WO2024122002A1 - 端末、システム、端末の制御方法及び記憶媒体 - Google Patents
端末、システム、端末の制御方法及び記憶媒体 Download PDFInfo
- Publication number
- WO2024122002A1 WO2024122002A1 PCT/JP2022/045180 JP2022045180W WO2024122002A1 WO 2024122002 A1 WO2024122002 A1 WO 2024122002A1 JP 2022045180 W JP2022045180 W JP 2022045180W WO 2024122002 A1 WO2024122002 A1 WO 2024122002A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- user
- service
- information
- terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
Definitions
- the present invention relates to a terminal, a system, a terminal control method, and a storage medium.
- Patent Document 1 states that a server device is provided that improves the convenience of an authentication system that includes multiple authentication terminals.
- the server device of Patent Document 1 includes an acquisition unit and an authentication unit.
- the acquisition unit acquires authentication rules that include conditions for determining whether authentication is successful.
- the authentication unit performs a first biometric authentication in response to a first authentication request sent from a first terminal, and performs a second biometric authentication using the authentication rule in response to a second authentication request sent from a second terminal.
- Patent Document 2 describes how the device allows multiple service operators to use a biometric authentication terminal while minimizing the time that an authentication terminal is occupied by one user.
- the authentication device in Patent Document 2 comprises an authentication table, a reception means, an authentication means, and a notification means.
- the authentication table manages each user's identification information and personal information including contact information for the user terminal owned by the user in association with each other.
- the reception means receives user identification information and authentication information from the user.
- the authentication means compares the authentication information input by the user with reference authentication information that serves as the basis for authentication, and performs identity authentication based on the comparison result.
- the notification means references the authentication table and notifies the user terminal corresponding to the user of the identity authentication result.
- Patent Documents 1 and 2 do not disclose an authentication system that allows a user to select a service provider from among multiple service providers.
- the main objective of the present invention is to provide a terminal, a system, a terminal control method, and a storage medium that contribute to realizing management of authentication history at a service provider selected by a user.
- a terminal includes: a receiving means for receiving a notification of successful authentication from a service server of a service provider selected by a user from among a plurality of service providers, the service provider having succeeded in biometric authentication of the user; and an authentication history control means for controlling the history of successful biometric authentication at the service provider in response to receiving the notification of successful authentication.
- a system including a service server of a service provider selected by a user from among a plurality of service providers that has succeeded in biometric authentication of the user, and a terminal carried by the user, the terminal including a receiving means for receiving a notification of successful authentication from the service server, and an authentication history control means for controlling the history of successful biometric authentication at the service provider in response to receiving the notification of successful authentication.
- a method for controlling a terminal in which a notification of successful authentication is received from a service server of a service provider selected by a user from among a plurality of service providers and which has succeeded in biometric authentication of the user, and in response to receiving the notification of successful authentication, control is performed regarding the history of successful biometric authentication at the service provider.
- a computer-readable storage medium stores a program for causing a computer mounted on a terminal to execute the following processes: receiving a notification of successful authentication from a service server of a service provider selected by a user from among a plurality of service providers and that has succeeded in biometric authentication of the user; and, in response to receiving the notification of successful authentication, controlling the history of successful biometric authentication at the service provider.
- a terminal, a system, a terminal control method, and a storage medium are provided that contribute to realizing management of authentication history at a service provider selected by a user.
- the effects of the present invention are not limited to the above.
- the present invention may achieve other effects instead of or in addition to the above effects.
- FIG. 1 is a diagram for explaining an overview of an embodiment.
- FIG. 2 is a flowchart illustrating an example of the operation of one embodiment.
- FIG. 3 is a diagram illustrating an example of a schematic configuration of an authentication system according to the first embodiment.
- FIG. 4 is a diagram for explaining the operation of the authentication system according to the first embodiment.
- FIG. 5 is a diagram for explaining the operation of the authentication system according to the first embodiment.
- FIG. 6 is a diagram for explaining the operation of the authentication system according to the first embodiment.
- FIG. 7 is a diagram for explaining the operation of the authentication system according to the first embodiment.
- FIG. 8 is a diagram illustrating an example of a processing configuration of the control server according to the first embodiment.
- FIG. 9 is a diagram illustrating an example of an account management database according to the first embodiment.
- FIG. 10 is a diagram illustrating an example of a display on the terminal according to the first embodiment.
- FIG. 11 is a diagram illustrating an example of a processing configuration of the service server according to the first embodiment.
- FIG. 12 is a diagram illustrating an example of a user management database according to the first embodiment.
- FIG. 13 is a flowchart illustrating an example of the operation of the authentication unit according to the first embodiment.
- FIG. 14 is a diagram illustrating an example of a processing configuration of the authentication terminal according to the first embodiment.
- FIG. 15 is a diagram illustrating an example of a processing configuration of a terminal according to the first embodiment.
- FIG. 16 is a diagram illustrating an example of a display on the terminal according to the first embodiment.
- FIG. 17 is a diagram illustrating an example of an authentication history management database according to the first embodiment.
- FIG. 18 is a diagram illustrating an example of a display on the terminal according to the first embodiment.
- FIG. 19 is a diagram illustrating an example of a display on the terminal according to the first embodiment.
- FIG. 20 is a diagram illustrating an example of a display on the terminal according to the first embodiment.
- FIG. 21 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment.
- FIG. 22 is a diagram illustrating an example of a hardware configuration of a control server according to the present disclosure.
- FIG. 23 is a diagram showing an example of a display of a terminal according to a modification of the present disclosure.
- FIG. 24 is a diagram showing an example of a display of a terminal according to a modification of the present disclosure.
- the terminal 100 includes a receiving means 101 and an authentication history control means 102 (see FIG. 1).
- the receiving means 101 is a service provider selected by a user from among a plurality of service providers, and receives an authentication success notification from a service server of the service provider that has succeeded in biometric authentication of the user (step S1 in FIG. 2).
- the authentication history control means 102 controls the history of successful biometric authentication at the service provider (step S2).
- the user selects from among a number of service providers from which the user wishes to receive services.
- the original authentication information used for biometric authentication is provided to the selected service provider.
- the service server of the service provider successfully authenticates the user using the authentication information, it transmits an authentication success notification to the terminal 100 notifying the terminal 100 of the fact and details of the successful authentication.
- the terminal 100 controls the biometric authentication history. For example, the terminal 100 allows the user to view the authentication history. In this way, the terminal 100 realizes management of the authentication history at the service provider selected by the user from among a number of service providers. By checking the authentication history, the user can discover unauthorized biometric authentication that he or she is not aware of.
- FIG. 3 is a diagram showing an example of a schematic configuration of an authentication system (information processing system) according to the first embodiment.
- the authentication system includes a plurality of service providers A to C and an authentication center.
- a service provider is a business entity that uses biometric authentication to provide services to users.
- the authentication system disclosed in this application is premised on service providers belonging to various business types and industries providing services using biometric authentication. Note that services provided by service providers may be either paid or free of charge.
- service providers include businesses that provide rental housing services such as condominiums, businesses where employees work (the user's workplace), businesses that provide events such as concerts, and businesses that operate means of transportation such as airplanes.
- Service providers disclosed in this application also include businesses that provide accommodation services, businesses such as retail stores, businesses that provide financial services, and educational businesses. Service providers are not limited to private businesses. Public institutions such as local governments may also be service providers.
- the authentication center will control and manage the biometric authentication of each of the multiple service providers. Businesses (service providers) that provide services using biometric authentication to users (general consumers) will need to enter into a contract with the authentication center.
- the authentication center includes a control server 10.
- the control server 10 performs the main functions of the authentication center.
- the control server 10 may be installed in the building of the authentication center, or may be a server installed on a network (cloud).
- biometric authentication is performed when a user arrives at the office or returns to their apartment, and only users (employees, residents) with the proper credentials can enter the office, etc.
- biometric authentication is performed when checking tickets at an event venue, checking in at a hotel, going through immigration procedures at an airport, etc.
- services are provided to users with the proper credentials.
- payment procedures at retail stores, etc. are performed using biometric authentication.
- each service provider has a service server 20 and at least one authentication terminal 30.
- the devices (service server 20, authentication terminal 30) of the service provider are connected so that they can communicate with each other.
- the service server 20 and the authentication terminal 30 are connected by a wired or wireless communication means.
- the service server 20 is connected to the control server 10 via a network.
- the service server 20 may be installed in the building of the service provider, or may be installed on the cloud.
- the service server 20 stores information required when providing services to users. Specifically, the service server 20 stores business information required when each service provider provides a service using biometric authentication, and information required for biometric authentication.
- the service server 20 uses a user management database to store business information and information required for biometric authentication. Details of the user management database will be described later.
- the service server 20 of the company where the user works stores information such as the user's (employee's) name, date of birth, employee number, department, place of work, etc. as business information.
- the service server 20 of an event company hosting an event stores information regarding tickets purchased by event participants as business information.
- the service server 20 of a retail store or the like stores credit card information (payment information) required for payment as business information.
- the authentication terminal 30 is a device that serves as an interface for users who receive services.
- the authentication terminal 30 is installed at the service providing location of each service provider. More specifically, the authentication terminal 30 is installed in a store or the like that the user actually visits.
- the authentication terminal 30 has functions and forms that correspond to the type of business of the service provider.
- an authentication terminal 30 installed in a workplace or event venue can be a gate device equipped with a gate that restricts the passage of users (persons to be authenticated).
- an authentication terminal 30 installed in a retail store can be a tablet-type terminal.
- the authentication center may include two or more control servers 10.
- at least one or more service providers may participate in the authentication system.
- each service provider may include at least one or more service servers 20 and at least one or more authentication terminals 30.
- a user who wishes to receive a service from a service provider needs to create an account in the system. Specifically, the user operates a terminal 40 owned by the user to access the control server 10 (see FIG. 4).
- the user inputs login information (e.g., login ID, password), name, date of birth, contact information, etc., on a WEB page provided by the control server 10.
- login information e.g., login ID, password
- name e.g., name
- date of birth e.g., birth
- contact information e.g., contact information
- control server 10 acquires the login information, etc., it generates an ID for identifying the user.
- the ID generated by the control server 10 is referred to as the "system ID.”
- the control server 10 associates the generated system ID with the login information, etc., and stores them in an account management database. Details of the account management database will be described later.
- Biometric information registration> A user who wishes to receive services using biometric authentication needs to register his/her own biometric information in the terminal 40 .
- biometric authentication it is necessary that authentication information generated from biometric information be registered in advance with the service provider.
- biometric information For example, when a service is provided using face authentication, it is necessary that feature amounts (feature vectors) generated from a face image be registered in advance as authentication information.
- feature amounts feature vectors
- fingerprint authentication it is necessary that feature amounts generated from a fingerprint image be registered in advance as authentication information.
- original (foundation) information used to generate authentication information such as a face image or fingerprint image
- original biometric information the features generated from the original biometric information and registered in advance
- registered authentication information the features generated from the original biometric information and registered in advance
- a user who has completed creating a system account must register the original biometric information (e.g., a facial image) on the terminal 40 that holds the information.
- the terminal 40 acquires the original biometric information using a GUI (Graphical User Interface) or the like.
- the terminal 40 stores the acquired original biometric information (e.g., a facial image) internally. In this way, the terminal 40 stores the original biometric information that serves as the original authentication information used for biometric authentication.
- ⁇ Select a service> A user who has registered in the system (created a system account) and registered their original biometric information selects a service provider from which they would like to receive biometric authentication services. The user selects a service provider from which they would like to receive services from among multiple service providers participating in the authentication system (service providers under contract with the authentication center).
- the control server 10 stores information about the service providers participating in the authentication system. For example, the control server 10 stores the name, industry, location, etc. of the service provider. The control server 10 holds information about each of multiple service providers and allows the user to select a service provider.
- the control server 10 When a user operates the terminal 40 to perform a specified operation on the portal site, the control server 10 displays a GUI or the like on the terminal 40 that enables the user to select a desired service (service provider). The control server 10 uses the GUI to obtain the service (biometric authentication service) desired by the user.
- service biometric authentication service
- control server 10 acquires the service provider selected by the user, the control server 10 executes control related to "user registration" that enables the selected service provider to provide the user with a service using biometric authentication.
- control server 10 controls the above-mentioned selected service provider to acquire the original biometric information stored in the user's terminal 40.
- the service provider generates registered authentication information from the acquired original biometric information, and associates the generated registered authentication information with business information, thereby becoming ready to provide the service to the user.
- the user operates the terminal 40 to access the control server 10 and logs in to the user's portal site.
- the control server 10 displays a GUI including a list of service providers on the terminal 40.
- control server 10 requests the user to provide the original biometric information. Specifically, the control server 10 sends an "original provision request" to the user's terminal 40 (see step S01 in FIG. 5).
- the terminal 40 transmits the user's original biometric information (e.g., a facial image) to the control server 10 (step S02).
- the user's original biometric information e.g., a facial image
- the control server 10 notifies the service provider selected by the user of the user's system ID, the acquired original biometric information, personal identification information, etc.
- the personal identification information is information for identifying the user. Examples of personal identification information include the user's name, or a combination of the user's name and date of birth.
- the control server 10 sends a "user registration request" including the system ID, the original biometric information, and the personal identification information to the service server 20 of the service provider selected by the user (step S03).
- the service server 20 When the service server 20 receives the user registration request, it searches the user management database using the acquired personal identification information to identify the user who wishes to register (to receive services using biometric authentication). The service server 20 stores the system ID and registration authentication information (e.g., features) obtained from the original biometric information in the entry for the identified user.
- system ID and registration authentication information e.g., features
- the service server 20 sends a response including the result of the user registration (user registration successful or unsuccessful) to the control server 10 (step S04).
- the control server 10 deletes the original biometric information (e.g., face image) acquired from the user when the control server 10 transmits a user registration request to the service server 20 or when the control server 10 receives a response to the request.
- the service server 20 generates registration authentication information (e.g., feature amount), it deletes the original biometric information acquired from the control server 10.
- the user visits the service provider to receive the service.
- the service provider For example, the user visits the facility or store of the service provider, such as an office, an amusement park, an event venue, or a retail store, where the user receives the service selected by the user.
- the authentication terminal 30 acquires biometric information of the user (person to be authenticated) receiving the service. For example, the authentication terminal 30 photographs the person to be authenticated and acquires biometric information (e.g., a facial image) corresponding to the original biometric information.
- the authentication terminal 30 transmits an authentication request including the acquired facial image to the service server 20 (see FIG. 6). If necessary, the authentication terminal 30 transmits other information (e.g., the name of the purchased product, the price of the purchased product, etc.) along with the biometric information to the service server 20.
- the authentication terminal 30 may transmit information used in the authentication process (e.g., credit card information) along with the biometric information (information for identifying an individual, ID) to the service server 20.
- the service server 20 generates authentication information for matching from the acquired face image. For example, the service server 20 generates features from the face image for matching.
- the service server 20 executes a matching process (1:N matching; N is a positive integer, the same below) using the generated authentication information for matching (hereinafter referred to as matching authentication information) and the registered authentication information registered in the user management database.
- the service server 20 identifies the user (person to be authenticated) registered in the user management database through a matching process.
