, the person-to-be-authenticated detection unit 202 determines that the person-to-be-authenticated has been detected within the predetermined range. If the distance between the eyes is equal to or less than the threshold, the person-to-be-authenticated detection unit 202 determines that the person-to-be-authenticated does not exist within the predetermined range.
 所定範囲内に被認証者を検出すると、被認証者検出部202は、被認証者情報テーブルにエントリを追加する。被認証者検出部202は、被認証者を識別する被認証者IDを採番し、当該被認証者IDを新たなエントリに記憶する。また、被認証者検出部202は、被認証者を被認証者情報テーブルに登録した時刻(新たなエントリを追加した時刻)も併せて被認証者情報テーブルに記憶する。 When an authenticated person is detected within a predetermined range, the authenticated person detection unit 202 adds an entry to the authenticated person information table. The to-be-authenticated person detection unit 202 numbers the to-be-authenticated person ID for identifying the to-be-authenticated person, and stores the ID of the to-be-authenticated person in a new entry. In addition, the authentication-subjected person detection unit 202 also stores the time when the authentication-subjected person is registered in the authentication-subjected person information table (the time when a new entry is added) in the authentication-subjected person information table.
 図5は、第1の実施形態に係る被認証者情報テーブルの一例を示す図である。被認証者情報テーブルは生体認証制御ユニット14のメモリ上に構築される。図5の最下段に示すように、被認証者検出部202は、例えば、位置X1において人を検出すると、被認証者情報テーブルにエントリを追加し、当該検出された人物を被認証者に設定する。なお、エントリが追加されたタイミングでは、認証ステータスフィールド、追跡ステータスフィールドには何も設定されない。 FIG. 5 is a diagram showing an example of an authentication-subjected person information table according to the first embodiment. The authenticated person information table is constructed on the memory of the biometric authentication control unit 14 . As shown in the bottom part of FIG. 5, for example, when the person-to-be-authenticated detection unit 202 detects a person at the position X1, it adds an entry to the person-to-be-authenticated information table and sets the detected person as the person to be authenticated. do. Note that nothing is set in the authentication status field and the tracking status field when the entry is added.
 認証ステータスフィールドは、被認証者の生体認証に関する状況を管理するためのフィールドである。追跡ステータスフィールドは、被認証者の追跡状況を管理するためのフィールドである。 The authentication status field is a field for managing the biometric authentication status of the authenticated person. The tracking status field is a field for managing the tracking status of the person to be authenticated.
 なお、図5に示す被認証者情報テーブルは例示であって、記憶する項目等を限定する趣旨ではない。例えば、被認証者の生体情報(顔画像、特徴量)が被認証者情報テーブルに登録されていてもよい。被認証者検出部202は、当該生体情報を用いて既に被認証者として登録されている利用者が再び被認証者情報テーブルに登録されることを防止してもよい。被認証者検出部202は、画像データから抽出された顔画像(特徴量)と被認証者情報テーブルに登録された顔画像(特徴量)が実質的に一致する場合には、当該画像データから抽出された顔画像に対応する人物を被認証者に設定しない。 Note that the authentication-subjected person information table shown in FIG. 5 is an example, and is not meant to limit the items to be stored. For example, the biometric information (face image, feature amount) of the person to be authenticated may be registered in the person-to-be-authenticated information table. The authentication-subject detection unit 202 may prevent a user who has already been registered as an authentication-subject from being registered again in the authentication-subject information table using the biometric information. If the face image (feature amount) extracted from the image data substantially matches the face image (feature amount) registered in the authentication-subjected person information table, the authentication-subjected person detection unit 202 detects the face image (feature amount) from the image data. The person corresponding to the extracted face image is not set as the person to be authenticated.
 被認証者の登録が終了すると、被認証者検出部202は、被認証者IDと被認証者検出時の画像データ(カメラ11から取得した画像データ、顔画像)を、認証要求部203に引き渡す。 When the registration of the person to be authenticated is completed, the person-to-be-authenticated detection unit 202 passes the ID of the person-to-be-authenticated and the image data (image data and face image obtained from the camera 11) at the time of detection of the person-to-be-authenticated to the authentication requesting unit 203. .
 さらに、被認証者の登録が終了すると、被認証者検出部202は、顔画像が抽出された利用者の位置(座標;X座標、Y座標)を推定する。例えば、被認証者検出部202は、画像データに含まれる顔の位置、大きさから当該顔に対応する人物の位置(X座標、Y座標)を推定する。 Furthermore, when the registration of the person to be authenticated is completed, the person-to-be-authenticated detection unit 202 estimates the position (coordinates; X coordinate, Y coordinate) of the user whose face image is extracted. For example, the person-to-be-authenticated detection unit 202 estimates the position (X coordinate, Y coordinate) of the person corresponding to the face from the position and size of the face included in the image data.
 あるいは、被認証者検出部202は、学習モデルを使って当該位置を推定してもよい。具体的には、被認証者検出部202は、画像にラベル(X座標、Y座標)が付与された教師データを用いた機械学習により生成された学習モデルを使用して位置を推定してもよい。当該学習モデルの生成には、サポートベクタマシン、ブースティングやニューラルネットワーク等の任意のアルゴリズムを用いることができる。なお、上記サポートベクタマシン等のアルゴリズムは公知の技術を使用することができるので、その説明を省略する。 Alternatively, the person-to-be-authenticated detection unit 202 may estimate the position using a learning model. Specifically, the person-to-be-authenticated detection unit 202 estimates a position using a learning model generated by machine learning using teacher data in which labels (X coordinates, Y coordinates) are assigned to images. good. Arbitrary algorithms, such as a support vector machine, a boosting, and a neural network, can be used for the production|generation of the said learning model. Since well-known techniques can be used for algorithms such as the support vector machine, the description thereof is omitted.
 被認証者検出部202は、例えば、「ID_A:X1、Y1」のように、顔画像が抽出された利用者(利用者の被認証者ID)ごとにその位置を推定する。被認証者検出部202は、被認証者IDと利用者の位置(X座標、Y座標)を追跡制御部204に引き渡す。 The to-be-authenticated person detection unit 202 estimates the position of each user (user's to-be-authenticated person ID) whose face image is extracted, for example, "ID_A: X1, Y1". The to-be-authenticated person detection unit 202 passes the to-be-authenticated person ID and the user's position (X coordinate, Y coordinate) to the tracking control unit 204 .
 認証要求部203は、被認証者検出部202により検出された被認証者の認証をサーバ装置20に要求する手段である。被認証者の顔画像を取得すると、認証要求部203は、取得した顔画像から特徴量(複数の特徴量からなる特徴ベクトル)を生成する。 The authentication request unit 203 is means for requesting the server device 20 to authenticate the person to be authenticated detected by the person-to-be-authenticated detection unit 202 . After acquiring the face image of the person to be authenticated, the authentication requesting unit 203 generates a feature amount (a feature vector composed of a plurality of feature amounts) from the acquired face image.
 特徴量の生成処理に関しては既存の技術を用いることができるので、その詳細な説明を省略する。例えば、認証要求部203は、顔画像から目、鼻、口等を特徴点として抽出する。その後、認証要求部203は、特徴点それぞれの位置や各特徴点間の距離を特徴量として計算し、複数の特徴量からなる特徴ベクトル(顔画像を特徴づけるベクトル情報)を生成する。 Existing technology can be used for the feature generation process, so a detailed description thereof will be omitted. For example, the authentication requesting unit 203 extracts the eyes, nose, mouth, etc. from the face image as feature points. After that, the authentication requesting unit 203 calculates the position of each feature point and the distance between each feature point as a feature amount, and generates a feature vector (vector information that characterizes the face image) composed of a plurality of feature amounts.
 認証要求部203は、当該生成された特徴量(生体情報)、被認証者ID及びゲートIDを含む認証要求を生成し、サーバ装置20に送信する(図6参照)。ゲートIDは、ゲート装置10を識別するための識別情報である。ゲートIDには、ゲート装置10のMAC(Media Access Control)アドレスやIP(Internet Protocol)アドレスを用いることができる。あるいは、ゲートIDは、システム固有の識別情報(識別ID)であってもよい。サーバ装置20側にも識別IDをマスタとして保持することにより、送信した認証要求が許可されたゲート装置10からのものであることが判定できる。 The authentication requesting unit 203 generates an authentication request including the generated feature amount (biometric information), the ID of the person to be authenticated, and the gate ID, and transmits it to the server device 20 (see FIG. 6). The gate ID is identification information for identifying the gate device 10 . The MAC (Media Access Control) address or IP (Internet Protocol) address of the gate device 10 can be used as the gate ID. Alternatively, the gate ID may be system-specific identification information (identification ID). By holding the identification ID as a master also on the server device 20 side, it can be determined that the transmitted authentication request is from the permitted gate device 10 .
 認証要求をサーバ装置20に送信すると、認証要求部203は、被認証者情報テーブルの該当するエントリ(被認証者IDが同じエントリ)の認証ステータスフィールドに「認証中」を設定する(図5の下から2番目のエントリ参照)。 When the authentication request is transmitted to the server device 20, the authentication requesting unit 203 sets "authenticating" in the authentication status field of the corresponding entry (entries with the same authentication-subject ID) in the authentication-subject information table (see FIG. 5). See the second entry from the bottom).
 認証要求部203は、認証要求に対するサーバ装置20からの応答(認証結果を含む応答)を受信する。認証要求部203は、受信した応答から被認証者IDを抽出する。認証要求部203は、抽出した被認証者IDに基づいて被認証者を特定し、認証結果を被認証者情報テーブルの対応するエントリに登録する(図5の上から1番目、2番目のエントリ参照)。このように、認証要求部203は、サーバ装置20から生体認証の結果を受信すると、受信した生体認証の結果を被認証者検出部202により追加されたエントリの認証ステータスフィールドに設定する。 The authentication requesting unit 203 receives a response (including the authentication result) from the server device 20 to the authentication request. The authentication requesting unit 203 extracts the ID of the person to be authenticated from the received response. The authentication request unit 203 identifies the person to be authenticated based on the extracted person-to-be-authenticated ID, and registers the authentication result in the corresponding entry of the person-to-be-authenticated information table (the first and second entries from the top in FIG. 5). reference). In this way, upon receiving the biometric authentication result from the server device 20 , the authentication requesting unit 203 sets the received biometric authentication result in the authentication status field of the entry added by the authentication-subject detecting unit 202 .
 追跡制御部204は、被認証者検出部202により検出された被認証者の追跡を制御する手段である。追跡制御部204は、測距センサ16を用いて追跡対象者を追跡する追跡ユニット15に対し、被認証者の位置情報を含む追跡開始指示を送信する。追跡制御部204は、追跡ユニット15から追跡結果を取得する。 The tracking control unit 204 is means for controlling tracking of the person-to-be-authenticated detected by the person-to-be-authenticated detection unit 202 . The tracking control unit 204 transmits a tracking start instruction including the position information of the person to be authenticated to the tracking unit 15 that tracks the person to be tracked using the distance measuring sensor 16 . The tracking control section 204 acquires tracking results from the tracking unit 15 .
 具体的には、追跡制御部204は、被認証者検出部202から、被認証者IDと被認証者の位置情報(X座標、Y座標)を取得する。その後、追跡制御部204は、被認証者の位置情報(推定された被認証者の位置)と被認証者IDを含む「追跡開始指示」を追跡ユニット15に送信する。 Specifically, the tracking control unit 204 acquires the authenticated person ID and the authenticated person's location information (X coordinate, Y coordinate) from the authenticated person detection unit 202 . After that, the tracking control section 204 transmits a “tracking start instruction” including the location information of the person to be authenticated (estimated location of the person to be authenticated) and the ID of the person to be authenticated to the tracking unit 15 .
 追跡制御部204は、追跡開始指示を送信した被認証者の追跡ステータスを「追跡中」に設定し、被認証者情報テーブルを更新する(図5の下から3番目のエントリ参照)。 The tracking control unit 204 sets the tracking status of the authenticated person who sent the tracking start instruction to "tracking" and updates the authenticated person information table (see the third entry from the bottom in FIG. 5).
 追跡制御部204は、追跡ユニット15から「被認証者進入通知」を受信する。当該通知を受信したことに応じて、追跡制御部204は、被認証者の追跡が完了したと判断する。追跡制御部204は、当該通知に含まれる被認証者IDを用いて対応する被認証者の追跡ステータスを更新する。具体的には、追跡制御部204は、被認証者情報テーブルの対応するエントリの追跡ステータスフィールドに「追跡完了」を設定する(図5の最上段のエントリ参照)。 The tracking control unit 204 receives the "notification of entry of the person to be authenticated" from the tracking unit 15. Upon receiving the notification, the tracking control unit 204 determines that tracking of the person to be authenticated has been completed. The tracking control unit 204 updates the tracking status of the corresponding authenticated person using the authenticated person ID included in the notification. Specifically, the tracking control unit 204 sets "tracking completed" in the tracking status field of the corresponding entry in the authenticated person information table (see the topmost entry in FIG. 5).
 このように、追跡制御部204は、追跡対象者がゲート装置10に進入したことを示す被認証者進入通知を追跡ユニット15から受信する。追跡制御部204は、追跡ユニット15から取得した追跡結果(被認証者の追跡が完了した事実)を被認証者検出部202により追加されたエントリの追跡ステータスフィールドに設定する。 In this way, the tracking control unit 204 receives from the tracking unit 15 an authentication-subjected person entry notification indicating that the tracked person has entered the gate device 10 . The tracking control unit 204 sets the tracking result (fact that tracking of the person to be authenticated has been completed) obtained from the tracking unit 15 in the tracking status field of the entry added by the person to be authenticated detection unit 202 .
 追跡制御部204は、追跡ユニット15からの被認証者進入通知を被認証者情報テーブルに反映すると、その旨を通行許可通知部205に通知する。 When the tracking control unit 204 reflects the subject entry notification from the tracking unit 15 in the authentication subject information table, the tracking control unit 204 notifies the passage permission notification unit 205 to that effect.
 通行許可通知部205は、被認証者(利用者)がゲート装置10を通行することを許可するか否かをゲート装置10に通知する手段である。通行許可通知部205は、サーバ装置20による被認証者の生体認証の結果と、追跡ユニット15による被認証者の追跡結果と、に基づいて被認証者がゲート装置10を通行できるか否か判定し、判定結果をゲート装置10に通知する。 The passage permission notification unit 205 is means for notifying the gate device 10 whether or not the person to be authenticated (user) is permitted to pass through the gate device 10 . The passage permission notification unit 205 determines whether or not the person to be authenticated can pass through the gate device 10 based on the result of biometric authentication of the person to be authenticated by the server device 20 and the tracking result of the person to be authenticated by the tracking unit 15. and notifies the gate device 10 of the determination result.
 通行許可通知部205は、被認証者の追跡が終了したタイミング(追跡制御部204から追跡が完了した旨を取得したタイミング)で、被認証者情報テーブルにアクセスする。 The pass permission notification unit 205 accesses the authenticated person information table at the timing when the tracking of the authenticated person is completed (when the tracking control unit 204 acquires the fact that the tracking has been completed).
 通行許可通知部205は、被認証者情報テーブルに含まれる各エントリの認証ステータスフィールドと追跡ステータスフィールドを確認する。通行許可通知部205は、認証ステータスフィールドの設定値が「認証成功」、且つ、追跡ステータスフィールドの設定値が「追跡完了」のエントリが存在すれば、被認証者がゲート装置10を通行することを許可する。具体的には、上記2つの条件が満たすエントリが存在すれば、通行許可通知部205は、利用者がゲート装置10を通行できることをゲート装置10に通知する。通行許可通知部205は、「通行許可通知」をゲート装置10に送信する。 The passage permission notification unit 205 checks the authentication status field and tracking status field of each entry included in the authentication subject information table. If there is an entry in which the set value of the authentication status field is "authentication successful" and the set value of the tracking status field is "tracking completed", the passage permission notification unit 205 allows the person to be authenticated to pass through the gate device 10. allow Specifically, if there is an entry that satisfies the above two conditions, the passage permission notification unit 205 notifies the gate device 10 that the user can pass through the gate device 10 . The passage permission notification unit 205 transmits a “passage permission notification” to the gate device 10 .
 図5の例では、最上段のエントリが上記2つの条件を満たすので、通行許可通知部205は、「通行許可通知」をゲート装置10に送信する。 In the example of FIG. 5, the topmost entry satisfies the above two conditions, so the passage permission notification unit 205 transmits a "passage permission notice" to the gate device 10.
 通行許可通知部205は、利用者(被認証者)のゲート通過を許可した場合には、その根拠となったエントリを削除する。図5の例では、通行許可通知部205は、最上段のエントリを削除する。 When the passage permission notification unit 205 permits the user (person to be authenticated) to pass through the gate, it deletes the entry that serves as the basis for the permission. In the example of FIG. 5, the passage permission notification unit 205 deletes the topmost entry.
