WO2023058225A1 - System, departure management server, departure management server control method, and storage medium - Google Patents

System, departure management server, departure management server control method, and storage medium Download PDF

Info

Publication number
WO2023058225A1
WO2023058225A1 PCT/JP2021/037353 JP2021037353W WO2023058225A1 WO 2023058225 A1 WO2023058225 A1 WO 2023058225A1 JP 2021037353 W JP2021037353 W JP 2021037353W WO 2023058225 A1 WO2023058225 A1 WO 2023058225A1
Authority
WO
WIPO (PCT)
Prior art keywords
user
server
country
information
management server
Prior art date
Application number
PCT/JP2021/037353
Other languages
French (fr)
Japanese (ja)
Inventor
伸明 川瀬
邦生 筆本
律子 中平
Original Assignee
日本電気株式会社
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 日本電気株式会社 filed Critical 日本電気株式会社
Priority to PCT/JP2021/037353 priority Critical patent/WO2023058225A1/en
Publication of WO2023058225A1 publication Critical patent/WO2023058225A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q50/00Systems or methods specially adapted for specific business sectors, e.g. utilities or tourism
    • G06Q50/10Services

Definitions

  • the present invention relates to a system, a departure management server, a departure management server control method, and a storage medium.
  • Patent Document 1 states that by using biometric information as a boarding pass, it is possible to eliminate the need to use (present) paper or mobile media, thereby improving user convenience and improving airport throughput. It is In Patent Literature 1, after selecting a menu for confirming a reservation or changing a flight, a check-in terminal reads biometric information, acquires the biometric information of the user, and searches the biometric information in the boarding server. If the matching of the biometric information is established, the reservation information is displayed and the flight is selected. Then, check-in is performed, and when "Confirm" is selected, the data in the host server is changed.
  • Patent Document 2 by automatically performing immigration control and check-in operations that are performed at airports and seaports where international flights depart and land, in a limited facility space, immigration related to a large number of passengers It is stated that security management and service operations will be carried out quickly and efficiently.
  • a user when traveling abroad, a user carries a smart passport card with an image, which is an IC card having a passport function, an air ticket or boarding ticket function, and a credit card function.
  • the user undergoes check-in or examination by sharing this image-attached smart passport card for security check and boarding or boarding check-in and departure examination or immigration examination.
  • JP 2007-079656 A Japanese Unexamined Patent Application Publication No. 2002-304448
  • the main purpose of the present invention is to provide a system, a departure management server, a control method for the departure management server, and a storage medium that contribute to reducing the burden on staff who are involved in departure work at airports and the like.
  • a departure management server that manages the departure of a user and stores health passport information regarding the health of said user who has booked an airline ticket; and verifies the entry requirements of each country; a verification server, wherein the departure management server transmits to the verification server an immigration requirements verification request including at least the health passport information of the user who performs check-in procedures, and the verification server receives the health passport information. verifies whether the user satisfies the entry requirements of the country of arrival into which the user enters, transmits the verification result to the departure management server, and the departure management server determines that the user is permitted to enter the country of arrival.
  • a system is provided that, if determined, issues a boarding pass to the user.
  • an immigration requirement including at least a storage unit for storing health passport information relating to health of a user who has reserved an airline ticket, and the health passport information of the user who performs check-in procedures a sending unit for sending a verification request to a verification server that verifies the entry requirements of each country; Provided by a departure management server, comprising: a receiving unit for receiving a verification result; be done.
  • the departure management server stores health passport information relating to the health of a user who has reserved an airline ticket, and an immigration management server that includes at least the health passport information of the user who performs check-in procedures.
  • a method for controlling a departure management server is provided for receiving and issuing a boarding pass to the user when the user is determined to be allowed to enter the arrival country.
  • a computer installed in a departure management server stores health passport information relating to the health of a user who has reserved an airline ticket; a process of transmitting an entry requirements verification request including at least health passport information to a verification server that verifies the entry requirements of each country; A program for executing a process of receiving a verification result regarding whether or not the requirements are satisfied, and a process of issuing a boarding pass to the user when the user is determined to be allowed to enter the country of arrival.
  • a computer-readable storage medium is provided for storing.
  • a system a departure management server, a control method for the departure management server, and a storage medium are provided that contribute to reducing the burden on staff who are in charge of departure work at an airport or the like.
  • the effect of this invention is not limited above. Other effects may be achieved by the present invention instead of or in addition to this effect.
  • FIG. 1 is a diagram for explaining an overview of one embodiment.
  • FIG. 2 is a diagram showing an example of a schematic configuration of the immigration control system according to the first embodiment.
  • FIG. 3 is a diagram illustrating an example of display on a terminal according to the first embodiment;
  • FIG. 4 is a diagram for explaining the operation of the immigration control system according to the first embodiment.
  • FIG. 5 is a diagram for explaining the operation of the immigration control system according to the first embodiment.
  • FIG. 6 is a diagram for explaining the operation of the immigration control system according to the first embodiment.
  • FIG. 7 is a diagram for explaining the operation of the immigration control system according to the first embodiment.
  • FIG. 8 is a diagram for explaining the operation of the immigration control system according to the first embodiment.
  • FIG. 1 is a diagram for explaining an overview of one embodiment.
  • FIG. 2 is a diagram showing an example of a schematic configuration of the immigration control system according to the first embodiment.
  • FIG. 3 is a diagram illustrating an example of display on a terminal according to
  • FIG. 9 is a diagram illustrating an example of a processing configuration of a reservation server according to the first embodiment
  • FIG. 10 is a diagram illustrating an example of display on a terminal according to the first embodiment
  • FIG. 11 is a diagram showing an example of a user information database according to the first embodiment
  • 12 is a diagram illustrating an example of a processing configuration of a departure management server according to the first embodiment
  • FIG. 13 is a diagram showing an example of a reservation person information database according to the first embodiment.
  • 14 is a flowchart illustrating an example of the operation of the boarding pass control unit according to the first embodiment
  • FIG. 15 is a diagram illustrating an example of a processing configuration of a verification server according to the first embodiment
  • FIG. 16 is a diagram showing an example of an entry requirement database according to the first embodiment.
  • 17 is a diagram illustrating an example of a processing configuration of an authentication server according to the first embodiment;
  • FIG. 18 is a diagram illustrating an example of a display on the terminal according to the first embodiment;
  • FIG. 19 is a diagram showing an example of an authenticated person information database according to the first embodiment.
  • 20 is a diagram illustrating an example of a processing configuration of a CIQ server according to the first embodiment;
  • FIG. 21 is a diagram illustrating an example of a processing configuration of a check-in terminal according to the first embodiment;
  • FIG. 22 is a diagram showing an example of display on the check-in terminal according to the first embodiment.
  • FIG. 23A and 23B are diagrams showing an example of a boarding pass according to the first embodiment.
  • 24 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment
  • FIG. 25 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment
  • FIG. 26 is a sequence diagram showing an example of the operation of the immigration control system according to the first embodiment
  • FIG. 27 is a diagram showing an example of a schematic configuration of an immigration control system according to the second embodiment.
  • FIG. 28 is a diagram illustrating an example of a processing configuration of a joint reservation server according to the second embodiment
  • FIG. 29 is a diagram for explaining the operation of air ticket reservation according to the second embodiment.
  • FIG. 30 is a diagram for explaining the operation of the immigration control system according to the second embodiment.
  • FIG. 31 is a diagram for explaining the operation of the immigration control system according to the second embodiment.
  • FIG. 32 is a sequence diagram showing an example of the operation of the immigration control system according to the second embodiment.
  • FIG. 33 is a diagram showing an example of a schematic configuration of an immigration control system according to the third embodiment.
  • FIG. 34 is a diagram for explaining the operation of air ticket reservation according to the third embodiment.
  • FIG. 35 is a diagram showing an example of a user information database according to the third embodiment.
  • FIG. 36 is a diagram for explaining the operation of the immigration control system according to the third embodiment.
  • FIG. 37 is a diagram for explaining the operation of the immigration control system according to the third embodiment.
  • FIG. 38 is a sequence diagram showing an example of the operation of the immigration control system according to the third embodiment.
  • FIG. 39 is a diagram showing an example of a hardware configuration of a departure management server according to the disclosure of the present application
  • a system includes a departure management server 101 and a verification server 102 (see FIG. 1).
  • the departure management server 101 manages departures of users and stores health passport information regarding the health of users who have reserved airline tickets.
  • Validation server 102 validates the entry requirements of each country.
  • the departure management server 101 transmits to the verification server 102 an immigration requirement verification request including at least the health passport information of the user who performs the check-in procedure.
  • the verification server 102 verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server 101 .
  • the departure management server 101 issues a boarding pass to the user when it is determined that the user can enter the country of arrival.
  • the departure management server 101 When the departure management server 101 issues a boarding pass to a person departing from the airport, it requests the verification server 102 to verify whether the person can enter the country of arrival.
  • the verification server 102 stores the immigration requirements of each country and performs requested verification.
  • the departure management server 101 issues a boarding pass to the departing person when it is confirmed that the departing person can enter the arrival country.
  • Airport departure personnel do not need to check the entry requirements of countries around the world and verify the entry requirements for each person leaving the country. As a result, the burden on the staff concerned is reduced.
  • FIG. 2 is a diagram showing an example of a schematic configuration of an immigration control system (information processing system) according to the first embodiment.
  • the immigration control system includes a reservation server 10 , an authentication server 20 and a verification server 30 .
  • the departure airport includes the departure management server 40, check-in terminal 50, and authentication terminal 51-1.
  • the arrival airport includes a CIQ (Customs Immigration Quarantine) server 60 and an authentication terminal 51-2.
  • CIQ Customers Immigration Quarantine
  • the authentication terminal 51-1 and the authentication terminal 51-2 are simply referred to as "authentication terminal 51" unless there is a particular reason to distinguish them.
  • other elements are represented by the symbols on the left side of the hyphen.
  • the reservation server 10 is a server that implements an airline reservation system. Each airline manages and operates its own reservation server 10 .
  • the reservation server 10 implements the main functions of a reservation system called PSS (Passenger Service System).
  • PSS Passenger Service System
  • the reservation server 10 is installed in facilities of an airport company, an airline company, or the like. Alternatively, the reservation server 10 may be a server installed in the cloud on the network.
  • the authentication server 20 is a server that authenticates users who use the airport.
  • the user can proceed with procedures in the airport by presenting a paper boarding pass or passport to a staff member or the like, or can proceed with biometric authentication.
  • the authentication server 20 provides a biometric authentication service using user's biometric information (for example, face image).
  • a predetermined procedure is required to use biometric authentication, and users who have completed the procedure can proceed with various procedures (services) at the airport using biometric authentication.
  • the authentication server 20 is installed in a facility such as an airport company. Alternatively, the authentication server 20 may be a server installed in the cloud on the network.
  • the verification server 30 verifies the entry requirements of each country. More specifically, verification server 30 verifies (confirms) the entry requirements of the country of arrival of the aircraft. Validation server 30 implements a database function called TIMATIC, which can look up documents required for entry into the country of arrival. TIMATIC is managed and operated by IATA (International Air Transport Association). The verification server 30 is installed in the facility of the association. Alternatively, verification server 30 may be a server located in a cloud on a network.
  • the departure management server 40 is installed at the departure airport.
  • the departure management server 40 is a server that manages departures of users. More specifically, the departure management server 40 implements the main functions of an airport check-in system called DCS (Departure Control System).
  • DCS Departure Control System
  • the departure management server 40 is installed at each airport by each airline company. Therefore, although FIG. 2 shows the departure management server 40 installed at the departure airport, the departure management server 40 may actually be a server installed on the cloud.
  • the check-in terminal 50 is a terminal that provides check-in services to users.
  • the check-in terminal 50 issues a boarding pass to the user who has reserved the airline ticket.
  • the boarding pass issued by the check-in terminal 50 includes a paper boarding pass and an electronic boarding pass (for example, a boarding pass converted into a two-dimensional code).
  • the authentication terminal 51 is a terminal that is installed at the airport of departure and the airport of arrival and provides predetermined services. More specifically, the authentication terminal 51 provides services to users who have successfully passed biometric authentication.
  • the authentication terminal 51-1 has a gate and is installed at the boarding gate.
  • the authentication terminal 51-1 installed at the boarding gate permits the passage of the user who has a valid passport and boarding pass.
  • the authentication terminal 51-1 is a baggage deposit machine.
  • An authentication terminal 51-1 that operates as a baggage check-in machine is installed in an area adjacent to the baggage counter (manned counter) or in the vicinity of the check-in terminal 50 in the airport.
  • the authentication terminal 51-1 is a self-service terminal that is operated by the user to carry out procedures for checking in baggage that is not carried into the aircraft (baggage check-in procedure).
  • the authentication terminal 51-2 installed at the arrival airport is installed at the immigration office and permits passage (entry into the country) of users who have valid passports.
  • the authentication terminal 51 is an arbitrary terminal that provides services to users who have successfully passed biometric authentication.
  • the authentication terminal 51 is illustrated as a gate device having a gate.
  • the CIQ server 60 is installed at the arrival airport and performs processing related to customs, immigration control, and quarantine when the user enters the country.
  • the CIQ server 60 distributes necessary information regarding quarantine inspections of immigrants to government agencies such as customs.
  • the terminal 70 is a mobile terminal such as a smart phone, mobile phone, or tablet.
  • the terminal 70 may be an information processing terminal such as a personal computer or a notebook computer.
  • Each device (reservation server 10, authentication server 20, verification server 30, departure management server 40, etc.) shown in FIG. 2 is configured to be able to communicate with each other via a network.
  • the reservation server 10 and the departure management server 40 are connected by wired or wireless communication means, and are configured to be able to communicate with each other.
  • FIG. 2 is an example and is not intended to limit the configuration of the immigration control system disclosed in the present application.
  • the immigration control system may include two or more authentication servers 20 and verification servers 30 .
  • one reservation server 10 is shown in FIG. 2, the system actually includes a plurality of reservation servers 10 managed and operated by each airline company.
  • the illustration of the departure management server 40 is omitted at the arrival airport and the illustration of the CIQ server 60 is omitted at the departure airport, but in reality these servers are installed corresponding to each airport. be done.
  • a user installs an application for realizing a digital wallet on the terminal 70 that the user possesses. For example, by creating a digital wallet on the terminal 70, the user can use electronic money, identification cards such as passports and driver's licenses, various ticket information such as airline tickets and boarding passes, vaccination certificates and negative certificates. (Common Pass) and other certificates are stored in the terminal 70 .
  • identification cards such as passports and driver's licenses
  • ticket information such as airline tickets and boarding passes, vaccination certificates and negative certificates. (Common Pass) and other certificates are stored in the terminal 70 .
  • the user's terminal 70 stores digital information as shown in FIG.
  • public identification documents such as passports, driver's licenses, health certificates (certificates related to infectious diseases) such as vaccination certificates, negative certificates, and recovery certificates are stored in the digital wallet. .
  • Vaccination certificate includes name, date of birth, passport number, vaccine type, manufacturer, product name, production number, date of vaccination, country of vaccination, certificate issuer, certificate ID, certificate Information such as the date of issue, the expiration date of the vaccine, and the number of vaccinations is included.
  • the negative certificate includes the subject's name, date of birth, passport number, sex, test method, collected sample, result, sample collection date, result date, test certificate issuance date, medical institution name, medical institution Information such as address, doctor name, medical institution seal impression, negative certificate expiration date, etc. is included.
  • the recovery certificate includes the subject's name, date of birth, passport number, gender, test method, sample collected, result (positive), date and time of sample collection, date of result determination, date of test certificate issuance, test medical institution Information such as the name, address of the examination medical institution, name of the examination doctor, seal imprint of the examination medical institution, etc. is included. Furthermore, the recovery certificate includes information such as the name of the medical institution, the address of the medical institution, the name of the doctor, the imprint/signature of the medical institution, etc., related to the certificate of healing.
  • FIG. 3 shows an example of three health passport information stored in a digital wallet.
  • the health passport information may be a digital certificate or image data (a copy of the certificate) obtained by taking a picture of a paper certificate.
  • the health passport information may be a two-dimensional code obtained by converting the content described in a vaccination certificate or the like.
  • the terminal 70 stores the user ID and biometric information of the user in the digital wallet in addition to the vaccination certificate. For example, the user operates the terminal 70 to photograph his/her own face.
  • the terminal 70 stores the facial image or the feature amount generated from the facial image as the biometric information of the user.
  • biometric information examples include data (feature amounts) calculated from physical features unique to individuals, such as faces, fingerprints, voiceprints, veins, retinas, and iris patterns.
  • the biometric information may be image data such as a face image or a fingerprint image.
  • the biometric information should just contain a user's physical characteristic as information. In the disclosure of the present application, a case of using biometric information (a face image or a feature amount generated from the face image) regarding a person's “face” will be described.
  • Air ticket reservation> A user who travels across countries reserves an airline ticket (see FIG. 4). The user accesses the reservation server 10 of the airline company to use and reserves an airline ticket. For example, the user operates the terminal 70 to access the homepage provided by the reservation server 10 and reserve an airline ticket.
  • the terminal 70 inputs information on the passport (hereinafter referred to as passport information) and health passport information to the reservation server 10.
  • passport information includes a passport face image, name, gender, nationality, passport number, passport issuing country, and the like.
  • the passport information may be image data (a copy of the passport) obtained by photographing the passport.
  • the reservation server 10 When a user reserves an aircraft, the reservation server 10 issues an airline ticket.
  • the reservation server 10 issues paper airline tickets or electronic airline tickets.
  • an electronic medium airline ticket for example, a two-dimensional code converted from airline ticket information
  • information about the airline ticket hereinafter referred to as airline ticket information
  • Airline ticket information includes airline code, flight number, departure date, departure time, destination (arrival airport), seat type, etc.
  • the terminal 70 stores the issued airline ticket (airline ticket information) in a digital wallet.
  • the user may operate the terminal 70 to take an image of the airline ticket and store the acquired image data in the digital wallet.
  • a reservation number will be issued.
  • the ticket includes reservation information (the information on the ticket and the reservation information are the same).
  • a predetermined time before departure for example, 24 hours before
  • a boarding pass is issued. That is, the airline ticket is issued at the time of reservation, and the boarding pass is issued after the check-in procedure is completed.
  • the reservation server 10 associates passport information, health passport information, and airline ticket information and stores them in the user information database. Details of the user information database will be described later.
  • the reservation server 10 stores the acquired passport information and the like as a PNR (Passenger Name Record).
  • a PNR is a reservation record of an airline ticket by a user, and includes information such as the user's name, nationality, reserved flight number, and the like.
  • a user's airline ticket reservation record is transferred from the reservation server 10 to the departure management server 40 a predetermined time before the departure of the reserved aircraft (see FIG. 5). Specifically, 24 hours before departure of an aircraft, passport information, airline ticket information, and health passport information regarding each passenger (a plurality of passengers) who have reserved the aircraft are sent to the departure management server 40 .
  • the reservation server 10 transmits the PNR of the set of passengers of the aircraft to the departure management server 40 as a PNL (Passenger Name List).
  • the reservation server 10 transmits the health passport information to the departure management server 40 using DOCO (Document Other; definition of additional information to be added to SSR) of SSR (Special Service Requirement), which is an additional information format of PNR.
  • DOCO Document Other; definition of additional information to be added to SSR
  • SSR Service Requirement
  • information is defined by giving a four letter prefix with the information added to the PNR.
  • prefixes such as "DOCH" and "HLCT” may be defined.
  • the latest airline ticket reservation record is sent to the departure management server 40 using the ADL (Additions/Deletions List).
  • the departure management server 40 stores the acquired airline ticket reservation record in the reservation person information database. The details of the reservation person information database will be described later.
  • the reservation server 10 transmits at least the health passport information of the user who reserved the airline ticket to the departure management server 40 a predetermined time before the departure of the aircraft corresponding to the reserved airline ticket.
  • the check-in terminal 50 acquires the user's biometric information, passport information, and airline ticket information.
  • the check-in terminal 50 performs biometric authentication (for example, one-to-one authentication) using the obtained biometric information (face image obtained by photographing) and the face image written on the passport.
  • biometric authentication for example, one-to-one authentication
  • the check-in terminal 50 transmits a "boarding pass request" including the passport information and airline ticket information of the user to the departure management server 40 (step S1).
  • the departure management server 40 Upon receiving the request, the departure management server 40 identifies the user who will be checking in from the passport information, and issues a boarding pass for the identified user. Specifically, the departure management server 40 determines whether or not the airline ticket information acquired from the check-in terminal 50 is stored in the reservation person information database.
  • the departure management server 40 sends an "immigration requirements verification request" including at least information about the user's arrival airport (for example, airport code), the user's passport information and health passport information. to the verification server 30 (step S2).
  • the verification server 30 processes the entry requirements verification request. Specifically, the verification server 30 verifies (examines) whether or not the user satisfies the entry requirements of the country of arrival using the user's passport information, health passport information, and the like.
  • the verification server 30 sends a response including the verification result (entry permitted, entry denied) to the departure management server 40 (step S3).
  • Validation server 30 may send details regarding the validation of entry requirements to departure control server 40 .
  • the departure management server 40 issues a boarding pass for the user if the user's immigration verification result is "permitted to enter”.
  • the departure management server 40 determines the seat of the user and issues a boarding pass.
  • the departure management server 40 transmits a response including information on the issued boarding pass (hereinafter referred to as boarding pass information) to the check-in terminal 50 (step S4).
  • boarding pass information includes name (surname, first name), airline code, flight number, boarding date, departure point (boarding airport), destination (arrival airport), seat number, boarding time, arrival time, and the like.
  • the departure management server 40 may send health passport information to the check-in terminal 50 in addition to the boarding pass information, or may send details regarding verification of entry requirements to the check-in terminal 50 .
  • the check-in terminal 50 issues a boarding pass based on the acquired boarding pass information.
  • the check-in terminal 50 issues a paper boarding pass or an electronic boarding pass.
  • an electronic boarding pass for example, a two-dimensional code converted from the boarding pass information
  • the user operates the terminal 70 to read the two-dimensional code and read the issued boarding pass.
  • the user may store the boarding pass in the digital wallet by taking a picture of the paper boarding pass.
  • the issued boarding pass may include the details of the verification result by the verification server 30. For example, information such as "health passport information: OK” and “negative certificate: OK" may be written on the boarding pass.
  • the departure management server 40 transmits a "passenger information notification" including passport information and health passport information to the CIQ server 60 of the arrival country (step S5). More specifically, the departure management server 40 uses iAPI (Interactive API; an interactive API (Application Programming Interface), an API that enables two-way information exchange between the government of the arrival country and the airline). Send the information to the CIQ server 60 .
  • Passenger information also called APIS (Advance Passenger Information System), is information sent in advance from the airline to the government of the arrival country.
  • the departure management server 40 transmits to the verification server 30 an immigration requirements verification request that includes at least the health passport information of the user who performs the check-in procedure.
  • the verification server 30 verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server 40 .
  • the departure management server 40 issues a boarding pass to the user when it is determined that the user can enter the country of arrival.
  • the check-in terminal 50 transmits to the departure management server 40 a boarding pass issuance request including airline ticket information related to the airline ticket reserved (purchased) by the user.
  • the departure management server 40 transmits boarding pass information related to the issued boarding pass to the check-in terminal 50 when it is determined that the airline ticket information is valid and that the user can enter the country of arrival.
  • Biometric authentication use registration> When the boarding pass is issued, the user can register for use in order to proceed with procedures at the airport using biometric authentication (see FIG. 7). It should be noted that whether or not to proceed with the procedure using biometric authentication is an option, and is a matter for each user to decide.
  • a user who wishes to be provided with a service using biometric authentication operates the terminal 70, accesses the authentication server 20, and registers for use of biometric authentication.
  • the user operates the terminal 70 to access the homepage provided by the authentication server 20 and register for use of biometric authentication.
  • the user inputs biometric information, passport information, boarding pass information, and health passport information stored in the digital wallet into the authentication server 20.
  • the authentication server 20 associates the acquired biometric information, passport information, boarding pass information, and health passport information and stores them in the authenticated person information database. Details of the authenticated person information database will be described later.
  • a user who has completed registration for use of biometric authentication can proceed with procedures at the airport using biometric authentication (see FIG. 8). Specifically, when the user arrives at the authentication terminal 51, the authentication terminal 51 acquires the biometric information of the user (person to be authenticated). The authentication terminal 51 transmits an authentication request including the biometric information of the user and the terminal ID to the authentication server 20 .
  • the terminal ID is an ID for identifying the authentication terminal 51 installed in various places in the airport.
  • the MAC (Media Access Control) address or IP (Internet Protocol) address of the authentication terminal 51 can be used as the terminal ID.
  • the terminal ID is shared between the authentication server 20 and the authentication terminal 51 by any method. For example, a system administrator determines a terminal ID and sets the determined terminal ID in the authentication server 20 . Also, the system administrator sets the determined terminal ID to the authentication terminal 51 .
  • the authentication server 20 identifies the type of the authentication terminal 51 that is the source of the authentication request based on the terminal ID included in the authentication request (identifies the function of the authentication terminal 51).
  • the authentication server 20 acquires requirements for the authentication terminal 51 to provide services to the user based on the type of the authentication terminal 51 . For example, if the authentication terminal 51 is a gate device installed at a boarding gate, the authentication server 20 acquires the requirements for passing through the gate device (for example, the user possesses a valid passport and boarding pass). .
  • the authentication server 20 identifies the user through biometric authentication using the acquired biometric information and the biometric information stored in the authenticated person information database.
  • the authentication server 20 determines whether or not the service can be provided to the user based on each information (passport information, boarding pass information, health passport information) of the specified user and the requirements of the specified authentication terminal 51. .
  • the authentication terminal 51 determines that the service can be provided to the user, it sets the authentication result to "authentication success”. If the authentication terminal 51 determines that the service cannot be provided to the user, the authentication terminal 51 sets the authentication result to "authentication failure".
  • the authentication server 20 notifies the authentication terminal 51 of the authentication result (authentication success, authentication failure).
  • the authentication terminal 51 provides services to users who have succeeded in authentication, and does not provide services to users who have failed in authentication.
  • the departure management server 40 may notify the details of the verification result of the verification server 30 regarding the user to the terminal possessed by the staff working in the airport.
  • Terminals carried by staff may display information such as "health passport information: OK” and "negative certificate: OK" for each user. Employees exposed to such information will be able to proceed smoothly with their work if it is necessary to verify the health passport information.
  • the user is identified by a passport or the like possessed by the user instead of biometric information.
  • the authentication server 20 stores at least the first biometric information of the user.
  • the authentication terminal 51 acquires the second biometric information of the user and transmits an authentication request including the acquired biometric information to the authentication server 20 .
  • the authentication server 20 performs biometric authentication using the first biometric information and the second biometric information, and transmits the authentication result to the authentication terminal 51 .
  • the authentication terminal 51 provides services to users who have successfully authenticated.
  • the reservation server 10 is a server that realizes airline ticket reservations by users.
  • the reservation server 10 stores at least health passport information of the user (the user who purchased the airline ticket).
  • FIG. 9 is a diagram showing an example of the processing configuration (processing modules) of the reservation server 10 according to the first embodiment.
  • reservation server 10 includes communication control section 201 , reservation control section 202 , reservation record transmission section 203 , and storage section 204 .
  • the communication control unit 201 is means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the terminal 70 . Also, the communication control unit 201 transmits data to the terminal 70 . The communication control unit 201 transfers data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 201 .
  • the communication control unit 201 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the reservation control unit 202 is means for controlling air ticket reservations by users.
  • the reservation control unit 202 displays a GUI (Graphical User Interface) or the like for reserving an airline ticket on the terminal 70. do.
  • GUI Graphic User Interface
  • the reservation control unit 202 displays a GUI as shown in FIG.
  • the reservation control unit 202 uses a GUI as shown in FIG. 10 to obtain information on a flight for which the user wishes to make a reservation.
  • the reservation control unit 202 acquires the user's passport information and health passport information.
  • the user operates the terminal 70 to select passport information and health passport information (at least one of vaccination certificate, negative certificate and recovery certificate) stored in the digital wallet.
  • the reservation control unit 202 issues an airline ticket when the "Confirm" button is pressed.
  • the reservation control unit 202 generates airline ticket information according to the user's selection and transmits it to the terminal 70 .
  • the airline ticket information may be a text file containing the contents of the issued airline ticket, or a two-dimensional code containing the contents of the airline ticket (in which the contents of the airline ticket are converted).
  • the reservation control unit 202 associates the user's passport information, health passport information, and airline ticket information and stores them in the user information database (see FIG. 11).
  • the user information database includes passport information fields, airline ticket information fields, and health passport information fields.
  • the user information database shown in FIG. 11 is an example, and is not meant to limit the items to be stored.
  • health passport information that the user does not possess is indicated using "hyphens”.
  • the reservation record transmission unit 203 is means for transmitting the user's airline ticket reservation record to the departure management server 40 .
  • the reservation record transmission unit 203 accesses the user information database regularly or at a predetermined timing.
  • the reservation record transmission unit 203 checks the airline ticket information field (departure time field) of each entry, and extracts an aircraft (flight number) that departs after a predetermined time (for example, 24 hours) from the current time.
  • the reservation record transmission unit 203 collects the extracted entries for each aircraft (flight, flight number) and transmits them to the departure management server 40 .
  • the reservation record transmission unit 203 transmits the passport information, airline ticket information, and health passport information of each user who has reserved an aircraft to depart after the elapse of a predetermined time as an "airline ticket reservation record" to the departure management server 40 .
  • the storage unit 204 is means for storing information necessary for the operation of the reservation server 10.
  • a user information database is constructed in the storage unit 204 .
  • the departure management server 40 manages the departure of the user and stores at least the health passport information regarding the health of the user who has reserved the airline ticket.
  • FIG. 12 is a diagram showing an example of the processing configuration (processing modules) of the departure management server 40 according to the first embodiment.
  • departure management server 40 includes communication control section 301 , reservation record control section 302 , boarding pass control section 303 , and storage section 304 .
  • the communication control unit 301 is means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the verification server 30 . Also, the communication control unit 301 transmits data to the verification server 30 . The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301 .
  • the communication control unit 301 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the reservation record control unit 302 is means for controlling air ticket reservation records (passport information, airline ticket information, health passport information) transmitted from the reservation server 10 .
  • the reservation recording control unit 302 acquires the passport information and the like from the reservation server 10, the acquired information is registered in the reservation person information database (see FIG. 13).
  • the reservation person information database includes a passport information field, an airline ticket information field, a health passport information field, and a boarding pass information field. Note that the reservation person information database shown in FIG. 13 is an example, and is not meant to limit the items to be stored.
  • the boarding pass control unit 303 is means for controlling the issuance of boarding passes.
  • the operation of the boarding pass control unit 303 will be described with reference to FIG.
  • FIG. 14 is a flow chart showing an example of the operation of the boarding pass control unit 303 according to the first embodiment.
  • the boarding pass control unit 303 receives a "boarding pass issuance request" from the check-in terminal 50 (step S101).
  • the boarding pass control unit 303 searches the reservation person information database using the passport number of the passport information included in the request as a key, and tries to identify the corresponding user (searches the reservation person information database (DB; Data Base); step S102).
  • the boarding pass control unit 303 sets the processing result to prohibit the issuance of a boarding pass (step S104).
  • the boarding pass control unit 303 determines whether the airline ticket information in the corresponding entry matches the airline ticket information included in the boarding pass issuance request. Determine (verification of airline ticket information; step S105). That is, the boarding pass control unit 303 determines whether or not the airline ticket (pre-reserved aircraft) registered in the reservation person information database matches the airline ticket obtained from the check-in terminal 50 .
  • step S106 If the airline ticket information does not match (step S106, No branch), the boarding pass control unit 303 sets the processing result to prohibit issuance of a boarding pass (step S104).
  • step S106 If the airline ticket information matches (step S106, Yes branch), the boarding pass control unit 303 sends to the verification server 30 an "immigration requirements verification request" including the passport information and health passport information of the user specified by the above search. Send (step S107)
  • the boarding pass control unit 303 receives the verification result (entry permitted, entry denied) from the verification server 30 (step S108).
  • the boarding pass control unit 303 receives a response (positive response, negative response) to the entry requirements verification request from the verification server 30 .
  • step S109 If the verification result is "impossible to enter the country" (step S109, No branch), the boarding pass control unit 303 sets the processing result to prohibit issuance of a boarding pass (step S104).
  • step S109 If the verification result is "permitted to enter the country" (step S109, Yes branch), the boarding pass control unit 303 sets the processing result to permit issuance of a boarding pass (step S110).
  • the boarding pass control unit 303 issues a boarding pass (step S111).
  • the boarding pass control unit 303 refers to the seat type or the like described in the airline ticket information, determines the seat of the user, and issues a boarding pass (boarding pass information).
  • the boarding pass control unit 303 registers the generated boarding pass information (boarding pass information) in the reservation person information database.
  • the boarding pass control unit 303 transmits the processing result (boarding pass issuable or not) to the check-in terminal 50 (step S112).
  • the boarding pass control unit 303 notifies the check-in terminal 50 that a boarding pass cannot be issued. Specifically, the boarding pass control unit 303 transmits to the check-in terminal 50 a negative response indicating that the boarding pass cannot be issued.
  • the boarding pass control unit 303 notifies the check-in terminal 50 of the issued boarding pass (boarding pass information). Specifically, the boarding pass control unit 303 transmits to the check-in terminal 50 an affirmative response indicating that the boarding pass has been successfully issued. At that time, the boarding pass control unit 303 transmits an acknowledgment including the boarding pass information to the check-in terminal 50 .
  • the boarding pass control unit 303 may send a response (positive response, negative response) including the details to the check-in terminal 50.
  • the boarding pass control unit 303 notifies the CIQ server 60 of the arrival country of the information of the user who issued the boarding pass. Specifically, the boarding pass control unit 303 transmits a "passenger information notification" including the user's passport information and health passport information to the CIQ server 60 (step S113).
  • the boarding pass control unit 303 realizes the user's check-in procedure, and when the boarding pass is successfully issued, notifies the check-in terminal 50 of the boarding pass information related to the boarding pass. At that time, when the verification server 30 acquires the detailed information regarding the verification of the entry requirements, the boarding pass control section 303 may notify the check-in terminal 50 of the detailed information regarding the verification of the entry requirements. The check-in terminal 50 may issue a boarding pass with detailed information regarding verification of entry requirements.
  • the boarding pass control unit 303 is installed in the arrival airport of the arrival country, and the CIQ server 60 that performs processing related to customs, immigration control, and quarantine when the user enters the country.
  • Send information (including passport information, health passport information).
  • the passenger information By sending the passenger information to the CIQ server 60 by the boarding pass control unit 303, information cooperation with government agencies is realized.
  • the storage unit 304 is means for storing information necessary for the operation of the departure management server 40 .
  • a reservation person information database is constructed in the storage unit 304 .
  • FIG. 15 is a diagram showing an example of a processing configuration (processing modules) of the verification server 30 according to the first embodiment.
  • verification server 30 includes communication control section 401 , immigration requirement verification section 402 , and storage section 403 .
  • the communication control unit 401 is means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the departure management server 40 . The communication control unit 401 also transmits data to the departure management server 40 . The communication control unit 401 transfers data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 401 .
  • the communication control unit 401 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the entry requirements verification unit 402 is a means of verifying the entry requirements of travelers.
  • the entry requirements verification unit 402 processes the entry requirements verification request received from the departure management server 40 .
  • the entry requirements verification unit 402 refers to the entry requirements database and processes the entry requirements verification request.
  • FIG. 16 is a diagram showing an example of the entry requirement database according to the first embodiment.
  • the entry requirements database stores entry requirements by country (by airport code). Entry requirements include entry requirements for passport information and entry requirements for health passport information. Note that the immigration requirement database shown in FIG. 16 is an example, and is not meant to limit the items to be stored.
  • the entry requirements verification unit 402 refers to the entry requirements database and reads the entry requirements corresponding to the information on the arrival airport (airport code) included in the entry requirements verification request.
  • the entry requirements verification unit 402 uses the read entry requirements and the passport information and health passport information included in the entry requirements verification request to determine whether the traveler satisfies the entry requirements of the arrival country.
  • the entry requirements verification unit 402 uses the nationality of the passport information to determine whether the entry requirements of the arrival country are met. Alternatively, the entry requirements verification unit 402 determines whether or not the user possesses the type of health passport information specified by the arrival country. For example, if the arrival country stipulates possession of a valid "vaccination certificate” or "negative certificate” as entry requirements, the entry requirements verification unit or "negative certificate” is included. In other words, the entry requirements verification unit 402 does not determine that the entry requirements of the destination country are satisfied even if the entry requirements verification request includes a valid "recovery certificate".
  • the immigration requirements verification unit 402 determines that even a valid vaccination certificate or a valid negative certificate does not meet the entry requirements if it has not been tested with the vaccine or method required by the country of arrival.
  • the entry requirements verification unit 402 notifies the departure management server 40 of the verification result (entry permitted, entry denied). If it is determined that the entry requirements are satisfied, the entry requirements verification unit 402 transmits to the departure management server 40 a positive response indicating that the traveler is permitted to enter the country. If it is determined that the entry requirements are not met, the entry requirements verification unit 402 sends a negative response to the departure management server 40 indicating that the traveler is not allowed to enter the country.
  • the immigration requirement verification unit 402 may notify the departure management server 40 of details regarding the verification of entry requirements. For example, when the immigration requirement verification unit 402 determines that the entry is not allowed, it notifies the departure management server 40 of the factors that led to the determination. For example, the entry requirements verification unit 402 notifies the departure management server 40 of detailed information such as "I do not have a valid vaccination certificate" and "The test method for the negative certificate does not meet the entry requirements".
  • the entry requirement verification unit 402 may notify the departure management server 40 of the details of all or part of the entry requirements subject to the determination. For example, regarding the health passport information, the immigration requirement verification unit 402 indicates that "there is no problem with the verification of the vaccination certificate (vaccination certificate: OK)" and "there is no problem with the verification of the negative certificate (negative certificate: OK)”. ” to the departure management server 40 .
  • the immigration requirements verification unit 402 may send a positive response or a negative response including details regarding the verification result of the immigration requirements to the departure management server 40 .
  • the storage unit 403 is means for storing information necessary for the operation of the verification server 30 .
  • An entry requirements database is constructed in the storage unit 403 .
  • FIG. 17 is a diagram showing an example of the processing configuration (processing modules) of the authentication server 20 according to the first embodiment.
  • the authentication server 20 includes a communication control section 501 , a usage registration control section 502 , an authentication section 503 and a storage section 504 .
  • the communication control unit 501 is means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the authentication terminal 51 . Also, the communication control unit 501 transmits data to the authentication terminal 51 . The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 501 .
  • the communication control unit 501 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the use registration control unit 502 is means for controlling the user's biometric authentication use registration.
  • the usage registration control unit 502 displays a GUI for acquiring information for realizing biometrics authentication of the user. etc. are displayed on the terminal 70 .
  • the usage registration control unit 502 displays a GUI as shown in FIG.
  • the use registration control unit 502 acquires the user's biometric information, passport information, boarding pass information, and health passport information through a GUI as shown in FIG.
  • the use registration control unit 502 acquires a face image as biometric information
  • the use registration control unit 502 generates a feature amount from the face image.
  • the usage registration control unit 502 stores the acquired biometric information in the authenticated person information database (see FIG. 19).
  • FIG. 19 is a diagram showing an example of an authenticated person information database according to the first embodiment. As shown in FIG. 19, the authenticated person information database stores the biometric information (feature amount) of the authenticated person, passport information, boarding pass information, and health passport information in association with each other. Note that the authentication-subjected person information database shown in FIG. 19 is an example, and is not intended to limit the items to be stored.
  • the authentication unit 503 is means for performing biometric authentication of the user (person to be authenticated) who has arrived at the authentication terminal 51 .
  • the authentication unit 503 receives an authentication request including the biometric information of the person to be authenticated and the terminal ID from the authentication terminal 51 .
  • the authentication unit 503 performs biometric authentication using the acquired biometric information and the biometric information stored in the authentication subject information database.
  • the authentication unit 503 extracts biometric information (feature amount) from the authentication request.
  • the authenticating unit 503 sets the feature amount as a matching target, and performs matching processing with the feature amount registered in the authenticated person information database.
  • the authentication unit 503 sets the extracted feature amount (feature vector) as a matching object, and compares the extracted feature amount (feature vector) with a plurality of feature amounts registered in the authenticated person information database in a one-to-N (N is a positive integer, the same applies below).
  • the authentication unit 503 calculates the degree of similarity between the feature amount to be matched and each of the plurality of feature amounts on the registration side. Chi-square distance, Euclidean distance, or the like can be used for the degree of similarity. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
  • the authenticating unit 503 succeeds in the matching process if there is a feature amount whose similarity to the feature amount to be matched is equal to or greater than a predetermined value among the plurality of feature amounts registered in the authentication subject information database. I judge. The authenticating unit 503 fails the matching process if there is no feature amount whose similarity to the matching target feature amount is equal to or greater than a predetermined value among the plurality of feature amounts registered in the authentication subject information database. It is determined that
  • the authentication unit 503 sets "authentication failure" to the authentication result. If the collation process succeeds, the authentication unit 503 identifies the entry with the highest degree of similarity (entries in the person-to-be-authenticated information database), and reads out the corresponding passport information, health passport information, and boarding pass information.
  • the authentication unit 503 identifies the type of the authentication terminal 51 from the terminal ID included in the authentication request, and the passport information of the person to be authenticated meets the predetermined requirements for the identified authentication terminal 51 (determined as successful authentication). requirements) are met.
  • the authentication unit 503 reads the passport Refer to information and health passport information to determine whether or not the requirements are met.
  • the authentication unit 503 sets the authentication result of the person to be authenticated to "successful authentication”. If the requirements are not met, the authentication unit 503 sets the authentication result of the person-to-be-authenticated to "authentication failure".
  • the authentication unit 503 notifies the authentication terminal 51 of the authentication result (authentication success, authentication failure). In the case of authentication success, the authentication unit 503 transmits an affirmative response to that effect to the authentication terminal 51 . In the case of authentication failure, the authentication unit 503 transmits a negative response to that effect to the authentication terminal 51 .
  • the authentication unit 503 may notify the authentication terminal 51 of the passport information of the person who has successfully authenticated.
  • the storage unit 504 is means for storing information necessary for the operation of the authentication server 20.
  • An authenticated person information database is constructed in the storage unit 504 .
  • FIG. 20 is a diagram showing an example of the processing configuration (processing modules) of the CIQ server 60 according to the first embodiment.
  • CIQ server 60 includes communication control section 601 , passenger information processing section 602 , and storage section 603 .
  • the communication control unit 601 is means for controlling communication with other devices. For example, the communication control unit 601 receives data (packets) from the departure management server 40 . The communication control unit 601 also transmits data to the departure management server 40 . The communication control unit 601 passes data received from other devices to other processing modules. The communication control unit 601 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 601 .
  • the communication control unit 601 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to another device.
  • the passenger information processing unit 602 is means for processing passenger information notifications received from the departure management server 40 .
  • Passenger information processing unit 602 provides the passport information and health passport information included in the notification to each government agency responsible for customs, immigration, and quarantine. More specifically, the passenger information processing unit 602 transmits passport information and health passport information to terminals used by customs officials.
  • the storage unit 603 is means for storing information necessary for the operation of the CIQ server 60.
  • the check-in terminal 50 is a terminal that acquires airline ticket information related to an airline ticket reserved by a user (an airline ticket purchased by the user) and implements a check-in procedure.
  • FIG. 21 is a diagram showing an example of the processing configuration (processing modules) of the check-in terminal 50 according to the first embodiment.
  • the check-in terminal 50 includes a communication control section 701, a check-in control section 702, and a storage section 703.
  • the communication control unit 701 is means for controlling communication with other devices. For example, the communication control unit 701 receives data (packets) from the departure management server 40 . The communication control unit 701 also transmits data to the departure management server 40 . The communication control unit 701 passes data received from other devices to other processing modules. The communication control unit 701 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 701 .
  • the communication control unit 701 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to another device.
  • the check-in control unit 702 is means for controlling the user's check-in procedure.
  • a predetermined action for example, pressing a check-in start button
  • the check-in control unit 702 acquires the user's biometric information, passport information, and airline ticket information.
  • the check-in control unit 702 displays a GUI as shown in FIG. 22, and upon detecting pressing of the “photograph” button, controls the camera device installed in the check-in control unit 702 to display the biometric information (face image) of the user. ).
  • the check-in control unit 702 detects pressing of the "start” button, the check-in control unit 702 controls the scanner to acquire passport information and airline ticket information.
  • the user may operate the terminal 70 to display the two-dimensional code converted from the passport information or airline ticket information. .
  • the check-in control unit 702 may read the two-dimensional code displayed on the terminal 70 to acquire passport information and airline ticket information.
  • the check-in control unit 702 generates a feature amount from the acquired face image. Also, the check-in control unit 702 generates a feature amount from the face image included in the passport information (described in the passport).
  • the check-in control unit 702 executes biometric authentication (one-to-one authentication) using the two generated feature amounts.
  • the check-in control unit 702 If biometric authentication fails, the check-in control unit 702 notifies the user that the check-in procedure has failed. At that time, the check-in control unit 702 may guide the passenger to go to the counter where an airline staff member or the like is waiting.
  • the check-in control unit 702 sends a "boarding pass request" including the user's passport information and airline ticket information to the departure management server 40.
  • the check-in control unit 702 receives a response (positive response, negative response) from the departure management server 40.
  • the check-in control unit 702 When receiving a negative response (boarding pass issuance not possible), the check-in control unit 702 notifies the user that a boarding pass cannot be issued.
  • the check-in control unit 702 When a positive response (response including boarding pass information) is received, the check-in control unit 702 issues a boarding pass. For example, the check-in control unit 702 issues a paper medium or electronic medium boarding pass with the content shown in FIG. 23A.
  • the check-in control unit 702 may issue a boarding pass on which the detailed information is described (see FIG. 23B). .
  • the verification result of the entry requirements (entry allowed) by the verification server 30 may be described in the boarding pass.
  • a boarding pass as shown in FIGS. 23A and 23B may be displayed on the check-in terminal 50 or may be displayed on the terminal 70 carried by the user.
  • the boarding pass as shown in FIGS. 23A and 23B may be displayed on a terminal used by an airport company, airline staff, or the like.
  • the user may operate the terminal 70 to read information about the boarding pass from the online check-in described below or from the check-in terminal 50 (kiosk terminal), and store the boarding pass information in the terminal 70 .
  • the storage unit 703 is means for storing information necessary for the operation of the check-in terminal 50.
  • FIG. 24 is a diagram showing an example of a processing configuration (processing modules) of the authentication terminal 51 according to the first embodiment.
  • authentication terminal 51 includes communication control section 801 , biometric information acquisition section 802 , authentication request section 803 , and storage section 804 .
  • the communication control unit 801 is means for controlling communication with other devices. For example, the communication control unit 801 receives data (packets) from the authentication server 20 . Also, the communication control unit 801 transmits data to the authentication server 20 . The communication control unit 801 passes data received from other devices to other processing modules. The communication control unit 801 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 801 .
  • the communication control unit 801 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the biometric information acquisition unit 802 is means for controlling the camera device (the camera device provided in the authentication terminal 51) and acquiring the biometric information (for example, face image) of the user in front of the user.
  • the biological information acquisition unit 802 captures an image of the front of the device periodically or at a predetermined timing.
  • the biometric information acquisition unit 802 determines whether or not the acquired image contains a face image of a person, and if the face image is contained, extracts the face image from the acquired image data.
  • the biometric information acquisition unit 802 may extract a face image (face region) from image data using a learning model learned by a CNN (Convolutional Neural Network).
  • the biometric information acquisition unit 802 may extract a facial image using a technique such as template matching.
  • the biometric information acquisition unit 802 generates a feature amount from the extracted face image.
  • the biometric information acquisition unit 802 passes the generated feature amount to the authentication request unit 803 .
  • the authentication requesting unit 803 is means for requesting authentication of the user in front of the authentication server 20 .
  • the authentication requesting unit 803 generates an authentication request including the acquired biometric information and the terminal ID, and transmits the authentication request to the authentication server 20 .
  • the authentication request unit 803 receives a response (authentication success, authentication failure) from the authentication server 20 to the authentication request.
  • the authentication requesting unit 803 notifies the user (authentication failure person; person to be authenticated who is determined to have failed authentication) to that effect. For example, the authentication requesting unit 803 outputs a message such as "A valid vaccination certificate is required to pass through the gate. Please ask the staff how to deal with this.” For example, the authentication requesting unit 803 uses a display device such as a liquid crystal panel or an acoustic device such as a speaker to notify the person to be authenticated of the message.
  • the authentication requesting unit 803 provides services to the user (authenticated person; person to be authenticated who is determined to be authenticated successfully). For example, the authentication terminal 51 installed at the boarding gate opens the gate and guides the user to pass through the gate.
  • the storage unit 804 is means for storing information necessary for the operation of the authentication terminal 51 .
  • FIG. 25 is a diagram showing an example of a processing configuration (processing modules) of the terminal 70 according to the first embodiment.
  • the terminal 70 includes a communication control section 901, an electronic wallet control section 902, an airline ticket reservation section 903, a usage registration section 904, and a storage section 905.
  • the communication control unit 901 is means for controlling communication with other devices. For example, the communication control unit 901 receives data (packets) from the reservation server 10 . Also, the communication control unit 901 transmits data to the reservation server 10 . The communication control unit 901 passes data received from other devices to other processing modules. The communication control unit 901 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 901 .
  • the communication control unit 901 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
  • the electronic wallet control unit 902 is a means for managing and controlling digital wallets.
  • the electronic wallet control unit 902 acquires various certificates and the like according to the user's operation, and stores them in the storage unit 905 .
  • the electronic wallet control unit 902 is implemented by an application installed on the terminal 70. A detailed description of the installation of the application for implementing the digital wallet and the registration of specific certificates will be omitted. This is because these operations and the like are different from the gist of the disclosure of the present application.
  • the user may operate the terminal 70 to access the homepage provided by the issuer of various certificates, etc., and register the digital information in the digital wallet from the homepage.
  • the electronic wallet control unit 902 accesses websites managed by certificate issuing entities such as local governments and medical institutions.
  • the electronic wallet control unit 902 acquires a vaccination certificate or a negative certificate by inputting the user's ID or the like into the home page according to the user's operation, and stores it in the storage unit 905 .
  • the electronic wallet control unit 902 may capture images of these documents according to the user's operation, and store the image data as digital information related to passports and the like. .
  • the electronic wallet control unit 902 may acquire the vaccination certificate or the like by photographing a two-dimensional code corresponding to the vaccination certificate or the like according to the user's operation.
  • the electronic wallet control unit 902 generates a user ID for identifying the user who owns the digital wallet.
  • the user ID may be any information as long as it can uniquely identify the user.
  • the electronic wallet control unit 902 may acquire an e-mail address from the user and treat the e-mail address as the user ID.
  • Electronic wallet control unit 902 stores the user ID in storage unit 905 .
  • the airline ticket reservation section 903 is a means for realizing airline ticket reservations by users.
  • the airline ticket reservation unit 903 accesses a predetermined homepage provided by the reservation server 10 according to the user's operation. For example, the airline ticket reservation unit 903 acquires the information shown in FIG. 10 and transmits it to the reservation server 10 .
  • the airline ticket reservation unit 903 stores the airline ticket information received from the reservation server 10 in the storage unit 905 .
  • the airline ticket reservation unit 903 stores the airline ticket information in the digital wallet.
  • the usage registration unit 904 is means for realizing usage registration for biometric authentication.
  • the usage registration unit 904 accesses a predetermined homepage provided by the authentication server 20 according to the user's operation.
  • the use registration unit 904 acquires biometric information (face image), passport information, boarding pass information, health passport information (vaccination certificate, negative certificate, recovery certificate) and the like shown in FIG.
  • the use registration unit 904 transmits the acquired biometric information and the like to the authentication server 20 .
  • the storage unit 905 is means for storing information necessary for the operation of the terminal 70 .
  • FIG. 26 is a sequence diagram showing an example of the operation of the immigration control system according to the first embodiment; FIG. The operation of the immigration control system for issuing a boarding pass will be described with reference to FIG.
  • the check-in terminal 50 transmits a boarding pass issuance request including the user's passport information and airline ticket information to the departure management server 40 (step S11).
  • the departure management server 40 sends an entry requirements verification request including the user's passport information and health passport information to the verification server 30 (step S12).
  • the verification server 30 transmits the verification result (entry permitted, entry denied) to the departure management server 40 (step S13).
  • the departure management server 40 issues a boarding pass and notifies the check-in terminal 50 of the boarding pass information (step S14). .
  • the check-in terminal 50 issues a boarding pass based on the acquired boarding pass information (step S15).
  • the departure management server 40 transmits passenger information notification including the user's passport information and health passport information to the CIQ server 60 (step S16).
  • the departure management server 40 preferably transmits the passenger information notification to the CIQ server 60 of the arrival country after the aircraft has departed.
  • the departure control server 40 when issuing a boarding pass, requests the verification server 30 to verify whether the traveler can enter the country of arrival. .
  • the verification server 30 verifies whether the health passport information (eg, vaccination certificate, etc.) possessed by the traveler meets the entry requirements of the destination country.
  • the departure management server 40 issues a boarding pass for the traveler when the verification server 30 confirms that the traveler can enter the country of arrival.
  • airline staff and others do not need to confirm the entry requirements of the destination country, reducing the burden on the staff and others.
  • automating the confirmation of immigration requirements it is possible to eliminate human error caused by staff, etc., and prevent users who cannot enter the country of arrival from boarding the aircraft.
  • the automation facilitates confirmation of entry requirements and improves throughput in departure operations.
  • flight numbers of multiple airlines are assigned to each flight.
  • the actual operation of the aircraft is one airline that provides the aircraft, and the user (passenger) is subject to the airline's regulations (e.g., weight restrictions, in-flight meals, etc.) .
  • FIG. 27 is a diagram showing an example of the schematic configuration of the immigration control system according to the second embodiment.
  • the immigration control system according to the second embodiment includes a joint reservation server 11.
  • FIG. The joint reservation server 11 is a server managed and operated by an airline alliance.
  • FIG. 27 shows the reservation servers 10-1 and 10-2 of each airline participating in the airline alliance.
  • FIG. 27 also shows a departure management server 40-1 and a departure management server 40-2 operated by each airline corresponding to the departure airport.
  • the reservation server 10-1 and departure management server 40-1 are managed and operated by the same airline, and the reservation server 10-2 and departure management server 40-2 are managed and operated by the same airline. Note that in FIG. 27, illustration of other servers and the like described in the first embodiment is omitted.
  • FIG. 28 is a diagram showing an example of the processing configuration of the joint reservation server 11 according to the second embodiment.
  • the joint reservation server 11 includes a communication control section 211 , a reservation control section 212 , a reservation record transmission section 213 and a storage section 214 .
  • the basic operations of the processing modules of the joint reservation server 11 may be the same as those of the corresponding processing modules (with the same names) of the reservation server 10 described with reference to FIG. 9 in the first embodiment. can. Differences between the joint reservation server 11 and the reservation server 10 will be mainly described below.
  • the reservation control unit 212 of the joint reservation server 11 enables users to reserve codeshare flights.
  • the reservation control unit 212 displays information such as that shown in FIG. 29 on the user's terminal 70 and accepts a reservation for a codeshare flight. Note that the flight shown in the first line of FIG. 29 is a codeshare flight, and the operating company is indicated by a circle.
  • FIG. 29 is a drawing corresponding to FIG. 10 described in the first embodiment, and is a display (GUI) related to airline ticket reservation extracted from the display of FIG.
  • the reservation control unit 212 like the reservation control unit 202 of the reservation server 10, acquires airline ticket information for codeshare flights, passport information, and health passport information.
  • the reservation control unit 212 transmits the acquired passport information, health passport information, and airline ticket information related to the code-share flight to the reservation server 10 of each code-share airline (see FIG. 30).
  • the reservation control unit 212 transmits passport information, health passport information, and air ticket information (air ticket information for code-share flights) to the reservation servers 10 of the airlines that jointly operate the aircraft.
  • passport information and the like are sent not only to the reservation server 10-1 of the operating company, but also to the reservation server 10-2 of another airline.
  • the reservation control unit 202 of each reservation server 10 stores the passport information, health passport information and airline ticket information received from the joint reservation server 11 in the user information database.
  • the reservation record transmission unit 203 of each reservation server 10 transmits the user's airline ticket reservation record to the corresponding departure management server 40 a predetermined time before the departure of the aircraft (see FIG. 31). As shown in FIG. 31, the reservation server 10-1 transmits the airline ticket reservation record to the departure management server 40-1 managed by the company, and the reservation server 10-2 transmits the airline ticket reservation record to the departure management server 40-2. Submit your records.
  • each departure management server 40 at the departure airport issues a boarding pass according to the procedure referring to FIG. 6 in the first embodiment. That is, when each departure management server 40 receives a boarding pass issuance request from its own check-in terminal 50, it transmits an "entry requirements verification request" to the verification server 30. issue a ticket.
  • FIG. 32 is a sequence diagram showing an example of the operation of the immigration control system according to the second embodiment.
  • the operation of the immigration control system for airline ticket reservation will be described with reference to FIG.
  • the joint reservation server 11 transmits the airline ticket information, passport information, and health passport information when the codeshare flight was reserved to each reservation server 10 (step S21).
  • Each reservation server 10 transmits an airline ticket reservation record to its own departure management server 40 a predetermined time before the departure of the codeshare flight (step S22).
  • the departure management server 40 executes processing related to issuing a boarding pass in response to a request from the check-in terminal 50 (step S23).
  • the departure management server 40 determines a seat within the range assigned to the company and issues a boarding pass. Also in the second embodiment, when the departure management server 40 requests the verification server 30 to verify the immigration requirements of the user, and obtains a result indicating that the verification of the immigration requirements for the user has been successful, boarding is performed. issue a ticket.
  • the immigration control system includes the joint reservation server 11 that realizes reservations for codeshare flights jointly operated by a plurality of airlines.
  • the joint reservation server 11 transmits at least the health passport information of the user who has reserved the code-share flight to the reservation servers 10 corresponding to each of the plurality of airlines operating the code-share flight.
  • the reservation server 10 corresponding to each of the plurality of airlines transmits at least health passport information to the departure management server 40 corresponding to each reservation server 10 of each of the plurality of airlines.
  • the user's health passport information is shared by each airline that jointly operates the codeshare flight. Verification of immigration requirements for users using codeshare flights is also automatically performed, reducing the burden on staff involved in departure work.
  • FIG. 33 is a diagram showing an example of the schematic configuration of the immigration control system according to the third embodiment.
  • the immigration control system according to the third embodiment includes a departure control server 40-3 and a departure control server 40-4 at each of the departure airport and the transfer airport. Note that in FIG. 33, illustration of some servers and the like described in the first embodiment is omitted.
  • the reservation server 10, departure management server 40-3 and departure management server 40-4 are managed and operated by the same airline.
  • the user operates the terminal 70 to access the reservation server 10 and arrange an airline ticket to the destination (arrival airport).
  • the reservation control unit 202 of the reservation server 10 enables reservation of airline tickets including connecting flights.
  • the reservation control unit 202 displays information such as that shown in FIG. 34 on the user's terminal 70, and accepts reservations for airline tickets (a plurality of airline tickets) including connecting flights.
  • FIG. 34 shows an example in which a connection is made at B2 airport in A2 country.
  • FIG. 34 is a drawing corresponding to FIG. 10 described in the first embodiment, and is a display (GUI) related to airline ticket reservation extracted from the display of FIG.
  • the reservation control unit 202 acquires a plurality of pieces of airline ticket information, passport information, and health passport information.
  • the reservation control unit 202 stores the acquired passport information, health passport information, and multiple pieces of airline ticket information in the user information database (see FIG. 35).
  • the reservation record transmission unit 203 transmits the user's airline ticket reservation record to the departure management server 40-3 and departure management server 40-4 of the departure country and the transit country a predetermined time before the departure of the aircraft (see FIG. 36). Note that the reservation record transmission unit 203 sends an air ticket reservation record including air ticket information related to the air ticket from the departure country to the transit country (air ticket for the departure flight) to the departure management server 40-3 of the departure country. Send. In the example of FIG. 35, an airline ticket reservation record relating to the entry in the first row of the user information database is transmitted.
  • the reservation record transmission unit 203 transmits an air ticket reservation record including air ticket information related to an air ticket from the transit country to the destination country (air ticket of the transit flight) to the departure management server 40-4 of the transit country. .
  • the airline ticket reservation record regarding the entry on the second line of the user information database is transmitted.
  • the departure management server 40-3 of the departure country and the departure management server 40-4 of the transit country store the received airline ticket reservation record in the reservation person information database.
  • the reservation record control unit 302 of the departure management server 40-3 and the departure management server 40-4 reflects the acquired airline ticket reservation record in the reservation person information database.
  • the check-in terminal 50 acquires airline ticket information (air ticket information for departing flights and connecting flights) and passport information from the user.
  • the check-in terminal 50 performs biometric authentication of the user (one-to-one authentication using the biometric information obtained by photographing the face image of the passport information and the user).
  • biometric authentication is successful, the check-in terminal 50 (check-in control unit 702) transmits a "boarding pass request" including the airline ticket information and passport information of the user to the departure management server 40-3 (step S31 ).
  • the departure management server 40-3 Upon receiving the request, the departure management server 40-3 performs boarding pass issuance processing for the user. Specifically, the boarding pass control unit 303 of the departure management server 40-3 confirms the airline ticket information (airline ticket information regarding the departure flight) of the user to determine whether a valid airline ticket has been reserved. verify whether
  • the boarding pass control unit 303 sends an "entry requirements verification request" containing information about the user's transit airport (airport code), passport information, and health passport information. ” to the verification server 30 (step S32).
  • the boarding pass control unit 303 of the departure management server 40-3 transmits a "boarding pass issue request" to the departure management server 40-4 of the transit country (step S33).
  • the boarding pass control unit 303 of the departure management server 40-3 transmits a boarding pass issuance request including airline ticket information (airline ticket information of the connecting flight) and passport information to the departure management server 40-4 of the connecting country.
  • the departure management server 40-4 of the transit country checks the user's airline ticket information (airline ticket information related to the connecting flight) and determines whether a valid airline ticket reservation has been made.
  • the boarding pass control unit 303 of the departure management server 40-4 verifies the airline ticket of the connecting flight (verifies whether or not the reservation is valid).
  • the boarding pass control unit 303 of the departure management server 40-4 sends the "immigration requirements verification request" including information (airport code) on the user's arrival airport, passport information and health passport information to the verification server. 30 (step S34).
  • the verification server 30 processes immigration requirement verification requests received from the departure management server 40-3 and the departure management server 40-4 of the country of departure and the country of transit, respectively.
  • the verification server 30 verifies whether the user's passport information or health passport information satisfies the entry requirements of the transit country with respect to the entry requirements verification request received from the departure management server 40-3.
  • the verification server 30 verifies whether or not the user's passport information and health passport information meet the entry requirements of the arrival country in response to the entry requirements verification request received from the departure management server 40-4.
  • the verification server 30 transmits a response including the verification result (entry permitted, entry denied) to each of the departure management server 40-3 and departure management server 40-4 (steps S35 and S36).
  • the departure management server 40-4 (boarding pass control unit 303) of the transit country issues a boarding pass (boarding pass for the transit flight) to the user if the verification result of the arrival country is "entry possible”.
  • the boarding pass control unit 303 of the departure management server 40-4 transmits the issued boarding pass (boarding pass information) to the departure management server 40-3 of the departure country (step S37).
  • Departure management server 40-3 (boarding pass control unit 303) of the departure country issues a boarding pass for the departure flight when the verification result of the transit country is "entry permitted" and a boarding pass for the transit flight is issued. issue.
  • the boarding pass control unit 303 of the departure management server 40-3 determines the seat of the user and issues a boarding pass for the departing flight.
  • the boarding pass control unit 303 of the departure management server 40-3 transmits the boarding pass information and the like for the departure flight and the connecting flight to the check-in terminal 50 (step S38).
  • the check-in terminal 50 issues boarding passes for each departure flight and connecting flight based on the obtained boarding pass information.
  • the check-in terminal 50 may write detailed information on the verification result of the entry requirements by the verification server 30 on each boarding pass.
  • the check-in terminal 50 may issue a boarding pass on which information such as that shown in FIG. 23B (certificate of vaccination: information such as OK) is described.
  • the verification server 30 notifies the departure management server 40-3 (first departure management server 40) of the departure country of detailed information regarding the verification of the entry requirements of the transit country.
  • the verification server 30 also notifies the departure management server 40-4 (second departure management server 40) of the transit country of detailed information on the verification of the entry requirements of the arrival country.
  • the transit country departure management server 40-4 notifies the departure country departure management server 40-3 of detailed information regarding the verification of entry country entry requirements.
  • the departure management server 40-3 of the departure country notifies the check-in terminal 50 of information regarding the verification of the entry requirements of the transit country and the arrival country.
  • a check-in terminal 50 issues a boarding pass for a departing flight describing detailed information on verification of entry requirements of a transit country and a boarding pass for a connecting flight describing detailed information on verification of entry requirements for an arrival country.
  • the boarding pass control unit 303 of the departure management server 40-3 transmits a "passenger information notification" including passport information and health passport information to the CIQ server 60 of the arrival country (step S39).
  • the departure management server 40-3 (first departure management server 40) of the departure country stores the health passport information, etc. of the user entering the arrival country in the CIQ server 60 installed at the arrival airport of the arrival country. to send.
  • FIG. 38 is a sequence diagram showing an example of the operation of the immigration control system according to the third embodiment.
  • the operation of the immigration control system for issuing a boarding pass will be described with reference to FIG.
  • the departure management server 40-3 Upon receiving a boarding pass issuance request from the check-in terminal 50, the departure management server 40-3 transmits a "request for verifying immigration requirements" to the verification server 30 (step S41).
  • the departure management server 40-3 sends a "boarding pass issue request" to the departure management server 40-4 (step S42).
  • the departure management server 40-4 Upon receiving the boarding pass issuance request from the departure management server 40-3, the departure management server 40-4 transmits a "request to verify entry requirements" to the verification server 30 (step S43).
  • the verification server 30 processes the two immigration requirement verification requests and sends the verification results to the departure management server 40-3 and departure management server 40-4 (steps S44 and S45).
  • Departure management server 40-4 issues a boarding pass for the connecting flight and transmits the boarding pass information to departure management server 40-3 (step S46 ).
  • the departure management server 40-3 issues a boarding pass for the departing flight when the verification result regarding the immigration requirements of the transit country is "entry allowed" and a boarding pass for the connecting flight is issued.
  • the departure management server 40-3 transmits the boarding pass information of the departure flight and the connecting flight to the check-in terminal 50 (step S47).
  • the departure management server 40-3 sends "passenger information notification" to the CIQ server 60 of the arrival country (step S48).
  • a first departure management server 40 that manages departure from the country of departure of the departure flight transmits to the verification server 30 an entry requirement verification request for verification of the entry requirements of the transit country where the departure flight arrives for transit.
  • the second departure management server 40 which manages departures from the transit country, transmits to the verification server 30 an entry requirements verification request for verifying the entry requirements of the destination country where the transit flight arrives.
  • the second departure management server 40 issues a boarding pass for a connecting flight when it is determined that the user is permitted to enter the country of arrival, and sends the boarding pass information of the issued boarding pass to the first departure management server 40.
  • the first departure management server 40 issues a boarding pass for the departure flight and, if it is determined that the user is allowed to enter the transit country and has issued a boarding pass for the transit flight, (The boarding pass information is sent to the check-in terminal 50).
  • the joint reservation server 11 acquires airline ticket information for each departure flight and connecting flight.
  • the joint reservation server 11 sends passport information, health passport information, and airline ticket information (for both the departure flight and the connection flight) to the reservation server 10 of the airline that operates the departing flight and the reservation server 10 of the airline that operates the connecting flight. flight ticket information).
  • the departing flight reservation server 10 transmits the airline ticket reservation record of the departing flight to the departure management server 40 of the departure country
  • the connecting flight reservation server 10 transmits the airline ticket reservation record of the connecting flight to the departure management server 40 of the connecting country.
  • the departure management server 40 in the departure country Upon receiving a boarding pass issuance request from the check-in terminal 50 in the departure country, the departure management server 40 in the departure country requests the verification server 30 to verify the immigration requirements for the transit country. Further, the departure management server 40 transmits a boarding pass issuance request for the connecting flight corresponding to the departing flight to the departure management server 40 of the transit country.
  • the departure management server 40 of the transit country Upon receiving the boarding pass issuance request, the departure management server 40 of the transit country requests the verification server 30 to verify the immigration requirements for the arrival country.
  • the verification server 30 verifies the entry requirements of each transit country and arrival country, and sends the verification results (entry allowed, entry not allowed) to each departure management server 40.
  • the departure management server 40 of the transit country When the departure management server 40 of the transit country receives the verification result that entry is permitted, it issues a boarding pass for the connecting flight and transmits the boarding pass information to the departure management server 40 of the departure country.
  • the departure management server 40 of the country of departure When the departure management server 40 of the country of departure receives the verification result that entry is permitted and the boarding pass of the transit country is issued, it issues the boarding pass of the departure flight.
  • the departure management server 40 of the departure country transmits the boarding pass information of the departure flight and the connecting flight to the check-in terminal 50 .
  • the ticket information for departure flights and connecting flights is sent to the reservation server 10 of each airline.
  • the airline ticket reservation record is transmitted from the reservation server 10 to each corresponding departure management server 40 .
  • the verification server 30 verifies the immigration requirements of the transit country and the arrival country. If the immigration requirements of the transit country and the arrival country are met, the check-in terminal 50 issues boarding passes for the departure flight and the transit flight.
  • the immigration control system when a user enters an arrival country using a connecting flight, not only the entry requirements of the arrival country but also the entry requirements of the transit country are verified. be. Therefore, users who do not meet the entry requirements of the transit and/or destination countries are prevented from leaving the country.
  • FIG. 39 is a diagram showing an example of the hardware configuration of the departure management server 40. As shown in FIG. 39
  • the departure management server 40 can be configured by an information processing device (so-called computer), and has the configuration illustrated in FIG.
  • the departure management server 40 includes a processor 311, a memory 312, an input/output interface 313, a communication interface 314, and the like.
  • Components such as the processor 311 are connected by an internal bus or the like and configured to be able to communicate with each other.
  • the departure management server 40 may include hardware (not shown), and may not have the input/output interface 313 if necessary. Also, the number of processors 311 and the like included in the departure management server 40 is not limited to the example shown in FIG.
  • the processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), DSP (Digital Signal Processor). Alternatively, processor 311 may be a device such as FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or the like. The processor 311 executes various programs including an operating system (OS).
  • OS operating system
  • the memory 312 is RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), or the like.
  • the memory 312 stores an OS program, application programs, and various data.
  • the input/output interface 313 is an interface for a display device and an input device (not shown).
  • the display device is, for example, a liquid crystal display.
  • the input device is, for example, a device such as a keyboard or mouse that receives user operations.
  • the communication interface 314 is a circuit, module, etc. that communicates with other devices.
  • the communication interface 314 includes a NIC (Network Interface Card) or the like.
  • the functions of the departure management server 40 are realized by various processing modules.
  • the processing module is implemented by the processor 311 executing a program stored in the memory 312, for example.
  • the program can be recorded in a computer-readable storage medium.
  • the storage medium can be non-transitory such as semiconductor memory, hard disk, magnetic recording medium, optical recording medium, and the like. That is, the present invention can also be embodied as a computer program product.
  • the program can be downloaded via a network or updated using a storage medium storing the program.
  • the processing module may be realized by a semiconductor chip.
  • the reservation server 10, the authentication server 20, and the like can also be configured by an information processing device in the same manner as the departure management server 40, and the basic hardware configuration thereof is the same as that of the departure management server 40, so description thereof will be omitted. .
  • the departure management server 40 which is an information processing device, is equipped with a computer, and the functions of the departure management server 40 can be realized by causing the computer to execute a program. Further, the departure management server 40 executes the control method of the departure management server 40 by the program.
  • the check-in terminal 50 identifies the user by executing authentication (one-to-one authentication) using the biometric information of the user performing the check-in procedure and the biometric information written in the passport.
  • the check-in terminal 50 can identify the user by storing the airline ticket information (ticket information, reservation information) in addition to the user's biometric information, passport information, health passport information, etc. in the authentication server 20.
  • the check-in terminal 50 transmits to the authentication server 20 the biometric information of the user who desires the check-in procedure.
  • the authentication server 20 executes biometric authentication (one-to-N authentication) using the acquired biometric information and the pre-registered biometric information.
  • the authentication server 20 transmits the passport information and airline ticket information of the successfully authenticated user to the check-in terminal 50 .
  • the check-in terminal 50 may transmit a boarding pass issuance request including the acquired passport information and airline ticket information to the departure management server 40 .
  • the check-in terminal 50 may identify the user using passport information or the like without executing biometric authentication (face authentication).
  • the user operates the terminal 70 to register the use of biometric authentication with the authentication server 20. bottom.
  • registration regarding the use of biometric authentication may be performed at the check-in terminal 50 .
  • the check-in terminal 50 may transmit the user's biometric information, passport information, boarding pass information, health passport information, and the like to the authentication server 20 .
  • the biometric information registered in the authentication server 20 may be biometric information acquired by the check-in terminal 50 (a facial image obtained by photographing the user or a facial image written on a passport).
  • the authentication server 20 and the CIQ server 60 operate independently.
  • these servers may work together.
  • the authentication server 20 may store the user's biometric information and passport information, and obtain the health passport information from the CIQ server 60 .
  • the user uses the check-in terminal 50 to perform the check-in procedure.
  • the user may perform online check-in using a smartphone, PC (Personal Computer), or the like. That is, 24 hours before departure of the reserved aircraft, the user may start the check-in procedure using a smartphone or the like and complete the procedure. In this case, before the user arrives at the airport, an immigration requirements verification request is sent from the departure management server 40 to the verification server 30 . Further, among users who have completed the online check-in procedure, those who wish may issue a paper ticket (boarding pass) at the check-in terminal 50 .
  • PC Personal Computer
  • the departure management server 40 stores the health passport information as disclosed in the present application, so that the request can be easily met. Specifically, the departure management server 40 can issue a boarding pass to a user who has health passport information by refusing to issue a boarding pass to a user who does not have health passport information. In other words, airlines can operate online check-in because there is no need for manual verification of health passport information at check-in counters. As a result, the burden on the airline staff can be reduced.
  • the immigration control system disclosed in the present application it is possible to easily confirm that the user has information other than the health passport information on the terminal 70.
  • information on a specific application installed in the terminal 70 for example, the name and version of the application
  • the user (terminal 70) can register information on an application for health management and an application for confirming contact with a patient suffering from an infectious disease in the reservation server 10.
  • FIG. in the immigration control system disclosed in the present application it is possible to automatically (without human intervention) confirm that the above applications are installed in the terminal 70 .
  • the installation of the above application may be included in the requirements for the departure management server 40 to issue a boarding pass.
  • the authentication server 20 may treat the authentication request (authentication request from the authentication terminal 51) of the user who owns the terminal 70 in which the application is not installed as "authentication failure". With such measures, the immigration control system disclosed in the present application can automatically confirm whether or not the application required for immigration has already been installed on the terminal 70 of the user.
  • the departure management server 40 may notify the check-in terminal 50 of the reason why the boarding pass cannot be issued, when the boarding pass cannot be issued (when a negative response is sent to the boarding pass issuance request). For example, the departure management server 40 may notify the check-in terminal 50 of reasons such as that a valid airline ticket is not registered (no valid reservation), or that entry requirements for the country of arrival have not been met. In this case, the check-in terminal 50 may notify the user of the reason for the notification.
  • airline ticket reservation information is transferred from the reservation server 10 to the departure management server 40 a predetermined time (24 hours) before the departure of the aircraft.
  • the airline ticket reservation information may be transferred.
  • reservations for code-share flights may be made by the reservation server 10 managed by any one of the airlines jointly operating the code-share flights.
  • the reservation server 10 that has accepted the reservation for the codeshare flight sends the ticket purchaser's passport information and ticket information to the reservation server 10 managed by another airline (another airline jointly operating the codeshare flight). Information and health passport information should be notified.
  • the departure management server 40 of the country of departure and the departure management server 40 of the transit country each transmit an entry requirements verification request to the verification server 30 .
  • either one of the two departure management servers 40 may collectively transmit the entry requirement verification requests regarding the entry requirements of the transit country and the arrival country to the verification server 30 .
  • the verification server 30 collects the verification results regarding the country of transit and the country of arrival and transmits them to the departure management server 40, which is the source of the immigration requirement verification request. For example, consider a case where the departure management server 40 of the country of departure collectively transmits an immigration requirement verification request to the verification server 30 .
  • the departure management server 40 of the departure country transmits a boarding pass issuance request to the departure management server 40 of the transit country, acquires the boarding pass (boarding pass information of the connecting flight) from the server, and sets the transit country and arrival date. Issue two boarding passes if entry into the country is permitted.
  • the departure management server 40 of the transit country does not need to send an entry requirements verification request to the verification server 30 because the departure management server 40 of the departure country has sent the entry requirements verification request.
  • the departure management server 40 of the transit country may transmit the boarding pass information of the connecting flight to the departure management server 40 of the departure country.
  • the departure management server 40 in the country of departure sends a passenger information notification to the CIQ server 60 in the country of arrival after issuing the boarding passes for the departure flight and the connecting flight.
  • the departure management server 40 of the transit country may transmit the passenger information notification to the CIQ server 60 of the arrival country.
  • the departure management server 40 of the departure country notifies the departure management server 40 of the transit country that two boarding passes have been issued.
  • the transit country departure management server 40 transmits a passenger information notification to the CIQ server 60 .
  • the departure management server 40 of the departure country transmits a passenger information notification regarding the departure flight to the CIQ server 60 of the transit country
  • the departure management server 40 of the transit country sends the CIQ server 60 of the arrival country a boarding notification regarding the transit flight.
  • the departure management server 40 of the departure country and the departure management server 40 of the connecting country each transmit the passenger information notification to the CIQ server 60 after the departure flight and the connecting flight depart. As described above, this is to avoid a situation in which the user who is reported to the transit country and arrival country as the user boarding the aircraft is different from the user who actually arrived.
  • the check-in terminal 50 may directly transmit a boarding pass issuance request (request for issuing a boarding pass for a connecting flight) to the departure management server 40-4 of the connecting country.
  • the departure management server 40-4 acquires the verification result of the entry requirements of the country of arrival, issues a boarding pass (boarding pass for a connecting flight) for the user permitted to enter the country, and sends the boarding pass information to the check-in terminal 50. You may send.
  • the check-in terminal 50 acquires the boarding pass information of the departure flight from the departure management server 40-3 of the departure country.
  • the immigration control system disclosed in the present application operates in the same manner when entering the arrival country via two or more transit countries.
  • the departure management server 40 of the country of departure sends to the verification server 30 an entry requirements verification request for the entry requirements of the first transit country.
  • the departure management server 40 of the first transit country transmits an entry requirement verification request regarding the entry requirements of the next transit country to the verification server 30, and if the user's entry is permitted, the boarding pass (first transit flight boarding pass).
  • the departure management server 40 of the second transit country transmits an entry requirement verification request regarding the entry requirements of the final arrival country to the verification server 30, and if the user is permitted to enter the country, the boarding pass (second transit issue a boarding pass for the flight.
  • the departure management server 40 of the departure country issues three boarding passes (boarding pass for three boarding passes) if boarding passes for two connecting flights are issued and entry to the first transit country is permitted. information to the check-in terminal 50).
  • the user accesses the reservation server 10 managed by the airline to reserve (purchase) an airline ticket.
  • the user can also reserve an airline ticket from a WEB (web) site or the like operated and managed by a travel agency.
  • the server of the travel agency should notify the reservation server 10 of the airline corresponding to the reserved airline ticket of the ticket purchaser's passport information, airline ticket information, health passport information, and the like.
  • the authentication server 20 when the authentication server 20 processes an authentication request, a case has been described where authentication success or authentication failure is determined using the passport information, health passport information, etc. of the person to be authenticated.
  • the determination may be made at the authentication terminal 51 . That is, the authentication server 20 transmits to the authentication terminal 51 the passport information, health passport information, etc. of the user specified by the verification process using biometric information.
  • the authentication terminal 51 may determine whether or not to provide the service to the person to be authenticated based on the received passport information or the like.
  • face images may be transmitted and received between servers.
  • the server on the receiving side may generate a feature amount from the face image and use it for subsequent processing.
  • biometric information stored in various databases may be feature amounts or face images. When face images are stored, feature amounts may be generated from the face images as needed. Alternatively, both face images and feature amounts may be stored in the database.
  • each server has been described, but the databases may be configured in an external database server or the like. That is, some functions of each server may be implemented in another server. More specifically, if the above-described "reservation record control section (reservation record control means)", “boarding pass control section (boarding pass control means)”, etc. are implemented in any device included in the system good.
  • each device (reservation server 10, authentication server 20, verification server 30, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Passport information and the like are transmitted and received between these devices, and in order to properly protect personal information, it is desirable that encrypted data be transmitted and received.
  • each embodiment may be used alone or in combination.
  • additions, deletions, and replacements of other configurations are possible for some of the configurations of the embodiments.
  • the industrial applicability of the present invention is clear, and the present invention can be suitably applied to an immigration control system for users of aircraft.
  • a departure management server for managing the departure of a user and storing health passport information relating to the health of said user who has booked an airline ticket; a validation server that validates each country's entry requirements; including The departure management server transmits to the verification server an immigration requirements verification request including at least the health passport information of the user who performs check-in procedures; The verification server verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server; The system, wherein the departure management server issues a boarding pass to the user when it is determined that the user is allowed to enter the country of arrival.
  • Appendix 2 further comprising a check-in terminal for obtaining ticket information relating to a ticket booked by the user;
  • the check-in terminal transmits a boarding pass issuance request including the airline ticket information to the departure management server,
  • the departure management server transmits boarding pass information related to the issued boarding pass to the check-in terminal when it is determined that the airline ticket information is valid and the user is allowed to enter the arrival country.
  • Supplement 1 [Appendix 3] further comprising a reservation server facilitating reservation of said airline ticket and storing at least said health passport information; 3.
  • the reservation server transmits at least the health passport information to the departure management server a predetermined time before departure of an aircraft corresponding to the reserved airline ticket.
  • [Appendix 4] further comprising a joint reservation server for realizing reservations for codeshare flights jointly operated by multiple airlines;
  • the joint reservation server transmits at least the health passport information of the user who has reserved the code-share flight to the reservation servers corresponding to each of the plurality of airlines operating the code-share flight, 4.
  • the system of Claim 3 wherein the reservation servers corresponding to each of the plurality of airlines transmit at least the health passport information to the departure management server corresponding to the reservation servers of each of the plurality of airlines.
  • the departure management server is installed at the arrival airport of the arrival country, and is a CIQ (Customs Immigration Quarantine) server that performs processing related to customs, immigration control, and quarantine when the user enters the country. 5.
  • CIQ Customers Immigration Quarantine
  • the verification server notifies the departure management server of detailed information regarding the verification of the entry requirements;
  • the departure management server notifies the check-in terminal of detailed information regarding verification of the entry requirements; 3.
  • the system of Claim 2 wherein the check-in terminal issues a boarding pass containing detailed information regarding verification of the entry requirements.
  • the reservation server enables reservation of airline tickets for departure flights and connecting flights, A first departure management server that manages departure from a departure country from which the departure flight departs, transmits the entry requirements verification request regarding verification of entry requirements of a transit country to which the departure flight arrives for transit, to the verification server.
  • a second departure management server that manages departures from the transit country transmits to the verification server the entry requirements verification request for verification of entry requirements of the destination country where the transit flight arrives,
  • the second departure management server issues a boarding pass for the connecting flight when it is determined that the user is allowed to enter the arrival country, and transfers the boarding pass information of the issued boarding pass to the second departure management server.
  • the first departure management server issues a boarding pass for the departure flight if the user is determined to be allowed to enter the transit country and a boarding pass for the transit flight has been issued, and 4.
  • the system of clause 3 issuing boarding passes for outgoing flights and said connecting flights.
  • the first departure management server is a CIQ (Customs Immigration Quarantine) server that is installed at the arrival airport of the arrival country and performs processing related to customs, immigration control, and quarantine when the user enters the country. 8. The system of claim 7, wherein the health passport information of the user entering the country is transmitted.
  • the verification server notifies the first departure management server of detailed information regarding the verification of entry requirements of the transit country, and notifies the second departure management server of detailed information regarding the verification of entry requirements of the destination country.
  • the second departure management server notifies the first departure management server of detailed information regarding verification of entry requirements of the arrival country;
  • the first departure management server notifies the check-in terminal of detailed information regarding verification of the entry requirements of each of the transit country and the arrival country;
  • the check-in terminal provides a boarding pass for the departing flight containing detailed information regarding verification of entry requirements of the transit country and a boarding pass for the connecting flight containing detailed information regarding verification of entry requirements for the destination country.
  • [Appendix 12] a storage unit for storing health passport information relating to the health of a user who has booked an airline ticket; a transmission unit for transmitting an entry requirements verification request including at least the health passport information of the user who checks in to a verification server for verifying the entry requirements of each country; a receiving unit that receives verification results from the verification server as to whether or not the health passport information satisfies the entry requirements of the country of arrival of the user; a boarding pass control unit that issues a boarding pass to the user when the user is determined to be allowed to enter the country of arrival;
  • Departure management server comprising: [Appendix 13] In the departure management server, remember health passport information about the health of the user who booked the ticket, sending an entry requirements verification request including at least said health passport information of said user checking in to a verification server for verifying the entry requirements of each country; receiving from the verification server a verification result as to whether the health passport information satisfies the entry requirements of the country of arrival of the user;

