Head portrait management system, head portrait management method, and program
By managing the identity proof information associated with each avatar in the avatar management system in the virtual space, the problem of inactivation of avatar utilization is solved, the authenticity and identity authentication of the avatar are realized, and the avatar activation efficiency in the virtual space is improved.
Patent Information
- Application Number
- CN202380060777.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-29
- Filing Date
- 2023-08-31
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, the avatar utilization in the virtual space cannot be effectively activated, and the identity proof information management mechanism is lacking, making it difficult to verify the authenticity and identity authentication of the avatar.
The identity proof information is managed through the avatar identity proof information management department, and the identity authentication identifier associated with each avatar is issued and stored using the identity proof information issuance system to realize the proof and management of the avatar identity.
It realizes the effective use of avatars in the virtual space, ensures the authenticity of the avatar and the reliability of the identity, and improves the activation and authentication efficiency of the avatars in network services.
Smart Images

Figure CN120359515A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an avatar management system, an avatar management method, and a program.
[0002] This application claims the priority of Japanese Patent Application No. 2022-137904 filed on August 31, 2022, and Japanese Patent Application No. 2022-190241 filed on November 29, 2022, the contents of which are incorporated herein by reference. Background Art
[0003] There is known a technique in which an avatar in a virtual space can perform actions such as purchasing virtual objects according to a user's operation (for example, see Patent Document 1).
[0004] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2022-117111 Summary of the Invention
[0005] Preferably, activation of the use of an avatar existing in a virtual space is achieved.
[0006] An object of the present invention is to achieve activation of the use of an avatar existing in a virtual space.
[0007] An avatar system according to one aspect of the present invention for solving the above problems includes an avatar identification information management unit that manages by causing an identification information issuing system to issue identification information and causing a storage unit to store the issued identification information, the identification information being associated with an avatar authentication identifier issued in a unique manner for each avatar registered to be usable in a network service provided to an end user on a network, and proving the identity of the avatar.
[0008] An avatar management method of an avatar management system according to one aspect of the present invention includes the following avatar identification information management step: an avatar identification information management unit manages by causing an identification information issuing system to issue identification information and causing a storage unit to store the issued identification information, the identification information being associated with an avatar authentication identifier issued in a unique manner for each avatar registered to be usable in a network service provided to an end user on a network, and proving the identity of the avatar.
[0009] A program according to one aspect of the present invention causes a computer of an avatar management system to function as an avatar identification information management unit that manages by causing an identification information issuing system to issue identification information and causing a storage unit to store the issued identification information. The identification information is associated with an avatar authentication identifier issued in a unique manner for each avatar registered to be usable in a network service provided to an end user on a network, and proves the identity of the avatar.
[0010] Effect of the Invention
[0011] According to the present invention, it is possible to activate the use of avatars existing in a virtual space. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 It is a diagram showing an example of the overall configuration of the identity management system according to the present embodiment.
[0013] Figure 2 It is a diagram showing an example of the configuration of the avatar generation system according to the present embodiment.
[0014] Figure 3 It is a diagram schematically showing the process of avatar generation according to the present embodiment.
[0015] Figure 4 It is a diagram showing an example of the hardware configuration of the identity management device according to the present embodiment.
[0016] Figure 5 It is a diagram showing an example of the functional configuration of the identity management device according to the present embodiment.
[0017] Figure 6 It is a diagram showing an example of the end user information according to the present embodiment.
[0018] Figure 7 It is a diagram showing an example of the avatar information according to the present embodiment.
[0019] Figure 8 It is a diagram showing an example of the metafile according to the present embodiment.
[0020] Figure 9 It is a diagram showing an example of the information stored corresponding to the avatar in the avatar VC storage unit according to the present embodiment.
[0021] Figure 10 It is a diagram showing an example of the information stored corresponding to the user in the avatar VC storage unit according to the present embodiment.
[0022] Figure 11This is a diagram showing the structural example of the credit information related to this embodiment.
[0023] Figure 12 This is a diagram showing the structural example of the issuer information related to this embodiment.
[0024] Figure 13 This is a sequence diagram showing an example of the processing flow executed in association with the generation, registration of an avatar, and registration of avatar authentication information by the identity management system related to this embodiment.
[0025] Figure 14 This is a sequence diagram showing an example of the processing flow executed corresponding to authenticity confirmation by the identity management system related to this embodiment.
[0026] Figure 15 This is a sequence diagram showing an example of the processing flow related to the granting of the usage right of an avatar and an example of the processing flow for using the avatar for identity verification related to this embodiment.
[0027] Figure 16 This is a diagram showing an example of the management of the wallet holding the avatar related to this embodiment.
[0028] Figure 17 This is a sequence diagram showing an example of the processing flow executed corresponding to the transaction between the identity management system and the avatar related to this embodiment. Detailed Embodiment
[0029] <Embodiment>
[0030] Figure 1 This shows an example of the overall structure of the identity management system (an example of an avatar management system) of this embodiment. The identity management system of this embodiment includes an avatar generation system 100, a user interface environment 200, an identity management device 400, a network service environment 500, a VC (Verifiable Credentials) issuance system 600, and a DPKI system 700 as
[0031] structural elements. The connections between the structural elements of the above systems are made via a network.
[0032] The avatar generation system 100 is a system for generating avatars used in the network service environment 500.
[0033] Figure 2 This shows an example of the structure of the avatar generation system 100. The avatar generation system 100 shown in this diagram includes a plurality of avatar material providing systems 110 and one integration system 120.
[0034] The avatar material providing system 110 is a system that respectively generates the specified avatar materials (avatar materials) that constitute the avatar and provides the generated avatar materials. The avatar material providing system 110 can be operated by a specified avatar material provider (company), for example.
[0035] The integration system 120 obtains the required avatar materials from the avatar materials provided by the avatar material providing system 110, and generates an avatar by integrating (combining) the obtained avatar materials.
[0036] In the avatar generation system 100, the avatar material providing system 110 and the integration system 120 can be connected via a network.
[0037] In addition, the number of avatar material providing systems 110 of the avatar generation system 100 only needs to be greater than or equal to 1, and is not particularly limited. In addition, the number of integration systems 120 only needs to be greater than or equal to 1, and is not particularly limited.
[0038] Figure 3 Schematically shows the process of avatar generation of the avatar generation system 100. The avatar of this embodiment can be, for example, a 2D or 3D (3D) character, etc., or can also be a 3D real avatar such as a person. When explaining this figure, an example of generating a 3D real avatar of a person is cited. The real avatar is, for example, information obtained by photographing the source person PS, and is an avatar that truly reproduces the posture of the actual person PS.
[0039] In the avatar generation system 100 of this figure, an example of having 6 avatar material providing systems 110-1 to 110-6 is shown.
[0040] The avatar material providing system 110-1 generates a 3D face (head) material as an avatar material, and provides the generated face material MT-1.
[0041] The avatar material providing system 110-2 generates a body material MT-2 as an avatar material, and provides the generated body material MT-2. The body material MT-2 here is the part of the human body except the head. In addition, the avatar material providing system 110-2 can generate the body material MT-2 in a state of wearing clothes.
[0042] The avatar material providing system 110-3 generates a voice material MT-3 as an avatar material, and provides the generated voice material MT-3. The voice material MT-3 is the material of the voice emitted by the avatar.
[0043] The head material providing system 110-4 generates emotional material MT-4 as head material and provides the generated emotional material MT-4. The emotional material MT-4 contains, for example, information that changes the expression of the face material and the actions of the body material MT-2 corresponding to each specified emotion. The emotional material MT-4 can be used to express the emotion of the avatar.
[0044] The head material providing system 110-5 generates movement material MT-5 as head material and provides the generated movement material MT-5. The movement material MT-5 contains information for applying actions to the avatar. For example, when the avatar is a weather forecaster appearing in the web content of a weather forecast, actions corresponding to the weather forecaster, such as indicating a weather map, can be applied according to the movement material MT-5 generated corresponding to the weather forecaster.
[0045] The head material providing system 110-6 generates spatial material MT-6 as head material and provides the generated spatial material MT-6. The spatial material MT-6 is the material of the space where the avatar exists.
[0046] In the avatar generation system 100 of this figure, the head material providing system 110-1 photographs the source person PS to generate the face material MT-1 of the person PS. In addition, the head material providing system 110-2 photographs the source person PS to generate the body material MT-2 of the person PS. In addition, the head material providing system 110-3 generates voice material MT-3 using the data obtained by recording the voice of the source person PS.
[0047] Furthermore, the integration system 120 acquires the head materials (face material MT-1, body material MT-2, voice material MT-3, emotional material MT-4, movement material MT-5, spatial material MT-6) respectively generated by the head material providing systems 110-1 to 110-6. The integration system 120 integrates the acquired head materials to generate an avatar AVT.
[0048] The avatar AVT may not use all the materials of the head materials (face material, body material, voice material, emotional material, movement material, spatial material) exemplified in this figure. That is, the avatar AVT can be generated using, for example, a part of the head materials exemplified in this figure. Which head materials to use in the generation of the avatar can be changed according to, for example, the web service using the generated avatar, the environment of the metaverse where the avatar exists, etc.
[0049] Return the explanation to Figure 1. The user interface environment 200 is an environment that provides a user interface for end-users who utilize the network service environment 500. Specifically, the user interface environment 200 has at least one end-user terminal 300 corresponding to each of at least one end-user.
[0050] The end-user terminal 300 is a terminal for an end-user to receive the provision of network services in the network service environment 500.
[0051] The end-user terminal 300 can be connected to the service provision system 510 according to the operation of the end-user, and can output applications and content corresponding to the network services provided by the connected service provision system 510 by means of display, voice, etc.
[0052] The end-user terminal 300 can be a personal computer, a smart phone, a tablet terminal, etc.
[0053] The identity management device 400 manages identities. In this embodiment, the identity includes an avatar existing in the metaverse. Such an avatar can act independently of the operations of the corresponding end-user, for example, by using AI (Artificial Intelligence) etc., or can be an independent existence not associated with the end-user and also include an avatar (AI avatar) that can act autonomously in addition to acting according to the operations and instructions of the end-user. The metaverse is a virtual space constructed in the network (an example of an activity space). Also, in this embodiment, the identity can be associated with the avatar and also include the end-user acting in the real space. The end-user as an identity is sometimes referred to as a "real user".
[0054] In addition, in this embodiment, the identity can also include organizations such as enterprises and groups. The identity of such an organization can also include a real organization existing in the real space and an organization existing in the metaverse associated with the real organization. Also, as the identity in this embodiment, it can include real users, real organizations, avatars, etc. that hold intellectual property rights (IP (Intellectual Property)) such as two-dimensional or three-dimensional images, texts, and music as IP holders.
