Terminal, information processing apparatus, control method for terminal, and program

The proposed solution addresses the challenge of ensuring authenticity in digital wallet transactions by using a terminal and system that verify and store biometric information to match the identity certificate with the user's biometric data, effectively preventing fraudulent access.

JP7687505B2Active Publication Date: 2025-06-03NEC CORP
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
JP2024160553
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2025-06-03
Estimated Expiration
2043-03-22

AI Technical Summary

Technical Problem

Existing digital wallet technologies face challenges in ensuring the authenticity of content provided, as biometric authentication methods can be compromised by fraudulent registration of biometric information, leading to verification issues.

Method used

A terminal and system that incorporate identity verification means to match biometric information from an identity certificate with the biometric information of the user opening the digital wallet, and store this information as the biometric data of the digital wallet account holder, ensuring authentication.

Benefits of technology

This solution effectively ensures the authenticity of content provided from a digital wallet by verifying the identity of the user and ensuring that the biometric information matches the registered account holder, thereby preventing fraudulent access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007687505000001
    Figure 0007687505000001
  • Figure 0007687505000002
    Figure 0007687505000002
  • Figure 0007687505000003
    Figure 0007687505000003
Patent Text Reader

Abstract

To provide a terminal that guarantees the authenticity of contents provided from a digital wallet.SOLUTION: A terminal comprises identity verification means and storage means. The identity verification means verifies the identity of a creator who creates a digital wallet by using biometric information obtained from an identification card and the biometric information of the creator who creates the digital wallet. If the identity verification is successful, the storage means stores the biometric information obtained from the identification card or the biometric information of the creator who creates the digital wallet as the biometric information of a digital wallet holder.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a terminal, a system, a method for controlling a terminal, and a storage medium.

Background Art

[0002] There are technologies related to digital wallets.

[0003] For example, Patent Document 1 describes that a device and a method for using biometric technology are disclosed in order to ensure secure transactions using blockchain technology. Further, Patent Document 1 describes reducing at least some security-related problems in conventional blockchain digital wallets, specifically, blockchain digital wallets that cannot reliably authenticate user identification information. Further, Patent Document 1 presents a method and an apparatus for using authentication and data protection to implement a blockchain offline wallet using biometrics.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] When a user uses a digital wallet, digital content (for example, a certificate such as a student ID) stored in the digital wallet is presented to the verifier of the certificate. At that time, the verifier confirms the authenticity of the presented digital content. That is, the verifier confirms that the user in front of them matches the person in whose name the digital wallet is registered.

[0006] In the technology disclosed in Patent Document 1, verification of the user and the named person is performed using biometric authentication. That is, in Patent Document 1, when a user uses a digital wallet, biometric authentication is used to confirm that the service user and the named person of the digital wallet are the same.

[0007] However, if the biometric information used for biometric authentication when the user uses the digital wallet is not the biometric information of the named person of the digital wallet, the verifier may provide services to a user different from the named person of the digital wallet. That is, when opening a digital wallet, if someone else fraudulently registers biometric information under a false name, the verifier cannot confirm the authenticity of the provided digital content (for example, a certificate such as a student ID).

[0008] The main object of the present invention is to provide a terminal, a system, a control method for a terminal, and a storage medium that contribute to ensuring the authenticity of content provided from a digital wallet.

Means for Solving the Problems

[0009] According to a first aspect of the present invention, there is provided an identity verification means for verifying the identity of the person who opens the digital wallet using the biometric information obtained from the identity certificate and the biometric information of the person who opens the digital wallet, and when the identity verification is successful, the biometric information obtained from the identity certificate or the biometric information of the person who opens the digital wallet is stored as the biometric information of the named person of the digital wallet. A terminal is provided that includes a storage means.

[0010] According to a second aspect of the present invention, there is provided a system including a terminal and a carrier terminal used by a service provider when providing a service to a user, wherein the terminal includes: an identity verification means for verifying the identity of an account opener who opens a digital wallet by using biometric information obtained from an identity certificate and biometric information of the account opener who opens the digital wallet; a storage means for storing, when the identity verification is successful, the biometric information obtained from the identity certificate or the biometric information of the account opener who opens the digital wallet as the biometric information of the digital wallet account holder; and a usage control means for providing the content stored in the digital wallet and the biometric information of the digital wallet account holder to the carrier terminal.

[0011] According to a third aspect of the present invention, there is provided a method for controlling a terminal, in which the terminal verifies the identity of an account opener who opens a digital wallet by using biometric information obtained from an identity certificate and biometric information of the account opener who opens the digital wallet, and when the identity verification is successful, stores the biometric information obtained from the identity certificate or the biometric information of the account opener who opens the digital wallet as the biometric information of the digital wallet account holder.

[0012] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium storing a program for causing a computer mounted on a terminal to execute a process of verifying the identity of an account opener who opens a digital wallet by using biometric information obtained from an identity certificate and biometric information of the account opener who opens the digital wallet, and a process of storing, when the identity verification is successful, the biometric information obtained from the identity certificate or the biometric information of the account opener who opens the digital wallet as the biometric information of the digital wallet account holder.

Advantages of the Invention

[0013] According to each aspect of the present invention, there are provided a terminal, a system, a method for controlling the terminal, and a storage medium that contribute to ensuring the authenticity of content provided from a digital wallet. Note that the effects of the present invention are not limited to the above. Instead of or together with the above effects, other effects may be achieved by the present invention.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

[0015] First, an overview of an embodiment will be described. Note that the reference numerals in the drawings appended to this overview are for convenience of each element as an example for assisting understanding, and the description of this overview is not intended to be limiting in any way. Further, unless otherwise specified, the blocks described in each drawing represent a configuration of a functional unit, not a configuration of a hardware unit. The connection lines between the blocks in each figure include both bidirectional and unidirectional ones. The one-way arrow schematically shows the flow of the main signal (data) and does not exclude bidirectionality. In the present specification and drawings, for elements that can be similarly described, duplicate description may be omitted by attaching the same reference numerals.

