Verifiable certificate system, method, and recording medium
The verifiable credential system addresses biometric information leakage by generating and verifying credentials using auxiliary data and encoded keys, ensuring secure authentication without exposing sensitive biometric data, thus enhancing security.
Patent Information
- Application Number
- JP2024005829
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-18
- Publication Date
- 2025-07-31
AI Technical Summary
Existing verifiable credential systems face the risk of biometric information leakage and unauthorized use during verification processes.
A verifiable credential system involving a credential issuing device, a holding device, and a verification device, where auxiliary data is generated using a signature key and biometric information, allowing secure verification without direct transmission of biometric data, ensuring the generation and verification of credentials and presentations using encoded keys and signatures.
The system effectively prevents biometric information leakage and unauthorized use, enhancing security by verifying the authenticity of biometric information without exposing sensitive data to potential risks.
Smart Images

Figure 2025111903000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a verifiable certificate system, method, and medium recording a program.
Background Art
[0002] Regarding a verifiable certificate system, for example, Fig. 1(A) is referred to (Non-Patent Document 1: Figure 1 The roles and information flows forming the basis for this specification). A verifiable credential (VC) can be said to be a certificate that digitizes information representing attributes of an individual or the like that physically exists, such as a driver's license, academic certificate, qualification certificate, and other confidential data, and makes it verifiable online. Note that "verifiable certificate" is also denoted / abbreviated as "certificate (VC)" or simply "VC". When a user uses various services of an application, the user presents a certificate (VC), and the application side verifies whether the conditions are met and gives permission for use to the user. Generally, the certificate (VC) that proves the attributes of this user is issued by a specific issuer (such as a university, bank, government, etc.).
[0003] An issuer makes a claim about one or more subjects (things about which a claim is made), creates a certificate (VC) from the claim, and sends the certificate (VC) to the holder.
[0004] A holder owns one or more certificates (VCs) and generates a verifiable presentation (VP). The holder is usually the subject of the VC(s) held. Note that "verifiable presentation" is also denoted / abbreviated as "presentation (VP)" or simply "VP".
[0005] A proof presentation (VP) can be said to be data derived from one or more verifiable credentials (VCs) issued by one or more issuers. To prevent reuse, a proof presentation (VP) may be generated in response to a challenge from a verifier.
[0006] The verifier receives and verifies the proof presentation (VP). For example, the verifier verifies the signature attached to the verifiable credential (VC) in the proof presentation (VP) using the issuer's verification key (public key) to confirm that the content of the verifiable credential (VC) has not been tampered with. Also, the verifier (Verifier) obtains the holder's verification key and verifies the signature attached to the proof presentation (VP) to confirm that the content of the proof presentation (VP) has not been tampered with.
[0007] When the holder does not want the other party to know the content of the information but only wants to inform the other party that they have information that meets the conditions, a zero - knowledge proof (ZKP) can be used to verify that the presented information meets the conditions and that this information is a verifiable credential (VC) issued by a trustworthy issuer. Note that the issuer, holder, and verifier may each be implemented as an information processing device equipped with a communication function.
[0008] In addition, in Figure 1(A), a verifiable data registry manages related data necessary for the system to use verifiable credentials (VCs), such as the schema of the verifiable credential (VC) and the issuer's public key. Examples of verifiable data registries include a trustworthy database, a distributed database, a government ID database, and a distributed ledger.
[0009] Figure 1(B) shows the elements of a verifiable credential (VC) (Non - Patent Document 1 §3.2 Credentials, Figure 5 Basic components of a verifiable credential). · Credential Metadata: Metadata indicating the issuer, issue date, etc. · Claim(s): The content to be proven as shown in the certificate · Proof(s): Digital signature by the issuer, etc.
[0010] Figure 1(C) shows the elements of a Verifiable Presentation (VP) (Non-Patent Document 1 §3.3 Presentations, Figure 7 Basic components of a verifiable presentation). A Verifiable Presentation (VP) is a data format for presenting a certificate to a verifier, · Presentation Metadata: Metadata indicating the presenter, issue date and time, etc. · Verifiable Credential(s): The VC to be presented · Proof(s): Digital signature indicating that the creator is the holder, etc. The verification of a Verifiable Presentation (VP) follows, for example, Non-Patent Document 1 (§3.3 Presentations, Figure 8 Information graphs associated with a basic verifiable presentation) and Reference Document 1, etc.
[0011] A signature of the issuer is attached to the certificate (VC). A signature of the holder is attached to the Verifiable Presentation (VP). The verifier obtains the verification keys of the issuer and the holder from a public repository and verifies the signatures to verify the content of the certificate (VC) and the issuer, and the content of the Verifiable Presentation (VP) and the presenter.
Prior Art Documents
Non-Patent Documents
[0012]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0013] Here, when assuming a system that verifies the authenticity by presenting biometric information to a verifier as part of a verifiable credential (VC) and comparing it with the biometric information obtained by the verifier, the verifier side will handle the biometric information (biometric signature). Therefore, there is a possibility of leakage or unauthorized use of biometric information on the verifier side.
[0014] One of the objectives of the present disclosure is to provide a verifiable credential system, method, and recording medium that can avoid the possibility of leakage or unauthorized use of biometric information and improve security.
Means for Solving the Problems
[0015] According to the present disclosure, a verifiable credential system includes a credential issuing device, a credential holding device, and a credential verification device, each of which includes a processor and a communication device. The credential issuing device generates first auxiliary data using a first signature key and first biometric information, generates a credential including a verification key corresponding to the first signature key, and executes a process of transmitting the credential and the first auxiliary data to the credential holding device. The credential holding device acquires second biometric information, receives the credential and the first auxiliary data transmitted from the credential holding device, generates a signature using the second biometric information and the first auxiliary data, generates a credential presentation from the credential, and executes a process of transmitting the credential presentation and the signature to the credential verification device. The credential verification device receives the credential presentation and the signature transmitted from the credential holding device, verifies the credential included in the credential presentation, and verifies the signature using the verification key included in the credential, and executes a process.
[0016] According to the present disclosure, a verification method in a verifiable certificate system including a certificate issuing node, a certificate holding node, and a certificate verification node is disclosed. At the certificate issuing node, generate first auxiliary data using a first signature key and first biometric information, generate a certificate including a verification key corresponding to the first signature key, and transmit the certificate and the first auxiliary data to the certificate holding node. At the certificate holding node, obtain second biometric information, receive the certificate and the first auxiliary data transmitted from the certificate holding node, generate a signature using the second biometric information and the first auxiliary data, generate a certificate presentation from the certificate, and transmit the certificate presentation and the signature to the certificate verification node. At the certificate verification node, receive the certificate presentation and the signature transmitted from the certificate holding node, verify the certificate included in the certificate presentation, and verify the signature using the verification key included in the certificate.