[0055] The identity management device 400 stores the avatar generated by the avatar generation system 100 as the identity to be managed. The identity management device 400 uploads the avatar stored as the management object to the network service environment 500. The network service environment 500 provides network services using the avatar provided by the network service environment 500 to the end-user.
[0056] In addition, the identity management device 400 can confirm the authenticity of an avatar by assigning authenticity proof information to the avatar of the management target.
[0057] In addition, the identity management device 400 determines the authenticity of the avatar of the inquiry target based on an authenticity inquiry (authenticity confirmation request) regarding the avatar used in the network service provided to the end-user terminal 300, and sends the determination result to the end-user terminal 300.
[0058] In addition, the identity management device 400 causes the VC issuance system 600 to issue information (avatar identity proof information) of an identity card that serves as an identity proof for the avatar itself of the management target. The identity management device 400 can set the management target by storing the issued avatar identity proof information.
[0059] Specifically, the identity management device 400 sends the avatar identity proof information of the avatar of the identity proof target to the network service that is the source of the identity proof request according to an identity proof request for the avatar of a certain network service from the network service environment 500. At this time, the identity management device 400 can sign (electronic signature) (encrypt) the identity proof information for the transmission target using the key associated with the avatar of the target.
[0060] The network service environment 500 is an environment that provides one or more network services. Specifically, the network service environment 500 has one or more service providing systems 510 that provide a specified network service. The service providing system 510 can be configured as, for example, a network server or an application server constructed according to the content of the network service to be provided.
[0061] The network service provided by the service providing system 510 can be a website that uses an avatar, an online game, a web conferencing system, etc. In addition, in such a network service that uses an avatar, it can include a service that makes the avatar exist in the metaverse as a three-dimensional virtual space and makes it act in the metaverse. Specifically, as network services, in addition to services such as a market where an avatar can purchase goods, etc. in a store, etc. in the metaverse, a service where avatars can directly conduct transactions with each other in the metaverse, and a service where an artist or a specific character exists in the metaverse, for example, it can implement the provision of a weather forecast with the avatar as a weather forecaster, medical consultations with the avatar regarded as a doctor, prediction services with the avatar as a predictor, etc.
[0062] In addition, the service providing system 510 can be configured to be able to provide multiple network services. Regarding the service providing system 510 that provides the metaverse as a network service, multiple metaverses can be provided.
[0063] The service providing system 510 that provides network services that can be traded in the metaverse, such as a market or buying and selling between avatars, has a transaction control unit 511 that performs control related to transactions.
[0064] The VC issuance system 600 is a system for issuing identity certification information in response to an issuance request. The VC issuance system 600 may be composed of, for example, one or more devices connected to a network.
[0065] The VC issuing system 600 of the present embodiment can issue identity certification information that certifies the identity of a terminal user, and can also issue identity certification information that certifies the identity of the avatar itself that is a management target of the identity management device 400 .
[0066] The VC issuing system 600 may be configured to be capable of issuing a plurality of pieces of identity certification information corresponding to a plurality of different issuers (issuing sources).
[0067] On this basis, the VC issuing system 600 of this embodiment includes a public VC issuing system 610 and a private VC issuing system 620 .
[0068] The public VC issuance system 610 issues the public issuer's identity information (public identity information). The public issuer refers to, for example, an issuer that is an administratively operated institution, an administratively recognized institution, or an institution with a certain degree of social credibility. Specifically, for the public issuer, for example, there can be cited institutions that issue licenses corresponding to the prescribed qualifications, recognized enterprises, educational institutions, municipalities, financial institutions, etc. For example, with respect to public identity information used for settlement in the metaverse, a financial institution can become an issuing institution and issue it. In addition, for example, with respect to public identity information for entering a specific facility in the metaverse, the enterprise, educational institution, municipality, etc. that operates the facility can become an issuing institution and issue it.
[0069] The private VC issuance system 620 issues the identity information of the private issuer (private identity information). The private issuer may be, for example, a non-governmental organization such as a volunteer group, a citizen sports group, or a school department activity. The private identity information issued by the private issuer may, for example, prove that the avatar belongs to the corresponding non-governmental organization, that the corresponding non-governmental organization has issued a certificate or license and granted it to the avatar.
[0070] In addition, the private issuers may include, for example, fans (supporters) of the artist. The private identification information issued by the fans of the artist is, for example, given to the artist's avatar to prove that the artist's avatar exists with the support of the fans.
[0071] In addition, end users can be included among the private issuers. As an example, an end user as a private issuer can issue private identification information with a friend certificate. The avatar of the private identification information with the friend certificate, for example, can prove the existence of a friend relationship with the avatar of the end user as the private issuer.
[0072] In addition, an end user as a private issuer can issue private identification information with an organization membership certificate that proves belonging to an organization such as a company. In this case, the issued private identification information with the organization membership certificate can be managed as information always carried by the corresponding avatar.
[0073] The avatar that holds the private identification information with the organization membership certificate can prove that it is a member of the same organization as other avatars of the private identification information with the organization membership certificate that belong to the same organization.
[0074] In addition, the private issuer can be, for example, an operator of the service providing system 510. As an example, the service providing system 510 as a private issuer can issue private identification information with an excellence certificate. The avatar of the end user with the excellence certificate can prove, for example, that no improper behavior has occurred in the metaverse provided by the service providing system 510 and is excellent.
[0075] In addition, event organizers, etc. can be included among the private issuers. As an example, a private issuer can issue private identification information that serves as an admission ticket for an event held in the metaverse of a specified service providing system 510. The avatar with the private identification information as the admission ticket can prove the qualification to participate in the event held in the metaverse of the specified service providing system 510.
[0076] From the above examples of private issuers, it can be seen that private identification information can function as information for the private issuer to prove the identity of the avatar or the user corresponding to the avatar based on personal relationships and personal evaluations.
[0077] As an example of the issuance of identification information based on personal relationships, in addition, for example, it can be configured to be able to issue private identification information based on the relevant relationships of SNS (Social Network System). The private identification information in this case can prove, for example, that a certain user or avatar is a friend of a friend of the private issuer in the SNS.
[0078] In addition, as an example of private identification information based on personal evaluations, for example, it can be configured to be able to issue private identification information that is an evaluation of users (sellers, buyers) who are users of a network service for personal transactions.
[0079] In addition, as an example of personal identification information based on the evaluation of other individuals, personal identification information can be issued based on information (credit information) indicating the creditworthiness of a user provided by a service that evaluates the high or low creditworthiness of an individual by inputting information such as the user's age, gender, occupation, purchase history, etc.
[0080] It can be said that the degree of reliability of the identity proofed by identification information varies depending on the issuer of the identification information and the identity being proved.
[0081] Therefore, the VC issuance system 600 can have a proof credit setting unit (not shown) that can set a proof credit indicating the degree of reliability of the identification function for the identification information to be issued. The proof credit can be represented by a numerical value, for example. By setting the proof credit for the identification information in this way, it is possible to clearly indicate the degree of credit of the identification information.
[0082] In addition, as an example of the setting of the proof credit, the VC issuance system 600 can, for example, set the proof credit of the identification information issued by a public issuer to a relatively high level greater than or equal to a certain degree. It can be said that the proof degree of the identification information issued by a public issuer with a relatively high social credit is higher than that of the identification information issued by a private issuer.
[0083] In addition, on the basis that information indicating the creditworthiness of the issuer (issuer creditworthiness) is stored in the issuer information ( Figure 12 ), a proof credit corresponding to the issuer creditworthiness can be set for the identification information issued by the corresponding issuer.
[0084] The proof credit of the identification information can be stored in a field of the identification information (avatar identification information) based on the structure of Figure 9 described later.
[0085] In addition, institutions other than the VC issuance system 600, etc., can set the proof credit of the identification information. For example, a proof credit setting unit (not shown) provided in the identity management device 400 can set the proof credit of the identification information, and a proof credit setting unit (not shown) provided in the service provision system 510 can also be set separately according to the service to be provided.
[0086] In addition, for example, the service provision system 510 can stipulate the type of identification information and the threshold of the proof credit as a condition for accepting the service to be provided. In this case, the service provision system 510 can provide the service by restricting the identity of the avatar, end user, etc. of the identification information that meets the specified conditions.
[0087] In addition, when providing services, the service providing system 510 can vary the level and content of the services according to the proof credibility of the identification information possessed by the identity.
[0088] Thus, when the service providing system 510 requests the identification information of the identity, for example, it can request the identification information issued by issuers with a relatively high credibility such as publicly-issued ones. In addition, the service providing system 510 can request multiple pieces of identification information issued by multiple different issuers. In this case, the service providing system 510 can request in a manner that mixes public identification information and private identification information, or can request either public identification information or private identification information.
[0089] In addition, the service providing system 510 can commission the issuance of the required identification information corresponding to the services provided in the service providing system 510 for a specified issuer. At this time, the service providing system 510 can also specify the definition of the proof credibility of the identification information to be commissioned for issuance.
[0090] The identification information issued by the VC issuance system 600 of the present embodiment can correspond to, for example, VC (Verifiable Credential). In the following description, the case where the identification information of the present embodiment corresponds to VC is taken as an example. Therefore, in the subsequent description, the identification information issued by the VC issuance system 600 is sometimes denoted as VC.
[0091] In addition, in the present embodiment, the identification information for proving the identity of the avatar itself is denoted as avatar identification information (avatar VC), which is distinguished from the identification information for proving the identity of the end user (end user identification information (end user VC)). In addition, when the avatar identification information and the end user identification information are not particularly distinguished, it is denoted as identification information or VC.
[0092] The DPKI system 700 manages public keys corresponding to DPKI (Decentralized Public Key Infrastructure).
[0093] The VC issuance system 600 of the present embodiment generates a pair of public key and private key corresponding to the issuer DID, which is a DID (Decentralized Identifier) uniquely representing the issuing institution, when issuing the identification information as VC. In addition, it generates a pair of public key and private key corresponding to the holder DID (end user DID or avatar DID), which is a DID uniquely representing the holder (end user or avatar) of the identification information.
[0094] The VC issuance system 600 registers the generated public keys (the public key corresponding to the issuer DID and the public key corresponding to the holder DID) in the DPKI system 700. The DPKI system 700 stores the registered public keys in association with each issuer DID and holder DID.
[0095] The DPKI system 700 can register the public key by storing the public key in the blockchain. In addition, the DPKI system 700 can be composed of a device that is a node corresponding to the blockchain storing the public key.
[0096] When there is a need to generate the identification of the holder, the service providing system 510 obtains the public key associated with the holder DID of the target holder from the DPKI system 700. The service providing system 510 can execute the determination (authentication) of whether the identification information is legitimate by decrypting the identification information using the obtained public key.
[0097] The wallet management system 800 manages wallets. The wallet stores information corresponding to the end user, such as assets, based on the usage environment of the cryptocurrency.