 このように、通行許可通知部205は、被認証者進入通知が追跡制御部204により受信されたことに応じて、被認証者がゲート装置10を通行できるか否か判定する。即ち、生体認証制御ユニット14は、被認証者進入通知の受信を契機とし、サーバ装置20による認証結果に基づいて被認証者がゲート装置10を通行できるか否か判定する。 In this way, the passage permission notification unit 205 determines whether or not the person to be authenticated can pass through the gate device 10 in response to the receipt of the entry notification of the person to be authenticated by the tracking control unit 204 . That is, the biometrics control unit 14 determines whether or not the person to be authenticated can pass through the gate device 10 based on the authentication result by the server device 20 when receiving the notification of the entry of the person to be authenticated.
 なお、通行許可通知部205は、ゲート装置10から「ゲート閉通知」を受信することがある。通行許可通知部205は、当該通知を受信すると、所定期間、被認証者情報テーブルにアクセスを続け、上記2つの条件を満たすエントリが現れるか否か(存在するか否か)を確認する。当該所定期間の間に上記2つの条件を満たすエントリが出現すれば、通行許可通知部205は、被認証者(利用者)のゲート通過を許可する。具体的には、上記2つの条件を満たすエントリが出現すれば、通行許可通知部205は、「通行許可通知」をゲート装置10に送信する。 Note that the passage permission notification unit 205 may receive a "gate closed notification" from the gate device 10. Upon receiving the notification, the passage permission notification unit 205 continues to access the authentication subject information table for a predetermined period of time, and checks whether an entry satisfying the above two conditions appears (exists). If an entry that satisfies the above two conditions appears during the predetermined period, the passage permission notification unit 205 permits the person to be authenticated (user) to pass through the gate. Specifically, when an entry that satisfies the above two conditions appears, the passage permission notifying unit 205 transmits a “passage permission notification” to the gate device 10 .
 例えば、ゲート装置10とサーバ装置20の間のネットワーク環境等に起因して、サーバ装置20からの認証結果(認証成功)が被認証者情報テーブルに反映されることが遅れた場合に、上記現象が起こり得る。あるいは、被認証者がゲート装置10を駆け抜けようとした場合にも、上記現象が起こり得る。 For example, when the authentication result (authentication success) from the server device 20 is delayed to be reflected in the authenticated person information table due to the network environment between the gate device 10 and the server device 20, the above phenomenon occurs. can happen. Alternatively, the above phenomenon may occur when the person to be authenticated tries to run through the gate device 10 .
 所定期間経過しても上記2つの条件を満たすエントリが現れない場合には、通行許可通知部205は、駅員(駅員が使用する端末)に問題発生を通知する。あるいは、通行許可通知部205は、メッセージ出力部207を介して被認証者に駅員のもとに向かうように促してもよい。 If no entry that satisfies the above two conditions appears after a predetermined period of time, the passage permission notification unit 205 notifies the station staff (the terminal used by the station staff) that a problem has occurred. Alternatively, the pass permission notification unit 205 may prompt the person to be authenticated to go to the station staff via the message output unit 207 .
 テーブル管理部206は、被認証者情報テーブルを管理する手段である。テーブル管理部206は、定期的又は所定のタイミングで被認証者情報テーブルにアクセスし、不要となったエントリを削除する。 The table management unit 206 is means for managing the authenticated person information table. The table management unit 206 accesses the authentication-subjected person information table periodically or at a predetermined timing, and deletes unnecessary entries.
 テーブル管理部206は、各エントリの登録時刻フィールドを確認し、エントリが被認証者情報テーブルに追加されてから所定期間経過しているエントリを削除する。即ち、テーブル管理部206は、エントリの登録から所定期間経過しても上記2つの条件(認証成功、追跡完了)を満たさないエントリを削除する。 The table management unit 206 checks the registration time field of each entry, and deletes entries for which a predetermined period has passed since the entry was added to the authentication-subjected person information table. That is, the table management unit 206 deletes an entry that does not satisfy the above two conditions (authentication success, tracking completion) even after a predetermined period of time has passed since the entry was registered.
 このようなテーブル管理部206の動作により、被認証者として検出された利用者がゲート装置10に向かわず他に移動した場合であっても、そのような被認証者のエントリが削除される。 With this operation of the table management unit 206, even if the user detected as the person to be authenticated moves away from the gate device 10 without going to the gate device 10, the entry of such person to be authenticated is deleted.
 エントリを削除した場合には、テーブル管理部206は、その旨をサーバ装置20や追跡ユニット15に通知してもよい。テーブル管理部206は、サーバ装置20に対しては被認証者IDを伝え、対応する被認証者の認証をキャンセルしてもよい。また、テーブル管理部206は、追跡ユニット15に対しても被認証者IDを伝え、当該被認証者IDに対応する追跡対象者を追跡の対象から外すように指示してもよい。 When the entry is deleted, the table management unit 206 may notify the server device 20 and the tracking unit 15 to that effect. The table management unit 206 may transmit the ID of the person to be authenticated to the server device 20 and cancel the authentication of the corresponding person to be authenticated. The table management section 206 may also transmit the ID of the person to be authenticated to the tracking unit 15 and instruct it to exclude the person to be tracked corresponding to the ID of the person to be authenticated from being tracked.
 メッセージ出力部207は、利用者に通知するメッセージ等を出力する手段である。メッセージ出力部207は、ディスプレイ(図示せず)やスピーカー(図示せず)等を用いて必要なメッセージを利用者に通知する。例えば、ゲート装置10のゲート制御部403が利用者の通行を拒否した場合には、メッセージ出力部207は、その旨と共に対応策に関するメッセージ(例えば、駅員に連絡)を出力する。 The message output unit 207 is means for outputting a message or the like to be notified to the user. The message output unit 207 notifies the user of necessary messages using a display (not shown), a speaker (not shown), or the like. For example, when the gate control unit 403 of the gate device 10 refuses the user to pass, the message output unit 207 outputs a message to that effect and a countermeasure (for example, contact the station staff).
 記憶部208は、生体認証制御ユニット14の動作に必要な情報を記憶する手段である。 The storage unit 208 is means for storing information necessary for the operation of the biometrics control unit 14 .
[追跡ユニット]
 図7は、第1の実施形態に係る追跡ユニット15の処理構成(処理モジュール)の一例を示す図である。図7参照すると、追跡ユニット15は、通信制御部301と、追跡部302と、記憶部303と、を含む。
[Tracking unit]
FIG. 7 is a diagram showing an example of a processing configuration (processing modules) of the tracking unit 15 according to the first embodiment. Referring to FIG. 7 , tracking unit 15 includes communication control section 301 , tracking section 302 , and storage section 303 .
 通信制御部301は、他の装置(デバイス)との間の通信を制御する手段である。例えば、通信制御部301は、生体認証制御ユニット14からデータ(パケット)を受信する。また、通信制御部301は、生体認証制御ユニット14に向けてデータを送信する。通信制御部301は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部301は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部301を介して他の装置とデータの送受信を行う。通信制御部301は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 301 is means for controlling communication with other apparatuses (devices). For example, the communication control section 301 receives data (packets) from the biometric authentication control unit 14 . The communication control section 301 also transmits data to the biometric authentication control unit 14 . The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301 . The communication control unit 301 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 追跡部302は、被認証者の追跡を行う手段である。追跡部302は、生体認証制御ユニット14から「追跡開始指示」を受信する。追跡部302は、測距センサ16を制御し、ゲート装置10の周囲(とりわけ、ゲート装置10の前方)を隈なくスキャンする。追跡部302は、当該スキャンによりゲート装置10の周囲に存在する物体を検出する。 The tracking unit 302 is means for tracking the person to be authenticated. The tracking unit 302 receives a “tracking start instruction” from the biometric control unit 14 . The tracking unit 302 controls the distance measuring sensor 16 and scans all around the gate device 10 (especially in front of the gate device 10). The tracking unit 302 detects objects existing around the gate device 10 through the scanning.
 測距センサ16のスキャンによって、追跡部302は、無数の点の集合(点群)を取得する。追跡部302は、当該得られた点群に含まれる各点を物体ごとに振り分けるクラスタリングを行うことで、クラスタ(物体を構成する点の集合)を得る。追跡部302は、得られたクラスタに意味づけ(例えば、床、壁、人)を行うことで物体を検出する。例えば、追跡部302は、機械学習による画像認識(レーザが物体に反射することで得られるレーザ画像に対する画像認識)によって物体(人など)を検出する。 Through the scanning of the ranging sensor 16, the tracking unit 302 acquires a countless set of points (point group). The tracking unit 302 obtains a cluster (a set of points forming an object) by clustering the points included in the obtained point group for each object. The tracking unit 302 detects objects by assigning meanings (for example, floors, walls, people) to the obtained clusters. For example, the tracking unit 302 detects an object (person, etc.) by image recognition based on machine learning (image recognition of a laser image obtained by reflecting a laser off an object).
 なお、測距センサ16を用いた物体検出には、自動車やロボットの制御における人物検出技術を用いることができるので、より詳細な説明を省略する。例えば、追跡部302は、下記の参考文献1に開示された技術を用いて物体検出を行う。
<参考文献1>
特開2021-099698号公報
For object detection using the distance measuring sensor 16, a human detection technique used in controlling automobiles and robots can be used, so a more detailed description will be omitted. For example, the tracking unit 302 performs object detection using the technique disclosed in Reference 1 below.
<Reference 1>
JP 2021-099698 A
 追跡部302は、少なくとも1人以上の人物を検出すると、当該検出された人の位置(座標)を計算する。例えば、図3に示すように、利用者A1が位置(X1、Y1)に立ち利用者A2が位置(X0、Y0)に立っている状況で、スキャンが行われると、図8Aに示すような位置関係で2人の人物が検出される。2人の人物が検出されると、追跡部302は、それぞれの人物の中心位置を当該人物の位置(X座標、Y座標)として計算する。 When the tracking unit 302 detects at least one person, it calculates the position (coordinates) of the detected person. For example, as shown in FIG. 3, when scanning is performed in a situation where user A1 stands at position (X1, Y1) and user A2 stands at position (X0, Y0), as shown in FIG. 8A Two persons are detected in the positional relationship. When two persons are detected, the tracking unit 302 calculates the center position of each person as the position (X coordinate, Y coordinate) of the person.
 なお、理解の容易のため、生体認証制御ユニット14の座標系と追跡ユニット15の座標系を同じものとして本願開示の説明を行うが、2つの座標系が異なる場合には、いずれかのユニットで必要な座標変換を行えばよい。 For ease of understanding, the disclosure of the present application will be described with the coordinate system of the biometric authentication control unit 14 and the coordinate system of the tracking unit 15 being the same. Any necessary coordinate transformation can be performed.
 追跡部302は、追跡開始指示に含まれる位置情報と実質的に同じ場所に存在する人物を追跡対象に設定する。図3及び図8Aの例では、追跡部302は、利用者A1を追跡対象に設定する。 The tracking unit 302 sets a person who exists substantially at the same location as the position information included in the tracking start instruction as a tracking target. In the examples of FIGS. 3 and 8A, the tracking unit 302 sets user A1 as a tracking target.
 追跡対象が設定されると、追跡部302は、当該追跡対象の位置と被認証者IDを対応付けて管理する。例えば、図8Aの例では、利用者A1が追跡対象に設定されるので、追跡部302は、(ID_A1;X1、Y1)のような対応付けを行う。 When a tracked target is set, the tracking unit 302 associates and manages the position of the tracked target and the ID of the person to be authenticated. For example, in the example of FIG. 8A, the user A1 is set as a tracking target, so the tracking unit 302 makes a correspondence such as (ID_A1; X1, Y1).
 追跡部302は、定期的又は所定のタイミングで測距センサ16を制御し、物体の検出を行う。例えば、利用者A1が図3の位置(X2、Y1)に移動したタイミングで物体検出が行われると、追跡部302は、図8Bに示すような位置関係で2人の人物を検出する。 The tracking unit 302 controls the distance measuring sensor 16 periodically or at a predetermined timing to detect an object. For example, when object detection is performed at the timing when user A1 moves to position (X2, Y1) in FIG. 3, tracking unit 302 detects two persons in a positional relationship as shown in FIG. 8B.
 追跡部302は、直前のスキャンにより得られた人物の形状と現スキャンによって得られた人物の形状を比較することで、現スキャンにより検出された人物のなかから追跡対象を特定する。追跡部302は、特定された追跡対象の位置(X座標、Y座標)を更新する。上記の例では、追跡対象者である利用者A1の位置が(X2、Y1)に更新される。 The tracking unit 302 identifies the tracking target from among the people detected by the current scan by comparing the shape of the person obtained by the previous scan with the shape of the person obtained by the current scan. The tracking unit 302 updates the identified position (X coordinate, Y coordinate) of the tracked object. In the above example, the position of the tracked user A1 is updated to (X2, Y1).
 追跡部302は、更新された追跡対象の位置を確認し、当該追跡対象がゲート装置10の内部に進入しているか否か判定する。例えば、図3の例では、追跡部302は、利用者A1のX座標が位置X3よりもゲート装置10寄りであれば、当該利用者A1はゲート装置10の内部に進入したと判定する。追跡部302は、利用者A1のX座標が位置X3よりもゲート装置10から離れていれば、当該利用者A1はゲート装置10の内部に進入していないと判定する。 The tracking unit 302 confirms the updated position of the tracked object and determines whether the tracked object has entered the inside of the gate device 10 . For example, in the example of FIG. 3, the tracking unit 302 determines that the user A1 has entered the gate device 10 if the X coordinate of the user A1 is closer to the gate device 10 than the position X3. The tracking unit 302 determines that the user A1 has not entered the gate device 10 if the X coordinate of the user A1 is farther from the gate device 10 than the position X3.
 追跡部302は、追跡対象者がゲート装置10の内部に進入したと判定した場合、当該追跡対象者の被認証者IDを含む「被認証者進入通知」を生体認証制御ユニット14に送信する。即ち、追跡部302は、追跡対象者がゲート装置10に進入したことを示す被認証者進入通知を生体認証制御ユニット14に送信する。 When the tracking unit 302 determines that the tracked person has entered the inside of the gate device 10, the tracking unit 302 transmits to the biometrics control unit 14 a "person to be authenticated entrance notification" including the ID of the person to be tracked. In other words, the tracking unit 302 transmits to the biometric authentication control unit 14 a notification of entry of the person to be authenticated indicating that the person to be tracked has entered the gate device 10 .
 このように、追跡ユニット15(追跡部302)は、追跡対象者の位置と被認証者IDを対応付けて管理し、追跡対象者がゲート装置10に進入したことに応じて追跡を完了する。追跡部302は、当該追跡を完了した追跡対象者の被認証者IDを生体認証制御ユニット14に通知する。 In this way, the tracking unit 15 (tracking unit 302) manages the position of the tracked person in association with the ID of the person to be authenticated, and completes tracking when the tracked person enters the gate device 10. The tracking unit 302 notifies the biometric authentication control unit 14 of the subject ID of the person to be tracked who has completed the tracking.
 なお、追跡部302は、追跡を開始してから所定時間経過しても追跡完了とならない追跡対象者の情報(被認証者IDと位置)を削除してもよい。あるいは、追跡部302は、追跡対象者が所定範囲から外れた場合(例えば、追跡対象者がゲート装置10に向かわず他の場所に向かった場合)にも、当該追跡対象者の情報を削除してもよい。 It should be noted that the tracking unit 302 may delete the information (authenticated person ID and location) of the person to be tracked who has not completed tracking even after a predetermined time has elapsed since the start of tracking. Alternatively, the tracking unit 302 also deletes the information of the tracked person when the tracked person leaves the predetermined range (for example, when the tracked person does not go to the gate device 10 but heads to another place). may
 記憶部303は、追跡ユニット15の動作に必要な情報を記憶する手段である。 The storage unit 303 is means for storing information necessary for the operation of the tracking unit 15.
[ゲート装置]
 図9は、第1の実施形態に係るゲート装置10の処理構成(処理モジュール)の一例を示す図である。図9を参照すると、ゲート装置10は、通信制御部401と、進入者検出部402と、ゲート制御部403と、記憶部404と、を備える。
[Gate device]
FIG. 9 is a diagram showing an example of a processing configuration (processing modules) of the gate device 10 according to the first embodiment. Referring to FIG. 9 , the gate device 10 includes a communication control section 401 , an intruder detection section 402 , a gate control section 403 and a storage section 404 .
 通信制御部401は、他の装置との間の通信を制御する手段である。例えば、通信制御部401は、生体認証制御ユニット14からデータ(パケット)を受信する。また、通信制御部401は、生体認証制御ユニット14に向けてデータを送信する。通信制御部401は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部401は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部401を介して他の装置とデータの送受信を行う。通信制御部401は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 401 is means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the biometric authentication control unit 14 . Also, the communication control unit 401 transmits data to the biometric authentication control unit 14 . The communication control unit 401 transfers data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 401 . The communication control unit 401 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 進入者検出部402は、自装置(ゲート装置10)への進入者を検出する手段である。より具体的には、進入者検出部402は、検出センサ12からの検出信号を用いて、ゲート装置10の中間地点(図3の位置X4)に到達した利用者を検出する。進入者検出部402は、位置X4にて利用者を検出すると、その旨をゲート制御部403に通知する。 The intruder detection unit 402 is a means for detecting an intruder into its own device (gate device 10). More specifically, the intruder detection unit 402 uses the detection signal from the detection sensor 12 to detect the user who has reached the intermediate point of the gate device 10 (position X4 in FIG. 3). When the intruder detection unit 402 detects the user at the position X4, the intruder detection unit 402 notifies the gate control unit 403 to that effect.
