Terminal, system, control method of terminal, and program

The terminal and system address the burden of repeated user authentication by using a biometric information certification certificate for initial and subsequent simplified identity verifications, enhancing user convenience and efficiency.

JP2025088101APending Publication Date: 2025-06-11NEC CORP
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2023202564
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-06-11

AI Technical Summary

Technical Problem

Existing user authentication systems burden users by repeatedly requesting personal identification when accessing services that require biometric information, leading to user inconvenience and increased authentication efforts.

Method used

A terminal and system that store a biometric information certification certificate, allowing for a first identity verification using stored biometric information and subsequent second identity verifications that are simpler and different from the first, reducing the burden on users.

Benefits of technology

This approach reduces the user's authentication burden by allowing a simple and efficient second identity verification process, even when repeatedly requested by the same service provider.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025088101000001_ABST
    Figure 2025088101000001_ABST
Patent Text Reader

Abstract

To provide a terminal configured to reduce the burden of a user who receives a service that requires identity verification.SOLUTION: A terminal includes storage means and confirmation means. The storage means stores biometric information certificate, which is a certificate for certifying biometric information of a certificate holder, including biometric information of the certificate holder. The confirmation means executes first identity verification, in response to a request for identity verification from a service provider, using biometric information acquired from the stored biometric information certificate, and notifies the service provider of a result of the first identity verification. The confirmation means executes, on receipt of another request for identity verification from the service provider, second identity verification different from the first identity verification, and notifies the service provider of a result of the second identity verification.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a terminal, a system, a method for controlling a terminal, and a program.

Background Art

[0002] There are technologies related to user authentication.

[0003] For example, Patent Document 1 describes selecting an authentication means suitable for the user's context from among a plurality of authentication means. The information processing apparatus of Patent Document 1 includes an estimation unit, a selection unit, and a presentation unit. The estimation unit estimates the user's situation from the user's context information. The selection unit selects an authentication means suitable for the user's situation, avoiding authentication means not suitable for the user's situation from among a plurality of authentication means. The presentation unit presents the selected authentication means to the user. Further, the estimation unit estimates the user's current behavior from the user's behavior analysis information. The selection unit selects an authentication means suitable for the user's current behavior, avoiding authentication means not suitable for the user's current behavior from among a plurality of authentication means.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] As disclosed in Patent Document 1, biometric information is used for user identification. When a user receives a service, the service provider may request user identification using biometric information. In that case, repeatedly requesting user identification from the same service provider and forcing the user to perform user identification each time places a heavy burden on the user.

[0006] The main object of the present invention is to provide a terminal, a system, a method for controlling the terminal, and a program that contribute to reducing the burden on users who enjoy services that require personal identification.

Means for Solving the Problems

[0007] According to a first aspect of the present invention, there is provided a terminal including: storage means for storing a biometric information certification certificate that is a certification certificate proving that it is biometric information of an issuer and includes the biometric information of the issuer; and confirmation means for, in response to a request for personal identification from a service provider, performing a first personal identification using the biometric information obtained from the stored biometric information certification certificate and notifying the service provider of the result of the first personal identification. When the confirmation means is requested again by the service provider to perform the personal identification, the confirmation means performs a second personal identification different from the first personal identification and notifies the service provider of the result of the second personal identification.

[0008] According to a second aspect of the present invention, there is provided a system including an apparatus of a service provider and a terminal. The terminal includes: storage means for storing a biometric information certification certificate that is a certification certificate proving that it is biometric information of an issuer and includes the biometric information of the issuer; and confirmation means for, in response to a request for personal identification from the apparatus of the service provider, performing a first personal identification using the biometric information obtained from the stored biometric information certification certificate and notifying the apparatus of the service provider of the result of the first personal identification. When the confirmation means is requested again by the apparatus of the service provider to perform the personal identification, the confirmation means performs a second personal identification different from the first personal identification and notifies the apparatus of the service provider of the result of the second personal identification.

[0009] According to a third aspect of the present invention, there is provided a method for controlling a terminal, which stores a biometric information certification certificate that proves to be biometric information of an issuer and includes the biometric information of the issuer, and upon receiving a request for identity verification from a service provider, performs a first identity verification using the biometric information obtained from the stored biometric information certification certificate, notifies the service provider of the result of the first identity verification, and when the service provider requests the identity verification again, performs a second identity verification different from the first identity verification and notifies the service provider of the result of the second identity verification.

[0010] According to a fourth aspect of the present invention, there is provided a program for causing a computer mounted on a terminal to perform a process of storing a biometric information certification certificate that proves to be biometric information of an issuer and includes the biometric information of the issuer, a process of performing a first identity verification using the biometric information obtained from the stored biometric information certification certificate upon receiving a request for identity verification from a service provider and notifying the service provider of the result of the first identity verification, and a process of performing a second identity verification different from the first identity verification and notifying the service provider of the result of the second identity verification when the service provider requests the identity verification again.

Advantages of the Invention

[0011] According to each aspect of the present invention, there are provided a terminal, a system, a method for controlling a terminal, and a program, which contribute to reducing the burden on users who enjoy services that require identity verification. Note that the effects of the present invention are not limited to the above. Instead of or together with the above effects, other effects may be achieved by the present invention.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

DETAILED DESCRIPTION OF THE INVENTION

[0013] First, an overview of an embodiment will be described. Note that the reference numerals in the drawings appended to this overview are for convenience of each element as an example to assist understanding, and the description of this overview is not intended to be limiting in any way. Also, unless otherwise specified, the blocks described in each drawing represent a configuration in terms of functional units, not hardware units. The connection lines between the blocks in each figure include both bidirectional and unidirectional ones. The one-way arrow schematically shows the flow of the main signal (data) and does not exclude bidirectionality. In this specification and the drawings, for elements that can be similarly described, duplicate description may be omitted by assigning the same reference numerals.

[0014] A terminal 100 according to an embodiment includes a storage unit 101 and a verification unit 102 (see FIG. 1). The storage unit 101 stores a biometric information certification document that proves that it is the biometric information of the issuer and includes the biometric information of the issuer (step S1 in FIG. 2). In response to a request for identity verification from a service provider, the verification unit 102 performs a first identity verification using the biometric information obtained from the stored biometric information certification document, and notifies the service provider of the result of the first identity verification (step S2). When the verification unit 102 is requested for identity verification again by the service provider, it performs a second identity verification different from the first identity verification, and notifies the service provider of the result of the second identity verification (step S3).

[0015] When the terminal 100 is requested for identity verification by a service provider, it performs a first identity verification by a regular procedure using the biometric information acquired in advance. The terminal 100 notifies the service provider of the result of the first identity verification. When the terminal 100 is requested for identity verification again by the service provider, it performs a simple second identity verification different from the first identity verification. The terminal 100 notifies the service provider of the result of the second identity verification. As a result, even when identity verification is repeatedly requested from the same service provider, the user only needs to perform a simple identity verification. That is, the burden on the user who enjoys services that require identity verification is reduced.

[0016] Specific embodiments will be described in more detail below with reference to the drawings.

[0017] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0018] [Configuration of System] As shown in FIG. 3, the information processing system according to the first embodiment includes at least one or more certification document issuers and at least one or more service providers.

[0019] The certification issuer is the entity that issues the certification to the user. For example, the certification issuer issues a certification that proves the "identity" and "attributes" of the user. For example, the certification issuer issues an identity certificate that proves the user's name, gender, date of birth, address, etc.

[0020] Alternatively, the certification issuer issues a "biometric information certification" that proves the "biometric information", which is the physical characteristic of the user. The biometric information certification proves that the biometric information contained in the certification is the biometric information of the certificate recipient. That is, the certification issuer proves that the biometric information contained in the biometric information certification is the biometric information of the certificate recipient.

[0021] Note that examples of biometric information include data (feature quantities) calculated from physical characteristics unique to an individual, such as face, fingerprint, voiceprint, vein, retina, and iris pattern of the pupil. Alternatively, the biometric information may be image data such as a face image or a fingerprint image. The biometric information may be anything that contains the user's physical characteristics as information. In the present disclosure, the case of using biometric information (face image or feature quantity generated from the face image) related to a person's "face" will be described.

[0022] Alternatively, the certification issuer issues a certification that proves the "rights" and "qualifications" of the user. For example, the certification issuer issues a "service entitlement certificate" that proves that the user has the qualification (right) to receive a predetermined service.

[0023] For example, public institutions that issue identity certificates such as driver's licenses, passports, and My Number cards correspond to the certification issuer. Alternatively, companies, universities, etc. that possess the face images of users (employees, students) correspond to the certification issuer.

[0024] Alternatively, the business operator that provides services to the user (customer) corresponds to the certification issuer. For example, a ticket seller that sells tickets for airplanes, trains, concerts, etc. corresponds to the certification issuer.

[0025] Note that the tickets sold by ticket vendors correspond to the above-mentioned service entitlement certificates. In the following descriptions, the certification certificate regarding the tickets necessary for users to receive services may also be referred to as a "ticket certification certificate". The ticket certification certificate is one type of service entitlement certificate.

[0026] Each certification certificate issuer is equipped with a server device 10. The server device 10 is a server that performs the processes and operations necessary for the certification certificate issuer to conduct its business. The server device 10 may be managed and operated by the certification certificate issuer, or the management and operation may be entrusted to other operators or the like. The server device 10 may be installed within the building of the certification certificate issuer, or may be installed on the network (in the cloud).

[0027] A service provider is a business operator that provides services to users. As described above, a ticket vendor that sells tickets to users is a service provider. Alternatively, an operator of a theme park or a business operator that holds a concert corresponds to a service provider. Alternatively, an operator of transportation means such as railways, buses, or airplanes corresponds to a service provider. Alternatively, an operator of a retail store, a restaurant, or the like corresponds to a service provider. Service providers are not limited to private companies, and public institutions such as city halls are also included in the service providers disclosed in this application.

[0028] Note that depending on the type and form of business of the service provider, the same business operator may conduct business as a certification certificate issuer or as a service provider.

[0029] Each service provider is equipped with a service server 20 and a business operator terminal 21 for providing services to users. For example, the service server 20 provides services to users via a website. For example, the service server 20 provides online services to users without the need for instructions or operations from employees or the like of the service provider (the service server 20 provides services automatically and autonomously).

[0030] Alternatively, an employee of the service provider or the like operates the business operator terminal 21 to provide services to the user. The business operator terminal 21 may be a terminal such as a personal computer, a tablet-type terminal, or may be a POS (Point of Sale) terminal or a signage-type terminal.

[0031] Alternatively, the service server 20 and the business operator terminal 21 may be connected, and an employee of the service provider or the like may provide services to the user while referring to information stored in the service server 20 via the business operator terminal 21.

[0032] The user possesses the terminal 30. For example, the user operates the terminal 30 to request (demand) the issuance of a certification certificate from the certification certificate issuer. Further, the user uses the terminal 30 to provide the service provider with the certification certificate (for example, service enjoyment qualification certificate; ticket certification certificate) required by the service provider.

[0033] Each device shown in FIG. 3 is connected to a network. Specifically, the server device 10, the service server 20, the business operator terminal 21, and the terminal 30 are connected to the network by wired or wireless communication means.