[0098] The wallet management system 800 can manage the wallets registered (opened) as the information held by the end user.
[0099] In addition, the wallet management system 800 can manage the wallets assigned to the avatars. When assigning a wallet to an avatar, it can be achieved in the following way. For example, the corresponding end user operates the end user terminal 300 to open a wallet in the wallet management system 800 and register the opened wallet in association with the avatar.
[0100] The wallet management system 800 can manage the wallet data in the blockchain.
[0101] Figure 4 Shows the hardware structure of the identity management device 400. The identity management device 400 in this figure has a communication device 4001, a ROM (Read Only Memory) 4002, a RAM (Random Access Memory) 4003, a storage device 4004, and a CPU (Central Processing Unit) 4005. The communication device 4001, ROM 4002, RAM 4003, storage device 4004, and CPU 4005 are connected by a bus 4006.
[0102] The communication device 4001 is a device corresponding to communication via the network.
[0103] The ROM 4002 stores data that cannot be rewritten.
[0104] The RAM 4003 temporarily stores the data for the operations executed by the CPU 4005.
[0105] The storage 4004 is, for example, an HDD (Hard Disc Drive) or an SSD (Solid State Drive), and stores various data represented by, for example, program data and the like.
[0106] The CPU 4005 executes operations corresponding to various controls, processes, etc. by executing the programs stored in the storage 4004.
[0107] In addition, although not shown in this figure, the identity management device 400 may also have a GPU (Graphics Processing Unit).
[0108] In addition, it is possible to obtain functions equivalent to those of the identity management device 400 by using a plurality of network terminals distributed in a manner capable of executing transactions corresponding to the blockchain.
[0109] Figure 5 This shows an example of the functional structure of the identity management device 400. As the functions of the identity management device 400 in this figure, they are realized by the CPU (Central Processing Unit) of the identity management device 400 executing programs.
[0110] The identity management device 400 in this figure has a communication unit 401, a control unit 402, and a storage unit 403.
[0111] The communication unit 401 communicates via the network.
[0112] The control unit 402 executes various controls of the identity management device 400. The control unit 402 in this figure has an avatar registration unit 421, an authenticity proof information management unit 422, an avatar provision control unit 423, a VC management unit 424, and a credit management unit 425.
[0113] The avatar registration unit 421 registers the avatar generated in the avatar generation system 100 as a management object. The registration of the avatar here is performed by causing the avatar information storage unit 432 to store the avatar information of the management object (described later).
[0114] The avatar registered by the avatar registration unit 421 can be used by the service provision system 510 in the network service environment 500 in the network services it provides.
[0115] The authenticity proof information management unit 422 (an example of the authenticity proof information assignment unit and the authenticity confirmation unit) manages the authenticity proof information of the profile picture. Specifically, the authenticity proof information management unit 422 assigns authenticity proof information to the registered profile picture. The authenticity proof information will be described later.
[0116] In addition, in response to an authenticity confirmation request from the end-user terminal 300, the authenticity proof information management unit 422 uses the authenticity proof information assigned to the registered profile picture to perform an authenticity determination on the profile picture to be confirmed for authenticity. The authenticity proof information management unit 422 sends the determination result regarding authenticity to the end-user terminal 300, which is the source of the authenticity confirmation request.
[0117] The profile picture provision control unit 423 executes control related to the provision (transmission of profile picture information) of the registered profile picture to the service provision system 510. The identity management device 400 and each service provision system 510 are connected by an API, and the profile picture provision control unit 423 can transmit the data of the profile picture to the service provision system 510 based on the online connection status.
[0118] The VC management unit 424 manages the VC (identity proof information) of the user existing in the real space or the profile picture existing in the metaverse. The VC management unit 424 manages the user identity proof information (user VC) corresponding to the real user and the profile picture identity proof information (profile picture VC) corresponding to the profile picture for the VC set as the management object.
[0119] The VC management unit 424 entrusts the identity proof information issuance of the identity (real user or profile picture) to the VC issuance system 600 via the network. The VC issuance system 600 issues the identity proof information of the target identity according to the entrustment. The VC issuance system 600 sends the issued identity proof information and the corresponding keys (the key corresponding to the issuer DID, the key corresponding to the holder DID) to the identity management device 400. The VC management unit 424 stores the sent identity proof information (profile picture identity proof information or user identity proof information) and the keys in association with each other in the profile picture VC storage unit 433 or the user VC storage unit 434.
[0120] The credit management unit 425 evaluates the creditworthiness of the issuer (issuing source) of the profile picture identity proof information assigned to the profile picture based on the credit information stored in the credit information storage unit 435.
[0121] The storage unit 403 stores various information corresponding to the identity management device 400. The storage unit 403 includes an end-user information storage unit 431, a profile picture information storage unit 432, a profile picture VC storage unit 433, a user VC storage unit 434, and a credit information storage unit 435.
[0122] The end-user information storage unit 431 stores end-user information. The end-user information is information associated with an end user who registers one or more avatars corresponding to himself / herself to the identity management device 400.
[0123] Figure 6 An example of end-user information corresponding to one end user is shown. The end-user information in this figure includes areas for the end-user ID and user basic information.
[0124] The area for the end-user ID stores the end-user ID that uniquely represents the corresponding end user.
[0125] The area for user basic information stores the user basic information of the corresponding end user. The user basic information may include, for example, the name, gender, address, etc. of the end user.
[0126] The avatar information storage unit 432 stores avatar information.
[0127] Figure 7 An example of the avatar information stored in the avatar information storage unit 432 is shown. The avatar information storage unit 432 in this figure has an object data storage unit 4321, a material group data storage unit 4322, and a meta-file storage unit 4323.
[0128] The avatar information corresponding to one avatar includes, for example, object data, material group data, and a meta-file.
[0129] The object data storage unit 4321 stores the object data of each registered avatar.
[0130] The material group data storage unit 4322 stores the material group data of each registered avatar.
[0131] The meta-file storage unit 4323 stores the meta-file of each registered avatar.
[0132] Among the object data storage unit 4321, the material group data storage unit 4322, and the meta-file storage unit 4323, the same avatar ID is used to associate the object data, material group data, and meta-file corresponding to the same avatar.
[0133] Specifically, the avatar ID [00000A] that uniquely represents avatar A is used to associate the object data A, material group data A, and meta-file A stored in the object data storage unit 4321, the material group data storage unit 4322, and the meta-file storage unit 4323, respectively, corresponding to avatar A.
[0134] The object data is the entity data of the object that is the corresponding avatar. The object data is formed, for example, by combining components such as a head and a body generated using a specified avatar material.
[0135] The material group data is data that includes at least one avatar material for the avatar of the object data in a specified manner. The material group data can include, for example, voice materials, emotion materials, movement materials, space materials, etc. Based on the material group data, it is possible to make the avatar object emit sounds, change facial expressions, perform actions, or exist in a virtual space based on a specified design.
[0136] The meta file contains at least one metadata assigned to the corresponding avatar.
[0137] Figure 8 Shows an example of a meta file corresponding to one avatar. In the meta file of this figure, metadata such as avatar ID, generation source information, creator information, authentication code, authorized user information, avatar form, avatar sharing information, action history information, wallet holding information, etc. are included.
[0138] The avatar ID is an identifier that uniquely represents the avatar with respect to the avatar information stored in the avatar information storage unit 432. The avatar ID can be issued by the avatar registration unit 421 at the time of registration of the corresponding avatar. As described above, the avatar ID is used to associate the object data, material group data, and meta file corresponding to the same avatar.
[0139] The generation source information is information related to the original person (generation source) of the corresponding avatar. The generation source information can include, as information items, a generation source ID, basic information of the person of the generation source, etc. The generation source information can be provided from the avatar generation system 100. In the case where the person as the generation source is the end user, the terminal user ID of the corresponding end user can be used for the generation source ID.
[0140] The creator information is information related to the creator of the corresponding avatar. The creator can be, for example, an organization or individual such as an enterprise corresponding to the integration system 120 that generated the corresponding avatar in the avatar generation system 100.
[0141] The authentication code is a code issued to associate the identity management device 400 with the provided avatar when the service providing system 510 receives the provision of the avatar (transmission of avatar information) from the identity management device 400.
[0142] The information of the user with usage permission is information related to the user with usage permission. The user with usage permission is a person who has the usage permission corresponding to an avatar. The user with usage permission can be an end user who is the source of the generation of the avatar. In this case, the user with usage permission can make the avatar generated from themselves exist in the metaverse provided by the service providing system 510, for example, can act in the metaverse according to the operations of the end user terminal 300. In addition, the user with usage permission can be an operator of a specific service providing system 510, etc. The information of the user with usage permission is information representing such a user with usage permission. Specifically, the information of the user with usage permission can be user accounts such as the usage permission ID, user name, password, etc. registered by the user with usage permission. When the user with usage permission is an end user, the usage permission ID can use the end user ID.
[0143] In addition, the information of the user with usage permission can include, for example, the user with usage permission (secondary user with usage permission) representing other end users who have been granted usage permission, in addition to the original user with usage permission (primary user with usage permission) such as an end user who is the source of the generation of the avatar.
[0144] The avatar form represents the file form, format, etc. of the avatar as the form corresponding to the avatar.
[0145] In the present embodiment, for example, one avatar can be shared with a third party according to the consent of the user with usage permission. The avatar sharing information is information related to the sharing of the corresponding avatar.
[0146] The avatar sharing information in this figure includes sharer information and sharing conditions. The sharer information is information of the sharer who consents to share the corresponding avatar with the user with usage permission. The sharer information can be, for example, the user account of the sharer. The sharing conditions are the conditions under which the sharer can share the corresponding avatar. The sharing conditions can include, for example, the expiration date, information indicating the service providing system 510, etc. that the sharer can use the avatar to specify.
[0147] The action history information is information in the metaverse provided by each service providing system 510 that represents the history related to the actions of the corresponding avatar. The action history information of each avatar can be obtained by the avatar providing control unit 423 from each service providing system 510, for example.
[0148] The wallet holding information is information related to the holding status of the wallet of the corresponding avatar.
[0149] Return the explanation to Figure 5 The avatar VC storage unit 433 stores the avatar identification information (avatar VC) for each registered avatar. In addition, the avatar VC storage unit 433 stores the keys associated with the avatar identification information (the key corresponding to the issuer DID, the key corresponding to the avatar DID).
[0150] Figure 9 An example of information (avatar identification information and key) stored in the avatar VC storage unit 433 corresponding to one avatar.
[0151] As shown in this figure, in the avatar VC storage unit 433, for the avatar VC_ID and the avatar ID, the avatar identification information and the key corresponding to the avatar DID are stored in association with each other. The avatar VC_ID is an identifier that uniquely identifies the corresponding avatar identification information.
