WO2014207821A1 - 情報処理装置、端末装置、情報処理プログラム及び情報処理方法 - Google Patents
情報処理装置、端末装置、情報処理プログラム及び情報処理方法 Download PDFInfo
- Publication number
- WO2014207821A1 WO2014207821A1 PCT/JP2013/067361 JP2013067361W WO2014207821A1 WO 2014207821 A1 WO2014207821 A1 WO 2014207821A1 JP 2013067361 W JP2013067361 W JP 2013067361W WO 2014207821 A1 WO2014207821 A1 WO 2014207821A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- image data
- information
- request
- authentication
- image
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/36—User authentication by graphic or iconic representation
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
Definitions
- the present invention relates to an information processing device, a terminal device, an information processing program, and an information processing method.
- Patent Document 1 Various technologies (for example, see Patent Document 1) have been developed as techniques for personal authentication. For this reason, it is possible to perform personal authentication that is difficult to impersonate when updating the Web page as described above. However, if the existing personal authentication that is difficult to impersonate is adopted, the Web page cannot be updated by a simple operation of inputting a user ID and a password.
- the problem of the disclosed technique is to provide a technique capable of confirming that a requester who requests processing of image data via a network is the person himself without increasing the load on the user.
- An information processing apparatus is An information storage unit that stores the feature information representing the feature of the authentication image data in association with the user identification information; With a control unit, The controller is The image data, user identification information, and position presentation information indicating the position of the authentication image data embedded in the image data are obtained from a requester who requests processing for certain image data via the network. , Image data at a position indicated by the acquired position presentation information is extracted from the acquired image data, and the information storage unit associates the characteristic information indicating the characteristics of the extracted image data with the acquired user identification information in the information storage unit. By comparing with the stored feature information, it is determined whether the requester is the user identified by the acquired user identification information, When it is determined that the requester is the user identified by the acquired user identification information, the processing requested by the requester is executed on the acquired image data.
- the disclosed technology it is possible to provide a technology capable of confirming that the requester who requests processing of image data via the network is the person himself without increasing the load on the user.
- FIG. 1 is an explanatory diagram of the configuration and usage of the information processing apparatus according to the first embodiment.
- FIG. 2 is an explanatory diagram of a functional block configuration example of the information processing apparatus according to the first embodiment and a functional block configuration example of the user terminal.
- FIG. 3 is a hardware configuration diagram of a computer that can be used as each component of the information processing apparatus.
- FIG. 4 is a hardware configuration diagram of a mobile phone that can be used as a user terminal.
- FIG. 5 is a flowchart of an example of the personal introduction page opening request process.
- FIG. 6 is an explanatory diagram of a profile picture shooting screen displayed during the personal introduction page opening request process.
- FIG. 1 is an explanatory diagram of the configuration and usage of the information processing apparatus according to the first embodiment.
- FIG. 2 is an explanatory diagram of a functional block configuration example of the information processing apparatus according to the first embodiment and a functional block configuration example of the user terminal.
- FIG. 3 is a hardware configuration diagram of a computer that can
- FIG. 7 is an explanatory diagram of the position and size of the authentication image area whose position is specified by the area position specifying process with respect to the profile picture.
- FIG. 8 is a flowchart of an example of the opening request response process.
- FIG. 9 is a flowchart of an example of the feature information registration request response process.
- FIG. 10 is a flowchart of an example of the image / video registration request process.
- FIG. 11 is a flowchart of an example of the registration request response process.
- FIG. 12 is a flowchart of an example of the authentication request response process.
- FIG. 13 is a sequence diagram among the user terminal A, the authentication management server, the image determination server, and the Web service server when the personal introduction page is opened.
- FIG. 13 is a sequence diagram among the user terminal A, the authentication management server, the image determination server, and the Web service server when the personal introduction page is opened.
- FIG. 14 is a sequence diagram among the user terminal A, the authentication management server, the image determination server, and the Web service server at the time of registering the image data on the personal introduction page.
- FIG. 15 is a sequence diagram among the user terminal B, the authentication management server, the image discrimination server, and the Web service server when image data is illegally registered on the personal introduction page.
- FIG. 16 is an explanatory diagram of a functional block configuration example of the information processing apparatus and a user terminal functional block configuration example according to the second embodiment.
- FIG. 17 is a flowchart of a registration request response process performed by the authentication management server of the information processing apparatus according to the second embodiment.
- FIG. 18 is an explanatory diagram of an example algorithm for restoring the authentication image area.
- FIG. 19 is an explanatory diagram of a functional block configuration example of the information processing apparatus and a user terminal functional block configuration example according to the third embodiment.
- FIG. 20 is a flowchart of an example of the opening request response process executed by the user terminal combined with the information processing apparatus according to the third embodiment.
- FIG. 21 is a sequence diagram among the user terminal, the authentication management server, the image determination server, and the Web service server when the personal introduction page is opened.
- FIG. 22 is a sequence diagram among the user terminal, the authentication management server, the image discrimination server, and the Web service server when registering the moving image data on the personal introduction page.
- FIG. 1 is an explanatory diagram of the configuration and usage of the information processing apparatus 1 according to the first embodiment.
- FIG. 2 is an explanatory diagram of a functional block configuration example of the user terminal 40 and a functional block configuration example of the information processing apparatus 1.
- 3 is a hardware configuration diagram of a computer that can be used as the authentication management server 10 and the like, and
- FIG. 4 is a hardware configuration diagram of a mobile phone that can be used as the user terminal 40.
- the information processing apparatus 1 is an apparatus for providing a Web service that allows a user to easily open a personal introduction page (without managing the server by himself).
- the user is a person who has acquired a user ID (IDentification) from the information processing apparatus 1 by performing a user registration procedure.
- a user's personal introduction page is a Web page on which the profile picture of the user is posted, and the user registers (adds) image data or video data or changes the profile picture. This is a Web page that can be used.
- the information processing apparatus 1 includes an authentication management server 10, an image determination server 20, and a Web service server 30 connected to the Internet.
- the authentication management server 10 is a device in which an authentication management server program 15 is installed together with an OS (Operating System) or the like on a computer capable of communication via the Internet.
- the image discrimination server 20 is a device in which an image discrimination server program 25 is installed together with an OS or the like on a computer capable of communication via the Internet.
- the Web service server 30 is an apparatus in which a Web service server program 35 is installed together with an OS or the like on a computer capable of communication via the Internet.
- the authentication management server program 15 and the like are installed on the computer by reading from a portable recording medium such as a CD-ROM (Compact Disc Read-Only Memory) or transferring from a storage device of another computer. .
- the authentication management server 10 executes, for example, a user management DB 11, an authentication processing unit 12, an opening request response unit 13, and a request response unit 14 by the CPU executing an authentication management server program 15. It operates as a device equipped with.
- the image discrimination server 20 operates as an apparatus including, for example, a feature information management DB 21, a feature information registration unit 22, and an image discrimination unit 23 when the CPU executes the image discrimination server program 25.
- the Web service server 30 operates as an apparatus including the personal introduction page management DB 31, the opening processing unit 32, and the update processing unit 33 when the CPU executes the Web service server program 35.
- a computer 50 having a hardware configuration as shown in FIG. 3 is used as the computer for each server.
- the serial port 52, the parallel port 53, and the CF (Compact Flash) interface card 59 provided in the computer 50 are interfaces used for program correction and various settings.
- the flash memory 55 is used for storing an OS, a program for each server (such as the authentication management server program 15) and a setting file, and a memory used as an extended memory area.
- the storage 56 is an HDD used for storing various data.
- the communication card 58 is an interface card for performing communication via the Internet, and the real-time clock 60 is an integrated circuit that keeps the current time even when the computer 50 is turned off.
- the RAM 54 is a memory used as a work area for various processes, and the chip set 57 is a circuit that manages the data transfer between the units in the computer 50.
- the CPU 51 is a unit that operates as the various functional blocks described above by executing a program (such as the authentication management server program 15) on the flash memory 55.
- the user terminal 40 (FIG. 1) is a terminal device used when a user requests the information processing apparatus 1 to open or update a personal introduction page.
- An image data registration program 45 is installed in the user terminal 40 of each user.
- the image data registration program 45 is a kind of Web client.
- the image data registration program 45 includes a terminal device for which IMEI (International Mobile Equipment Identity) is set and a terminal device for which IMEI is not set.
- the image data registration program 45 includes a mobile phone or data communication terminal (hereinafter referred to as a mobile phone) for which IMEI is set, and a terminal device (hereinafter referred to as a PC) that does not have a telephone function. (Indicated as Personal Computer)).
- Each type of image data registration program 45 is provided to the user by downloading from a Web server (for example, the Web service server 30) or a portable recording medium such as a CD-ROM (Compact-Disc-Read-Only Memory). .
- a Web server for example, the Web service server 30
- a portable recording medium such as a CD-ROM (Compact-Disc-Read-Only Memory).
- a mobile phone used as the user terminal 40 by installing the image data registration program 45 is usually a mobile phone with a built-in digital camera.
- FIG. 4 shows a hardware configuration example of such a mobile phone.
- a WiFi (Wireless Fidelity) circuit 81 included in the mobile phone 80 is a communication circuit for a wireless LAN.
- the WiFi circuit 81 is normally used for accessing the information processing apparatus 1.
- the 3G / LTE (3rd. Generation / Long Term Evolution) circuit 82 is a communication circuit for packet communication (for telephone).
- a microphone (“microphone”) 88 is a device that converts sound into an analog electrical signal
- a loudspeaker (“speaker”) 90 is a device that converts an analog electrical signal into sound.
- the sound chip 89 is a circuit that performs processing for converting an analog signal output from the microphone 88 into a digital signal, and processing for converting a digital signal input from the chipset 87 side into an analog signal and supplying the analog signal to the loudspeaker 90. is there.
- the timer 92 is a so-called watch dog timer.
- the liquid crystal display 86 is a display device for various information.
- the input device 84 is a device for inputting information to the mobile phone 80.
- the input device 84 includes a push button switch provided on the casing of the mobile phone 80 and a transparent touch panel disposed on the liquid crystal display 86.
- the storage 83 is a unit for storing various information.
- the storage 83 includes a flash memory (ROM: “Read Only Memory” in FIG. 2) in which various programs and data are recorded, and a RAM (Random Access Memory) used as a temporary storage area for programs and data.
- ROM Read Only Memory
- RAM Random Access Memory
- Both the two cameras 85 in the mobile phone 80 are digital cameras that generate image data representing an optical image (photographing result).
- One camera 85 (what is called an in-camera or a front camera) is attached to the casing of the mobile phone 80 so that an operator looking at the liquid crystal display 86 can be photographed.
- the other camera 85 (what is called an out camera or a main camera) is attached to the casing of the mobile phone 80 so as to capture the reverse direction.
- the output of each camera 85 is also used to generate moving image data.
- the chip set 87 is a circuit that manages data transfer between devices in the mobile phone 80.
- the graphic accelerator in the chip set 87 is a circuit that performs processing for displaying a desired image on the liquid crystal display 86 instead of the CPU 91.
- the CPU 91 is a unit that reads various programs from the flash memory onto the RAM and executes them.
- the image data registration program 45 (for mobile phone) is stored in the flash memory (ROM) of the storage 83. Then, the CPU 91 in the user terminal 40 (mobile phone 80) reads and executes the image data registration program 45 on the RAM of the storage 83 when a predetermined operation is performed on the input device 84.
- the image data registration program 45 (for PC) is stored in an HDD (Hard Disk Drive) or SDD (Solid State Drive) in the PC. Then, the CPU in the user terminal 40 (PC) reads the image data registration program 45 onto the RAM and executes it when the execution of the image data registration program 45 is instructed by operation of the keyboard or mouse.
- HDD Hard Disk Drive
- SDD Solid State Drive
- the user terminal 40 on which the CPU executes the image data registration program 45 operates as an apparatus including, for example, an authentication image storage unit 41 and a request transmission unit 42, as shown in FIG.
- image / moving image data refers to image data or moving image data.
- the profile photo data is image data of a photo posted as a profile photo on the personal introduction page.
- the authentication image storage unit 41 included in the user terminal 40 is a storage unit (storage area) for storing authentication image data that is image data of an authentication image.
- the authentication image is an image of a default size used for personal authentication.
- the CPU (for example, CPU 91) of the user terminal 40 prepares an authentication image storage unit 41 that stores nothing in the user terminal 40 when the image data registration program 45 is executed for the first time. Then, the CPU stores the authentication image data in the authentication image storage unit 41 when the personal introduction page for the user of the user terminal 40 is opened.
- the user terminal 40 which is the mobile phone 80 (FIG. 4) a part of the storage area of the flash memory (ROM) in the storage 83 is used as the authentication image storage unit 41.
- ROM flash memory
- the user terminal 40 that is a PC a part of the storage area of the HDD or SDD is used as the authentication image storage unit 41.
- the request transmission unit 42 is a unit (details will be described later) that acquires various types of information in an interactive manner from the operator of the user terminal 40, generates various types of requests based on the acquired information, and transmits them to the authentication management server 10. is there.
- the personal introduction page management DB 31 in the Web service server 30 stores information (URL (Uniform Resource Locator), establishment date, etc.) about each established personal introduction page, and the user ID of the owner (establisher) of each individual introduction page. It is a database for storing in association with.
- URL Uniform Resource Locator
- the opening processing unit 32 is a unit (functional block) that opens a personal introduction page for each user and publishes it on the Internet.
- the establishment processing unit 32 receives an establishment request including the user ID, the image data of the profile picture, and the text information from the authentication management server 10, the establishment processing unit 32 establishes a personal introduction page for the user identified by the user ID.
- the opening processing unit 32 also performs processing for storing the URL of the opened personal introduction page in the personal introduction page management DB 31 in a form associated with the user ID. Then, the opening processing unit 32 that has completed the series of processing transmits a completion notification to the authentication management server 10.
- the update processing unit 33 in the Web service server 30 is a unit in charge of processing for updating the contents of each user's personal introduction page.
- the update processing unit 33 receives a registration request including at least a user ID and image / video data from the authentication management server 10.
- the update processing unit 33 that has received the registration request refers to the personal introduction page management DB 31 to identify the personal introduction page for the user identified by the user ID in the registration request.
- the update processing unit 33 registers (adds) the received image / moving image data as an element of the registration request in the specified personal introduction page.
- the update processing unit 33 also performs processing for adding the text information to the personal introduction page.
- the update processing unit 33 that has completed the registration of the image / moving image data transmits a completion notification to the authentication management server 10.
- the update processing unit 33 also receives a profile photo change request (hereinafter also referred to as a change request) including at least a user ID and profile photo data (profile photo image data) from the authentication management server 10.
- a profile photo change request (hereinafter also referred to as a change request) including at least a user ID and profile photo data (profile photo image data) from the authentication management server 10.
- the update processing unit 33 refers to the personal introduction page management DB 31 to specify the personal introduction page for the user identified by the user ID in the change request.
- the update processing unit 33 changes the profile photo data of the specified personal introduction page to the profile photo data received as an element of the registration request.
- the update processing unit 33 also performs a process of changing the text information posted together with the profile photo to the text information being requested to be changed.
- the update processing unit 33 that has finished changing the profile photo data and the like transmits a completion notification to the authentication management server 10.
- the user management DB 11 in the authentication management server 10 stores the user ID and password of each user together with the personal information (first name, last name, address, etc.) of each user and information on services provided to each user. It is a database.
- the authentication processing unit 12 is a unit that performs personal authentication using a user ID and a password.
- a login request including login information (user ID and password) is transmitted from the user terminal 40 of each user to the authentication processing unit 12.
- the authentication processing unit 12 determines whether or not the same login information as the login information included in the login request is registered in the user management DB 11. Then, when the same login information as the received login information is registered in the user management DB 11, the authentication processing unit 12 displays information indicating that the login is completed (hereinafter referred to as a login completion notification) in the user terminal. Return to 40. Further, when the same login information as the received login information is not registered in the user management DB 11, the authentication processing unit 12 returns information indicating that the login has failed to the user terminal 40.
- session management is started. That is, a session tracking parameter is included in each piece of information transmitted from the user terminal 40, and the sender of information is specified on the authentication management server 10 side based on the session tracking parameter.
- the authentication processing unit 12 also has a function of accepting user registration. Briefly describing the function, the authentication processing unit 12 determines a user ID to be given to a requester of user registration (an operator of the user terminal 40) and notifies the requester at the time of user registration. In addition, the authentication processing unit 12 causes the requester to input personal information (such as a name) and a password through various Web pages. When the information necessary for user registration can be acquired, the authentication processing unit 12 registers the information in the user information DB 11 as information on the new user together with the user ID notified to the requester. Then, the authentication processing unit 12 transmits information indicating that the user registration is completed to the user terminal 40.
- the authentication processing unit 12 determines a user ID to be given to a requester of user registration (an operator of the user terminal 40) and notifies the requester at the time of user registration. In addition, the authentication processing unit 12 causes the requester to input personal information (such as a name) and a password through various Web pages. When the information necessary for user registration can
- the feature information management DB 21 in the image discrimination server 20 is a database for storing feature information (details will be described later) related to each user's authentication image in association with the user ID of each user.
- the opening request response unit 13 of the authentication management server 10 is a unit (function) that processes the opening request from the user terminal 40 in cooperation with the feature information registration unit 22 of the image discrimination server 20 and the opening processing unit 32 of the Web service server 30. Block). Further, the request response unit 14 of the authentication management server 10 cooperates with the image determination unit 23 of the image determination server 20 and the update processing unit 33 of the Web service server 30 to issue a registration request and a profile photo change request from the user terminal 40. The unit to process. The opening request, the registration request, and the profile picture change request from the user terminal 40 are converted into a request with the same name for the Web service server 30 by the authentication management server 10 (the opening request response unit 13 and the request response unit 14). It is a request.
- an opening request processing procedure by the opening request response unit 13, the feature information registration unit 22, and the opening processing unit 32 will be described together with an opening request transmission procedure by the user terminal 40 (request transmitting unit 42).
- a login page for logging in to the image processing apparatus 1 is displayed on the display (liquid crystal display 86 or the like). More specifically, the request transmission unit 42 acquires the login page source data from the image processing apparatus 1 by transmitting a predetermined request on the Internet. Then, the request transmission unit 42 displays a login page on the display by performing drawing based on the acquired source data.
- the operator of the user terminal 40 logs in to the image processing apparatus 1 by inputting his / her user ID and password on the login page. If the operator has not completed user registration, the operator performs user registration through a series of operations starting with a link operation to a user registration page provided on the login page, and then the image processing apparatus 1 Log in to
- the request transmission unit 42 determines whether the authentication image data is stored in the authentication image storage unit 41 when the login of the operator is completed (that is, when the above-described login completion notification is received). As already described, the authentication image data is not stored in the authentication image storage unit 41 in the user terminal 40 of the user who has not yet opened the personal introduction page. Therefore, when the authentication image data is not stored in the authentication image storage unit 41, the request transmission unit 42 requests the personal introduction page to be opened in the image processing apparatus 1 for the personal introduction page for the operator of the own terminal. Start processing.
- the personal introduction page opening request process executed by the request transmitter 42 is, for example, a process shown in FIG.
- the request transmission unit 42 that has started this personal introduction page opening request processing first performs profile picture data acquisition processing (step S101).
- the profile picture data acquisition process performed by the request transmission unit 42 according to the present embodiment is a process for causing the operator of the own user terminal 40 to take or select image data of a picture to be posted as a profile picture on the personal introduction page.
- the profile picture data acquisition process is also a process for allowing the operator to input text information to be posted together with the profile picture.
- the content of the profile photo data acquisition process performed by the request transmission unit 42 according to the present embodiment will be described using the case where the user terminal 40 is the mobile phone 80 as an example.
- the request transmission unit 42 that has started the profile photo data acquisition process first displays a predetermined screen (hereinafter referred to as a first selection screen) on the liquid crystal display 86, thereby making the profile photo a photographed photo. Or let the operator select whether to take a new picture.
- a predetermined screen hereinafter referred to as a first selection screen
- the request transmitting unit 42 displays a profile picture taking screen as shown in FIG.
- This profile picture shooting screen is a screen that disappears when the message shown in the frame 95 elapses for a certain period of time.
- the profile photo shooting screen is a screen on which the shooting result of the camera 85 for operator shooting is displayed in the frame 95, and is about several percent larger than the actually shot photo. Is a screen on which a small frame 95 is shown.
- the request transmission unit 42 stores the shooting result at that time of the camera 85 for operator shooting in the storage 83 as profile photo data. And the request
- the request transmission unit 42 displays a profile picture selection screen for selecting the profile picture data from the existing image data on the liquid crystal display 86. To display.
- the request transmission unit 42 stores that the image data is profile picture data.
- the request transmission unit 42 of the mobile phone (the user terminal 40 which is a mobile phone) displays the first selection screen described above because the mobile phone is connected to the in-camera (the camera 85 for photographing the operator in the mobile phone 80). Only if it has an equivalent).
