WO2024009604A1 - 認証装置 - Google Patents
認証装置 Download PDFInfo
- Publication number
- WO2024009604A1 WO2024009604A1 PCT/JP2023/017588 JP2023017588W WO2024009604A1 WO 2024009604 A1 WO2024009604 A1 WO 2024009604A1 JP 2023017588 W JP2023017588 W JP 2023017588W WO 2024009604 A1 WO2024009604 A1 WO 2024009604A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- image
- avatar
- user
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/45—Structures or tools for the administration of authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06T—IMAGE DATA PROCESSING OR GENERATION, IN GENERAL
- G06T13/00—Animation
- G06T13/20—Three-dimensional [3D] animation
- G06T13/40—Three-dimensional [3D] animation of characters, e.g. humans, animals or virtual beings
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/16—Human faces, e.g. facial parts, sketches or expressions
- G06V40/172—Classification, e.g. identification
Definitions
- the present invention relates to an authentication device.
- a virtual space using XR (Cross Reality) technology including VR (Virtual Reality) technology, AR (Augmented Reality) technology, and MR (Mixed Reality) technology
- VR Virtual Reality
- AR Augmented Reality
- MR Magnetic Reality
- 3D images there is an avatar created using a photograph of the user's own face.
- real avatars that look very similar to the users themselves
- Patent Document 1 discloses the creation of an avatar in which photo data of the user's face transmitted from a terminal device used by the user through a network is received, and facial parts of the avatar are created using the photo data.
- the editing method is disclosed.
- an object of the present invention is to provide an authentication device that can add and delete authentication for the fact that an avatar that looks very similar to a certain person has been created by the person himself/herself.
- An authentication device includes an avatar generation unit that generates avatar data indicating an avatar of a service user using a user image obtained by capturing an image of a service user who uses a service related to an avatar. , an authentication unit that generates authentication data to be added to the avatar data when the avatar data is authenticated as genuine; an authentication deletion unit that deletes the authentication data from the avatar data when a deletion condition is satisfied;
- an avatar data authentication device comprising:
- FIG. 1 is a diagram showing the overall configuration of an avatar system 1.
- FIG. 5 is a flowchart showing an example of the operation when the authentication device 10 generates avatar data AD. 5 is a flowchart illustrating an operation example when the authentication device 10 deletes authentication data.
- FIG. 2 is a block diagram showing a configuration example of an authentication device 10A.
- FIG. 3 is a functional block diagram showing the configuration of a request reception unit 118A.
- FIG. 2 is a functional block diagram showing the configuration of a request determination unit 120.
- FIG. 10 is a flowchart illustrating an operation example when the authentication device 10A forcibly generates authentication data.
- FIG. 3 is a functional block diagram showing the configuration of a request determination unit 120B.
- the flowchart which shows the example of an operation when authentication device 10B forcibly deletes authentication data.
- FIGS. 1 to 6 First Embodiment
- an avatar system 1 including an authentication device 10 according to a first embodiment of the present invention will be described with reference to FIGS. 1 to 6.
- the authentication device 10 first generates avatar data indicating an avatar that has not been authenticated by the person himself/herself, and then adds authentication of authenticity to the avatar data after the fact.
- FIG. 1 shows the overall configuration of an avatar system 1 according to the first embodiment.
- the avatar system 1 includes an authentication device 10 and terminal devices 30-1, 30-2, . . . 30-K, . . . 30-N.
- N is an integer of 2 or more.
- K is an integer greater than or equal to 1 and less than or equal to N.
- the terminal devices 30-1 to 30-N have the same configuration. However, terminal devices with different configurations may be included.
- terminal device 30 may be collectively referred to as "terminal device 30."
- the authentication device 10 and the terminal devices 30-1 to 30-N may be, for example, a smartphone or a tablet, or a PC (Personal Computer).
- the authentication device 10 and the terminal devices 30-1 to 30-N are communicably connected to each other via the communication network NET.
- user UK uses a terminal device 30-K.
- users who use any of the terminal devices 30-1 to 30-N may be collectively referred to as "users U.”
- the authentication device 10 is a device used by the user U to generate an avatar, and is also a device that adds and deletes authentication to avatar data indicating the generated avatar.
- the "authentication" is authentication that the avatar data is genuine avatar data generated by the user U himself/herself.
- the authentication device 10 when the user UK uses the authentication device 10 to generate an avatar, the authentication device 10 generates avatar data indicating an avatar that looks very similar to the user UK . Further, when the user UK generates an avatar, the authentication device 10 authenticates that the avatar data indicating the avatar is genuine data generated by the user UK himself, and adds authentication to the avatar data. Generate data. Furthermore, the authentication device 10 deletes the authentication data from the avatar data when a predetermined deletion condition is satisfied.
- FIG. 2 is an example of an avatar AK that was generated by the user UK himself using the authentication device 10 and whose avatar data representing the avatar has been authenticated as genuine. As shown in FIG. 2, an authentication mark M is added to the avatar AK to indicate that the avatar data representing the avatar AK has been authenticated. Note that in FIG. 2, avatars AK are depicted in a simplified manner.
- the terminal device 30 is a device that displays the avatar A. Specifically, the terminal device 30 is equipped with a display 34, which will be described later. Avatar A is displayed on the display 34. Note that the avatar AK generated by the user UK and corresponding to the user UK himself is not limited to the terminal device 30-K, but is also displayed on other terminal devices 30, and users U other than the user UK can Avatar AK can be visually recognized on the display 34 provided in the other terminal device 30. Furthermore, XR glasses, XR goggles, or an HMD (Head Mounted Display) using XR technology may be connected to the terminal device 30.
- XR glasses, XR goggles, or an HMD (Head Mounted Display) using XR technology may be connected to the terminal device 30.
- FIG. 3 is a block diagram showing an example of the configuration of the terminal device 30-K.
- the terminal device 30-K includes a processing device 31, a storage device 32, a communication device 33, a display 34, an input device 35, and an imaging device 36.
- Each element included in the terminal device 30 is interconnected by one or more buses for communicating information.
- the processing device 31 is a processor that controls the entire terminal device 30-K. Further, the processing device 31 is configured using, for example, a single chip or a plurality of chips. The processing device 31 is configured using, for example, a central processing unit (CPU) that includes an interface with peripheral devices, an arithmetic unit, registers, and the like. Note that some or all of the functions of the processing device 31 may be realized by hardware such as a DSP, ASIC, PLD, and FPGA. The processing device 31 executes various processes in parallel or sequentially.
- CPU central processing unit
- the storage device 32 is a recording medium that can be read and written by the processing device 31 . Furthermore, the storage device 32 stores a plurality of programs including the control program PR3 executed by the processing device 31. The storage device 32 also stores account information for user UK to log into the avatar system 1.
- the account information includes, for example, user UK 's account ID, user UK 's phone number, user UK 's email address, user UK 's biometric information such as fingerprints, password set by user UK himself, It includes any one or more of an authentication pattern, a photo of user UK 's driver's license, and a database of user UK 's face photo.
- the account information is transmitted from the terminal device 30-K to the authentication device 10 and stored in the storage device 12 provided in the authentication device 10. As an example, when user UK logs in to avatar system 1, account information stored in terminal device 30-K and account information stored in authentication device 10 are compared.
- the communication device 33 is hardware as a transmitting/receiving device for communicating with other devices.
- the communication device 33 is also called, for example, a network device, a network controller, a network card, a communication module, or the like.
- the communication device 33 may include a connector for wired connection and an interface circuit corresponding to the connector.
- the communication device 33 may include a wireless communication interface. Examples of connectors and interface circuits for wired connections include products compliant with wired LAN, IEEE1394, and USB.
- examples of the wireless communication interface include products compliant with wireless LAN, Bluetooth (registered trademark), and the like.
- the display 34 is a device that displays images and text information.
- the display 34 displays various images under the control of the processing device 31.
- various display panels such as a liquid crystal display panel and an organic EL (Electro Luminescence) display panel are suitably used as the display 34.
- XR glasses, XR goggles, or an HMD using XR technology are connected to the terminal device 30-K, these XR glasses, XR goggles, or HMD using XR technology, It may also be used in place of the display 34.
- the input device 35 accepts operations from the user UK .
- the input device 35 includes a keyboard, a touch pad, a touch panel, or a pointing device such as a mouse.
- the input device 35 may also serve as the display 34.
- the user UK When generating the avatar AK , the user UK uploads a user image used for generating the avatar AK to the authentication device 10. At the time of uploading, the input device 35 is used by the user UK to input the above-mentioned user image into the terminal device 30. Note that it is preferable that the user image is, for example, a face photo or a full-body photo of the user UK .
