Service identity inspection apparatus and method
The service identity inspection device addresses the lack of automated authenticity verification in service switching by converting service descriptions into intermediate representations, generating message digests, and comparing them to verify service identity before and after switching, ensuring data authenticity and reliability.
Patent Information
- Application Number
- JP2023202288
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-06-11
- Estimated Expiration
- 2043-11-30
AI Technical Summary
Existing service switching technologies lack automated verification of data authenticity when switching services such as Internet connections, home automation, and mobile phones, relying on trust in service providers or manual data export and import.
A service identity inspection device that converts service descriptions into an intermediate representation, generates message digests, and compares them to verify the identity of services before and after switching, with optional storage using a blockchain protocol.
Automatically confirms the identity of services before and after switching, ensuring data authenticity and reliability through automated verification, thereby enhancing trust and security in service transitions.
Smart Images

Figure 2025087949000001_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a technique for inspecting the identity between a service before switching and a service after switching when the service destination is changed.
Background Art
[0002] When switching services such as Internet connection services, home automation services, mobile phones, etc., whether the customer's genuine data is carried over is rarely confirmed in most cases, and it is left to the trust in the provider or the reliability of the export from the old service and import to the new service by the customer himself / herself. It is desired to automate service switching as much as possible and make it possible to verify the authenticity of data.
[0003] In home automation, although it has been proposed to provide a communication adapter to absorb differences in standards (Japanese Patent Application Laid-Open No. 2015-119389), no proposal has been known to address service switching itself.
[0004] Note that the above-mentioned prior art and its problems are described only for explaining a part of the background of this invention. It should be noted that this invention is not limited to the above-mentioned prior art and problems.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] The present invention has been made in view of the above circumstances, and an object thereof is to enable inspection of the identity between the service before transfer and the service after transfer when the service destination is changed.
Means for Solving the Problems
[0007] According to the present invention, in order to achieve the above object, the configuration as described in the claims is adopted. Here, prior to explaining the invention in detail, supplementary explanation will be given regarding the description in the claims.
[0008] That is, according to one aspect of the present invention, in a service identity inspection device that inspects the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network: service description conversion means for converting a service description written in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation; message digest calculation means for generating a message digest from the service description in the intermediate representation converted by the service description conversion means; and comparison means for comparing between two message digests generated by the message digest calculation means from two service descriptions in the intermediate representation generated by the service description conversion means for two corresponding services, and inspecting the identity of the two corresponding services.
[0009] In this configuration, the identity of the service can be confirmed by comparing the message digests of the service descriptions before and after the transfer.
[0010] In this configuration, message digest storage means for storing the message digest may be further provided.
[0011] In this configuration, the message digest storage means may store the message digest by means of a blockchain protocol.
[0012] In this configuration, the service description conversion means may be implemented by a large language model.
[0013] In this configuration, the message digest calculation means may be a hash function.
[0014] In this configuration, the message digest may be used as a fixed-length identifier in the message digest storage means.
[0015] In this configuration, the comparison means may determine identity based on whether the same value as the message digest newly generated by the message digest calculation means is already stored in the message digest storage means.
[0016] In this configuration, the service description conversion means may convert the service description of the original vendor described in the first description language of the original vendor into the service description of the destination vendor described in the second description language of the destination vendor.
[0017] In this configuration, the service may be a home automation service, an Internet connection service, or the service may be a mobile communication connection service.
[0018] According to another aspect of the present invention, in a service identity management device that manages data related to the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network: service description conversion means for converting a service description described in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation; and one-way function means for generating a digest from the service description in the intermediate representation converted by the service description conversion means. For two corresponding services, two digests generated by the one-way function means are output from the two service descriptions in the intermediate representation generated by the service description conversion means, and the output two digests are compared so that the identity of the two corresponding services can be inspected.
[0019] Also in this configuration, the identity of the service can be confirmed by comparing the digests of the service descriptions before and after the switch.