- the request transmission unit 42 of the mobile phone that does not include the in-camera displays the profile photo selection screen without displaying the first selection screen.
- the profile picture data acquisition process performed by the request transmission unit 42 in the user terminal 40 which is a PC, is the same process as described above.
- the profile picture data acquisition process performed by the request transmission unit 42 in the PC the operator of the PC can take a picture of the profile picture data using a Web camera connected to the PC, etc.
- the processing can also be selected from among them.
- the request transmission unit 42 After completing the profile picture data acquisition process (FIG. 5, step S101), the request transmission unit 42 X size (number of pixels) Lx of profile picture data (processed image data in FIG. 5) photographed / selected by the operator. And Y direction size Ly is specified (step S102). Further, the request transmission unit 42 also specifies the terminal-specific information of the own user terminal 40 (Step S102).
- Information that the request transmission unit 42 in the user terminal 40 that is a mobile phone specifies as the terminal-specific information at the time of processing in step S102 is IMEI set in the mobile phone.
- the information specified by the request transmission unit 42 in the user terminal 40, which is a PC, as the terminal-specific information is a MAC (Media Access Control) address set in a NIC (Network Interface Card) in the PC.
- step S103 After completing the process in step S102, the request transmission unit 42 performs an area position specifying process (step S103).
- the position of the authentication image area on the profile photograph (the processing target image in FIG. 5) is specified based on the specified terminal specific information by an algorithm whose processing result varies depending on the value of the terminal specific information. It is processing.
- the authentication image area is a rectangular area in which the internal image is handled as the “default-size authentication image”.
- the authentication image area is a rectangular area in which image data representing an image inside the authentication image area is handled as the authentication image data described above.
- the area position specifying process a process of specifying an area near the edge of the profile picture as an authentication image area is usually employed.
- Sx and Sy are values set in advance as the X-direction size and the Y-direction size of the authentication image (authentication image area), respectively.
- Rh is a value set in advance as the height (Y-direction size) of the selection target area from which the authentication image area is selected.
- Sx and Sy values of about 5 to 20 are usually used, and as Rh, for example, a value of about 100 (for example, “80”) is used.
- the request transmitting unit 42 that has started the region position specifying process first extracts a part representing the serial number / serial ID (hereinafter referred to as serial number information) from the terminal-specific information specified in the process of step S102. .
- serial number information a part representing the serial number / serial ID (hereinafter referred to as serial number information) from the terminal-specific information specified in the process of step S102.
- the first to eighth digits are information indicating the manufacturer, model, and country of manufacture
- the ninth to fourteenth digits are serial numbers.
- 15-digit information in which the 15th digit is a check digit.
- the MAC address is information in which the upper 32 bits are information indicating the model name of the network device and the lower 16 bits are a serial ID.
- the request transmission unit 42 in the user terminal 40 which is a mobile phone extracts a numeric string from the 9th digit to the 14th digit as serial number information from the terminal specific information (IMEI). Further, the request transmission unit 42 in the user terminal 40 which is a PC extracts information for the lower 16 bits as serial number information from the terminal unique information (MAC address).
- IMEI terminal specific information
- MAC address terminal unique information
- the request transmission unit 42 divides the extracted serial number information into two parts, the first half information and the second half information. Next, the request transmission unit 42 calculates the remainder obtained by dividing the numerical value represented by the first half information by “Lx ⁇ Sx + 1”, and stores the calculation result as the X coordinate value x0 of the start point of the authentication image area.
- the starting point of the authentication image area is a vertex that is displayed on the upper left side when image display based on the processing target image data is performed, among the four vertices of the authentication image area.
- the request transmission unit 42 calculates a remainder obtained by dividing the numerical value represented by the latter half information by “Rh ⁇ Sy + 1”, and stores the calculation result as the Y coordinate value y0 of the start point of the authentication image area. Then, the request transmission unit 42 ends the region position specifying process.
- the region position specifying process in the above procedure is a process for obtaining the start point position of the authentication image area 110 from the terminal specific information so that all of the area is within the selection target area 112 indicated by hatching in FIG. It will be.
- the frame 95 of the above-described profile photograph shooting screen (FIG. 6) is about several percent smaller than the actually photographed photograph because the selection target area 112 is the background portion of the profile photograph. It is for entering.
- the size ratio of the regions 110 and 112 to the profile photo is as shown in FIG. 7, where Lx and Ly are 768 and 1024, Sx and Sy are both 10, and the size of the selection target region 112 is as follows. This is a case where the height Rh is 80.
- the size (Lx, Ly) of the profile picture is larger, the size ratio of the selection target area 112 and the authentication image area 110 to the profile picture becomes smaller.
- the size of the profile picture is smaller, the size ratio of the selection target area 112 and the authentication image area 110 to the profile picture becomes larger.
- region position specifying process a process having a processing procedure different from that described above, for example, a process that calculates only one coordinate value or a process that uses a fixed value of about 500 instead of Lx can be adopted.
- region position specifying process for calculating the X coordinate value and the Y coordinate value of the start point of the authentication image region from the terminal identification information, Lx, Sx, Sy, and Rh is executed in step S103.
- the functions of the information processing apparatus 1 and the user terminal 40 will be described as follows.
- the request transmitting unit 42 extracts image data related to the image in the authentication image area whose position has been specified by the area position specifying process from the profile photograph data photographed / selected by the operator (step S104). ). That is, the request transmission unit 42 profile image data obtained by selecting / photographing image data related to a rectangular image whose coordinates of the two vertices of the diagonal are (x0, y0) and (x0 + Sx-1, y0 + Sy-1). Extract from
- the request transmission unit 42 stores the extracted image data as authentication image data in the authentication image storage unit 41, and ends the process of step S104.
- the process of step S104 is a process of storing the authentication image data in the bitmap format in the authentication image storage unit 41 without changing the contents of the profile photo data photographed / selected by the operator.
- the profile photo data is JPEG (Joint Photographic Experts Group) data
- step S104 first, bitmap image data is generated from the JPEG data. And the image data regarding the said rectangular image is extracted from the produced
- the profile photo data is bitmap image data
- the request transmission unit 42 sends an opening request including profile photo data photographed / selected by the operator, text information input by the operator, and specified terminal-specific information to the authentication management server 10. (Step S105).
- the opening request transmitted to the authentication management server 10 is received by the opening request response unit 13 (FIG. 2) of the authentication management server 10.
- the opening request response unit 13 determines whether the received opening request is proper or inappropriate (for example, MAC address / It is determined whether the terminal specific information is clearly not IMEI). Then, if the opening request is inadequate, the opening request response unit 13 does not start the opening request response process and sends a response notifying notification indicating that it cannot respond to the received request. It is returned to the user terminal 40 that sent it (hereinafter referred to as the request sender). In addition, when the received opening request is appropriate, the opening request response unit 13 describes the user ID of the opening requester (hereinafter referred to as the opening requester ID) from the session tracking parameter included in the opening request. ).
- the opening requester ID the user ID of the opening requester
- the opening request response unit 13 searches the information in the user management DB 11 using the specified opening requester ID to determine whether the opening requester has already opened the personal introduction page. to decide. Then, the opening request response unit 13 starts the opening request response process if the opening requester is a person who has not opened the personal introduction page, and if not, performs the opening request response process. Without starting, a response impossible notice is returned to the request sender.
- the opening request response unit 13 that has started the opening request response process first outputs a feature information registration request including processing target image data, processing target terminal specific information, and an opening requester ID. It transmits with respect to the discrimination
- the processing target image data and the processing target terminal specific information are image data (that is, profile picture data) and terminal specific information included in the received opening request, respectively.
- the opening requester ID is the user ID of the opening requester identified from the session tracking parameter included in the received opening request as already defined.
- the feature information registration request transmitted to the image discrimination server 20 is received by the feature information registration unit 22 (FIG. 2).
- requirement starts the feature information registration request response process of the procedure shown, for example in FIG.
- the feature information registration unit 22 that has received the feature information registration request firstly has an x-direction size Lx and a Y-direction size Ly of image data (hereinafter referred to as processing target image data) received as an element of the feature information registration request. Is specified (step S251).
- the feature information registration unit 22 determines the position of the authentication image region on the processing target image represented by the processing target image data by the region position specifying process having the same content as that performed in the user terminal 40. Identify.
- step S252 the feature information registration unit 22 extracts serial number information from the processing target terminal specific information. Then, the feature information registration unit 22 calculates the remainder obtained by dividing the numerical value represented by the first half of the extracted serial number information by “Lx ⁇ Sx + 1” as the X coordinate value x0 of the start point of the authentication image area. Also, the feature information registration unit 22 calculates the remainder obtained by dividing the numerical value represented by the latter half of the extracted serial number information by “Rh ⁇ Sy + 1” as the Y coordinate value y0 of the start point of the authentication image area.
- the feature information registration unit 22 that has finished the region position specifying process extracts, from the processing target image data, image data related to the image in the authentication image region whose position has been specified by the region position specifying process (step S253). That is, the feature information registration unit 22 extracts the same image data extracted from the profile photo data as that extracted during the process of step S104 of the personal introduction page opening request process (FIG. 5).
- the feature information registration unit 22 generates feature information representing the features of the extracted image data (Step S254), and stores the generated feature information in the feature information management DB 21 in association with the establishment requester ID (Step S254). S255).
- the use of the feature information will be described later, but as the feature information of certain image data, for example, luminance histogram data by luminance / luminance classification of the image data or color histogram data by color / color classification is used. it can.
- the feature information registration unit 22 After completing the process of step S255, the feature information registration unit 22 transmits a completion notification to the authentication management server 10 (opening request response unit 13) (step S256). Then, the feature information registration unit 22 ends the feature information registration request response process.
- the establishment request response unit 13 that has transmitted the feature information registration request to the image discrimination server 20 (feature information registration unit 22) waits for the completion notification to be sent from the image discrimination server 20 (FIG. 8). Step S201).
- the opening request response unit 13 When receiving the completion notification, the opening request response unit 13 sends an opening request including the processing target image data, processing target text information, and the opening requester ID to the Web service server 30 (opening processing unit 32). It transmits to (step S202).
- the processing target text information is text information included in the received opening request.
- the processing target image data is image data (that is, profile picture data) included in the received opening request as already defined.
- the opening processing unit 32 that has received the opening request opens a personal introduction page for the opening requester based on the information in the opening request, and then sends a completion notification to the authentication management server 10 (opening request response Part 13).
- the establishment request response unit 13 that has transmitted the establishment request to the Web service server 30 waits for this completion notification to be transmitted from the Web service server 30 (step S202).
- the establishment request response unit 13 adds information indicating that the establishment of the personal introduction page for the establishment requester is completed to the user management DB 11 (step S203). Then, the opening request response unit 13 transmits a completion notification to the request transmission source (step S204), and then ends the opening request response process (FIG. 8).
- the request transmission unit 42 that has transmitted the opening request to the authentication management server 10 waits for reception of this completion notification (step S105 in FIG. 5). Then, when receiving the completion notification, the request transmission unit 42 ends the process of step S105 and the personal introduction page opening request process (the process of FIG. 5).
- the request transmission unit 42 finds that the authentication image data is stored in the authentication image storage unit 41 after the operator's login is completed, the request transmission unit 42 displays a predetermined work selection screen on the display, thereby Let the operator select whether to perform the operation. ⁇ Add images / videos to the personal introduction page ⁇ Change profile photo
- the request transmission unit 42 starts image / video registration request processing, and the operator changes “Profile photo change”. If selected, the profile picture change request process is started.
- the image / moving picture registration request process is, for example, the process shown in FIG. That is, since the operator has selected to add an image / moving image to the personal introduction page, the request transmitting unit 42 that has started the image / moving image registration request processing first performs registration target data acquisition processing (step S151).
- the registration target data acquisition process is a modification of the above-described profile photo data acquisition process so that the operator can select data to be registered (added) on the personal introduction page from the following image / video data. . ⁇ Existing image data or moving image data ⁇ New image data or moving image data
- registration target data image data or moving image data selected by the operator during the registration target data acquisition process or selected from existing data.
- the request transmission unit 42 that has completed the registration target data acquisition process specifies the X direction size Lx and the Y direction size Ly of the registration target data and the terminal-specific information of the own user terminal 40 (step S152).
- step S152 is the same as the process of step S102 described above except that the processing target may be moving image data. That is, in step S152, the request transmission unit 42 in the user terminal 40 that is a mobile phone specifies the IMEI set for the mobile phone as terminal-specific information. Further, the request transmission unit 42 in the user terminal 40 which is a PC specifies the MAC address set in the NIC of the own PC as terminal specific information.
- the request transmission unit 42 After completing the process of step S152, the request transmission unit 42 performs the region position specifying process having the same content as that performed in step S103 (FIG. 5) using the specified terminal specific information and Lx (step S153).
- the request transmission unit 42 generates data in which the image data related to the image in the authentication image area whose position is specified by the area position specifying process in the registration target data is replaced with the authentication image data (step S154).
- step S154 the request transmission unit 42 first determines whether the registration target data is image data or moving image data.
- the request transmission unit 42 prepares a copy of the registration target data on the RAM. Next, the request transmission unit 42 replaces the image data relating to the image in the authentication image area in the prepared copy with the authentication image data stored in the authentication image storage unit 41. That is, the request transmission unit 42 transmits the image data regarding the image in the prepared copy whose diagonal two vertex coordinates are (x0, y0) and (x0 + Sx-1, y0 + Sy-1) to the authentication image storage unit. The authentication image data stored in 41 is replaced.
- the request transmission unit 42 prepares a copy of the registration target data on the RAM. Then, the request transmission unit 42 replaces the image data related to the image in the authentication image area in the prepared image data related to the first frame in the copy with the authentication image data stored in the authentication image storage unit 41.
- the registration target data is usually irreversibly compressed regardless of whether it is image data or moving image data. Accordingly, in step S154, the image data that is normally “lossy compressed” is decompressed (in other words, the format of the image data is converted to the bitmap format), and a part thereof is replaced with the authentication image data. , “Reversible compression process” is performed.
- the request transmission unit 42 After completing the process of step S154, the request transmission unit 42 sends a registration request including the generated image / video data, text information acquired from the operator, and terminal-specific information specified during the process of step S152 to the authentication management server 10. It transmits to (step S155).
- the registration request transmitted to the authentication management server 10 is received by the request response unit 13 (FIG. 2) of the authentication management server 10.
- the request response part 14 which received the registration request starts the registration request response process of the procedure shown in FIG. 11, for example.
- the request response unit 14 only receives a registration request response if the received registration request is appropriate and it can be confirmed that the request sender is a person who has already opened a personal introduction page. Start processing. If the received registration request is not proper or the request sender is a person who has not yet opened a personal introduction page, the request response unit 14 does not start the registration request response process, A response impossible notification is returned to the request transmission source (the user terminal 40 that has transmitted the registration request).
- the request response unit 14 first sends an authentication request including processing target terminal specific information, determination target image data, and request sender ID to the image determination server 20. It transmits to (step S301).
- the processing target terminal specific information is terminal specific information included in the received registration request.
- the determination target image data is the image data when the received registration request includes image data, and when the received registration request includes moving image data, This is image data related to the first frame included in the moving image data.
- the request sender ID is a user ID input by the request sender at the time of login. This request sender ID is specified from the session tracking parameter in the registration request.
- the authentication request transmitted to the authentication management server 10 is received by the image determination unit 23 (FIG. 2).
- the image determination unit 23 that has received the authentication request starts, for example, an authentication request response process of the procedure shown in FIG.
- the image determination unit 23 that has received the authentication request first specifies the x-direction size Lx and the Y-direction size Ly of the determination target image data (step S351).
- the determination target image data and the processing target terminal specific information are the received image data and terminal specific information that are being requested for authentication, respectively.
- the feature information registration unit 22 performs region position specifying processing having exactly the same content as that performed in the user terminal 40, using the processing target terminal specific information together with the specified Lx or the like.
- the feature information registration unit 22 extracts the image data related to the image in the authentication image area whose position is specified by the area position specifying process from the processing target image data (step S353).
- the feature information registration unit 22 generates feature information representing the features of the extracted image data (hereinafter referred to as authentication image region data) using the same algorithm as the feature information generation algorithm in step S254 (step S354). ).
- the image discriminating unit 23 compares the generated feature information with the feature information associated with the request sender ID in the feature information management DB 21 so that the request sender has the request sender ID.
- a process of determining whether or not it is a legitimate holder (step S355) is performed.
- the request sender ID is a user ID in the received authentication request, and the authorized holder of the request sender ID is a user to whom the request sender ID is actually assigned. .
- the image discriminating unit 23 first reads out the feature information associated with the request sender ID (the received user ID in the authentication request) from the feature information management DB 21.
- the image determination unit 23 obtains a dissimilarity indicating the degree of dissimilarity between the generated feature information and the read feature information. Note that the dissimilarity obtained by the image determination unit 23 is a numerical value that increases as the difference between the two pieces of feature information increases.
- the image discriminating unit 23 determines that the request sender is a legitimate holder of the request sender ID when the obtained dissimilarity is equal to or less than a preset threshold value, and if not, In addition, it is determined that the request sender is not a valid holder of the request sender ID.
- feature information related to the same image data as the authentication image data in the authentication image storage unit 41 of each user terminal 40 is stored in association with the user ID of the user of each user terminal 40. Yes.
- the authentication image data in the authentication image storage unit 41 of the user terminal 40 can be specified from the terminal-specific information requested to be updated. Embedded in position.
- step S355 can be a process for determining whether or not the two feature information matches.
- determination target image data in the authentication request response process normally expands “lossy compressed image data” The data is replaced with authentication image data and then re-irreversibly compressed ”.
- step S355. This process is the process of the above procedure.
- various information can be used as a dissimilarity at the time of the process of step S355.
- the feature information is luminance histogram data
- the square value of the difference in the number of pixels having the same luminance (or luminance classification), the sum of absolute values, or the like can be used as the dissimilarity.
- the feature information is color histogram data
- the square value of the difference in the number of pixels having the same color (or color classification), the sum of absolute values, or the like can be used as the dissimilarity.
- the threshold value in the process of step S355 is information in which an appropriate value changes according to the values of SX and SY, feature information, and the type of dissimilarity (calculation algorithm). Therefore, after determining the values of SX and SY, the type of feature information and the degree of dissimilarity, the dissimilarity is actually calculated for several types of image data, and the threshold is more than the maximum value of the calculation results. A large value may be adopted.
- step S356 After determining that the request sender is a legal holder of the request sender ID (step S356; YES), the image determination unit 23 that has finished the process of step S355 (authentication management server 10 (request response unit 14)). An authentication success notification is transmitted to (step S357). On the other hand, when it is determined that the request sender is not a valid holder of the request sender ID (step S356; NO), the image determination unit 23 sends an authentication failure notification to the authentication management server 10 (request response unit 14). Transmit (step S358). Then, the image discriminating unit 23 that has finished the process of step S357 or S358 ends the authentication request response process.
- the request response unit 14 that has transmitted the authentication request waits for an authentication success notification or an authentication failure notification from the image determination server 20 (image determination unit 23). (Step S301).
- the request response unit 14 receives the authentication success notification (step S302; success)
- the registration request including the received image / video data and text information in the registration request and the request sender ID is received. Is transmitted to the Web service server 30 (step S303).
- the update processing unit 33 Received by the update processing unit 33 transmitted to the Web service server 30. Then, the update processing unit 33 that has received the registration request adds image / video data or the like to the personal introduction page of the request sender, and then transmits a completion notification to the authentication management server 10 as described above. .
- the request response unit 14 that has transmitted the registration request to the Web service server 30 waits for the completion notification to be transmitted from the Web service server 30 (step S303). Then, when a completion notification is transmitted, the request response unit 14 transmits a completion notification to the registration request transmission source (step S304), and then ends this registration request response process (FIG. 11). .
- step S302 If the request response unit 14 receives an authentication failure notification (step S302; failure), the request response unit 14 transmits a completion notification to the registration request transmission source (step S305), and then ends the registration request response process. To do.
- the request transmission unit 42 that has transmitted the registration request to the authentication management server 10 (request response unit 14) waits for reception of this completion notification (FIG. 10, step S155). Then, when receiving the completion notification, the request transmission unit 42 ends the process of step S155 and the image / moving picture registration request process.
- the request transmission unit 42 starts the profile picture change request process.
- This profile photo change request process is a process of generating and sending a profile photo change request.
- the profile photo change request process is basically the same procedure as the image / video registration request process (FIG. 10). It has become. Therefore, in the following, the contents of the profile photo change request process will be described with reference to FIG. 10, focusing on the difference from the image / moving picture registration request process.
- the profile photo change request process is a process for changing the profile picture data used in the personal introduction page to other profile picture data (that is, image data). Therefore, in the profile picture change request process, the same profile picture data acquisition process as that performed in step 101 of FIG. 5 is performed instead of the registration target data acquisition process for acquiring image data or moving picture data from the user.
- a profile photo change request including the profile photo data or the like in which a part of the profile photo change request is replaced is transmitted to the authentication management server 10. A process of waiting for the completion notification is performed.