[0152] In this way, by associating the avatar identification information and the key with respect to the avatar ID, it is possible to manage the avatar identification information and the key in association with the avatar information of the corresponding avatar.
[0153] The avatar identification information includes fields for the VC type, the issuer DID, the avatar DID, and the identity association information.
[0154] The field of the VC type stores information indicating the type (form) of the identification information.
[0155] The field of the issuer DID stores the issuer DID indicating the issuer of the avatar identification information.
[0156] The field of the avatar DID stores the avatar DID of the corresponding avatar.
[0157] The field of the identity association information stores the identity association information of the corresponding avatar. The content of the information included in the identity association information is not particularly limited, but for example, it may include information such as rights and qualifications obtained by the avatar's actions in the metaverse. In addition, the identity association information may also include the same action history information as the information stored in the avatar information.
[0158] In addition, at least one of the avatar identification information and the key may be stored in the blockchain under the control of the VC management unit 424 of the identity management device 400. In the case where both the avatar identification information and the key are stored in the blockchain, the avatar VC storage unit 433 may be omitted.
[0159] Return the explanation to Figure 5 The user VC storage unit 434 stores the user identification information (user VC) of each end user (real user) registered (stored) in the end user information storage unit 431. In addition, the user VC storage unit 434 stores keys associated with the user identification information (keys corresponding to the issuer DID, keys corresponding to the user DID).
[0160] Figure 10An example of information (user identification information and key) stored in the user VC storage unit 434 corresponding to one user (end user).
[0161] As shown in this figure, in the user VC storage unit 434, for the user VC_ID and the user ID, the user identification information and the key corresponding to the user DID are stored in association with each other. The user VC_ID is an identifier that uniquely identifies the corresponding user identification information.
[0162] In this way, the user identification information and the key are associated with each other for the user ID, so that the user identification information and the key can be managed in association with each other for the user information of the corresponding user.
[0163] The user identification information includes fields of VC type, issuer DID, user DID, and user association information.
[0164] The field of identity association information stores information (identity association information) associated with the corresponding user. The content of the information included in the identity association information is not particularly limited. For example, it may include information such as rights and qualifications obtained by the user corresponding to the results of actions (shopping, moving to a specified location, etc.) of the corresponding user in the real space. In addition, the identity association information may include action history information about the actions of the corresponding real user in the real space.
[0165] In addition, at least one of the user identification information and the key may be stored in the blockchain under the control of the VC management unit 424 of the identity management device 400. When both the user identification information and the key are stored in the blockchain, the user VC storage unit 434 may be omitted.
[0166] In addition, the identity management device 400 may be composed of one device, or may be realized by multiple devices cooperating to execute processing on the basis of respectively assigning specified functions to multiple devices that are communicably connected on the network.
[0167] Return the description to Figure 5 The credit information storage unit 435 stores information (credit information) related to the credit associated with the issuer who issued the avatar identification information.
[0168] Figure 11 A structural example of credit information corresponding to the issuer who issued one avatar identification information is shown. The credit information in this figure includes areas of issuer ID, target VC, credit certification information, and guarantee level.
[0169] The area of the issuer ID stores the issuer ID that uniquely represents the issuer of the credit object.
[0170] The area of the object VC represents the identification information issued by the issuer of the credit object. The credit information represents the creditworthiness of the issuer ID, and because it has the issuer ID and the object VC, credit can be assigned to the issuer corresponding to each piece of identification information. That is, in the case where one issuer issues multiple pieces of identification information, for that one issuer, credit can be set for each piece of identification information.
[0171] The area of the credit certification information stores information (credit certification information) representing the creditworthiness of the corresponding issuer. The credit certification information can, for example, include information indicating the basis for the corresponding issuer having the credit of the person issuing the identification information.
[0172] In the case where the corresponding issuer is a public issuer that issues public identification information, the credit certification information can, for example, have content proving the public status of the issuer, such as the registration content of an institution / enterprise, etc. as the issuer. Additionally, in the case where the corresponding issuer is a private issuer that issues private identification information, the credit certification information can have content indicating the basis for the issuer to issue the private identification information. For example, in the case where a private identification information indicating the support of fans exists is assigned to the avatar corresponding to an artist, it can have content proving that the issuer of the private identification information is a fan of the corresponding artist.
[0173] The area of the guarantee level stores the guarantee level. The guarantee level represents the level of creditworthiness (guarantee level) guaranteed for the combination of the corresponding issuer and the object VC. The guarantee level can be set, for example, by the identity management device 400 or the VC issuance system 600.
[0174] In addition, the VC issuance system 600 can store a database related to the issuer (issuer database).
[0175] Figure 12 An example of the structure of a record (issuer information) stored corresponding to one issuer in the issuer database is shown. The issuer information in this figure includes the issuer ID, the issuer basic information, and the area for issuing VCs.
[0176] The area of the issuer ID stores the issuer ID of the corresponding issuer.
[0177] The area for issuer basic information stores the issuer basic information. The issuer basic information is information representing the basic information of the issuer. As shown in this figure, the issuer basic information may include areas such as issuer type and issuer name, for example. The area for issuer type stores information indicating which of a public issuer and a private issuer, for example, corresponding to the type of the issuer. The area for issuer name stores the name (issuer name) of the corresponding issuer.
[0178] The area for issuing VC stores information related to the identity verification information issued by the corresponding issuer as the issuer.
[0179] Refer to Figure 13 the sequence diagram to illustrate an example of the processing flow executed in association with the generation, registration, and registration of avatar authentication information of the identity management system of this embodiment.
[0180] Step S100: The end user operates the end user terminal 300 held by himself / herself and accesses the avatar generation system 100 to perform an avatar generation operation. The end user terminal 300 sends an avatar generation instruction corresponding to the avatar generation operation to the avatar generation system 100.
[0181] Step S102: The avatar generation system executes the process of generating an avatar according to the avatar generation instruction.
[0182] Step S104: The end user operates the end user terminal 300 to perform avatar registration procedures in such a way that the generated avatar is registered using the identity management device 400. In the avatar registration procedures, the avatar to be registered is specified and the identity management device 400 as the registration target of the specified avatar is specified.
[0183] Step S106: The avatar generation system 100 and the identity management device 400 execute the process corresponding to the avatar registration according to the avatar registration procedures in Step S104.
[0184] First, the avatar generation system 100 uploads the avatar information of the avatar specified as the registration target through the avatar registration procedures to the identity management device 400.
[0185] The avatar registration unit 421 of the identity management device 400 causes the avatar information storage unit 432 to store the uploaded avatar information.
[0186] In addition, in this step S106, the authenticity proof information management unit 422 of the identity management device 400 assigns authenticity proof information to the avatar that is the registration target this time.
[0187] The authenticity proof information is information for proving the authenticity of the avatar itself existing in the metaverse or the like of the service providing system 510. Here, for the avatar to have authenticity means that the avatar is not faked or tampered with and is legitimate. As examples of improper avatars, there can be cited avatars that are tampered with by replacing the avatar material such as face material with a different fake material, avatars that are copied without the promise of a person with certain rights regarding the creator of the avatar, etc.
[0188] Specifically, for the assignment of the authenticity proof information for the target avatar, the authenticity proof information management unit 422 can perform the assignment of digital watermark (an example of authenticity proof information) and the assignment of electronic certificate (an example of authenticity proof information) in the following manner.
[0189] The authenticity proof information management unit 422 assigns information inherent to the target avatar as a digital watermark, such as the avatar ID, to the target data of the target avatar. The digital watermark assigned to the target data of the avatar in this way is preferably of a structure that is difficult to perceive, but can also be of a perceivable structure.
[0190] In addition, the authenticity proof information management unit 422 assigns an electronic certificate to the target avatar.
[0191] At this time, the authenticity proof information management unit 422 can assign a real certificate that proves the creator of the target avatar, the storage location (URL) of the target avatar, the service providing system 510 that uses the target avatar, etc. to the target avatar.
[0192] Regarding the real certificate, for example, the authenticity proof information management unit 422 and the issuing unit of the real certificate on the network can perform prescribed transactions, and thus the issuing unit issues a real certificate regarding the target avatar. Such a real certificate can be managed on the network in association with the avatar ID (an example of information inherent to the registered target avatar) of the target avatar.
[0193] As an example, the real certificate assigned by the authenticity proof information management unit 422 to the avatar can be an NFT (Non-Fungible Token) managed in a blockchain. In this case, the authenticity proof information management unit 422 can, for example, use an external NFT platform to assign a real certificate to the avatar. In addition, the authenticity proof information management unit 422 can assign a real certificate generated using quantum-resistant cryptography and quantum-resistant blockchain to the avatar.
[0194] In addition, the authenticity proof information management department 422 can assign a real certificate to the avatar, which can be an SBT (Soulbound Token) that is an NFT that cannot be transferred. In this case, the authenticity proof information management department 422 can assign the SBT as authenticity proof information to the avatar instead of the NFT, or can assign both the NFT and the SBT to the avatar. When both the NFT and the SBT are assigned as authenticity proof information to the avatar, when proving the authenticity of the avatar, the authenticity proof information management department 422 can choose to use either the NFT or the SBT, or can use both the NFT and the SBT at the same time.
[0195] In addition, in this step S106, the authenticity proof information management department 422 issues a unique authentication code for the avatar that is the object of this registration. The authentication code is a code provided to the service providing system 510 that uses the avatar of the user for providing network services together with the avatar data of the target avatar. As will be described later, the authentication code is used for determining the authenticity of the avatar corresponding to the request from the end user.
[0196] Since the authentication code is uniquely associated with the target avatar, for example, the avatar ID can be used.
[0197] However, for example, when strengthening the security for the determined avatar or the registration information that may contain the user's personal information, etc., it is preferable to use a code generated independently of the avatar ID as the authentication code.
[0198] The authenticity proof information management department 422 appends the issued authentication code as one of the metadata of the metafile stored in the metafile storage department 4323 in association with the target avatar ( Figure 7 ).
[0199] Step S108: The end user who is the creator of the avatar registered in step S106 makes the end user terminal 300 access the VC issuance system 600 and performs an operation for the issuance procedure of the avatar identity proof information. The end user terminal 300 executes the processing of the issuance procedure according to the operation.
[0200] As the processing of the issuance procedure, the end user terminal 300 can send an issuance request to the VC issuance system 600 together with the avatar information that is the object of the avatar identity proof information. In addition, the issuance request can include information (issuance certificate specification information) specifying the avatar identity proof information that should be issued.
[0201] In addition, the VC issuance system 600 can determine the avatar identity proof information issued to the target avatar in response to the issuance request.
[0202] In addition, when sending a distribution request, the end-user terminal 300 can temporarily obtain avatar information from the identity management device 400 and send the obtained avatar information to the VC distribution system 600, or can specify the avatar of the recipient to the identity management device 400, and send the avatar information from the identity management device 400 to the VC distribution system 600.