- the imaging device 36 outputs imaging information obtained by imaging the outside world. Further, the imaging device 36 includes, for example, a lens, an imaging element, an amplifier, and an AD converter.
- the light collected through the lens is converted into an image signal, which is an analog signal, by an image sensor.
- the amplifier amplifies the imaging signal and outputs it to the AD converter.
- the AD converter converts the amplified imaging signal, which is an analog signal, into imaging information, which is a digital signal.
- the converted imaging information is supplied to the processing device 31.
- the imaging information supplied to the processing device 31 is output to the authentication device 10 via the communication device 33.
- the authentication device 10 When generating the avatar AK , the authentication device 10 needs to confirm the authenticity of the user UK .
- the imaging device 36 images the user UK .
- the imaging device 36 captures an image of the user UK 's head.
- Imaging information indicating a captured image captured by the imaging device 36 is supplied to the processing device 31 .
- the imaging information output to the processing device 31 is sent from the terminal device 30-K to the authentication device as information indicating a first confirmation image, which is an image for confirming that the user UK is a service user who uses the service. 10.
- the authentication device 10 when deleting authentication data, the authentication device 10 requires the user UK to confirm his/her identity.
- the imaging device 36 images the user UK .
- the imaging device 36 captures an image of the user UK 's head.
- Imaging information indicating a captured image captured by the imaging device 36 is supplied to the processing device 31 .
- the imaging information output to the processing device 31 is output to the authentication device 10 as information indicating a second confirmation image that is an image for identity confirmation.
- the second confirmation image is an example of a "confirmation image.”
- the processing device 31 functions as an acquisition section 311, a display control section 312, and a communication control section 313 by reading out and executing the control program PR3 from the storage device 32.
- the acquisition unit 311 acquires information indicating the user image from the input device 35.
- the acquisition unit 311 also acquires information indicating the first confirmation image and information indicating the second confirmation image from the imaging device 36.
- the acquisition unit 311 acquires the avatar data from the authentication device 10 via the communication device 33 .
- the display control unit 312 uses the avatar data acquired by the acquisition unit 311 to display avatar AK on the display 34.
- the communication control unit 313 causes the authentication device 10 to transmit the information indicating the user image, the first confirmation image, and the second confirmation image acquired by the acquisition unit 311 to the communication device 33.
- the communication control unit 313 also causes the authentication device 10 to transmit a deletion request requesting deletion of the authentication.
- FIG. 4 is a block diagram showing an example of the configuration of the authentication device 10.
- the authentication device 10 includes a processing device 11 , a storage device 12 , a communication device 13 , a display 14 , and an input device 15 .
- Each element included in the authentication device 10 is interconnected by a single bus or multiple buses for communicating information.
- the processing device 11 is a processor that controls the entire authentication device 10. Further, the processing device 11 is configured using, for example, a single chip or a plurality of chips. The processing device 11 is configured using, for example, a central processing unit (CPU) that includes an interface with peripheral devices, an arithmetic unit, registers, and the like. Note that some or all of the functions of the processing device 11 may be realized by hardware such as a DSP, ASIC, PLD, or FPGA. The processing device 11 executes various processes in parallel or sequentially.
- CPU central processing unit
- the storage device 12 is a recording medium that can be read and written by the processing device 11 . Furthermore, the storage device 12 stores a plurality of programs including the control program PR1 executed by the processing device 11. Furthermore, the storage device 12 stores avatar data AD generated by an avatar generation unit 116, which will be described later. Furthermore, the storage device 12 stores a user image used to generate avatar data AD representing the avatar AK of the user UK . Note that when each of the plurality of users U uses the method described below to generate avatar data AD indicating the avatar A corresponding to the user, each image, each information, and each data stored in the storage device 12 are , is preferably confirmed, collated, created, managed, and stored in association with each user U's account. Further, data stored in the storage device 12 can be read from the terminal device 30.
- the communication device 13 is hardware as a transmitting/receiving device for communicating with other devices.
- the communication device 13 is also called, for example, a network device, a network controller, a network card, a communication module, or the like.
- the communication device 13 may include a connector for wired connection and an interface circuit corresponding to the connector.
- the communication device 13 may include a wireless communication interface. Examples of connectors and interface circuits for wired connections include products compliant with wired LAN, IEEE1394, and USB.
- examples of the wireless communication interface include products compliant with wireless LAN, Bluetooth (registered trademark), and the like.
- the display 14 is a device that displays images and text information.
- the display 14 displays various images under the control of the processing device 11.
- various display panels such as a liquid crystal display panel and an organic EL (Electro Luminescence) display panel are suitably used as the display 14.
- the input device 15 accepts operations from the administrator of the authentication device 10.
- the input device 15 includes a keyboard, a touch pad, a touch panel, or a pointing device such as a mouse.
- the input device 15 may also serve as the display 14.
- the processing device 11 reads out and executes the control program PR1 from the storage device 12, thereby controlling the acquisition section 111, the image determination section 112, the image reception section 113, the verification section 114, the authentication section 115, the avatar generation section 116, and the communication control section. 117, a request reception unit 118, and an authentication deletion unit 119.
- the acquisition unit 111, image determination unit 112, image reception unit 113, matching unit 114, authentication unit 115, avatar generation unit 116, and communication control unit 117 are Collectively referred to as "functional unit FU1".
- the acquisition unit 111 displays a first confirmation image from the terminal device 30-K via the communication device 13 to confirm that the user UK is the user using the service. Get information. Note that the "user who uses the service” is an example of the "service user.”
- the acquisition unit 111 obtains a second confirmation image, which is an image for the user UK to confirm his or her identity, from the terminal device 30-K via the communication device 13. Get information indicating.
- the image determination unit 112 determines whether the first confirmation image acquired by the acquisition unit 111 when generating the avatar data AD is an image obtained by capturing an image of the user of the terminal device 30-K at the present time. Determine.
- the image determination unit 112 determines whether the person appearing in the first confirmation image is, for example, a person included in an image printed on paper, a person included in a two-dimensional photograph displayed on a display, or a person whose face is printed with another person's face. It is determined whether or not the person is not a person wearing a mask, but a person who is currently the object of image capture by the image capture device 36 provided in the terminal device 30-K.
- a specific determination method is, for example, whether the data representing a face photographed by the user UK moving his/her face forward, backward, left, and right in front of the imaging device 36 is data representing a three-dimensional image.
- One example is a method of determining.
- a method of determining a change in the way light hits the user UK especially when the user UK moves his face or body in front of the imaging device 36, the change in the way the light hits the user UK. can be mentioned.
- the determination method when the user UK moves his face in front of the imaging device 36, a method of determining whether there is a minute movement of the parts that make up the face and a blinking movement can be mentioned. .
- the user of the terminal device 30-K is wearing a mask with another person's face printed on it, physiological movements of the facial area will not be detected, so impersonation by wearing the mask will be eliminated. be done. Note that the "user of the terminal device 30-K" is an example of the "terminal user of the terminal device 30-K.”
- the image determination unit 112 determines whether the second confirmation image acquired by the acquisition unit 111 is currently on the terminal device 30 using the same method as when generating the avatar data AD. - Determine whether the image is obtained by capturing an image of the user K.
- the image receiving unit 113 receives, from the terminal device 30-K, a user image used to generate the avatar data AD representing the avatar AK of the user UK when generating the avatar data AD. As mentioned above, it is preferable that the user image is a face photo or a full body photo of user UK . Further, the image receiving unit 113 stores the received user image in the storage device 12.
- the matching unit 114 matches the person appearing in the first confirmation image with the person appearing in the user image. For example, the matching unit 114 determines whether the facial features included in the facial data representing the face of the person appearing in the first confirmation image match the facial features representing the face of the person appearing in the user image. Match both people based on. Examples of the facial features include the shapes of eyebrows, eyes, nose, and mouth, and the distances between the parts that make up the face.
- the matching unit 114 uses the same method as when generating the avatar data AD to match the person appearing in the second confirmation image with the person appearing in the user image. .
- the authentication unit 115 authenticates that the avatar data AD generated by the avatar generation unit 116, which will be described later, is genuine. Further, when authenticating the avatar data AD, the authentication unit 115 generates authentication data to be added to the avatar data AD.
- the "predetermined authentication condition" is, for example, that the determination result of the image determination unit 112 is positive and the verification result of the verification unit 114 is positive.
- the authentication unit 115 may add authentication data to the avatar data AD. Conversely, if the authentication unit 115 cannot authenticate the authenticity of the avatar data AD, it generates non-authentication data indicating that the avatar data AD is not authenticated, and sends the non-authentication data to the avatar data AD. May be added.
