Information processing device, information processing method, and program
The information processing device efficiently identifies and authenticates multiple digital IDs by using catalog information to sequence access methods, addressing inefficiencies and ensuring secure, rapid verification.
Patent Information
- Application Number
- JP2024070859
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-11-06
AI Technical Summary
Verification devices struggle to quickly identify and authenticate multiple types of digital IDs without human intervention, leading to operational inefficiencies and time constraints in environments requiring rapid identification.
An information processing device that communicates with digital devices, utilizing catalog information to determine the sequence of access methods for various ID applications, verifies authenticity, and notifies users of errors or successes in the identification process.
Enables rapid and accurate identification of digital IDs, improving operational efficiency by automating the verification process and ensuring secure authentication of multiple ID types.
Smart Images

Figure 2025166677000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to the technical field of devices that can communicate with digital devices that implement electronic ID certificates. [Background technology]
[0002] Traditionally, personal identification (ID) certificates have been implemented using physical media such as plastic cards or booklets. Digital transformation is leading to the digitization of IDs and their storage in digital devices, such as smartphones. For example, driver's licenses are evolving into the mobile driving license (mDL) defined in ISO / IEC 18013-5, and passports are expected to adopt the digital travel credentials (DTC) standard developed by ICAO. Patent Document 1 discloses a technology that enables secure registration of ID information implemented using an application installed on a portable electronic device (mobile terminal) such as a smartphone through a simple procedure. Meanwhile, there are also technologies, such as decentralized identifiers (DIDs), that offer new forms of personal identification originating from digital IDs, rather than traditional physical ID media. When verifying the authenticity of an ID stored on a digital device, a verification device (reader) is required to access the digital device and read and verify the ID, since it cannot be visually verified like a hologram on a physical medium.
[0003] For example, if one digital device is equipped with applications that support multiple types of ID cards (i.e., manage the ID of an ID card) including mDL, DTC, employee ID card, health insurance card, national ID card (e.g., My Number card), and professional certificate, and the verification device is specialized in verifying a single ID, the verification device only needs to be equipped with access means that are compatible with a single application. Specifically, if a verification device for access control that manages entrance and exit to a building is a system that verifies that entrants are holding legitimate employee ID cards, the verification device only needs to be equipped with access means that are specialized for the application that corresponds to the employee ID card. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Publication No. 2022-96855 Summary of the Invention [Problem to be solved by the invention]
[0005] If a verification device is equipped with access means corresponding to applications for multiple types of IDs (e.g., mDL and health insurance cards), the types of IDs that the verification device can verify are communicated to the user (ID holder) of the digital device via a screen display or verbally by an attendant. When the user selects one of the types of IDs that can be presented by the digital device, the verification device attempts to access the application using access means corresponding to the application corresponding to the type selected by the user. Here, the ID is specified by, for example, the user verbally telling the attendant the ID or by the user inputting the ID into an input unit provided in the verification device.
[0006] On the other hand, if no attendant is present during ID verification and the verification device does not have an input unit, the verification device does not know the type of ID stored on the digital device, so a method can be considered in which the verification device sequentially tries each of the multiple access methods implemented in the verification device in a predetermined order. For example, suppose a digital device implemented with applications corresponding to the health insurance card, national ID card, and employee ID card is presented to a verification device that implements access methods corresponding to applications corresponding to the mDL, DTC, health insurance card, and national ID card, respectively. In this case, the verification device attempts to access the digital device in the order of executable access methods using a trial and error method. That is, the verification device attempts to access each application by executing the access method corresponding to each in the order mDL → DTC → health insurance card → national ID card.
[0007] For example, if the verification device attempts to access an application corresponding to the mDL, the digital device will respond with an error because the application corresponding to the mDL is not installed on the digital device. In response to this response, the verification device then attempts to access an application corresponding to the DTC, but the digital device also does not have an application corresponding to the DTC installed, so the digital device will again respond with an error. In response to this response, the verification device then attempts to access an application corresponding to the health insurance card, but the digital device has an application corresponding to the health insurance card installed, so the application corresponding to the health insurance card executes appropriate processing according to the access means installed on the verification device. As a result, the ID managed by the application corresponding to the health insurance card is transmitted to the verification device.
[0008] However, regardless of which of the above methods is adopted, there are concerns that operational issues may arise in environments where labor saving is required or where ID verification must be completed in an extremely short time.
[0009] Therefore, the present invention has been made in consideration of the above-mentioned problems, and aims to provide an information processing device, an information processing method, and a program that can quickly identify an application that can be accessed by an access means from among multiple types of applications implemented on a digital device and read the ID. [Means for solving the problem]
[0010] In order to solve the above problem, the invention described in claim 1 is an information processing device capable of communicating with a digital device that implements multiple types of applications that manage identification information capable of identifying individuals, wherein the digital device stores catalog information that stores, for each of the multiple types of applications, access means identification information that indicates a sequence for the information processing device to access the application, read the identification information, and verify authenticity, and the information processing device is characterized in comprising: a storage means that stores identification information of at least one of the access means implemented by the information processing device among the access means for each of the applications; an acquisition means that acquires the catalog information from the digital device; a selection means that selects one or more access means that can be executed by the information processing device based on the identification information stored in the catalog information acquired by the acquisition means and the identification information stored in the storage means; and a reading means that executes the access means selected by the selection means and reads the identification information from the application corresponding to the access means.