Abstract

Provided is a system for alleviating a load on staff and other personnel in charge of operations for departure from a country in an airport and other facilities. This system comprises a departure management server and an inspection server. The departure management server manages departure of a user from a country and stores health passport information on the health of a user who has booked an airplane ticket. The inspection server inspects a requirement for entering each country. The departure management server transmits, to the inspection server, a country entry requirement inspection request including the health passport information relating to a user who performs at least a check-in procedure. The inspection server inspects whether or not the health passport information satisfies a requirement for entering an arrival country to be entered by the user, and transmits an inspection result to the departure management server. The departure management server issues a boarding ticket to the user if the user is determined to be eligible for entering the arrival country.

Description

システム、出発管理サーバ、出発管理サーバの制御方法及び記憶媒体SYSTEM, DEPARTURE MANAGEMENT SERVER, CONTROL METHOD OF DEPARTURE MANAGEMENT SERVER, AND STORAGE MEDIUM
 本発明は、システム、出発管理サーバ、出発管理サーバの制御方法及び記憶媒体に関する。 The present invention relates to a system, a departure management server, a departure management server control method, and a storage medium.
 空港利用者の利便性向上を目的とした技術や空港内の業務効率改善を目的とした技術の開発が進められている。  Technologies aimed at improving convenience for airport users and technologies aimed at improving operational efficiency within airports are being developed.
 例えば、特許文献1には、生体情報を搭乗券として用いることにより、紙やモバイルの媒体を利用(提示)する必要を無くし、利用者の利便性向上と空港内のスループット向上を図る、と記載されている。特許文献1では、予約確認または便変更のメニュー選択後、チェックイン端末で生体情報を読取り、利用者の生体情報を取得し、搭乗サーバ内の生体情報を検索する。生体情報の照合が成立したなら既予約情報の表示をして便を選択する。するとチェックインが実施され、「確認」を選択するとホストサーバ内データの変更がなされる。 For example, Patent Document 1 states that by using biometric information as a boarding pass, it is possible to eliminate the need to use (present) paper or mobile media, thereby improving user convenience and improving airport throughput. It is In Patent Literature 1, after selecting a menu for confirming a reservation or changing a flight, a check-in terminal reads biometric information, acquires the biometric information of the user, and searches the biometric information in the boarding server. If the matching of the biometric information is established, the reservation information is displayed and the flight is selected. Then, check-in is performed, and when "Confirm" is selected, the data in the host server is changed.
 特許文献2には、国際便が発着陸する空港や海港等で行われている出入国管理及びチェックイン業務を自動的に行うことにより、限られた施設スペースで、大量の旅客に対して出入国に関する保安管理およびサービス業務を迅速に効率よく行う、と記載されている。特許文献2では、利用者は、海外旅行には旅券機能、航空券また乗船券機能、クレジットカード機能を持たせたICカードである影像付スマートパスポートカードを持参する。さらに、利用者は、セキュリティチェックと搭乗または乗船のチェックインおよび出国審査または入国審査はこの影像付スマートパスポートカードを共用してチェックインまたは審査を受ける。 In Patent Document 2, by automatically performing immigration control and check-in operations that are performed at airports and seaports where international flights depart and land, in a limited facility space, immigration related to a large number of passengers It is stated that security management and service operations will be carried out quickly and efficiently. In Patent Document 2, when traveling abroad, a user carries a smart passport card with an image, which is an IC card having a passport function, an air ticket or boarding ticket function, and a credit card function. In addition, the user undergoes check-in or examination by sharing this image-attached smart passport card for security check and boarding or boarding check-in and departure examination or immigration examination.
特開2007-079656号公報JP 2007-079656 A 特開2002-304448号公報Japanese Unexamined Patent Application Publication No. 2002-304448
 国を跨いだ移動時に、感染症に関する証明書の所持が求められることがある。有効な証明書を提示できない利用者は、入国することができない。そのため、出発国にて当該証明書の確認が航空会社の職員等により行われているが、国ごとに入国要件が異なり職員等の大きな負担になっている。なお、当該問題点は、特許文献1及び特許文献2に開示された技術を適用しても解消できない。これらの文献には、感染症に関する証明書の記載は存在しない。  When traveling across countries, you may be required to possess a certificate related to infectious diseases. Users who cannot present a valid certificate will not be allowed to enter the country. Therefore, confirmation of the certificate in the country of departure is carried out by airline staff, etc., but immigration requirements differ from country to country, which places a heavy burden on the staff. It should be noted that this problem cannot be solved even by applying the techniques disclosed in Patent Documents 1 and 2. There is no documented mention of infectious diseases in these documents.
 本発明は、空港等における出国業務にあたる職員等の負担を軽減することに寄与する、システム、出発管理サーバ、出発管理サーバの制御方法及び記憶媒体を提供することを主たる目的とする。 The main purpose of the present invention is to provide a system, a departure management server, a control method for the departure management server, and a storage medium that contribute to reducing the burden on staff who are involved in departure work at airports and the like.
 本発明の第1の視点によれば、利用者の出国を管理し、航空券を予約した前記利用者の健康に関する健康パスポート情報を記憶する、出発管理サーバと、各国の入国要件を検証する、検証サーバと、を含み、前記出発管理サーバは、少なくともチェックイン手続きを行う前記利用者の前記健康パスポート情報を含む入国要件検証要求を前記検証サーバに送信し、前記検証サーバは、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否か検証し、検証結果を前記出発管理サーバに送信し、前記出発管理サーバは、前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、システムが提供される。 According to a first aspect of the present invention, a departure management server that manages the departure of a user and stores health passport information regarding the health of said user who has booked an airline ticket; and verifies the entry requirements of each country; a verification server, wherein the departure management server transmits to the verification server an immigration requirements verification request including at least the health passport information of the user who performs check-in procedures, and the verification server receives the health passport information. verifies whether the user satisfies the entry requirements of the country of arrival into which the user enters, transmits the verification result to the departure management server, and the departure management server determines that the user is permitted to enter the country of arrival. A system is provided that, if determined, issues a boarding pass to the user.
 本発明の第2の視点によれば、航空券を予約した利用者の健康に関する健康パスポート情報を記憶する、記憶部と、チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信する、送信部と、前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信する受信部と、前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、搭乗券制御部と、を備える、出発管理サーバが提供される。 According to a second aspect of the present invention, an immigration requirement including at least a storage unit for storing health passport information relating to health of a user who has reserved an airline ticket, and the health passport information of the user who performs check-in procedures a sending unit for sending a verification request to a verification server that verifies the entry requirements of each country; Provided by a departure management server, comprising: a receiving unit for receiving a verification result; be done.
 本発明の第3の視点によれば、出発管理サーバにおいて、航空券を予約した利用者の健康に関する健康パスポート情報を記憶し、チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信し、前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信し、前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、出発管理サーバの制御方法が提供される。 According to a third aspect of the present invention, the departure management server stores health passport information relating to the health of a user who has reserved an airline ticket, and an immigration management server that includes at least the health passport information of the user who performs check-in procedures. Sending a requirements verification request to a verification server that verifies the entry requirements of each country, and receiving from the verification server a verification result as to whether the health passport information satisfies the entry requirements of the country of arrival of the user. A method for controlling a departure management server is provided for receiving and issuing a boarding pass to the user when the user is determined to be allowed to enter the arrival country.
 本発明の第4の視点によれば、出発管理サーバに搭載されたコンピュータに、航空券を予約した利用者の健康に関する健康パスポート情報を記憶する処理と、チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信する処理と、前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信する処理と、前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する処理と、を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体が提供される。 According to a fourth aspect of the present invention, a computer installed in a departure management server stores health passport information relating to the health of a user who has reserved an airline ticket; a process of transmitting an entry requirements verification request including at least health passport information to a verification server that verifies the entry requirements of each country; A program for executing a process of receiving a verification result regarding whether or not the requirements are satisfied, and a process of issuing a boarding pass to the user when the user is determined to be allowed to enter the country of arrival. A computer-readable storage medium is provided for storing.
 本発明の各視点によれば、空港等における出国業務にあたる職員等の負担を軽減することに寄与する、システム、出発管理サーバ、出発管理サーバの制御方法及び記憶媒体が提供される。なお、本発明の効果は上記に限定されない。本発明により、当該効果の代わりに、又は当該効果と共に、他の効果が奏されてもよい。 According to each aspect of the present invention, a system, a departure management server, a control method for the departure management server, and a storage medium are provided that contribute to reducing the burden on staff who are in charge of departure work at an airport or the like. In addition, the effect of this invention is not limited above. Other effects may be achieved by the present invention instead of or in addition to this effect.
図1は、一実施形態の概要を説明するための図である。FIG. 1 is a diagram for explaining an overview of one embodiment. 図2は、第1の実施形態に係る出入国管理システムの概略構成の一例を示す図である。FIG. 2 is a diagram showing an example of a schematic configuration of the immigration control system according to the first embodiment. 図3は、第1の実施形態に係る端末の表示の一例を示す図である。FIG. 3 is a diagram illustrating an example of display on a terminal according to the first embodiment; 図4は、第1の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 4 is a diagram for explaining the operation of the immigration control system according to the first embodiment. 図5は、第1の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 5 is a diagram for explaining the operation of the immigration control system according to the first embodiment. 図6は、第1の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 6 is a diagram for explaining the operation of the immigration control system according to the first embodiment. 図7は、第1の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 7 is a diagram for explaining the operation of the immigration control system according to the first embodiment. 図8は、第1の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 8 is a diagram for explaining the operation of the immigration control system according to the first embodiment. 図9は、第1の実施形態に係る予約サーバの処理構成の一例を示す図である。FIG. 9 is a diagram illustrating an example of a processing configuration of a reservation server according to the first embodiment; 図10は、第1の実施形態に係る端末の表示の一例を示す図である。FIG. 10 is a diagram illustrating an example of display on a terminal according to the first embodiment; 図11は、第1の実施形態に係る利用者情報データベースの一例を示す図である。FIG. 11 is a diagram showing an example of a user information database according to the first embodiment. 図12は、第1の実施形態に係る出発管理サーバの処理構成の一例を示す図である。12 is a diagram illustrating an example of a processing configuration of a departure management server according to the first embodiment; FIG. 図13は、第1の実施形態に係る予約者情報データベースの一例を示す図である。FIG. 13 is a diagram showing an example of a reservation person information database according to the first embodiment. 図14は、第1の実施形態に係る搭乗券制御部の動作の一例を示すフローチャートである。14 is a flowchart illustrating an example of the operation of the boarding pass control unit according to the first embodiment; FIG. 図15は、第1の実施形態に係る検証サーバの処理構成の一例を示す図である。15 is a diagram illustrating an example of a processing configuration of a verification server according to the first embodiment; FIG. 図16は、第1の実施形態に係る入国要件データベースの一例を示す図である。FIG. 16 is a diagram showing an example of an entry requirement database according to the first embodiment. 図17は、第1の実施形態に係る認証サーバの処理構成の一例を示す図である。17 is a diagram illustrating an example of a processing configuration of an authentication server according to the first embodiment; FIG. 図18は、第1の実施形態に係る端末の表示の一例を示す図である。18 is a diagram illustrating an example of a display on the terminal according to the first embodiment; FIG. 図19は、第1の実施形態に係る被認証者情報データベースの一例を示す図である。FIG. 19 is a diagram showing an example of an authenticated person information database according to the first embodiment. 図20は、第1の実施形態に係るCIQサーバの処理構成の一例を示す図である。20 is a diagram illustrating an example of a processing configuration of a CIQ server according to the first embodiment; FIG. 図21は、第1の実施形態に係るチェックイン端末の処理構成の一例を示す図である。21 is a diagram illustrating an example of a processing configuration of a check-in terminal according to the first embodiment; FIG. 図22は、第1の実施形態に係るチェックイン端末の表示の一例を示す図である。FIG. 22 is a diagram showing an example of display on the check-in terminal according to the first embodiment. 図23A及び図23Bは、第1の実施形態に係る搭乗券の一例を示す図である。23A and 23B are diagrams showing an example of a boarding pass according to the first embodiment. 図24は、第1の実施形態に係る認証端末の処理構成の一例を示す図である。24 is a diagram illustrating an example of a processing configuration of an authentication terminal according to the first embodiment; FIG. 図25は、第1の実施形態に係る端末の処理構成の一例を示す図である。25 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment; FIG. 図26は、第1の実施形態に係る出入国管理システムの動作の一例を示すシーケンス図である。26 is a sequence diagram showing an example of the operation of the immigration control system according to the first embodiment; FIG. 図27は、第2の実施形態に係る出入国管理システムの概略構成の一例を示す図である。FIG. 27 is a diagram showing an example of a schematic configuration of an immigration control system according to the second embodiment. 図28は、第2の実施形態に係る共同予約サーバの処理構成の一例を示す図である。FIG. 28 is a diagram illustrating an example of a processing configuration of a joint reservation server according to the second embodiment; 図29は、第2の実施形態に係る航空券予約の動作を説明するための図である。FIG. 29 is a diagram for explaining the operation of air ticket reservation according to the second embodiment. 図30は、第2の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 30 is a diagram for explaining the operation of the immigration control system according to the second embodiment. 図31は、第2の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 31 is a diagram for explaining the operation of the immigration control system according to the second embodiment. 図32は、第2の実施形態に係る出入国管理システムの動作の一例を示すシーケンス図である。FIG. 32 is a sequence diagram showing an example of the operation of the immigration control system according to the second embodiment. 図33は、第3の実施形態に係る出入国管理システムの概略構成の一例を示す図である。FIG. 33 is a diagram showing an example of a schematic configuration of an immigration control system according to the third embodiment. 図34は、第3の実施形態に係る航空券予約の動作を説明するための図である。FIG. 34 is a diagram for explaining the operation of air ticket reservation according to the third embodiment. 図35は、第3の実施形態に係る利用者情報データベースの一例を示す図である。FIG. 35 is a diagram showing an example of a user information database according to the third embodiment. 図36は、第3の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 36 is a diagram for explaining the operation of the immigration control system according to the third embodiment. 図37は、第3の実施形態に係る出入国管理システムの動作を説明するための図である。FIG. 37 is a diagram for explaining the operation of the immigration control system according to the third embodiment. 図38は、第3の実施形態に係る出入国管理システムの動作の一例を示すシーケンス図である。FIG. 38 is a sequence diagram showing an example of the operation of the immigration control system according to the third embodiment. 図39は、本願開示に係る出発管理サーバのハードウェア構成の一例を示す図である。FIG. 39 is a diagram showing an example of a hardware configuration of a departure management server according to the disclosure of the present application.
 はじめに、一実施形態の概要について説明する。なお、この概要に付記した図面参照符号は、理解を助けるための一例として各要素に便宜上付記したものであり、この概要の記載はなんらの限定を意図するものではない。また、特段の釈明がない場合には、各図面に記載されたブロックはハードウェア単位の構成ではなく、機能単位の構成を表す。各図におけるブロック間の接続線は、双方向及び単方向の双方を含む。一方向矢印については、主たる信号(データ)の流れを模式的に示すものであり、双方向性を排除するものではない。なお、本明細書及び図面において、同様に説明されることが可能な要素については、同一の符号を付することにより重複説明が省略され得る。 First, an outline of one embodiment will be described. It should be noted that the drawing reference numerals added to this outline are added to each element for convenience as an example to aid understanding, and the description of this outline does not intend any limitation. Also, unless otherwise specified, the blocks shown in each drawing represent the configuration of each function rather than the configuration of each hardware unit. Connecting lines between blocks in each figure include both bi-directional and uni-directional. The unidirectional arrows schematically show the flow of main signals (data) and do not exclude bidirectionality. In addition, in the present specification and drawings, elements that can be described in the same manner can be omitted from redundant description by assigning the same reference numerals.
 一実施形態に係るシステムは、出発管理サーバ101と、検証サーバ102と、を含む(図1参照)。出発管理サーバ101は、利用者の出国を管理し、航空券を予約した利用者の健康に関する健康パスポート情報を記憶する。検証サーバ102は、各国の入国要件を検証する。出発管理サーバ101は、少なくともチェックイン手続きを行う利用者の健康パスポート情報を含む入国要件検証要求を検証サーバ102に送信する。検証サーバ102は、健康パスポート情報が、利用者が入国する到着国の入国要件を満たしているか否か検証し、検証結果を出発管理サーバ101に送信する。出発管理サーバ101は、利用者が到着国に入国可と判定された場合に、利用者に搭乗券を発行する。 A system according to one embodiment includes a departure management server 101 and a verification server 102 (see FIG. 1). The departure management server 101 manages departures of users and stores health passport information regarding the health of users who have reserved airline tickets. Validation server 102 validates the entry requirements of each country. The departure management server 101 transmits to the verification server 102 an immigration requirement verification request including at least the health passport information of the user who performs the check-in procedure. The verification server 102 verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server 101 . The departure management server 101 issues a boarding pass to the user when it is determined that the user can enter the country of arrival.
 出発管理サーバ101は、空港から出国する出国者に搭乗券を発行する際、当該出国者が到着国に入国できるか否かの検証を検証サーバ102に依頼する。検証サーバ102は、各国の入国要件を記憶しており、依頼された検証を行う。出発管理サーバ101は、出国者が到着国に入国できることが確認された場合に、当該出国者に搭乗券を発行する。空港における出国業務にあたる職員等は、世界各国の入国要件を確認し、各出国者について入国要件を検証する必要がない。その結果、当該職員等の負担が軽減される。 When the departure management server 101 issues a boarding pass to a person departing from the airport, it requests the verification server 102 to verify whether the person can enter the country of arrival. The verification server 102 stores the immigration requirements of each country and performs requested verification. The departure management server 101 issues a boarding pass to the departing person when it is confirmed that the departing person can enter the arrival country. Airport departure personnel do not need to check the entry requirements of countries around the world and verify the entry requirements for each person leaving the country. As a result, the burden on the staff concerned is reduced.
 以下に具体的な実施形態について、図面を参照してさらに詳しく説明する。 Specific embodiments will be described in more detail below with reference to the drawings.
[第1の実施形態]
 第1の実施形態について、図面を用いてより詳細に説明する。
[First embodiment]
The first embodiment will be described in more detail with reference to the drawings.
[システムの構成]
 図2は、第1の実施形態に係る出入国管理システム(情報処理システム)の概略構成の一例を示す図である。図2に示すように、出入国管理システムには、予約サーバ10と、認証サーバ20と、検証サーバ30と、が含まれる。
[System configuration]
FIG. 2 is a diagram showing an example of a schematic configuration of an immigration control system (information processing system) according to the first embodiment. As shown in FIG. 2 , the immigration control system includes a reservation server 10 , an authentication server 20 and a verification server 30 .
 出発空港には、出発管理サーバ40、チェックイン端末50、認証端末51-1が含まれる。到着空港には、CIQ(Customs Immigration Quarantine)サーバ60と認証端末51-2が含まれる。以降の説明において、認証端末51-1及び認証端末51-2を区別する特段の理由がない場合には単に「認証端末51」と表記する。他の要素についても同様に、ハイフンより左側の符号に当該要素を代表して表記する。 The departure airport includes the departure management server 40, check-in terminal 50, and authentication terminal 51-1. The arrival airport includes a CIQ (Customs Immigration Quarantine) server 60 and an authentication terminal 51-2. In the following description, the authentication terminal 51-1 and the authentication terminal 51-2 are simply referred to as "authentication terminal 51" unless there is a particular reason to distinguish them. Similarly, other elements are represented by the symbols on the left side of the hyphen.
 予約サーバ10は、航空会社の予約システムを実現するサーバである。各航空会社はそれぞれ、自社の予約サーバ10を管理、運営する。予約サーバ10は、PSS(Passenger Service System)と称される予約システムの主たる機能を実現する。予約サーバ10は、空港会社や航空会社等の施設内に設置されている。あるいは、予約サーバ10はネットワーク上のクラウドに設置されたサーバであってもよい。 The reservation server 10 is a server that implements an airline reservation system. Each airline manages and operates its own reservation server 10 . The reservation server 10 implements the main functions of a reservation system called PSS (Passenger Service System). The reservation server 10 is installed in facilities of an airport company, an airline company, or the like. Alternatively, the reservation server 10 may be a server installed in the cloud on the network.
 認証サーバ20は、空港を利用する利用者の認証を行うサーバである。ここで、利用者は、空港内の手続きを紙媒体の搭乗券やパスポートを係員等に提示することで進めることができるし、生体認証によって進めることができる。認証サーバ20は、利用者の生体情報(例えば、顔画像)を用いた生体認証サービスを提供する。 The authentication server 20 is a server that authenticates users who use the airport. Here, the user can proceed with procedures in the airport by presenting a paper boarding pass or passport to a staff member or the like, or can proceed with biometric authentication. The authentication server 20 provides a biometric authentication service using user's biometric information (for example, face image).
 生体認証を利用するためには所定の手続きが必要であり、当該手続きを完了した利用者は、生体認証により空港内の各種手続き(サービス)を進めることができる。認証サーバ20は、空港会社等の施設内に設置されている。あるいは、認証サーバ20はネットワーク上のクラウドに設置されたサーバであってもよい。 A predetermined procedure is required to use biometric authentication, and users who have completed the procedure can proceed with various procedures (services) at the airport using biometric authentication. The authentication server 20 is installed in a facility such as an airport company. Alternatively, the authentication server 20 may be a server installed in the cloud on the network.
 検証サーバ30は、各国の入国要件を検証する。より具体的には、検証サーバ30は、航空機が到着する到着国の入国要件を検証(確認)する。検証サーバ30は、TIMATICと称される、到着国に入国する際に要求されるドキュメントを調べることができるデータベース機能を実現する。なお、TIMATICは、IATA(International Air Transport Association;国際航空運送協会)により管理、運営される。検証サーバ30は、上記協会の施設内に設置されている。あるいは、検証サーバ30はネットワーク上のクラウドに設置されたサーバであってもよい。 The verification server 30 verifies the entry requirements of each country. More specifically, verification server 30 verifies (confirms) the entry requirements of the country of arrival of the aircraft. Validation server 30 implements a database function called TIMATIC, which can look up documents required for entry into the country of arrival. TIMATIC is managed and operated by IATA (International Air Transport Association). The verification server 30 is installed in the facility of the association. Alternatively, verification server 30 may be a server located in a cloud on a network.
 上述のように、出発空港には出発管理サーバ40が設置される。出発管理サーバ40は、利用者の出国を管理するサーバである。より具体的には、出発管理サーバ40は、DCS(Departure Control System)と称される空港チェックインシステムの主たる機能を実現する。出発管理サーバ40は、各航空会社によって各空港に対応して設置される。そのため、図2では、出発空港に出発管理サーバ40が設置されているように図示しているが、実際には、出発管理サーバ40はクラウド上に設置されたサーバであってもよい。 As described above, the departure management server 40 is installed at the departure airport. The departure management server 40 is a server that manages departures of users. More specifically, the departure management server 40 implements the main functions of an airport check-in system called DCS (Departure Control System). The departure management server 40 is installed at each airport by each airline company. Therefore, although FIG. 2 shows the departure management server 40 installed at the departure airport, the departure management server 40 may actually be a server installed on the cloud.
 チェックイン端末50は、利用者にチェックインサービスを提供する端末である。チェックイン端末50は、航空券を予約した利用者に対して搭乗券を発券する。なお、チェックイン端末50が発券する搭乗券には、紙媒体の搭乗券と電子媒体の搭乗券(例えば、2次元コードに変換された搭乗券)が含まれる。 The check-in terminal 50 is a terminal that provides check-in services to users. The check-in terminal 50 issues a boarding pass to the user who has reserved the airline ticket. The boarding pass issued by the check-in terminal 50 includes a paper boarding pass and an electronic boarding pass (for example, a boarding pass converted into a two-dimensional code).
 認証端末51は、出発空港、到着空港に設置され、予め定められたサービスを提供する端末である。より具体的には、認証端末51は、生体認証に成功した利用者にサービスを提供する。例えば、認証端末51-1は、ゲートを備え、搭乗口に設置される。当該搭乗口に設置された認証端末51-1は、有効なパスポート、搭乗券を所持している利用者の通行を許可する。 The authentication terminal 51 is a terminal that is installed at the airport of departure and the airport of arrival and provides predetermined services. More specifically, the authentication terminal 51 provides services to users who have successfully passed biometric authentication. For example, the authentication terminal 51-1 has a gate and is installed at the boarding gate. The authentication terminal 51-1 installed at the boarding gate permits the passage of the user who has a valid passport and boarding pass.
 あるいは、認証端末51-1は、手荷物預け機である。手荷物預け機として動作する認証端末51-1は、空港内の手荷物カウンタ(有人カウンタ)の隣接領域あるいはチェックイン端末50の近傍領域に設置されている。認証端末51-1は、利用者が操作することにより、航空機内に持ち込まない手荷物を預ける手続(手荷物預け手続)を行うためのセルフ端末である。 Alternatively, the authentication terminal 51-1 is a baggage deposit machine. An authentication terminal 51-1 that operates as a baggage check-in machine is installed in an area adjacent to the baggage counter (manned counter) or in the vicinity of the check-in terminal 50 in the airport. The authentication terminal 51-1 is a self-service terminal that is operated by the user to carry out procedures for checking in baggage that is not carried into the aircraft (baggage check-in procedure).
 あるいは、到着空港に設置された認証端末51-2は、例えば、入国審査所に設置され、有効なパスポートを所持している利用者の通行(入国)を許可する。 Alternatively, the authentication terminal 51-2 installed at the arrival airport, for example, is installed at the immigration office and permits passage (entry into the country) of users who have valid passports.
 上記説明したように、認証端末51は生体認証に成功した利用者にサービスを提供する任意の端末である。なお、図2を含む図面において、認証端末51は、ゲートを備えるゲート装置として図示している。 As explained above, the authentication terminal 51 is an arbitrary terminal that provides services to users who have successfully passed biometric authentication. In the drawings including FIG. 2, the authentication terminal 51 is illustrated as a gate device having a gate.
 CIQサーバ60は、到着空港に設置され、利用者が入国する際の税関、入国管理、検疫に関する処理を行う。CIQサーバ60は、入国者の検疫検査等に関する必要な情報を税関等の政府機関に配布する。 The CIQ server 60 is installed at the arrival airport and performs processing related to customs, immigration control, and quarantine when the user enters the country. The CIQ server 60 distributes necessary information regarding quarantine inspections of immigrants to government agencies such as customs.
 利用者は、端末70を使用する。例えば、端末70は、スマートフォン、携帯電話、タブレット等のモバイル端末である。あるいは、端末70は、パーソナルコンピュータ、ノートパソコン等の情報処理端末であってもよい。 The user uses the terminal 70. For example, the terminal 70 is a mobile terminal such as a smart phone, mobile phone, or tablet. Alternatively, the terminal 70 may be an information processing terminal such as a personal computer or a notebook computer.
 図2に示す各装置(予約サーバ10、認証サーバ20、検証サーバ30、出発管理サーバ40等)は、ネットワークを介して相互に通信可能に構成されている。例えば、予約サーバ10と出発管理サーバ40は、有線又は無線の通信手段により接続され、相互に通信が可能となるように構成されている。 Each device (reservation server 10, authentication server 20, verification server 30, departure management server 40, etc.) shown in FIG. 2 is configured to be able to communicate with each other via a network. For example, the reservation server 10 and the departure management server 40 are connected by wired or wireless communication means, and are configured to be able to communicate with each other.
 図2は例示であって、本願開示の出入国管理システムの構成等を限定する趣旨ではない。例えば、出入国管理システムには2台以上の認証サーバ20や検証サーバ30が含まれていてもよい。なお、図2において、1台の予約サーバ10が図示されているが、実際には、各航空会社それぞれが管理、運営する複数の予約サーバ10がシステムには含まれる。さらに、図2において、到着空港には出発管理サーバ40の図示を省略し、出発空港にはCIQサーバ60の図示を省略しているが、実際にはこれらのサーバが各空港に対応して設置される。 FIG. 2 is an example and is not intended to limit the configuration of the immigration control system disclosed in the present application. For example, the immigration control system may include two or more authentication servers 20 and verification servers 30 . Although one reservation server 10 is shown in FIG. 2, the system actually includes a plurality of reservation servers 10 managed and operated by each airline company. Furthermore, in FIG. 2, the illustration of the departure management server 40 is omitted at the arrival airport and the illustration of the CIQ server 60 is omitted at the departure airport, but in reality these servers are installed corresponding to each airport. be done.
[動作概略]
 続いて、第1の実施形態に係る出入国管理システムの動作概略について説明する。
[Overview of operation]
Next, an outline of the operation of the immigration control system according to the first embodiment will be described.
<デジタルウォレットの準備>
 利用者は、所持する端末70にデジタルウォレットを実現するためのアプリケーションをインストールする。例えば、利用者は、デジタルウォレットを端末70に作成することで、電子マネー、パスポートや運転免許証等の身分証明書、航空券や搭乗券等の各種チケット情報、ワクチン接種証明書や陰性証明書(コモンパス)等の各種証明書を端末70に保管する。
<Preparing a digital wallet>
A user installs an application for realizing a digital wallet on the terminal 70 that the user possesses. For example, by creating a digital wallet on the terminal 70, the user can use electronic money, identification cards such as passports and driver's licenses, various ticket information such as airline tickets and boarding passes, vaccination certificates and negative certificates. (Common Pass) and other certificates are stored in the terminal 70 .
 例えば、利用者の端末70は、図3に示すようなデジタル情報を保管する。例えば、パスポート、運転免許証等の公的な身分証明書やワクチン接種証明書、陰性証明書、回復証明書のような健康に関する証明書(感染症に関する証明書)がデジタルウォレット内に保管される。 For example, the user's terminal 70 stores digital information as shown in FIG. For example, public identification documents such as passports, driver's licenses, health certificates (certificates related to infectious diseases) such as vaccination certificates, negative certificates, and recovery certificates are stored in the digital wallet. .
 ワクチン接種証明書には、ワクチン接種者の氏名、生年月日、パスポート番号、ワクチンの種類、メーカー、製品名、製造番号、接種年月日、接種国、証明発行者、証明書ID、証明書発行年月日、ワクチン有効期限、接種回数等の情報が含まれる。 Vaccination certificate includes name, date of birth, passport number, vaccine type, manufacturer, product name, production number, date of vaccination, country of vaccination, certificate issuer, certificate ID, certificate Information such as the date of issue, the expiration date of the vaccine, and the number of vaccinations is included.
 陰性証明書には、対象者の氏名、生年月日、パスポート番号、性別、検査法、採取検体、結果、検体採取日時、結果判明日、検査証明書交付年月日、医療機関名、医療機関住所、医師名、医療機関印影、陰性証明書有効期限等の情報が含まれる。 The negative certificate includes the subject's name, date of birth, passport number, sex, test method, collected sample, result, sample collection date, result date, test certificate issuance date, medical institution name, medical institution Information such as address, doctor name, medical institution seal impression, negative certificate expiration date, etc. is included.
 回復証明書には、対象者の氏名、生年月日、パスポート番号、性別、検査法、採取検体、結果(陽性)、検体採取日時、結果判明日、検査証明書交付年月日、検査医療機関名、検査医療機関住所、検査医師名、検査医療機関印影等の情報が含まれる。さらに、回復証明書には、治癒証明に関する、医療機関名、医療機関住所、医師名、医療機関印影/サイン等の情報が含まれる。 The recovery certificate includes the subject's name, date of birth, passport number, gender, test method, sample collected, result (positive), date and time of sample collection, date of result determination, date of test certificate issuance, test medical institution Information such as the name, address of the examination medical institution, name of the examination doctor, seal imprint of the examination medical institution, etc. is included. Furthermore, the recovery certificate includes information such as the name of the medical institution, the address of the medical institution, the name of the doctor, the imprint/signature of the medical institution, etc., related to the certificate of healing.
 なお、以降の説明において、感染症に関する、ワクチン接種証明書、陰性証明書、回復証明書のような健康に関わる証明書を「健康パスポート情報」と表記する。図3には、3つの健康パスポート情報がデジタルウォレット内に保管されている例が図示されている。 In the following explanation, health-related certificates such as vaccination certificates, negative certificates, and recovery certificates regarding infectious diseases are referred to as "health passport information". FIG. 3 shows an example of three health passport information stored in a digital wallet.
 健康パスポート情報は、デジタル的な証明書であってもよいし、紙媒体の証明書を撮影することで得られる画像データ(証明書の写し)であってもよい。あるいは、健康パスポート情報は、ワクチン接種証明書等に記載された内容が変換された2次元コードであってもよい。 The health passport information may be a digital certificate or image data (a copy of the certificate) obtained by taking a picture of a paper certificate. Alternatively, the health passport information may be a two-dimensional code obtained by converting the content described in a vaccination certificate or the like.
 端末70は、上記ワクチン接種証明書等に加え、利用者のユーザIDと生体情報をデジタルウォレットに保管する。例えば、利用者は、端末70を操作して自身の顔を撮影する。端末70は、当該顔画像又は顔画像から生成された特徴量を利用者の生体情報として記憶する。 The terminal 70 stores the user ID and biometric information of the user in the digital wallet in addition to the vaccination certificate. For example, the user operates the terminal 70 to photograph his/her own face. The terminal 70 stores the facial image or the feature amount generated from the facial image as the biometric information of the user.
 生体情報には、例えば、顔、指紋、声紋、静脈、網膜、瞳の虹彩の模様(パターン)といった個人に固有の身体的特徴から計算されるデータ(特徴量)が例示される。あるいは、生体情報は、顔画像、指紋画像等の画像データであってもよい。生体情報は、利用者の身体的特徴を情報として含むものであればよい。本願開示では、人の「顔」に関する生体情報(顔画像又は顔画像から生成された特徴量)を用いる場合について説明する。 Examples of biometric information include data (feature amounts) calculated from physical features unique to individuals, such as faces, fingerprints, voiceprints, veins, retinas, and iris patterns. Alternatively, the biometric information may be image data such as a face image or a fingerprint image. The biometric information should just contain a user's physical characteristic as information. In the disclosure of the present application, a case of using biometric information (a face image or a feature amount generated from the face image) regarding a person's “face” will be described.
<航空券の予約>
 国を跨いだ移動をする利用者は、航空券の予約を行う(図4参照)。利用者は、利用する航空会社の予約サーバ10にアクセスし、航空券の予約を行う。例えば、利用者は、端末70を操作して、予約サーバ10が提供するホームページにアクセスし、航空券の予約を行う。
<Air ticket reservation>
A user who travels across countries reserves an airline ticket (see FIG. 4). The user accesses the reservation server 10 of the airline company to use and reserves an airline ticket. For example, the user operates the terminal 70 to access the homepage provided by the reservation server 10 and reserve an airline ticket.
 その際、端末70は、パスポートに関する情報(以下、パスポート情報と表記する)と健康パスポート情報を予約サーバ10に入力する。なお、パスポート情報には、パスポート顔画像、氏名、性別、国籍、パスポート番号、パスポート発行国等が含まれる。あるいは、パスポート情報は、パスポートを撮影することで得られる画像データ(パスポートの写し)であってもよい。 At that time, the terminal 70 inputs information on the passport (hereinafter referred to as passport information) and health passport information to the reservation server 10. The passport information includes a passport face image, name, gender, nationality, passport number, passport issuing country, and the like. Alternatively, the passport information may be image data (a copy of the passport) obtained by photographing the passport.
 利用者が航空機を予約すると、予約サーバ10は、航空券を発券する。予約サーバ10は、紙媒体の航空券又は電子媒体の航空券を発券する。電子媒体の航空券(例えば、航空券の情報が変換された2次元コード)が発券された場合には、当該航空券に関する情報(以下、航空券情報と表記する)が端末70に送信される。 When a user reserves an aircraft, the reservation server 10 issues an airline ticket. The reservation server 10 issues paper airline tickets or electronic airline tickets. When an electronic medium airline ticket (for example, a two-dimensional code converted from airline ticket information) is issued, information about the airline ticket (hereinafter referred to as airline ticket information) is sent to the terminal 70. .
 航空券情報には、エアラインコード、便名、出発日、出発時刻、目的地(到着空港)、席種等が含まれる。 Airline ticket information includes airline code, flight number, departure date, departure time, destination (arrival airport), seat type, etc.
 電子媒体の航空券が発行された場合には、端末70は、発券された航空券(航空券情報)をデジタルウォレットに保管する。あるいは、紙媒体の航空券が発行された場合には、利用者は、端末70を操作して、当該航空券を撮影し、取得した画像データをデジタルウォレットに保管してもよい。 When an electronic medium airline ticket is issued, the terminal 70 stores the issued airline ticket (airline ticket information) in a digital wallet. Alternatively, when a paper-medium airline ticket is issued, the user may operate the terminal 70 to take an image of the airline ticket and store the acquired image data in the digital wallet.
 なお、利用者が航空機の予約(航空券の予約)を完了すると、予約番号が発行される。航空券には予約情報が含まれる(航空券の情報と予約情報は同一である)。また、予約者が、出発の所定時間前(例えば、24時間前)にチェックイン手続きを行うと、搭乗券が発券される。即ち、航空券は予約時に発券され、搭乗券はチェックイン手続き終了後に発券される。 In addition, when the user completes the aircraft reservation (airline ticket reservation), a reservation number will be issued. The ticket includes reservation information (the information on the ticket and the reservation information are the same). Also, if the person who made the reservation completes the check-in procedure a predetermined time before departure (for example, 24 hours before), a boarding pass is issued. That is, the airline ticket is issued at the time of reservation, and the boarding pass is issued after the check-in procedure is completed.
 予約サーバ10は、パスポート情報、健康パスポート情報及び航空券情報を対応付けて利用者情報データベースに記憶する。利用者情報データベースの詳細は後述する。なお、予約サーバ10は、取得したパスポート情報等をPNR(Passenger Name Record)として記憶する。PNRは、利用者による航空券の予約記録であり、当該利用者の氏名や国籍、予約された便名等の情報を含む。 The reservation server 10 associates passport information, health passport information, and airline ticket information and stores them in the user information database. Details of the user information database will be described later. The reservation server 10 stores the acquired passport information and the like as a PNR (Passenger Name Record). A PNR is a reservation record of an airline ticket by a user, and includes information such as the user's name, nationality, reserved flight number, and the like.
<航空券予約記録の転送>
 利用者の航空券予約記録は、予約された航空機が出発する所定時間前に予約サーバ10から出発管理サーバ40に転送される(図5参照)。具体的には、航空機の出発24時間前になると、当該航空機を予約している各乗客(複数の乗客)に関するパスポート情報、航空券情報及び健康パスポート情報が出発管理サーバ40に送信される。
<Transfer of Airline Ticket Reservation Records>
A user's airline ticket reservation record is transferred from the reservation server 10 to the departure management server 40 a predetermined time before the departure of the reserved aircraft (see FIG. 5). Specifically, 24 hours before departure of an aircraft, passport information, airline ticket information, and health passport information regarding each passenger (a plurality of passengers) who have reserved the aircraft are sent to the departure management server 40 .
