Display system, display method, and program
The display system integrates user and certification information on a user terminal, addressing the need for separate verification media by displaying authentic user attributes, thus simplifying and securing the authentication process.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-09
- Publication Date
- 2026-04-02
AI Technical Summary
Existing systems require separate presentation of user attributes verification media, such as IC cards, in addition to user terminals, complicating the authentication process.
A display system that integrates user information acquisition, certification information acquisition, provider information acquisition, and certification image generation to display certification information on a user terminal, including a user's face photograph and provider information, ensuring authenticity through dynamic images.
Facilitates seamless user attribute verification by integrating necessary information on a user terminal, enhancing security and simplifying the authentication process.
Smart Images

Figure 2026057472000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a display system, a display method, and a program.
Background Art
[0002] IC cards that can be used for various services such as personal identification and local government services are widespread. For example, the My Number Card stores electronic certificates and applications (APs) that can be used not only by local governments but also by private businesses. In addition, technologies have been proposed that enable user terminals such as mobile terminals to acquire and use the information stored in personal identification cards such as the My Number Card.
[0003] For example, in the technology described in Patent Document 1, after receiving the authentication information input to the user terminal, the reading unit reads the personal identification medium and transmits the authentication information, and when authenticated, the information acquisition unit acquires the information from the first information source and the second information source.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, when a user proves their attributes in a predetermined service or the like, in addition to the information acquired by the user terminal, there may be a possibility that a card or the like for proving the user's attributes needs to be presented separately.
[0006] In view of the above problems, an object of the present disclosure is to provide a display system or the like that preferably displays information for proving a user's attributes.
Means for Solving the Problems
[0007] The display system described herein displays certification information on the user terminal for the user to prove their own attributes. The display system comprises a user information acquisition unit, a certification information acquisition unit, a provider information acquisition unit, a certification image generation unit, and a display control unit. The user information acquisition unit acquires image data of the user's face photograph, which has been publicly guaranteed by an organization related to the national or local government, and links it with the user information of the user, which has been certified by a certification authority for a public personal authentication service. The certification information acquisition unit acquires information for display as certification information from an information management device that manages related information concerning the user. The provider information acquisition unit acquires provider information concerning the provider of the certification information from the information management device. The certification image generation unit generates a certification image to prove that the image displayed on the user terminal is authentic. The display control unit displays the face photograph, certification information, provider information, and certification image on the display unit of the user terminal.
[0008] The display method described herein is a display system in which a computer performs the following steps to display certification information on a user terminal for the user to prove their own attributes: The computer obtains image data of the user's face photograph, which has been publicly guaranteed by an organization related to the national or local government, and links it with the user information of the user, which has been certified by a certification authority for a public personal authentication service. The computer obtains information for display as certification information from an information management device that manages related information concerning the user. The computer obtains source information regarding the provider of the certification information. The computer generates a certification image to prove that the image to be displayed on the user terminal is authentic. The computer displays the face photograph, the certification information, the source information, and the certification image on the display unit of the user terminal.
[0009] The program relating to this disclosure is a display system that displays certification information on a user terminal for a user to prove their own attributes, and causes a computer to execute the following display method. The display method includes a user information acquisition step, a certification information acquisition step, a provider information acquisition step, a certification image generation step, and a display control step. The user information acquisition step acquires image data of the user's face photograph, which has been publicly guaranteed by an organization related to the national or local government, and links it with the user information of the user that has been certified by a certification authority for a public personal authentication service. The certification information acquisition step acquires information for display as certification information from an information management device that manages related information concerning the user. The provider information acquisition step acquires provider information concerning the provider of the certification information. The certification image generation step generates a certification image to prove that the image to be displayed on the user terminal is authentic. The display control step causes the face photograph, certification information, provider information, and certification image to be displayed on the display unit of the user terminal. [Effects of the Invention]
[0010] This disclosure provides a display system, display method, and program that suitably display information for verifying user attributes. [Brief explanation of the drawing]
[0011] [Figure 1] This is a block diagram of the certification system according to the first embodiment. [Figure 2] This is a block diagram of a user terminal including a display system according to the first embodiment. [Figure 3] This is a block diagram illustrating the hardware configuration of a computer. [Figure 4] This is a block diagram showing the software hierarchy of a user terminal. [Figure 5] This is a block diagram showing the software hierarchy for identity verification media. [Figure 6] This is a flowchart showing how to acquire screen data. [Figure 7]It is a diagram showing a state where a user terminal and an identity-verifiable medium communicate with each other. [Figure 8] It is a flowchart showing a display method according to the first embodiment. [Figure 9] It is a table showing related information. [Figure 10] It is a diagram showing an image in which proof information is displayed. [Figure 11] It is a block diagram of a user terminal according to the second embodiment. [Figure 12] It is a flowchart showing a display method according to the second embodiment. [Figure 13] It is a block diagram of a user terminal according to the third embodiment. [Figure 14] It is a flowchart showing a display method according to the first embodiment.
Embodiments for Carrying Out the Invention
[0012] Hereinafter, the present invention will be described through embodiments of the invention, but the invention according to the claims is not limited to the following embodiments. Also, not all of the configurations described in the embodiments are essential as means for solving the problems. For the sake of clarity of explanation, the following description and drawings have been appropriately omitted and simplified. In each drawing, the same reference numerals are assigned to the same elements, and redundant explanations are omitted as necessary.
[0013] <First Embodiment> (Proof System 1) Referring to FIG. 1, the configuration overview of the proof system 1 will be described. FIG. 1 is a block diagram of the proof system 1 according to the first embodiment. The proof system 1 is a system for a user who uses the proof system 1 to prove his or her own attributes to others. In the present disclosure, the attributes of the user himself / herself may also be referred to as user attributes or user characteristics. The user attributes may include the user's demographic attributes or psychographic attributes. Specifically, the user attributes may include the user's gender, age, family composition. The user attributes may include the user's address, the organization or group to which the user belongs. The user attributes may include the user's hobbies and preferences. The main components of the proof system 1 include an authentication system 10, a first business management system 40, a second business management system 50, an information management device 20, a certificate verification system 30, and a user terminal 100. These components are communicably connected via a network N1.
[0014] The authentication system 10 cooperates with the certificate verification system 30 to authenticate the user who uses the user terminal 100. The authentication system 10 also accesses the information management device 20 that stores information related to the authenticated user (i.e., related information 21) to manage the related information 21.
[0015] The authentication system 10 is operated by, for example, a predetermined platform operator. The platform operator is, for example, a private operator that meets certain standards related to information security, etc., and is a person who operates the authentication system 10 after receiving certification from the Minister in charge. In this case, the platform operator that operates the authentication system 10 receives the signature verification service of the public personal authentication service from the operators who operate the first business management system 40 and the second business management system 50 respectively. The platform operator provides, for example, a platform that uses a my number card, which is an identity confirmation medium 200, as an identity confirmation means, to other operators.
[0016] The information management device 20 includes a non-volatile storage device that stores user-related information 21. The related information 21 may include the user's personal information. For example, the related information 21 may include information referred to as basic four information. The basic four information is the user's name, date of birth, address, and gender. The related information 21 may also include the user's telephone number, email address, etc. Furthermore, the related information 21 may include information about points that the user can use in a designated area, the user's occupation, and family structure. The related information 21 may also include information about medicines or cosmetics used by the user. The related information 21 may also be referred to as user-related information 21.