- the authentication unit 115 may generate data indicating the correspondence between the ID of the avatar data AD that specifies the avatar data AD and the presence or absence of authentication, and store the data indicating the correspondence in the storage device 12. Further, the authentication data, non-authentication data, and data indicating correspondence may be managed by the authentication unit 115 or by an authentication information management unit (not shown). For example, the determination as to whether or not to add the authentication mark M to the avatar AK displayed on the display 34 is made by the authentication information management section based on the avatar data AD indicating the avatar AK read from the storage device 12. The determination may be made based on the presence or absence of linked authentication data or non-authentication data.
- the avatar generation unit 116 generates avatar data AD using the user image. Specifically, the avatar generation unit 116 generates avatar A that resembles the person appearing in the user image, or avatar data AD that indicates the avatar A that has the characteristics of the person. For example, the avatar generation unit 116 generates avatar data AD indicating avatar A having a face that closely resembles the face of the person in question, or avatar A having facial features of the person in question. As described above, when the authentication unit 115 authenticates the authenticity of the avatar data AD and generates authentication data, the avatar generation unit 116 adds the authentication data to the avatar data AD, for example.
- the authentication device 10 can authenticate that the avatar A, which has an appearance that closely resembles that of a certain person, was created by that person.
- the communication control unit 117 causes the communication device 13 to transmit the avatar data AD generated by the avatar generation unit 116 to the terminal device 30.
- the processing device 11 may cause the avatar generation unit 116 to generate the avatar data AD after the authentication unit 115 executes the authentication. Authentication may also be performed. Furthermore, after the avatar generation unit 116 generates the avatar data AD, the processing device 11 may perform determination by the image determination unit 112, verification by the verification unit 114, and authentication by the authentication unit 115. As a result, after the avatar data AD that was generated in advance and has not been authenticated as genuine is authenticated after the fact, information indicating that the avatar data AD has been authenticated is obtained. can be added later. As a result, even after user UK has generated avatar A without authentication, he can change it to avatar A with authentication without changing the appearance of avatar A.
- user UK when user UK generates avatar A K for the first time, user UK saves the trouble of authentication and simply generates avatar A K without authentication. Thereafter, the user UK can authenticate when he/she has time, using the avatar AK that has the same appearance as the previously generated avatar AK .
- the request receiving unit 118 receives a deletion request from the terminal device 30 instructing deletion of authentication data from the avatar data AD. Note that the request reception unit 118 is an example of a “reception unit”.
- the authentication deletion unit 119 is triggered by the request reception unit 118 accepting the deletion request, and deletes the authentication data from the avatar data AD if a predetermined deletion condition is satisfied.
- the "predetermined deletion condition" is, for example, that the determination result of the image determination unit 112 is positive and the verification result of the verification unit 114 is positive.
- the authentication deletion unit 119 may not only delete the authentication data from the avatar data AD but also add non-authentication data to the avatar data AD when a predetermined deletion condition is satisfied. Alternatively, when a predetermined deletion condition is satisfied, the authentication deletion unit 119 rewrites the data stored in the storage device 12 that indicates the correspondence between the ID of the avatar data AD that specifies the avatar data AD and the presence or absence of authentication. Good too.
- the authentication data deleted by the authentication deletion unit 119 is not limited to the authentication data generated by the authentication unit 115.
- the authentication deletion unit 119 Authentication data can be deleted.
- the authentication device 10 is able to add and delete authentication for the fact that the avatar A, which looks very similar to a certain person, was created by the person himself/herself.
- FIG. 5 is a flowchart showing an example of the operation when the authentication device 10 generates avatar data AD.
- an example of the operation of the authentication device 10 will be described with reference to FIG. 5.
- step S1 the processing device 11 functions as the acquisition unit 111.
- the processing device 11 acquires information indicating the first confirmation image CP1 for confirming that the user UK is the user using the service from the terminal device 30-K via the communication device 13.
- step S2 the processing device 11 functions as the image determination section 112.
- the processing device 11 determines whether the first confirmation image CP1 acquired in step S1 is an image obtained by capturing an image of the user of the terminal device 30-K at the present time.
- step S3 the processing device 11 functions as the image reception unit 113.
- the processing device 11 receives from the terminal device 30-K a user image UP used to generate avatar data AD indicating the avatar AK of the user UK using the service.
- step S4 the processing device 11 functions as the matching unit 114.
- the processing device 11 compares the person appearing in the first confirmation image CP1 with the person appearing in the user image UP.
- step S5 if the authentication condition is satisfied, that is, if both the determination result in step S2 and the verification result in step S4 are positive, the processing device 11 executes the process of step S6. On the other hand, if the authentication condition is not satisfied, that is, if at least one of the determination result in step S2 and the verification result in step S4 is negative, the processing device 11 ends all processing.
- step S6 the processing device 11 functions as the authentication unit 115.
- the processing device 11 authenticates the authenticity of the generated avatar data AD. Furthermore, the processing device 11 generates authentication data CD.
- step S7 the processing device 11 functions as the avatar generation unit 116.
- the processing device 11 generates avatar data AD using the user image UP received in step S3.
- the authentication data CD generated in step S5 is added to the avatar data AD.
- the processing device 11 stores the generated avatar data AD in the storage device 12 with the authentication data CD added thereto.
- step S8 the processing device 11 functions as the communication control unit 117.
- the processing device 11 causes the communication device 13 to transmit the avatar data AD generated in step S7 to the terminal device 30-K.
- FIG. 6 is a flowchart showing an example of the operation when the authentication device 10 deletes the authentication data CD.
- an example of the operation of the authentication device 10 will be described with reference to FIG. 6.
- step S11 the processing device 11 functions as the request reception unit 118.
- the processing device 11 receives a deletion request DD requesting deletion of the authentication data CD from the terminal device 30-K via the communication device 13.
- step S12 the processing device 11 functions as the acquisition unit 111.
- the processing device 11 acquires information indicating the second confirmation image CP2 for confirming that the user UK is the user using the service from the terminal device 30-K via the communication device 13.
- step S13 the processing device 11 functions as the image determination unit 112.
- the processing device 11 determines whether the second confirmation image CP2 acquired in step S12 is an image obtained by capturing an image of the user of the terminal device 30-K at the present time.
- step S14 the processing device 11 functions as the image reception unit 113.
- the processing device 11 receives from the terminal device 30-K the user image UP used to generate the avatar data AD indicating the avatar AK of the user UK using the service.
- the processing device 11 may receive the user image UP by reading the user image UP from the storage device 12.
- step S15 the processing device 11 functions as the matching unit 114.
- the processing device 11 compares the person appearing in the second confirmation image CP2 with the person appearing in the user image UP.
- step S16 if the deletion condition is satisfied, that is, if both the determination result in step S13 and the verification result in step S15 are affirmative, the processing device 11 executes the process of step S17. On the other hand, if the deletion condition is not satisfied, that is, if at least one of the determination result in step S13 and the verification result in step S15 is negative, the processing device 11 ends all processing.
- step S17 the processing device 11 functions as the authentication deletion unit 119.
- the processing device 11 deletes the authentication data CD from the avatar data AD.
- the authentication device 10 includes the avatar generation section 116, the authentication section 115, and the authentication deletion section 119.
- the avatar generation unit 116 generates avatar data AD indicating the avatar AK of the user UK using the user image UP obtained by capturing an image of the user UK using the service.
- the authentication unit 115 When authenticating the avatar data AD, the authentication unit 115 generates authentication data CD.
- the authentication deletion unit 119 deletes the authentication data CD when the deletion conditions are satisfied.
- the authentication device 10 Since the authentication device 10 has the above configuration, it is possible to add and delete authentication for the fact that the avatar A, which has an appearance that closely resembles that of a certain person, has been created by the person himself/herself.
- the authentication device 10 can change the avatar AK to the avatar AK without personal authentication without changing the appearance of the avatar AK .
- the user UK who no longer feels the need to use the avatar AK with personal authentication can delete the personal authentication while keeping the same avatar AK as the avatar AK that was generated in advance.
- the authentication device 10 includes a request reception section 118 as a reception section, an acquisition section 111, an image determination section 112, and a collation section 114.
- the request accepting unit 118 accepts a deletion request DD for deleting the authentication data CD from the terminal device 30-K.
- the acquisition unit 111 acquires a second confirmation image CP2 as a confirmation image for user UK to confirm his/her identity from the terminal device 30-K.
- the image determination unit 112 confirms that the second confirmation image CP2 is an image obtained by capturing an image of the terminal user of the terminal device 30-K at the present time.
- the matching unit 114 matches the person appearing in the second confirmation image CP2 with the person appearing in the user image UP.