- the service server 20 authenticates the identified user using the business information of that user. For example, the service server 20 of the employee's employer will determine that the authentication has been successful if the person to be authenticated is an employee of that company and is qualified to enter the office. Alternatively, a service server 20 installed at an event venue will determine that the authentication has been successful if the ticket purchased by the person to be authenticated is valid. Alternatively, a service server 20 installed at a retail store will determine that the authentication has been successful if the payment for the goods etc. purchased by the person to be authenticated is successful.
- the first service provider is a service provider that continues to hold the registered authentication information (feature amounts), etc., even if authentication of the authenticated person is successful.
- the user's employer or an apartment management company are examples of first service providers. These service providers do not delete the registered authentication information, etc. stored in the user management database, even if authentication of the user (entrance and exit to an office, apartment, etc.) is successful.
- a retailer that offers a service related to facial payment for product prices using pre-registered credit card information, etc. is also an example of a first service provider. The retailer continues to store the credit card information and the registered authentication information in association with each other.
- the second service provider is, in principle, a service provider that deletes the registered authentication information (feature amounts) etc. when authentication of the authenticated person is successful.
- an event company that holds an event is an example of a second service provider.
- the event company successfully authenticates the user (when the user enters the event venue using the purchased ticket), it deletes the registered authentication information stored in the user management database.
- the same service provider may continue to store the registered authentication information or delete it depending on the content of the service provided to the user.
- a business that operates an amusement park or the like sells tickets that are limited to use for one day. In this case, the business becomes a second service provider. If the above business also sells tickets (e.g., annual tickets) that allow admission to the amusement park or the like for a specified period of time, it becomes a first service provider. In this case, the business continues to hold the registered authentication information until the annual ticket expires.
- tickets e.g., annual tickets
- the service server 20 sends the authentication result (authentication successful, authentication failed) to the authentication terminal 30.
- the authentication terminal 30 executes processing according to the authentication result. For example, when successful authentication is received, an authentication terminal 30 installed in an office opens the gate and allows the authenticated person to pass through. Alternatively, when successful authentication is received, an authentication terminal 30 installed at an event venue allows the authenticated person to pass through the gate. Alternatively, when successful authentication is received, an authentication terminal 30 installed at a retail store notifies the authenticated person that payment for the product has been completed.
- the service server 20 notifies the user of that fact.
- the service server 20 notifies the terminal 40 carried by the user of details of the authentication result via the control server 10.
- the service server 20 transmits an authentication success notification to the control server 10, which includes the system ID of the person who has been successfully authenticated (the person who has been determined to have been successfully authenticated), detailed information on the authentication process, and the state of the authentication information (see FIG. 7).
- Detailed information about the authentication process may include, for example, the date and time of authentication, the location of authentication, and details of the service provided (e.g., the name of the product purchased, the amount paid, etc.).
- the service server 20 at the workplace of the person to be authenticated generates the date and time of the successful authentication person's arrival at work and the name of the office as details of the services provided.
- the service server 20 at a retail store generates the date and time of the successful authentication person's visit to the store, the store, the purchased item, the amount paid, etc. as details of the services provided.
- the authentication information status is set to the status (retained, deleted) of the registered authentication information (features) of the successfully authenticated user after the authentication process.
- the service server 20 of a first service provider such as the authenticatee's workplace, sets the authentication information status to "authentication information retained.”
- the service server 20 of a second service provider such as an event company, sets the authentication information status to "authentication information deleted.”
- the control server 10 receives the authentication success notification.
- the control server 10 searches the account management database using the system ID included in the authentication success notification as a key, and identifies the corresponding entry (user).
- the control server 10 transmits (transfers) the authentication success notification received from the service server 20 to the terminal 40 of the identified user.
- the terminal 40 generates an authentication history based on the received authentication success notification. Furthermore, each time the terminal 40 receives an authentication success notification, it notifies the user that the notification has been received. For example, the terminal 40 displays the contents included in the authentication success notification (details of the authentication process, status of the authentication information) by means of a pop-up or the like.
- the terminal 40 displays the authentication history. By checking the authentication history, the user can check whether there has been any unauthorized use, etc.
- the service server 20 may transmit the successful authentication notification to the terminal 40 via the control server 10, or may transmit the successful authentication notification to the terminal 40 directly without going through the control server 10.
- the service server 20 may obtain the user's contact information (such as an email address that the terminal 40 can receive) when obtaining business information.
- FIG. 8 is a diagram showing an example of a processing configuration (processing module) of the control server 10 according to the first embodiment.
- the control server 10 includes a communication control unit 201, an account management unit 202, a business operator management unit 203, a service selection control unit 204, a user registration control unit 205, and a storage unit 206.
- the communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the service server 20. The communication control unit 201 also transmits data to the service server 20. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 201.
- the communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
- the account management unit 202 is a means for managing a user's account. When a user operates the terminal 40 to access a specific homepage or the like, the account management unit 202 obtains the information necessary to create an account for that user.
- the account management unit 202 acquires personal information such as login information, name, date of birth, and contact information (e.g., an email address that the terminal 40 can receive). Upon acquiring the login information, the account management unit 202 generates a system ID for identifying the user.
- the system ID may be any information that can uniquely identify the user. For example, the account management unit 202 may assign a unique value each time an account is created, and use this as the system ID.
- the account management unit 202 associates the generated system ID, login information, name, etc., and stores them in the account management database (see FIG. 9).
- the account management database shown in FIG. 9 is an example, and is not intended to limit the items to be stored.
- the account generation date and time, etc. may also be stored in the account management database.
- the account management unit 202 also acquires login information for logging in to the portal site from the user's terminal 40.
- the account management unit 202 performs authentication using the login information.
- the business management unit 203 is a means for managing the service providers (service businesses) participating in the authentication system.
- the business management unit 203 obtains business information (service provider name, business type, location, address of service server 20, etc.) to be registered in the system from employees of each service provider.
- the business management unit 203 may provide each service provider with an interface for inputting business information, etc.
- each service provider may send a USB (Universal Serial Bus) memory or the like on which the business information, etc. is stored to the authentication center.
- the business management unit 203 may obtain the business information, etc. from staff, etc. at the authentication center.
- the business management unit 203 generates an ID (business ID) for the service provider that has acquired the business information, etc.
- the business management unit 203 stores the generated business ID in association with the acquired business information, etc.
- the service selection control unit 204 is a means for controlling the selection of a biometric authentication service (service provider) by the user.
- the service selection control unit 204 enables the user to select the service provider from which the user wishes to receive services from among multiple service providers that offer services using biometric authentication.
- the service selection control unit 204 displays, for example, a GUI such as that shown in FIG. 10 on the terminal 40.
- the service selection control unit 204 displays the service provider in a way that allows the user to distinguish between a service provider that has already been selected and a service provider that has not been selected.
- a service provider with a check mark in the upper right corner of the icon indicating the service business indicates a service provider that has already been selected, and a service provider with no check mark indicates an unselected service provider.
- the service selection control unit 204 uses the business information and information registered in the account management database to display a GUI such as that shown in FIG. 10. Specifically, the service selection control unit 204 references the business information and generates a list of service providers that have concluded contracts with the authentication center. The service selection control unit 204 also references the selected service field in the account management database to obtain the service provider (the business ID of the service provider) that has been selected by the user.
- the service selection control unit 204 may also provide the user with more detailed information about each service provider (e.g., the type of business, services offered, store location, etc.).
- the service selection control unit 204 passes information about the service provider selected by the user (e.g., the business ID of the service provider for which the user wishes to register) to the user registration control unit 205.
- the user registration control unit 205 is a means for controlling "user registration” by the control server 10.
- the user registration control unit 205 controls "user registration” that enables a service provider selected by a user to provide the user with a service using biometric authentication.
- the user registration control unit 205 When the user selects a service provider, the user registration control unit 205 sends an "original provision request" to the terminal 40 held by the user.
- the user registration control unit 205 receives the user's original biometric information (e.g., a facial image) from the terminal 40.
- the user registration control unit 205 sends a user registration request, including the user's system ID, original biometric information, and personal identification information, to the service server 20 of the service provider that corresponds to the service selected by the user.
- the user registration control unit 205 also obtains the system ID and personal identification information (e.g., name or a combination of name and date of birth) from the account management database.
- system ID and personal identification information e.g., name or a combination of name and date of birth
- the user registration control unit 205 receives a response (positive response, negative response) to the user registration request.
- the user registration control unit 205 registers the business ID of the service provider selected by the user in the account management database. Also, if a positive response is received, the user registration control unit 205 notifies the user that user registration for the selected service provider was successful.
- the user registration control unit 205 If a negative response (user registration failed) is received, the user registration control unit 205 notifies the user accordingly.
- the memory unit 206 is a means for storing information necessary for the operation of the control server 10.
- FIG. 11 is a diagram showing an example of a processing configuration (processing module) of the service server 20 according to the first embodiment.
- the service server 20 includes a communication control unit 301, a business information management unit 302, a user registration control unit 303, an authentication unit 304, and a storage unit 305.
- the communication control unit 301 is a means for controlling communication with other devices.
- the communication control unit 301 receives data (packets) from the control server 10.
- the communication control unit 301 also transmits data to the control server 10.
- the communication control unit 301 passes data received from other devices to other processing modules.
- the communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 301.
- the communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
- the business information management unit 302 is a means for the service provider to manage and control business information required for providing services.
- the business information management unit 302 uses any means to acquire business information necessary for the provision of services by its own company or organization.
- the business information management unit 302 of the user's employer company acquires information such as the employee's name, date of birth, employee number, department, and place of work as business information.
- the business information management unit 302 may obtain the business information from staff of the service provider, etc., or may obtain the business information directly from the user using a website or other means.
- the business information management unit 302 manages business information using a user management database.
- business information management unit 302 A more detailed description of the business information management unit 302 will be omitted because the details of the business information for each service and the method of acquiring the information are different from the purpose of this disclosure.
- the user registration control unit 303 is a means for controlling user registration by the service provider.
- the user registration control unit 303 processes user registration requests received from the control server 10.
- the user registration control unit 303 searches the user management database using the personal identification information (e.g., name) included in the user registration request as a key to identify the corresponding user (entry).
- personal identification information e.g., name
- the user registration control unit 303 If the corresponding user is registered in the user management database, the user registration control unit 303 generates registration authentication information from the acquired original biometric information (e.g., a facial image). For example, when a facial image is acquired, the user registration control unit 303 generates a feature amount (feature vector) corresponding to the facial recognition algorithm adopted by the company as the registration authentication information.
- the acquired original biometric information e.g., a facial image
- feature vector feature vector
- the user registration control unit 303 extracts the eyes, nose, mouth, etc. from the face image as feature points. The user registration control unit 303 then calculates the position of each feature point and the distance between each feature point as feature amounts, and generates a feature vector (vector information that characterizes the face image) consisting of multiple feature amounts.
- the user registration control unit 303 associates the system ID, the generated registration authentication information (features), and the business information and stores them in the user management database (see FIG. 12).
- the user management database shown in FIG. 12 is an example and is not intended to limit the items to be stored.
- the date and time of user registration may be registered in the user management database.
- the user registration control unit 303 When user registration is completed normally, the user registration control unit 303 sends an affirmative response to the control server 10 indicating that user registration was successful.
- the user registration control unit 303 generates registration authentication information (e.g., feature amounts), registers the generated registration authentication information in the user management database, and then deletes the original biometric information obtained from the control server 10.
- registration authentication information e.g., feature amounts
- the user registration control unit 303 sends a negative response to the control server 10 indicating that user registration has failed. For example, a negative response is sent to the control server 10 when the personal identification information (e.g., name) received from the control server 10 is not registered in the user management database or when valid registration authentication information cannot be generated from the original biometric information.
- personal identification information e.g., name
- the authentication unit 304 is a means for performing biometric authentication of the person to be authenticated.
- FIG. 13 is a flowchart showing an example of the operation of the authentication unit 304 according to the first embodiment. The operation of the authentication unit 304 will be described with reference to FIG. 13.
- the authentication unit 304 executes a matching process using biometric information (step S101).
- the authentication unit 304 generates matching authentication information from the biometric information included in the authentication request. For example, when a facial image is acquired, the authentication unit 304 generates features corresponding to the facial recognition algorithm adopted by the company. The authentication unit 304 executes a matching process using the generated matching authentication information (feature) and the registered authentication information (feature) registered in the user management database.
- the authentication unit 304 calculates the similarity between the feature amount (feature vector) to be matched and each of the multiple feature amounts on the registration side.
- the similarity can be calculated using chi-square distance, Euclidean distance, or the like. Note that the greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
- the authentication unit 304 determines that the matching process has failed. If there is a feature with a similarity equal to or greater than a predetermined value, the authentication unit 304 determines that the matching process has been successful. If the matching process is successful, the user of the entry with the most similar feature (registered authentication information) among multiple entries registered in the user management database is identified as the person to be authenticated.
- the authentication unit 304 ends the process. In this case, the authentication unit 304 may notify the authentication terminal 30 that the authentication has failed. Alternatively, the authentication unit 304 may store the fact that the matching process has failed and details of the matching process as a log in order to check the soundness of the face authentication.
- the authentication unit 304 uses the business information of the person identified by the matching process to determine whether or not it is possible to provide the service to the person.
- the authentication unit 304 determines whether or not it is possible to provide the service based on the business information (step S103).
- the authentication unit 304 of the service server 20 of the employee's employer company will determine that the service can be provided if the person to be authenticated is an employee of that company and is qualified to enter the office.
- the service server 20 of an event company will determine that the service can be provided if the ticket purchased by the person to be authenticated is valid.
- the authentication unit 304 of the service server 20 of a retail store or the like will determine that the service can be provided if payment for the product price is successfully made using credit card information or the like.
- step S104 If the service cannot be provided (step S104, No branch), the authentication unit 304 sets the authentication result to "authentication failed" (step S105).
- step S104 If the service can be provided (step S104, Yes branch), the authentication unit 304 sets the authentication result to "authentication successful" (step S106).
- the authentication unit 304 transmits the authentication result (authentication successful, authentication failed) to the authentication terminal 30 (step S107).
- the authentication unit 304 sends a negative response to that effect to the authentication terminal 30.
- the authentication unit 304 sends an affirmative response indicating that to the authentication terminal 30. At that time, the authentication unit 304 sends an affirmative response including information necessary to provide the service to the user to the authentication terminal 30 as necessary. In the above example of issuing a resident's certificate, the information necessary to issue (print) the resident's certificate is sent to the authentication terminal 30.
- the authentication unit 304 updates the user management database as necessary (update database; step S108). More specifically, the authentication unit 304 deletes at least the registered authentication information of the person who was successfully authenticated, depending on the contents of the authentication process.
- the authentication unit 304 does not perform any special processing (does not delete registered authentication information) in the case of authentication processing related to the entry and exit of the person to be authenticated (coming to work at the office, returning to the apartment, etc.). Or, the authentication unit 304 does not perform any special processing when the person to be authenticated uses credit card information to pay for a product that he or she has purchased.
- the authentication unit 304 sets the state of the authentication information to "authentication information retained.”
