Information processing apparatus, information processing method, and program

The information processing device ensures secure and efficient distribution of user information by generating certification information with transfer history and verifying digital signatures, addressing issues in existing technologies.

JP2026006988APending Publication Date: 2026-01-16JCB CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024106392
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-01
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Existing technologies do not efficiently manage the distribution and verification of user credential information, leading to issues in data usage fee collection and potential liability for issuers.

Method used

An information processing device that generates certification information with associated transfer history, verifies digital signatures, and manages billing based on verified transfer paths, ensuring secure and efficient distribution of user information.

Benefits of technology

Guarantees legitimate distribution channels and enables efficient fee collection for user information, enhancing security and business viability by verifying transfer history and digital signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026006988000001_ABST
    Figure 2026006988000001_ABST
Patent Text Reader

Abstract

To provide an information processor, an information processing method and a program, capable of improving efficiency of distribution of information related to a user.SOLUTION: An information processing apparatus 2 according to an aspect of the present disclosure is an information processing apparatus 2 including one or more processors 700, in which the processor 700 is configured to acquire certification information including user information regarding a user and an electronic signature generated on the basis of at least a part of the user information, and to perform, on the certification information: The information processing apparatus executes associating transfer history information relating to a history of transfer of at least one of the certification information and user information included in the certification information, outputting the certification information associated with the transfer history information to another information processing apparatus, and changing the transfer history information based on outputting the certification information to the other information processing apparatus.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] Conventionally, techniques related to transmission and reception of user credential information are known. For example, Patent Document 1 describes a technique for permitting access to user credential information on a client device with less user input. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2023-145552 Summary of the Invention [Problem to be solved by the invention]

[0004] However, the technology described in Patent Document 1 does not allow for sufficient efficiency in the distribution of information about users. For example, there is room for further consideration regarding recording the transfer of information about users. Therefore, an object of the present disclosure is to provide an information processing device, an information processing method, and a program that can improve the efficiency of distribution of information related to users. [Means for solving the problem]

[0005] An information processing device according to one embodiment of the present disclosure is an information processing device having one or more processors, wherein the processors perform the following operations: acquiring certification information including user information about a user and an electronic signature generated based on at least a portion of the user information; associating the certification information with transfer history information regarding the history of transfer of at least one of the certification information and the user information included in the certification information; outputting the certification information associated with the transfer history information to another information processing device; and modifying the transfer history information based on outputting the certification information to the other information processing device.

[0006] An information processing method according to another aspect of the present disclosure includes one or more processors acquiring certification information including user information about a user and an electronic signature generated based on at least a portion of the user information, associating transfer history information with the certification information regarding the history of transfer of at least one of the certification information and the user information included in the certification information, outputting the certification information associated with the transfer history information to another information processing device, and modifying the transfer history information based on outputting the certification information to the other information processing device.

[0007] A program according to another aspect of the present disclosure causes one or more processors to perform the following operations: obtain certification information including user information about a user and an electronic signature generated based on at least a portion of the user information; associate the certification information with transfer history information regarding the history of transfer of at least one of the certification information and the user information included in the certification information; output the certification information associated with the transfer history information to another information processing device; and change the transfer history information based on the output of the certification information to the other information processing device. [Effects of the Invention]

[0008] According to the present disclosure, it is possible to provide an information processing device, an information processing method, and a program that can efficiently distribute information about users. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram showing an outline of the operation of the system 1 according to the present embodiment. [Figure 2] 1 is a diagram illustrating an example of a functional configuration of a system 1 according to the present embodiment. [Figure 3] FIG. 2 is a diagram illustrating an example of the operation of the system 1 according to the present embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of the operation of the system 1 according to the present embodiment. [Figure 5] 1 is a diagram illustrating an example of the hardware configuration of each device included in a system 1 according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS A preferred embodiment of the present invention will be described with reference to the accompanying drawings. In the drawings, components with the same reference numerals have the same or similar configurations.

[0011] <1. Overview> In recent years, business models have emerged that utilize digital identity wallets to exchange data whose legitimacy can be verified, such as VC (Verifiable Credential). In one example, a business model has been realized in which businesses exchange VC to pay data usage fees.

[0012] However, once VC is issued, even if it is provided to a third party via a user's wallet or the like, the issuer of the VC may not be able to grasp the transfer. As a result, it is expected that the issuer of the VC will not be able to fully collect data usage fees. Furthermore, because VC is verifiable data, there is a risk that the issuer of the VC will be held responsible if there is a defect in the data. One of the purposes of the system 1 according to this embodiment (hereinafter simply referred to as "system 1") is to solve such problems.