[0011] The invention as set forth in claim 2 is characterized in that the information processing device as set forth in claim 1 further comprises a verifying unit that verifies the authenticity of the identification information read by the reading unit.
[0012] The invention described in claim 3 is characterized in that, in the information processing device described in claim 2, it further comprises a notification means for notifying the user of the digital device of an error message if the verification result of the authenticity of the identification information by the verification means indicates failure.
[0013] The invention described in claim 4 is characterized in that, in the information processing device described in any one of claims 1 to 3, the reading means executes any other access means and reads the identification information from the application corresponding to the other access means when execution of any one of the multiple access means selected by the selection means fails.
[0014] The invention described in claim 5 is characterized in that, in the information processing device described in claim 2, the reading means executes each of the multiple access means selected by the selection means to read the identification information from each of the applications, the verification means verifies the authenticity of the identification information read from each of the applications, and if at least one of the verification results of the authenticity of each of the identification information by the verification means indicates a failure, the invention further includes a notification means for notifying an error message to a user of the digital device.
[0015] The invention described in claim 6 is characterized in that, in the information processing device described in claim 2, the reading means executes each of the multiple access means selected by the selection means to read the identification information from each of the applications, the verification means verifies the authenticity of the identification information read from each of the applications, and if the verification result of the authenticity of each of the identification information by the verification means indicates failure, the information processing device further includes a notification means for notifying an error message to a user of the digital device.
[0016] The invention described in claim 7 is an information processing device described in claim 2, wherein the storage means stores, for each access means, a score that is added when the authenticity of the identification information is successfully verified; the reading means executes each of the multiple access means selected by the selection means to read the identification information from each of the applications; the verification means verifies the authenticity of the identification information read from each of the applications, compares the sum of the scores corresponding to the access means corresponding to each of the multiple identification information for which the authenticity verification result is successful with a threshold, and further comprises a determination means for determining whether the comparison result meets a predetermined condition; and further comprises a notification means for notifying an error message to a user of the digital device if the determination means determines that the comparison result does not meet the predetermined condition.
[0017] The invention described in claim 8 is an information processing device described in claim 2, wherein combination conditions for a plurality of the access means are stored, the reading means executes each of the plurality of access means selected by the selection means to read the identification information from each of the applications, the verification means verifies the authenticity of the identification information read from each of the applications, and further includes a judgment means for judging whether the combination of the access means corresponding to each of the plurality of identification information for which the verification result of the authenticity is successful satisfies the combination conditions, and further includes a notification means for notifying an error message to a user of the digital device if the judgment means judges that the combination of the access means does not satisfy the combination conditions.
[0018] The invention described in claim 9 is characterized in that, in the information processing device described in claim 2, if the verification result of the authenticity of the identification information by the verification means indicates success, the controlled object is controlled or secret information is presented.
[0019] The invention as set forth in claim 10 is the information processing device as set forth in any one of claims 1 to 3, wherein the specific information of the access means is an object identifier.
[0020] The invention described in claim 11 is an information processing method executed by an information processing device capable of communicating with a digital device that implements multiple types of applications that manage identification information capable of identifying individuals, wherein the digital device stores catalog information that stores, for each of the multiple types of applications, access means identification information indicating a sequence for the information processing device to access the application, read the identification information, and verify authenticity, and the information processing method includes the steps of: storing, in a storage means, the identification information of at least one of the access means implemented by the information processing device among the access means for each of the applications; acquiring the catalog information from the digital device; selecting one or more access means that can be executed by the information processing device based on the identification information stored in the acquired catalog information and the identification information stored in the storage means; and executing the selected access means to read the identification information from the application corresponding to the access means.
[0021] The invention described in claim 12 is a program readable by a computer included in an information processing device capable of communicating with a digital device that implements multiple types of applications that manage identification information capable of identifying individuals, wherein the digital device stores catalog information that stores, for each of the multiple types of applications, access means identification information indicating a sequence by which the information processing device accesses the application, reads the identification information, and verifies authenticity, and the program causes the computer to execute the following steps: storing, in a storage means, the identification information of at least one of the access means implemented by the information processing device among the access means for each of the applications; acquiring the catalog information from the digital device; selecting one or more access means executable by the information processing device based on the identification information stored in the acquired catalog information and the identification information stored in the storage means; and executing the selected access means to read the identification information from the application corresponding to the access means. [Effects of the Invention]
[0022] According to the present invention, it is possible to quickly identify an application that can be accessed by an access means from among multiple types of applications installed in a digital device and read the ID. [Brief explanation of the drawings]
[0023] [Figure 1] FIG. 1 is a diagram illustrating an example of a schematic configuration of an ID verification system S. [Figure 2] FIG. 10 is a diagram showing an example of the data structure of catalog information stored in a digital device D1. [Figure 3] FIG. 2 is a diagram illustrating an example of a schematic configuration of an ID reading and verification device Vm. [Figure 4] FIG. 10 is a diagram showing an example of an ID-APP access means list stored in the ID reading and verification device V1. [Figure 5]FIG. 10 is a diagram showing control information (example 1) stored in ID reading and verification device V1. [Figure 6] FIG. 10 is a diagram showing control information (example 2) stored in ID reading and verification device V1. [Figure 7] 1 is a sequence diagram showing an example of an ID verification process performed in an ID verification system S. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0024] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. Note that the embodiments described below are embodiments in which the present invention is applied to an ID verification system.