[0034] The configuration of the information processing system shown in FIG. 3 is an example and is not intended to limit the configuration. For example, the server device 10 of each certificate issuer and the devices of the service provider (service server 20, business operator terminal 21) may belong to different networks. Alternatively, each certificate issuer may include a plurality of server devices 10. Load distribution and redundancy may be achieved by the plurality of server devices 10. Similarly, each service provider may include a plurality of service servers 20 and a plurality of business operator terminals 21.

[0035] [Schematic Operation] Subsequently, the schematic operation of the information processing system according to the first embodiment will be described.

[0036] [Preparation of Digital Wallet] The user's terminal 30 is equipped with a digital wallet function. The digital wallet is an electronic information storage service that ensures information security such as data integrity, reliability, and availability.

[0037] The user installs an application for realizing the digital wallet on the possessed terminal 30. By opening a digital wallet on the terminal 30, the user can store various digital contents such as identity certificates like employee ID cards and student ID cards, ticket certificates like airline tickets and concert tickets, biometric information certificates, electronic money, and credit card information in the terminal 30.

[0038] <Acquisition of Digital Content> The user who has opened a digital wallet acquires the digital content to be stored in the digital wallet.

[0039] The user operates the terminal 30 to request the issuer of the certificate to issue a certificate. Specifically, the digital wallet application makes a request for issuing a certificate to the issuer of the certificate. All or part of the certificate issuers issue VCs (Verifiable Credentials) that can be verified online as certificates. In the following description, VCs are referred to as "credential certificates".

[0040] By acquiring certificates from each certificate issuer, the user's terminal 30 stores digital contents as shown in, for example, Figure 4. The digital contents stored in the terminal 30 include biometric information certificates, passports, driver's licenses, service entitlement certificates (ticket certificates), electronic money, etc.

[0041] Here, when opening a digital wallet, the user first obtains a biometric information certificate regarding their own biometric information. The user obtains a biometric information certificate (VCs) issued as a credential certificate. Then, the user obtains an identity certificate such as an employee ID card or a service eligibility certificate. For example, the user obtains a service eligibility certificate (VCs) issued as a credential certificate.

[0042] In the following description, unless otherwise specified, the biometric information certificate and the service eligibility certificate are credential certificates.

[0043] <Procedure for Obtaining Credential Certificates> First, the acquisition of credential certificates will be described. The procedures common to the acquisition of biometric information certificates and service eligibility certificates will be described as the procedures for obtaining credential certificates. Then, the procedures different in the acquisition of biometric information certificates and service eligibility certificates will be described.

[0044] Prior to the issuance request of the credential certificate, the user's terminal 30 generates a pair of public key and private key. Also, the terminal 30 generates a decentralized identifier (DID). The terminal 30 registers the generated DID (user ID; holder ID) and public key in the blockchain (step S01 in Fig. 5).

[0045] Furthermore, while presenting the user ID, the user's terminal 30 requests the issuance of a credential certificate from the certificate issuer (server device 10). Specifically, the terminal 30 transmits a "certificate issuance request" including information regarding the certificate to be issued (e.g., the type of the credential certificate), information specifying the object to be proved by the credential certificate, the user ID, etc. to the server device 10 (step S02).

[0046] Note that the server device 10 generates, stores in advance the DID (issuer ID), private key and public key of the issuer.

[0047] Upon receiving a request for issuing a certification certificate, the certification certificate issuer determines whether it is possible to issue the credential certification certificate desired by the user.

[0048] If it is possible to issue the credential certification certificate desired by the user, the server device 10 generates a credential certification certificate including the issuer ID and the user ID.

[0049] Specifically, the server device 10 generates a credential certification certificate including metadata such as the type of the credential certification certificate, the name of the issuing organization, the issue date and time, the validity period, etc., the qualification information body, and the public key information and electronic signature of the issuer, etc. Note that the specific information to be certified by the issuer is described in the qualification information body.

[0050] The server device 10 transmits the generated credential certification certificate to the terminal 30 of the user (the user who becomes the holder of the certification certificate; the requester for issuing the certification certificate) (certification certificate issuance; step S03).

[0051] Furthermore, the server device 10 registers the issuer ID and the generated public key, etc. in the blockchain (step S04).

[0052] The terminal 30 stores the received credential certification certificate in the digital wallet. When storing the credential certification certificate in the digital wallet, the terminal 30 performs authentication of the user.

[0053] <Obtaining a Biometric Information Certification Certificate> The user operates the terminal 30 to request the issuance of a biometric information certification certificate from the company, university, etc. to which the user belongs. That is, the company, university, etc. becomes the issuer of the biometric information certification certificate. Here, the case where the user requests the issuance of a biometric information certification certificate regarding "facial image" from the company where the user works will be described. The terminal 30 obtains a biometric information certification certificate regarding a person's face.

[0054] The user's terminal 30 sets the type of the certification document for which issuance is requested as the "biometric information certification document", and sets the "employee number" and "face image" as the information for specifying the object to be certified, respectively, and transmits a "certification document issuance request" regarding the biometric information certification document to the server device 10 (see Fig. 6). Note that, as the information for specifying the object to be certified, the user's name or a combination of the name and date of birth of the user may be used.

[0055] Note that when requesting the issuance of a biometric information certification document, the information for specifying the object to be certified by the biometric information certification document includes the information for specifying the issuer of the biometric information certification document (for example, the employee number) and the type of biometric information for which certification is sought by the biometric information certification document (for example, the face image).

[0056] If the user who wishes to obtain a biometric information certification document is an employee of the company (if there is an employee corresponding to the employee number), the server device 10 generates a biometric information certification document (face information certification document; face VCs) using the face image of the employee. Note that the qualification information body of the biometric information certification document stores the face image obtained at the time of the employee's employment, etc. (the face image registered in the server device 10 after the identity verification at the time of employment).

[0057] The server device 10 transmits the generated biometric information certification document (face information certification document; face VCs) to the terminal 30.

[0058] Upon receiving the biometric information certification document, the terminal 30 performs identity verification of the user. At that time, the terminal 30 acquires the user's biometric information. Specifically, the terminal 30 instructs the user to take a self-portrait and acquires the face image of the user.

[0059] The terminal 30 performs identity verification using the face image obtained from the biometric information certification document and the face image obtained by the self-portrait. When the identity verification is successful, the terminal 30 stores the biometric information certification document (face VCs) in the digital wallet.

[0060] If the identity verification fails, the terminal 30 discards the acquired biometric information certification document.

[0061] In this way, when the terminal 30 obtains a biometric information certificate, it checks whether the biometric information certified by the certificate matches the biometric information of the user (operator) of the terminal 30. When the two biometric information match (when the identity verification is successful), the terminal 30 accepts the biometric information certificate obtained from an organization or group such as a company or a university. As a result, it is possible to prevent a user from obtaining someone else's biometric information certificate and storing the biometric information certificate in their digital wallet. That is, by a simple method of performing identity verification when storing biometric information in the digital wallet, impersonation is prevented. In this way, the terminal 30 stores the biometric information of the digital wallet nominal person in the digital wallet as a biometric information certificate (biometric information certificate issued as a credential certificate).

[0062] <Obtaining a Service Eligibility Certificate> When a biometric information certificate is stored in the digital wallet, the user obtains a credential certificate other than the biometric information certificate. Here, the case where the user obtains a service eligibility certificate regarding a concert ticket from a ticket vendor will be taken as an example for explanation.

[0063] Note that it is assumed that the user has an account with the ticket vendor and has already purchased a ticket in that account. When the user purchases a ticket, a ticket ID for identifying the purchased ticket is issued to the ticket purchaser.

[0064] The user's terminal 30 sets "service eligibility certificate" for the type of certificate to be requested for issuance and "ticket ID" for the information specifying the proof target by the service eligibility certificate, and transmits a "certificate issuance request" regarding the service eligibility certificate to the server device 10 (see FIG. 7).

[0065] If there is a ticket purchased by a user who wishes to obtain a service eligibility certificate (if the ticket ID is valid), the server device 10 generates a service eligibility certificate (ticket certificate) using the purchased ticket information of the ticket purchaser. Note that information regarding the ticket purchased by the user (for example, concert name, concert date and time, concert venue, seat type, etc.) is stored in the eligibility information body of the service eligibility certificate.

[0066] The server device 10 transmits the generated service eligibility certificate (ticket certificate) to the terminal 30.

[0067] Upon receiving the service eligibility certificate (ticket certificate), the terminal 30 performs user authentication. At that time, the terminal 30 acquires the biometric information of the user. Specifically, the terminal 30 instructs the user to take a self - portrait and acquires the face image of the user.

[0068] The terminal 30 performs user authentication using the face image obtained from the biometric information certificate (face VCs) stored in the digital wallet and the face image obtained by the self - portrait. When the user authentication is successful, the terminal 30 stores the service eligibility certificate in the digital wallet.

[0069] When the user authentication fails, the terminal 30 discards the service eligibility certificate.

[0070] In this way, when the terminal 30 obtains the service eligibility certificate, it performs user authentication. By this user authentication, the identity of the user who received the biometric information certificate and the operator of the terminal 30 (the recipient of the service eligibility certificate) is confirmed. As a result, fraud such as a user borrowing another person's terminal 30 and storing the proof certificate (service eligibility certificate) of the ticket they purchased in the digital wallet of the borrowed terminal 30 is prevented. In this way, the terminal 30 stores the service eligibility certificate (service eligibility certificate issued as a credential proof certificate) in the digital wallet in the name of the digital wallet owner.

[0071] <Enjoyment of Service> When a biometric information certificate and a service eligibility certificate are stored in a digital wallet, the user can receive services from service providers. In this case, the user presents to the service provider the certificate required by the service provider or the certificate required by the service provider for providing the service. For example, when trying to enter a concert venue, the user presents a service eligibility certificate (ticket certificate) to the operator of the concert.

[0072] Hereinafter, the operation of the information processing system will be described by taking the case where the user enters a concert venue as an example. Note that an operator terminal 21 is installed at the entrance of the concert venue. An employee of the concert operator or the like operates the operator terminal 21 to determine whether the visitor can enter. The operator terminal 21 and the terminal 30 communicate with each other by means of short-range wireless communication such as Bluetooth (registered trademark).

[0073] When the user wishes to enter the concert venue, the operator terminal 21 requests the terminal 30 to perform identity verification. For example, the operator terminal 21 transmits "identity verification request" to the terminal 30 (step S11 in FIG. 8).

[0074] Upon receiving the identity verification request, the terminal 30 photographs the operator operating the own device to acquire biometric information (face image). The terminal 30 performs identity verification using the acquired biometric information and the biometric information obtained from the biometric information certificate stored in the digital wallet.

[0075] The terminal 30 transmits the identity verification result (identity verification success, identity verification failure) to the operator terminal 21 (step S12).

[0076] Upon receiving the identity verification success, the operator terminal 21 requests the terminal 30 to provide the information (service eligibility certificate) necessary for providing the service to the user.

[0077] Specifically, the business operator terminal 21 sends a "certificate of proof provision request" to the terminal 30 (step S13). The certificate of proof provision request describes information about at least one service entitlement certificate necessary for the service provider to provide the service. For example, the certificate of proof provision request describes information for identifying the service qualification certificate that the service provider requests. For example, when the business operator terminal 21 requests the provision of a ticket certificate, information such as the concert name, concert date and time, and concert venue is included in the certificate of proof provision request.