 より具体的には、予約サーバ10は、PNL(Passenger Name List)として航空機の乗客一式のPNRを出発管理サーバ40に送信する。なお、予約サーバ10は、PNRの追加情報フォーマットであるSSR(Special Service Requirement)のDOCO(Document Other;SSRに追加する追加情報の定義)を用いて健康パスポート情報を出発管理サーバ40に送信する。SSRでは、PNRに追加される情報により4文字の接頭辞を与えることで、情報が定義される。健康パスポート情報を送受信する際には、既存のDOCOに追加されてもよいし、新たな接頭辞が定義されてもよい。例えば、「DOCH」や「HLCT」のような接頭辞(コード)が定義されてもよい。 More specifically, the reservation server 10 transmits the PNR of the set of passengers of the aircraft to the departure management server 40 as a PNL (Passenger Name List). The reservation server 10 transmits the health passport information to the departure management server 40 using DOCO (Document Other; definition of additional information to be added to SSR) of SSR (Special Service Requirement), which is an additional information format of PNR. In SSR, information is defined by giving a four letter prefix with the information added to the PNR. When sending and receiving health passport information, it may be added to an existing DOCO, or a new prefix may be defined. For example, prefixes (codes) such as "DOCH" and "HLCT" may be defined.
 既に送信されたPNLに内容の変更があった場合には、ADL(Additions/Deletions List)を用いて最新の航空券予約記録が出発管理サーバ40に送信される。出発管理サーバ40は、取得した航空券予約記録を予約者情報データベースに記憶する。予約者情報データベースの詳細は後述する。 If there is a change in the content of the PNL that has already been sent, the latest airline ticket reservation record is sent to the departure management server 40 using the ADL (Additions/Deletions List). The departure management server 40 stores the acquired airline ticket reservation record in the reservation person information database. The details of the reservation person information database will be described later.
 このように、予約サーバ10は、予約された航空券に対応する航空機が出発する所定時間前に、当該航空券を予約した利用者の少なくとも健康パスポート情報を出発管理サーバ40に送信する。 In this way, the reservation server 10 transmits at least the health passport information of the user who reserved the airline ticket to the departure management server 40 a predetermined time before the departure of the aircraft corresponding to the reserved airline ticket.
<搭乗券の発行>
 出発日が到来すると、利用者は出発空港に移動する。利用者は、出発空港に設置されたチェックイン端末50を用いてチェックイン手続きを行う(図6参照)。
<Issuance of boarding pass>
When the departure date arrives, the user moves to the departure airport. A user performs a check-in procedure using a check-in terminal 50 installed at the departure airport (see FIG. 6).
 チェックイン端末50は、利用者の生体情報、パスポート情報及び航空券情報を取得する。チェックイン端末50は、取得した生体情報(撮影により得られた顔画像)とパスポートに記載された顔画像を用いた生体認証(例えば、1対1認証)を行う。認証に成功すると、チェックイン端末50は、当該利用者のパスポート情報及び航空券情報を含む「搭乗券発行要求」を出発管理サーバ40に送信する(ステップS1)。 The check-in terminal 50 acquires the user's biometric information, passport information, and airline ticket information. The check-in terminal 50 performs biometric authentication (for example, one-to-one authentication) using the obtained biometric information (face image obtained by photographing) and the face image written on the passport. When the authentication is successful, the check-in terminal 50 transmits a "boarding pass request" including the passport information and airline ticket information of the user to the departure management server 40 (step S1).
 当該要求を受信した出発管理サーバ40は、パスポート情報からチェックイン手続きをする利用者を特定し、当該特定した利用者に関する搭乗券発行処理を行う。具体的には、出発管理サーバ40は、チェックイン端末50から取得した航空券情報が予約者情報データベースに記憶されているか否かを判定する。 Upon receiving the request, the departure management server 40 identifies the user who will be checking in from the passport information, and issues a boarding pass for the identified user. Specifically, the departure management server 40 determines whether or not the airline ticket information acquired from the check-in terminal 50 is stored in the reservation person information database.
 航空券情報が記憶されていれば、出発管理サーバ40は、少なくとも当該利用者の到着空港に関する情報(例えば、空港コード)、当該利用者のパスポート情報及び健康パスポート情報を含む「入国要件検証要求」を検証サーバ30に送信する(ステップS2)。 If the airline ticket information is stored, the departure management server 40 sends an "immigration requirements verification request" including at least information about the user's arrival airport (for example, airport code), the user's passport information and health passport information. to the verification server 30 (step S2).
 検証サーバ30は、入国要件検証要求を処理する。具体的には、検証サーバ30は、利用者のパスポート情報及び健康パスポート情報等を用いて、当該利用者が到着国の入国要件を満たしているか否かを検証(審査)する。 The verification server 30 processes the entry requirements verification request. Specifically, the verification server 30 verifies (examines) whether or not the user satisfies the entry requirements of the country of arrival using the user's passport information, health passport information, and the like.
 検証サーバ30は、検証結果(入国可、入国不可)を含む応答を出発管理サーバ40に送信する(ステップS3)。検証サーバ30は、入国要件の検証に関する詳細を出発管理サーバ40に送信してもよい。 The verification server 30 sends a response including the verification result (entry permitted, entry denied) to the departure management server 40 (step S3). Validation server 30 may send details regarding the validation of entry requirements to departure control server 40 .
 出発管理サーバ40は、利用者の入国検証結果が「入国可」であった場合、当該利用者の搭乗券を発行する。出発管理サーバ40は、当該利用者の座席を決定し、搭乗券を発行する。 The departure management server 40 issues a boarding pass for the user if the user's immigration verification result is "permitted to enter". The departure management server 40 determines the seat of the user and issues a boarding pass.
 搭乗券を発行すると、出発管理サーバ40は、発行された搭乗券に関する情報(以下、搭乗券情報と表記する)を含む応答をチェックイン端末50に送信する(ステップS4)。搭乗券情報には、氏名(姓、名)、エアラインコード、便名、搭乗日、出発地(搭乗空港)、目的地(到着空港)、シート番号、搭乗時間、到着時間等が含まれる。 When the boarding pass is issued, the departure management server 40 transmits a response including information on the issued boarding pass (hereinafter referred to as boarding pass information) to the check-in terminal 50 (step S4). The boarding pass information includes name (surname, first name), airline code, flight number, boarding date, departure point (boarding airport), destination (arrival airport), seat number, boarding time, arrival time, and the like.
 あるいは、出発管理サーバ40は、搭乗券情報に加え、健康パスポート情報をチェックイン端末50に送信してもよいし、入国要件の検証に関する詳細をチェックイン端末50に送信してもよい。 Alternatively, the departure management server 40 may send health passport information to the check-in terminal 50 in addition to the boarding pass information, or may send details regarding verification of entry requirements to the check-in terminal 50 .
 チェックイン端末50は、取得した搭乗券情報等に基づいて搭乗券を発券する。チェックイン端末50は、紙媒体の搭乗券又は電子媒体の搭乗券を発券する。電子媒体の搭乗券(例えば、搭乗券情報が変換された2次元コード)が発券された場合には、利用者は、端末70を操作して当該2次元コードを読み取り、発券された搭乗券をデジタルウォレットに保管する。あるいは、利用者は、紙媒体の搭乗券を撮影することで、搭乗券をデジタルウォレットに保管してもよい。 The check-in terminal 50 issues a boarding pass based on the acquired boarding pass information. The check-in terminal 50 issues a paper boarding pass or an electronic boarding pass. When an electronic boarding pass (for example, a two-dimensional code converted from the boarding pass information) is issued, the user operates the terminal 70 to read the two-dimensional code and read the issued boarding pass. Store in a digital wallet. Alternatively, the user may store the boarding pass in the digital wallet by taking a picture of the paper boarding pass.
 なお、発券された搭乗券には、検証サーバ30による検証結果の詳細が記載されていてもよい。例えば、「健康パスポート情報:OK」、「陰性証明書:OK」のような情報が搭乗券に記載されていてもよい。 It should be noted that the issued boarding pass may include the details of the verification result by the verification server 30. For example, information such as "health passport information: OK" and "negative certificate: OK" may be written on the boarding pass.
 また、搭乗券を発行すると、出発管理サーバ40は、到着国のCIQサーバ60に対してパスポート情報と健康パスポート情報を含む「搭乗者情報通知」を送信する(ステップS5)。より具体的には、出発管理サーバ40は、iAPI(Interactive API;双方向のAPI(Application Programming Interface)、到着国の政府と航空会社が双方向で情報のやり取りを可能とするAPI)により搭乗者情報をCIQサーバ60に送信する。搭乗者情報は、APIS(Advance Passenger Information System)とも称され、航空会社から到着国の政府に事前送付される情報である。 Also, when the boarding pass is issued, the departure management server 40 transmits a "passenger information notification" including passport information and health passport information to the CIQ server 60 of the arrival country (step S5). More specifically, the departure management server 40 uses iAPI (Interactive API; an interactive API (Application Programming Interface), an API that enables two-way information exchange between the government of the arrival country and the airline). Send the information to the CIQ server 60 . Passenger information, also called APIS (Advance Passenger Information System), is information sent in advance from the airline to the government of the arrival country.
 このように、出発管理サーバ40は、少なくともチェックイン手続きを行う利用者の健康パスポート情報を含む入国要件検証要求を検証サーバ30に送信する。検証サーバ30は、健康パスポート情報が、利用者が入国する到着国の入国要件を満たしているか否か検証し、検証結果を出発管理サーバ40に送信する。出発管理サーバ40は、利用者が到着国に入国可と判定された場合に、当該利用者に搭乗券を発行する。より具体的には、チェックイン端末50は、利用者が予約した(購入した)航空チケットに関する航空券情報を含む搭乗券発行要求を出発管理サーバ40に送信する。出発管理サーバ40は、航空券情報が有効、且つ、利用者が到着国に入国可と判定された場合に、上記発行された搭乗券に関する搭乗券情報をチェックイン端末50に送信する。 In this way, the departure management server 40 transmits to the verification server 30 an immigration requirements verification request that includes at least the health passport information of the user who performs the check-in procedure. The verification server 30 verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server 40 . The departure management server 40 issues a boarding pass to the user when it is determined that the user can enter the country of arrival. More specifically, the check-in terminal 50 transmits to the departure management server 40 a boarding pass issuance request including airline ticket information related to the airline ticket reserved (purchased) by the user. The departure management server 40 transmits boarding pass information related to the issued boarding pass to the check-in terminal 50 when it is determined that the airline ticket information is valid and that the user can enter the country of arrival.
<生体認証利用登録>
 搭乗券の発券を受けると、利用者は、空港内の手続きを生体認証で進めるための利用登録を行える(図7参照)。なお、生体認証を用いて手続きを進めるか否かはオプションであり、各利用者が決定する事項である。
<Biometric authentication use registration>
When the boarding pass is issued, the user can register for use in order to proceed with procedures at the airport using biometric authentication (see FIG. 7). It should be noted that whether or not to proceed with the procedure using biometric authentication is an option, and is a matter for each user to decide.
 生体認証を用いたサービスの提供を希望する利用者は、端末70を操作して、認証サーバ20にアクセスし、生体認証の利用登録を行う。例えば、利用者は、端末70を操作して、認証サーバ20が提供するホームページにアクセスし、生体認証の利用登録を行う。 A user who wishes to be provided with a service using biometric authentication operates the terminal 70, accesses the authentication server 20, and registers for use of biometric authentication. For example, the user operates the terminal 70 to access the homepage provided by the authentication server 20 and register for use of biometric authentication.
 具体的には、利用者は、デジタルウォレットに格納された、生体情報、パスポート情報、搭乗券情報及び健康パスポート情報を認証サーバ20に入力する。認証サーバ20は、取得した生体情報、パスポート情報、搭乗券情報及び健康パスポート情報を対応付けて被認証者情報データベースに記憶する。被認証者情報データベースの詳細は後述する。 Specifically, the user inputs biometric information, passport information, boarding pass information, and health passport information stored in the digital wallet into the authentication server 20. The authentication server 20 associates the acquired biometric information, passport information, boarding pass information, and health passport information and stores them in the authenticated person information database. Details of the authenticated person information database will be described later.
<出入国手続き>
 生体認証の利用登録を完了した利用者は、空港内の手続きを生体認証により進めることができる(図8参照)。具体的には、利用者が認証端末51に到着すると、認証端末51は、当該利用者(被認証者)の生体情報を取得する。認証端末51は、当該利用者の生体情報と端末IDを含む認証要求を認証サーバ20に送信する。
<Immigration procedures>
A user who has completed registration for use of biometric authentication can proceed with procedures at the airport using biometric authentication (see FIG. 8). Specifically, when the user arrives at the authentication terminal 51, the authentication terminal 51 acquires the biometric information of the user (person to be authenticated). The authentication terminal 51 transmits an authentication request including the biometric information of the user and the terminal ID to the authentication server 20 .
 端末IDは、空港内の各所に設置された認証端末51を識別するためのIDである。端末IDには、認証端末51のMAC(Media Access Control)アドレスやIP(Internet Protocol)アドレスを用いることができる。また、端末IDは、認証サーバ20と認証端末51の間において任意の方法によって共有される。例えば、システム管理者が端末IDを決定し当該決定された端末IDを認証サーバ20に設定する。また、システム管理者は、当該決定された端末IDを認証端末51に設定する。  The terminal ID is an ID for identifying the authentication terminal 51 installed in various places in the airport. The MAC (Media Access Control) address or IP (Internet Protocol) address of the authentication terminal 51 can be used as the terminal ID. Also, the terminal ID is shared between the authentication server 20 and the authentication terminal 51 by any method. For example, a system administrator determines a terminal ID and sets the determined terminal ID in the authentication server 20 . Also, the system administrator sets the determined terminal ID to the authentication terminal 51 .
 認証サーバ20は、認証要求に含まれる端末IDに基づいて認証要求の送信元である認証端末51の種類を特定する(認証端末51の機能を特定する)。認証サーバ20は、認証端末51の種類に基づいて、当該認証端末51が利用者にサービスを提供するための要件を取得する。例えば、認証端末51が搭乗口に設置されたゲート装置であれば、認証サーバ20は、当該ゲート装置を通行するための要件(例えば、利用者が有効なパスポート及び搭乗券を所持)を取得する。 The authentication server 20 identifies the type of the authentication terminal 51 that is the source of the authentication request based on the terminal ID included in the authentication request (identifies the function of the authentication terminal 51). The authentication server 20 acquires requirements for the authentication terminal 51 to provide services to the user based on the type of the authentication terminal 51 . For example, if the authentication terminal 51 is a gate device installed at a boarding gate, the authentication server 20 acquires the requirements for passing through the gate device (for example, the user possesses a valid passport and boarding pass). .
 さらに、認証サーバ20は、取得した生体情報と被認証者情報データベースに記憶された生体情報を用いた生体認証により利用者を特定する。認証サーバ20は、特定した利用者の各情報(パスポート情報、搭乗券情報、健康パスポート情報)と上記特定した認証端末51の要件に基づいて当該利用者にサービスの提供が可能か否か判定する。 Furthermore, the authentication server 20 identifies the user through biometric authentication using the acquired biometric information and the biometric information stored in the authenticated person information database. The authentication server 20 determines whether or not the service can be provided to the user based on each information (passport information, boarding pass information, health passport information) of the specified user and the requirements of the specified authentication terminal 51. .
 認証端末51は、利用者にサービスの提供が可能と判定すれば認証結果を「認証成功」に設定する。認証端末51は、利用者にサービスの提供が不可能と判定すれば認証結果を「認証失敗」に設定する。 If the authentication terminal 51 determines that the service can be provided to the user, it sets the authentication result to "authentication success". If the authentication terminal 51 determines that the service cannot be provided to the user, the authentication terminal 51 sets the authentication result to "authentication failure".
 認証サーバ20は、認証結果(認証成功、認証失敗)を認証端末51に通知する。認証端末51は、認証に成功した利用者にサービスを提供し、認証に失敗した利用者にサービスを提供しない。 The authentication server 20 notifies the authentication terminal 51 of the authentication result (authentication success, authentication failure). The authentication terminal 51 provides services to users who have succeeded in authentication, and does not provide services to users who have failed in authentication.
 ここで、上述のように、生体認証により空港内の手続きを進めるか否かは利用者が決定する事項である。そのため、生体認証を利用しない利用者も存在する。このような利用者の手続きを円滑に進めるため、出発管理サーバ40は、空港内で業務にあたる職員が所持する端末に利用者に関する検証サーバ30の検証結果の詳細を通知してもよい。職員が所持する端末は、各利用者について「健康パスポート情報:OK」、「陰性証明書:OK」のような情報を表示してもよい。そのような情報に接した職員は、業務に健康パスポート情報の確認が必要であれば、当該業務を円滑に進めることができる。なお、この場合、生体情報ではなく利用者が所持するパスポート等によって利用者が特定される。 Here, as described above, it is up to the user to decide whether or not to proceed with procedures in the airport using biometric authentication. Therefore, there are users who do not use biometric authentication. In order to facilitate such procedures for the user, the departure management server 40 may notify the details of the verification result of the verification server 30 regarding the user to the terminal possessed by the staff working in the airport. Terminals carried by staff may display information such as "health passport information: OK" and "negative certificate: OK" for each user. Employees exposed to such information will be able to proceed smoothly with their work if it is necessary to verify the health passport information. In this case, the user is identified by a passport or the like possessed by the user instead of biometric information.
 このように、認証サーバ20は、少なくとも、利用者の第1の生体情報を記憶する。認証端末51は、利用者の第2の生体情報を取得し、当該取得された生体情報を含む認証要求を認証サーバ20に送信する。認証サーバ20は、第1の生体情報及び第2の生体情報を用いた生体認証を行い、認証結果を認証端末51に送信する。認証端末51は、認証に成功した利用者にサービスを提供する。 Thus, the authentication server 20 stores at least the first biometric information of the user. The authentication terminal 51 acquires the second biometric information of the user and transmits an authentication request including the acquired biometric information to the authentication server 20 . The authentication server 20 performs biometric authentication using the first biometric information and the second biometric information, and transmits the authentication result to the authentication terminal 51 . The authentication terminal 51 provides services to users who have successfully authenticated.
 続いて、第1の実施形態に係る出入国管理システムに含まれる各装置の詳細について説明する。 Next, details of each device included in the immigration control system according to the first embodiment will be described.
[予約サーバ]
 予約サーバ10は、利用者による航空券の予約を実現するサーバである。予約サーバ10は、利用者(航空券を購入した利用者)の少なくとも健康パスポート情報を記憶する。
[Reservation server]
The reservation server 10 is a server that realizes airline ticket reservations by users. The reservation server 10 stores at least health passport information of the user (the user who purchased the airline ticket).
 図9は、第1の実施形態に係る予約サーバ10の処理構成(処理モジュール)の一例を示す図である。図9を参照すると、予約サーバ10は、通信制御部201と、予約制御部202と、予約記録送信部203と、記憶部204と、を備える。 FIG. 9 is a diagram showing an example of the processing configuration (processing modules) of the reservation server 10 according to the first embodiment. Referring to FIG. 9, reservation server 10 includes communication control section 201 , reservation control section 202 , reservation record transmission section 203 , and storage section 204 .
 通信制御部201は、他の装置との間の通信を制御する手段である。例えば、通信制御部201は、端末70からデータ(パケット)を受信する。また、通信制御部201は、端末70に向けてデータを送信する。通信制御部201は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部201は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部201を介して他の装置とデータの送受信を行う。通信制御部201は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 201 is means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the terminal 70 . Also, the communication control unit 201 transmits data to the terminal 70 . The communication control unit 201 transfers data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 201 . The communication control unit 201 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 予約制御部202は、利用者による航空券の予約に関する制御を行う手段である。予約制御部202は、利用者が端末70を使用して所定の動作(例えば、チケット予約ページにアクセス)を行うと、航空券を予約するためのGUI(Graphical User Interface)等を端末70に表示する。 The reservation control unit 202 is means for controlling air ticket reservations by users. When the user uses the terminal 70 to perform a predetermined operation (for example, accesses a ticket reservation page), the reservation control unit 202 displays a GUI (Graphical User Interface) or the like for reserving an airline ticket on the terminal 70. do.
 例えば、予約制御部202は、図10に示すようなGUIを表示する。予約制御部202は、図10に示すようなGUIを使って利用者が予約を希望するフライトの情報を取得する。 For example, the reservation control unit 202 displays a GUI as shown in FIG. The reservation control unit 202 uses a GUI as shown in FIG. 10 to obtain information on a flight for which the user wishes to make a reservation.
 また、予約制御部202は、利用者のパスポート情報、健康パスポート情報を取得する。利用者は、端末70を操作して、デジタルウォレットに保管されている、パスポート情報、健康パスポート情報(ワクチン接種証明書、陰性証明書及び回復証明書のうち少なくとも1つ)を選択する。 Also, the reservation control unit 202 acquires the user's passport information and health passport information. The user operates the terminal 70 to select passport information and health passport information (at least one of vaccination certificate, negative certificate and recovery certificate) stored in the digital wallet.
 予約制御部202は、「決定」ボタンが押下されると、航空券を発行する。予約制御部202は、利用者の選択に応じた航空券情報を生成し、端末70に送信する。当該航空券情報は、発行された航空券の内容を含むテキストファイルであってもよいし、航空券の内容を含む(航空券の内容が変換された)2次元コードであってもよい。 The reservation control unit 202 issues an airline ticket when the "Confirm" button is pressed. The reservation control unit 202 generates airline ticket information according to the user's selection and transmits it to the terminal 70 . The airline ticket information may be a text file containing the contents of the issued airline ticket, or a two-dimensional code containing the contents of the airline ticket (in which the contents of the airline ticket are converted).
 予約制御部202は、予約が完了すると、利用者のパスポート情報、健康パスポート情報及び航空券情報を対応付けて利用者情報データベースに記憶する(図11参照)。図11に示すように、利用者情報データベースは、パスポート情報フィールド、航空券情報フィールド、健康パスポート情報フィールドを含む。なお、図11に示す利用者情報データベースは例示であって、記憶する項目等を限定する趣旨ではない。また、図11において、利用者が所持していない(デジタルウォレットに格納されていない)健康パスポート情報を「ハイフン」を用いて表記している。 When the reservation is completed, the reservation control unit 202 associates the user's passport information, health passport information, and airline ticket information and stores them in the user information database (see FIG. 11). As shown in FIG. 11, the user information database includes passport information fields, airline ticket information fields, and health passport information fields. Note that the user information database shown in FIG. 11 is an example, and is not meant to limit the items to be stored. In addition, in FIG. 11, health passport information that the user does not possess (not stored in the digital wallet) is indicated using "hyphens".
 予約記録送信部203は、利用者の航空券予約記録を出発管理サーバ40に送信する手段である。予約記録送信部203は、利用者情報データベースに定期的又は所定のタイミングでアクセスする。予約記録送信部203は、各エントリの航空券情報フィールド(出発時刻フィールド)を確認し、現在時刻から所定時間経過後(例えば、24時間後)に出発する航空機(便名)を抽出する。 The reservation record transmission unit 203 is means for transmitting the user's airline ticket reservation record to the departure management server 40 . The reservation record transmission unit 203 accesses the user information database regularly or at a predetermined timing. The reservation record transmission unit 203 checks the airline ticket information field (departure time field) of each entry, and extracts an aircraft (flight number) that departs after a predetermined time (for example, 24 hours) from the current time.
 予約記録送信部203は、抽出したエントリを航空機(フライト、便名)ごとにまとめ、出発管理サーバ40に送信する。予約記録送信部203は、所定時間経過後に出発する航空機を予約している各利用者のパスポート情報、航空券情報及び健康パスポート情報を「航空券予約記録」として出発管理サーバ40に送信する。 The reservation record transmission unit 203 collects the extracted entries for each aircraft (flight, flight number) and transmits them to the departure management server 40 . The reservation record transmission unit 203 transmits the passport information, airline ticket information, and health passport information of each user who has reserved an aircraft to depart after the elapse of a predetermined time as an "airline ticket reservation record" to the departure management server 40 .
 記憶部204は、予約サーバ10の動作に必要な情報を記憶する手段である。記憶部204には、利用者情報データベースが構築される。 The storage unit 204 is means for storing information necessary for the operation of the reservation server 10. A user information database is constructed in the storage unit 204 .
[出発管理サーバ]
 出発管理サーバ40は、利用者の出国を管理し、航空券を予約した利用者の少なくとも健康に関する健康パスポート情報を記憶する。
[Departure management server]
The departure management server 40 manages the departure of the user and stores at least the health passport information regarding the health of the user who has reserved the airline ticket.
 図12は、第1の実施形態に係る出発管理サーバ40の処理構成(処理モジュール)の一例を示す図である。図12を参照すると、出発管理サーバ40は、通信制御部301と、予約記録制御部302と、搭乗券制御部303と、記憶部304と、を備える。 FIG. 12 is a diagram showing an example of the processing configuration (processing modules) of the departure management server 40 according to the first embodiment. Referring to FIG. 12 , departure management server 40 includes communication control section 301 , reservation record control section 302 , boarding pass control section 303 , and storage section 304 .
 通信制御部301は、他の装置との間の通信を制御する手段である。例えば、通信制御部301は、検証サーバ30からデータ(パケット)を受信する。また、通信制御部301は、検証サーバ30に向けてデータを送信する。通信制御部301は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部301は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部301を介して他の装置とデータの送受信を行う。通信制御部301は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 301 is means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the verification server 30 . Also, the communication control unit 301 transmits data to the verification server 30 . The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301 . The communication control unit 301 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 予約記録制御部302は、予約サーバ10から送信される航空券予約記録(パスポート情報、航空券情報、健康パスポート情報)に関する制御を行う手段である。予約記録制御部302は、予約サーバ10からパスポート情報等を取得すると、当該取得した情報を予約者情報データベースに登録する(図13参照)。 The reservation record control unit 302 is means for controlling air ticket reservation records (passport information, airline ticket information, health passport information) transmitted from the reservation server 10 . When the reservation recording control unit 302 acquires the passport information and the like from the reservation server 10, the acquired information is registered in the reservation person information database (see FIG. 13).
 図13に示すように、予約者情報データベースは、パスポート情報フィールド、航空券情報フィールド、健康パスポート情報フィールド、搭乗券情報フィールドを含む。なお、図13に示す予約者情報データベースは例示であって、記憶する項目等を限定する趣旨ではない。 As shown in FIG. 13, the reservation person information database includes a passport information field, an airline ticket information field, a health passport information field, and a boarding pass information field. Note that the reservation person information database shown in FIG. 13 is an example, and is not meant to limit the items to be stored.
 搭乗券制御部303は、搭乗券の発行等に関する制御を行う手段である。図14を参照して、搭乗券制御部303の動作を説明する。図14は、第1の実施形態に係る搭乗券制御部303の動作の一例を示すフローチャートである。 The boarding pass control unit 303 is means for controlling the issuance of boarding passes. The operation of the boarding pass control unit 303 will be described with reference to FIG. FIG. 14 is a flow chart showing an example of the operation of the boarding pass control unit 303 according to the first embodiment.
 搭乗券制御部303は、チェックイン端末50から「搭乗券発行要求」を受信する(ステップS101)。 The boarding pass control unit 303 receives a "boarding pass issuance request" from the check-in terminal 50 (step S101).
 搭乗券制御部303は、当該要求に含まれるパスポート情報のパスポート番号をキーとして予約者情報データベースを検索し、対応する利用者の特定を試みる(予約者情報データベース(DB;Data Base)を検索;ステップS102)。 The boarding pass control unit 303 searches the reservation person information database using the passport number of the passport information included in the request as a key, and tries to identify the corresponding user (searches the reservation person information database (DB; Data Base); step S102).
 搭乗券制御部303は、検索に失敗し利用者が特定されないと(ステップS103、No分岐)、処理結果に搭乗券の発行不可を設定する(ステップS104)。 If the search fails and the user is not identified (step S103, No branch), the boarding pass control unit 303 sets the processing result to prohibit the issuance of a boarding pass (step S104).
 搭乗券制御部303は、検索に成功し利用者が特定されると(ステップS103、Yes分岐)、対応するエントリの航空券情報と搭乗券発行要求に含まれる航空券情報が一致するか否か判定する(航空券情報の検証;ステップS105)。即ち、搭乗券制御部303は、予約者情報データベースに登録された航空券(事前予約された航空機)とチェックイン端末50から取得した航空券が一致するか否か判定する。 When the search succeeds and the user is specified (step S103, Yes branch), the boarding pass control unit 303 determines whether the airline ticket information in the corresponding entry matches the airline ticket information included in the boarding pass issuance request. Determine (verification of airline ticket information; step S105). That is, the boarding pass control unit 303 determines whether or not the airline ticket (pre-reserved aircraft) registered in the reservation person information database matches the airline ticket obtained from the check-in terminal 50 .
 航空券情報が一致しなければ(ステップS106、No分岐)、搭乗券制御部303は、処理結果に搭乗券の発行不可を設定する(ステップS104)。 If the airline ticket information does not match (step S106, No branch), the boarding pass control unit 303 sets the processing result to prohibit issuance of a boarding pass (step S104).
 航空券情報が一致すれば(ステップS106、Yes分岐)、搭乗券制御部303は、上記検索により特定された利用者のパスポート情報及び健康パスポート情報を含む「入国要件検証要求」を検証サーバ30に送信する(ステップS107) If the airline ticket information matches (step S106, Yes branch), the boarding pass control unit 303 sends to the verification server 30 an "immigration requirements verification request" including the passport information and health passport information of the user specified by the above search. Send (step S107)
 搭乗券制御部303は、検証サーバ30から検証結果(入国可、入国不可)を受信する(ステップS108)。搭乗券制御部303は、検証サーバ30から入国要件検証要求に対する応答(肯定応答、否定応答)を受信する。 The boarding pass control unit 303 receives the verification result (entry permitted, entry denied) from the verification server 30 (step S108). The boarding pass control unit 303 receives a response (positive response, negative response) to the entry requirements verification request from the verification server 30 .
 検証結果が「入国不可」であれば(ステップS109、No分岐)、搭乗券制御部303は、処理結果に搭乗券の発行不可を設定する(ステップS104)。 If the verification result is "impossible to enter the country" (step S109, No branch), the boarding pass control unit 303 sets the processing result to prohibit issuance of a boarding pass (step S104).
 検証結果が「入国可」であれば(ステップS109、Yes分岐)、搭乗券制御部303は、処理結果に搭乗券の発行可を設定する(ステップS110)。 If the verification result is "permitted to enter the country" (step S109, Yes branch), the boarding pass control unit 303 sets the processing result to permit issuance of a boarding pass (step S110).
 その後、搭乗券制御部303は、搭乗券を発行する(ステップS111)。搭乗券制御部303は、航空券情報に記載された席種等を参照し、利用者の座席を決定し、搭乗券(搭乗券情報)を発行する。搭乗券制御部303は、生成した搭乗券の情報(搭乗券情報)を予約者情報データベースに登録する。 After that, the boarding pass control unit 303 issues a boarding pass (step S111). The boarding pass control unit 303 refers to the seat type or the like described in the airline ticket information, determines the seat of the user, and issues a boarding pass (boarding pass information). The boarding pass control unit 303 registers the generated boarding pass information (boarding pass information) in the reservation person information database.
 搭乗券制御部303は、処理結果(搭乗券の発行可、発行不可)をチェックイン端末50に送信する(ステップS112)。 The boarding pass control unit 303 transmits the processing result (boarding pass issuable or not) to the check-in terminal 50 (step S112).
 処理結果が「搭乗券の発行不可」であれば、搭乗券制御部303は、搭乗券を発行できない旨をチェックイン端末50に通知する。具体的には、搭乗券制御部303は、搭乗券を発行できない旨を示す否定応答をチェックイン端末50に送信する。 If the processing result is "cannot issue a boarding pass", the boarding pass control unit 303 notifies the check-in terminal 50 that a boarding pass cannot be issued. Specifically, the boarding pass control unit 303 transmits to the check-in terminal 50 a negative response indicating that the boarding pass cannot be issued.
 処理結果が「搭乗券の発行可」であれば、搭乗券制御部303は、発行した搭乗券(搭乗券情報)をチェックイン端末50に通知する。具体的には、搭乗券制御部303は、搭乗券の発行に成功した旨を示す肯定応答をチェックイン端末50に送信する。その際、搭乗券制御部303は、搭乗券情報を含む肯定応答をチェックイン端末50に送信する。 If the processing result is "boarding pass issuable", the boarding pass control unit 303 notifies the check-in terminal 50 of the issued boarding pass (boarding pass information). Specifically, the boarding pass control unit 303 transmits to the check-in terminal 50 an affirmative response indicating that the boarding pass has been successfully issued. At that time, the boarding pass control unit 303 transmits an acknowledgment including the boarding pass information to the check-in terminal 50 .
 検証サーバ30から入国要件の検証に関する詳細を受信した場合には、搭乗券制御部303は、当該詳細を含む応答(肯定応答、否定応答)をチェックイン端末50に送信してもよい。 When receiving details regarding the verification of entry requirements from the verification server 30, the boarding pass control unit 303 may send a response (positive response, negative response) including the details to the check-in terminal 50.
 さらに、搭乗券制御部303は、搭乗券を発行した利用者の情報を到着国のCIQサーバ60に通知する。具体的には、搭乗券制御部303は、利用者のパスポート情報及び健康パスポート情報を含む「搭乗者情報通知」をCIQサーバ60に送信する(ステップS113)。 Furthermore, the boarding pass control unit 303 notifies the CIQ server 60 of the arrival country of the information of the user who issued the boarding pass. Specifically, the boarding pass control unit 303 transmits a "passenger information notification" including the user's passport information and health passport information to the CIQ server 60 (step S113).
 このように、搭乗券制御部303は、利用者のチェックイン手続きを実現し、搭乗券の発行に成功すると、当該搭乗券に関する搭乗券情報をチェックイン端末50に通知する。その際、搭乗券制御部303は、検証サーバ30は、入国要件の検証に関する詳細情報を取得すると、当該入国要件の検証に関する詳細情報をチェックイン端末50に通知してもよい。チェックイン端末50は、入国要件の検証に関する詳細情報が記載された搭乗券を発券することができる。 In this way, the boarding pass control unit 303 realizes the user's check-in procedure, and when the boarding pass is successfully issued, notifies the check-in terminal 50 of the boarding pass information related to the boarding pass. At that time, when the verification server 30 acquires the detailed information regarding the verification of the entry requirements, the boarding pass control section 303 may notify the check-in terminal 50 of the detailed information regarding the verification of the entry requirements. The check-in terminal 50 may issue a boarding pass with detailed information regarding verification of entry requirements.
 また、搭乗券制御部303は、到着国の到着空港に設置され、利用者が入国する際の税関、入国管理、検疫に関する処理を行うCIQサーバ60に、到着国に入国する利用者の搭乗者情報(パスポート情報、健康パスポート情報を含む情報)を送信する。搭乗券制御部303が搭乗者情報をCIQサーバ60に送信することで、政府機関との情報連携が実現される。 In addition, the boarding pass control unit 303 is installed in the arrival airport of the arrival country, and the CIQ server 60 that performs processing related to customs, immigration control, and quarantine when the user enters the country. Send information (including passport information, health passport information). By sending the passenger information to the CIQ server 60 by the boarding pass control unit 303, information cooperation with government agencies is realized.
 記憶部304は、出発管理サーバ40の動作に必要な情報を記憶する手段である。記憶部304には、予約者情報データベースが構築される。 The storage unit 304 is means for storing information necessary for the operation of the departure management server 40 . A reservation person information database is constructed in the storage unit 304 .
[検証サーバ]
 図15は、第1の実施形態に係る検証サーバ30の処理構成(処理モジュール)の一例を示す図である。図15を参照すると、検証サーバ30は、通信制御部401と、入国要件検証部402と、記憶部403と、を備える。
[Validation server]
FIG. 15 is a diagram showing an example of a processing configuration (processing modules) of the verification server 30 according to the first embodiment. Referring to FIG. 15 , verification server 30 includes communication control section 401 , immigration requirement verification section 402 , and storage section 403 .
 通信制御部401は、他の装置との間の通信を制御する手段である。例えば、通信制御部401は、出発管理サーバ40からデータ(パケット)を受信する。また、通信制御部401は、出発管理サーバ40に向けてデータを送信する。通信制御部401は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部401は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部401を介して他の装置とデータの送受信を行う。通信制御部401は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 401 is means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the departure management server 40 . The communication control unit 401 also transmits data to the departure management server 40 . The communication control unit 401 transfers data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 401 . The communication control unit 401 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 入国要件検証部402は、渡航者の入国要件に関する検証を行う手段である。入国要件検証部402は、出発管理サーバ40から受信した入国要件検証要求を処理する。入国要件検証部402は、入国要件データベースを参照し、入国要件検証要求を処理する。 The entry requirements verification unit 402 is a means of verifying the entry requirements of travelers. The entry requirements verification unit 402 processes the entry requirements verification request received from the departure management server 40 . The entry requirements verification unit 402 refers to the entry requirements database and processes the entry requirements verification request.
 図16は、第1の実施形態に係る入国要件データベースの一例を示す図である。図16に示すように、入国要件データベースは、国別(空港コード別)に、入国要件を記憶する。入国要件には、パスポート情報に関する入国要件、健康パスポート情報に関する入国要件等が含まれる。なお、図16に示す入国要件データベースは例示であって、記憶する項目等を限定する趣旨ではない。 FIG. 16 is a diagram showing an example of the entry requirement database according to the first embodiment. As shown in FIG. 16, the entry requirements database stores entry requirements by country (by airport code). Entry requirements include entry requirements for passport information and entry requirements for health passport information. Note that the immigration requirement database shown in FIG. 16 is an example, and is not meant to limit the items to be stored.
 入国要件検証部402は、入国要件データベースを参照し、入国要件検証要求に含まれる到着空港に関する情報(空港コード)に対応する入国要件を読み出す。入国要件検証部402は、読み出した入国要件と、入国要件検証要求に含まれるパスポート情報及び健康パスポート情報と、を用いて渡航者が到着国の入国要件を満たすか否か判定する。 The entry requirements verification unit 402 refers to the entry requirements database and reads the entry requirements corresponding to the information on the arrival airport (airport code) included in the entry requirements verification request. The entry requirements verification unit 402 uses the read entry requirements and the passport information and health passport information included in the entry requirements verification request to determine whether the traveler satisfies the entry requirements of the arrival country.
 例えば、入国要件検証部402は、パスポート情報の国籍を用いて到着国の入国要件を満たすか否か判定する。あるいは、入国要件検証部402は、到着国が定める種類の健康パスポート情報を利用者が所持しているか否か判定する。例えば、到着国が有効な「ワクチン接種証明書」や「陰性証明書」の所持を入国要件として定めている場合、入国要件検証部402は、入国要件検証要求に有効な「ワクチン接種証明書」や「陰性証明書」が含まれるか否か判定する。換言すれば、入国要件検証部402は、入国要件検証要求に有効な「回復証明書」が含まれていても、上記到着国の入国要件を満たすとは判定しない。 For example, the entry requirements verification unit 402 uses the nationality of the passport information to determine whether the entry requirements of the arrival country are met. Alternatively, the entry requirements verification unit 402 determines whether or not the user possesses the type of health passport information specified by the arrival country. For example, if the arrival country stipulates possession of a valid "vaccination certificate" or "negative certificate" as entry requirements, the entry requirements verification unit or "negative certificate" is included. In other words, the entry requirements verification unit 402 does not determine that the entry requirements of the destination country are satisfied even if the entry requirements verification request includes a valid "recovery certificate".
 あるいは、入国要件検証部402は、有効なワクチン接種証明書や有効な陰性証明書であっても、到着国の求めるワクチンや求める方法で検査されていなければ入国要件を満たさないと判定する。 Alternatively, the immigration requirements verification unit 402 determines that even a valid vaccination certificate or a valid negative certificate does not meet the entry requirements if it has not been tested with the vaccine or method required by the country of arrival.
 入国要件検証部402は、検証結果(入国可、入国不可)を出発管理サーバ40に通知する。入国要件を満たすと判定された場合、入国要件検証部402は、渡航者は入国可であることを示す肯定応答を出発管理サーバ40に送信する。入国要件を満たさないと判定された場合、入国要件検証部402は、渡航者は入国不可であることを示す否定応答を出発管理サーバ40に送信する。 The entry requirements verification unit 402 notifies the departure management server 40 of the verification result (entry permitted, entry denied). If it is determined that the entry requirements are satisfied, the entry requirements verification unit 402 transmits to the departure management server 40 a positive response indicating that the traveler is permitted to enter the country. If it is determined that the entry requirements are not met, the entry requirements verification unit 402 sends a negative response to the departure management server 40 indicating that the traveler is not allowed to enter the country.