- the authentication unit 304 deletes the registered authentication information of that authenticated person (deletes the corresponding entry in the user management database). In this case, the authentication unit 304 sets the status of the authentication information to "authentication information deleted.”
- Whether or not to delete the registered authentication information is determined in advance depending on the service provided to the user.
- the decision to delete the registered authentication information may be made based on information included in the business information. For example, if the ticket purchased by the user is a ticket that can be used repeatedly, such as an "annual passport," the authentication unit 304 will not delete the registered authentication information.
- the authentication unit 304 sends a notification of successful authentication to the control server 10 (step S109).
- the authentication unit 304 sends an authentication success notification to the control server 10, which includes the system ID of the person to be authenticated (the user identified by the matching process), detailed information about the authentication process, and the status of the authentication information.
- the authentication unit 304 obtains the above system ID from the entry identified by the matching process (the entry in the user management database).
- the authentication unit 304 generates an authentication date and time from the date and time when the authentication request received from the authentication terminal 30 was processed, and generates an authentication location from the installation location of the authentication terminal 30.
- the authentication unit 304 also generates details of the provided service from the contents of the authentication process using the business information.
- the memory unit 305 is a means for storing information necessary for the operation of the service server 20.
- FIG. 14 is a diagram showing an example of a processing configuration (processing module) of the authentication terminal 30 according to the first embodiment.
- the authentication terminal 30 includes a communication control unit 401, a provided service control unit 402, an authentication request unit 403, and a storage unit 404.
- the communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the service server 20. The communication control unit 401 also transmits data to the service server 20. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data with other devices via the communication control unit 401.
- the communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
- the provided service control unit 402 is a means for executing control related to the services provided to the user.
- the provided service control unit 402 realizes the functions assigned to the authentication terminal 30.
- the provided service control unit 402 acquires biometric information (e.g., a facial image) of the user (person to be authenticated). For example, the provided service control unit 402 captures an image of the area in front of the device periodically or at a specified timing. The provided service control unit 402 determines whether the acquired image contains a human facial image, and if a facial image is included, extracts the facial image from the acquired image data.
- biometric information e.g., a facial image
- the provided service control unit 402 captures an image of the area in front of the device periodically or at a specified timing.
- the provided service control unit 402 determines whether the acquired image contains a human facial image, and if a facial image is included, extracts the facial image from the acquired image data.
- the facial image detection process and facial image extraction process performed by the provided service control unit 402 can use existing technology, so a detailed explanation will be omitted.
- the provided service control unit 402 may extract facial images (facial areas) from image data using a learning model trained by a CNN (Convolutional Neural Network).
- the provided service control unit 402 may extract facial images using a method such as template matching.
- the service provision control unit 402 passes the acquired biometric information (e.g., a facial image) to the authentication request unit 403.
- acquired biometric information e.g., a facial image
- the authentication request unit 403 is a means for requesting authentication of the person to be authenticated from the service server 20. When authentication of the person to be authenticated becomes necessary, the authentication request unit 403 transmits an authentication request including biometric information of the person to be authenticated (the user in front of the authentication terminal 30) to the service server 20.
- the authentication request unit 403 receives the authentication result (authentication successful, authentication failed) from the service server 20.
- the authentication request unit 403 passes the received authentication result to the service provided control unit 402.
- the provided service control unit 402 of the authentication terminal 30 installed at the user's workplace receives a successful authentication, it opens the gate and allows the authenticated person to enter.
- the provided service control unit 402 may output a predetermined message, etc.
- the memory unit 404 is a means for storing information necessary for the operation of the authentication terminal 30.
- FIG. 15 is a diagram showing an example of a processing configuration (processing module) of the terminal 40 according to the first embodiment.
- the terminal 40 includes a communication control unit 501, an account creation control unit 502, an original information acquisition unit 503, a service selection unit 504, an authentication history control unit 505, and a storage unit 506.
- the communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the control server 10. The communication control unit 501 also transmits data to the control server 10. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, the other processing modules transmit and receive data to and from other devices via the communication control unit 501.
- the communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
- the communication control unit 501 transmits the original biometric information stored in the storage unit 506 to the service server 20 of the service provider selected by the user via the control server 10.
- the communication control unit 501 also receives a notification of successful authentication directly or indirectly from the service server 20 of the service provider selected by the user from among the multiple service providers and that has succeeded in the biometric authentication of the user.
- the account creation control unit 502 is a means for controlling the creation of an account by a user.
- the account creation control unit 502 accesses a specific web page or the like provided by the control server 10 in response to a user's operation.
- the account creation control unit 502 inputs login information, name, date of birth, contact information, etc. into the web page in response to user operations.
- the original information acquisition unit 503 is a means for acquiring the biometric information of the user (original biometric information).
- the original information acquisition unit 503 displays a GUI or the like for acquiring the original biometric information (e.g., a facial image) in response to the user's operation.
- the original information acquisition unit 503 acquires the original biometric information using a GUI such as that shown in FIG. 16.
- the original information acquisition unit 503 stores the acquired original biometric information (e.g., a facial image) in the storage unit 506. At that time, the original information acquisition unit 503 may encrypt, code, etc. the acquired original biometric information and store the encrypted original biometric information in the storage unit 506. That is, the terminal 40 held by the user may hold the encrypted original biometric information.
- the encrypted original biometric information may be decrypted when the original biometric information is transmitted to the control server 10.
- information for decrypting the encrypted original biometric information e.g., a common key
- the control server 10 may decrypt the encrypted original biometric information.
- the terminal 40 does not delete the original biometric information (e.g., a facial image) of the user. In other words, the terminal 40 does not delete the original biometric information stored in the storage unit 506 unless there is a clear instruction from the user.
- the original biometric information e.g., a facial image
- the service selection unit 504 is a means for enabling the user to select a biometric authentication service.
- the service selection unit 504 logs in to a portal site provided by the control server 10 in response to the user's operation.
- the service selection unit 504 transmits to the control server 10 information on the service provider selected by the user using a GUI provided by the control server 10.
- the service selection unit 504 receives a request to provide the original from the control server 10. Upon receiving the request, the service selection unit 504 transmits the original biometric information stored in the storage unit 506 to the control server 10. The original biometric information is transmitted via the control server 10 to the service server 20 of the service provider selected by the user.
- the authentication history control unit 505 is a means for executing control regarding the authentication history of the user.
- the authentication history control unit 505 processes the authentication success notification received from the control server 10. In response to receiving the authentication success notification, the authentication history control unit 505 performs control regarding the history of successful biometric authentication at the service provider.
- the authentication success notification includes detailed information about the successful authentication process performed by the service provider and the status of the authentication information used by the service provider for biometric authentication.
- the authentication history control unit 505 stores the detailed information of the authentication process and the state of the authentication information included in the authentication success notification in the authentication history management database (see FIG. 17).
- the authentication history control unit 505 generates a history of the user's biometric authentication by storing the detailed information of the authentication process and the state of the authentication information in the authentication history management database.
- the authentication history management database shown in FIG. 17 is an example, and is not intended to limit the items to be stored.
- the authentication history control unit 505 upon receiving a successful authentication notification, notifies the user (the owner of the terminal 40) that authentication of the user has been performed. For example, each time the authentication history control unit 505 receives a successful authentication notification, it displays information related to the user's authentication using a pop-up notification as shown in FIG. 18. That is, each time the authentication history control unit 505 receives a successful authentication notification, it displays a message including detailed information about the authentication process and the status of the authentication information.
- the authentication history control unit 505 displays a list of the authentication history stored in the authentication history management database (see FIG. 19). That is, the authentication history control unit 505 displays the history related to biometric authentication stored in the authentication history management database in response to a predetermined operation by the user.
- the authentication history control unit 505 may display detailed information about the authentication process as shown in FIG. 19, or may display the state of the authentication information in addition to the detailed information about the authentication process as shown in FIG. 20.
- the storage unit 506 is a means for storing information necessary for the operation of the terminal 40.
- the storage unit 506 stores original biometric information that is the original of the authentication information used for biometric authentication.
- the original biometric information is a facial image
- the authentication information is a feature amount generated from the facial image.
- FIG. 21 is a sequence diagram showing an example of the operation of the authentication system according to the first embodiment.
- the service server 20 executes the authentication process (step S21).
- the service server 20 sends an authentication success notification to the control server 10 (step S22).
- the control server 10 transfers the successful authentication notification to the terminal 40 of the person who was successfully authenticated (step S23).
- the terminal 40 notifies the user that the authentication process has been performed (the fact that authentication was successful and the details thereof) (notifying the user of the fact of authentication; step S24).
- a user may select a service provider using a predetermined code.
- a management code may be used that allows a user to easily specify a service selector from among many service providers.
- the control server 10 displays a GUI that requests input of a management code.
- the control server 10 treats the service provider corresponding to the management code input by the user as the service provider selected by the user.
- control server 10 may treat the management code entered by the user like a password. Specifically, when the user selects a service provider, the control server 10 prompts the user to enter the management code of the selected service provider. If the management code entered by the user matches the predetermined management code of the selected service provider, the control server 10 may accept the user's selection of a service provider. In other words, the control server 10 rejects the user's selection of a service provider if the two management codes do not match.
- the service provider (service server 20) identifies the user by using personal identification information when registering the user.
- the user may be selected by using an ID (hereinafter, referred to as an individual ID) by which the service provider manages the user (customer).
- the control server 10 transmits a redirect URL (Uniform Resource Locator) with the user's system ID embedded therein to the terminal 40.
- the redirect URL is a URL for logging in to the portal site (account) of the service provider selected by the user.
- the service server 20 obtains the individual ID (login ID) of the user and the system ID embedded in the redirect URL.
- the service server 20 searches the user management database using the acquired individual ID and identifies the corresponding entry (user).
- the service server 20 stores the system ID in the identified entry.
- a redirect URL with an embedded system ID may be used to achieve user registration.
- the original biometric information stored in the user's terminal 40 is provided to the service server 20 of the service provider selected by the user.
- the service server 20 generates registered authentication information from the user's original biometric information and stores the generated registered authentication information in association with business information, thereby enabling the provision of a service using biometric authentication to the user.
- the service server 20 transmits an authentication success notification to the user's terminal 40 via the control server 10.
- the terminal 40 displays a pop-up notification of the fact that biometric authentication has been performed by the service provider, or displays a list of past authentication results.
- the user can verify whether or not unauthorized biometric authentication has been performed by the pop-up notification or the list display of the authentication history. In other words, the user can discover unauthorized biometric authentication by the pop-up notification or the list display of the authentication history.
- Figure 22 is a diagram showing an example of the hardware configuration of the control server 10.
- the control server 10 can be configured by an information processing device (so-called a computer), and has the configuration shown in FIG. 22.
- the control server 10 has a processor 311, a memory 312, an input/output interface 313, and a communication interface 314.
- the components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
- control server 10 may include hardware not shown, and may not include an input/output interface 313 as necessary.
- number of processors 311 and the like included in the control server 10 is not intended to be limited to the example shown in FIG. 22, and for example, the control server 10 may include multiple processors 311.
- the processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or a DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs including an operating system (OS).
- OS operating system
- Memory 312 may be a RAM (Random Access Memory), a ROM (Read Only Memory), a HDD (Hard Disk Drive), a SSD (Solid State Drive), etc. Memory 312 stores the OS program, application programs, and various data.
- RAM Random Access Memory
- ROM Read Only Memory
- HDD Hard Disk Drive
- SSD Solid State Drive
- the input/output interface 313 is an interface for a display device and an input device (not shown).
- the display device is, for example, a liquid crystal display.
- the input device is, for example, a device that accepts user operations such as a keyboard or a mouse.
- the communication interface 314 is a circuit, module, etc. that communicates with other devices.
- the communication interface 314 includes a NIC (Network Interface Card), etc.
- the functions of the control server 10 are realized by various processing modules.
- the processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312.
- the program can be recorded on a computer-readable storage medium.
- the storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium.
- the present invention can also be embodied as a computer program product.
- the program can be downloaded via a network, or updated using a storage medium that stores the program.
- the processing modules may also be realized by a semiconductor chip.
- the service server 20, authentication terminal 30, terminal 40, etc. can also be configured using information processing devices, just like the control server 10, and their basic hardware configurations are no different from those of the control server 10, so a description of them will be omitted.
- the authentication terminal 30 may be equipped with a camera device for photographing the person to be authenticated.
- the control server 10 which is an information processing device, is equipped with a computer, and the functions of the control server 10 can be realized by having the computer execute a program.
- the control server 10 also executes the control method of the control server 10 by the program.
- the terminal 40 which is an information processing device, is equipped with a computer, and the functions of the terminal 40 can be realized by having the computer execute a program.
- the terminal 40 also executes the control method of the terminal 40 by the program.
- the control server 10 and the terminal 40 allow the user to identify the information of the opted-in service provider by checking the icon of the service provider, as shown in FIG. 10.
- the control server 10 and the terminal 40 may allow the user to opt-out, that is, delete registered authentication information from the opted-in service provider.
- the control server 10 transmits a user deregistration request including the user's system ID to the service server 20 of the selected service provider.
- the service server 20 deletes the user's registered authentication information, etc., corresponding to the system ID.
- the service server 20 may notify the authenticatee (the authenticatee identified by the matching process) of the failure.
- the authentication unit 304 may also notify the authenticatee of the reason for the authentication failure. For example, the authentication unit 304 may notify the authenticatee of reasons such as "no authority to enter the office", "failed to pay by credit card", "ticket is invalid", etc.
- the authentication unit 304 transmits an authentication failure notification including the system ID of the authenticatee and the reason for the authentication failure to the control server 10.
- the control server 10 identifies the terminal 40 of the authenticatee using the system ID and transmits an authentication failure notification to the identified terminal 40.
- the terminal 40 Upon receiving the authentication failure notification, the terminal 40 notifies the user of the reason for the authentication failure. For example, the terminal 40 notifies the user of the reason for the authentication failure by a pop-up notification as shown in FIG. 23. Alternatively, the terminal 40 may generate an authentication history using the authentication failure notification. In this case, the terminal 40 may display the cause of authentication failure in response to a user operation, as shown in FIG. 24.
- the operation of the authentication system has been described using a person's "face" as an example of biometric information.
- the authentication system disclosed in this application can also use other types of biometric information.
- data comprising physical characteristics unique to an individual, such as a fingerprint, voiceprint, veins, retina, or iris pattern, may be used.
- the user's biometric information may be anything that includes the user's physical characteristics as information.
- the user's terminal 40 may obtain consent from the user to send the original biometric information (e.g., a facial image) to the service provider each time it receives a request to provide the original from the control server 10. Specifically, when it receives a request to provide the original, the service selection unit 504 of the terminal 40 obtains whether or not the original biometric information (e.g., a facial image) can be provided using a GUI or the like. When the service selection unit 504 obtains consent from the user to the provision of the original biometric information, it transmits the original biometric information stored internally to the control server 10.
- the original biometric information e.g., a facial image
- the account management database is configured inside the control server 10
- the database may also be constructed in an external database server or the like.
- some of the functions of the control server 10 may be implemented in another server.
- the above-described “service selection control unit (service selection control means)” and the like may be implemented in any of the devices included in the system.