[0020] Alternatively, the service description in the intermediate representation may be converted into fixed-length data and the conversion results may be compared.
[0021] Note that the present invention can be realized not only as an apparatus or a system but also as a method. Of course, a part of such an invention can be configured as software. Naturally, a software product used to cause a computer to execute such software is also included in the technical scope of the present invention.
[0022] The above and other aspects of the present invention are described in the claims and will be detailed below using examples.
Advantages of the Invention
[0023] According to the present invention, the identity of the service before and after the switch can be confirmed.
Brief Description of the Drawings
[0024]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5A
Figure 5B
Figure 5C
Figure 6A
Figure 6B
Figure 6C
Figure 7
Figure 8
Mode for Carrying Out the Invention
[0025] Hereinafter, the service identity verification system 100 according to an embodiment of the present invention will be described.
[0026] [Example 1] FIG. 1 shows the overall usage environment of the service identity verification system 100 according to Embodiment 1 of the present invention. The service identity verification system 100 is applicable to, for example, home automation services, but is also applicable to mobile communication services, Internet services, and the like. In FIG. 1, the service identity verification system 100 is connected to an IP network 500. A user device 600 and a service provider system 700 are connected to the IP network 500, and the user device 600 receives service provision from the service provider system 700. The service identity verification system 100 includes an identity service unit 200 and an evidence service unit 300. The identity service unit 200 converts a service description in the service provider system 700 (700A) into a service description in another service provider system 700 (700B), and also converts a service description in the service provider system 700 into a service description in an intermediate representation unique to the service identity verification system 100. The evidence service unit 300 generates a digest from the service description converted into the service description in the intermediate representation unique to the service identity verification system 100, stores it, and enables verification of the identity of the service description using this digest.
[0027] FIG. 2 shows a configuration example of the service identity inspection system 100 according to Embodiment 1. In FIG. 2, the service identity inspection system 100 includes an identity service unit 200 and an evidence service unit 300. The identity service unit 200 includes a large language model 210 and a service description database 220. The service description database 220 holds a large amount of data on service descriptions written in a predetermined programming language and service descriptions written in an intermediate representation specific to the service identity inspection system 100, and configures a conversion unit 230 that performs conversion (translation) of service descriptions between the above-mentioned predetermined description languages for the large language model 210, and conversion (translation) of service descriptions in the above-mentioned intermediate representation into service descriptions in the above-mentioned predetermined description language. The evidence service unit 300 includes a digest generation unit 310, a digest storage unit 320, and a comparison unit 330. The digest generation unit 310 generates a fixed-length message digest (sometimes simply referred to as a digest in this embodiment) from the service description in the intermediate representation, and is typically generated by a cryptographic hash function. The digest is of a fixed length and can be used as an identifier. The generated digest is stored in the digest storage unit 320. The digest is stored in a blockchain protocol as shown in FIG. 7 and is protected from deletion, modification, and forgery. The comparison unit 330 compares the digests stored in the digest storage unit 320 and determines whether they are the same.
[0028] A large language model (LLM) constructs a language model through machine learning using a large learning source, and predicts likely subsequent outputs based on a probability distribution for texts, program codes, etc. along a given context. When a word sequence of length m is given, the language model gives the probability P(w 1 ,…,w m ) for the entire word sequence. In a large language model, by regarding a character string as a sequence separated by finer constituent elements (tokens), predictions can be made not only for English etc. where words are separated, but also for Japanese, program codes including symbols, etc.
[0029] Large language models can be constructed by using a neural network having, for example, an input layer, an output layer, and a plurality of intermediate hidden layers, which can be learned using a large corpus.
[0030] Examples of cryptographic hash functions include the SHA (Secure Hash Algorithm) series defined by NIST (National Institute of Standards and Technology in the United States). It is acceptable to use 256-bit output versions of SHA-2 or SHA-3, but it is not limited to these.