- the above deletion condition is that the determination result of the image determination unit 112 is positive and the verification result of the verification unit 114 is positive.
- the authentication device 10 Since the authentication device 10 has the above configuration, the first condition that the second confirmation image CP2 is an image obtained by capturing an image of the user of the terminal device 30-K, and the second confirmation The authentication data CD is deleted based on the second condition of whether or not the person reflected in the image CP2 and the person reflected in the user image UP are the same person. Therefore, the authentication device 10 can prevent someone else from deleting the authentication data CD by impersonating the user.
- FIGS. 7 to 11 Second Embodiment
- an avatar system 1A including an authentication device 10A according to a second embodiment of the present invention will be described with reference to FIGS. 7 to 11.
- the same reference numerals are used for the same components as those in the avatar system 1 among the components included in the avatar system 1A, and the explanation thereof may be omitted. be.
- the authentication device 10A forcibly generates or deletes the authentication data CD when there is a request to generate or delete the authentication data CD from the terminal device 30 as an external device.
- the avatar system 1A differs from the avatar system 1 in that it includes an authentication device 10A instead of the authentication device 10.
- the overall configuration of the avatar system 1A is the same as the overall configuration of the avatar system 1 shown in FIG. 1, so illustration thereof will be omitted.
- the configuration of the authentication device 10A will be mainly described.
- FIG. 7 is a block diagram showing an example of the configuration of the authentication device 10A.
- the authentication device 10A includes a processing device 11A instead of the processing device 11, and a storage device 12A instead of the storage device 12.
- the storage device 12A stores a control program PR1A instead of the control program PR1.
- the processing device 11A reads out and executes the control program PR1A from the storage device 12A, thereby controlling the functional unit FU1, that is, the acquisition unit 111, the image determination unit 112, the image reception unit 113, the verification unit 114, the authentication unit 115, and the avatar generation unit.
- the functional unit having the section 116 and the communication control section 117 it functions as a request reception section 118A, an authentication deletion section 119, and a request determination section 120.
- the request accepting unit 118A accepts requests from the terminal device 30.
- FIG. 8 is a functional block diagram showing the configuration of the request reception unit 118A.
- the request receiving section 118A includes a first receiving section 118A-1 and a second receiving section 118A-2.
- the first reception unit 118A-1 receives a deletion request DD from the terminal device 30 instructing to delete the authentication data CD.
- the second receiving unit 118A-2 receives a generation request from the terminal device 30 instructing to generate the authentication data CD.
- FIG. 9 is a functional block diagram showing the configuration of the request determination section 120.
- the request determining section 120 includes a first request determining section 120-1 and a second request determining section 120-2.
- the first request determination unit 120-1 determines whether the deletion request DD received by the first reception unit 118A-1 includes a forced instruction to forcibly delete the authentication data CD without the user UK 's approval. Determine whether or not it is possible. Note that the above-mentioned "predetermined deletion condition" used by the authentication deletion unit 119 is that the determination result of the first request determination unit 120-1 is affirmative. That is, the authentication deletion unit 119 deletes the authentication data CD when the determination result of the first request determination unit 120-1 is positive.
- the second request determination unit 120-2 determines that the generation request received by the second reception unit 118A-2 includes a forced instruction to forcibly generate the authentication data CD without the user UK 's approval. Determine whether or not. Note that the above-mentioned "predetermined authentication condition" used by the authentication unit 115 is that the determination result of the second request determination unit 120-2 is affirmative. That is, the authentication unit 115 generates authentication data CD when the determination result of the second request determination unit 120-2 is positive.
- FIG. 10 is a flowchart showing an example of the operation when the authentication device 10A forcibly deletes the authentication data CD.
- FIG. 10 an example of the operation of the authentication device 10A will be described with reference to FIG. 10.
- step S21 the processing device 11A functions as the first reception unit 118A-1.
- the processing device 11A receives a deletion request DD requesting deletion of the authentication data CD from the terminal device 30 via the communication device 13.
- step S22 the processing device 11A executes the process in step S23.
- the processing device 11A ends all the processes shown in FIG. 10. In this case, the processing device 11A may execute the processing from step S12 onward in the flowchart shown in FIG.
- the processing device 11A functions as a first request determination unit 120-1.
- the processing device 11A determines whether the deletion request DD received in step S21 includes a forced instruction. If the deletion request DD includes a forced instruction, the processing device 11A executes the process of step S23. On the other hand, if the deletion request DD does not include a forced instruction, the processing device 11A ends all processing. In this case, the processing device 11A may execute the processing from step S12 onward in the flowchart shown in FIG.
- step S23 the processing device 11A functions as the authentication deletion unit 119.
- the processing device 11A deletes the authentication data CD from the avatar data AD.
- FIG. 11 is a flowchart showing an example of the operation when the authentication device 10A forcibly generates authentication data CD.
- FIG. 11 an example of the operation of the authentication device 10A will be described with reference to FIG. 11.
- step S31 the processing device 11A functions as the second reception unit 118A-2.
- the processing device 11A receives a generation request GD requesting generation of authentication data CD from the terminal device 30 via the communication device 13.
- step S32 If the authentication condition is satisfied in step S32, the processing device 11A executes the process in step S33. On the other hand, if the authentication condition is not satisfied, the processing device 11A ends all the processes shown in FIG. 11.
- the processing device 11A functions as a second request determination section 120-2.
- the processing device 11A determines whether the generation request GD received in step S32 includes a forced instruction. If the generation request GD includes a forced instruction, the processing device 11A executes the process of step S33. On the other hand, if the generation request GD does not include a forced instruction, the processing device 11A ends all processing.
- step S33 the processing device 11A functions as the authentication unit 115.
- the processing device 11A generates authentication data CD.
- the authentication device 10A includes the first reception section 118A-1 and the first request determination section 120-1.
- the first receiving unit 118A-1 receives a deletion request DD from the terminal device 30 instructing to delete the authentication data CD.
- the first request determination unit 120-1 determines whether the deletion request DD includes a forced instruction to forcibly delete the authentication data CD without the user UK 's approval.
- the above deletion condition is that the determination result of the first request determination unit 120-1 is affirmative.
- the authentication device 10A since the authentication device 10A has the above configuration, when there is a request to delete the authentication data CD from the terminal device 30 as an external device, the authentication data CD can be forcibly deleted.
- the authentication device 10A forcibly deletes the authentication data CD from the avatar data AD indicating the avatar A, and A can be prevented from being used by others. Furthermore, when the creator of avatar A becomes unable to use avatar A for some reason, the authentication device 10A forcibly deletes the authentication data CD from the avatar data AD indicating avatar A, and prevents someone else from impersonating the avatar. The risk of using Avatar A can be reduced.
- the authentication device 10A includes the second reception section 118A-2 and the second request determination section 120-2.
- the second reception unit 118A-2 receives a generation request GD from the terminal device 30 instructing to generate authentication data CD.
- the second request determination unit 120-2 determines whether the generation request GD includes a forced instruction to forcibly generate the authentication data CD without satisfying the authentication conditions.
- Authentication unit 115 generates authentication data CD when the determination result of second request determination unit 120-2 is positive.
- the authentication device 10A since the authentication device 10A has the above configuration, when there is a request to generate the authentication data CD from the terminal device 30 as an external device, it can forcibly generate the authentication data CD.
- the authentication device 10A generates an avatar A without the authentication mark M added thereto when the person attempting to create the avatar A is the user UK , but the user UK is not authenticated. .
- the authentication device 10A forcibly adds the authentication data CD to the avatar data AD corresponding to the avatar A, thereby allowing the user UK himself to use the avatar A to which the authentication mark M has been added.
- FIGS. 12 and 13 Third Embodiment
- an avatar system 1B including an authentication device 10B according to a third embodiment of the present invention will be described with reference to FIGS. 12 and 13.
- the same reference numerals are used for the same components as those included in the avatar systems 1 and 1A, and the explanation thereof will be omitted.
- the authentication device 10B stores the first confirmation image CP1 used when generating the avatar data AD. Thereafter, for example, if it is suspected that spoofing was performed when the avatar data AD was generated, the authentication device 10B uses the stored first confirmation image CP1 to ensure that the person is correctly authenticated when the avatar data AD is generated. If the deletion conditions are satisfied, the authentication data CD is deleted.
- FIG. 1 Configuration of Third Embodiment 3-1-1: Overall Configuration Avatar system 1B differs from avatar system 1 in that it includes an authentication device 10B instead of authentication device 10. In other respects, the overall configuration of the avatar system 1B is the same as the overall configuration of the avatar system 1 shown in FIG. 1, so illustration thereof will be omitted. Below, the configuration of the authentication device 10B will be mainly explained.