[0078] In response to receiving the certificate of proof provision request, the terminal 30 sends the certificate of proof (service entitlement certificate) stored in the digital wallet to the business operator terminal 21. Specifically, the terminal 30 selects the specified certificate of proof (service entitlement certificate) from among the multiple certificates of proof stored in the digital wallet.

[0079] After that, the terminal 30 signs the selected service entitlement certificate using the private key corresponding to the user's DID (user ID). The terminal 30 sends the signed service entitlement certificate to the business operator terminal 21 (step S14).

[0080] The business operator terminal 21 verifies the validity of the received service entitlement certificate. At this time, the business operator terminal 21 obtains the public key from the blockchain (step S15). Details regarding the verification of the validity of the service entitlement certificate will be described later.

[0081] If the terminal 30 has successfully authenticated the user and the obtained service entitlement certificate is valid, the business operator terminal 21 provides the service to the user. For example, the business operator terminal 21 notifies the employees of the service provider, etc., that the user can enter the concert venue.

[0082] Regarding the operation of the information processing system when a user receives a service from a service provider, the service provider has described the case of using the business operator terminal 21 as an example. Here, even when the service provider uses the service server 20, the basic operation of the information processing system when a user receives a service from the service provider is the same. The service server 20 requests the terminal 30 to execute identity verification. After that, when the service server 20 receives a notification of successful identity verification, it acquires a service enjoyment qualification certificate necessary for providing the service from the terminal 30.

[0083] In this way, before providing the service enjoyment qualification certificate to the service provider, the terminal 30 executes identity verification using the biometric information certificate stored in the digital wallet. As a result, it is possible to prevent a user who is not eligible to receive the service from fraudulently receiving the service from the service provider by pretending to be eligible to receive the service. That is, by performing simple identity verification at the time of service provision, fraud such as impersonation is prevented.

[0084] Subsequently, details of each device included in the information processing system according to the first embodiment will be described.

[0085] [Terminal] FIG. 9 is a diagram showing an example of the processing configuration (processing module) of the terminal 30 according to the embodiment disclosed in the present application. Referring to FIG. 9, the terminal 30 includes a communication control unit 201, an acquisition control unit 202, a utilization control unit 203, and a storage unit 204.

[0086] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. Also, the communication control unit 201 transmits data to the server device 10. The communication control unit 201 delivers the data received from other devices to other processing modules. The communication control unit 201 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit for receiving data from other devices and a function as a transmitting unit for transmitting data to other devices.

[0087] Note that the communication control unit 201 also supports short-range wireless communication such as Bluetooth (registered trademark) and NFC (Near Field Communication). The communication control unit 201 communicates with the operator terminal 21 using short-range wireless communication.

[0088] The digital wallet application is realized by each module of the acquisition control unit 202 and the utilization control unit 203. Note that a detailed description of the installation of the digital wallet application is omitted. This is because the installation of the digital wallet application is obvious to those skilled in the art.

[0089] The acquisition control unit 202 is a means for controlling the acquisition of credential certificates including biometric information certificates and service enjoyment qualification certificates. The acquisition control unit 202 requests the certificate issuer to issue the certificate selected by the user, and stores the certificate acquired from the certificate issuer in the digital wallet.

[0090] The acquisition control unit 202 has a function as an acquisition means and a function as a confirmation means.

[0091] When obtaining a biometric information certification certificate, the obtaining means acquires, from a certification certificate issuer holding the user's biometric information, a certification certificate that certifies the biometric information of the person to be issued, and that is a biometric information certification certificate including the biometric information of the person to be issued. The confirmation means performs identity verification using the biometric information obtained from the acquired biometric information certification certificate and the user's biometric information.

[0092] When obtaining a service eligibility certification certificate, the obtaining means acquires, from a certification certificate issuer, a service eligibility certification certificate that certifies that the user is eligible to receive the service. The confirmation means performs identity verification using the biometric information obtained from the stored biometric information certification certificate and the user's biometric information in response to the acquisition of the service eligibility certification certificate.

[0093] FIG. 10 is a flowchart showing an example of the operation of the acquisition control unit 202. While referring to FIG. 10, the operation of the acquisition control unit 202 according to the embodiment of the present disclosure will be described.

[0094] When a user who has opened a digital wallet starts a digital wallet application and performs a predetermined operation (for example, pressing a certification certificate issuance button), the acquisition control unit 202 performs control related to the acquisition of a credential certification certificate desired by the user.

[0095] First, the acquisition control unit 202 generates a pair of a public key and a private key, and a user ID (the user's DID), which is a distributed identifier. The acquisition control unit 202 registers the generated user ID and public key in the blockchain (registering the public key, etc.; step S101).

[0096] Subsequently, the acquisition control unit 202 acquires information necessary for a certification certificate issuance request using a GUI or the like (acquisition of necessary information; step S102).

[0097] Specifically, the acquisition control unit 202 acquires information on a credential issuer having the right to issue a credential certificate that the user wishes to issue (for example, company name, university name, ticket vendor name), the type of the desired credential certificate (for example, biometric information credential certificate, service enjoyment qualification certificate), and the like. Further, the acquisition control unit 202 acquires information for the credential issuer to identify the proof target (for example, employee number and face image, ticket ID, etc.).

[0098] The acquisition control unit 202 notifies the credential issuer of the acquired necessary information and the user ID. Specifically, the acquisition control unit 202 notifies the credential issuer of the type of the credential certificate, the information for identifying the proof target, and the user ID.

[0099] The acquisition control unit 202 transmits a "credential certificate issuance request" including the type of the credential certificate, the information for identifying the proof target, the user ID, etc. to the server device 10 of the credential issuer selected by the user (step S103).

[0100] The acquisition control unit 202 receives a response (positive response, negative response) to the credential certificate issuance request from the server device 10 (step S104).

[0101] When receiving a negative response indicating that the issuance of the credential certificate has failed (step S105, No branch), the acquisition control unit 202 notifies the user of the fact that the credential certificate has not been issued (notifies non-issuance; step S106).

[0102] When receiving a positive response indicating that the issuance of the credential certificate has been successful (step S105, Yes branch), the acquisition control unit 202 performs user authentication (step S107).

[0103] When the user wishes to issue a biometric information credential certificate, the acquisition control unit 202 acquires biometric information from the biometric information credential certificate included in the positive response received from the server device 10. That is, the acquisition control unit 202 acquires biometric information (face image) from the qualification information body of the biometric information credential certificate.

[0104] When the user wishes to issue a proof certificate other than the biometric information proof certificate (service eligibility certificate), the acquisition control unit 202 acquires biometric information (face image) from the biometric information proof certificate stored in the digital wallet.

[0105] When acquiring biometric information from the received or stored biometric information proof certificate, the acquisition control unit 202 acquires the biometric information of the user (the operator of the terminal 30). For example, the acquisition control unit 202 prompts the user to take a picture of their own face using a GUI (Graphical User Interface) or the like (i.e., acquires a face image by taking a self-portrait).

[0106] The acquisition control unit 202 performs a matching process (authentication process; one-to-one authentication) using the biometric information obtained from the biometric information proof certificate and the biometric information of the user. The acquisition control unit 202 determines whether the two biometric information substantially matches.

[0107] Specifically, the acquisition control unit 202 generates feature amounts from each of the two face images.

[0108] Regarding the generation process of the feature amounts, existing technologies can be used, so detailed descriptions thereof are omitted. For example, the acquisition control unit 202 extracts eyes, nose, mouth, etc. as feature points from the face image. Thereafter, the acquisition control unit 202 calculates the positions of each feature point and the distances between each feature point as feature amounts (generates a feature vector consisting of a plurality of feature amounts).

[0109] Next, the acquisition control unit 202 performs a matching process (authentication process) using the two generated feature amounts. Specifically, the acquisition control unit 202 calculates the similarity between the corresponding face images using the two feature amounts. The acquisition control unit 202 determines whether the two images are face images of the same person based on the result of the threshold process for the calculated similarity. Note that, for the similarity, the chi-square distance, the Euclidean distance, or the like can be used. The farther the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0110] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the acquisition control unit 202 determines that the personal verification has been successful. If the similarity is equal to or less than the predetermined value, the acquisition control unit 202 determines that the personal verification has failed.

[0111] When the personal verification fails (branching to No in step S108), the acquisition control unit 202 notifies the user that the credential certificate cannot be stored in the digital wallet (notifies non-storage; step S109). In addition, the acquisition control unit 202 discards the acquired credential certificate (biometric information certificate, service entitlement certificate). When the credential certificate is discarded, the acquisition control unit 202 may notify the server device 10, which is the sender of the credential certificate, to that effect.

[0112] When the personal verification is successful (branching to Yes in step S108), the acquisition control unit 202 stores the credential certificate (biometric information certificate, service entitlement certificate) received from the certificate issuer in the digital wallet (step S110).

[0113] The usage control unit 203 is a means for performing control regarding the usage of the digital content (credential certificate) stored in the digital wallet.

[0114] The usage control unit 203 executes personal verification using the biometric information obtained from the biometric information certificate stored in the digital wallet, and when the personal verification is successful, provides the stored service entitlement certificate to the service provider, and has a function as a providing means.

[0115] The usage control unit 203 executes personal verification in response to a request from the service provider, and provides the credential certificate specified by the service provider among the credential certificates stored in the digital wallet.

[0116] Specifically, the usage control unit 203 processes the personal verification request and the credential certificate providing request received from the device of the service provider (service server 20, operator terminal 21).

[0117] When the use control unit 203 receives the self-identification request, it acquires the biometric information (e.g., face image) of the operator of the own device using a GUI or the like. The use control unit 203 captures the face of the operator by so-called self-photography.

[0118] The use control unit 203 performs self-identification using the acquired biometric information and the biometric information obtained from the biometric information certificate stored in the digital wallet. The use control unit 203 performs self-identification in the same manner as the acquisition control unit 202.

[0119] The use control unit 203 notifies the business operator terminal 21 or the like of the self-identification result (self-identification success, self-identification failure). In the case of successful self-identification, the use control unit 203 transmits an affirmative response indicating that fact to the business operator terminal 21 or the like. In the case of failed self-identification, the use control unit 203 transmits a negative response indicating that fact to the business operator terminal 21 or the like.

[0120] In this way, the use control unit 203 performs self-identification using the biometric information obtained from the previously acquired biometric information certificate and the biometric information of the operator who operates the own device in response to a request from the service provider.

[0121] When receiving the certificate provision request, the use control unit 203 selects the credential certificate (service enjoyment qualification certificate) specified by the service provider from among the plurality of credential certificates stored in the digital wallet. Then, the use control unit 203 signs the selected service enjoyment qualification certificate using the private key corresponding to the user's DID (user ID).

[0122] Note that the use control unit 203 signs the service enjoyment qualification certificate using the private key (private key corresponding to the user ID) generated at the time of issuance of the service enjoyment qualification certificate requested to be provided by the service provider. For example, when the user enters a concert venue, the use control unit 203 signs the ticket certificate (service enjoyment qualification certificate) using the private key corresponding to the user ID transmitted to the server device 10 of the ticket vendor.

[0123] If a service eligibility certificate specified by the service provider is available, the usage control unit 203 transmits an affirmative response including the signed service eligibility certificate to the operator terminal 21 or the like. If the service eligibility certificate specified by the service provider cannot be provided, the usage control unit 203 transmits a negative response indicating the unavailability of the service eligibility certificate to the operator terminal 21 or the like.