[0031] A cryptographic hash function is a substantially one-way function. Even if the digest is made public, the original service description (intermediate representation) cannot be reproduced, so there are no problems in terms of privacy protection and protection of proprietary information.
[0032] It is desirable for a cryptographic hash function to ensure uniformity such that message digests do not become the same for different inputs, that is, collisions do not occur.
[0033] The comparison unit 330 may examine whether the newly generated message digest is already stored in the digest storage unit 320, but is not limited to this. A hash tree can be formed using a hash function with a small number of digits, and the message digest can be sorted and stored on the leaf pages of the tree for fast matching, but is not limited to this.
[0034] Associated with each message digest in the digest memory unit 320, auxiliary data such as user data, transfer history, etc. may be stored. This associated data may be managed separately from the message digest and kept unpublished (for example, access may be managed). Cryptographic hash functions are expected to substantially avoid collisions. Considering the rare case where the hash values of different service descriptions collide (become identical), for the same message digest, the associated data linked thereto may be matched to ensure more strict consistency, but is not limited thereto.
[0035] FIG. 7 shows a conceptual example of a blockchain. Each block (A, B, C) contains a set of data therein. This data can be arbitrarily set, but traditionally is a list of transactions. Each block has a reference to the previous block. One prominent feature of the blockchain as a data structure is that it includes evidence by the output of a cryptographic hash function indicating that the data held in each block has not been tampered with. The digest memory unit 320 may be held in any evidence network (FIGS. 5A to 5C). This network is not limited to the blockchain, and any method capable of detecting and preventing tampering may be adopted.
[0036] FIG. 3 shows a schematic configuration example of a computer constituting the service identity verification system 100, but is not limited thereto. In FIG. 3, the computer 1000 includes a CPU (processor) 1001, a main memory 1002, an external interface 1003, an external storage device 1004, etc., and by installing the application 1005 in this computer 1000, the operation of the service identity verification system 100 can be realized. The service identity verification system 100 may be configured distributively across a plurality of computers.
[0037] Figures 4, 5A to 5C show operation examples of the service identity verification system 100. First, the operation during normal use (indicated by X) will be described (Figure 5A). During normal use, the user programs the living environment in relation to, for example, the home automation service. The code (service description) is stored by the provider system 700 (700A), and the living environment operates automatically when the code is called as needed (e.g., lighting, TV, air conditioner, etc. shut down all at once with the "good night" command). When a service description (code) is newly input or changed (X1), it is converted and normalized into the internal representation of the large language model 210 through the identity service unit 200 based on the conversion and normalization request (X2), and based on the digest registration request (X3), its cryptographic digest is registered in the digest storage unit 320 in the evidence service unit 300.
[0038] The user can back up the service description from the provider system 700 and verify its identity. This verification operation is indicated by Y (Figure 5B). First, the user backs up the service description from the provider system 700 (Y1). This can be achieved by making a backup request to the provider system 700. The user sends an identity confirmation request to the identity service unit 200 together with the backed-up service request (Y2), and the identity service unit 200 converts the service description into an intermediate representation and sends it to the evidence service unit 300 (Y3). The comparison unit 330 of the evidence service unit 300 checks the identity based on the corresponding digest and returns the presence or absence of identity to the user (Y4).
[0039] Next, the transfer and confirmation of service continuity (indicated by Z) will be described (Fig. 5C). The user sends a transfer notification (Z1) to the original provider system 700 (700A). The original provider system 700 (700A) instructs the identity service unit 200 to convert (translate) the service description it holds into the description language of the destination service provider system 700 (700B) along with the service description, and transfer the conversion result to the destination service provider system 700 (700B) (Z2). The identity service unit 200 converts the original service description into a destination service description by the conversion unit 230 and supplies it to the destination provider system 700 (700B) (Z3). The provider system 700 (700B) stores this and subsequently provides services to the user based on the service description. The provider system 700 (700B) further supplies a backup of the service description to the user (Z4). The user sends an identity confirmation request (Z5) to the identity service unit 200 together with this backed-up service description. The identity service unit 200 converts this into an intermediate representation and sends it to the evidence service unit 300. The evidence service unit 300 generates a digest, compares the digests, verifies the identity (Z6), and returns the presence or absence of identity to the user (XZ7).
