Credential adjustment system and credential adjustment method
Patent Information
- Application Number
- JP2025036565
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2026-09-17
AI Technical Summary
【0011】 本発明によれば、クレデンシャルの保有者(Holder)に対してクレデンシャルを要求するために行うリクエストのフォーマットを属性情報の検証者(Verifier)が容易に作成することができる。
Smart Images

Figure 2026148163000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to technology for credential adjustment. [Background Art]
[0002] VC (Verifiable Credentials) and mDoc (Mobile Documents), which are digital certificates storing a user's own attribute information, have been widely spread mainly in Europe and North America. There are many types of VC and mDoc covering driver's licenses, qualification information, academic degrees, etc., and their holders store each of them in an application called a Wallet. Protocols and methods for the exchange of these VC and mDoc have been published as specifications by W3C and other organizations.
[0003] In relation to such background, technologies according to the following Patent Documents 1 to 3 are known, for example. [Prior Art Documents] [Patent Documents]
[0004] [Patent Document 1] Japanese Unexamined Patent Application Publication No. 2003-015277 [Patent Document 2] Japanese Unexamined Patent Application Publication No. 2021-140299 [Patent Document 3] International Publication No. WO 2023 / 026343 Specification [Summary of the Invention] [Problem to be Solved by the Invention]
[0005] Patent Document 1 describes a technology for calculating relevance from free text descriptions and analyzing opinions. However, with the technology described in Patent Document 1, it is difficult to request a credential to be presented in order to request VC (Verifiable Credentials) or mDoc (Mobile Documents) from a holder.
[0006] Furthermore, Patent Document 2 describes a technology for ensuring the confidentiality of personal information in matching using user information. However, the technology described in Patent Document 2 cannot create requests that meet the requirements of the verifier, and therefore, similar to the technology described in Patent Document 1, it is difficult to request the credentials to be presented in order to request VC (Verifiable Credentials) or mDoc (Mobile Documents) from the holder.
[0007] Furthermore, Patent Document 3 describes a technology that prevents identification of the same user when verifying credentials multiple times by the same user, thereby maintaining unlinkability. However, in the technology described in Patent Document 3, since the verifier server itself determines the credential request, it is difficult for the verifier to determine the appropriate one from among a wide variety of verifiable credentials (VCs) and mobile documents (mDocs) in order to authorize the holder.
[0008] Furthermore, in the technology described in Patent Document 3, since the verifier server itself requests / creates the credential request, it is difficult to request the credentials to be presented in order to request a wide variety of VCs (Verifiable Credentials) from the Holder.
[0009] This invention has been made in view of the above problems, and aims to provide a technology that allows an attribute information verifier to easily create a request format for requesting credentials from a credential holder. [Means for solving the problem]
[0010] The credential adjustment system according to the present invention is a system for adjusting credentials, comprising at least a computer which includes a processor and a memory device and is connected to a terminal used by the holder of the credentials and a terminal used by the verifier of the attribute information, respectively, so as to be able to communicate data with each other. The processor presents candidate attribute information necessary for authorization to the verifier's terminal based on the request content presented by the verifier's terminal, and creates a request format for the verifier's terminal to request the credentials from the holder's terminal and presents it to the verifier's terminal. [Effects of the Invention]
[0011] According to the present invention, an attribute information verifier can easily create a request format for requesting credentials from a credential holder.
[0012] Further details regarding the problems disclosed in this application, and their solutions, will be made clear in the section on embodiments for carrying out the invention and in the drawings. [Brief explanation of the drawing]
[0013] [Figure 1] This figure shows an example of the overall system configuration, including the credential adjustment system. [Figure 2] This figure shows an example of the hardware configuration of a credential adjustment system. [Figure 3] This figure shows an example of a functional block of a credential adjustment system. [Figure 4] This figure shows an example of a functional block in Issuer. [Figure 5] This figure shows an example of a functional block for the Holder. [Figure 6] This diagram shows an example of a Verifier functional block. [Figure 7]FIG. 1 is a diagram schematically showing the flow of various data processing executed by a credential adjustment system. [Figure 8] FIG. 2 is a diagram showing an example of registration information in a credential search database (DB). [Figure 9] FIG. 3 is a diagram showing an example of registration information in a credential format database (DB). [Figure 10] FIG. 4 is a diagram schematically showing the flow of processing executed by the credential adjustment system in attribute information candidate presentation processing. [Figure 11] FIG. 5 is a diagram showing an example of a GUI display screen in attribute information candidate presentation processing. [Figure 12] FIG. 6 is a sequence diagram showing an example of the flow of credential registration processing when an Issuer registers credentials by itself. [Figure 13] FIG. 7 is a sequence diagram showing an example of the flow of credential registration processing when credential information is created by the credential adjustment system. [Figure 14] FIG. 8 is a sequence diagram showing an example of the flow of attribute information candidate presentation processing and attribute confirmation processing when there is a credential that satisfies a request. [Figure 15] FIG. 9 is a diagram showing an example of a GUI display screen in attribute information confirmation processing. [Figure 16] FIG. 10 is a diagram showing an example of a GUI display screen in attribute information confirmation processing. [Figure 17] FIG. 11 is a diagram showing an example of a GUI display screen in attribute information confirmation processing. [Figure 18] FIG. 12 is a diagram showing an example of a GUI display screen in attribute information confirmation processing. [Figure 19] FIG. 13 is a diagram showing an example of a GUI display screen in attribute information confirmation processing. [Figure 20] FIG. 14 is a sequence diagram showing an example of the flow of attribute information candidate presentation processing when there is no credential that satisfies a request. [Figure 21] FIG. 15 is a sequence diagram showing an example of the flow of Presentation Definition creation processing. [Figure 22]This figure shows an example of attribute information that has undergone conditional processing through attribute information verification. [Figure 23] This figure shows an example of a Presentation Definition created by a credential adjustment system. [Modes for carrying out the invention]
[0014] Embodiments of the present invention will be described in detail below with reference to the drawings. However, the present invention is not limited to the embodiments and modifications described below. Examples of modifications to the specific configuration are also included, as long as they do not depart from the idea or spirit of the present invention. For example, each of the embodiments below is a detailed explanation of the present invention and is not necessarily limited to those that include all the configurations described.
[0015] In the configuration of the invention described below, the same reference numerals are used in common across different drawings for identical parts and / or elements, or parts and / or elements having similar functions, and redundant descriptions may be omitted.
[0016] Furthermore, when there are multiple identical parts and / or elements, or parts and / or elements with similar functions, different subscripts may be assigned to the same symbol in order to distinguish between them. On the other hand, when there is no need to distinguish between such multiple parts and / or elements, the subscripts may be omitted in the explanation.
[0017] Furthermore, the designations such as "First," "Second," and "Third" used in this specification are for identifying constituent elements and do not necessarily limit their number, order, or content. These letters and numbers used to identify constituent elements are used on a context-by-context basis, and the letters and numbers used in one context do not necessarily indicate the same configuration in another. Moreover, a constituent element identified by one letter or number does not prevent it from also functioning as a constituent element identified by another letter or number.
[0018] In other words, in this specification, elements expressed in the singular form include the plural form unless otherwise clearly indicated in the context.
[0019] Furthermore, in the following explanation, "interface device" may refer to one or more interface devices. These one or more interface devices may be at least one of the following: • One or more input / output interface devices. The input / output interface device is an interface device to at least one of the following: an I / O (Input / Output) device and a remote display computer. The input / output interface device to the display computer may be a communication interface device. The at least one I / O device may be either a user interface device, such as an input interface device like a keyboard and a pointing device, or an output interface device like a display device. • One or more communication interface devices. These one or more communication interface devices may be one or more identical communication interface devices (e.g., one or more NICs (Network Interface Cards)) or two or more different communication interface devices (e.g., a NIC and an HBA (Host Bus Adapter)). The network that the communication interface device accesses for communication may be, but is not limited to, the Internet, a LAN (Local Area Network), a WAN (Wide Area Network), or a mobile phone network.
[0020] Furthermore, in the following description, "storage device" includes at least one memory device (hereinafter also referred to as "memory") as main memory. This memory may be a volatile memory device (hereinafter also referred to as "volatile memory") or a non-volatile memory device (hereinafter also referred to as "non-volatile memory"). In addition, the storage device may include one or more PDEVs (Physical storage Devices) as auxiliary storage devices. These PDEVs are typically non-volatile storage devices (e.g., persistent storage devices), and specifically may be various storage devices (hereinafter also referred to as "storage") such as HDDs (Hard Disk Drives), SSDs (Solid State Drives), NVME (Non-Volatile Memory Express) drives, or SCMs (Storage Class Memory).
[0021] In other words, in the following explanation, "storage device" may refer to at least the memory of the main memory device and the storage device that serves as the secondary storage device.
[0022] Furthermore, in the following description, the term "processor," which is an arithmetic unit, refers to one or more processor devices. At least one processor device is typically a microprocessor device such as a CPU (Central Processing Unit), but may include other types of processor devices such as a GPU (Graphics Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). At least one processor device may be single-core or multi-core. At least one processor device may be a processor core. At least one processor device may be a broad-sense processor device such as a hardware circuit that performs some or all of the processing (e.g., an FPGA (Field Programmable Gate Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)), or may include such broad-sense processor devices.