 入国要件検証部402は、入国要件の検証に関する詳細を出発管理サーバ40に通知してもよい。例えば、入国要件検証部402は、入国不可と判定した場合には、当該判定の要因となった事項を出発管理サーバ40に通知する。例えば、入国要件検証部402は、「有効なワクチン接種証明書を所持していない」や「陰性証明書の検査方法が入国要件に合致しない」といった詳細情報を出発管理サーバ40に通知する。 The immigration requirement verification unit 402 may notify the departure management server 40 of details regarding the verification of entry requirements. For example, when the immigration requirement verification unit 402 determines that the entry is not allowed, it notifies the departure management server 40 of the factors that led to the determination. For example, the entry requirements verification unit 402 notifies the departure management server 40 of detailed information such as "I do not have a valid vaccination certificate" and "The test method for the negative certificate does not meet the entry requirements".
 あるいは、入国可と判定された場合に、入国要件検証部402は、判定対象となった入国要件の全部又は一部の詳細を出発管理サーバ40に通知してもよい。例えば、健康パスポート情報に関し、入国要件検証部402は、「ワクチン接種証明書に関する検証は問題なし(ワクチン接種証明書:OK)」、「陰性証明書に関する検証は問題なし(陰性証明書:OK)」といった詳細情報を出発管理サーバ40に通知する。 Alternatively, when it is determined that entry is permitted, the entry requirement verification unit 402 may notify the departure management server 40 of the details of all or part of the entry requirements subject to the determination. For example, regarding the health passport information, the immigration requirement verification unit 402 indicates that "there is no problem with the verification of the vaccination certificate (vaccination certificate: OK)" and "there is no problem with the verification of the negative certificate (negative certificate: OK)". ” to the departure management server 40 .
 入国要件検証部402は、入国要件の検証結果に関する詳細を含む肯定応答や否定応答を出発管理サーバ40に送信してもよい。 The immigration requirements verification unit 402 may send a positive response or a negative response including details regarding the verification result of the immigration requirements to the departure management server 40 .
 記憶部403は、検証サーバ30の動作に必要な情報を記憶する手段である。記憶部403には、入国要件データベースが構築される。 The storage unit 403 is means for storing information necessary for the operation of the verification server 30 . An entry requirements database is constructed in the storage unit 403 .
[認証サーバ]
 図17は、第1の実施形態に係る認証サーバ20の処理構成(処理モジュール)の一例を示す図である。図17を参照すると、認証サーバ20は、通信制御部501と、利用登録制御部502と、認証部503と、記憶部504と、を備える。
[Authentication server]
FIG. 17 is a diagram showing an example of the processing configuration (processing modules) of the authentication server 20 according to the first embodiment. Referring to FIG. 17 , the authentication server 20 includes a communication control section 501 , a usage registration control section 502 , an authentication section 503 and a storage section 504 .
 通信制御部501は、他の装置との間の通信を制御する手段である。例えば、通信制御部501は、認証端末51からデータ(パケット)を受信する。また、通信制御部501は、認証端末51に向けてデータを送信する。通信制御部501は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部501は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部501を介して他の装置とデータの送受信を行う。通信制御部501は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 501 is means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the authentication terminal 51 . Also, the communication control unit 501 transmits data to the authentication terminal 51 . The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 501 . The communication control unit 501 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 利用登録制御部502は、利用者の生体認証利用登録に関する制御を行う手段である。利用登録制御部502は、利用者が端末70を使用して所定の動作(例えば、生体認証利用登録ページにアクセス)を行うと、当該利用者の生体認証を実現する情報を取得するためのGUI等を端末70に表示する。 The use registration control unit 502 is means for controlling the user's biometric authentication use registration. When the user performs a predetermined operation (for example, accesses a biometrics authentication usage registration page) using the terminal 70, the usage registration control unit 502 displays a GUI for acquiring information for realizing biometrics authentication of the user. etc. are displayed on the terminal 70 .
 例えば、利用登録制御部502は、図18に示すようなGUIを端末70に表示する。利用登録制御部502は、図18に示すようなGUIによって利用者の生体情報、パスポート情報、搭乗券情報及び健康パスポート情報を取得する。利用登録制御部502は、顔画像を生体情報として取得した場合には、当該顔画像から特徴量を生成する。 For example, the usage registration control unit 502 displays a GUI as shown in FIG. The use registration control unit 502 acquires the user's biometric information, passport information, boarding pass information, and health passport information through a GUI as shown in FIG. When the use registration control unit 502 acquires a face image as biometric information, the use registration control unit 502 generates a feature amount from the face image.
 利用登録制御部502は、取得した生体情報等を被認証者情報データベースに記憶する(図19参照)。図19は、第1の実施形態に係る被認証者情報データベースの一例を示す図である。図19に示すように、被認証者情報データベースは、被認証者の生体情報(特徴量)、パスポート情報、搭乗券情報及び健康パスポート情報を対応付けて記憶する。なお、図19に示す被認証者情報データベースは例示であって、記憶する項目等を限定する趣旨ではない。 The usage registration control unit 502 stores the acquired biometric information in the authenticated person information database (see FIG. 19). FIG. 19 is a diagram showing an example of an authenticated person information database according to the first embodiment. As shown in FIG. 19, the authenticated person information database stores the biometric information (feature amount) of the authenticated person, passport information, boarding pass information, and health passport information in association with each other. Note that the authentication-subjected person information database shown in FIG. 19 is an example, and is not intended to limit the items to be stored.
 認証部503は、認証端末51に到着した利用者(被認証者)の生体認証を行う手段である。認証部503は、認証端末51から被認証者の生体情報と端末IDを含む認証要求を受信する。認証部503は、取得された生体情報と被認証者情報データベースに記憶された生体情報を用いた生体認証を行う。 The authentication unit 503 is means for performing biometric authentication of the user (person to be authenticated) who has arrived at the authentication terminal 51 . The authentication unit 503 receives an authentication request including the biometric information of the person to be authenticated and the terminal ID from the authentication terminal 51 . The authentication unit 503 performs biometric authentication using the acquired biometric information and the biometric information stored in the authentication subject information database.
 より具体的には、認証部503は、認証要求から生体情報(特徴量)を取り出す。認証部503は、当該特徴量を照合対象に設定し、被認証者情報データベースに登録された特徴量との間で照合処理を行う。より具体的には、認証部503は、上記取り出した特徴量(特徴ベクトル)を照合対象に設定し、被認証者情報データベースに登録されている複数の特徴量との間で1対N(Nは正の整数、以下同じ)照合処理を実行する。 More specifically, the authentication unit 503 extracts biometric information (feature amount) from the authentication request. The authenticating unit 503 sets the feature amount as a matching target, and performs matching processing with the feature amount registered in the authenticated person information database. More specifically, the authentication unit 503 sets the extracted feature amount (feature vector) as a matching object, and compares the extracted feature amount (feature vector) with a plurality of feature amounts registered in the authenticated person information database in a one-to-N (N is a positive integer, the same applies below).
 認証部503は、照合対象の特徴量と登録側の複数の特徴量それぞれとの間の類似度を計算する。当該類似度には、カイ二乗距離やユークリッド距離等を用いることができる。なお、距離が離れているほど類似度は低く、距離が近いほど類似度が高い。 The authentication unit 503 calculates the degree of similarity between the feature amount to be matched and each of the plurality of feature amounts on the registration side. Chi-square distance, Euclidean distance, or the like can be used for the degree of similarity. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
 認証部503は、被認証者情報データベースに登録された複数の特徴量のうち、照合対象の特徴量との間の類似度が所定の値以上の特徴量が存在すれば、照合処理に成功したと判定する。認証部503は、被認証者情報データベースに登録された複数の特徴量のうち、照合対象の特徴量との間の類似度が所定の値以上の特徴量が存在しなければ、照合処理に失敗したと判定する。 The authenticating unit 503 succeeds in the matching process if there is a feature amount whose similarity to the feature amount to be matched is equal to or greater than a predetermined value among the plurality of feature amounts registered in the authentication subject information database. I judge. The authenticating unit 503 fails the matching process if there is no feature amount whose similarity to the matching target feature amount is equal to or greater than a predetermined value among the plurality of feature amounts registered in the authentication subject information database. It is determined that
 照合処理に失敗すると、認証部503は、認証結果に「認証失敗」を設定する。照合処理に成功すると、認証部503は、類似度が最も高いエントリ(被認証者情報データベースのエントリ)を特定し、対応するパスポート情報、健康パスポート情報及び搭乗券情報を読み出す。 If the verification process fails, the authentication unit 503 sets "authentication failure" to the authentication result. If the collation process succeeds, the authentication unit 503 identifies the entry with the highest degree of similarity (entries in the person-to-be-authenticated information database), and reads out the corresponding passport information, health passport information, and boarding pass information.
 認証部503は、認証要求に含まれる端末IDから認証端末51の種類を特定し、被認証者のパスポート情報等が、上記特定した認証端末51に予め定められた要件(認証成功と判定されるための要件)を満たすか否か判定する。 The authentication unit 503 identifies the type of the authentication terminal 51 from the terminal ID included in the authentication request, and the passport information of the person to be authenticated meets the predetermined requirements for the identified authentication terminal 51 (determined as successful authentication). requirements) are met.
 例えば、認証端末51の被認証者を「認証成功」と判定するための要件が「有効なパスポートを所持」と「有効な陰性証明書を所持」であれば、認証部503は、読み出したパスポート情報及び健康パスポート情報を参照し、当該要件を満たすか否か判定する。 For example, if the requirements for determining that the person to be authenticated of the authentication terminal 51 is "successfully authenticated" are "having a valid passport" and "having a valid negative certificate", the authentication unit 503 reads the passport Refer to information and health passport information to determine whether or not the requirements are met.
 要件を満たす場合には、認証部503は、被認証者の認証結果を「認証成功」に設定する。要件を満たさない場合には、認証部503は、被認証者の認証結果を「認証失敗」に設定する。 If the requirements are satisfied, the authentication unit 503 sets the authentication result of the person to be authenticated to "successful authentication". If the requirements are not met, the authentication unit 503 sets the authentication result of the person-to-be-authenticated to "authentication failure".
 認証部503は、認証結果(認証成功、認証失敗)を認証端末51に通知する。認証成功の場合には、認証部503は、その旨を示す肯定応答を認証端末51に送信する。認証失敗の場合には、認証部503は、その旨を示す否定応答を認証端末51に送信する。 The authentication unit 503 notifies the authentication terminal 51 of the authentication result (authentication success, authentication failure). In the case of authentication success, the authentication unit 503 transmits an affirmative response to that effect to the authentication terminal 51 . In the case of authentication failure, the authentication unit 503 transmits a negative response to that effect to the authentication terminal 51 .
 認証部503は、認証成功を認証端末51に通知する際には、認証成功者のパスポート情報等を認証端末51に通知してもよい。 When notifying the authentication terminal 51 of successful authentication, the authentication unit 503 may notify the authentication terminal 51 of the passport information of the person who has successfully authenticated.
 記憶部504は、認証サーバ20の動作に必要な情報を記憶する手段である。記憶部504には、被認証者情報データベースが構築される。 The storage unit 504 is means for storing information necessary for the operation of the authentication server 20. An authenticated person information database is constructed in the storage unit 504 .
[CIQサーバ]
 図20は、第1の実施形態に係るCIQサーバ60の処理構成(処理モジュール)の一例を示す図である。図20を参照すると、CIQサーバ60は、通信制御部601と、搭乗者情報処理部602と、記憶部603と、を備える。
[CIQ Server]
FIG. 20 is a diagram showing an example of the processing configuration (processing modules) of the CIQ server 60 according to the first embodiment. Referring to FIG. 20 , CIQ server 60 includes communication control section 601 , passenger information processing section 602 , and storage section 603 .
 通信制御部601は、他の装置との間の通信を制御する手段である。例えば、通信制御部601は、出発管理サーバ40からデータ(パケット)を受信する。また、通信制御部601は、出発管理サーバ40に向けてデータを送信する。通信制御部601は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部601は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部601を介して他の装置とデータの送受信を行う。通信制御部601は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 601 is means for controlling communication with other devices. For example, the communication control unit 601 receives data (packets) from the departure management server 40 . The communication control unit 601 also transmits data to the departure management server 40 . The communication control unit 601 passes data received from other devices to other processing modules. The communication control unit 601 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 601 . The communication control unit 601 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to another device.
 搭乗者情報処理部602は、出発管理サーバ40から受信する搭乗者情報通知を処理する手段である。搭乗者情報処理部602は、当該通知に含まれるパスポート情報と健康パスポート情報を税関、入国審査、検疫を行う各政府機関に提供する。より具体的には、搭乗者情報処理部602は、パスポート情報及び健康パスポート情報を税関等の職員が使用する端末に送信する。 The passenger information processing unit 602 is means for processing passenger information notifications received from the departure management server 40 . Passenger information processing unit 602 provides the passport information and health passport information included in the notification to each government agency responsible for customs, immigration, and quarantine. More specifically, the passenger information processing unit 602 transmits passport information and health passport information to terminals used by customs officials.
 職員が使用する端末に送信されたパスポート情報や健康パスポート情報は、各部署の業務に活用される。 Passport information and health passport information sent to the terminals used by staff will be used for the work of each department.
 記憶部603は、CIQサーバ60の動作に必要な情報を記憶する手段である。 The storage unit 603 is means for storing information necessary for the operation of the CIQ server 60.
[チェックイン端末]
 チェックイン端末50は、利用者により予約された航空券(利用者が購入した航空券)に関する航空券情報を取得し、チェックイン手続きを実現する端末である。
[Check-in terminal]
The check-in terminal 50 is a terminal that acquires airline ticket information related to an airline ticket reserved by a user (an airline ticket purchased by the user) and implements a check-in procedure.
 図21は、第1の実施形態に係るチェックイン端末50の処理構成(処理モジュール)の一例を示す図である。図21を参照すると、チェックイン端末50は、通信制御部701と、チェックイン制御部702と、記憶部703と、を備える。 FIG. 21 is a diagram showing an example of the processing configuration (processing modules) of the check-in terminal 50 according to the first embodiment. Referring to FIG. 21, the check-in terminal 50 includes a communication control section 701, a check-in control section 702, and a storage section 703.
 通信制御部701は、他の装置との間の通信を制御する手段である。例えば、通信制御部701は、出発管理サーバ40からデータ(パケット)を受信する。また、通信制御部701は、出発管理サーバ40に向けてデータを送信する。通信制御部701は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部701は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部701を介して他の装置とデータの送受信を行う。通信制御部701は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 701 is means for controlling communication with other devices. For example, the communication control unit 701 receives data (packets) from the departure management server 40 . The communication control unit 701 also transmits data to the departure management server 40 . The communication control unit 701 passes data received from other devices to other processing modules. The communication control unit 701 transmits data acquired from other processing modules to other devices. In this manner, other processing modules transmit and receive data to and from other devices via the communication control unit 701 . The communication control unit 701 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to another device.
 チェックイン制御部702は、利用者のチェックイン手続きに関する制御を行う手段である。利用者が自装置にて所定の動作(例えば、チェックイン開始ボタンの押下)を行うと、チェックイン制御部702は、当該利用者の生体情報、パスポート情報及び航空券情報を取得する。 The check-in control unit 702 is means for controlling the user's check-in procedure. When the user performs a predetermined action (for example, pressing a check-in start button) on the device, the check-in control unit 702 acquires the user's biometric information, passport information, and airline ticket information.
 例えば、チェックイン制御部702は、図22に示すようなGUIを表示し、「撮影」ボタンの押下を検出すると、自装置に搭載されたカメラ装置を制御して利用者の生体情報(顔画像)を取得する。また、チェックイン制御部702は、「開始」ボタンの押下を検出すると、スキャナーを制御し、パスポート情報及び航空券情報を取得する。 For example, the check-in control unit 702 displays a GUI as shown in FIG. 22, and upon detecting pressing of the “photograph” button, controls the camera device installed in the check-in control unit 702 to display the biometric information (face image) of the user. ). When the check-in control unit 702 detects pressing of the "start" button, the check-in control unit 702 controls the scanner to acquire passport information and airline ticket information.
 なお、電子媒体のパスポートや航空券がデジタルウォレットに保管されている場合には、利用者は、端末70を操作してパスポート情報や航空券情報が変換された2次元コードを表示してもよい。チェックイン制御部702は、端末70に表示された2次元コードを読み取ってパスポート情報、航空券情報を取得してもよい。 If the electronic passport or airline ticket is stored in a digital wallet, the user may operate the terminal 70 to display the two-dimensional code converted from the passport information or airline ticket information. . The check-in control unit 702 may read the two-dimensional code displayed on the terminal 70 to acquire passport information and airline ticket information.
 チェックイン制御部702は、取得した顔画像から特徴量を生成する。また、チェックイン制御部702は、パスポート情報に含まれる(パスポートに記載された)顔画像から特徴量を生成する。 The check-in control unit 702 generates a feature amount from the acquired face image. Also, the check-in control unit 702 generates a feature amount from the face image included in the passport information (described in the passport).
 チェックイン制御部702は、生成した2つの特徴量を用いた生体認証(1対1認証)を実行する。 The check-in control unit 702 executes biometric authentication (one-to-one authentication) using the two generated feature amounts.
 生体認証に失敗すると、チェックイン制御部702は、チェックイン手続きに失敗した旨を利用者に通知する。その際、チェックイン制御部702は、航空会社の職員等が待機しているカウンターに向かうように案内してもよい。 If biometric authentication fails, the check-in control unit 702 notifies the user that the check-in procedure has failed. At that time, the check-in control unit 702 may guide the passenger to go to the counter where an airline staff member or the like is waiting.
 生体認証に成功すると、チェックイン制御部702は、利用者のパスポート情報及び航空券情報を含む「搭乗券発行要求」を出発管理サーバ40に送信する。 When the biometric authentication is successful, the check-in control unit 702 sends a "boarding pass request" including the user's passport information and airline ticket information to the departure management server 40.
 チェックイン制御部702は、出発管理サーバ40から応答(肯定応答、否定応答)を受信する。 The check-in control unit 702 receives a response (positive response, negative response) from the departure management server 40.
 否定応答(搭乗券の発行不可)を受信した場合には、チェックイン制御部702は、搭乗券を発券できない旨を利用者に通知する。 When receiving a negative response (boarding pass issuance not possible), the check-in control unit 702 notifies the user that a boarding pass cannot be issued.
 肯定応答(搭乗券情報を含む応答)を受信した場合には、チェックイン制御部702は、搭乗券を発券する。例えば、チェックイン制御部702は、図23Aに示すような内容が記載された紙媒体又は電子媒体の搭乗券を発券する。 When a positive response (response including boarding pass information) is received, the check-in control unit 702 issues a boarding pass. For example, the check-in control unit 702 issues a paper medium or electronic medium boarding pass with the content shown in FIG. 23A.
 なお、出発管理サーバ40から入国要件の検証結果に関する詳細情報が通知された場合には、チェックイン制御部702は、当該詳細情報が記載された搭乗券を発券してもよい(図23B参照)。あるいは、検証サーバ30による入国要件の検証結果(入国可)が搭乗券に記載されていてもよい。 When the departure management server 40 notifies the detailed information about the verification result of the immigration requirements, the check-in control unit 702 may issue a boarding pass on which the detailed information is described (see FIG. 23B). . Alternatively, the verification result of the entry requirements (entry allowed) by the verification server 30 may be described in the boarding pass.
 図23A及び図23Bに示すような搭乗券は、チェックイン端末50に表示されてもよいし、利用者が所持する端末70に表示さてもよい。あるいは、図23A及び図23Bに示すような搭乗券は、空港会社や航空会社の職員等が使用する端末に表示されてもよい。あるいは、利用者は、端末70を操作することで、後述するオンラインチェックインやチェックイン端末50(キオスク端末)から搭乗券に関する情報を読み取り、端末70に搭乗券情報を格納してもよい。 A boarding pass as shown in FIGS. 23A and 23B may be displayed on the check-in terminal 50 or may be displayed on the terminal 70 carried by the user. Alternatively, the boarding pass as shown in FIGS. 23A and 23B may be displayed on a terminal used by an airport company, airline staff, or the like. Alternatively, the user may operate the terminal 70 to read information about the boarding pass from the online check-in described below or from the check-in terminal 50 (kiosk terminal), and store the boarding pass information in the terminal 70 .
 記憶部703は、チェックイン端末50の動作に必要な情報を記憶する手段である。 The storage unit 703 is means for storing information necessary for the operation of the check-in terminal 50.
[認証端末]
 図24は、第1の実施形態に係る認証端末51の処理構成(処理モジュール)の一例を示す図である。図24を参照すると、認証端末51は、通信制御部801と、生体情報取得部802と、認証要求部803と、記憶部804と、を備える。
[Authentication terminal]
FIG. 24 is a diagram showing an example of a processing configuration (processing modules) of the authentication terminal 51 according to the first embodiment. Referring to FIG. 24 , authentication terminal 51 includes communication control section 801 , biometric information acquisition section 802 , authentication request section 803 , and storage section 804 .
 通信制御部801は、他の装置との間の通信を制御する手段である。例えば、通信制御部801は、認証サーバ20からデータ(パケット)を受信する。また、通信制御部801は、認証サーバ20に向けてデータを送信する。通信制御部801は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部801は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部801を介して他の装置とデータの送受信を行う。通信制御部801は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 801 is means for controlling communication with other devices. For example, the communication control unit 801 receives data (packets) from the authentication server 20 . Also, the communication control unit 801 transmits data to the authentication server 20 . The communication control unit 801 passes data received from other devices to other processing modules. The communication control unit 801 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 801 . The communication control unit 801 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 生体情報取得部802は、カメラ装置(認証端末51が備えるカメラ装置)を制御し、面前の利用者の生体情報(例えば、顔画像)を取得する手段である。生体情報取得部802は、定期的又は所定のタイミングにおいて自装置の前方を撮像する。生体情報取得部802は、取得した画像に人の顔画像が含まれるか否かを判定し、顔画像が含まれる場合には取得した画像データから顔画像を抽出する。 The biometric information acquisition unit 802 is means for controlling the camera device (the camera device provided in the authentication terminal 51) and acquiring the biometric information (for example, face image) of the user in front of the user. The biological information acquisition unit 802 captures an image of the front of the device periodically or at a predetermined timing. The biometric information acquisition unit 802 determines whether or not the acquired image contains a face image of a person, and if the face image is contained, extracts the face image from the acquired image data.
 なお、生体情報取得部802による顔画像の検出処理や顔画像の抽出処理には既存の技術を用いることができるので詳細な説明を省略する。例えば、生体情報取得部802は、CNN(Convolutional Neural Network)により学習された学習モデルを用いて、画像データの中から顔画像(顔領域)を抽出してもよい。あるいは、生体情報取得部802は、テンプレートマッチング等の手法を用いて顔画像を抽出してもよい。 Since existing techniques can be used for face image detection processing and face image extraction processing by the biometric information acquisition unit 802, detailed description thereof will be omitted. For example, the biometric information acquisition unit 802 may extract a face image (face region) from image data using a learning model learned by a CNN (Convolutional Neural Network). Alternatively, the biometric information acquisition unit 802 may extract a facial image using a technique such as template matching.
 生体情報取得部802は、抽出した顔画像から特徴量を生成する。生体情報取得部802は、生成した特徴量を認証要求部803に引き渡す。 The biometric information acquisition unit 802 generates a feature amount from the extracted face image. The biometric information acquisition unit 802 passes the generated feature amount to the authentication request unit 803 .
 認証要求部803は、認証サーバ20に対して面前の利用者に関する認証を要求する手段である。認証要求部803は、取得した生体情報と端末IDを含む認証要求を生成し、認証サーバ20に送信する。 The authentication requesting unit 803 is means for requesting authentication of the user in front of the authentication server 20 . The authentication requesting unit 803 generates an authentication request including the acquired biometric information and the terminal ID, and transmits the authentication request to the authentication server 20 .
 認証要求部803は、認証要求に対する認証サーバ20からの応答(認証成功、認証失敗)を受信する。 The authentication request unit 803 receives a response (authentication success, authentication failure) from the authentication server 20 to the authentication request.
 認証要求部803は、認証結果が「認証失敗」であれば、その旨を利用者(認証失敗者;認証失敗と判定された被認証者)に通知する。例えば、認証要求部803は、「ゲート通過には有効なワクチン接種証明書が必要です。対応を職員にお尋ね下さい。」といったメッセージを出力する。例えば、認証要求部803は、液晶パネル等の表示デバイスやスピーカー等の音響デバイスを使って上記メッセージを被認証者に通知する。 If the authentication result is "authentication failure", the authentication requesting unit 803 notifies the user (authentication failure person; person to be authenticated who is determined to have failed authentication) to that effect. For example, the authentication requesting unit 803 outputs a message such as "A valid vaccination certificate is required to pass through the gate. Please ask the staff how to deal with this." For example, the authentication requesting unit 803 uses a display device such as a liquid crystal panel or an acoustic device such as a speaker to notify the person to be authenticated of the message.
 認証要求部803は、認証結果が「認証成功」であれば、利用者(認証成功者;認証成功と判定された被認証者)に対してサービスを提供する。例えば、搭乗口に設置された認証端末51は、ゲートを開き当該ゲートを通行するように案内する。 If the authentication result is "successful authentication", the authentication requesting unit 803 provides services to the user (authenticated person; person to be authenticated who is determined to be authenticated successfully). For example, the authentication terminal 51 installed at the boarding gate opens the gate and guides the user to pass through the gate.
 記憶部804は、認証端末51の動作に必要な情報を記憶する手段である。 The storage unit 804 is means for storing information necessary for the operation of the authentication terminal 51 .
[端末]
 図25は、第1の実施形態に係る端末70の処理構成(処理モジュール)の一例を示す図である。図25を参照すると、端末70は、通信制御部901と、電子財布制御部902と、航空券予約部903と、利用登録部904と、記憶部905と、を備える。
[Terminal]
FIG. 25 is a diagram showing an example of a processing configuration (processing modules) of the terminal 70 according to the first embodiment. Referring to FIG. 25, the terminal 70 includes a communication control section 901, an electronic wallet control section 902, an airline ticket reservation section 903, a usage registration section 904, and a storage section 905.
 通信制御部901は、他の装置との間の通信を制御する手段である。例えば、通信制御部901は、予約サーバ10からデータ(パケット)を受信する。また、通信制御部901は、予約サーバ10に向けてデータを送信する。通信制御部901は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部901は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部901を介して他の装置とデータの送受信を行う。通信制御部901は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。 The communication control unit 901 is means for controlling communication with other devices. For example, the communication control unit 901 receives data (packets) from the reservation server 10 . Also, the communication control unit 901 transmits data to the reservation server 10 . The communication control unit 901 passes data received from other devices to other processing modules. The communication control unit 901 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 901 . The communication control unit 901 has a function as a receiving unit that receives data from another device and a function as a transmitting unit that transmits data to the other device.
 電子財布制御部902は、デジタルウォレットに関する管理、制御等を行う手段である。電子財布制御部902は、利用者の操作に応じて各種証明書等を取得し、記憶部905に記憶する。 The electronic wallet control unit 902 is a means for managing and controlling digital wallets. The electronic wallet control unit 902 acquires various certificates and the like according to the user's operation, and stores them in the storage unit 905 .
 なお、電子財布制御部902は、端末70にインストールされたアプリケーションにより実現される。デジタルウォレットを実現するためのアプリケーションに関するインストールや具体的な証明書等の登録に関する詳細な説明は省略する。これらの動作等は、本願開示の趣旨とは異なるためである。 The electronic wallet control unit 902 is implemented by an application installed on the terminal 70. A detailed description of the installation of the application for implementing the digital wallet and the registration of specific certificates will be omitted. This is because these operations and the like are different from the gist of the disclosure of the present application.
 例えば、デジタル情報の登録に関し、利用者は、端末70を操作して、各種証明書等の発行主体が提供するホームページにアクセスし、当該ホームページからデジタル情報をデジタルウォレットに登録してもよい。 For example, regarding the registration of digital information, the user may operate the terminal 70 to access the homepage provided by the issuer of various certificates, etc., and register the digital information in the digital wallet from the homepage.
 例えば、ワクチン接種証明書や陰性証明書に関し、電子財布制御部902は、自治体や医療機関等の証明書発行主体が管理するホームページ等にアクセスする。電子財布制御部902は、利用者の操作に応じて、当該利用者のID等をホームページに入力することで、ワクチン接種証明書や陰性証明書を取得し、記憶部905に記憶する。 For example, regarding vaccination certificates and negative certificates, the electronic wallet control unit 902 accesses websites managed by certificate issuing entities such as local governments and medical institutions. The electronic wallet control unit 902 acquires a vaccination certificate or a negative certificate by inputting the user's ID or the like into the home page according to the user's operation, and stores it in the storage unit 905 .
 あるいは、パスポート、航空券、搭乗券等の書類に関しては、電子財布制御部902は、利用者の操作に応じてこれらの書類を撮像し、画像データをパスポート等に関するデジタル情報として記憶してもよい。あるいは、電子財布制御部902は、利用者の操作に応じてワクチン接種証明書等に対応する2次元コードを撮影することでワクチン接種証明書等を取得してもよい。 Alternatively, for documents such as passports, airline tickets, boarding passes, etc., the electronic wallet control unit 902 may capture images of these documents according to the user's operation, and store the image data as digital information related to passports and the like. . Alternatively, the electronic wallet control unit 902 may acquire the vaccination certificate or the like by photographing a two-dimensional code corresponding to the vaccination certificate or the like according to the user's operation.
 また、電子財布制御部902は、デジタルウォレットを所有する利用者を識別するためのユーザIDを生成する。ユーザIDは、利用者を一意に識別できる情報であればどのような情報であってもよい。例えば、電子財布制御部902は、利用者からメールアドレスを取得し、当該メールアドレスをユーザIDとして扱ってもよい。電子財布制御部902は、ユーザIDを記憶部905に記憶する。 Also, the electronic wallet control unit 902 generates a user ID for identifying the user who owns the digital wallet. The user ID may be any information as long as it can uniquely identify the user. For example, the electronic wallet control unit 902 may acquire an e-mail address from the user and treat the e-mail address as the user ID. Electronic wallet control unit 902 stores the user ID in storage unit 905 .
 航空券予約部903は、利用者による航空券の予約を実現する手段である。航空券予約部903は、利用者の操作に応じて、予約サーバ10が提供する所定のホームページにアクセスする。例えば、航空券予約部903は、図10に示す情報を取得し、予約サーバ10に送信する。 The airline ticket reservation section 903 is a means for realizing airline ticket reservations by users. The airline ticket reservation unit 903 accesses a predetermined homepage provided by the reservation server 10 according to the user's operation. For example, the airline ticket reservation unit 903 acquires the information shown in FIG. 10 and transmits it to the reservation server 10 .
 航空券予約部903は、予約サーバ10から受信した航空券情報を記憶部905に記憶する。航空券予約部903は、航空券情報をデジタルウォレットに保管する。 The airline ticket reservation unit 903 stores the airline ticket information received from the reservation server 10 in the storage unit 905 . The airline ticket reservation unit 903 stores the airline ticket information in the digital wallet.
 利用登録部904は、生体認証の利用登録を実現する手段である。利用登録部904は、利用者の操作に応じて、認証サーバ20が提供する所定のホームページにアクセスする。利用登録部904は、図18に示す生体情報(顔画像)、パスポート情報、搭乗券情報、健康パスポート情報(ワクチン接種証明書、陰性証明書、回復証明書)等を取得する。利用登録部904は、取得した生体情報等を認証サーバ20に送信する。 The usage registration unit 904 is means for realizing usage registration for biometric authentication. The usage registration unit 904 accesses a predetermined homepage provided by the authentication server 20 according to the user's operation. The use registration unit 904 acquires biometric information (face image), passport information, boarding pass information, health passport information (vaccination certificate, negative certificate, recovery certificate) and the like shown in FIG. The use registration unit 904 transmits the acquired biometric information and the like to the authentication server 20 .
 記憶部905は、端末70の動作に必要な情報を記憶する手段である。 The storage unit 905 is means for storing information necessary for the operation of the terminal 70 .
[システムの動作]
 続いて、第1の実施形態に係る出入国管理システムの動作について説明する。図26は、第1の実施形態に係る出入国管理システムの動作の一例を示すシーケンス図である。図26を参照しつつ、搭乗券発券に関する出入国管理システムの動作を説明する。
[System operation]
Next, operation of the immigration control system according to the first embodiment will be described. 26 is a sequence diagram showing an example of the operation of the immigration control system according to the first embodiment; FIG. The operation of the immigration control system for issuing a boarding pass will be described with reference to FIG.
 チェックイン端末50は、利用者のパスポート情報、航空券情報を含む搭乗券発行要求を出発管理サーバ40に送信する(ステップS11)。 The check-in terminal 50 transmits a boarding pass issuance request including the user's passport information and airline ticket information to the departure management server 40 (step S11).
 出発管理サーバ40は、有効な航空券情報が予約者情報データベースに登録されていると、利用者のパスポート情報及び健康パスポート情報を含む入国要件検証要求を検証サーバ30に送信する(ステップS12)。 When valid airline ticket information is registered in the reservation person information database, the departure management server 40 sends an entry requirements verification request including the user's passport information and health passport information to the verification server 30 (step S12).
 検証サーバ30は、検証結果(入国可、入国不可)を出発管理サーバ40に送信する(ステップS13)。 The verification server 30 transmits the verification result (entry permitted, entry denied) to the departure management server 40 (step S13).
 利用者(チェックイン手続きをする利用者)の検証結果が「入国可」であれば、出発管理サーバ40は、搭乗券を発行し、搭乗券情報をチェックイン端末50に通知する(ステップS14)。 If the verification result of the user (the user who performs the check-in procedure) is "permitted to enter the country," the departure management server 40 issues a boarding pass and notifies the check-in terminal 50 of the boarding pass information (step S14). .
 チェックイン端末50は、取得した搭乗券情報に基づいて搭乗券を発券する(ステップS15)。 The check-in terminal 50 issues a boarding pass based on the acquired boarding pass information (step S15).
 さらに、搭乗券を発行した場合には、出発管理サーバ40は、利用者のパスポート情報、健康パスポート情報を含む搭乗者情報通知をCIQサーバ60に送信する(ステップS16)。なお、出発管理サーバ40は、航空機が出発した後に、到着国のCIQサーバ60に搭乗者情報通知を送信するのが望ましい。このような対応により、航空機に搭乗している乗客として到着国に報告された利用者と実際に到着した利用者が異なる事態を避けることができる。 Furthermore, when the boarding pass is issued, the departure management server 40 transmits passenger information notification including the user's passport information and health passport information to the CIQ server 60 (step S16). The departure management server 40 preferably transmits the passenger information notification to the CIQ server 60 of the arrival country after the aircraft has departed. By such measures, it is possible to avoid a situation in which the user reported to the destination country as a passenger on board the aircraft is different from the user who actually arrived.
 以上のように、第1の実施形態に係る出入国管理システムにおいて、出発管理サーバ40は、搭乗券を発行する際、渡航者が到着国に入国できるか否かの検証を検証サーバ30に依頼する。検証サーバ30は、当該渡航者が所持する健康パスポート情報(例えば、ワクチン接種証明書等)が到着国の入国要件を満たしているか否か検証する。出発管理サーバ40は、検証サーバ30により渡航者が到着国に入国できることが確認された場合に、当該渡航者の搭乗券を発行する。その結果、航空会社の職員等が到着国の入国要件を確認する必要がなくなり、当該職員等の負担が軽減される。また、入国要件の確認が自動化されることで、職員等によるヒューマンエラーが排除され、到着国に入国できない利用者が航空機に搭乗することを防止できる。さらに、当該自動化により、入国要件の確認が円滑に行われ、出国業務におけるスループットが向上する。 As described above, in the immigration control system according to the first embodiment, when issuing a boarding pass, the departure control server 40 requests the verification server 30 to verify whether the traveler can enter the country of arrival. . The verification server 30 verifies whether the health passport information (eg, vaccination certificate, etc.) possessed by the traveler meets the entry requirements of the destination country. The departure management server 40 issues a boarding pass for the traveler when the verification server 30 confirms that the traveler can enter the country of arrival. As a result, airline staff and others do not need to confirm the entry requirements of the destination country, reducing the burden on the staff and others. In addition, by automating the confirmation of immigration requirements, it is possible to eliminate human error caused by staff, etc., and prevent users who cannot enter the country of arrival from boarding the aircraft. In addition, the automation facilitates confirmation of entry requirements and improves throughput in departure operations.
[第2の実施形態]
 続いて、第2の実施形態について図面を参照して詳細に説明する。
[Second embodiment]
Next, a second embodiment will be described in detail with reference to the drawings.
 第1の実施形態では、航空会社の予約システム(予約サーバ10)を用いて航空券を予約する場合について説明した。第2の実施形態では、複数の航空会社が連携(提携)することで形成された航空会社間の連合組織(エアラインアライアンス)の予約システムを用いて航空券を予約する場合について説明する。 In the first embodiment, the case where an airline ticket is reserved using an airline company's reservation system (reservation server 10) has been described. In the second embodiment, a case will be described in which an airline ticket is reserved using a reservation system of an alliance (airline alliance) formed by a plurality of airlines working together.
 とりわけ、利用者がコードシェア便(2社以上の航空会社が共同運行する航空機)を利用する場合について説明する。なお、エアラインアライアンスの予約システムを使用する場合であって、通常の便(コードシェア便ではない航空機)を予約する場合のシステム動作は第1の実施形態と同一とすることができるので説明を省略する。 In particular, we will explain when users use code-share flights (aircraft jointly operated by two or more airlines). In the case of using an airline alliance reservation system, the system operation in the case of reserving a normal flight (aircraft that is not a codeshare flight) can be the same as in the first embodiment. omitted.
 なお、コードシェア便では、1つの便に対して、複数の航空会社それぞれの便名が付与される。しかしながら、実際に航空機を運航するのは航空機を提供する1社の航空会社であり、利用者(乗客)には当該航空会社の規定(例えば、重量制限や機内食等のサービス)が適用される。 In addition, on codeshare flights, flight numbers of multiple airlines are assigned to each flight. However, the actual operation of the aircraft is one airline that provides the aircraft, and the user (passenger) is subject to the airline's regulations (e.g., weight restrictions, in-flight meals, etc.) .
 以下、第1の実施形態と第2の実施形態の相違点を中心に説明する。 The following description will focus on the differences between the first embodiment and the second embodiment.
 図27は、第2の実施形態に係る出入国管理システムの概略構成の一例を示す図である。図27に示すように、第2の実施形態に係る出入国管理システムは、共同予約サーバ11を含む。共同予約サーバ11は、エアラインアライアンスにより管理、運営されるサーバである。 FIG. 27 is a diagram showing an example of the schematic configuration of the immigration control system according to the second embodiment. As shown in FIG. 27, the immigration control system according to the second embodiment includes a joint reservation server 11. FIG. The joint reservation server 11 is a server managed and operated by an airline alliance.
 図27には、エアラインアライアンスに参加している各航空会社の予約サーバ10-1、10-2が図示されている。また、図27には、各航空会社が出発空港に対応して運営する出発管理サーバ40-1、出発管理サーバ40-2が図示されている。 FIG. 27 shows the reservation servers 10-1 and 10-2 of each airline participating in the airline alliance. FIG. 27 also shows a departure management server 40-1 and a departure management server 40-2 operated by each airline corresponding to the departure airport.