[0203] Step S110: According to the distribution request from the end-user terminal 300 in step S108, the VC distribution system 600 makes a credit inquiry to the identity management device 400. The credit inquiry is to inquire whether the issuer of the avatar identity certification information to be distributed this time has credit. That is, regarding the credit inquiry, it is inquired whether the issuer is a person with a certain degree of reliability. The credit inquiry includes the issuer ID of the issuer of the avatar identity certification information to be issued for the avatar this time.
[0204] Step S112: The credit management department 425 retrieves the credit information stored for the same issuer ID included in the received credit inquiry from the credit information storage department 435. The credit management department 425 refers to the credit certification information and guarantee level stored in the retrieved credit information, and conducts an evaluation related to the creditworthiness of the issuer of the avatar identity certification information to be issued for the avatar this time.
[0205] Specifically, the credit management department 425 can determine whether there is creditworthiness as an evaluation regarding creditworthiness. For example, regarding an issuer without credit, no credit information is stored in the credit information storage department 435. In this case, the credit management department 425 can determine whether there is creditworthiness based on whether credit information is stored in the credit information storage department 435. In addition, when it is determined that there is creditworthiness, the credit management department 425 can set the level of creditworthiness based on the content of the credit certification information and the information indicated by the guarantee level of the credit information.
[0206] The credit management department 425 sends the result of the evaluation regarding the credit of the issuer (credit evaluation result) as described above to the VC distribution system.
[0207] Step S114: When the credit evaluation result sent from the identity management device 400 through step S112 has a creditworthiness level greater than or equal to a certain degree, the VC distribution system 600 generates avatar identity certification information that proves the identity of the avatar of the avatar information received together with the distribution request in step S108. At this time, the VC distribution system 600 generates (issues) an avatar DID representing the corresponding avatar, and generates a pair of public key and private key corresponding to the avatar DID. On this basis, the VC distribution system 600 signs (encrypts) the avatar identity certification information generated by using the key pair corresponding to the issuer DID representing itself.
[0208] The VC issuance system 600 can include at least a part of the content of the received avatar information in the identity - related information.
[0209] Step S116: The VC issuance system 600 registers the avatar identity certification information to the identity management device 400. Specifically, the avatar identity certification information (an example of the signed certification information) signed with the key corresponding to the issuer DID assigned by the corresponding issuing agency and the key corresponding to the avatar DID of the corresponding avatar are sent to the identity management device 400. The VC management unit 424 of the identity management device 400 stores the avatar identity certification information received from the VC issuance system 600 and the key corresponding to the avatar DID in the avatar VC storage unit 433 in a manner associated with the avatar ID of the corresponding avatar.
[0210] Step S118: In addition, the VC issuance system 600 registers the public keys (the public key corresponding to the issuer DID, the public key corresponding to the avatar DID) generated together with the avatar identity certification information in step S114 to the DPKI system 700.
[0211] As described above, after registering the avatar identity certification information corresponding to the avatar, the registered avatar identity certification information can be prompted by display on the end - user terminal 300. By prompting the avatar identity certification information in this way, the end - user can confirm whether the avatar identity certification information is appropriately registered corresponding to the target avatar.
[0212] Refer to the same Figure 13 , a processing flow example for prompting the avatar identity certification information on the end - user terminal 300 will be described.
[0213] Step S120: The end - user performs an operation on the end - user terminal 300 to specify an avatar and instruct the prompt of the avatar identity certification information. The end - user terminal 300 sends a prompt request for the avatar identity certification information for prompting the avatar identity certification information of the specified avatar to the identity management device 400 according to the operation.
[0214] Step S122: In the identity management device 400, when the VC management unit 424 receives the prompt request for the avatar identity certification information, it obtains the avatar identity certification information of the specified avatar from the avatar VC storage unit 433 and generates a screen (avatar identity certification information screen) for prompting the obtained avatar identity certification information.
[0215] Step S124: The VC management unit 424 sends the avatar identity certification information screen generated in step S122 to the end - user terminal 300.
[0216] Step S126: The end-user terminal 300 causes the display unit to display the avatar identity verification information screen sent through Step S124.
[0217] In the identity management system of the present embodiment, the end user can confirm the authenticity of the avatar by using the authenticity verification information given to the avatar.
[0218] Figure 14 The sequence diagram represents an example of the processing flow executed by the identity management system of the present embodiment corresponding to the authenticity confirmation.
[0219] Step S200: The end user who has received the provision of a certain network service by the end-user terminal 300 has doubts about whether the avatar used in the network service is improper.
[0220] The end user conducts a confirmation of the authenticity of the avatar used in the above network service (authenticity confirmation). In this case, the user operates the end-user terminal 300 and sends an authentication code request from the end-user terminal 300 to the service providing system 510 of the network service that provides the avatar for which authenticity confirmation is to be performed.
[0221] The authentication code request includes information that can identify the avatar specified as the object of authenticity confirmation. The information that can identify the avatar can be, for example, information that specifies the content of the network service for which the avatar for which authenticity confirmation is to be performed is used, the name (avatar name) given to the avatar for which authenticity confirmation is to be performed, etc.
[0222] Step S202: The service providing system 510 receives the authentication code request sent through Step S200. The service providing system 510 obtains the authentication code associated with the avatar used in the content of the network service specified by the received authentication code request from the avatar storage unit 3131.
[0223] The service providing system 510 sends the obtained authentication code to the end-user terminal 300 that is the source of the authentication code request.
[0224] Step S204: The end-user terminal 300 receives the authentication code sent from the service providing system 510 through Step S202. Although omitted in this figure, the end-user terminal 300 can, for example, be notified of the received authentication code request through display corresponding to the sending of the authentication code request.
[0225] If the end-user terminal 300 receives the authentication code, it sends a authenticity confirmation request to the identity management device 400. The authenticity confirmation request may include information (network service determination information) that can identify the network service (content) for which the avatar for which authenticity confirmation is to be performed is used and the authentication code received in Step S202.
[0226] The authenticity proof information management unit 422 of the identity management device 400 receives the authenticity confirmation request sent through step S204. In response to the reception of the authenticity confirmation request, the authenticity proof information management unit 422 performs the process of authenticating the authenticity of the profile picture of the object to be authenticated through the following steps S206 to S210.
[0227] Step S206: The authenticity proof information management unit 422 retrieves, from the profile picture information stored in the profile picture information storage unit 432, the profile picture information of the profile picture (official profile picture) registered as the official profile picture of the object to be authenticated. Therefore, the authenticity proof information management unit 422 retrieves, from the profile picture information stored in the profile picture information storage unit 432, the profile picture information that contains the authentication code included in the received authenticity confirmation request in the meta file.
[0228] In the case where the profile picture information of the object to be authenticated is not retrieved through this step S206, the profile picture itself associated with the authentication code included in the received authenticity confirmation request is not registered in the identity management device 400. That is, in this case, the authentication code itself included in the received authenticity confirmation request is improper. In this case, the authenticity proof information management unit 422 can determine that the profile picture of the object to be authenticated is improper on the basis of the improper authentication code. In this case, since the authenticity proof information management unit 422 cannot obtain the profile picture information of the object to be authenticated, the processes of the following steps S208 and S210 can be skipped.
[0229] Step S208: In the case where the profile picture information of the object to be authenticated is retrieved through step S206, the authenticity proof information management unit 422 performs the process of authenticating the authenticity based on digital watermarking.
[0230] In this case, the authenticity proof information management unit 422 accesses the network service determined by the network service determination information included in the received authenticity confirmation request, and obtains the image of the object of the profile picture (i.e., the profile picture of the object to be authenticated) used in the accessed network service.
[0231] The authenticity proof information management unit 422 extracts the digital watermark from the obtained image of the object of the profile picture of the object to be authenticated. The authenticity proof information management unit 422 also extracts the digital watermark from the object data of the official profile picture. The authenticity proof information management unit 422 compares the digital watermark extracted from the profile picture of the object to be authenticated with the digital watermark extracted from the official profile picture, and determines whether the two are consistent.
[0232] Step S210: In addition, the authenticity proof information management unit 422 authenticates the authenticity of the profile picture of the object to be authenticated based on the authenticity proof information in the following manner.
[0233] The authenticity proof information management department 422 obtains the authentic certificate associated with the avatar ID of the avatar information of the official avatar retrieved through step S206 from the issuing unit of the authentic certificate on the network, and refers to the content of the obtained authentic certificate.
[0234] For example, the authentic certificate can record information indicating the storage location of the official avatar and the network service using the official avatar. In this case, the authenticity proof information management department 422 compares whether the information such as the network service of the avatar to be used for confirmation and the storage location of the official avatar (comparison object information) is consistent with the description in the authentic certificate.
[0235] Through the processing of steps S206 to S210, the authenticity proof information management department 422 can obtain the result of the authenticity confirmation of the avatar to be confirmed in the following manner.
[0236] In the case where the avatar information corresponding to the official avatar cannot be retrieved through step S206, as described above, the authenticity proof information management department 422 can obtain an improper authenticity confirmation result for the avatar to be confirmed because the authentication code associated with the avatar to be confirmed itself is counterfeit.
[0237] As an improper method in the case where the authentication code is counterfeit, for example, the avatar to be confirmed is not generated by the official creator, so it is an example that cannot be associated with the official authentication code.
[0238] In addition, in the case where it is determined through step S208 that the digital watermark of the avatar to be confirmed is inconsistent with the digital watermark of the official avatar, the authenticity proof information management department 422 can obtain an improper authenticity confirmation result for the avatar to be confirmed because of the inconsistent digital watermark.
[0239] As an improper method in the case of such inconsistent digital watermarks, for example, it is an example where the official avatar is tampered with by replacing or partially rewriting the face material, body material, etc. to generate the avatar to be confirmed.
[0240] In addition, in the case where it is determined through step S210 that the content of the comparison object information is inconsistent with the authentic certificate, the authenticity proof information management department 422 can obtain an improper authenticity confirmation result for the avatar to be confirmed because the authentic certificate is not given.
[0241] As an improper method in this case, it is an example where the generator of the avatar to be confirmed is not an official person or the use of the corresponding official avatar is not promised in the network service using the avatar to be confirmed.
[0242] On the other hand, in the case where it is determined in step S208 that the digital watermark of the head portrait to be confirmed is the same as the digital watermark of the official head portrait, and it is determined in step S210 that the content of the information to be compared is consistent with the real certificate, the authenticity proof information management unit 422 can obtain the authenticity confirmation result that the head portrait to be confirmed is the real official head portrait.
[0243] Step S212: The authenticity proof information management unit 422 sends the information indicating the authenticity confirmation result obtained through the processing of steps S206 to S210 (authenticity confirmation result information) to the terminal user terminal 300, which is the source of the authenticity confirmation request.