- the authentication device 10B includes a processing device 11B instead of the processing device 11, and a storage device 12B instead of the storage device 12.
- the storage device 12B stores a control program PR1B instead of the control program PR1.
- the processing device 11B reads out and executes the control program PR1B from the storage device 12B, thereby generating the acquisition section 111B, image determination section 112B, image reception section 113B, matching section 114B, authentication section 115B, and avatar generation section as the functional unit FU1B.
- 116 and a communication control unit 117 it functions as a request reception unit 118, an authentication deletion unit 119, and a request determination unit 120B.
- the overall configuration of the authentication device 10B is the same as the configuration of the authentication device 10A according to the second embodiment shown in FIGS. 7 and 8, so illustration thereof will be omitted.
- the acquisition unit 111B acquires the first confirmation image CP1 from the terminal device 30-K when generating the avatar data AD. Furthermore, the acquisition unit 111B stores the acquired first confirmation image CP1 in the storage device 12B. Note that in this embodiment, the first confirmation image CP1 is an example of a "confirmation image.” Furthermore, the terminal device 30-K is an example of an "external device.”
- the image determining unit 112B determines whether the first confirmation image CP1 acquired by the acquiring unit 111B is currently obtained by imaging the user of the terminal device 30-K when generating the avatar data AD. It is determined whether or not the image is a captured image.
- the image determination unit 112B executes the above determination using the first confirmation image CP1 read from the storage device 12B. Specifically, the image determination unit 112B determines whether the first confirmation image CP1 read from the storage device 12B is an image obtained by capturing an image of the user of the terminal device 30-K at the time of generating the avatar data AD. Determine whether or not.
- the image receiving section 113B receives the user image UP used for generating the avatar data AD representing the avatar AK of the user UK from the terminal device 30-K when generating the avatar data AD. Further, the image receiving unit 113B stores the received user image UP in the storage device 12B.
- the image reception unit 113B reads the user image UP from the storage device 12B when deleting the authentication data CD from the avatar data AD.
- the image receiving unit 113B also receives the read user image UP.
- the matching unit 114B matches the person appearing in the first confirmation image CP1 with the person appearing in the user image UP when generating the avatar data AD.
- the verification unit 114B when deleting the authentication data CD from the avatar data AD, the verification unit 114B performs the above verification using the first confirmation image CP1 and the user image UP read from the storage device 12B. Specifically, the matching unit 114B matches the person appearing in the first confirmation image CP1 with the person appearing in the user image UP.
- the authentication unit 115B authenticates the authenticity of the avatar data AD using the first confirmation image CP1 acquired by the acquisition unit 111B when generating the avatar data AD. Specifically, the authentication unit 115B determines whether both the determination result based on the first determination criterion by the image determination unit 112B and the verification result based on the second determination criterion by the collation unit 114B are affirmative. Determine. Specifically, the first determination criterion is that the first confirmation image CP1 acquired by the acquisition unit 111B is obtained by imaging the user of the terminal device 30-K at the time of generating the avatar data AD. This is a criterion used when determining whether or not it is an image.
- the second criterion is a criterion used to determine whether the person appearing in the first confirmation image CP1 and the person appearing in the user image UP received by the image reception unit 113 are the same person. be.
- the above-mentioned "predetermined authentication condition" means that both the determination result based on the first determination criterion and the comparison result based on the second determination criterion are positive.
- FIG. 12 is a functional block diagram showing the configuration of the request determination section 120B.
- the request determining section 120B includes a reference determining section 120-3 instead of the second request determining section 120-2, compared to the request determining section 120 according to the second embodiment.
- the standard determination unit 120-3 makes a determination based on a first determination criterion that is similar to the first determination criterion used by the authentication unit 115B. Further, the standard determination unit 120-3 makes a determination based on a second determination criterion similar to the second determination criterion used by the authentication unit 115B. Specifically, the first determination criterion is whether the first confirmation image CP1 read from the storage device 12B is an image obtained by capturing an image of the user of the terminal device 30-K as an external device.
- the second criterion is whether the person reflected in the first confirmation image CP1 read from the storage device 12B and the person reflected in the user image UP read from the storage device 12B are the same person. This is the criterion for determining. If both the determination based on the first determination criterion and the determination based on the second determination criterion are affirmative, the determination result by the standard determination unit 120-3 is affirmative. On the other hand, if at least one of the determination based on the first determination criterion and the determination based on the second determination criterion is negative, the determination result by the standard determination unit 120-3 is negative.
- the first judgment criterion used by the authentication section 115B and the first judgment criterion used by the standard judgment section 120-3 are different in severity.
- the image determination unit 112B only confirms that the data representing the face photographed by the user UK moving his face back and forth and left and right in front of the imaging device 36 is data representing a three-dimensional image.
- the image determination section 112B not only confirms that the data representing the face is data representing a three-dimensional image, but also confirms that the data representing the face represents a three-dimensional image. Determine blinking movements.
- the second judgment criterion used by the authentication section 115B and the second judgment criterion used by the standard judgment section 120-3 are different in severity. For example, both at the time of authentication by the authentication unit 115B and at the time of determination by the standard determination unit 120-3, the matching unit 114B determines that the person appearing in the first confirmation image CP1 is the same as the person appearing in the user image UP. Verify. However, unless the similarity between the two persons is higher during the judgment by the reference judgment section 120-3 than during the authentication by the authentication section 115B, the matching section 114B will not judge that the two persons are the same. .
- the above-mentioned "predetermined deletion condition" used by the authentication deletion unit 119 is that the determination result by the first request determination unit 120-1 is positive and the determination result by the reference determination unit 120-3 is negative. . That is, the authentication deletion unit 119 deletes the authentication data CD when the determination result by the first request determination unit 120-1 is positive and the determination result by the reference determination unit 120-3 is negative.
- FIG. 3 An operation example when the authentication device 10B generates avatar data AD is basically the authentication shown in FIG. The operation example is the same as when the device 10 generates the avatar data AD, so its illustration is omitted. Below, among the operation examples when the authentication device 10B generates the avatar data AD, points that are different from the operation examples when the authentication device 10 generates the avatar data AD will be explained.
- step S1 the processing device 11B functions as the acquisition unit 111B.
- the processing device 11 acquires information indicating the first confirmation image CP1 for confirming that the user UK is the user using the service from the terminal device 30-K via the communication device 13. Further, the processing device 11B stores the acquired first confirmation image CP1 in the storage device 12A.
- the terminal device 30-K is an example of an "external device.”
- step S6 the processing device 11B functions as the authentication section 115B.
- the processing device 11B uses the first confirmation image CP1 to authenticate the authenticity of the generated avatar data AD.
- the "authentication conditions" in step S5 include that the first confirmation image CP1 acquired by the acquisition unit 111B images the user of the terminal device 30-K at the time of generating the avatar data AD. This includes the fact that the image determining unit 112B has determined that the image is an image obtained by.
- the processing device 11B authenticates that the generated avatar data AD is genuine based on the authentication condition using the first confirmation image CP1 as the determination criterion in step S5. Furthermore, the processing device 11B generates authentication data CD.
- FIG. 13 is a flowchart showing an example of the operation when the authentication device 10B deletes the authentication data CD.
- an example of the operation of the authentication device 10B will be described with reference to FIG. 13.
- step S41 the processing device 11B functions as the request reception unit 118.
- the processing device 11B receives, via the communication device 13, a deletion request DD requesting deletion of the authentication data CD from a terminal device 30 that is different from the terminal device 30-K used to generate the avatar data AD.
- the processing device 11A may receive a deletion request DD requesting deletion of the authentication data CD from the terminal device 30-K.
- step S42 the processing device 11B functions as the acquisition unit 111B.
- the processing device 11B acquires information indicating the first confirmation image CP1 for confirming that the user UK is the user using the service from the storage device 12B.
- step S43 the processing device 11B functions as the image determination section 112B.
- the processing device 11B determines whether the first confirmation image CP1 acquired in step S42 is an image obtained by capturing an image of the user of the terminal device 30-K when generating the avatar data AD.
- step S44 the processing device 11B functions as the image reception unit 113B.
- the processing device 11A receives from the storage device 12B the user image UP used to generate the avatar data AD representing the avatar AK of the user UK using the service.
- step S45 the processing device 11A functions as the matching unit 114B.
- the processing device 11B compares the person appearing in the first confirmation image CP1 with the person appearing in the user image UP.
- step S46 when the deletion condition is satisfied, that is, when the processing device 11B functions as the first request determination section 120-1, the determination result is affirmative, and the processing device 11B functions as the reference determination section 120-3. If the determination result in this case is negative, the processing device 11B executes the process of step S47. On the other hand, if the deletion condition is not satisfied, the processing device 11B ends all processing.