 予約サーバ10-1と出発管理サーバ40-1が同じ航空会社により管理、運営され、予約サーバ10-2と出発管理サーバ40-2が同じ航空会社により管理、運営される。なお、図27では、第1の実施形態で説明した他のサーバ等の図示を省略している。 The reservation server 10-1 and departure management server 40-1 are managed and operated by the same airline, and the reservation server 10-2 and departure management server 40-2 are managed and operated by the same airline. Note that in FIG. 27, illustration of other servers and the like described in the first embodiment is omitted.
 図28は、第2の実施形態に係る共同予約サーバ11の処理構成の一例を示す図である。図28に示すように、共同予約サーバ11は、通信制御部211と、予約制御部212と、予約記録送信部213と、記憶部214と、を備える。 FIG. 28 is a diagram showing an example of the processing configuration of the joint reservation server 11 according to the second embodiment. As shown in FIG. 28 , the joint reservation server 11 includes a communication control section 211 , a reservation control section 212 , a reservation record transmission section 213 and a storage section 214 .
 共同予約サーバ11の処理モジュールの基本的な動作は、第1の実施形態において図9を参照して説明した予約サーバ10の対応する処理モジュール(同名の処理モジュール)の動作と同一とすることができる。以下、共同予約サーバ11と予約サーバ10の相違点を中心に説明する。 The basic operations of the processing modules of the joint reservation server 11 may be the same as those of the corresponding processing modules (with the same names) of the reservation server 10 described with reference to FIG. 9 in the first embodiment. can. Differences between the joint reservation server 11 and the reservation server 10 will be mainly described below.
 共同予約サーバ11の予約制御部212は、利用者によるコードシェア便の予約を可能とする。例えば、予約制御部212は、図29に示すような情報を利用者の端末70に表示し、コードシェア便の予約を受け付ける。なお、図29の1行目に示すフライトがコードシェア便であり、運行会社は丸印で表記されている。 The reservation control unit 212 of the joint reservation server 11 enables users to reserve codeshare flights. For example, the reservation control unit 212 displays information such as that shown in FIG. 29 on the user's terminal 70 and accepts a reservation for a codeshare flight. Note that the flight shown in the first line of FIG. 29 is a codeshare flight, and the operating company is indicated by a circle.
 図29は、第1の実施形態で説明した図10に対応する図面であり、図10の表示から航空券の予約に関する表示(GUI)を抽出したものである。予約制御部212は、予約サーバ10の予約制御部202と同様に、コードシェア便の航空券情報と、パスポート情報と、健康パスポート情報を取得する。 FIG. 29 is a drawing corresponding to FIG. 10 described in the first embodiment, and is a display (GUI) related to airline ticket reservation extracted from the display of FIG. The reservation control unit 212, like the reservation control unit 202 of the reservation server 10, acquires airline ticket information for codeshare flights, passport information, and health passport information.
 予約制御部212は、取得したコードシェア便に関するパスポート情報、健康パスポート情報及び航空券情報をコードシェアする各航空会社の予約サーバ10に送信する(図30参照)。予約制御部212は、航空機を共同で運行する各航空会社の予約サーバ10にパスポート情報、健康パスポート情報及び航空券情報(コードシェア便の航空券情報)を送信する。 The reservation control unit 212 transmits the acquired passport information, health passport information, and airline ticket information related to the code-share flight to the reservation server 10 of each code-share airline (see FIG. 30). The reservation control unit 212 transmits passport information, health passport information, and air ticket information (air ticket information for code-share flights) to the reservation servers 10 of the airlines that jointly operate the aircraft.
 図30に示すように、パスポート情報等は、運行会社の予約サーバ10-1だけでなく、他の航空会社の予約サーバ10-2にも送信される。 As shown in FIG. 30, passport information and the like are sent not only to the reservation server 10-1 of the operating company, but also to the reservation server 10-2 of another airline.
 各予約サーバ10の予約制御部202は、共同予約サーバ11から受信したパスポート情報、健康パスポート情報及び航空券情報を利用者情報データベースに記憶する。 The reservation control unit 202 of each reservation server 10 stores the passport information, health passport information and airline ticket information received from the joint reservation server 11 in the user information database.
 各予約サーバ10の予約記録送信部203は、航空機出発の所定時間前に利用者の航空券予約記録を対応する出発管理サーバ40に送信する(図31参照)。図31に示すように、予約サーバ10-1は、自社で管理する出発管理サーバ40-1に航空券予約記録を送信し、予約サーバ10-2は、出発管理サーバ40-2に航空券予約記録を送信する。 The reservation record transmission unit 203 of each reservation server 10 transmits the user's airline ticket reservation record to the corresponding departure management server 40 a predetermined time before the departure of the aircraft (see FIG. 31). As shown in FIG. 31, the reservation server 10-1 transmits the airline ticket reservation record to the departure management server 40-1 managed by the company, and the reservation server 10-2 transmits the airline ticket reservation record to the departure management server 40-2. Submit your records.
 その後、出発空港の各出発管理サーバ40は、第1の実施形態において図6を参照した手順により搭乗券を発行する。即ち、各出発管理サーバ40は、自社のチェックイン端末50から搭乗券発行要求を受信すると、検証サーバ30に「入国要件検証要求」を送信し、検証結果が「入国可」であれば、搭乗券を発行する。 After that, each departure management server 40 at the departure airport issues a boarding pass according to the procedure referring to FIG. 6 in the first embodiment. That is, when each departure management server 40 receives a boarding pass issuance request from its own check-in terminal 50, it transmits an "entry requirements verification request" to the verification server 30. issue a ticket.
[システムの動作]
 続いて、第2の実施形態に係る出入国管理システムの動作について説明する。図32は、第2の実施形態に係る出入国管理システムの動作の一例を示すシーケンス図である。図32を参照しつつ、航空券予約に関する出入国管理システムの動作を説明する。
[System operation]
Next, operation of the immigration control system according to the second embodiment will be described. FIG. 32 is a sequence diagram showing an example of the operation of the immigration control system according to the second embodiment. The operation of the immigration control system for airline ticket reservation will be described with reference to FIG.
 共同予約サーバ11は、コードシェア便が予約された際の航空券情報、パスポート情報及び健康パスポート情報を各予約サーバ10に送信する(ステップS21)。 The joint reservation server 11 transmits the airline ticket information, passport information, and health passport information when the codeshare flight was reserved to each reservation server 10 (step S21).
 各予約サーバ10は、コードシェア便の出発の所定時間前に航空券予約記録を自社の出発管理サーバ40に送信する(ステップS22)。 Each reservation server 10 transmits an airline ticket reservation record to its own departure management server 40 a predetermined time before the departure of the codeshare flight (step S22).
 出発管理サーバ40は、チェックイン端末50からの要求に応じて、搭乗券発行に関する処理を実行する(ステップS23)。出発管理サーバ40は、自社に割り当てられた範囲内で座席を決定し、搭乗券を発行する。なお、第2の実施形態においても、出発管理サーバ40が、検証サーバ30に利用者の入国要件検証を要求し、利用者に関する入国要件の検証に成功した旨の結果を取得した場合に、搭乗券を発券する。 The departure management server 40 executes processing related to issuing a boarding pass in response to a request from the check-in terminal 50 (step S23). The departure management server 40 determines a seat within the range assigned to the company and issues a boarding pass. Also in the second embodiment, when the departure management server 40 requests the verification server 30 to verify the immigration requirements of the user, and obtains a result indicating that the verification of the immigration requirements for the user has been successful, boarding is performed. issue a ticket.
 以上のように、第2の実施形態に係る出入国管理システムは、複数の航空会社が共同運行するコードシェア便の予約を実現する、共同予約サーバ11を含む。共同予約サーバ11は、コードシェア便を運行する複数の航空会社それぞれに対応する予約サーバ10に、少なくとも、コードシェア便を予約した利用者の健康パスポート情報を送信する。複数の航空会社それぞれに対応する予約サーバ10は、当該複数の航空会社それぞれの予約サーバ10に対応する出発管理サーバ40に、少なくとも健康パスポート情報を送信する。このように、コードシェア便が利用される場合には、利用者の健康パスポート情報がコードシェア便を共同運行する各航空会社で共有される。コードシェア便を利用する利用者の入国要件に関する検証も自動的に行われ、出国業務にあたる職員等の負担が軽減する。 As described above, the immigration control system according to the second embodiment includes the joint reservation server 11 that realizes reservations for codeshare flights jointly operated by a plurality of airlines. The joint reservation server 11 transmits at least the health passport information of the user who has reserved the code-share flight to the reservation servers 10 corresponding to each of the plurality of airlines operating the code-share flight. The reservation server 10 corresponding to each of the plurality of airlines transmits at least health passport information to the departure management server 40 corresponding to each reservation server 10 of each of the plurality of airlines. In this way, when a codeshare flight is used, the user's health passport information is shared by each airline that jointly operates the codeshare flight. Verification of immigration requirements for users using codeshare flights is also automatically performed, reducing the burden on staff involved in departure work.
[第3の実施形態]
 続いて、第3の実施形態について図面を参照して詳細に説明する。
[Third embodiment]
Next, a third embodiment will be described in detail with reference to the drawings.
 第1の実施形態及び第2の実施形態では、利用者は、出発国から到着国(目的国)に直接移動する場合について説明した。第3の実施形態では、利用者は、乗り継ぎ国を経由して目的地に移動する場合について説明する。 In the first and second embodiments, the case where the user moves directly from the country of departure to the country of arrival (destination country) has been described. In the third embodiment, a case will be described in which the user travels to the destination via a transit country.
 以下、第1の実施形態乃至第3の実施形態の相違点を中心に説明する。 The following description will focus on the points of difference between the first to third embodiments.
 図33は、第3の実施形態に係る出入国管理システムの概略構成の一例を示す図である。図33に示すように、第3の実施形態に係る出入国管理システムは、出発空港と乗り継ぎ空港のそれぞれに出発管理サーバ40-3と出発管理サーバ40-4を含む。なお、図33では、第1の実施形態で説明した一部のサーバ等の図示を省略している。 FIG. 33 is a diagram showing an example of the schematic configuration of the immigration control system according to the third embodiment. As shown in FIG. 33, the immigration control system according to the third embodiment includes a departure control server 40-3 and a departure control server 40-4 at each of the departure airport and the transfer airport. Note that in FIG. 33, illustration of some servers and the like described in the first embodiment is omitted.
 図33において、予約サーバ10、出発管理サーバ40-3及び出発管理サーバ40-4のそれぞれは同じ航空会社により管理、運営されている。 In FIG. 33, the reservation server 10, departure management server 40-3 and departure management server 40-4 are managed and operated by the same airline.
 利用者は、端末70を操作して、予約サーバ10にアクセスし、目的地(到着空港)までの航空券を手配する。予約サーバ10の予約制御部202は、乗り継ぎ便を含む航空券の予約を可能とする。 The user operates the terminal 70 to access the reservation server 10 and arrange an airline ticket to the destination (arrival airport). The reservation control unit 202 of the reservation server 10 enables reservation of airline tickets including connecting flights.
 予約制御部202は、図34に示すような情報を利用者の端末70に表示し、乗り継ぎ便を含む航空券(複数の航空券)の予約を受け付ける。図34には、A2国のB2空港にて乗り継ぎが行われる例が示されている。 The reservation control unit 202 displays information such as that shown in FIG. 34 on the user's terminal 70, and accepts reservations for airline tickets (a plurality of airline tickets) including connecting flights. FIG. 34 shows an example in which a connection is made at B2 airport in A2 country.
 図34は、第1の実施形態で説明した図10に対応する図面であり、図10の表示から航空券の予約に関する表示(GUI)を抽出したものである。予約制御部202は、複数の航空券情報と、パスポート情報と、健康パスポート情報を取得する。 FIG. 34 is a drawing corresponding to FIG. 10 described in the first embodiment, and is a display (GUI) related to airline ticket reservation extracted from the display of FIG. The reservation control unit 202 acquires a plurality of pieces of airline ticket information, passport information, and health passport information.
 予約制御部202は、取得したパスポート情報、健康パスポート情報及び複数の航空券情報を利用者情報データベースに記憶する(図35参照)。 The reservation control unit 202 stores the acquired passport information, health passport information, and multiple pieces of airline ticket information in the user information database (see FIG. 35).
 予約記録送信部203は、航空機出発の所定時間前に利用者の航空券予約記録を出発国と乗り継ぎ国の出発管理サーバ40-3及び出発管理サーバ40-4に送信する(図36参照)。なお、予約記録送信部203は、出発国の出発管理サーバ40-3に対しては、出発国から乗り継ぎ国までの航空券(出発便の航空券)に関する航空券情報を含む航空券予約記録を送信する。図35の例では、利用者情報データベースの1行目のエントリに関する航空券予約記録が送信される。 The reservation record transmission unit 203 transmits the user's airline ticket reservation record to the departure management server 40-3 and departure management server 40-4 of the departure country and the transit country a predetermined time before the departure of the aircraft (see FIG. 36). Note that the reservation record transmission unit 203 sends an air ticket reservation record including air ticket information related to the air ticket from the departure country to the transit country (air ticket for the departure flight) to the departure management server 40-3 of the departure country. Send. In the example of FIG. 35, an airline ticket reservation record relating to the entry in the first row of the user information database is transmitted.
 予約記録送信部203は、乗り継ぎ国の出発管理サーバ40-4に対しては、乗り継ぎ国から到着国までの航空券(乗り継ぎ便の航空券)に関する航空券情報を含む航空券予約記録を送信する。図35の例では、利用者情報データベースの2行目のエントリに関する航空券予約記録が送信される。 The reservation record transmission unit 203 transmits an air ticket reservation record including air ticket information related to an air ticket from the transit country to the destination country (air ticket of the transit flight) to the departure management server 40-4 of the transit country. . In the example of FIG. 35, the airline ticket reservation record regarding the entry on the second line of the user information database is transmitted.
 出発国の出発管理サーバ40-3及び乗り継ぎ国の出発管理サーバ40-4は、受信した航空券予約記録を予約者情報データベースに記憶する。出発管理サーバ40-3及び出発管理サーバ40-4の予約記録制御部302は、取得した航空券予約記録を予約者情報データベースに反映する。 The departure management server 40-3 of the departure country and the departure management server 40-4 of the transit country store the received airline ticket reservation record in the reservation person information database. The reservation record control unit 302 of the departure management server 40-3 and the departure management server 40-4 reflects the acquired airline ticket reservation record in the reservation person information database.
 利用者が出発空港を訪れ、チェックイン手続きを開始する(図37参照)。 The user visits the departure airport and starts the check-in procedure (see Figure 37).
 チェックイン端末50は、利用者から航空券情報(出発便と乗り継ぎ便の航空券情報)とパスポート情報を取得する。チェックイン端末50は、利用者の生体認証(パスポート情報の顔画像と利用者を撮影することで得られる生体情報を使った1対1認証)を実行する。生体認証に成功すると、チェックイン端末50(チェックイン制御部702)は、当該利用者の航空券情報及びパスポート情報を含む「搭乗券発行要求」を出発管理サーバ40-3に送信する(ステップS31)。 The check-in terminal 50 acquires airline ticket information (air ticket information for departing flights and connecting flights) and passport information from the user. The check-in terminal 50 performs biometric authentication of the user (one-to-one authentication using the biometric information obtained by photographing the face image of the passport information and the user). When the biometric authentication is successful, the check-in terminal 50 (check-in control unit 702) transmits a "boarding pass request" including the airline ticket information and passport information of the user to the departure management server 40-3 (step S31 ).
 当該要求を受信した出発管理サーバ40-3は、当該利用者に関する搭乗券発行処理を行う。具体的には、出発管理サーバ40-3の搭乗券制御部303は、当該利用者の航空券情報(出発便に関する航空券情報)を確認して有効な航空券の予約が行われているか否かを検証する。 Upon receiving the request, the departure management server 40-3 performs boarding pass issuance processing for the user. Specifically, the boarding pass control unit 303 of the departure management server 40-3 confirms the airline ticket information (airline ticket information regarding the departure flight) of the user to determine whether a valid airline ticket has been reserved. verify whether
 検証に成功すれば(2つの航空券情報が一致すれば)、搭乗券制御部303は、当該利用者の乗り継ぎ空港に関する情報(空港コード)、パスポート情報及び健康パスポート情報を含む「入国要件検証要求」を検証サーバ30に送信する(ステップS32)。 If the verification succeeds (if the two pieces of airline ticket information match), the boarding pass control unit 303 sends an "entry requirements verification request" containing information about the user's transit airport (airport code), passport information, and health passport information. ” to the verification server 30 (step S32).
 また、出発管理サーバ40-3の搭乗券制御部303は、「搭乗券発行要求」を乗り継ぎ国の出発管理サーバ40-4に送信する(ステップS33)。出発管理サーバ40-3の搭乗券制御部303は、航空券情報(乗り継ぎ便の航空券情報)及びパスポート情報を含む搭乗券発行要求を乗り継ぎ国の出発管理サーバ40-4に送信する。 Also, the boarding pass control unit 303 of the departure management server 40-3 transmits a "boarding pass issue request" to the departure management server 40-4 of the transit country (step S33). The boarding pass control unit 303 of the departure management server 40-3 transmits a boarding pass issuance request including airline ticket information (airline ticket information of the connecting flight) and passport information to the departure management server 40-4 of the connecting country.
 乗り継ぎ国の出発管理サーバ40-4は、利用者の航空券情報(乗り継ぎ便に関する航空券情報)を確認して有効な航空券の予約が行われているか否かを判定する。出発管理サーバ40-4の搭乗券制御部303は、乗り継ぎ便の航空券に関する検証(有効な予約か否かの検証)を行う。 The departure management server 40-4 of the transit country checks the user's airline ticket information (airline ticket information related to the connecting flight) and determines whether a valid airline ticket reservation has been made. The boarding pass control unit 303 of the departure management server 40-4 verifies the airline ticket of the connecting flight (verifies whether or not the reservation is valid).
 検証に成功すれば、出発管理サーバ40-4の搭乗券制御部303は、当該利用者の到着空港に関する情報(空港コード)、パスポート情報及び健康パスポート情報を含む「入国要件検証要求」を検証サーバ30に送信する(ステップS34)。 If the verification succeeds, the boarding pass control unit 303 of the departure management server 40-4 sends the "immigration requirements verification request" including information (airport code) on the user's arrival airport, passport information and health passport information to the verification server. 30 (step S34).
 検証サーバ30は、出発国及び乗り継ぎ国それぞれの出発管理サーバ40-3及び出発管理サーバ40-4から受信した入国要件検証要求を処理する。検証サーバ30は、出発管理サーバ40-3から受信した入国要件検証要求に関しては、利用者のパスポート情報や健康パスポート情報が乗り継ぎ国の入国要件を満たすか否か検証する。検証サーバ30は、出発管理サーバ40-4から受信した入国要件検証要求に関しては、利用者のパスポート情報や健康パスポート情報が到着国の入国要件を満たすか否か検証する。 The verification server 30 processes immigration requirement verification requests received from the departure management server 40-3 and the departure management server 40-4 of the country of departure and the country of transit, respectively. The verification server 30 verifies whether the user's passport information or health passport information satisfies the entry requirements of the transit country with respect to the entry requirements verification request received from the departure management server 40-3. The verification server 30 verifies whether or not the user's passport information and health passport information meet the entry requirements of the arrival country in response to the entry requirements verification request received from the departure management server 40-4.
 検証サーバ30は、検証結果(入国可、入国不可)を含む応答を出発管理サーバ40-3及び出発管理サーバ40-4のそれぞれに送信する(ステップS35、ステップS36)。 The verification server 30 transmits a response including the verification result (entry permitted, entry denied) to each of the departure management server 40-3 and departure management server 40-4 (steps S35 and S36).
 乗り継ぎ国の出発管理サーバ40-4(搭乗券制御部303)は、到着国の検証結果が「入国可」であった場合、当該利用者に搭乗券(乗り継ぎ便の搭乗券)を発行する。出発管理サーバ40-4の搭乗券制御部303は、発行した搭乗券(搭乗券情報)を出発国の出発管理サーバ40-3に送信する(ステップS37)。 The departure management server 40-4 (boarding pass control unit 303) of the transit country issues a boarding pass (boarding pass for the transit flight) to the user if the verification result of the arrival country is "entry possible". The boarding pass control unit 303 of the departure management server 40-4 transmits the issued boarding pass (boarding pass information) to the departure management server 40-3 of the departure country (step S37).
 出発国の出発管理サーバ40-3(搭乗券制御部303)は、乗り継ぎ国の検証結果が「入国可」であり、且つ、乗り継ぎ便の搭乗券が発行された場合、出発便に関する搭乗券を発行する。出発管理サーバ40-3の搭乗券制御部303は、当該利用者の座席を決定し、出発便に関する搭乗券を発行する。 Departure management server 40-3 (boarding pass control unit 303) of the departure country issues a boarding pass for the departure flight when the verification result of the transit country is "entry permitted" and a boarding pass for the transit flight is issued. issue. The boarding pass control unit 303 of the departure management server 40-3 determines the seat of the user and issues a boarding pass for the departing flight.
 出発便に関する搭乗券を発行すると、出発管理サーバ40-3の搭乗券制御部303は、出発便と乗り継ぎ便に関する搭乗券情報等をチェックイン端末50に送信する(ステップS38)。 When the boarding pass for the departure flight is issued, the boarding pass control unit 303 of the departure management server 40-3 transmits the boarding pass information and the like for the departure flight and the connecting flight to the check-in terminal 50 (step S38).
 チェックイン端末50は、取得した搭乗券情報等に基づいて出発便と乗り継ぎ便それぞれの搭乗券を発券する。チェックイン端末50は、複数国に跨がって搭乗券を発券した場合には、各搭乗券に検証サーバ30による入国要件の検証結果に関する詳細情報を記載してもよい。チェックイン端末50は、図23Bに示すような情報(ワクチン接種証明書:OK等の情報)が記載された搭乗券を発券してもよい。 The check-in terminal 50 issues boarding passes for each departure flight and connecting flight based on the obtained boarding pass information. When the check-in terminal 50 issues boarding passes for multiple countries, the check-in terminal 50 may write detailed information on the verification result of the entry requirements by the verification server 30 on each boarding pass. The check-in terminal 50 may issue a boarding pass on which information such as that shown in FIG. 23B (certificate of vaccination: information such as OK) is described.
 この場合、検証サーバ30は、乗り継ぎ国の入国要件の検証に関する詳細情報を出発国の出発管理サーバ40-3(第1の出発管理サーバ40)に通知する。また、検証サーバ30は、到着国の入国要件の検証に関する詳細情報を乗り継ぎ国の出発管理サーバ40-4(第2の出発管理サーバ40)に通知する。乗り継ぎ国の出発管理サーバ40-4は、到着国の入国要件の検証に関する詳細情報を出発国の出発管理サーバ40-3に通知する。出発国の出発管理サーバ40-3は、乗り継ぎ国及び到着国それぞれの入国要件の検証に関する情報をチェックイン端末50に通知する。チェックイン端末50は、乗り継ぎ国の入国要件の検証に関する詳細情報が記載された出発便の搭乗券と、到着国の入国要件の検証に関する詳細情報が記載された乗り継ぎ便の搭乗券を発券する。 In this case, the verification server 30 notifies the departure management server 40-3 (first departure management server 40) of the departure country of detailed information regarding the verification of the entry requirements of the transit country. The verification server 30 also notifies the departure management server 40-4 (second departure management server 40) of the transit country of detailed information on the verification of the entry requirements of the arrival country. The transit country departure management server 40-4 notifies the departure country departure management server 40-3 of detailed information regarding the verification of entry country entry requirements. The departure management server 40-3 of the departure country notifies the check-in terminal 50 of information regarding the verification of the entry requirements of the transit country and the arrival country. A check-in terminal 50 issues a boarding pass for a departing flight describing detailed information on verification of entry requirements of a transit country and a boarding pass for a connecting flight describing detailed information on verification of entry requirements for an arrival country.
 また、搭乗券を発行すると、出発管理サーバ40-3の搭乗券制御部303は、到着国のCIQサーバ60に対してパスポート情報と健康パスポート情報を含む「搭乗者情報通知」を送信する(ステップS39)。このように、出発国の出発管理サーバ40-3(第1の出発管理サーバ40)は、到着国の到着空港に設置されたCIQサーバ60に、到着国に入国する利用者の健康パスポート情報等を送信する。 Further, when the boarding pass is issued, the boarding pass control unit 303 of the departure management server 40-3 transmits a "passenger information notification" including passport information and health passport information to the CIQ server 60 of the arrival country (step S39). In this way, the departure management server 40-3 (first departure management server 40) of the departure country stores the health passport information, etc. of the user entering the arrival country in the CIQ server 60 installed at the arrival airport of the arrival country. to send.
[システムの動作]
 続いて、第3の実施形態に係る出入国管理システムの動作について説明する。図38は、第3の実施形態に係る出入国管理システムの動作の一例を示すシーケンス図である。図38を参照しつつ、搭乗券発券に関する出入国管理システムの動作を説明する。
[System operation]
Next, the operation of the immigration control system according to the third embodiment will be explained. FIG. 38 is a sequence diagram showing an example of the operation of the immigration control system according to the third embodiment. The operation of the immigration control system for issuing a boarding pass will be described with reference to FIG.
 チェックイン端末50から搭乗券発行要求を受信すると、出発管理サーバ40-3は、検証サーバ30に「入国要件検証要求」を送信する(ステップS41)。 Upon receiving a boarding pass issuance request from the check-in terminal 50, the departure management server 40-3 transmits a "request for verifying immigration requirements" to the verification server 30 (step S41).
 また、入国要件検証要求の送信に前後して、出発管理サーバ40-3は、出発管理サーバ40-4に「搭乗券発行要求」を送信する(ステップS42)。 Also, before and after sending the immigration requirements verification request, the departure management server 40-3 sends a "boarding pass issue request" to the departure management server 40-4 (step S42).
 出発管理サーバ40-3から搭乗券発行要求を受信すると、出発管理サーバ40-4は、検証サーバ30に「入国要件検証要求」を送信する(ステップS43)。 Upon receiving the boarding pass issuance request from the departure management server 40-3, the departure management server 40-4 transmits a "request to verify entry requirements" to the verification server 30 (step S43).
 検証サーバ30は、2つの入国要件検証要求を処理し、検証結果を出発管理サーバ40-3、出発管理サーバ40-4に送信する(ステップS44、ステップS45)。 The verification server 30 processes the two immigration requirement verification requests and sends the verification results to the departure management server 40-3 and departure management server 40-4 (steps S44 and S45).
 出発管理サーバ40-4は、到着国の入国要件に関する検証結果が「入国可」であれば、乗り継ぎ便の搭乗券を発行し、搭乗券情報を出発管理サーバ40-3に送信する(ステップS46)。 Departure management server 40-4 issues a boarding pass for the connecting flight and transmits the boarding pass information to departure management server 40-3 (step S46 ).
 出発管理サーバ40-3は、乗り継ぎ国の入国要件に関する検証結果が「入国可」であって、乗り継ぎ便の搭乗券が発行された場合、出発便の搭乗券を発行する。出発管理サーバ40-3は、出発便と乗り継ぎ便の搭乗券情報をチェックイン端末50に送信する(ステップS47)。 The departure management server 40-3 issues a boarding pass for the departing flight when the verification result regarding the immigration requirements of the transit country is "entry allowed" and a boarding pass for the connecting flight is issued. The departure management server 40-3 transmits the boarding pass information of the departure flight and the connecting flight to the check-in terminal 50 (step S47).
 出発管理サーバ40-3は、搭乗券情報の送信に前後して、到着国のCIQサーバ60に「搭乗者情報通知」を送信する(ステップS48)。 Around the time of sending the boarding pass information, the departure management server 40-3 sends "passenger information notification" to the CIQ server 60 of the arrival country (step S48).
 このように、予約サーバ10は、出発便と乗り継ぎ便の航空券を予約可能とする。出発便が出発する出発国からの出国を管理する第1の出発管理サーバ40は、出発便が乗り継ぎのために到着する乗り継ぎ国の入国要件の検証に関する入国要件検証要求を検証サーバ30に送信する。乗り継ぎ国からの出国を管理する第2の出発管理サーバ40は、乗り継ぎ便が到着する到着国の入国要件の検証に関する入国要件検証要求を検証サーバ30に送信する。第2の出発管理サーバ40は、利用者が到着国に入国可と判定された場合に、乗り継ぎ便の搭乗券を発行し、発行された搭乗券の搭乗券情報を第1の出発管理サーバ40に送信する。第1の出発管理サーバ40は、利用者が乗り継ぎ国に入国可と判定され、且つ、乗り継ぎ便の搭乗券が発行されていれば、出発便の搭乗券を発行すると共に、出発便と乗り継ぎ便の搭乗券を発券する(チェックイン端末50に搭乗券情報を送信する)。 In this way, the reservation server 10 makes it possible to reserve airline tickets for departing flights and connecting flights. A first departure management server 40 that manages departure from the country of departure of the departure flight transmits to the verification server 30 an entry requirement verification request for verification of the entry requirements of the transit country where the departure flight arrives for transit. . The second departure management server 40, which manages departures from the transit country, transmits to the verification server 30 an entry requirements verification request for verifying the entry requirements of the destination country where the transit flight arrives. The second departure management server 40 issues a boarding pass for a connecting flight when it is determined that the user is permitted to enter the country of arrival, and sends the boarding pass information of the issued boarding pass to the first departure management server 40. Send to The first departure management server 40 issues a boarding pass for the departure flight and, if it is determined that the user is allowed to enter the transit country and has issued a boarding pass for the transit flight, (The boarding pass information is sent to the check-in terminal 50).
<第3の実施形態の変形例>
 第3の実施形態では、出発便、乗り継ぎ便の運行を同じ航空会社が担う場合について説明した。しかし、第2の実施形態で説明したように、エアラインアライアンスに参加する異なる航空会社が出発便、乗り継ぎ便のそれぞれを運行してもよい。
<Modified example of the third embodiment>
3rd Embodiment demonstrated the case where the same airline took charge of the operation of a departure flight and a connecting flight. However, as described in the second embodiment, different airlines participating in the airline alliance may operate departure flights and connecting flights.
 この場合、共同予約サーバ11が、出発便、乗り継ぎ便それぞれの航空券情報を取得する。共同予約サーバ11は、出発便を運行する航空会社の予約サーバ10と乗り継ぎ便を運行する航空会社の予約サーバ10のそれぞれにパスポート情報、健康パスポート情報及び航空券情報(出発便と乗り継ぎ便それぞれの航空券情報)を送信する。 In this case, the joint reservation server 11 acquires airline ticket information for each departure flight and connecting flight. The joint reservation server 11 sends passport information, health passport information, and airline ticket information (for both the departure flight and the connection flight) to the reservation server 10 of the airline that operates the departing flight and the reservation server 10 of the airline that operates the connecting flight. flight ticket information).
 出発便の予約サーバ10は、出発便の航空券予約記録を出発国の出発管理サーバ40に送信し、乗り継ぎ便の予約サーバ10は、乗り継ぎ便の航空券予約記録を乗り継ぎ国の出発管理サーバ40に送信する。 The departing flight reservation server 10 transmits the airline ticket reservation record of the departing flight to the departure management server 40 of the departure country, and the connecting flight reservation server 10 transmits the airline ticket reservation record of the connecting flight to the departure management server 40 of the connecting country. Send to
 出発国において、チェックイン端末50から搭乗券発行要求を受信すると、出発国の出発管理サーバ40は、乗り継ぎ国に関する入国要件の検証を検証サーバ30に要求する。さらに、出発管理サーバ40は、乗り継ぎ国の出発管理サーバ40に対して出発便に対応する乗り継ぎ便の搭乗券発行要求を送信する。 Upon receiving a boarding pass issuance request from the check-in terminal 50 in the departure country, the departure management server 40 in the departure country requests the verification server 30 to verify the immigration requirements for the transit country. Further, the departure management server 40 transmits a boarding pass issuance request for the connecting flight corresponding to the departing flight to the departure management server 40 of the transit country.
 乗り継ぎ国の出発管理サーバ40は、搭乗券発行要求を受信すると、到着国に関する入国要件の検証を検証サーバ30に要求する。 Upon receiving the boarding pass issuance request, the departure management server 40 of the transit country requests the verification server 30 to verify the immigration requirements for the arrival country.
 検証サーバ30は、乗り継ぎ国及び到着国それぞれの入国要件を検証し、検証結果(入国可、入国不可)を各出発管理サーバ40に送信する。 The verification server 30 verifies the entry requirements of each transit country and arrival country, and sends the verification results (entry allowed, entry not allowed) to each departure management server 40.
 乗り継ぎ国の出発管理サーバ40は、入国可の検証結果を受信すると、乗り継ぎ便の搭乗券を発行し、出発国の出発管理サーバ40に搭乗券情報を送信する。 When the departure management server 40 of the transit country receives the verification result that entry is permitted, it issues a boarding pass for the connecting flight and transmits the boarding pass information to the departure management server 40 of the departure country.
 出発国の出発管理サーバ40は、入国可の検証結果を受信し、且つ、乗り継ぎ国の搭乗券が発行されると、出発便の搭乗券を発行する。出発国の出発管理サーバ40は、出発便及び乗り継ぎ便の搭乗券情報をチェックイン端末50に送信する。 When the departure management server 40 of the country of departure receives the verification result that entry is permitted and the boarding pass of the transit country is issued, it issues the boarding pass of the departure flight. The departure management server 40 of the departure country transmits the boarding pass information of the departure flight and the connecting flight to the check-in terminal 50 .
 このように、第3の実施形態に係る変形例では、図30に示すように、出発便と乗り継ぎ便の航空券情報が、各航空会社の予約サーバ10に送信される。その後、図31に示すように、予約サーバ10から対応する各出発管理サーバ40に航空券予約記録が送信される。その後、図37に示すように、出発国のチェックイン端末50から搭乗券の発行要求が行われると、検証サーバ30にて乗り継ぎ国及び到着国それぞれの入国要件が検証される。乗り継ぎ国及び到着国それぞれの入国要件が満たされていれば、チェックイン端末50から出発便、乗り継ぎ便それぞれの搭乗券が発券される。 As described above, in the modification of the third embodiment, as shown in FIG. 30, the ticket information for departure flights and connecting flights is sent to the reservation server 10 of each airline. After that, as shown in FIG. 31, the airline ticket reservation record is transmitted from the reservation server 10 to each corresponding departure management server 40 . Thereafter, as shown in FIG. 37, when the check-in terminal 50 of the departure country requests issuance of a boarding pass, the verification server 30 verifies the immigration requirements of the transit country and the arrival country. If the immigration requirements of the transit country and the arrival country are met, the check-in terminal 50 issues boarding passes for the departure flight and the transit flight.
 以上のように、第3の実施形態に係る出入国管理システムにおいて、利用者が乗り継ぎ便を用いて到着国に入国する場合、当該到着国の入国要件だけでなく、乗り継ぎ国の入国要件も検証される。そのため、乗り継ぎ国及び/又は到着国の入国要件を満たしていない利用者が出国することが防止される。 As described above, in the immigration control system according to the third embodiment, when a user enters an arrival country using a connecting flight, not only the entry requirements of the arrival country but also the entry requirements of the transit country are verified. be. Therefore, users who do not meet the entry requirements of the transit and/or destination countries are prevented from leaving the country.
 続いて、出入国管理システムを構成する各装置のハードウェアについて説明する。図39は、出発管理サーバ40のハードウェア構成の一例を示す図である。 Next, we will explain the hardware of each device that makes up the immigration control system. FIG. 39 is a diagram showing an example of the hardware configuration of the departure management server 40. As shown in FIG.
 出発管理サーバ40は、情報処理装置(所謂、コンピュータ)により構成可能であり、図39に例示する構成を備える。例えば、出発管理サーバ40は、プロセッサ311、メモリ312、入出力インターフェイス313及び通信インターフェイス314等を備える。上記プロセッサ311等の構成要素は内部バス等により接続され、相互に通信可能に構成されている。 The departure management server 40 can be configured by an information processing device (so-called computer), and has the configuration illustrated in FIG. For example, the departure management server 40 includes a processor 311, a memory 312, an input/output interface 313, a communication interface 314, and the like. Components such as the processor 311 are connected by an internal bus or the like and configured to be able to communicate with each other.
 但し、図39に示す構成は、出発管理サーバ40のハードウェア構成を限定する趣旨ではない。出発管理サーバ40は、図示しないハードウェアを含んでもよいし、必要に応じて入出力インターフェイス313を備えていなくともよい。また、出発管理サーバ40に含まれるプロセッサ311等の数も図39の例示に限定する趣旨ではなく、例えば、複数のプロセッサ311が出発管理サーバ40に含まれていてもよい。 However, the configuration shown in FIG. 39 is not meant to limit the hardware configuration of the departure management server 40. The departure management server 40 may include hardware (not shown), and may not have the input/output interface 313 if necessary. Also, the number of processors 311 and the like included in the departure management server 40 is not limited to the example shown in FIG.
 プロセッサ311は、例えば、CPU(Central Processing Unit)、MPU(Micro Processing Unit)、DSP(Digital Signal Processor)等のプログラマブルなデバイスである。あるいは、プロセッサ311は、FPGA(Field Programmable Gate Array)、ASIC(Application Specific Integrated Circuit)等のデバイスであってもよい。プロセッサ311は、オペレーティングシステム(OS;Operating System)を含む各種プログラムを実行する。 The processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), DSP (Digital Signal Processor). Alternatively, processor 311 may be a device such as FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or the like. The processor 311 executes various programs including an operating system (OS).
 メモリ312は、RAM(Random Access Memory)、ROM(Read Only Memory)、HDD(Hard Disk Drive)、SSD(Solid State Drive)等である。メモリ312は、OSプログラム、アプリケーションプログラム、各種データを格納する。 The memory 312 is RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), or the like. The memory 312 stores an OS program, application programs, and various data.
 入出力インターフェイス313は、図示しない表示装置や入力装置のインターフェイスである。表示装置は、例えば、液晶ディスプレイ等である。入力装置は、例えば、キーボードやマウス等のユーザ操作を受け付ける装置である。 The input/output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device such as a keyboard or mouse that receives user operations.
 通信インターフェイス314は、他の装置と通信を行う回路、モジュール等である。例えば、通信インターフェイス314は、NIC(Network Interface Card)等を備える。 The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card) or the like.
 出発管理サーバ40の機能は、各種処理モジュールにより実現される。当該処理モジュールは、例えば、メモリ312に格納されたプログラムをプロセッサ311が実行することで実現される。また、当該プログラムは、コンピュータが読み取り可能な記憶媒体に記録することができる。記憶媒体は、半導体メモリ、ハードディスク、磁気記録媒体、光記録媒体等の非トランジェント(non-transitory)なものとすることができる。即ち、本発明は、コンピュータプログラム製品として具現することも可能である。また、上記プログラムは、ネットワークを介してダウンロードするか、あるいは、プログラムを記憶した記憶媒体を用いて、更新することができる。さらに、上記処理モジュールは、半導体チップにより実現されてもよい。 The functions of the departure management server 40 are realized by various processing modules. The processing module is implemented by the processor 311 executing a program stored in the memory 312, for example. Also, the program can be recorded in a computer-readable storage medium. The storage medium can be non-transitory such as semiconductor memory, hard disk, magnetic recording medium, optical recording medium, and the like. That is, the present invention can also be embodied as a computer program product. Also, the program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the processing module may be realized by a semiconductor chip.
 なお、予約サーバ10、認証サーバ20等も出発管理サーバ40と同様に情報処理装置により構成可能であり、その基本的なハードウェア構成は出発管理サーバ40と相違する点はないので説明を省略する。 Note that the reservation server 10, the authentication server 20, and the like can also be configured by an information processing device in the same manner as the departure management server 40, and the basic hardware configuration thereof is the same as that of the departure management server 40, so description thereof will be omitted. .
 情報処理装置である出発管理サーバ40は、コンピュータを搭載し、当該コンピュータにプログラムを実行させることで出発管理サーバ40の機能が実現できる。また、出発管理サーバ40は、当該プログラムにより出発管理サーバ40の制御方法を実行する。 The departure management server 40, which is an information processing device, is equipped with a computer, and the functions of the departure management server 40 can be realized by causing the computer to execute a program. Further, the departure management server 40 executes the control method of the departure management server 40 by the program.
[変形例]
 なお、上記実施形態にて説明した出入国管理システムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
[Modification]
The configuration, operation, and the like of the immigration control system described in the above embodiment are examples, and are not intended to limit the configuration and the like of the system.
 上記実施形態では、利用者が航空機を使って国を跨いで移動する場合について説明した。しかし、利用者が船舶を使って国を跨いで移動する場合であっても、本願開示の出入国管理システムは適用できる。 In the above embodiment, the case where the user travels across countries using an airplane has been explained. However, the immigration control system disclosed in the present application can be applied even when the user travels across countries by ship.
 上記実施形態では、主にデジタルウォレットに保管されたデジタル情報(ワクチン接種証明書等)がシステムに提供される場合について説明した。しかし、全部又は一部の情報はデジタルウォレットに保管されていなくてもよい。利用者は、パスポートやワクチン接種証明書等をシステム(予約サーバ10)に提供できれば、このような情報はどのような手段によって管理されていてもよい。 In the above embodiment, we explained the case where digital information (such as vaccination certificates) mainly stored in a digital wallet is provided to the system. However, all or part of the information need not be stored in a digital wallet. As long as the user can provide the system (reservation server 10) with a passport, vaccination certificate, etc., such information may be managed by any means.