[0244] The authenticity confirmation result information may include information such as the head portrait ID of the head portrait to be confirmed, the information of the creator, and the information of the person from the generation source. In addition, the authenticity confirmation result information may include information describing the reason for being determined as improper in the case of obtaining an improper authenticity confirmation result.
[0245] Step S214: The terminal user terminal 300 receives the authenticity confirmation result information sent from the identity management device 400 through step S312. The terminal user terminal 300 outputs the received authenticity confirmation result information in a specified manner.
[0246] The terminal user terminal 300 can display the authenticity confirmation result information through text, for example. In this case, as the confirmation result regarding authenticity, information indicating whether the head portrait to be confirmed is real, the reason in the case of impropriety, the head portrait ID of the head portrait to be confirmed, the information of the creator, etc. can be displayed through a string, etc.
[0247] As described above, the identity management system of the present embodiment can confirm the authenticity of the head portrait by attaching authenticity proof information to the head portrait.
[0248] On this basis, similar to the case where the terminal user using the network has identity proof information, the head portrait used in the network service environment 500 itself has head portrait identity proof information.
[0249] By having the head portrait identity proof information in this way, for example, when the head portrait acts in a settlement manner in the metaverse, the head portrait identity proof information of the head portrait can be used for settlement instead of the identity proof information of the terminal user with the usage right of the head portrait. That is, in the present embodiment, the head portrait acting in the metaverse can use its own head portrait identity proof information to prove that the head portrait itself is legitimate.
[0250] In addition, in the present embodiment, at the time of settlement in the metaverse, etc., the avatar itself can prove its identity by using the avatar identification information that the avatar itself has. Therefore, when the avatar performs actions required for identity verification in the metaverse, the degree of dependence on the identity verification information of the end user is reduced.
[0251] Therefore, it is also easy for multiple end users to use one avatar in a sharable manner. In order for multiple end users to share one avatar, for example, as long as the end user who is the main user of the avatar sets other end users who can use the avatar for the corresponding avatar information as secondary users of the usage right. Thereby, the usage right of the avatar is granted to the end users described in the usage right information.
[0252] Therefore, with reference to Figure 15 the sequence diagram, an example of the processing flow for granting the usage right from the end user who is the main user of the avatar to other end users and an example of the processing flow for accepting identity verification of the avatar operated by the end user to whom the usage right is granted will be described.
[0253] When explaining this figure, as the end user terminal 300 that is the execution subject of the processing, it includes the first end user terminal 300-1 that is the main user of the avatar and the second end user terminal 300-2 that is other end users who are not the main user of the avatar.
[0254] In addition, in the following description, regarding the end user who is the main user of the avatar, it is also denoted as the first user, and regarding other end users who are not the main user of the avatar, it is also denoted as the second end user.
[0255] Step S300: The first end user who is the main user of the avatar as the object can set other end users who can use the avatar as the object in addition to himself / herself. That is, the first end user can specify the second end user and grant the usage right of the avatar as the object.
[0256] Therefore, the first end user makes the first end user terminal 300-1 access the identity management device 400 and performs an operation of specifying the second end user who has the usage right of the avatar as the object.
[0257] The first end user terminal 300-1 instructs the identity management device 400 to set the usage right of the avatar according to the operation. Specifically, the first end user terminal 300-1 sends the usage right setting information to the identity management device 400. The usage right setting information includes the avatar ID of the avatar as the object and the information of the user account of the specified end user.
[0258] Step S302: In the identity management device 400, the avatar registration unit 421 (an example of the permission setting unit) accesses the permission information of the avatar information of the object shown in the received usage permission setting information ( Figure 7 ), and stores the user account of the second end user specified in the received usage permission setting information for the accessed permission information of the user. Thus, the second end user specified in the usage permission setting information is given the usage permission of the object's avatar.
[0259] In addition, the second end user who has been given the usage permission of the avatar can, by operating the second end user terminal 300-2, Figure 13 in the same process as steps S120 to S126, display the identity certificate information screen of the object's avatar on the second end user terminal 300-2.
[0260] Next, a processing flow example for using the avatar identity certificate information to prove the identity of the avatar in the metaverse will be described. When proving the identity of the avatar, the end user who uses (operates) the avatar can be either the first end user or the second end user. Here, an example of proving the identity of the avatar based on the situation of the second end user using the avatar will be given.
[0261] Step S310: The second end user who has been given the usage permission makes the second end user terminal 300-2 access the service providing system 510 in the metaverse that provides services corresponding to the usage purpose of the object's avatar. The second end user performs an avatar cooperation operation for making the avatar exist in the accessed service providing system 510. The second end user terminal 300-2 notifies the service providing system 510 being accessed of the avatar ID of the object's avatar existing in the metaverse as an avatar cooperation control corresponding to the avatar cooperation operation.
[0262] Step S312: The service providing system 510 requests the identity management device 400 for the avatar information of the avatar represented by the notified avatar ID. The avatar providing control unit 423 of the identity management device 400 transmits the avatar based on the requested avatar information to the service providing system 510 that is the request source. The service providing system 510 makes the transmitted avatar exist in the metaverse. At this time, on the second end user terminal 300-2 accessing the service providing system 510, a situation where the object's avatar exists in the metaverse is displayed.
[0263] Step S314: The second end user performs an operation to make the object's avatar existing in the service providing system 510 act according to the usage purpose. The object's avatar acts in the metaverse according to the operation.
[0264] Step S316: Here, in a state where the avatar is acting in the metaverse, a situation that requires the identity proof of the avatar (a situation requiring identity proof) is generated. Specific examples of the situation requiring identity proof will be described later.
[0265] Step S318: Corresponding to the generation of the situation requiring identity proof, the service providing system 510 that becomes the identity verifier sends an identity proof information request to the identity management device 400 that manages the avatar of interest. The identity proof information request is a command to request the avatar identity proof information of the avatar for which the situation requiring identity proof has been generated. The information of the avatar determined as the object in the identity proof information request may include the avatar ID of the object's avatar.
[0266] Step S320: The VC management unit 424 of the identity management device 400 retrieves the avatar identity proof information associated with the same avatar ID as that included in the received identity proof information request from the avatar VC storage unit 433. Regarding the retrieved avatar identity proof information, the VC management unit 424 performs signature assignment (encryption) in the avatar VC storage unit 433 using the key corresponding to the avatar DID associated with the avatar identity proof information.
[0267] In addition, the VC management unit 424 may Figure 13 at the time of registration of the avatar identity proof information in step S112, on the basis of performing signature assignment using the key corresponding to the avatar DID, store the avatar identity proof information to be registered in the avatar VC storage unit 433. In this case, the processing of step S320 can be skipped.
[0268] Step S322: The VC management unit 424 sends the avatar identity proof information that has been signed using the key corresponding to the DID through step S320 to the service providing system 510 that is the source of the identity proof information request in step S318. The corresponding issuer DID and avatar DID may be attached to the sent avatar identity proof information.
[0269] Step S324: The service providing system 510 sends a public key request for requesting the public key corresponding to the received avatar identity proof information to the DPKI system 700. The public key request includes the issuer DID and avatar DID attached to the received avatar identity proof information.
[0270] Step S326: The DPKI system 700 obtains the public key corresponding to the issuer DID and the public key corresponding to the avatar DID respectively corresponding to the issuer DID and avatar DID included in the received public key request from the blockchain.
[0271] Step S328: The DPKI system 700 sends the two public keys (the public key corresponding to the issuer DID and the public key corresponding to the avatar DID) obtained through Step S326 to the service providing system 510, the source of the public key request.
[0272] Step S330: The service providing system 510 performs an identity verification process. That is, the service providing system 510 uses the two public keys sent through Step S328 to decrypt the avatar identity verification information received through Step S322. If the decryption is successful, the received avatar identity verification information is legitimate, proving the identity of the object's avatar. If the decryption fails, the received avatar identity verification information is illegitimate and cannot prove the identity of the object's avatar.
[0273] Step S332: The service providing system 510 performs a process corresponding to the verification result of Step S330.
[0274] In addition, Figure 15 shows the process in which an avatar operated by a second end user as a secondary usage right holder undergoes identity verification based on avatar identity verification information. In this embodiment, even when the first user as the primary usage right holder operates the avatar, identity verification can be performed based on the avatar identity verification information.
[0275] Next, an example in which the first end user sets the usage right of an avatar for another second end user based on the identity management system of this embodiment is given.
[0276] Regarding one example, when the first end user is a director of a company and the second end user is an employee of the same company, it is necessary for the first end user to enter the director's office in the metaverse with their corresponding avatar at a certain specified time to conduct business. However, the director has different important tasks within the specified time. Therefore, the director enables the second end user, who is an employee, to operate their avatar through an agent to participate in the metaverse meeting.
[0277] In this case, the director sets the second end user, who is an employee, as the secondary usage right holder of their own avatar. The second end user, who has the usage right of the director's avatar, can operate their own second end user terminal 300-2 at the specified moment to enter the director's office in the metaverse with the director's avatar and conduct business on behalf of the first end user, who is the director.
[0278] In this case, in order for the director's avatar to enter the director's office, it is necessary to have the director's identity verification. In this case, without setting identity verification information for the avatar itself, it is necessary to use the identity verification information of the first end user who is the main user with permission and is also a director to accept identity verification. However, in this case, when operating on the director's avatar, it is the second end user who is an employee acting as an agent and does not have the identity verification information of the first end user. Therefore, the director's avatar cannot enter the director's office.
[0279] In contrast, in the present embodiment, avatar identity verification information having identity-related information indicating that the avatar itself is a director is given to the director's avatar itself. Therefore, regardless of whether the second end user has performed an operation, the director's avatar can accept identity verification based on the avatar identity verification information given to itself and enter the director's office in the metaverse.
[0280] Another example is as follows. The first end user and the second end user are family members. The first end user is in their 30s, and the second end user is not in their 30s. Also, in the metaverse, at the ticket office, during a specified discount period, it is limited to people in their 30s, and discounts are applied to sell admission tickets.
[0281] The first end user plans to have their own avatar go to the ticket office in the metaverse to receive the discount limited to people in their 30s and purchase an admission ticket. However, the first end user is in a situation where they cannot operate their own avatar during the discount period to purchase an admission ticket. Therefore, the first end user sets the second end user, who is a family member, as a secondary user with permission, and during the discount period, has the second end user operate their own avatar to purchase an admission ticket.
[0282] In this case, when the avatar receives the application of the discount, it is necessary to prove based on the identity verification information that the admission ticket purchaser is in their 30s. In this case, without setting identity verification information for the avatar itself, when verifying the identity of a person in their 30s, it is necessary to use the identity verification information of the second end user. However, the second end user is not in their 30s. Therefore, it cannot be proven that the person is in their 30s, and the admission ticket cannot be purchased.