- control server 10, service server 20, authentication terminal 30 The form of data transmission and reception between each device (control server 10, service server 20, authentication terminal 30) is not particularly limited, but data transmitted and received between these devices may be encrypted. Biometric information and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.
- each embodiment may be used alone or in combination.
- [Appendix 1] a receiving means for receiving a notification of authentication success from a service server of a service provider selected by a user from among a plurality of service providers and which has succeeded in biometric authentication of the user; an authentication history control means for controlling a history of successful biometric authentication at the service provider in response to receiving the authentication success notification;
- a terminal comprising: [Appendix 2] the authentication success notification includes detailed information of the authentication process that the service provider has succeeded in and a state of authentication information used by the service provider for biometric authentication;
- the terminal according to claim 2 further comprising: [Appendix 6] The terminal according to claim 5, wherein the original biometric information is a facial image, and the authentication information is a feature amount generated from the facial image.
- Control server 20 Service server 30 Authentication terminal 40 Terminal 100 Terminal 101 Receiving means 102 Authentication history control means 201 Communication control unit 202 Account management unit 203 Business management unit 204 Service selection control unit 205 User registration control unit 206 Storage unit 301 Communication control unit 302 Business information management unit 303 User registration control unit 304 Authentication unit 305 Storage unit 311 Processor 312 Memory 313 Input/output interface 314 Communication interface 401 Communication control unit 402 Provided service control unit 403 Authentication request unit 404 Storage unit 501 Communication control unit 502 Account generation control unit 503 Original information acquisition unit 504 Service selection unit 505 Authentication history control unit 506 Storage unit
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
利用者が選択したサービス提供者における認証履歴の管理等を実現する端末を提供する。端末は、受信手段と、認証履歴制御手段と、を備える。受信手段は、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、当該利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する。認証履歴制御手段は、認証成功通知の受信に応じて、サービス提供者において成功した生体認証の履歴に関する制御を行う。
Description
本発明は、端末、システム、端末の制御方法及び記憶媒体に関する。
生体認証に関する技術が存在する。
例えば、特許文献1には、複数の認証端末を含む認証システムにおける利便性を向上させるサーバ装置を提供する、と記載されている。特許文献1のサーバ装置は、取得部と、認証部と、を備える。取得部は、認証成功と判定するための条件を含む認証ルールを取得する。認証部は、第1の端末から送信された第1の認証要求に応じて第1の生体認証を行い、第2の端末から送信された第2の認証要求に応じて、認証ルールを用いる第2の生体認証を行う。
特許文献2には、一ユーザあたりの認証端末の占有時間を極力抑えながら、複数のサービス運営者が生体認証端末を利用できるようにする、と記載されている。特許文献2の認証装置は、認証テーブルと、受付手段と、認証手段と、通知手段と、を備える。認証テーブルは、各ユーザの識別情報、および、ユーザが所有するユーザ端末の連絡先を含む個人情報を対応づけて管理する。受付手段は、ユーザからユーザ識別情報および認証情報を受け付ける。認証手段は、ユーザから入力された認証情報と、認証するための基準となる基準認証情報とを比較し、その比較結果に基づき本人認証を行う。通知手段は、認証テーブルを参照し、ユーザに対応するユーザ端末に対して、本人認証の結果を通知する。
近年、生体認証を用いた様々なサービスの提供が始まっている。ここで、個人情報保護、プライバシー保護の観点から生体認証に用いる認証情報や認証結果等を利用者自身が管理したいという要望がある。具体的には、利用者が、複数のサービス提供者のなかから生体認証を受けるサービス提供者を選択し、当該選択したサービス提供者における認証履歴等を管理、確認したいという要望がある。
なお、当該要望は、特許文献1や特許文献2に開示された技術を適用しても実現されない。特許文献1や特許文献2は、利用者が複数のサービス提供者のなかからサービス提供者を選択するような認証システムを開示していない。
本発明は、利用者が選択したサービス提供者における認証履歴の管理等を実現することに寄与する、端末、システム、端末の制御方法及び記憶媒体を提供することを主たる目的とする。
本発明の第1の視点によれば、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する、受信手段と、前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、を備える、端末が提供される。
本発明の第2の視点によれば、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバと、前記利用者が所持する端末と、を含み、前記端末は、前記サービスサーバから、認証成功通知を受信する、受信手段と、前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、を備える、システムが提供される。
本発明の第3の視点によれば、端末において、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信し、前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、端末の制御方法が提供される。
本発明の第4の視点によれば、端末に搭載されたコンピュータに、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する処理と、前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う処理と、を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体が提供される。
本発明の各視点によれば、利用者が選択したサービス提供者における認証履歴の管理等を実現することに寄与する、端末、システム、端末の制御方法及び記憶媒体が提供される。なお、本発明の効果は上記に限定されない。本発明により、当該効果の代わりに、又は当該効果と共に、他の効果が奏されてもよい。
はじめに、一実施形態の概要について説明する。なお、この概要に付記した図面参照符号は、理解を助けるための一例として各要素に便宜上付記したものであり、この概要の記載はなんらの限定を意図するものではない。また、特段の釈明がない場合には、各図面に記載されたブロックはハードウェア単位の構成ではなく、機能単位の構成を表す。各図におけるブロック間の接続線は、双方向及び単方向の双方を含む。一方向矢印については、主たる信号(データ)の流れを模式的に示すものであり、双方向性を排除するものではない。なお、本明細書及び図面において、同様に説明されることが可能な要素については、同一の符号を付することにより重複説明が省略され得る。
一実施形態に係る端末100は、受信手段101と、認証履歴制御手段102と、を備える(図1参照)。受信手段101は、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、当該利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する(図2のステップS1)。認証履歴制御手段102は、認証成功通知の受信に応じて、サービス提供者において成功した生体認証の履歴に関する制御を行う(ステップS2)。
利用者は、複数のサービス提供者のなかからサービスの提供を受けたいサービス提供者を選択する。当該選択に応じて、生体認証に使われる認証情報の原本が上記選択されたサービス提供者に提供される。サービス提供者のサービスサーバは、認証情報を使って利用者の認証に成功すると、当該認証成功の事実及び詳細を通知する認証成功通知を端末100に送信する。端末100は、当該認証成功通知の受信に応じて、生体認証の履歴に関する制御を行う。例えば、端末100は、利用者による認証履歴の閲覧を可能にする。このように、端末100は、利用者が複数のサービス提供者のなかから選択したサービス提供者における認証履歴の管理等を実現する。認証履歴等を確認することで、利用者は、身に覚えのない不正な生体認証の実施等を発見できる。
以下に具体的な実施形態について、図面を参照してさらに詳しく説明する。
[第1の実施形態]
第1の実施形態について、図面を用いてより詳細に説明する。
第1の実施形態について、図面を用いてより詳細に説明する。
[システムの構成]
図3は、第1の実施形態に係る認証システム(情報処理システム)の概略構成の一例を示す図である。図3に示すように、認証システムには、複数のサービス提供者A~C、認証センターが含まれる。
図3は、第1の実施形態に係る認証システム(情報処理システム)の概略構成の一例を示す図である。図3に示すように、認証システムには、複数のサービス提供者A~C、認証センターが含まれる。
サービス提供者は、生体認証を用いて利用者にサービスを提供する事業者である。本願開示に係る認証システムは、様々な業種、業界に属するサービス提供者が生体認証を用いてサービスを提供することを前提とする。なお、サービス提供者により提供されるサービスは、有償無償を問わない。
例えば、マンション等の賃貸住宅サービスを提供する事業者、従業員の勤務先である事業者(利用者の勤務先)、コンサート等のイベントを提供する事業者、航空機等の交通手段を運営する事業者等がサービス提供者として例示される。あるいは、宿泊サービスを提供する事業者、小売店等の事業者、金融サービスを提供する事業者、教育事業者等も本願開示のサービス提供者に含まれる。また、サービス提供者は、民間事業者に限らない。自治体等の公的機関がサービス提供者であってもよい。
認証センターは、複数のサービス提供者それぞれの生体認証に関する制御、管理等を行う。利用者(一般消費者)に対して生体認証を用いたサービスを提供する事業者(サービス提供者)は、認証センターと契約を締結する必要がある。
認証センターは、制御サーバ10を備える。制御サーバ10は、認証センターの主たる機能を実現する。制御サーバ10は、認証センターの建物内に設置されていてもよいし、ネットワーク(クラウド)上に設置されたサーバであってもよい。
上述のように、サービス提供者は、生体認証を用いたサービスを利用者に提供する。例えば、利用者がオフィスに出勤する際やマンションに帰宅する際に生体認証が行われ、正当な資格を有する利用者(社員、住民)がオフィス等に入ることができる。あるいは、イベント会場等におけるチケット確認、ホテルにおけるチェックイン手続き、空港における出入国手続き等において生体認証が行われる。このようなサービス(手続き)においても正当な資格を有する利用者にサービスが提供される。あるいは、小売店等での決済手続きが生体認証を用いて行われる。
図3に示すように、各サービス提供者は、サービスサーバ20と、少なくとも1以上の認証端末30と、を備える。サービス提供者が備える装置(サービスサーバ20、認証端末30)は相互に通信可能に接続される。具体的には、サービスサーバ20と認証端末30は、有線又は無線の通信手段により接続される。
サービスサーバ20は、ネットワークを介して制御サーバ10と接続されている。サービスサーバ20は、サービス提供者の建物に設置されていてもよいし、クラウド上に設置されていてもよい。
サービスサーバ20は、利用者にサービスを提供する際に必要な情報を記憶する。具体的には、サービスサーバ20は、各サービス提供者が生体認証を用いたサービスを提供する際に必要な業務情報と、生体認証に必要な情報と、を記憶する。サービスサーバ20は、利用者管理データベースを用いて、業務情報と生体認証に必要な情報を記憶する。利用者管理データベースの詳細は後述する。
例えば、利用者が勤務する企業のサービスサーバ20は、利用者(従業員)の氏名、生年月日、社員番号、所属部署、勤務地等の情報を業務情報として記憶する。また、イベントを主催するイベント会社のサービスサーバ20は、イベント参加者が購入したチケットに関する情報を業務情報として記憶する。さらに、小売店等のサービスサーバ20は、代金決済に必要なクレジットカード情報(決済情報)等を業務情報として記憶する。
サービスサーバ20が記憶する生体認証に必要な情報の詳細は後述する。
認証端末30は、サービスの提供を受ける利用者のインターフェイスとなる装置である。認証端末30は、各サービス提供者それぞれのサービス提供場所に設置される。より具体的には、認証端末30は、利用者が実際に訪れる店舗等に設置される。
認証端末30は、サービス提供者の業種等に応じた機能、形態を備える。例えば、職場やイベント会場に設置された認証端末30は、利用者(被認証者)の通行を制限するゲートを備えたゲート装置とすることができる。また、小売店に設置された認証端末30には、タブレット型の端末を用いることができる。
なお、図3は例示であって、本願開示の認証システムの構成等を限定する趣旨ではない。例えば、認証センターには2台以上の制御サーバ10が含まれていてもよい。また、認証システムには、少なくとも1以上のサービス提供者が参加していればよい。さらに、各サービス提供者は、少なくとも1台以上のサービスサーバ20と、少なくとも1台以上の認証端末30と、を備えていればよい。
[概略動作]
続いて、第1の実施形態に係る認証システムの概略動作について説明する。
続いて、第1の実施形態に係る認証システムの概略動作について説明する。
<アカウント生成>
サービス提供者からサービスの提供を希望する利用者は、システムにアカウントを生成する必要がある。具体的には、利用者は、所持する端末40を操作して、制御サーバ10にアクセスする(図4参照)。
サービス提供者からサービスの提供を希望する利用者は、システムにアカウントを生成する必要がある。具体的には、利用者は、所持する端末40を操作して、制御サーバ10にアクセスする(図4参照)。
利用者は、制御サーバ10が提供するWEB(ウェブ)ページ等において、ログイン情報(例えば、ログインID、パスワード)、氏名、生年月日、連絡先等を入力する。制御サーバ10は、ログイン情報等を取得すると、当該利用者を識別するためのIDを生成する。なお、以降の説明において、制御サーバ10が生成したIDを「システムID」と表記する。制御サーバ10は、生成したシステムID、ログイン情報等を対応付けてアカウント管理データベースに記憶する。アカウント管理データベースの詳細は後述する。
<生体情報登録>
生体認証を用いてサービスの提供を受けることを希望する利用者は、自身の生体情報を端末40に登録する必要がある。
生体認証を用いてサービスの提供を受けることを希望する利用者は、自身の生体情報を端末40に登録する必要がある。