- the profile photo change request (hereinafter also referred to as a change request) transmitted to the authentication management server 10 is received by the request response unit 14.
- the request response unit 14 that has received the change request starts change request response processing. It should be noted that the request response unit 14 changes the response to the change request only when the received change request is appropriate and the request sender can confirm that the person introduction page has already been opened. Start processing.
- the change request response process is essentially the same process as the above registration request response process (FIG. 11).
- the request response unit 14 that has started the change request response process first sends an authentication request including the processing target terminal specific information, the determination target image data, and the request sender ID to the image determination server 20 (image determination unit 23). Send to.
- the determination target data in the registration request response process is image data relating to the first frame (first frame) included in the received image data requested for registration or moving image data requested for registration.
- the change request does not include moving image data. Therefore, the determination target image data in the change request response process is image data (profile photo data) included in the received change request.
- the image determination unit 23 that has received the authentication request determines whether or not the request sender is a valid holder of the request sender ID by performing the above-described authentication request response process (FIG. 12). Then, when it is determined that the request sender is a valid holder of the request sender ID, the image determination unit 23 transmits an authentication completion notification to the authentication management server 10 (request response unit 14). Further, when it is determined that the request sender is not a valid holder of the request sender ID, the image determination unit 23 transmits an authentication failure notification to the authentication management server 10 (request response unit 14).
- the request response unit 14 that has transmitted the authentication request to the image determination server 20 (image determination unit 23) waits for any of the above notifications to be transmitted from the image determination server 20.
- the request response unit 14 When the request response unit 14 receives the authentication success notification, the request response unit 14 sends a change request (profile photo data change request) including the received image data and text information in the registration request and the request sender ID. Transmit to the Web service server 30.
- a change request profile photo data change request
- the change request transmitted to the Web service server 30 is received by the update processing unit 33. Then, the update processing unit 33 that has received the change request changes the profile photo data on the personal introduction page of the request sender as described above, and then transmits a completion notification to the authentication management server 10. .
- the request response unit 14 that has transmitted the change request to the Web service server 30 waits for this completion notification to be transmitted from the Web service server 30.
- the request response unit 14 transmits the completion notification to the request transmission source, and then ends the change request response process.
- the request response unit 14 when the request response unit 14 receives the authentication failure notification, the request response unit 14 notifies the request transmission source of a response impossible notification without transmitting the change request (profile photo data change request) to the Web service server 30. Send. Then, the request response unit 14 ends the change request response process.
- FIG. 13 shows a sequence diagram among the user terminal A, the authentication management server 10, the image discrimination server, and the Web service server 30 when the user A opens a personal introduction page.
- FIG. 14 shows a sequence diagram among the user terminal A, the authentication management server 10, the image discrimination server, and the Web service server 30 when the user A registers image data on the personal introduction page.
- the user terminal A is the user terminal 40 of the user A.
- TSI-A is terminal-specific information of user terminal A
- ID-A is a user ID of user A.
- the authentication image area data is image data of an image in the authentication image area whose position is specified from the unique terminal information as already defined.
- a login process is performed between the user A (user terminal A) and the authentication management server 10. Thereafter, in the user terminal A, processing for causing the user A to shoot / specify profile picture data (hereinafter referred to as image data A0) (not shown), and processing for specifying the position of the authentication image area from the TSI-A Is done. Then, after the process of storing the authentication image area data in the image data A0 as the authentication image data of the user A (hereinafter referred to as authentication image data ⁇ ), the image data A0, TSI-A, and the like are included. An opening request is transmitted to the authentication management server 10.
- the authentication management server 10 Upon receiving the opening request, the authentication management server 10 (opening request response unit 12) confirms that the opening request is a proper request from a user who has not yet opened the personal introduction page (not shown). Then, if the authentication management server 10 can confirm that the received opening request is such a request, the authentication management server 10 registers the feature information including the image data A0 and TSI-A together with the ID-A specified from the session tracking parameter. The request is transmitted to the image discrimination server 20.
- the image discrimination server 20 that has received the feature information registration request, processing for specifying the position of the authentication image area from the terminal-specific information in the feature information registration request is performed. Thereafter, the feature information of the authentication image area data in the image data A0 is stored in the feature information management DB 21 in association with ID-A. Note that since the terminal-specific information included in the feature information registration request when the personal introduction page is opened by the user A is TSI-A, the authentication image area data in the image data A0 is the authentication image data ⁇ . Therefore, the feature information of the authentication image data ⁇ is stored in the feature information management DB 21 in association with ID-A.
- the authentication management server 10 Upon receiving this completion notification, the authentication management server 10 transmits to the Web service server 30 an opening request including the image data A0 received as an element of the registration request and the ID-A specified from the session tracking parameter.
- the Web service server 30 that has received the opening request opens the personal introduction page A of the user A using the image data A0 as profile picture data.
- a login process is first performed. Thereafter, in the user terminal A, a process (not shown) for causing the user A to shoot / designate the image data A1 registered in the personal introduction page A and a process for specifying the position of the authentication image area from the TSI-A are performed. . Thereafter, a process of replacing the authentication image area data in the image data A1 with the authentication image data ⁇ is performed. Then, a registration request including image data A1 [ ⁇ ], TSI-A, etc., which is part of the image data A1 in which the authentication image data ⁇ is replaced, is transmitted to the authentication management server 10.
- the authentication management server 10 that has received the registration request confirms that the registration request is a proper request from the user who has opened the personal introduction page. If the authentication management server 10 can confirm that the received registration request satisfies the above condition, the authentication management server 10 can identify the ID-A specified from the image data A1 [ ⁇ ] and TSI-A and the session tracking parameter. Is sent to the image discrimination server 20.
- the position of the authentication image area is specified from the TSI-A included in the authentication request.
- the sender of the determination target data is the user A from the characteristic information regarding the authentication image area data in the image data (hereinafter referred to as determination target data) included in the authentication request and the characteristic information of the user A. It is determined whether or not.
- the feature information of the user A is feature information stored in the feature information management DB 11 in association with the user ID (ID-A in this case) requesting authentication.
- the authentication image area data in the determination target data is the authentication image data ⁇ (however, the content is slightly different from the original authentication image data ⁇ due to recompression). It becomes. Therefore, the feature information obtained from the authentication image area data in the determination target data is not much different from the feature information of the user A.
- the authentication management server 10 transmits a registration request including the image data A1 [ ⁇ ] and the like received as elements of the registration request and ID-A to the Web service server 30.
- the Web service server 30 that has received this registration request registers (adds) the image data A1 [ ⁇ ] and the like in the personal introduction page A.
- image data whose authentication image area data is the authentication image data ⁇ is passed to the image discrimination server 20. . Therefore, the image determination server 20 determines that the sender of each request is the user A. As a result, the contents of the personal introduction page A are updated as desired by the user A.
- the user B logs in to the information processing apparatus 1 by inputting the user ID and password of the user A using the user terminal 40 (hereinafter referred to as the user terminal B), and the image data B is stored in the personal introduction page A.
- the terminal-specific information of the user terminal B is TSI-B
- the authentication image data ⁇ is stored in the authentication image storage unit 41 of the user terminal B.
- the registration request transmitted from the user terminal B to the authentication management server 10 is the image data B obtained by replacing the authentication image area data in the image data B with the authentication image data ⁇ . [ ⁇ ], including TSI-B. Then, since the received registration request is a request from a user who has logged in with ID-A, the authentication management server 10 determines the authentication request including the image data B [ ⁇ ], TSI-B, and ID-A as an image discrimination. It transmits to the server 20.
- the position of the authentication image area is specified from the TSI-B included in the authentication request.
- the feature information of the authentication image area data in the determination target data is associated with ID-A in the feature information management DB 21. Current feature information (that is, feature information of the authentication image data ⁇ ) is compared. In this case, since the authentication image area data in the determination target data is authentication image data ⁇ , the feature information of the authentication image area data is usually quite different from the feature information A of the authentication image data ⁇ . Therefore, it is determined that the sender of the determination target data is not the user A, and an authentication failure notification is transmitted to the authentication management server 10.
- the authentication management server 10 transmits a response failure notification to the user terminal B without transmitting a registration request to the Web service server 30. That is, the processing for the change request of the information processing apparatus 10 is completed without the image data B being registered in the personal introduction page A.
- the authentication image data is also greatly different, so that the sender of the profile photo request is determined not to be the user A. The Therefore, the profile picture on the personal introduction page A is not changed.
- the information processing apparatus 1 is an apparatus that cannot illegally modify the personal introduction page by using the image data registration program 45.
- the user B may be able to create a program that can transmit a proper registration / change request (in other words, a request for starting a registration request response process or a change request response process).
- a proper registration / change request in other words, a request for starting a registration request response process or a change request response process.
- the information processing apparatus 1 adds image data to the personal introduction page A, Do not change profile photo data on introduction page A. Since the authentication image data ⁇ is image data related to the image in the small area (see the authentication image area 110 in FIG. 7), the user B notices that the image data included in the registration / change request needs to be processed. There is almost no.
- the information processing apparatus 1 is a device that is difficult to illegally modify the personal introduction page by the user's own program.
- the information processing apparatus 1 is an apparatus that can confirm that the requester who requests the processing for the image / moving image data via the network is the person himself / herself without increasing the load on the user.
- FIG. 16 shows a functional block configuration example of the information processing apparatus 2 according to the second embodiment together with a functional block configuration example of the user terminal 40.
- the information processing apparatus 2 requests the request response unit 14 in the authentication management server 10 of the information processing apparatus 1 according to the first embodiment.
- the device is changed to the response unit 14B.
- the information processing apparatus 2 is an apparatus in which a program used as the authentication management server 10 is installed with a program having a different content from the authentication management server program in the authentication management server 10 of the information processing apparatus 1.
- the user terminal 40 used for using the information processing apparatus 2 according to the present embodiment is the same apparatus as the user terminal 40 according to the first embodiment. Therefore, hereinafter, the function of the information processing apparatus 2 according to the second embodiment will be described focusing on the function of the request response unit 14B.
- the request response unit 14B is a unit obtained by modifying (improving) the request response unit 14 so as to perform a registration request response process and a change request response process having different contents from those described above.
- the registration request response process executed by the request response unit 14B is a process of the procedure shown in FIG. That is, the request response unit 14B that has started the registration request response process first performs the same process as the process of step S301 (FIG. 11) in step S401.
- the request response unit 14B receives an authentication failure notification from the image discrimination server 20 (step S402; NO)
- the request response unit 14B transmits an authentication failure notification to the request transmission source, as with the request response unit 14.
- step S406 the registration request response process is terminated.
- step S403 the request response unit 14B regards the authentication image area of the registration target data as an area where the image data is missing and restores the authentication image. Perform area repair processing.
- the registration target data is image data or moving image data received as an element of the received registration request.
- the request response unit 14B specifies the position of the authentication image region by performing the region position specifying process having the same contents as those performed by the image determining unit 23 and the request transmitting unit 42.
- the restoration algorithm of the authentication image area restoration process in Step 403 may be a high-level algorithm (such as an image restoration algorithm based on sequential texture synthesis) that can well correct a large defect area.
- a high-level algorithm such as an image restoration algorithm based on sequential texture synthesis
- the authentication image area can be restored to an area where the difference from the other areas is not noticeable even if a simple restoration algorithm is used. Therefore, in order not to increase the load on the authentication management server 10, for example, it is preferable to use a restoration algorithm as schematically shown in FIG.
- the authentication image area (in FIG. 18, an area composed of 8 ⁇ 8 pixels not shaded) is divided into four areas, upper left, upper right, lower left, and lower right.
- the color is the average value of the color of the pixel one level above and the color of the pixel left one level
- the color is the average value of the color of the pixel one level above and the color of the pixel right one level
- the color is the average value of the color of the pixel one step below and the color of the pixel left one step
- the request response unit 14B transmits a registration request including the registration target data in which the authentication image area is restored to the Web service server 30 (step S404). More specifically, the request response unit 14B generates a registration request including the registration target data in which the authentication image area is restored, the received text information in the registration request, and the request sender ID specified from the session tracking parameter. Transmit to the Web service server 30.
- the request response unit 14B waits for the completion notification transmitted from the Web service server 30 (step S404), and when the completion notification is transmitted, the request transmission source After the completion notice is transmitted (step S405), the registration request response process (FIG. 17) is terminated.
- the change request response process executed by the request response unit 14B is essentially the same process as the registration request response process.
- the request response unit 14B that has started the change request response process first determines the authentication request including the processing target terminal specific information, the determination target image data (profile photo data in the change request), and the request sender ID. It transmits with respect to the server 20 (image discrimination
- the request response unit 14B When the request response unit 14B receives the authentication success notification, the request response unit 14B restores the authentication image area of the profile photo data received as an element of the change request. Then, the request response unit 14B transmits a change request (profile photo data change request) including the profile photo data in which the authentication image area is restored, the text information, and the request sender ID to the Web service server 30.
- a change request profile photo data change request
- the change request transmitted to the Web service server 30 is received by the update processing unit 33. Then, the update processing unit 33 that has received the change request changes the profile photo data on the personal introduction page of the request sender, and then transmits a completion notification to the authentication management server 10.
- the request response unit 14B that has transmitted the change request to the Web service server 30 waits for the completion notification to be transmitted from the Web service server 30. Then, when the completion notification is transmitted, the request response unit 14B transmits the completion notification to the request transmission source, and then ends the change request response process.
- the request response unit 14B receives the authentication failure notification, the request response unit 14B transmits a response impossible notification to the request transmission source without transmitting the change request to the Web service server 30. Then, the request response unit 14B ends the change request response process.
- the information processing apparatus 2 also transmits the request image authentication image area data in the image / video data included in the registration / change request as in the information processing apparatus 1 according to the first embodiment.
- the registration / change request is not accepted unless it is almost the same as the authentication image data of the user. Therefore, in order to generate a registration / change request accepted by the information processing apparatus 2, at least terminal-specific information and an authentication image (authentication image data) must be known.
- the information processing apparatus 2 adds “an image / moving image in which the embedded authentication image is replaced with another image” to the personal introduction page of each user. It is a device to be posted.
- the personal introduction page published by the information processing apparatus 2 is an apparatus in which it is extremely difficult to specify an authentication image from each image / moving image posted. Therefore, the information processing apparatus 2 according to the present embodiment performs unauthorized modification more than the information processing apparatus 2 according to the first embodiment that places an image / moving image including the authentication image as a part thereof on the personal introduction page. It can be said that the device is difficult to perform.
- FIG. 19 shows a functional block configuration example of the information processing apparatus 3 according to the third embodiment together with a functional block configuration example of the user terminal 40.
- the information processing device 3 is a device obtained by modifying (improving) the information processing device 2 according to the second embodiment. Similarly to the information processing device 2 (and 1), authentication management connected to the Internet. A server 10, an image determination server 20, and a Web service server 30 are included.
- the Web service server 30 of the information processing apparatus 3 is the same server as the Web server 30 of the information processing apparatus 2 (and 1).
- the authentication management server 10 of the information processing device 3 is a server in which the opening request response unit 13 and the request response unit 14B in the authentication management server 10 of the information processing device 2 are replaced with an opening request response unit 13C and a request response unit 14C.
- the image discrimination server 20 of the information processing device 3 is a server in which the feature information registration unit 22 and the image discrimination unit 23 of the information processing device 2 are replaced with a feature information registration unit 22C and an image discrimination unit 23C.
- the authentication management server 10 is a computer in which an authentication management server program having a different content from the authentication management server program in the authentication management server 10 of the information processing apparatus 2 is installed.
- the image discrimination server 20 is also a computer in which an image discrimination server program having a different content from the image discrimination server program 25 in the image discrimination server 10 of the information processing apparatus 2 (and 1) is installed.
- the user terminal 40 used for transmitting an opening request or the like to the information processing apparatus 3 includes a request transmission unit 42 of the user terminal 40 used for transmitting an opening request or the like to the information processing apparatus 2 (and 1).
- the device is replaced with the request transmission unit 42C. That is, the user terminal 40 is a terminal device in which an image data registration program having a different content from the image data registration program 45 is installed.
- the request transmission unit 42C is a unit that performs a personal introduction page establishment request process, an image / video registration request process, and a profile picture change request process with basically the same contents as those performed by the request transmission unit 42.
- each process performed by the request transmission unit 42C is a process of specifying the position of the authentication image area from the generated random number and including the generated random number in the request to be transmitted.
- the personal introduction page opening request process performed by the request transmitting unit 42C is a process of the procedure shown in FIG.
- the request transmission unit 42C that has started this personal introduction page opening request process first performs the same profile picture data acquisition process (step S501) as that performed in step S101 (FIG. 5).
- the request transmission unit 42C specifies the X direction size Lx and the Y direction size Ly of the profile photo data (processed image data in FIG. 20) photographed / selected by the operator (step S102). ). In step S102, the request transmission unit 42C also performs processing for generating a random number having a predetermined number of digits.
- the request transmission unit 42C specifies the position of the authentication image region on the profile photograph (the processing target image in FIG. 20) with an algorithm whose processing result varies depending on the value of the random number based on the generated random number.
- An area position specifying process (step S503) is performed.
- this area position specifying process for example, a process is performed in which the serial number information in the area position specifying process described above is replaced with “generated random number”.
- the remainder obtained by dividing the first half of the generated random number by “Lx ⁇ Sx + 1” is calculated as the X coordinate value x0 of the starting point of the authentication image area, and the remainder obtained by dividing the steel plate portion of the generated random number by “Rh ⁇ Sy + 1” Is calculated as the Y coordinate value y0 of the start point of the authentication image area.
- the request transmitting unit 42C After completing the area position specifying process, the request transmitting unit 42C extracts image data related to the image in the authentication image area whose position has been specified by the area position specifying process from the profile photograph data photographed / selected by the operator (step S504). ). Then, the request transmission unit 42C stores the extracted image data as authentication image data in the authentication image storage unit 41, and then ends the process of step S504.
- the request transmission unit 42C After completing the processing in step S504, the request transmission unit 42C authenticates the opening request including the profile photo data photographed / selected by the operator, the text information input by the operator, and the random number used to specify the authentication image area. It transmits with respect to the management server 10 (step S505). Then, the request transmission unit 42C waits for the completion notification transmitted from the authentication management server 10 (step S505), and when the completion notification is received, the process of step S505 and the request for opening the personal introduction page The process (the process of FIG. 20) is terminated.
- the image / video registration request process and the profile picture change request process performed by the request transmission unit 42C are processes that specify the position of the authentication image area from the generated random number and include the generated random number in the transmission request. Yes.
- FIG. 21 shows a sequence diagram among the user terminal X, the authentication management server 10, the image discrimination server, and the Web service server 30 when the personal introduction page is opened by the user X.
- the user terminal X is the user terminal 40 of the user X (arbitrary user)
- ID-X is the user ID of the user X.
- the authentication management server 10 Upon receiving the opening request, the authentication management server 10 (opening request response unit 13C) performs an opening request response process essentially the same as the above-described opening request response process (FIG. 8). However, as schematically shown in FIG. 21, in the opening request response process performed by the opening request response unit 13C, the feature information registration request and the opening request to be transmitted are not the terminal specific information but the user terminal 40 (user terminal The random number RND0 transmitted from X) is included.
- the image discriminating server 20 that has received the feature information registration request has the same contents as the above-described feature information registration request response process (FIG. 9) except that the method for specifying the position of the authentication image region is different.
- the feature information registration request response process is performed. That is, the feature information registration unit 22C differs from the above-described feature information registration request response processing only in that the same region position specifying process as that performed by the request transmission unit 42C is performed in the step corresponding to step S252. Perform request response processing.
- the establishment request response unit 13C that has received the completion notification from the image discrimination server 20 performs the same processing as the establishment request response unit 13 in the information processing apparatuses 1 and 2.
- the opening request response unit 13C that has received the completion notification transmits an opening request including the processing target image data, the processing target text information, and the opening requester ID to the Web service server 30 (the opening processing unit 32). . Then, the opening request response unit 13C waits for the completion notification to be transmitted from the Web service server 30, and when the completion notification is transmitted, the opening of the personal introduction page for the opening requester is completed. Information indicating that is added to the user management DB 11. Then, the opening request response unit 13C transmits a completion notification to the request transmission source, and then ends the opening request response process.
- FIG. 22 shows a sequence diagram among the user terminal X, the authentication management server 10, the image discrimination server, and the Web service server 30 when the user X registers image data on the personal introduction page.
- the authentication management server 10 Upon receiving the registration request, the authentication management server 10 (request response unit 14C) performs registration request response processing (FIG. 17) essentially the same as the registration request response processing (FIG. 17) performed by the request response unit 14B in the information processing apparatus 2. Do. However, as schematically shown in FIG. 22, in the opening request response process performed by the opening request response unit 13C, the authentication request to be transmitted is transmitted from the user terminal 40 (user terminal X) instead of the terminal specific information. Random number RND1 is included.