[0124] The storage unit 204 is a means for storing information necessary for the operation of the terminal 30. The storage unit 204 stores the certification certificates issued by each certification certificate issuer in a digital wallet.

[0125] When the acquisition control unit 202 determines that the identity verification is successful, the storage unit 204 stores the biometric information certification certificate acquired by the acquisition control unit 202. When the acquisition control unit 202 determines that the identity verification is successful, the storage unit 204 stores the service eligibility certificate acquired by the acquisition control unit 202.

[0126] In this way, the storage unit 204 stores a certification certificate that proves that it is the biometric information of the certificate holder, a biometric information certification certificate including the biometric information of the certificate holder, and a service eligibility certificate that proves that the user holds the qualification to receive the service.

[0127] Furthermore, the storage unit 204 stores information of each certification certificate issuer (name of the certification certificate issuer, address of the server device 10, etc.).

[0128] [Server device] FIG. 11 is a diagram showing an example of the processing configuration (processing module) of the server device 10 according to the embodiment disclosed in the present application. Referring to FIG. 11, the server device 10 includes a communication control unit 301, a certification certificate issuing unit 302, and a storage unit 303.

[0129] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 30. Also, the communication control unit 301 transmits data to the terminal 30. The communication control unit 301 delivers the data received from other devices to other processing modules. The communication control unit 301 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0130] The credential issuance unit 302 is a means for issuing a credential certificate to the user. The credential issuance unit 302 processes the "credential issuance request" received from the terminal 30.

[0131] Upon receiving the credential issuance request, the credential issuance unit 302 searches a database (not shown in FIG. 11 etc.) that stores user information using, as a key, information (e.g., employee number, face image, ticket ID) for specifying the proof target included in the credential issuance request.

[0132] If the above search fails (e.g., the corresponding user's face image is not registered in the database, the corresponding ticket ID does not exist), the credential issuance unit 302 transmits a negative response indicating issuance failure to the terminal 30.

[0133] If the above search is successful, the credential issuance unit 302 determines, as necessary, whether it is possible to issue the credential certificate that the user wishes to issue.

[0134] For example, when issuance of a biometric information certificate is requested, the credential issuance unit 302 determines that it is not possible to issue a biometric information certificate for a face image that has not been updated for a long time. Note that the credential issuance unit 302 may determine that it is possible to issue a biometric information certificate if a face image is registered in the database regardless of the registration period of the face image.

[0135] Alternatively, if the ticket purchased by the ticket purchaser is valid (for example, before the concert is held), the certification document issuing unit 302 determines that it is possible to issue a ticket certification document (service entitlement certificate). On the other hand, if the concert has already been held, the certification document issuing unit 302 determines that it is not possible to issue a ticket certification document.

[0136] Note that detailed descriptions regarding the management of employees, tickets, etc. are omitted. This is because the detailed descriptions regarding the management of employees, tickets, etc. are different from the gist of the present disclosure.

[0137] If it is not possible to issue a credential certification document to the user, the certification document issuing unit 302 transmits a negative response indicating a failure in issuing the certification document (inability to issue the certification document) to the terminal 30.

[0138] If it is possible to issue a credential certification document to the user, the certification document issuing unit 302 generates a certification document (credential certification document; for example, biometric information certification document, service entitlement certificate) to be issued to the user. The certification document issuing unit 302 generates a credential certification document including the issuer ID and the user ID (DID of the certificate recipient of the certification document; user ID included in the certification document issuance request).

[0139] Specifically, the certification document issuing unit 302 generates a credential certification document (VCs) including metadata such as the type of the credential certification document, the name of the issuing organization, the issue date and time, the expiration period, etc., the qualification information body, and the public key information and electronic signature of the issuer. Note that the electronic signature attached to the credential certification document is performed using the private key corresponding to the pre-generated issuer ID.

[0140] The certification document issuing unit 302 transmits the generated credential certification document to the terminal 30. Further, the certification document issuing unit 302 registers the pre-generated issuer ID, public key, etc. on the blockchain.

[0141] The storage unit 303 is a means for storing information necessary for the operation of the server device 10. A database that stores information necessary for issuing a credential certificate (for example, an employee number, a face image, etc. of an employee) is constructed in the storage unit 303.

[0142] [Business Operator Terminal] FIG. 12 is a diagram showing an example of a processing configuration (processing module) of the business operator terminal 21 according to an embodiment of the present disclosure. Referring to FIG. 12, the business operator terminal 21 includes a communication control unit 401, a service provision control unit 402, and a storage unit 403.

[0143] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the terminal 30. Also, the communication control unit 401 transmits data to the terminal 30. The communication control unit 401 delivers the data received from other devices to other processing modules. The communication control unit 401 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0144] The service provision control unit 402 is a means for executing control related to services provided to users.

[0145] When a user desires the provision of a service, the service provision control unit 402 requests the terminal 30 to authenticate the user. When the user authentication is successful, the service provision control unit 402 acquires a proof certificate (for example, a ticket proof certificate) necessary for the provision of the service.

[0146] While referring to FIG. 13, the operation of the service provision control unit 402 will be described.

[0147] The service provision control unit 402 sends an identity verification request to the user's terminal 30 (step S201). The service provision control unit 402 requests the implementation of identity verification for the terminal 30 according to the operations of employees of the service provider, etc.

[0148] When a negative response (identity verification failed) is received from the terminal 30 (step S202, No branch), the service provision control unit 402 notifies the user, employees of the service provider, etc. that the service cannot be provided because the identity verification has failed (step S203).

[0149] When an affirmative response (identity verification successful) is received from the terminal 30 (step S202, Yes branch), the service provision control unit 402 acquires the information (service entitlement certificate) necessary to provide the service to the user.

[0150] Specifically, the service provision control unit 402 sends a "certificate of proof provision request" to the terminal 30 (step S204). The service provision control unit 402 sends a certificate of proof provision request including information for specifying the required service entitlement certificate (for example, when a ticket certificate is required for service provision, information such as the concert name, concert date and time, etc.) to the terminal 30.

[0151] When a negative response (unable to provide certificate of proof) is received from the terminal 30 (step S205, No branch), the service provision control unit 402 notifies the user, etc. that the service cannot be provided because the necessary information cannot be acquired (step S203).

[0152] When an affirmative response (response including service entitlement certificate) is received from the terminal 30 (step S205, Yes branch), the service provision control unit 402 verifies the validity of the service entitlement certificate included in the affirmative response (verify validity; step S206).

[0153] The service provision control unit 402 verifies at least one or more of four items regarding the validity of the service entitlement certificate.

[0154] The first item is the verification of the electronic signature attached to the service entitlement certificate.

[0155] In this case, the service provision control unit 402 acquires the issuer ID and the user ID described in the service entitlement certificate. The service provision control unit 402 acquires the public key corresponding to the acquired issuer ID from the blockchain. Similarly, the service provision control unit 402 acquires the public key corresponding to the acquired user ID from the blockchain.

[0156] The service provision control unit 402 verifies the signature of the holder (user who wishes to receive the service) and the signature of the issuer attached to the service entitlement certificate. By verifying these signatures, the service provision control unit 402 confirms that the service entitlement certificate acquired from the user (holder of the service entitlement certificate) has not been forged and that it is a certification certificate issued by a reliable issuer.

[0157] When the service provision control unit 402 successfully verifies the signatures of the holder and the issuer of the service entitlement certificate, it determines that the service entitlement certificate is valid.

[0158] The second item is the verification that the service entitlement certificate has not been set to invalid.

[0159] In this case, the service provision control unit 402 accesses the blockchain and confirms that the received service entitlement certificate is not listed in the revocation list of the certification certificate issuer. The service provision control unit 402 confirms that the service entitlement certificate has not been invalidated by the issuer before the expiration date of the service entitlement certificate acquired from the user.

[0160] If the service entitlement certificate is not listed in the revocation list, the service provision control unit 402 determines that the acquired service entitlement certificate is valid.

[0161] The third item is the verification that the validity period (expiration date) of the service entitlement certificate has not expired.

[0162] The service provision control unit 402 checks the validity period set for the service entitlement certificate. If the validity period set for the service entitlement certificate has not expired, the service provision control unit 402 determines that the obtained service entitlement certificate is valid.

[0163] The fourth item is the verification of the qualification information certified by the service entitlement certificate.

[0164] In this case, the service provision control unit 402 reads out the qualification information (for example, ticket information) from the qualification information body included in the service entitlement certificate, and determines whether the user has the right (qualification) to receive the service based on the qualification information.

[0165] For example, if the concert date and time and concert venue obtained from the ticket information are correct, the service provision control unit 402 determines that the user has the right to receive the service (the qualification to enter the concert venue). On the other hand, if the concert date and time or concert venue obtained from the ticket information are incorrect, the service provision control unit 402 determines that the user does not have the right to receive the service (the qualification to enter the concert venue).

[0166] If the user has the right to receive the service, the service provision control unit 402 determines that the obtained service entitlement certificate is valid.

[0167] According to the business and business type of its own company (service provider), when it is determined that the service entitlement certificate is "valid" in a predetermined item among the first to fourth items, the service provision control unit 402 determines that the service entitlement certificate obtained from the user is valid.

[0168] For example, when it is determined that the "service entitlement certificate is valid" for each of the four items, the service provision control unit 402 determines that the acquired service entitlement certificate is valid (accepts the service entitlement certificate). Alternatively, the service provision control unit 402 may determine that the acquired service entitlement certificate is valid when it is determined that the "service entitlement certificate is valid" for two items, namely, the first item and the fourth item.

[0169] When the service entitlement certificate is not valid (branching to No in step S207), the service provision control unit 402 notifies the user or the like that the service cannot be provided because the service entitlement certificate is invalid (step S203).

[0170] When the service entitlement certificate is valid (branching to Yes in step S207), the service provision control unit 402 provides the service to the user (step S208).

[0171] For example, the service provision control unit 402 notifies the user or an employee of the service provider that they can enter the concert venue.

[0172] Note that more detailed descriptions regarding individual service provisions are omitted. This is because detailed descriptions of services specific to each service provider are different from the gist of the present disclosure.

[0173] The storage unit 403 is a means for storing information necessary for the operation of the operator terminal 21.

[0174] [Service Server] A detailed description of the configuration and operation of the service server 20 will be omitted. The basic configuration and operation of the service server 20 can be the same as those of the operator terminal 21. The operator terminal 21 communicates with the terminal 30 by short-range wireless communication such as Bluetooth (registered trademark) to obtain a credential certificate. On the other hand, the service server 20 communicates with the terminal 30 via a communication network such as the Internet to obtain a credential certificate. When the terminal 30 successfully authenticates the user and successfully verifies the validity of the credential certificate (service eligibility certificate) required for providing the service, the service server 20 provides the service to the user.

[0175] [Operation of the System] Subsequently, the operation of the information processing system according to the first embodiment will be described.

[0176] FIG. 14 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment disclosed in the present application. Referring to FIG. 14, the operation related to the issuance of a proof certificate in the information processing system according to the first embodiment will be described.

[0177] The terminal 30 generates a public key, a private key, and a user ID, and registers the user ID and the public key in the blockchain (step S21).