 ゲート制御部403は、ゲート装置10が備えるゲート13を制御する手段である。ゲート制御部403は、利用者がゲート装置10の所定位置(図3の位置X4)に到達したタイミングで、ゲート13の開閉制御を行う。 The gate control unit 403 is means for controlling the gate 13 provided in the gate device 10 . The gate control unit 403 performs opening/closing control of the gate 13 at the timing when the user reaches a predetermined position (position X4 in FIG. 3) of the gate device 10 .
 ゲート制御部403は、利用者が位置X4に到達したタイミングで、生体認証制御ユニット14から「通行許可通知」を既に受信していれば、ゲート13の開状態を維持する。対して、ゲート制御部403は、当該タイミングにて生体認証制御ユニット14から「通行許可通知」を受信していない場合には、ゲート13を閉じる。 The gate control unit 403 keeps the gate 13 open if it has already received the "passage permission notification" from the biometric authentication control unit 14 when the user reaches the position X4. On the other hand, the gate control unit 403 closes the gate 13 when the "passage permission notification" is not received from the biometrics control unit 14 at the timing.
 なお、ゲート13を閉じた場合には、ゲート制御部403は、その旨を生体認証制御ユニット14に通知する。具体的には、ゲート制御部403は、「ゲート閉通知」を生体認証制御ユニット14に送信する。ゲート制御部403は、ゲート閉通知を送信してから所定期間の間に「利用者通行許可」を受信すると、ゲート13を開く。 When the gate 13 is closed, the gate control section 403 notifies the biometric authentication control unit 14 to that effect. Specifically, the gate control unit 403 transmits a “gate closed notification” to the biometric authentication control unit 14 . The gate control unit 403 opens the gate 13 when receiving the “passage permission for the user” within a predetermined period of time after transmitting the gate closing notification.
 なお、ゲート制御部403は、被認証者がゲート13を通過した事実を、生体認証制御ユニット14を介してサーバ装置20に通知する。具体的には、ゲート制御部403は、位置X4にて利用者が検出され、生体認証制御ユニット14から通行許可通知を受信していることで、利用者のゲート通過を許可した場合には、その旨を生体認証制御ユニット14に通知する。生体認証制御ユニット14の通行許可通知部205は、通行許可通知を送信することの根拠となったエントリ(被認証者情報テーブルのエントリ)に記載された被認証者IDとゲート装置10のゲートIDを含む「ゲート通過通知」をサーバ装置20に送信する。即ち、ゲート装置10(生体認証制御ユニット14)は、ゲート13を通過した被認証者の被認証者ID、ゲートIDを含む「ゲート通過通知」をサーバ装置20に送信する。 The gate control unit 403 notifies the server device 20 via the biometric authentication control unit 14 of the fact that the person to be authenticated has passed through the gate 13 . Specifically, when the gate control unit 403 permits the user to pass through the gate because the user is detected at the position X4 and the pass permission notice is received from the biometric authentication control unit 14, The biometric authentication control unit 14 is notified to that effect. The pass permission notification unit 205 of the biometric authentication control unit 14 receives the authenticated person ID described in the entry (the entry of the authenticated person information table) that is the basis for transmitting the pass permission notification and the gate ID of the gate device 10. to the server device 20. That is, the gate device 10 (biometric authentication control unit 14 ) transmits to the server device 20 a “gate passage notification” including the subject ID of the person to be authenticated who has passed through the gate 13 and the gate ID.
 記憶部404は、ゲート装置10の動作に必要な情報を記憶する手段である。 The storage unit 404 is means for storing information necessary for the operation of the gate device 10 .
 図10は、第1の実施形態に係る生体認証制御ユニット14及びゲート装置10の動作の一例を示すシーケンス図である。 FIG. 10 is a sequence diagram showing an example of operations of the biometric authentication control unit 14 and the gate device 10 according to the first embodiment.
 生体認証制御ユニット14は、ゲート装置10からみて前方の所定範囲内において被認証者の検出を試みる(ステップS101)。被認証者が検出されないと(ステップS101、No分岐)、生体認証制御ユニット14はステップS101の処理を繰り返す。 The biometric authentication control unit 14 attempts to detect the person to be authenticated within a predetermined range in front of the gate device 10 (step S101). If the person to be authenticated is not detected (step S101, No branch), the biometric authentication control unit 14 repeats the process of step S101.
 被認証者が検出されると(ステップS101、Yes分岐)、生体認証制御ユニット14は、当該被認証者に関する認証要求をサーバ装置20に要求する(ステップS102)。 When the person to be authenticated is detected (step S101, Yes branch), the biometrics control unit 14 requests the server device 20 to request authentication of the person to be authenticated (step S102).
 また、生体認証制御ユニット14は、認証要求の送信と実質的に同時に、被認証者の追跡を開始する。生体認証制御ユニット14は、被認証者の位置と被認証者IDを含む追跡開始指示を追跡ユニット15に送信する(ステップS103)。 Also, the biometrics control unit 14 starts tracking the person to be authenticated substantially at the same time as sending the authentication request. The biometrics control unit 14 sends a tracking start instruction including the location of the person to be authenticated and the ID of the person to be authenticated to the tracking unit 15 (step S103).
 生体認証制御ユニット14は、サーバ装置20から認証結果を受信する(ステップS104)。生体認証制御ユニット14は、認証結果を被認証者情報テーブルに反映する。 The biometric authentication control unit 14 receives the authentication result from the server device 20 (step S104). The biometric authentication control unit 14 reflects the authentication result in the authenticated person information table.
 追跡ユニット15は、被認証者の追跡を行い、被認証者がゲート装置10の入口に到着すると被認証者進入通知を生体認証制御ユニット14に送信する。換言すれば、生体認証制御ユニット14は、被認証者進入通知を追跡ユニット15から受信する(ステップS105)。生体認証制御ユニット14は、追跡ユニット15による追跡結果を被認証者情報テーブルに反映する。 The tracking unit 15 tracks the person-to-be-authenticated, and when the person-to-be-authenticated arrives at the entrance of the gate device 10, it sends a notification of entry of the person-to-be-authenticated to the biometrics control unit 14. In other words, the biometric control unit 14 receives the entry notification of the person to be authenticated from the tracking unit 15 (step S105). The biometric authentication control unit 14 reflects the tracking result by the tracking unit 15 in the authentication subject information table.
 生体認証制御ユニット14は、被認証者がゲート装置10の入口に到達したタイミングにおいて、被認証者の認証に成功していれば、通行許可通知をゲート装置10に送信する(ステップS106)。 If the person to be authenticated has been successfully authenticated at the timing when the person to be authenticated reaches the entrance of the gate device 10, the biometrics control unit 14 transmits a notice of permission to pass to the gate device 10 (step S106).
 ゲート装置10は、被認証者がゲート装置10の所定位置に到達したか否か判定する(ステップS201)。被認証者が所定位置に到達していなければ(ステップS201、No分岐)、ゲート装置10はステップS201の処理を繰り返す。 The gate device 10 determines whether or not the person to be authenticated has reached a predetermined position on the gate device 10 (step S201). If the person to be authenticated has not reached the predetermined position (step S201, No branch), the gate device 10 repeats the process of step S201.
 被認証者が所定位置に到達していると(ステップS201、Yes分岐)、ゲート装置10は、ゲート13の開閉制御を行う(ステップS202)。ゲート装置10は、通行許可通知を受信していれば、被認証者の通過を許可する。換言すれば、ゲート装置10は、被認証者が所定位置(ゲート装置10のゲート13付近;位置X4)に到達したタイミングで通行許可通知を受信していなければ、ゲート13を閉じて利用者の通行を遮断する。 When the person to be authenticated has reached the predetermined position (step S201, Yes branch), the gate device 10 performs opening/closing control of the gate 13 (step S202). The gate device 10 permits the person-to-be-authenticated to pass if the notification of passage permission is received. In other words, the gate device 10 closes the gate 13 to let the user Block traffic.
 なお、ゲート装置10は、被認証者の通行を許可した場合には、当該事実をサーバ装置20に通知する。 When the gate device 10 permits the person to be authenticated to pass, the gate device 10 notifies the server device 20 of this fact.
 このように、生体認証制御ユニット14は、被認証者を検出し、当該検出された被認証者の生体情報を含む認証要求をサーバ装置20に送信する。また、生体認証制御ユニット14は、追跡ユニット15に対し、被認証者の位置情報を含む追跡開始指示を送信する。生体認証制御ユニット14は、被認証者の位置情報を追跡ユニット15に通知することで、追跡対象者を当該追跡ユニット15に設定する。追跡ユニット15は、追跡開始指示に含まれる位置情報に対応する場所に存在する人物を追跡対象者に設定し、測距センサ16を用いて当該追跡対象者の追跡を行う。追跡ユニット15は、追跡対象者がゲート装置10に進入すると被認証者進入通知を生体認証制御ユニット14に送信することで、被認証者がゲート装置10に到達したことを通知する。生体認証制御ユニット14は、被認証者進入通知を受信すると、サーバ装置20による認証結果に基づいて被認証者がゲート装置10を通行できるか否か判定する。生体認証制御ユニット14は、被認証者がゲート装置10を通行する資格を備えていれば(認証に成功すれば)、当該被認証者はゲート装置10を通行できると判断する。 In this way, the biometric authentication control unit 14 detects a person to be authenticated and transmits an authentication request including the detected biometric information of the person to be authenticated to the server device 20 . Also, the biometrics control unit 14 transmits a tracking start instruction including the location information of the person to be authenticated to the tracking unit 15 . The biometric authentication control unit 14 notifies the tracking unit 15 of the location information of the person to be authenticated, thereby setting the person to be tracked in the tracking unit 15 . The tracking unit 15 sets a person existing at a location corresponding to the position information included in the tracking start instruction as a person to be tracked, and uses the distance measurement sensor 16 to track the person to be tracked. When the person to be tracked enters the gate device 10 , the tracking unit 15 notifies that the person to be authenticated has arrived at the gate device 10 by transmitting a notification of entry of the person to be authenticated to the biometric authentication control unit 14 . Upon receiving the notification of the entrance of the person to be authenticated, the biometrics control unit 14 determines whether or not the person to be authenticated can pass through the gate device 10 based on the authentication result by the server device 20 . The biometric authentication control unit 14 determines that the person to be authenticated can pass through the gate device 10 if the person to be authenticated is qualified to pass through the gate device 10 (if the authentication is successful).
[サーバ装置]
 図11は、第1の実施形態に係るサーバ装置20の処理構成(処理モジュール)の一例を示す図である。図11を参照すると、サーバ装置20は、通信制御部501と、利用者登録部502と、認証部503と、ゲート通過通知処理部504と、記憶部505と、を含む。
[Server device]
FIG. 11 is a diagram showing an example of a processing configuration (processing modules) of the server device 20 according to the first embodiment. Referring to FIG. 11 , server device 20 includes communication control section 501 , user registration section 502 , authentication section 503 , gate passage notification processing section 504 , and storage section 505 .
 通信制御部501は、他の装置との間の通信を制御する手段である。例えば、通信制御部501は、生体認証制御ユニット14からデータ(パケット)を受信する。また、通信制御部501は、生体認証制御ユニット14に向けてデータを送信する。通信制御部501は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部501は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部501を介して他の装置とデータの送受信を行う。通信制御部501は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 501 is means for controlling communication with other devices. For example, the communication control section 501 receives data (packets) from the biometrics control unit 14 . Also, the communication control unit 501 transmits data to the biometric authentication control unit 14 . The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 501 . The communication control unit 501 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 利用者登録部502は、ゲート装置10を通過できる利用者をシステム登録する手段である。利用者登録部502は、任意の手段を用いてゲート装置10を通過できる利用者の生体情報(例えば、顔画像)を取得する。 The user registration unit 502 is means for system registration of users who can pass through the gate device 10 . The user registration unit 502 acquires biometric information (for example, facial images) of users who can pass through the gate device 10 using arbitrary means.
 例えば、システム利用者は、鉄道会社のWEB(ウェブ)ページや駅に設置されたキオスク端末を用いて生体情報や個人情報(氏名、住所等)をサーバ装置20に入力する。 For example, a system user inputs biometric information and personal information (name, address, etc.) into the server device 20 using a web page of a railway company or a kiosk terminal installed at a station.
 利用者登録部502は、顔画像を取得した場合には、当該顔画像から特徴量を計算する。利用者登録部502は、システム利用者(生体情報の登録者)を識別する利用者IDと共に、利用者の生体情報(例えば、顔画像から計算された特徴量)を「利用者情報データベース」に登録する(図12参照)。 When the user registration unit 502 acquires a face image, it calculates a feature amount from the face image. A user registration unit 502 stores a user ID that identifies a system user (biometric information registrant) and a user's biometric information (for example, a feature amount calculated from a face image) in a "user information database". Register (see FIG. 12).
 利用者登録部502は、必要に応じて、利用者の認証処理に必要な情報(業務情報)を利用者情報データベースに登録する。例えば、サーバ装置20が駅に設置された改札機(ゲート装置10)からの認証要求を処理する場合には、利用者登録部502は、チャージ金額等の情報と生体情報を対応付けて利用者情報データベースに記憶する。 The user registration unit 502 registers information (business information) required for user authentication processing in the user information database as necessary. For example, when the server device 20 processes an authentication request from a ticket gate (gate device 10) installed at a station, the user registration unit 502 associates information such as the charge amount with biometric information to identify the user. Store in an information database.
 図12に示す利用者情報データベースは例示であって、他の項目が生体情報(特徴量)と対応付けて記憶されていてもよい。例えば、利用者の氏名や顔画像が利用者情報データベースに登録されていてもよい。 The user information database shown in FIG. 12 is an example, and other items may be stored in association with biometric information (feature amounts). For example, the user's name and face image may be registered in the user information database.
 認証部503は、生体認証制御ユニット14(ゲート装置10)から受信した認証要求を処理する手段である。認証部503は、認証要求を受信すると、当該認証要求からゲートID、被認証者IDを抽出する。認証部503は、認証状況データベースに新たなエントリを追加し、上記抽出されたゲートID、被認証者IDを記憶する(図13参照)。また、認証部503は、追記したエントリの処理ステータスに「処理中」を設定する。図13では、理解の容易のため、ゲートIDにはゲート装置10の符号を用いている。 The authentication unit 503 is means for processing an authentication request received from the biometric authentication control unit 14 (gate device 10). Upon receiving the authentication request, the authentication unit 503 extracts the gate ID and the person-to-be-authenticated ID from the authentication request. The authentication unit 503 adds a new entry to the authentication status database and stores the extracted gate ID and authenticated person ID (see FIG. 13). Also, the authentication unit 503 sets the processing status of the added entry to “processing”. In FIG. 13, for ease of understanding, the gate device 10 is used as the gate ID.
 認証状況データベースに情報登録を行うと、認証部503は、認証要求に含まれる生体情報(特徴量)を照合対象に設定し、利用者情報データベースに登録された生体情報との間で照合処理を行う。 When information is registered in the authentication status database, the authentication unit 503 sets the biometric information (feature amount) included in the authentication request as a matching target, and performs matching processing with the biometric information registered in the user information database. conduct.
 より具体的には、認証部503は、認証要求から取り出した特徴量を照合対象に設定し、利用者情報データベースに登録されている複数の特徴量との間で1対N(Nは正の整数、以下同じ)照合を実行する。 More specifically, the authentication unit 503 sets the feature amount extracted from the authentication request as a matching object, and performs one-to-N (N is a positive (integer, same below) perform matching.
 認証部503は、照合対象の特徴量(特徴ベクトル)と登録側の複数の特徴量それぞれとの間の類似度を計算する。当該類似度には、カイ二乗距離やユークリッド距離等を用いることができる。なお、距離が離れているほど類似度は低く、距離が近いほど類似度が高い。 The authentication unit 503 calculates the degree of similarity between the feature amount (feature vector) to be matched and each of the plurality of feature amounts on the registration side. Chi-square distance, Euclidean distance, or the like can be used for the degree of similarity. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
 類似度が所定の値以上の特徴量が利用者情報データベースに登録されていなければ、認証部503は、認証結果に「認証失敗」を設定する。 If a feature amount with a degree of similarity equal to or greater than a predetermined value is not registered in the user information database, the authentication unit 503 sets "authentication failure" as the authentication result.
 類似度が所定の値以上の特徴量が利用者情報データベースに登録されていれば、認証部503は、照合処理により特定された利用者に関してゲート装置10を通過する資格を有するか否か判定する。 If a feature amount with a degree of similarity equal to or greater than a predetermined value is registered in the user information database, the authentication unit 503 determines whether or not the user specified by the collation process is qualified to pass through the gate device 10. .
 例えば、駅に入場するためのゲート装置10から受信した認証要求を処理する場合には、認証部503は、特定された利用者のチャージ金額が初乗り運賃以上の残高か否かを判定する。チャージ金額の残高が初乗り運賃以下であれば、認証部503は、特定された利用者はゲート装置10を通過する資格はないと判定する。チャージ金額の残高が初乗り運賃より多ければ、認証部503は、特定された利用者はゲート装置10を通過する資格があると判定する。 For example, when processing an authentication request received from the gate device 10 for entering a station, the authentication unit 503 determines whether the specified user's charge amount is equal to or greater than the initial fare. If the balance of the charge amount is equal to or less than the initial fare, the authentication unit 503 determines that the specified user is not qualified to pass through the gate device 10 . If the balance of the charged amount is greater than the initial fare, the authentication unit 503 determines that the identified user is qualified to pass through the gate device 10 .