[0013] Referring to FIG. 1, an overview of the operation of the system 1 is shown. The system 1 includes an information processing device 2 and a user terminal device 3. First, the user terminal device 3 requests the information processing device 2 to generate certification information based on a user operation or the like (S1). In one embodiment, the certification information is used to prove that the user information related to the user is valid. The certification information is, for example, a VC or the like.

[0014] The information processing device 2 requests company A, which is a company that provides the user information, to transmit the user information (S2). In response to this, company A transmits the user information to the information processing device 2 (S3). The user information transmitted by company A may include, for example, user registration information for the service provided by company A.

[0015] The information processing device 2 generates certification information based on the received user information, and further associates transfer history information with the certification information (S4). The transfer history information includes information related to the transfer history of the user information included in the certification information. In the example of FIG. 1, the user information was transmitted from company A to the information processing device 2. Therefore, in step S4, the transfer history information may include information that the user information was provided by company A.

[0016] 1, the certification information includes user information and a digital signature generated based on the user information. A device that acquires the certification information can verify the digital signature to confirm that the user information included in the certification information has not been tampered with. In the example of FIG. 1, the digital signature included in the certification information is configured so that it can be verified by the information processing device 2 but cannot be verified by company B.

[0017] The information processing device 2 transmits certification information associated with the transfer history information to the user terminal device 3 (S5). Since the certification information includes user information, in step S5, the information processing device 2 adds information to the transfer history information indicating that the certification information has been transmitted to the user terminal device 3. Thereafter, the user terminal device 3 transmits the certification information to company B, to which the user information will be disclosed, based on the user's operation or the like (S6).

[0018] Upon receiving the certification information, company B requests the information processing device 2 to verify the certification information (S7). The verification of the certification information may include verifying the digital signature included in the certification information and verifying the transfer history information associated with the certification information. By verifying the digital signature, the information processing device 2 confirms that the user information included in the certification information has not been tampered with. Furthermore, by verifying the transfer history information, the information processing device 2 confirms that the distribution route of the certification information recorded in the transfer history information is consistent with the actual distribution route of the certification information. In other words, through these verifications, the information processing device 2 can confirm that the certification information was provided to company B through a legitimate distribution route (e.g., not by a third party who stole the certification information) without being tampered with. Based on step S7, the information processing device 2 may add information to the transfer history information indicating that the certification information was sent from the user terminal device 3 to company B.

[0019] The information processing device 2 transmits information on the verification result performed based on step S7 and billing information on the usage fee for the user information to company B (S8). The billing information may include information that at least a portion of the data usage fee for the user information should be paid to company A.

[0020] According to System 1, since transfer history information is associated with the certification information, the legitimacy of the distribution channel of the certification information can be guaranteed and the usage fee for the user information can be distributed to the provider of the certification information. Furthermore, since the certification information includes a digital signature generated based on the user information, it is possible to guarantee that the user information has not been tampered with. This makes it possible to achieve both high security regarding the distribution of user information and ease of business viability. The configuration and operation of System 1 are described in detail below.

[0021] <2. Functional configuration> An example of the functional configuration of the system 1 will be described with reference to Fig. 2. The system 1 includes an information processing device 2, a user terminal device 3, a source server device 4a, a destination server device 4b, and a communication network 5. Although not shown in the figure, the system 1 can be connected to a blockchain system via the communication network 5. Each device will be described below.

[0022] [Information processing device 2] The information processing device 2 manages the certification information. The information processing device 2 includes a control unit 10, a storage unit 12, a network interface unit 14, and a bus 16. The control unit 10, the storage unit 12, and the network interface unit 14 are electrically connected via the bus 16.

[0023] The control unit 10 can function as an acquisition unit 100, a generation unit 102, a verification unit 104, an encryption processing unit 106, a transfer history management unit 108, a judgment unit 109, and an output unit 110 by executing various programs stored in the memory unit 12.

[0024] The acquisition unit 100 acquires various types of information. In the present disclosure, acquiring information includes making the information processable in the control unit 10. Acquiring information may be, for example, receiving the information from another device, obtaining the information through predetermined processing, reading the information from the storage unit 12, etc.

[0025] The generating unit 102 generates various types of information. Generating information may mean, for example, making information obtained by a predetermined process processable in the control unit 10, and storing the information obtained by the processing in the storage unit 12.

[0026] The verification unit 104 verifies the digital signature. In one embodiment, verifying the digital signature includes confirming that the information to be signed by the digital signature has not been tampered with. In this case, successful verification of the digital signature includes obtaining a result, through a predetermined process, indicating that the information to be signed by the digital signature has not been tampered with. A failure in the verification of a digital signature may occur when a predetermined process produces a result indicating that the information to be signed by the digital signature has been tampered with, or when a result indicating that the information has not been tampered with is not produced. In one embodiment, various processes related to digital signatures may be implemented based on a public key cryptosystem.