- the image determination server 20 (image determination unit 23C) that has received the authentication request has the same contents as the authentication request response process (FIG. 12) described above except that the method for specifying the position of the authentication image area is different. I do. That is, the image determination unit 23C performs an authentication request response process that is different from the above-described authentication request response process only in that the same region position specifying process as that performed by the request transmission unit 42C is performed in a step corresponding to step S352. .
- the request response unit 14C that has received the completion notification from the image determination server 20 (image determination unit 23C) performs the same processing as the request response unit 14B in the information processing apparatus 2.
- the request response unit 14C that has received the completion notification first repairs the authentication image area of the registration target data. Then, the request response unit 14C transmits a registration request including the repaired registration target data and processing target text information and the request sender ID to the Web service server 30 (update processing unit 33). Then, the request response unit 14C waits for the completion notification to be transmitted from the Web service server 30, and when the completion notification is transmitted, after transmitting the completion notification to the request transmission source, The registration request response process ends.
- the information processing apparatus 3 is an individual introduction page on which “an image / video in which the embedded authentication image is replaced with another image” is posted, and the authentication image is embedded. It has a function of publishing a personal introduction page whose position is different for each image / video.
- the information processing device 3 also registers the authentication image area data in the image / moving image data included in the registration / change request when the personal introduction page of the request sender is opened, as in the information processing devices 1 and 2. If it is not substantially the same as the authenticated image data, the registration / change request is not accepted. Therefore, in order to generate a registration / change request accepted by the information processing apparatus 3, at least the terminal specific information and the authentication image must be known.
- the authentication image cannot be specified from the page. Therefore, it can be said that the information processing apparatus 3 according to the present embodiment is an apparatus that is particularly difficult to perform unauthorized modification.
- the information processing apparatuses 1 to 3 can be variously modified. For example, if the terminal specific information is stored in the information processing apparatus in association with the user ID, the terminal specific information can be specified from the user ID even if the registration request / change request does not include the terminal specific information. Therefore, when the establishment request is received, the information processing devices 1 and 2 are devices that store the terminal unique information and the feature information in association with the user ID in the feature information management DB 21 and do not include the terminal unique information. It can be transformed into a device for receiving a request / change request. If the information processing apparatuses 1 and 2 are modified in this way, the terminal-specific information flows only once on the network. Therefore, the terminal-specific information transmitted from the user terminal 40 to the information processing apparatus can be practically prevented from being wiretapped.
- the information processing apparatuses 1 and 2 can be modified into an apparatus in which the authentication image area is selected from the entire area of the profile picture data.
- the information processing apparatus 3 can be modified to an apparatus in which the authentication image area is selected from the entire area of the first frame image of each image or each moving image.
- the central portion of the image is the original image. For this reason, it is preferable that the authentication image area is positioned near the edge of the image.
- the information processing devices 1 to 3 can be modified into a device that stores the authentication image area data itself in the profile photo data as feature information.
- the request sender is usually authenticated by direct comparison of the two image data. This is because if the feature information of the two image data is generated and compared, the feature information of the authentication image area data in the profile photo data is stored more frequently, and the same feature information is generated many times. This is because it can be prevented.
- the above modification it is possible to generate feature information of two image data and compare them.
- the information processing apparatuses 1 and 2 can be transformed into an apparatus for specifying the position of the authentication image area from the value specified by each user when the personal introduction page is opened.
- the user terminal 40 is also transformed into a device for specifying the position of the authentication image area from the value specified when the user opened the personal introduction page.
- Each of the information processing apparatuses 1 to 3 is an apparatus for providing a Web service that allows a user to easily open a personal introduction page. However, the information processing apparatuses 1 to 3 can receive image / video data from each user. Can be transformed into a device for storing in the storage.
- the information processing apparatuses 1 to 3 can be transformed into apparatuses that do not require installation of a special program (the above-described image data registration program 45) on the user terminal 40. That is, the information processing apparatuses 1 to 3 can be modified into apparatuses that provide applets or the like for causing each user terminal 40 to execute a personal introduction page opening request process. In this case, it is usually necessary for each user to set a policy file in the user terminal 40 that permits the operation of the local file by each applet.
- a special program the above-described image data registration program 45
- the information processing apparatuses 1 to 3 are the apparatuses (the apparatus including two servers) in which the authentication management server 10 also functions as the image determination server 20, and the Web service server 30 is the authentication management server 10 and the image determination server 20. It can also be modified to a device having the above function. Further, the information processing apparatuses 1 to 3 are transformed into apparatuses in which the Web service server 30 receives various requests, and the Web service server 30 requests the authentication management server 10 and the image determination server 20 to perform login authentication and authentication using an authentication image. You can also The information processing apparatuses 1 to 3 can be modified into apparatuses that are used by connecting to a network other than the Internet.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- Health & Medical Sciences (AREA)
- Biomedical Technology (AREA)
- General Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Information Transfer Between Computers (AREA)
Abstract
情報処理装置は、認証画像データの特徴を表す特徴情報を、ユーザ識別情報に対応づけて記憶する情報記憶部と制御部とを、備え、制御部は、或る画像データに対する処理をネットワークを介して要求する要求者から、当該画像データと、ユーザ識別情報と、当該画像データに埋め込まれている認証画像データの位置を示す位置提示情報とを取得し、取得した画像データから、取得した位置提示情報が示している位置の画像データを抽出し、抽出した画像データの特徴を表す特徴情報と、取得したユーザ識別情報に対応づけられて前記情報記憶部に記憶されている特徴情報とを比較することにより、要求者が、取得したユーザ識別情報にて識別される利用者本人であるか否かを判定し、要求者が、取得したユーザ識別情報にて識別される利用者本人であると判定した場合に、要求者が要求している処理を取得した画像データに対して実行する。
Description
本発明は、情報処理装置と、端末装置と、情報処理プログラムと、情報処理方法とに、関する。
周知のように、近年、デジカメ写真等を自身のWebページ(Webサイト)で公開することが盛んに行われるようになってきているが、そのようなWebページは、ユーザIDとパスワードとを知ってさえいれば、内容を改ざんできるものとなっている。
本人認証のための技術としては、様々なもの(例えば、特許文献1参照)が開発されている。そのため、上記のようなWebページの更新時に、なりすましが困難な本人認証が行われるようにすることも出来る。ただし、既存の,なりすましが困難な本人認証を採用すると、Webページの更新が、ユーザIDとパスワードの入力という簡単な作業では行えなくなってしまう。
開示の技術の課題は、画像データに対する処理をネットワークを介して要求する要求者が本人であることを、ユーザの負荷を増やさずに確認できる技術を提供することにある。
開示の技術の一観点の情報処理装置は、
認証画像データの特徴を表す特徴情報を、ユーザ識別情報に対応づけて記憶する情報記憶部と、
制御部と
を、備え、
前記制御部は、
或る画像データに対する処理をネットワークを介して要求する要求者から、当該画像データと、ユーザ識別情報と、当該画像データに埋め込まれている前記認証画像データの位置を示す位置提示情報とを取得し、
取得した画像データから、取得した位置提示情報が示している位置の画像データを抽出し、抽出した画像データの特徴を表す特徴情報と、取得したユーザ識別情報に対応づけられて前記情報記憶部に記憶されている特徴情報とを比較することにより、前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であるか否かを判定し、
前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であると判定した場合に、前記要求者が要求している前記処理を前記取得した画像データに対して実行する。
認証画像データの特徴を表す特徴情報を、ユーザ識別情報に対応づけて記憶する情報記憶部と、
制御部と
を、備え、
前記制御部は、
或る画像データに対する処理をネットワークを介して要求する要求者から、当該画像データと、ユーザ識別情報と、当該画像データに埋め込まれている前記認証画像データの位置を示す位置提示情報とを取得し、
取得した画像データから、取得した位置提示情報が示している位置の画像データを抽出し、抽出した画像データの特徴を表す特徴情報と、取得したユーザ識別情報に対応づけられて前記情報記憶部に記憶されている特徴情報とを比較することにより、前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であるか否かを判定し、
前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であると判定した場合に、前記要求者が要求している前記処理を前記取得した画像データに対して実行する。
開示の技術によれば、画像データに対する処理をネットワークを介して要求する要求者が本人であることを、ユーザの負荷を増やさずに確認できる技術を提供できる。
以下、図面に基づいて、本発明の実施の形態を説明する。以下の各実施形態の構成は例示であり、本発明は各実施形態の構成に限定されない。
《第1実施形態》
まず、図1~図4を用いて、第1実施形態に係る情報処理装置1の概要を説明する。尚、これらの図のうち、図1は、第1実施形態に係る情報処理装置1の構成及び使用形態の説明図である。図2は、ユーザ端末40の機能ブロック構成例及び情報処理装置1の機能ブロック構成例の説明図である。また、図3は、認証管理サーバ10等として使用可能なコンピュータのハードウェア構成図であり、図4は、ユーザ端末40として使用可能な携帯電話のハードウェア構成図である。
まず、図1~図4を用いて、第1実施形態に係る情報処理装置1の概要を説明する。尚、これらの図のうち、図1は、第1実施形態に係る情報処理装置1の構成及び使用形態の説明図である。図2は、ユーザ端末40の機能ブロック構成例及び情報処理装置1の機能ブロック構成例の説明図である。また、図3は、認証管理サーバ10等として使用可能なコンピュータのハードウェア構成図であり、図4は、ユーザ端末40として使用可能な携帯電話のハードウェア構成図である。
本実施形態に係る情報処理装置1は、ユーザが個人紹介ページを簡単に(自身でサーバを管理しなくても)開設できるWebサービスを提供するための装置である。ここで、ユーザとは、ユーザ登録手続きを行うことにより情報処理装置1からユーザID(IDentification)を取得している者のことである。また、或るユーザの個人紹介ページとは、当該ユーザのプロフィール写真が掲載されるWebページであると共に、当該ユーザが、画像データや動画データを登録(追加)することやプロフィール写真を変更することが可能なWebページのことである。
図1に示してあるように、情報処理装置1は、インターネットに接続された認証管理サーバ10、画像判別サーバ20及びWebサービスサーバ30を含む。
認証管理サーバ10は、インターネットを介した通信が可能なコンピュータに、認証管理サーバ用プログラム15をOS(Operating System)等と共にインストールした装置である。また、画像判別サーバ20は、インターネットを介した通信が可能なコンピュータに、画像判別サーバ用プログラム25をOS等と共にインストールした装置である。同様に、Webサービスサーバ30は、インターネットを介した通信が可能なコンピュータに、Webサービスサーバ用プログラム35をOS等と共にインストールした装置である。尚、認証管理サーバ用プログラム15等のコンピュータへのインストールは、CD-ROM(Compact Disc Read-Only Memory)等の可搬型記録媒体からの読み出しや、他コンピュータの記憶装置からの転送により、行われる。
図2に示してあるように、認証管理サーバ10は、CPUが認証管理サーバ用プログラム15を実行することにより、例えば、ユーザ管理DB11、認証処理部12、開設要求応答部13及び要求応答部14を備えた装置として動作する。また、画像判別サーバ20は、CPUが画像判別サーバ用プログラム25を実行することにより、例えば、特徴情報管理DB21、特徴情報登録部22及び画像判別部23を備えた装置として動作する。さらに、Webサービスサーバ30は、CPUがWebサービスサーバ用プログラム35を実行することにより、個人紹介ページ管理DB31、開設処理部32及び更新処理部33を備えた装置として動作する。
尚、各サーバ用のコンピュータとしては、例えば、図3に示したようなハードウェア構成を有するコンピュータ50が使用される。
このコンピュータ50が備えるシリアルポート52、パラレルポート53、CF(Compact Flash)インタフェースカード59は、プログラムの修正や各種設定を行うために使用されるインタフェースである。フラッシュメモリ55は、OS、各サーバ用のプログラム(認証管理サーバ用プログラム15等)や設定ファイルの記憶に使用されると共に、拡張メモリ領域として使用されるメモリである。
ストレージ56は、各種データを保存しておくために使用されるHDDである。通信カード58は、インターネットを介した通信を行うためのインタフェースカードであり、リアルタイムクロック60は、コンピュータ50の電源が切られても現在時刻を刻み続ける集積回路である。RAM54は、各種処理の作業領域として使用されるメモリであり、チップセット57は、コンピュータ50内の各部間のデータの受け渡しを管理する回路である。CPU51は、フラッシュメモリ55上のプログラム(認証管理サーバ用プログラム15等)を実行することにより、上記した各種機能ブロックとして動作するユニットである。
ユーザ端末40(図1)は、ユーザが、個人紹介ページの開設や更新を情報処理装置1に要求する際に使用する端末装置である。各ユーザのユーザ端末40には、画像データ登録プログラム45がインストールされる。