- step S47 the processing device 11B functions as the authentication deletion unit 119.
- the processing device 11B deletes the authentication data CD from the avatar data AD.
- the user image UP is sent from the terminal device 30-K as an external device together with the first confirmation image CP1 as a confirmation image when generating the avatar data AD. be obtained.
- the user image UP is stored in the storage device 12B together with the first confirmation image CP1.
- the authentication unit 115B determines that the first confirmation image CP1 is an image obtained by capturing an image of the user of the terminal device 30-K, and that the person reflected in the first confirmation image CP1 and the person reflected in the user image UP are If the avatar data AD is the same person, the authenticity of the avatar data AD is authenticated.
- the authentication device 10B also includes a reference determination section 120-3.
- the reference determination unit 120-3 determines whether the first confirmation image CP1 read from the storage device 12B is an image obtained by capturing an image of the user of the terminal device 30-K. The reference determination unit 120-3 also determines whether the person appearing in the first confirmation image CP1 read from the storage device 12B and the person appearing in the user image UP read from the storage device 12B are the same person. Determine whether or not.
- the above deletion condition is that the determination result by the first request determination section 120-1 is affirmative, and at least one of the two determination results by the reference determination section 120-3 is negative.
- the authentication device 10B Since the authentication device 10B has the above-described configuration, for example, if it is suspected that spoofing was carried out when the avatar data AD was generated, the authentication device 10B uses the stored first confirmation image CP1 to generate the avatar data AD. It is determined again whether the user was authenticated correctly when the data AD was generated, and if the deletion conditions are satisfied, the authentication data CD can be deleted.
- the avatar system 1 according to the first embodiment may use face information of the user UK who uses the avatar data AD to verify the identity of the user when using the avatar data AD.
- the authentication device 10 obtains user UK 's account information from the terminal device 30-K during normal times and stores it in the storage device 12.
- the account information includes, for example, User UK 's account ID, User UK 's phone number, User UK 's email address, User UK 's biometric information such as fingerprints, User UK 's driver's license photo, User UK's Contains one or more of K 's face photo databases.
- the authentication device 10 When authorizing the use of the avatar data AD after authenticating that the user UK is an authentic user, the authentication device 10 authenticates the user UK 's license information included in the above account information, for example. A confirmation image such as a face photograph of user UK is obtained from a database of photographs and face photographs of user UK . Then, the authentication device 10 confirms that the confirmation image such as the face photo of the user UK corresponds to the image currently obtained by capturing the user of the terminal device 30-K. If the above confirmation result is positive, the authentication device 10 authenticates that the user UK is an authentic user and then permits the use of the avatar data AD.
- the authentication device 10 embeds user image data indicating a user image UP, such as a face photo of the user UK , as a digital watermark in the avatar data AD.
- the authentication device 10 extracts user image data from the avatar data AD when permitting use of the avatar data AD after authenticating that the user UK is an authentic user.
- the authentication device 10 compares the person appearing in the user image UP indicated by the user image data with the person appearing in the image obtained by capturing the user of the terminal device 30-K. If the above verification result is positive, the authentication device 10 authenticates that the user UK is an authentic user and then permits the use of the avatar data AD.
- the authentication device 10 when the authentication device 10 according to the first embodiment deletes the authentication data CD from the avatar data AD, the authentication device 10 may delete the account information of the user UK from the storage device 12. Alternatively, the authentication device 10 may delete the user image data embedded in the avatar data AD. The same applies to the second embodiment and the third embodiment.
- the authentication devices 10 to 10B and the terminal device 30 are illustrated, but the storage devices included in the authentication devices 10 to 10B and the terminal device 30 are flexible disks, magneto-optical disks ( For example, compact discs, digital versatile discs, Blu-ray discs), smart cards, flash memory devices (e.g. cards, sticks, key drives), CD-ROMs (Compact Disc-ROMs), registers, removable A disk, hard disk, floppy disk, magnetic strip, database, server, or other suitable storage medium.
- the program executed by the external device may be transmitted from the network via a telecommunications line. Further, the program may be transmitted from the communication network NET via a telecommunications line.
- the information, signals, etc. described may be represented using any of a variety of different technologies.
- data, instructions, commands, information, signals, bits, symbols, chips, etc. which may be referred to throughout the above description, may refer to voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, light fields or photons, or any of these. It may also be represented by a combination of
- the input/output information may be stored in a specific location (for example, memory) or may be managed using a management table. Information etc. to be input/output may be overwritten, updated, or additionally written. The output information etc. may be deleted. The input information etc. may be transmitted to other devices.
- the determination may be made using a value expressed using 1 bit (0 or 1) or a truth value (Boolean: true or false).
- the comparison may be performed by comparing numerical values (for example, comparing with a predetermined value).
- each function illustrated in FIGS. 1, 3, 4, 7 to 9, and 12 is realized by an arbitrary combination of at least one of hardware and software.
- the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using one physically or logically coupled device, or may be realized using two or more physically or logically separated devices directly or indirectly (e.g. , wired, wireless, etc.) and may be realized using a plurality of these devices.
- the functional block may be realized by combining software with the one device or the plurality of devices.
- the programs exemplified in the above-described embodiments are instructions, instruction sets, codes, codes, regardless of whether they are called software, firmware, middleware, microcode, hardware description language, or by other names. Should be broadly construed to mean a segment, program code, program, subprogram, software module, application, software application, software package, routine, subroutine, object, executable, thread of execution, procedure, function, etc.
- software, instructions, information, etc. may be sent and received via a transmission medium.
- a transmission medium For example, if the software uses wired technology (coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), etc.) and/or wireless technology (infrared, microwave, etc.) to create a website, When transmitted from a server or other remote source, these wired and/or wireless technologies are included within the definition of transmission medium.
- wired technology coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), etc.
- wireless technology infrared, microwave, etc.
- the information, parameters, etc. described in this disclosure may be expressed using absolute values, relative values from a predetermined value, or other corresponding information. It may also be expressed as
- the authentication devices 10 to 10B and the terminal device 30 may be mobile stations (MS).
- a mobile station is defined by a person skilled in the art as a subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless It may also be referred to as a terminal, remote terminal, handset, user agent, mobile client, client, or some other suitable terminology. Further, in the present disclosure, terms such as “mobile station,” “user terminal,” “user equipment (UE),” and “terminal” may be used interchangeably.
- connection refers to direct or indirect connections between two or more elements.
- the coupling or connection between elements may be a physical coupling or connection, a logical coupling or connection, or a combination thereof.
- connection may be replaced with "access.”
- two elements may include one or more wires, cables, and/or printed electrical connections, as well as in the radio frequency domain, as some non-limiting and non-inclusive examples.
- electromagnetic energy having wavelengths in the microwave and optical (both visible and non-visible) ranges, etc. can be considered to be “connected” or “coupled” to each other.
- determining and “determining” used in this disclosure may encompass a wide variety of operations.
- “Judgment” and “decision” include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, search, and inquiry. (e.g., searching in a table, database, or other data structure), and regarding an ascertaining as a “judgment” or “decision.”
- judgment and “decision” refer to receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, and access.
- (accessing) may include considering something as a “judgment” or “decision.”
- judgment and “decision” refer to resolving, selecting, choosing, establishing, comparing, etc. as “judgment” and “decision”. may be included.
- judgment and “decision” may include regarding some action as having been “judged” or “determined.”
- judgment (decision) may be read as “assuming", “expecting", “considering”, etc.
- notification of prescribed information is not limited to explicit notification, but may also be done implicitly (for example, by not notifying the prescribed information). Good too.
- 1-1B...Avatar system 10-10B...Authentication device, 11-11B...Processing device, 12-12B...Storage device, 13...Communication device, 14...Display, 15...Input device, 30...Terminal device, 31...Processing Device, 32... Storage device, 33... Communication device, 34... Display, 35... Input device, 36... Imaging device, 111, 111B... Acquisition unit, 112, 112B... Image determination unit, 113, 113B...