 例えば、駅から退場するためのゲート装置10から受信した認証要求を処理する場合には、認証部503は、特定された利用者に乗車駅が設定されているか否かを判定する。乗車駅が設定されていなければ、認証部503は、特定された利用者はゲート装置10を通過する資格はないと判定する。乗車駅が設定されていると、認証部503は、利用者の経路(乗車駅と降車駅の間の経路)に応じた運賃を計算する。計算された運賃がチャージ金額を超えていれば、認証部503は、利用者はゲート装置10を通過する資格はないと判定する。計算された運賃がチャージ金額以下であれば、認証部503は、特定された利用者はゲート装置10を通過する資格があると判定する。 For example, when processing an authentication request received from the gate device 10 for exiting from a station, the authentication unit 503 determines whether the boarding station is set for the specified user. If the boarding station is not set, the authentication unit 503 determines that the specified user is not qualified to pass through the gate device 10 . If the boarding station is set, the authentication unit 503 calculates the fare according to the route of the user (the route between the boarding station and the alighting station). If the calculated fare exceeds the charged amount, the authentication unit 503 determines that the user is not qualified to pass through the gate device 10 . If the calculated fare is equal to or less than the charged amount, the authentication unit 503 determines that the specified user is qualified to pass through the gate device 10 .
 特定された利用者がゲート装置10を通過する資格を有さない場合には、認証部503は、認証結果に「認証失敗」を設定する。 If the identified user is not qualified to pass through the gate device 10, the authentication unit 503 sets "authentication failure" to the authentication result.
 特定された利用者がゲート装置10を通過する資格を有する場合には、認証部503は、認証結果に「認証成功」を設定する。 If the identified user is qualified to pass through the gate device 10, the authentication unit 503 sets "authentication success" to the authentication result.
 認証部503は、認証対象者(被認証者)の被認証者IDと認証結果(認証成功、認証失敗)を生体認証制御ユニット14(ゲート装置10)に通知する。認証成功の場合には、認証部503は、認証成功を示す肯定応答を生体認証制御ユニット14に送信する。その際、認証部503は、認証処理の対象となった利用者の被認証者IDを含む肯定応答を生体認証制御ユニット14に送信する。 The authentication unit 503 notifies the biometric authentication control unit 14 (gate device 10) of the person-to-be-authenticated ID of the person to be authenticated (person to be authenticated) and the authentication result (authentication success, authentication failure). In the case of successful authentication, the authentication section 503 transmits an affirmative response indicating successful authentication to the biometrics control unit 14 . At that time, the authentication unit 503 transmits to the biometric authentication control unit 14 an affirmative response including the user ID of the user to be authenticated.
 認証失敗の場合には、認証部503は、認証失敗を示す否定応答を生体認証制御ユニット14に送信する。否定応答を送信する場合には、認証部503は、認証に失敗した原因を併せて生体認証制御ユニット14に通知してもよい。例えば、認証部503は、生体情報がシステムに登録されていない、チャージ金額が不足している、乗車駅が設定されていない等の認証失敗に関する要因を生体認証制御ユニット14に送信してもよい。また、認証失敗時にも、認証部503は、認証処理の対象となった利用者の被認証者IDを含む否定応答を生体認証制御ユニット14に送信する。 In the case of authentication failure, the authentication unit 503 sends a negative response indicating authentication failure to the biometric authentication control unit 14. When sending a negative response, the authentication section 503 may also notify the biometric authentication control unit 14 of the cause of authentication failure. For example, the authentication unit 503 may transmit to the biometric authentication control unit 14 factors related to authentication failure, such as biometric information not being registered in the system, insufficient charging amount, and boarding station not being set. . Also, when the authentication fails, the authentication unit 503 transmits a negative response including the authenticated person ID of the user to be authenticated to the biometric authentication control unit 14 .
 認証要求に対する応答をゲート装置10に送信すると、認証部503は、対応する認証状況データベースのエントリに「応答済」を設定する。また、認証成功をゲート装置10に通知した場合には、認証部503は、対応するエントリの利用者IDに認証成功者(認証成功と判定された利用者)の利用者IDを設定する。 After sending a response to the authentication request to the gate device 10, the authentication unit 503 sets "responded" to the corresponding entry in the authentication status database. Also, when notifying the gate device 10 of successful authentication, the authentication unit 503 sets the user ID of the successful authentication person (the user determined to have been successfully authenticated) to the user ID of the corresponding entry.
 ゲート通過通知処理部504は、ゲート装置10(生体認証制御ユニット14)から受信するゲート通過通知を処理する手段である。ゲート通過通知処理部504は、受信した通知からゲートID及び被認証者IDを抽出する。ゲート通過通知処理部504は、ゲートID及び被認証者IDをキーとして認証状況データベースを検索し、対応するエントリを特定する。 The gate passage notification processing unit 504 is means for processing gate passage notifications received from the gate device 10 (biometric authentication control unit 14). The gate passage notification processing unit 504 extracts the gate ID and the person-to-be-authenticated ID from the received notification. The gate-passing notification processing unit 504 searches the authentication status database using the gate ID and the person-to-be-authenticated ID as keys to identify the corresponding entry.
 ゲート通過通知処理部504は、当該特定したエントリの利用者IDフィールドから利用者IDを読み出す。ゲート通過通知処理部504は、当該読み出した利用者IDをキーとして利用者情報データベースを検索し、対応するエントリを特定する。 The gate passage notification processing unit 504 reads the user ID from the user ID field of the identified entry. The gate passage notification processing unit 504 searches the user information database using the read user ID as a key to identify the corresponding entry.
 ゲート通過通知処理部504は、特定したエントリに対して利用者のゲート通過に伴う処理を実行する。 The gate passage notification processing unit 504 executes processing associated with the user passing through the gate for the specified entry.
 例えば、駅に入場するためのゲート装置10から受信したゲート通過通知を処理する場合には、ゲート通過通知処理部504は、特定したエントリの乗車駅にゲート装置10が設置された駅を設定する。 For example, when processing a gate passage notification received from the gate device 10 for entering a station, the gate passage notification processing unit 504 sets the station where the gate device 10 is installed as the boarding station of the specified entry. .
 例えば、駅から退場するためのゲート装置10から受信したゲート通過通知を処理する場合には、ゲート通過通知処理部504は、利用者の運賃を計算し、チャージ金額から当該運賃を減額する。また、ゲート通過通知処理部504は、乗車駅フィールドの設定値をクリアする。 For example, when processing a gate passage notification received from the gate device 10 for exiting the station, the gate passage notification processing unit 504 calculates the user's fare and subtracts the fare from the charge amount. In addition, the gate passage notification processing unit 504 clears the setting value of the boarding station field.
 記憶部505は、サーバ装置20の動作に必要な各種情報を記憶する。記憶部505には、利用者情報データベース、認証状況データベースが構築される。 The storage unit 505 stores various information necessary for the operation of the server device 20 . A user information database and an authentication status database are constructed in the storage unit 505 .
 図14は、第1の実施形態に係るサーバ装置20の動作の一例を示すフローチャートである。 FIG. 14 is a flow chart showing an example of the operation of the server device 20 according to the first embodiment.
 サーバ装置20は、生体認証制御ユニット14から認証要求を受信する(ステップS301)。 The server device 20 receives an authentication request from the biometric authentication control unit 14 (step S301).
 サーバ装置20は、認証要求に含まれる生体情報と利用者情報データベースに登録された生体情報を用いた照合処理を実行する(ステップS302)。 The server device 20 executes matching processing using the biometric information included in the authentication request and the biometric information registered in the user information database (step S302).
 サーバ装置20は、生体情報間の類似度が所定の値以上のエントリが存在するか否か判定する(ステップS303)。 The server device 20 determines whether or not there is an entry with a degree of similarity between biometric information equal to or greater than a predetermined value (step S303).
 そのようなエントリが存在しなければ(ステップS303、No分岐)、サーバ装置20は、認証結果を認証失敗に設定する(ステップS304)。 If such an entry does not exist (step S303, No branch), the server device 20 sets the authentication result to authentication failure (step S304).
 そのようなエントリが存在すれば(ステップS303、Yes分岐)、サーバ装置20は、被認証者がゲート装置10を通過する資格を有するか否か判定する(ステップS305)。 If such an entry exists (step S303, Yes branch), the server device 20 determines whether the person to be authenticated is qualified to pass through the gate device 10 (step S305).
 被認証者がゲート装置10を通過する資格を備えていなければ(ステップS305、No分岐)、サーバ装置20は、認証結果を認証失敗に設定する(ステップS304)。 If the person to be authenticated is not qualified to pass through the gate device 10 (step S305, No branch), the server device 20 sets the authentication result to authentication failure (step S304).
 被認証者がゲート装置10を通過する資格を備えていれば(ステップS305、Yes分岐)、サーバ装置20は、認証結果を認証成功に設定する(ステップS306)。 If the person to be authenticated is qualified to pass through the gate device 10 (step S305, Yes branch), the server device 20 sets the authentication result to authentication success (step S306).
 サーバ装置20は、認証結果(認証成功、認証失敗)を生体認証制御ユニット14に送信する(ステップS307)。 The server device 20 transmits the authentication result (authentication success, authentication failure) to the biometric authentication control unit 14 (step S307).
 なお、ゲート通過通知を受信した際のサーバ装置20の動作に関する説明は省略する。 A description of the operation of the server device 20 when receiving the gate passage notification will be omitted.
 続いて、図面を参照しつつ、第1の実施形態に係る認証システムの動作を説明する。図15は、第1の実施形態に係る認証システムの動作の一例を示すシーケンス図である。なお、図15の動作に先立ち、システム利用者の登録は予め行われているものとする。また、図15では、生体認証制御ユニット14、追跡ユニット15はゲート装置10に一体化されたものと捉え、システムの動作を説明する。 Next, the operation of the authentication system according to the first embodiment will be described with reference to the drawings. 15 is a sequence diagram illustrating an example of the operation of the authentication system according to the first embodiment; FIG. It is assumed that system users have already been registered prior to the operation of FIG. Also, in FIG. 15, the biometric authentication control unit 14 and the tracking unit 15 are assumed to be integrated with the gate device 10, and the operation of the system will be described.
 ゲート装置10は、自装置の前方に設定された所定範囲内の被認証者を検出する(ステップS01)。 The gate device 10 detects a person to be authenticated within a predetermined range set in front of itself (step S01).
 ゲート装置10は、被認証者の生体情報を取得し、当該生体情報を含む認証要求をサーバ装置20に送信する(ステップS02)。 The gate device 10 acquires the biometric information of the person to be authenticated, and transmits an authentication request including the biometric information to the server device 20 (step S02).
 また、認証要求の送信と実質的に同じタイミングにおいて、ゲート装置10は、被認証者の追跡を開始する(ステップS03)。 Also, at substantially the same timing as the transmission of the authentication request, the gate device 10 starts tracking the person to be authenticated (step S03).
 サーバ装置20は、認証処理を実行し、その結果をゲート装置10に送信する(ステップS11、S12)。 The server device 20 executes authentication processing and transmits the result to the gate device 10 (steps S11 and S12).
 ゲート装置10は、認証結果を受信し、認証結果を被認証者情報テーブルに反映する(認証結果の反映;ステップS04)。 The gate device 10 receives the authentication result and reflects the authentication result in the authentication subject information table (reflection of the authentication result; step S04).
 被認証者がゲート装置10の入り口に到達すると、ゲート装置10は、被認証者の追跡を完了する(ステップS05)。 When the person to be authenticated reaches the entrance of the gate device 10, the gate device 10 completes tracking of the person to be authenticated (step S05).
 被認証者がゲート装置10の所定位置に到達すると、ゲート装置10は、ゲート制御を行う(ステップS06)。具体的には、ゲート装置10は、認証成功及び追跡完了と設定されている被認証者の通過を許可する。 When the person to be authenticated reaches the predetermined position of the gate device 10, the gate device 10 performs gate control (step S06). Specifically, the gate device 10 permits passage of the person to be authenticated for whom authentication is successful and tracking is completed.
 被認証者の通過を許可すると、ゲート装置10は、サーバ装置20に対してゲート通過通知を送信する(ステップS07)。 After permitting the person to be authenticated to pass through, the gate device 10 transmits a gate passage notification to the server device 20 (step S07).
 ゲート通過通知を受信すると、サーバ装置20は、ゲート通過者(認証成功者;認証成功と判定された被認証者)の情報更新を行う(ステップS13)。具体的には、サーバ装置20は、ゲート通過者に対応する利用者情報データベースのエントリを更新する。 Upon receiving the gate passage notification, the server device 20 updates the information of the person who passed through the gate (authenticated person; person to be authenticated who was determined to be authenticated successfully) (step S13). Specifically, the server device 20 updates the entry in the user information database corresponding to the gate passer.
 続いて、図面を参照しつつ、利用者(被認証者、認証対象ではない利用者)による様々な移動を想定したゲート装置10の具体的な動作を説明する。 Next, specific operations of the gate device 10 assuming various movements of users (users to be authenticated, users who are not to be authenticated) will be described with reference to the drawings.
 図16の上段に示すように、利用者30が被認証者に設定され、利用者31は認証対象ではない利用者とする。なお、図16を含む図面において被認証者を灰色、認証対象ではない利用者を白色でそれぞれ図示する。利用者31は、位置X1にて被認証者として検出されていないので、被認証者ではない。そのため、利用者31に関するエントリは被認証者情報テーブルには存在しない。 As shown in the upper part of FIG. 16, user 30 is set as a person to be authenticated, and user 31 is a user who is not to be authenticated. In the drawings including FIG. 16, the person to be authenticated is shown in gray, and the user who is not to be authenticated is shown in white. User 31 is not a person to be authenticated because it is not detected as a person to be authenticated at position X1. Therefore, there is no entry for user 31 in the authenticated person information table.
 利用者30は、ゲート装置10に向かって歩く。利用者31は、利用者30の横からゲート装置10の内部に進入するように移動する。この場合、時間の経過とともに、両者の位置関係は図16の下段に示すようになる。 The user 30 walks toward the gate device 10. The user 31 moves so as to enter the inside of the gate device 10 from the side of the user 30 . In this case, the positional relationship between the two becomes as shown in the lower part of FIG. 16 as time elapses.
 利用者31のエントリは被認証者情報テーブルに登録されていないので、利用者31が位置X4に到達するとゲート13は閉じる。また、ゲート13が閉じてから所定期間経過しても、利用者31の認証結果が被認証者情報テーブルに登録されることはないので、ゲート13が開くこともない。 Since the entry for user 31 is not registered in the authentication subject information table, gate 13 closes when user 31 reaches position X4. Further, even if a predetermined period of time has passed since the gate 13 was closed, the authentication result of the user 31 is not registered in the authenticated person information table, so the gate 13 is not opened.
 あるいは、被認証者が前を歩く他の被認証者を追い抜くことも考えられる。例えば、図17の上段に示すように、利用者32及び利用者33がゲート装置10に向かって歩く場合を考える。この場合、利用者32、利用者33は共に、位置X1にて生体情報が取得され、追跡が開始されているので、被認証者(灰色の人物)に設定される。 Alternatively, it is conceivable that the person to be authenticated passes another person to be authenticated walking in front. For example, consider a case where users 32 and 33 walk toward the gate device 10 as shown in the upper part of FIG. In this case, both the user 32 and the user 33 are set as the person to be authenticated (the person in gray) because the biometric information is acquired at the position X1 and the tracking is started.
 後ろを歩く利用者33は、図17の上段に示す一点鎖線のように移動し、前の利用者32を追い抜く。この場合、時間の経過とともに、両者の位置関係は図17の下段に示すようになる。 The user 33 walking behind moves as shown in the dashed line in the upper part of FIG. 17 and overtakes the user 32 in front. In this case, the positional relationship between the two becomes as shown in the lower part of FIG. 17 as time elapses.
 利用者32、利用者33のエントリは被認証者情報テーブルに登録されており、利用者33の認証処理(サーバ装置20における認証処理)が成功している場合には、利用者33が位置X4に到達してもゲート13は開状態を維持する。また、利用者33に続き利用者32が位置X4に到達してもゲート13が閉じることはない。 Entries for the user 32 and the user 33 are registered in the authenticated person information table. , the gate 13 remains open. Further, even if the user 32 arrives at the position X4 following the user 33, the gate 13 is not closed.
 このように、位置X1にて生体情報が取得され、被認証者として設定された利用者は、設定された順番でゲート装置10に到達(進入)しなくとも、正常に処理される。即ち、被認証者の歩行速度の相違等により、被認証者として登録された順番通りに利用者がゲート装置10に到達しなくとも利用者はゲート装置10を通過できる。このように、第1の実施形態に係る認証システムは、イレギュラーな状況も許容するのでシステムのスループットが向上する。 In this way, the user whose biometric information is acquired at the position X1 and who is set as the person to be authenticated can be processed normally even if they do not reach (enter) the gate device 10 in the set order. That is, the user can pass through the gate device 10 even if the user does not reach the gate device 10 in the order in which the person to be authenticated was registered due to a difference in the walking speed of the person to be authenticated. In this way, the authentication system according to the first embodiment also allows irregular situations, so the throughput of the system is improved.