[0178] The terminal 30 transmits a proof certificate issuance request including the above user ID to the server device 10 of the proof certificate issuer (step S22).

[0179] The server device 10 generates qualification information of the user (the person to whom the credential certificate is to be issued), and generates a credential certificate including the generated qualification information. The server device 10 generates a credential certificate including the user ID and the issuer ID and signed with an electronic signature.

[0180] The server device 10 transmits the generated credential certificate to the terminal 30 (step S24).

[0181] The terminal 30 performs an identity verification (step S25).

[0182] When receiving a biometric information certification certificate, the terminal 30 performs an identity verification using the biometric information described in the received biometric information certification certificate and the biometric information certification certificate obtained by self - photography. When receiving a service entitlement certification certificate, the terminal 30 performs an identity verification using the biometric information described in the biometric information certification certificate stored internally and the biometric information certification certificate obtained by self - photography.

[0183] When the identity verification is successful, the terminal 30 stores the credential certification certificate in the digital wallet (step S26).

[0184] FIG. 15 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. Referring to FIG. 15, the operation regarding the use of the certification certificate of the information processing system according to the first embodiment will be described.

[0185] The device of the service provider (in FIG. 15, the business operator terminal 21) transmits an identity verification request to the terminal 30 (step S31).

[0186] The terminal 30 performs an identity verification using the biometric information obtained from the biometric information certification certificate stored in its own device and the biometric information obtained by photographing the operator of its own device, and transmits the identity verification result to the server device 10 (step S32).

[0187] When receiving the success of the identity verification, the business operator terminal 21 transmits a certification certificate providing request for specifying the necessary service entitlement certification certificate to the terminal 30 (step S33).

[0188] The terminal 30 reads out the service entitlement certification certificate specified by the service provider from the digital wallet and transmits the signed service entitlement certification certificate to the business operator terminal 21 (step S34).

[0189] The business operator terminal 21 determines the validity of the obtained service entitlement certification certificate (step S35).

[0190] If the service entitlement certificate is valid, the service provider terminal 21 provides the service to the user (step S36).

[0191] Subsequently, a modification of the first embodiment will be described.

[0192] <Modification 1> The terminal 30 may authenticate the user at the first use of the digital wallet or the like. In this case, the terminal 30 includes an authentication unit 205 (see FIG. 16).

[0193] The authentication unit 205 is a means for authenticating the person who opened the digital wallet. The authentication unit 205 authenticates the person who opened the digital wallet by using the biometric information obtained from the identity certificate and the biometric information of the person who opened the digital wallet. More specifically, the authentication unit 205 confirms that the name of the person who opened the digital wallet is the same as the name of the person (the person to whom the certificate is issued) of the identity certificate issued by a public institution.

[0194] The authentication unit 205 acquires biometric information from the identity certificate held by the user at the time of opening (first startup) of the digital wallet or at an arbitrary timing. For example, the authentication unit 205 acquires biometric information from an IC (Integrated Circuit) chip mounted on a My Number card or a passport. Alternatively, the authentication unit 205 may instruct the user to photograph the identity certificate and acquire biometric information from the image data in which the identity certificate is captured.

[0195] Furthermore, the authentication unit 205 acquires the biometric information of the user. For example, the authentication unit 205 acquires a face image by taking a self-portrait.

[0196] The personal verification unit 205 acquires biometric information from the identity certificate, and when acquiring the biometric information of the user who operates the own device, performs personal verification using the two biometric informations. When the personal verification is successful, the personal verification unit 205 treats that the person named in the issued identity certificate and the user of the terminal 30 are the same person, and permits the user to use the digital wallet.

[0197] Note that the terminal 30 may generate a biometric information certificate using the biometric information acquired at the time of opening the digital wallet or the like. In this case, the personal verification unit 205 delivers the biometric information acquired from the identity certificate or the biometric information obtained by self-photographing to the acquisition control unit 202. The acquisition control unit 202 generates a biometric information certificate using the biometric information and stores it in the digital wallet. Thus, when the personal verification using the identity certificate is successful, the terminal 30 may generate a biometric information certificate using the biometric information obtained from the identity certificate or the biometric information obtained by self-photographing.

[0198] Alternatively, the terminal 30 may transmit the biometric information acquired from the identity certificate at the time of opening the digital wallet or the like to the server device 10, and request the server device 10 to issue a biometric information certificate using the biometric information acquired from the identity certificate. Specifically, the terminal 30 transmits a certificate issuance request including the biometric information acquired from the identity certificate to the server device 10. In response to receiving the certificate issuance request, the server device 10 generates a biometric information certificate using the biometric information obtained from the identity certificate. The server device 10 transmits the generated biometric information certificate to the terminal 30. Thus, instead of the biometric information held by an organization such as a company or a university, a biometric information certificate may be issued using the biometric information read by the terminal 30 from an official identity certificate or the like according to the operation of the user.

[0199] <Modification Example 2> In the above embodiment, the case where the terminal 30 stores the biometric information described in the biometric information certificate acquired from a company or the like in the digital wallet has been described. However, the terminal 30 may store the biometric information obtained from an identity certificate such as a my number card or a passport in the digital wallet.

[0200] When the acquisition control unit 202 receives a biometric information certificate from the server device 10 of an enterprise or the like, it acquires the biometric information (face image) included in the biometric information certificate. The acquisition control unit 202 performs a one-to-one comparison using the biometric information (biometric information obtained from an identity certificate issued by a public institution) stored at the time of opening the digital wallet and the biometric information obtained from the biometric information certificate.

[0201] When the one-to-one comparison is successful (when the two biometric information is substantially the same), the acquisition control unit 202 stores the biometric information certificate in the digital wallet.

[0202] Alternatively, when the usage control unit 203 of the terminal 30 is requested by the service provider to perform identity verification, it may perform identity verification using the biometric information obtained from the identity certificate (biometric information stored at the time of opening the digital wallet).

[0203] <Modification Example 3> The server device 10 that has received a request for issuing a biometric information certificate may perform identity verification of the user. When requesting the issuance of a biometric information certificate, the terminal 30 transmits, for example, a certificate issuance request including image data showing the identity certificate held by the user to the server device 10.

[0204] The certificate issuance unit 302 of the server device 10 extracts biometric information from the image data showing the identity certificate. The certificate issuance unit 302 performs a one-to-one comparison using the extracted biometric information and the biometric information (biometric information of employees or the like specified by employee numbers or the like) managed in its own database.

[0205] When the one-to-one comparison is successful (when the two biometric information is substantially the same), the certificate issuance unit 302 issues a biometric information certificate using any one of the two biometric information.

[0206] <Modification Example 4> When providing services to users, the service provider may obtain a biometric information certificate from the terminal 30. For example, when selling tickets, a ticket vendor may obtain a biometric information certificate.

[0207] In this case, the service server 20 of the ticket vendor designates the biometric information certificate as the certificate required for service provision and sends a certificate provision request to the terminal 30.

[0208] The service server 20 obtains the biometric information certificate from the terminal 30 by sending the certificate provision request. The service server 20 checks the validity of the obtained biometric information certificate. After checking the validity of the biometric information certificate, the service server 20 obtains biometric information (e.g., face image) from the certificate. The service server 20 stores the obtained face image. For example, the service server 20 of the ticket vendor stores the ticket information and the face image in association with each other in the user's account.

[0209] The service server 20 can provide services to users by utilizing the obtained biometric information. For example, the service server 20 may issue a ticket with an attached face image.

[0210] Also, when the ticket vendor acts as the certificate issuer of the ticket certificate, the service server 20 operates as the server device 10. In this case, the service server 20 (server device 10) may issue a ticket certificate (service enjoyment qualification certificate) including the face image of the ticket purchaser in the qualification information to the user.

[0211] When obtaining a ticket certificate (service enjoyment qualification certificate including face information) with a face image (face information), the acquisition control unit 202 of the terminal 30 may perform identity verification using the biometric information obtained from the ticket certificate with the face information and the biometric information obtained by taking a self - portrait. If the identity verification is successful, the acquisition control unit 202 may store the ticket certificate with the face information in the digital wallet.

[0212] Alternatively, after obtaining a ticket proof certificate from a ticket vendor (the server device 10 of the vendor), the user may provide a biometric information proof certificate to the ticket vendor. After successfully verifying the validity of the obtained biometric information proof certificate, the service server 20 may store the biometric information included in the biometric information proof certificate in an account.

[0213] <Modification Example 5> In the above embodiment, it has been explained that the identity verification result is provided from the user to the service provider by means of communication such as the Internet or Bluetooth (registered trademark). However, the identity verification result may be provided from the user to the service provider (the operator terminal 21) by screen display by the terminal 30.

[0214] For example, when providing a service to a user, an employee of the service provider or the like informs the user that identity verification is required to receive the service (verbally). The user operates the terminal 30 to perform a predetermined operation (for example, pressing an identity verification button). The terminal 30 executes the identity verification described above according to the user's operation.

[0215] The terminal 30 displays the identity verification result (identity verification successful, identity verification failed). An employee of the service provider or the like checks the displayed identity verification result and determines whether to continue providing the service to the user.

[0216] Alternatively, when the identity verification is successful, the terminal 30 may display the biometric information (face image) used for the identity verification together with the identity verification result (see FIG. 17). In that case, the terminal 30 may employ a screen shot prevention and discrimination mechanism such as a countdown timer. By such an operation of the terminal 30, it is possible to prevent the unauthorized use of the terminal 30 by a person to whom a user who has successfully passed the identity verification has handed over the terminal 30.

[0217] <Modification Example 6> Not only the confirmation result of the user himself / herself, but also the service eligibility certificate (credential certificate) may be provided from the user to the service provider by means different from communication means such as the Internet or Bluetooth (registered trademark). For example, the service eligibility certificate may be provided from the user (terminal 30) to the service provider (operator terminal 21) using means such as a two-dimensional barcode (see FIG. 18).

[0218] For example, when the confirmation of the user himself / herself is successful, an employee of the service provider or the like tells the user the certificate necessary to receive the service. The user operates the terminal 30 to select the transmitted service eligibility certificate (ticket certificate). The terminal 30 signs the selected service eligibility certificate and converts the signed service eligibility certificate into a two-dimensional barcode. The terminal 30 displays the two-dimensional barcode.

[0219] An employee of the service provider or the like operates the operator terminal 21 to read the two-dimensional barcode and obtains the service eligibility certificate by decoding the two-dimensional barcode.

[0220] <Modification Example 7> When the terminal 30 of the user receives a confirmation request for the user himself / herself from the device (service server 20, operator terminal 21) of the service provider, it may determine the validity of the biometric information certificate (biometric information certificate stored in the digital wallet) that reads the biometric information.

[0221] The terminal 30 of the user may determine that the expiration date of the biometric information certificate used for user confirmation has not passed and that the biometric information certificate is not registered in the invalidation list. If the biometric information certificate is valid, the terminal 30 may read the biometric information from the certificate and execute user confirmation.

[0222] In this way, the usage control unit 203 of the terminal 30 may verify the validity of the biometric information certificate stored in the digital wallet and execute user confirmation when the stored biometric information certificate is valid.

[0223] <Modification Example 8> In the above embodiment, the case where the service provider verifies the validity of the service entitlement certificate acquired from the user has been described. Here, all or part of the verification of the validity of the service entitlement certificate may be executed on the terminal 30.