[0027] Furthermore, the verification unit 104 verifies the distribution route of the information. Successful verification of the distribution route of the information may mean that the actual distribution route of the information is consistent with the distribution route of the information that is recognized by the information processing device 2. Failure in verification of the information may mean that the actual distribution route of the information is inconsistent with the distribution route of the information that is recognized by the information processing device 2.

[0028] The encryption processing unit 106 performs encryption and decryption of information. Encrypting information involves making the original information incomprehensible to humans and machines. Decrypting encrypted information involves obtaining the information before it was encrypted through a decryption process. In one embodiment, information encrypted by the encryption processing unit 106 can only be decrypted by the encryption processing unit 106 itself.

[0029] The transfer history management unit 108 manages the transfer history information. Managing the transfer history information may include, for example, adding information to the transfer history information, changing information included in the transfer history information, and deleting information included in the transfer history information.

[0030] The determination unit 109 determines whether or not a user information output condition related to the output unit 110 outputting the user information is satisfied.

[0031] The output unit 110 outputs information. Outputting information may involve, for example, transmitting the information to another device, displaying the information, and the like.

[0032] The following describes functions realized by the control unit 10 operating as the acquisition unit 100, generation unit 102, verification unit 104, encryption processing unit 106, transfer history management unit 108, and output unit 110.

[0033] (Certification information generation function) The certification information generation function is a function for generating certification information. First, the acquisition unit 100 acquires user information. The acquisition unit 100 may acquire the user information from the storage unit 12, from a source server device 4a (corresponding to company A in the example of FIG. 1) that provides the user information, or from the user terminal device 3. Next, the generation unit 102 generates a digital signature based on the user information. The generation unit 102 further generates certification information based on the user information and the digital signature.

[0034] The user information included in the certification information may be any information to be certified. The user information may be, for example, attribute information related to the user's attributes, qualification information related to qualifications, processing information related to various operations, transaction information related to transactions, and information related to copyrighted works, etc. The attribute information may include, for example, information related to the user's name, date of birth, address, gender, and family composition, etc. The qualification information may include information related to the qualifications held by the user (e.g., national qualifications, educational background, etc.). The processing information may include, for example, information related to the user's usage history of services provided by the provider server device 4a. The transaction information may include information related to the user's credit card usage history and information related to purchased items, etc. An example of the certification information is a VC. The user information may be information related to a public key associated with the user (or the user terminal device 3). An example of the certification information when the user information is information related to a public key is a digital certificate. The certification information may include information other than the user information and the digital signature (e.g., identification information of the information processing device 2, information related to the intermediate certification authority, etc.).

[0035] In one embodiment, the certification information generation function generates certification information including encrypted user information (hereinafter referred to as "encrypted user information"). The encryption processing unit 106 encrypts the user information acquired by the acquisition unit 100. The generation unit 102 generates a digital signature based on the encrypted user information acquired by the encryption processing unit 106. Furthermore, the generation unit 102 generates certification information based on the encrypted user information and the digital signature. In other words, by verifying the digital signature included in this certification information, it is possible to confirm whether the encrypted user information has been tampered with.

[0036] According to this configuration, it is possible to prevent the plaintext user information from being immediately disclosed to the device that has received the certification information, thereby improving security. Note that, as will be described later, a device that has received the certification information including the encrypted user information may be able to obtain the plaintext user information by performing a predetermined process.

[0037] In one embodiment, the acquiring unit 100 acquires a request for generating certification information and generates certification information based on the request. In one example, the request may include a specification regarding information to be included in the user information (e.g., including name and age but not address). In another example, the request may include an instruction regarding whether the user information to be included in the certification information should be encrypted or in plain text. The acquiring unit 100 may acquire the request from any of the user terminal device 3, the source server device 4a, and the destination server device 4b.

[0038] The output unit 110 outputs the certification information generated by the generation unit 102. The output unit 110 may output the certification information to either the user terminal device 3 or the destination server device 4b. If the information processing device 2 has a user interface (for example, a display), the output unit 110 may output the certification information via the user interface.

[0039] (Transfer history management function) The transfer history management function is a function for managing transfer history information. Based on the fact that the generation unit 102 has generated the certification information, the transfer history management unit 108 associates the transfer history information with the certification information.