<第1の実施形態に係る変形例>
 上記実施形態では、追跡を完了すると、追跡ユニット15は、追跡対象者の被認証者IDを含む被認証者進入通知を生体認証制御ユニット14に送信する場合について説明した。しかし、生体認証制御ユニット14は、追跡ユニット15に対し、被認証者(追跡対象者)の追跡が終了したか否かを定期的に問い合わせてもよい。
<Modified example according to the first embodiment>
In the above embodiment, the tracking unit 15 sends to the biometrics control unit 14 the subject entry notification including the subject ID of the tracked person when tracking is completed. However, the biometrics control unit 14 may periodically inquire of the tracking unit 15 whether or not tracking of the person to be authenticated (tracked person) has ended.
 具体的には、生体認証制御ユニット14の追跡制御部204は、追跡開始指示を追跡ユニット15に送信した後、定期的に、被認証者IDを含む「位置問い合わせ」を追跡ユニット15に送信する。 Specifically, after transmitting a tracking start instruction to the tracking unit 15, the tracking control unit 204 of the biometric authentication control unit 14 periodically transmits a "location inquiry" including the ID of the person to be authenticated to the tracking unit 15. .
 追跡ユニット15の追跡部302は、当該問い合わせに含まれる被認証者IDの位置情報(X座標、Y座標)を生体認証制御ユニット14に送信する。追跡制御部204は、取得した位置情報を用いて被認証者(追跡対象者)がゲート装置10に進入したか否か判定する。追跡制御部204は、取得した位置情報から被認証者がゲート装置10に進入したと判定した場合には、被認証者情報テーブルの対応するエントリにおける追跡ステータスに「追跡完了」を設定する。追跡制御部204は、エントリに追跡完了を設定すると、その旨を通行許可通知部205に通知する。 The tracking unit 302 of the tracking unit 15 transmits the position information (X coordinate, Y coordinate) of the ID of the person to be authenticated included in the inquiry to the biometrics control unit 14 . The tracking control unit 204 determines whether or not the person to be authenticated (person to be tracked) has entered the gate device 10 using the acquired position information. When the tracking control unit 204 determines that the person to be authenticated has entered the gate device 10 from the acquired position information, the tracking control unit 204 sets the tracking status of the corresponding entry in the information table of the person to be authenticated to "tracking completed". When tracking completion is set in the entry, the tracking control unit 204 notifies the passage permission notification unit 205 to that effect.
 通行許可通知部205は、当該通知に応じて、被認証者がゲート装置10を通行できるか否か判定する。即ち、追跡制御部204が取得した追跡対象者の位置情報が、追跡対象者がゲート装置10に進入したことを示す場合、通行許可通知部205は、被認証者がゲート装置10を通行できるか否か判定する。 The passage permission notification unit 205 determines whether or not the person to be authenticated can pass through the gate device 10 according to the notification. That is, when the tracked person's position information acquired by the tracking control unit 204 indicates that the tracked person has entered the gate device 10 , the passage permission notification unit 205 determines whether the person to be authenticated can pass through the gate device 10 . Determine whether or not.
 以上のように、第1の実施形態にゲート装置10(生体認証制御ユニット14と追跡ユニット15が搭載されたゲート装置10)は、被認証者の検出を行う。ゲート装置10は、被認証者を検出すると、当該被認証者に関する認証と追跡を実質的に同じタイミングで開始する。サーバ装置20は、ゲート装置10から離れた場所から認証処理を開始できるので、生体認証の実行時間を確保できる。また、ゲート装置10は、上記離れた場所から被認証者の追跡を開始する。その際、ゲート装置10は、測距センサ16を用いた追跡を行う。ゲート装置10は、測距センサ16を使った被認証者の追跡により当該被認証者の正確な現在位置を把握できるので、被認証者によるゲート装置10への進入を確実に認識できる。換言すれば、被認証者ではない利用者がゲート装置10に割り込んだとしても、ゲート装置10は、当該割り込んだ利用者の通行を遮断できる。 As described above, the gate device 10 (the gate device 10 equipped with the biometric authentication control unit 14 and the tracking unit 15) in the first embodiment detects the person to be authenticated. When the gate device 10 detects the person to be authenticated, the gate device 10 starts authentication and tracking of the person to be authenticated at substantially the same timing. Since the server device 20 can start the authentication process from a place away from the gate device 10, it is possible to secure the execution time of the biometric authentication. Also, the gate device 10 starts tracking the person to be authenticated from the remote location. At that time, the gate device 10 performs tracking using the ranging sensor 16 . Since the gate device 10 can grasp the accurate current position of the person to be authenticated by tracking the person to be authenticated using the distance measuring sensor 16, the entry into the gate device 10 by the person to be authenticated can be reliably recognized. In other words, even if a user who is not the person to be authenticated interrupts the gate device 10, the gate device 10 can block the passage of the interrupting user.
 続いて、認証システムを構成する各装置のハードウェアについて説明する。図18は、生体認証制御ユニット14のハードウェア構成の一例を示す図である。 Next, the hardware of each device that makes up the authentication system will be explained. FIG. 18 is a diagram showing an example of the hardware configuration of the biometrics control unit 14. As shown in FIG.
 生体認証制御ユニット14は、プロセッサ311、メモリ312及び通信インターフェイス313等を備える。上記プロセッサ311等の構成要素は内部バス等により接続され、相互に通信可能に構成されている。 The biometric authentication control unit 14 includes a processor 311, a memory 312, a communication interface 313, and the like. Components such as the processor 311 are connected by an internal bus or the like and configured to be able to communicate with each other.
 但し、図18に示す構成は、生体認証制御ユニット14のハードウェア構成を限定する趣旨ではない。生体認証制御ユニット14は、図示しないハードウェアを含んでもよい。また、生体認証制御ユニット14に含まれるプロセッサ311等の数も図18の例示に限定する趣旨ではなく、例えば、複数のプロセッサ311が生体認証制御ユニット14に含まれていてもよい。 However, the configuration shown in FIG. 18 is not intended to limit the hardware configuration of the biometric authentication control unit 14. The biometrics control unit 14 may include hardware (not shown). Also, the number of processors 311 and the like included in the biometrics control unit 14 is not limited to the example shown in FIG.
 プロセッサ311は、例えば、CPU(Central Processing Unit)、MPU(Micro Processing Unit)、DSP(Digital Signal Processor)等のプログラマブルなデバイスである。あるいは、プロセッサ311は、FPGA(Field Programmable Gate Array)、ASIC(Application Specific Integrated Circuit)等のデバイスであってもよい。プロセッサ311は、オペレーティングシステム(OS;Operating System)を含む各種プログラムを実行する。 The processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), DSP (Digital Signal Processor). Alternatively, processor 311 may be a device such as FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or the like. The processor 311 executes various programs including an operating system (OS).
 メモリ312は、RAM(Random Access Memory)、ROM(Read Only Memory)、HDD(Hard Disk Drive)、SSD(Solid State Drive)等である。メモリ312は、OSプログラム、アプリケーションプログラム、各種データを格納する。 The memory 312 is RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), or the like. The memory 312 stores an OS program, application programs, and various data.
 通信インターフェイス313は、他の装置と通信を行う回路、モジュール等である。例えば、通信インターフェイス313は、NIC(Network Interface Card)等を備える。 The communication interface 313 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 313 includes a NIC (Network Interface Card) or the like.
 生体認証制御ユニット14の機能は、各種処理モジュールにより実現される。当該処理モジュールは、例えば、メモリ312に格納されたプログラムをプロセッサ311が実行することで実現される。また、当該プログラムは、コンピュータが読み取り可能な記憶媒体に記録することができる。記憶媒体は、半導体メモリ、ハードディスク、磁気記録媒体、光記録媒体等の非トランジェント(non-transitory)なものとすることができる。即ち、本発明は、コンピュータプログラム製品として具現することも可能である。また、上記プログラムは、ネットワークを介してダウンロードするか、あるいは、プログラムを記憶した記憶媒体を用いて、更新することができる。さらに、上記処理モジュールは、半導体チップにより実現されてもよい。 The functions of the biometric authentication control unit 14 are realized by various processing modules. The processing module is implemented by the processor 311 executing a program stored in the memory 312, for example. Also, the program can be recorded in a computer-readable storage medium. The storage medium can be non-transitory such as semiconductor memory, hard disk, magnetic recording medium, optical recording medium, and the like. That is, the present invention can also be embodied as a computer program product. Also, the program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing module may be realized by a semiconductor chip.
 生体認証制御ユニット14は、コンピュータを搭載し、当該コンピュータにプログラムを実行させることで生体認証制御ユニット14の機能が実現できる。また、生体認証制御ユニット14は、当該プログラムにより生体認証制御ユニット14の制御方法を実行する。 The biometric authentication control unit 14 is equipped with a computer, and the functions of the biometric authentication control unit 14 can be realized by causing the computer to execute a program. Moreover, the biometrics control unit 14 performs the control method of the biometrics control unit 14 by the said program.
 追跡ユニット15のハードウェア構成は、生体認証制御ユニット14のハードウェア構成と同一とすることができるので説明を省略する。 The hardware configuration of the tracking unit 15 can be the same as the hardware configuration of the biometrics control unit 14, so the description is omitted.
 ゲート装置10は、上述のように、カメラ11、検出センサ12及びゲート13を備える(図19参照)。なお、ゲート装置10は、生体認証制御ユニット14と同様に、プロセッサ、メモリ、通信インターフェイス等のハードウェアを備えるが、これらの構成に関する図示と説明は省略する。 The gate device 10 includes the camera 11, the detection sensor 12 and the gate 13 as described above (see FIG. 19). The gate device 10 has hardware such as a processor, a memory, and a communication interface in the same manner as the biometric authentication control unit 14, but illustrations and descriptions of these configurations are omitted.
 カメラ11は、可視光画像を取得可能なカメラ装置である。図3では、ゲート装置10は、1つのカメラ11を備える場合について説明したが、カメラ11の数や設置を限定する趣旨ではない。例えば、複数のカメラ11がゲート装置10に設置されていてもよい。 The camera 11 is a camera device capable of acquiring visible light images. In FIG. 3, the gate device 10 has been described as having one camera 11, but this is not intended to limit the number or installation of the cameras 11. FIG. For example, multiple cameras 11 may be installed in the gate device 10 .
 あるいは、被認証者を検出するためのカメラ11に代えて、他の手段により被認証者が検出されてもよい。例えば、人感センサ等を用いてゲート装置10から所定の距離離れた場所の人物が検出されてもよい。あるいは、人感センサにより人物が検出されたことを契機としてカメラ11が画像データを取得し、被認証者の検出が行われてもよい。 Alternatively, the person to be authenticated may be detected by other means instead of the camera 11 for detecting the person to be authenticated. For example, a human sensor or the like may be used to detect a person at a predetermined distance from the gate device 10 . Alternatively, the camera 11 may acquire image data when a human sensor detects a person, and the person to be authenticated may be detected.
 検出センサ12は、人を検出するセンサである。検出センサ12として、例えば、光の送信デバイスと受信デバイスにより構成されたセンサ(所謂、光を用いた通過センサ)を利用できる。例えば、光の送信デバイスと受信デバイスのそれぞれが対向するように設置される(本体の内壁に2つのデバイスが設置される)。送信デバイスは、光を常時送信し、受信デバイスは、当該送信された光を受信する。ゲート装置10は、受信デバイスが光を受信できなかった場合に、人が検出されたと判定する。なお、図3では、検出センサ12を構成する2つのデバイスのうち一方のデバイスを図示している。 The detection sensor 12 is a sensor that detects people. As the detection sensor 12, for example, a sensor composed of a light transmitting device and a light receiving device (so-called light passing sensor) can be used. For example, an optical transmission device and an optical reception device are installed so as to face each other (two devices are installed on the inner wall of the main body). A transmitting device constantly transmits light and a receiving device receives the transmitted light. The gate device 10 determines that a person is detected when the receiving device fails to receive the light. Note that FIG. 3 shows one of the two devices that constitute the detection sensor 12 .
 ゲート13は、利用者の通行を制御するデバイスである。ゲート13の方式は、特に限定されるものではなく、例えば、通路の片側又は両側から設けられたフラッパーが開閉するフラッパーゲート、3本バーが回転するターンスタイルゲート等である。 The gate 13 is a device that controls the passage of users. The method of the gate 13 is not particularly limited, and may be, for example, a flapper gate that opens and closes with flappers provided from one or both sides of the passage, a turnstile gate that rotates three bars, or the like.
 生体認証制御ユニット14や追跡ユニット15の機能は、ゲート装置10の全体を制御するCPU等により実現されてもよい。逆に、ゲート装置10の機能は、生体認証制御ユニット14が備えるプロセッサ311により実現されてもよい。 The functions of the biometric authentication control unit 14 and the tracking unit 15 may be implemented by a CPU or the like that controls the gate device 10 as a whole. Conversely, the functions of the gate device 10 may be realized by the processor 311 included in the biometrics control unit 14. FIG.
 あるいは、追跡ユニット15の機能は生体認証制御ユニット14により実現されてもよい。あるいは、追跡ユニット15の機能は測距センサ16に内蔵されていてもよい。即ち、追跡ユニット15の機能が内蔵された測距センサ16と生体認証制御ユニット14が接続されていてもよい。 Alternatively, the functions of the tracking unit 15 may be realized by the biometric control unit 14. Alternatively, the functionality of tracking unit 15 may be incorporated in ranging sensor 16 . That is, the distance measurement sensor 16 having the function of the tracking unit 15 and the biometric control unit 14 may be connected.
 なお、サーバ装置20は、情報処理装置により構成可能である。サーバ装置20は、生体認証制御ユニット14と同様に、プロセッサ、メモリ、通信インターフェイス等を備えていればよく、当業者にとってその構成は明らかであるので詳細な説明を省略する。 Note that the server device 20 can be configured by an information processing device. As with the biometric authentication control unit 14, the server device 20 only needs to include a processor, a memory, a communication interface, and the like.
[変形例]
 なお、上記実施形態にて説明した認証システムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
[Modification]
The configuration, operation, and the like of the authentication system described in the above embodiment are examples, and are not intended to limit the configuration and the like of the system.
 上記実施形態では、ゲート装置10は駅に設置された改札機として説明を行った。しかし、ゲート装置10を改札機に限定する趣旨ではないことは勿論である。ゲート装置10は、空港、イベント会場、オフィス等に設置され利用者の通行を制御する装置であればよい。 In the above embodiment, the gate device 10 is explained as a ticket gate installed at the station. However, it is of course not intended to limit the gate device 10 to a ticket gate. The gate device 10 may be a device that is installed in an airport, an event site, an office, or the like, and controls the passage of users.
 上記実施形態では、サーバ装置20が利用者情報データベースを有する場合について説明した。しかし、当該データベースは、サーバ装置20とは異なるデータベースサーバに構築されていてもよい。また、認証システムには、上記実施形態にて説明した各種手段(認証要求部203、追跡制御部204等)が含まれていればよい。例えば、サーバ装置20にて実行される認証処理はゲート装置10(生体認証制御ユニット14)にて実行されてもよい。サーバ装置20の一部又は全部の機能はゲート装置10にて実現されてもよい。 In the above embodiment, the case where the server device 20 has a user information database has been described. However, the database may be constructed in a database server different from the server device 20 . Also, the authentication system may include various means (authentication request unit 203, tracking control unit 204, etc.) described in the above embodiment. For example, the authentication process performed by the server device 20 may be performed by the gate device 10 (biometric authentication control unit 14). A part or all of the functions of the server device 20 may be realized by the gate device 10 .
 上記実施形態では、生体認証制御ユニット14からサーバ装置20に顔画像から生成された特徴量に係る生体情報が送信される場合について説明した。しかし、生体認証制御ユニット14からサーバ装置20に「顔画像」そのものが生体情報として送信されてもよい。サーバ装置20は、取得した顔画像から特徴量を生成し、認証処理(1対N照合)を実行してもよい。 In the above embodiment, a case has been described in which the biometric information related to the feature amount generated from the face image is transmitted from the biometric authentication control unit 14 to the server device 20 . However, the “face image” itself may be transmitted from the biometric authentication control unit 14 to the server device 20 as the biometric information. The server device 20 may generate a feature amount from the acquired face image and perform authentication processing (one-to-N matching).
 上記実施形態では、被認証者検出部202が、被認証者の位置(X座標、Y座標)を推定する場合について説明した。しかし、被認証者の位置に関する推定は、追跡制御部204が行ってもよい。この場合、被認証者検出部202は、被認証者IDと画像データを追跡制御部204に引き渡せばよい。追跡制御部204は、取得した画像データを用いて被認証者の位置(X座標、Y座標)を推定すればよい。 In the above embodiment, the case where the authenticated person detection unit 202 estimates the position (X coordinate, Y coordinate) of the authenticated person has been described. However, the estimation of the location of the person to be authenticated may be performed by the tracking control unit 204 . In this case, the person-to-be-authenticated detection unit 202 may pass the person-to-be-authenticated ID and the image data to the tracking control unit 204 . The tracking control unit 204 may estimate the position (X coordinate, Y coordinate) of the person to be authenticated using the acquired image data.