[0017] According to the present disclosure, a program for causing each process of a certificate issuer, a certificate holder, and a certificate verifier in a verifiable certificate system to be executed by at least first to third processing devices, by the first processing device, generate first auxiliary data using a first signature key and first biometric information, generate a certificate including a verification key corresponding to the first signature key, and a process of transmitting the certificate and the first auxiliary data to the second processing device, by the second processing device, obtain second biometric information, generate a signature using the second biometric information and the first auxiliary data, A process of generating a certificate presentation from the certificate and transmitting the certificate presentation and the signature to the third processing device, by the third processing device, verifying the certificate from the certificate presentation, A recording medium recording a program for causing execution of a process of verifying the signature using the verification key included in the certificate is disclosed.
Advantages of the Invention
[0018] According to the present disclosure, it is possible to avoid the possibility of leakage and unauthorized use of biological information and improve safety.
Brief Description of the Drawings
[0019]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Modes for Carrying Out the Invention
[0020] Some embodiments of the present disclosure will be described. According to the present disclosure, the issuer generates verifiable credentials (VCs) including a public key and auxiliary data for enabling signature generation only when biometric information of the same person as the presented biometric information is given, and sends the credentials (VCs) and the auxiliary data to the holder. The holder generates a verifiable presentation (VP) from the credentials (VCs), generates a signature using the presented biometric information and the auxiliary data, and sends the presentation (VP) and the signature to the verifier. The verifier verifies the presentation (VP) and the signature. Verification of the presentation (VP) includes verification of the credentials (VCs) included in the presentation (VP).
[0021] FIG. 2 schematically shows an example of the certificate verification system 100 of the present disclosure. In FIG. 2, the verifiable data registry of FIG. 1(A) is omitted. The same applies to the following drawings.
[0022] The issuer (certificate issuer) 101 generates auxiliary data from the presented first biometric information w and the signature key (private key). This auxiliary data is data that enables signature generation when the second biometric information w' of the same person as the first biometric information w used at the time of generation is given. The auxiliary data may be a sketch of a secure sketch, key parameters of a biometric-based distributed signature, or the like. The verification key (public key) corresponding to the signature key is included in the credentials (VCs). The auxiliary data may be included in the credentials (VCs).
[0023] The holder (certificate holder) 102 generates a signature from the presented second biometric information w' and the auxiliary data. A signature using the signature key corresponding to the verification key in the credentials (VCs) is generated only when the second biometric information w' of the same person as the biometric information w used at the time of generation of the auxiliary data is presented. The holder 102 creates a presentation (VP) from the credentials (VCs). The holder 102 always includes the verification key in the presentation (VP). The signature may be included in the presentation (VP).
[0024] The verifier (certificate verifier) 103 verifies the presentation of the certificate (VP). It can verify that the verification key is issued for the certificate (VC). Subsequently, it verifies the signature. The ability to generate a signature with the private key corresponding to the verification key can verify that the first biometric information w presented at the time of issuing the certificate (VC) and the second biometric information w' presented at the time of creating the certificate presentation (VP) are from the same person.
[0025] [[ID=З]] FIG. 3 is a diagram for explaining an example of the configuration of each element of the certificate verification system 100 described with reference to FIG. 2. The issuer 101, the holder 102, and the verifier 103 are implemented as a certificate issuing device 110, a certificate holding device 120, and a certificate verification device 130, respectively, each of which has at least a processor and a communication device and is an information processing device capable of establishing a communication connection between opposing devices.
[0026] The certificate issuing device 110 includes a first biometric information acquisition unit 111, a key generation unit 112, an auxiliary data generation unit 113, an auxiliary data transmission unit 114, a certificate generation unit 115, and a certificate transmission unit 116. The processing of each of these units may be realized by a program module executed by the hardware of the information processing device and the processor.
[0027] The certificate holding device 120 includes a challenge acquisition unit 121, a second biometric information acquisition unit 122, an auxiliary data acquisition unit 123, a storage unit 124A, a signature generation unit 125, a signature transmission unit 126, a certificate acquisition unit 127, a storage unit 124B, a certificate presentation generation unit 128, and a certificate presentation transmission unit 129. The processing of each of these units may be realized by a program module executed by the hardware of the information processing device and the processor.
[0028] The certificate verification device 130 includes a challenge generation unit 131, a challenge transmission unit 132, a signature acquisition unit 133, a certificate presentation acquisition unit 134, a certificate presentation verification unit 135, and a signature verification unit 136. Each of these units may be realized by a program module executed by the hardware of the information processing device and the processor.
[0029] FIG. 4 is a diagram for explaining the processing flow of each part of each device of the certificate verification system 100 in FIG. 3. Referring to FIG. 4, in the certificate issuing device 110, the first biometric information acquisition unit 111 acquires the first biometric information w of the user from a sensor or the like (step A1). The key generation unit 112 generates a pair of a signature key (private key) x and a verification key (public key) v (step A2). The auxiliary data generation unit 113 generates auxiliary data s using the first biometric information w and the signature key x (step A3). The auxiliary data transmission unit 114 transmits the auxiliary data s to the certificate holding device 120 (step A4). The certificate generation unit 115 generates the certificate (VC) in FIG. 1(B) (step A5). The certificate generation unit 115 includes the verification key v in the claim of the certificate (VC), and the certificate transmission unit 116 transmits the certificate (VC) including the verification key v to the certificate holding device 120 (step A6). The auxiliary data s may be included in the claim of the certificate (VC).
[0030] In the certificate holding device 120, the challenge acquisition unit 121 acquires the challenge c transmitted from the certificate verification device 130 (step B1). The second biometric information acquisition unit 122 acquires the second biometric information w' from a sensor or the like (not shown) (step B2). The auxiliary data acquisition unit 123 receives the auxiliary data s transmitted from the certificate issuing device 110 and stores it in the storage unit 124A (step B3). The signature generation unit 125 restores the signature key x' using the second biometric information w' and the auxiliary data s (generated based on the first biometric information w and the signature key x), and generates a signature σ for the challenge c using the restored signature key x' (step B4).
[0031] In the certificate holding device 120, the signature transmission unit 126 transmits the generated signature σ to the certificate verification device 130 (step B5). The certificate acquisition unit 127 receives the certificate (VC) transmitted from the certificate issuing device 110 and stores it in the storage unit 124B (step B6). The certificate presentation generation unit 128 generates the certificate presentation (VP) in FIG. 1(C) using the certificate (VC) (including the verification key v in the claim) transmitted from the certificate issuing device 110 (step B7). The certificate presentation transmission unit 129 transmits the generated certificate presentation (VP) to the certificate verification device 130 (step B8). Step B5 may be executed at the same timing as step B8. The signature σ may be included in the certificate presentation (VP).