ここで、生体認証を用いたサービスの提供には、生体情報から生成された認証情報が事前にサービス提供者に登録されている必要がある。例えば、顔認証を用いてサービスが提供される際には、顔画像から生成された特徴量(特徴ベクトル)が認証情報として事前に登録されている必要がある。あるいは、指紋認証を用いてサービスが提供される際には、指紋画像から生成された特徴量が認証情報として事前に登録されている必要がある。
以降の説明において、顔画像や指紋画像のように、認証情報を生成する際の原本(基礎)となる情報を「原本生体情報」と表記する。また、原本生体情報から生成され、事前に登録される特徴量を「登録認証情報」と表記する。
システムアカウント生成を完了した利用者は、原本生体情報(例えば、顔画像)を所持する端末40に登録する必要がある。端末40は、GUI(Graphical User Interface)等を用いて原本生体情報を取得する。端末40は、取得した原本生体情報(例えば、顔画像)を内部に記憶する。このように、端末40は、生体認証に用いられる認証情報の原本となる原本生体情報を記憶する。
<サービスの選択>
システム登録(システムアカウント作成)及び原本生体情報の登録を行った利用者は、生体認証サービスの提供を受けたいサービス提供者を選択する。利用者は、認証システムに参加している複数のサービス提供者(認証センターと契約しているサービス提供者)のなかからサービスの提供を受けたいサービス提供者を選択する。
システム登録(システムアカウント作成)及び原本生体情報の登録を行った利用者は、生体認証サービスの提供を受けたいサービス提供者を選択する。利用者は、認証システムに参加している複数のサービス提供者(認証センターと契約しているサービス提供者)のなかからサービスの提供を受けたいサービス提供者を選択する。
制御サーバ10は、認証システムに参加しているサービス提供者の情報を記憶する。例えば、制御サーバ10は、サービス提供者の名称、業種、所在地等を記憶する。制御サーバ10は、複数のサービス提供者それぞれの情報を保持すると共に、利用者によるサービス提供者の選択を可能とする。
利用者が端末40を操作してポータルサイト上にて所定の動作を行うと、制御サーバ10は、利用者が希望するサービス(サービス提供者)の選択を可能とするGUI等を端末40に表示する。制御サーバ10は、GUIを用いて利用者が希望するサービス(生体認証サービス)を取得する。
<利用者登録>
利用者が選択したサービス提供者を取得すると、制御サーバ10は、当該選択されたサービス提供者が、生体認証を用いたサービスを利用者に提供可能とする「利用者登録」に関する制御を実行する。
利用者が選択したサービス提供者を取得すると、制御サーバ10は、当該選択されたサービス提供者が、生体認証を用いたサービスを利用者に提供可能とする「利用者登録」に関する制御を実行する。
具体的には、制御サーバ10は、利用者の端末40に格納された原本生体情報を上記選択されたサービス提供者が取得するための制御を行う。サービス提供者は、取得した原本生体情報から登録認証情報を生成し、当該生成した登録認証情報と業務情報を対応付けることで利用者にサービスを提供する準備が整う。
利用者は、端末40を操作して制御サーバ10にアクセスし、当該利用者のポータルサイトにログインする。利用者がポータルサイト上で所定の操作(例えば、サービス提供者の選択ボタンの押下)を行うと、制御サーバ10は、サービス提供者の一覧を含むGUIを端末40に表示する。
サービス提供者が選択されると、制御サーバ10は、利用者に対して原本生体情報の提供を要求する。具体的には、制御サーバ10は、「原本提供要求」を利用者の端末40に送信する(図5のステップS01参照)。
原本提供要求を受信すると、端末40は、利用者の原本生体情報(例えば、顔画像)を制御サーバ10に送信する(ステップS02)。
制御サーバ10は、利用者のシステムID、取得した原本生体情報、個人特定情報等を利用者が選択したサービス提供者に通知する。なお、個人特定情報は、利用者を特定するための情報である。個人特定情報として、利用者の氏名、又は、氏名と生年月日の組み合わせが例示される。
制御サーバ10は、システムID、原本生体情報及び個人特定情報等を含む「利用者登録要求」を利用者が選択したサービス提供者のサービスサーバ20に送信する(ステップS03)。
利用者登録要求を受信したサービスサーバ20は、取得した個人特定情報を用いて利用者管理データベースを検索し、利用者登録(生体認証を用いたサービスの提供)を希望する利用者を特定する。サービスサーバ20は、特定された利用者のエントリにシステムID、原本生体情報から得られる登録認証情報(例えば、特徴量)を記憶する。
サービスサーバ20は、利用者登録の結果(利用者登録に成功、失敗)を含む応答を制御サーバ10に送信する(ステップS04)。
なお、制御サーバ10は、利用者登録要求をサービスサーバ20に送信したタイミング、又は当該要求に対する応答を受信したタイミングにおいて、利用者から取得した原本生体情報(例えば、顔画像)を削除する。また、サービスサーバ20は、登録認証情報(例えば、特徴量)を生成すると、制御サーバ10から取得した原本生体情報を削除する。
<サービスの提供>
サービスの選択を完了した利用者は、サービスの提供を受けるためサービス提供者を訪れる。例えば、利用者は、オフィス、遊園地、イベント会場、小売店等自身で選択したサービスの提供を受けるサービス提供者の施設、店舗等を訪れる。
サービスの選択を完了した利用者は、サービスの提供を受けるためサービス提供者を訪れる。例えば、利用者は、オフィス、遊園地、イベント会場、小売店等自身で選択したサービスの提供を受けるサービス提供者の施設、店舗等を訪れる。
認証端末30は、サービスの提供を受ける利用者(被認証者)の生体情報を取得する。例えば、認証端末30は、被認証者を撮影し、原本生体情報に対応する生体情報(例えば、顔画像)を取得する。認証端末30は、取得した顔画像を含む認証要求をサービスサーバ20に送信する(図6参照)。なお、認証端末30は、必要に応じて、生体情報と共に他の情報(例えば、購入商品名、購入商品の代金等)をサービスサーバ20に送信する。あるいは、認証端末30は、生体情報(個人を特定するための情報、ID)と共に認証処理に使用される情報(例えば、クレジットカード情報)をサービスサーバ20に送信してもよい。
サービスサーバ20は、取得した顔画像から照合用の認証情報を生成する。例えば、サービスサーバ20は、照合用の顔画像から特徴量を生成する。サービスサーバ20は、当該生成された照合用の認証情報(以下、照合認証情報と表記する)と、利用者管理データベースに登録された登録認証情報と、を用いた照合処理(1対N照合;Nは正の整数、以下同じ)を実行する。
サービスサーバ20は、照合処理により利用者管理データベースに登録された利用者(被認証者)を特定する。
サービスサーバ20は、特定された利用者の業務情報を用いて当該利用者の認証を行う。例えば、社員の勤務先企業のサービスサーバ20は、被認証者が自社の社員であってオフィスに入場する資格を備えていれば「認証成功」と判定する。あるいは、イベント会場に設置されたサービスサーバ20は、被認証者が購入したチケットが有効であれば「認証成功」と判定する。あるいは、小売店に設置されたサービスサーバ20は、被認証者が購入した商品等の代金決済に成功すると「認証成功」と判定する。
なお、サービス提供者には、2種類のサービス事業者が存在する。
第1のサービス提供者は、原則として、被認証者の認証に成功しても登録認証情報(特徴量)等を保持し続けるサービス提供者である。例えば、利用者の勤務先企業やマンション管理会社等が第1のサービス提供者として例示される。これらのサービス提供者は、利用者の認証(オフィス、マンション等への入退場)に成功しても利用者管理データベースに記憶された登録認証情報等を削除しない。あるいは、事前登録されたクレジットカード情報等を用いて商品代金の顔決済に関するサービスを提供する小売店も第1のサービス提供者として例示される。当該小売店は、クレジットカード情報と登録認証情報を対応付けて記憶し続ける。
第2のサービス提供者は、原則として、被認証者の認証に成功すると登録認証情報(特徴量)等を削除するサービス提供者である。例えば、イベントを開催するイベント会社等が第2のサービス提供者として例示される。当該イベント会社は、利用者の認証に成功すると(購入チケットを用いて利用者がイベント会場に入場すると)、利用者管理データベースに記憶された登録認証情報を削除する。
なお、同じサービス提供者であっても、利用者に提供するサービスの内容によっては登録認証情報を記憶し続けたり、登録認証情報を削除したりする。例えば、遊園地等を運営する事業者は、1日の使用に限定されるチケットを販売する。この場合、当該事業者は、第2のサービス提供者となる。上記事業者が、所定期間に亘り遊園地等に入場できるチケット(例えば、年間チケット)も販売する場合、第1のサービス提供者となる。この場合、事業者は、年間チケットの期限が到来するまで登録認証情報を保持し続ける。
サービスサーバ20は、認証結果(認証成功、認証失敗)を認証端末30に送信する。
認証端末30は、認証結果に応じた処理を実行する。例えば、認証成功を受信すると、オフィスに設置された認証端末30は、ゲートを開き被認証者の通行を許可する。あるいは、イベント会場に設置された認証端末30は、認証成功を受信すると、被認証者のゲート通過を許可する。あるいは、小売店に設置された認証端末30は、認証成功を受信すると、商品の決済が終了した旨を被認証者に通知する。
<認証成功の通知>
また、サービスサーバ20は、被認証者の認証に成功すると、その旨を利用者に通知する。サービスサーバ20は、認証結果の詳細を、制御サーバ10を介して利用者が所持する端末40に通知する。具体的には、被認証者の認証に成功すると、サービスサーバ20は、認証成功者(認証成功と判定された被認証者)のシステムID、認証処理の詳細情報及び認証情報の状態を含む認証成功通知を制御サーバ10に送信する(図7参照)。
また、サービスサーバ20は、被認証者の認証に成功すると、その旨を利用者に通知する。サービスサーバ20は、認証結果の詳細を、制御サーバ10を介して利用者が所持する端末40に通知する。具体的には、被認証者の認証に成功すると、サービスサーバ20は、認証成功者(認証成功と判定された被認証者)のシステムID、認証処理の詳細情報及び認証情報の状態を含む認証成功通知を制御サーバ10に送信する(図7参照)。
認証処理の詳細情報には、例えば、認証日時、認証場所、提供サービスの詳細(例えば、購入商品名、支払金額等)が含まれる。
例えば、被認証者の勤務先のサービスサーバ20は、認証成功者の出勤日時、オフィス名を提供サービスの詳細として生成する。あるいは、例えば、小売店のサービスサーバ20は、認証成功者の来店日時、店舗、購入商品、支払金額等を提供サービスの詳細として生成する。
認証情報の状態には、認証処理後における認証成功者の登録認証情報(特徴量)の状態(保持、削除)が設定される。
例えば、被認証者の勤務先のような第1のサービス提供者のサービスサーバ20は、認証情報の状態に「認証情報保持」を設定する。あるいは、イベント会社のような第2のサービス提供者のサービスサーバ20は、認証情報の状態に「認証情報削除」を設定する。
制御サーバ10は、認証成功通知を受信する。制御サーバ10は、認証成功通知に含まれるシステムIDをキーとしてアカウント管理データベースを検索し、対応するエントリ(利用者)を特定する。制御サーバ10は、特定した利用者の端末40にサービスサーバ20から受信した認証成功通知を送信(転送)する。
端末40は、受信した認証成功通知に基づいて認証履歴を生成する。また、端末40は、認証成功通知を受信するたびに、当該通知の受信事実を利用者に通知する。例えば、端末40は、ポップアップ等の手段により認証成功通知に含まれる内容(認証処理の詳細、認証情報の状態)を表示する。
あるいは、端末40は、所定のボタン(履歴確認ボタン)が押下されると、認証履歴を表示する。利用者は、認証履歴を確認することで、不正利用の有無等を確認できる。
このように利用者が事前に選択したサービス提供者が当該利用者の認証に成功すると、当該認証成功の事実が利用者に通知される。なお、サービスサーバ20は、上記説明したように、制御サーバ10を介して認証成功通知を端末40に送信してもよいし、制御サーバ10を介さずに直接、認証成功通知を端末40に送信してもよい。この場合、サービスサーバ20は、業務情報を取得する際、利用者の連絡先(端末40が受信可能なメールアドレス等)を取得すればよい。
続いて、第1の実施形態に係る認証システムに含まれる各装置の詳細について説明する。
[制御サーバ]
図8は、第1の実施形態に係る制御サーバ10の処理構成(処理モジュール)の一例を示す図である。図8を参照すると、制御サーバ10は、通信制御部201と、アカウント管理部202と、事業者管理部203と、サービス選択制御部204と、利用者登録制御部205と、記憶部206と、を備える。
図8は、第1の実施形態に係る制御サーバ10の処理構成(処理モジュール)の一例を示す図である。図8を参照すると、制御サーバ10は、通信制御部201と、アカウント管理部202と、事業者管理部203と、サービス選択制御部204と、利用者登録制御部205と、記憶部206と、を備える。
通信制御部201は、他の装置との間の通信を制御する手段である。例えば、通信制御部201は、サービスサーバ20からデータ(パケット)を受信する。また、通信制御部201は、サービスサーバ20に向けてデータを送信する。通信制御部201は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部201は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部201を介して他の装置とデータの送受信を行う。通信制御部201は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。
アカウント管理部202は、利用者のアカウントを管理する手段である。アカウント管理部202は、利用者が端末40を操作して、所定のホームページ等にアクセスすると、当該利用者のアカウントを生成するために必要な情報を取得する。
具体的には、アカウント管理部202は、ログイン情報、氏名、生年月日、連絡先(例えば、端末40が受信可能なメールアドレス)等の個人情報を取得する。ログイン情報等を取得すると、アカウント管理部202は、当該利用者を識別するためのシステムIDを生成する。システムIDは、利用者を一意に識別できる情報であればどのような情報であってもよい。例えば、アカウント管理部202は、アカウント生成のたびに一意な値を採番しシステムIDとしてもよい。
アカウント管理部202は、生成されたシステムID、ログイン情報、氏名等を対応付けてアカウント管理データベースに記憶する(図9参照)。なお、図9に示すアカウント管理データベースは例示であって、記憶する項目等を限定する趣旨ではない。例えば、アカウント生成日時等がアカウント管理データベースに記憶されていてもよい。
また、アカウント管理部202は、利用者の端末40からポータルサイトにログインするためのログイン情報を取得する。アカウント管理部202は、ログイン情報を使った認証を行う。
事業者管理部203は、認証システムに参加するサービス提供者(サービス事業者)を管理する手段である。事業者管理部203は、各サービス提供者の職員等からシステム登録する事業者情報(サービス提供者の名称、業種、所在地、サービスサーバ20のアドレス等)を取得する。
例えば、事業者管理部203は、事業者情報等を入力するためのインターフェイスを各サービス提供者に提供してもよい。あるいは、各サービス提供者は、事業者情報等が格納されたUSB(Universal Serial Bus)メモリ等を認証センターに送付してもよい。事業者管理部203は、認証センターの職員等から事業者情報等を取得してもよい。
事業者管理部203は、事業者情報等を取得したサービス提供者についてのID(事業者ID)を生成する。事業者管理部203は、当該生成された事業者ID、取得した事業者情報等を対応付けて記憶する。
サービス選択制御部204は、利用者による生体認証サービス(サービス提供者)の選択を制御する手段である。サービス選択制御部204は、生体認証を用いたサービスを提供する複数のサービス提供者のなかから、利用者がサービスの提供を受けたいサービス提供者を選択することを可能とする。
利用者が端末40を操作してポータルサイトにログインし、当該ポータルサイト上で所定の動作を行うと、サービス選択制御部204は、例えば、図10に示すようなGUIを端末40に表示する。
上記GUIを表示する際、サービス選択制御部204は、利用者が選択済のサービス提供者と未選択なサービス提供者を区別可能な表示を行う。図10の例では、サービス事業者を示すアイコンの右上にチェックが入ったサービス提供者は既に選択されたサービス提供者を示し、チェックが入っていないサービス提供者は未選択なサービス提供者を示す。
なお、サービス選択制御部204は、図10に示すようなGUIを表示するために事業者情報及びアカウント管理データベースに登録された情報を用いる。具体的には、サービス選択制御部204は、事業者情報を参照し、認証センターと契約を締結しているサービス提供者の一覧を生成する。また、サービス選択制御部204は、アカウント管理データベースの選択サービスフィールドを参照し、利用者が選択済のサービス提供者(サービス提供者の事業者ID)を取得する。
また、サービス選択制御部204は、サービス提供者の一覧を表示する際、各サービス提供者のより詳細な情報(例えば、業種、提供するサービス、店舗の場所等)も併せて利用者に提供してもよい。
サービス選択制御部204は、利用者が選択したサービス提供者の情報(例えば、利用者登録が希望されたサービス提供者の事業者ID)を利用者登録制御部205に引き渡す。
利用者登録制御部205は、制御サーバ10による「利用者登録」を制御する手段である。利用者登録制御部205は、利用者により選択されたサービス提供者が生体認証を用いたサービスを当該利用者に提供可能とする「利用者登録」を制御する。
利用者がサービス提供者を選択すると、利用者登録制御部205は、利用者が所持する端末40に「原本提供要求」を送信する。利用者登録制御部205は、端末40から利用者の原本生体情報(例えば、顔画像)を受信する。
利用者登録制御部205は、利用者のシステムID、原本生体情報及び個人特定情報等を含む利用者登録要求を、利用者が選択したサービスに対応するサービス提供者のサービスサーバ20に送信する。
なお、利用者登録制御部205は、アカウント管理データベースからシステムID及び個人特定情報(例えば、氏名又は氏名と生年月日の組み合わせ)を取得する。