 上記実施形態では、カメラ11は単眼のカメラであることを前提としているが、カメラ11は、奥行方向を測定できるデプスカメラ(ステレオカメラ)であってもよい。この場合、生体認証制御ユニット14は、目間距離に対する閾値処理に代えて、ステレオカメラから得られる画像を用いてゲート装置10から所定の距離離れた場所の被認証者を検出してもよい。具体的には、生体認証制御ユニット14は、ステレオカメラから得られる2枚の画像を解析(視差を利用した解析)し、ゲート装置10を基準とした利用者の位置を計算する。生体認証制御ユニット14は、当該計算された位置が予め定めた場所に含まれていれば、当該利用者を被認証者に設定する。 In the above embodiment, the camera 11 is assumed to be a monocular camera, but the camera 11 may be a depth camera (stereo camera) capable of measuring the depth direction. In this case, the biometric authentication control unit 14 may detect the person to be authenticated at a predetermined distance from the gate device 10 using an image obtained from a stereo camera instead of thresholding the distance between the eyes. Specifically, the biometrics control unit 14 analyzes two images obtained from the stereo camera (analysis using parallax), and calculates the user's position with respect to the gate device 10 . If the calculated position is included in the predetermined location, the biometric authentication control unit 14 sets the user as a person to be authenticated.
 生体認証制御ユニット14とサーバ装置20の間のデータ送受信の形態は特に限定されないが、これら装置間で送受信されるデータは暗号化されていてもよい。顔画像や当該顔画像から算出される特徴量は個人情報であり当該個人情報を適切に保護するためには、暗号化されたデータが送受信されることが望ましい。 The form of data transmission/reception between the biometric authentication control unit 14 and the server device 20 is not particularly limited, but the data transmitted/received between these devices may be encrypted. A face image and a feature amount calculated from the face image are personal information, and in order to appropriately protect the personal information, it is desirable to transmit and receive encrypted data.
 なお、上記実施形態では、ゲート装置10と生体認証制御ユニット14、追跡ユニット15が分離している場合について説明した。しかし、これらの装置が統合されていてもよい。即ち、生体認証制御ユニット14及び追跡ユニット15はゲート装置10と一体化されていてもよい。この場合、ゲート装置10は、図9に示す構成に加え、図4に示す生体認証制御ユニット14の被認証者検出部202、認証要求部203、追跡制御部204等と、図7に示す追跡ユニット15の追跡部302を備えていればよい。 In addition, in the above embodiment, the case where the gate device 10, the biometrics control unit 14, and the tracking unit 15 are separated has been described. However, these devices may be integrated. That is, the biometrics control unit 14 and the tracking unit 15 may be integrated with the gate device 10 . In this case, the gate device 10 includes, in addition to the configuration shown in FIG. It is sufficient if the tracking section 302 of the unit 15 is provided.
 上記実施形態では、被認証者情報テーブルを用いて被認証者に関する情報を記憶、管理する場合について説明した。しかし、被認証者に関する情報はデータベース(被認証者情報データベース)を用いて記憶、管理されてもよい。 In the above embodiment, a case has been described in which the information about the person to be authenticated is stored and managed using the information table for the person to be authenticated. However, the information about the person to be authenticated may be stored and managed using a database (person to be authenticated information database).
 上記説明で用いた流れ図(フローチャート、シーケンス図)では、複数の工程(処理)が順番に記載されているが、実施形態で実行される工程の実行順序は、その記載の順番に制限されない。実施形態では、例えば各処理を並行して実行する等、図示される工程の順番を内容的に支障のない範囲で変更することができる。 In the flowcharts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiment is not limited to the described order. In the embodiment, the order of the illustrated steps can be changed within a range that does not interfere with the content, such as executing each process in parallel.
 上記の実施形態は本願開示の理解を容易にするために詳細に説明したものであり、上記説明したすべての構成が必要であることを意図したものではない。また、複数の実施形態について説明した場合には、各実施形態は単独で用いてもよいし、組み合わせて用いてもよい。例えば、実施形態の構成の一部を他の実施形態の構成に置き換えることや、実施形態の構成に他の実施形態の構成を加えることも可能である。さらに、実施形態の構成の一部について他の構成の追加、削除、置換が可能である。 The above embodiments have been described in detail to facilitate understanding of the disclosure of the present application, and are not intended to require all the configurations described above. Also, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of the embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of the embodiment. Furthermore, additions, deletions, and replacements of other configurations are possible for some of the configurations of the embodiments.
 上記の説明により、本発明の産業上の利用可能性は明らかであるが、本発明は、空港や駅等に設置される認証システムなどに好適に適用可能である。 From the above description, the industrial applicability of the present invention is clear, and the present invention can be suitably applied to authentication systems installed at airports, stations, and the like.
 上記の実施形態の一部又は全部は、以下の付記のようにも記載され得るが、以下には限られない。
[付記1]
 被認証者を検出する、被認証者検出部と、
 前記被認証者の生体情報を含む認証要求をサーバ装置に送信する、要求部と、
 測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得する追跡制御部と、
 前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、通知部と、
 を備える、生体認証制御ユニット。
[付記2]
 前記追跡制御部は、前記追跡対象者が前記ゲート装置に進入したことを示す被認証者進入通知を前記追跡ユニットから受信し、
 前記被認証者進入通知が受信されたことに応じて、前記通知部は、前記被認証者がゲート装置を通行できるか否か判定する、付記1に記載の生体認証制御ユニット。
[付記3]
 前記追跡制御部は、
 前記追跡開始指示を送信した後、前記被認証者IDを含む位置問い合わせを前記追跡ユニットに送信し、前記追跡ユニットから前記被認証者IDに対応する前記追跡対象者の位置情報を取得し、
 前記通知部は、前記取得した追跡対象者の位置情報が、前記追跡対象者が前記ゲート装置に進入したことを示す場合、前記被認証者がゲート装置を通行できるか否か判定する、付記1に記載の生体認証制御ユニット。
[付記4]
 前記被認証者検出部は、前記被認証者を検出すると、被認証者情報テーブルにエントリを追加し、
 前記要求部は、前記サーバ装置から前記生体認証の結果を受信すると、前記受信した生体認証の結果を前記追加されたエントリの認証ステータスフィールドに設定し、
 前記追跡制御部は、前記追跡結果を前記追加されたエントリの追跡ステータスフィールドに設定し、
 前記通知部は、前記認証ステータスフィールドの設定値と前記追跡ステータスフィールドの設定値に基づき、前記被認証者が前記ゲート装置を通行できるか否か判定する、付記1乃至3のいずれか一項に記載の生体認証制御ユニット。
[付記5]
 前記被認証者情報テーブルに追加されてから所定期間経過したエントリを削除する、テーブル管理部をさらに備える、付記4に記載の生体認証制御ユニット。
[付記6]
 前記生体情報は、顔画像又は顔画像から生成された特徴量である、付記1乃至5のいずれか一項に記載の生体認証制御ユニット。
[付記7]
 複数の利用者それぞれの生体情報を記憶し、生体認証を行うサーバ装置と、
 生体認証制御ユニット及び追跡ユニットが搭載されたゲート装置と、
 を含み、
 前記生体認証制御ユニットは、
 被認証者を検出し、前記検出された被認証者の生体情報を含む認証要求を前記サーバ装置に送信すると共に、前記追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信し、
 前記追跡ユニットは、
 前記追跡開始指示に含まれる位置情報に対応する場所に存在する人を追跡対象者に設定し、測距センサを用いて前記追跡対象者の追跡を行い、前記追跡対象者が前記ゲート装置に進入すると被認証者進入通知を前記生体認証制御ユニットに送信し、
 前記生体認証制御ユニットは、
 前記被認証者進入通知を受信すると、前記サーバ装置による認証結果に基づいて前記被認証者が前記ゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、システム。
[付記8]
 前記生体認証制御ユニットは、
 前記被認証者の位置情報と前記被認証者の被認証者IDを含む前記追跡開始指示を前記追跡ユニットに送信し、
 前記追跡ユニットは、
 前記追跡対象者の位置と前記被認証者IDを対応付けて管理し、前記追跡対象者が前記ゲート装置に進入したことに応じて追跡を完了すると、前記追跡を完了した追跡対象者の前記被認証者IDを前記生体認証制御ユニットに通知する、付記7に記載のシステム。
[付記9]
 前記生体認証制御ユニットは、
 前記検出された被認証者の生体情報と前記被認証者IDを含む認証要求を前記サーバ装置に送信し、
 前記サーバ装置は、認証対象者の前記被認証者IDを前記生体認証制御ユニットに通知する、付記8に記載のシステム。
[付記10]
 前記生体認証制御ユニットは、前記サーバ装置から通知された前記被認証者IDと前記追跡ユニットから通知された前記被認証者IDが一致する被認証者について前記ゲート装置を通行できるか否か判定する、付記9に記載のシステム。
[付記11]
 前記サーバ装置は、前記複数の利用者それぞれの生体情報と前記認証要求に含まれる生体情報を用いた照合処理を行う、付記7乃至10のいずれか一項に記載のシステム。
[付記12]
 前記サーバ装置は、前記照合処理により特定された利用者が前記ゲート装置を通行する資格を備えているか否か判定する、付記11に記載のシステム。
[付記13]
 前記測距センサは、3次元距離センサである、付記7乃至12のいずれか一項に記載のシステム。
[付記14]
 生体認証制御ユニットにおいて、
 被認証者を検出し、
 前記被認証者の生体情報を含む認証要求をサーバ装置に送信し、
 測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得し、
 前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、生体認証制御ユニットの制御方法。
[付記15]
 生体認証制御ユニットに搭載されたコンピュータに、
 被認証者を検出する処理と、
 前記被認証者の生体情報を含む認証要求をサーバ装置に送信する処理と、
 測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得する処理と、
 前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する処理と、
 を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
Some or all of the above embodiments may also be described in the following additional remarks, but are not limited to the following.
[Appendix 1]
an authenticated person detection unit for detecting an authenticated person;
a request unit that transmits an authentication request including the biometric information of the person to be authenticated to a server device;
a tracking control unit that transmits a tracking start instruction including position information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtains a tracking result from the tracking unit;
determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device notifying, a notification unit;
A biometric control unit.
[Appendix 2]
The tracking control unit receives from the tracking unit an authentication-subjected person entry notification indicating that the tracked person has entered the gate device,
The biometric authentication control unit according to supplementary note 1, wherein the notification unit determines whether or not the person to be authenticated can pass through a gate device in response to receiving the notification of entry of the person to be authenticated.
[Appendix 3]
The tracking control unit
after transmitting the tracking start instruction, transmitting a location inquiry including the subject ID to the tracking unit, obtaining location information of the tracked person corresponding to the subject ID from the tracking unit;
Supplementary Note 1: The notification unit determines whether the person-to-be-authenticated can pass through the gate device when the acquired position information of the tracked person indicates that the tracked person has entered the gate device. The biometric authentication control unit according to .
[Appendix 4]
When the authentication-subject detection unit detects the authentication-subject, the authentication-subject detection unit adds an entry to an authentication-subject information table,
When the request unit receives the biometric authentication result from the server device, the request unit sets the received biometric authentication result in an authentication status field of the added entry,
The tracking control unit sets the tracking result in a tracking status field of the added entry;
4. The notification unit according to any one of appendices 1 to 3, wherein the notification unit determines whether or not the person to be authenticated can pass through the gate device based on the set value of the authentication status field and the set value of the tracking status field. A biometric control unit as described.
[Appendix 5]
5. The biometric authentication control unit according to appendix 4, further comprising a table management unit that deletes an entry that has passed a predetermined period of time after being added to the authentication-subjected person information table.
[Appendix 6]
6. The biometric authentication control unit according to any one of appendices 1 to 5, wherein the biometric information is a facial image or a feature amount generated from the facial image.
[Appendix 7]
a server device that stores biometric information of each of a plurality of users and performs biometric authentication;
a gate device equipped with a biometric control unit and a tracking unit;
including
The biometric control unit,
A person to be authenticated is detected, an authentication request including biometric information of the detected person to be authenticated is transmitted to the server device, and a tracking start instruction including location information of the person to be authenticated is transmitted to the tracking unit. death,
The tracking unit is
A person existing at a location corresponding to the position information included in the tracking start instruction is set as a person to be tracked, the person to be tracked is tracked using a range sensor, and the person to be tracked enters the gate device. Then, a notification of entry of the person to be authenticated is transmitted to the biometric authentication control unit,
The biometric control unit,
A system for determining whether or not the person-to-be-authenticated can pass through the gate device based on the result of authentication by the server device upon receiving the notification of entry of the person-to-be-authenticated, and notifying the gate device of the determination result.
[Appendix 8]
The biometric control unit,
transmitting the tracking start instruction including the location information of the subject and the subject ID of the subject to the tracking unit;
The tracking unit is
When the position of the tracked person and the ID of the person to be authenticated are associated and managed, and when the tracking is completed in response to the entry of the tracked person into the gate device, the target of the tracked person who has completed the tracking is managed. 8. The system of claim 7, wherein an authenticator ID is communicated to the biometric control unit.
[Appendix 9]
The biometric control unit,
transmitting an authentication request including the detected biometric information of the person to be authenticated and the ID of the person to be authenticated to the server device;
The system according to appendix 8, wherein the server device notifies the biometric authentication control unit of the authenticated person ID of the person to be authenticated.
[Appendix 10]
The biometric authentication control unit determines whether or not a person to be authenticated whose ID of the person to be authenticated notified from the server device matches the ID of the person to be authenticated notified from the tracking unit can pass through the gate device. , Supplement 9.
[Appendix 11]
11. The system according to any one of appendices 7 to 10, wherein the server device performs matching processing using biometric information of each of the plurality of users and biometric information included in the authentication request.
[Appendix 12]
12. The system according to supplementary note 11, wherein the server device determines whether or not the user identified by the verification process is qualified to pass through the gate device.
[Appendix 13]
13. The system of any one of clauses 7-12, wherein the ranging sensor is a three-dimensional range sensor.
[Appendix 14]
In the biometric control unit,
detect the subject,
transmitting an authentication request including the biometric information of the person to be authenticated to a server device;
sending a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtaining a tracking result from the tracking unit;
determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device A method of controlling a biometrics control unit to notify.
[Appendix 15]
In the computer installed in the biometric control unit,
a process of detecting an authenticated person;
a process of transmitting an authentication request including the biometric information of the person to be authenticated to a server device;
A process of transmitting a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtaining a tracking result from the tracking unit;
determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device a notification process;
A computer-readable storage medium that stores a program for executing
 なお、引用した上記の先行技術文献の各開示は、本書に引用をもって繰り込むものとする。以上、本発明の実施形態を説明したが、本発明はこれらの実施形態に限定されるものではない。これらの実施形態は例示にすぎないということ、及び、本発明のスコープ及び精神から逸脱することなく様々な変形が可能であるということは、当業者に理解されるであろう。即ち、本発明は、請求の範囲を含む全開示、技術的思想にしたがって当業者であればなし得る各種変形、修正を含むことは勿論である。 It should be noted that each disclosure of the above cited prior art documents shall be incorporated into this document by citation. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will appreciate that these embodiments are illustrative only and that various modifications can be made without departing from the scope and spirit of the invention. That is, the present invention naturally includes various variations and modifications that can be made by those skilled in the art according to the entire disclosure including claims and technical ideas.
10   ゲート装置
10-1 ゲート装置
10-2 ゲート装置
10-3 ゲート装置
11   カメラ
12   検出センサ
13   ゲート
14   生体認証制御ユニット
15   追跡ユニット
16   測距センサ
20   サーバ装置
30   利用者
31   利用者
32   利用者
33   利用者
100  生体認証制御ユニット
101  被認証者検出部
102  要求部
103  追跡制御部
104  通知部
201  通信制御部
202  被認証者検出部
203  認証要求部
204  追跡制御部
205  通行許可通知部
206  テーブル管理部
207  メッセージ出力部
208  記憶部
301  通信制御部
302  追跡部
303  記憶部
311  プロセッサ
312  メモリ
313  通信インターフェイス
401  通信制御部
402  進入者検出部
403  ゲート制御部
404  記憶部
501  通信制御部
502  利用者登録部
503  認証部
504  ゲート通過通知処理部
505  記憶部
10 gate device 10-1 gate device 10-2 gate device 10-3 gate device 11 camera 12 detection sensor 13 gate 14 biometric authentication control unit 15 tracking unit 16 ranging sensor 20 server device 30 user 31 user 32 user 33 User 100 Biometric authentication control unit 101 Subject detection unit 102 Request unit 103 Tracking control unit 104 Notification unit 201 Communication control unit 202 Authentication subject detection unit 203 Authentication request unit 204 Tracking control unit 205 Pass permission notification unit 206 Table management unit 207 message output unit 208 storage unit 301 communication control unit 302 tracking unit 303 storage unit 311 processor 312 memory 313 communication interface 401 communication control unit 402 intruder detection unit 403 gate control unit 404 storage unit 501 communication control unit 502 user registration unit 503 Authentication unit 504 Gate passage notification processing unit 505 Storage unit