[0032] In the certificate verification device 130, the challenge generation unit 131 generates a challenge (random number) c (step C1), and the challenge transmission unit 132 transmits the challenge c to the certificate holding device 120 (step C2). The signature acquisition unit 133 receives the signature σ transmitted from the certificate holding device 120 (step C3). The certificate presentation acquisition unit 134 receives the certificate presentation (VP) transmitted from the certificate holding device 120 (step C4). The certificate presentation verification unit 135 verifies the certificate presentation (VP) (step C5). The signature verification unit 136 verifies the signature using the verification key included in the claim of the certificate (VC) included in the certificate presentation (VP) (step C6). The verification of the certificate presentation (VP) by the certificate presentation verification unit 135 follows the above-mentioned Non-Patent Document 1, Reference Document 1, etc. Note that the signature given to the certificate (VC) (included in the certificate presentation (VP)) by the certificate issuing device 110 and the signature given to the certificate presentation (VP) by the certificate holding device 120, which are used for verifying the certificate presentation (VP) in the certificate presentation verification unit 135, are different signatures from the signature σ received in step C3.
[0033] FIG. 5 is a diagram schematically showing an example of arithmetic processing in the system according to the embodiment of the present disclosure. The numbers of each device represent the processing steps in each device (not necessarily corresponding to the steps in each device described with reference to FIG. 4). Hereinafter, at the end of the sentence describing the processing of each device, the processing step number in each device shown in FIG. 5 is described in parentheses.
[0034] The certificate issuing device 110 acquires the first biometric information w (1), randomly selects x from the information source, sets it as the signature key (private key) x (2), and generates a verification key v corresponding to the signature key x (3). The certificate issuing device 110 synthesizes the encoded key ENC(x) obtained by encoding the signature key (private key) x with the encoding function Encode and the first biometric information w to generate auxiliary data (also referred to as first auxiliary data) s (4).
[0035] The auxiliary data s may be obtained by the following formula (1). s = Encode(x) + w …(1)
[0036] However, the binary operator in formula (1) is not limited to addition, and may be subtraction, or may be a bit-wise exclusive OR, etc.
[0037] The encoding function Encode converts the plaintext m included in the information source space into the code c. The decoding function Decode returns the code c to the plaintext m. c← Encode(m) …(2) m← Decode(c) …(3)
[0038] Here, for the code c' whose difference from the code c which is an arbitrary plaintext m included in the information source space is within the error correction capability, for example, m = Decode(c') …(4) must hold. Hereinafter, a linear code is used.
[0039] Linearity: Encode(m1) + Encode(m2) …(5) is the codeword of m1 + m2, m1 + m2 = Decode(Encode(m1) + Encode(m2)) …(6) holds. In Equation (6), the ‘+’ on the left - hand side and the right - hand side may not be the same operation.
[0040] Regarding encoding, for example, error - correcting codes (Hamming code, BCH (Bose - Chaudhuri - Hocquenghem code), RS (Reed - Solomon) code, LDPC (low - density parity - check code), etc.) may be used. Alternatively, for example, lattice coding etc. may be used. More specifically, in addition to the method using an integer lattice and the method using a triangular lattice, methods using more complex lattices etc. are known (see Reference 5). The auxiliary data s can also correspond to the secure sketch of Reference 2. The auxiliary data s may correspond to a commitment (Reference 6) in which biometric information is embedded in a secret key.
[0041] The certificate issuing device 110 generates a certificate (VC) including a verification key in the claim and transmits it to the certificate holding device 120 (5).
[0042] The certificate holding device 120 acquires the challenge generated by the certificate verification device 130 (1). The certificate holding device 120 acquires the second biometric information w' (2).
[0043] The certificate holding device 120 inputs the difference between the auxiliary data s (= Encode(x)+w) and the second biometric information w' into the decoding function Decode to restore the restored signature key x'. x' = Decode(s - w') …(7)
[0044] Looking at the right - hand side of Equation (7), Decode(s - w') = Decode({Encode(x)+w}-w') = Decode(Encode(x)+(w - w')) …(8)
[0045] In Equation (8), if the distance d(w - w') of the difference between the first biological information w and the second biological information w' is within the error correction capability, the following holds. x' = Decode(Encode(x)) = x …(9)
[0046] Note that since the restored signature key x'( = x) is a secret key, for security reasons, it is discarded after use.
[0047] The certificate holding device 120 generates a signature σ for the challenge c using the restored signature key x' (4). The certificate holding device 120 generates a certificate presentation (VP) including the signature σ and transmits it to the certificate verification device 130 (5).
[0048] The certificate verification device 130 generates a challenge c uniformly at random and transmits it to the certificate holding device 120 (1).
[0049] When the certificate verification device 130 receives a certificate presentation (VP) including the signature σ, it verifies the certificate presentation (VP) (2). Further, the certificate verification device 130 verifies the signature σ using the verification key v and the signature included in the certificate presentation (VP) (Verify(v, σ, c)) (3).
[0050] By the process (2) in the certificate verification device 130, it is verified that the verification key (public key) v was generated for the certificate (VC) and that the signature σ was generated for the certificate presentation (VP).
[0051] By the process (3) in the certificate verification device 130, it can be verified that the second biological information w' of the same person as the first biological information w used by the certificate issuing device 110 was presented by the certificate holding device 120.
[0052] Combining processes (2) and (3) in the certificate verification device 130 enables verification that the biometric information presented at the time of certificate issuance and certificate presentation is that of the same person.
[0053] According to the present disclosure, the first and second biometric information w and w' respectively acquired by the certificate issuing device 110 and the certificate holding device 120 are not transmitted to the certificate verification device 130, and the auxiliary data s generated based on the first biometric information w and the signature key x is also not transmitted to the certificate verification device 130. The possibility of leakage of the first biometric information w or the signature key x from the auxiliary data s is extremely low, ensuring security.
[0054] As an example of the above signature, an example using Schnorr signature will be described.
[0055] The certificate issuing device 110 generates a pair of a secret key x and a public key v by the following key generation algorithm, and sets x and v as the signature key and the verification key. p and q are prime numbers, and q|(p - 1) (q is a divisor of p - 1) g is an element of the multiplicative group Zp * of order q, that is, g^q ≡ 1 (mod p)
[0056] Randomly select the secret key x uniformly. x ← R Zq (=Z / qZ: the set of integers from 0 to less than q, x ∈ [0, q - 1)) …(10) The symbol "← R " represents selecting uniformly at random from the information source (in this case, Zq). Calculate the public key v according to the following equation (11). v = g^x mod p …(11) Note that the public key may be p, q, g, v. However, p, q, g may be shared by each device as common parameters, and the public key may be v.
[0057] The certificate issuing device 110 generates a certificate including the verification key v for the claim and transmits it to the certificate holding device 120.