[0040] In one embodiment, the transfer history management unit 108 adds information regarding the provider of the certification information to the transfer history information with which the certification information is associated, based on the acquisition of the certification information by the acquisition unit 100. In another embodiment, the transfer history management unit 108 adds information regarding the provider of the user information to the transfer history information with which the certification information including the user information is associated, based on the acquisition of the user information by the acquisition unit 100.

[0041] In one embodiment, the transfer history management unit 108 adds information regarding the output destination of the certification information to the transfer history information associated with the certification information, based on the output of the certification information by the output unit 110. In another embodiment, the transfer history management unit 108 adds information regarding the output destination of the user information to the transfer history information associated with the certification information including the user information, based on the output of the user information by the output unit 110.

[0042] Hereinafter, "certification information and / or user information included in the certification information" may be referred to as "certification information, etc."

[0043] In the present disclosure, transferring information from a first entity to a second entity may mean transmitting the information from the first entity to the second entity. In one example, transfer history information may be a history of sending and receiving authentication information, etc. In the present disclosure, an "entity" may be, for example, a device, a user account, a company account, etc. In the present disclosure, transferring information from a first entity to a second entity may mean changing the state of the information from being associated with the identification information of the first entity to being associated with the second entity.

[0044] In one embodiment, the acquiring unit 100 acquires information regarding the transfer of certification information and the like from a first entity to a second entity different from the information processing device 2. For example, when certification information is transmitted from the user terminal device 3 to the destination server device 4b, the acquiring unit 100 may acquire information indicating that the certification information has been transmitted and received from at least one of the user terminal device 3 and the destination server device 4b.

[0045] The transfer history management unit 108 updates the transfer history information associated with the certification information based on information regarding the transfer of the certification information, etc. In this way, the transfer history management unit 108 can record the history of the transfer of the certification information, etc., even when the information processing device 2 is not directly involved in the transfer of the certification information, etc.

[0046] In one embodiment, the transfer history information may include a list of one or more entities that have at least temporarily acquired the credential with which the transfer history information is associated or the user information contained in the credential. For example, (1) The acquisition unit 100 acquires user information from the source server device 4a, (2) The generation unit 102 generates authentication information based on the user information; (3) The output unit 110 transmits the certification information to the user terminal device 3; (4) When the user terminal device 3 transmits the certification information to the destination server device 4b, The transfer history information may include a list such as "source server device 4a → information processing device 2 → user terminal device 3 → destination server device 4b." In this case, the source server device 4a corresponds to an entity that at least temporarily holds the user information. Also, the information processing device 2, the user terminal device 3, and the destination server device 4b correspond to entities that at least temporarily hold the certification information.

[0047] In one embodiment, the transfer history information includes information about the history of transfers of non-fungible tokens (NFTs) associated with the certification. In one example, a single NFT is fixedly associated with the certification, and the transfer history manager 108 changes the entity associated with the NFT based on the certification being transferred.

[0048] In one embodiment, information about the history of NFT transfers may be recorded on a blockchain. The transfer history manager 108 may generate and modify transfer history information on the blockchain, for example, by a smart contract.

[0049] In one embodiment, the association of the NFT with the proof is achieved by, for example, associating the identification information of the NFT (e.g., a token ID) with the identification information of the proof (e.g., a VC ID). Information about this association may be recorded on the blockchain.

[0050] In one embodiment, the information about the transfer history of the NFT may be information about the transition of the entity's identity (e.g., a wallet ID) associated with the NFT's identity. Such transition information may be recorded as a change history on the blockchain or may be recorded in the NFT itself.

[0051] (User information output function) The user information output function is a function for outputting user information. In one embodiment, the determination unit 109 determines whether a user information output condition is satisfied, and the output unit 110 outputs the user information when it is determined that the user information output condition is satisfied.

[0052] In one embodiment, the user information output condition includes that the acquisition unit 100 acquires certification information and the verification unit 104 successfully verifies the digital signature included in the certification information. In one example, the output unit 110 may output the user information included in the certification information when the verification result indicates that the user information included in the certification information has not been tampered with. This configuration makes it possible to provide user information that has been confirmed to have not been tampered with.

[0053] In one embodiment, the user information output condition includes that the acquisition unit 100 acquires certification information and the verification unit 104 successfully verifies the transfer history information associated with the certification information. In one example, the output unit 110 may output the user information included in the certification information when the transfer history information associated with the certification information matches the actual distribution path of the certification information. This configuration makes it possible to provide user information that has been transferred via a legitimate distribution path (i.e., has not been stolen by a third party).

[0054] In one embodiment, the user information output condition includes completion of payment for the billing information. That is, the output unit 110 can output the user information based on the payment of the usage fee for the user information included in the certification information. The acquisition unit 100 can acquire information indicating that payment for the billing information has been completed from, for example, a server of a financial institution.