[0224] For example, among the four verification items, the terminal 30 may confirm that the service entitlement certificate specified by the service provider is not registered in the invalid list and that the validity period of the service entitlement certificate has not expired. If the terminal 30 fails these verifications, it may notify the service provider (the business operator terminal 21, the service server 20) that it cannot provide the service entitlement certificate specified by the service provider. Specifically, when the terminal 30 fails the above verification, it may send a negative response to the certificate providing request.

[0225] In this way, the usage control unit 203 may verify the validity of the service entitlement certificate stored in the digital wallet and provide the service entitlement certificate to the service provider when the stored service entitlement certificate is valid.

[0226] Alternatively, the usage control unit 203 may notify the service provider of the result of determining the validity of the service entitlement certificate (ticket certificate) (the service entitlement certificate is valid or invalid). The usage control unit 203 may notify the service provider of the determination result using short-range wireless communication means such as Bluetooth (registered trademark). Alternatively, the usage control unit 203 may notify the service provider of the determination result of the validity of the service entitlement certificate by screen display or the like. For example, the usage control unit 203 may make a display as shown in FIG. 19. The user presents the terminal 30 with the display as shown in FIG. 19 to an employee of the service provider or the like. In this way, the terminal 30 may determine the validity of the service entitlement certificate and notify the service provider of the result. Further, as shown in FIG. 19, the terminal 30 may notify the service provider of the result of the identity verification and the result of the validity determination of the service entitlement certificate at the same time.

[0227] <Modification Example 9> In the above embodiment, the case where the service provider (service server 20, business operator terminal 21) requests the terminal 30 to provide a service eligibility certificate after requesting the terminal 30 to perform identity verification has been described. However, the device of the service provider (service server 20, business operator terminal 21) may request the terminal 30 to submit the identity verification result and the service eligibility certificate simultaneously.

[0228] Specifically, the business operator terminal 21 or the like does not send an identity verification request, but sends a proof certificate provision request to the terminal 30. The terminal 30 that receives the proof certificate provision request performs identity verification of the user. When the identity verification is successful, the terminal 30 sends the service eligibility certificate specified by the service provider to the business operator terminal 21 or the like.

[0229] In this way, even if the terminal 30 is not explicitly requested to perform identity verification by the service provider (service server 20, business operator terminal 21), the terminal 30 may perform identity verification using the biometric information obtained from the biometric information proof certificate. When the identity verification is successful, the terminal 30 provides the service eligibility certificate specified by the service provider to the service provider.

[0230] <Modification Example 10> In the above embodiment, it has been described that the user's identity verification is performed by the terminal 30. However, the identity verification may be performed by the device of the service provider (service server 20, business operator terminal 21).

[0231] In this case, the business operator terminal 21 or the like sends a "biometric information provision request" to the terminal 30 instead of an identity verification request.

[0232] Upon receiving the biometric information provision request, the terminal 30 sends the biometric information obtained from the biometric information proof certificate and the biometric information obtained by the user's self - photography to the business operator terminal 21 or the like.

[0233] Alternatively, the terminal 30 may send the biometric information proof certificate stored in the digital wallet and the biometric information obtained by self - photography to the business operator terminal 21 or the like.

[0234] The operator terminal 21 and the like execute identity verification using the two pieces of biometric information obtained. When the identity verification is successful, the operator terminal 21 requests the terminal 30 to provide a service eligibility certificate.

[0235] Alternatively, when the service is provided by the operator terminal 21, the operator terminal 21 may capture an image of the user (the holder of the terminal 30) to obtain biometric information. In this case, the terminal 30 may transmit the biometric information certificate (or the biometric information obtained from the certificate) stored in the digital wallet to the operator terminal 21 in response to the biometric information provision request received from the operator terminal 21.

[0236] The operator terminal 21 may execute identity verification using the face image obtained by photographing the user in front and the face image of the biometric information certificate obtained from the terminal 30. After the identity verification is successful, the operator terminal 21 transmits a certificate provision request to the terminal 30.

[0237] Alternatively, the terminal 30 may display the biometric information (face image) described in the biometric information certificate in response to the reception of the biometric information provision request. An employee of the service provider or the like may perform identity verification by comparing the face image displayed on the display of the terminal 30 with the face of the user in front.

[0238] <Modification Example 11> When the acquisition control unit 202 of the terminal 30 acquires a biometric information certificate from the certificate issuer, the acquisition control unit 202 may determine the validity of the acquired biometric information certificate. When the acquired biometric information certificate is valid, the acquisition control unit 202 may store the acquired biometric information certificate in the digital wallet. For example, when the expiration date of the acquired biometric information certificate has not passed and the biometric information certificate is not registered in the invalidation list, the acquisition control unit 202 may accept the biometric information certificate received from the server device 10.

[0239] As described above, when the terminal 30 according to the first embodiment acquires a biometric information certificate, it performs identity verification using the biometric information proven by the certificate and the biometric information of the user (operator) of the terminal 30. When the identity verification is successful, the terminal 30 accepts the biometric information certificate acquired from the certificate issuer. As a result, even if the user operates their own terminal 30 to request the issuance of a biometric information certificate of another person and acquires the biometric information certificate of the other person, the biometric information certificate of the other person will not be stored in the terminal 30. That is, since the biometric information of the user of the terminal 30 and the biometric information of the biometric information certificate of another person are different, fraud in which the user stores the biometric information certificate of another person in their own digital wallet is prevented.

[0240] Also, when the terminal 30 acquires a service eligibility certificate from the certificate issuer, it performs identity verification using the biometric information certificate acquired in advance. By this identity verification, the identity of the user who received the issuance of the biometric information certificate and the user of the terminal 30 is confirmed. As a result, fraud such as a user borrowing another person's terminal 30 and storing the proof certificate (service eligibility certificate) of the ticket they purchased in the digital wallet of the borrowed terminal 30 is prevented.

[0241] Furthermore, when the user receives a service, the terminal 30 performs identity verification using the biometric information certificate stored in the digital wallet. When the identity verification is successful, the terminal 30 provides the service eligibility certificate to the service provider. As a result, it is prevented that a user who is not eligible to receive the service borrows a terminal 30 in which the service eligibility certificate of another person is stored from another person and receives the service from the service provider. In this way, the terminal 30 prevents unauthorized use (impersonation) of the service eligibility certificate stored in the digital wallet by performing identity verification.

[0242] [Second Embodiment] Subsequently, the second embodiment will be described in detail with reference to the drawings.

[0243] In the second embodiment, the omission of identity verification using biometric information obtained from a biometric information certificate will be described. When presenting a service eligibility certificate, the terminal 30 according to the second embodiment provides a simple identity verification method (identity verification alternative method) that substitutes for identity verification using a biometric information certificate.

[0244] Note that since the configuration of the authentication system according to the second embodiment can be the same as that of the first embodiment, the description corresponding to FIG. 3 is omitted. Also, since the processing configurations of the server device 10, the operator terminal 21, the terminal 30, etc. according to the second embodiment can be the same as those of the first embodiment, the description thereof is omitted.

[0245] Hereinafter, the description will focus on the differences between the first embodiment and the second embodiment.

[0246] When the terminal 30 is frequently requested for identity verification by the service provider, instead of performing identity verification (regular identity verification) using a biometric information certificate in response to the request, the terminal 30 may perform other simple identity verification. By performing simple identity verification, the terminal 30 may omit regular identity verification using biometric information.

[0247] As an example of simple identity verification, identity verification using a password is exemplified. For example, consider a case where a password necessary to unlock the terminal 30 is set in the terminal 30.

[0248] When an identity verification request is received from the service provider, the usage control unit 203 of the terminal 30 determines whether a predetermined condition (identity verification omission condition) for omitting regular identity verification is satisfied.

[0249] For example, an example of the identity verification omission condition is "after successful regular identity verification, an identity verification request is received from the same service provider within a predetermined period". For example, within one hour after successful identity verification, regular identity verification can be omitted for an identity verification request from the same service provider.

[0250] Note that the devices of the service provider according to the second embodiment (service server 20, operator terminal 21) notify the terminal 30 of the operator ID for identifying the service provider when a personal confirmation request or a proof document provision request is made. The terminal 30 determines whether a personal confirmation has been requested from the same service provider using the operator ID.

[0251] When a personal confirmation is requested from the service provider, the usage control unit 203 of the terminal 30 performs a regular personal confirmation and notifies the service provider to that effect if the personal confirmation is successful. After that, if a personal confirmation is requested from the same service provider before a predetermined time has elapsed since the success of the regular personal confirmation, the usage control unit 203 omits the regular personal confirmation.

[0252] Instead of the regular personal confirmation, the usage control unit 203 performs another simple personal confirmation. For example, the usage control unit 203 performs a personal confirmation by inputting a password (see Fig. 20). When the password authentication using the password is successful, the usage control unit 203 notifies the service provider of the success of the personal confirmation.

[0253] In this way, the usage control unit 203 has a function as a confirmation means of performing a first personal confirmation using biometric information obtained from a biometric information proof document in response to a personal confirmation request from the service provider and notifying the service provider of the result of the first personal confirmation. When the service provider requests a personal confirmation again, the usage control unit 203 (confirmation means) performs a second personal confirmation different from the first personal confirmation and notifies the service provider of the result of the second personal confirmation.

[0254] The usage control unit 203 can perform a second personal confirmation instead of the first personal confirmation when a predetermined condition is satisfied. For example, the usage control unit 203 may perform a second personal confirmation instead of the first personal confirmation when a request for performing a personal confirmation is made again from the service provider before a predetermined time has elapsed since the success of the first personal confirmation.

[0255] Alternatively, as a simple authentication of the user, authentication using a biometric authentication device provided in the terminal 30 is exemplified. For example, a fingerprint reading device can be used as another simple user authentication. For example, fingerprint authentication may be applied to unlock the terminal 30. In this case, when the same service provider requests user authentication before a predetermined time has elapsed since successful normal user authentication using the biometric information authentication certificate, the usage control unit 203 performs user authentication by fingerprint authentication in the same manner as when a password is set in the terminal 30.

[0256] Note that various conditions can be set for the conditions (user authentication omission conditions) for the usage control unit 203 to perform other simple user authentications. For example, as described above, when user authentication is requested before a predetermined time (for example, one hour) has elapsed since successful user authentication using the biometric information authentication certificate, other simple user authentications may be performed.

[0257] Alternatively, a period during which the original user authentication can be omitted may be set according to the number of successful user authentications using the biometric information authentication certificate during a predetermined period. For example, if user authentication using the biometric information authentication certificate is successful three or more times within three hours, the usage control unit 203 may perform simple user authentication for one hour from the third successful user authentication (normal user authentication is omitted for one hour).

[0258] Alternatively, the usage control unit 203 may change the number of successful user authentications using the biometric information authentication certificate during the above-mentioned predetermined period for omitting normal user authentication according to the service provider. For example, a setting may be made such that the number of times for omitting normal user authentication for Service A is "3" and the number of times for omitting normal user authentication for Service B is "5".

[0259] In this way, the usage control unit 203 may perform a second user authentication instead of the first user authentication in a second period determined according to the number of the first user authentications successful in the first period. In this case, the number of successful first user authentications in the first period for setting the second period may be determined for each of the plurality of service providers.

