Information processing device, user terminal, information processing system, information processing method and program

The system enables users to generate and manage verifiable certificates using their devices, addressing centralized risks by integrating My Number card information for secure, decentralized identity management.

JP2025135763APending Publication Date: 2025-09-19NTT DATA JAPAN CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024033707
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-06
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing information processing systems centralize user personal information management, leading to risks of unintentional tampering or invalidation, and lack user control over their own data.

Method used

Implement a system where users can generate and manage verifiable certificates (VCs) using their own devices, integrating My Number card information to issue and store identity verification and administrative VCs in a digital wallet, encrypting with a private key for secure control.

Benefits of technology

Users can securely manage and control their personal information without external intervention, ensuring authenticity and privacy through decentralized identity management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025135763000001_ABST
    Figure 2025135763000001_ABST
Patent Text Reader

Abstract

To provide an information processing device, an information processing method and a program that allow a user to control their own personal information according to their intention without intervention of another person when utilizing a system that certifies the validity of the user.SOLUTION: An information processing device acquires from a user terminal an issuance request which requests issuance of a verifiable certificate, and acquires from a digital data issuance terminal digital, data corresponding to the verifiable certificate of which issuance is requested by the acquired issuance request. A verifiable certificate is then generated on the basis of the acquired digital data, and the generated verifiable certificate is provided to a user by storing the certificate in a digital wallet on the user terminal.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, a user terminal, an information processing system, an information processing method, and a program. [Background technology]

[0002] Conventionally, several technologies have been proposed for verifying the identity of clients in response to requests from them and for providing certificates issued by trusted institutions. For example, Patent Document 1 discloses a system that reduces implementation and operational costs by enabling multiple registration authorities to be built on a single general-purpose computer, and enables certificate users to apply for the issuance or revocation of certificates using a simple, predetermined method. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2003-309555 Summary of the Invention [Problem to be solved by the invention]

[0004] However, in the information processing device described in Patent Document 1, the service provider issues and manages the user's personal information in a centralized manner, which raises the risk of the user unintentionally tampering with or invalidating the information. Therefore, there is room for improvement in terms of allowing the user to control their own personal information, including login information, at their own will without the intervention of others.

[0005] The present invention has been made in consideration of the above-mentioned circumstances, and aims to provide an information processing device, user terminal, information processing system, information processing method, and program that enable a user to control his or her own personal information at his or her own will without the intervention of others when using a system that proves the user's legitimacy. [Means for solving the problem]

[0006] In order to achieve the above object, an information processing device according to a first aspect of the present invention comprises: an issuance request acquisition unit that acquires an issuance request for requesting the issuance of a verifiable certificate from a user terminal; a digital data acquisition unit that acquires, from a digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired by the issuance request acquisition unit; a certificate generation unit that generates the verifiable certificate based on the digital data acquired by the digital data acquisition unit; a certificate providing unit that provides the verifiable certificate generated by the certificate generating unit to the user by storing the verifiable certificate in a digital wallet in the user terminal; Equipped with.

[0007] the digital data acquisition unit acquires My Number card information included in the My Number card of the user, and acquires the digital data corresponding to the verifiable certificate requested to be issued by the issuance request from the digital data issuing terminal based on the My Number card information; This may be done.

[0008] the certificate generation unit acquires My Number card information included in the My Number card of the user, and generates the verifiable certificate indicating that the user is the person in question based on the My Number card information; the certificate providing unit provides the verifiable certificate, which indicates the identity of the user, to the user by storing the certificate in a digital wallet in the user terminal; This may be done.

[0009] In order to achieve the above object, a user terminal according to a second aspect of the present invention comprises: a request sending unit that sends an issuance request for a verifiable certificate to an issuing server; a certificate acquisition unit that acquires the verifiable certificate generated by the issuing server from the issuing server; a certificate storage unit that stores the verifiable certificate acquired by the certificate acquisition unit in a digital wallet; Equipped with.

[0010] A key generation unit that generates keys necessary for operating the digital wallet, the certificate storage unit encrypts the verifiable certificate using the key generated by the key generation unit when storing the verifiable certificate in the digital wallet; This may be done.

[0011] When storing the verifiable certificate in the digital wallet, the certificate storage unit further encrypts the key generated by the key generation unit with a private key of the My Number Card. This may be done.

[0012] In order to achieve the above object, an information processing system according to a third aspect of the present invention comprises: An information processing system having an information processing device, a digital data issuing terminal, and a user terminal, The information processing device includes: an issuance request acquisition unit that acquires an issuance request for a verifiable certificate from the user terminal; a digital data acquisition unit that acquires, from the digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired by the issuance request acquisition unit; a certificate generation unit that generates the verifiable certificate based on the digital data acquired by the digital data acquisition unit; a certificate providing unit that provides the verifiable certificate generated by the certificate generating unit to the user by storing the verifiable certificate in a digital wallet in the user terminal; Equipped with The user terminal a request sending unit that sends the issuance request to the information processing device; a certificate acquisition unit that acquires the verifiable certificate generated by the information processing device from the information processing device; a certificate storage unit that stores the verifiable certificate acquired by the certificate acquisition unit in a digital wallet; Equipped with.