[0016] A terminal 100 according to an embodiment includes an identity verification means 101 and a storage means 102 (see FIG. 1). The identity verification means 101 verifies the identity of the person who opens the digital wallet by using the biometric information obtained from the identity certificate and the biometric information of the person who opens the digital wallet (step S1 in FIG. 2). When the identity verification is successful, the storage means 102 stores the biometric information obtained from the identity certificate or the biometric information of the person who opens the digital wallet as the biometric information of the digital wallet holder (step S2).

[0017] The terminal 100 verifies the identity of the digital wallet account holder using the identity certificate issued by a public institution when opening the digital wallet. When the identity verification is successful, the terminal 100 stores the biometric information obtained at the time of opening the digital wallet as the biometric information of the digital wallet account holder. When the user receives a service from the service provider, the terminal 30 can provide the biometric information of the digital wallet account holder together with the digital content to the service provider. The service provider can verify whether the person presenting in front of it is the same as the account holder of the digital wallet that provides the certificate by performing an authentication process using the biometric information obtained from the terminal 30 and the biometric information of the user who wishes to enjoy the service. As a result, even if a person other than the digital wallet account holder attempts to receive a service from the service provider using the terminal 30 of the digital wallet account holder, the service provider can detect such improper behavior. That is, the authenticity of the content provided from the digital wallet is ensured.

[0018] Specific embodiments will be described in more detail below with reference to the drawings.

[0019] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0020] [System Configuration] As shown in FIG. 3, the information processing system according to the first embodiment includes at least one or more certificate issuers and at least one or more service providers.

[0021] The certificate issuer is a party that issues a certificate to the user. For example, educational institutions such as universities and vocational schools that issue student IDs correspond to certificate issuers. Alternatively, institutions and associations that issue certificates such as language proficiency certificates correspond to certificate issuers. Also, the certificate issuer is not limited to private companies, and public institutions that issue driver's licenses and the like are also included in the certificate issuers disclosed in the present application.

[0022] Each certificate issuer is equipped with a server device 10. The server device 10 is a server that performs processes and operations necessary for the business of the certificate issuer. The server device 10 may be managed and operated by the certificate issuer, or the management and operation may be entrusted to other operators or the like. The server device 10 may be installed inside the building of the certificate issuer, or may be installed on the network (in the cloud).

[0023] The certificate issuer issues a certificate in response to a request from the user. For example, a university issues a student ID (digital student ID) in response to a request from a student belonging to it. Alternatively, an organization that conducts language learning or the like issues a certification (digital certification) indicating the language proficiency of the examinee.

[0024] A service provider is an operator that provides services to users. For example, service providers include operators that operate means of transportation such as railways, buses, and airplanes. Alternatively, operators such as retail stores and restaurants fall under service providers. Service providers are not limited to private companies, and public institutions such as city halls, organizations such as NGOs (Non-Governmental Organizations) and NPOs (Non-Profit Organizations) are also included in the service providers disclosed in the present application.

[0025] The service provider requests the user to present a certificate corresponding to the business of its own company (organization). For example, a railway company that sells discounted monthly passes to students requests the student to present a student ID. Alternatively, a retail store that sells tobacco, alcohol, etc. to users requests the user to present a certificate that can confirm age.

[0026] Each service provider is equipped with a business operator terminal 20 used when providing services to users. The business operator terminal 20 may be a terminal such as a personal computer, a tablet-type terminal, or a POS (Point of Sale) terminal. Note that the service provider may be equipped with a server for providing services to users (not shown in FIG. 3 etc.).

[0027] Employees of the service provider, etc. operate the business operator terminal 20 to provide services to users. At this time, the business operator terminal 20 verifies the certificate presented by the user, etc. The business operator terminal 20 notifies the employee, etc. of the verification result.

[0028] The user holds the terminal 30. The user operates the terminal 30 to request (require) the certificate issuer to issue a certificate. Also, the user presents the certificate (for example, a student ID card) required by the service provider using the terminal 30.

[0029] Each device shown in FIG. 3 is connected to the network. Specifically, the server device 10, the business operator terminal 20, and the terminal 30 are connected to the network by wired or wireless communication means.

[0030] The configuration of the information processing system shown in FIG. 3 is an example and is not intended to limit the configuration. For example, each certificate issuer may include a plurality of server devices 10. Similarly, each service provider may include a plurality of business operator terminals 20.

[0031] [Schematic Operation] Next, the schematic operation of the information processing system according to the first embodiment will be described.

[0032] [Preparation of Digital Wallet] The user's terminal 30 has a digital wallet function. The digital wallet is an electronic information storage service that ensures information security such as data integrity, reliability, and availability. The digital wallet preferably has self-sovereign management, but a subject other than the user himself / herself may be the management subject.

[0033] The user installs an application for realizing a digital wallet on the terminal 30 they possess. By opening a digital wallet on the terminal 30, the user can store digital money, student ID cards, identity certificates such as passports and driver's licenses, various ticket information such as airline tickets and boarding passes, and various digital contents such as vaccination certificates on the terminal 30.

[0034] For example, the user's terminal 30 stores digital contents as shown in FIG. 4. Among the digital contents stored in the terminal 30, there are public identity certificates such as passports and driver's licenses, and student ID cards issued by universities.

[0035] When the digital wallet application is started for the first time, the terminal 30 performs identity verification using an identity certificate issued by a public agency such as a national administrative agency. That is, the terminal 30 performs identity verification of the user when opening the digital wallet.

[0036] For example, the terminal 30 performs identity verification using an identity certificate on which the biometric information of the named person, such as a My Number card or a passport, is described. The terminal 30 uses the My Number card or passport as a Root of Trust.

[0037] Note that examples of biometric information include data (feature quantities) calculated from personal and unique physical characteristics such as face, fingerprint, voiceprint, vein, retina, and iris pattern of the pupil. Alternatively, the biometric information may be image data such as a face image or a fingerprint image. The biometric information only needs to include the user's physical characteristics as information. In the present disclosure, the case of using biometric information (face image or feature quantity generated from the face image) related to a person's "face" will be described.