[0023] Furthermore, in the following explanation, functions may be described using the expression "xxx section," but a function may be realized by the execution of one or more computer programs (hereinafter also simply referred to as "programs") by a processor, by one or more hardware circuits (e.g., FPGAs or ASICs), or by a combination thereof. When a function is realized by the execution of a program by a processor, the defined processing is carried out using memory devices and / or interface devices as appropriate, so the function may be at least a part of the processor. Processing described with a function as the subject may also be processing performed by the processor (or a device such as a controller having that processor). Programs may be installed from program source. Program source may be, for example, a program distribution computer or a computer-readable recording medium (e.g., a non-temporary recording medium). The description of each function is an example, and multiple functions may be combined into one function, or one function may be divided into multiple functions.
[0024] Furthermore, in the following explanation, the subject of the process may be "program," but since a program is executed by a processor and performs defined processes using memory and / or interface devices as appropriate, the subject of the process may also be the processor (or a device such as a controller having that processor). A program may be installed from a program source into a device such as a computer. The program source may be, for example, a program distribution server or a computer-readable (e.g., non-temporary) recording medium. Also, in the following explanation, two or more programs may be implemented as one program, or one program may be implemented as two or more programs.
[0025] Furthermore, in the following explanation, we may use expressions such as "yyy database" and "yyy table" to describe information from which an output is obtained for a given input. This information may be represented by data of any structure (for example, it may be structured data or unstructured data), or by a learning model such as a neural network, genetic algorithm, or random forest that generates an output from an input. Therefore, "yyy database" and "yyy table" can be rephrased as "yyy information." Also, in the following explanation, the configuration of each database and table is just an example; one database or table may be divided into two or more databases or tables, or all or part of two or more databases or tables may be one database or table.
[0026] Furthermore, in the following explanation, "dataset" means data consisting of one or more data elements (a logical block of electronic data), which may be, for example, a record, a file, a key-value pair, or a tuple.
[0027] Furthermore, in the following description, the "credential adjustment system" may be a device consisting of one or more physical computers (e.g., an on-premise device) or a system implemented on a group of physical computing resources (e.g., a cloud infrastructure) (e.g., a cloud computing system). The credential adjustment system "displaying" display information may mean displaying the information on a display device owned by the computer (credential adjustment system), or it may mean the computer (credential adjustment system) transmits the display information to a display computer (e.g., a user terminal) (in the latter case, the display information is displayed by the display computer).
[0028] <Example System Configuration> First, an example of the configuration of the overall system 1, including the credential adjustment system 100 according to this embodiment, will be explained using Figures 1 to 6.
[0029] Figure 1 shows an example of the configuration of the overall system 1, including the credential adjustment system 100.
[0030] (Example of the overall system configuration) The credential matching system 100 according to this embodiment is, in general terms, a computer system that can reduce the burden on the verifier during credential matching by presenting candidate attribute information necessary for authorization to the verifier based on the request content presented by the verifier of attribute information, and by creating and presenting to the verifier a request format that the attribute information verifier makes to request the credentials (digital certificate) from the holder. To this end, the credential matching system 100 is a computer system capable of creating a Presentation Definition (hereinafter also referred to as "PD") after analyzing the request content, and is implemented by at least one computer and / or server having (each of) the configurations described below. That is, the credential matching system 100 is a general-purpose computer system that is configured on a single physical computer or on multiple logically or physically configured computers, and may operate in separate threads on the same computer, or may operate on a virtual computer built on multiple physical computer resources. In this embodiment, the credential adjustment system 100 is described as consisting of a single computer, but the credential adjustment system 100 may consist of, for example, multiple computers and / or servers.
[0031] As shown in Figure 1, various devices and terminals such as terminals used by issuers (hereinafter also referred to as "Issuer 400"), terminals used by holders of credentials (hereinafter also referred to as "Holder 500"), terminals used by attribute information verifiers (hereinafter also referred to as "Verifier 600"), data servers storing the credential search database (hereinafter also referred to as "Credential Search DB") 700 and the credential format database (hereinafter also referred to as "Credential Format DB") 800, and a request content analysis system 900, a computer system that determines appropriate credentials from the request content and data search results, are connected to this credential adjustment system 100 as external devices, via an appropriate communication network (hereinafter simply referred to as "Network") 50, such as the Internet or a dedicated line, enabling data communication between them.
[0032] As shown in Figure 1, the credential adjustment system 100 and various external devices such as Issuer 400, Holder 500, Verifier 600, a data server storing the credential search database 700 and the credential format database 800, and a request content analysis system 900 are interconnected via the network 50 to enable data communication, thereby constituting the overall system 1.
[0033] Furthermore, various user terminals (not shown), such as laptop PCs, tablets, and smartphones owned by users such as the administrator of the credential adjustment system 100 or the system administrator of the overall system 1 including the credential adjustment system 100, are connected to the credential adjustment system 100 as external devices via the network 50, each including an input device (not shown) and a display device (not shown), enabling data communication between them. Of these, the input device is a type of input interface device that accepts input operations from the user, such as a keyboard, pointing device, or touch panel. The display device is a type of output interface device that outputs processing results to the user in a format that is visually apparent, such as a liquid crystal display or touch screen. In this embodiment, the input device and the display device are described as being operated integrally within the same user terminal, each handling input and output functions respectively. However, the input device and the display device may be implemented as separate terminals, for example. For example, each user terminal and the network 50 are connected wirelessly by Wi-Fi®, LTE®, 4G, 5G, etc., but they may also be connected by wire. Each user of the credential adjustment system 100 that possesses a user terminal is assigned a unique ID called a user ID in advance.
[0034] Furthermore, other devices, equipment, terminals, etc., may be connected to the credential adjustment system 100 as external devices via the network 50, enabling data communication. In this case, the external devices and the network 50 may be connected by wire via well-known communication equipment (not shown) or by wireless connection. In this case, the credential adjustment system 100 may also acquire various data from such external devices, for example, for use in the processes described later.
[0035] In this embodiment, the credential adjustment system 100 was described as consisting of a single computer. However, for example, the credential adjustment system 100 may consist of multiple computers.
[0036] Furthermore, in this embodiment, the credential adjustment system 100 and various external devices such as the Issuer 400, Holder 500, Verifier 600, data server storing the credential search database 700 and credential format database 800, request content analysis system 900, and user terminals have been described as being composed of separate devices. However, the credential adjustment system 100 and these external devices may, for example, be composed of the same device. In this case, the credential adjustment system may be configured as a system including these external devices. Alternatively, for example, the credential adjustment system may be configured to include some or all of the functions performed by these external devices.
[0037] (Example hardware configuration of credential adjustment system 100) Next, an example of the hardware configuration of the credential adjustment system 100 will be explained using Figure 2.
[0038] The credential adjustment system 100 according to this embodiment is implemented by a computer having at least a storage device including a memory 102 which is a main memory and a storage device 103 which is an auxiliary storage device, an interface device including at least a communication device 104, and a processor 101 which is an arithmetic unit connected thereto. In this credential adjustment system 100, the interface device may also include an input device 105 and / or an output device 106.
[0039] The following description assumes that the credential adjustment system 100 is implemented by a single general-purpose computer comprising one or more processors 101, one or more memories 102, one or more storage devices 103, one or more communication devices 104, one or more input devices 105, one or more output devices 106, and wired or wireless buses connecting them.
[0040] The auxiliary storage device, storage 103, is an auxiliary storage device consisting of a non-volatile memory element such as flash memory. Specific examples of this storage 103 include various storage devices such as SSDs (Solid State Drives) and HDDs (Hard Disk Drives). Storage 103 stores at least a credential adjustment program (not shown). This credential adjustment program is a computer program that implements the functions necessary for the credential adjustment system 100.
[0041] In other words, when the credential adjustment program is executed by the processor 101, the functions performed by each functional unit of the credential adjustment system 100, such as the request content acquisition unit 1111, data search unit 1112, request content processing unit 1113, attribute information confirmation unit 1114, condition processing unit 1115, Presentation Definition creation unit 1116, and Presentation Definition presentation unit 1117, which will be described later, are realized. To put it another way, when the credential adjustment program is executed by the processor 101, various processes described later in relation to Figures 7 to 23 are performed.
[0042] The credential adjustment program is provided to the credential adjustment system 100 via the network 50 and / or various removable media such as CD-ROMs and flash memory, and is stored in the storage 103, which is a non-temporary storage medium. Therefore, it is preferable that the credential adjustment system 100 has an interface for reading data from the removable media.
[0043] Furthermore, the credential adjustment program may be installed from the program source. The program source may be, for example, a program distribution computer or a computer-readable recording medium. The credential adjustment program may also consist of a device driver, an operating system, various application programs located at a higher layer, and libraries that provide common functions to these programs. Moreover, two or more programs may be implemented as one credential adjustment program, or one credential adjustment program may be implemented as two or more programs.