[0040] Once the user's identity is confirmed, the normal operation (X) described above is repeated hereafter.
[0041] Fig. 6A shows an example of a service description (YAML) in the original provider, Fig. 6B shows an example of an intermediate representation service description (XML) in the identity service unit 200, and Fig. 6C shows an example of a service description (JSON) in the destination provider. Of course, the service description and intermediate representation are not limited to a specific description language.
[0042] In the above embodiment, although a cryptographic hash function is used, one-way functions may be widely used.
[0043] [Embodiment 2] Next, the present invention will be described with respect to Example 2. FIG. 8 shows the configuration of Example 2. In this figure, corresponding parts to those in FIG. 2 are denoted by corresponding reference numerals, and the description thereof will be omitted. In this example, the comparison unit 330 is removed from the evidence service unit 300 and realized on the user side or by another service. The user may realize the comparison unit on a mobile terminal such as a mobile phone (smartphone).
[0044] [Example 3] In the present invention, although a substantially one-way function such as a cryptographic hash function is used for the service description in the intermediate representation, the service description in the intermediate representation may be converted into fixed-length data and the conversion results may be compared. A part of the service description in the intermediate representation may be cut out to be fixed-length data. When a part of the service description can be read as it is from the fixed-length data, it is preferable to use data protection means to protect personal information and property information from access by an external third party. For example, in FIG. 2, the digest generation unit 310 may be a conversion unit that converts the service description in the intermediate representation into fixed-length data.
[0045] In the above description, mainly the switching of home automation services has been described as a premise. However, it is also applicable to the switching of mobile phone services, the switching of Internet service providers, services related to home routers, the switching between task automation tools (IFTTT, Zapier, trademarks), the switching of cloud storage services, the switching of electronic platforms, the switching of home security services, the so-called switching of metaverse-based services (switching of VR worlds), the hosting service switching of virtual machines in IaaS, and the hosting service switching of functions in FaaS. It is also applicable to the switching of mobile phones and personal computers, the switching of their configuration files (.bashrc,.emacs), and machine code translation.
[0046] In the case of switching (MNP) of a mobile phone (mobile station of mobile communication), the following procedures are taken, and the identity check of this invention can be performed in any of the procedures.
[0047] [One-stop method] 1. The customer applies for a contract on the website of the transfer destination carrier. 2. Automatically transition to the website of the transfer source carrier, log in to the customer's my page, etc., and then enter the cancellation procedure. 3. When the confirmation of cancellation is completed, transition to the website of the transfer destination carrier again and proceed with the contract. 4. When the contract is completed, an automatic handover occurs. The contract with the transfer source carrier is cancelled. 5. The customer can confirm the service identity using the service identity inspection device.
[0048] [Two-stop method] 1. The customer applies for a transfer to the transfer source carrier. 2. Receive an explanation of cancellation from the transfer source carrier and receive a "transfer reservation number". 3. Notify the transfer destination carrier of the "transfer reservation number" and apply for a new contract. 4. When the new contract process is completed at the transfer destination carrier, an automatic handover occurs. 5. The customer can confirm the service identity using the service identity inspection device.
[0049] The service identity represents the consistency of functional requirements, and users can transfer carriers, for example, to improve performance (processing speed, response speed, price, support, etc.).
[0050] The description of the embodiments of this invention ends here. Note that this invention is not limited to the above-described embodiments, and various modifications are possible without departing from the spirit thereof. For example, the components of the above-described embodiments may be distributed and arranged in a communication network.