Claims (15)

  1.  被認証者を検出する、被認証者検出部と、
     前記被認証者の生体情報を含む認証要求をサーバ装置に送信する、要求部と、
     測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得する追跡制御部と、
     前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、通知部と、
     を備える、生体認証制御ユニット。
    an authenticated person detection unit for detecting an authenticated person;
    a request unit that transmits an authentication request including the biometric information of the person to be authenticated to a server device;
    a tracking control unit that transmits a tracking start instruction including position information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtains a tracking result from the tracking unit;
    determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device notifying, a notification unit;
    A biometric control unit.
  2.  前記追跡制御部は、前記追跡対象者が前記ゲート装置に進入したことを示す被認証者進入通知を前記追跡ユニットから受信し、
     前記被認証者進入通知が受信されたことに応じて、前記通知部は、前記被認証者がゲート装置を通行できるか否か判定する、請求項1に記載の生体認証制御ユニット。
    The tracking control unit receives from the tracking unit an authentication-subjected person entry notification indicating that the tracked person has entered the gate device,
    2. The biometric authentication control unit according to claim 1, wherein said notification unit determines whether said person to be authenticated can pass through a gate device in response to said person to be authenticated entry notification being received.
  3.  前記追跡制御部は、
     前記追跡開始指示を送信した後、前記被認証者IDを含む位置問い合わせを前記追跡ユニットに送信し、前記追跡ユニットから前記被認証者IDに対応する前記追跡対象者の位置情報を取得し、
     前記通知部は、前記取得した追跡対象者の位置情報が、前記追跡対象者が前記ゲート装置に進入したことを示す場合、前記被認証者がゲート装置を通行できるか否か判定する、請求項1に記載の生体認証制御ユニット。
    The tracking control unit
    after transmitting the tracking start instruction, transmitting a location inquiry including the subject ID to the tracking unit, obtaining location information of the tracked person corresponding to the subject ID from the tracking unit;
    The notification unit determines whether or not the person-to-be-authenticated can pass through the gate device when the acquired position information of the tracked person indicates that the tracked person has entered the gate device. 2. The biometric authentication control unit according to 1.
  4.  前記被認証者検出部は、前記被認証者を検出すると、被認証者情報テーブルにエントリを追加し、
     前記要求部は、前記サーバ装置から前記生体認証の結果を受信すると、前記受信した生体認証の結果を前記追加されたエントリの認証ステータスフィールドに設定し、
     前記追跡制御部は、前記追跡結果を前記追加されたエントリの追跡ステータスフィールドに設定し、
     前記通知部は、前記認証ステータスフィールドの設定値と前記追跡ステータスフィールドの設定値に基づき、前記被認証者が前記ゲート装置を通行できるか否か判定する、請求項1乃至3のいずれか一項に記載の生体認証制御ユニット。
    When the authentication-subject detection unit detects the authentication-subject, the authentication-subject detection unit adds an entry to an authentication-subject information table,
    When the request unit receives the biometric authentication result from the server device, the request unit sets the received biometric authentication result in an authentication status field of the added entry,
    The tracking control unit sets the tracking result in a tracking status field of the added entry;
    4. The notification unit determines whether or not the person to be authenticated can pass through the gate device based on the set value of the authentication status field and the set value of the tracking status field. The biometric authentication control unit according to .
  5.  前記被認証者情報テーブルに追加されてから所定期間経過したエントリを削除する、テーブル管理部をさらに備える、請求項4に記載の生体認証制御ユニット。 The biometric authentication control unit according to claim 4, further comprising a table management unit that deletes an entry that has passed a predetermined period of time after being added to the authentication-subjected person information table.
  6.  前記生体情報は、顔画像又は顔画像から生成された特徴量である、請求項1乃至5のいずれか一項に記載の生体認証制御ユニット。 The biometric authentication control unit according to any one of claims 1 to 5, wherein the biometric information is a facial image or a feature amount generated from the facial image.
  7.  複数の利用者それぞれの生体情報を記憶し、生体認証を行うサーバ装置と、
     生体認証制御ユニット及び追跡ユニットが搭載されたゲート装置と、
     を含み、
     前記生体認証制御ユニットは、
     被認証者を検出し、前記検出された被認証者の生体情報を含む認証要求を前記サーバ装置に送信すると共に、前記追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信し、
     前記追跡ユニットは、
     前記追跡開始指示に含まれる位置情報に対応する場所に存在する人を追跡対象者に設定し、測距センサを用いて前記追跡対象者の追跡を行い、前記追跡対象者が前記ゲート装置に進入すると被認証者進入通知を前記生体認証制御ユニットに送信し、
     前記生体認証制御ユニットは、
     前記被認証者進入通知を受信すると、前記サーバ装置による認証結果に基づいて前記被認証者が前記ゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、システム。
    a server device that stores biometric information of each of a plurality of users and performs biometric authentication;
    a gate device equipped with a biometric control unit and a tracking unit;
    including
    The biometric control unit,
    A person to be authenticated is detected, an authentication request including biometric information of the detected person to be authenticated is transmitted to the server device, and a tracking start instruction including location information of the person to be authenticated is transmitted to the tracking unit. death,
    The tracking unit is
    A person existing at a location corresponding to the position information included in the tracking start instruction is set as a person to be tracked, the person to be tracked is tracked using a range sensor, and the person to be tracked enters the gate device. Then, a notification of entry of the person to be authenticated is transmitted to the biometric authentication control unit,
    The biometric control unit,
    A system for determining whether or not the person-to-be-authenticated can pass through the gate device based on the result of authentication by the server device upon receiving the notification of entry of the person-to-be-authenticated, and notifying the gate device of the determination result.
  8.  前記生体認証制御ユニットは、
     前記被認証者の位置情報と前記被認証者の被認証者IDを含む前記追跡開始指示を前記追跡ユニットに送信し、
     前記追跡ユニットは、
     前記追跡対象者の位置と前記被認証者IDを対応付けて管理し、前記追跡対象者が前記ゲート装置に進入したことに応じて追跡を完了すると、前記追跡を完了した追跡対象者の前記被認証者IDを前記生体認証制御ユニットに通知する、請求項7に記載のシステム。
    The biometric control unit,
    transmitting the tracking start instruction including the location information of the subject and the subject ID of the subject to the tracking unit;
    The tracking unit is
    When the position of the tracked person and the ID of the person to be authenticated are associated and managed, and when the tracking is completed in response to the entry of the tracked person into the gate device, the target of the tracked person who has completed the tracking is managed. 8. The system of claim 7, wherein an authenticator ID is communicated to the biometric control unit.
  9.  前記生体認証制御ユニットは、
     前記検出された被認証者の生体情報と前記被認証者IDを含む認証要求を前記サーバ装置に送信し、
     前記サーバ装置は、認証対象者の前記被認証者IDを前記生体認証制御ユニットに通知する、請求項8に記載のシステム。
    The biometric control unit,
    transmitting an authentication request including the detected biometric information of the person to be authenticated and the ID of the person to be authenticated to the server device;
    9. The system according to claim 8, wherein said server device notifies said biometric authentication control unit of said person-to-be-authenticated ID of a person to be authenticated.
  10.  前記生体認証制御ユニットは、前記サーバ装置から通知された前記被認証者IDと前記追跡ユニットから通知された前記被認証者IDが一致する被認証者について前記ゲート装置を通行できるか否か判定する、請求項9に記載のシステム。 The biometric authentication control unit determines whether or not a person to be authenticated whose ID of the person to be authenticated notified from the server device matches the ID of the person to be authenticated notified from the tracking unit can pass through the gate device. 10. The system of claim 9.
  11.  前記サーバ装置は、前記複数の利用者それぞれの生体情報と前記認証要求に含まれる生体情報を用いた照合処理を行う、請求項7乃至10のいずれか一項に記載のシステム。 11. The system according to any one of claims 7 to 10, wherein said server device performs matching processing using biometric information of each of said plurality of users and biometric information included in said authentication request.
  12.  前記サーバ装置は、前記照合処理により特定された利用者が前記ゲート装置を通行する資格を備えているか否か判定する、請求項11に記載のシステム。 The system according to claim 11, wherein the server device determines whether or not the user specified by the verification process is qualified to pass through the gate device.
  13.  前記測距センサは、3次元距離センサである、請求項7乃至12のいずれか一項に記載のシステム。 The system according to any one of claims 7 to 12, wherein said ranging sensor is a three-dimensional distance sensor.
  14.  生体認証制御ユニットにおいて、
     被認証者を検出し、
     前記被認証者の生体情報を含む認証要求をサーバ装置に送信し、
     測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得し、
     前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する、生体認証制御ユニットの制御方法。
    In the biometric control unit,
    detect the subject,
    transmitting an authentication request including the biometric information of the person to be authenticated to a server device;
    sending a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtaining a tracking result from the tracking unit;
    determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device A method of controlling a biometrics control unit to notify.
  15.  生体認証制御ユニットに搭載されたコンピュータに、
     被認証者を検出する処理と、
     前記被認証者の生体情報を含む認証要求をサーバ装置に送信する処理と、
     測距センサを用いて追跡対象者を追跡する追跡ユニットに対し、前記被認証者の位置情報を含む追跡開始指示を送信すると共に、前記追跡ユニットから追跡結果を取得する処理と、
     前記サーバ装置による前記被認証者の生体認証の結果と、前記追跡ユニットによる前記追跡結果と、に基づいて前記被認証者がゲート装置を通行できるか否か判定し、判定結果を前記ゲート装置に通知する処理と、
     を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
    In the computer installed in the biometric control unit,
    a process of detecting an authenticated person;
    a process of transmitting an authentication request including the biometric information of the person to be authenticated to a server device;
    A process of transmitting a tracking start instruction including the location information of the person to be authenticated to a tracking unit that tracks the person to be tracked using a range sensor, and obtaining a tracking result from the tracking unit;
    determining whether or not the person to be authenticated can pass through the gate device based on the biometric authentication result of the person to be authenticated by the server device and the tracking result by the tracking unit, and sending the determination result to the gate device a notification process;
    A computer-readable storage medium that stores a program for executing
PCT/JP2021/031782 2021-08-30 2021-08-30 Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium WO2023032011A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/JP2021/031782 WO2023032011A1 (en) 2021-08-30 2021-08-30 Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium
JP2023544816A JPWO2023032011A5 (en) 2021-08-30 Biometric authentication control unit, system, and method and program for controlling a biometric authentication control unit