[0055] The user information output condition may include a plurality of conditions exemplified in the present disclosure. In this case, the determination unit 109 may determine that the user information output condition is satisfied based on whether all of the plurality of conditions are satisfied, or whether some of the plurality of conditions are satisfied.

[0056] If the certification information includes encrypted user information, the determination unit 109 determines whether the decryption condition is satisfied, and the encryption processing unit 106 may decrypt the encrypted user information if it is determined that the decryption condition is satisfied. After that, the output unit 110 outputs the decrypted user information if it is determined that the user information output condition is satisfied.

[0057] In one embodiment, the decryption condition includes that the obtaining unit 100 obtains a request to decrypt the encrypted user information.

[0058] In one embodiment, the decryption condition may include at least a part of the user information output condition. In one example, the encryption processing unit 106 decrypts the encrypted user information when the verification of the digital signature included in the certification information is successful. In another example, the encryption processing unit 106 decrypts the encrypted user information when the verification of the transfer history information associated with the certification information is successful.

[0059] (billing function) The billing function is a function for generating and outputting billing information. After the output unit 110 outputs the certification information associated with the transfer history information to another device, the generation unit 102 generates billing information regarding the consideration to be paid to the provider of the user information included in the certification information based on the transfer history information.

[0060] As an example, consider a situation in which the acquisition unit 100 acquires user information from a first entity, and the output unit 110 outputs certification information including the user information to a second entity. The transfer history information in this situation may include information indicating that the certification information, etc., has been transferred from the first entity to the second entity via the information processing device 2. Based on this transfer history information, the generation unit 102 may generate billing information regarding the payment to be made by the second entity to the first entity. The output unit 110 may output this billing information to the second entity.

[0061] As another example, consider a scenario in which a first entity provides user information to a second entity, the acquisition unit 100 subsequently acquires the user information from the second entity, and the output unit 110 outputs certification information including the user information to a third entity. The transfer history information in this scenario may include information indicating that the certification information, etc., was transferred from the first entity to the third entity via the second entity and the information processing device 2. Based on this transfer history information, the generation unit 102 may generate billing information regarding the fees to be paid by the third entity to each of the first entity and the second entity. The output unit 110 may output this billing information to the third entity.

[0062] The storage unit 12 stores various information necessary for the operation of the information processing device 2. In one example, the storage unit 12 stores user information, encrypted user information, certification information, transfer history information, etc. In another example, the storage unit 12 stores a private key for generating a digital signature, information for encrypting user information, information for decrypting encrypted user information, etc.

[0063] The network interface unit 14 realizes communication with other devices via the communication network 5 .

[0064] [User terminal device 3] The user terminal device 3 is a device used by a user. The user terminal device 3 is, for example, a personal computer, a smartphone, a tablet terminal, or a smart device. The user terminal device 3 may have a user interface. The user terminal device 3 may output images, sounds, and the like via the user interface. The user terminal device 3 may also receive input from the user via the user interface.

[0065] [Source Server Device 4a and Destination Server Device 4b] The source server device 4a is a server device managed by an entity that is a source of user information, and the destination server device 4b is a server device managed by an entity that is a destination of user information.

[0066] [Communication Network 5] The communication network 5 realizes communication between the information processing device 2, the user terminal device 3, the source server device 4a, and the destination server device 4b.

[0067] <3.Operation> An example of the operation of the system 1 will be described with reference to Fig. 3. First, the user terminal device 3 requests certification information from the information processing device 2 (S100). In response, the information processing device 2 requests user information from the source server device 4a (S102) and receives the user information (S104).

[0068] The information processing device 2 encrypts the received user information to obtain encrypted user information (S106), and generates a digital signature based on the encrypted user information (S108). The information processing device 2 generates certification information including the encrypted user information obtained in step S106 and the digital signature generated in step S108 (S109).

[0069] The information processing device 2 issues an NFT in the blockchain (S110). The information processing device 2 associates the NFT issued in step S110 with the proof information generated in step S109 (S111). The information processing device 2 adds identification information of the source server device 4a, which is the source of the user information, to the NFT (S112). Note that the information added to the NFT is an example of transfer history information.

[0070] The information processing device 2 transmits the certification information associated with the NFT in step S112 to the user terminal device 3 that requested the certification information in step S100 (S114). At this time, the information processing device 2 adds, to the NFT, identification information of the user terminal device 3 that is the recipient of the certification information, etc. at this time (S116).