[0058] In the certificate holding device 120, the difference between the auxiliary data s (= Encode(x) + w) and the second biometric information w' is input to the decoding function Decode to restore the signature key x'. x' = Decode(s - w') …(12)
[0059] Using the restored signature key x', a signature for the challenge c is generated. k ← R Zq …(13) is uniformly randomly selected. r = g^k mod p …(14) e = H(r, c) …(15) s = k - e*x' mod q …(16) The signature σ = (e, s) …(17)
[0060] The certificate verification device 130 obtains the verification key v included in the presented certificate, and in the signature verification Verify(v, σ, c) (v = g^x mod p: public key), for the signature σ = (e, s) and the message c, r' = (g^s)(v^e) mod p …(18) is calculated, e = H(r', c) …(19) If it holds, 1 (accepted) is returned, and if it does not hold, 0 (rejected) is returned. Although it is the same thing, in Verify(v, σ, c), g^k = (g^s)*(v^e) mod p …(20) If it holds, 1 (accepted) may be returned, and if it does not hold, 0 (rejected) may be returned. That is, if the restored signature key x' is equal to the original signature key x, (g^s)*(v^e) = g^{(k - e*x')+x*e mod q} mod p …(21) The right side of is g^k mod p. If the restored signature key x' is not equal to the original signature key x, the right side of Equation (21) will not be g^k mod p.
[0061] There is known a Fuzzy Signature that treats biometric information as fuzzy data and generates a signature (References 6 and 7).
[0062] In the key generation stage of the fuzzy signature, when a security parameter (key length) λ and fuzzy data w such as biometric information are input to a key generation algorithm KeyGen, a public key (verification key) v is generated. At this time, a key parameter (for example, a linear sketch) kp may be output. v←KeyGen(λ,w) …(22)
[0063] In the signature stage, when fuzzy data w' and a message M are input to a signature algorithm Sign, a signature σ is output. σ←Sign(w', M) …(23)
[0064] The key parameter kp output at the time of key generation may be additionally input to the signature algorithm Sign.
[0065] In the signature verification stage, a verification key v, a message M, and a signature σ are input to a verification algorithm Verify, and Verify outputs acceptance (for example, 1) or non-acceptance (for example, 0) as a signature σ verification result. 1 / 0←Verify(v, M,σ) …(24)
[0066] When verifying a signature σ generated for a message M using a second fuzzy data w'∈W that is sufficiently close to the first fuzzy data w (the distance d(w, w') between w and w') is less than or equal to a threshold θ) using the verification key v generated by the key generation algorithm from the first fuzzy data w, acceptance occurs.
[0067] FIG. 6 is a diagram schematically showing another example of operations in the system according to the embodiment of the present disclosure, and shows an example using the fuzzy signature method. The numbers of each device represent processing steps. Hereinafter, in the parentheses at the end of the sentence describing the processing of each device, the processing step numbers in each device shown in FIG. 6 are described (not necessarily corresponding to the steps in FIG. 4).
[0068] The certificate issuing device 110 acquires the first biometric information w (1), and generates a first key parameter kp and a verification key v by using the first biometric information w (fuzzy data) as a signing key notationally (2). (kp, v)←KeyGen(w, λ) …(25) The certificate issuing device 110 generates a certificate (VC) including the verification key v in the claim (3), and transmits the first key parameter kp and the certificate (VC) to the certificate holding device 120 (4). As described above, the auxiliary data s may be a key parameter, and thus the first key parameter kp may be referred to as the first auxiliary data.
[0069] The certificate holding device 120 acquires the second biometric information w' (2).
[0070] The certificate holding device 120 generates a signature on the challenge c by using the second biometric information w' and the first key parameter kp through biometric-usage distributed signature generation: σ =Sign(w', kp, c) …(26) creates it (3), generates a certificate presentation (VC) including the signature σ, and transmits it to the certificate verification device 130 (4).
[0071] In biometric-usage distributed signature generation, an entity having biometric information and an entity having a key parameter generate a signature without restoring the signing key. Although not particularly limited, biometric-usage distributed signature generation may execute distributed processing in two applications or distributed signature with a biometric information acquisition unit as a separate device, for example.
[0072] The certificate verification device 130 generates a challenge c uniformly at random and transmits it to the certificate holding device 120 (1).
[0073] When the certificate verification device 130 receives a certificate presentation (VC) including a signature σ, it verifies the certificate presentation (VC) (2). Further, the certificate verification device 130 verifies the signature σ using the verification key v included in the certificate presentation (VC) and the signature σ (Verify(v, σ, c)) (3).
[0074] By the process (2) in the certificate verification device 130, it is verified that the public key v was generated for the certificate (VC) and the signature σ was generated for the certificate presentation (VP).
[0075] By the process (3) in the certificate verification device 130, it is possible to verify that the second biometric information w' of the same person as the first biometric information w used in the certificate issuing device 110 was presented by the certificate holding device 120.
[0076] Combining the processes (2) and (3) in the certificate verification device 130 makes it possible to verify that the biometric information of the same person was presented at the time of certificate issuance and at the time of certificate presentation.
[0077] Regarding an example to which the fuzzy signature method of FIG. 6 is applied, an example of generating a biometrically used distributed signature will be described with reference to FIG. 7. Note that for the distributed signature generation process, references 3, 4, etc. are referred to.
[0078] The certificate holding device 120 acquires the challenge c generated by the certificate verification device 130 (1). The certificate holding device 120 acquires the second biometric information w' (2).
[0079] The certificate issuing device 110 performs an operation from the value obtained by encoding the signature key x and the second biometric information w' in the same manner as the above-described correction data: kp = Encode(x) + w …(27) to obtain the first key parameter kp. In this case, the verification key v is the public key corresponding to the signature key x.
[0080] FIG. 7 is a diagram for explaining the generation of a biometric-based distributed signature using Schnorr signatures as an example. In FIG. 7, the distributed signature generation process corresponds to the signature σ = Sign(w', kp, c) in step 3 of FIG. 6 in the certificate holding device 120. Note that the distributed signature generation device 140 is an information processing device (application device) on the other side that performs distributed signature generation with the signature generation unit 125 of the certificate holding device 120.
[0081] The signature generation unit 125 of the certificate holding device 120 uniformly and randomly obtains a first distributed key (private key) x' for the distributed signature from the information source (3), and from the second biometric information w' and the value Encode(x') obtained by encoding the first distributed key x', for example, the following operation: kp' = Encode(x') + w' …(28) is used to generate the second key parameter kp' (4).
[0082] The signature generation unit 125 of the certificate holding device 120 transmits the second key parameter kp' to the distributed signature generation device 140 (5). The second key parameter kp' may be referred to as the second auxiliary data.