[0044] The main memory, memory 102, is a main memory device consisting mainly of volatile memory elements such as RAM (Random Access Memory). Memory 102 also includes ROM (Read Only Memory), which consists of non-volatile memory elements. ROM stores immutable programs (e.g., BIOS). Memory 102 temporarily holds data representing various information read from storage 103, as well as various data acquired via communication device 104 and / or input device 105.
[0045] The processor 101, which is the arithmetic unit, is a processor device such as a CPU (Central Processing Unit) and various coprocessors. This processor 101 controls the credential adjustment system 100 itself by calling and executing various computer programs, including the credential adjustment program, from the memory 102, and also controls the arithmetic unit 111 that performs various processing such as calculations, judgments, and control.
[0046] The interface device includes a communication device 104 that controls the communication unit 114 described later, an input device 105 that controls the input unit 115 described later, and an output device 106 that controls the output unit 116 described later.
[0047] The communication device 104 is a communication interface device that connects to the network 50 and controls communication with various external devices such as the aforementioned Issuer 400, Holder 500, Verifier 600, data server storing the credential search database 700 and credential format database 800, request content analysis system 900, and user terminals, according to a predetermined protocol.
[0048] The input device 105 is a variety of input interface devices for receiving input operations from the user of the credential adjustment system 100, such as a touch panel, keyboard, mouse, or controller.
[0049] The output device 106 is a variety of output interface devices for outputting the processing results of the credential adjustment program in a recognizable format to the user of the credential adjustment system 100, including, for example, a display device such as a liquid crystal display or a touchscreen.
[0050] The credential adjustment system 100 may be implemented by a separate device or by an embedded device.
[0051] (Example of a functional block for the credential adjustment system 100) Next, an example of the various function blocks provided by the credential adjustment system 100 will be explained using Figure 3. Note that the blocks described below represent function units, not hardware units.
[0052] The credential adjustment system 100 is composed of functional blocks including an arithmetic unit 111 mainly implemented by the aforementioned processor 101, a main memory unit 112 implemented by the aforementioned memory 102, an auxiliary memory unit 113 implemented by the aforementioned storage 103, a communication unit 114 implemented by the aforementioned communication device 104, and a user interface unit including an input unit 115 implemented by the aforementioned input device 105 and an output unit 116 implemented by the aforementioned output device 106. In the following description, the main memory unit 112 and the auxiliary memory unit 113 may be collectively referred to as the memory unit (112, 113).
[0053] The arithmetic unit 111 performs various data processing based on the programs and data stored in the storage units (112, 113) and the data acquired by the communication unit 114. The arithmetic unit 111 also functions as an interface to the storage units (112, 113) and the communication unit 114.
[0054] The calculation unit 111 has at least the following functional blocks, which are a request content acquisition unit 1111, a data search unit 1112, a request content processing unit 1113, an attribute information confirmation unit 1114, a condition processing unit 1115, a Presentation Definition creation unit 1116, and a Presentation Definition presentation unit 1117, as the processor 101 executes the aforementioned credential adjustment program.
[0055] The request content acquisition unit 1111 performs at least the process of acquiring the request content from the Verifier 600 (details will be described later in relation to Figure 14).
[0056] The data retrieval unit 1112 performs at least the process of retrieving data to determine the necessary attribute information according to the request (details will be described later in relation to Figure 14).
[0057] The request processing unit 1113 performs a process to request the necessary attribute information from the request analysis system 900 using the request content and data search results (details will be described later in relation to Figure 14).
[0058] The attribute information verification unit 1114 performs at least the process of verifying the presented attribute information with the Verifier 600 (details will be described later in relation to Figure 14).
[0059] The condition processing unit 1115 performs processing on the results of the verification process to the Verifier 600 performed by the attribute information verification unit 1114 (details will be described later in relation to Figure 14).
[0060] The Presentation Definition creation unit 1116 performs at least the process of creating a Presentation Definition from the confirmed information (details will be described later in relation to Figure 21).
[0061] The Presentation Definition display unit 1117 performs at least the process of presenting the Presentation Definition to the Verifier 600 (details will be described later in relation to Figure 21).
[0062] Furthermore, the arithmetic unit 111 may also have a use case acquisition unit 1118, a rulebook acquisition unit 1119, a credential format acquisition unit 1120, a credential search database registration unit 1121, and a credential format database registration unit 1122 as functional blocks, as the processor 101 executes the aforementioned credential adjustment program.
[0063] The use case acquisition unit 1118 performs at least the processing related to acquiring use cases (details will be described later in relation to Figure 13).
[0064] The rulebook acquisition unit 1119 performs at least the processing related to acquiring the rulebook (details will be described later in relation to Figure 13).
[0065] The credential format acquisition unit 1120 performs at least the process of acquiring the format of the credentials (details will be described later in relation to Figure 13).
[0066] The credential search database registration unit 1121 performs at least the registration process to the credential search database 700 (details will be described later in relation to Figure 13).
[0067] The credential format database registration unit 1122 performs at least the registration process to the credential format database 800 (details will be described later in relation to Figure 13).
[0068] The arithmetic unit 111 is configured using a processor 101, which is an arithmetic device, and these functional blocks can be realized by executing the aforementioned credential adjustment program. Alternatively, the arithmetic unit 111 may be configured using logic circuits such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit) instead of the processor 101. Furthermore, the arithmetic unit 111 may be configured using a combination of the processor 101 and logic circuits.
[0069] As described above, the storage unit (112, 113) is composed of a main storage unit 112, which is realized by the main memory 102, and an auxiliary storage unit 113, which is realized by the auxiliary storage 103. It stores programs that supply various processing instructions to the arithmetic unit 111, and data representing various information used in the processing executed by the arithmetic unit 111.
[0070] The arithmetic unit 111 can perform various processes described later by reading and writing data representing this information to the storage units (112, 113).
[0071] The communications unit 114 is responsible for communication processing with various external devices such as Issuer 400, Holder 500, Verifier 600, a data server storing the credential search database 700 and credential format database 800, a request content analysis system 900, and user terminals, which are conducted via the internet (an example of network 50). The communications unit 114 is configured using, for example, a NIC (Network Interface Card) and an HBA (Host Bus Adapter).
[0072] The user interface section (not shown) is composed of the functional blocks of the input section 115 and the output section 116.
[0073] The input unit 115 is responsible for processing related to the user interface, such as receiving input operations from the user. The input unit 115 is configured using various input devices 105, such as a touch panel, keyboard, mouse, or controller, and detects various operations performed by the user.
[0074] The output unit 116 is responsible for output-related processing, such as displaying various screens and outputting audio, as part of the user interface processing. The output unit 116 is configured using various output devices 106, including, for example, display devices such as touchscreens and liquid crystal displays.
[0075] Furthermore, the inclusion of the input unit 115 and / or output unit 116 is not mandatory when, for example, a user remotely logs into the credential adjustment system 100 from another external device such as a tablet, smartphone, or laptop PC, or when the system receives input information from an external device or provides output information to an external device via the communication device 104. In this case, the credential adjustment system 100 may have web server functionality to accept access from an external device using a predetermined protocol.
[0076] In other words, each component of the credential adjustment system 100 is realized through the cooperation of hardware, including a processor 101 which is an arithmetic unit, storage devices such as memory 102 which is a main memory and storage 103 which is an auxiliary storage device, interface devices such as a communication device 104, an input device 105, and an output device 106, and wired or wireless buses which connect them, and software stored in the storage devices (102, 103) that supplies processing instructions to the arithmetic unit (processor 101).
[0077] The above description of the functions of the credential adjustment system 100 is based on the assumption that each function of the credential adjustment system 100 is implemented integrally by a single computer. However, these functions may be implemented by multiple interconnected computers and / or servers. Furthermore, the credential adjustment system 100 may include a general-purpose computer such as a laptop PC and various portable devices.
[0078] In other words, in the credential adjustment system 100, each functional unit, such as the request content acquisition unit 1111, the data search unit 1112, the request content processing unit 1113, the attribute information confirmation unit 1114, the condition processing unit 1115, the Presentation Definition creation unit 1116, and the Presentation Definition presentation unit 1117, may operate on separate physical or logical computers, or multiple units may be combined and operate on a single physical or logical computer.
[0079] Furthermore, the above descriptions of each function are merely examples, and multiple functions may be combined into one function, or one function may be divided into multiple functions.
[0080] Furthermore, the credential adjustment system 100 may have additional functions in addition to those described above. For example, the credential adjustment system 100 may be configured to include some or all of the various functions of various external devices such as the Issuer 400, Holder 500, Verifier 600, a data server storing the credential search database 700 and the credential format database 800, a request content analysis system 900, and a user terminal.
[0081] (Example of hardware configuration for external devices) Furthermore, among the various external devices that are connected to the credential adjustment system 100 via the network 50 and communicate with each other, the hardware configuration of at least the aforementioned Issuer 400, Holder 500, Verifier 600, data server storing the credential search database 700 and credential format database 800, request content analysis system 900, and user terminals is generally the same as the hardware configuration of the credential adjustment system 100 illustrated in Figure 2.