- Image reception unit 114 , 114B...Verification section, 115, 115B...Authentication section, 116...Avatar generation section, 117...Communication control section, 118, 118A...Request reception section, 118A-1...First reception section, 118A-2...Second reception section , 119...Authentication deletion section, 120, 120B...Request determination section, 120-1...First request determination section, 120-2...Second request determination section, 120-3...Reference determination section, 311...Acquisition section, 312... Display control unit, 313... Communication control unit, FU1, FU1B... Functional unit, CP1... First confirmation image, CP2... Second confirmation image, PR1, PR1A, PR1B, PR3... Control program
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Oral & Maxillofacial Surgery (AREA)
- Human Computer Interaction (AREA)
- Multimedia (AREA)
- Collating Specific Patterns (AREA)
Abstract
Description
以下、図1~図6を参照しつつ、本発明の第1実施形態に係る認証装置10を備えるアバターシステム1について説明する。
1-1-1:全体構成
図1は、第1実施形態に係るアバターシステム1の全体構成を示す。図1に示されるように、アバターシステム1は、認証装置10、及び端末装置30-1、30-2、…30-K、…30-Nを備える。Nは2以上の整数である。Kは1以上N以下の整数である。本実施形態において、端末装置30-1~30-Nは同一の構成である。但し、構成が同一でない端末装置が含まれても良い。なお、以下では、端末装置30-1~30-Nを、「端末装置30」と総称することがある。また、認証装置10、及び端末装置30-1~30-Nは、例えば、スマートフォン又はタブレットであってもよく、あるいはPC(Personal Computer)であってもよい。
図3は、端末装置30-Kの構成例を示すブロック図である。端末装置30-Kは、処理装置31、記憶装置32、通信装置33、ディスプレイ34、入力装置35、及び撮像装置36を備える。端末装置30が有する各要素は、情報を通信するための単体又は複数のバスによって相互に接続される。
図4は、認証装置10の構成例を示すブロック図である。認証装置10は、処理装置11、記憶装置12、通信装置13、ディスプレイ14、及び入力装置15を備える。認証装置10が有する各要素は、情報を通信するための単体又は複数のバスによって相互に接続される。
1-2-1:アバターデータAD生成時の動作
図5は、認証装置10がアバターデータADを生成する場合の動作例を示すフローチャートである。以下、図5を参照することにより、認証装置10の動作例について説明する。
図6は、認証装置10が認証データCDを削除する場合の動作例を示すフローチャートである。以下、図6を参照することにより、認証装置10の動作例について説明する。
以上の説明によれば、本実施形態に係る認証装置10は、アバター生成部116と、認証部115と、認証削除部119とを備える。アバター生成部116は、サービスを利用するユーザUKを撮像することにより得られたユーザ画像UPを用いて、ユーザUKのアバターAKを示すアバターデータADを生成する。認証部115は、アバターデータADが真正であることを認証した場合、認証データCDを生成する。認証削除部119は、削除条件を充足する場合、認証データCDを削除する。
以下、図7~図11を参照しつつ、本発明の第2実施形態に係る認証装置10Aを備えるアバターシステム1Aについて説明する。なお、説明の簡略化のため、アバターシステム1Aに備わる構成要素のうち、アバターシステム1に備わる構成要素と同一の構成要素に対しては、同一の符号を用いると共に、その説明を省略することがある。
2-1-1:全体構成
アバターシステム1Aは、アバターシステム1に比較して、認証装置10の代わりに認証装置10Aを備える点で異なる。その他の点で、アバターシステム1Aの全体構成は、図1に示されるアバターシステム1の全体構成と同一であるため、その図示を省略する。以下では主として、認証装置10Aの構成について説明する。
図7は、認証装置10Aの構成例を示すブロック図である。認証装置10Aは、認証装置10に比較して、処理装置11の代わりに処理装置11Aを、記憶装置12の代わりに記憶装置12Aを備える。記憶装置12Aは、制御プログラムPR1の代わりに制御プログラムPR1Aを記憶する。処理装置11Aは、記憶装置12Aから制御プログラムPR1Aを読み出して実行することによって、機能ユニットFU1、すなわち、取得部111、画像判定部112、画像受付部113、照合部114、認証部115、アバター生成部116、及び通信制御部117を有する機能ユニットに加え、要求受付部118A、認証削除部119、及び要求判定部120として機能する。
2-2-1:アバターデータAD生成時の動作
認証装置10AがアバターデータADを生成する場合の動作例は、図5に示される、認証装置10がアバターデータADを生成する場合の動作例と同一であるため、その説明を省略する。
通常時において、認証装置10Aが認証データCDを削除する場合の動作例は、図6に示される、認証装置10が認証データCDを削除する場合の動作例と同一であるため、その説明を省略する。
図10は、認証装置10Aが認証データCDを強制的に削除する場合の動作例を示すフローチャートである。以下、図10を参照することにより、認証装置10Aの動作例について説明する。
図11は、認証装置10Aが認証データCDを強制的に生成する場合の動作例を示すフローチャートである。以下、図11を参照することにより、認証装置10Aの動作例について説明する。
以上の説明によれば、本実施形態に係る認証装置10Aは、第1受付部118A-1と、第1要求判定部120-1を備える。第1受付部118A-1は、端末装置30から認証データCDを削除することを指示する削除要求DDを受け付ける。第1要求判定部120-1は、ユーザUKが承認することなく強制的に認証データCDを削除することを指示する強制指示が、削除要求DDに含まれるか否かを判定する。上記の削除条件は、第1要求判定部120-1の判定結果が肯定であることである。
以下、図12~図13を参照しつつ、本発明の第3実施形態に係る認証装置10Bを備えるアバターシステム1Bについて説明する。なお、説明の簡略化のため、アバターシステム1Bに備わる構成要素のうち、アバターシステム1及び1Aに備わる構成要素と同一の構成要素に対しては、同一の符号を用いると共に、その説明を省略することがある。
3-1-1:全体構成
アバターシステム1Bは、アバターシステム1に比較して、認証装置10の代わりに認証装置10Bを備える点で異なる。その他の点で、アバターシステム1Bの全体構成は、図1に示されるアバターシステム1の全体構成と同一であるため、その図示を省略する。以下では主として、認証装置10Bの構成について説明する。
認証装置10Bは、認証装置10に比較して、処理装置11の代わりに処理装置11Bを、記憶装置12の代わりに記憶装置12Bを備える。記憶装置12Bは、制御プログラムPR1の代わりに制御プログラムPR1Bを記憶する。処理装置11Bは、記憶装置12Bから制御プログラムPR1Bを読み出して実行することによって、機能ユニットFU1Bとして、取得部111B、画像判定部112B、画像受付部113B、照合部114B、認証部115B、アバター生成部116、及び通信制御部117を有する機能ユニットに加えて、要求受付部118、認証削除部119、及び要求判定部120Bとして機能する。その他の点で、認証装置10Bの全体構成は、図7及び図8に示される、第2実施形態に係る認証装置10Aの構成と同一であるため、その図示を省略する。
3-2-1:アバターデータAD生成時の動作
認証装置10BがアバターデータADを生成する場合の動作例は、基本的に、図5に示される、認証装置10がアバターデータADを生成する場合の動作例と同一であるため、その図示を省略する。以下では、認証装置10BがアバターデータADを生成する場合の動作例のうち、認証装置10によるアバターデータAD生成時の動作例と異なる点について説明する。
図13は、認証装置10Bが認証データCDを削除する場合の動作例を示すフローチャートである。以下、図13を参照することにより、認証装置10Bの動作例について説明する。
本開示は、以上に例示した実施形態に限定されない。例えば、上記の実施形態から任意に選択された2以上の態様を併合してもよい。更に、具体的な変形の態様を以下に例示する。以下の例示から任意に選択された2以上の態様を併合してもよい。
第1実施形態に係るアバターシステム1は、アバターデータADの使用時に、本人確認のため、アバターデータADを使用するユーザUK本人の顔情報を用いて本人確認をしてもよい。
(1)上述した実施形態では、認証装置10~10B、及び端末装置30を例示したが、認証装置10~10B、及び端末装置30が備える記憶装置は、フレキシブルディスク、光磁気ディスク(例えば、コンパクトディスク、デジタル多用途ディスク、Blu-ray(登録商標)ディスク)、スマートカード、フラッシュメモリデバイス(例えば、カード、スティック、キードライブ)、CD-ROM(Compact Disc-ROM)、レジスタ、リムーバブルディスク、ハードディスク、フロッピー(登録商標)ディスク、磁気ストリップ、データベース、サーバその他の適切な記憶媒体である。また、外部装置が実行するプログラムは、電気通信回線を介してネットワークから送信されてもよい。また、プログラムは、電気通信回線を介して通信網NETから送信されてもよい。
Claims (5)
- アバターに関するサービスを利用するサービスユーザを撮像することにより得られたユーザ画像を用いて、前記サービスユーザのアバターを示すアバターデータを生成するアバター生成部と、
前記アバターデータが真正であることを認証した場合、前記アバターデータに付加する認証データを生成する認証部と、
削除条件を充足する場合、前記アバターデータから前記認証データを削除する認証削除部と、
を備えるアバターデータの認証装置。 - 端末装置から前記認証データを削除することを指示する削除要求を受け付ける受付部と、
前記端末装置から前記サービスユーザが本人確認をするための確認画像を取得する取得部と、
前記確認画像が、現在、前記端末装置の端末ユーザを撮像することにより得られた画像か否かを判定する画像判定部と、
前記確認画像に写り込む人物を前記ユーザ画像に写り込む人物と照合する照合部とをさらに備え、
前記削除条件は、前記画像判定部の判定結果が肯定であり、且つ、前記照合部の照合結果が肯定であることである、
請求項1に記載のアバターデータの認証装置。 - 端末装置から前記認証データを削除することを指示する削除要求を受け付ける第1受付部と、
前記ユーザが承認することなく強制的に前記認証データを削除することを指示する強制指示が、前記削除要求に含まれるか否かを判定する第1要求判定部と、
をさらに備え、
前記削除条件は、少なくとも前記第1要求判定部の判定結果が肯定であることである、
請求項1に記載のアバターデータの認証装置。 - 端末装置から前記認証データを生成することを指示する生成要求を受け付ける第2受付部と、
前記ユーザが承認することなく強制的に前記認証データを生成することを指示する強制指示が、前記生成要求に含まれるか否かを判定する第2要求判定部と、
をさらに備え、
前記認証部は、前記第2要求判定部の判定結果が肯定である場合、前記認証データを生成する、