[0260] Alternatively, conditions for omitting formal identity verification (identity verification omission conditions) may be notified from the service provider to the terminal 30. For example, when the business operator terminal 21 sends an identity verification request to the terminal 30, the identity verification omission conditions may be notified to the terminal 30.

[0261] <Specific Example> The operation of the information processing system according to the second embodiment will be specifically described.

[0262] For example, as shown in FIG. 21, a business operator terminal 21-1 is installed at the entrance of the concert hall. Also, a business operator terminal 21-2 is installed at the souvenir shop inside the concert hall.

[0263] When entering the concert hall, the user provides a ticket proof certificate (service entitlement certificate) to the business operator terminal 21-1. Also, when purchasing goods at the souvenir shop, the user provides electronic money (ID of the electronic money account) or credit card information stored in the digital wallet to the business operator terminal 21-2.

[0264] When entering the concert hall and when purchasing goods at the souvenir shop, the user performs identity verification in response to requests from the business operator terminals 21-1 and 21-2. Note that the same business operator ID is set for the business operator terminals 21-1 and 21-2.

[0265] When the user first enters the concert hall, the terminal 30 performs formal identity verification (performs identity verification using a biometric information proof certificate). When the user purchases goods at the souvenir shop, if the identity verification omission conditions are satisfied, the terminal 30 omits formal identity verification and performs simple identity verification (for example, password authentication).

[0266] Alternatively, when the user exits the concert venue and re-enters the concert venue, the user submits the ticket proof certificate again to the operator terminal 21-1. At this time, if the conditions for omitting the identity verification are met, the terminal 30 omits the regular identity verification and performs other simple identity verifications.

[0267] Next, a modification according to the second embodiment will be described.

[0268] <Modification 1> When the conditions for omitting the identity verification are met, the terminal 30 may also omit the execution of the simple identity verification. Alternatively, conditions for omitting the simple identity verification (conditions for completely omitting the identity verification) may be set in the terminal 30.

[0269] For example, the simple identity verification may also be omitted for an extremely short period (e.g., 3 minutes) after a successful regular identity verification. Alternatively, the simple identity verification may be omitted for a predetermined period after the simple identity verification is executed.

[0270] <Modification 2> The conditions for omitting the identity verification (or the conditions for completely omitting the identity verification) may include conditions using the location information of the terminal 30. For example, when the identity verification is requested from the same service provider within a predetermined range centered on the location where the regular identity verification was successful, the terminal 30 may replace the second and subsequent identity verifications with simple identity verifications.

[0271] Alternatively, the conditions for omitting the identity verification may be configured by combining the location information of the terminal 30 and the time element of the regular identity verification. For example, the terminal 30 may omit the regular identity verification and perform a simple identity verification within a predetermined range and within a predetermined time after a successful regular identity verification.

[0272] The conditions for omitting the identity verification are determined according to the business content of the service provider, the business form, the content of the service entitlement certificate handled, and the like.

[0273] <Modification 3> The above-mentioned initial regular identity verification (the first identity verification) may be performed by combining a plurality of authentication means. For example, regular identity verification may be performed by combining biometric authentication using a biometric information certificate and password authentication using a password. That is, the initial regular identity verification may be performed by multi-modal authentication that combines two or more authentication methods. In this case, the subsequent simple identity verification (the second identity verification) may be performed by a single authentication method (single-modal authentication) such as biometric authentication using a biometric information certificate or password authentication. Also, when the regular identity verification is performed by multi-modal authentication, the simple identity verification may be omitted. Further, even when the regular identity verification is performed by single-modal authentication, the simple identity verification may be omitted.

[0274] <Modification Example 4> In the second embodiment, the case where the initial regular identity verification is first performed and then the simple identity verification is performed when a predetermined condition is satisfied has been described. However, the regular identity verification and the simple identity verification may be performed in the reverse order. That is, depending on the service or business type provided by the service provider, there may be cases where it is preferable to first perform a simple identity verification and then perform a regular identity verification. In such a case, the terminal 30 may first perform a simple identity verification and then perform a regular identity verification.

[0275] Alternatively, the device of the service provider (service server 20, operator terminal 21) may notify the terminal 30 of the execution order of the regular identity verification and the simple identity verification. In that case, the device of the service provider may also notify the terminal 30 of the conditions for switching the authentication method.

[0276] As described above, when the terminal 30 according to the second embodiment is requested by the service provider to perform identity verification, it performs normal identity verification using the biometric information acquired in advance. The terminal 30 notifies the service provider of the result of the normal identity verification. When the service provider requests identity verification again and a predetermined condition is satisfied, the terminal 30 performs a simple identity verification different from the normal identity verification. The terminal 30 notifies the service provider of the result of the simple identity verification. As a result, even when the same service provider repeatedly requests identity verification, the user only needs to perform a simple identity verification. That is, the burden on the user who enjoys the service that requires identity verification is reduced.

[0277] Subsequently, the hardware of each device constituting the information processing system will be described. FIG. 22 is a diagram showing an example of the hardware configuration of the terminal 30.

[0278] The terminal 30 can be configured by an information processing apparatus (so-called computer) and has the configuration illustrated in FIG. 22. For example, the terminal 30 includes a processor 311, a memory 312, an input / output interface 313, a communication interface 314, and the like. The components such as the processor 311 are connected by an internal bus or the like and are configured to be able to communicate with each other.

[0279] However, the configuration shown in FIG. 22 is not intended to limit the hardware configuration of the terminal 30. The terminal 30 may include hardware not shown, or may not include the input / output interface 313 as necessary. Also, the number of components such as the processor 311 included in the terminal 30 is not intended to be limited to the example shown in FIG. 22. For example, a plurality of processors 311 may be included in the terminal 30.

[0280] The processor 311 is a programmable device such as, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a DSP (Digital Signal Processor), etc. Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), etc. The processor 311 executes various programs including an operating system (OS; Operating System).

[0281] The memory 312 is a RAM (Random Access Memory), a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), etc. The memory 312 stores an OS program, application programs, and various data.

[0282] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is a device that receives user operations such as, for example, a keyboard and a mouse.

[0283] The communication interface 314 is a circuit, a module, etc. that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card), etc.

[0284] The functions of the terminal 30 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. Further, the program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory one such as a semiconductor memory, a hard disk, a magnetic recording medium, an optical recording medium, etc. That is, the present invention can also be embodied as a computer program product. Further, the above program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the above processing module may be realized by a semiconductor chip.

[0285] Note that the server device 10, the service server 20, the business operator terminal 21, etc. can also be configured by an information processing device in the same manner as the terminal 30, and the basic hardware configuration is the same as that of the terminal 30, so the description is omitted.

[0286] The terminal 30, which is an information processing device, is equipped with a computer, and the functions of the terminal 30 can be realized by causing the computer to execute a program. Further, the terminal 30 executes a control method of the terminal 30 according to the program. Similarly, the server device 10 is equipped with a computer, and the functions of the server device 10 can be realized by causing the computer to execute a program. Further, the server device 10 executes a control method of the server device 10 according to the program.

[0287] [Modification Example] Note that the configuration, operation, etc. of the information processing system described in the above embodiment are examples and are not intended to limit the configuration of the system.

[0288] In the above embodiment, the case where the server device 10 of the proof certificate issuer issues a credential proof certificate that does not require a certification authority for verification of the proof certificate has been described. However, the server device 10 may issue a proof certificate (a proof certificate based on a public key infrastructure) that requires a certification authority.

[0289] In the above embodiment, mainly taking the biometric information certificate related to the "face" as an example, the operation of the information processing system and the like have been described. It is natural that the information processing system can handle biometric information certificates related to biometric information other than the face. For example, the terminal 30 may acquire biometric information certificates (fingerprint VCs, voiceprint VCs) related to biometric information such as fingerprints and voiceprints, and store them in the digital wallet. Alternatively, when the user enjoys the service, the terminal 30 may perform identity verification using biometric information certificates such as fingerprints and voiceprints.

[0290] The terminal 30 may acquire biometric information certificates related to the same biometric information from different certificate issuers, and store a plurality of biometric information certificates that prove the same biometric information in the digital wallet. For example, the terminal 30 may acquire biometric information certificates related to the face from each of the certificate issuers A and B.

[0291] Alternatively, the terminal 30 may acquire biometric information certificates related to different types of biometric information from the same certificate issuer, and store biometric information certificates related to different biometric information acquired from the same certificate issuer in the digital wallet. For example, the terminal 30 may acquire a biometric information certificate related to the face and a biometric information certificate related to the fingerprint from the certificate issuer A.

[0292] The device of the service provider (service server 20, operator terminal 21) may specify the biometric information certificate used by the terminal 30 for identity verification. For example, the operator terminal 21 or the like may instruct to perform identity verification using a biometric information certificate related to the face (face VCs). In this case, the operator terminal 21 or the like may simply send an identity verification request including the type of biometric information to the terminal 30.

[0293] The terminal 30 may notify the device of the service provider (service server 20, business operator terminal 21) of information (detailed information) regarding the biometric information certificate used for identity verification. For example, the terminal 30 may transmit information regarding the type of biometric information certified by the biometric information certificate, the issuer of the biometric information certificate, etc. to the business operator terminal 21 or the like together with the result of identity verification. Even if the identity verification result is a successful identity verification, the business operator terminal 21 may reject the service provision to the user depending on the type of information used for identity verification and the issuer of the biometric information certificate. The business operator terminal 21 may reject the result of identity verification that does not satisfy its own security policy or the like. For example, when a service provider such as a financial institution or an insurance company provides services related to account opening or insurance application, identity verification using a biometric information certificate issued by a public institution such as a passport or a My Number card is required instead of a biometric information certificate issued by a private company. Thus, depending on the content of the service provided by the service provider to the user, conditions regarding the issuer of the biometric information certificate may be set.

[0294] When the terminal 30 obtains the service entitlement certificate from the certificate issuer or provides it to the service provider, the terminal 30 may execute control according to the issuer of the biometric information certificate. For example, the terminal 30 may make it impossible to provide the service entitlement certificate (ticket certificate) to the service provider unless the identity verification using the biometric information certificate issued by a reliable issuer is successful.

[0295] In the above embodiment, the utilization of the biometric information certificate and the service entitlement certificate has been mainly described. In the information processing system according to the present disclosure, an identity certificate can also be utilized in the same manner as the service entitlement certificate. For example, when the terminal 30 receives an identity certificate from the certificate issuer, the terminal 30 may execute identity verification using the biometric information certificate. Similar to the service entitlement certificate, when the identity verification using the biometric information certificate is successful, the terminal 30 may store the obtained identity certificate in the digital wallet.

[0296] Alternatively, when providing the identity certificate to the service provider, the terminal 30 may perform identity verification using the biometric information certificate. Also in this case, when the identity verification using the biometric information certificate is successful, similar to the service eligibility certificate, the terminal 30 may provide the identity certificate stored in the digital wallet to the service provider.

[0297] Before providing the service eligibility certificate to the service provider, the terminal 30 may obtain the user's consent regarding the provision of the service eligibility certificate. In that case, the terminal 30 may obtain consent regarding the submission of the service eligibility certificate while clearly indicating the service eligibility certificate for which the provision is requested.