[0082] In other words, in this embodiment, each device such as Issuer400, Holder500, Verifier600, data server storing credential search database 700 and credential format database 800, request content analysis system 900, and user terminal is implemented by a computer having at least a storage device including memory and storage, an interface device including at least a communication device, and a processor connected thereto, similar to the hardware configuration of the credential adjustment system 100 illustrated in Figure 2. Furthermore, in these external devices, the interface device may include an input device and / or an output device.
[0083] The following explanation assumes that the aforementioned Issuer400, Holder500, Verifier600, data server storing the credential search database 700 and credential format database 800, request content analysis system 900, user terminals, and other various external devices are all implemented by a single general-purpose computer equipped with one or more processors, one or more memories, one or more storage devices, one or more communication devices, one or more input devices (e.g., input devices for user terminals), one or more output devices (e.g., display devices for user terminals), and wired or wireless buses connecting them.
[0084] (Example of a functional block for an external device) Next, we will explain examples of the various functional blocks provided by these external devices (400, 500, 600, 700, 800, and 900) using Figures 4 to 6. Note that the blocks described below represent functional blocks, not hardware-level configurations.
[0085] (Example of Issuer400 functional blocks) Figure 4 shows an example of the blocks of various functions provided by Issuer400.
[0086] In this embodiment, Issuer 400 is configured with various functional blocks, including an arithmetic unit 411 mainly implemented by a processor (not shown), a main memory unit 412 implemented by memory (not shown), an auxiliary memory unit 413 implemented by storage (not shown), a communication unit 414 implemented by a communication device (not shown), and a user interface unit including an input unit 415 implemented by an input device (not shown) and an output unit 416 implemented by an output device (not shown). In the following description, the main memory unit 412 and the auxiliary memory unit 413 may be collectively referred to as the memory unit (412, 413).
[0087] The arithmetic unit 411 performs various data processing based on programs and data stored in the storage units (412, 413) and / or data acquired by the communication unit 414. The arithmetic unit 411 also functions as an interface to the storage units (412, 413) and the communication unit 414.
[0088] The calculation unit 411 includes at least the following functional blocks: a use case registration unit 4111, a rulebook registration unit 4112, a credential format registration unit 4113, a credential issuance reception unit 4114, and a credential issuance unit 4115.
[0089] The use case registration unit 4111 performs at least the processing related to the registration of use cases (details will be described later in relation to Figure 12).
[0090] The rulebook registration unit 4112 performs at least the processing related to the registration of the rulebook (details will be described later in relation to Figure 12).
[0091] The credential format registration unit 4113 performs at least the processing related to the registration of the credential format (details will be described later in relation to Figure 12).
[0092] The credential issuance acceptance unit 4114 performs at least the processing related to the acceptance of credential issuance (details will be described later in relation to Figure 12).
[0093] The credential issuing unit 4115 performs at least the processing related to the issuance of credentials (details will be described later in relation to Figure 12).
[0094] The arithmetic unit 411 is configured using a processor, which is an arithmetic device, and these functional blocks can be realized by executing the corresponding programs. Alternatively, the arithmetic unit 411 may be configured using logic circuits such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit) instead of a processor. Furthermore, the arithmetic unit 411 may be configured using a combination of a processor and logic circuits.
[0095] As mentioned above, the memory unit (412, 413) is composed of a main memory unit 412, which is implemented by a main memory device, and an auxiliary memory unit 413, which is implemented by an auxiliary storage device. It stores programs that supply various processing instructions to the arithmetic unit 411, and data representing various information used in the processing executed by the arithmetic unit 411.
[0096] The arithmetic unit 411 can execute various processes described later by reading and writing these programs and data to the storage units (412, 413).
[0097] The communications unit 414 is responsible for processing communications with the credential adjustment system 100 and other various external devices via the internet (an example of network 50). The communications unit 414 is configured using, for example, a NIC (Network Interface Card) or an HBA (Host Bus Adapter).
[0098] The user interface section (not shown) is comprised of the functional blocks of the input section 415 and the output section 416.
[0099] The input unit 415 is responsible for processing related to the user interface, such as receiving input operations from the user. The input unit 415 is configured using various input devices such as a touch panel, keyboard, mouse, or controller, and detects various operations performed by the user.
[0100] The output unit 416 is responsible for output-related processing, such as displaying various screens and outputting audio, as part of the user interface processing. The output unit 416 is configured using various output devices, such as display devices like touchscreens and liquid crystal displays.
[0101] Furthermore, when remotely logging into Issuer400 from another device such as a tablet, smartphone, or laptop PC, or when receiving input information from another device or providing output information to another device via a communication device, the inclusion of the input unit 415 and / or output unit 416 is not mandatory. In this case, Issuer400 may accept access from the other device using a predetermined protocol by having web server functionality.
[0102] In other words, each component of Issuer400 is realized through the cooperation of hardware, including a processor (a calculation unit), storage devices such as main memory and auxiliary storage, interface devices such as communication devices, input devices, and output devices, and wired or wireless buses that connect them, and software stored in the storage devices that supplies processing instructions to the calculation unit (processor).
[0103] (Example of a functional block for Holder500) Figure 5 shows an example of the blocks of various functions provided by Holder500.
[0104] In this embodiment, the Holder 500 is configured with various functional blocks, including an arithmetic unit 511 mainly implemented by a processor (not shown), a main memory unit 512 implemented by memory (not shown), an auxiliary storage unit 513 implemented by storage (not shown), a communication unit 514 implemented by a communication device (not shown), and a user interface unit including an input unit 515 implemented by an input device (not shown) and an output unit 516 implemented by an output device (not shown). In the following description, the main memory unit 512 and the auxiliary storage unit 513 may be collectively referred to as the storage unit (512, 513).
[0105] The arithmetic unit 511 performs various data processing based on programs and data stored in the storage units (512, 513) and / or data acquired by the communication unit 514. The arithmetic unit 511 also functions as an interface to the storage units (512, 513) and the communication unit 514.
[0106] The calculation unit 511 includes at least the following functional blocks: a credential issuance request unit 5111, a credential reception unit 5112, a credential request reception unit 5113, a credential request determination unit 5114, a credential creation unit 5115, and a credential presentation unit 5116.
[0107] The credential issuance request unit 5111 performs at least the processing related to the request for the issuance of credentials (details below).
[0108] The credential reception unit 5112 performs at least the processing related to the reception of credentials (details below).
[0109] The credential request receiving unit 5113 performs at least the processing related to receiving credential requests (details will be described later in relation to Figures 20-21).
[0110] The credential request determination unit 5114 performs at least processing related to determining whether a credential is requested (details will be described later in relation to Figures 20-21).
[0111] The credential creation unit 5115 performs at least the processing related to the creation of credentials (details will be described later in relation to Figure 21).
[0112] The credential presentation unit 5116 performs at least the processing related to the presentation of credentials (details will be described later in relation to Figure 21).
[0113] Furthermore, the arithmetic unit 511 may also have an alternative credential presentation unit 5117 as a functional block.
[0114] The alternative credential presentation unit 5117 performs processing related to the presentation of alternative credentials, which represent alternative (alternative) credentials (details will be described later in relation to Figure 20).
[0115] The arithmetic unit 511 is configured using a processor, which is an arithmetic device, and these functional blocks can be realized by executing the corresponding programs. Alternatively, the arithmetic unit 511 may be configured using logic circuits such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit) instead of a processor. Furthermore, the arithmetic unit 511 may be configured using a combination of a processor and logic circuits.
[0116] As described above, the memory unit (512, 513) is composed of a main memory unit 512, which is implemented by a main memory device, and an auxiliary memory unit 513, which is implemented by an auxiliary storage device. It stores programs that supply various processing instructions to the arithmetic unit 511, and data representing various information used in the processing executed by the arithmetic unit 511.
[0117] Furthermore, the auxiliary storage unit 513 has at least a credential storage unit 5131 as a functional block.
[0118] The credential storage unit 5131 stores at least the credentials.
[0119] The arithmetic unit 511 can execute various processes described later by reading and writing these programs and data to the storage units (512, 513).
[0120] The communication unit 514 is responsible for processing communication with the credential adjustment system 100 and other various external devices via the internet (an example of network 50). The communication unit 514 is configured using, for example, a NIC (Network Interface Card) or an HBA (Host Bus Adapter).
[0121] The user interface section (not shown) is comprised of the functional blocks of the input section 515 and the output section 516.
[0122] The input unit 515 is responsible for processing related to user interface, such as receiving input operations from the user. The input unit 515 is configured using various input devices such as a touch panel, keyboard, mouse, or controller, and detects various operations performed by the user.
[0123] The output unit 516 is responsible for output-related processing, such as displaying various screens and outputting audio, as part of the user interface processing. The output unit 516 is configured using various output devices, such as display devices like touchscreens and liquid crystal displays.
[0124] Furthermore, the inclusion of the input unit 515 and / or output unit 516 is not mandatory when, for example, remotely logging into Holder 500 from another device such as a tablet, smartphone, or laptop PC, or when receiving input information from another device or providing output information to another device via a communication device. In this case, Holder 500 may accept access from the other device using a predetermined protocol by having web server functionality.