[0038] The terminal 30 acquires information about the named person (the person to whom the identity certificate is issued) from the user's identity certificate. For example, the terminal 30 acquires information about the named person of the My Number card from the IC (Integrated Circuit) of the My Number card.

[0039] Specifically, the terminal 30 acquires the basic information of the cardholder of the My Number Card (so-called basic four information: name, gender, date of birth, address) and the biometric information (face image) of the cardholder. The terminal 30 internally stores the basic information and biometric information read from the My Number Card.

[0040] Furthermore, the terminal 30 acquires the biometric information of the user (the issuer of the digital wallet). For example, the terminal 30 acquires and stores a face image by photographing the user.

[0041] The terminal 30 executes a verification process (authentication process) using the biometric information acquired from the identity certificate and the biometric information of the user. When the authentication process (one-to-one authentication) is successful, the terminal 30 opens a digital wallet. The terminal 30 confirms by a verification process (authentication process) using biometric information that the person in whose name the identity certificate was issued and the user who uses the digital wallet of the terminal 30 are the same person.

[0042] <Issuance of Certificate> The user acquires digital content to be stored in the digital wallet. For example, the user operates the terminal 30 to request the certificate issuer to issue a certificate. For example, a student requests (demands) the issuance of a student ID card from the university to which the student belongs. Specifically, the digital wallet application requests the university to which the student belongs to issue a student ID card.

[0043] The terminal 30 transmits a "certificate issuance request" including information for identifying the user (for example, name, combination of name and date of birth, student ID number, etc.) to the server device 10 of the certificate issuer (see FIG. 5).

[0044] The certificate issuer determines whether the user who requests the issuance of the certificate has the authority (qualification) to receive the issuance of the certificate. For example, the server device 10 determines whether the student who wishes to obtain a student ID card is enrolled in the university.

[0045] If a student belongs to the university itself, the server device 10 issues a student ID card (digital student ID card). The server device 10 issues a signed certificate of its own organization (certificate issuer; for example, a university). The server device 10 transmits the issued signed certificate to the terminal 30.

[0046] The terminal 30 (digital wallet application) verifies the signature of the received certificate.

[0047] When the signature verification is successful, the terminal 30 acquires basic information (name, gender, date of birth, address) from the received certificate. That is, the terminal 30 acquires basic information regarding the subject of the acquired certificate. The terminal 30 collates the basic information acquired from the identity certificate (root of trust) at the initial startup of the digital wallet application with the basic information acquired from the certificate generated by the certificate issuer.

[0048] In the above example, the terminal 30 collates the basic information acquired from the My Number card with the basic information acquired from the student ID card. If the basic information acquired from two different media matches, the terminal 30 determines that the collation is successful.

[0049] When the terminal 30 successfully verifies the signature attached to the certificate and successfully collates using the two pieces of basic information (the two pieces of basic information match), the terminal 30 accepts the certificate received from the certificate issuer. The terminal 30 stores the certificate (for example, a student ID card) acquired from the certificate issuer internally and manages it so that it can be used in the digital wallet.

[0050] <Usage of Certificate> The user presents the certificate required by the service provider to the service provider. For example, a student who wants to purchase a commuter pass presents a student ID card to the railway company.

[0051] For example, the user operates the terminal 30 to launch the digital wallet application. The user selects a certificate (e.g., student ID) specified by the service provider on the digital wallet application.

[0052] The terminal 30 generates a two-dimensional barcode using the certificate selected by the user and the biometric information stored internally (e.g., a face image obtained from a my number card or a face image taken at the time of opening the digital wallet). The terminal 30 generates a two-dimensional barcode in which the certificate specified by the service provider and the user's biometric information are converted. The terminal 30 displays the generated two-dimensional barcode.

[0053] The user presents the terminal 30 on which the two-dimensional barcode is reflected to the service provider (e.g., a railway company employee, etc.) (see Fig. 6).

[0054] The service provider (an employee of the service provider, etc.) operates the merchant terminal 20 to read the presented two-dimensional barcode. Also, the service provider operates the merchant terminal 20 to acquire the biometric information of the user in front (the user presenting the certificate). For example, the service provider operates the merchant terminal 20 to photograph the user in front and acquire a face image.

[0055] The merchant terminal 20 acquires the two-dimensional barcode (the two-dimensional barcode including the signed certificate and biometric information) and the biometric information of the user who wishes to receive the service.

[0056] The merchant terminal 20 performs a collation process (authentication process) using the biometric information obtained from the two-dimensional barcode and the biometric information of the user in front. When the authentication process (one-to-one authentication) is successful, the merchant terminal 20 treats the presented certificate as a legitimate certificate issued to the user in front.

[0057] The business operator terminal 20 notifies the service provider (such as a staff member of the service provider) that the presented certificate is valid. Alternatively, the business operator terminal 20 determines the legitimacy, validity, etc. of the presented certificate as necessary. For example, the business operator terminal 20 verifies the signature attached to the student ID card and verifies the expiration date of the student ID card. The business operator terminal 20 notifies the service provider of the verification result.

[0058] When a certificate necessary for the service provider to provide a service to a user is presented, the service provider provides the service to the user. In the above example, a staff member of the railway company sells a discounted monthly pass to a student.

[0059] In this way, when opening a digital wallet, the terminal 30 performs identity verification using the biometric information obtained from the identity certificate of the account opener and the biometric information of the account opener. When the identity verification is successful, the terminal 30 enables the use of the digital wallet. In addition, the terminal 30 stores a certificate whose authenticity is guaranteed by the certificate issuer through an electronic signature or the like in the digital wallet. At this time, the terminal 30 (digital wallet application) collates the basic information extracted from the identity certificate with the basic information obtained from the certificate issuer. The terminal 30 verifies the authenticity of the obtained certificate. Furthermore, when the user uses the certificate stored in the digital wallet, the terminal 30 provides the certificate and the biometric information of the digital wallet account holder to the service provider (verifier). The service provider verifies that the user in front of them is the digital wallet account holder by performing authentication using the biometric information of the digital wallet account holder and the biometric information obtained from the user in front of them. If the digital wallet used by the user is a highly reliable digital wallet, the service provider can trust the certificate obtained from the digital wallet.