[0013] In order to achieve the above object, an information processing method according to a fourth aspect of the present invention comprises: An information processing method by an information processing device, an issuance request acquisition step of acquiring an issuance request for requesting issuance of a verifiable certificate from a user terminal; a digital data acquisition step of acquiring, from a digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired in the issuance request acquisition step; a certificate generation step of generating the verifiable certificate based on the digital data acquired in the digital data acquisition step; a certificate providing step of providing the verifiable certificate generated in the certificate generating step to the user by storing the verifiable certificate in a digital wallet in the user terminal; Equipped with.

[0014] In order to achieve the above object, a program according to a fifth aspect of the present invention comprises: Computer, an issuance request acquisition unit that acquires an issuance request for requesting the issuance of a verifiable certificate from a user terminal; a digital data acquisition unit that acquires, from a digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired by the issuance request acquisition unit; a certificate generation unit that generates the verifiable certificate based on the digital data acquired by the digital data acquisition unit; a certificate providing unit that provides the verifiable certificate generated by the certificate generating unit to the user by storing the verifiable certificate in a digital wallet in the user terminal; Function as. [Effects of the Invention]

[0015] According to the present invention, when using a system that certifies the legitimacy of a user, the user can control his or her own personal information at his or her own will without the intervention of others. [Brief explanation of the drawings]

[0016] [Figure 1] FIG. 1 is a block diagram illustrating an example of an information processing system. [Figure 2] FIG. 2 is a block diagram illustrating an example of a user terminal. [Figure 3] FIG. 1 is a block diagram illustrating an example of an information processing device. [Figure 4] FIG. 10 is an explanatory diagram showing an example of a VC. [Figure 5] 10 is a flowchart illustrating an example of processing by an information system. [Figure 6] FIG. 10 is an explanatory diagram showing an example of a display on a user terminal. [Figure 7] FIG. 10 is an explanatory diagram showing an example of a display on a user terminal. [Figure 8] 10 is a flowchart illustrating an example of processing by an information system. [Figure 9] FIG. 10 is an explanatory diagram showing an example of a display on a user terminal. [Figure 10] 10 is a flowchart showing an example of a VP submission process in a user terminal. [Figure 11] FIG. 10 is an explanatory diagram showing an example of a display on a user terminal. DETAILED DESCRIPTION OF THE INVENTION

[0017] (Embodiment) An information processing device, an information processing method, and a program according to an embodiment of the present invention will be described in detail with reference to the drawings. The same or corresponding parts in the drawings are denoted by the same reference numerals. The following description will be given using an example in which the information processing device of the present invention is applied to an information processing system 1 shown in FIG.

[0018] 1, in the information processing system 1, a user terminal 100, an application server 200, an information processing device 300, and an administrative terminal 400 are communicably connected via a network 210 such as the Internet. In the illustrated example, there is one user terminal 100 and one administrative terminal 400, but in actuality, there are multiple user terminals 100 and one administrative terminal 400.

[0019] As shown in Fig. 1, the user terminal 100 is an information terminal connected to a network 210. The user terminal 100 is an information terminal (so-called computer) such as a mobile phone, smartphone, tablet, or PC (Personal Computer) owned by a user, and is capable of transmitting and receiving various data to and from an application server 200, an information processing device 300, and an administrative terminal 400 via the network 210. The user terminal 100 and the application server 200 are linked via an API (Application Programming Interface). Therefore, a user can use the functions of the application server 200 simply by starting an application on the user terminal 100 and logging in.

[0020] The application server 200 is a server that realizes the functions of an application stored in the user terminal 100. The application server 200 provides the user terminal 100 with various functions that can be used in the application.

[0021] The information processing device 300 is an information terminal such as a smartphone, tablet, server, or PC, and is capable of transmitting and receiving various data to and from the user terminal 100, the application server 200, and the administrative terminal 400 via the network 210. The information processing device 300 in this embodiment has a function of issuing VC (Verifiable Credentials), which are self-sovereign digital personal information (verifiable certificates) whose contents can be verified online, to the user terminal 100. Note that digital personal information includes, for example, personal information such as age, name, and address, as well as digitized versions of various personal information physically possessed by the user, such as a resident card, tax payment certificate, seal registration certificate, driver's license, qualification certificate, and academic certificate. As will be described in detail later, the information processing device 300 in this embodiment has a function of generating an identity verification VC based on a VC issuance request received from the user terminal 100 and issuing the identity verification VC to the user terminal 100, and a function of generating an administrative VC based on digital data of administrative jurisdiction documents acquired from the administrative terminal 400 and issuing the administrative VC to the user terminal 100. The identity verification VC is a VC that proves the identity of the user, and corresponds to a verifiable certificate that proves the identity of the user. The administrative VC is a VC that corresponds to administrative jurisdiction documents (administrative jurisdiction data) issued by the government, such as a resident registration card.

[0022] The administrative terminal 400 is an information terminal such as a smartphone, tablet, server, or PC used in an administrative agency, and is capable of transmitting and receiving various data to and from the information processing device 300 via the network 210. The administrative terminal 400 has a function of providing the information processing device 300 with digital data of personal information (administrative jurisdiction data) corresponding to an issuance request in response to a request received from the information processing device 300 via the MynaPortal API, for example. In other words, the administrative terminal 400 that provides the information processing device 300 with digital data of personal information (administrative jurisdiction data) corresponding to the issuance request via the MynaPortal API corresponds to a digital data issuing terminal.

[0023] Next, the configuration of the user terminal 100 will be described with reference to Fig. 2. As shown in Fig. 2, the user terminal 100 includes a storage unit 110, a control unit 120, an input / output unit 130, a communication unit 140, and a system bus (not shown) that interconnects these units.

[0024] The storage unit 110 includes a ROM (Read Only Memory), a RAM (Random Access Memory), etc. The ROM stores a program 111 executed by the control unit 120, various data (not shown) required in advance for executing the program 111, a wallet 112, and an encryption key 113.

[0025] Program 111 is a program that executes the initial setting process (see Figure 5), VC acquisition process (see Figure 8), and VP submission process (see Figure 10) described below, and is stored in memory unit 110 through API integration with application server 200.

[0026] The wallet 112 is a digital identity wallet that allows a user to store their own ID information and provide it to a service they wish to link with. The wallet 112 uses an identifier (DID (Decentralized Identifier)) assigned to the user (not necessarily singular), and VC is stored in the wallet 112. As a result, for example, when a user combines data (VC) stored in the wallet 112 and submits it to a business as a verifiable presentation (VP), the business can verify the contents of the signature data attached to the VC and determine that the data was issued by a legitimate issuer. The wallet 112 is generated by an initial setting process (described later) and stored in the storage unit 110. Note that by managing IDs using distributed ledger technology with the DID, it is possible to reduce the dependency of digital identities on so-called identity providers (IdPs), such as specific countries or businesses. The wallet 112 corresponds to a digital wallet.

[0027] The encryption key 113 is a key obtained by encrypting the private key handled in the wallet 112 using the private key in the My Number card. The encryption key 113 is encrypted by an initial setting process described later and stored in the storage unit 110.

[0028] The control unit 120 is configured with a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), etc. The control unit 120 operates in accordance with a program 111 stored in the storage unit 110, and executes processing in accordance with the program 111. The control unit 120 includes, as main functional units provided by the program 111 stored in the storage unit 110, a personal information acquisition unit 121, a wallet generation unit 122, a key encryption unit 123, a VC issuance request unit 124, and a VP generation unit 125. As described above, the user terminal 100 and the application server 200 are API-linked, and therefore these functional units in the control unit 120 are realized in cooperation with the application server 200.

[0029] The personal information acquisition unit 121 is a functional unit that performs identity authentication and acquires personal information if the authentication is successful. Specifically, the personal information acquisition unit 121 performs identity authentication by performing authentication using a personal identification number entered to read the My Number card (see FIG. 6), and if the authentication is successful, it is a functional unit that reads information stored in the My Number card (see FIG. 7) to acquire the personal information stored in the My Number card. Note that the personal information acquisition unit 121 may perform identity authentication by installing an electronic certificate for the My Number card in the user terminal 100 and performing a personal identification number and biometric authentication linked to the personal identification number.

[0030] 2 is a functional unit that generates the wallet 112. Specifically, the wallet generation unit 122 has a function of generating the wallet 112, which is a digital identity wallet that uses an identifier (DID) assigned to a user, and generating a pair of keys consisting of a private key required for operating a VC stored in the wallet 112 and a public key corresponding to the private key.

[0031] The key encryption unit 123 is a functional unit that generates the encryption key 113. Specifically, the key encryption unit 123 is a functional unit that generates the encryption key 113 by encrypting the private key generated by the wallet generation unit 122 using the private key in the My Number card.

[0032] The VC issuance request unit 124 is a functional unit that transmits a VC issuance request that requests the issuance of a VC to the information processing device 300. Specifically, the VC issuance request unit 124 is a functional unit that has a function of transmitting, to the information processing device 300, personal identification VC issuance request information that is a request for issuance of a personal identification VC that proves that the user is the person in question, and a function of transmitting, to the information processing device 300, administrative VC issuance request information that indicates a request for issuance of an administrative VC that is a VC corresponding to a document issued by the government.

[0033] The VP generation unit 125 is a functional unit that generates a VP that includes only the information required by the business entity that is the recipient of the submission. Specifically, the VP generation unit 125 is a functional unit that generates a VP by combining multiple VCs that include only the information required by the recipient, among the VCs stored in the wallet 112.

[0034] The input / output unit 130 is a device that is configured with a keyboard, a mouse, a camera, a microphone, a liquid crystal display, an organic EL (Electro-Luminescence) display, and the like, and is used to input and output various types of data.

[0035] The communication unit 140 is a device that enables the user terminal 100 to communicate with other information terminals, such as the application server 200 and the information processing device 300, via the network 210. The communication unit 140 also includes a function that enables the user terminal 100 to communicate with external security devices, including My Number cards, by short-range wireless communication such as NFC (Near Field Communication).

[0036] Next, the configuration of the information processing device 300 will be described with reference to Fig. 3. As shown in Fig. 3, the information processing device 300 includes a storage unit 310, a control unit 320, an input / output unit 330, a communication unit 340, and a system bus (not shown) that interconnects these units.

[0037] The storage unit 310 includes a ROM, a RAM, etc. The ROM stores a program 311 to be executed by the control unit 320, and various data (not shown) required in advance for executing the program 311.

[0038] The program 311 is a program for executing a VC issuing process (see FIGS. 5 and 8) to be described later, and is stored in the storage unit 110 in advance.

[0039] The control unit 320 is configured with a CPU, an ASIC, etc. The control unit 320 operates in accordance with a program 311 stored in the storage unit 310, and executes processing in accordance with the program 311. The control unit 320 includes a VC issuing unit 321 and an administrative jurisdiction data acquiring unit 322 as main functional units provided by the program 311 stored in the storage unit 310.

[0040] The VC issuing unit 321 is a functional unit that issues a personal identification VC and an administrative VC. Specifically, the VC issuing unit 321 is a functional unit that has a function of generating a personal identification VC based on a VC issuance request received from the user terminal 100, and a function of generating an administrative VC based on digital data of personal information acquired from the administrative terminal 400. As shown in FIG. 4, each of the personal identification VC and the administrative VC includes "metadata," "certification content data," and "signature data." Therefore, the business operator to whom the VP is submitted can determine that the data has been issued by a legitimate issuer by verifying the contents of the VC signature data included in the VP.

[0041] The administrative jurisdiction data acquisition unit 322 is a functional unit that acquires digital data of personal information under the jurisdiction of the administration from the administrative terminal 400. Specifically, the administrative jurisdiction data acquisition unit 322 is a functional unit that acquires digital data of personal information (administrative jurisdiction document) corresponding to the administrative VC that the user wishes to issue (for example, administrative jurisdiction data such as digital data of a resident registration card or digital data of a tax payment certificate) from the administrative terminal 400 via the Mynaportal API.

[0042] The input / output unit 330 is a device that is configured with a keyboard, a mouse, a camera, a microphone, a liquid crystal display, an organic EL (Electro-Luminescence) display, and the like, and is used to input and output various types of data.

[0043] The communication unit 340 is a device that enables the information processing device 300 to communicate with other information terminals such as the user terminal 100, the application server 200, and the information processing device 300 via the network 210.

[0044] The above is the configuration of the user terminal 100 and the information processing device 300. Next, the operation of the information processing system 1 will be described. Fig. 5 is a flowchart showing an example of processing of the information system. Note that the processing of the information system begins when an application is started by an input operation by the user, and an operation to execute initial setting processing is performed, thereby starting initial setting processing in the user terminal 100.

[0045] When the initial setting process starts, the control unit 120 of the user terminal 100 authenticates the user using the function of the personal information acquisition unit 121 (step S11). Specifically, in the process of step S11, the personal information acquisition unit 121 displays a screen for reading personal information from a My Number card, as shown in Fig. 6, and authenticates the user by confirming the validity of the personal identification number entered by the user. Note that in the process of step S11, the personal information acquisition unit 121 may be configured to authenticate the user by loading an electronic certificate of the My Number card into the user terminal 100 and performing a personal identification number and biometric authentication linked to the personal identification number.

[0046] 5, the control unit 120 determines whether the authentication in the process of step S11 is successful or not by the function of the personal information acquisition unit 121 (step S12). If the authentication is unsuccessful (step S12; No), the control unit 120 ends the initial setting process. Note that if the authentication is unsuccessful, the user may be prompted to input the PIN again.

[0047] On the other hand, if it is determined in the processing of step S12 that the authentication is successful (step S12; Yes), the control unit 120 uses the function of the personal information acquisition unit 121 to read the user's My Number card as shown in Fig. 7 and acquire personal information stored in the My Number card (step S13). Note that the personal information acquired in the processing of step S13 may include information on the electronic certificate stored in the My Number card in addition to the four basic pieces of information, name, sex, address, and date of birth.

[0048] 5, the control unit 120 generates wallet 112, which is a digital identity wallet that uses the identifier (DID) assigned to the user, by the function of the wallet generation unit 122, and generates a pair of keys consisting of a private key required for operating a VC stored in the wallet 112 and a public key corresponding to the private key (step S14). The wallet generation unit 122 that generates the pair of keys in the processing of step S14 corresponds to the key generation unit.

[0049] After executing the processing of step S14, the control unit 120 uses the function of the key encryption unit 123 to encrypt the private key generated in the processing of step S14 using the private key of the My Number card, thereby generating the encryption key 113 (step S15).

[0050] After executing the process of step S15, the control unit 120 makes a personal verification VC issuance request, which is a request to issue a personal verification VC that proves that the user is the person himself / herself, by the function of the VC issuance request unit 124 (step S16). Specifically, in the process of step S16, the VC issuance request unit 124 makes a personal verification VC issuance request by transmitting personal verification VC issuance request information including the basic four information included in the personal information acquired in the process of step S13 to the information processing device 300.

[0051] On the information processing device 300 side, when receiving the identity verification VC issuance request information from the user terminal 100, the information processing device 300 starts executing the VC issuance process. When the VC issuance process starts, the control unit 320 of the information processing device 300 generates an identity verification VC based on the four basic information included in the received identity verification VC issuance request information by the function of the VC issuing unit 321 (step S17). Note that in the processing of step S17, the VC issuing unit 321 transmits, for example, the electronic certificate information of the My Number card included in the received identity verification VC issuance request information to the Japan Agency for Local Authority Information Systems (J-LIS), and generates the identity verification VC after confirming the validity of the electronic certificate information. Note that the validity of the four basic information is confirmed in the identity verification VC, and signature data by the private key of the information processing device 300 is added. The private key of the information processing device 300 may be generated in pair with the corresponding public key, for example, when the information processing device 300 starts operation. Also, for example, the metadata includes information on the VC issuer (the information processing device 300 is the issuer), the certification content data includes the basic four information and the DID of the user to be certified, and the signature data includes signature data obtained by processing the hash of the metadata and certification content data with a private key, the signature type, signature date, signature purpose, signature means, signer, etc. There are at least two methods for issuing a personal authentication VC in the processing of step S17: a method in which a personal authentication VC is issued for each item of the basic four information (in this case, the certification content includes each item + the user's DID), and a different method in which all information of the basic four information is included in one personal authentication VC and the disclosure range can be selected for each item. In this embodiment, the method in which a personal authentication VC is issued for each item of the basic four information is used.

[0052] After executing the process of step S17, the control unit 320 records the validity of the identity verification VC generated in the process of step S17 in a predetermined area of ​​the storage unit 110 (step S17A). For example, in the process of step S17A, a validity period indicating how long the identity verification VC generated in the process of step S17 is valid may be set.

[0053] After executing the processing of step S17A, the control unit 320 uses the function of the VC issuing unit 321 to send the identity verification VC generated in the processing of step S17 to the user terminal 100, thereby providing the generated identity verification VC to the user (step S18), and terminates the VC issuance processing.

[0054] On the user terminal 100 side, when the personal identification VC is received from the information processing device 300, the received personal identification VC is stored in the wallet 112 (step S19), and the initial setting process is terminated. When storing the personal identification VC, the personal identification VC is encrypted. Various means may be used to encrypt the personal identification VC, such as using the private key generated in step S14. When using the private key generated in step S14, the key encryption unit 123 may encrypt the private key using the private key of the My Number card to generate the encryption key 113.

[0055] In this way, by executing the initial setting process by the user terminal 100, the wallet 112 is generated and the personal identification VC is issued by the information processing device 300. In addition, in the initial setting process, the private key generated together with the wallet 112 is encrypted using the private key of the My Number card, and the encryption key 113 is generated.

[0056] Next, the operation of the information processing system 1 when a user desires to issue an administrative VC will be described. Fig. 8 is a flowchart showing an example of the processing of the information system. The processing of the information system starts when an application is started by an input operation by the user, and the user performs an operation to the effect that he desires to issue an administrative VC, and the VC acquisition processing in the user terminal 100 is started. In this example, for ease of understanding, the following description will be given taking as an example a case where the user desires to issue a VC corresponding to a resident registration card.

[0057] 8 starts, the control unit 120 of the user terminal 100 makes an administrative VC issuance request to the information processing device 300 to issue an administrative VC in accordance with the user's input operation, using the function of the VC issuance request unit 124 (step S31). Specifically, in the processing of step S31, the VC issuance request unit 124 transmits administrative VC issuance request information requesting the issuance of an administrative VC corresponding to the administrative jurisdiction document (administrative jurisdiction data) selected by the user to the information processing device 300. For example, if the user desires the issuance of a VC corresponding to a resident card, the user selects "resident card" from the selection screen displayed on the user terminal 100 and presses the "OK" button, as shown in FIG. 9. As a result, in the processing of step S31, the VC issuance request unit 124 transmits administrative VC issuance request information corresponding to the resident card to the information processing device 300, thereby requesting the issuance of the administrative VC to the information processing device 300. The VC issuance request unit 124 that requests the issuance of the administrative VC to the information processing device 300 in the processing of step S31 corresponds to the request sending unit.

[0058] 8, when the administrative VC issuance request information is sent to the information processing device 300 in the processing of step S31, the information processing device 300 receives the administrative VC issuance request information from the user terminal 100, and starts executing the VC issuance process in response to this. Note that the function of the information processing device 300 that receives the administrative VC issuance request information and the step correspond to the issuance request acquisition unit and the issuance request acquisition step.

[0059] When the VC issuance process is started, the control unit 320 of the information processing device 300 requests the user terminal 100 to authenticate using the My Number card by transmitting an authentication request using the function of the VC issuing unit 321 (step S32). Specifically, in the process of step S32, the VC issuing unit 321 sequentially displays the display screens of Fig. 6 and Fig. 7 on the user terminal 100, and requests the personal information acquiring unit 121 of the user terminal 100 to read personal information stored in the My Number card. That is, in the process of step S32, personal identification based on My Number card authentication based on Mynaportal API (PIN (Personal Identification Number) input and reading of electronic certificate, etc.) may be requested.

[0060] Returning to Fig. 8, when the user terminal receives an authentication request, the personal information acquisition unit 121 displays a screen for reading personal information from the My Number card as shown in Fig. 6, and authenticates the user by confirming the validity of the personal identification number entered by the user (step S33), similar to the process of step S11 in Fig. 5. Note that in the process of step S33, the personal information acquisition unit 121 may authenticate the user by loading an electronic certificate of the My Number card into the user terminal 100 and performing a personal identification number and biometric authentication linked to the personal identification number.

[0061] 8, the control unit 120 determines whether the authentication in the process of step S33 is successful or not by the function of the personal information acquisition unit 121 (step S34). If the authentication is unsuccessful (step S34; No), the control unit 120 ends the VC acquisition process. If the authentication is unsuccessful, the control unit 120 may prompt the user to input the PIN again.

[0062] On the other hand, if it is determined in the processing of step S34 that the authentication is successful (step S34; Yes), the control unit 120 uses the function of the personal information acquisition unit 121 to read the user's My Number card as shown in Fig. 7 and acquire the personal information stored in the My Number card (step S35). Note that, as shown in Fig. 8, the personal information on the My Number card acquired in the processing of step S35 is transmitted to the information processing device 300.

[0063] On the information processing device 300 side, when the My Number card information is received from the user terminal 100, the administrative jurisdiction data acquisition unit 322 acquires administrative jurisdiction data based on the received My Number card information (step S36). Specifically, in the processing of step S36, the administrative jurisdiction data acquisition unit 322 acquires digital data (administrative jurisdiction data) of personal information (administrative jurisdiction document) corresponding to the administrative VC that the user wishes to be issued from the administrative terminal 400 via the My Number Portal API. In this example, digital data of the resident registration card corresponding to the user identified by the received My Number card information is acquired from the administrative terminal 400 via the My Number Portal API. The administrative jurisdiction data acquisition unit 322 that executes the processing of step S36 and step S36 correspond to the digital data acquisition unit and the digital data acquisition step, respectively.

[0064] After executing the processing of step S36, the control unit 320 generates an administrative VC based on the administrative jurisdiction data acquired in the processing of step S36 using the function of the VC issuing unit 321 (step S37). Specifically, in the processing of step S37, the VC issuing unit 321 generates an administrative VC signed with the private key of the information processing device 300, using the contents of the digital data of the resident record acquired in the processing of step S36 as certification content data. Note that the generated administrative VC may be generated for each item included in the resident record, such as the address, name, name of the head of household, and registered domicile, or one VC including all items included in the resident record may be generated. In this embodiment, to facilitate understanding of the VP submission processing described later, it is assumed that a VC is generated for each item. That is, in the processing of step S37, the VC issuing unit 321 may generate an administrative VC corresponding to each item included in the resident record, such as an administrative VC in which the address item included in the resident record is used as metadata, the address information is used as certification content data, and the administrative agency that issued the digital data is used as signature data. The VC issuing unit 321 that executes the process of step S37 and step S37 correspond to the certificate generating unit and the certificate generating step, respectively. Also, the information processing device 300 that issues the administrative VC corresponds to the issuing server. In addition, when a VC is issued in a company, the server that issues the VC in the company becomes the issuing server.

[0065] After executing the processing of step S37, the control unit 320 provides the administrative VC by transmitting the administrative VC generated in the processing of step S37 to the user terminal 100 by the function of the VC issuing unit 321 (step S38), and ends the VC issuing processing. The VC issuing unit 321 that executes the processing of step S38 and step S38 correspond to the certificate providing unit and the certificate providing step, respectively.

[0066] On the user terminal 100 side, when the administrative VC is received from the information processing device 300, the received administrative VC is stored in the wallet 112 (step S39), and the VC acquisition process is terminated. When storing the administrative VC, the administrative VC is encrypted. Various means may be used to encrypt the administrative VC, such as using the private key generated in step S14. When using the private key generated in step S14, the key encryption unit 123 may encrypt the private key using the private key of the My Number card to generate the encryption key 113. The function of storing the received administrative VC in the wallet 112 in the process of step S39 corresponds to the certificate storage unit, and the function of receiving the administrative VC from the information processing device 300 corresponds to the certificate acquisition unit.

[0067] In this way, the information processing device 300 generates an administrative VC based on the administrative jurisdiction document acquired from the administrative terminal 400, making it possible for the user to acquire an administrative VC corresponding to the administrative jurisdiction document (administrative jurisdiction data) desired by the user. Furthermore, since administrative jurisdiction data is acquired based on My Number card information, the authenticity of the user can be ensured. When the four basic pieces of information stored on the My Number card, such as name, gender, address, and date of birth, are acquired in the processing of step S35, the four basic pieces of information are transmitted to the information processing device 300 as My Number card information. In addition, the personal verification VC stored in the wallet 112 may also be transmitted to the information processing device 300. This allows the information processing device 300 to determine whether the user indicated by the My Number card information matches the user indicated by the personal verification VC, thereby further enhancing the authenticity of the user. The personal verification VC may be included in the administrative VC issuance request information transmitted in the processing of step S31. The personal verification VC is decrypted using the same means used for encryption in step S19. When the private key generated in step S14 is used for decryption, if the private key has been encrypted by the key encryption unit 123 with the private key of the My Number card, the private key is decrypted from the encryption key 113 using the private key of the My Number card before decryption using the private key.

[0068] Next, the operation of the user terminal 100 when a user submits a VP to a submission destination based on the acquired VC will be described. FIG. 10 is a flowchart showing an example of the VP submission process on a user terminal. The VP submission process begins when an application is launched by a user's input operation and an operation to submit a VP is performed. In this example, the administrative VC corresponding to the address and the administrative VC corresponding to the name are combined from the administrative VCs of the acquired resident registration (the administrative VCs of each item included in the resident registration) and the combination is submitted to a business as a VP. The following description assumes that the business to which the VP is to be submitted has already been set. The business to which the VP is to be submitted may be set by the user selecting from multiple options, or the address of the business wallet of the business to which the VP is to be submitted may be entered directly. In the case of direct input, various means may be used, such as specifying the business's address or endpoint.