[0125] In other words, each component of Holder500 is realized through the cooperation of hardware, including a processor (a calculation unit), storage devices such as main memory and auxiliary storage, interface devices such as communication devices, input devices, and output devices, and wired or wireless buses that connect them, and software stored in the storage devices that supplies processing instructions to the calculation unit (processor).
[0126] (Example of Verifier600 functional blocks) Figure 6 shows an example of the blocks of various functions provided by the Verifier 600.
[0127] In this embodiment, the Verifier 600 is configured with various functional blocks, including an arithmetic unit 611 mainly implemented by a processor (not shown), a main memory unit 612 implemented by memory (not shown), an auxiliary memory unit 613 implemented by storage (not shown), a communication unit 614 implemented by a communication device (not shown), and a user interface unit including an input unit 615 implemented by an input device (not shown) and an output unit 616 implemented by an output device (not shown). In the following description, the main memory unit 612 and the auxiliary memory unit 613 may be collectively referred to as the memory unit (612, 613).
[0128] The arithmetic unit 611 performs various data processing based on programs and data stored in the storage units (612, 613) and / or data acquired by the communication unit 614. The arithmetic unit 611 also functions as an interface to the storage units (612, 613) and the communication unit 614.
[0129] The calculation unit 611 includes at least the following functional blocks: a request content creation unit 6111, a request content presentation unit 6112, an attribute information response unit 6113, a Presentation Definition acquisition unit 6114, a credential request unit 6115, and a credential acquisition unit 6116.
[0130] The request content creation unit 6111 performs at least the processing related to the creation of the request content (details will be described later in relation to Figure 14).
[0131] The request content presentation unit 6112 performs at least processing related to the presentation of the request content (details will be described later in relation to Figure 14).
[0132] The attribute information response unit 6113 performs at least processing related to the response of attribute information (details will be described later in relation to Figure 14).
[0133] The Presentation Definition acquisition unit 6114 performs at least the processing related to acquiring the Presentation Definition (details will be described later in relation to Figure 21).
[0134] The credential request unit 6115 performs at least the processing related to the credential request (details will be described later in relation to Figure 21).
[0135] The credential acquisition unit 6116 performs at least the processing related to acquiring credentials (details will be described later in relation to Figure 21).
[0136] Furthermore, the calculation unit 611 may also have an alternative credential acquisition unit 6117 as a functional block.
[0137] The alternate credential acquisition unit 6117 performs at least the processing related to acquiring alternate credentials (details will be described later in relation to the diagram).
[0138] The arithmetic unit 611 is configured using a processor, which is an arithmetic device, and these functional blocks can be realized by executing the corresponding programs. Alternatively, the arithmetic unit 611 may be configured using logic circuits such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit) instead of a processor. Furthermore, the arithmetic unit 611 may be configured using a combination of a processor and logic circuits.
[0139] As mentioned above, the storage unit (612, 613) is composed of a main storage unit 612, which is implemented by a main memory device, and an auxiliary storage unit 613, which is implemented by an auxiliary storage device. It stores programs that supply various processing instructions to the arithmetic unit 611, and data representing various information used in the processing executed by the arithmetic unit 611.
[0140] The arithmetic unit 611 can execute various processes described later by reading and writing these programs and data to the storage units (612, 613).
[0141] The communication unit 614 is responsible for processing communication with the credential adjustment system 100 and other various external devices via the internet (an example of network 50). The communication unit 614 is configured using, for example, a NIC (Network Interface Card) or an HBA (Host Bus Adapter).
[0142] The user interface section (not shown) is comprised of the functional blocks of the input section 615 and the output section 616.
[0143] The input unit 615 is responsible for processing related to the user interface, such as receiving input operations from the user. The input unit 615 is configured using various input devices such as a touch panel, keyboard, mouse, or controller, and detects various operations performed by the user.
[0144] The output unit 616 is responsible for output-related processing, such as displaying various screens and outputting audio, as part of the user interface processing. The output unit 616 is configured using various output devices, such as display devices like touchscreens and liquid crystal displays.
[0145] Furthermore, the inclusion of the input unit 615 and / or output unit 616 is not mandatory when, for example, remotely logging into the Verifier 600 from another device such as a tablet, smartphone, or laptop PC, or when receiving input information from another device or providing output information to another device via a communication device. In this case, the Verifier 600 may have web server functionality to accept access from the other device using a predetermined protocol.
[0146] In other words, each component of the Verifier600 is realized through the cooperation of hardware, including a processor (a calculation unit), storage devices such as main memory and auxiliary storage, interface devices such as communication devices, input devices, and output devices, and wired or wireless buses that connect them, and software stored in the storage devices that supplies processing instructions to the calculation unit (processor).
[0147] (Examples of functional blocks for other external devices) In this embodiment, among the various external devices described above, the data server that stores the credential search database 700 and the credential format database 800, the request content analysis system 900, and the user terminal are each configured with a control unit, a storage unit, and a communication unit, and a user interface unit consisting of an input unit and an output unit.
[0148] The control unit performs various data processing operations based on the programs and data stored in the memory unit and / or data acquired by the communication unit. The control unit also functions as an interface between the memory unit and the communication unit.
[0149] The control unit is configured using a processor, which is a control device, and each functional block can be realized by executing the corresponding program. Alternatively, the control unit may be configured using logic circuits such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application Specific Integrated Circuits) instead of a processor. Furthermore, the control unit may be configured using a combination of a processor and logic circuits.
[0150] The storage unit is configured to include, for example, a main storage unit implemented by a primary memory device and an auxiliary storage unit implemented by an auxiliary storage device, and stores programs that supply various processing instructions to the control unit, and data representing various information used in the processing executed by the control unit.
[0151] The control unit can perform various processes by reading and writing these programs and data to the storage unit.
[0152] The communications unit is responsible for processing communications with the credential adjustment system 100 and other various external devices via the internet (an example of network 50). The communications unit is configured using, for example, a NIC (Network Interface Card) and an HBA (Host Bus Adapter).
[0153] The user interface section consists of input and output functional blocks.
[0154] The input unit is responsible for processing related to user interface input, such as receiving input operations from the user. The input unit is configured using various input devices (e.g., input devices of the user terminal), such as a touch panel, keyboard, mouse, or controller, and detects various operations performed by the user.
[0155] The output unit is responsible for processing related to the user interface, including output-related processing such as displaying various screens and outputting audio. The output unit is composed of various output devices, such as display devices (e.g., the display device of the user terminal) such as touch screens and liquid crystal displays.
[0156] Furthermore, when remotely logging in from another terminal such as a tablet, smartphone, or laptop PC to various external devices, such as a data server storing the credential search database 700 or the credential format database 800, or a request content analysis system 900, or when receiving input information from another terminal or providing output information to another terminal via a communication device, it is not essential to equip these external devices with input and / or output units. In this case, these external devices may accept access from the other terminal using a predetermined protocol by having web server functionality.
[0157] In other words, each component of external devices such as the data server that stores the aforementioned credential search database 700 and credential format database 800, the request content analysis system 900, and user terminals are realized through the cooperation of hardware including a processor (a computing unit), storage devices such as memory (a main memory unit) and storage devices (a secondary storage unit), interface devices such as communication devices, input devices (e.g., input devices of user terminals), and output devices (e.g., display devices of user terminals), and wired or wireless buses that connect them, and software stored in the storage devices that supplies processing instructions to the processor.
[0158] The above descriptions of the functions of external devices such as Issuer400, Holder500, Verifier600, the data server storing the credential search database 700 and credential format database 800, the request content analysis system 900, and user terminals were given assuming that each of these functions of external devices is implemented integrally by a single computer. However, each of these functions may be implemented by multiple interconnected computers and / or servers. Furthermore, these external devices may consist of a general-purpose computer such as a laptop PC and a web browser installed on it, or they may consist of various portable devices.
[0159] Furthermore, each functional component of these external devices may operate on a separate physical or logical computer, or multiple components may be combined and operate on a single physical or logical computer.
[0160] Furthermore, the above descriptions of each function are merely examples, and multiple functions may be combined into one function, or one function may be divided into multiple functions.
[0161] Furthermore, these external devices may have additional functions in addition to those described above.
[0162] <Example of system operation> Next, an example of the operation of the credential adjustment system 100 according to this embodiment will be explained using Figures 7 to 23.
[0163] (Example of overall system operation) Figure 7 is a schematic diagram illustrating the flow of various data processing operations performed by the credential adjustment system 100.
[0164] As illustrated in Figure 7 (and Figure 10), the credential matching system 100 according to this embodiment is a computer system that, in general terms, performs the following processes related to Figures 12-13 (hereinafter also referred to as the "credential registration process"), the following processes related to Figures 14 and 20 (hereinafter also referred to as the "attribute information candidate presentation process"), and the following processes related to Figure 21 (hereinafter also referred to as the "Presentation Definition creation process") to present attribute information necessary for authorization based on the service authorization requirements of the verifier (Verifier) holding the Verifier 600, and creates a request to the holder (Holder) holding the Holder 500 to request a digital certificate, thereby reducing the load on the verifier (Verifier) during credential matching.