Explanation of reference numerals
[0051] 100 Service Identity Inspection System 200 Identity Service Unit 210 Large Language Model 220 Service Description Database 230 Conversion Unit 300 Evidence Service Unit 310 Digest Generation Unit 320 Digest Storage Unit 330 Comparison Unit 500 IP Network 600 User Device 700 Service Provider System
Claims
1. In a service identity inspection device that inspects the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network, service description conversion means for converting a service description written in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation; message digest calculation means for generating a message digest from the service description in the intermediate representation converted by the service description conversion means; comparison means for comparing between two message digests generated by the message digest calculation means from two service descriptions in the intermediate representation generated by the service description conversion means for two corresponding services, and inspecting the identity of the two corresponding services. A service identity inspection device characterized by having.
2. The service identity inspection device according to claim 1, further comprising message digest storage means for storing the message digest.
3. The service identity device according to claim 2, wherein the message digest storage means stores the message digest by a blockchain protocol.
4. The service identity inspection device according to claim 1, wherein the service description conversion means is realized by a large language model.
5. The service identity inspection device according to claim 1, wherein the message digest calculation means is a hash function.
6. The service identity management device according to claim 2, wherein the message digest is used as a fixed-length identifier in the message digest storage means.
7. The service identity management device according to claim 2, wherein the comparison means determines identity based on whether the same value as the message digest newly generated by the message digest calculation means is already stored in the message digest storage means.
8. The service identity inspection device according to claim 1, wherein the service description conversion means converts the service description of the source vendor written in the first description language of the source vendor into the service description of the destination vendor written in the second description language of the destination vendor.
9. The service identity inspection device according to claim 1, wherein the service is a home automation service.
10. The service identity inspection device according to claim 1, wherein the service is an Internet connection service.
11. The service identity inspection device according to claim 1, wherein the service is a mobile communication connection service.
12. In a service identity inspection method for inspecting the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network, a step in which service description conversion means converts a service description described in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation; a step in which message digest calculation means generates a message digest from the service description in the intermediate representation converted by the service description conversion means; and a comparison means compares between two digests generated by the message digest calculation means from two service descriptions in the intermediate representation generated by the service description conversion means for two corresponding services, and inspects the identity of the two corresponding services. A service identity inspection method characterized by having the steps of.
13. In a computer program for inspecting the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network, a processor is configured as service description conversion means for converting a service description described in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation, and configured to function as message digest calculation means for generating a message digest from the service description in the intermediate representation converted by the service description conversion means, and compares between two message digests generated by the message digest calculation means from two service descriptions in the intermediate representation generated by the service description conversion means for two corresponding services, so as to be able to inspect the identity of the two corresponding services. A computer program for service identity inspection, characterized by this.
14. In a service identity management device that manages data related to the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network, Service description conversion means for converting a service description described in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation; One-way function means for generating a digest from the service description in the intermediate representation converted by the service description conversion means; For two corresponding services, two digests generated by the one-way function means are output from the two service descriptions in the intermediate representation generated by the service description conversion means, and the two output digests are compared to enable verification of the identity of the two corresponding services. A service identity management apparatus characterized by this.
15. In a service identity management apparatus for managing data related to the identity of a service when a user switches services among a plurality of service providers that provide services to the user via a communication network, Service description conversion means for converting a service description described in any one of a plurality of predetermined description languages into a service description in a predetermined intermediate representation; Fixed-length data generation means for generating fixed-length data of a predetermined data length from the service description in the intermediate representation converted by the service description conversion means; For two corresponding services, two pieces of fixed-length data generated by the fixed-length data generation means are output from the two service descriptions in the intermediate representation generated by the service description conversion means, and the two output pieces of fixed-length data are compared to enable verification of the identity of the two corresponding services. A service identity management apparatus characterized by this.
Citation Information
Patent Citations
File migration method and device, equipment, medium and program product
CN116069725A
System and method for assuring identity of electronic data
JP2005259056A
Document verifying apparatus, document verifying method and program
JP2006351002A
E-mail transmitting and receiving system
JP2009093314A
File verification device, file transfer system and program
JP2019079280A