[0083] In the distributed signature generation device 140, it is assumed that the first key parameter kp (= Encode(x) + w) generated by the certificate holding device 120 is obtained and stored (1). In the distributed signature generation device 140, the second key parameter kp' transmitted from the certificate holding device 120 is received (2), and the difference (kp - kp') between the second key parameter and kp and the kp' of the second key parameter is decoded to obtain the key difference x - x' (= Δ) (3). Decode(kp - kp') = Decode(Encode(x) + w - (Encode(x') + w')) = Decode(Encode(x - x') + w - w') …(29)
[0084] If the distance d(w - w') between the first biometric information w and the second biometric information w' is within the error correction capability, Δ = x - x' …(30) It becomes as follows. The key difference Δ between the signature key x and the first dispersion key is the second dispersion key (private key) for the distributed signature.
[0085] In the distributed signature generation device 140, a signature for the challenge c is obtained using the second dispersion key Δ, and a part of the signature is transmitted to the certificate holding device 120. In the certificate holding device 120, a signature σ for the challenge c with Δ + x'(= x) as the signature key may be generated using a part of the signature generated by the distributed signature generation device 140. Hereinafter, the Schnorr signature will be described as an example for the biometric-based distributed signature generation (σ = Sign(w', kp, c) in step 3 of FIG. 6).
[0086] In the signature generation unit 125 of the certificate holding device 120, a first random number k1 is uniformly randomly selected (6). k1 ← R Zq(k1∈[0,q - 1])) …(31) " ← R " represents that it is uniformly randomly selected from the information source.
[0087] In the signature generation unit 125 of the certificate holding device 120, a value r1 obtained by raising the generator g to the power of the first random number k1 is obtained (7). r1 = g^k1 mod p …(32)
[0088] The signature generation unit 125 of the certificate holding device 120 transmits the challenge c and r1 to the distributed signature generation device 140 (8).
[0089] The distributed signature generation device 140 receives the challenge c and r1 transmitted from the certificate holding device 120 (4).
[0090] The distributed signature generation device 140 uniformly randomly selects a second random number k2 (5). k2← R Zq(k2∈[0,q - 1])) …(33)
[0091] The distributed signature generation device 140 obtains a value r2 obtained by raising the generator g to the power of the second random number k2 (6). r2 = g^k2 mod p …(34)
[0092] The distributed signature generation device 140 obtains a value r obtained by multiplying r2 by r1 transmitted from the certificate holding device 120 (7). r = r1*r2 mod p …(35)
[0093] The distributed signature generation device 140 inputs r and the challenge c into the hash function H, e = H(r, c) (∈Z q * :Z q and the set of integers relatively prime to q) …(36) and calculates it (8).
[0094] The distributed signature generation device 140 uses the value obtained by multiplying e by the second distributed key Δ and the second random number k2, s' = k2 -e*Δ mod q …(37) and calculates it (9). The signature (e, s') can be said to be part of the distributed signature.
[0095] The distributed signature generation device 140 transmits s' (s' is the second element (part) of the signature (e, s')) and r2 to the certificate holding device 120 (10).
[0096] The signature generation unit 125 of the certificate holding device 120 receives s' (part of the signature) and r2 transmitted from the distributed signature generation device 140 (9).
[0097] The signature generation unit 125 of the certificate holding device 120 obtains a value obtained by multiplying r1 (= g^k1 mod p) by r2 (= g^k2 mod p) transmitted from the distributed signature generation device 140 (10). r = r1*r2 mod p=g^(k1+k2 mod q) mod p …(38)
[0098] The signature generation unit 125 of the certificate holding device 120 inputs r obtained in Equation (38) and the challenge c into the hash function H, e = H(r, c) …(39) Find (11).
[0099] The certificate holding device 120 uses the s' sent from the distributed signature generation device 140, the value obtained by multiplying the e obtained in Equation (39) and the first distributed key x', and the first random number k2, s = s' + k1 - e*x' mod q = (k1+k2) - e*(Δ + x') mod q …(40) Calculate (12).
[0100] In the above, the certificate holding device 120, in cooperation with the distributed signature generation device 140, generates a signature σ=(e, s) for the challenge c based on the first distributed key x' and the second distributed key Δ. (13). Since the second biometric information w' and the first distributed key (private key) x' (encoded value) obtained by the certificate holding device 120 are combined and transmitted to the distributed signature generation device 140 as the first key parameter kp2, the possibility of forgery or leakage of the second biometric information w' or the first distributed key (private key) x' is extremely low. Also, since the second distributed key (private key) Δ generated by the distributed signature generation device 140 is transmitted to the certificate holding device 120 as s' of the signature σ=(e, s'), the possibility of leakage of the second distributed key Δ is also extremely low, ensuring security.
[0101] The certificate holding device 120 transmits the signature σ=(e, s) to the certificate verification device 130 (Fig. 6). (14).
[0102] In the certificate verification device 130, the signature acquisition unit 133 receives the signature σ=(e, s). The signature verification unit 136 of the certificate verification device 130 verifies the correctness of the pair of the signature σ=(e, s) and the challenge c using the verification key v (=g^x mod p) included in the certificate. That is, it obtains a value r' obtained by multiplying the value obtained by raising the generator g to the power of s and the value obtained by raising the verification key v to the power of e. r' = (g^s)*(v^e) mod p …(41)
[0103] And then, calculate the hash value for r' and challenge c H(r', c) …(42) and, e = H(r', c) …(43) if it holds, return 1 (accepted); if it does not hold, return 0 (not accepted).
[0104] That is, for the right side of Equation (41), g^s = g^{k1 + k2 - e*(Δ + x') mod q} mod p …(44) v^e = g^(x*e mod q) mod p …(45) from which, r' in Equation (41) is given by the following Equation (46). r' = g^{k1+k2 - e*(Δ) + e*(x-x') mod q} mod p …(46)
[0105] Here,[[]] Δ = x -x' mod q …(47) if so, the right side of Equation (46) is r' = g^(k1 + k2 mod q) mod p …(48) and r' is consistent with r obtained in Equation (38) (r'=r). Therefore,[[]] H(r', c) = H(r, c) = e …(49) holds, and Verify(v, σ, M) returns 1 (accepted).
[0106] On the other hand,[[]] x ≠ x'+Δ mod q …(50) if so, from Equation (47), r' is different from r obtained in Equation (38) (r'≠ r), and therefore,[[]] e= H(r, c)≠H(r', c) …(51) holds, and the signature verification unit 136 (Verify(v, σ, c)) returns 0 (not accepted).
[0107] In the case of the example in FIG. 6, the key difference Δ (= x - x') is decrypted by Decode(kp - kp') in Expression (29), but the signature key x itself is not decrypted. On the other hand, in the example of FIG. 5, if the distance d(w - w') between the first biometric information w and the second biometric information w' is within the error correction capability, the signature key x itself is decrypted as x' by Decode(s - w') in Expression (12).