[0060] Subsequently, the details of each device included in the information processing system according to the first embodiment will be described.

[0061] [Terminal] FIG. 7 is a diagram showing an example of the processing configuration (processing modules) of the terminal 30 according to the first embodiment. Referring to FIG. 7, the terminal 30 includes a communication control unit 201, a digital wallet control unit 202, and a storage unit 203.

[0062] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. Also, the communication control unit 201 transmits data to the server device 10. The communication control unit 201 delivers the data received from other devices to other processing modules. The communication control unit 201 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0063] The digital wallet control unit 202 is a means for managing and controlling the digital wallet. As shown in FIG. 8, the digital wallet control unit 202 includes sub-modules consisting of an identity verification unit 211, a certificate acquisition control unit 212, and a usage control unit 213.

[0064] Note that a detailed description of the installation of the digital wallet application is omitted because it is obvious to those skilled in the art.

[0065] The identity verification unit 211 is a means for verifying the identity of the digital wallet account holder. The identity verification unit 211 verifies the identity of the digital wallet account holder using the biometric information obtained from the identity certificate and the biometric information of the digital wallet account holder. More specifically, the identity verification unit 211 verifies that the name of the digital wallet account holder is the same as the name of the person (certificate holder) issued by the public institution in the identity certificate.

[0066] FIG. 9 is a flowchart showing an example of the operation of the personal authentication unit 211 according to the first embodiment. While referring to FIG. 9, the operation of the personal authentication unit 211 according to the first embodiment will be described.

[0067] At the time of opening the digital wallet (at the first startup), the personal authentication unit 211 acquires information regarding the person named in the identity certificate from the identity certificate held by the user. For example, the personal authentication unit 211 acquires basic information and biometric information of the person named in the identity certificate from an IC (Integrated Circuit) chip mounted on a my number card or a passport (step S101).

[0068] For example, when a my number card is used as the identity certificate, the personal authentication unit 211 acquires a PIN for the electronic certificate for user authentication using a GUI (Graphical User Interface) or the like (see FIG. 10). Alternatively, when a passport is used as the identity certificate, the personal authentication unit 211 acquires information described in the MRZ (Machine Readable Zone) described on the passport face using OCR (Optical Character Recognition) technology.

[0069] The personal authentication unit 211 reads information from the IC chip using the acquired PIN (a four-digit number) or the information described in the MRZ as a password. The personal authentication unit 211 stores the basic information (name, gender, date of birth, address) and biometric information (face information, face image) regarding the person named in the identity certificate (my number card, passport, etc.) read from the identity certificate in the storage unit 203 (step S102).

[0070] Furthermore, the personal authentication unit 211 acquires biometric information of the user (the user of the terminal 30; the opener of the digital wallet) (step S103). For example, the personal authentication unit 211 prompts the user to take a picture of his / her face using a GUI or the like (so-called, acquiring a face image by taking a self-portrait).

[0071] The user authentication unit 211 acquires biometric information from the identity certificate, and when acquiring the biometric information of the user who operates the own device, executes a collation process using the biometric information obtained from the identity certificate and the biometric information of the user (step S104). The user authentication unit 211 determines whether or not the two biometric information substantially match.

[0072] Specifically, the user authentication unit 211 generates feature amounts from each of the two biometric information (for example, face images).

[0073] Regarding the generation process of the feature amount, an existing technique can be used, so the detailed description thereof is omitted. For example, the user authentication unit 211 extracts eyes, nose, mouth, etc. as feature points from the face image. Thereafter, the user authentication unit 211 calculates the positions of the respective feature points and the distances between the feature points as feature amounts (generates a feature vector composed of a plurality of feature amounts).

[0074] Next, the user authentication unit 211 executes a collation process (authentication process) using the two generated feature amounts. Specifically, the user authentication unit 211 calculates the similarity between the corresponding face images using the two feature amounts. The user authentication unit 211 determines whether or not the two images are face images of the same person based on the result of the threshold process for the calculated similarity. Note that, as the similarity, a chi-square distance, a Euclidean distance, or the like can be used. The farther the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0075] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the user authentication unit 211 determines that the collation process has succeeded. If the similarity is equal to or less than the predetermined value, the user authentication unit 211 determines that the collation process has failed.

[0076] When the collation process succeeds (step S105, Yes branch), the user authentication unit 211 permits the user to use the digital wallet (permission to use; step S106). That is, when the authentication process (one-to-one authentication) succeeds, the user authentication unit 211 opens a digital wallet.

[0077] When the identity verification process (authentication process) using biometric information is successful, the identity verification unit 211 treats that the person named in the issued identity certificate and the user of the terminal 30 are the same person. At the first startup of the digital wallet, it is determined whether the person named in the identity certificate and the user of the terminal 30 are the same person. If the person named in the identity certificate and the person who opened the digital wallet are the same person, the terminal 30 enables the use of the digital wallet application.

[0078] When the verification process fails (branch to No in step S105), the identity verification unit 211 does not permit the user to use the digital wallet (refuses use; step S107). That is, when the authentication process (one-to-one authentication) fails, the user cannot use the digital wallet (cannot open the digital wallet).

[0079] In this way, when the first authentication process using the biometric information obtained from the identity certificate and the biometric information of the person who opens the digital wallet is successful, the identity verification unit 211 determines that the identity verification is successful. When the identity verification is successful, the digital wallet is opened.

[0080] In principle, the basic information extracted from the identity certificate is not changed. In order to change the basic information, a verification process between the changed basic information and the basic information obtained from an identity certificate such as a My Number card is required.

[0081] The certificate acquisition control unit 212 is a means for performing control related to the acquisition of a certificate.

[0082] The certificate acquisition control unit 212 requests the certificate issuer to issue a certificate and receives the certificate from the certificate issuer. The certificate acquisition control unit 212 executes a verification process using the basic information regarding the person named in the identity certificate obtained from the identity certificate and the basic information regarding the person named in the received certificate obtained from the received certificate. When the two pieces of basic information match, the certificate acquisition control unit 212 stores the certificate received from the certificate issuer in the digital wallet.