[0283] However, in the present embodiment, the identity-related information of the identity verification information given to the avatar itself corresponds to the first end user and indicates that the avatar itself is in its 30s. Therefore, regardless of whether the second end user has performed an operation, it can be proven that the avatar is in its 30s, and the application of the discount can be accepted to purchase an admission ticket.
[0284] Another example is as follows. The avatar is a character in a movie series. The first end user is the actor or movie company playing the role, and the second end user is a fan of the character. The first end user, who is the main user with permission, sets the second end user as a secondary user with permission, for example, according to an application from the second end user.
[0285] The second end-user, who is set as a secondary user with usage rights, operates their own second end-user terminal 300-2 to make the avatar of the character move in the metaverse. That is, the second end-user can make the avatar of the character move according to their own ideas in the metaverse. As an example, the second end-user can reproduce the scene by operating the avatar of the character in the metaverse that simulates the space corresponding to the scene of the movie.
[0286] In order for the avatar of the character to exist in the metaverse as the space corresponding to the scene of the movie based on this application, it is necessary to prove the identity of whether the avatar of the character is an avatar with an identity recognized by the movie company. In this case, in the present embodiment, avatar identity proof information with identity-related information indicating that the avatar itself is a character in the movie is also given to the avatar of the character itself. Therefore, regardless of who the second end-user is, the avatar of the character can receive identity verification based on the avatar identity proof information given to itself, enabling the second end-user to exist in the metaverse of the space corresponding to the scene of the movie.
[0287] In addition, the present embodiment can also handle the following cases by giving avatar identity proof information to the avatar itself.
[0288] For example, sometimes a certain end-user wants to participate in an activity in the metaverse using an anonymous avatar instead of the avatar clearly corresponding to themselves. In this case, in order to participate in the activity, a participation qualification is required, and the participation qualification is that the specified identity proof information is given to the target avatar.
[0289] In this case, the end-user generates a preliminary avatar with a limited number of uses, such as being able to be used only once, and uses the generated preliminary avatar as the anonymous avatar.
[0290] Regarding the preliminary avatar generated in this way, on the basis that the authenticity proof information management unit 422 gives a real certificate, the VC issuance system 600 gives identity proof information that meets the conditions for the participation qualification of the activity. The identity proof information given here can be multiple. In addition, each of the given identity proof information can be either public identity proof information or private identity proof information.
[0291] The preliminary avatar can disappear according to the operation of the end-user corresponding to after the completion of the participation in the activity. Or, the preliminary avatar can be controlled to disappear by using the avatar registration unit 421 corresponding to the completion of the participation in the activity.
[0292] By using the preliminary avatar in this way, for example, the identity of the end-user cannot be clarified, and the avatar corresponding to oneself can participate in the desired activity.
[0293] In addition, by assigning avatar identity authentication information to the avatar itself as in this embodiment, the following advantages can be obtained.
[0294] For example, depending on the nature of the avatar, it may be difficult to strictly define the holder of the avatar in terms of its application. Specifically, in the case where the avatar is a character in an animation, a comic, etc., it may be difficult to pre-set the holder of the avatar as any one of the author, the publisher, the TV station, the animation producer, etc. depending on the circumstances such as the rights relationship. Even in such a case, if it is the case of this embodiment, by assigning avatar identity authentication information to the avatar itself, it is possible to manage the avatar as an independent existence in the metaverse without relying on any end user.
[0295] In addition, it is possible to assign avatar identity authentication information to the avatar itself so that the avatar itself is independently managed as a structure existing in the metaverse. Thus, even in the case where the corresponding user (e.g., the main user with permission) dies and the avatar cannot be operated, it is possible to make it continue to exist and be managed in the metaverse.
[0296] In addition, regarding the identity-related information included in the avatar identity authentication information assigned to the avatar itself, it is possible to pre-accumulate the action history of the avatar. By accumulating the action history of the avatar in the identity-related information in this way, the credibility of the avatar in the metaverse can be improved. By improving the credibility of the avatar, it is possible to obtain rights in the metaverse, and the action range of the avatar in the metaverse is also expanded.
[0297] In addition, since the content of the identity-related information that accumulates the action history of the avatar in the above manner is information unique to the avatar, it can be used as the SBT of the avatar.
[0298] As described above, based on the identity management system of this embodiment, by assigning avatar identity authentication information to the avatar itself, it is possible to activate the utilization of the avatar.
[0299] In addition, based on the identity management system of this embodiment, it is possible to buy and sell avatars existing in the metaverse. Therefore, in the identity management system of this embodiment, on the basis that the end user holds a wallet, each avatar itself can hold a wallet.
[0300] Figure 16 An example of a management method related to the holding of a wallet of an avatar based on the identity management system of this embodiment is shown.
[0301] In this figure, end user A and end user B are shown. End user IDs are respectively associated with end user A and end user B. The identity management device 400 of this embodiment can manage one or more avatars in association with the end user ID. The following example is shown in this figure, that is, end user A associates one avatar A with his own end user ID, and end user B associates two avatars B and C with his own end user ID.
[0302] On this basis, avatar A, avatar B, and avatar C are respectively associated with one wallet A, wallet B, and wallet C. That is, avatar A holds wallet A, avatar B holds wallet B, and avatar C holds wallet C. The wallets held by these avatars are managed by the wallet management system 800.
[0303] In addition, Figure 16 shows an example of the process of buying and selling the commodity MC between avatar A and avatar B as follows.
[0304] In response to the operation of end user B on end user terminal 300, avatar B causes the commodity MC to enter the market MP operated in the metaverse by a certain service providing system 510. The commodity MC is held by avatar B in the metaverse, for example.
[0305] End user A operates on end user terminal 300 to cause avatar A to enter the market MP. End user A causes avatar A to purchase the commodity MC sold by avatar B from the commodities displayed in the market MP.
[0306] In this case, end user A operates on end user terminal 300 and acts in such a way that avatar A purchases the commodity MC in the metaverse.
[0307] In the market MP, corresponding to the situation where avatar A conducts a transaction to purchase the commodity MC, the ownership of the commodity MC in the metaverse is transferred to avatar A. In addition, according to this transaction, the wallet management system 800 pays the payment corresponding to the commodity MC from wallet A of avatar A and conducts the collection corresponding to the sale of the commodity MC in wallet B of avatar B. At this time, for example, the amount collected in wallet B can be calculated on the basis of subtracting the handling fee of the market MP, etc.
[0308] Figure 17 The sequence diagram of... represents an example of the processing flow executed by the identity management system corresponding to the transaction between Figure 16 the avatars A and B shown. This figure's processing is executed based on the situation where avatar A exists in the metaverse where the market MP is set up.
[0309] Step S400: The end-user A operates the end-user terminal 300-A to make the avatar A purchase the product of avatar B in the metaverse market MP.
[0310] Step S402: In the service providing system 510, according to the situation that avatar A purchases the product A of avatar B, the transaction control unit 511 accesses the avatar information stored in the avatar information storage unit 432 of the identity management device 400. From the accessed avatar information, the transaction control unit 511 refers to the wallet holding information of avatar A as the buyer of the product MC and avatar B as the seller, and determines the wallets held by avatars A and B respectively.
[0311] Step S404: The transaction control unit 511 gives an instruction for payment and receipt (payment and receipt instruction) to the wallet management system 800 targeting the wallets determined in Step S402. At the time of the payment and receipt instruction, the transaction control unit 511 sends the information indicating the transaction details to the wallet management system 800.
[0312] Step S406: The wallet management system 800 performs a process for making a payment corresponding to the payment for the product A with respect to wallet A (payment process) according to the payment and receipt instruction in Step S404.
[0313] Step S408: On the other hand, the wallet management system 800 performs a process for receiving payment corresponding to the payment for the product A with respect to wallet B (receipt process).
[0314] Step S410: After the processes in Step S406 and Step S408, the wallet management system 800 sends a payment and receipt completion notice indicating the completion of payment and receipt corresponding to the payment and receipt instruction to the service providing system 510.
[0315] Step S412: The transaction control unit 511 determines that the payment and receipt of the discount price of the product MC between avatars A and B in this transaction are completed by receiving the payment and receipt completion notice. Therefore, the transaction control unit 511 transfers the ownership of the product MC from avatar B to avatar A.
[0316] Step S414: The transaction control unit 511 sends a transaction completion notice to the end-user terminal 300-A of the end-user A corresponding to avatar A.
[0317] Step S416: In addition, the transaction control unit 511 sends the transaction completion notice to the end-user terminal 300-B of the end-user B corresponding to avatar B.
[0318] The end-user terminal 300-A that has received the transaction completion notice accordingly notifies the completion of the purchase of product A with avatar A. This notification can be made in such a way that, for example, the situation where avatar A holds product A is displayed in the metaverse where the market MP is set up.
[0319] In addition, the end-user terminal 300-B that has received the transaction completion notice accordingly notifies the completion of the purchase of product B. In the metaverse where the market MP is set up, this notification is made, for example, in such a way that the situation where product A disappears from the assets held by avatar B is displayed.
[0320] In addition, it can be configured such that the custody status of the assets in the wallet held by the avatar can be viewed on the end-user terminal 300 of the end-user corresponding to the avatar. At this time, it can be configured such that the end-user terminal 300 accesses the wallet management system 800 according to the operation of the end-user and refers to the asset custody status of the wallet of the avatar associated with the end-user. In addition, it can be configured such that, for example, the wallet management system 800 can manage one-dimensionally the multiple wallets respectively held by multiple avatars corresponding to one user. In this case, if the user's own assets are dispersed to the wallets of multiple avatars, the user's own assets can be managed by managing the multiple wallets one-dimensionally.
[0321] In this embodiment, in addition to being able to hold assets based on the usage environment of cryptocurrency, as information related to the corresponding avatar, the wallet can also hold, for example, identity-related information ( Figure 9 , Fig. 20).
[0322] When the identity-related information includes information related to a specified qualification, the corresponding avatar can be treated as the existence of proof of that qualification. As a specific example, when the information of the employee ID is held as identity-related information in the wallet associated with the avatar of an employee, the avatar of the employee itself can be treated as the employee ID.
[0323] In addition, when multiple end-users can share one avatar based on the identity management system of this embodiment, corresponding to the situation where the first end-user sets the usage permission of the avatar for other second end-users, the second end-user can also have the permission to manage the wallet associated with the avatar. Or, it can be configured such that, corresponding to the situation where the first end-user sets or transfers the usage permission of the avatar for other second end-users, the permission to manage the wallet is transferred from the first end-user to the second end-user.
[0324] The avatars shared or transferred among multiple end-users in this way can be actual existing characters, fictional characters generated by AI, avatars held by companies, etc.