[0108] In FIG. 7, for the purpose of enhancing security, a zero-knowledge proof (Non-Interactive zero-knowledge: NIZK) that the distributed signature generation device 140 knows the first random number k1 may be performed from the certificate holding device 120. In this case, the certificate holding device 120 and the distributed signature generation device 140 share a proof generation key and a proof verification key. For example, in FIG. 7, after the certificate holding device calculates r1 using, for example, the first random number k1 (step (6) of the certificate holding device 120 in FIG. 7), a specific example of the proposition to be proved (instance: knowing the first random number k1) and a proof (witness) that this proposition is correct are used to generate a proof (NIZK proof) π1, and the instance (r1) and the proof π1 may be transmitted to the distributed signature generation device 140. After receiving the instance (r1) and the proof π1, the distributed signature generation device 140 may verify the proof π1 using the proof verification key.
[0109] The non-interactive zero-knowledge proof that the second random number k2 is known may be performed from the distributed signature generation device 140 to the certificate holding device 120. For example, in FIG. 7, the distributed signature generation device 140 calculates r2 using, for example, the second random number k2 (step (6) of the distributed signature generation device 140 in FIG. 7), and then generates a proof π2 from a specific example of the proposition to be proven (instance: knowing the second random number k2) and the evidence that this proposition is correct. After that, the instance (r2) and the proof π2 may be sent to the certificate holding device 120, which is the verifier. The certificate holding device 120, which is the verifier, verifies the proof π2 using the proof verification key after receiving the instance (r2) and the proof π2. The certificate holding device 120 decommits with respect to the instance (r2) and the proof π2, and after the commitment is released (decommitted), the distributed signature generation device 140 may perform the verification of the proof π1 (Reference 4).
[0110] As described above, the Two-party Schnorr signature has been described as an example, but it is similarly applicable to ECDSA (Elliptic Curve Digital Signature Algorithm) as the biometric utilization distributed signature generation process (Reference 4).
[0111] FIG. 8 is a schematic diagram for explaining an example in which each device (110, 120 / 140, 130) of the above-described certificate verification system 100 is implemented by computers that have a communication function and can communicate with each other via a network. In FIG. 8(A), each device (110, 120 / 140, 130) includes a processor 201 (multiple processors are also possible), a storage device 202, an input / output device 203, and a communication interface 204. The storage device 202 may be configured to include a semiconductor storage such as a RAM (Random Access Memory), a ROM (Read Only Memory), or an EEPROM (Electrically Erasable and Programmable ROM), an HDD (Hard Disk Drive), a CD (Compact Disc), a DVD (Digital Versatile Disc), or the like. The processor 201 realizes the processing and functions of each device by executing a program (not shown) stored in the storage device 202. The input / output device 203 may be configured to include a keyboard and a display. For example, in the certificate holding device 120, the verification result in the certificate verification device 130 may be configured to be displayed and output to an output device such as a display. Also, in the certificate issuing device 110 and the certificate holding device 120 that acquire biometric information, the input / output device 203 may be configured to include a sensor that acquires biometric information. In this case, the sensor may be an image sensor (camera) when the biometric information is a face, an iris, etc., a fingerprint sensor when it is a fingerprint, or, when it is a finger vein, for example, an LED (Light Emitting Diode) that irradiates near-infrared light and a near-infrared camera that images the light transmitted through the finger. Note that the sensor may be a removable sensor such as a USB (Universal Serial Bus) device. The communication interface 204 may be configured to include a network interface card, a transceiver, etc., and communicate with each other via a LAN (Local Area Network), a WAN (Wide Area Network) such as the Internet, a wireless LAN, a mobile communication network, or the like.In addition, the communication interface 204 may be configured to have an interface in the certificate issuing device 110 or the certificate holding device 120 that communicates with an external sensor (such as a Bluetooth (registered trademark) connected sensor) and receives biometric information acquired by the external sensor.
[0112] FIG. 8(B) is a diagram illustrating an example in which the devices (110, 120 / 140, 130) of the certificate validation system 100 described above are implemented as virtual machines using server virtualization technology. Multiple virtual machines (VM303) run on a virtualization platform 302, such as a hypervisor, implemented on a physical machine 301 of the server. One or more of the devices (110, 120 / 140, 130) of the certificate validation system 100 may be implemented as virtual machines (VM303). Although there is a single physical server, a virtual server environment in which multiple servers run is provided. Each virtual machine (VM) is preferably configured to operate in an isolated environment in memory space. In this case, a program that realizes the processing of any of the devices (110, 120 / 140, 130) runs on the virtual OS (Operating System) of the virtual machine (VM). A virtual machine VM303 that virtually realizes one of the devices (110, 120 / 140, 130) may be configured to communicate with other virtual machines via a virtual network, or may be configured to communicate with other devices among the devices (110, 120 / 140, 130) via a LAN, a WAN such as the Internet, or the like via a physical interface (communication interface) of the physical machine 301. In this case, the multiple virtual machines VM303 do not need to be executed on the same physical machine, and may be configured to communicate with virtual machines VM executed on other physical machines.
[0113] The first biometric information w and the second biometric information w' may be a binary vector, a real number vector, or an integer vector.
[0114] In the above-described embodiment, a system that performs processing based on biological information was described as an example. However, the present disclosure is not limited to biological information and can also be realized using fuzzy information other than biological information. For example, it may be applied to a PUF (Physically Unclonable Function: a technology that uses individual differences generated in the manufacturing process of an IC (Integrated Circuit) chip, etc. for identifying an individual (IC chip) such as a human fingerprint).
[0115] The above-described embodiment is appended as follows (however, it is not limited thereto).
[0116] (Appendix 1) The verifiable certificate system includes a certificate issuing device, a certificate holding device, and a certificate verification device, each of which includes a processor and a communication device, The certificate issuing device, generates auxiliary data using a signature key and first biological information, generates a certificate including a verification key corresponding to the signature key, transmits the certificate and the auxiliary data to the certificate holding device, executes processing, The certificate holding device, acquires second biological information, receives the certificate and the auxiliary data transmitted from the certificate holding device, generates a signature using the second biological information and the auxiliary data, generates a certificate presentation from the certificate, and transmits the certificate presentation and the signature to the certificate verification device, executes processing, The certificate verification device, receives the certificate presentation and the signature transmitted from the certificate holding device, verifies the signature using the verification key included in the certificate, executes processing.
[0117] (Appendix 2) In the verifiable certificate system of Appendix 1, the certificate verification device generates a challenge and transmits it to the certificate holding device, the certificate holding device receives the challenge, generates the signature for the challenge by using the second biometric information and the auxiliary data, and transmits the signature together with the certificate presentation to the certificate verification device.