[0017] Related information 21 includes management information for managing the user information described above. The management information includes information on access rights and item types corresponding to each item of user information. In other words, the information management device 20 manages user information based on the defined management information.
[0018] The information management device 20 accepts access from the authentication system 10, the first business management system 40, and the second business management system 50. The information management device 20 stores the related information 21 in a manner that allows the authentication system 10, the first business management system 40, and the second business management system 50 to read and write at least a portion of the related information 21. At the same time, the information management device 20 controls access from the authentication system 10, the first business management system 40, and the second business management system 50 based on the management information described above.
[0019] The information management device 20 may be a so-called cloud storage or cloud server. The information management device 20 can also be a common data platform for managing related information 21 accessible by the authentication system 10, the first business management system 40, and the second business management system 50. In this disclosure, the common data platform may also be referred to as a registry.
[0020] The certificate verification system 30 is a system that verifies that the authentication procedure performed by a user using the user terminal 100 is authentic. For example, the certificate verification system 30 receives information about the user sent by the user terminal 100 and verifies that this information is authentic. Specifically, the certificate verification system 30 performs verification by comparing the information provided by the user terminal 100 with information corresponding to user authentication that it has stored in advance. The information provided by the user terminal 100 may include, for example, signature information or key information. The certificate verification system 30 feeds back the verification result to at least one of the user terminal 100 or the authentication system 10.
[0021] The certificate verification system 30 may, for example, be used to authenticate the public personal authentication service operated by the Japan Local Government Information Systems Organization (J-LIS). The public personal authentication service is a means of identity verification used when performing administrative procedures such as online applications and notifications via the internet. The certification authority for the public personal authentication service authenticates users who use the public personal authentication service. That is, the certificate verification system 30, as the certification authority for the public personal authentication service, receives information to be authenticated from designated organizations such as local governments and responds as to whether the received information is valid or not. The information to be authenticated is, for example, an electronic certificate. In addition to procedures by the national or local government, the public personal authentication service is also used for procedures by private businesses. For example, the operator of the authentication system may be a local government or a private business. Similarly, the first business operator managing the first business management system 40 may be a local government or a private business. The second business operator managing the second business management system 50 may be a local government or a private business.
[0022] The first business management system 40 is a system managed by the first business operator that provides the first service to users via the user terminal 100. The first business management system 40 is a system that utilizes a computer, server, or cloud. The first business management system 40 provides the first service to users by utilizing at least a portion of the related information 21 stored in the information management device 20.
[0023] The second business management system 50 is a system managed by the second business operator that provides the second service to the user via the user terminal 100. The second business management system 50 is a system that utilizes a computer, server, or cloud. The second business management system 50 provides the second service to the user by utilizing at least a portion of the related information 21 stored in the information management device 20.
[0024] The first and second services are, for example, point services related to stores used by the user. Alternatively, the first and second services may be services related to a specific organization to which the user belongs. The first and second services may also be information provision services related to disaster prevention, or services managing information about medications used by the user. Furthermore, the first and second services may be administrative services of the local government where the user resides.
[0025] The first business management system 40 and the second business management system 50 can provide the above-mentioned services through applications installed on the user terminal 100. The application may be dedicated application software, a web application accessible via a browser, or a website itself.
[0026] The first business operator and the second business operator, who operate the first business management system 40 and the second business management system 50 respectively, may be referred to as service provider operators. When service provider operators provide services to users, they use user authentication using the identity verification medium 200 as a means of identity verification. Furthermore, the platform operator and the service provider operators can use the information stored in the information management device 20 as appropriate and under certain conditions.
[0027] User terminal 100 is a portable terminal used by a user who wishes to prove their attributes using the authentication system 1. User terminal 100 can be, for example, a smartphone, tablet, mobile phone, or notebook PC. User terminal 100 may also be a wearable device such as a smartwatch with communication functions and a display. User terminal 100 can communicate with each component of the authentication system 1 via the network N1.
[0028] The user terminal 100 has means for reading user information and image data from the identity verification medium 200. The means for reading user information and image data may be, for example, near-field communication such as NFC (Near Field Communication). The means for reading user information and image data may also be wired communication, for example, through contact between the user terminal 100 and the identity verification medium 200.
[0029] The user information described above is personal information of the user that can be obtained by authenticating the user. User information is information about the user that can be obtained from the identity verification medium 200. User information is typically information about the electronic certificate stored on the user's identity verification medium 200. Information about the electronic certificate may be the electronic certificate itself or the serial number of the electronic certificate. Personal information is information about a living individual that can identify a specific individual, such as name, date of birth, address, and facial photograph. Personal information may be the four basic pieces of information, or it may be information other than these four pieces of information. User information can also be said to be personal information that can be obtained by performing authentication with a signature electronic certificate that can be used for public personal authentication services. Alternatively, user information may be personal information that can be obtained by using a ticket information input assistance application or a ticket information verification application.
[0030] The image data described above is an image of the user's face, i.e., a photograph of the user's face. The image data stored in the identity verification medium 200 is publicly guaranteed by an organization related to the national or local government. The user terminal 100 acquires this image data, and the authentication system 1 authenticates the user's attributes by displaying the acquired image data as authentication information. The authentication system 1 may, in place of the acquired image data, or in addition to the acquired image data, display alternative image data that is different from this image data. In this case, the alternative image data includes a photograph of the user's face. Whether or not the image data includes a photograph of the user's face can be determined by calculating the feature quantities of the user's face from the image data. In other words, in this case, the user terminal 100 has a function to calculate the feature quantities of the face image included in the image data. Alternatively, the user terminal 100 may have a function to extract alternative image data using the function to calculate the feature quantities of the face image included in the image data. This allows the user terminal 100 to extract image data that includes the user's face image from the image data that the user terminal 100 has stored in advance. This allows the authentication system 1 to display a color image stored in the user terminal 100 if, for example, the image data obtained from the identity verification medium 200 is monochrome. Alternatively, the authentication system 1 can display a face image with a higher resolution than the image data obtained from the identity verification medium 200. The alternative image data may be stored in the information management device 20.
[0031] The identity verification medium 200 is a medium that stores at least user information and image data in a manner that can be read by the user terminal 100. The identity verification medium 200 is used, for example, to verify identity in services provided by local governments or private businesses. More specifically, the identity verification medium 200 is, for example, a My Number Card. The identity verification medium 200 may be a medium other than a My Number Card, as long as it stores publicly guaranteed image data of the user's face photograph.
[0032] If the user terminal 100 has the function to read information from the identity verification medium 200 via NFC, the identity verification medium 200 has an NFC-compatible antenna and communication function. When the user terminal 100 reads information from the identity verification medium 200 using a barcode reading camera, the identity verification medium 200 displays a barcode containing user information and image data that can be photographed.
[0033] The above describes the configuration overview of the authentication system 1. When using the authentication system 1, the user displays information that proves the user's attributes (i.e., authentication information) on the user terminal 100. To achieve the above function, the user causes the user terminal 100 to read information from the identity verification medium 200. The user also causes the user terminal 100 to acquire information stored in the information management device 20. The user terminal 100 displays the information acquired from the identity verification medium 200 and the information management device 20 as authentication information.