[0165] The credential adjustment system 100 performs the above-described process using the information registered in the credential search database 700 illustrated in Figure 8 and the information registered in the credential format database 800 illustrated in Figure 9.
[0166] Furthermore, the processes mainly performed by the credential adjustment system 100 in the attribute information candidate presentation process described above are, as illustrated in Figure 10, the request content acquisition process by the request content acquisition unit 1111, the data search process against the credential search database 700 by the data search unit 1112, and the processing of the request content performed by the request content processing unit 1113 in cooperation with the request content analysis system 900. Of these, the process of acquiring the request content by the request content acquisition unit 1111 is performed by accepting user input operations on the GUI display screen illustrated in Figure 11.
[0167] (Credential registration process) Figures 12 and 13 are sequence diagrams illustrating the flow of the credential registration process. Of these, the sequence diagram shown in Figure 12 shows an example of the credential registration process flow that is executed when Issuer 400, which issued the credentials, registers the information of those credentials in the credential search database 700 or the credential format database 800 itself. On the other hand, the sequence diagram shown in Figure 13 shows an example of the credential registration process flow that is executed when the credential information is created in the credential adjustment system 100 from publicly available specifications.
[0168] (If Issuer400 registers it themselves) In the credential registration process illustrated in the sequence diagram of Figure 12, Issuer 400 registers the information of the credentials it has issued in the credential search database 700 and the credential format database 800.
[0169] In this case, the credential adjustment system 100 is not significantly involved in the credential registration process, and therefore is omitted from the sequence diagram shown in Figure 12.
[0170] In step S1201, the calculation unit 411 of Issuer 400 executes a process in which the use case registration unit 4111 indexes the use case information and registers it in the credential search database 700. As a result, the indexed use case information is registered in the credential search database 700. Once the processing in step S1201 is complete, the calculation unit 411 of Issuer 400 proceeds to step S1202.
[0171] In step S1202, the calculation unit 411 of Issuer 400 executes a process in which the rulebook registration unit 4112 indexes the rulebook information and registers it in the credential search database 700. As a result, the indexed rulebook information is registered in the credential search database 700. Once the processing in step S1202 is complete, the calculation unit 411 of Issuer 400 proceeds to step S1203.
[0172] In step S1203, the calculation unit 411 of Issuer 400 executes a process to register the credential format in the credential format database 800 using the credential format registration unit 4113. Specifically, this process is performed by registering the information to be described in the Presentation Definition for each credential, which represents the credential format, in the credential format database 800. As a result, the credential format is registered in the credential format database 800. Once the process in step S1203 is completed, the calculation unit 411 of Issuer 400 terminates the credential registration process shown in the sequence diagram of Figure 12.
[0173] (When created using the credential adjustment system 100) On the other hand, in the credential registration process illustrated in the sequence diagram of Figure 13, the credential information is created in the credential adjustment system 100 from publicly available specifications.
[0174] In step S1301, the calculation unit 111 of the credential adjustment system 100 executes a process to obtain use case information from the Issuer 400 database (hereinafter also referred to as the "Issuer database" or "Issuer DB") 1300 using the use case acquisition unit 1118. As a result, use case information is obtained from the Issuer database 1300. Once the processing in step S1301 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1302.
[0175] In step S1302, the calculation unit 111 of the credential adjustment system 100 executes a process to obtain rulebook information from the Issuer database 1300 using the rulebook acquisition unit 1119. As a result, the rulebook information is obtained from the Issuer database 1300. Once the processing in step S1302 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1303.
[0176] In step S1303, the calculation unit 111 of the credential adjustment system 100 uses the credential format acquisition unit 1120 to retrieve information to be included in the Presentation Definition for each credential from the Issuer database 1300. As a result, the information to be included in the Presentation Definition for each credential is retrieved from the Issuer database 1300. Once the processing in step S1303 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1304.
[0177] In step S1304, the calculation unit 111 of the credential adjustment system 100 performs a process to index the use case information obtained in step S1301 and the rulebook information obtained in step S1302, respectively, using the credential search database registration unit 1121, and register them in the credential search database 700. As a result, the indexed use case information and rulebook information are registered in the credential search database 700. Once the processing in step S1304 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1305.
[0178] In step S1305, the calculation unit 111 of the credential adjustment system 100 executes a process to register the credential format in the credential format database 800 using the credential format database registration unit 1122. Specifically, this process is performed by registering the information described in the Presentation Definition for each credential obtained in step S1303 as information representing the credential format in the credential format database 800. As a result, the credential format is registered in the credential format database 800. Once the process in step S1305 is completed, the calculation unit 111 of the credential adjustment system 100 terminates the credential registration process shown in the sequence diagram of Figure 13.
[0179] As described above, in the credential registration process illustrated in the sequence diagram of Figure 13, use case information and rulebook information are obtained from the Issuer database 1300 as specifications (steps S1301-S1302 in Figure 13), indexed by the credential adjustment system 100, and then registered in the credential search database 700 (step S1304 in Figure 13). In addition, information to be described in the Presentation Definition for each credential is also obtained from the Issuer database 1300 as specifications (step S1303 in Figure 13), and this is used to register the credential format in the credential format database 800 (step S1305 in Figure 13). By executing the credential registration process in this manner, the credential adjustment system 100 can reduce the workload of the Issuer 400.
[0180] (Attribute information candidate presentation process) Figures 14 and 20 are sequence diagrams illustrating the flow of attribute information candidate presentation processing. Figure 14 primarily shows an example of the attribute information candidate presentation processing flow, executed when credentials satisfying the request exist, along with an example of attribute verification processing. On the other hand, Figure 20 shows an example of the attribute information candidate presentation processing flow, executed when no credentials satisfying the request exist.
[0181] (If you have the necessary credentials) As described above, Figure 14 is a sequence diagram showing an example of the attribute information candidate presentation process (steps S1401 to S1405 in Figure 14) that is executed when credentials that meet the requirements exist, along with an example of the attribute verification process (steps S1406 to S1408 in Figure 14).
[0182] In step S1401, the calculation unit 611 of the Verifier 600 executes the process of creating the request content using the request content creation unit 6111. This creates the request content. Once the processing in step S1401 is complete, the calculation unit 611 of the Verifier 600 proceeds to step S1402.
[0183] In step S1402, the calculation unit 611 of the Verifier 600 executes a process to present the request content created in step S1401 to the credential adjustment system 100 using the request content presentation unit 6112. As a result, the request content is presented to the credential adjustment system 100.
[0184] In step S1403, the calculation unit 111 of the credential adjustment system 100 executes a process to acquire the request content presented by the Verifier 600 in step S1402 using the request content acquisition unit 1111. As a result, the request content is acquired from the Verifier 600. Once the processing in step S1403 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1404.
[0185] In step S1404, the calculation unit 111 of the credential adjustment system 100 performs a data search process on the data stored in the credential search database 700 in order to determine the necessary attribute information according to the request content obtained in step S1403, using the data search unit 1112. This obtains the result of the data search process. Once the processing in step S1404 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1405.
[0186] In step S1405, the calculation unit 111 of the credential adjustment system 100 executes a process to request the request content analysis system 900 to present the necessary attribute information, separated by attribute information, using the request content acquired in step S1403 and the data search results obtained in step S1404, via the request content processing unit 1113. The request content analysis system 900 may store a large-scale language model, which is a large-scale trained model that has been machine-learned using natural language data, and input the request content acquired in step S1403 and the data search results obtained in step S1404 as prompts to the large-scale language model, and perform a process to generate candidate attribute information according to the input content. When the large-scale language model is given a prompt written in natural language as input, it outputs information written in natural language (text, program code, etc.) that it has generated according to the prompt. The calculation unit of the request content analysis system 900, which has received a request from the credential adjustment system 100 for the necessary attribute information, executes a process to present the attribute information to the credential adjustment system 100. Requests for attribute information to the request content analysis system 900 are made, for example, based on the content of input operations received via the GUI display screens illustrated in Figures 15 to 19. Figure 15 shows an example of a GUI display screen when the attribute of the request to the request content analysis system 900, in other words, the attribute presented by the request content analysis system 900, is a personal attribute such as basic four information, a driver's license, or a passport. Similarly, Figure 16 shows an example of a GUI display screen when the target attribute of the request is an acquired degree, Figure 17 shows an example of a GUI display screen when the target attribute of the request is a private qualification, Figure 18 shows an example of a GUI display screen when the target attribute of the request is a national qualification, and Figure 19 shows an example of a GUI display screen when the target attribute of the request is a behavioral attribute such as motivation for applying, achievements during student years, or self-introduction. In the GUI display screens illustrated in Figures 15 to 19, after the necessary input operations are performed on the display screen shown on the left, the user presses the "OK" button, which transitions to the display screen shown on the right, where the user continues to perform the necessary input operations.In this way, the user inputs the necessary information. As a result, attribute information matching the content of the request is presented by the request content analysis system 900. When the processing in step S1405 is completed, the calculation unit 111 of the credential adjustment system 100 proceeds to step S1406.