詳細については後述するが、画像データ登録プログラム45は、一種のWebクライアントである。画像データ登録プログラム45には、IMEI(International Mobile Equipment Identity)が設定されている端末装置用のものと、IMEIが設定されていない端末装置用のものとがある。換言すれば、画像データ登録プログラム45には、IMEIが設定されている携帯電話やデータ通信端末(以下、携帯電話と表記する)用のものと、電話機能を有さない端末装置(以下、PC(Personal Computer)と表記する)用のものとがある。
各タイプの画像データ登録プログラム45は、Webサーバ(例えば、Webサービスサーバ30)からのダウンロードや、CD-ROM(Compact Disc Read-Only Memory)等の可搬型記録媒体により、希望者に提供される。
尚、画像データ登録プログラム45のインストールによりユーザ端末40として使用される携帯電話は、通常、デジタルカメラを内蔵した携帯電話である。
図4に、そのような携帯電話のハードウェア構成例を示す。
この携帯電話80が備えるWiFi(Wireless Fidelity)回路81は、無線LAN用の通信回路である。情報処理装置1へのアクセスには、通常、このWiFi回路81が使用される。
この携帯電話80が備えるWiFi(Wireless Fidelity)回路81は、無線LAN用の通信回路である。情報処理装置1へのアクセスには、通常、このWiFi回路81が使用される。
3G/LTE(3rd. Generation/Long Term Evolution)回路82は、パケット通信用(電話用)の通信回路である。マイクロフォン(“マイク”)88は、音をアナログ電気信号に変換する装置であり、ラウドスピーカー(“スピーカー”)90は、アナログ電気信号を音に変換する装置である。サウンドチップ89は、マイクロフォン88から出力されるアナログ信号をデジタル信号に変換する処理や、チップセット87側から入力されたデジタル信号をアナログ信号に変換してラウドスピーカー90に供給する処理を行う回路である。
タイマー92は、いわゆるウォッチドッグタイマーである。液晶ディスプレイ86は、各種情報の表示装置である。入力装置84は、携帯電話80に情報を入力するための装置である。この入力装置84は、携帯電話80の筐体上に設けられている押しボタンスイッチと、液晶ディスプレイ86上に配置されている,透明なタッチパネルとを含む。
ストレージ83は、各種情報を記憶しておくためのユニットである。このストレージ83は、様々なプログラムやデータが記録されたフラッシュメモリ(図2では、ROM: Read Only Memory)と、プログラムやデータの一時記憶領域として使用されるRAM(Random Access Memory)とを含む。
携帯電話80内の2つのカメラ85は、いずれも、光学像(撮影結果)を表す画像データを生成するデジタルカメラである。一方のカメラ85(インカメラやフロントカメラと呼ばれているもの)は、液晶ディスプレイ86を見ている操作者を撮影できるように携帯電話80の筐体に取り付けられている。また、他方のカメラ85(アウトカメラやメインカメラと呼ばれているもの)は、逆方向を撮影できるように携帯電話80の筐体に取り付けられている。尚、各カメラ85の出力は、動画データを生成するためにも使用される。
チップセット87は、携帯電話80内の各デバイス間のデータの受け渡しを管理する回路である。チップセット87内のグラフィックアクセラレータは、液晶ディスプレイ86に所望の画像を表示させるための処理をCPU91の代わりに行う回路である。CPU91は、各種プログラムをフラッシュメモリからRAM上に読み出して実行するユニットである。
ユーザ端末40がこの携帯電話80である場合、画像データ登録プログラム45(携帯電話用のもの)は、ストレージ83のフラッシュメモリ(ROM)に格納される。そして、ユーザ端末40(携帯電話80)内のCPU91は、入力装置84に対して所定の操作がなされたときに、画像データ登録プログラム45をストレージ83のRAM上に読み出して実行する。
また、ユーザ端末40がPCである場合、画像データ登録プログラム45(PC用のもの)は、当該PC内のHDD(Hard Disk Drive)又はSDD(Solid State Drive)に格納される。そして、ユーザ端末40(PC)内のCPUは、キーボードやマウスの操作により画像データ登録プログラム45の実行が指示されたときに、画像データ登録プログラム45をRAM上に読み出して実行する。
そして、CPUが画像データ登録プログラム45を実行したユーザ端末40は、図2に示してあるように、例えば、認証画像記憶部41及び要求送信部42を備えた装置として動作する。
以下、情報処理装置1の機能を、ユーザ端末40の機能と共に具体的に説明する。尚、以下の説明において、画像/動画データとは、画像データ又は動画データのことである。また、プロフィール写真データとは、個人紹介ページにプロフィール写真として掲載される写真の画像データのことである。
ユーザ端末40(図2)が備える認証画像記憶部41は、認証画像の画像データである認証画像データを保存しておくための記憶部(記憶領域)である。詳細については後述するが、認証画像とは、本人認証に使用される既定サイズの画像のことである。ユーザ端末40のCPU(例えば、CPU91)は、画像データ登録プログラム45の初回実行時に、何も記憶していない認証画像記憶部41をユーザ端末40内に用意する。そして、CPUは、自ユーザ端末40のユーザ用の個人紹介ページが開設されたときに、この認証画像記憶部41に認証画像データを記憶する。尚、携帯電話80(図4)であるユーザ端末40では、ストレージ83内のフラッシュメモリ(ROM)の一部の記憶領域が、認証画像記憶部41として使用される。また、PCであるユーザ端末40では、HDD又はSDDの一部の記憶領域が認証画像記憶部41として使用される。
要求送信部42は、ユーザ端末40の操作者から対話形式で各種情報を取得し、取得した情報に基づき、各種要求を生成して認証管理サーバ10に対して送信するユニット(詳細は後述)である。
Webサービスサーバ30内の個人紹介ページ管理DB31は、開設済みの各個人紹介ページに関する情報(URL(Uniform Resource Locator)、開設日時等)を、各個人紹介ページの所有者(開設者)のユーザIDに対応づけて記憶しておくためのデータベースである。
開設処理部32は、各ユーザの個人紹介ページを開設してインターネット上で公開するユニット(機能ブロック)である。開設処理部32は、ユーザIDとプロフィール写真の画像データとテキスト情報とを含む開設要求を認証管理サーバ10から受信したときに、当該ユーザIDで識別されるユーザについての個人紹介ページを開設する。さらに、開設処理部32は、開設した個人紹介ページのURL等を当該ユーザIDに対応づけた形で個人紹介ページ管理DB31に記憶する処理も行う。そして、一連の処理を終えた開設処理部32は、認証管理サーバ10に対して完了通知を送信する。
Webサービスサーバ30内の更新処理部33は、各ユーザの個人紹介ページの内容を更新する処理を担当するユニットである。更新処理部33は、ユーザIDと画像/動画データとを少なくとも含む登録要求を認証管理サーバ10から受信する。登録要求を受信した更新処理部33は、個人紹介ページ管理DB31を参照することにより、当該登録要求中のユーザIDで識別されるユーザについての個人紹介ページを特定する。そして、更新処理部33は、特定した個人紹介ページに、登録要求の要素として受信した画像/動画データを登録(追加)する。また、更新処理部33は、受信した登録要求中にテキスト情報が含まれていた場合には、当該テキスト情報を個人紹介ページに追加する処理も行う。そして、画像/動画データの登録等を終えた更新処理部33は、認証管理サーバ10に対して完了通知を送信する。
また、更新処理部33は、認証管理サーバ10から、少なくともユーザIDとプロフィール写真データ(プロフィール写真の画像データ)とを含むプロフィール写真変更要求(以下、変更要求とも表記する)も受信する。変更要求を受信した更新処理部33は、個人紹介ページ管理DB31を参照することにより、当該変更要求中のユーザIDで識別されるユーザについての個人紹介ページを特定する。そして、更新処理部33は、特定した個人紹介ページのプロフィール写真データを、登録要求の要素として受信したプロフィール写真データに変更する。また、更新処理部33は、受信した変更要求中にテキスト情報が含まれていた場合には、プロフィール写真と共に掲載していたテキスト情報を変更要求中のテキスト情報に変更する処理も行う。そして、プロフィール写真データの変更等を終えた更新処理部33は、認証管理サーバ10に対して完了通知を送信する。
認証管理サーバ10内のユーザ管理DB11は、各ユーザのユーザID及びパスワードを、各ユーザの個人情報(姓名、住所等)や、各ユーザに提供されているサービスに関する情報と共に記憶しておくためのデータベースである。
認証処理部12は、ユーザID及びパスワードによる本人認証を行うユニットである。各ユーザの情報処理装置1へのログイン時には、各ユーザのユーザ端末40から、ログイン情報(ユーザID及びパスワード)を含むログイン要求が認証処理部12に対して送信されてくる。或るユーザ端末40からのログイン要求を受信した場合、認証処理部12は、当該ログイン要求に含まれるログイン情報と同じログイン情報が、ユーザ管理DB11に登録されているか否かを判断する。そして、認証処理部12は、受信したログイン情報と同じログイン情報がユーザ管理DB11に登録されていた場合には、ログインが完了した旨を示す情報(以下、ログイン完了通知と表記する)をユーザ端末40に返送する。また、認証処理部12は、受信したログイン情報と同じログイン情報がユーザ管理DB11に登録されていなかった場合には ログインに失敗した旨を示す情報をユーザ端末40に返送する。
尚、認証処理部12によりログインが認められると、いわゆるセッション管理が開始される。すなわち、ユーザ端末40から送信される各情報中にセッション追跡パラメータが含められ、当該セッション追跡パラメータに基づき認証管理サーバ10側で情報の送信者が特定される状態となる
認証処理部12は、ユーザ登録を受け付ける機能も有している。当該機能を簡単に説明すると、認証処理部12は、ユーザ登録時、ユーザ登録の要求者(ユーザ端末40の操作者)に付与するユーザIDを決定して要求者に通知する。また、認証処理部12は、各種Webページにより、要求者に個人情報(名前等)やパスワードを入力させる。認証処理部12は、ユーザ登録に必要な情報を取得できた場合には、それらの情報を、要求者に通知したユーザIDと共に、新規ユーザに関する情報としてユーザ情報DB11に登録する。そして、認証処理部12は、ユーザ登録が完了した旨を示す情報をユーザ端末40に対して送信する。
画像判別サーバ20内の特徴情報管理DB21は、各ユーザの認証画像に関する特徴情報(詳細は後述)を、各ユーザのユーザIDに対応づけて記憶しておくためのデータベースである。
認証管理サーバ10の開設要求応答部13は、画像判別サーバ20の特徴情報登録部22及びWebサービスサーバ30の開設処理部32と連携して、ユーザ端末40からの開設要求を処理するユニット(機能ブロック)である。また、認証管理サーバ10の要求応答部14は、画像判別サーバ20の画像判別部23及びWebサービスサーバ30の更新処理部33と連携して、ユーザ端末40からの登録要求及びプロフィール写真変更要求を処理するユニットである。尚、ユーザ端末40からの開設要求、登録要求、プロフィール写真変更要求とは、認証管理サーバ10(開設要求応答部13及び要求応答部14)によって、Webサービスサーバ30に対する同名の要求に変換される要求のことである。
まず、開設要求応答部13、特徴情報登録部22及び開設処理部32による開設要求の処理手順を、ユーザ端末40(要求送信部42)による開設要求の送信手順と共に説明する。
要求送信部42は、動作を開始すると、まず、ディスプレイ(液晶ディスプレイ86等)上に、画像処理装置1にログインするためのログインページを表示する。より具体的には、要求送信部42は、所定のリクエストをインターネット上に送信することにより、画像処理装置1からログインページのソースデータを取得する。そして、要求送信部42は、取得したソースデータに基づく描画を行うことにより、ディスプレイ上にログインページを表示する。
ユーザ端末40の操作者は、ユーザ登録が完了している場合には、当該ログインページに自身のユーザID及びパスワードを入力することにより、画像処理装置1にログインする。また、操作者は、ユーザ登録を完了していない場合には、ログインページ上に設けられているユーザ登録ページへのリンクの操作で始まる一連の操作によりユーザ登録を行ってから、画像処理装置1にログインする。
要求送信部42は、操作者のログインが完了した場合(すなわち、上記したログイン完了通知を受信した場合)には、認証画像データが認証画像記憶部41に記憶されているか否かを判断する。既に説明したように、個人紹介ページをまだ開設していないユーザのユーザ端末40内の認証画像記憶部41には、認証画像データが記憶されていない。そのため、要求送信部42は、認証画像データが認証画像記憶部41に記憶されていなかった場合、自端末の操作者についての個人紹介ページを画像処理装置1に開設させるための個人紹介ページ開設要求処理を開始する。
要求送信部42が実行する個人紹介ページ開設要求処理は、例えば、図5に示した手順の処理である。
すなわち、この個人紹介ページ開設要求処理を開始した要求送信部42は、まず、プロフィール写真データ取得処理(ステップS101)を行う。本実施形態に係る要求送信部42が行うプロフィール写真データ取得処理は、個人紹介ページにプロフィール写真として掲載する写真の画像データを自ユーザ端末40の操作者に撮影又は選択させる処理である。また、プロフィール写真データ取得処理は、プロフィール写真と共に掲載するテキスト情報を操作者に入力させる処理ともなっている。
以下、ユーザ端末40が携帯電話80である場合を例に、本実施形態に係る要求送信部42が行うプロフィール写真データ取得処理の内容を説明する。
プロフィール写真データ取得処理を開始した要求送信部42は、まず、所定の画面(以下、第1選択画面と表記する)を液晶ディスプレイ86上に表示することにより、プロフィール写真を撮影済みの写真とするか新たに撮影するかを操作者に選択させる。
プロフィール写真を新たに撮影することを操作者が選択した場合、要求送信部42は、図6に示したようなプロフィール写真撮影用画面を液晶ディスプレイ86上に表示する。
このプロフィール写真撮影用画面は、フレーム95内に示されているメッセージが一定時間経過すると消える画面である。また、プロフィール写真撮影用画面は、操作者撮影用のカメラ85の,その時点における撮影結果がフレーム95内に表示される画面であると共に、実際に撮影される写真よりも、数パーセント程度、サイズが小さなフレーム95が示される画面となっている。
要求送信部42は、プロフィール写真撮影用画面上の“撮影”ボタンが押下されたときに、操作者撮影用のカメラ85の,その時点における撮影結果を、プロフィール写真データとしてストレージ83に記憶する。そして、要求送信部42は、プロフィール写真と共に掲載するテキスト情報を操作者から取得する処理を行ってから、プロフィール写真データ取得処理を終了する。
一方、プロフィール写真を撮影済みの写真とすることを操作者が選択した場合、要求送信部42は、プロフィール写真データを既存の画像データの中から選択させるためのプロフィール写真選択画面を液晶ディスプレイ86上に表示する。要求送信部42は、操作者により或る画像データが選択された場合には、当該画像データがプロフィール写真データであることを記憶する。そして、要求送信部42は、プロフィール写真と共に掲載するテキスト情報を操作者から取得する処理を行ってから、プロフィール写真データ取得処理を終了する。
尚、携帯電話(携帯電話であるユーザ端末40)の要求送信部42が、上記した第1選択画面を表示するのは、携帯電話がインカメラ(携帯電話80における操作者撮影用のカメラ85に相当するもの)を備えている場合だけである。インカメラを備えない携帯電話の要求送信部42は、第1選択画面を表示することなく、プロフィール写真選択画面を表示する。
また、PCであるユーザ端末40内の要求送信部42が行うプロフィール写真データ取得処理も、上記したものと同様の処理である。すなわち、PC内の要求送信部42が行うプロフィール写真データ取得処理も、PCの操作者が、プロフィール写真データを、PCに接続されたWebカメラ等を利用して撮影することも既存の画像データの中から選択することも可能な処理となっている。
プロフィール写真データ取得処理(図5、ステップS101)を終えた要求送信部42は、操作者が撮影/選択したプロフィール写真データ(図5では、処理対象画像データ)のX方向サイズ(画素数)Lx及びY方向サイズLyを特定する(ステップS102)。また、要求送信部42は、自ユーザ端末40の端末固有情報も特定する(ステップS102)。
携帯電話であるユーザ端末40内の要求送信部42が、このステップS102の処理時に端末固有情報として特定する情報は、自携帯電話内に設定されているIMEIである。また、PCであるユーザ端末40内の要求送信部42が、端末固有情報として特定する情報は、PC内のNIC(Network Interface Card)に設定されているMAC(Media Access Control)アドレスである。
ステップS102の処理を終えた要求送信部42は、領域位置特定処理(ステップS103)を行う。
領域位置特定処理は、特定した端末固有情報に基づき、端末固有情報の値により処理結果が異なるアルゴリズムにて、認証画像領域の,プロファイル写真(図5では、処理対象画像)上における位置を特定する処理である。ここで、認証画像領域とは、その内部の画像が、上記した“既定サイズの認証画像”として取り扱われる矩形領域のことである。換言すれば、認証画像領域とは、その内部の画像を表す画像データが、上記した認証画像データとして取り扱われる矩形領域のことである。尚、領域位置特定処理としては、通常、プロフィール写真の縁近傍の領域を認証画像領域として特定する処理が採用される。
以下、領域位置特定処理の一例(領域位置特定処理時の要求送信部42の動作例)を、説明する。尚、以下の説明において、Sx、Syとは、それぞれ、認証画像(認証画像領域)のX方向サイズ、Y方向サイズとして予め設定されている値のことである。また、Rhとは、その中から認証画像領域が選択される選択対象領域の高さ(Y方向サイズ)として予め設定されている値のことである。Sx、Syとしては、通常、5~20程度の値が使用され、Rhとしては、例えば、100程度の値(例えば、“80”)が使用される。
領域位置特定処理を開始した要求送信部42は、まず、ステップS102の処理で特定した端末固有情報から、シリアル番号/シリアルIDを表している部分(以下、シリアル番号情報と表記する)を抽出する。すなわち、IMEIは、1桁目から8桁目までの数字列が、製造元、機種及び生産国を示す情報となっており、9桁目から14桁目までの数字列がシリアル番号となっており、15桁目の数字がチェックデジットとなっている15桁の情報である。また、MACアドレスは、上位32ビットがネットワーク機器の機種名等を示す情報となっており、下位16ビットがシリアルIDとなっている情報である。従って、携帯電話であるユーザ端末40内の要求送信部42は、端末固有情報(IMEI)から、9桁目から14桁目までの数字列をシリアル番号情報として抽出する。また、PCであるユーザ端末40内の要求送信部42は、端末固有情報(MACアドレス)から、下位16ビット分の情報をシリアル番号情報として抽出する。
その後、要求送信部42は、抽出したシリアル番号情報を、前半の情報と後半の情報とに2分する。次いで、要求送信部42は、前半の情報が表している数値を“Lx-Sx+1”で割った余りを算出し、算出結果を認証画像領域の始点のX座標値x0として記憶する。ここで、認証画像領域の始点とは、認証画像領域の4頂点の中の、処理対象画像データに基づく画像表示を行ったときに左上側に示されることになる頂点のことである。
また、要求送信部42は、後半の情報が表している数値を“Rh-Sy+1”で割った余りを算出し、算出結果を認証画像領域の始点のY座標値y0として記憶する。そして、要求送信部42は、領域位置特定処理を終了する。
要するに、或る数値を“Lx-Sx+1”で割った余りは、“0”以上、“Lx-Sx”以下の値となる。また、或る数値を“Rh-Sy+1”で割った余りは、“0”以上、“Rh-Sy”以下の値となる。そして、Sx、Syは、それぞれ、認証画像領域のX方向サイズ、Y方向サイズである。従って、上記手順の領域位置特定処理は、図7にハッチングを付して示してある選択対象領域112内にその全てが収まるように、認証画像領域110の始点位置を端末固有情報から求める処理となっていることになる。
尚、上記したプロフィール写真撮影用画面(図6)のフレーム95を、実際に撮影される写真よりも、数パーセント程度、サイズが小さなものとしているのは、選択対象領域112がプロフィール写真の背景部分に入るようにするためである。また、領域110,112のプロフィール写真に対するサイズ比が図7に示したものとなるのは、Lx、Lyがそれぞれ、768、1024であり、Sx、Syが共に10であり、選択対象領域112の高さRhが80である場合である。プロフィール写真のサイズ(Lx,Ly)がより大きな場合、選択対象領域112、認証画像領域110のプロフィール写真に対するサイズ比はより小さくなる。逆に、プロフィール写真のサイズがより小さな場合、選択対象領域112、認証画像領域110のプロフィール写真に対するサイズ比はより大きくなる。
領域位置特定処理としては、上記したものとは処理手順が異なるもの、例えば、一方の座標値しか算出しないものや、Lxの代わりに500程度の固定値を使用するもの、を採用することも出来る。ただし、以下では、上記した『端末識別情報とLxとSxとSyとRhとから認証画像領域の始点のX座標値、Y座標値を算出する領域位置特定処理』がステップS103にて実行されるとして、情報処理装置1及びユーザ端末40の機能を説明することにする。
図5に戻って、個人紹介ページ開設要求処理の説明を続ける。
領域位置特定処理を終えた要求送信部42は、操作者が撮影/選択したプロフィール写真データから、領域位置特定処理によりその位置を特定した認証画像領域内の画像に関する画像データを抽出する(ステップS104)。すなわち、要求送信部42は、対角の2頂点の座標が(x0、y0)及び(x0+Sx-1、y0+Sy-1)である矩形画像に関する画像データを、操作者が撮影/選択したプロフィール写真データから抽出する。
領域位置特定処理を終えた要求送信部42は、操作者が撮影/選択したプロフィール写真データから、領域位置特定処理によりその位置を特定した認証画像領域内の画像に関する画像データを抽出する(ステップS104)。すなわち、要求送信部42は、対角の2頂点の座標が(x0、y0)及び(x0+Sx-1、y0+Sy-1)である矩形画像に関する画像データを、操作者が撮影/選択したプロフィール写真データから抽出する。
そして、要求送信部42は、抽出した画像データを、認証画像データとして認証画像記憶部41に記憶してから、ステップS104の処理を終了する。
尚、ステップS104の処理は、操作者が撮影/選択したプロフィール写真データの内容を変更することなく、ビットマップ形式の認証画像データを認証画像記憶部41に記憶する処理である。具体的には、例えば、プロフィール写真データが、JPEG(Joint Photographic Experts Group)データであった場合、ステップS104では、まず、JPEGデータからビットマップ画像データが生成される。そして、生成したビットマップ画像データから、上記矩形画像に関する画像データが抽出され、認証画像データとして認証画像記憶部41に記憶される。また、プロフィール写真データが、ビットマップ画像データであった場合、ステップS104では、そのビットマップ画像データから、上記矩形画像に関する画像データが読み出され、認証画像データとして認証画像記憶部41に記憶される。
ステップS104の処理を終えた要求送信部42は、操作者が撮影/選択したプロフィール写真データ、操作者が入力したテキスト情報、及び特定した端末固有情報を含めた開設要求を認証管理サーバ10に対して送信する(ステップS105)。
認証管理サーバ10に対して送信された開設要求は、認証管理サーバ10の開設要求応答部13(図2)により受信される。
そして、開設要求を受信した開設要求応答部13は、例えば、図8に示した手順の開設要求応答処理を開始する。
尚、開設要求応答部13は、開設要求を受信した場合、開設要求応答処理を実際に開始する前に、受信した開設要求が適式なものであるか不適式なもの(例えば、MACアドレス/IMEIではないことが明らかな端末固有情報を含むもの)であるかを判断する。そして、開設要求応答部13は、開設要求が不適式なものであった場合には、開設要求応答処理を開始することなく、受信した要求に応答できない旨を示す応答不可通知を、開設要求を送信してきたユーザ端末40(以下、要求送信元と表記する)に返送する。また、開設要求応答部13は、受信した開設要求が適式なものであった場合、当該開設要求に含まれるセッション追跡パラメータから、開設要求者のユーザID(以下、開設要求者IDと表記する)を特定する。次いで、開設要求応答部13は、特定した開設要求者IDを用いてユーザ管理DB11内の情報を検索することにより、開設要求者が個人紹介ページを既に開設している者であるか否かを判断する。そして、開設要求応答部13は、開設要求者が個人紹介ページを開設していない者であった場合には、開設要求応答処理を開始し、そうでなかった場合には、開設要求応答処理を開始することなく、応答不可通知を要求送信元に返送する。