[0025] [1. Configuration and Function of ID Verification System S] First, referring to FIG. 1, an overview of the configuration and functions of an ID verification system S according to this embodiment will be described. FIG. 1 is a diagram showing an example of the schematic configuration of the ID verification system S. As shown in FIG. 1, the ID verification system S includes digital devices Dn (n=1, 2, . . .), ID reading and verification devices Vm (m=1, 2, . . .) (an example of an information processing device according to the present invention), and ID verification servers SAl (l=1, 2, . . .), which are connected to a communication network NW. The communication network NW includes, for example, the Internet, a mobile communication network, and its wireless base stations. The ID verification server SAl is a server that performs signature verification of a predetermined digital signature in response to a verification request from the ID reading and verification device Vm. However, depending on the ID reading and verification device Vm, the ID reading and verification device Vm may perform signature verification of a predetermined digital signature by itself without making a verification request to the ID verification server SAl.
[0026] The digital device Dn is used (possessed) by a user Un, who is an ID holder, and is capable of communicating with an ID reading and verification device Vm via an interface such as NFC (Near Field Communication), a short-range wireless communication method. It is desirable that the digital device Dn be a mobile terminal such as a smartphone with NFC functionality. NFC has a communication distance of approximately 10 cm, making it highly secure because it is difficult to implement man-in-the-middle attacks, which are a frequent problem in wireless communication technologies. The digital device Dn also has an operating system (OS) and applications that run on the OS installed. The applications include multiple applications (hereinafter referred to as "ID-APPs") that manage IDs (identification information) that can identify an individual (user Un). In other words, the digital device Dn has installed thereon applications that manage each of the multiple types of IDs. IDs are managed, for example, by storing them in a file accessible by the ID-APP. The ID system may differ or may be the same for each application.
[0027] For example, digital device D1 used by user U1, a domestic resident, is implemented with multiple ID-APPs, including mDL ID-APP1 and My Number Card ID-APP2. Here, mDL ID-APP1 manages a driver's license number as an ID, and My Number Card ID-APP2 manages a My Number as an ID. Meanwhile, digital device D2 used by user U2, an overseas resident (entrant), is implemented with multiple ID-APPs, including DTC ID-APP3, airline ticket ID-APP4, and credit card ID-APP5. Here, DTC ID-APP3 manages a passport number as an ID, airline ticket ID-APP4 manages an airline ticket number as an ID, and credit card ID-APP5 manages a credit card number as an ID.
[0028] The ID managed by the ID-APP may be included in a digital certificate managed by the ID-APP along with information indicating the ID holder's attributes. The digital certificate includes a digital signature generated using the private key of the ID issuer (e.g., a local government or a company). The authenticity of the ID (in other words, the reliability of the ID holder's attributes) can be verified by verifying the ID issuer's digital signature using a public key that pairs with the ID issuer's private key. The digital certificate may also include the ID issuer's public key or an Internet address indicating the location of the public key (e.g., its location on the Web).
[0029] Furthermore, the digital device Dn stores catalog information (i.e., a list of the specific information of the ID-APP access means) that stores, for each of multiple types of ID-APPs, specific information of the access means (hereinafter referred to as "ID-APP access means") that indicates the sequence (procedure) by which the ID reading and verification device Vm accesses the ID-APP, reads (i.e., reads) the ID, and verifies its authenticity. In other words, the ID-APP access means is a procedure described in a procedure manual, including, for example, the command execution order, command parameters, and required encryption algorithms. Information for identifying this procedure is stored in the catalog information, and this procedure is implemented in the ID reading and verification device Vm. The catalog information that stores the specific information of multiple types of ID-APP access means is expressed, for example, by a uniform resource identifier (URI). The specific information of the ID-APP access means may be expressed, for example, by an object identifier (hereinafter referred to as an "OID (Object IDentifier)"). Using an OID, the procedure described in the procedure manual can be uniquely identified. In other words, the OID not only identifies the procedure manual, but also partially identifies the contents of the procedure manual, such as the chapter number and algorithm. The OID is expressed as "XXXXX.XXXXX" (where X is a number). For example, the OID corresponding to the mDL defined in the international standard ISO / IEC 18013-5 is written as "1.0.18013.5." Note that "1.0.18013.5" only identifies the standard document number described in ISO / IEC 18013-5, but this is because it uniquely identifies the access method described in the standard document. Depending on the content of the standard document, it may be necessary to include information specifying the chapter number or algorithm.
[0030] FIG. 2 is a diagram showing an example of the data structure of catalog information stored in digital device D1. The catalog information shown in FIG. 2 includes a data type identifier, a payload length, and a payload. The data type identifier is, for example, an identifier (tag) indicating that the payload contains specific information about an ID-APP access method. The payload length indicates the data length of the payload. In the example of FIG. 2, the payload includes L1, the OID (XXXXX.XXXXX) of the ID-APP1 access method, L2, and the OID of the ID-APP2 access method. Here, the ID-APP1 access method indicates an access method corresponding to ID-APP1 in the mDL, and L1 indicates the data length of the OID of the ID-APP1 access method. The ID-APP2 access method indicates an access method corresponding to ID-APP2 on the My Number Card, and L2 indicates the data length of the OID of the ID-APP2 access method.