[0071] With reference to FIG. 4, an example of the continuation of the operation of the system 1 shown in FIG. 3 will be described. First, the user terminal device 3 transmits the certification information received in step S114 to the destination server device 4b (S200). In response, the destination server device 4b transmits the certification information, a request to decrypt the encrypted user information included in the certification information, and a request to verify the digital signature and NFT to the information processing device 2 (S202). Having received this information, the information processing device 2 adds identification information of the destination server device 4b to the NFT (S203). Note that the NFT verification request here includes information about the entity that provided the certification information to the destination server device 4b (the user terminal device 3 in the example of FIG. 4).

[0072] Upon receiving the request to verify the digital signature, the information processing device 2 verifies the digital signature included in the certification information (S204), thereby enabling the information processing device 2 to confirm whether the encrypted user information included in the certification information has been tampered with.

[0073] Furthermore, based on receiving the NFT verification request, the information processing device 2 verifies the NFT associated with the certification information (S206). Specifically, it verifies whether information about the entity that provided the certification information to the destination server device 4b is consistent with the information recorded in the NFT. This allows the information processing device 2 to confirm whether the distribution channel of the certification information, etc. is legitimate.

[0074] Here, an example of NFT verification will be described. In step S112 of FIG. 3, the information processing device 2 adds identification information of the source server device 4a to the NFT. Also, in step S116 of FIG. 3, the information processing device 2 adds identification information of the user terminal device 3 to the NFT. Also, in S203 of FIG. 4, the information processing device 2 adds identification information of the destination server device 4b to the NFT. Therefore, the NFT records information that certification information, etc. has been transferred in the order of source server device 4a → user terminal device 3 → destination server device 4b.

[0075] As described above, the NFT verification request received by the information processing device 2 in step S202 includes information that the entity that provided the certification information to the destination server device 4b is the user terminal device 3. Therefore, in that the certification information, etc. has been transferred from the user terminal device 3 to the destination server device 4b, the distribution path of the certification information, etc. recorded in the NFT matches the actual distribution path of the certification information, etc. Based on this, the information processing device 2 determines that the verification of the NFT has been successful.

[0076] Based on the results of these verifications, the information processing device 2 determines whether the decryption conditions and the user information output conditions are satisfied (S208). In the example of FIG. 4, the user information output conditions include successful verification of the electronic signature (corresponding to S204) and successful verification of the NFT (corresponding to S206). Furthermore, the decryption conditions include satisfied user information output conditions and a decryption request being acquired (corresponding to S202). In the example of FIG. 4, the description will be given assuming that the decryption conditions and the user information output conditions are satisfied.

[0077] The information processing device 2 decrypts the encrypted user information included in the certification information (S210). Next, the information processing device 2 generates billing information based on the information recorded in the NFT (i.e., information indicating that the certification information, etc., has been transferred in the order of source server device 4a → user terminal device 3 → destination server device 4b) (S212). In the example of FIG. 4, the billing information includes information indicating that a usage fee for the user information should be paid to the entity that manages source server device 4a.

[0078] Next, the information processing device 2 transmits the user information obtained in step S210 and the billing information generated in step S212 to the destination server device 4b (S214). The entity managing the destination server device 4b pays the usage fee for the user information to the entity managing the source server device 4a based on the received billing information (S216).

[0079] According to the system 1, the utilization of user information is made more efficient for both the source server device 4a and the destination server device 4b. Specifically, transfer history information is associated with the certification information (see S111 in FIG. 3), and billing information is generated based on the transfer history information (see S212 in FIG. 4). Therefore, even if the user is included in the distribution path of the certification information, the entity managing the source server device 4a can collect the consideration for providing the user information (see S104 in FIG. 3) from the entity managing the destination server device 4b (see S216 in FIG. 4).

[0080] Furthermore, since the user information and transfer history information contained in the certification information are verified by the information processing device 2 (see S204 and S206 in Figure 4), the destination server device 4b can handle user information whose reliability is guaranteed (see S214 in Figure 4).

[0081] Furthermore, by making the user information included in the certification information into encrypted user information (see S106 in FIG. 3), the user information can be protected even if the certification information is stolen by a third party. Furthermore, the entity that has acquired the certification information needs to send a decryption request to the information processing device 2 in order to use the user information (see S202 in FIG. 4). This ensures that an opportunity can be provided to collect the usage fee for the user information from the entity that has acquired the certification information.

[0082] In this embodiment, an example in which user information is provided from the source server device 4a to the destination server device 4b has been described, but this is not limiting. The destination server device 4b, which has acquired the user information, may provide (transfer) the acquired user information to another server device. In this case, the information processing device 2 may transmit billing information to the other server device, informing the entity managing the source server device 4a and the entity managing the destination server device 4b, that a usage fee for the user information should be paid. In this way, the information processing device 2 may generate billing information including information informing the entity managing the source server device 4a and the destination server device 4b that a usage fee for the user information should be paid, tracing back multiple generations of the distribution path of the certification information, etc.