図8に示してあるように、この開設要求応答処理を開始した開設要求応答部13は、まず、処理対象画像データ、処理対象端末固有情報及び開設要求者IDを含めた特徴情報登録要求を画像判別サーバ20に対して送信する(ステップS201)。ここで、処理対象画像データ、処理対象端末固有情報とは、それぞれ、受信した開設要求に含まれていた画像データ(つまり、プロフィール写真データ)、端末固有情報のことである。また、開設要求者IDとは、既に定義したように、受信した開設要求に含まれるセッション追跡パラメータから特定した開設要求者のユーザIDのことである。
画像判別サーバ20に対して送信された特徴情報登録要求は、特徴情報登録部22(図2)により受信される。そして、特徴情報登録要求を受信した特徴情報登録部22は、例えば、図9に示した手順の特徴情報登録要求応答処理を開始する。
すなわち、特徴情報登録要求を受信した特徴情報登録部22は、まず、特徴情報登録要求の要素として受信した画像データ(以下、処理対象画像データと表記する)のx方向サイズLx、Y方向サイズLyを特定する(ステップS251)。
続くステップS252にて、特徴情報登録部22は、ユーザ端末40内で行われるものと同内容の領域位置特定処理により、処理対象画像データが表している処理対象画像上における認証画像領域の位置を特定する。
すなわち、ステップS252にて、特徴情報登録部22は、処理対象端末固有情報からシリアル番号情報を抽出する。そして、特徴情報登録部22は、抽出したシリアル番号情報の前半の情報が表している数値を“Lx-Sx+1”で割った余りを、認証画像領域の始点のX座標値x0として算出する。また、特徴情報登録部22は、抽出したシリアル番号情報の後半の情報が表している数値を“Rh-Sy+1”で割った余りを、認証画像領域の始点のY座標値y0として算出する。
領域位置特定処理を終えた特徴情報登録部22は、当該領域位置特定処理によりその位置を特定した認証画像領域内の画像に関する画像データを、処理対象画像データから抽出する(ステップS253)。すなわち、特徴情報登録部22は、個人紹介ページ開設要求処理(図5)のステップS104の処理時に抽出されたものと同じ画像データをプロフィール写真データから抽出する。
そして、特徴情報登録部22は、抽出した画像データの特徴を表す特徴情報を生成(ステップS254)し、生成した特徴情報を、開設要求者IDに対応づけて特徴情報管理DB21に記憶する(ステップS255)。特徴情報の用途については後述するが、或る画像データの特徴情報としては、例えば、当該画像データの輝度別/輝度区分別の輝度ヒストグラムデータや、色別/色区分別の色ヒストグラムデータを使用できる。
ステップS255の処理を終えた特徴情報登録部22は、完了通知を認証管理サーバ10(開設要求応答部13)に対して送信する(ステップS256)。そして、特徴情報登録部22は、この特徴情報登録要求応答処理を終了する。
特徴情報登録要求を画像判別サーバ20(特徴情報登録部22)に対して送信した開設要求応答部13は、この完了通知が画像判別サーバ20から送信されてくるのを待機している(図8、ステップS201)。
そして、開設要求応答部13は、完了通知を受信した場合には、処理対象画像データ及び処理対象テキスト情報と開設要求者IDとを含めた開設要求をWebサービスサーバ30(開設処理部32)に対して送信する(ステップS202)。ここで、処理対象テキスト情報とは、受信した開設要求に含まれていたテキスト情報のことである。また、処理対象画像データとは、既に定義したように、受信した開設要求に含まれていた画像データ(つまり、プロフィール写真データ)のことである。
既に説明したように、開設要求を受信した開設処理部32は、開設要求中の情報に基づき、開設要求者用の個人紹介ページを開設してから、完了通知を認証管理サーバ10(開設要求応答部13)に対して送信する。開設要求をWebサービスサーバ30に対して送信した開設要求応答部13は、この完了通知がWebサービスサーバ30から送信されてくるのを待機する(ステップS202)。
完了通知が送信されてきた場合、開設要求応答部13は、開設要求者についての個人紹介ページの開設が完了した旨を示す情報をユーザ管理DB11に追加する(ステップS203)。そして、開設要求応答部13は、要求送信元に対して完了通知を送信(ステップS204)してから、この開設要求応答処理(図8)を終了する。
開設要求を認証管理サーバ10に対して送信した要求送信部42は、この完了通知の受信を待機している(図5、ステップS105)。そして、要求送信部42は、完了通知を受信した際に、ステップS105の処理、及び、個人紹介ページ開設要求処理(図5の処理)を終了する。
次に、要求応答部14、画像判別部23及び更新処理部33による登録要求の処理手順を、ユーザ端末40(要求送信部42)による登録要求の送信手順と共に説明する。
要求送信部42は、操作者のログインの完了後に認証画像記憶部41に認証画像データが記憶されていることを見出した場合、ディスプレイ上に所定の作業選択画面を表示することにより、以下のいずれの作業を行うのかを操作者に選択させる。
・個人紹介ページへの画像/動画の追加
・プロフィール写真の変更
・個人紹介ページへの画像/動画の追加
・プロフィール写真の変更
そして、要求送信部42は、“個人紹介ページへの画像/動画の追加”を操作者が選択した場合には、画像/動画登録要求処理を開始し、“プロフィール写真の変更”を操作者が選択した場合には、プロフィール写真変更要求処理を開始する。
画像/動画登録要求処理は、例えば、図10に示した手順の処理である。
すなわち、個人紹介ページへの画像/動画の追加を操作者が選択したため、この画像/動画登録要求処理を開始した要求送信部42は、まず、登録対象データ取得処理(ステップS151)を行う。
すなわち、個人紹介ページへの画像/動画の追加を操作者が選択したため、この画像/動画登録要求処理を開始した要求送信部42は、まず、登録対象データ取得処理(ステップS151)を行う。
登録対象データ取得処理は、個人紹介ぺージに登録(追加)するデータを、以下の画像/動画データの中から操作者が選択できるように、上記したプロフィール写真データ取得処理を変形した処理である。
・既存の画像データ又は動画データ
・新たに撮影する画像データ又は動画データ
・既存の画像データ又は動画データ
・新たに撮影する画像データ又は動画データ
以下、この登録対象データ取得処理時に、操作者が、撮影するか既存のデータの中から選択した画像データ又は動画データのことを、登録対象データと表記する。
登録対象データ取得処理を終えた要求送信部42は、登録対象データのX方向サイズLx及びY方向サイズLyと、自ユーザ端末40の端末固有情報とを特定する(ステップS152)。
このステップS152の処理は、処理対象が動画データである場合があることを除けば、上記したステップS102の処理と同じ処理である。すなわち、携帯電話であるユーザ端末40内の要求送信部42は、このステップS152において、自携帯電話に設定されているIMEIを、端末固有情報として特定する。また、PCであるユーザ端末40内の要求送信部42は、自PCのNICに設定されているMACアドレスを、端末固有情報として特定する。
ステップS152の処理を終えた要求送信部42は、特定した端末固有情報及びLxを用いて、ステップS103(図5)で行われるものと同内容の領域位置特定処理を行う(ステップS153)。
その後、要求送信部42は、登録対象データ中の,領域位置特定処理にてその位置を特定した認証画像領域内の画像に関する画像データを認証画像データに置換したデータを生成する(ステップS154)。
具体的には、このステップS154にて、要求送信部42は、まず、登録対象データが画像データであるか動画データであるかを判断する。
登録対象データが画像データであった場合、要求送信部42は、登録対象データのコピーをRAM上に用意する。次いで、要求送信部42は、用意したコピー中の,認証画像領域内の画像に関する画像データを、認証画像記憶部41に記憶されている認証画像データに置換する。すなわち、要求送信部42は、用意したコピー中の,対角の2頂点座標が(x0、y0)及び(x0+Sx-1、y0+Sy-1)となっている画像に関する画像データを、認証画像記憶部41に記憶されている認証画像データに置換する。
一方、登録対象データが動画データであった場合、要求送信部42は、登録対象データのコピーをRAM上に用意する。そして、要求送信部42は、用意したコピー中の先頭フレームに関する画像データ中の,認証画像領域内の画像に関する画像データを、認証画像記憶部41に記憶されている認証画像データに置換する。
尚、登録対象データは、画像データ、動画データのいずれである場合も、通常、非可逆圧縮されている。従って、ステップS154では、通常、“非可逆圧縮されている画像データを伸張し(換言すれば、画像データの形式をビットマップ形式に変換し)、その一部を認証画像データに置換してから、非可逆圧縮し直す処理”が行われる。
ステップS154の処理を終えた要求送信部42は、生成した画像/動画データ、操作者から取得したテキスト情報、及びステップS152の処理時に特定した端末固有情報を含めた登録要求を認証管理サーバ10に対して送信する(ステップS155)。
認証管理サーバ10に対して送信された登録要求は、認証管理サーバ10の要求応答部13(図2)により受信される。
そして、登録要求を受信した要求応答部14は、例えば、図11に示した手順の登録要求応答処理を開始する。
尚、要求応答部14は、受信した登録要求が適式なものであり、且つ、要求送信者が個人紹介ページを既に開設している者であることが確認できた場合に限り、登録要求応答処理を開始する。受信した登録要求が適式なものでなかった場合や、要求送信者が個人紹介ページをまだ開設していない者であった場合、要求応答部14は、登録要求応答処理を開始することなく、応答不可通知を、要求送信元(登録要求を送信してきたユーザ端末40)に返送する。
図11に示してあるように、この登録要求応答処理時、要求応答部14は、まず、処理対象端末固有情報、判定対象画像データ及び要求送信者IDを含めた認証要求を画像判別サーバ20に対して送信する(ステップS301)。ここで、処理対象端末固有情報とは、受信した登録要求に含まれていた端末固有情報のことである。また、判定対象画像データとは、受信した登録要求に画像データが含まれていた場合には、当該画像データのことであり、受信した登録要求に動画データが含まれていた場合には、当該動画データに含まれる,先頭フレームに関する画像データのことである。さらに、要求送信者IDとは、要求送信者がログイン時に入力したユーザIDのことである。この要求送信者IDは、登録要求中のセッション追跡パラメータから特定される。
認証管理サーバ10に対して送信された認証要求は、画像判別部23(図2)により受信される。認証要求を受信した画像判別部23は、例えば、図12に示した手順の認証要求応答処理を開始する。
すなわち、認証要求を受信した画像判別部23は、まず、判定対象画像データのx方向サイズLx、Y方向サイズLyを特定する(ステップS351)。ここで、判定対象画像データ、処理対象端末固有情報とは、それぞれ、受信した認証要求中の画像データ、端末固有情報のことである。
続くステップS352にて、特徴情報登録部22は、処理対象端末固有情報を、特定したLx等と共に用いて、ユーザ端末40内で行われるものと全く同内容の領域位置特定処理を行う。
その後、特徴情報登録部22は、領域位置特定処理によりその位置を特定した認証画像領域内の画像に関する画像データを、処理対象画像データから抽出する(ステップS353)。次いで、特徴情報登録部22は、抽出した画像データ(以下、認証画像領域データと表記する)の特徴を表す特徴情報を、ステップS254における特徴情報の生成アルゴリズムと同じアルゴリズムにて生成する(ステップS354)。
そして、画像判別部23は、生成した特徴情報と、特徴情報管理DB21内の,要求送信者IDに対応づけられている特徴情報とを比較することにより、要求送信者が、要求送信者IDの正当保有者であるか否かを判定する処理(ステップS355)を行う。ここで、要求送信者IDとは、受信した認証要求中のユーザIDのことであり、要求送信者IDの正当保有者とは、要求送信者IDが実際に付与されているユーザのことである。
より具体的には、このステップS355において、画像判別部23は、まず、要求送信者ID(受信した認証要求中のユーザID)に対応づけられている特徴情報を特徴情報管理DB21から読み出す。次いで、画像判別部23は、生成した特徴情報と読み出した特徴情報との間の非類似性の程度を示す非類似度を求める。尚、画像判別部23が求める非類似度は、両特徴情報の違いが大きくなるにつれ、値が大きくなる数値である。
そして、画像判別部23は、求めた非類似度が予め設定されている閾値以下であった場合に、要求送信者が要求送信者IDの正当保有者であると判定し、そうではなかった場合に、要求送信者が要求送信者IDの正当保有者ではないと判定する。
要するに、特徴情報管理DB21には、各ユーザ端末40の認証画像記憶部41内の認証画像データと同じ画像データに関する特徴情報が、各ユーザ端末40のユーザのユーザIDに対応づけられて記憶されている。そして、或るユーザ端末40からの更新要求中の画像データ(又は動画データ)には、当該ユーザ端末40の認証画像記憶部41内の認証画像データが、更新要求中の端末固有情報から特定できる位置に埋め込まれている。
従って、埋め込まれた認証画像データ自体を更新要求中の画像データから抽出できるのであれば、ステップS355の処理を、上記2特徴情報が一致しているか否かを判断する処理とすることが出来る。ただし、画像/動画登録要求処理(図10)の内容から明らかなように、認証要求応答処理における“判定対象画像データ”は、通常、“非可逆圧縮されている画像データを伸張し、その一部を認証画像データに置換してから非可逆圧縮し直したデータ”となっている。
従って、判定対象画像データからは、通常、元の認証画像データとは幾つかの画素の値が異なる画像データが、認証画像領域データとして抽出される。そのような,元の認証画像データとは内容が若干異なる認証画像領域データが抽出されても、要求送信者が要求送信者IDの正当保有者であると判定できるようにするために、ステップS355の処理を、上記手順の処理としているのである。
尚、ステップS355の処理時における非類似度としては、様々な情報を用いることが出来る。例えば、特徴情報が輝度ヒストグラムデータである場合には、輝度(又は輝度区分)が同じ画素数の差の二乗値や絶対値の総和等を非類似度として使用できる。特徴情報が色ヒストグラムデータである場合には、色(又は色区分)が同じ画素数の差の二乗値や絶対値の総和等を非類似度として使用できる。
また、ステップS355の処理における閾値は、SX及びSYの値や特徴情報及び非類似度の種類(算出アルゴリズム)に応じて適切な値が変化する情報である。そのため、閾値としては、SX及びSYの値と特徴情報及び非類似度の種類とを決定した後、実際に何種類かの画像データについて非類似度を算出し、算出結果の最大値よりも数%大きな値を採用すれば良い。
ステップS355の処理を終えた画像判別部23は、要求送信者が要求送信者IDの正当保有者であると判定した場合(ステップS356;YES)には、認証管理サーバ10(要求応答部14)に対して認証成功通知を送信する(ステップS357)。一方、要求送信者が要求送信者IDの正当保有者ではないと判定した場合(ステップS356;NO)、画像判別部23は、認証管理サーバ10(要求応答部14)に対して認証失敗通知を送信する(ステップS358)。そして、ステップS357又はS358の処理を終えた画像判別部23は、この認証要求応答処理を終了する。
図10に示してあるように、認証要求を送信した要求応答部14は、画像判別サーバ20(画像判別部23)からの認証成功通知か認証失敗通知が送信されてくるのを待機している(ステップS301)。
そして、要求応答部14は、認証成功通知を受信した場合(ステップS302;成功)には、受信済みの登録要求中の画像/動画データ及びテキスト情報と、要求送信者IDとを含めた登録要求をWebサービスサーバ30に送信する(ステップS303)。
Webサービスサーバ30に対して送信された更新処理部33により受信される。そして、登録要求を受信した更新処理部33は、既に説明したように、要求送信者の個人紹介ページに画像/動画データ等を追加してから、完了通知を認証管理サーバ10に対して送信する。
登録要求をWebサービスサーバ30(更新処理部33)に対して送信した要求応答部14は、この完了通知がWebサービスサーバ30から送信されてくるのを待機する(ステップS303)。そして、要求応答部14は、完了通知が送信されてきた場合には、登録要求送信元に対して完了通知を送信(ステップS304)してから、この登録要求応答処理(図11)を終了する。
また、要求応答部14は、認証失敗通知を受信した場合(ステップS302;失敗)には、登録要求送信元に対して完了通知を送信(ステップS305)してから、この登録要求応答処理を終了する。
認証管理サーバ10(要求応答部14)に対して登録要求を送信した要求送信部42は、この完了通知の受信を待機している(図10,ステップS155)。そして、要求送信部42は、、完了通知を受信した際に、ステップS155の処理及び画像/動画登録要求処理を終了する。
次に、ユーザ端末40(要求送信部42)によるプロフィール写真変更要求の送信手順と、要求応答部14、画像判別部23及び更新処理部33によるプロフィール写真変更要求登録要求の処理手順とを、説明する。
既に説明したように、ディスプレイ上に表示される作業選択画面から操作者が“プロフィール写真の変更”を選択した場合、要求送信部42は、プロフィール写真変更要求処理を開始する。
このプロフィール写真変更要求処理が、プロフィール写真変更要求を生成して送信する処理なのであるが、プロフィール写真変更要求処理は、画像/動画登録要求処理(図10)と基本的には同手順の処理となっている。そのため、以下では、図10を用いて、画像/動画登録要求処理との違いを中心に、プロフィール写真変更要求処理の内容を説明することにする。
プロフィール写真変更要求処理は、個人紹介ページに使用されているプロフィール写真データを他のプロフィール写真データ(つまり画像データ)に変更するための処理である。そのため、プロフィール写真変更要求処理では、画像データ又は動画データをユーザから取得する登録対象データ取得処理の代わりに、図5のステップ101で行われるものと同じプロフィール写真データ取得処理が行われる。
プロフィール写真データ取得処理後には、登録対象データが画像データである場合にステップS152~S154で行われる処理と同じ処理が行われる。そして、プロフィール写真変更要求処理の最終ステップでは、その一部を認証画像データに置換したプロフィール写真データ等を含めたプロフィール写真変更要求を認証管理サーバ10に対して送信し、認証管理サーバ10からの完了通知を待機する処理が行われる。
認証管理サーバ10に対して送信されたプロフィール写真変更要求(以下、変更要求とも表記する)は、要求応答部14により受信される。変更要求を受信した要求応答部14は、変更要求応答処理を開始する。尚、要求応答部14は、受信した変更要求が適式なものであり、且つ、要求送信者が個人紹介ページを既に開設している者であることが確認できた場合に限り、変更要求応答処理を開始する。
変更要求応答処理は、上記した登録要求応答処理(図11)と本質的には同じ処理である。
すなわち、変更要求応答処理を開始した要求応答部14は、まず、処理対象端末固有情報、判定対象画像データ及び要求送信者IDとを含めた認証要求を画像判別サーバ20(画像判別部23)に対して送信する。尚、登録要求応答処理における判定対象データは、受信した登録要求中の画像データ、又は、受信した登録要求中の動画データに含まれる,第1フレーム(先頭フレーム)に関する画像データであった。ただし、変更要求に動画データが含まれていることはない。よって、変更要求応答処理における判定対象画像データとは、受信した変更要求に含まれる画像データ(プロフィール写真データ)のことである。
認証要求を受信した画像判別部23は、上記した認証要求応答処理(図12)を行うことにより、要求送信者が、要求送信者IDの正当保有者であるか否かを判定する。そして、画像判別部23は、要求送信者が要求送信者IDの正当保有者であると判定した場合には、認証完了通知を認証管理サーバ10(要求応答部14)に対して送信する。また、画像判別部23は、要求送信者が要求送信者IDの正当保有者ではないと判定した場合には、認証失敗通知を認証管理サーバ10(要求応答部14)に対して送信する。
画像判別サーバ20(画像判別部23)に対して認証要求を送信した要求応答部14は、画像判別サーバ20から上記通知のいずれかが送信されてくるのを待機する。
そして、要求応答部14は、認証成功通知を受信した場合には、受信済みの登録要求中の画像データ及びテキスト情報と、要求送信者IDとを含めた変更要求(プロフィール写真データ変更要求)をWebサービスサーバ30に送信する。
Webサービスサーバ30に対して送信された変更要求は、更新処理部33により受信される。そして、変更要求を受信した更新処理部33は、既に説明したように、要求送信者の個人紹介ページのプロフィール写真データの変更等を行ってから、完了通知を認証管理サーバ10に対して送信する。
変更要求をWebサービスサーバ30(更新処理部33)に対して送信した要求応答部14は、この完了通知がWebサービスサーバ30から送信されてくるのを待機する。そして、要求応答部14は、完了通知が送信されてきた場合には、要求送信元に対して完了通知を送信してから、変更要求応答処理を終了する。
また、要求応答部14は、認証失敗通知を受信した場合には、変更要求(プロフィール写真データ変更要求)をWebサービスサーバ30に対して送信することなく、要求送信元に対して応答不可通知を送信する。そして、要求応答部14は、変更要求応答処理を終了する。
ここまでの説明から既に明らかであるとは考えるが、ここで、ユーザ端末40及び情報処理装置1の認証画像データ関連の総合的な動作を説明しておくことにする。
図13に、ユーザAによる個人紹介ページの開設時におけるユーザ端末A、認証管理サーバ10、画像判別サーバ及びWebサービスサーバ30間のシーケンス図を示す。また、図14に、ユーザAによる個人紹介ページへの画像データ登録時におけるユーザ端末A、認証管理サーバ10、画像判別サーバ及びWebサービスサーバ30間のシーケンス図を示す。尚、図13、図14及び以下の説明において、ユーザ端末Aとは、ユーザAのユーザ端末40のことである。また、TSI-Aとは、ユーザ端末Aの端末固有情報のことであり、ID-Aとは、ユーザAのユーザIDのことである。さらに、認証画像領域データとは、既に定義したように、固有端末情報からその位置が特定された認証画像領域内の画像の画像データのことである。
図13に示してあるように、ユーザAによる個人紹介ページの開設時には、まず、ユーザA(ユーザ端末A)と認証管理サーバ10との間でログイン処理が行われる。その後、ユーザ端末A内で、プロフィール写真データ(以下、画像データA0と表記する)をユーザAに撮影/指定させる処理(図示略)と、TSI-Aから認証画像領域の位置を特定する処理とが行われる。そして、画像データA0中の認証画像領域データを、ユーザAの認証画像データ(以下、認証画像データαと表記する)として記憶する処理が行われてから、画像データA0、TSI-A等を含む開設要求が認証管理サーバ10に対して送信される。
開設要求を受信した認証管理サーバ10(開設要求応答部12)は、当該開設要求が、個人紹介ページを未だ開設していないユーザからの適式な要求であることを確認する(図示略)。そして、認証管理サーバ10は、受信した開設要求がそのような要求であることが確認できた場合には、画像データA0及びTSI-Aをセッション追跡パラメータから特定したID-Aと共に含む特徴情報登録要求を画像判別サーバ20に対して送信する。
特徴情報登録要求を受信した画像判別サーバ20内では、特徴情報登録要求中の端末固有情報から認証画像領域の位置を特定する処理が行われる。その後、画像データA0中の認証画像領域データの特徴情報を特徴情報管理DB21内にID-Aに対応づけて記憶する処理が行われる。尚、ユーザAによる個人紹介ページの開設時における特徴情報登録要求に含まれる端末固有情報は、TSI-Aであるため、画像データA0中の認証画像領域データは、認証画像データαとなる。従って、特徴情報管理DB21内には、認証画像データαの特徴情報がID-Aに対応づけて記憶されることになる。
認証画像データαの特徴情報をID-Aに対応づけて特徴情報管理DB21内に記憶する処理が完了すると、完了通知が認証管理サーバ10に対して送信される。
この完了通知を受信した認証管理サーバ10は、登録要求の要素として受信している画像データA0等と、セッション追跡パラメータから特定したID-Aとを含む開設要求をWebサービスサーバ30に送信する。そして、この開設要求を受信したWebサービスサーバ30によって、画像データA0がプロフィール写真データとして使用された,ユーザAの個人紹介ページAが開設される。
また、図14に示してあるように、ユーザAによる個人紹介ページAへの画像データの登録時にも、まず、ログイン処理が行われる。その後、ユーザ端末A内で、個人紹介ページAに登録する画像データA1をユーザAに撮影/指定させる処理(図示略)と、TSI-Aから認証画像領域の位置を特定する処理とが行われる。その後、画像データA1中の認証画像領域データを認証画像データαに置換する処理が行われる。そして、その一部が認証画像データαが置換された画像データA1である画像データA1[α]、TSI-A等を含む登録要求が認証管理サーバ10に対して送信される。
登録要求を受信した認証管理サーバ10は、当該登録要求が、個人紹介ページを開設済みのユーザからの適式な要求であることを確認する。そして、認証管理サーバ10は、受信した登録要求が上記条件を満たす要求であることが確認できた場合には、画像データA1[α]及びTSI-Aと、セッション追跡パラメータから特定したID-Aを含む認証要求を画像判別サーバ20に対して送信する。
認証要求を受信した画像判別サーバ20内では、当該認証要求に含まれるTSI-Aから認証画像領域の位置が特定される。そして、当該認証要求に含まれる画像データ(以下、判定対象データと表記する)中の認証画像領域データに関する特徴情報と、ユーザAの特徴情報とから、判定対象データの送信者がユーザAであるか否かが判定される。尚、ユーザAの特徴情報とは、認証要求中のユーザID(この場合、ID-A)に対応づけられて特徴情報管理DB11内に記憶されている特徴情報のことである。