[0034] The above describes the configuration of the certification system 1, but the certification system 1 is not limited to the above configuration. For example, the authentication system 10 may include an information management device 20. Also, the platform operator that operates the authentication system 10 and the operator that operates the first business management system 40 or the second business management system 50 may be the same person.
[0035] (User terminal 100) Next, the configuration of the user terminal 100 will be described with reference to Figure 2. Figure 2 is a block diagram of the user terminal 100 including the display system 110 according to the first embodiment. The user terminal 100 mainly consists of a display system 110, a communication unit 121, a display unit 122, an input reception unit 123, a login unit 125, and an onboarding start function unit 140.
[0036] (Display system 110) The display system 110 has a function to display certification information on the user terminal for the user to prove their own attributes. The display system 110 includes a user information acquisition unit 111, a certification information acquisition unit 112, a provider information acquisition unit 113, a certification image generation unit 114, and a display control unit 115.
[0037] The user information acquisition unit 111 acquires image data of a user's face, which has been publicly guaranteed by an organization related to the national or local government, and links it with the user information of the user, which has been authenticated by a certification authority for the public personal authentication service.
[0038] Specifically, for example, the user information acquisition unit 111 acquires image data stored in the identity verification medium 200 when the user terminal 100 communicates with the identity verification medium 200. At this time, the user information acquisition unit 111 acquires the image data while it is linked to the user information authenticated by the certification authority of the public personal authentication service. As a result, the user information acquisition unit 111 acquires authentic image data in a suitable manner.
[0039] The certification information acquisition unit 112 acquires information for display as certification information from the information management device 20, which manages related information 21 related to the user. That is, the certification information acquisition unit 112 acquires items from the related information 21 stored by the information management device 20 via the network N1 that are to be displayed on the user terminal 100 as certification information. In addition, the user information acquisition unit 111 may acquire user information at the same time as acquiring image data. In this case, the certification information acquisition unit 112 may also add the user information acquired by the user information acquisition unit 111 along with the image data to the information for display as certification information. In this case, the user terminal 100 may also register the user information acquired by the user information acquisition unit 111 with the information management device 20.
[0040] The items to be displayed on the user terminal 100 as authentication information may be pre-configured. The items to be displayed on the user terminal 100 as authentication information may be configured according to, for example, the first service or the second service. In other words, in this case, the display system 110 may be configured to retrieve authentication information associated with a particular service.
[0041] Specifically, for example, in the display system 110, a user may want to display on the user terminal 100 certification information related to a service operated by a first or second business operator that has access to the information management device 20. In that case, the certification information acquisition unit 112 acquires the information set by the business operator from the information management device 20 as certification information.
[0042] The provider information acquisition unit 113 acquires provider information regarding the provider of the certification information from the information management device 20. That is, the provider information acquisition unit 113 refers to the related information 21 of the information management device 20 and acquires information regarding the provider of the certification information acquired by the certification information acquisition unit 112 from the related information 21. In this disclosure, "provider" means the source of the information acquired by the certification information acquisition unit 112 as certification information. The provider may be a provider or the information source / service from which the provision originated. In this disclosure, "provider" means the person who registered the information acquired by the certification information acquisition unit 112 as certification information in the information management device 20. For example, if the certification information is related to the first service, the provider is the first business operator. If there are multiple pieces of information acquired by the certification information acquisition unit 112, there may be multiple providers. An information source is, for example, a My Number Card. An information source service is, for example, MyNa Portal or other administrative services by local governments. An information source service may also include private services. An example of information that uses MyNa Portal as an information source is family register information.
[0043] The certification image generation unit 114 generates a certification image to prove that the image displayed on the user terminal is authentic. By displaying the certification image generated by the certification image generation unit 114 on the same screen as the certification information, the display system 110 makes it easier for third parties to recognize that the certification information is authentic. For example, if someone other than the user attempts to plagiarize and use the certification information, the image containing the plagiarized information can be distinguished from the authentic one.
[0044] The proof image is, for example, a character, color tone, or image that changes according to the time. In this case, the proof image generation unit 114 generates a proof image of a character, color tone, or image that changes according to the time at predetermined intervals.
[0045] The proof image may be an image of a two-dimensional code that changes according to the time. In this case, the reader used by the person verifying the user's attributes reads the proof image. That is, in this case, the proof image generation unit 114 generates a proof image, which is a two-dimensional code that changes according to the time, so that the reader used to determine whether the proof information is genuine can read it.
[0046] The display control unit 115 displays the facial photograph, certification information, provider information, and certification image on the display unit 122 of the user terminal 100. That is, the display control unit 115 generates an image to prove the user's attributes and displays the generated image on the display unit 122 of the user terminal 100. Here, the display control unit 115 may also display the facial photograph from the alternative image data mentioned above as the facial photograph on the display unit 122. That is, in this case, the display control unit 115 displays the facial photograph from the alternative image data corresponding to the user's facial photograph obtained in association with user information on the display unit 122. As a result, the display system 110 can display a facial photograph suitable for proving the user's attributes.
[0047] Furthermore, when the certification image generation unit 114 generates characters, colors, or images that change according to the time at predetermined intervals, the display control unit 115 sequentially displays the updated certification images on the display unit 122. By displaying characters, colors, or images that change according to the time on the display unit 122 at predetermined intervals, the display system 110 can effectively indicate that the certification information is genuine.
[0048] Furthermore, when the certification image generation unit 114 generates a two-dimensional code image that changes according to the time, the display control unit 115 sequentially displays the updated two-dimensional code image on the display unit 122. When the display unit 122 displays a two-dimensional code image that changes according to the time, the display system 110 can suitably present information to the reader indicating that the certification information is genuine.
[0049] (Other configurations of user terminal 100) The communication unit 121 transmits and receives various information with the authentication system 10, information management device 20, and certificate verification system 30, etc., via the network N1. The communication unit 121 also performs short-range wireless communication with the identity verification medium 200.
[0050] The display unit 122 displays various information on a liquid crystal panel or a display containing organic electroluminescence. The display unit 122 in this disclosure displays an image generated by the display control unit 115. The image generated by the display control unit 115 includes an image for verifying the user's attributes. That is, the "image for verifying the user's attributes" includes a photograph of the user's face, verification information, provider information, and a verification image. In other words, the display unit 122 displays a photograph of the face, verification information, provider information, and a verification image.
[0051] The input receiving unit 123 receives input from the user operating the user terminal 100. The input receiving unit 123 receives user operations, for example, via switches on the user terminal 100 and a touch panel superimposed on the display of the display unit 122.
[0052] The login unit 125 performs the user login process for the application installed on the user terminal 100 if the user's authentication registration has been completed. The login unit 125 may use pre-registered authentication information in the login process. The onboarding start function unit 140 performs processes for user authentication and user authentication registration from the start of the authentication process.
[0053] The functional configuration of the user terminal 100 has been described above. Note that communication between the user terminal 100 and the identity verification medium 200 is not limited to short-range wireless communication. Communication between the user terminal 100 and the identity verification medium 200 may also be wired communication through physical contact between the user terminal 100 and the identity verification medium 200. Furthermore, the user terminal 100 can supply image data acquired by the user information acquisition unit 111 or alternative image data corresponding to this image data to the information management device 20 and register it as related information 21 in the information management device 20. In this case, by storing the image data in the information management device 20 and retrieving the stored image data from the information management device 20, the display system 110 can repeatedly use the facial photograph stored in the information management device 20. Also, if the user newly takes or registers image data that can serve as alternative image data, the display system 110 may use the newly taken or registered alternative image data instead of previously acquired image data or previously registered alternative image data. After storing the image data in the information management device 20, the display system 110 displays it on the display unit 122. However, the display system 110 may display the image data on the display unit 122 before storing it in the information management device 20.
[0054] In relation to the functions of the user terminal 100 described above, the authentication system 10, in cooperation with the onboarding start function unit 140, registers the user's authentication information in the information management device 20 after successful authentication in user authentication registration. Here, user authentication registration means, for example, registering that the user is a person who will use services related to at least a part of the certification system 1. The authentication information includes user-specific information such as an electronic signature used during the authentication process, or information linked thereto. Preferably, the authentication information includes an electronic signature encoded by a predetermined algorithm.
[0055] The user authenticates themselves via the user terminal 100 through an onboarding start process using the identity verification medium 200. If authentication is successful, the authentication system 10 registers the user's authentication information in the information management device 20. Once the user's authentication information is registered, the user can log in to services related to the certification system 1 in subsequent operations and use various services. By performing user authentication registration using this public personal authentication service, the certification system 1 prevents fraudulent registration.
[0056] Furthermore, after user authentication registration is complete, the authentication system 10 determines whether the information obtained from the identity verification medium 200 is genuine or not. More specifically, for example, the authentication system 10 compares the information obtained from the identity verification medium 200 with the authentication information registered in the information management device 20.
[0057] (Example hardware configuration) Figure 3 is a block diagram illustrating the hardware configuration of a computer. The user terminal 100 described above may have the configuration shown in Figure 3. The computer 1000 has a bus 1010, a processor 1020, memory 1030, a storage device 1040, an input / output interface 1050, and a network interface 1060.
[0058] Bus 1010 is a data transmission path for the processor 1020, memory 1030, storage device 1040, input / output interface 1050, and network interface 1060 to send and receive data to and from each other. However, the method of connecting the processor 1020 and the other components to each other is not limited to bus connection.
[0059] Processor 1020 is a circuit that includes arithmetic units such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit).
[0060] Memory 1030 is a main memory device implemented using RAM (Random Access Memory), etc.
[0061] The storage device 1040 is an auxiliary storage device such as an HDD (Hard Disk Drive), SSD (Solid State Drive), flash memory, or ROM (Read Only Memory). The storage device 1040 stores a program for realizing the functions of this disclosure.
[0062] The processor 1020 reads this program into memory 1030 and executes it. This causes the processor 1020 to perform the function corresponding to this program. In other words, the program stored in memory 1030 causes the computer 1000 to perform the function of this disclosure.
[0063] The input / output interface 1050 connects the computer 1000 to a predetermined input / output device. The input / output device is, for example, an input device such as a keyboard, an output device such as a display, or an input / output device in which a touch panel is superimposed on a display.
[0064] The network interface 1060 is an interface for connecting the computer 1000 to a predetermined communication network.
[0065] The computer 1000 has been described above, but in addition to the above configuration, the computer 1000 may have an information input device for the user to input various information into the computer 1000 through operation. The information input device may be, for example, a keyboard, mouse, or touch panel. The computer 1000 may also have a display, speaker, vibration motor, or LED (light-emitting diode) for showing various information to the user.
[0066] (Software configuration of user terminal 100) Next, an overview of the software configuration of the user terminal 100 will be described with reference to Figure 4. Figure 4 is a block diagram showing the software hierarchy of the user terminal 100. The user terminal 100 has at least an operating system, an authentication application, a first application, and a second application.
[0067] The operating system is the basic software on user terminal 100. The operating system serves as the foundation for the operation of multiple application software programs.
[0068] Authentication applications are application software that operates based on the functions of the operating system. Authentication applications perform functions related to services operated by platform operators. For example, an authentication application authenticates users using a verifiable medium 200. Furthermore, an authentication application has the function of displaying an image that proves the user's attributes within the services provided by the platform operator.
[0069] The authentication application forms the foundation for the operation of the first and second applications. In other words, the authentication application can be referred to as a super application. A super application is an application that encompasses multiple applications with different functions within a single application. In addition to providing users with services operated by the platform provider, the authentication application provides the first service operated by the first provider through the first application and the second service operated by the second provider through the second application.
[0070] The first and second applications each function based on the authentication application. The first and second applications may also be referred to as mini-applications running on top of the super application. The first application may, for example, have the functionality to display an image to verify the user's attributes in the first service. Similarly, the second service provider may, for example, have the functionality to display an image to verify the user's attributes in the second service via the second application. The services acting as mini-applications may also be provided by the platform provider.
[0071] (Software configuration for 200 media capable of identity verification) Next, with reference to Figure 5, an overview of the software configuration of the identity verification medium 200 will be described. Figure 5 is a block diagram showing the software hierarchy of the identity verification medium 200. The identity verification medium 200 shown in Figure 5 is a My Number Card. Note that the My Number Card is one embodiment of the identity verification medium 200. The My Number Card mainly consists of an operating system, a public personal authentication application, a card surface information verification application, and a card surface information input assistance application.
[0072] The operating system is the basic software that enables the IC chip (Integrated Circuit) on the My Number Card to function. The operating system is also called the card OS (Operating System). The operating system forms the foundation for the operation of the public personal authentication application, the card information verification application, and the card information input assistance application. In other words, the public personal authentication application, the card information verification application, and the card information input assistance application all function based on the operating system.
[0073] The Public Personal Authentication Application is an application used in the Public Personal Authentication Service using My Number Cards to authenticate users using their own electronic certificates. The Public Personal Authentication Application is used for identity verification in online services. More specifically, it is used to log in to MyNa Portal, the online portal for administrative procedures. Alternatively, it is used to log in to services provided by private companies.
[0074] The Card Information Verification Application is an application for verifying the information printed on a My Number Card. The Card Information Verification Application reads the card information, including the four basic pieces of information, stored in the IC chip embedded in the My Number Card and displays it on the user terminal 100. The Card Information Verification Application can also display the user's facial photograph, which is stored in the IC chip embedded in the My Number Card, on the user terminal 100.
[0075] The Card Information Input Assistance Application is an application that uses the information on the My Number Card to assist with various procedures and form input. The Card Information Input Assistance Application reads the information on the IC chip of the My Number Card and automatically reflects it in the application's input fields.
[0076] The IC chip embedded in the My Number Card stores two electronic certificates issued to individuals through the Public Personal Authentication Service: a user authentication electronic certificate and a signature electronic certificate. The user authentication electronic certificate is used to verify the identity of the user when logging into the My Number Portal or when using the public certificate issuance procedure at a convenience store. The signature electronic certificate contains four pieces of information: name, address, date of birth, and gender, and is used to electronically sign and transmit electronic documents, etc. The platform operator that operates the authentication system 10 uses these two electronic certificates in the authentication procedure.
[0077] (Image data acquisition routine) Next, referring to Figure 6, the process by which the display system 110 of the user terminal 100 acquires image data will be explained. Figure 6 is a flowchart of the image data acquisition method. Here, the process shown in Figure 6 is referred to as the image data acquisition routine. The image data acquisition routine also includes processes of components other than the display system 110 in the user terminal 100.
[0078] In step S101, the user information acquisition unit 111 requests the input of a PIN for identity verification and a PIN for image data acquisition. The user terminal 100 receives this request and displays a message on the display unit 122 prompting the user to input the PIN for identity verification and the PIN for image data acquisition. The user information acquisition unit 111 may accept the input of the PIN for identity verification and the PIN for image data acquisition simultaneously (for example, on a single screen of the user terminal 100) or at different times. Here, the PIN for identity verification is typically the PIN for the digital signature certificate or the PIN for the digital user authentication certificate. The PIN for image data acquisition is, for example, the PIN for the card information verification application. A typical combination of PINs requested by the user information acquisition unit 111 is the PIN for the digital user authentication certificate and the PIN for the card information verification application. The PIN for identity verification may also be referred to as the first authentication information. The PIN used to obtain image data can also be referred to as the second authentication information.
[0079] In step S102, the user terminal 100 receives a PIN for identity verification and a PIN for image data acquisition. That is, the user terminal 100 receives, for example, the PIN for the user authentication electronic certificate and the PIN for the certificate information verification application.
[0080] In step S103, the user information acquisition unit 111 requests that the identity verification medium 200 be read. In response, the user terminal 100 displays a message on the display unit 122 prompting the user to bring the user terminal 100 and the identity verification medium 200 closer together.
[0081] In step S104, the user terminal 100 performs a read operation on the identity verification medium 200. Here, the user terminal 100 sends a PIN for identity verification and a PIN for acquiring image data to the identity verification medium 200. If authentication on the identity verification medium 200 is successful using the PINs sent by the user terminal 100, the identity verification medium 200 sends user information to the user terminal 100. User information is, for example, the four basic pieces of information of the user. The user terminal 100 receives the user information from the identity verification medium 200. The user terminal 100 supplies the received user information to the authentication system 10. If authentication on the identity verification medium 200 fails, the process may be terminated.
[0082] In the communication between the user terminal 100 and the identity verification medium 200 described above, the user information acquisition unit 111 may acquire at least a portion of personal information (for example, basic four pieces of information) as user information, which can be obtained by performing authentication using a digital signature certificate usable in the public personal authentication service.
[0083] Furthermore, in the communication between the user terminal 100 and the identity verification medium 200 described above, the user information acquisition unit 111 may acquire at least a portion of the personal information that can be obtained by using the ticket surface information input assistance application as user information. Similarly, the user information acquisition unit 111 may acquire at least a portion of the personal information that can be obtained by using the ticket surface information verification application as user information. The user terminal 100 may also perform a process to register the user information acquired through communication between the user terminal 100 and the identity verification medium 200 in the related information 21.
[0084] In step S105, the user information acquisition unit 111 determines whether the authentication by the authentication system 10 was successful. Here, the authentication of the authentication system 10 is considered successful if, firstly, the user's identity is verified using the user information authenticated by the certification authority of the public personal authentication service, and the authentication system 10 receives information indicating that the identity verification was successful. Secondly, the user's identity is verified by comparing the authentication information stored in the information management device 20 with the user information acquired in this instance.
[0085] If the authentication system 10 determines that authentication was successful (step S105: YES), the user information acquisition unit 111 proceeds to step S106. If the authentication system 10 does not determine that authentication was successful (step S105: NO), the display system 110 terminates the image data acquisition routine.
[0086] In step S106, the user information acquisition unit 111 acquires image data. Specifically, the user information acquisition unit 111 acquires image data of the user's face, which has been publicly guaranteed by an organization related to the national or local government, and links it with the user information of the user authenticated by the certification authority of the public personal authentication service. Acquiring it linked with the user's user information means, for example, acquiring image data corresponding to the user information used for authentication in step S105. Corresponding to user information means, for example, that it is stored in the same information source as the user information. In this case, the same information source as the user information is, for example, the identity verification medium 200. To acquire image data from the same information source as the user information, it is preferable to acquire the image data together, for example, within the period of the session in which the user was authenticated. More specifically in this case, the user information acquisition unit 111 acquires image data of the user's face from, for example, the ticket surface item confirmation application. In this way, the user information acquisition unit 111 acquires image data of the face linked with the user information of the user whose authentication was successful. As a result, the display system 110 suitably acquires the face of the user whose identity has been verified. In other words, the display system 110 prevents the acquisition of a non-authenticated facial photograph from a medium different from the identity verification medium 200 used for identity verification. Once the user information acquisition unit 111 acquires the image data, the display system 110 proceeds to step S107.
[0087] In step S107, the display system 110 determines whether or not to proceed to the display routine. The display routine is a process that displays the certification data, including the acquired image data, on the display unit 122. Whether or not to proceed to the display routine may be prompted to the user by the application running on the user terminal 100.
[0088] If it is determined not to proceed to the display routine (step S107: NO), the display system 110 terminates the image data acquisition routine. If it is determined to proceed to the display routine (step S107: YES), the display system 110 starts the display routine. The display routine will be described later.
[0089] The process by which the user information acquisition unit 111 acquires image data has been described above. However, the image data acquisition routine is not limited to the process described above. For example, if a user has never undergone an authentication procedure, the information management device 20 does not contain any authentication information indicating that the user has been authenticated. In this case, the user terminal 100 operates the onboarding start function unit 140 to perform the onboarding procedure. At this time, the user information acquisition unit 111 may acquire image data in the process of reading the identity verification medium 200 during the onboarding procedure. However, even when acquiring image data during the onboarding procedure, the user terminal 100 performs the same processing as steps S101 to S106 described above.
[0090] In the process described above, the user information acquisition unit 111 acquires user information from the identity verification medium 200, which is a tangible object, through an authentication procedure performed via near-field communication between the medium and the user terminal 100. The user information acquisition unit 111 also acquires image data from the identity verification medium 200 through an authentication procedure performed via near-field communication. Specifically, for example, the user information acquisition unit 111 acquires user information from the My Number Card, which is a tangible object, through an authentication procedure performed via NFC (registered trademark) between the My Number Card and the user terminal 100. The user information acquisition unit 111 also acquires image data from the My Number Card through an authentication procedure performed via NFC.
[0091] Furthermore, in the above-described process, the user information acquisition unit 111 acquires at least a portion of the personal information that can be obtained by performing authentication using a digital signature certificate as user information. The user information acquisition unit 111 may also acquire at least a portion of the personal information that can be obtained by using a ticket information input assistance application or a ticket information verification application as user information.
[0092] In the process described above, the user information acquisition unit 111 acquires image data from the identity verification medium 200 within the reading period if the authentication procedure is successful through a single reading process performed when the identity verification medium 200 and the user terminal come close together once.
[0093] (Status of reading process) Figure 7 shows the state in which the user terminal 100 and the identity verification medium 200 communicate. A typical example of the identity verification medium 200 is a My Number Card. The user brings the short-range wireless communication antenna of the user terminal 100 close to the identity verification medium 200. This enables the user terminal 100 to communicate with the identity verification medium 200. In communication with the identity verification medium 200, the user terminal 100 supplies the identity verification medium 200 with first authentication information (a PIN for identity verification) and second authentication information (a PIN for acquiring image data). The identity verification medium 200 stores first information of the first information source corresponding to the first authentication information in its IC chip. Here, if the first authentication information is the PIN for the user authentication electronic certificate, the first information source is a public personal authentication application, and the first information is, for example, the user's electronic signature. The identity verification medium 200 stores second information of the second information source corresponding to the second authentication information in its IC chip. If the second authentication information is the PIN for the ticket information verification application, the second information source is the ticket information verification application, and the second information is image data of the user's face photograph. The identity verification medium 200 receives the first authentication information and the second authentication information from the user terminal 100 and performs authentication of the two received authentication pieces of information (first authentication information and second authentication information). If authentication is successful, the identity verification medium 200 supplies the first and second information corresponding to the received authentication information to the user terminal 100.
[0094] As described above, the display system 110 may acquire image data from the identity verification medium 200 within the reading period if the authentication procedure is successful through a single reading process performed when the user terminal 100 and the identity verification medium 200 come close together once. In this case, the user terminal 100 acquires information corresponding to each of the two PINs mentioned above from the identity verification medium 200 by bringing the user terminal 100 and the identity verification medium 200 close together once. The display system 110 may also acquire user information in addition to image data from the identity verification medium 200 within the reading period if the authentication procedure is successful through a single reading process.
[0095] (Display method) Next, the processes executed by the display system 110 will be described with reference to Figure 8. Figure 8 is a flowchart of the display method according to the first embodiment. The flowchart shown in Figure 8 shows the processes executed by the display system 110 when the user displays verification information for the user to prove their own attributes on the user terminal 100.
[0096] In step S110, the display system 110 determines whether the user terminal 100 has already acquired image data. If it is determined that the user terminal 100 has not already acquired image data (step S110: NO), the display system 110 proceeds to step S111. If it is determined that the user terminal 100 has already acquired image data (step S110: YES), the display system 110 proceeds to step S120.
[0097] In step S111, the display system 110 determines whether or not to acquire image data. Specifically, for example, the display system 110 displays a message on the display unit 122 asking whether or not to acquire image data, and accepts instructions from the user. If the display system 110 does not determine to acquire image data based on the user's instructions (step S111: NO), the display system 110 terminates the display routine. On the other hand, if the display system 110 determines to acquire image data based on the user's instructions (step S111: YES), the display system 110 moves to the image data acquisition routine and starts the image data acquisition routine shown in Figure 6.
[0098] In step S120, the certification information acquisition unit 112 acquires information for display as certification information from the information management device 20 which manages related information 21 related to the user. The certification information acquisition unit 112 supplies the acquired related information 21 to the display control unit 115. Note that the user information acquisition unit 111 may acquire user information at the same time as acquiring image data. In this case, the certification information acquisition unit 112 may also add the user information acquired by the user information acquisition unit 111 along with the image data to the information for display as certification information.
[0099] In step S130, the provider information acquisition unit 113 acquires provider information regarding the provider of the certification information from the information management device 20. The provider information acquisition unit 113 supplies the acquired certification information to the display control unit 115.
[0100] In step S140, the proof image generation unit 114 generates a proof image to prove that the image to be displayed on the user terminal is authentic. The proof image generation unit 114 supplies the generated proof image to the display control unit 115.
[0101] In step S150, the display control unit 115 displays the facial photograph, identification information, provider information, and identification image on the display unit 122 of the user terminal. More specifically, the display control unit 115 generates a display image that includes the facial photograph, identification information, provider information, and identification image received from each of the above-mentioned components. Furthermore, the display control unit 115 displays this display image on the display unit 122.
[0102] (Related Information 21) Next, we will explain the related information 21 with reference to Figure 9. Figure 9 is a table showing the related information 21 stored by the information management device 20. The table of related information 21 shown in Figure 9 includes "item number," "configurator," "access rights," "definition," and user number vertically, and the defined information is shown horizontally in order of item number.
[0103] "Item number" is a number assigned to each configured item. "Configurator" indicates the name of the business operator that configured the information content for the corresponding item number. The configurer is the person who defined the information for the corresponding item number in related information 21. In this disclosure, the configurer can also be referred to as the provider or source. "Access rights" indicates the business operators who can access the information configured for each item number. "Definition" indicates the type of information defined for each item. User number is a number assigned to each of the multiple users who use certification system 1.
[0104] In related information 21, for example, item number #001 is information set by the platform operator, all operators have access rights, and the defined information is "name information". Item number #002 is information set by the first operator, both the first and second operators have access rights, and the defined information is "address". Similarly, item number #003 is information set by the first operator, the first operator has access rights, and the defined information is "family structure". Item number #004 is information set by the second operator, the second operator has access rights, and the defined information is "medication information".
[0105] As described above, for user number 0001, the name information is registered as "**Ichiro" and the address is registered as "A Prefecture, B City...". Similarly, the family structure and medication information for user number 0001 are also registered. For user number 0002, the name information is registered as "**Hanako" and the address is registered as "C Prefecture, D City...". In addition, the family structure and medication information are also registered. For user number 0003, the name information is registered as "**Taro" and the address is registered as "E Prefecture, F City...". In addition, the family structure and medication information are also registered.
[0106] The above explains related information 21. Users of the certification system 1 utilize related information 21 as shown below, for example. For example, suppose user number 0001, "**Ichiro", owns user terminal 100. Also, suppose the user wishes to display an identification card that proves their attributes on user terminal 100 in the first service. In this case, the certification information acquisition unit 112 of the display system 110 acquires information to be displayed as certification information from the related information 21 described above. In this case, the certification information acquisition unit 112 acquires information that can be displayed as certification information from the information that the first service provider that provides the first service can access. In the above explanation, access rights were set for each item, but access rights may be set for each item and for each user. The related information 21 may include information about the provider, which is the source of each of the registered pieces of information.
[0107] (Image displayed) Next, with reference to Figure 10, an example of an image displayed on the display unit 122 of the user terminal 100 will be described. Figure 10 is a diagram showing an image displaying authentication information. Figure 10 shows the display image 150. The display image 150 is an image that displays authentication information in an authentication application. The display image 150 includes a virtual card area 160, a facial photograph 170, and an authentication image 180.
[0108] The virtual card area 160 includes provider information 161 and certification information 162. The facial photograph 170 is obtained by the user terminal 100 from the identity verification medium 200. The facial photograph 170 is a facial photograph of the user officially guaranteed by an organization related to the national or local government. The provider information 161 includes one or more providers related to the provision of certification information. The provider information 161 may include two or more providers. Furthermore, the provider information 161 may include providers corresponding to each of multiple pieces of certification information.
[0109] The proof image 180 includes a time display 181, a moving image 182, and a two-dimensional code 183. The time display 181 is a string of characters that changes according to the time. The moving image 182 is an image whose color tone or shape changes according to the time. The two-dimensional code 183 is a two-dimensional code that changes according to the time. More specifically, for example, the information in the two-dimensional code 183 includes time information that is updated every second.
[0110] By displaying an image containing a suitably guaranteed authentic facial photograph and identification information on the user terminal 100, the display system 110 can suitably verify the user's attributes. Furthermore, by displaying the aforementioned image on the user terminal 100, users utilizing the certification system 1 can easily present their user attributes in various services.
[0111] The proof image 180 may display at least one of the above-mentioned time display 181, moving image 182, and two-dimensional code 183. The background 151 of the image displaying the proof information may change in color according to the time.
[0112] The image above is an example of how authentication information is displayed in a super app service provided by a platform operator. However, the image displaying the authentication information may also be one that verifies the user's attributes in a mini-app that functions on the super app. Furthermore, the authentication application on the user terminal 100 may be configured to allow switching between the authentication information of the super app, the authentication information of the first service, and the authentication information of the second service. By enabling the display of authentication information for multiple different services in a switchable manner, the display system 110 can prevent the user from having to handle information to prove multiple different attributes in a complicated manner.
[0113] The first embodiment has been described above. In this embodiment, a My Number Card is given as an example of the identity verification medium 200, but the identity verification medium 200 is not limited to this. The identity verification medium 200 may be, for example, a coin-shaped medium equipped with an IC chip that stores an electronic certificate issued to an individual in the public personal authentication service. The identity verification medium 200 may be, for example, a portable medium having a USB (Universal Serial Bus) interface.
[0114] As described above, this embodiment provides a display system, display method, and program that suitably display information for verifying user attributes.
[0115] <Second Embodiment> Next, a second embodiment will be described. Figure 11 is a block diagram of the user terminal 100 according to the second embodiment. The display system 110 according to the second embodiment differs from the display system 110 described above in that it has a selection reception unit 116.
[0116] The selection receiving unit 116 receives a selection from the user regarding the information to be displayed as certification information from among the related information 21 related to the user. That is, the selection receiving unit 116 presents to the user, in selectable form, multiple pieces of related information 21 that are linked to the service relating to the attribute the user wants to certify. The selection receiving unit 116 then receives the selection from the user. Once the selection receiving unit 116 receives the user's selection, it supplies the content of the received selection to the certification information acquisition unit 112.
[0117] In this embodiment, the certification information acquisition unit 112 receives the content selected by the selection reception unit 116. The certification information acquisition unit 112 acquires the information selected by the user from the information management device 20.
[0118] Figure 12 is a flowchart of the display method according to the second embodiment. The flowchart shown in Figure 12 differs from the flowchart shown in Figure 8 in that it has a step S112 between step S110 and step S120.
[0119] In step S110 of this implementation, the display system 110 determines whether the user terminal 100 has already acquired image data. If it is determined that the user terminal 100 has not already acquired image data (step S110: NO), the display system 110 proceeds to step S111. If it is determined that the user terminal 100 has already acquired image data (step S110: YES), the display system 110 proceeds to step S112.
[0120] In step S112, the selection receiving unit 116 accepts the selection of information to be displayed as certification information. That is, the selection receiving unit 116 accepts from the user the selection of information to be displayed as certification information. More specifically, the selection receiving unit 116 extracts selectable information from related information 21 and displays it on the display unit 122 in a manner that allows the user to select it. The selection receiving unit 116 supplies the received content to the certification information acquisition unit 112.
[0121] In step S120, the certification information acquisition unit 112 receives information regarding the selection of related information from the selection reception unit 116. The certification information acquisition unit 112 also acquires information for display as certification information from the information management device 20. The certification information acquisition unit 112 supplies the acquired related information 21 to the display control unit 115.
[0122] The second embodiment has been described above. The display system 110 according to this embodiment can flexibly display certification information by accepting user selections. In other words, the display system 110 can exclude items that the user does not wish to select from the certification information. Therefore, according to this embodiment, it is possible to provide a display system, display method, and program that flexibly and suitably display information for certifying user attributes.
[0123] <Third Embodiment> Next, a third embodiment will be described. Figure 13 is a block diagram of the user terminal 100 according to the third embodiment. The display system 110 according to this embodiment has a display information receiving unit 117 and an estimation unit 118 instead of a selection receiving unit 116.
[0124] The display information receiving unit 117 receives information regarding the content to be displayed as certification information. More specifically, for example, the display information receiving unit 117 receives information regarding the content to be displayed as certification information from applications provided by the platform operator, first applications provided by first operators, etc. The display information receiving unit 117 supplies the received information to the estimation unit 118.
[0125] The estimation unit 118 estimates the content to be displayed as proof information from the related information if the content to be displayed as proof information does not match the related information. For example, the estimation unit 118 receives items that need to be displayed as proof information via the super app, the first application, or the second application. The estimation unit 118 also determines whether the content to be displayed as proof information matches the related information. Furthermore, if the content to be displayed as proof information does not match the related information, the estimation unit 118 extracts information related to the content to be displayed as proof information from the information stored as related information.
[0126] To achieve the above functions, the estimation unit 118 may, for example, pre-store a database of languages that have meanings similar to the related information. The estimation unit 118 may extract related information that has languages with language vectors similar to the language vectors of the items to be displayed as proof information. Alternatively, the estimation unit 118 may input the content to be displayed as proof information and the related information into a large-scale language model that has been pre-trained on a large number of languages, and have it estimate the content of the proof information.
[0127] The certification information acquisition unit 112 according to this embodiment acquires the relevant information related to the above estimation from the information management device as certification information.
[0128] Next, the display method according to this embodiment will be described with reference to Figure 14. Figure 14 is a flowchart of the display method according to the third embodiment. The flowchart shown in Figure 14 differs from the flowchart shown in Figure 8 in the processing between step S110 and step S120.
[0129] In step S110 of this implementation, the display system 110 determines whether the user terminal 100 has already acquired image data. If it is determined that the user terminal 100 has not already acquired image data (step S110: NO), the display system 110 proceeds to step S111. If it is determined that the user terminal 100 has already acquired image data (step S110: YES), the display system 110 proceeds to step S113.
[0130] In step S113, the display information receiving unit 117 receives the content to be displayed as certification information. More specifically, for example, the display information receiving unit 117 receives information about the content to be displayed as certification information via a predetermined application. The display information receiving unit 117 supplies the received content to the estimation unit 118.
[0131] In step S114, the estimation unit 118 determines whether the content to be displayed as proof information matches the related information. If it determines that the content to be displayed as proof information matches the related information (step S114; YES), the display system 110 proceeds to step S120. If it does not determine that the content to be displayed as proof information matches the related information (step S114; NO), the display system 110 proceeds to step S115.
[0132] In step S115, the estimation unit 118 estimates the information to be displayed as proof information based on the related information 21. More specifically, the proof information acquisition unit 112 extracts related information that is highly relevant to the information about the content to be displayed as proof information, which has been received by the display information receiving unit 117. The estimation unit 118 then estimates the content to be displayed as proof information from the content to be displayed as proof information and the extracted related information, and supplies the estimation result to the proof information acquisition unit 112. Once the estimation unit 118 supplies the estimation result to the proof information acquisition unit 112, the display system 110 proceeds to step S120.
[0133] The third embodiment has been described above. In the display system 110 according to the third embodiment, even if the content to be displayed as certification information does not match the related information, the system preferably estimates the content to be displayed as certification information from the information included in the related information.
[0134] For example, suppose the related information contains the user's family structure, and it is necessary to display whether the user is "married" or "single" as proof information. In such a case, the estimation unit 118 estimates whether the user is married or single based on the family structure.
[0135] Alternatively, if the date of birth is stored in the related information, it may be necessary to display "age" as proof information. In such cases, the estimation unit 118 estimates the user's age from the date of birth and the current date.
[0136] Thus, the display system 110 can estimate and display the certification information even if the related information 21 does not contain information that perfectly matches the certification information. In other words, according to this embodiment, a display system, display method, and program can be provided that suitably select and display information for proving the user's attributes. The electronic certificate in the public personal authentication service may be installed on a smartphone. By installing the electronic certificate on a smartphone, the display system 110 can use the public personal authentication service even without an identity verification medium 200. In this case, the display system 110 can acquire image data using the electronic certificate installed on the smartphone.
[0137] The program described above includes, when loaded into a computer, a set of instructions (or software code) for causing the computer to perform one or more of the functions described in the embodiments. The program may be stored in a non-temporary computer-readable medium or a physical storage medium. Examples, but not limited to, include RAM, ROM, flash memory, SSD or other memory technologies, CD-ROM, DVD (digital versatile disc), Blu-ray disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may be transmitted over a temporary computer-readable medium or a communication medium. Examples, but not limited to, include, a temporary computer-readable medium or a communication medium that includes an electrical, optical, acoustic or other form of propagating signal.
[0138] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the configuration and details of the present disclosure can be made that will be understood by those skilled in the art within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate. In step S110 of the flowcharts shown in Figures 8, 12, and 14, the process is shown in which the display system 110 acquires certification information when the acquisition of image data is successful. However, the display system 110 may acquire the certification information from the information management device 20 before acquiring the image data. Furthermore, the order in which the user information acquisition unit 111 acquires image data and user information, the certification information acquisition unit 112 acquires certification information, the provider information acquisition unit 113 acquires provider information, and the certification image generation unit 114 generates a certification image is not limited to the above.
[0139] Each drawing is merely illustrative to illustrate one or more embodiments. Each drawing may be associated with one or more other embodiments rather than with only one specific embodiment. As those skilled in the art will understand, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings, for example, to create embodiments not explicitly shown or described. Not all features or steps shown in any one drawing to illustrate an exemplary embodiment are necessarily required, and some features or steps may be omitted. The order of steps shown in any of the drawings may be changed as appropriate. [Explanation of Symbols]
[0140] 1. Proof System 10 Authentication System 11 Communications Department 12. Authentication Department 13 Information acquisition department 14 Storage section 20 Information management device 21 Related Information 30 Certificate Verification System 40. First Business Management System 50 Second Business Management System 100 user terminals 110 Display System 111 User Information Acquisition Unit 112 Certification Information Acquisition Department 113 Provider information acquisition department 114 Proof Image Generation Unit 115 Display Control Unit 116 Selection Reception Section 117 Display Information Reception Section 118 Estimation Department 121 Communications Department 122 Display section 123 Input Reception Section 125 Login Section 140 Onboarding Start Function Unit 150 displayed images 151 Background 160 virtual card space 161 Provider information 162 Proof Information 170 Face Photos 180 Proof Images 181 Time display 182 Videos 183 QR code 200 Identity verification medium 1000 computers 1010 Bus 1020 Processor 1030 memory 1040 Storage Devices 1050 Input / Output Interface 1060 Network Interfaces N1 Network
Claims
1. A display system that displays authentication information on the user's terminal for the user to prove their own attributes, A user information acquisition unit acquires image data of the user's face, which has been publicly guaranteed by an organization related to the national or local government, and links it with the user information of the user, which has been certified by a certification authority for a public personal authentication service. A certification information acquisition unit that acquires information for display as the aforementioned certification information from an information management device that manages related information related to the user, A provider information acquisition unit that acquires provider information regarding the provider of the aforementioned certification information from the information management device, A proof image generation unit generates a proof image to prove that the image displayed on the user terminal is authentic, The system includes a display control unit that causes the aforementioned facial photograph, the aforementioned identification information, the aforementioned provider information, and the aforementioned identification image to be displayed on the display unit of the user terminal. Display system.
2. In the display system described in claim 1, The system further includes a selection receiving unit that receives from the user a selection of information to be displayed as the certification information from among the related information related to the user, The aforementioned certification information acquisition unit acquires the information selected by the user from the information management device. Display system.
3. In the display system described in claim 1, When the user displays the aforementioned authentication information relating to a service operated by a business operator that has access to the information management device on the user terminal, The certification information acquisition unit acquires information set by the business operator from the information management device as information to be displayed as certification information. Display system.
4. In the display system described in claim 1, The user information acquisition unit acquires at least a portion of personal information as user information, which can be obtained by performing authentication using a digital signature certificate usable for the public personal authentication service or by using a ticket information input assistance application or a ticket information verification application. Display system.
5. In the display system described in claim 1, The display control unit causes the display unit to display the face photograph of the user, which is an alternative image data corresponding to the face photograph of the user obtained in association with the user information. Display system.
6. In the display system described in claim 5, The user information acquisition unit acquires the user information from the identity verification medium by an authentication procedure performed via short-range wireless communication between the tangible identity verification medium and the user terminal. The image data is obtained from the identity-verifiable medium through the authentication procedure performed via the aforementioned short-range wireless communication. Display system.
7. In the display system described in claim 6, The user information acquisition unit, as part of the authentication procedure, acquires the image data from the identity verification medium within the period of the reading process if the authentication procedure is successful through a single reading process performed when the identity verification medium and the user terminal come close together once. Display system.
8. In the display system described in claim 7, As a result of the reading process, the user terminal supplies the first authentication information and the second authentication information to the identity verification medium, and when the identity verification medium authenticates the first authentication information and the second authentication information, The user information acquisition unit acquires the user information and the image data from the identity verification medium within the period of the reading process. Display system.
9. In the display system described in claim 1, The system includes an estimation unit that estimates the content to be displayed as proof information from the related information if the content to be displayed as proof information does not match the related information. The certification information acquisition unit acquires the related information corresponding to the estimation from the information management device as the certification information. Display system.
10. In the display system according to any one of claims 1 to 8, The aforementioned certification image generation unit generates characters, colors, or images that change according to the time as the certification image at predetermined intervals. The display control unit sequentially displays the updated certification image on the display unit. Display system.
11. In the display system according to claim 9, The aforementioned certification image generation unit generates a two-dimensional code, which is part of the certification image and changes according to time, so that a reader device that determines whether the certification information is genuine can read it. Display system.
12. In a display system that displays authentication information on a user terminal for a user to prove their own attributes, the computer, The image data of the user's face, publicly guaranteed by an organization related to the national or local government, is obtained in conjunction with the user information of the user, which has been authenticated by a certification authority for a public personal authentication service. The information to be displayed as the aforementioned certification information is obtained from an information management device that manages related information related to the user, Obtain source information regarding the source of the aforementioned certification information, A proof image is generated to prove that the image displayed on the user terminal is authentic. The aforementioned facial photograph, the aforementioned identification information, the aforementioned provider information, and the aforementioned identification image are displayed on the display unit of the user terminal. Display method.
13. In a display system that displays authentication information on the user's terminal for the user to prove their own attributes, A user information acquisition step involves acquiring image data of the user's face, which has been publicly guaranteed by an organization related to the national or local government, and linking it with the user information of the user, which has been authenticated by a certification authority for a public personal authentication service. A certification information acquisition step involves obtaining information for display as the aforementioned certification information from an information management device that manages related information related to the user, A provider information acquisition step to obtain provider information regarding the provider of the aforementioned certification information, A proof image generation step of generating a proof image to prove that the image displayed on the user terminal is authentic, The system includes a display control step that causes the user terminal's display unit to display the aforementioned facial photograph, the aforementioned identification information, the aforementioned provider information, and the aforementioned identification image. The computer will execute the display method. program.
Citation Information
Patent Citations
Information processing system and information processing program
JP7478404B1