[0031] As an example different from that shown in Figure 2, the payload included in the catalog information may be written as "idc: / / OID|OID." Here, "idc" is the URI scheme name. For example, after "idc: / / ," it is written as "ID-APP1 access method OID|ID-APP2 access method OID." This description format is adopted by the NFC Data Exchange Format (NDEF) defined by the NFC Forum. NDEF is sent and received in the form of a data block called an NDEF Message. An NDEF Message consists of multiple NDEF Records, and each NDEF Record is divided into a Header and a Payload. By setting the NFC Forum Well Known Type (0x01) in the TNF included in the Header, it is possible to define that "idc: / / OID|OID" is included in the Payload. Here, OID may be replaced with another identifier that indicates specific information about the ID-APP access method (e.g., a URL (https: / / xxxx)), but using OID improves convenience.
[0032] The ID reading and verification device Vm is installed in facilities where user Un's identity verification is required, such as for administrative procedures, account opening, package receipt, entry, or alcohol sales. FIG. 3 is a diagram showing an example of the schematic configuration of the ID reading and verification device Vm. The ID reading and verification device Vm includes a short-range wireless communication unit 11, a communication unit 12, a storage unit 13, and an information processing unit 14 (an example of a computer), and is equipped (installed) with an OS, a PO-APP running on the OS, and a predetermined ID-APP access means. The short-range wireless communication unit 11 includes an antenna and can communicate (near-field wireless communication) with a digital device Dn within a short-range wireless communication range using, for example, an NFC function. At least one of the OS and the PO-APP is an example of a program of the present invention.
[0033] Here, the OS may be equipped with an NDEF reading function as one of the means for reading so-called NFC tags and a mechanism for automatically launching an application corresponding to the identifier written in the read NDEF. With this mechanism, for example, if the read NDEF contains an identifier indicating a telephone number, the OS may automatically launch a telephone application to call the listed telephone number, or if the read NDEF contains an identifier indicating an Internet address, the OS may automatically launch an Internet browser to access the listed Internet address. The OS reads the NDEF record, interprets the contents of the NDEF record, and if the NDEF record contains a URI (idc: / / ) indicating the catalog information, the OS may launch an ID verification portal application (hereinafter referred to as "PO-APP") located at the entrance to multiple ID-APP access methods and managing the ID-APP access methods. As a result, as described below, the present invention can be realized with a minimal configuration using OS functions (especially standard functions when using iOS (registered trademark) or Android (registered trademark) as the OS) to read and verify the ID from the ID-APP.
[0034] The communication unit 12 is connected to the communication network NW and controls communication with, for example, the ID verification server SAl. The communication unit 12 may also include a wireless communication device for connecting to a wireless base station of a mobile communication network. The storage unit 13 (an example of a storage means) is composed of, for example, an SSD or a nonvolatile semiconductor memory. The storage unit 13 stores an OS, a PO-APP, an ID-APP access program, and the like. Here, the ID-APP access program is a program implemented based on the ID-APP access means. Note that executing the access means is synonymous with executing the ID-APP access program. The ID reading and verification device Vm may implement one or more types of ID-APP access means. Depending on the characteristics of the ID reading and verification device Vm, some ID reading and verification devices Vm can access multiple ID-APPPs, while others can only access a single ID-APPP. In particular, an ID-APP access means list may be stored in the storage unit 13 of an ID reading and verification device Vm that is implemented with multiple types of ID-APP access means.
[0035] Fig. 4 is a diagram showing an example of an ID-APP access method list stored in the ID reading and verification device V1. In the ID-APP access method list shown in Fig. 4, access method identification numbers and specific information for ID-APP access methods are registered in association with each ID-APP access method. In the example of Fig. 4, "1.0.12345.1" indicates the OID of the ID-APP1 access method, "1.0.23456.1" indicates the OID of the ID-APP2 access method, "1.0.3456.7" indicates the OID of the ID-APP3 access method, "1.0.4567.8" indicates the OID of the ID-APP4 access method, and "1.0.4567.9" indicates the OID of the ID-APP5 access method.
[0036] The storage unit 13 may also store control information related to the ID-APP access means implemented in the ID reading and verification device Vm. For example, the operator of the facility or service where the ID reading and verification device Vm is installed can set the conditions for a single ID or a combination of multiple types of IDs (in other words, a combination of ID-APP access means) that are essential for identity verification in the control information. Note that control information related to each of the multiple types of ID-APP access means may be stored in each ID-APP access means. Figures 5 and 6 are diagrams showing control information (example 1 and example 2) stored in the ID reading and verification device V1.
[0037] In the control information (example 1) shown in Fig. 5, an access means identification number and a score are registered in association with each ID-APP access means. In other words, the control information (example 1) stores a score that is added when the authenticity of an ID is successfully verified for each ID-APP access means. In the control information (example 1), the ID combination conditions can be controlled by the score. For example, when an ID is read from the ID-APP by an ID-APP access means specified by the access means identification number and the authenticity is successfully verified, the score associated with the access means identification number is added (the initial value of the score is 0), and when the score reaches "100", it is determined that the identity verification has been passed.
[0038] 5, for example, if the authenticity of an ID read by the ID-APP1 or ID-APP2 access means is successfully verified, the score in one process is "100" and it is determined that the identity verification has been passed. On the other hand, if the authenticity of an ID read by the ID-APP3 access means is successfully verified, the score in one process is only "50", so in order to be considered as having passed the identity verification, it is necessary to subsequently successfully verify the authenticity of an ID read by, for example, the ID-APP4 access means. In other words, if the authenticity of an ID read by any two of the ID-APP3, ID-APP4, and ID-APP5 access means is successfully verified, the score is "100" and it is determined that the identity verification has been passed.