判定対象データが画像データA1[α]である場合、判定対象データ中の認証画像領域データは、認証画像データα(ただし、再圧縮により元の認証画像データαとは若干内容の異なったもの)となる。従って、判定対象データ中の認証画像領域データから得られる特徴情報は、ユーザAの特徴情報とあまり変わらないものとなる。
そのため、判定対象データの送信者がユーザAであると判定されて、画像判別サーバ30から認証管理サーバ10に認証成功通知が送信される。この認証成功通知を受信した認証管理サーバ10は、登録要求の要素として受信している画像データA1[α]等とID-Aとを含む登録要求をWebサービスサーバ30に送信する。そして、この登録要求を受信したWebサービスサーバ30により、個人紹介ページAに画像データA1[α]等が登録(追加)されることになる。
ユーザ端末Aから、プロフィール写真変更要求や、動画データを含む登録要求が送信された場合にも、画像判別サーバ20には、認証画像領域データが認証画像データαとなっている画像データが渡される。従って、画像判別サーバ20は、各要求の送信者がユーザAであると判定する。そして、その結果として、ユーザAの希望通りに個人紹介ページAの内容が更新されることになる。
次に、ユーザAのユーザID及びパスワードを不正に取得したユーザBが、情報処理装置1が公開している個人紹介ページAを改変しようとした場合を考える。
まず、ユーザBが自身のユーザ端末40(以下、ユーザ端末Bと表記する)を用いてユーザAのユーザID及びパスワードの入力により情報処理装置1にログインし、個人紹介ページAに画像データBを登録しようとした場合を考える。尚、ユーザ端末Bの端末固有情報は、TSI-Bであり、ユーザ端末Bの認証画像記憶部41には、認証画像データβが記憶されているとする。
この場合、図15に示してあるように、ユーザ端末Bから認証管理サーバ10に対して送信される登録要求は、画像データB中の認証画像領域データを認証画像データβに置換した画像データB[β]、TSI-Bを含むものとなる。そして、認証管理サーバ10は、受信した登録要求が、ID-Aでログインしたユーザからの要求であるため、画像データB[β]、TSI-B、ID-Aを含めた認証要求を画像判別サーバ20に対して送信する。
認証要求を受信した画像判別サーバ20内では、当該認証要求に含まれていたTSI-Bから認証画像領域の位置が特定される。そして、判定対象データの送信者がユーザAであるか否かを判定するために、判定対象データ中の認証画像領域データの特徴情報と、特徴情報管理DB21内の,ID-Aに対応づけられている特徴情報(つまり、認証画像データαの特徴情報)とが比較される。この場合、判定対象データ中の認証画像領域データは、認証画像データβであるので、認証画像領域データの特徴情報は、通常、認証画像データαの特徴情報Aと全く異なるものとなっている。そのため、判定対象データの送信者がユーザAではないと判定されて、認証失敗通知が認証管理サーバ10に対して送信される。
そして、認証失敗通知を受信した場合、認証管理サーバ10は、Webサービスサーバ30に対して登録要求を送信することなく、ユーザ端末Bに対して応答不可通知を送信する。すなわち、個人紹介ページAに画像データBが登録されることなく、情報処理装置10の変更要求に対する処理が完了することになる。
ユーザBが、ユーザ端末Bを用いて個人紹介ページAのプロフィール写真データを変更しようとした場合も、同様に、認証画像データが大きく異なるため、プロフィール写真要求の送信者がユーザAでないと判定される。従って、個人紹介ページA上のプロフィール写真が変更されないことになる。
このように、本実施形態に係る情報処理装置1は、画像データ登録プログラム45を用いたのでは、個人紹介ページを不正に改変することが出来ない装置となっている。
また、ユーザBが、自作のプログラムを用いて、個人紹介ページAを改変しようとすることも考えられる。この場合、ユーザBは、適式な登録/変更要求(換言すれば、登録要求応答処理や変更要求応答処理が開始される要求)を送信できるプログラムを作成することは出来るかもしれない。ただし、情報処理装置1は、登録/変更要求に含まれている画像データ中の認証画像領域データが、認証画像データαとほぼ同一でないと、個人紹介ページAへの画像データの追加や、個人紹介ページAのプロフィール写真データの変更を行わない。そして、認証画像データαは、小領域(図7の認証画像領域110参照)の画像に関する画像データであるため、ユーザBが、登録/変更要求に含める画像データに加工が必要なことを気づくことは殆どない。
そのため、情報処理装置1は、プログラムの自作による個人紹介ページの不正な改変も困難な装置となっている。
しかも、個人紹介ページへの画像/動画データの登録時にユーザが行わなければならない作業は、Webページへの画像/動画データの登録時に一般的に行われているものと同じ作業である。従って、情報処理装置1は、画像/動画データに対する処理をネットワークを介して要求する要求者が本人であることを、ユーザの負荷を増やさずに確認できる装置となっていると言うことが出来る。
《第2実施形態》
図16に、第2実施形態に係る情報処理装置2の機能ブロック構成例を、ユーザ端末40の機能ブロック構成例と共に示す。
図16に、第2実施形態に係る情報処理装置2の機能ブロック構成例を、ユーザ端末40の機能ブロック構成例と共に示す。
この図16を図4と比較すれば明らかなように、本実施形態に係る情報処理装置2は、第1実施形態に係る情報処理装置1の認証管理サーバ10内の要求応答部14を、要求応答部14Bに変更した装置である。すなわち、情報処理装置2は、認証管理サーバ10として使用するコンピュータに、情報処理装置1の認証管理サーバ10内の認証管理サーバ用プログラムとは内容が異なるプログラムをインストールした装置となっている。
また、本実施形態に係る情報処理装置2を利用するために使用されるユーザ端末40も、第1実施形態に係るユーザ端末40と同じ装置である。そのため、以下では、要求応答部14Bの機能を中心に第2実施形態に係る情報処理装置2の機能を説明することにする。
要求応答部14Bは、上記したものとは内容が異なる登録要求応答処理及び変更要求応答処理を行うように、要求応答部14を変形(改良)したユニットである。
要求応答部14Bが実行する登録要求応答処理は、図14に示した手順の処理である。
すなわち、この登録要求応答処理を開始した要求応答部14Bは、まず、ステップS401にて、ステップS301(図11)の処理と同じ処理を行う。そして、要求応答部14Bは、画像判別サーバ20から認証失敗通知を送信されてきた場合(ステップS402;NO)には、要求応答部14と同様に、要求送信元に対して認証失敗通知を送信(ステップS406)してから、登録要求応答処理を終了する。
すなわち、この登録要求応答処理を開始した要求応答部14Bは、まず、ステップS401にて、ステップS301(図11)の処理と同じ処理を行う。そして、要求応答部14Bは、画像判別サーバ20から認証失敗通知を送信されてきた場合(ステップS402;NO)には、要求応答部14と同様に、要求送信元に対して認証失敗通知を送信(ステップS406)してから、登録要求応答処理を終了する。
一方、認証成功通知を受信した場合(ステップS402;成功)、要求応答部14Bは、ステップS403にて、登録対象データの認証画像領域を画像データが欠損している領域としてみなして修復する認証画像領域修復処理を行う。尚、登録対象データとは、受信した登録要求の要素として受信している画像データ又は動画データのことである。また、ステップS403の処理時、要求応答部14Bは、画像判別部23及び要求送信部42が行うものと同内容の領域位置特定処理を行うことにより、認証画像領域の位置を特定する。
ステップ403における認証画像領域修復処理の修復アルゴリズムは、大きな欠損領域も良好に補正できる高級なアルゴリズム(テクスチャの逐次合成による画像修復アルゴリズム等)であっても良い。ただし、認証画像領域が小サイズの領域であるため、単純な修復アルゴリズムを用いても、認証画像領域を、他領域との違いが目立たないものに修復できる。従って、認証管理サーバ10の負荷を増やさないために、例えば、図18に模式的に示したような修復アルゴリズムを用いておくことが好ましい。
すなわち、認証画像領域(図18では、網掛けが付してない8×8個の画素からなる領域)を、左上、右上、左下及び右下の4領域に区分し、
左上の領域内の各画素については、矢印で示してある順に、その色を一段上の画素の色と一段左の画素の色との平均値とし、
右上の領域内の各画素については、矢印で示してある順に、その色を一段上の画素の色と一段右の画素の色との平均値とし、
左下の領域内の各画素については、矢印で示してある順に、その色を一段下の画素の色と一段左の画素の色との平均値とし、
右上の領域内の各画素については、矢印で示してある順に、その色を一段下の画素の色と一段右の画素の色との平均値とする
修復アルゴリズムを用いておくことが好ましい。
左上の領域内の各画素については、矢印で示してある順に、その色を一段上の画素の色と一段左の画素の色との平均値とし、
右上の領域内の各画素については、矢印で示してある順に、その色を一段上の画素の色と一段右の画素の色との平均値とし、
左下の領域内の各画素については、矢印で示してある順に、その色を一段下の画素の色と一段左の画素の色との平均値とし、
右上の領域内の各画素については、矢印で示してある順に、その色を一段下の画素の色と一段右の画素の色との平均値とする
修復アルゴリズムを用いておくことが好ましい。
ステップS403(図17)の処理を終えた要求応答部14Bは、認証画像領域を修復した登録対象データを含めた登録要求をWebサービスサーバ30に送信する(ステップS404)。より具体的には、要求応答部14Bは、認証画像領域を修復した登録対象データと、受信した登録要求中のテキスト情報と、セッション追跡パラメータから特定した要求送信者IDとを含めた登録要求をWebサービスサーバ30に送信する。
そして、要求応答部14Bは、要求応答部14と同様に、Webサービスサーバ30から完了通知が送信されてくるのを待機(ステップS404)し、完了通知が送信されてきたときに、要求送信元に対して完了通知を送信(ステップS405)してから、この登録要求応答処理(図17)を終了する。
要求応答部14Bが実行する変更要求応答処理は、この登録要求応答処理と本質的には同じ処理である。
すなわち、変更要求応答処理を開始した要求応答部14Bは、まず、処理対象端末固有情報、判定対象画像データ(変更要求中のプロフィール写真データ)及び要求送信者IDとを含めた認証要求を画像判別サーバ20(画像判別部23)に対して送信する。その後、要求応答部14は、画像判別サーバ20から認証失敗通知、認証失敗通知のいずれかが送信されてくるのを待機する。
要求応答部14Bは、認証成功通知を受信した場合には、変更要求の要素として受信しているプロフィール写真データの認証画像領域を修復する。そして、要求応答部14Bは、認証画像領域を修復したプロフィール写真データと、テキスト情報と、要求送信者IDとを含めた変更要求(プロフィール写真データ変更要求)をWebサービスサーバ30に送信する。
Webサービスサーバ30に対して送信された変更要求は、更新処理部33により受信される。そして、変更要求を受信した更新処理部33は、要求送信者の個人紹介ページのプロフィール写真データの変更等を行ってから、完了通知を認証管理サーバ10に対して送信する。
変更要求をWebサービスサーバ30(更新処理部33)に対して送信した要求応答部14Bは、この完了通知がWebサービスサーバ30から送信されてくるのを待機する。そして、要求応答部14Bは、完了通知が送信されてきた場合には、要求送信元に対して完了通知を送信してから、変更要求応答処理を終了する。
また、要求応答部14Bは、認証失敗通知を受信した場合には、変更要求をWebサービスサーバ30に対して送信することなく、要求送信元に対して応答不可通知を送信する。そして、要求応答部14Bは、変更要求応答処理を終了する。
要するに、本実施形態に係る情報処理装置2も、第1実施形態に係る情報処理装置1と同様に、登録/変更要求に含まれている画像/動画データ中の認証画像領域データが、要求送信者の認証画像データとほぼ同一でないと、登録/変更要求を受け付けない。従って、情報処理装置2が受け付ける登録/変更要求を生成するためには、少なくとも、端末固有情報と認証画像(認証画像データ)とが分からなければならない。ただし、上記した要求応答部14Bの機能から明らかなように、情報処理装置2は、各ユーザの個人紹介ページに、“埋め込まれていた認証画像が他の画像に置換された画像/動画”を掲載する装置となっている。すなわち、情報処理装置2が公開する個人紹介ページは、掲載されている各画像/動画から認証画像を特定することが極めて困難な装置となっている。従って、本実施形態に係る情報処理装置2は、認証画像をその一部に含む画像/動画を個人紹介ページに掲載してしまう第1実施形態に係る情報処理装置2よりも、不正な改変を行うことが困難な装置となっていると言うことが出来る。
《第3実施形態》
図19に、第3実施形態に係る情報処理装置3の機能ブロック構成例を、ユーザ端末40の機能ブロック構成例と共に示す。
図19に、第3実施形態に係る情報処理装置3の機能ブロック構成例を、ユーザ端末40の機能ブロック構成例と共に示す。
本実施形態に係る情報処理装置3は、第2実施形態に係る情報処理装置2を変形(改良)した装置であり、情報処理装置2(及び1)と同様に、インターネットに接続された認証管理サーバ10、画像判別サーバ20及びWebサービスサーバ30を含む。
情報処理装置3のWebサービスサーバ30は、情報処理装置2(及び1)のWebサーバ30と同じサーバである。情報処理装置3の認証管理サーバ10は、情報処理装置2の認証管理サーバ10内の開設要求応答部13、要求応答部14Bを、開設要求応答部13C、要求応答部14Cに置き換えたサーバである。情報処理装置3の画像判別サーバ20は、情報処理装置2の特徴情報登録部22及び画像判別部23を、特徴情報登録部22C及び画像判別部23Cに置き換えたサーバである。
すなわち、認証管理サーバ10は、情報処理装置2の認証管理サーバ10内の認証管理サーバ用プログラムとは内容が異なる認証管理サーバ用プログラムがインストールされたコンピュータとなっている。また、画像判別サーバ20も、情報処理装置2(及び1)の画像判別サーバ10内の画像判別サーバ用プログラム25とは内容が異なる画像判別サーバ用プログラムがインストールされたコンピュータとなっている。
情報処理装置3に開設要求等を送信するために使用されるユーザ端末40は、情報処理装置2(及び1)に開設要求等を送信するために使用されるユーザ端末40の要求送信部42を、要求送信部42Cに置き換えた装置である。すなわち、ユーザ端末40は、画像データ登録プログラム45とは内容が異なる画像データ登録プログラムがインストールされた端末装置となっている。
以下、開設要求応答部13、要求応答部14B、特徴情報登録部22、画像判別部23、要求送信部42と異なる部分を中心に、開設要求応答部13C、要求応答部14C、特徴情報登録部22C、画像判別部23C、要求送信部42Cの機能を説明する。
まず、要求送信部42Cの機能を説明する。
要求送信部42Cは、要求送信部42が行うものと基本的には同内容の個人紹介ページ開設要求処理、画像/動画登録要求処理及びプロフィール写真変更要求処理を行うユニットである。ただし、要求送信部42Cが行う各処理は、生成した乱数から認証画像領域の位置を特定し、送信する要求中に生成した乱数を含める処理となっている。
要求送信部42Cは、要求送信部42が行うものと基本的には同内容の個人紹介ページ開設要求処理、画像/動画登録要求処理及びプロフィール写真変更要求処理を行うユニットである。ただし、要求送信部42Cが行う各処理は、生成した乱数から認証画像領域の位置を特定し、送信する要求中に生成した乱数を含める処理となっている。
具体的には、要求送信部42Cが行う個人紹介ページ開設要求処理は、図20に示した手順の処理となっている。
すなわち、この個人紹介ページ開設要求処理を開始した要求送信部42Cは、まず、ステップS101(図5)で行われるものと同じプロフィール写真データ取得処理(ステップS501)を行う。
プロフィール写真データ取得処理を終えた要求送信部42Cは、操作者が撮影/選択したプロフィール写真データ(図20では、処理対象画像データ)のX方向サイズLx及びY方向サイズLyを特定する(ステップS102)。また、このステップS102にて、要求送信部42Cは、所定桁数の乱数を生成する処理も行う。
その後、要求送信部42Cは、生成した乱数に基づき、乱数の値により処理結果が異なるアルゴリズムにて、認証画像領域の,プロファイル写真(図20では、処理対象画像)上における位置を特定するための領域位置特定処理(ステップS503)を行う。
この領域位置特定処理としては、例えば、上記した領域位置特定処理におけるシリアル番号情報を、“生成した乱数”に置き換えた処理が行われる。
すなわち、生成した乱数の前半部分を“Lx-Sx+1”で割った余りを、認証画像領域の始点のX座標値x0として算出し、生成した乱数の鋼板部分を“Rh-Sy+1”で割った余りを、認証画像領域の始点のY座標値y0として算出する処理が行われる。
領域位置特定処理を終えた要求送信部42Cは、操作者が撮影/選択したプロフィール写真データから、領域位置特定処理によりその位置を特定した認証画像領域内の画像に関する画像データを抽出する(ステップS504)。そして、要求送信部42Cは、抽出した画像データを、認証画像データとして認証画像記憶部41に記憶してから、ステップS504の処理を終了する。
ステップS504の処理を終えた要求送信部42Cは、操作者が撮影/選択したプロフィール写真データ、操作者が入力したテキスト情報、及び、認証画像領域の特定に用いた乱数を含めた開設要求を認証管理サーバ10に対して送信する(ステップS505)。そして、要求送信部42Cは、認証管理サーバ10から完了通知が送信されてくるのを待機(ステップS505)し、完了通知を受信した際に、ステップS505の処理、及び、この個人紹介ページ開設要求処理(図20の処理)を終了する。
要求送信部42Cが行う画像/動画登録要求処理、プロフィール写真変更要求処理も、同様に、生成した乱数から認証画像領域の位置を特定し、送信する要求中に生成した乱数を含める処理となっている。
次に、開設要求応答部13C及び特徴情報登録部22Cの機能を説明する。
図21に、ユーザXによる個人紹介ページの開設時におけるユーザ端末X、認証管理サーバ10、画像判別サーバ及びWebサービスサーバ30間のシーケンス図を示す。尚、図21及び以下の説明において、ユーザ端末Xとは、ユーザX(任意のユーザ)のユーザ端末40のことであり、ID-Xとは、ユーザXのユーザIDのことである。
図21に、ユーザXによる個人紹介ページの開設時におけるユーザ端末X、認証管理サーバ10、画像判別サーバ及びWebサービスサーバ30間のシーケンス図を示す。尚、図21及び以下の説明において、ユーザ端末Xとは、ユーザX(任意のユーザ)のユーザ端末40のことであり、ID-Xとは、ユーザXのユーザIDのことである。
開設要求を受信した認証管理サーバ10(開設要求応答部13C)は、上記した開設要求応答処理(図8)と本質的には同内容の開設要求応答処理を行う。ただし、図21に模式的に示してあるように、開設要求応答部13Cが行う開設要求応答処理では、送信する特徴情報登録要求及び開設要求に、端末固有情報ではなく、ユーザ端末40(ユーザ端末X)から送信されてきた乱数RND0が含められる。
特徴情報登録要求を受信した画像判別サーバ20(特徴情報登録部22C)は、認証画像領域の位置の特定法が異なる点を除けば、上記した特徴情報登録要求応答処理(図9)と同内容の特徴情報登録要求応答処理を行う。すなわち、特徴情報登録部22Cは、ステップS252に相当するステップにて、要求送信部42Cが行うものと同じ領域位置特定処理が行われる点のみが上記した特徴情報登録要求応答処理と異なる特徴情報登録要求応答処理を行う。
また、画像判別サーバ20(特徴情報登録部22C)からの完了通知を受信した開設要求応答部13Cは、情報処理装置1、2内の開設要求応答部13と同じ処理を行う。
すなわち、完了通知を受信した開設要求応答部13Cは、処理対象画像データ及び処理対象テキスト情報と開設要求者IDとを含めた開設要求をWebサービスサーバ30(開設処理部32)に対して送信する。そして、開設要求応答部13Cは、完了通知がWebサービスサーバ30から送信されてくるのを待機し、完了通知が送信されてきた場合には、開設要求者についての個人紹介ページの開設が完了した旨を示す情報をユーザ管理DB11に追加する。そして、開設要求応答部13Cは、要求送信元に対して完了通知を送信してから、開設要求応答処理を終了する。
次に、要求応答部14C及び画像判定部23Cの機能を説明する。
図22に、ユーザXによる個人紹介ページへの画像データ登録時におけるユーザ端末X、認証管理サーバ10、画像判別サーバ及びWebサービスサーバ30間のシーケンス図を示す。
図22に、ユーザXによる個人紹介ページへの画像データ登録時におけるユーザ端末X、認証管理サーバ10、画像判別サーバ及びWebサービスサーバ30間のシーケンス図を示す。
登録要求を受信した認証管理サーバ10(要求応答部14C)は、情報処理装置2内の要求応答部14Bが行う登録要求応答処理(図17)と本質的には同内容の登録要求応答処理を行う。ただし、図22に模式的に示してあるように、開設要求応答部13Cが行う開設要求応答処理では、送信する認証要求に、端末固有情報ではなく、ユーザ端末40(ユーザ端末X)から送信されてきた乱数RND1が含められる。
認証要求を受信した画像判別サーバ20(画像判別部23C)は、認証画像領域の位置の特定法が異なる点を除けば、上記した認証要求応答処理(図12)と同内容の認証要求応答処理を行う。すなわち、画像判別部23Cは、ステップS352に相当するステップにて、要求送信部42Cが行うものと同じ領域位置特定処理が行われる点のみが上記した認証要求応答処理と異なる認証要求応答処理を行う。
そして、画像判別サーバ20(画像判別部23C)からの完了通知を受信した要求応答部14Cは、情報処理装置2内の要求応答部14Bと同じ処理を行う。
すなわち、完了通知を受信した要求応答部14Cは、まず、登録対象データの認証画像領域を修復する。そして、要求応答部14Cは、修復後の登録対象データ及び処理対象テキスト情報と要求送信者者IDとを含めた登録要求をWebサービスサーバ30(更新処理部33)に対して送信する。そして、要求応答部14Cは、完了通知がWebサービスサーバ30から送信されてくるのを待機し、完了通知が送信されてきた場合には、要求送信元に対して完了通知を送信してから、登録要求応答処理を終了する。
以上の説明から明らかなように、本情報処理装置3は、“埋め込まれていた認証画像が他の画像に置換された画像/動画”が掲載される個人紹介ページであって、認証画像の埋め込み位置が画像/動画毎に異なる個人紹介ページを公開する機能を有している。そして、情報処理装置3も、情報処理装置1、2と同様に、登録/変更要求に含まれている画像/動画データ中の認証画像領域データが、要求送信者の個人紹介ページの開設時に登録された認証画像データとほぼ同一していないと、登録/変更要求を受け付けない。従って、情報処理装置3が受け付ける登録/変更要求を生成するためには、少なくとも、端末固有情報と認証画像とが分からなければならないのであるが、情報処理装置3が公開する上記したような個人紹介ページからは、認証画像を特定することが出来ない。従って、本実施形態に係る情報処理装置3は、不正な改変を行うことが特に困難な装置となっていると言うことが出来る。
《変形形態》
上記した各実施形態に係る情報処理装置1~3は、各種の変形が行えるものである。例えば、端末固有情報がユーザIDに対応づけて情報処理装置内に記憶されていれば、登録要求/変更要求に端末固有情報が含まれていなくても、ユーザIDから端末固有情報を特定できる。従って、情報処理装置1、2を、開設要求受信時に、特徴情報管理DB21内に、端末固有情報と特徴情報とをユーザIDに対応づけて記憶する装置であって、端末固有情報を含まない登録要求/変更要求を受信する装置に変形することができる。尚、情報処理装置1、2を、そのように変形しておけば、端末固有情報がネットワーク上を1回しか流れなくなる。従って、ユーザ端末40から情報処理装置に送信される端末固有情報が実際上盗聴できないようにすることが出来る。
上記した各実施形態に係る情報処理装置1~3は、各種の変形が行えるものである。例えば、端末固有情報がユーザIDに対応づけて情報処理装置内に記憶されていれば、登録要求/変更要求に端末固有情報が含まれていなくても、ユーザIDから端末固有情報を特定できる。従って、情報処理装置1、2を、開設要求受信時に、特徴情報管理DB21内に、端末固有情報と特徴情報とをユーザIDに対応づけて記憶する装置であって、端末固有情報を含まない登録要求/変更要求を受信する装置に変形することができる。尚、情報処理装置1、2を、そのように変形しておけば、端末固有情報がネットワーク上を1回しか流れなくなる。従って、ユーザ端末40から情報処理装置に送信される端末固有情報が実際上盗聴できないようにすることが出来る。
情報処理装置3から、認証画像領域の修復機能を取り除いておくことも出来る。また、情報処理装置1、2を、認証画像領域がプロフィール写真データの全領域の中から選択される装置に変形することも出来る。同様に、情報処理装置3を、認証画像領域が各画像や各動画の1フレーム目の画像の全領域の中から選択される装置に変形することも出来る。ただし、画像の中心部分は、元のままの画像であった方が良い。そのため、認証画像領域が画像の縁近傍に位置するようにしておくことが好ましい。