[0187] In step S1406, the calculation unit 111 of the credential adjustment system 100 performs a process to confirm the content of the attribute information presented by the request content analysis system 900 in step S1405 with the Verifier 600, using the attribute information confirmation unit 1114. As a result, the content of the attribute information is confirmed by the Verifier 600.
[0188] In step S1407, the calculation unit 611 of the Verifier 600 performs a process to respond to the attribute information confirmed by the credential adjustment system 100 in step S1406, using the attribute information response unit 6113. As a result, a response regarding said attribute information is sent to the credential adjustment system 100.
[0189] In step S1408, the calculation unit 111 of the credential adjustment system 100 performs condition processing based on the content of the response made by the Verifier 600 in step S1407, using the condition processing unit 1115. This completes the condition processing. Once the processing in step S1408 is complete, the calculation unit 111 of the credential adjustment system 100 terminates the attribute information candidate presentation process shown in the sequence diagram of Figure 14.
[0190] (If you do not have the necessary credentials) On the other hand, if no credentials that meet the requirements exist, the attribute information candidate presentation process illustrated in the sequence diagram of Figure 20 can be executed.
[0191] In step S2001, the arithmetic unit 611 of the Verifier 600 executes a process to request credentials from the Holder 500 using the credential request unit 6115. As a result, credentials are requested from the Holder 500.
[0192] In step S2002, the calculation unit 511 of Holder 500 executes a process to receive the credential request from Verifier 600 that was made in step S2001, via the credential request receiving unit 5113. As a result, the credential request is received. Once the processing in step S2002 is complete, the calculation unit 511 of Holder 500 proceeds to step S2003.
[0193] In step S2003, the calculation unit 511 of Holder 500, using the credential request determination unit 5114, performs processing to determine whether there are any credentials that satisfy the credential request received from Verifier 600 in step S2002, and whether, if there are no credentials that satisfy the credential request, the request can be satisfied with alternative credentials. These determinations are then made regarding the content of the request. Once the processing in step S2003 is complete, the calculation unit 511 of Holder 500 proceeds to step S2004.
[0194] In step S2004, the calculation unit 511 of the Holder 500, using the alternative credential presentation unit 5117, executes a process to present to the Verifier 600, based on the result of the determination made in step S1403, that it does not have credentials that satisfy the content of the credential request received in step S2002, and presents alternative credentials (hereinafter also referred to as "alternative credentials"). As a result, alternative credentials are presented to the Verifier 600.
[0195] In step S2005, the calculation unit 611 of Verifier 600 executes the process of obtaining the alternative credentials presented by Holder 500 in step S2004 using the alternative credential acquisition unit 6117. As a result, the alternative credentials are obtained. Once the processing in step S2005 is complete, the calculation unit 611 of Verifier 600 proceeds to step S2006.
[0196] In step S2006, the calculation unit 611 of the Verifier 600 executes a process to create a request content based on the content of the alternative credentials obtained in step S2005, using the request content creation unit 6111. This creates the request content. Once the processing in step S2006 is complete, the calculation unit 611 of the Verifier 600 proceeds to step S2007.
[0197] In step S2007, the calculation unit 611 of the Verifier 600 executes a process to present the request content created in step S2006 to the credential adjustment system 100 using the request content presentation unit 6112. As a result, the request content is presented to the credential adjustment system 100.
[0198] In step S2008, the calculation unit 111 of the credential adjustment system 100 executes a process to acquire the request details presented by the Verifier 600 in step S2007 using the request details acquisition unit 1111. This acquires the request details. Once the processing in step S2008 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S2009.
[0199] In step S2009, the calculation unit 111 of the credential adjustment system 100 performs a data retrieval process using the data retrieval unit 1112. As a result, the data is retrieved. Once the processing in step S2009 is complete, the calculation unit 111 of the credential adjustment system 100 proceeds to step S2010.
[0200] In step S2010, the calculation unit 111 of the credential adjustment system 100 processes the request content obtained in step S2008 using the request content processing unit 1113. This processes the request content. Once the processing in step S2010 is complete, the calculation unit 111 of the credential adjustment system 100 terminates the attribute information candidate presentation process shown in the sequence diagram of Figure 20.
[0201] Thus, in this embodiment, as illustrated in the sequence diagram of Figure 20, even if there are no credentials that satisfy the requirements, the attribute information candidate presentation process (and attribute verification process) can be executed in the same way as when there are credentials that satisfy the requirements by presenting alternative credentials to the Verifier 600.
[0202] (Presentation Definition creation process) Figure 21 is a sequence diagram showing an example of the process for creating a Presentation Definition.
[0203] In step S2101, the calculation unit 111 of the credential adjustment system 100 executes a process to create a Presentation Definition using the Presentation Definition creation unit 1116. This process involves checking the credential format database 800 for the format and path of the organized attribute information as illustrated in Figure 22, and creating a Presentation Definition based on this confirmation. As a result, the Presentation Definition is created in the manner illustrated in Figure 23. Once the process in step S2101 is completed, the calculation unit 111 of the credential adjustment system 100 proceeds to step S2102.
[0204] In step S2102, the calculation unit 111 of the credential adjustment system 100 executes a process to present the Presentation Definition created in step S2101 to the Verifier 600 using the Presentation Definition presentation unit 1117. As a result, the Presentation Definition is presented to the Verifier 600.
[0205] In step S2103, the calculation unit 611 of the Verifier 600 executes a process to acquire the Presentation Definition presented by the credential adjustment system 100 in step S2102, using the Presentation Definition acquisition unit 6114. As a result, the Presentation Definition is acquired by the Verifier 600. Once the processing in step S2103 is complete, the calculation unit 611 of the Verifier 600 proceeds to step S2104.
[0206] In step S2104, the arithmetic unit 611 of the Verifier 600 executes a process to request credentials based on the Presentation Definition obtained in step S2103, using the credential request unit 6115. As a result, the Presentation Definition is presented to the Verifier 600.
[0207] In step S2105, the calculation unit 511 of the Holder 500 executes a process to receive the credential request made by the Verifier 600 in step S2104, via the credential request receiving unit 5113. As a result, the credential request is received by the Holder 500. Once the processing in step S2105 is complete, the calculation unit 511 of the Holder 500 proceeds to step S2106.
[0208] In step S2106, the calculation unit 511 of the Holder 500 performs a process to determine the credential request received from the Verifier 600 in step S2105, using the credential request determination unit 5114. This determines the credential request. Once the processing in step S2106 is complete, the calculation unit 511 of the Holder 500 proceeds to step S2107.
[0209] In step S2107, the calculation unit 511 of the Holder 500 executes a process to create credentials based on the result of the decision made in step S2106 by the credential creation unit 5115. This creates the credentials. Once the processing in step S2107 is complete, the calculation unit 511 of the Holder 500 proceeds to step S2108.
[0210] In step S2108, the calculation unit 511 of the Holder 500 performs the process of presenting the credentials created in step S2107 to the Verifier 600 using the credential presentation unit 5116.
[0211] In step S2109, the calculation unit 611 of the Verifier 600 executes the process of acquiring the credentials presented by the Holder 500 in step S2105 using the credential acquisition unit 6116. As a result, the credentials are acquired. Once the process in step S2109 is completed, the calculation unit 611 of the Verifier 600 terminates the Presentation Definition creation process shown in the sequence diagram of Figure 21.
[0212] The credential adjustment system 100 according to this embodiment has been described above.
[0213] Each embodiment of the present invention described above can be summarized as follows.
[0214] (1) The credential adjustment system 100 is a system for adjusting credentials (digital certificates) and comprises at least a processor 101 and storage devices (102, 103), and includes at least a computer that is connected to a terminal used by the holder of the credentials (Holder 500) and a terminal used by the attribute information verifier (Verifier 600) so as to be able to communicate data with each other. The processor 101 presents candidates for attribute information necessary for authorization to the terminal used by the attribute information verifier (Verifier 600) based on the request content presented by the terminal used by the attribute information verifier (Verifier 600), and creates a presentation definition format for the request that the terminal used by the attribute information verifier (Verifier 600) makes to request the credentials from the terminal used by the holder of the credentials (Holder 500), and presents it to the terminal used by the verifier (Verifier 600). In this way, an attribute information verifier using the credential adjustment system 100 can easily create a presentation definition (Presentation Definition) for requesting credentials from the credential holder's terminal (Holder 500) simply by performing input operations on the Verifier 600 and presenting the request details to the credential adjustment system 100. As a result, the credential adjustment system 100 can reduce the burden on the attribute information verifier when requesting credentials from the credential holder.
[0215] (2) Presenting candidate attribute information to the terminal used by the attribute information verifier (Verifier 600) involves obtaining the request content presented by the terminal used by the attribute information verifier (Verifier 600), performing a data search on the data stored in the storage device (103) to determine the necessary attribute information according to the obtained request content, requesting the necessary attribute information from the request content analysis system 900 using the obtained request content and the data search results obtained as a result of the data search, receiving the presentation of attribute information that matches the content of the request from the request content analysis system 900, confirming the content of the attribute information presented by the request content analysis system 900 with the terminal used by the attribute information verifier (Verifier 600), and performing conditional processing based on the response from the terminal used by the attribute information verifier (Verifier 600).