[0039] The control information (Example 2) shown in Figure 6 registers a control rule identifier, Value 1 (logical expression), and Value 2 (logical operation target). Here, the logical expression indicates an OR condition or an AND condition. The logical operation target indicates a condition for a combination of access means identification numbers (i.e., a combination of ID-APP access methods). Multiple logical expressions are set in the control information (Example 2), allowing the verification results to be combined. According to the control information (Example 2), if an ID is read from the ID-APP using an ID-APP access method identified by an access method identification number for which the logical expression (1 or 2) or {3 and (4 or 5)} is satisfied, and the authenticity is successfully verified, it is determined that the identity verification has passed. Note that the logical expression (1 or 2) or {3 and (4 or 5)} is intended to represent, for example, conditions such as requiring domestic residents to present either a driver's license or a My Number card, or requiring all people, including those entering the country, to present a passport and airline ticket or a passport and credit card.
[0040] The information processing unit 14 includes a RAM (Random Access Memory) and a CPU (Central Processing Unit), and functions as the acquisition means, selection means, reading means, verification means, determination means, and notification means of the present invention in accordance with the OS and PO-APP, thereby executing ID verification processing. Specifically, when the information processing unit 14 acquires (receives) catalog information (e.g., an NDEF Message) from the digital device Dn via the short-range wireless communication unit 11, it interprets the catalog information according to a predetermined format, and if idc: / / OID|OID is present, launches the PO-APP. At this time, the information processing unit 14 may generate an ID-APP access means candidate list for accessing one or more ID-APPs registered in the digital device Dn. The access means candidate list may include, for example, specific information (e.g., OID) of the ID-APP access means.
[0041] The information processing unit 14 selects one or more ID-APP access methods executable by the ID reading and verification device Vm based on the specific information (e.g., the OID of the ID-APP access method) stored in the acquired catalog information and the specific information (e.g., the OID of the ID-APP access method) stored in the storage unit 13. For example, the information processing unit 14 may compare (i.e., match) the ID-APP access method candidate list generated based on the catalog information with the ID-APP access method list pre-stored in the storage unit 13, select ID-APP access methods whose specific information (e.g., the OID) matches in both lists, and generate an ID-APP access method execution target list in which the specific information (e.g., the OID) of the selected ID-APP access method is registered.
[0042] The information processing unit 14 executes the selected ID-APP access means to read the ID from the ID-APP corresponding to the selected ID-APP access means. For example, the information processing unit 14 interprets specific information (e.g., OID) registered in the ID-APP access means execution target list and executes the ID-APP access means to access the ID-APP of the digital device D1 via the short-range wireless communication unit 11 and read the ID from the ID-APP. At this time, related information including the ID (e.g., the above-mentioned digital certificate) may also be read. Note that the ID-APP access means may execute an authentication process involving cryptographic calculation, and the information processing unit 14 may read the ID from the ID-APP when the digital device Dn and the ID reading and verification device Vm are mutually authenticated.
[0043] Furthermore, when the above-mentioned selected multiple pieces of specific information are registered in the ID-APP access means execution target list, the information processing unit 14 executes any one of the selected multiple ID-APP access means to read the ID from the ID-APP corresponding to that one ID-APP access means, or executes each of the selected multiple ID-APP access means (trying them in a predetermined order) to read the ID from the ID-APP corresponding to each ID-APP access means. In this case, if the information processing unit 14 fails to execute (try) any one of the selected multiple ID-APP access means, it may execute any other ID-APP access means to read the ID from the ID-APP corresponding to that other ID-APP access means.
[0044] The information processing unit 14 verifies the authenticity of the ID read from the ID-APP and records the verification result indicating success or failure. When an ID is read from each of multiple types of ID-APPs, the authenticity of each ID is verified, and each verification result is recorded in association with the identification information of the corresponding ID-APP access means. For example, when a digital certificate including an ID is read from the ID-APP, the information processing unit 14 verifies the authenticity of the ID by performing signature verification on the digital signature included in the digital certificate using the public key of the ID issuer. If the signature verification is successful, the verification result of the ID authenticity indicates success. When the public key of the ID issuer is included in the digital certificate, the information processing unit 14 may acquire the public key from the digital certificate. On the other hand, the public key of the ID issuer may be associated with the identification information of the ID-APP access means and pre-stored in the storage unit 13 (when the public key is not included in the digital certificate). In this case, the information processing unit 14 may acquire the public key associated with the identification information of the executed ID-APP access means from the storage unit 13.
[0045] Alternatively, if the digital certificate includes an Internet address indicating the location of the ID issuer's public key, the information processing unit 14 may access a registry (an example of a location) that registers public keys according to the Internet address and obtain the public key. Alternatively, depending on security requirements, the ID issuer's public key may be pre-stored in the ID verification server SAl. In this case, the information processing unit 14 sends a verification request including the read digital certificate to the ID verification server SAl. In response to the received verification request, the ID verification server SAl performs signature verification on the digital signature included in the digital certificate using the ID issuer's public key and returns the signature verification result (indicating success or failure) to the ID reading and verification device Vm. The information processing unit 14 verifies the authenticity of the ID based on the signature verification result from the ID verification server SAl and records the verification result. If the signature verification result indicates success, the verification result indicating success is recorded. In this case, the information processing unit 14 does not verify the authenticity of the ID itself, but only confirms the signature verification result from the ID verification server SAl.