[0298] In the above embodiment, the usage control unit 203 of the terminal 30 has been described for the case of selecting the service eligibility certificate specified by the service provider. However, the user himself / herself may operate the terminal 30 to select the service eligibility certificate specified by the service provider. For example, when orally informed by an employee of the service provider or the like of the service eligibility certificate required to enjoy the necessary service, the usage control unit 203 may display a list of service eligibility certificates stored in the digital wallet according to the user's operation. The usage control unit 203 may realize the selection of the service eligibility certificate by the user through the display of the list of service eligibility certificates.

[0299] The biometric information certificate may include not only the biometric information certified by the certificate issuer but also the personal information of the certificate holder (for example, basic information such as name, gender, date of birth, address, etc.).

[0300] In the above embodiment, the case where the user (terminal 30) requests the issuance of a biometric information certificate from an organization or group such as a company or a university has been described. However, the terminal 30 may request the issuance of a biometric information certificate from the server device 10 of a public institution that stores the user's biometric information. Alternatively, when the terminal 30 cannot obtain a biometric information certificate from a company or the like, it may request the issuance of a biometric information certificate from a public institution.

[0301] The service provider may only request the terminal 30 to perform identity verification. For example, when providing services to a user, if it is sufficient to confirm that the user belongs to a company or a university, the service provider may only request the terminal 30 to perform identity verification. If the service provider determines that a user who has successfully passed the identity verification belongs to some organization or the like, the service provider may provide the service.

[0302] When the terminal 30 transmits a credential issuance request to the server device 10 of the credential issuer, the terminal 30 may sign the information included in the credential issuance request using the private key corresponding to the public key registered in the blockchain. The credential issuance unit 302 of the server device 10 may use the successful verification of the signature as a condition for issuing a credential (credential certificate).

[0303] When the acquisition control unit 202 of the terminal 30 acquires a credential certificate from the server device 10, the acquisition control unit 202 may notify the user of the fact that the credential certificate has been issued. Further, the acquisition control unit 202 may verify the signature attached to the credential certificate acquired from the credential issuer. In this case, the acquisition control unit 202 acquires the public key corresponding to the issuer ID described in the credential certificate from the blockchain. The acquisition control unit 202 verifies the signature attached to the credential certificate using the acquired public key. The acquisition control unit 202 may use the successful verification of the signature as a condition for storing the credential certificate in the digital wallet.

[0304] Some functions of the terminal 30 may be implemented in another device, device, etc. More specifically, any of the devices included in the system may implement the above-described "acquisition control unit (acquisition control means)", "usage control unit (usage control means)", etc.

[0305] The form of data transmission and reception between each device (for example, the server device 10 and the terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Between these devices, personal information of the user and the like is transmitted and received, and in order to appropriately protect this information, it is desirable that encrypted data is transmitted and received.

[0306] In the flowcharts (flowcharts, sequence diagrams) used in the above description, a plurality of steps (processes) are described in order, but the execution order of the steps executed in the embodiment is not limited to the described order. In the embodiment, for example, the order of the illustrated steps can be changed within a range that does not substantially affect the content, such as executing each process in parallel.

[0307] The above embodiments have been described in detail for ease of understanding of the disclosure of the present application, and it is not intended that all the configurations described above are necessary. Further, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is also possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace other configurations for a part of the configuration of the embodiment.

[0308] From the above description, the industrial applicability of the present invention is clear, but the present invention is preferably applicable to an information processing system including a service provider that provides services to users using a proof certificate stored in a digital wallet.

[0309] Some or all of the above embodiments may be described as follows in the appended claims, but are not limited thereto.

[0310] [Appended Claim 1] A proof certificate that proves that it is the biometric information of the issuer, and a storage means for storing a biometric information proof certificate including the biometric information of the issuer. In response to a request for identity verification from a service provider, perform a first identity verification using biometric information obtained from the stored biometric information certificate, and notify the service provider of the result of the first identity verification, the verification means; Comprising; When the verification means is requested to perform the identity verification again by the service provider, it performs a second identity verification different from the first identity verification, and notifies the service provider of the result of the second identity verification, the terminal. [Appendix 2] The verification means according to Appendix 1, which performs the second identity verification in place of the first identity verification when a predetermined condition is satisfied. [Appendix 3] When the verification means is requested to perform the identity verification again by the service provider before a predetermined time has elapsed since the success of the first identity verification, it performs the second identity verification in place of the first identity verification, the terminal according to Appendix 2. [Appendix 4] The verification means according to Appendix 2, which performs the second identity verification in place of the first identity verification in a second period determined according to the number of times of the first identity verification that was successful in the first period. [Appendix 5] For each of a plurality of the service providers, the number of successful first identity verifications in the first period for setting the second period is determined, the terminal according to Appendix 4. [Appendix 6] The verification means according to any one of Appendices 1 to 5, which performs the first identity verification using biometric information obtained from the stored biometric information certificate and biometric information obtained by photographing the user. [Appendix 7] The verification means according to any one of Appendices 1 to 5, which performs fingerprint authentication using fingerprints or password authentication using a password as the second identity verification. [Appendix 8] The biometric information certificate is generated using biometric information obtained from the public identity certificate of the issuer, the terminal according to Appendix 7. [Appendix 9] A device of a service provider, A terminal, including, The terminal is A proof certificate that proves to be the biometric information of the issuer, and stores a biometric information proof certificate including the biometric information of the issuer, a storage means; In response to a request for identity verification from the device of the service provider, executes a first identity verification using the biometric information obtained from the stored biometric information proof certificate, and notifies the result of the first identity verification to the device of the service provider, a verification means; equipped with, When the verification means is requested for the identity verification again from the device of the service provider, executes a second identity verification different from the first identity verification, and notifies the result of the second identity verification to the device of the service provider, a system. [Appendix 10] In a terminal, A proof certificate that proves to be the biometric information of the issuer, stores a biometric information proof certificate including the biometric information of the issuer, In response to a request for identity verification from a service provider, executes a first identity verification using the biometric information obtained from the stored biometric information proof certificate, and notifies the result of the first identity verification to the service provider, When being requested for the identity verification again from the service provider, executes a second identity verification different from the first identity verification, and notifies the result of the second identity verification to the service provider, a control method of a terminal. [Appendix 11] On a computer installed in a terminal, A process of storing a proof certificate that proves to be the biometric information of the issuer, and stores a biometric information proof certificate including the biometric information of the issuer, In response to a request for identity verification from a service provider, executes a first identity verification using the biometric information obtained from the stored biometric information proof certificate, and notifies the result of the first identity verification to the service provider, a process, When being requested for the identity verification again by the service provider, a process of performing a second identity verification different from the first identity verification and notifying the service provider of the result of the second identity verification, A program for causing the execution.

[0311] In addition, part or all of the configurations described in Appendices 2 to 8, which are subordinate to Appendix 1 described above, may be subordinate to Appendices 9, 10, and 11 in the same subordinate relationship as Appendices 2 to 8. Furthermore, not limited to Appendices 1, 9, 10, and 11, part or all of the configurations described as appendices can similarly be made subordinate to various hardware, software, various recording means for recording software, or systems, without departing from the scope of the above-described embodiments.

[0312] It should be noted that the disclosures of the above-cited prior art documents are incorporated herein by reference. As described above, the embodiments of the present invention have been explained, but the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications can be made without departing from the scope and spirit of the present invention. That is, the present invention naturally includes all disclosures including the claims, various modifications and corrections that can be made by those skilled in the art according to the technical idea.

Explanation of Reference Numerals

[0313] 10 Server device 20 Service server 21 Operator terminal 21-1 Operator terminal 21-2 Operator terminal 30 Terminal 100 Terminal 101 Storage means 102 Verification means 201 Communication control unit 202 Acquisition control unit 203 Usage control unit 204 Storage unit 205 Identity verification unit 301 Communication Control Unit 302 Certificate Issuing Unit 303 Memory Unit 311 Processor 312 Memory 313 Input / Output Interface 314 Communication Interface 401 Communication Control Unit 402 Service Provision Control Unit 403 Memory Unit

Claims

1. An authentication certificate that proves that it is the biometric information of the issuer, a storage means for storing a biometric information authentication certificate including the biometric information of the issuer, In response to a request for identity verification from a service provider, a first identity verification using biometric information obtained from the stored biometric information authentication certificate is performed, and the result of the first identity verification is notified to the service provider. , verification means, Comprising, When the verification means is requested to perform the identity verification again by the service provider, the verification means performs a second identity verification different from the first identity verification, and notifies the service provider of the result of the second identity verification. , terminal.

2. The terminal according to claim 1, wherein the verification means performs the second identity verification instead of the first identity verification when a predetermined condition is satisfied.

3. The terminal according to claim 2, wherein the verification means performs the second identity verification instead of the first identity verification when the service provider requests the execution of the identity verification again before a predetermined time has elapsed since the success of the first identity verification.

4. The terminal according to claim 2, wherein the verification means performs the second identity verification instead of the first identity verification in a second period determined according to the number of times of the first identity verification that has succeeded in a first period.

5. For each of a plurality of the service providers, the number of successful first identity verifications in the first period for setting the second period is determined. The terminal according to claim 4.

6. The terminal according to any one of claims 1 to 5, wherein the verification means performs the first identity verification using the biometric information obtained from the stored biometric information authentication certificate and the biometric information obtained by photographing the user.

7. The terminal according to any one of claims 1 to 5, wherein the verification means performs fingerprint authentication using a fingerprint or password authentication using a password as the second identity verification.

8. The terminal according to claim 7, wherein the biometric information authentication certificate is generated using biometric information obtained from a public identity certificate of the issuer.

9. An apparatus of a service provider, A terminal, Including, The terminal is, An authentication certificate that proves that it is the biometric information of the issuer, a storage means for storing a biometric information authentication certificate including the biometric information of the issuer, In response to a request for identity verification from the device of the service provider, perform a first identity verification using biometric information obtained from the stored biometric information certificate, and notify the device of the service provider of the result of the first identity verification, the verification means; comprising; When the verification means is requested to perform the identity verification again by the device of the service provider, it performs a second identity verification different from the first identity verification, and notifies the device of the service provider of the result of the second identity verification, the system.

10. In a terminal, A certificate that proves that it is the biometric information of the person to be issued, stores a biometric information certificate including the biometric information of the person to be issued, In response to a request for identity verification from a service provider, perform a first identity verification using biometric information obtained from the stored biometric information certificate, and notify the service provider of the result of the first identity verification, When the service provider requests the identity verification again, perform a second identity verification different from the first identity verification, and notify the service provider of the result of the second identity verification, a control method for a terminal.

11. On a computer mounted on a terminal, A process of storing a certificate that proves that it is the biometric information of the person to be issued, and stores a biometric information certificate including the biometric information of the person to be issued, In response to a request for identity verification from a service provider, perform a first identity verification using biometric information obtained from the stored biometric information certificate, and notify the service provider of the result of the first identity verification, When the service provider requests the identity verification again, perform a second identity verification different from the first identity verification, and notify the service provider of the result of the second identity verification, A program for causing the above to be executed.

Citation Information

Patent Citations

  • Electronic equipment with security function and security management system

    JP2003122443A

  • Information processor and authentication control method

    JP2007299034A

  • Terminal, system, terminal control method and program

    JP7371818B1

  • Adaptive Authentication

    US10630693B1

  • Method and system for providing biometric authentication at a point-of-sale via a mobile device

    US20080046366A1