[0083] <4. Hardware Configuration> 10, an example of a hardware configuration in which the devices included in the above-described system 1 are realized by a computer 70 will be described. Note that the functions of each device can also be realized by dividing them among multiple devices.

[0084] As shown in FIG. 10, a computer 70 includes a processor 700 , a storage device 702 , an input I / F 704 , a data I / F 706 , a communication I / F 708 , and a display device 710 .

[0085] The processor 700 controls various processes in the computer 70 by executing programs stored in the storage device 702. For example, each functional unit included in the control unit 10 of the information processing device 2 can be realized by the processor 700 executing the programs stored in the storage device 702.

[0086] The storage device 702 is a storage medium such as a RAM (Random Access Memory), etc. The RAM temporarily stores the program code of the program executed by the processor 700 and data required when the program is executed.

[0087] The storage device 702 may also be a non-volatile storage medium such as a hard disk drive (HDD) or flash memory. The storage device 702 stores an operating system and various programs for implementing the above-described configurations. The storage medium storing the various programs may be a non-transitory computer-readable medium. The storage device 702 may also store tables that register various types of information and a DB that manages the tables. Such programs and data are loaded into the storage device 702 as needed and referenced by the processor 700.

[0088] The input I / F 704 is a device for receiving input from a user. Specific examples of the input I / F 704 include a camera, a button, a microphone, a keyboard, a mouse, a touch panel, various sensors, and a wearable device. The input I / F 704 may be connected to the computer 70 via an interface such as a USB (Universal Serial Bus).

[0089] The data I / F 706 is a device for inputting data from outside the computer 70. A specific example of the data I / F 706 is a drive device for reading data stored in various storage media. The data I / F 706 may be provided outside the computer 70. In this case, the data I / F 706 is connected to the computer 70 via an interface such as a USB.

[0090] The communication I / F 708 is a device for performing wired or wireless data communication with devices external to the computer 70 via the communication network 5. The communication I / F 708 may be provided external to the computer 70. In this case, the communication I / F 708 is connected to the computer 70 via an interface such as a USB.

[0091] The display device 710 is a device for displaying various types of information. Specific examples of the display device 710 include a liquid crystal display, an organic EL (Electro-Luminescence) display, and a display of a wearable device. The display device 710 may be provided outside the computer 70. In this case, the display device 710 is connected to the computer 70 via, for example, a display cable. Furthermore, when a touch panel is adopted as the input I / F 704, the display device 710 can be configured as an integral part of the input I / F 704.

[0092] Furthermore, the components of the devices included in the system 1 described in the above embodiment are assumed to realize predetermined processing in cooperation with other hardware by the processor 700 executing a program stored in the storage device 702. In other words, these components are envisioned as both software or firmware and the corresponding hardware, and in both of these concepts, they are also referred to as "functions," "means," "parts," "processing circuits," "units," or "modules," and can be interpreted as such.

[0093] The above-described embodiments are intended to facilitate understanding of the present disclosure and are not intended to limit the present disclosure. The elements of the embodiments, as well as their arrangement, materials, conditions, shapes, sizes, etc., are not limited to those illustrated and can be modified as appropriate. Furthermore, configurations shown in different embodiments can be partially substituted or combined with each other.

[0094] <5. Other configurations> The present disclosure includes the following techniques:

[0095] [Appendix 1] An information processing device 2 having one or more processors 700, wherein the processors 700 perform the following operations: acquire certification information including user information about a user and an electronic signature generated based on at least a portion of the user information; associate the certification information with transfer history information regarding the history of transfer of at least one of the certification information and the user information included in the certification information; output the certification information associated with the transfer history information to another information processing device; and change the transfer history information based on the output of the certification information to the other information processing device.

[0096] [Appendix 2] The user information includes encrypted user information, and the processor 700 further outputs the certification information to the other information processing device, and then acquires decryption request information regarding a request for decryption of the encrypted user information included in the certification information from the other information processing device, decrypts the encrypted user information based on the acquired decryption request information, and outputs information obtained by decrypting the encrypted user information to the other information processing device; The information processing device 2 according to Supplementary Note 1,

[0097] [Appendix 3] An information processing device 2 described in Appendix 2, wherein the electronic signature included in the certification information is generated based on encrypted user information included in the certification information, and decrypting the encrypted user information includes verifying the electronic signature based on obtaining decryption request information, and decrypting the encrypted user information if the verification is successful.