[0046] Note that digital certificates may not be used depending on security requirements. In this case, for example, an ID list registering authentic IDs is associated with the specific information of the ID-APP access means and stored in advance in the storage unit 13. The information processing unit 14 then verifies the authenticity of the ID read from the ID-APP by executing the ID-APP access means by determining whether the ID is included in the ID list associated with the specific information of the ID-APP access means, and records the verification result indicating success or failure. Here, if the ID read from the ID-APP is included in the ID list, the verification result of the ID authenticity indicates success.
[0047] The information processing unit 14 determines whether the ID meets the pass criteria for identity verification based on the verification result of the ID authenticity (the verification result recorded as described above). For example, if the verification result of the ID authenticity indicates success, it is determined that the predetermined pass criteria are met (i.e., identity verification has passed). If the information processing unit 14 determines that the pass criteria are met, it executes pass-case processing, such as controlling controlled objects installed in the facility (e.g., unlocking or opening a gate), presenting confidential information to facility staff (e.g., displaying it on the digital device Dn), or approving and transmitting the digital document, based on the authority granted to the ID holder (e.g., user Un of the digital device Dn). Here, approving and transmitting the digital document refers to, for example, attaching a digital signature indicating that an electronic seal has been affixed to the digital document and transmitting the digital document to a predetermined device. On the other hand, if the information processing unit 14 determines that the pass criteria are not met, it executes fail-case processing, such as notifying the ID holder (e.g., user Un of the digital device Dn) of an error message via the digital device Dn and transmitting a predetermined message. Here, the error message indicates, for example, that the identity check has failed or that the authenticity of the ID has failed to be verified.
[0048] Furthermore, when the authenticity of multiple types of IDs is verified, if each of the verification results of the authenticity of each ID indicates success, it is determined that the predetermined pass criteria is met, and the above-mentioned pass-time processing is executed. On the other hand, if at least one of the verification results of the authenticity of each ID indicates failure, it is determined that the predetermined pass criteria is not met, and the above-mentioned fail-time processing is executed (i.e., the pass criteria are strict). This can improve security while improving the convenience of the ID reading and verification device Vm. Alternatively, when the authenticity of multiple types of IDs is verified, if at least one of the verification results of the authenticity of each ID indicates success, it is determined that the predetermined pass criteria is met, and the above-mentioned pass-time processing is executed. On the other hand, if each of the verification results of the authenticity of each ID indicates failure, it is determined that the predetermined pass criteria is not met, and the above-mentioned fail-time processing is executed (i.e., the pass criteria are lenient).
[0049] Furthermore, if control information related to the ID-APP access means is stored, the information processing unit 14 may determine whether or not the pass criteria for identity verification are met in accordance with the control information based on the verification result of the ID authenticity. For example, when the authenticity of multiple types of IDs is verified, the information processing unit 14 may identify scores corresponding to the ID-APP access means corresponding to each of the multiple IDs for which the verification result of authenticity is successful (i.e., the ID-APP access means corresponding to the ID-APP from which the ID was read) based on, for example, the control information (Example 1) shown in FIG. 5, calculate the sum of the identified scores, compare the calculated sum with a threshold (e.g., 100), and determine whether or not the comparison result meets a predetermined condition. For example, if the calculated sum is determined to be equal to or greater than the threshold (e.g., 100), it is determined that the predetermined pass criteria are met, and the pass processing is executed. On the other hand, if the calculated sum is determined to be less than the threshold (e.g., 100) (an example of a case in which the comparison result is determined not to meet the predetermined condition), it is determined that the predetermined pass criteria are not met, and the fail processing is executed. This makes it possible to improve the security and convenience of the ID reading and verification device Vm.
[0050] Alternatively, when the authenticity of multiple types of IDs is verified, the information processing unit 14 may determine whether the combination of ID-APP access means corresponding to each of the multiple IDs for which the authenticity verification results are successful satisfies the combination conditions shown in, for example, the control information (example 2) shown in Figure 6. For example, if it is determined that the combination of ID-APP access means satisfies the combination conditions, it is determined that the combination satisfies the predetermined pass criterion, and the pass processing is executed. On the other hand, if it is determined that the combination of ID-APP access means does not satisfy the combination conditions, it is determined that the combination does not satisfy the predetermined pass criterion, and the fail processing is executed. This makes it possible to improve the convenience of the ID reading and verification device Vm while improving security.
[0051] [2. Example of ID Verification System S] Next, the operation of the ID verification system S will be described with reference to Fig. 7. Fig. 7 is a sequence diagram showing an example of ID verification processing performed in the ID verification system S. Note that the operation example described below takes as an example a case where a digital device D1 and an ID reading and verification device V1 communicate with each other by short-range wireless communication.
[0052] In FIG. 7, when the ID reading and verification device V1 and the digital device D1 start communication, the ID reading and verification device V1 starts a catalog reading process (step S1), for example, using an OS, and sends a selection command (including, for example, a file ID) to the digital device D1 to select a specific file in which catalog information is stored.
[0053] Next, when the digital device D1 receives the selection command from the ID reading & verification device V1, it starts catalog response processing (step S2) using, for example, the OS, and if the file specified by the selection command exists, it sets the file to a selected state and sends a processing success message to the ID reading & verification device V1. On the other hand, if the file specified by the selection command does not exist, the digital device D1 sends a processing failure message to the ID reading & verification device V1.