 上記実施形態では、チェックイン端末50は、チェックイン手続きをする利用者の生体情報とパスポートに記載された生体情報を用いた認証(1対1認証)を実行することで、利用者を特定することを説明した。ここで、認証サーバ20が、利用者の生体情報、パスポート情報、健康パスポート情報等に加え、航空券情報(チケット情報、予約情報)を記憶することで、チェックイン端末50は利用者を特定してもよい。具体的には、チェックイン端末50は、チェックイン手続きを希望する利用者の生体情報を認証サーバ20に送信する。認証サーバ20は、取得した生体情報と事前に登録された生体情報を用いた生体認証(1対N認証)を実行する。認証サーバ20は、認証に成功した利用者のパスポート情報、航空券情報をチェックイン端末50に送信する。チェックイン端末50は、取得したパスポート情報、航空券情報を含む搭乗券発行要求を出発管理サーバ40に送信すればよい。なお、チェックイン端末50は、生体認証(顔認証)を実行せず、パスポート情報等を用いて利用者を特定してもよい。 In the above-described embodiment, the check-in terminal 50 identifies the user by executing authentication (one-to-one authentication) using the biometric information of the user performing the check-in procedure and the biometric information written in the passport. explained. Here, the check-in terminal 50 can identify the user by storing the airline ticket information (ticket information, reservation information) in addition to the user's biometric information, passport information, health passport information, etc. in the authentication server 20. may Specifically, the check-in terminal 50 transmits to the authentication server 20 the biometric information of the user who desires the check-in procedure. The authentication server 20 executes biometric authentication (one-to-N authentication) using the acquired biometric information and the pre-registered biometric information. The authentication server 20 transmits the passport information and airline ticket information of the successfully authenticated user to the check-in terminal 50 . The check-in terminal 50 may transmit a boarding pass issuance request including the acquired passport information and airline ticket information to the departure management server 40 . Note that the check-in terminal 50 may identify the user using passport information or the like without executing biometric authentication (face authentication).
 上記実施形態では、チェックイン手続きが終了した後(搭乗券が発券された後)に、利用者が端末70を操作して、生体認証の利用に関する登録を認証サーバ20に対して行うことを説明した。しかし、チェックイン端末50にて生体認証の利用に関する登録が行われてもよい。この場合、チェックイン端末50は、利用者の生体情報、パスポート情報、搭乗券情報、健康パスポート情報等を認証サーバ20に送信すればよい。また、認証サーバ20に登録される生体情報は、チェックイン端末50が取得した生体情報(利用者を撮影することで得られる顔画像やパスポートに記載された顔画像)であってもよい。 In the above embodiment, after the check-in procedure is completed (after the boarding pass is issued), the user operates the terminal 70 to register the use of biometric authentication with the authentication server 20. bottom. However, registration regarding the use of biometric authentication may be performed at the check-in terminal 50 . In this case, the check-in terminal 50 may transmit the user's biometric information, passport information, boarding pass information, health passport information, and the like to the authentication server 20 . The biometric information registered in the authentication server 20 may be biometric information acquired by the check-in terminal 50 (a facial image obtained by photographing the user or a facial image written on a passport).
 上記実施形態では、認証サーバ20とCIQサーバ60は独立して動作することを前提に説明を行った。しかし、これらのサーバは連携して動作してもよい。例えば、認証サーバ20は、利用者の生体情報とパスポート情報を記憶し、健康パスポート情報はCIQサーバ60から取得してもよい。 In the above embodiment, the explanation was given on the premise that the authentication server 20 and the CIQ server 60 operate independently. However, these servers may work together. For example, the authentication server 20 may store the user's biometric information and passport information, and obtain the health passport information from the CIQ server 60 .
 上記実施形態では、利用者は、チェックイン端末50を用いてチェックイン手続きを行うことを説明した。しかし、利用者は、スマートフォンやPC(Personal Computer)等を用いてオンラインチェックインを行ってもよい。即ち、予約した航空機の出発24時間前になると、利用者は、スマートフォン等を用いてチェックイン手続きを開始し、当該手続きを完了してもよい。この場合、利用者が空港に到着する前に、入国要件検証要求が出発管理サーバ40から検証サーバ30に送信される。また、オンラインでチェックイン手続きを完了した利用者のうち希望者は、チェックイン端末50で紙媒体のチケット(搭乗券)を発券してもいい。 In the above embodiment, the user uses the check-in terminal 50 to perform the check-in procedure. However, the user may perform online check-in using a smartphone, PC (Personal Computer), or the like. That is, 24 hours before departure of the reserved aircraft, the user may start the check-in procedure using a smartphone or the like and complete the procedure. In this case, before the user arrives at the airport, an immigration requirements verification request is sent from the departure management server 40 to the verification server 30 . Further, among users who have completed the online check-in procedure, those who wish may issue a paper ticket (boarding pass) at the check-in terminal 50 .
 また、オンラインでチェックイン手続きを完了することで航空会社の負担(航空会社の職員等の負担)を軽減することができる。具体的には、チェックイン手続きの際、利用者による健康パスポート情報の所持を確認することが求められる場合、チェックインカンターにおいて職員が健康パスポート情報を確認する必要がある。このような状況では、スマートフォン等を利用したオンラインチェックインを用いることができないので、当該オンラインチェックインを停止しなければならない。しかし、上記健康パスポート情報の所持が求められた場合でも、本願開示のように、出発管理サーバ40が健康パスポート情報を記憶することで、上記要求に容易に対応できる。具体的には、出発管理サーバ40は、健康パスポート情報を所持していない利用者の搭乗券発行を拒否することで、健康パスポート情報を所持している利用者に搭乗券を発券できる。換言すれば、チェックインカウンターにおける人力での健康パスポート情報の確認は不要なので、航空会社は、オンラインチェックインを稼働できる。その結果、航空会社職員の負担を軽減できる。 Also, by completing the check-in procedure online, it is possible to reduce the burden on the airline (burden on the airline staff, etc.). Specifically, when the check-in procedure requires confirmation of the user's possession of the health passport information, the staff must confirm the health passport information at the check-in counter. In such a situation, online check-in using a smartphone or the like cannot be used, so the online check-in must be suspended. However, even when the possession of the health passport information is requested, the departure management server 40 stores the health passport information as disclosed in the present application, so that the request can be easily met. Specifically, the departure management server 40 can issue a boarding pass to a user who has health passport information by refusing to issue a boarding pass to a user who does not have health passport information. In other words, airlines can operate online check-in because there is no need for manual verification of health passport information at check-in counters. As a result, the burden on the airline staff can be reduced.
 さらに、本願開示の出入国管理システムでは、利用者が健康パスポート情報以外の情報を端末70に所持していることを容易に確認できる。例えば、航空券の予約時に、端末70にインストールされている特定のアプリケーションの情報(例えば、アプリケーションの名称やバージョン)を予約サーバ10に登録することができる。具体的には、利用者(端末70)は、健康管理のためのアプリケーションや感染症罹患者との接触確認を行うアプリケーションの情報を予約サーバ10に登録できる。本願開示の出入国管理システムでは、上記のようなアプリケーションが端末70にインストールされていることを自動的に(人手を介さず)確認することができる。具体的には、出発管理サーバ40が搭乗券を発行する際の要件に上記アプリケーションのインストールが含まれていればよい。あるいは、認証サーバ20は、上記アプリケーションがインストールされていない端末70を所持する利用者の認証要求(認証端末51からの認証要求)を「認証失敗」とすればよい。このような対応により、本願開示の出入国管理システムは、出入国に必要アプリケーションが既に利用者の端末70にインストールされているか否か自動的に確認することができる。 Furthermore, in the immigration control system disclosed in the present application, it is possible to easily confirm that the user has information other than the health passport information on the terminal 70. For example, when booking an airline ticket, information on a specific application installed in the terminal 70 (for example, the name and version of the application) can be registered in the reservation server 10 . Specifically, the user (terminal 70) can register information on an application for health management and an application for confirming contact with a patient suffering from an infectious disease in the reservation server 10. FIG. In the immigration control system disclosed in the present application, it is possible to automatically (without human intervention) confirm that the above applications are installed in the terminal 70 . Specifically, the installation of the above application may be included in the requirements for the departure management server 40 to issue a boarding pass. Alternatively, the authentication server 20 may treat the authentication request (authentication request from the authentication terminal 51) of the user who owns the terminal 70 in which the application is not installed as "authentication failure". With such measures, the immigration control system disclosed in the present application can automatically confirm whether or not the application required for immigration has already been installed on the terminal 70 of the user.
 出発管理サーバ40は、搭乗券を発行できない場合(搭乗券発行要求に対して否定応答を送信する場合)に、搭乗券を発行できない理由も併せてチェックイン端末50に通知してもよい。例えば、出発管理サーバ40は、有効な航空券が登録されていない(有効な予約がない)、到着国の入国要件を満たされていない等の理由をチェックイン端末50に通知してもよい。この場合、チェックイン端末50は、当該通知された理由を利用者に通知してもよい。 The departure management server 40 may notify the check-in terminal 50 of the reason why the boarding pass cannot be issued, when the boarding pass cannot be issued (when a negative response is sent to the boarding pass issuance request). For example, the departure management server 40 may notify the check-in terminal 50 of reasons such as that a valid airline ticket is not registered (no valid reservation), or that entry requirements for the country of arrival have not been met. In this case, the check-in terminal 50 may notify the user of the reason for the notification.
 上記実施形態では、航空機が出発する所定時間前(24時間前)に予約サーバ10から出発管理サーバ40に航空券予約情報が転送される場合について説明した。しかし、所定時間経過前(24時間前)にチェックイン手続きが可能な状態になり、且つ、チェックイン端末50やオンラインチェックインが使用されてチェックイン手続きが行われるタイミングで、当該航空券予約情報が転送されてもよい。 In the above embodiment, a case has been described in which airline ticket reservation information is transferred from the reservation server 10 to the departure management server 40 a predetermined time (24 hours) before the departure of the aircraft. However, at the timing when the check-in procedure becomes possible before the elapse of a predetermined time (24 hours before) and the check-in procedure is performed using the check-in terminal 50 or online check-in, the airline ticket reservation information may be transferred.
 第2の実施形態では、共同予約サーバ11がコードシェア便の予約を実現する場合について説明した。しかし、コードシェア便の予約は、コードシェア便を共同運行する各航空会社のいずれか1つが管理する予約サーバ10により行われてもよい。この場合、コードシェア便の予約を受け付けた予約サーバ10は、他の航空会社(コードシェア便を共同運行する他の航空会社)が管理する予約サーバ10に航空券購入者のパスポート情報、航空券情報及び健康パスポート情報を通知すればよい。 In the second embodiment, a case has been described in which the joint reservation server 11 realizes reservations for codeshare flights. However, reservations for code-share flights may be made by the reservation server 10 managed by any one of the airlines jointly operating the code-share flights. In this case, the reservation server 10 that has accepted the reservation for the codeshare flight sends the ticket purchaser's passport information and ticket information to the reservation server 10 managed by another airline (another airline jointly operating the codeshare flight). Information and health passport information should be notified.
 第3の実施形態では、出発国の出発管理サーバ40と乗り継ぎ国の出発管理サーバ40のそれぞれが、入国要件検証要求を検証サーバ30に送信することを説明した。しかし、上記2つの出発管理サーバ40のうちいずれか一方が、乗り継ぎ国と到着国の入国要件に関する入国要件検証要求を纏めて検証サーバ30に送信してもよい。この場合、検証サーバ30は、乗り継ぎ国と到着国に関する検証結果を纏めて入国要件検証要求の送信元である出発管理サーバ40に送信する。例えば、出発国の出発管理サーバ40が纏めて入国要件検証要求を検証サーバ30に送信した場合を考える。この場合、出発国の出発管理サーバ40は、乗り継ぎ国の出発管理サーバ40に搭乗券発行要求を送信、当該サーバから搭乗券(乗り継ぎ便の搭乗券情報)を取得し、且つ、乗り継ぎ国及び到着国の入国が許可された場合に、2枚の搭乗券を発行する。なお、この場合、乗り継ぎ国の出発管理サーバ40は、出発国の出発管理サーバ40が入国要件検証要求を送信しているので、検証サーバ30に対して入国要件検証要求を送信する必要はない。乗り継ぎ国の出発管理サーバ40は、航空券の有効性を確認した後に、乗り継ぎ便の搭乗券情報を出発国の出発管理サーバ40に送信すればよい。 In the third embodiment, it was explained that the departure management server 40 of the country of departure and the departure management server 40 of the transit country each transmit an entry requirements verification request to the verification server 30 . However, either one of the two departure management servers 40 may collectively transmit the entry requirement verification requests regarding the entry requirements of the transit country and the arrival country to the verification server 30 . In this case, the verification server 30 collects the verification results regarding the country of transit and the country of arrival and transmits them to the departure management server 40, which is the source of the immigration requirement verification request. For example, consider a case where the departure management server 40 of the country of departure collectively transmits an immigration requirement verification request to the verification server 30 . In this case, the departure management server 40 of the departure country transmits a boarding pass issuance request to the departure management server 40 of the transit country, acquires the boarding pass (boarding pass information of the connecting flight) from the server, and sets the transit country and arrival date. Issue two boarding passes if entry into the country is permitted. In this case, the departure management server 40 of the transit country does not need to send an entry requirements verification request to the verification server 30 because the departure management server 40 of the departure country has sent the entry requirements verification request. After confirming the validity of the airline ticket, the departure management server 40 of the transit country may transmit the boarding pass information of the connecting flight to the departure management server 40 of the departure country.
 第3の実施形態では、出発国の出発管理サーバ40が、出発便及び乗り継ぎ便の搭乗券を発行した後に、到着国のCIQサーバ60に搭乗者情報通知を送信する場合について説明した。しかし、乗り継ぎ国の出発管理サーバ40が、当該搭乗者情報通知を到着国のCIQサーバ60に送信してもよい。この場合、出発国の出発管理サーバ40は、2枚の搭乗券を発行した旨を乗り継ぎ国の出発管理サーバ40に通知する。当該通知を受信したことに応じて、乗り継ぎ国の出発管理サーバ40は、搭乗者情報通知をCIQサーバ60に送信する。その際、乗り継ぎ国の出発管理サーバ40は、乗り継ぎ便が出発した後に搭乗者情報通知をCIQサーバ60に送信するのが望ましい。 In the third embodiment, a case has been described in which the departure management server 40 in the country of departure sends a passenger information notification to the CIQ server 60 in the country of arrival after issuing the boarding passes for the departure flight and the connecting flight. However, the departure management server 40 of the transit country may transmit the passenger information notification to the CIQ server 60 of the arrival country. In this case, the departure management server 40 of the departure country notifies the departure management server 40 of the transit country that two boarding passes have been issued. In response to receiving the notification, the transit country departure management server 40 transmits a passenger information notification to the CIQ server 60 . At this time, it is desirable that the departure management server 40 of the connecting country send the passenger information notification to the CIQ server 60 after the connecting flight has departed.
 第3の実施形態では、到着国のCIQサーバ60に搭乗者情報通知が送信される場合について説明したが、乗り継ぎ国のCIQサーバ60にも搭乗者情報が通知されてもよい。この場合、出発国の出発管理サーバ40が、乗り継ぎ国のCIQサーバ60に出発便に関する搭乗者情報通知を送信し、乗り継ぎ国の出発管理サーバ40が、到着国のCIQサーバ60に乗り継ぎ便に関する搭乗者情報通知を送信してもよい。また、出発国の出発管理サーバ40及び乗り継ぎ国の出発管理サーバ40のそれぞれは、出発便、乗り継ぎ便が出発した後に搭乗者情報通知をCIQサーバ60に送信するのが望ましい。上述のように、航空機に搭乗している利用者として乗り継ぎ国、到着国に報告された利用者と、実際に到着した利用者が異なる事態を避けるためである。 In the third embodiment, the case where the passenger information notification is sent to the CIQ server 60 of the arrival country has been described, but the passenger information may also be sent to the CIQ server 60 of the transit country. In this case, the departure management server 40 of the departure country transmits a passenger information notification regarding the departure flight to the CIQ server 60 of the transit country, and the departure management server 40 of the transit country sends the CIQ server 60 of the arrival country a boarding notification regarding the transit flight. You may send a person information notification. Moreover, it is preferable that the departure management server 40 of the departure country and the departure management server 40 of the connecting country each transmit the passenger information notification to the CIQ server 60 after the departure flight and the connecting flight depart. As described above, this is to avoid a situation in which the user who is reported to the transit country and arrival country as the user boarding the aircraft is different from the user who actually arrived.
 第3の実施形態において、チェックイン端末50は、乗り継ぎ国の出発管理サーバ40-4に対し、直接、搭乗券発行要求(乗り継ぎ便の搭乗券に関する発行要求)を送信してもよい。出発管理サーバ40-4は、到着国の入国要件の検証結果を取得し、入国が許可された利用者の搭乗券(乗り継ぎ便の搭乗券)を発行し、搭乗券情報をチェックイン端末50に送信してもよい。この場合、チェックイン端末50は、出発国の出発管理サーバ40-3からは出発便の搭乗券情報を取得する。 In the third embodiment, the check-in terminal 50 may directly transmit a boarding pass issuance request (request for issuing a boarding pass for a connecting flight) to the departure management server 40-4 of the connecting country. The departure management server 40-4 acquires the verification result of the entry requirements of the country of arrival, issues a boarding pass (boarding pass for a connecting flight) for the user permitted to enter the country, and sends the boarding pass information to the check-in terminal 50. You may send. In this case, the check-in terminal 50 acquires the boarding pass information of the departure flight from the departure management server 40-3 of the departure country.
 第3の実施形態では、1国の乗り継ぎ国を経由して到着国に入国する場合について説明した。ここで、2国以上の乗り継ぎ国を経由して到着国に入国する場合についても本願開示の出入国管理システムは同様に動作する。例えば、2国の乗り継ぎ国を経由する場合を考える。この場合、出発国の出発管理サーバ40は、最初の継ぎ国の入国要件に関する入国要件検証要求を検証サーバ30に送信する。最初の乗り継ぎ国の出発管理サーバ40は、次の乗り継ぎ国の入国要件に関する入国要件検証要求を検証サーバ30に送信すると共に、利用者の入国が許可された場合に、搭乗券(最初の乗り継ぎ便の搭乗券)を発行する。2番目の乗り継ぎ国の出発管理サーバ40は、最終到着国の入国要件に関する入国要件検証要求を検証サーバ30に送信すると共に、利用者の入国が許可された場合に、搭乗券(2番目の乗り継ぎ便の搭乗券)を発行する。出発国の出発管理サーバ40は、2枚の乗り継ぎ便に関する搭乗券が発行され、最初の乗り継ぎ国の入国が許可されれば、3枚の搭乗券を発行する(3枚の搭乗券に関する搭乗券情報をチェックイン端末50に送信する)。 In the third embodiment, the case of entering the arrival country via a transit country has been explained. Here, the immigration control system disclosed in the present application operates in the same manner when entering the arrival country via two or more transit countries. For example, consider a case of passing through two transit countries. In this case, the departure management server 40 of the country of departure sends to the verification server 30 an entry requirements verification request for the entry requirements of the first transit country. The departure management server 40 of the first transit country transmits an entry requirement verification request regarding the entry requirements of the next transit country to the verification server 30, and if the user's entry is permitted, the boarding pass (first transit flight boarding pass). The departure management server 40 of the second transit country transmits an entry requirement verification request regarding the entry requirements of the final arrival country to the verification server 30, and if the user is permitted to enter the country, the boarding pass (second transit issue a boarding pass for the flight. The departure management server 40 of the departure country issues three boarding passes (boarding pass for three boarding passes) if boarding passes for two connecting flights are issued and entry to the first transit country is permitted. information to the check-in terminal 50).
 上記実施形態では、利用者は、航空会社が管理する予約サーバ10にアクセスして航空券を予約(購入)することを説明した。しかし、利用者は、旅行代理店が運営、管理するWEB(ウェブ)サイト等から航空券を予約することもできる。この場合、旅行代理店のサーバは、予約された航空券に対応する航空会社の予約サーバ10に、チケット購入者のパスポート情報、航空券情報及び健康パスポート情報等を通知すればよい。 In the above embodiment, the user accesses the reservation server 10 managed by the airline to reserve (purchase) an airline ticket. However, the user can also reserve an airline ticket from a WEB (web) site or the like operated and managed by a travel agency. In this case, the server of the travel agency should notify the reservation server 10 of the airline corresponding to the reserved airline ticket of the ticket purchaser's passport information, airline ticket information, health passport information, and the like.
 上記実施形態では、認証サーバ20が認証要求を処理する際、被認証者のパスポート情報、健康パスポート情報等を用いて認証成功又は認証失敗を判定する場合について説明した。しかし、当該判定は、認証端末51で行われてもよい。即ち、認証サーバ20は、生体情報を用いた照合処理により特定された利用者のパスポート情報、健康パスポート情報等を認証端末51に送信する。認証端末51は、受信したパスポート情報等に基づいて、被認証者にサービスを提供するか否か判定してもよい。 In the above embodiment, when the authentication server 20 processes an authentication request, a case has been described where authentication success or authentication failure is determined using the passport information, health passport information, etc. of the person to be authenticated. However, the determination may be made at the authentication terminal 51 . That is, the authentication server 20 transmits to the authentication terminal 51 the passport information, health passport information, etc. of the user specified by the verification process using biometric information. The authentication terminal 51 may determine whether or not to provide the service to the person to be authenticated based on the received passport information or the like.
 上記実施形態では、顔画像から生成された特徴量がサーバ間で送受信される場合について説明した。しかし、顔画像がサーバ間で送受信されてもよい。この場合、受信側のサーバが、顔画像から特徴量を生成し、その後の処理に活用してもよい。あるいは、各種データベースに記憶される生体情報は特徴量であってもよいし顔画像であってもよい。顔画像が記憶されている場合には、必要に応じて顔画像から特徴量が生成されればよい。あるいは、顔画像と特徴量の両方がデータベースに記憶されていてもよい。 In the above embodiment, a case has been described in which feature values generated from face images are transmitted and received between servers. However, face images may be transmitted and received between servers. In this case, the server on the receiving side may generate a feature amount from the face image and use it for subsequent processing. Alternatively, biometric information stored in various databases may be feature amounts or face images. When face images are stored, feature amounts may be generated from the face images as needed. Alternatively, both face images and feature amounts may be stored in the database.
 上記実施形態では、各サーバの内部に各種データベースが構成される場合について説明したが、当該データベースは外部のデータベースサーバ等に構築されてもよい。即ち、各サーバ等の一部の機能は別のサーバに実装されていてもよい。より具体的には、上記説明した「予約記録制御部(予約記録制御手段)」、「搭乗券制御部(搭乗券制御手段)」等がシステムに含まれるいずれかの装置に実装されていればよい。 In the above embodiment, the case where various databases are configured inside each server has been described, but the databases may be configured in an external database server or the like. That is, some functions of each server may be implemented in another server. More specifically, if the above-described "reservation record control section (reservation record control means)", "boarding pass control section (boarding pass control means)", etc. are implemented in any device included in the system good.
 各装置(予約サーバ10、認証サーバ20、検証サーバ30等)間のデータ送受信の形態は特に限定されないが、これら装置間で送受信されるデータは暗号化されていてもよい。これらの装置間では、パスポート情報等が送受信され、個人情報を適切に保護するためには、暗号化されたデータが送受信されることが望ましい。 The form of data transmission and reception between each device (reservation server 10, authentication server 20, verification server 30, etc.) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Passport information and the like are transmitted and received between these devices, and in order to properly protect personal information, it is desirable that encrypted data be transmitted and received.
 上記説明で用いた流れ図(フローチャート、シーケンス図)では、複数の工程(処理)が順番に記載されているが、実施形態で実行される工程の実行順序は、その記載の順番に制限されない。実施形態では、例えば各処理を並行して実行する等、図示される工程の順番を内容的に支障のない範囲で変更することができる。 In the flowcharts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiment is not limited to the described order. In the embodiment, the order of the illustrated steps can be changed within a range that does not interfere with the content, such as executing each process in parallel.
 上記の実施形態は本願開示の理解を容易にするために詳細に説明したものであり、上記説明したすべての構成が必要であることを意図したものではない。また、複数の実施形態について説明した場合には、各実施形態は単独で用いてもよいし、組み合わせて用いてもよい。例えば、実施形態の構成の一部を他の実施形態の構成に置き換えることや、実施形態の構成に他の実施形態の構成を加えることも可能である。さらに、実施形態の構成の一部について他の構成の追加、削除、置換が可能である。 The above embodiments have been described in detail to facilitate understanding of the disclosure of the present application, and are not intended to require all the configurations described above. Also, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of the embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of the embodiment. Furthermore, additions, deletions, and replacements of other configurations are possible for some of the configurations of the embodiments.
 上記の説明により、本発明の産業上の利用可能性は明らかであるが、本発明は、航空機等を利用する利用者に関する出入国管理システムなどに好適に適用可能である。 From the above description, the industrial applicability of the present invention is clear, and the present invention can be suitably applied to an immigration control system for users of aircraft.
 上記の実施形態の一部又は全部は、以下の付記のようにも記載され得るが、以下には限られない。
[付記1]
 利用者の出国を管理し、航空券を予約した前記利用者の健康に関する健康パスポート情報を記憶する、出発管理サーバと、
 各国の入国要件を検証する、検証サーバと、
 を含み、
 前記出発管理サーバは、少なくともチェックイン手続きを行う前記利用者の前記健康パスポート情報を含む入国要件検証要求を前記検証サーバに送信し、
 前記検証サーバは、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否か検証し、検証結果を前記出発管理サーバに送信し、
 前記出発管理サーバは、前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、システム。
[付記2]
 前記利用者により予約された航空券に関する航空券情報を取得する、チェックイン端末をさらに含み、
 前記チェックイン端末は、前記航空券情報を含む搭乗券発行要求を前記出発管理サーバに送信し、
 前記出発管理サーバは、前記航空券情報が有効、且つ、前記利用者が前記到着国に入国可と判定された場合に、前記発行された搭乗券に関する搭乗券情報を前記チェックイン端末に送信する、付記1に記載のシステム。
[付記3]
 前記航空券の予約を実現すると共に、少なくとも前記健康パスポート情報を記憶する、予約サーバをさらに含み、
 前記予約サーバは、前記予約された航空券に対応する航空機が出発する所定時間前に、少なくとも前記健康パスポート情報を前記出発管理サーバに送信する、付記2に記載のシステム。
[付記4]
 複数の航空会社が共同運行するコードシェア便の予約を実現する、共同予約サーバをさらに含み、
 前記共同予約サーバは、前記コードシェア便を運行する前記複数の航空会社それぞれに対応する前記予約サーバに、少なくとも、前記コードシェア便を予約した利用者の前記健康パスポート情報を送信し、
 前記複数の航空会社それぞれに対応する前記予約サーバは、前記複数の航空会社それぞれの前記予約サーバに対応する前記出発管理サーバに、少なくとも前記健康パスポート情報を送信する、付記3に記載のシステム。
[付記5]
 前記出発管理サーバは、前記到着国の到着空港に設置され、前記利用者が入国する際の税関、入国管理、検疫に関する処理を行うCIQ(Customs Immigration Quarantine)サーバに、前記到着国に入国する前記利用者の前記健康パスポート情報を送信する、付記1乃至4のいずれか一項に記載のシステム。
[付記6]
 前記検証サーバは、前記入国要件の検証に関する詳細情報を前記出発管理サーバに通知し、
 前記出発管理サーバは、前記入国要件の検証に関する詳細情報を前記チェックイン端末に通知し、
 前記チェックイン端末は、前記入国要件の検証に関する詳細情報が記載された搭乗券を発券する、付記2に記載のシステム。
[付記7]
 前記予約サーバは、出発便と乗り継ぎ便の航空券を予約可能とし、
 前記出発便が出発する出発国からの出国を管理する第1の出発管理サーバは、前記出発便が乗り継ぎのために到着する乗り継ぎ国の入国要件の検証に関する前記入国要件検証要求を前記検証サーバに送信し、
 前記乗り継ぎ国からの出国を管理する第2の出発管理サーバは、前記乗り継ぎ便が到着する到着国の入国要件の検証に関する前記入国要件検証要求を前記検証サーバに送信し、
 前記第2の出発管理サーバは、前記利用者が前記到着国に入国可と判定された場合に、前記乗り継ぎ便の搭乗券を発行し、前記発行された搭乗券の前記搭乗券情報を前記第1の出発管理サーバに送信し、
 前記第1の出発管理サーバは、前記利用者が前記乗り継ぎ国に入国可と判定され、且つ、前記乗り継ぎ便の搭乗券が発行されていれば、前記出発便の搭乗券を発行すると共に、前記出発便と前記乗り継ぎ便の搭乗券を発券する、付記3に記載のシステム。
[付記8]
 前記第1の出発管理サーバは、前記到着国の到着空港に設置され、前記利用者が入国する際の税関、入国管理、検疫に関する処理を行うCIQ(Customs Immigration Quarantine)サーバに、前記到着国に入国する前記利用者の前記健康パスポート情報を送信する、付記7に記載のシステム。
[付記9]
 前記検証サーバは、前記乗り継ぎ国の入国要件の検証に関する詳細情報を前記第1の出発管理サーバに通知すると共に、前記到着国の入国要件の検証に関する詳細情報を前記第2の出発管理サーバに通知し、
 前記第2の出発管理サーバは、前記到着国の入国要件の検証に関する詳細情報を前記第1の出発管理サーバに通知し、
 前記第1の出発管理サーバは、前記乗り継ぎ国及び到着国それぞれの前記入国要件の検証に関する詳細情報を前記チェックイン端末に通知し、
 前記チェックイン端末は、前記乗り継ぎ国の入国要件の検証に関する詳細情報が記載された前記出発便の搭乗券と、前記到着国の入国要件の検証に関する詳細情報が記載された前記乗り継ぎ便の搭乗券を発券する、付記7又は8に記載のシステム。
[付記10]
 前記利用者の第1の生体情報を記憶する、認証サーバと、
 前記利用者の第2の生体情報を取得し、前記取得された生体情報を含む認証要求を前記認証サーバに送信する、認証端末と、
 をさらに含み、
 前記認証サーバは、前記第1の生体情報及び前記第2の生体情報を用いた生体認証を行い、認証結果を前記認証端末に送信し、
 前記認証端末は、認証に成功した前記利用者にサービスを提供する、付記1乃至9のいずれか一項に記載のシステム。
[付記11]
 前記健康パスポート情報は、感染症に関する、ワクチン接種証明書、陰性証明書及び回復証明書のうち少なくとも1つを含む、付記1乃至10のいずれか一項に記載のシステム。
[付記12]
 航空券を予約した利用者の健康に関する健康パスポート情報を記憶する、記憶部と、
 チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信する、送信部と、
 前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信する受信部と、
 前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、搭乗券制御部と、
 を備える、出発管理サーバ。
[付記13]
 出発管理サーバにおいて、
 航空券を予約した利用者の健康に関する健康パスポート情報を記憶し、
 チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信し、
 前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信し、
 前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、出発管理サーバの制御方法。
[付記14]
 出発管理サーバに搭載されたコンピュータに、
 航空券を予約した利用者の健康に関する健康パスポート情報を記憶する処理と、
 チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信する処理と、
 前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信する処理と、
 前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する処理と、
 を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
Some or all of the above embodiments may also be described in the following additional remarks, but are not limited to the following.
[Appendix 1]
a departure management server for managing the departure of a user and storing health passport information relating to the health of said user who has booked an airline ticket;
a validation server that validates each country's entry requirements;
including
The departure management server transmits to the verification server an immigration requirements verification request including at least the health passport information of the user who performs check-in procedures;
The verification server verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server;
The system, wherein the departure management server issues a boarding pass to the user when it is determined that the user is allowed to enter the country of arrival.
[Appendix 2]
further comprising a check-in terminal for obtaining ticket information relating to a ticket booked by the user;
The check-in terminal transmits a boarding pass issuance request including the airline ticket information to the departure management server,
The departure management server transmits boarding pass information related to the issued boarding pass to the check-in terminal when it is determined that the airline ticket information is valid and the user is allowed to enter the arrival country. , Supplement 1.
[Appendix 3]
further comprising a reservation server facilitating reservation of said airline ticket and storing at least said health passport information;
3. The system according to claim 2, wherein the reservation server transmits at least the health passport information to the departure management server a predetermined time before departure of an aircraft corresponding to the reserved airline ticket.
[Appendix 4]
further comprising a joint reservation server for realizing reservations for codeshare flights jointly operated by multiple airlines;
The joint reservation server transmits at least the health passport information of the user who has reserved the code-share flight to the reservation servers corresponding to each of the plurality of airlines operating the code-share flight,
4. The system of Claim 3, wherein the reservation servers corresponding to each of the plurality of airlines transmit at least the health passport information to the departure management server corresponding to the reservation servers of each of the plurality of airlines.
[Appendix 5]
The departure management server is installed at the arrival airport of the arrival country, and is a CIQ (Customs Immigration Quarantine) server that performs processing related to customs, immigration control, and quarantine when the user enters the country. 5. The system according to any one of the appendices 1 to 4, wherein said health passport information of a user is transmitted.
[Appendix 6]
The verification server notifies the departure management server of detailed information regarding the verification of the entry requirements;
The departure management server notifies the check-in terminal of detailed information regarding verification of the entry requirements;
3. The system of Claim 2, wherein the check-in terminal issues a boarding pass containing detailed information regarding verification of the entry requirements.
[Appendix 7]
The reservation server enables reservation of airline tickets for departure flights and connecting flights,
A first departure management server that manages departure from a departure country from which the departure flight departs, transmits the entry requirements verification request regarding verification of entry requirements of a transit country to which the departure flight arrives for transit, to the verification server. send to
A second departure management server that manages departures from the transit country transmits to the verification server the entry requirements verification request for verification of entry requirements of the destination country where the transit flight arrives,
The second departure management server issues a boarding pass for the connecting flight when it is determined that the user is allowed to enter the arrival country, and transfers the boarding pass information of the issued boarding pass to the second departure management server. 1 to the departure management server,
The first departure management server issues a boarding pass for the departure flight if the user is determined to be allowed to enter the transit country and a boarding pass for the transit flight has been issued, and 4. The system of clause 3, issuing boarding passes for outgoing flights and said connecting flights.
[Appendix 8]
The first departure management server is a CIQ (Customs Immigration Quarantine) server that is installed at the arrival airport of the arrival country and performs processing related to customs, immigration control, and quarantine when the user enters the country. 8. The system of claim 7, wherein the health passport information of the user entering the country is transmitted.
[Appendix 9]
The verification server notifies the first departure management server of detailed information regarding the verification of entry requirements of the transit country, and notifies the second departure management server of detailed information regarding the verification of entry requirements of the destination country. death,
The second departure management server notifies the first departure management server of detailed information regarding verification of entry requirements of the arrival country;
The first departure management server notifies the check-in terminal of detailed information regarding verification of the entry requirements of each of the transit country and the arrival country;
The check-in terminal provides a boarding pass for the departing flight containing detailed information regarding verification of entry requirements of the transit country and a boarding pass for the connecting flight containing detailed information regarding verification of entry requirements for the destination country. 9. The system of clause 7 or 8, wherein the system issues a
[Appendix 10]
an authentication server that stores first biometric information of the user;
an authentication terminal that acquires second biometric information of the user and transmits an authentication request including the acquired biometric information to the authentication server;
further comprising
The authentication server performs biometric authentication using the first biometric information and the second biometric information, and transmits an authentication result to the authentication terminal;
10. The system according to any one of appendices 1 to 9, wherein the authentication terminal provides a service to the successfully authenticated user.
[Appendix 11]
11. The system of any one of the clauses 1-10, wherein the health passport information includes at least one of a vaccination certificate, a negative certificate and a recovery certificate for an infectious disease.
[Appendix 12]
a storage unit for storing health passport information relating to the health of a user who has booked an airline ticket;
a transmission unit for transmitting an entry requirements verification request including at least the health passport information of the user who checks in to a verification server for verifying the entry requirements of each country;
a receiving unit that receives verification results from the verification server as to whether or not the health passport information satisfies the entry requirements of the country of arrival of the user;
a boarding pass control unit that issues a boarding pass to the user when the user is determined to be allowed to enter the country of arrival;
Departure management server, comprising:
[Appendix 13]
In the departure management server,
remember health passport information about the health of the user who booked the ticket,
sending an entry requirements verification request including at least said health passport information of said user checking in to a verification server for verifying the entry requirements of each country;
receiving from the verification server a verification result as to whether the health passport information satisfies the entry requirements of the country of arrival of the user;
A control method for a departure management server, wherein a boarding pass is issued to the user when the user is determined to be allowed to enter the arrival country.
[Appendix 14]
On the computer installed in the departure management server,
a process of storing Health Passport information relating to the health of the user who booked the airline ticket;
a process of sending an entry requirements verification request including at least the health passport information of the user who performs the check-in procedure to a verification server that verifies the entry requirements of each country;
a process of receiving, from the verification server, a verification result as to whether the health passport information satisfies the entry requirements of the country of arrival of the user;
a process of issuing a boarding pass to the user when the user is determined to be allowed to enter the country of arrival;
A computer-readable storage medium that stores a program for executing
 なお、引用した上記の先行技術文献の各開示は、本書に引用をもって繰り込むものとする。以上、本発明の実施形態を説明したが、本発明はこれらの実施形態に限定されるものではない。これらの実施形態は例示にすぎないということ、及び、本発明のスコープ及び精神から逸脱することなく様々な変形が可能であるということは、当業者に理解されるであろう。即ち、本発明は、請求の範囲を含む全開示、技術的思想にしたがって当業者であればなし得る各種変形、修正を含むことは勿論である。 It should be noted that each disclosure of the above cited prior art documents shall be incorporated into this document by citation. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will appreciate that these embodiments are illustrative only and that various modifications can be made without departing from the scope and spirit of the invention. That is, the present invention naturally includes various variations and modifications that can be made by those skilled in the art according to the entire disclosure including claims and technical ideas.
10   予約サーバ
10-1 予約サーバ
10-2 予約サーバ
11   共同予約サーバ
20   認証サーバ
30   検証サーバ
40   出発管理サーバ
40-1 出発管理サーバ
40-2 出発管理サーバ
40-3 出発管理サーバ
40-4 出発管理サーバ
50   チェックイン端末
51   認証端末
51-1 認証端末
51-2 認証端末
60   CIQサーバ
70   端末
101  出発管理サーバ
102  検証サーバ
201  通信制御部
202  予約制御部
203  予約記録送信部
204  記憶部
211  通信制御部
212  予約制御部
213  予約記録送信部
214  記憶部
301  通信制御部
302  予約記録制御部
303  搭乗券制御部
304  記憶部
311  プロセッサ
312  メモリ
313  入出力インターフェイス
314  通信インターフェイス
401  通信制御部
402  入国要件検証部
403  記憶部
501  通信制御部
502  利用登録制御部
503  認証部
504  記憶部
601  通信制御部
602  搭乗者情報処理部
603  記憶部
701  通信制御部
702  チェックイン制御部
703  記憶部
801  通信制御部
802  生体情報取得部
803  認証要求部
804  記憶部
901  通信制御部
902  電子財布制御部
903  航空券予約部
904  利用登録部
905  記憶部
10 reservation server 10-1 reservation server 10-2 reservation server 11 joint reservation server 20 authentication server 30 verification server 40 departure management server 40-1 departure management server 40-2 departure management server 40-3 departure management server 40-4 departure management Server 50 Check-in terminal 51 Authentication terminal 51-1 Authentication terminal 51-2 Authentication terminal 60 CIQ server 70 Terminal 101 Departure management server 102 Verification server 201 Communication control unit 202 Reservation control unit 203 Reservation record transmission unit 204 Storage unit 211 Communication control unit 212 reservation control unit 213 reservation record transmission unit 214 storage unit 301 communication control unit 302 reservation record control unit 303 boarding pass control unit 304 storage unit 311 processor 312 memory 313 input/output interface 314 communication interface 401 communication control unit 402 immigration requirements verification unit 403 Storage unit 501 Communication control unit 502 Use registration control unit 503 Authentication unit 504 Storage unit 601 Communication control unit 602 Passenger information processing unit 603 Storage unit 701 Communication control unit 702 Check-in control unit 703 Storage unit 801 Communication control unit 802 Biometric information acquisition Unit 803 Authentication request unit 804 Storage unit 901 Communication control unit 902 Electronic wallet control unit 903 Air ticket reservation unit 904 Usage registration unit 905 Storage unit