[0118] (Appendix 3) In the verifiable certificate system of Appendix 1 or 2, the certificate issuing device generates the auxiliary data by a first operation between the value obtained by encoding the signature key and the first biometric information, the certificate holding device restores the signature key by decrypting the value obtained by a second operation between the auxiliary data and the second biometric information.
[0119] (Appendix 4) In the verifiable certificate system according to any one of Appendices 1 to 3, the certificate verification device generates a challenge and transmits it to the certificate holding device, the certificate holding device receives the challenge, generates the signature for the challenge transmitted from the certificate verification device by a distributed signature generation process based on the second biometric information and the auxiliary data, the certificate verification device verifies the signature by using the verification key included in the certificate.
[0120] (Appendix 5) In the verifiable certificate system of Appendix 4, the certificate issuing device generates the auxiliary data by a first operation between the value obtained by encoding the signature key and the first biometric information, the certificate holding device generating a first shared key for a shared signature, and generating second auxiliary data by performing the first operation on a value obtained by encoding the first shared key and the second biometric information; A shared signature generation processing device that performs a shared signature generation process in cooperation with the certificate holding device includes: obtaining the auxiliary data from the certificate issuing device; further acquiring the second auxiliary data from the certificate holding device; a second key share for signature sharing that is a key difference between the signature key and the first key share, by decrypting a value obtained by a second operation on the auxiliary data and the second auxiliary data; generating a part of a signature for the challenge based on the second key share and sending the part to the certificate issuing device; the certificate holding device, The signature for the challenge is generated using a signature key generated from the first key share and the second key share for a part of the signature for the challenge.
[0121] (Appendix 6) A verification method in a verifiable certificate system including a certificate issuing node, a certificate holding node, and a certificate verifying node is as follows: In the certificate issuing node, generating auxiliary data using the signature key and the first biometric information; generating a certificate including a verification key corresponding to the signing key; sending the certificate and the auxiliary data to the certificate-holding node; At the certificate holding node, acquiring second biometric information; receiving the certificate and the auxiliary data transmitted from the certificate-holding node; generating a signature using the second biometric information and the auxiliary data; generating a certificate presentation from the certificate and transmitting the certificate presentation and the signature to the certificate validation node; In the certificate validation node, receiving the certificate presentation and the signature transmitted from the certificate-holding node; Verify the certificate included in the certificate presentation, and further verify the signature using the verification key included in the certificate.
[0122] (Appendix 7) In the verification method of Appendix 6, at the certificate verification node, generate a challenge and send it to the certificate holding node, at the certificate holding node, generate the signature for the challenge using the signature key restored using the second biometric information and the auxiliary data, and send it to the certificate verification node together with the certificate presentation.
[0123] (Appendix 8) In the verification method of Appendix 6 or 7, at the certificate issuing node, generate the auxiliary data by a first operation of the encoded value of the signature key and the first biometric information, at the certificate holding node, restore the signature key by decrypting the value obtained by a second operation of the auxiliary data and the second biometric information.
[0124] (Appendix 9) In any of the verification methods of Appendices 6 to 8, at the certificate verification node, send a random number as a challenge to the certificate holding node, at the certificate issuing node, generate the verification key corresponding to the signature key and the auxiliary data using the first biometric information, send the auxiliary data and the certificate to the certificate holding node, the certificate holding node generates a distributed signature for the challenge based on the second biometric information and the auxiliary data, at the certificate verification node, verify the signature using the verification key included in the certificate.
[0125] (Appendix 10) In the verification method of Appendix 9, at the certificate issuing node, generating the auxiliary data by a first calculation of a value obtained by encoding the signature key and the first biometric information; At the certificate holding node, generating a first shared key for a shared signature, and generating second auxiliary data by performing the first operation on a value obtained by encoding the first shared key and the second biometric information; In the distributed signature generation node that performs the distributed signature generation process in cooperation with the certificate holding node, acquiring the auxiliary data and the second auxiliary data; a second signature share obtained by decrypting a value obtained by a second operation on the auxiliary data and the second auxiliary data, the second signature share being a key difference between the signature key and the first key share; generating a part of a signature for the challenge based on the second key share and sending the part to the certificate issuing node; At the certificate holding node, A signature for the challenge is generated using a signature key generated from the first key share and the second key share for a part of the signature for the challenge.
[0126] (Supplementary Note 11) A program for causing at least first to third processing devices to execute processes for a certificate issuer, a certificate holder, and a certificate verifier in a verifiable certificate system, by the first processing device, generating auxiliary data using the signature key and the first biometric information; A process of generating a certificate including a verification key corresponding to the signing key; and transmitting the certificate and the auxiliary data to the second processing device; by the second processing device, A process of acquiring second biometric information; generating a signature using the second biometric information and the auxiliary data; and generating a certificate presentation from the certificate and transmitting the certificate presentation and the signature to the third processing device; by the third processing device, a process of verifying the certificate from the presentation of the certificate and verifying the signature using the verification key included in the certificate; A recording medium on which the program to be executed is recorded.
[0127] [References 1] OpenID for Verifiable Presentations - draft 20 (the internet <url>https: / / openid.net / specs / openid-4-verifiable-presentations-1_0.html) [Reference 2] Dodis, Yevgeniy / Reyzin, Leonid / Smith, Adam. "Fuzzy Extractors: How to Generate Strong Keys from Biometrics and Other Noisy Data.”, EUROCRYPT 2004. [Reference 3] Nicolosi, Antonio, et al. "Proactive Two-Party Signatures for User Authentication." NDSS. 2003. [Reference 4] Lindell, Yehuda. "Fast secure two-party ECDSA signing.” Advances in Cryptology-CRYPTO 2017: 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20-24, 2017, Proceedings, Part II 37. Springer International Publishing, 2017 [Reference 5] Japanese Unexamined Patent Application Publication No. 2021-087167 [Reference 6] Japanese Patent No. 5707311 [Reference 7] International Publication No. 2020 / 174516
[0128] Note that the disclosures of the above Non-Patent Document 1 and References 1 to 7 are incorporated herein by reference. Within the scope of the disclosure of the present application (including the claims), based on the basic technical idea thereof, changes, adjustments, and combinations of embodiments or examples are possible. Also, within the scope of the claims of the present invention, various combinations or selections of various disclosure elements (including each element of each claim, each element of each embodiment, each element of each drawing, etc.) are possible. That is, the present disclosure naturally includes all disclosures including the claims, and various modifications and corrections that could be made by those skilled in the art according to the technical idea.