利用者登録制御部205は、利用者登録要求に対する応答(肯定応答、否定応答)を受信する。
肯定応答(利用者登録に成功)を受信した場合、利用者登録制御部205は、利用者が選択したサービス提供者の事業者IDをアカウント管理データベースに登録する。また、肯定応答を受信した場合、利用者登録制御部205は、選択されたサービス提供者に関する利用者登録に成功した旨を利用者に通知する。
否定応答(利用者登録に失敗)を受信した場合、利用者登録制御部205は、その旨を利用者に通知する。
記憶部206は、制御サーバ10の動作に必要な情報を記憶する手段である。
[サービスサーバ]
図11は、第1の実施形態に係るサービスサーバ20の処理構成(処理モジュール)の一例を示す図である。図11を参照すると、サービスサーバ20は、通信制御部301と、業務情報管理部302と、利用者登録制御部303と、認証部304と、記憶部305と、を備える。
図11は、第1の実施形態に係るサービスサーバ20の処理構成(処理モジュール)の一例を示す図である。図11を参照すると、サービスサーバ20は、通信制御部301と、業務情報管理部302と、利用者登録制御部303と、認証部304と、記憶部305と、を備える。
通信制御部301は、他の装置との間の通信を制御する手段である。例えば、通信制御部301は、制御サーバ10からデータ(パケット)を受信する。また、通信制御部301は、制御サーバ10に向けてデータを送信する。通信制御部301は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部301は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部301を介して他の装置とデータの送受信を行う。通信制御部301は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。
業務情報管理部302は、サービス提供者が業務の提供に必要な業務情報に関する管理、制御を行う手段である。
業務情報管理部302は、任意の手段を用いて自社、自組織のサービス提供に必要な業務情報を取得する。例えば、利用者の勤務先企業の業務情報管理部302は、従業員の氏名、生年月日、社員番号、所属部署、勤務地等の情報を業務情報として取得する。
業務情報管理部302は、サービス提供者の職員等から上記業務情報を取得してもよいし、ホームページ等の手段を用いて利用者から直接、業務情報を取得してもよい。
業務情報管理部302は、利用者管理データベースを用いて業務情報を管理する。
なお、業務情報管理部302のより詳細な説明は省略する。個別のサービスにおける業務情報の詳細やその取得方法は、本願開示の趣旨とは異なるためである。
利用者登録制御部303は、サービス提供者による利用者登録を制御する手段である。利用者登録制御部303は、制御サーバ10から受信した利用者登録要求を処理する。
利用者登録要求を受信すると、利用者登録制御部303は、当該利用者登録要求に含まれる個人特定情報(例えば、氏名)をキーとして利用者管理データベースを検索し、対応する利用者(エントリ)を特定する。
対応する利用者が利用者管理データベースに登録されていると、利用者登録制御部303は、取得した原本生体情報(例えば、顔画像)から登録認証情報を生成する。例えば、顔画像を取得した場合、利用者登録制御部303は、自社で採用する顔認証アルゴリズムに対応した特徴量(特徴ベクトル)を登録認証情報として生成する。
特徴量の生成処理に関しては既存の技術を用いることができるので、その詳細な説明を省略する。例えば、利用者登録制御部303は、顔画像から目、鼻、口等を特徴点として抽出する。その後、利用者登録制御部303は、特徴点それぞれの位置や各特徴点間の距離を特徴量として計算し、複数の特徴量からなる特徴ベクトル(顔画像を特徴づけるベクトル情報)を生成する。
登録認証情報(例えば、特徴量)が生成されると、利用者登録制御部303は、システムID、生成された登録認証情報(特徴量)及び業務情報を対応付けて利用者管理データベースに記憶する(図12参照)。
なお、図12に示す利用者管理データベースは例示であって、記憶する項目等を限定する趣旨ではない。例えば、利用者登録の日時等が利用者管理データベースに登録されていてもよい。
利用者登録が正常に終了すると、利用者登録制御部303は、利用者登録に成功した旨を示す肯定応答を制御サーバ10に送信する。なお、利用者登録制御部303は、登録認証情報(例えば、特徴量)を生成し、当該生成された登録認証情報を利用者管理データベースに登録すると、制御サーバ10から取得した原本生体情報を削除する。
利用者登録が正常に終了しなければ、利用者登録制御部303は、利用者登録に失敗した旨を示す否定応答を制御サーバ10に送信する。例えば、制御サーバ10から受信した個人特定情報(例えば、氏名)が利用者管理データベースに登録されていない場合や原本生体情報から有効な登録認証情報が生成できない場合等に、否定応答が制御サーバ10に送信される。
認証部304は、被認証者の生体認証を行う手段である。
図13は、第1の実施形態に係る認証部304の動作の一例を示すフローチャートである。図13を参照して、認証部304の動作を説明する。
認証端末30から認証要求を受信すると、認証部304は、生体情報を用いた照合処理を実行する(ステップS101)。
具体的には、認証部304は、認証要求に含まれる生体情報から照合認証情報を生成する。例えば、顔画像を取得すると、認証部304は、自社で採用している顔認証アルゴリズムに対応した特徴量を生成する。認証部304は、生成した照合認証情報(特徴量)と、利用者管理データベースに登録された登録認証情報(特徴量)と、を用いた照合処理を実行する。
具体的には、認証部304は、照合対象の特徴量(特徴ベクトル)と登録側の複数の特徴量それぞれとの間の類似度を計算する。当該類似度には、カイ二乗距離やユークリッド距離等を用いることができる。なお、距離が離れているほど類似度は低く、距離が近いほど類似度が高い。
類似度が所定の値以上の特徴量が存在しなければ、認証部304は、照合処理に失敗したと判定する。類似度が所定の値以上の特徴量が存在すれば、認証部304は、照合処理に成功したと判定する。照合処理に成功すると、利用者管理データベースに登録された複数のエントリのうち最も類似度が高い特徴量(登録認証情報)を持つエントリの利用者が被認証者として特定される。
照合処理に失敗すると(ステップS102、No分岐)、認証部304は、処理を終了する。この場合、認証部304は、認証に失敗した旨を認証端末30に通知してもよい。あるいは、認証部304は、顔認証の健全性を確認するため、照合処理に失敗した事実及び照合処理の詳細をログとして記憶してもよい。
照合処理に成功すると(ステップS102、Yes分岐)、認証部304は、照合処理により特定された被認証者の業務情報を用いて当該被認証者にサービスの提供が可能か否か判定する。認証部304は、業務情報によるサービス提供可否の判定を行う(ステップS103)。
例えば、社員の勤務先企業のサービスサーバ20の認証部304は、被認証者が自社の社員であってオフィスに入場する資格を備えていれば、サービスの提供が可能と判定する。あるいは、イベント会社のサービスサーバ20は、被認証者が購入したチケットが有効であれば、サービスの提供が可能と判定する。あるいは、小売店等のサービスサーバ20の認証部304は、クレジットカード情報等を用いた商品代金の決済に成功した場合に、サービスの提供が可能と判定する。
なお、各サービス提供者における業務情報を用いた認証処理に関するより詳細な説明を省略する。各サービス提供者に特有な処理は本願開示の趣旨とは異なるためである。
サービスの提供が不可な場合(ステップS104、No分岐)、認証部304は、認証結果に「認証失敗」を設定する(ステップS105)。
サービスの提供が可能な場合(ステップS104、Yes分岐)、認証部304は、認証結果に「認証成功」を設定する(ステップS106)。
認証部304は、認証結果(認証成功、認証失敗)を認証端末30に送信する(ステップS107)。
認証失敗の場合には、認証部304は、その旨を示す否定応答を認証端末30に送信する。
認証成功の場合には、認証部304は、その旨を示す肯定応答を認証端末30に送信する。その際、認証部304は、必要に応じて、利用者にサービスを提供するために必要な情報を含む肯定応答を認証端末30に送信する。上記住民票発行の例では、住民票を発行(印刷)するために必要な情報が認証端末30に送信される。
また、認証成功の場合には、認証部304は、必要に応じて利用者管理データベースの更新を行う(データベースの更新;ステップS108)。より具体的には、認証部304は、認証処理の内容に応じて、少なくとも認証成功者の登録認証情報を削除する。
例えば、認証部304は、被認証者の入退(オフィスへの出勤、マンションへの帰宅等)に関する認証処理の場合には特段の処理を行わない(登録認証情報を削除しない)。あるいは、クレジットカード情報を使って被認証者が購入した商品の決済を行った場合にも、認証部304は、特段の処理を行わない。
このように、認証成功者の登録認証情報を削除しない場合には、認証部304は、認証情報の状態に「認証情報保持」を設定する。
被認証者が購入チケットを利用してイベント会場等に入場した場合には、認証部304は、当該被認証者の登録認証情報を削除する(対応する利用者管理データベースのエントリを削除する)。この場合、認証部304は、認証情報の状態に「認証情報削除」を設定する。
登録認証情報を削除するか否かは、利用者に提供されるサービスに応じて予め定められている。あるいは、業務情報に含まれる情報に基づいて登録認証情報(登録認証情報を含むエントリ)の削除が決定されてもよい。例えば、利用者の購入したチケットが「年間パスポート」のような繰り返し使えるチケットの場合には、認証部304は、登録認証情報を削除しない。
認証成功の場合には、認証部304は、認証成功通知を制御サーバ10に送信する(ステップS109)。
具体的には、認証部304は、被認証者(照合処理により特定された利用者)のシステムID、認証処理の詳細情報及び認証情報の状態を含む認証成功通知を制御サーバ10に送信する。
認証部304は、照合処理により特定されたエントリ(利用者管理データベースのエントリ)から上記システムIDを取得する。
認証部304は、認証端末30から受信した認証要求を処理した日時から認証日時を生成し、当該認証端末30の設置場所から認証場所を生成する。また、認証部304は、業務情報を使った認証処理の内容から提供サービスの詳細を生成する。
例えば、被認証者が勤務先に出勤した場合、認証部304は、「認証日時=2022年11月7日、08:30」、「認証場所=本社ビル」、「提供サービスの詳細=出勤」といった内容を含む認証処理の詳細情報を生成する。あるいは、被認証者が小売店で商品を購入した場合、認証部304は、「認証日時=2022年11月7日、13:00」、「認証場所=駅前店」、「提供サービスの詳細=栄養ドリンク購入、300円」といった内容の認証処理の詳細情報を生成する。
なお、利用者が退職した、利用者がマンションから退去した、年間パスポートの有効期限が経過した等が発生すると、利用者管理データベースから対応する利用者のエントリが削除される。この場合、当該利用者の認証に成功することはないので、利用者管理データベースの更新や認証成功通知の送信が行われることはない。
記憶部305は、サービスサーバ20の動作に必要な情報を記憶する手段である。
[認証端末]
図14は、第1の実施形態に係る認証端末30の処理構成(処理モジュール)の一例を示す図である。図14を参照すると、認証端末30は、通信制御部401と、提供サービス制御部402と、認証要求部403と、記憶部404と、を備える。
図14は、第1の実施形態に係る認証端末30の処理構成(処理モジュール)の一例を示す図である。図14を参照すると、認証端末30は、通信制御部401と、提供サービス制御部402と、認証要求部403と、記憶部404と、を備える。
通信制御部401は、他の装置との間の通信を制御する手段である。例えば、通信制御部401は、サービスサーバ20からデータ(パケット)を受信する。また、通信制御部401は、サービスサーバ20に向けてデータを送信する。通信制御部401は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部401は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部401を介して他の装置とデータの送受信を行う。通信制御部401は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。
提供サービス制御部402は、利用者に提供するサービスに関する制御を実行する手段である。提供サービス制御部402は、認証端末30に割り当てられた機能を実現する。
提供サービス制御部402は、利用者がサービスの享受を希望すると、当該利用者(被認証者)の生体情報(例えば、顔画像)を取得する。例えば、提供サービス制御部402は、定期的又は所定のタイミングにおいて自装置の前方を撮像する。提供サービス制御部402は、取得した画像に人の顔画像が含まれるか否かを判定し、顔画像が含まれる場合には取得した画像データから顔画像を抽出する。
なお、提供サービス制御部402による顔画像の検出処理や顔画像の抽出処理には既存の技術を用いることができるので詳細な説明を省略する。例えば、提供サービス制御部402は、CNN(Convolutional Neural Network)により学習された学習モデルを用いて、画像データの中から顔画像(顔領域)を抽出してもよい。あるいは、提供サービス制御部402は、テンプレートマッチング等の手法を用いて顔画像を抽出してもよい。
提供サービス制御部402は、取得した生体情報(例えば、顔画像)を認証要求部403に引き渡す。
認証要求部403は、サービスサーバ20に対して被認証者の認証を要求する手段である。認証要求部403は、被認証者の認証が必要になると、被認証者(認証端末30の面前の利用者)の生体情報を含む認証要求をサービスサーバ20に送信する。
認証要求部403は、サービスサーバ20から認証結果(認証成功、認証失敗)を受信する。認証要求部403は、受信した認証結果を提供サービス制御部402に引き渡す。
例えば、利用者の勤務先に設置された認証端末30の提供サービス制御部402は、認証成功を受信すると、ゲートを開き被認証者の入場を許可する。
認証失敗を受信した場合、提供サービス制御部402は、予め定められたメッセージ等を出力してもよい。
なお、各サービス提供者の認証端末30に含まれる提供サービス制御部402に関するより詳細な説明は省略する。提供サービス制御部402による認証端末30の機能実現は、本願開示の趣旨とは異なるためである。
記憶部404は、認証端末30の動作に必要な情報を記憶する手段である。
[端末]
図15は、第1の実施形態に係る端末40の処理構成(処理モジュール)の一例を示す図である。図15を参照すると、端末40は、通信制御部501と、アカウント生成制御部502と、原本情報取得部503と、サービス選択部504と、認証履歴制御部505と、記憶部506と、を備える。
図15は、第1の実施形態に係る端末40の処理構成(処理モジュール)の一例を示す図である。図15を参照すると、端末40は、通信制御部501と、アカウント生成制御部502と、原本情報取得部503と、サービス選択部504と、認証履歴制御部505と、記憶部506と、を備える。
通信制御部501は、他の装置との間の通信を制御する手段である。例えば、通信制御部501は、制御サーバ10からデータ(パケット)を受信する。また、通信制御部501は、制御サーバ10に向けてデータを送信する。通信制御部501は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部501は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部501を介して他の装置とデータの送受信を行う。通信制御部501は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。
通信制御部501は、複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバ10からの要求に応じて、記憶部506に記憶された原本生体情報を、制御サーバ10を介して利用者が選択したサービス提供者のサービスサーバ20に送信する。また、通信制御部501は、複数のサービス提供者のなかから利用者が選択したサービス提供者であって、当該利用者の生体認証に成功したサービス提供者のサービスサーバ20から、直接的又は間接的に認証成功通知を受信する。
アカウント生成制御部502は、利用者によるアカウント生成を制御する手段である。アカウント生成制御部502は、利用者の操作に応じて、制御サーバ10が提供する所定のWEBページ等にアクセスする。
アカウント生成制御部502は、利用者の操作に応じて、当該WEBページに、ログイン情報、氏名、生年月日、連絡先等を入力する。
原本情報取得部503は、利用者の生体情報(原本生体情報)を取得する手段である。原本情報取得部503は、利用者の操作に応じて、原本生体情報(例えば、顔画像)を取得するためのGUI等を表示する。例えば、原本情報取得部503は、図16に示すようなGUIを用いて原本生体情報を取得する。
原本情報取得部503は、取得した原本生体情報(例えば、顔画像)を記憶部506に格納する。その際、原本情報取得部503は、取得した原本生体情報に暗号化、コード化等を施し、当該暗号化された原本生体情報を記憶部506に記憶してもよい。即ち、利用者が所持する端末40は、暗号化された原本生体情報を保持してもよい。暗号化された原本生体情報は、原本生体情報が制御サーバ10に送信される際に復号されてもよい。あるいは、暗号化された原本生体情報を復号するための情報(例えば、共通鍵)が端末40と制御サーバ10の間で共有され、制御サーバ10が暗号化された原本生体情報を復号してもよい。
なお、端末40は、原則として、利用者の原本生体情報(例えば、顔画像)を削除しない。即ち、端末40は、利用者からの明確な指示がなければ記憶部506に記憶された原本生体情報を削除しない。
サービス選択部504は、利用者による生体認証サービスの選択を可能とする手段である。サービス選択部504は、利用者の操作に応じて、制御サーバ10が提供するポータルサイトにログインする。サービス選択部504は、制御サーバ10が提供するGUIを用いて利用者が選択したサービス提供者の情報を制御サーバ10に送信する。