[0054] Next, upon receiving a processing success message from the digital device D1, the ID reading & verification device V1 sends a catalog read command to the digital device D1. Upon receiving the catalog read command from the ID reading & verification device V1, the digital device D1 obtains catalog information from the selected file, for example, using an OS, and sends the catalog information along with a processing success message to the ID reading & verification device V1. On the other hand, if the selected file does not have catalog information, the digital device D1 sends a processing failure message to the ID reading & verification device V1.
[0055] In addition, if the information obtained by the ID reading & verification device V1 is written in NDEF and the information contains a URI of catalog information that stores the ID-APP access means, the ID reading & verification device V1 will launch the PO-APP that manages the ID-APP access means to the ID-APP.
[0056] Next, when the ID reading & verification device V1 receives a processing success message from the digital device D1 (obtains catalog information), it executes ID-APP access means candidate list generation processing, for example, by PO-APP (step S3). In the ID-APP access means candidate list generation processing, the information processing unit 14 interprets the catalog information obtained in step S2 and generates an ID-APP access means candidate list including specific information (e.g., OID) of the ID-APP access means for accessing the ID-APP registered in the digital device Dn.
[0057] Next, the ID reading & verification device V1 executes an ID-APP access means execution target list generation process using, for example, PO-APP (step S4). In the ID-APP access means execution target list generation process, the information processing unit 14 compares the ID-APP access means candidate list generated in step S3 with the ID-APP access means list pre-stored in the storage unit 13, selects ID-APP access means whose specific information (e.g., OID) matches in both lists, and generates an ID-APP access means execution target list including the specific information (e.g., OID) of the selected ID-APP access means.
[0058] Next, the ID reading & verification device V1 selects one specific information (element of the list) by, for example, PO-APP from the ID-APP access means execution list generated in step S4, and executes access processing for the ID-APP (ID reading processing) by the ID-APP access means specified by the selected specific information (step S5). In the access processing for the ID-APP, the information processing unit 14 executes the ID-APP access means specified by the selected specific information (for example, OID) to send an ID read command (addressed to the ID-APP) to the digital device D1.
[0059] Next, when the digital device D1 receives the ID read command from the ID reading & verification device V1, it executes access processing using the ID-APP (step S6). In the access processing using the ID-APP, the ID-APP of the digital device D1 obtains related information including the ID (ID-related information) from a predetermined file and transmits the ID-related information together with a processing success message to the ID reading & verification device V1.
[0060] Next, when the ID reading and verification device V1 receives a processing success message from the digital device D1 (reads the ID-related information), it executes ID authenticity confirmation processing using the ID-APP access means identified by the selected identification information (step S7). In the ID authenticity confirmation processing, the information processing unit 14 verifies the authenticity of the ID read from the ID-APP as described above and records the verification result indicating success or failure. Note that, as described above, the information processing unit 14 may have the ID verification server SA1 verify the authenticity of the ID read from the ID-APP and confirm the authenticity of the ID based on the verification result.
[0061] Next, the ID reading and verification device V1 determines whether the pass criteria for identity verification are met, for example, by the PO-APP, based on the verification result of the authenticity of the read ID (step S8). If it is determined that the pass criteria for identity verification are met (step S8: YES), the process proceeds to step S9. On the other hand, if it is determined that the pass criteria for identity verification are not met (step S8: NO), the process returns to step S5, where one piece of specific information that has not yet been selected from the ID-APP access means execution target list is selected, and the same process as above is executed. In this loop process, the authenticity of multiple types of IDs is verified, and each time it is determined whether the pass criteria for identity verification are met. If it is ultimately determined that the pass criteria for identity verification are not met even after all specific information has been selected from the ID-APP access means execution target list, the process proceeds to step S10.
[0062] In step S9, the ID reading and verification device V1 executes the pass process as described above using, for example, the PO-APP, and then ends the process. On the other hand, in step S10, the ID reading and verification device V1 executes the fail process as described above using, for example, the PO-APP, and then ends the process.
[0063] As described above, according to the above embodiment, the ID reading and verification device Vm acquires catalog information from the digital device Dn, selects one or more executable ID-APP access methods based on the identification information stored in the acquired catalog information and the identification information stored in the storage unit 13, and executes the selected ID-APP access method to read the ID from the ID-APP corresponding to the selected ID-APP access method. This eliminates redundant procedures and allows for quick identification of an ID-APP accessible by the ID-APP access method from among multiple types of ID-APPs implemented on the digital device Dn, thereby reading the ID. In other words, it is possible to quickly find an appropriate ID-APP and start the reading process. Furthermore, the ID reading and verification device Vm is configured to verify the authenticity of the read ID, thereby preventing operational disruptions, for example, in environments where labor reduction is required or where ID verification must be completed in an extremely short time.