[0083] FIG. 11 is a flowchart showing an example of the operation of the certificate acquisition control unit 212 according to the first embodiment. While referring to FIG. 11, the operation of the certificate acquisition control unit 212 according to the first embodiment will be described.

[0084] When a user who has opened a digital wallet starts a digital wallet application and performs a predetermined operation (for example, pressing a certificate issuance button), the certificate acquisition control unit 212 performs control related to the acquisition of the certificate desired by the user.

[0085] First, the certificate acquisition control unit 212 acquires information necessary for the certificate issuance request using a GUI or the like (acquisition of necessary information; step S201). Specifically, the certificate acquisition control unit 212 acquires information on the certificate issuer corresponding to the certificate that the user desires to issue, the type of the desired certificate, and the like. Alternatively, the certificate acquisition control unit 212 acquires information for the certificate issuer to identify the user (for example, student ID number at the time of student ID issuance request) as necessary.

[0086] The certificate acquisition control unit 212 notifies the acquired necessary information to the certificate issuer. For example, the certificate acquisition control unit 212 notifies the certificate issuer of the type of the certificate that the user desires to issue and information for identifying the user (for example, name and student ID number). Specifically, the certificate acquisition control unit 212 transmits a "certificate issuance request" including the type of the certificate, information for identifying the user, and the like to the server device 10 of the designated certificate issuer (step S202).

[0087] The certificate acquisition control unit 212 receives a response (positive response, negative response) to the certificate issuance request from the server device 10 (step S203).

[0088] When a negative response (certificate not issued) is received (step S204, No branch), the certificate acquisition control unit 212 notifies the user that the certificate has not been issued (notify non-issuance; step S205).

[0089] When a positive response (certificate is issued) is received (step S204, Yes branch), the certificate acquisition control unit 212 verifies the signature of the certificate included in the positive response (step S206). The certificate acquisition control unit 212 verifies the signature using the electronic signature attached to the certificate and the public key obtained from the electronic certificate corresponding to the electronic signature.

[0090] If the signature verification fails (step S207, No branch), the certificate acquisition control unit 212 discards the certificate received from the certificate issuer. Also, the certificate acquisition control unit 212 notifies the user that the certificate obtained from the certificate issuer is improper (notify improper; step S208).

[0091] If the signature verification is successful (step S207, Yes branch), the certificate acquisition control unit 212 acquires the basic information (name, gender, date of birth, address) of the person in whose name the received certificate is issued (acquire basic information; step S209).

[0092] The certificate acquisition control unit 212 collates the basic information regarding the person in whose name the acquired certificate is issued with the basic information acquired from the identity certificate at the initial startup of the digital wallet (step S210). That is, the certificate acquisition control unit 212 collates the basic information of the certificate holder with the basic information of the digital wallet holder (digital wallet opener).

[0093] If the two pieces of basic information match (if each of the name, gender, date of birth, and address that make up the basic information matches), the certificate acquisition control unit 212 determines that the collation of the basic information has succeeded. If the two pieces of basic information do not match, the certificate acquisition control unit 212 determines that the collation of the basic information has failed.

[0094] If the collation of the basic information fails (step S211, No branch), the certificate acquisition control unit 212 discards the certificate received from the certificate issuer. Also, the certificate acquisition control unit 212 notifies the user that the certificate obtained from the certificate issuer is improper (step S208).

[0095] When the verification of the basic information is successful (branch to Yes in step S211), the certificate acquisition control unit 212 stores the certificate received from the certificate issuer in the digital wallet (step S212).

[0096] In this way, when the certificate acquisition control unit 212 successfully verifies the signature attached to the certificate and also successfully matches using the two pieces of basic information (the two pieces of basic information match), it determines that the certificate received from the certificate issuer is a legitimate certificate. The certificate acquisition control unit 212 stores the legitimate certificate (for example, a student ID card) obtained from the certificate issuer in the storage unit 203.

[0097] The usage control unit 213 is a means for controlling the usage of digital content (for example, a digital certificate) stored in the digital wallet.

[0098] The usage control unit 213 acquires the certificate that the user wishes to use by using a GUI or the like. For example, the usage control unit 213 displays a list of digital content as shown in FIG. 4 and enables the user to select the certificate that the user wishes to use.

[0099] When the user selects a certificate (for example, a student ID card), the usage control unit 213 generates a two-dimensional barcode using the certificate selected by the user and the biometric information stored in the storage unit 203 (biometric information obtained from the identity certificate or biometric information obtained from the user). The usage control unit 213 displays the generated two-dimensional barcode.

[0100] In this way, when the user receives a service from the service provider, the usage control unit 213 provides the service provider with the certificate stored in the digital wallet and the biometric information of the person in whose name the digital wallet is registered.

[0101] The storage unit 203 is a means for storing information necessary for the operation of the terminal 30. When the personal authentication unit 211 successfully authenticates the identity of the digital wallet account holder, the storage unit 203 stores the biometric information obtained from the identity certificate or the biometric information of the digital wallet account holder as the biometric information of the digital wallet account holder. Note that the biometric information stored as the biometric information of the digital wallet account holder may be the biometric information obtained from the identity certificate or the biometric information obtained by photographing the user.

[0102] [Server device] FIG. 12 is a diagram showing an example of the processing configuration (processing modules) of the server device 10 according to the first embodiment. Referring to FIG. 12, the server device 10 includes a communication control unit 301, a certificate issuing unit 302, and a storage unit 303.

[0103] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 30. Also, the communication control unit 301 transmits data to the terminal 30. The communication control unit 301 delivers the data received from other devices to other processing modules. The communication control unit 301 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0104] The certificate issuing unit 302 is a means for issuing a certificate to the user. The certificate issuing unit 302 processes the "certificate issuance request" received from the terminal 30.

[0105] Upon receiving the certificate issuance request, the certificate issuing unit 302 searches a database (not shown in FIG. 12 or the like) that stores user information using the information (e.g., name or student ID number) for identifying the user included in the certificate issuance request as a key.

[0106] If the above search fails (i.e., the corresponding user is not registered in the database), the certificate issuing department 302 sends a negative response indicating certificate issuance failure to the terminal 30.

[0107] If the above search is successful, the certificate issuing department 302 determines whether it is possible to issue a certificate to the user based on the information stored in the database and the type of certificate that the user included in the certificate issuance request wishes to issue. That is, the certificate issuing department 302 determines whether the user who wishes to receive the certificate has the authority (qualification) to receive the certificate.

[0108] For example, if the issuance of a student ID is requested and the user who wishes to receive the student ID has not withdrawn from school or the like, the certificate issuing department 302 determines that the student has the authority to receive the certificate. On the other hand, if the student (former student) recorded in the database has withdrawn from school, the certificate issuing department 302 determines that the student does not have the authority to receive the certificate.

[0109] Note that a more detailed explanation regarding the issuance of individual certificates (e.g., student IDs, language proficiency certificates, etc.) is omitted. This is because a detailed explanation regarding the issuance of individual certificates is different from the gist of the present disclosure.

[0110] If the user does not have the authority to receive the certificate, the certificate issuing department 302 sends a negative response indicating certificate issuance failure (certificate issuance not possible) to the terminal 30.

[0111] If the user has the authority to receive the certificate, the certificate issuing department 302 generates a certificate to be issued to the user (digital certificate; e.g., digital student ID). The certificate issuing department 302 generates a certificate with the electronic signature of the self-organization (e.g., university) and the corresponding electronic certificate attached.

[0112] Note that the certificate issuing department 302 generates a certificate including the basic information of the user (certificate recipient) who receives the certificate. For example, the certificate issuing department 302 generates a student ID including the student's name, gender, date of birth, and address.

[0113] The certificate issuing unit 302 transmits the generated certificate (certificate including electronic document, electronic signature, electronic certificate) to the terminal 30. The certificate issuing unit 302 transmits an affirmative response (affirmative response including a signed certificate) indicating that the issuance of the requested certificate has been successful to the terminal 30.

[0114] The storage unit 303 is a means for storing information necessary for the operation of the server device 10.

[0115] [Business operator terminal] FIG. 13 is a diagram showing an example of the processing configuration (processing module) of the business operator terminal 20 according to the first embodiment. Referring to FIG. 13, the business operator terminal 20 includes a communication control unit 401, a service provision control unit 402, and a storage unit 403.

[0116] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from a server of a service provider (not shown in FIG. 3 etc.). Also, the communication control unit 401 transmits data to the server. The communication control unit 401 delivers the data received from other devices to other processing modules. The communication control unit 401 transmits the data acquired from other processing modules to other devices. In this way, other processing modules perform data transmission and reception with other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit for receiving data from other devices and a function as a transmitting unit for transmitting data to other devices.

[0117] The service provision control unit 402 is a means for executing control regarding the service provided to the user.

[0118] The service provision control unit 402 controls a two-dimensional barcode reader etc. according to the operations of employees etc. of the service provider, and reads the two-dimensional barcode presented by the user (user who receives the service). The service provision control unit 402 decodes the two-dimensional barcode and acquires a signed certificate and biometric information (biometric information of the digital wallet holder).

[0119] In addition, the service provision control unit 402 acquires biometric information (e.g., face image) of the user in front (the user who receives the service) in response to the operations of employees of the service provider or the like.

[0120] The service provision control unit 402 determines whether the certificate presented to the service provider is a valid certificate by using the two acquired biometric information.

[0121] Specifically, the service provision control unit 402 executes a collation process (authentication process) of the biometric information (e.g., face image) acquired from the two-dimensional barcode and the biometric information of the user in front (e.g., the face image obtained by photographing the user in front).

[0122] If the two biometric information are substantially the same (if the collation process is successful), the service provision control unit 402 determines that the certificate presented to the service provider is a valid certificate issued to the user in front.

[0123] If the two biometric information are not substantially the same (if the collation process fails), the service provision control unit 402 determines that the certificate presented to the service provider is not a valid certificate issued to the user in front.

[0124] If the certificate is not valid, the service provision control unit 402 notifies the employees of the service provider or the like to that effect. For example, the service provision control unit 402 displays a message to that effect on a liquid crystal monitor or outputs it from a speaker.

[0125] If the certificate is valid, the service provision control unit 402 notifies the service provider (employees of the service provider or the like) that the presented certificate is valid. Alternatively, the service provision control unit 402 determines the validity, effectiveness, etc. of the presented certificate as necessary. For example, the service provision control unit 402 verifies the signature attached to the student ID and the expiration date of the student ID.

[0126] Regarding individual service provision, detailed explanations regarding necessary certificates and the verification of certificates are omitted. This is because the detailed explanations regarding the verification of certificates and the like are different from the gist of the disclosure of this application.

[0127] The storage unit 403 is a means for storing information necessary for the operation of the business operator terminal 20.

[0128] [Operation of the System] Subsequently, the operation of the information processing system according to the first embodiment will be described.

[0129] FIG. 14 is a sequence diagram showing an example of the operation of the information processing system according to the first embodiment. With reference to FIG. 14, the operation of the information processing system according to the first embodiment will be described. Note that the description of the operation of the information processing system regarding the authentication of the user at the time of opening the digital wallet and the issuance of certificates is omitted.

[0130] The terminal 30 displays a two-dimensional barcode in which the certificate selected by the user and the biometric information are converted in accordance with the operation of the user (step S01).

[0131] The business operator terminal 20 reads the two-dimensional barcode in accordance with the operation of an employee or the like of the service provider (step S02).

[0132] Also, the business operator terminal 20 acquires biometric information from the user in front in accordance with the operation of an employee or the like of the service provider (step S03). For example, the business operator terminal 20 photographs the user in front and acquires a face image.

[0133] The business operator terminal 20 executes a collation process using the biometric information obtained from the two-dimensional barcode and the biometric information of the user in front (step S04).

[0134] When the collation process is successful, the business operator terminal 20 notifies an employee or the like of the service provider that the certificate presented by the user is valid (step S05). The employee or the like of the service provider who receives the notification provides the service to the user.

[0135] Next, a modification of the first embodiment will be described.

[0136] <Modification 1> In the above embodiment, the two-dimensional barcode is generated using the certificate and the biometric information stored inside the digital wallet, and the case where the two-dimensional barcode is provided to the service provider for identity verification has been described. Here, a certificate may also be issued from the certificate issuer for the biometric information. Specifically, the user requests the certificate issuer to issue a certificate for the biometric information, and stores the issued certificate in the digital wallet. When receiving the service, the user provides the service provider with the certificate for the biometric information. The service provider may perform identity verification using the provided certificate. For example, a certificate for the face, that is, a face VC, is issued from the certificate issuer as a Verifiable Credential (VC). Specifically, the user provides the face information to the issuer and requests the issuance of a face VC. The issuer compares the presented face with the stored face information, and if they match, issues a face VC. The user provides the issued face VC to the service provider, and the service provider performs identity verification using the face VC.

[0137] <Issuance of Certificate> The user acquires digital content to be stored in the digital wallet. For example, the user operates the terminal 30 to request the certificate issuer to issue a certificate. For example, a student requests (demands) the issuance of a student ID and a face VC from the university to which the student belongs. Specifically, the digital wallet application requests the university to which the student belongs to issue a student ID and a face VC. Note that an external contractor commissioned by the university may issue the face VC.

[0138] The terminal 30 transmits a "certificate issuance request" including information for identifying the user (e.g., name, combination of name and date of birth, student ID number, etc.) and biometric information to the server device 10 of the certificate issuer.

[0139] The certificate issuer determines whether the user who requests the issuance of a certificate has the authority (qualification) to receive the issuance of the certificate. For example, the server device 10 determines whether the student who wishes to obtain a student ID card and a face VC is enrolled in the university, and whether the biometric information presented by the student matches the biometric information held by the university.

[0140] If the student belongs to the university and the biometric information matches, the server device 10 issues a student ID card (digital student ID card) and a face VC. The server device 10 issues a signed certificate of its own organization (certificate issuer; for example, a university). The server device 10 transmits the issued signed certificate to the terminal 30.

[0141] The terminal 30 (digital wallet application) verifies the signature of the received certificate.

[0142] If the signature verification is successful, the terminal 30 obtains basic information (name, gender, date of birth, address) and biometric information from the received certificate. That is, the terminal 30 obtains the basic information and biometric information regarding the certificate holder of the obtained certificate. The terminal 30 compares the basic information and biometric information obtained from the identity certificate (root of trust) at the initial startup of the digital wallet application with the basic information and biometric information obtained from the certificate generated by the certificate issuer.

[0143] In the above example, the terminal 30 compares the basic information obtained from the My Number card with the basic information obtained from the student ID card. Similarly, the terminal 30 compares the biometric information obtained from the My Number card with the biometric information obtained from the face VC. If the basic information and biometric information obtained from two different media match, the terminal 30 determines that the verification is successful.

[0144] When the terminal 30 successfully verifies the signature attached to the certificate and also successfully matches (the two basic information and the biometric information match) using the two basic information and the biometric information, it accepts the certificate received from the certificate issuer. The terminal 30 stores the certificate (for example, a student ID and a face VC) obtained from the certificate issuer internally and manages it so that it can be used in the digital wallet. In the above, the case where the face VC is applied for and issued at the same timing as other certificates has been described. The face VC may be issued at a different timing from other certificates. The user provides the previously obtained face-attached certificate in the digital wallet to the certificate issuer and requests the issuance of the face VC. The certificate issuer collates the face information in the certificate presented by the user with the face information it holds, and if they match, issues the face VC.

[0145] <Usage of Certificate> The user presents the certificate required by the service provider to the service provider. For example, a student who wants to purchase a commuter pass presents a student ID and a face VC to the railway company.

[0146] For example, the user operates the terminal 30 to launch the digital wallet application. The user selects the certificates (for example, a student ID and a face VC) specified by the service provider on the digital wallet application.

[0147] The terminal 30 displays the certificates (for example, a student ID and a face VC) selected by the user.

[0148] The user presents the terminal 30 displaying the student ID and the face VC to the service provider (such as a railway company employee, etc.).

[0149] The service provider (such as an employee of the service provider) operates the business operator terminal 20 to read the presented student ID and face VC. Also, the service provider operates the business operator terminal 20 to obtain the biometric information of the user in front (the user presenting the certificate). For example, the service provider operates the business operator terminal 20 to photograph the user in front and obtains a face image.

[0150] The business operator terminal 20 acquires the biometric information of users who hope to obtain face VC and services.

[0151] The business operator terminal 20 performs collation processing (authentication processing) using the biometric information obtained from the face VC and the biometric information of the user in front. When the authentication processing (one-to-one authentication) is successful, the business operator terminal 20 treats the presented certificate as a legitimate certificate issued to the user in front.

[0152] The business operator terminal 20 notifies the service provider (such as the staff of the service provider) that the presented certificate is legitimate. Alternatively, the business operator terminal 20 determines the legitimacy, validity, etc. of the presented certificate as needed. For example, the business operator terminal 20 verifies the signature attached to the student ID and the expiration date of the student ID. The business operator terminal 20 notifies the service provider of the verification result.

[0153] When a certificate necessary for the service provider to provide services to the user is presented, the service provider provides services to the user. In the above example, the staff of the railway company sells discounted monthly passes to students.

[0154] <Modification Example 2> The collation processing of biometric information required when the service provider provides services to the user may be performed on the user's terminal 30. In this case, the usage control unit 213 of the terminal 30 executes a second authentication process using the biometric information of the digital wallet account holder and the biometric information of the user, and when the second authentication process is successful, uses the certificate stored in the digital wallet.

[0155] For example, the attendance confirmation of classes at a university may be performed on the terminal 30. In this case, when a student receives service from the university (when attending a university class), the usage control unit 213 of the terminal 30 executes an authentication process using the biometric information of the digital wallet account holder and the biometric information of the student. When the usage control unit 213 succeeds in the authentication process, it determines whether the student has the right to receive the class using the student ID stored in the digital wallet.