Claims (14)

  1.  利用者の出国を管理し、航空券を予約した前記利用者の健康に関する健康パスポート情報を記憶する、出発管理サーバと、
     各国の入国要件を検証する、検証サーバと、
     を含み、
     前記出発管理サーバは、少なくともチェックイン手続きを行う前記利用者の前記健康パスポート情報を含む入国要件検証要求を前記検証サーバに送信し、
     前記検証サーバは、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否か検証し、検証結果を前記出発管理サーバに送信し、
     前記出発管理サーバは、前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、システム。
    a departure management server for managing the departure of a user and storing health passport information relating to the health of said user who has booked an airline ticket;
    a validation server that validates each country's entry requirements;
    including
    The departure management server transmits to the verification server an immigration requirements verification request including at least the health passport information of the user who performs check-in procedures;
    The verification server verifies whether the health passport information satisfies the entry requirements of the country of arrival of the user, and transmits the verification result to the departure management server;
    The system, wherein the departure management server issues a boarding pass to the user when it is determined that the user is permitted to enter the country of arrival.
  2.  前記利用者により予約された航空券に関する航空券情報を取得する、チェックイン端末をさらに含み、
     前記チェックイン端末は、前記航空券情報を含む搭乗券発行要求を前記出発管理サーバに送信し、
     前記出発管理サーバは、前記航空券情報が有効、且つ、前記利用者が前記到着国に入国可と判定された場合に、前記発行された搭乗券に関する搭乗券情報を前記チェックイン端末に送信する、請求項1に記載のシステム。
    further comprising a check-in terminal for obtaining ticket information relating to a ticket booked by the user;
    The check-in terminal transmits a boarding pass issuance request including the airline ticket information to the departure management server,
    The departure management server transmits boarding pass information related to the issued boarding pass to the check-in terminal when it is determined that the airline ticket information is valid and the user is allowed to enter the arrival country. , the system of claim 1.
  3.  前記航空券の予約を実現すると共に、少なくとも前記健康パスポート情報を記憶する、予約サーバをさらに含み、
     前記予約サーバは、前記予約された航空券に対応する航空機が出発する所定時間前に、少なくとも前記健康パスポート情報を前記出発管理サーバに送信する、請求項2に記載のシステム。
    further comprising a reservation server facilitating reservation of said airline ticket and storing at least said health passport information;
    3. The system according to claim 2, wherein said reservation server transmits at least said health passport information to said departure management server a predetermined time before departure of an aircraft corresponding to said reserved airline ticket.
  4.  複数の航空会社が共同運行するコードシェア便の予約を実現する、共同予約サーバをさらに含み、
     前記共同予約サーバは、前記コードシェア便を運行する前記複数の航空会社それぞれに対応する前記予約サーバに、少なくとも、前記コードシェア便を予約した利用者の前記健康パスポート情報を送信し、
     前記複数の航空会社それぞれに対応する前記予約サーバは、前記複数の航空会社それぞれの前記予約サーバに対応する前記出発管理サーバに、少なくとも前記健康パスポート情報を送信する、請求項3に記載のシステム。
    further comprising a joint reservation server for realizing reservations for codeshare flights jointly operated by multiple airlines;
    The joint reservation server transmits at least the health passport information of the user who has reserved the code-share flight to the reservation servers corresponding to each of the plurality of airlines operating the code-share flight,
    4. The system of claim 3, wherein the reservation servers corresponding to each of the plurality of airlines transmit at least the health passport information to the departure management server corresponding to the reservation servers of each of the plurality of airlines.
  5.  前記出発管理サーバは、前記到着国の到着空港に設置され、前記利用者が入国する際の税関、入国管理、検疫に関する処理を行うCIQ(Customs Immigration Quarantine)サーバに、前記到着国に入国する前記利用者の前記健康パスポート情報を送信する、請求項1乃至4のいずれか一項に記載のシステム。 The departure management server is installed at the arrival airport of the arrival country, and is a CIQ (Customs Immigration Quarantine) server that performs processing related to customs, immigration control, and quarantine when the user enters the country. 5. The system according to any one of claims 1 to 4, wherein said health passport information of a user is transmitted.
  6.  前記検証サーバは、前記入国要件の検証に関する詳細情報を前記出発管理サーバに通知し、
     前記出発管理サーバは、前記入国要件の検証に関する詳細情報を前記チェックイン端末に通知し、
     前記チェックイン端末は、前記入国要件の検証に関する詳細情報が記載された搭乗券を発券する、請求項2に記載のシステム。
    The verification server notifies the departure management server of detailed information regarding the verification of the entry requirements;
    The departure management server notifies the check-in terminal of detailed information regarding verification of the entry requirements;
    3. The system of claim 2, wherein the check-in terminal issues a boarding pass containing detailed information regarding verification of the entry requirements.
  7.  前記予約サーバは、出発便と乗り継ぎ便の航空券を予約可能とし、
     前記出発便が出発する出発国からの出国を管理する第1の出発管理サーバは、前記出発便が乗り継ぎのために到着する乗り継ぎ国の入国要件の検証に関する前記入国要件検証要求を前記検証サーバに送信し、
     前記乗り継ぎ国からの出国を管理する第2の出発管理サーバは、前記乗り継ぎ便が到着する到着国の入国要件の検証に関する前記入国要件検証要求を前記検証サーバに送信し、
     前記第2の出発管理サーバは、前記利用者が前記到着国に入国可と判定された場合に、前記乗り継ぎ便の搭乗券を発行し、前記発行された搭乗券の前記搭乗券情報を前記第1の出発管理サーバに送信し、
     前記第1の出発管理サーバは、前記利用者が前記乗り継ぎ国に入国可と判定され、且つ、前記乗り継ぎ便の搭乗券が発行されていれば、前記出発便の搭乗券を発行すると共に、前記出発便と前記乗り継ぎ便の搭乗券を発券する、請求項3に記載のシステム。
    The reservation server enables reservation of airline tickets for departure flights and connecting flights,
    A first departure management server that manages departure from a departure country from which the departure flight departs, transmits the entry requirements verification request regarding verification of entry requirements of a transit country to which the departure flight arrives for transit, to the verification server. send to
    A second departure management server that manages departures from the transit country transmits to the verification server the entry requirements verification request for verification of entry requirements of the destination country where the transit flight arrives,
    The second departure management server issues a boarding pass for the connecting flight when it is determined that the user is allowed to enter the arrival country, and transfers the boarding pass information of the issued boarding pass to the second departure management server. 1 to the departure management server,
    The first departure management server issues a boarding pass for the departure flight if the user is determined to be allowed to enter the transit country and a boarding pass for the transit flight has been issued, and 4. The system of claim 3, issuing boarding passes for outgoing flights and said connecting flights.
  8.  前記第1の出発管理サーバは、前記到着国の到着空港に設置され、前記利用者が入国する際の税関、入国管理、検疫に関する処理を行うCIQ(Customs Immigration Quarantine)サーバに、前記到着国に入国する前記利用者の前記健康パスポート情報を送信する、請求項7に記載のシステム。 The first departure management server is a CIQ (Customs Immigration Quarantine) server that is installed at the arrival airport of the arrival country and performs processing related to customs, immigration control, and quarantine when the user enters the country. 8. The system of claim 7, transmitting the health passport information of the user entering the country.
  9.  前記検証サーバは、前記乗り継ぎ国の入国要件の検証に関する詳細情報を前記第1の出発管理サーバに通知すると共に、前記到着国の入国要件の検証に関する詳細情報を前記第2の出発管理サーバに通知し、
     前記第2の出発管理サーバは、前記到着国の入国要件の検証に関する詳細情報を前記第1の出発管理サーバに通知し、
     前記第1の出発管理サーバは、前記乗り継ぎ国及び到着国それぞれの前記入国要件の検証に関する詳細情報を前記チェックイン端末に通知し、
     前記チェックイン端末は、前記乗り継ぎ国の入国要件の検証に関する詳細情報が記載された前記出発便の搭乗券と、前記到着国の入国要件の検証に関する詳細情報が記載された前記乗り継ぎ便の搭乗券を発券する、請求項7又は8に記載のシステム。
    The verification server notifies the first departure management server of detailed information regarding the verification of entry requirements of the transit country, and notifies the second departure management server of detailed information regarding the verification of entry requirements of the destination country. death,
    The second departure management server notifies the first departure management server of detailed information regarding verification of entry requirements of the arrival country;
    The first departure management server notifies the check-in terminal of detailed information regarding verification of the entry requirements of each of the transit country and the arrival country;
    The check-in terminal provides a boarding pass for the departing flight containing detailed information regarding verification of entry requirements of the transit country and a boarding pass for the connecting flight containing detailed information regarding verification of entry requirements for the destination country. 9. A system according to claim 7 or 8, for issuing tickets for
  10.  前記利用者の第1の生体情報を記憶する、認証サーバと、
     前記利用者の第2の生体情報を取得し、前記取得された生体情報を含む認証要求を前記認証サーバに送信する、認証端末と、
     をさらに含み、
     前記認証サーバは、前記第1の生体情報及び前記第2の生体情報を用いた生体認証を行い、認証結果を前記認証端末に送信し、
     前記認証端末は、認証に成功した前記利用者にサービスを提供する、請求項1乃至9のいずれか一項に記載のシステム。
    an authentication server that stores first biometric information of the user;
    an authentication terminal that acquires second biometric information of the user and transmits an authentication request including the acquired biometric information to the authentication server;
    further comprising
    The authentication server performs biometric authentication using the first biometric information and the second biometric information, and transmits an authentication result to the authentication terminal;
    10. The system according to any one of claims 1 to 9, wherein said authentication terminal provides services to said user who has been successfully authenticated.
  11.  前記健康パスポート情報は、感染症に関する、ワクチン接種証明書、陰性証明書及び回復証明書のうち少なくとも1つを含む、請求項1乃至10のいずれか一項に記載のシステム。 11. The system according to any one of claims 1 to 10, wherein the health passport information includes at least one of a vaccination certificate, a negative certificate and a recovery certificate regarding an infectious disease.
  12.  航空券を予約した利用者の健康に関する健康パスポート情報を記憶する、記憶部と、
     チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信する、送信部と、
     前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信する受信部と、
     前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、搭乗券制御部と、
     を備える、出発管理サーバ。
    a storage unit for storing health passport information relating to the health of a user who has booked an airline ticket;
    a transmission unit for transmitting an entry requirements verification request including at least the health passport information of the user who checks in to a verification server for verifying the entry requirements of each country;
    a receiving unit that receives verification results from the verification server as to whether or not the health passport information satisfies the entry requirements of the country of arrival of the user;
    a boarding pass control unit that issues a boarding pass to the user when the user is determined to be allowed to enter the country of arrival;
    Departure management server, comprising:
  13.  出発管理サーバにおいて、
     航空券を予約した利用者の健康に関する健康パスポート情報を記憶し、
     チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信し、
     前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信し、
     前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する、出発管理サーバの制御方法。
    In the departure management server,
    remember health passport information about the health of the user who booked the ticket,
    sending an entry requirements verification request including at least said health passport information of said user checking in to a verification server for verifying the entry requirements of each country;
    receiving from the verification server a verification result as to whether the health passport information satisfies the entry requirements of the country of arrival of the user;
    A control method for a departure management server, wherein a boarding pass is issued to the user when the user is determined to be allowed to enter the arrival country.
  14.  出発管理サーバに搭載されたコンピュータに、
     航空券を予約した利用者の健康に関する健康パスポート情報を記憶する処理と、
     チェックイン手続きを行う前記利用者の前記健康パスポート情報を少なくとも含む入国要件検証要求を、各国の入国要件を検証する検証サーバに送信する処理と、
     前記検証サーバから、前記健康パスポート情報が、前記利用者が入国する到着国の入国要件を満たしているか否かに関する検証結果を受信する処理と、
     前記利用者が前記到着国に入国可と判定された場合に、前記利用者に搭乗券を発行する処理と、
     を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
    On the computer installed in the departure management server,
    a process of storing Health Passport information relating to the health of the user who booked the airline ticket;
    a process of sending an entry requirements verification request including at least the health passport information of the user who performs the check-in procedure to a verification server that verifies the entry requirements of each country;
    a process of receiving, from the verification server, a verification result as to whether the health passport information satisfies the entry requirements of the country of arrival of the user;
    a process of issuing a boarding pass to the user when the user is determined to be allowed to enter the country of arrival;
    A computer-readable storage medium that stores a program for executing
PCT/JP2021/037353 2021-10-08 2021-10-08 System, departure management server, departure management server control method, and storage medium WO2023058225A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/JP2021/037353 WO2023058225A1 (en) 2021-10-08 2021-10-08 System, departure management server, departure management server control method, and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2021/037353 WO2023058225A1 (en) 2021-10-08 2021-10-08 System, departure management server, departure management server control method, and storage medium