特徴情報として、プロフィール写真データ中の認証画像領域データ自体が記憶される装置に、情報処理装置1~3を変形することも出来る。尚、情報処理装置1~3をそのような装置に変形する場合、通常、2画像データの直接的な比較により要求送信者の認証が行われることになる。何故ならば、2画像データの特徴情報を生成して比較するのであれば、プロフィール写真データ中の認証画像領域データの特徴情報を保存しておいた方が、同じ特徴情報の生成が多数回行われるのを抑止できるため、良いからである。ただし、上記変形を行う場合にも、2画像データの特徴情報が生成されてそれらの比較が行われるようにすることが可能である。
情報処理装置1、2を、各ユーザが個人紹介ページの開設時に指定した値から認証画像領域の位置を特定する装置に変形することも出来る。尚、この場合、ユーザ端末40も、ユーザが個人紹介ページの開設時に指定した値から認証画像領域の位置を特定する装置に変形されることになる。
情報処理装置1~3は、いずれも、ユーザが個人紹介ページを簡単に開設できるWebサービスを提供するための装置であったが、情報処理装置1~3を、各ユーザからお画像/動画データを、ストレージに保存するための装置に変形することも出来る。
また、情報処理装置1~3を、特殊なプログラム(上記した画像データ登録プログラム45)のユーザ端末40へのインストールが不要な装置に変形することも出来る。すなわち、情報処理装置1~3を、各ユーザ端末40に対して個人紹介ページ開設要求処理を実行させるためのアプレット等を提供する装置に変形することが出来る。尚、この場合、通常、各ユーザに、各アプレットによるローカルファイルの操作を許可するポリシーファイルを自身のユーザ端末40内に設定させることが必要となる。
情報処理装置1~3を、認証管理サーバ10が画像判別サーバ20としての機能も有する装置(2台のサーバからなる装置)や、Webサービスサーバ30が、認証管理サーバ10及び画像判別サーバ20としての機能も有する装置に変形することも出来る。また、情報処理装置1~3を、Webサービスサーバ30が各種要求を受信し、Webサービスサーバ30がログイン認証や認証画像による認証を認証管理サーバ10や画像判別サーバ20に依頼する装置に変形することも出来る。情報処理装置1~3を、インターネットではないネットワークに接続して使用する装置に変形することも出来る。
1,2,3 情報処理装置
10 認証管理サーバ
11 ユーザ管理DB
12 認証処理部
13,13C 開設要求応答部
14,14B,14C 要求応答部
15 認証管理サーバ用プログラム
20 画像判別サーバ
21 特徴情報管理DB
22,22C 特徴情報登録部
23,23C 画像判別部
25 画像判別サーバ用プログラム
30 Webサービスサーバ
31 個人紹介ページ管理DB
32 開設処理部
33 更新処理部
35 Webサービスサーバ用プログラム
40 ユーザ端末
41 認証画像記憶部
42,42C 要求送信部
45 画像データ登録プログラム
10 認証管理サーバ
11 ユーザ管理DB
12 認証処理部
13,13C 開設要求応答部
14,14B,14C 要求応答部
15 認証管理サーバ用プログラム
20 画像判別サーバ
21 特徴情報管理DB
22,22C 特徴情報登録部
23,23C 画像判別部
25 画像判別サーバ用プログラム
30 Webサービスサーバ
31 個人紹介ページ管理DB
32 開設処理部
33 更新処理部
35 Webサービスサーバ用プログラム
40 ユーザ端末
41 認証画像記憶部
42,42C 要求送信部
45 画像データ登録プログラム
Claims (13)
- 認証画像データの特徴を表す特徴情報を、ユーザ識別情報に対応づけて記憶する情報記憶部と、
制御部と
を、備え、
前記制御部は、
或る画像データに対する処理をネットワークを介して要求する要求者から、当該画像データと、ユーザ識別情報と、当該画像データに埋め込まれている前記認証画像データの位置を示す位置提示情報とを取得し、
取得した画像データから、取得した位置提示情報が示している位置の画像データを抽出し、抽出した画像データの特徴を表す特徴情報と、取得したユーザ識別情報に対応づけられて前記情報記憶部に記憶されている特徴情報とを比較することにより、前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であるか否かを判定し、
前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であると判定した場合に、前記要求者が要求している前記処理を前記取得した画像データに対して実行する
ことを特徴とする情報処理装置。 - 前記制御部は、前記取得したユーザ識別情報で識別される利用者本人であると判定した場合、前記取得した画像データに対して、前記認証画像データが埋め込まれている部分を、有効な画素データが存在していない欠損領域として取り扱った画像修復処理を行い、画像修復処理後の画像データに対して前記処理を実行する
ことを特徴とする請求項1に記載の情報処理装置。 - 画像データの特徴を表す前記特徴情報が、当該画像データの色ヒストグラムデータである
ことを特徴とする請求項1又は2に記載の情報処理装置。 - 前記位置提示情報が、前記要求者が前記情報処理装置との間の情報の授受に使用している端末装置に固有の情報である
ことを特徴とする請求項1から3のいずれか一項に記載の情報処理装置。 - 前記制御部は、前記取得した位置提示情報に対する剰余演算を行うことにより、抽出する画像データの位置を特定する
ことを特徴とする請求項1から4のいずれか一項に記載の情報処理装置。 - 前記端末装置が、携帯電話又は衛星電話であり、
前記位置提示情報が、前記端末装置に付与されているIMEI(International Mobile Equipment Identity)である
ことを特徴とする請求項4に記載の情報処理装置。 - 前記位置提示情報が、前記端末装置のMAC(Media Access Control)アドレスである
ことを特徴とする請求項4に記載の情報処理装置。 - 前記処理が、前記画像データを前記要求者用のWebページに追加する処理である
ことを特徴とする請求項1から7のいずれかに記載の情報処理装置。 - 認証画像を表す認証画像データを保持する保持部と、
情報処理装置に処理させる画像データの一部を前記保持部に保持された前記認証画像データに置換することにより第2画像データを生成し、生成した第2画像データを前記情報処理装置に対して送信する第1機能と、前記第2画像データの,前記認証画像データに置換されている部分の位置を示す情報を前記情報処理装置に対して送信する第2機能とを有する送信処理部と、
を備えることを特徴とする端末装置。 - 前記情報処理装置に処理させる前記画像データを生成するためのデジタルカメラを、さらに備える
ことを特徴とする請求項9に記載の端末装置。 - 前記保持部に保持される前記認証画像データが、前記デジタルカメラにより生成された画像データの一部である
ことを特徴とする請求項10に記載の端末装置。 - コンピュータが、
或る画像データに対する処理をネットワークを介して要求する要求者から、当該画像データと、ユーザ識別情報と、当該画像データに埋め込まれている前記認証画像データの位置を示す位置提示情報とを取得し、
取得した画像データから、取得した位置提示情報が示している位置の画像データを抽出して抽出した画像データの特徴を表す特徴情報と、取得したユーザ識別情報に対応づけられて記憶装置に記憶されている特徴情報とを比較することにより、前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であるか否かを判定し、
前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であると判定した場合に、前記要求者が要求している前記処理を前記取得した画像データに対して実行する
ことを特徴とする情報処理方法。 - 或る画像データに対する処理をネットワークを介して要求する要求者から、当該画像データと、ユーザ識別情報と、当該画像データに埋め込まれている前記認証画像データの位置を示す位置提示情報とを取得し、
取得した画像データから、取得した位置提示情報が示している位置の画像データを抽出して抽出した画像データの特徴を表す特徴情報と、取得したユーザ識別情報に対応づけられて記憶装置に記憶されている特徴情報とを比較することにより、前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であるか否かを判定し、
前記要求者が、前記取得したユーザ識別情報にて識別される利用者本人であると判定した場合に、前記要求者が要求している前記処理を前記取得した画像データに対して実行する
処理をコンピュータに実行させることを特徴とする情報処理プログラム。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2013/067361 WO2014207821A1 (ja) | 2013-06-25 | 2013-06-25 | 情報処理装置、端末装置、情報処理プログラム及び情報処理方法 |
| EP13887818.6A EP3016013A4 (en) | 2013-06-25 | 2013-06-25 | INFORMATION PROCESSING DEVICE, END DEVICE, INFORMATION PROCESSING PROGRAM INFORMATION PROCESSING METHOD |
| JP2015523699A JP6123893B2 (ja) | 2013-06-25 | 2013-06-25 | 情報処理装置、端末装置、情報処理プログラム及び情報処理方法 |
| US14/976,099 US20160110531A1 (en) | 2013-06-25 | 2015-12-21 | Information processing apparatus, terminal apparatus and information processing method |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2013/067361 WO2014207821A1 (ja) | 2013-06-25 | 2013-06-25 | 情報処理装置、端末装置、情報処理プログラム及び情報処理方法 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US14/976,099 Continuation US20160110531A1 (en) | 2013-06-25 | 2015-12-21 | Information processing apparatus, terminal apparatus and information processing method |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014207821A1 true WO2014207821A1 (ja) | 2014-12-31 |
Family
ID=52141228
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2013/067361 Ceased WO2014207821A1 (ja) | 2013-06-25 | 2013-06-25 | 情報処理装置、端末装置、情報処理プログラム及び情報処理方法 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20160110531A1 (ja) |
| EP (1) | EP3016013A4 (ja) |
| JP (1) | JP6123893B2 (ja) |
| WO (1) | WO2014207821A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2018500696A (ja) * | 2014-12-31 | 2018-01-11 | バイドゥ オンライン ネットワーク テクノロジー(ペキン) カンパニー リミテッド | ユーザに対して認証を行うための方法及び装置 |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11199962B2 (en) * | 2015-04-27 | 2021-12-14 | Shane Venis | Freehand memo image authentication |
| CN106611112A (zh) * | 2016-12-14 | 2017-05-03 | 北京小米移动软件有限公司 | 应用程序安全处理方法、装置及设备 |
| US11100572B1 (en) | 2017-04-28 | 2021-08-24 | Wells Fargo Bank, N.A. | Customer verification and account creation systems and methods |
| CN107948592B (zh) * | 2017-11-22 | 2019-03-15 | 珠海格力电器股份有限公司 | 一种共享摄像头的方法、装置和智能终端 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2002230207A (ja) * | 2001-02-02 | 2002-08-16 | Ntt Electornics Corp | 電子データコンテンツの配信システム、配信方法および配信装置、並びに電子データコンテンツの配信用プログラムを記録した記録媒体 |
| JP2004312362A (ja) * | 2003-04-07 | 2004-11-04 | Casio Comput Co Ltd | 画像出力装置、画像管理装置及びプログラム |
| JP2007026330A (ja) | 2005-07-20 | 2007-02-01 | Olympus Imaging Corp | 本人認証装置及び本人認証方法 |
| JP2008219875A (ja) * | 2001-11-27 | 2008-09-18 | Fujitsu Ltd | 文書配布方法および文書管理方法 |
| JP2009111902A (ja) * | 2007-10-31 | 2009-05-21 | Ricoh Co Ltd | 画像処理装置、オペレーション実行方法、及びオペレーション実行プログラム |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030039402A1 (en) * | 2001-08-24 | 2003-02-27 | Robins David R. | Method and apparatus for detection and removal of scanned image scratches and dust |
| DE60233432D1 (de) * | 2001-11-30 | 2009-10-01 | Int Barcode Corp | System und verfahren zum validieren eines digitalen bildes und entsprechender daten |
| JP2004118627A (ja) * | 2002-09-27 | 2004-04-15 | Toshiba Corp | 人物認証装置および人物認証方法 |
| US20050053281A1 (en) * | 2003-09-06 | 2005-03-10 | Match Lab, Inc. | Method and apparatus for acquiring image characteristics |
| US20050240869A1 (en) * | 2004-04-23 | 2005-10-27 | Kalev Leetaru | Method and system for editable web browsing |
| US8145912B2 (en) * | 2005-03-01 | 2012-03-27 | Qualcomm Incorporated | System and method for using a visual password scheme |
| JP4862447B2 (ja) * | 2006-03-23 | 2012-01-25 | 沖電気工業株式会社 | 顔認識システム |
| JP5390943B2 (ja) * | 2008-07-16 | 2014-01-15 | キヤノン株式会社 | 画像処理装置及び画像処理方法 |
| US8086745B2 (en) * | 2008-08-29 | 2011-12-27 | Fuji Xerox Co., Ltd | Graphical system and method for user authentication |
| US8621578B1 (en) * | 2008-12-10 | 2013-12-31 | Confident Technologies, Inc. | Methods and systems for protecting website forms from automated access |
| GB0910545D0 (en) * | 2009-06-18 | 2009-07-29 | Therefore Ltd | Picturesafe |
| US8699370B2 (en) * | 2010-08-24 | 2014-04-15 | Euclid, Inc. | Method and apparatus for analysis of user traffic within a predefined area |
| AU2011202415B1 (en) * | 2011-05-24 | 2012-04-12 | Microsoft Technology Licensing, Llc | Picture gesture authentication |
-
2013
- 2013-06-25 EP EP13887818.6A patent/EP3016013A4/en not_active Withdrawn
- 2013-06-25 JP JP2015523699A patent/JP6123893B2/ja not_active Expired - Fee Related
- 2013-06-25 WO PCT/JP2013/067361 patent/WO2014207821A1/ja not_active Ceased
-
2015
- 2015-12-21 US US14/976,099 patent/US20160110531A1/en not_active Abandoned
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2002230207A (ja) * | 2001-02-02 | 2002-08-16 | Ntt Electornics Corp | 電子データコンテンツの配信システム、配信方法および配信装置、並びに電子データコンテンツの配信用プログラムを記録した記録媒体 |
| JP2008219875A (ja) * | 2001-11-27 | 2008-09-18 | Fujitsu Ltd | 文書配布方法および文書管理方法 |
| JP2004312362A (ja) * | 2003-04-07 | 2004-11-04 | Casio Comput Co Ltd | 画像出力装置、画像管理装置及びプログラム |
| JP2007026330A (ja) | 2005-07-20 | 2007-02-01 | Olympus Imaging Corp | 本人認証装置及び本人認証方法 |
| JP2009111902A (ja) * | 2007-10-31 | 2009-05-21 | Ricoh Co Ltd | 画像処理装置、オペレーション実行方法、及びオペレーション実行プログラム |
Non-Patent Citations (2)
| Title |
|---|
| ROY, S. ET AL.: "Watermarking color histograms", PROCEEDINGS OF 2004 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP '04), vol. 4, October 2004 (2004-10-01), pages 2191 - 2194, XP010786218, Retrieved from the Internet <URL:http://dx.doi.org/10.1109/ICIP.2004.1421531> [retrieved on 20130726] * |
| See also references of EP3016013A4 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2018500696A (ja) * | 2014-12-31 | 2018-01-11 | バイドゥ オンライン ネットワーク テクノロジー(ペキン) カンパニー リミテッド | ユーザに対して認証を行うための方法及び装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP3016013A4 (en) | 2016-10-26 |
| JP6123893B2 (ja) | 2017-05-10 |
| JPWO2014207821A1 (ja) | 2017-02-23 |
| US20160110531A1 (en) | 2016-04-21 |
| EP3016013A1 (en) | 2016-05-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9456072B2 (en) | Apparatus and method for managing application in wireless terminal | |
| US8572375B2 (en) | Device pairing based on graphically encoded data | |
| US9185245B2 (en) | Method and apparatus for remotely controlling a camera connected to a multi-function device | |
| JP6123893B2 (ja) | 情報処理装置、端末装置、情報処理プログラム及び情報処理方法 | |
| JP2015186127A (ja) | プログラム及びサーバ装置 | |
| JP2004282708A (ja) | 印刷物生成装置および方法、情報検出装置および方法並びにプログラム | |
| US20250355979A1 (en) | Authenticity verification system, content management apparatus, content generation apparatus, control method of the system and the apparatuses, and program for the system and the apparatuses | |
| JP6164954B2 (ja) | 認証サーバ、認証方法、およびプログラム | |
| JP2024016164A (ja) | 情報処理方法および情報処理システム | |
| US20120151575A1 (en) | Apparatus and method for certificating security in portable terminal | |
| JP5027702B2 (ja) | 画像認証システム、端末装置、及び認証サーバ装置 | |
| JP7633796B2 (ja) | 情報処理装置、画像処理装置およびそれらの制御方法、ならびに画像処理システム | |
| CN109299048A (zh) | 处理数据以及发布数据的方法 | |
| CN114462817A (zh) | 验证方法、装置、电子设备及存储介质 | |
| US9602768B2 (en) | Apparatus, system, and method of managing terminals, and recording medium | |
| US9992636B2 (en) | Transmission management system, management method, and recording medium | |
| CN109413340B (zh) | 一种生成影集的处理方法及装置 | |
| CN106204261A (zh) | 一种信息处理方法、终端和服务器 | |
| JP6498823B1 (ja) | 情報処理方法、情報処理装置及びプログラム | |
| KR20170054848A (ko) | 전자통신 기기의 외부 정보 저장방법 및 이를 이용한 전자통신 기기의 외부 정보 인증 방법 | |
| CN117274092A (zh) | 登记信息处理方法及相关设备 | |
| KR20120080379A (ko) | 디지털 카메라의 이미지 어노테이션 처리 방법 및 장치 | |
| JP2020013418A (ja) | 情報処理方法、情報処理装置及びプログラム | |
| CN115996123A (zh) | 摄像设备、管理系统、控制方法和存储介质 | |
| US11277527B2 (en) | System having an apparatus, a server, and a terminal that transmits an identifier of an application on the terminal to the server |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13887818 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2015523699 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2013887818 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |