Distributed identity management device, distributed identity management system, distributed identity management method, and distributed identity management storage medium

A decentralized identity management system using digital identifiers and verifiable credentials addresses the need for secure, contactless authentication by enabling users to manage their identities and data independently, ensuring privacy and security in authentication processes.

JP2025536371AActive Publication Date: 2025-11-05NEC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025522974
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-26
Filing Date
2023-10-26
Publication Date
2025-11-05
Estimated Expiration
2043-10-26

AI Technical Summary

Technical Problem

The need for secure and privacy-protecting authentication processes in facilities while minimizing contact and managing decentralized user information is urgent due to the COVID-19 pandemic and the risk of compromising personal information.

Method used

A decentralized identity management system using digital identifiers and verifiable credentials, implemented as an open standards-based framework, enables secure and privacy-preserving user identity management through decentralized identifiers, verifiable credentials, and cryptographic techniques.

Benefits of technology

Facilitates secure and contactless authentication processes, protecting user privacy by allowing users to independently manage their identities and data, reducing the risk of information compromise.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025536371000001_ABST
    Figure 2025536371000001_ABST
Patent Text Reader

Abstract

The device includes a memory and a processor. The processor sends a request to an external device to create decentralized identity (DID) information and receives DID information along with a digital token credential and a user certificate from the external device. The request includes an image of the DID subject and a public key of the device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a distributed identity management device, a distributed identity management system, a distributed identity management method, and a distributed identity management storage medium. More specifically, the present disclosure relates to a distributed identity management device, a distributed identity management system, a distributed identity management method, and a distributed identity management storage medium for facilitating mobile, interactive, and / or contactless operations in authentication processes that can be used in various facilities, such as airports. However, the present disclosure is not limited to authentication processes in airports. For example, one or more aspects of the present disclosure may be applied to other facilities or environments. [Background technology]

[0002] The world is currently experiencing the COVID-19 coronavirus pandemic, leading to widespread social distancing measures. These measures and concerns about transmission of the virus create an urgent and widespread need to limit contact with other people while still engaging in activities that require close proximity to others. Therefore, users using public or private facilities and following required process flows must perform the required authentication steps with minimal contact with publicly accessible devices.

[0003] Furthermore, in view of the large number of facilities and vendors that require authentication before providing services or products, a user's personal information required for authentication may be stored in various locations. Thus, threats to the security of a user's personal information increase. Therefore, there is a need to protect privacy and secure online interactions so that a user's information is not compromised. Summary of the Invention

[0004] According to one aspect of the present disclosure, decentralized identity technology, also referred to as self-sovereign identity technology, is provided that uses digital identifiers and verifiable credentials that are self-owned, independent, and enable trusted data exchange. Furthermore, the decentralized identity technology may be provided as an open standards-based identity framework. According to one aspect of the present disclosure, the decentralized identity technology protects privacy and secures online interactions.

[0005] According to one aspect of the present disclosure, an apparatus is provided that includes: a memory that stores one or more instructions; and a processor configured to execute the one or more instructions to obtain an image of a user, obtain a public key of the device, send a request to an external device to create decentralized identity (DID) information, and receive the DID information along with a digital token credential and a user certificate from the external device.

[0006] The image may be a selfie of the user.

[0007] The public key may be obtained by generating an RSA key pair.

[0008] The digital token credential may be signed by the private key of the external device.

[0009] The processor may be further configured to send a document credential request to the external device and receive document credential information from the external device.

[0010] The processor may be further configured to create a signature by signing the credential subject and the type of document using the private key portion of the RSA key pair, assemble a document credential request with a certificate including the credential subject, the type of document, the digital token credential, and the signature, and send the document credential request to the external device.

[0011] The signature may be a JSON Web Signature (JWS).

[0012] The credential entity may include at least one of document information and a scanned image of the document.

[0013] The document may be one of a driver's license, a passport, or a vaccination card.

[0014] The processor may be further configured to send a data sharing credential request to the external device, receive data sharing credentials from the external device, send a challenge issuance request to the external device, receive the challenge from the external device, create a data sharing request using the data sharing credential and the challenge, and send the data sharing request to the external device.

[0015] The data sharing credential request may include a credential entity containing event details and metadata corresponding to the event details.

[0016] The challenge may include an expiration date, and the challenge is associated with the DID information.

[0017] According to another aspect of the present disclosure, a method for distributed identity management is provided, including: obtaining, by an electronic device, an image and a public key of a user; sending, by the electronic device, a request to an external device to create distributed identification (DID) information; and receiving, by the electronic device, the DID information along with a digital token credential and a user certificate from the external device.

[0018] The method may further include sending a document credential request to an external device and receiving the document credential from the external device.

[0019] The method may further include creating a signature by signing the credential subject and the document type using the private key portion of the RSA key pair, assembling a document credential request with a certificate including the credential subject, the document type, the digital token credential, and the signature, and sending the document credential request to the external device.

[0020] The method may further include sending a data sharing credential request to the external device, receiving data sharing credential from the external device, sending a challenge issuance request to the external device, receiving the challenge from the external device, creating a data sharing request using the data sharing credential and the challenge, and sending the data sharing request to the external device.

[0021] According to another aspect of the present disclosure, a management apparatus is provided that includes a memory that stores one or more instructions and a processor that is configured to execute the one or more instructions to receive a request to create decentralized identification (DID) information for an external device, the request including an image of a user and a public key of the external device, and to transmit the DID information along with a digital token credential and a user certificate to the external device.

[0022] The processor may be further configured to receive a document credential request to the external device, the document credential request including a credential subject, a document type, digital token credentials, and a certificate including a signature, and to transmit the document credential from the external device.

[0023] The processor may be further configured to perform verification based on the digital token credential and the credential subject, perform verification of a signature in a certificate of the document credential request using a public key associated with the DID, and based on successful verification of the certificate, create a document credential having the credential subject, sign the document credential with a private key of the device, and send the document credential to the external device.

[0024] The processor may be further configured to receive a data sharing credential request from the external device, transmit the data sharing credential to the external device, receive a challenge issuance request from the external device, transmit the challenge to the external device, receive a data sharing request created using the data sharing credential and the challenge, and transmit a verification success or failure based on verification of information in the data sharing request.

[0025] According to another aspect of the present disclosure, a method for distributed identity management is provided, including receiving a request to create distributed identification (DID) information for an external device, the request including an image of a user and a public key of the external device, and transmitting the DID information along with a digital token credential and a user certificate to the external device.

[0026] The method may further include receiving a document credential request to the external device, the document credential request including a credential subject, a document type, digital token credentials, and a certificate including a signature, and transmitting the document credential from the external device.

[0027] The method may further include performing verification based on the digital token credential and the credential subject, performing verification of a signature in a certificate of the document credential request using a public key associated with the DID, creating a document credential having the credential subject based on successful verification of the certificate, signing the document credential with a private key of the device, and sending the document credential to the external device.

[0028] The method may further include receiving a data sharing credential request from the external device, transmitting the data sharing credential to the external device, receiving a challenge issuance request from the external device, transmitting the challenge to the external device, receiving a data sharing request created using the data sharing credential and the challenge, and transmitting a verification success or failure based on verification of information in the data sharing request. [Brief explanation of the drawings]

[0029] [Figure 1] 1 is a schematic diagram illustrating the configuration of a decentralized identifier (DID) management system according to an exemplary embodiment; [Figure 2A] FIG. 1 illustrates a concept for establishing a distributed identity management technique according to an exemplary embodiment. [Figure 2B] FIG. 1 illustrates a concept for establishing a distributed identity management technique according to an exemplary embodiment. [Figure 2C] FIG. 1 illustrates a concept for establishing a distributed identity management technique according to an exemplary embodiment. [Figure 2D] FIG. 1 illustrates a concept for establishing a distributed identity management technique according to an exemplary embodiment. [Figure 3] FIG. 1 illustrates a mobile application in accordance with an exemplary embodiment. [Figure 4] FIG. 1 is a schematic diagram illustrating the configuration of a distributed identifier (DID) management system according to another exemplary embodiment. [Figure 5A] 10 is a flowchart illustrating an account creation process according to an exemplary embodiment. [Figure 5B] 10 is a flowchart illustrating an account creation process according to another example embodiment. [Figure 6] 10 is a flowchart illustrating a document credential process in accordance with an exemplary embodiment. [Figure 7A]10 is a flowchart illustrating a data sharing process in accordance with an exemplary embodiment. [Figure 7B] 10 is a flowchart illustrating a data sharing process in accordance with an exemplary embodiment. [Figure 8A] FIG. 1 illustrates an example of a data sharing process according to an exemplary embodiment. [Figure 8B] FIG. 1 illustrates an example of a data sharing process according to an exemplary embodiment. [Figure 8C] FIG. 1 illustrates an example of a data sharing process according to an exemplary embodiment. [Figure 9] FIG. 2 is a block diagram of a management device in accordance with an exemplary embodiment. [Figure 10] FIG. 1 is a block diagram of a mobile device according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0030] Exemplary embodiments will now be described in more detail below with reference to the accompanying drawings. The following detailed description is provided to help the reader gain a comprehensive understanding of the methods, devices, and / or systems described herein. However, the exemplary embodiments provided in this disclosure should not be considered as limiting the scope of the disclosure. Accordingly, various changes, modifications, and equivalents of the systems, devices, and / or methods described herein will be suggested to those skilled in the art.

[0031] The terms used herein are intended to describe embodiments only and are not limiting in any way. Unless clearly used otherwise, singular terms include plural terms. As used herein, terms such as "including" are intended to specify a feature, number, step, operation, element, portion, or combination thereof, and should not be interpreted as excluding the presence or possibility of one or more other features, numbers, steps, operations, elements, portions, or combinations thereof.

[0032] One or more exemplary embodiments of the present disclosure will be described below with reference to the drawings, in which like or corresponding components are designated by like reference numerals throughout the drawings, and therefore, descriptions thereof may be omitted or simplified.

[0033] According to example embodiments, decentralized identity, also known as self-sovereign identity, can use digital identifiers and verifiable credentials that are self-owned, independent, and enable trusted data exchange. Decentralized identity can be implemented as an open standards-based identity framework and can use blockchain, distributed ledger technology, and private / public key cryptography to ensure the security and privacy of users' sensitive information.

[0034] According to exemplary embodiments, a distributed identity management system can be designed to augment or replace related technology identity management service (IDMS) platforms that centrally control or manage user information. According to exemplary embodiments, a distributed identity management system is a system that provides or enables user devices, such as mobile devices, to independently manage and control the user's digital identities and data. According to exemplary embodiments, the distributed identity management can have a framework implemented based on World Wide Web Consortium (W3C) standards. According to exemplary embodiments, the distributed identity management can be established based on the following concepts: (1) Decentralized Identifier (DID), (2) DID Subject, (3) DID Document, (4) Verifiable Credentials (VC), (5) Verifiable Presentation (VP), and (6) Self-Sovereign Identity (SSI) Chain of Trust. However, the present disclosure is not limited thereto, and thus, according to other exemplary embodiments, one or more of these concepts may be omitted and / or other concepts may be included. These concepts can be explained in more detail below.

[0035] FIG. 1 is a schematic diagram illustrating the configuration of a distributed identifier (DID) management system for facilitating an authentication process that preserves privacy and provides secure online interactions.

[0036] According to an exemplary embodiment, the DID management system includes an electronic device 1 and a data management platform 2. According to an exemplary embodiment, the electronic device may be a mobile device such as a smartphone, a laptop, a wearable device (i.e., a smart watch or a smart ring), a smart card, or another type of mobile electronic device. However, the present disclosure is not limited thereto, and thus, according to another exemplary embodiment, the electronic device 1 may be a desktop computer, a consumer electronic device, or the like.

[0037] According to an exemplary embodiment, the data management platform 2 may include a management device and a database. According to an exemplary embodiment, the management device and the database may be implemented as a single device or separate devices. According to an exemplary embodiment, the management device may be a server.

[0038] According to an exemplary embodiment, the DID management system may include a touchpoint device 3. However, the present disclosure is not limited thereto, and therefore the touchpoint device 3 may be omitted.

[0039] According to an exemplary embodiment, referring to FIG. 1 , an account creation process 100 and a data sharing process 200 are shown. Here, as an example, the electronic device 2 is referred to as a mobile device. According to an exemplary embodiment, a user of the mobile device can download and install a DID application on the mobile device. The DID application may be a DID mobile app. The mobile app may include a software development kit (SDK). According to an exemplary embodiment, the SDK provides the ability to communicate with other applications or devices. For example, the SDK may enable the mobile app to communicate with a data management platform through an application program interface (API).

[0040] According to an exemplary embodiment, the mobile app may execute program code and / or instructions to create a user account with data management platform 2 and share data with data management platform 2 to create verifiable document credentials and / or verifiable document presentations.

[0041] According to an exemplary embodiment, a mobile app can initiate the account creation process 100, for example, when an account creation is selected by a user. For example, the mobile app can initiate the account creation process using a DID registration API. According to an exemplary embodiment, a DID API, such as a DID registration API, can be accessed without logging in. Thus, because the DID API does not require login, the API is not secured but instead protected. According to an exemplary embodiment, a secured API can be authenticated using JSON Web Token (JWT), an open standard that defines a compact, self-contained way to securely transmit information between parties as a JSON object. According to an exemplary embodiment, the data management platform (i.e., backend) only verifies whether the DID that is part of the JWT payload exists in the system.

[0042] According to an exemplary embodiment, during the account creation process 100, the mobile app can send an image and a public key to a management device of the data management platform, which returns a digital token credential along with a DID user certificate. According to an exemplary embodiment, during the account creation process 100, the user can provide an image to be included in the account creation (or registration) request. According to an exemplary embodiment, the mobile app can prompt the user to take a selfie image. However, the present disclosure is not limited in this respect, and thus the mobile app can receive the user image in different manners. According to an exemplary embodiment, the selfie image can be included in the account creation request as a base64 string.

[0043] According to an exemplary embodiment, the mobile app may include the public key with the request for registration. According to an exemplary embodiment, the mobile device or mobile app may obtain or generate the public key by generating an RSA key pair. According to an exemplary embodiment, the RSA key pair may have a key size of 2048 bits. However, the present disclosure is not limited thereto. Furthermore, generating the public key from the RSK key pair may further include generating Distinguished Encoding Rules (DER) encoded bytes from the public key portion of the RSA key pair, generating x509EncodedKeySpecEncoded bytes from the DER encoded bytes, and generating a Base64 encoded string from the x509EncodedKeySpecEncoded bytes. Thus, the Base64 encoded string may be included as the public key in the account creation request along with the user's image. However, the present disclosure is not limited thereto, and thus the public key may be obtained or generated in different manners.

[0044] According to an example embodiment, after sending an account creation request with the image and public key, the mobile app can receive digital token credentials along with the DID and user certificate.

[0045] According to an exemplary embodiment, the management device can receive the image and the public key. According to an exemplary embodiment, the management device can verify the public key and the image. After verifying the public key and confirming that the image is a valid image, the management device can generate a decentralized identifier (DID). Furthermore, the management device may generate a digital token and generate a user certificate. According to an exemplary embodiment, the digital token can include the DID, the image, the proof, and a credential type. According to an exemplary embodiment, the user certificate includes information for conducting subsequent DID transactions via a mobile app. For example, the user certificate can be used during the data sharing process 200 to create document credentials and / or verifiable presentations.

[0046] According to an exemplary embodiment, the management device can store the DID, the public key, and the user certificate. According to an exemplary embodiment, the management device can send a response including the DID, the user certificate, and the digital token. According to an exemplary embodiment, the response can be returned via the account creation API. According to an exemplary embodiment, the digital token proof (i.e., the credential) can be signed by the management device's private key. However, the present disclosure is not limited thereto, and therefore the digital token proof (i.e., the credential) can be signed by the private key of an authorized third party. According to an exemplary embodiment, the authorized user can be a JSON Web Token (JWT). However, the present disclosure is not limited thereto, and therefore, can be implemented by a different certification process. According to an exemplary embodiment, the user certificate can never expire and can be required as a bearer token in all subsequent transactions between the mobile app and the management device or digital management platform. For example, the user certificate can be included in the authorization header of an API request for a call to create a verifiable document credential and / or a verifiable presentation using the DID received during the account creation process 100. However, the present disclosure is not limited in this respect, and thus user credentials may be used in other manners according to various other exemplary embodiments.

[0047] According to an exemplary embodiment, after the DID is generated and sent to the mobile app, the management device can enable the user to digitize the identity document by issuing a verifiable credential (VC) that encapsulates all information available on the document. According to an exemplary embodiment, the identity document can include, but is not limited to, a driver's license, a passport, and a vaccination card. According to an exemplary embodiment, the management device can rely on the mobile app to extract and / or verify data from the scanned document and issue a verifiable credential for the driver's license, passport, and vaccination card.

[0048] According to an exemplary embodiment, a document credential may be required based on a tenant's Identity Assurance Level (IAL) requirements. According to an exemplary embodiment, a tenant may be an entity that provides a specific service to users. For example, a tenant may be an airline, an amusement park, or a restaurant. However, the present disclosure is not limited thereto, and thus a tenant may be a tenant in various industries that provides services to users and requires user authentication. To provide the service, the user must be verified through some form of authentication. According to an exemplary embodiment, IAL requirements may include: (IAL1) requiring only an image and no document credential; (IAL2) requiring an image and at least one document credential; and (IAL3) requiring an image and two document credentials.

[0049] According to one example, the document credential creation process may include the mobile app creating a JSON Web Signature (JWS) by signing a credential subject and a document type using the private key portion of an RSA key pair. According to an example embodiment, the credential subject may include document information and a cropped image scanned from the document. The document information may also be information extracted from the document.

[0050] According to an example embodiment, the mobile app can assemble a request payload for a document credential with a credential subject, a document type, a digital token credential, and a proof including a JWS, and send the request payload to a management device. Upon receiving the request payload, the management device can perform validation on the data in the request payload and issue a document credential.

[0051] According to an exemplary embodiment, the request payload for a document credential may be similar to the payload for creating an account, except that the request payload may be signed with a private key paired with the public key shared in the payload to create the payload, and a JWS is added to the proof of request. According to an exemplary embodiment, the digital token credential may be included in the request payload for the document credential, since the management device can perform one-to-one (1:1) verification using a selfie image (from the account creation process) and a cropped image of the document. In addition to image verification, the management device can also verify the signature (JWS) in the proof of request using a public key associated with the DID. After the proof verification is successfully completed, the management device can create a document credential with the same credential principal, sign the document credential with the management device's private key, and return the document credential in a response to the mobile app.

[0052] According to an exemplary embodiment, after the account creation process and data credential process, data sharing can be selected. According to an exemplary embodiment, the data sharing process 200 may be triggered by an event, such as a check-in event, or by user input. However, the present disclosure is not limited in this respect, and thus, various other events may trigger the data sharing process 200.

[0053] According to an exemplary embodiment, the data sharing process 200 may include creating data sharing credentials, fetching a challenge from the management device, and creating a data sharing request. According to an exemplary embodiment, the data sharing credentials may be temporary credentials that provide event details that later help the management device (or backend) resolve the targeted data set. According to an exemplary embodiment, the event details may be tenant-specific configuration. According to an exemplary embodiment, the mobile app may store the event detail key and corresponding metadata in the mobile app's local configuration. However, the present disclosure is not limited in this respect, and thus the event detail key and / or corresponding metadata may be stored in a different manner.

[0054] According to an exemplary embodiment, the data sharing credential request payload may include a credential subject, which may include event details and metadata. According to an exemplary embodiment, the credential subject may include a DID.

[0055] According to an exemplary embodiment, upon receiving the data sharing credential request payload, the management device can perform credential subject validation. Additionally, the management device can examine the public key associated with the DID included in the data sharing credential request payload subject and verify the signature. If the signature is verified as valid, the management device can sign the credential subject using the management device's private key. However, if the signature is not verified, the management device can return an error message.

[0056] According to an exemplary embodiment, after obtaining the data sharing credential, the mobile app can send a request to the management device to issue a challenge. The request can include the DID for which a challenge is desired. According to an exemplary embodiment, the management device can issue and send the challenge to the mobile app. According to an exemplary embodiment, the challenge can be a JWT with a limited validity period, and the challenge can be associated with the DID provided in the request for issuance of the challenge. According to an exemplary embodiment, the management device can issue a challenge with an expiration date to avoid replay attacks, and therefore the challenge can be mandatory to be part of the proof in the data sharing request.

[0057] According to an exemplary embodiment, the mobile app can create a data sharing request using the data sharing credential and a challenge. According to an exemplary embodiment, the data sharing request may also be referred to as a verifiable presentation (VP). According to one example, the VP may include the mobile app creating a JSON Web Signature (JWS) included in the presentation by signing the digital token, the data sharing credential, one or more document credentials, and the credential subject and document type using the private key portion of an RSA key pair. According to an exemplary embodiment, the mobile app can include the challenge in the presentation. The mobile app can then call a data sharing API and send a payload including the verifiable presentation and user credentials. However, the present disclosure is not limited in this respect, and thus the payload can further include a target system, which may be a third-party system, for resolving the verifiable presentation.

[0058] According to an exemplary embodiment, upon receiving the data share request payload, the management device can validate the challenge, verify the signature, and verify whether the identity of the credential subject matches the verifiable proof of presentation. If any of these validations / validations fail, an error message is sent to the mobile app. According to an exemplary embodiment, the data share request payload may be stored in a local database of the management device.

[0059] According to an exemplary embodiment, the management device can share credential entities (including facial images) with the target system. According to an exemplary embodiment, the target system may be the identity management service of the management device. However, the present disclosure is not limited in this respect, and thus the target system may be a third-party system. According to an exemplary embodiment, the target data set is resolved by comparing the system / tenant configuration of the target system with the payload shared by the mobile app.

[0060] According to an exemplary embodiment, by creating DIDs and other verifiable credentials, users can share data in a tamper-evident presentation that is encoded so that the authorship of the data can be trusted after a process of cryptographic verification. Additionally, the DID system provides a domain-agnostic implementation that allows data sharing requests to be resolved by targeted datasets according to tenant configuration.

[0061] 2A-2D illustrate concepts for establishing a distributed identity management technique. For example, the concepts may include (1) a Decentralized Identifier (DID), (2) a DID Subject, (3) a DID Document, (4) a Verifiable Credential (VC), (5) a Verifiable Presentation (VP), and (6) a Self-Sovereign Identity (SSI) Chain of Trust.

[0062] According to an exemplary embodiment, a decentralized identifier (DID) is a globally unique identifier that may exhibit four characteristics: decentralized, persistent, cryptographically verifiable, and cryptographically resolvable. According to an exemplary embodiment, a DID 200 may include three parts, as shown in FIG. 2A. For example, a DID 200 may include a scheme identifier 201, a method identifier 202, and a method-specific identifier 203. According to an exemplary embodiment, the DID scheme identifier 201 may be a Uniform Resource Identifier (URI) scheme identifier. According to a DID, the method identifier 202 may identify the mechanism by which a particular type of DID and its associated DID documents are created, resolved, updated, and deactivated. According to an exemplary embodiment, the DID method-specific identifier 203 may be a unique identifier.

[0063] According to an exemplary embodiment, a DID subject is an entity identified by a DID. A DID subject may also be a DID controller. According to an exemplary embodiment, a DID subject is not limited to a person and may therefore further include a group, organization, thing, or concept. According to an exemplary embodiment, a DID document may be a set of data describing a DID subject. According to an exemplary embodiment, the data describing the subject may include mechanisms such as a cryptographic public key that the DID subject can use to authenticate itself and prove its association with the DID. An example of a DID document is shown in FIG. 2B.

[0064] 2C illustrates the structure of a verifiable credential (VC) or document credential according to an exemplary embodiment. According to an exemplary embodiment, a verifiable credential can represent all of the same information that a physical credential (e.g., driver's license / passport) represents. However, with the addition of technologies such as digital signatures, a verifiable credential is more tamper-resistant and trustworthy than its physical counterpart. According to an exemplary embodiment, a verifiable credential can include credential metadata, a credential principal, and a proof.

[0065] 2D illustrates the structure of a verifiable presentation (VP) or data share according to an exemplary embodiment. According to an exemplary embodiment, a verifiable presentation is a tamper-proof presentation of verifiable credentials that is encoded such that the authorship of the data can be trusted after a process of cryptographic verification. According to an exemplary embodiment, a verifiable presentation can include presentation metadata, credentials, and proofs.

[0066] FIG. 3 illustrates a mobile application according to an exemplary embodiment. According to an exemplary embodiment, the mobile application may be compatible with various platforms, including, but not limited to, Android and iOS devices. According to an exemplary embodiment, the mobile application may include a digital wallet SDK or digital wallet feature that enables users to manage DIDs and credentials in an efficient and seamless manner. For example, the digital wallet SDK may provide mechanisms for storing, managing, and using digital signatures, document credentials (such as driver's licenses and passports), health certificates (such as vaccination cards), and membership information (such as gym memberships or amusement park memberships). However, the present disclosure is not limited thereto, and thus the digital wallet SDK may manage other types of documents and information. For example, the digital wallet SDK may manage flight itineraries or other event details.

[0067] According to an example embodiment, the digital wallet may be further configured to manage credentials of other persons associated with the user of the mobile device. For example, a parent may use the parent's mobile application to implement document credential and data sharing processes for their child and store the credentials in the parent's digital wallet.

[0068] According to example embodiments, the mobile application may provide other features including, but not limited to, APIs for mobile application integration, registration services including face registration, document verification, content management, back-end matching, and highly scalable face recognition algorithms that provide fast and accurate results for real-time or post-event face recognition use cases.

[0069] 4 is a schematic diagram illustrating the configuration of a distributed identifier (DID) management system according to another exemplary embodiment. According to this exemplary embodiment, a third-party system may be further provided to perform one or more operations of an account creation process, a document credential process, and a data sharing process. For example, a management device or server of the third-party system may perform one or more of the functions performed by the management device 2 shown in FIG. 1. Thus, a DID system according to one or more exemplary embodiments of the present disclosure may provide a domain-independent implementation that enables data sharing requests to be resolved by targeted data sets according to tenant configurations.

[0070] FIG. 5A is a flowchart illustrating an account creation process according to an exemplary embodiment. According to an exemplary embodiment, a mobile app can initiate the account creation process 100, for example, when a user selects account creation. According to an exemplary embodiment, in operation S51, the mobile device can send a DID creation request to the management device. According to an exemplary embodiment, the DID creation request can include an image and a public key to the management device. According to an exemplary embodiment, the user provides an image to be included in the account creation. For example, the mobile app can prompt the user to take a selfie. According to an exemplary embodiment, the mobile device or mobile app can obtain or generate the public key by generating an RSA key pair.

[0071] According to an exemplary embodiment, the management device may receive the image and the public key. According to an exemplary embodiment, in operation S52, the management device may generate a decentralized identifier (DID) after verifying the public key and the image included in the creation request. Furthermore, in operation S53, the management device may generate a digital token. According to an exemplary embodiment, the digital token may include the DID, the image, the proof, and a credential type. Furthermore, in operation S54, the management device may generate a user certificate. According to an exemplary embodiment, the user certificate may include information for conducting subsequent DID transactions via the mobile app.

[0072] According to an exemplary embodiment, in operation S55, the management device can store the DID, the public key, and the user certificate. According to an exemplary embodiment, the management device can send a response that includes the DID, the user certificate, and the digital token.

[0073] According to an exemplary embodiment, in operation S56, the mobile device may receive a response message from the management device. According to an exemplary embodiment, the response message may include the digital token credential along with the DID and the user certificate.

[0074] Although Figure 5A illustrates an example embodiment of an account creation process, the present disclosure is not limited to the order or sequence of operations shown in Figure 5 A. Thus, according to other example embodiments, additional operations may be included, or operations may be removed from the process shown in Figure 5A, without departing from the spirit of the present disclosure.

[0075] 5B is a flowchart showing an account creation process according to another exemplary embodiment. The detailed description of operations S51, S53, S54, and S56 may be the same as that of FIG. 5A, and therefore will not be repeated.

[0076] According to an exemplary embodiment, in operation S51, a mobile device can send a DID creation request to a management device. According to an exemplary embodiment, in operation S52A, the management device can generate a decentralized identifier (DID) after verifying the public key and image included in the creation request. Additionally, according to an exemplary embodiment, the management device can set an expiration date. According to an exemplary embodiment, the expiration date and time can include data and a time at which the DID is to be revoked from the management device. According to an exemplary embodiment, the expiration date and time can be selected by a user using a mobile wallet SDK and set in the management device. However, the present disclosure is not limited thereto, and therefore, according to another exemplary embodiment, the management device can locally generate the data and time. According to one aspect of the present disclosure, the user himself manages and stores confidential information locally on the mobile device in a decentralized manner using an application such as a mobile wallet SDK. Therefore, the management device does not centrally store or manage user information. In this manner, the security and privacy of user data are further improved.

[0077] According to an exemplary embodiment, in operation S53, the management device can generate a digital token, and in operation S54, the management device can generate a user certificate. According to an exemplary embodiment, in operation S55A, the management device can temporarily store the DID, the public key, and the user certificate and send a response message S56 to the mobile device. According to an exemplary embodiment, in operation S56, the mobile device can receive the response message from the management device.

[0078] According to an example embodiment, upon determining in operation S57 that the expiration date and time has been reached, the management device may discard the DID. However, the present disclosure is not limited in this respect, and according to an example embodiment, the management device may discard other information related to transactions with the user that may be temporarily stored on the management device or backend.

[0079] Although Figure 5B illustrates an example embodiment of an account creation process, the present disclosure is not limited to the order or sequence of operations shown in Figure 5B. Thus, according to other example embodiments, additional operations may be included, or operations may be removed from the process shown in Figure 5B, without departing from the spirit of the present disclosure.

[0080] 6 is a flowchart illustrating the document credential process according to an exemplary embodiment. According to an exemplary embodiment, after a DID is generated and sent to a mobile device, a management device can enable a user to digitize an identity document by issuing a verifiable credential (VC) that encapsulates all information available on the document.

[0081] According to an exemplary embodiment, in operation S61, the mobile device may send a document credential request to the management device. According to an exemplary embodiment, before sending the document credential request, the mobile device may extract and / or verify data from a scanned document for which document credential information is requested. For example, the document may include, but is not limited to, a driver's license, a passport, and a vaccination card.

[0082] The document credential request may include a digital token, a document type, a credential principal, and a certificate. According to one example, the mobile device may create a JSON Web Signature (JWS) by signing the credential principal and the document type using the private key portion of an RSA key pair. According to an exemplary embodiment, the credential principal may include document information and a cropped image scanned from the document. The document information may also be information extracted from the document.

[0083] According to an exemplary embodiment, in operation S61, the mobile app can assemble a request payload for the document credential with a credential subject, a document type, a digital token credential, and a certificate including a JWS, and send the request payload to the management device.

[0084] According to an example embodiment, the request payload for a document credential request may be similar to the payload for creating an account, except that it may be signed with the private key paired with the public key shared in the payload to create the payload, and a JWS is added to the proof of request.

[0085] According to an exemplary embodiment, in operation S62, the management device can verify the signature. According to an exemplary embodiment, the management device can verify the signature in the proof of request (JWS) using a public key associated with the DID.

[0086] According to an exemplary embodiment, in operation S63, the management device can verify the digital token and document information. For example, the digital token credential may also be included in the document credential request payload, since the management device can perform one-to-one (1:1) verification using the selfie image (from the account creation process) and the cropped image of the document. After the certificate verification and the verification of the digital token and document information are successfully completed, in operation S66, the management device can create a document credential with the same credential principal, sign the document credential with the management device's private key, and return the document credential to the mobile device in response.

[0087] However, the present disclosure is not limited in this respect. Thus, according to an exemplary embodiment, in operation S64, the management device can send a document verification request to a third-party service provider. For example, if the document to be verified is a driver's license or a passport, the management device can send the document verification request with associated document information to an appropriate third-party service provider for document verification. For example, in the case of a driver's license or a passport, the management device can send the document to an authority that issues driver's licenses or passports for further verification.

[0088] According to an exemplary embodiment, in operation S65, the management device receives a response from the third-party service provider. According to an exemplary embodiment, the response may indicate whether there is a match.

[0089] According to an exemplary embodiment, if there is a match, then in operation S66 the administrative device may add a signature to the credential subject and document type, create a document credential, and send it to the mobile device.

[0090] According to an exemplary embodiment, in act S67, the mobile device may receive a response from the administrative device that includes document entitlement information.

[0091] According to an example embodiment, if either of the verification operations S62 or S63 fails, an error message may be sent to the mobile device.

[0092] According to an exemplary embodiment, the operation for creating a document credential may include creating an object including a credential principal, a digital token credential, and a type. For example, if the document is a driver's license, the credential type may be "Driver's License." Furthermore, according to an exemplary embodiment, the mobile device may serialize this object into a JSON String in alphabetical order. According to an exemplary embodiment, the mobile device may generate a signature using the private key portion of the same RSA key pair that was the id described above in connection with the account creation process. According to an exemplary embodiment, the mobile device may generate a Base64-encoded string from the resulting bytes of the previous operation and sign it using the "SHA256withRSA" algorithm. While a method for creating a document credential is described according to an exemplary embodiment, the present disclosure is not limited thereto, and thus, different methods for creating a document credential may be implemented according to different exemplary embodiments.

[0093] According to an exemplary embodiment, the management device (or backend system) can perform the same operations to create the credential proof, except that the private key belongs to the management device's RSA key pair and the management device uses the management device's public key to verify the management device's issued credentials. Additionally, the management device can also perform similar operations for proof verification of the verifiable credential and verifiable presentation request by using the public key shared in the account creation request.

[0094] While Figure 6 illustrates an example embodiment of a data credential process, the present disclosure is not limited to the order or sequence of operations shown in Figure 6. Thus, according to other example embodiments, additional operations may be included, or operations may be removed from the process shown in Figure 6, without departing from the spirit of the present disclosure.

[0095] 7A and 7B are flowcharts illustrating a data sharing process according to an example embodiment.

[0096] According to an exemplary embodiment, data sharing process 200 may be triggered by an event, such as a check-in event, or may be triggered by user input, however, the present disclosure is not limited in this respect, and thus a variety of other events may trigger data sharing process 200.

[0097] 7A and 7B, according to an exemplary embodiment, the data sharing process may include creating a data sharing credential request (operations S71-S75), fetching a challenge from a management device (operations S76-S78), and creating a data sharing request (operations S81-S88). According to an exemplary embodiment, the data sharing credential may be a temporary credential that provides event details that later help the management device (or backend) resolve the targeted data set. According to an exemplary embodiment, the event details may be tenant-specific configuration. According to an exemplary embodiment, the mobile device may store a key for the event details and corresponding metadata in the mobile device's local configuration. However, the present disclosure is not limited thereto, and thus the key for the event details and / or corresponding metadata may be stored in a different manner.

[0098] According to an exemplary embodiment, in operation S71, the mobile device can create a data sharing credential request. The data sharing credential request payload can include a credential subject, which can include event details and metadata. According to an exemplary embodiment, the credential subject may include a DID.

[0099] According to an exemplary embodiment, upon receiving the data sharing credential request payload, the management device may perform credential subject validation in operation S72. Further, in operation S73, the management device may examine the public key associated with the DID included in the data sharing credential request payload subject and verify the signature. If the signature is verified as valid, in operation S74, the management device may sign the credential subject using the management device's private key. However, if the signature is not verified, the management device may return an error message.

[0100] According to an exemplary embodiment, after obtaining the data sharing credential, in operation S76, the mobile device can send a request to issue a challenge to the management device. The request may include the DID for which the challenge is desired. According to an exemplary embodiment, in operation S77, the management device can issue and send a challenge to the mobile device. According to an exemplary embodiment, in operation S78, the mobile device can receive the challenge. According to an exemplary embodiment, the challenge may be a JWT with a limited validity period, and the challenge may be associated with the DID provided in the request for the issuance of the challenge. According to an exemplary embodiment, the management device can issue a challenge with an expiration date to avoid replay attacks, and therefore the challenge may be mandatory to be part of the proof in the data sharing request.

[0101] According to an exemplary embodiment, the data sharing request may also be referred to as a verifiable presentation (VP). According to an exemplary embodiment, at operation S81, the mobile device may prepare verifiable presentation data using the data sharing credential and the challenge. According to one example, the verifiable presentation may include the mobile device creating a JSON Web Signature (JWS) included in the presentation by signing the digital token, the data sharing credential, one or more document credentials, and the credential subject and document type using the private key portion of an RSA key pair. According to an exemplary embodiment, at operation S82, the mobile device may include the challenge in the presentation. Thereafter, at operation S83, the mobile device may call a data sharing API and send a payload including the verifiable presentation and a user certificate. However, the present disclosure is not limited thereto, and thus, the payload may further include a target system, which may be a third-party system, for resolving the verifiable presentation.

[0102] According to an exemplary embodiment, upon receiving the data share request payload, the management device may validate the challenge (at operation S84), verify the signature (at operation S85), and verify whether the identity of the credential subject matches the verifiable presentation proof (at operation S86). If any of these validations / validations fail, an error message is sent to the mobile device. According to an exemplary embodiment, in operation S87, the data share request payload may be stored in a local database of the management device. According to an exemplary embodiment, the management device may send a response S88 indicating the number of stored data share payloads.

[0103] According to an exemplary embodiment, the management device can share credential entities (including facial images) with the target system. According to an exemplary embodiment, the target system may be an identity management service of the management device. However, the present disclosure is not limited in this respect, and thus the target system may be a third-party system. According to an exemplary embodiment, the target data set is resolved by comparing the system / tenant configuration of the target system with the payload shared by the mobile device.

[0104] 7A-7E illustrate an example embodiment of a data sharing process, the present disclosure is not limited to the order or sequence of operations shown in Figures 7A-7E. Thus, according to other example embodiments, additional operations may be included, or operations may be removed, from the process shown in Figures 7A-7E without departing from the spirit of the present disclosure.

[0105] 8A, 8B, and 8C are diagrams illustrating an example of a data sharing process according to an example embodiment.

[0106] 8A illustrates a sample data sharing credential entity, according to an exemplary embodiment. Although flight details are provided as event detail data according to this exemplary embodiment, the present disclosure is not limited thereto, and thus other data may be provided as event detail data.

[0107] According to an exemplary embodiment, FIG. 8B shows a sample data sharing request. According to this exemplary embodiment, both passport and driver's license credentials are provided as verifiable credentials (or document credentials), but the present disclosure is not limited thereto, and therefore other data may be provided. For example, a DID management system according to an exemplary embodiment may allow for selective details from a verifiable credential to be provided. For example, a mobile app may allow a user to pick and choose which elements or portions of a verifiable credential to share, instead of sharing the entire verifiable credential during a data sharing request. To facilitate selective sharing, BBS+ signatures may be implemented, which provide selective disclosure fully controlled by the holder when all fields in a verifiable credential have a signature. Thus, the verifiable credential itself is a compilation of individual signatures, one for each field. For example, in a scenario requiring age verification (e.g., to purchase age-restricted products), a user may select and share only the age information portion (e.g., field) of the verifiable credential with a vendor, rather than sharing all information in the verifiable credential. Thus, a DID management system provides additional security and privacy, while further limiting unnecessary sharing of sensitive data.

[0108] According to an exemplary embodiment, FIG. 8C illustrates an example of how a target dataset for data sharing is resolved according to a target system and tenant configuration. According to this example, Tenant A may be an airline service provider, and Tenant B may be a retail service provider. Thus, when a data sharing request corresponding to Tenant A is created, the payload may include an airline code, flight number, departure data, and expiration date data that are resolved by the target dataset according to Tenant A's configuration. Meanwhile, when a data sharing request corresponding to Tenant B is created, the payload may include a city, state, store name, and expiration date that are resolved by the target dataset according to Tenant B's configuration.

[0109] Therefore, users of the DID management system can easily provide data sharing selectively to various tenants while managing personal and confidential data in a self-controlled manner.

[0110] According to an exemplary embodiment, the DID management system may include a feature for disabling a DID. For example, a mobile device user may select a disabling option to either disable the entire DID or a specific data sharing request. Furthermore, according to an exemplary embodiment, a user may selectively disable individual verifiable credentials or document credentials, resulting in the rejection of future authentication (data sharing) requests that include the disabled verifiable credentials or document credentials. In this manner, users are provided with the ability to manage personal and sensitive data in an improved manner. According to another exemplary embodiment, the management device may also be capable of disabling verifiable credentials or document credentials, DIDs, and / or specific data shares.

[0111] 9 shows a block diagram of a management device according to an example embodiment. As shown in FIG. 9 and described below, the management device may be implemented as a server 10. However, the present disclosure is not limited to servers, and thus the management device may be another type of device configured to implement a DID management process.

[0112] According to an exemplary embodiment, the management server 10 may include a CPU 102, a RAM 104, a storage device 106, and a communication circuit 108. The CPU 102, the RAM 104, the storage device 106, and the communication circuit 108 are connected to a bus line 110.

[0113] The CPU 102 operates by executing programs stored in the storage device 106 and may function as a controller that controls the overall operation of the management server 10. According to an exemplary embodiment, the CPU 102 can function as an orchestration layer that coordinates interactions between the front-end components of the mobile device 80 and the back-end DID management infrastructure, such as accessing a database or communicating with a third-party system. Furthermore, the CPU 102 executes application programs stored in the storage device 106 and implements various processes of the management server 10. The RAM 104 provides memory fields necessary for the operation of the CPU 102.

[0114] More specifically, the CPU 102 can receive a request to create distributed identity (DID) information for an external device and send the DID information along with a digital token credential and a user certificate from the external device. The request can include an image of the user and a public key of the external device.

[0115] According to an exemplary embodiment, CPU 102 receives a document credential request to an external device, the document credential request including a credential subject, a document type, digital token credentials, and a certificate including a signature, and may send the document credential from the external device.

[0116] According to an exemplary embodiment, the CPU 102 may perform verification based on the digital token credential and the credential subject, perform verification of the signature in the document credential request certificate using a public key associated with the DID, and based on successful verification of the certificate, create a document credential having the credential subject, sign the document credential with the device's private key, and send the document credential to the external device.

[0117] According to an exemplary embodiment, CPU 102 may receive a data sharing credential request from an external device, send the data sharing credential to the external device, receive a challenge issuance request from the external device, send the challenge to the external device, receive a data sharing request created using the data sharing credential and the challenge, and send a verification success or failure based on verification of the information in the data sharing request.

[0118] 10 shows a block diagram of features of a mobile device 80 according to an exemplary embodiment. For example, the mobile device 80 has a central processing unit (CPU) 802, a random access memory (RAM) 804, a storage device 806, communication circuitry 808, a display 812, an input / output (I / O) interface 814, and a camera 816, which may be connected to a bus line 810. According to an exemplary embodiment, the mobile device may include some or all of the features in the mobile application shown in FIG.

[0119] According to an exemplary embodiment, the CPU 802 operates by executing programs stored in the storage device 806 and functions as a controller that controls the operation of the mobile device 80. Furthermore, the CPU 802 executes application programs stored in the storage device 806 and performs various processes of the mobile device 80. The RAM 804 provides memory fields necessary for the operation of the CPU 802.

[0120] According to an exemplary embodiment, the communications circuitry 808 may include a transceiver configured to transmit and receive data from one or more devices external to the mobile device. According to an exemplary embodiment, the communications circuitry 808 may implement wireless communications. According to an exemplary embodiment, the display 812 may display information thereon. According to an exemplary embodiment, the display may include a touchscreen for receiving touch input. According to an exemplary embodiment, the input / output (I / O) interface 814 may include a microphone and a speaker for receiving audio input and outputting audio output. According to an exemplary embodiment, the camera 816 may capture one or more images.

[0121] According to an exemplary embodiment, the CPU 802 may obtain an image of the user, obtain a device public key, send a request to an external device to create decentralized identity (DID) information, and receive the DID information along with a digital token credential and a user certificate from the external device. According to an exemplary embodiment, the image may be a selfie of the user captured by the camera 816. According to an exemplary embodiment, the image may be received through the communication circuitry 808. The public key may be obtained by generating an RSA key pair, and the digital token credential may be signed by the private key of the external device.

[0122] According to an exemplary embodiment, the CPU 802 may send a document credential request to an external device and receive a document credential from the external device. According to an exemplary embodiment, the CPU 802 may create a signature by signing a credential subject and a document type using the private key portion of an RSA key pair, assemble a document credential request together with a certificate including the credential subject, the document type, the digital token credential, and the signature, and send the document credential request to the external device. The signature may be a JSON Web Signature (JWS), the credential subject may include at least one of document information and an image scanned from the document, the credential subject may include at least one of document information and an image scanned from the document, and the document may be one of a driver's license, a passport, or a vaccination card.

[0123] According to an example embodiment, CPU 802 may send a data sharing credential request to the external device, receive data sharing credential from the external device, send a challenge issuance request to the external device, receive the challenge from the external device, create a data sharing request using the data sharing credential and the challenge, and send the data sharing request to the external device. The data sharing credential request may include a credential subject including event details and metadata corresponding to the event details, the challenge may include an expiration date, and the challenge is associated with DID information.

[0124] The present disclosure is not limited to the above-described exemplary embodiments and may be modified as appropriate without departing from the spirit of the present disclosure. For example, although the exemplary embodiments illustrate a mobile device and a management server used in connection with an airline service offering or a retail service offering, the present disclosure is not limited thereto. For example, according to another exemplary embodiment, the mobile device and / or management server may be used in any facility that requires authentication or authorization of a user to use the services offered by the facility, such as a mass transit facility, a tourist attraction, an amusement park, a museum, a supermarket, or the like.

[0125] The scope of one or more exemplary embodiments also includes a processing method for storing a program that causes the configuration of the exemplary embodiment to perform the functions of the above-described exemplary embodiment in a storage medium, reading the program stored in the storage medium as code, and executing the code on a computer. That is, a computer-readable storage medium is also included in the scope of each exemplary embodiment. Furthermore, not only the storage medium on which the above-described program is stored, but also the program itself is included in each exemplary embodiment. Furthermore, one or more components included in the above-described exemplary embodiments may be circuits such as application-specific integrated circuits (ASICs) or field-programmable gate arrays (FPGAs) configured to perform the functions of each component.

[0126] Examples of storage media that can be used include floppy disks, hard disks, optical disks, magneto-optical disks, compact disks (CD-ROMs), magnetic tapes, non-volatile memory cards, and ROMs. Furthermore, the scope of each of the exemplary embodiments is not limited to examples in which processes are implemented by individual programs stored on storage media, but also includes examples in which processes are implemented in cooperation with the functions of other software or add-in boards that run on an operating system (OS).

[0127] Services implemented by the functionality of one or more of the exemplary embodiments described above may be provided to users in the form of Software as a Service (SaaS).

[0128] It should be noted that the above exemplary embodiments are merely examples of embodiments for implementing the present disclosure, and the technical scope of the present disclosure should not be construed in a limited sense by these exemplary embodiments. That is, the present disclosure can be implemented in various forms without departing from its technical idea or main features.

[0129] Some or all of the above exemplary embodiments can be described as follows, but are not limited to:

[0130] (Appendix 1) 1. An apparatus comprising: a memory storing one or more instructions; Executing said one or more instructions Get the user's image, obtaining a public key for the device; Sending a request to an external device to create distributed identification (DID) information; receiving the DID information along with digital token credentials and user certificates from the external device; and a processor configured as An apparatus comprising:

[0131] (Appendix 2) 2. The apparatus of claim 1, wherein the image is a selfie of the user, the public key is obtained by generating an RSA key pair, and the digital token credential is signed by a private key of the external device.

[0132] (Appendix 3) The processor: Sending a document credential request to the external device; receiving document qualification information from the external device 2. The apparatus of claim 1, further configured as follows:

[0133] (Appendix 4) The processor: creating a signature by signing the credential subject and the document type with the private key portion of the RSA key pair; Assembling the document credential request with a certificate including the credential subject, the type of the document, the digital token credential, and the signature; Sending the document credential request to the external device 4. The apparatus of claim 3, further configured as follows:

[0134] (Appendix 5) 5. The apparatus of claim 4, wherein the signature is a JSON Web Signature (JWS), the credential entity includes at least one of document information and an image scanned from a document, and the document is one of a driver's license, a passport, or a vaccination card.

[0135] (Appendix 6) The processor: sending a data sharing credential request to the external device; receiving data sharing credentials from the external device; Sending a challenge issuance request to the external device; receiving a challenge from the external device; creating a data sharing request using said data sharing credentials and said challenge; Sending the data sharing request to the external device 2. The apparatus of claim 1, further configured as follows:

[0136] (Appendix 7) 7. The apparatus of claim 6, wherein the data sharing credential request includes a credential entity including event details and metadata corresponding to the event details, and the challenge includes an expiration date, and the challenge is associated with the DID information.

[0137] (Appendix 8) obtaining, by the electronic device, an image and a public key of the user; sending, by the electronic device, a request to an external device to create distributed identity (DID) information; receiving, by the electronic device, the DID information along with digital token credentials and a user certificate from the external device; A distributed identity management method comprising:

[0138] (Appendix 9) 9. The method of claim 8, wherein the image is a selfie of the user, the public key is obtained by generating an RSA key pair, and the digital token credential is signed by a private key of the external device.

[0139] (Appendix 10) sending a document credential request to the external device; receiving document qualification information from the external device; 9. The method of claim 8, further comprising:

[0140] (Appendix 11) creating a signature by signing the credential subject and the document type using the private key portion of the RSA key pair; Assembling the document credential request with a certificate including the credential subject, the type of the document, the digital token credential, and the signature; sending the document credential request to the external device; 11. The method of claim 10, further comprising:

[0141] (Appendix 12) 12. The method of claim 11, wherein the signature is a JSON Web Signature (JWS), the credential entity includes at least one of document information and an image scanned from a document, and the document is one of a driver's license, a passport, or a vaccination card.

[0142] (Appendix 13) sending a data sharing credential request to the external device; receiving data sharing credentials from the external device; sending a challenge issuance request to the external device; receiving a challenge from the external device; creating a data sharing request using the data sharing credentials and the challenge; sending the data sharing request to the external device; 12. The method of claim 11, further comprising:

[0143] (Appendix 14) 14. The method of claim 13, wherein the data sharing credential request includes a credential entity including event details and metadata corresponding to the event details, and the challenge includes an expiration date, and the challenge is associated with the DID information.

[0144] (Appendix 15) receiving a request to create distributed identity (DID) information for an external device, the request including an image of a user and a public key of the external device; transmitting said DID information along with digital token credentials and a user certificate to said external device; A distributed identity management method comprising:

[0145] (Appendix 16) Setting an expiration date destroying the temporarily stored copy of the DID upon said expiration date; 16. The method of claim 15, further comprising:

[0146] (Appendix 17) receiving a document credential request to the external device, the document credential request including a credential subject, a document type, the digital token credential, and a certificate including a signature; transmitting document qualification information from the external device; 16. The method of claim 15, further comprising:

[0147] (Appendix 18) performing a verification based on the digital token credential and the credential subject; performing verification of the signature on the certificate of the document credential request using a public key associated with the DID; creating the document credential having the credential subject based on successful verification of the certificate; signing said document credentials with a private key of a management device; transmitting the document qualification information to the external device; 18. The method of claim 17, further comprising:

[0148] (Appendix 19) 18. The method of claim 17, wherein the signature is a JSON Web Signature (JWS), the credential entity includes at least one of document information and a scanned image from a document, and the document is one of a driver's license, a passport, or a vaccination card.

[0149] (Appendix 20) receiving a data sharing credential request from the external device; transmitting data sharing credentials to the external device; receiving a challenge issuance request from the external device; sending a challenge to the external device; receiving a data sharing request formulated using the data sharing credentials and the challenge; transmitting a verification result based on verification of the information in the data sharing request; further comprising the data sharing credential request includes a credential entity including event details and metadata corresponding to the event details, the challenge includes an expiration date, and the challenge is associated with the DID information; The method described in Appendix 15.

[0150] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 419,581, filed October 26, 2022, which is incorporated herein by reference in its entirety.

Claims

1. 1. An apparatus comprising: a memory storing one or more instructions; Executing said one or more instructions Get the user's image, obtaining a public key for the device; Sending a request to an external device to create distributed identification (DID) information; receiving the DID information along with digital token credentials and user certificates from the external device; and a processor configured as An apparatus comprising:

2. 2. The apparatus of claim 1, wherein the image is a selfie of the user, the public key is obtained by generating an RSA key pair, and the digital token credential is signed by a private key of the external device.

3. The processor: Sending a document credential request to the external device; receiving document qualification information from the external device The apparatus of claim 1 further configured to:

4. The processor: creating a signature by signing the credential subject and the document type using the private key portion of the RSA key pair; Assembling the document credential request with a certificate including the credential subject, the type of the document, the digital token credential, and the signature; Sending the document credential request to the external device The apparatus of claim 3 further configured to:

5. 5. The apparatus of claim 4, wherein the signature is a JSON Web Signature (JWS), the credential subject includes at least one of document information and an image scanned from a document, and the document is one of a driver's license, a passport, or a vaccination card.

6. The processor: sending a data sharing credential request to the external device; receiving data sharing credentials from the external device; Sending a challenge issuance request to the external device; receiving a challenge from the external device; creating a data sharing request using said data sharing credentials and said challenge; Sending the data sharing request to the external device The apparatus of claim 1 further configured to:

7. 7. The apparatus of claim 6, wherein the data sharing credential request includes a credential entity including event details and metadata corresponding to the event details, and the challenge includes an expiration date, and the challenge is associated with the DID information.

8. obtaining, by the electronic device, an image and a public key of the user; sending, by the electronic device, a request to an external device to create distributed identification (DID) information; receiving, by the electronic device, the DID information along with digital token credentials and a user certificate from the external device; A distributed identity management method comprising:

9. 9. The method of claim 8, wherein the image is a selfie of the user, the public key is obtained by generating an RSA key pair, and the digital token credential is signed by a private key of the external device.

10. sending a document credential request to the external device; receiving document qualification information from the external device; The method of claim 8 further comprising:

11. creating a signature by signing the credential subject and the document type using the private key portion of the RSA key pair; Assembling the document credential request with a certificate including the credential subject, the type of the document, the digital token credential, and the signature; sending the document credential request to the external device; The method of claim 10 further comprising:

12. 12. The method of claim 11, wherein the signature is a JSON Web Signature (JWS), the credential subject includes at least one of document information and an image scanned from a document, and the document is one of a driver's license, a passport, or a vaccination card.

13. sending a data sharing credential request to the external device; receiving data sharing credentials from the external device; sending a challenge issuance request to the external device; receiving a challenge from the external device; creating a data sharing request using the data sharing credentials and the challenge; sending the data sharing request to the external device; The method of claim 11 further comprising:

14. 14. The method of claim 13, wherein the data sharing credential request includes a credential subject including event details and metadata corresponding to the event details, and the challenge includes an expiration date, and the challenge is associated with the DID information.

15. receiving a request to create distributed identification (DID) information for an external device, the request including an image of a user and a public key of the external device; transmitting the DID information along with digital token credentials and a user certificate to the external device; A distributed identity management method comprising:

16. Setting an expiration date destroying the temporarily stored copy of the DID upon said expiration date; 16. The method of claim 15, further comprising:

17. receiving a document credential request to the external device, the document credential request including a credential subject, a document type, the digital token credential, and a certificate including a signature; transmitting document qualification information from the external device; 16. The method of claim 15, further comprising:

18. performing a verification based on the digital token credential and the credential subject; performing verification of the signature on the certificate of the document credential request using a public key associated with the DID; creating the document credential having the credential subject based on successful verification of the certificate; signing said document credentials with a private key of a management device; transmitting the document qualification information to the external device; 20. The method of claim 17, further comprising:

19. 18. The method of claim 17, wherein the signature is a JSON Web Signature (JWS), the credential subject includes at least one of document information and an image scanned from a document, and the document is one of a driver's license, a passport, or a vaccination card.

20. receiving a data sharing credential request from the external device; transmitting data sharing credentials to the external device; receiving a challenge issuance request from the external device; transmitting a challenge to the external device; receiving a data sharing request formulated using the data sharing credentials and the challenge; transmitting a verification result based on verification of the information in the data sharing request; further comprising the data sharing credential request includes a credential entity including event details and metadata corresponding to the event details, the challenge includes an expiration date, and the challenge is associated with the DID information; 16. The method of claim 15.

Citation Information

Patent Citations

  • Identity verification method based on block chain, client and server

    CN113204752A

  • User terminal, authenticator terminal, registrant terminal, management system and program

    JP2022012244A

  • Artwork management method, computer, and program

    WO2022220062A1