サービス選択部504は、制御サーバ10から原本提供要求を受信する。当該要求を受信すると、サービス選択部504は、記憶部506に記憶された原本生体情報を制御サーバ10に送信する。原本生体情報は、制御サーバ10を介して、利用者が選択したサービス提供者のサービスサーバ20に送信される。
認証履歴制御部505は、利用者の認証履歴に関する制御を実行する手段である。認証履歴制御部505は、制御サーバ10から受信する認証成功通知を処理する。認証履歴制御部505は、認証成功通知の受信に応じて、サービス提供者において成功した生体認証の履歴に関する制御を行う。
認証成功通知には、サービス提供者が成功した認証処理の詳細情報と、サービス提供者が生体認証に用いる認証情報の状態と、が含まれる。
認証履歴制御部505は、認証成功通知に含まれる認証処理の詳細情報及び認証情報の状態を認証履歴管理データベースに記憶する(図17参照)。認証履歴制御部505は、認証処理の詳細情報及び認証情報の状態を認証履歴管理データベースに記憶することで、利用者の生体認証に関する履歴を生成する。なお、図17に示す認証履歴管理データベースは例示であって、記憶する項目等を限定する趣旨ではない。
また、認証成功通知を受信すると、認証履歴制御部505は、利用者(端末40の所有者)の認証が行われた事実を当該利用者に通知する。例えば、認証履歴制御部505は、認証成功通知を受信するたびに、図18に示すようなポップアップ通知を用いて利用者の認証に関する情報を表示する。即ち、認証履歴制御部505は、認証成功通知を受信するたびに、認証処理の詳細情報及び認証情報の状態を含むメッセージを表示する。
あるいは、認証履歴制御部505は、利用者が所定の動作を行うと(例えば、認証履歴ボタンを押下すると)、認証履歴管理データベースに記憶された認証履歴の一覧を表示する(図19参照)。即ち、認証履歴制御部505は、利用者の所定の操作に応じて、認証履歴管理データベースに記憶された生体認証に関する履歴の表示を行う。
なお、認証履歴制御部505は、認証履歴の一覧表示を行う際、図19に示すように、認証処理の詳細情報を表示してもよいし、図20に示すように認証処理の詳細情報に加えて認証情報の状態を表示してもよい。
記憶部506は、端末40の動作に必要な情報を記憶する手段である。記憶部506は、生体認証に用いられる認証情報の原本となる原本生体情報を記憶する。なお、例えば、原本生体情報は顔画像であり、認証情報は顔画像から生成された特徴量である。
[システムの動作]
続いて、第1の実施形態に係る認証システムの動作について説明する。なお、アカウント生成等に関する動作の説明は省略する。図21は、第1の実施形態に係る認証システムの動作の一例を示すシーケンス図である。
続いて、第1の実施形態に係る認証システムの動作について説明する。なお、アカウント生成等に関する動作の説明は省略する。図21は、第1の実施形態に係る認証システムの動作の一例を示すシーケンス図である。
認証端末30から認証要求を受信すると、サービスサーバ20は、認証処理を実行する(ステップS21)。
被認証者の認証に成功すると、サービスサーバ20は、認証成功通知を制御サーバ10に送信する(ステップS22)。
制御サーバ10は、認証成功通知を認証成功者の端末40に転送する(ステップS23)。
端末40は、認証処理が行われた事実(認証に成功した事実及びその詳細)を利用者に通知する(認証の事実を通知;ステップS24)。
続いて、第1の実施形態に係る変形例について説明する。
<第1の実施形態に係る変形例1>
利用者は、所定のコードを用いてサービス提供者を選択してもよい。例えば、数多くのサービス提供者のなかから利用者が容易にサービス選択者を指定可能とする管理コードが使用されてもよい。例えば、制御サーバ10は、図10に示されたアイコンの一覧において、利用者が所定のアイコンを選択すると、管理コードの入力を求めるGUIを表示する。制御サーバ10は、利用者が入力した管理コードに対応するサービス提供者を当該利用者により選択されたサービス提供者として扱う。
利用者は、所定のコードを用いてサービス提供者を選択してもよい。例えば、数多くのサービス提供者のなかから利用者が容易にサービス選択者を指定可能とする管理コードが使用されてもよい。例えば、制御サーバ10は、図10に示されたアイコンの一覧において、利用者が所定のアイコンを選択すると、管理コードの入力を求めるGUIを表示する。制御サーバ10は、利用者が入力した管理コードに対応するサービス提供者を当該利用者により選択されたサービス提供者として扱う。
あるいは、制御サーバ10は、利用者が入力する管理コードをパスワードのように扱ってもよい。具体的には、利用者がサービス提供者を選択すると、制御サーバ10は、当該選択されたサービス提供者の管理コードの入力を利用者に求める。制御サーバ10は、利用者が入力した管理コードと、選択されたサービス提供者の予め定められた管理コードと、が一致した場合、利用者によるサービス提供者の選択を受け入れてもよい。換言すれば、制御サーバ10は、上記2つの管理コードが一致しない場合、利用者によるサービス提供者の選択を拒否する。
<第1の実施形態に係る変形例2>
上記実施形態では、利用者登録の際、サービス提供者(サービスサーバ20)は個人特定情報を用いて利用者を特定する場合について説明した。しかし、当該利用者の選択は、サービス提供者が利用者(顧客)を管理するID(以下、個別IDと表記する)を用いて行われてもよい。
上記実施形態では、利用者登録の際、サービス提供者(サービスサーバ20)は個人特定情報を用いて利用者を特定する場合について説明した。しかし、当該利用者の選択は、サービス提供者が利用者(顧客)を管理するID(以下、個別IDと表記する)を用いて行われてもよい。
具体的には、利用者がサービス提供者を選択すると、制御サーバ10は、当該利用者のシステムIDが埋め込まれたリダイレクト用URL(Uniform Resource Locator)を端末40に送信する。当該リダイレクト用URLは、利用者が選択したサービス提供者のポータルサイト(アカウント)へログインするためのURLである。
受信したリダイレクト用URLに従って、利用者がサービス提供者のログインページにログインすると、サービスサーバ20は、当該利用者の個別ID(ログインID)とリダイレクト用URLに埋め込まれたシステムIDを取得する。
サービスサーバ20は、取得した個別IDを用いて利用者管理データベースを検索し、対応するエントリ(利用者)を特定する。サービスサーバ20は、特定したエントリにシステムIDを記憶する。
このように、システムIDが埋め込まれたリダイレクト用URLが使用されて、利用者登録が実現されてもよい。
以上のように、第1の実施形態に係る認証システムは、利用者の端末40に格納された原本生体情報は、当該利用者が選択したサービス提供者のサービスサーバ20に提供される。サービスサーバ20は、当該利用者の原本生体情報から登録認証情報を生成し、当該生成した登録認証情報と業務情報を対応付けて記憶することで、利用者に生体認証を用いたサービスの提供を可能とする。利用者がサービス提供者から生体認証サービスを受けると、サービスサーバ20は、制御サーバ10を介して認証成功通知を利用者の端末40に送信する。認証成功通知の受信に応じて、端末40は、サービス提供者にて生体認証が行われた事実をポップアップ通知したり、過去の認証結果の一覧を表示したりする。利用者は、当該ポップアップ通知や認証履歴の一覧表示により、不正な生体認証が行われていないか検証できる。換言すれば、利用者は、ポップアップ通知や認証履歴の一覧表示により不正な生体認証を発見できる。
続いて、認証システムを構成する各装置のハードウェアについて説明する。図22は、制御サーバ10のハードウェア構成の一例を示す図である。
制御サーバ10は、情報処理装置(所謂、コンピュータ)により構成可能であり、図22に例示する構成を備える。例えば、制御サーバ10は、プロセッサ311、メモリ312、入出力インターフェイス313及び通信インターフェイス314等を備える。上記プロセッサ311等の構成要素は内部バス等により接続され、相互に通信可能に構成されている。
但し、図22に示す構成は、制御サーバ10のハードウェア構成を限定する趣旨ではない。制御サーバ10は、図示しないハードウェアを含んでもよいし、必要に応じて入出力インターフェイス313を備えていなくともよい。また、制御サーバ10に含まれるプロセッサ311等の数も図22の例示に限定する趣旨ではなく、例えば、複数のプロセッサ311が制御サーバ10に含まれていてもよい。
プロセッサ311は、例えば、CPU(Central Processing Unit)、MPU(Micro Processing Unit)、DSP(Digital Signal Processor)等のプログラマブルなデバイスである。あるいは、プロセッサ311は、FPGA(Field Programmable Gate Array)、ASIC(Application Specific Integrated Circuit)等のデバイスであってもよい。プロセッサ311は、オペレーティングシステム(OS;Operating System)を含む各種プログラムを実行する。
メモリ312は、RAM(Random Access Memory)、ROM(Read Only Memory)、HDD(Hard Disk Drive)、SSD(Solid State Drive)等である。メモリ312は、OSプログラム、アプリケーションプログラム、各種データを格納する。
入出力インターフェイス313は、図示しない表示装置や入力装置のインターフェイスである。表示装置は、例えば、液晶ディスプレイ等である。入力装置は、例えば、キーボードやマウス等のユーザ操作を受け付ける装置である。
通信インターフェイス314は、他の装置と通信を行う回路、モジュール等である。例えば、通信インターフェイス314は、NIC(Network Interface Card)等を備える。
制御サーバ10の機能は、各種処理モジュールにより実現される。当該処理モジュールは、例えば、メモリ312に格納されたプログラムをプロセッサ311が実行することで実現される。また、当該プログラムは、コンピュータが読み取り可能な記憶媒体に記録することができる。記憶媒体は、半導体メモリ、ハードディスク、磁気記録媒体、光記録媒体等の非トランジェント(non-transitory)なものとすることができる。即ち、本発明は、コンピュータプログラム製品として具現することも可能である。また、上記プログラムは、ネットワークを介してダウンロードするか、あるいは、プログラムを記憶した記憶媒体を用いて、更新することができる。さらに、上記処理モジュールは、半導体チップにより実現されてもよい。
なお、サービスサーバ20、認証端末30、端末40等も制御サーバ10と同様に情報処理装置により構成可能であり、その基本的なハードウェア構成は制御サーバ10と相違する点はないので説明を省略する。例えば、認証端末30は、被認証者を撮影するためのカメラ装置を備えていればよい。
情報処理装置である制御サーバ10は、コンピュータを搭載し、当該コンピュータにプログラムを実行させることで制御サーバ10の機能が実現できる。また、制御サーバ10は、当該プログラムにより制御サーバ10の制御方法を実行する。同様に、情報処理装置である端末40は、コンピュータを搭載し、当該コンピュータにプログラムを実行させることで端末40の機能が実現できる。また、端末40は、当該プログラムにより端末40の制御方法を実行する。
[変形例]
なお、上記実施形態にて説明した認証システムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
なお、上記実施形態にて説明した認証システムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
上記実施形態では、利用者によるサービス提供者の選択と、当該選択に伴う原本生体情報の提供(オプトイン)について説明した。制御サーバ10や端末40は、当該オプトインしたサービス提供者の情報を図10に示すように、サービス提供者のアイコンにチェックを入れることで利用者が識別可能としている。制御サーバ10及び端末40は、オプトインしたサービス提供者から登録認証情報を削除するオプトアウトを可能としてもよい。この場合、制御サーバ10は、図10において、利用者が選択済のサービス提供者(オプトインされたサービス提供者)を選択すると、当該選択されたサービス提供者のサービスサーバ20に対して、利用者のシステムIDを含む利用者登録解除要求を送信する。サービスサーバ20は、システムIDに対応する利用者の登録認証情報等を削除する。
サービスサーバ20(認証部304)は、業務情報を用いたサービス提供可否の判定に失敗した場合には、当該失敗の事実を被認証者(照合処理により特定された被認証者)に通知してもよい。その際、認証部304は、認証に失敗した原因も併せて被認証者に通知してもよい。例えば、認証部304は、「オフィスに入場する権限がない」、「クレジットカードによる決済に失敗した」、「チケットが無効」等の理由を被認証者に通知してもよい。この場合、認証部304は、被認証者のシステムIDと認証失敗の理由を含む認証失敗通知を制御サーバ10に送信する。制御サーバ10は、システムIDを用いて被認証者の端末40を特定し、当該特定された端末40に認証失敗通知を送信する。認証失敗通知を受信すると、端末40は、利用者に認証に失敗した理由を通知する。例えば、端末40は、図23に示すようなポップアップ通知により認証に失敗した理由を利用者に通知する。あるいは、端末40は、認証失敗通知を使って認証履歴を生成してもよい。この場合、端末40は、利用者の操作に応じて、図24に示すように認証失敗時の原因を表示してもよい。
上記実施形態では、人の「顔」を生体情報の例にとり認証システムの動作を説明した。しかし、本願開示の認証システムは、他の種類の生体情報を用いることもできる。例えば、指紋、声紋、静脈、網膜、瞳の虹彩の模様(パターン)といった個人に固有の身体的特徴を備えるデータが用いられてもよい。即ち、利用者の生体情報は、利用者の身体的特徴を情報として含むものであればよい。
利用者の端末40は、制御サーバ10から原本提供要求を受信するたびに、原本生体情報(例えば、顔画像)をサービス提供者に送信することについての同意を利用者から取得してもよい。具体的には、原本提供要求を受信すると、端末40のサービス選択部504は、GUI等を用いて原本生体情報(例えば、顔画像)の提供可否を取得する。サービス選択部504は、原本生体情報の提供に関する利用者の同意が得られると、内部に記憶された原本生体情報を制御サーバ10に送信する。
上記実施形態では、制御サーバ10の内部にアカウント管理データベースが構成される場合について説明したが、当該データベースは外部のデータベースサーバ等に構築されてもよい。即ち、制御サーバ10の一部の機能は別のサーバに実装されていてもよい。より具体的には、上記説明した「サービス選択制御部(サービス選択制御手段)」等がシステムに含まれるいずれかの装置に実装されていればよい。
各装置(制御サーバ10、サービスサーバ20、認証端末30)間のデータ送受信の形態は特に限定されないが、これら装置間で送受信されるデータは暗号化されていてもよい。これらの装置間では、生体情報等が送受信され、これらの情報を適切に保護するためには、暗号化されたデータが送受信されることが望ましい。
上記説明で用いた流れ図(フローチャート、シーケンス図)では、複数の工程(処理)が順番に記載されているが、実施形態で実行される工程の実行順序は、その記載の順番に制限されない。実施形態では、例えば各処理を並行して実行する等、図示される工程の順番を内容的に支障のない範囲で変更することができる。
上記の実施形態は本願開示の理解を容易にするために詳細に説明したものであり、上記説明したすべての構成が必要であることを意図したものではない。また、複数の実施形態について説明した場合には、各実施形態は単独で用いてもよいし、組み合わせて用いてもよい。例えば、実施形態の構成の一部を他の実施形態の構成に置き換えることや、実施形態の構成に他の実施形態の構成を加えることも可能である。さらに、実施形態の構成の一部について他の構成の追加、削除、置換が可能である。
上記の説明により、本発明の産業上の利用可能性は明らかであるが、本発明は、生体認証サービスを提供する情報処理システムなどに好適に適用可能である。
上記の実施形態の一部又は全部は、以下の付記のようにも記載され得るが、以下には限られない。
[付記1]
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する、受信手段と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、
を備える、端末。
[付記2]
前記認証成功通知には、前記サービス提供者が成功した認証処理の詳細情報と、前記サービス提供者が生体認証に用いる認証情報の状態と、が含まれ、
前記認証履歴制御手段は、前記認証処理の詳細情報及び前記認証情報の状態を記憶することで、前記利用者の生体認証に関する履歴を生成する、付記1に記載の端末。
[付記3]
前記認証履歴制御手段は、前記認証成功通知を受信するたびに、前記認証処理の詳細情報及び前記認証情報の状態を含むメッセージを表示する、付記2に記載の端末。
[付記4]
前記認証履歴制御手段は、前記利用者の所定の操作に応じて、前記記憶された生体認証に関する履歴の表示を行う、付記3に記載の端末。
[付記5]
前記生体認証に用いられる前記認証情報の原本となる原本生体情報を記憶する、記憶手段と、
前記複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバからの要求に応じて、前記記憶された原本生体情報を、前記制御サーバを介して前記利用者が選択したサービス提供者のサービスサーバに送信する、送信手段と、
をさらに備える、付記2乃至4のいずれか一項に記載の端末。
[付記6]
前記原本生体情報は顔画像であり、前記認証情報は前記顔画像から生成された特徴量である、付記5に記載の端末。
[付記7]
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバと、
前記利用者が所持する端末と、
を含み、
前記端末は、
前記サービスサーバから、認証成功通知を受信する、受信手段と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、