[0216] (3) Data searches are performed based on the content of the input operation, which is accepted as input items, including name, business type, and request details.
[0217] (4) Requests for necessary attribute information to the request content analysis system 900 are made in such a way that they are presented separately for each type of attribute information.
[0218] (5) The request format is Presentation Definition.
[0219] (6) The processor 101 acquires use case information and rulebook information, indexes them, registers them in the first database (credential search database 700), and further performs the process of registering credentials by acquiring information to be included in the request format for each credential and registering it in the second database (credential format database 800).
[0220] (7) In the process of registering credentials, the credential information is created based on the information published in the specifications.
[0221] (8) The presentation of candidate attribute information to the terminal used by the attribute information verifier (Verifier 600) is performed by obtaining the request content created by the terminal used by the attribute information verifier (Verifier 600) based on the alternative credentials presented by the terminal used by the holder of the credentials (Holder 500) to the terminal used by the attribute information verifier (Verifier 600), performing a data search on the data stored in the storage device (103) in order to determine the necessary attribute information according to the obtained request content, and using the obtained request content and the data search results obtained as a result of the data search, requesting the request content analysis system 900 to determine whether the request can be satisfied with the alternative credentials, and receiving the result of the determination from the request content analysis system 900.
[0222] (9) The request format is created based on the information obtained by checking the format and path of the attribute information in question in a second database (credential format database 800).
[0223] (10) Multiple candidate attribute information is presented to the terminal (Verifier 600) used by the attribute information verifier, and the request format is created based on the attribute information selected by the terminal (Verifier 600) from among the multiple attribute information. In this way, verifiers using the credential adjustment system 100 can request suitable credentials from the holder. As a result, the credential adjustment system 100 can further reduce the burden on attribute information verifiers when requesting credentials from the holder of credentials.
[0224] (11) The request format will be tailored to the needs of the attribute information verifier.
[0225] (12) The presentation of candidate attribute information required for authorization to the terminal used by the attribute information verifier (Verifier600) includes processing using a large-scale language model.
[0226] (13) In processing using a large-scale language model, the attribute information selected by the user terminal (Verifier600) of the attribute information verifier and / or the conditions specified by the user terminal (Verifier600) of the verifier are input to the large-scale language model as prompts, and candidate attribute information generated by the large-scale language model according to the attribute information and / or conditions input as prompts is obtained and presented to the user terminal (Verifier600) of the attribute information verifier.
[0227] (14) In processing using a large-scale language model, the search phase involves performing a data search on the data stored in the storage device (103) in order to determine the necessary attribute information according to the acquired request content, and the generation phase involves inputting the request content acquired from the terminal used by the attribute information verifier (Verifier 600) and the data search results obtained as a result of the data search as prompts into the large-scale language model, and acquiring candidate attribute information generated by the large-scale language model according to the input content and presenting it to the terminal used by the attribute information verifier (Verifier 600).
[0228] It should be noted that the present invention is not limited to the embodiments described above, and can be implemented using any components without departing from the spirit of the invention.
[0229] The embodiments and modifications described above are merely examples, and the present invention is not limited to these, as long as the features of the invention are not impaired. Furthermore, although various embodiments and modifications have been described above, the present invention is not limited to these. Other embodiments conceivable within the scope of the technical idea of the present invention are also included within the scope of the present invention.
[0230] In the diagrams above, the control lines and information lines shown are those deemed necessary for explanation and do not necessarily represent all control lines and information lines in the actual implementation. For example, it can be assumed that almost all components are interconnected in practice.
[0231] Furthermore, the arrangement of each functional component of the credential adjustment system 100 described above is merely an example. The arrangement of each functional component can be changed to the optimal arrangement from the perspective of the performance, processing efficiency, and communication efficiency of the hardware and software provided by the credential adjustment system 100.
[0232] Furthermore, each of the aforementioned configurations, functions, processing units, and processing means may be implemented in hardware, for example, by designing them as integrated circuits, or they may be implemented in software, by having the processor 101, which is an arithmetic unit, interpret and execute programs that realize each of these functions. [Explanation of Symbols]
[0233] 100: Credential Adjustment System
Claims
1. A credential adjustment system for adjusting credentials, comprising at least a computer equipped with a processor and a memory device, and connected to a terminal used by the holder of the credentials and a terminal used by the verifier of attribute information, respectively, in a manner that enables data communication between them, The aforementioned processor, Based on the request presented by the terminal used by the verifier of the attribute information, candidate attribute information necessary for authorization is presented to the terminal used by the verifier. The terminal used by the verifier of the attribute information creates a request format for the terminal used by the holder of the credentials to request those credentials, and presents it to the terminal used by the verifier. Credential adjustment system.
2. The presentation of candidate attribute information to the terminal used by the verifier of the aforementioned attribute information is as follows: The request content presented by the terminal used by the verifier of the aforementioned attribute information is obtained, In order to determine the necessary attribute information according to the acquired request, a data search is performed on the data stored in the storage device. Using the acquired request content and the data search results obtained as a result of the data search, a request for necessary attribute information is made to the request content analysis system, and the request content analysis system provides attribute information that matches the content of the request. The content of the attribute information presented by the request analysis system is confirmed on the terminal used by the verifier of the attribute information. Based on the response from the terminal used by the verifier of the attribute information, conditional processing is performed. The credential adjustment system according to claim 1.
3. The aforementioned data search is performed based on the content of the input operation, which receives at least the name, business type, and request details as input items. The credential adjustment system according to claim 2.
4. Requests for necessary attribute information to the aforementioned request content analysis system are made in such a way that they are presented separately for each attribute type. The credential adjustment system according to claim 2.
5. The format of the aforementioned request is Presentation Definition. The credential adjustment system according to claim 1.
6. The aforementioned processor, Use case information and rulebook information are retrieved, indexed, and registered in the first database. The information to be entered for each credential in the aforementioned request format is retrieved and registered in the second database. The credential adjustment system according to claim 1, further comprising the process of registering credentials by means of the above.
7. In the process of registering the aforementioned credentials, the credential information is created based on information published in the specifications. The credential adjustment system according to claim 6.
8. The presentation of candidate attribute information to the terminal used by the verifier of the aforementioned attribute information is as follows: The terminal used by the holder of the aforementioned credentials obtains the request content created by the terminal used by the attribute information verifier based on the alternative credentials presented by the terminal used by the attribute information verifier. In order to determine the necessary attribute information according to the acquired request, a data search is performed on the data stored in the storage device. Using the acquired request details and the data search results obtained as a result of the data search, a request is made to the request content analysis system to determine whether the request can be satisfied with alternative credentials. The result of the said determination is received from the request content analysis system. The credential adjustment system according to claim 1.
9. The format of the aforementioned request is created based on the verification results obtained by checking the second database regarding the format and path of the attribute information. The credential adjustment system according to claim 6.
10. The verifier of the aforementioned attribute information presents multiple candidate attribute information to their terminal, The format of the aforementioned request is created based on the attribute information selected by the terminal used by the verifier of the attribute information from among the multiple attribute information. The credential adjustment system according to claim 1.
11. The format of the aforementioned request is created to suit the needs of the verifier of the attribute information. The credential adjustment system according to claim 10.
12. The presentation of candidate attribute information necessary for the aforementioned authorization to the terminal used by the verifier of said attribute information is carried out including processing using a large-scale language model. The credential adjustment system according to claim 1.
13. The attribute information selected by the verifier's operation on the terminal and / or the conditions specified by the verifier's operation on the terminal are input to the large-scale language model as prompts. The system retrieves attribute information entered as a prompt and / or candidates for attribute information generated by the large-scale language model according to the conditions, and presents them to the terminal used by the verifier of the attribute information. The credential adjustment system according to claim 1.
14. In order to determine the necessary attribute information according to the acquired request, a data search is performed on the data stored in the storage device. The request content obtained from the terminal used by the verifier of the attribute information and the data search results obtained as a result of the data search are input to the large-scale language model as prompts. The system retrieves candidate attribute information generated by the large-scale language model based on the input content and presents it to the terminal used by the verifier of the attribute information. The credential adjustment system according to claim 1.
15. A credential adjustment method for adjusting credentials, comprising a computer having at least a processor and a memory device, and connected to a terminal used by the holder of the credentials and a terminal used by the verifier of attribute information, respectively, in a manner that enables data communication between them, The aforementioned processor, Based on the request presented by the terminal used by the verifier of the attribute information, candidate attribute information necessary for authorization is presented to the terminal used by the verifier. The terminal used by the verifier of the attribute information creates a request format for the terminal used by the holder of the credentials to request those credentials, and presents it to the terminal used by the verifier. Credential adjustment method.
Citation Information
Patent Citations
Photosensitive composition and method for manufacturing article covered with patterned film
JP2003015277A
Data matching system, information processing apparatus, and data matching method
JP2021140299A
Data management program, data management method, data management device, and data management system
WO2023026343A1