[0069] When the VP submission process shown in Fig. 10 is started, the control unit 120 of the user terminal 100 acquires disclosure selection information indicating the information to be disclosed selected by the user (step S51). Specifically, as shown in Fig. 11, if the user selects address and name information from the various information included in the resident registration card, the control unit 120 acquires the address and name information selected by the user as disclosure selection information in the process of step S51.

[0070] Returning to FIG. 10, after executing the process of step S51, the control unit 120, using the function of the VP generation unit 125, combines the VCs corresponding to the selected disclosure information acquired in the process of step S51 to generate a VP (step S52). Specifically, in the process of step S52, the VP generation unit 125 combines the administrative VC corresponding to the address selected in the process of step S51 and the administrative VC corresponding to the name among the administrative VCs stored in the wallet 112, and generates a VP for submission by performing an electronic signature using the private key of the user terminal 100, i.e., the private key generated in the process of step S14 of FIG. 5. Note that in the process of step S52, the VP generation unit 125 may also combine the personal identification VC corresponding to the information selected in the process of step S51 as a VP. Specifically, in addition to the administrative VC corresponding to the address and the administrative VC corresponding to the name selected in the process of step S51, the VP generation unit 125 may further combine the personal identification VC corresponding to the address and the personal identification VC corresponding to the name and generate this as a VP. This makes it possible to determine whether the information indicated by the administrative VC matches the user indicated by the personal identification VC, thereby further improving the authenticity of the user. The administrative VC decrypts the data using the means used for encryption in step S39. When using the private key generated in step S14 for decryption, if the private key has been encrypted by the key encryption unit 123 with the private key of the My Number card, the private key is decrypted from the encryption key 113 using the private key of the My Number card before decryption using the private key.

[0071] After executing the process of step S52, the control unit 120 submits the VP generated in the process of step S52 to the designated business operator (step S53), and ends the VP submission process. Specifically, in the process of step S53, the control unit 120 submits the VP to the designated business operator by sending the VP generated in the process of step S52 to the wallet of the designated business operator.

[0072] The above is the operation of the user terminal 100 in the VP submission process. In this way, the VP combined with the VC corresponding to the information selected by the user is submitted to the destination wallet. Therefore, the user can select and submit only the information they wish to disclose to the destination, and can refrain from submitting information they do not wish to disclose.

[0073] As described above, the information processing system 1 in this embodiment can determine whether the information indicated by each administrative VC included in the submitted VP matches the information indicated by the identity verification VC. Therefore, it can be used to verify the authenticity of the user.

[0074] Furthermore, according to the information processing system 1 in this embodiment, it is possible to provide a user with an administrative VC generated based on digital data acquired from the administrative terminal 400 via the My Number Portal API. This allows the user to manage the administrative VC in the wallet 112, which is a digital identity wallet, thereby improving convenience and security. In other words, a certificate issued by an external organization such as an administrative agency that has not issued the VC can be used as the VC and can be controlled at the user's own discretion without the intervention of others.

[0075] Furthermore, according to the information processing system 1 of this embodiment, the private key (private key for the wallet) generated together with the wallet 112, which is a digital identity wallet, when the wallet 112 is generated is encrypted using the private key in the My Number card, and managed as the encryption key 113. This improves security because even if the encryption key 113 is leaked, it cannot be used fraudulently unless it is decrypted using the private key in the My Number card using the user's own My Number card. Also, because the private key for the wallet is encrypted using the private key in the My Number card, even if the user terminal 100 is lost or damaged, the private key for the wallet can be regenerated while ensuring high security by combining it with separately saved information.

[0076] (Variation) It should be noted that the present invention is not limited to the above-described embodiment, and various modifications and applications are possible. For example, the user terminal 100 according to the above-described embodiment does not need to have all of the technical features described above, but may have some of the configurations described in the above-described embodiment so as to solve at least one problem in the prior art. Furthermore, at least a portion of each of the following modifications may be combined.

[0077] In the above embodiment, an example has been shown in which the information processing device 300 generates an administrative VC based on digital data of administrative jurisdiction documents acquired from the administrative terminal 400, but this is just one example. The information processing device 300 may also generate a corporate VC based on digital data acquired from a company, such as resume data registered in advance. In this case, the corporate VC does not have to be generated by the information processing device 300; for example, the corporate VC may be generated at an information terminal of the company, and the information processing device 300 may acquire the corporate VC generated at the information terminal of the company and provide it to the user terminal 100.

[0078] In addition, in the above embodiment, an example was shown in which the identity verification VC and administrative VC were generated for each item, but this is just one example. The identity verification VC may not be generated as four VCs corresponding to each of the four basic pieces of information, but as a single VC including all four pieces of information from the four basic pieces of information. Similarly, for the administrative VC, instead of a VC for each item included in the resident record, such as address, name, head of household name, and registered domicile, a VC including all items included in the resident record may be generated. In this case, in the VP submission process shown in FIG. 10, the parts corresponding to the information selected in the process of step S51 are extracted from the identity verification VC and administrative VC, and the extracted parts are combined to generate a VP.

[0079] Furthermore, in the above embodiment, an example has been shown in which the identity verification VC and administrative VC are stored in wallet 112, but for example, the identity verification VC and administrative VC may be encrypted using a private key owned by user terminal 100 and stored in wallet 112. Furthermore, the identity verification VC generated in the processing of step S17 in Fig. 5 may also be stored in information processing device 300, and the identity verification VC stored in information processing device 300 may also be encrypted. Then, the identity of the user may be verified on the information processing device 300 side using the identity verification VC.