Publications (1)

Publication Number Publication Date
WO2023058225A1 true WO2023058225A1 (en) 2023-04-13

Family

ID=85804029

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2021/037353 WO2023058225A1 (en) 2021-10-08 2021-10-08 System, departure management server, departure management server control method, and storage medium

Country Status (1)

Country Link
WO (1) WO2023058225A1 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102216499B1 (en) * 2019-06-13 2021-02-17 주식회사 날라주 Passport for companion animals and method of proceeding immigration procedure
JP6933317B1 (en) * 2020-12-01 2021-09-08 日本電気株式会社 Information processing equipment, information processing systems, information processing methods, information terminals and programs
US20210287768A1 (en) * 2020-03-13 2021-09-16 NextGen Monetization Trust Trusted third-party computerized platform for ai-based health wallet

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102216499B1 (en) * 2019-06-13 2021-02-17 주식회사 날라주 Passport for companion animals and method of proceeding immigration procedure
US20210287768A1 (en) * 2020-03-13 2021-09-16 NextGen Monetization Trust Trusted third-party computerized platform for ai-based health wallet
JP6933317B1 (en) * 2020-12-01 2021-09-08 日本電気株式会社 Information processing equipment, information processing systems, information processing methods, information terminals and programs

Similar Documents

Publication Publication Date Title
JP2023138550A (en) Gate device, immigration examination system, method for controlling gate device, and program
JP7287512B2 (en) SERVER DEVICE, SYSTEM, CONTROL METHOD FOR SERVER DEVICE, AND COMPUTER PROGRAM
WO2023058225A1 (en) System, departure management server, departure management server control method, and storage medium
JP7006865B1 (en) Management server, system, token issuance method and computer program
WO2023053360A1 (en) Authentication terminal, system, method for controlling authentication terminal, and storage medium
WO2022024281A1 (en) Authentication server, authentication system, authentication request processing method, and storage medium
WO2021260940A1 (en) Server device, system, control method for server device, and recording medium
JP7414167B1 (en) Server device, control method and program for server device
WO2024084713A1 (en) Terminal, system, method for controlling terminal, and storage medium
JP7276523B2 (en) MANAGEMENT SERVER, SYSTEM, TOKEN ISSUING METHOD AND COMPUTER PROGRAM
JP7298737B2 (en) SERVER DEVICE, SYSTEM, CONTROL METHOD FOR SERVER DEVICE, AND COMPUTER PROGRAM
JP7040690B1 (en) Server equipment, system, control method of server equipment and computer program
JP7283597B2 (en) SERVER DEVICE, SYSTEM, CONTROL METHOD FOR SERVER DEVICE, AND COMPUTER PROGRAM
JP7279772B2 (en) SERVER DEVICE, SYSTEM, CONTROL METHOD FOR SERVER DEVICE, AND COMPUTER PROGRAM
WO2023248445A1 (en) System, terminal, method for controlling terminal, and storage medium
JP7004128B1 (en) Server equipment, system, control method of server equipment and computer program
WO2023053362A1 (en) Authentication terminal, system, control method for authentication terminal, and recording medium
JP2023093699A (en) Management server, system, method, and computer program
JP7028385B1 (en) Server equipment, system, control method of server equipment and computer program
JP7108243B1 (en) SYSTEM, SERVER DEVICE, CONTROL METHOD AND PROGRAM FOR SERVER DEVICE
JP2023115090A (en) Server device, method for controlling server device, and computer program
JP7298733B2 (en) SERVER DEVICE, SYSTEM, CONTROL METHOD FOR SERVER DEVICE, AND COMPUTER PROGRAM
WO2023157158A1 (en) System, server device, server device control method, and storage medium
WO2023162041A1 (en) Server device, system, server device control method, and storage medium
WO2023053268A1 (en) System, authentication terminal, authentication terminal control method, and storage medium

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21959966

Country of ref document: EP

Kind code of ref document: A1