[0064] In the above embodiment, the ID reading and verification device Vm has been described as an example of the information processing device of the present invention. However, the ID reading device and the ID verification device may be separate devices. Furthermore, in the above embodiment, the identification information capable of identifying an individual may be a DID. As is well known, a DID is composed of a Scheme, a DID Method, and a DID Method-Specific Identifier. The DID Method describes the identification name of the registry in which the DID is registered, and the DID Method-Specific Identifier describes a unique identifier assigned to the individual in the registry. When a DID holder (the above-mentioned user Un) requests the issuance of a DID, the DID issuer creates a new DID and also creates a DID document. The DID document includes the DID of user Un, a public key associated with the DID, and information about the DID issuer, and is registered in the registry. The DID can be included in a verifiable digital certificate (VC (Verifiable Credential)), and the VC further includes the DID of the VC issuer, the VC issuer's digital signature, and the like. The ID-APP implemented in the digital device Dn includes an ID wallet APP for managing DID. The ID reading and verification device Vm executes an ID-APP access means in accordance with the ID wallet APP to read a VC from the ID wallet APP corresponding to the ID-APP access means, and executes the ID verification process described above. [Explanation of symbols]
[0065] 11 Near Field Wireless Communication Department 12 Communications Department 13 Storage section 14 Information Processing Department Dn Digital Device VM ID Reader & Verifier SAl ID Verification Server S ID Verification System
Claims
1. An information processing device capable of communicating with a digital device that implements a plurality of applications that manage identification information that can identify an individual, the digital device stores catalog information that stores, for each of the plurality of types of applications, specific information of an access means that indicates a sequence for the information processing device to access the application, read the identification information, and verify authenticity; The information processing device includes: a storage means for storing specific information of at least one of the access means for each application that is implemented in the information processing device; an acquisition means for acquiring the catalog information from the digital device; a selection means for selecting one or more access means executable by the information processing device based on the specific information stored in the catalog information acquired by the acquisition means and the specific information stored in the storage means; a reading means for executing the access means selected by the selecting means and reading the identification information from the application corresponding to the access means; An information processing device comprising:
2. 2. The information processing apparatus according to claim 1, further comprising a verifying unit that verifies the authenticity of the identification information read by said reading unit.
3. 3. The information processing apparatus according to claim 2, further comprising a notification unit that notifies a user of the digital device of an error message when the verification unit fails to verify the authenticity of the identification information.
4. The information processing device according to any one of claims 1 to 3, characterized in that, when execution of any one of the plurality of access means selected by the selection means fails, the reading means executes any other access means and reads the identification information from the application corresponding to the other access means.
5. the reading means executes each of the plurality of access means selected by the selection means to read the identification information from each of the applications; the verification means verifies the authenticity of the identification information read from each of the applications; 3. The information processing apparatus according to claim 2, further comprising a notification means for notifying a user of the digital device of an error message when at least one of the verification results of the authenticity of each of the identification information by the verification means indicates failure.
6. the reading means executes each of the plurality of access means selected by the selection means to read the identification information from each of the applications; the verification means verifies the authenticity of the identification information read from each of the applications; 3. The information processing apparatus according to claim 2, further comprising a notification unit that notifies a user of the digital device of an error message when the verification unit fails to verify the authenticity of each piece of identification information.
7. the storage means stores, for each of the access means, a score that is added when the authenticity of the identification information is successfully verified; the reading means executes each of the plurality of access means selected by the selection means to read the identification information from each of the applications; the verification means verifies the authenticity of the identification information read from each of the applications; a determination unit that compares a sum of the scores corresponding to the access means corresponding to each of the plurality of pieces of identification information for which the authenticity verification result is successful with a threshold value and determines whether or not the comparison result satisfies a predetermined condition; 3. The information processing apparatus according to claim 2, further comprising a notification unit that notifies a user of the digital device with an error message when the determination unit determines that the comparison result does not match a predetermined condition.
8. A combination condition of a plurality of the access means is stored, the reading means executes each of the plurality of access means selected by the selection means to read the identification information from each of the applications; the verification means verifies the authenticity of the identification information read from each of the applications; a determination unit that determines whether or not the combination of the access units corresponding to each of the plurality of pieces of identification information for which the verification of authenticity has been successful satisfies the combination condition; 3. The information processing apparatus according to claim 2, further comprising a notification unit that notifies a user of the digital device with an error message when the determination unit determines that the combination of the access units does not satisfy the combination condition.
9. 3. The information processing apparatus according to claim 2, wherein, when the verification result of the authenticity of the identification information by the verification means indicates success, the information processing apparatus controls an object to be controlled or presents secret information.
10. 4. The information processing apparatus according to claim 1, wherein the specific information of the access means is an object identifier.
11. 1. An information processing method executed by an information processing device capable of communicating with a digital device that implements multiple types of applications that manage identification information that can identify individuals, comprising: the digital device stores catalog information that stores, for each of the plurality of types of applications, specific information of an access means that indicates a sequence for the information processing device to access the application, read the identification information, and verify authenticity; The information processing method includes: storing, in a storage means, specific information of at least one of the access means for each application that is implemented in the information processing device; obtaining the catalog information from the digital device; selecting one or more access means executable by the information processing device based on the specific information stored in the acquired catalog information and the specific information stored in the storage means; executing the selected access means to read the identification information from the application corresponding to the selected access means; An information processing method comprising:
12. A computer-readable program included in an information processing device capable of communicating with a digital device that implements multiple types of applications for managing identification information that can identify individuals, the digital device stores catalog information that stores, for each of the plurality of types of applications, specific information of an access means that indicates a sequence for the information processing device to access the application, read the identification information, and verify authenticity; storing, in a storage means, specific information of at least one of the access means for each application that is implemented in the information processing device; obtaining the catalog information from the digital device; selecting one or more access means executable by the information processing device based on the specific information stored in the acquired catalog information and the specific information stored in the storage means; executing the selected access means to read the identification information from the application corresponding to the selected access means; A program that causes the computer to execute the above.
Citation Information
Patent Citations
Management server, id registration system, id registration method, and program
JP2022096855A