[0080] The user terminal 100 and information processing device 300 according to the above-described embodiments can be realized using a normal computer, rather than a dedicated device. For example, the user terminal 100 and information processing device 300 that execute the above-described processes may be configured by installing a program for executing any of the above-described processes on a computer from a recording medium that stores the program. Also, a single user terminal 100 may be configured by multiple computers operating in cooperation with each other.

[0081] Furthermore, when the above-mentioned functions are realized by sharing the functions between an OS (Operating System) and an application, or by cooperation between the OS and the application, only the parts other than the OS may be stored on the medium.

[0082] It is also possible to superimpose the program on a carrier wave and distribute it via a communication network. For example, the program may be posted on a bulletin board system (BBS) on the communication network and distributed via the network. These programs may then be started and run under the control of an operating system in the same way as other application programs, thereby enabling the above-mentioned processing to be performed. [Explanation of symbols]

[0083] 1 Information processing system, 100 User terminal, 110, 310 Memory unit, 111, 311 Program, 112 Wallet, 113 Encryption key, 120, 320 Control unit, 121 Personal information acquisition unit, 122 Wallet generation unit, 123 Key encryption unit, 124 VC issuance request unit, 125 VP generation unit, 130, 330 Input / output unit, 140, 340 Communication unit, 200 Application server, 210 Network, 300 Information processing device, 321 VC issuing unit, 322 Administrative jurisdiction data acquisition unit, 400 Administrative terminal

Claims

1. an issuance request acquisition unit that acquires an issuance request for requesting the issuance of a verifiable certificate from a user terminal; a digital data acquisition unit that acquires, from a digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired by the issuance request acquisition unit; a certificate generation unit that generates the verifiable certificate based on the digital data acquired by the digital data acquisition unit; a certificate providing unit that provides the verifiable certificate generated by the certificate generating unit to the user by storing the verifiable certificate in a digital wallet in the user terminal; An information processing device comprising:

2. the digital data acquisition unit acquires My Number card information included in the My Number card of the user, and acquires the digital data corresponding to the verifiable certificate requested to be issued by the issuance request from the digital data issuing terminal based on the My Number card information; The information processing device according to claim 1 .

3. the certificate generation unit acquires My Number card information included in the My Number card of the user, and generates the verifiable certificate indicating that the user is the person in question based on the My Number card information; the certificate providing unit provides the verifiable certificate, which indicates the identity of the user, to the user by storing the certificate in a digital wallet in the user terminal; 3. The information processing device according to claim 1.

4. a request sending unit that sends an issuance request for a verifiable certificate to an issuing server; a certificate acquisition unit that acquires the verifiable certificate generated by the issuing server from the issuing server; a certificate storage unit that stores the verifiable certificate acquired by the certificate acquisition unit in a digital wallet; A user terminal comprising:

5. A key generation unit that generates keys necessary for operating the digital wallet, the certificate storage unit encrypts the verifiable certificate using the key generated by the key generation unit when storing the verifiable certificate in the digital wallet; 5. The user terminal according to claim 4.

6. When storing the verifiable certificate in the digital wallet, the certificate storage unit further encrypts the key generated by the key generation unit with a private key of the My Number Card.

6. The user terminal according to claim 5.

7. An information processing system having an information processing device, a digital data issuing terminal, and a user terminal, The information processing device includes: an issuance request acquisition unit that acquires an issuance request for a verifiable certificate from the user terminal; a digital data acquisition unit that acquires, from the digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired by the issuance request acquisition unit; a certificate generation unit that generates the verifiable certificate based on the digital data acquired by the digital data acquisition unit; a certificate providing unit that provides the verifiable certificate generated by the certificate generating unit to the user by storing the verifiable certificate in a digital wallet in the user terminal; Equipped with The user terminal a request sending unit that sends the issuance request to the information processing device; a certificate acquisition unit that acquires the verifiable certificate generated by the information processing device from the information processing device; a certificate storage unit that stores the verifiable certificate acquired by the certificate acquisition unit in a digital wallet; An information processing system comprising:

8. An information processing method by an information processing device, an issuance request acquisition step of acquiring an issuance request for requesting issuance of a verifiable certificate from a user terminal; a digital data acquisition step of acquiring, from a digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired in the issuance request acquisition step; a certificate generation step of generating the verifiable certificate based on the digital data acquired in the digital data acquisition step; a certificate providing step of providing the verifiable certificate generated in the certificate generating step to the user by storing the verifiable certificate in a digital wallet in the user terminal; An information processing method comprising:

9. Computer, an issuance request acquisition unit that acquires an issuance request for requesting the issuance of a verifiable certificate from a user terminal; a digital data acquisition unit that acquires, from a digital data issuing terminal, digital data corresponding to the verifiable certificate whose issuance is requested by the issuance request acquired by the issuance request acquisition unit; a certificate generation unit that generates the verifiable certificate based on the digital data acquired by the digital data acquisition unit; a certificate providing unit that provides the verifiable certificate generated by the certificate generating unit to the user by storing the verifiable certificate in a digital wallet in the user terminal; A program that functions as a

Citation Information

Patent Citations

  • Public key base registration bureau, its construction method and its program, and recording medium having recorded the program

    JP2003309555A