を備える、システム。
[付記8]
前記複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバをさらに含み、
前記受信手段は、前記制御サーバを介して、前記認証成功通知を受信する、付記7に記載のシステム。
[付記9]
端末において、
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信し、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、端末の制御方法。
[付記10]
端末に搭載されたコンピュータに、
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する処理と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
[付記1]
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する、受信手段と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、
を備える、端末。
[付記2]
前記認証成功通知には、前記サービス提供者が成功した認証処理の詳細情報と、前記サービス提供者が生体認証に用いる認証情報の状態と、が含まれ、
前記認証履歴制御手段は、前記認証処理の詳細情報及び前記認証情報の状態を記憶することで、前記利用者の生体認証に関する履歴を生成する、付記1に記載の端末。
[付記3]
前記認証履歴制御手段は、前記認証成功通知を受信するたびに、前記認証処理の詳細情報及び前記認証情報の状態を含むメッセージを表示する、付記2に記載の端末。
[付記4]
前記認証履歴制御手段は、前記利用者の所定の操作に応じて、前記記憶された生体認証に関する履歴の表示を行う、付記3に記載の端末。
[付記5]
前記生体認証に用いられる前記認証情報の原本となる原本生体情報を記憶する、記憶手段と、
前記複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバからの要求に応じて、前記記憶された原本生体情報を、前記制御サーバを介して前記利用者が選択したサービス提供者のサービスサーバに送信する、送信手段と、
をさらに備える、付記2乃至4のいずれか一項に記載の端末。
[付記6]
前記原本生体情報は顔画像であり、前記認証情報は前記顔画像から生成された特徴量である、付記5に記載の端末。
[付記7]
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバと、
前記利用者が所持する端末と、
を含み、
前記端末は、
前記サービスサーバから、認証成功通知を受信する、受信手段と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、
を備える、システム。
[付記8]
前記複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバをさらに含み、
前記受信手段は、前記制御サーバを介して、前記認証成功通知を受信する、付記7に記載のシステム。
[付記9]
端末において、
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信し、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、端末の制御方法。
[付記10]
端末に搭載されたコンピュータに、
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する処理と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
なお、引用した上記の先行技術文献の各開示は、本書に引用をもって繰り込むものとする。以上、本発明の実施形態を説明したが、本発明はこれらの実施形態に限定されるものではない。これらの実施形態は例示にすぎないということ、及び、本発明のスコープ及び精神から逸脱することなく様々な変形が可能であるということは、当業者に理解されるであろう。即ち、本発明は、請求の範囲を含む全開示、技術的思想にしたがって当業者であればなし得る各種変形、修正を含むことは勿論である。
10 制御サーバ
20 サービスサーバ
30 認証端末
40 端末
100 端末
101 受信手段
102 認証履歴制御手段
201 通信制御部
202 アカウント管理部
203 事業者管理部
204 サービス選択制御部
205 利用者登録制御部
206 記憶部
301 通信制御部
302 業務情報管理部
303 利用者登録制御部
304 認証部
305 記憶部
311 プロセッサ
312 メモリ
313 入出力インターフェイス
314 通信インターフェイス
401 通信制御部
402 提供サービス制御部
403 認証要求部
404 記憶部
501 通信制御部
502 アカウント生成制御部
503 原本情報取得部
504 サービス選択部
505 認証履歴制御部
506 記憶部
20 サービスサーバ
30 認証端末
40 端末
100 端末
101 受信手段
102 認証履歴制御手段
201 通信制御部
202 アカウント管理部
203 事業者管理部
204 サービス選択制御部
205 利用者登録制御部
206 記憶部
301 通信制御部
302 業務情報管理部
303 利用者登録制御部
304 認証部
305 記憶部
311 プロセッサ
312 メモリ
313 入出力インターフェイス
314 通信インターフェイス
401 通信制御部
402 提供サービス制御部
403 認証要求部
404 記憶部
501 通信制御部
502 アカウント生成制御部
503 原本情報取得部
504 サービス選択部
505 認証履歴制御部
506 記憶部
Claims (10)
- 複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する、受信手段と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、
を備える、端末。 - 前記認証成功通知には、前記サービス提供者が成功した認証処理の詳細情報と、前記サービス提供者が生体認証に用いる認証情報の状態と、が含まれ、
前記認証履歴制御手段は、前記認証処理の詳細情報及び前記認証情報の状態を記憶することで、前記利用者の生体認証に関する履歴を生成する、請求項1に記載の端末。 - 前記認証履歴制御手段は、前記認証成功通知を受信するたびに、前記認証処理の詳細情報及び前記認証情報の状態を含むメッセージを表示する、請求項2に記載の端末。
- 前記認証履歴制御手段は、前記利用者の所定の操作に応じて、前記記憶された生体認証に関する履歴の表示を行う、請求項3に記載の端末。
- 前記生体認証に用いられる前記認証情報の原本となる原本生体情報を記憶する、記憶手段と、
前記複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバからの要求に応じて、前記記憶された原本生体情報を、前記制御サーバを介して前記利用者が選択したサービス提供者のサービスサーバに送信する、送信手段と、
をさらに備える、請求項2乃至4のいずれか一項に記載の端末。 - 前記原本生体情報は顔画像であり、前記認証情報は前記顔画像から生成された特徴量である、請求項5に記載の端末。
- 複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバと、
前記利用者が所持する端末と、
を含み、
前記端末は、
前記サービスサーバから、認証成功通知を受信する、受信手段と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、認証履歴制御手段と、
を備える、システム。 - 前記複数のサービス提供者それぞれの生体認証に関する管理を行う、制御サーバをさらに含み、
前記受信手段は、前記制御サーバを介して、前記認証成功通知を受信する、請求項7に記載のシステム。 - 端末において、
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信し、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う、端末の制御方法。 - 端末に搭載されたコンピュータに、
複数のサービス提供者のなかから利用者が選択したサービス提供者であって、前記利用者の生体認証に成功したサービス提供者のサービスサーバから、認証成功通知を受信する処理と、
前記認証成功通知の受信に応じて、前記サービス提供者において成功した生体認証の履歴に関する制御を行う処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2022/045180 WO2024122002A1 (ja) | 2022-12-07 | 2022-12-07 | 端末、システム、端末の制御方法及び記憶媒体 |
| JP2024521816A JP7544305B1 (ja) | 2022-12-07 | 2022-12-07 | 端末、システム、端末の制御方法及びプログラム |
| JP2024137503A JP7711820B2 (ja) | 2022-12-07 | 2024-08-19 | プログラム、サービスサーバ、端末の制御方法及びサービスサーバの制御方法 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2022/045180 WO2024122002A1 (ja) | 2022-12-07 | 2022-12-07 | 端末、システム、端末の制御方法及び記憶媒体 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024122002A1 true WO2024122002A1 (ja) | 2024-06-13 |
Family
ID=91378812
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2022/045180 Ceased WO2024122002A1 (ja) | 2022-12-07 | 2022-12-07 | 端末、システム、端末の制御方法及び記憶媒体 |
Country Status (2)
| Country | Link |
|---|---|
| JP (2) | JP7544305B1 (ja) |
| WO (1) | WO2024122002A1 (ja) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2005284701A (ja) * | 2004-03-30 | 2005-10-13 | Matsushita Electric Ind Co Ltd | 認証履歴管理装置、端末装置及び端末装置のプログラム |
| JP2010049568A (ja) * | 2008-08-22 | 2010-03-04 | Kpe Inc | 処理実行装置、アプリケーションプログラム及びダウンロードサーバ装置 |
| JP5950318B1 (ja) * | 2015-09-03 | 2016-07-13 | ブレイニー株式会社 | 多機能カード、カード決済端末、及びカード決済システム |
| WO2021214969A1 (ja) * | 2020-04-24 | 2021-10-28 | 日本電気株式会社 | 認証システム、端末、端末の制御方法及び記憶媒体 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2009217598A (ja) | 2008-03-11 | 2009-09-24 | Hitachi Information & Control Solutions Ltd | 個人認証装置および個人認証方法 |
| JP5121681B2 (ja) | 2008-04-30 | 2013-01-16 | 株式会社日立製作所 | 生体認証システム、認証クライアント端末、及び生体認証方法 |
| JP2015111329A (ja) | 2013-11-06 | 2015-06-18 | 株式会社あいびし | ネットワークサービス提供システム、ネットワークサービス提供方法、及びプログラム |
| WO2022092266A1 (ja) | 2020-11-02 | 2022-05-05 | 株式会社メディア4u | 情報処理装置 |
-
2022
- 2022-12-07 JP JP2024521816A patent/JP7544305B1/ja active Active
- 2022-12-07 WO PCT/JP2022/045180 patent/WO2024122002A1/ja not_active Ceased
-
2024
- 2024-08-19 JP JP2024137503A patent/JP7711820B2/ja active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2005284701A (ja) * | 2004-03-30 | 2005-10-13 | Matsushita Electric Ind Co Ltd | 認証履歴管理装置、端末装置及び端末装置のプログラム |
| JP2010049568A (ja) * | 2008-08-22 | 2010-03-04 | Kpe Inc | 処理実行装置、アプリケーションプログラム及びダウンロードサーバ装置 |
| JP5950318B1 (ja) * | 2015-09-03 | 2016-07-13 | ブレイニー株式会社 | 多機能カード、カード決済端末、及びカード決済システム |
| WO2021214969A1 (ja) * | 2020-04-24 | 2021-10-28 | 日本電気株式会社 | 認証システム、端末、端末の制御方法及び記憶媒体 |
Also Published As
| Publication number | Publication date |
|---|---|
| JP7711820B2 (ja) | 2025-07-23 |
| JPWO2024122002A1 (ja) | 2024-06-13 |
| JP7544305B1 (ja) | 2024-09-03 |
| JP2024149810A (ja) | 2024-10-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7188660B1 (ja) | システム、制御サーバ、制御サーバの制御方法、方法及びプログラム | |
| JP7794257B2 (ja) | 端末、システム、端末の制御方法及びプログラム | |
| JP7409411B2 (ja) | サーバ、システム、サーバの制御方法、プログラム、端末、及び端末の制御方法 | |
| JP2024028612A (ja) | 管理サーバ、情報提供方法及びコンピュータプログラム | |
| JP7827188B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びプログラム | |
| JP2025088095A (ja) | 端末、システム、端末の制御方法及びプログラム | |
| JP7218840B1 (ja) | システム、方法、サーバ、サーバの制御方法及びプログラム | |
| JP7711820B2 (ja) | プログラム、サービスサーバ、端末の制御方法及びサービスサーバの制御方法 | |
| JP7589864B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びプログラム | |
| JP7643643B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びプログラム | |
| JP7589865B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びプログラム | |
| JP7589863B2 (ja) | サーバ装置、システム、サーバ装置の制御方法及びプログラム | |
| JP7589829B2 (ja) | システム、認証端末、認証端末の制御方法及びプログラム | |
| WO2022185542A1 (ja) | サーバ装置、端末、システム、サーバの制御方法及び記憶媒体 | |
| WO2025027828A1 (ja) | サーバ装置、サーバ装置の制御方法、記憶媒体及びシステム | |
| JP7609166B2 (ja) | 認証システム、端末、管理サーバ、個人情報提供方法及びプログラム | |
| JP7601264B2 (ja) | システム、サーバ装置、サーバ装置の制御方法及びプログラム | |
| WO2024057457A1 (ja) | 認証端末、システム、認証端末の制御方法及び記憶媒体 | |
| WO2025262768A1 (ja) | サーバ装置、システム、サーバ装置の制御方法及び記憶媒体 | |
| WO2025004221A1 (ja) | サーバ装置、サーバ装置の制御方法及び記憶媒体 | |
| JP2025030345A (ja) | サーバ装置、サーバ装置の制御方法及びプログラム | |
| JP2025110643A (ja) | サーバ装置、サーバ装置の制御方法及びプログラム | |
| WO2025009106A1 (ja) | サーバ装置、サーバ装置の制御方法及び記憶媒体 | |
| WO2024003985A1 (ja) | サーバ装置、システム、サーバ装置の制御方法及び記憶媒体 | |
| JP2023093699A (ja) | 管理サーバ、システム、方法及びコンピュータプログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024521816 Country of ref document: JP |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22967851 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22967851 Country of ref document: EP Kind code of ref document: A1 |