請求項3に記載のアバターデータの認証装置。 - 前記ユーザ画像は、前記アバターデータの生成時に、確認画像と共に外部装置から取得され、
前記ユーザ画像は、前記確認画像と共に記憶装置に記憶され、
前記認証部は、前記確認画像が、前記外部装置のユーザを撮像することによって得られた画像であり、且つ、前記確認画像に写り込む人物と前記ユーザ画像に写り込む人物とが同一人物である場合に、前記アバターデータが真正であることを認証し、
前記記憶装置から読み出された前記確認画像が前記外部装置の使用者を撮像することによって得られた画像であるか否かを判定し、且つ、前記記憶装置から読み出された前記確認画像に写り込む人物と前記記憶装置から読み出された前記ユーザ画像に写り込む人物とが同一人物であるか否かを判定する基準判定部をさらに備え、
前記確認画像が前記外部装置の使用者を撮像することによって得られた画像であるか否かを判定する際に用いる第1判定基準と、前記確認画像に写り込む人物と前記ユーザ画像に写り込む人物とが同一人物であるか否かを判定する際に用いる第2判定基準とのうち、少なくとも一方は、前記認証部のアバターデータの認証時と前記基準判定部の判定時とにおいて相違し、
前記削除条件は、前記第1要求判定部による判定結果が肯定であり、且つ前記基準判定部による2つの判定結果のうち少なくとも1つが否定であることである、
請求項3に記載のアバターデータの認証装置。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2024531935A JP7776646B2 (ja) | 2022-07-05 | 2023-05-10 | 認証装置 |
| US18/878,778 US20250384114A1 (en) | 2022-07-05 | 2023-05-10 | Authentication apparatus |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2022108383 | 2022-07-05 | ||
| JP2022-108383 | 2022-07-05 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024009604A1 true WO2024009604A1 (ja) | 2024-01-11 |
Family
ID=89453024
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2023/017588 Ceased WO2024009604A1 (ja) | 2022-07-05 | 2023-05-10 | 認証装置 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20250384114A1 (ja) |
| JP (1) | JP7776646B2 (ja) |
| WO (1) | WO2024009604A1 (ja) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2007249317A (ja) * | 2006-03-14 | 2007-09-27 | Dotcity Inc | ドットシティにおける生体認証システムとその認証手段 |
| JP2007328590A (ja) * | 2006-06-08 | 2007-12-20 | Omron Corp | 情報処理装置および情報処理方法、監視システム、並びにプログラム |
| WO2023074022A1 (ja) * | 2021-10-29 | 2023-05-04 | 凸版印刷株式会社 | アバター管理システム、アバター管理方法、プログラム、及びコンピュータ読み取り可能な記録媒体 |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090254968A1 (en) * | 2008-04-03 | 2009-10-08 | International Business Machines Corporation | Method, system, and computer program product for virtual world access control management |
| AU2011205223C1 (en) * | 2011-08-09 | 2013-03-28 | Microsoft Technology Licensing, Llc | Physical interaction with virtual objects for DRM |
| US9967320B2 (en) * | 2014-12-18 | 2018-05-08 | Google Llc | Methods, systems, and media for controlling information used to present content on a public display device |
| JP2019009740A (ja) | 2017-06-28 | 2019-01-17 | 株式会社リコー | 廃棄管理システム、廃棄管理方法、印刷装置 |
| JP7563118B2 (ja) | 2020-10-30 | 2024-10-08 | 株式会社リコー | 情報処理装置、プログラム、画像処理システム |
-
2023
- 2023-05-10 JP JP2024531935A patent/JP7776646B2/ja active Active
- 2023-05-10 WO PCT/JP2023/017588 patent/WO2024009604A1/ja not_active Ceased
- 2023-05-10 US US18/878,778 patent/US20250384114A1/en active Pending
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2007249317A (ja) * | 2006-03-14 | 2007-09-27 | Dotcity Inc | ドットシティにおける生体認証システムとその認証手段 |
| JP2007328590A (ja) * | 2006-06-08 | 2007-12-20 | Omron Corp | 情報処理装置および情報処理方法、監視システム、並びにプログラム |
| WO2023074022A1 (ja) * | 2021-10-29 | 2023-05-04 | 凸版印刷株式会社 | アバター管理システム、アバター管理方法、プログラム、及びコンピュータ読み取り可能な記録媒体 |
Non-Patent Citations (1)
| Title |
|---|
| ANONYMOUS: "Development of "AVATECT" which is a management platform to prove the authenticity of avatars", 18 February 2022 (2022-02-18), XP093126979, Retrieved from the Internet <URL:https://www.toppan.co.jp/news/2022/02/sto3as0000006xhd-att/TOPPAN_220218_1.pdf> * |
Also Published As
| Publication number | Publication date |
|---|---|
| JPWO2024009604A1 (ja) | 2024-01-11 |
| US20250384114A1 (en) | 2025-12-18 |
| JP7776646B2 (ja) | 2025-11-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11551482B2 (en) | Facial recognition-based authentication | |
| CA2676845C (en) | Method and apparatus for network authentication of human interaction and user identity | |
| US10805501B2 (en) | Converting biometric data into two-dimensional images for use in authentication processes | |
| US11270544B2 (en) | Access control for access restricted domains using first and second biometric data | |
| CN110113535A (zh) | 终端信息溯源方法、装置、终端和介质 | |
| CN112699354B (zh) | 一种用户权限管理方法及终端设备 | |
| JP7776646B2 (ja) | 認証装置 | |
| CN107679411A (zh) | 一种移动终端隐私处理方法及移动终端 | |
| WO2024009603A1 (ja) | アバター生成装置及びアバター使用許可装置 | |
| CN118696316A (zh) | 用于确定用户的访问权限的方法、请求计算机设备、认证计算机设备以及认证系统 | |
| Zabidi et al. | A survey of user preferences on biometric authentication for smartphones | |
| US20250124727A1 (en) | Avatar generation apparatus | |
| JP2022182824A (ja) | 認証装置、認証方法、及び、プログラム | |
| CN117370996B (zh) | 一种授权方法以及相关装置 | |
| JP7851969B2 (ja) | 情報設定装置 | |
| US12511362B2 (en) | Multi-modal verification and authentication system and methods | |
| Nguyen et al. | Personalized Image-based User Authentication using Wearable Cameras | |
| CN116305255B (zh) | 数据查询方法、装置、设备以及存储介质 | |
| KR102750290B1 (ko) | 영상 데이터에 기반하여 사용자를 인증하는 장치 및 방법 | |
| JP2024024917A (ja) | アカウント管理装置 | |
| Gayathri et al. | Secure authentication mechanism for users using virtual reality | |
| JP2025056503A (ja) | イベント管理装置 | |
| JP2020088747A (ja) | 情報処理装置、情報処理システム、電子黒板装置、制御方法、およびプログラム | |
| CN108647636A (zh) | 身份鉴权方法、身份鉴权装置及电子设备 | |
| WO2022270114A1 (ja) | 情報機器又は通信機器の不正アクセス防止方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23835145 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18878778 Country of ref document: US |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024531935 Country of ref document: JP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23835145 Country of ref document: EP Kind code of ref document: A1 |
|
| WWP | Wipo information: published in national office |
Ref document number: 18878778 Country of ref document: US |