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2021/031782 WO2023032011A1 (en) 2021-08-30 2021-08-30 Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium

Publications (1)

Publication Number Publication Date
WO2023032011A1 true WO2023032011A1 (en) 2023-03-09

Family

ID=85410787

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2021/031782 WO2023032011A1 (en) 2021-08-30 2021-08-30 Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium

Country Status (1)

Country Link
WO (1) WO2023032011A1 (en)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2020086780A (en) * 2018-11-21 2020-06-04 日本電気株式会社 Information processing device
WO2021059537A1 (en) * 2019-09-27 2021-04-01 日本電気株式会社 Information processing device, terminal device, information processing system, information processing method, and recording medium

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2020086780A (en) * 2018-11-21 2020-06-04 日本電気株式会社 Information processing device
WO2021059537A1 (en) * 2019-09-27 2021-04-01 日本電気株式会社 Information processing device, terminal device, information processing system, information processing method, and recording medium

Also Published As

Publication number Publication date
JPWO2023032011A1 (en) 2023-03-09

Similar Documents

Publication Publication Date Title
US11749043B2 (en) Passive multi-factor access control with biometric and wireless capability
JP7075702B2 (en) Entry / exit authentication system and entry / exit authentication method
AU2024202070A1 (en) Gate device, authentication system, gate control method, and storage medium
WO2022064830A1 (en) Image processing device, image processing system, image processing method, and program
CN111462374A (en) Access control system including occupancy estimation
WO2023032011A1 (en) Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium
EP4089254A1 (en) Gate device, server device, immigration inspection system, method for controlling gate device, and method for controlling server device
JP2023153176A (en) Gate device, gate device control method, and program
JP2023153850A (en) Gate device, authentication system, gate device control method, and storage medium
JP2006099687A (en) User authentication device
WO2022149376A1 (en) Biometric authentication control unit, system, control method for biometric authentication control unit, and recording medium
JP2008052549A (en) Image processing system
WO2022234613A1 (en) System, gate device, control method for gate device, and storage medium
WO2022208640A1 (en) Gate device, biometric authentication control unit, system, gate device control method, and storage medium
WO2021172391A1 (en) Information processing device, face authentication system, and information processing method
WO2021191966A1 (en) Information processing device, information processing system, information processing method, and program
JPWO2022208640A5 (en)
JP2024147680A (en) Gate device, biometric authentication control unit, system, gate device control method and computer program
WO2024105721A1 (en) Passage control device, system, control method for passage control device, and storage medium
KR102538649B1 (en) Parking management method and apparatus based on occupant authentication
WO2024154430A1 (en) Person verifying system, information processing device, person verifying method, and person verifying program
WO2023176167A1 (en) Registration device, registration method, and program
EP4216180B1 (en) Trusted seamless authentication method for access control
KR20220165338A (en) A method, a system and an apparatus for providing payment services based on facility operation information by using facial recognitions

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21955907

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2023544816

Country of ref document: JP

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21955907

Country of ref document: EP

Kind code of ref document: A1