Explanation of Reference Signs
[0129] 100 Certificate Verification System 101 Issuer 102 Holder 103 Verifier 110 Certificate Issuing Device 111 First Biometric Information Acquisition Unit 112 Key Generation Unit 113 Auxiliary Data Generation Unit 114 Auxiliary Data Transmission Unit 115 Certificate Generation Unit 116 Certificate Transmission Unit 120 Certificate Holding Device 121 Challenge Acquisition Unit 122 Second Biometric Information Acquisition Unit 123 Auxiliary Data Acquisition Unit 124A Storage Unit 124B Storage Unit 125 Signature Generation Unit 126 Signature Transmission Unit 127 Certificate Acquisition Unit 128 Certificate Presentation Generation Unit 129 Certificate Presentation Transmission Unit 130 Certificate Verification Device 131 Challenge Generation Unit 132 Challenge Transmission Unit 133 Signature Acquisition Unit 134 Certificate Presentation Acquisition Unit 135 Certificate Presentation Verification Unit 136 Signature Verification Unit 140 Distributed signature generation device 200 Computer 201 Processor 202 Memory device 203 Input / output device 204 Communication interface 300 Server 301 Physical machine 302 Virtualization infrastructure 303 Virtual machine< / url> < / url>
Claims
1. A verifiable certificate system including a certificate issuing device, a certificate holding device, and a certificate verification device, each of which includes a processor and a communication device, wherein the certificate issuing device generates auxiliary data using a signature key and first biometric information, generates a certificate including a verification key corresponding to the signature key, transmits the certificate and the auxiliary data to the certificate holding device, executes a process, wherein the certificate holding device acquires second biometric information, receives the certificate and the auxiliary data transmitted from the certificate holding device, generates a signature using the second biometric information and the auxiliary data, generates a certificate presentation from the certificate, and transmits the certificate presentation and the signature to the certificate verification device, executes a process, wherein the certificate verification device receives the certificate presentation and the signature transmitted from the certificate holding device, verifies the signature using the verification key included in the certificate, executes a process, a verifiable certificate system.
2. The certificate verification device generates a challenge and transmits it to the certificate holding device, wherein the certificate holding device receives the challenge, generates the signature for the challenge using the second biometric information and the auxiliary data, and transmits the signature together with the certificate presentation to the certificate verification device, the verifiable certificate system according to claim 1.
3. The certificate issuing device generates the auxiliary data by a first operation of a value obtained by encoding the signature key and the first biometric information, wherein the certificate holding device restores the signature key by decrypting a value obtained by a second operation of the auxiliary data and the second biometric information, the verifiable certificate system according to claim 1.
4. The certificate verification device generates a challenge and transmits it to the certificate holding device, wherein the certificate holding device receives the challenge, generates a signature for the challenge transmitted from the certificate verification device based on the second biometric information and the auxiliary data by a distributed signature generation process, The certificate verification device verifies the signature using the verification key included in the certificate, the verifiable certificate system according to claim 1.
5. The certificate issuing device generates the auxiliary data by a first operation of a value obtained by encoding the signature key and the first biometric information, wherein the certificate holding device Generate a first distributed key for distributed signature, and generate second auxiliary data by performing the first operation on the encoded value of the first distributed key and the second biometric information. A distributed signature generation processing device that performs distributed signature generation processing in cooperation with the certificate holding device acquires the auxiliary data from the certificate issuing device further acquires the second auxiliary data from the certificate holding device By decrypting the value obtained by performing the second operation on the auxiliary data and the second auxiliary data, obtain the key difference between the signature key and the first distributed key as the second distributed key for distributed signature. Based on the second distributed key, generate a part of the signature for the challenge and transmit it to the certificate issuing device. The certificate holding device For the part of the signature for the challenge, generate the signature for the challenge using the signature key generated from the first distributed key and the second distributed key. The verifiable certificate system according to claim 4.
6. A verification method in a verifiable certificate system including a certificate issuing node, a certificate holding node, and a certificate verification node, In the certificate issuing node, generate auxiliary data using a signature key and first biometric information, generate a certificate including a verification key corresponding to the signature key, transmit the certificate and the auxiliary data to the certificate holding node, In the certificate holding node, acquire second biometric information, receive the certificate and the auxiliary data transmitted from the certificate holding node, generate a signature using the second biometric information and the auxiliary data, generate a certificate presentation from the certificate, and transmit the certificate presentation and the signature to the certificate verification node, In the certificate verification node, receive the certificate presentation and the signature transmitted from the certificate holding node, verify the certificate included in the certificate presentation, Furthermore, a verification method for verifying the signature using the verification key included in the certificate.
7. In the certificate verification node, generate a challenge and transmit it to the certificate holding node, In the certificate holding node, generate the signature for the challenge using the signature key restored using the second biometric information and the auxiliary data, and transmit it to the certificate verification node together with the certificate presentation. The verification method according to claim 6.
8. In the certificate issuing node, generate the auxiliary data by performing the first operation on the encoded value of the signature key and the first biometric information. In the certificate holding node, The verification method according to claim 6, wherein the signature key is restored by decrypting a value obtained by a second operation between the auxiliary data and the second biometric information.
9. In the certificate verification node, Sending a random number as a challenge to the certificate holding node, In the certificate issuing node, Generating a verification key corresponding to the signature key and the auxiliary data using the first biometric information, Sending the auxiliary data and the certificate to the certificate holding node, The certificate holding node, Based on the second biometric information and the auxiliary data, generating a distributed signature for the challenge, The verification method according to claim 6, wherein in the certificate verification node, the signature is verified using the verification key included in the certificate.
10. In the certificate issuing node, Generating the auxiliary data by a first operation between a value obtained by encoding the signature key and the first biometric information, In the certificate holding node, Generating a first distributed key for distributed signature, and generating second auxiliary data by a first operation between a value obtained by encoding the first distributed key and the second biometric information, In the distributed signature generation node that performs distributed signature generation processing in cooperation with the certificate holding node, Obtaining the auxiliary data and the second auxiliary data, By decrypting a value obtained by a second operation between the auxiliary data and the second auxiliary data, obtaining a key difference between the signature key and the first distributed key as a second distributed key for distributed signature, Based on the second distributed key, generating a part of the signature for the challenge and sending it to the certificate issuing node, In the certificate holding node, The verification method according to claim 9, wherein for a part of the signature for the challenge, a signature for the challenge is generated using a signature key generated from the first distributed key and the second distributed key.
11. A program for causing each process of a certificate issuer, a certificate holder, and a certificate verifier in a verifiable certificate system to be executed by at least first to third processing devices, By the first processing device, A process of generating auxiliary data using a signature key and first biometric information, A process of generating a certificate including a verification key corresponding to the signature key, and A process of sending the certificate and the auxiliary data to the second processing device, By the second processing device, A process of obtaining second biometric information, A process of generating a signature using the second biometric information and the auxiliary data, and A process of generating a certificate presentation from the certificate and transmitting the certificate presentation and the signature to the third processing device; by the third processing device; a process of verifying the certificate from the certificate presentation and verifying the signature using the verification key included in the certificate; A recording medium recording the program to be executed.