[0098] [Appendix 4] An information processing device 2 described in Appendix 2 or 3, wherein decrypting encrypted user information includes verifying transfer history information based on obtaining decryption request information, and decrypting the encrypted user information if the verification is successful.

[0099] [Appendix 5] An information processing device 2 as described in Appendix 4, wherein the transfer history information includes information regarding the history of transfers of non-fungible tokens associated with the proof information.

[0100] [Appendix 6] The information processing device 2 according to any one of Supplementary notes 2 to 5, wherein the other information processing device is a user's terminal device (user terminal device 3).

[0101] [Appendix 7] An information processing device 2 described in any one of Appendices 1 to 6, wherein the processor 700 further generates information regarding the compensation to be paid to the provider of the user information included in the certification information based on the transfer history information when outputting certification information associated with the transfer history information to another information processing device.

[0102] [Appendix 8] An information processing method in which one or more processors 700 acquire certification information including user information about a user and an electronic signature generated based on at least a portion of the user information, associate the certification information with transfer history information regarding the history of transfer of at least one of the certification information and the user information included in the certification information, output the certification information associated with the transfer history information to another information processing device, and change the transfer history information based on outputting the certification information to the other information processing device.

[0103] [Appendix 9] A program that causes one or more processors 700 to perform the following steps: obtain certification information including user information about a user and an electronic signature generated based on at least a portion of the user information; associate the certification information with transfer history information regarding the history of transfer of at least one of the certification information and the user information included in the certification information; output the certification information associated with the transfer history information to another information processing device; and change the transfer history information based on outputting the certification information to the other information processing device. [Explanation of symbols]

[0104] 1...system, 2...information processing device, 3...user terminal device, 4a...source server device, 4b...destination server device, 5...communication network, 10...control unit, 12...storage unit, 14...network interface unit, 70...computer, 100...acquisition unit, 102...generation unit, 104...verification unit, 106...encryption processing unit, 108...transfer history management unit, 109...determination unit, 110...output unit, 700...processor, 702...storage device, 710...display device

Claims

1. An information processing device comprising one or more processors, the processors comprising: obtaining certification information including user information about a user and a digital signature generated based on at least a portion of the user information; Associating the certification information with transfer history information regarding a history of transfer of at least one of the certification information and the user information included in the certification information; outputting the certification information associated with the transfer history information to another information processing device; changing the transfer history information based on outputting the certification information to the other information processing device; An information processing device that executes the above.

2. the user information includes encrypted user information; The processor further comprises: After outputting the certification information to the other information processing device, acquiring decryption request information regarding a request for decrypting the encrypted user information included in the certification information from the other information processing device; decrypting the encrypted user information based on the acquired decryption request information; outputting information obtained by decrypting the encrypted user information to the other information processing device; The information processing apparatus according to claim 1 , wherein the information processing apparatus executes the following:

3. the electronic signature included in the certification information is generated based on the encrypted user information included in the certification information; 3. The information processing device according to claim 2, wherein decrypting the encrypted user information includes verifying the electronic signature based on the acquisition of the decryption request information, and decrypting the encrypted user information if the verification is successful.

4. The information processing device according to claim 2 , wherein decrypting the encrypted user information includes verifying the transfer history information based on the acquisition of the decryption request information, and decrypting the encrypted user information if the verification is successful.

5. The information processing device according to claim 1 , wherein the transfer history information includes information relating to a history of transfers of non-fungible tokens associated with the certification information.

6. The information processing apparatus according to claim 2 , wherein the other information processing apparatus is a terminal device of the user.

7. The processor further comprises: The information processing device described in claim 1, wherein when the certification information associated with the transfer history information is output to the other information processing device, information regarding the compensation to be paid to the provider of the user information included in the certification information is generated based on the transfer history information.

8. One or more processors obtaining certification information including user information about a user and a digital signature generated based on at least a portion of the user information; Associating the certification information with transfer history information regarding a history of transfer of at least one of the certification information and the user information included in the certification information; outputting the certification information associated with the transfer history information to another information processing device; changing the transfer history information based on outputting the certification information to the other information processing device; An information processing method that performs the above.

9. one or more processors, obtaining certification information including user information about a user and a digital signature generated based on at least a portion of the user information; Associating the certification information with transfer history information regarding a history of transfer of at least one of the certification information and the user information included in the certification information; outputting the certification information associated with the transfer history information to another information processing device; changing the transfer history information based on outputting the certification information to the other information processing device; A program that executes.

Citation Information

Patent Citations

  • Method and system for authenticating secure qualification information transfer to device

    JP2023145552A