[0325] For example, when the avatar of the general manager owned by a certain company exists in the metaverse, multiple employees belonging to the company have the right to use the avatar of the general manager. The operation history of each of the multiple employees acting on the avatar of the general manager is stored in the avatar information storage unit 432 as operation history information.
[0326] The operation history information stored in the above manner is the actual achievement of the employees who have the right to use and have operated on the avatar of the general manager. In the present embodiment, based on the fact that the operation history information represents the actual achievement as described above, the operation history information itself can be made to function as identification information for proving the identity of the general manager of the avatar. In this case, as a method of issuing the identification information, the VC issuance system 600 can be set to process the operation history information as identification information. As a specific example, the VC issuance system 600 can attach information indicating a label that functions as identification information for the general manager to the operation history information. Alternatively, when a request for identification of the avatar of the general manager is received, the VC issuance system 600 can respond based on the operation history information to prove the identity of the general manager.
[0327] In addition, it can be configured such that a program for implementing functions of the above-described avatar generation system 100, end-user terminal 300, identity management device 400, service provision system 510, VC issuance system 600, DPKI system 700, wallet management system 800, etc. is recorded on a computer-readable recording medium, and by reading the program recorded on this recording medium into a computer system and executing it, processing of the above-described avatar generation system 100, end-user terminal 300, identity management device 400, service provision system 510, VC issuance system 600, DPKI system, wallet management system 800, etc. is performed. Here, "reading the program recorded on the recording medium into a computer system and executing it" includes installing the program in the computer system. The "computer system" mentioned here includes hardware such as an OS and peripheral devices. In addition, the "computer system" can include a plurality of computer devices connected via a network including communication lines such as the Internet, WAN, LAN, and dedicated lines. In addition, the "computer-readable recording medium" refers to removable media such as floppy disks, optical disks, ROMs, CD-ROMs, and storage devices such as hard disks built into the computer system. In this way, the recording medium for storing the program can be a non-temporary recording medium such as a CD-ROM. In addition, the recording medium can also include an internal or external recording medium provided for distributing the program and accessible from a distribution server. The code of the program stored in the recording medium of the distribution server can be different from the code of the program in a form that can be executed using the terminal device. That is, if it can be downloaded from the distribution server and installed in a form that can be executed using the terminal device, the form stored in the distribution server is arbitrary. In addition, a structure in which the program is divided into multiple parts, downloaded at different times, and then merged on the terminal device, and distribution servers that distribute the divided programs separately can be different. Also, the "computer-readable recording medium" also includes a structure that stores the program for a constant time, such as a server in the case where the program is sent via a network and a volatile memory (RAM) inside the computer system that is the client. In addition, the above program can be used to implement a part of the above functions. And it can be a so-called differential file (differential program) that can be implemented by combining with a program that has already recorded the above functions in the computer system.
[0328] <Supplementary Note>
[0329] (1) One aspect of the present embodiment is an avatar management system, wherein the avatar management system has an avatar identification information management unit that manages by causing an identification information issuing system to issue identification information and causing a storage unit to store the issued identification information. The identification information is associated with an avatar authentication identifier issued in a unique manner for each avatar that can be used in a network service provided to end users on the network, and proves the identity of the avatar.
[0330] (2) One aspect of the present embodiment, based on the avatar management system described in (1), can be configured such that the avatar identification information management unit generates signed identification information, which is electronic signature given to the identification information for the avatar by a key associated with the avatar authentication identifier of the avatar. The signed identification information for the avatar of the target is sent to a verifier who verifies the identification related to the avatar by decrypting the signed identification information using the public key corresponding to the key.
[0331] (3) One aspect of the present embodiment, based on the avatar management system described in (1) or (2), can be configured such that, as the identification information issuing system, there is a public identification information issuing system that issues public identification information of a public issuer.
[0332] (4) One aspect of the present embodiment, based on the avatar management system described in any one of (1) to (3), can be configured such that, as the identification information issuing system, there is a private identification information issuing system that issues private identification information corresponding to a private issuer.
[0333] (5) One aspect of the present embodiment, based on the avatar management system described in any one of (1) to (4), can be configured to further have a proof credibility setting unit that can set a proof credibility indicating the level of credibility of the identity proof by the identification information.
[0334] (6) One aspect of the present embodiment, based on the avatar management system described in any one of (1) to (5), can be configured to further have a credit management unit that evaluates the credibility of the issuer based on credit information indicating the credibility of the issuer that causes the identification information issuing system to issue identification information.
[0335] (7) One aspect of the present embodiment can be configured, based on the avatar management system described in any one of (1) to (6), to further include a usage permission setting unit that can set, for end users other than the main usage permission holder, the usage permission to have an avatar exist in the metaverse for use.
[0336] (8) One aspect of the present embodiment can be configured, based on the avatar management system described in any one of (1) to (7), to further include: a wallet granting unit that associates a wallet that can be used in transactions in the metaverse with the avatar; and a transaction control unit that controls transactions between avatars that use wallets respectively associated with multiple avatars in the metaverse.
[0337] (9) One aspect of the present embodiment can be configured, based on the avatar management system described in any one of (1) to (8), to further include: a authenticity proof information granting unit that grants authenticity proof information to the registered avatar; and an authenticity confirmation unit that, in response to an authenticity confirmation inquiry for designating an avatar to be used in the network service, confirms the authenticity of the designated avatar based on the granting status of the authenticity proof information for the designated avatar.
[0338] (10) One aspect of the present embodiment is an avatar management method of an avatar management system, which includes the following avatar identity verification information management step. That is, the avatar identity verification information management unit manages by causing an identity verification information issuing system to issue identity verification information and causing a storage unit to store the issued identity verification information. The identity verification information is associated with an avatar authentication identifier issued in an inherent manner for each avatar registered to be usable in a network service provided to end users on the network, and proves the identity of the avatar.
[0339] (11) One aspect of the present embodiment is a program that causes a computer of an avatar management system to function as an avatar identity verification information management unit. The avatar identity verification information management unit manages by causing an identity verification information issuing system to issue identity verification information and causing a storage unit to store the issued identity verification information. The identity verification information is associated with an avatar authentication identifier issued in an inherent manner for each avatar registered to be usable in a network service provided to end users on the network, and proves the identity of the avatar.
[0340] The embodiments described above can be expressed in the following manner.
[0341] A computer-readable non-transitory storage medium stores a program that causes a computer to manage by issuing identification information through an identification information issuing system and storing the issued identification information in a storage unit. The identification information is associated with an avatar authentication identifier issued in a unique manner for each avatar registered to be usable in a network service provided to a terminal user on a network, and proves the identity of the avatar.
[0342] Industrial Applicability
[0343] According to the present invention, activation of utilization of an avatar existing in a virtual space can be achieved.
[0344] Description of Reference Numerals
[0345] 100… Avatar generation system, 110… Avatar material providing system, 120… Integration system, 200… User interface environment, 300… Terminal user terminal, 300-1… First terminal user terminal, 300-2… Second terminal user terminal, 400… Identity management device, 401… Communication unit, 402… Control unit, 403… Storage unit, 421… Avatar registration unit, 422… Authenticity proof information management unit, 423… Avatar providing control unit, 424… VC management unit, 431… Terminal user information storage unit, 432… Avatar information storage unit, 433… Avatar VC storage unit, 434… User VC storage unit, 435… Credit information storage unit, 500… Network service environment, 510… Service providing system, 511… Transaction control unit, 600… VC issuing system, 610… Public VC issuing system, 620… Private VC issuing system, 700… DPKI system, 800… Wallet management system, 4001… Communication device, 4002… ROM, 4003… RAM, 4004… Storage, CPU… 4005.
Claims
1. An avatar management system, wherein, the avatar management system has an avatar identity certification information management unit, which manages by causing an identity certification information issuance system to issue identity certification information and causing a storage unit to store the issued identity certification information. The identity certification information is associated with an avatar authentication identifier issued in a manner inherent to each avatar registered to be usable in a network service provided to end users on the network, and proves the identity of the avatar.
2. The avatar management system according to claim 1, wherein, the avatar identity certification information management unit generates signed identity certification information, which is an electronic signature given to the identity certification information for the avatar by a key associated with the avatar authentication identifier of the avatar. The signed identity certification information of the target avatar is sent to a verifier who verifies the identity related to the avatar by decrypting the signed identity certification information using the public key corresponding to the key.
3. The avatar management system according to claim 1 or 2, wherein, as the identity certification information issuance system, the avatar management system has a public identity certification information issuance system that issues public identity certification information of a public issuer.
4. The avatar management system according to claim 1 or 2, wherein, as the identity certification information issuance system, the avatar management system has a private identity certification information issuance system that issues private identity certification information corresponding to a private issuer.
5. The avatar management system according to claim 1 or 2, wherein, the avatar management system further has a certification credibility setting unit that can set a certification credibility indicating the level of credibility of the identity certification information in proving identity.
6. The avatar management system according to claim 1 or 2, wherein, the avatar management system further has a credit management unit that evaluates the credibility of the issuer based on credit information indicating the credibility of the issuer that causes the identity certification information issuance system to issue identity certification information.
7. The avatar management system according to claim 1 or 2, wherein, the avatar management system further has a usage permission setting unit that can set, for end users other than the main usage permission holder, the usage permission to have the avatar exist in the metaverse for use.
8. The avatar management system according to claim 1 or 2, wherein, the avatar management system further has: a wallet assignment unit that associates a wallet usable in transactions in the metaverse with the avatar; and a transaction control unit that controls transactions between avatars using wallets respectively associated with multiple avatars in the metaverse.
9. The avatar management system according to claim 1 or 2, wherein, the avatar management system further has: a authenticity certification information assignment unit that assigns authenticity certification information to the registered avatar; and An authenticity confirmation unit that, in response to an authenticity confirmation inquiry for designating an avatar used in the network service, confirms the authenticity of the designated avatar based on the granting status of authenticity proof information for the designated avatar.
10. An avatar management method, which is an avatar management method of an avatar management system, wherein, The avatar management method includes the following avatar identity proof information management step, that is, the avatar identity proof information management unit manages by causing an identity proof information issuing system to issue identity proof information and causing a storage unit to store the issued identity proof information. The identity proof information is associated with an avatar authentication identifier issued in an inherent manner for each avatar registered as being usable in a network service provided to an end user on the network, and proves the identity of the avatar.
11. A program, wherein, The program causes a computer of an avatar management system to function as an avatar identity proof information management unit that manages by causing an identity proof information issuing system to issue identity proof information and causing a storage unit to store the issued identity proof information. The identity proof information is associated with an avatar authentication identifier issued in an inherent manner for each avatar registered as being usable in a network service provided to an end user on the network, and proves the identity of the avatar.
Citation Information
Patent Citations
Computer program, method, and server
JP2022117111A
Method and device for inspecting surface
JP2022137904A
Information processor, information processing system, method for providing analysis result, and control program
JP2022190241A