[0156] A device that emits a beacon is installed in the classroom of the university. The beacon transmitting device transmits a beacon including a management number corresponding to the class conducted in the classroom.

[0157] When the terminal 30 receives the beacon emitted by the beacon transmitting device, it activates the usage control unit 213. The usage control unit 213 photographs the user (the owner of the device itself). The usage control unit 213 executes a collation process using the biometric information stored in the digital wallet (the biometric information of the digital wallet account holder) and the biometric information obtained by photographing the owner.

[0158] When the usage control unit 213 succeeds in the collation process, it determines that the user operating the device itself is the account holder of the digital wallet. If the user is the account holder of the digital wallet (if the authenticity of the user is confirmed), the usage control unit 213 determines whether the user has the qualification to receive the class conducted in the classroom based on the student ID stored in the digital wallet.

[0159] The usage control unit 213 identifies the class (class name) being conducted in the classroom from the management number transmitted by the beacon transmitting device, and determines whether the student has the qualification to receive the class based on the information such as the department described in the student ID. If the student has the qualification to receive the class, the usage control unit 213 notifies a server (for example, the server device 10) managed by the university of the student's class attendance. That is, if the student has the qualification to receive the class, the usage control unit 213 notifies the university of the student's situation as "class attendance".

[0160] When the verification process fails, the control unit 213 determines that the student attempting to attend the class is not the owner of the terminal 30 (the person in the name of the digital wallet), and instructs the user to leave the room. Also, when the usage control unit 213 determines that the user does not have the qualification to participate in the class, it instructs the user to leave the room.

[0161] Note that the usage control unit 213 may perform the above authentication process and verification of the authority regarding class participation even when it detects a predetermined operation of the user (for example, pressing the attendance button) without relying on the reception of the beacon. Alternatively, the terminal 30 may estimate the current position of the user using GPS (Global Positioning System). The terminal 30 may activate the usage control unit 213 when it is determined that the user has entered the classroom. Thereafter, the usage control unit 213 may determine whether the user has the qualification to take the class held in the classroom based on the student ID stored in the digital wallet.

[0162] Alternatively, the attendance confirmation may be performed using the business operator terminal 20 prepared by the university. A tablet-type business operator terminal 20 or a kiosk-type business operator terminal 20 may be installed at the entrance of the classroom, and the business operator terminal 20 may execute the acquisition of the certificate and the verification process of the biometric information. That is, the terminal 30 transmits information regarding the face image and the student ID to the business operator terminal 20 installed at the entrance of the classroom. The business operator terminal 20 may execute a verification process using the face image captured by the user in front and the face image acquired from the terminal 30.

[0163] In this way, when the usage control unit 213 receives a beacon from the beacon transmission device installed in the classroom of the educational institution, it executes the second authentication process. When the usage control unit 213 succeeds in the second authentication process, it determines whether the user has the qualification to take the class held in the classroom based on the student ID stored in the digital wallet.

[0164] <Modification Example 3> Between the terminal 30 and the operator terminal 20, a plurality of digital contents may be transmitted and received. For example, when a user enters a facility such as a museum, a student ID indicating that the user is a student and a coupon that can receive a predetermined discount may be provided to the operator terminal 20. In this case, the terminal 30 may display a two-dimensional barcode obtained by converting the digital content (student ID, coupon) designated by the user and the biometric information. Note that the user may specify the digital content to be presented to the service provider based on the information provided by the service provider or the like. Alternatively, when the user receives a predetermined service, the terminal 30 may automatically specify the digital content.

[0165] When the operator terminal 20 succeeds in the collation process using the face image obtained by photographing the user in front and the face image obtained from the terminal 30, it determines that the obtained student ID is valid. In this case, the user can receive a student discount. Also, if the coupon obtained from the terminal 30 is valid, the operator terminal 20 gives a discount according to the coupon (notifies the employees of the service provider or the like that the coupon is valid).

[0166] In this way, tablets or kiosk terminals installed at the entrance of the facility or the like may confirm the validity of a student ID or the like by biometric authentication. The operator terminal 20 prevents users other than students from using the student discount.

[0167] <Modification Example 4> In the above embodiment, it has been described that the certificate and the biometric information are transmitted and received between the terminal 30 and the operator terminal 20 using a two-dimensional barcode. The certificate and the biometric information may be transmitted and received between the terminal 30 and the operator terminal 20 using short-range wireless communication means such as Bluetooth (registered trademark) or NFC (Near Field Communication). Alternatively, the certificate and the biometric information may be transmitted and received between the terminal 30 and the operator terminal 20 using mobile communication means such as 4G (4th Generation) or 5G (5th Generation) or wireless LAN (Local Area Network) such as Wi-Fi (Wireless Fidelity).

[0168] In this case, the usage control unit 213 of the terminal 30 transmits the certificate (signed certificate) selected by the user and the biometric information of the digital wallet holder to the business operator terminal 20 using the short-range wireless communication means.

[0169] When the service provision control unit 402 of the business operator terminal 20 receives the certificate and the biometric information, it acquires the biometric information of the user in front. Then, as described in the first embodiment, the service provision control unit 402 performs biometric authentication using the two biometric information.

[0170] <Modification Example 5> In the above embodiment, the case where the certificate (digital content) issued by the certificate issuer is stored in the digital wallet of the terminal 30 has been described. The certificate (digital content) may be issued and verified as an NFT (Non Fungible Token) or a VC (Verifiable Credential) using a blockchain. Specifically, the certificate issuer registers the transaction information obtained by issuing the NFT or VC in the blockchain, and the service provider verifies the reliability of the certificate using the transaction information recorded in the blockchain.

[0171] The user's terminal 30 requests the certificate issuer (server device 10) to issue a certificate (certificate issuance request; step S11 in FIG. 15).

[0172] When the server device 10 (certificate issuance unit 302) receives a certificate issuance request from the terminal 30, it generates a signed certificate. The server device 10 of the certificate issuer issues an NFT or a VC for the generated signed certificate (certificate issuance; step S12).

[0173] In addition, the server device 10 of the certificate issuer registers the transaction information obtained by issuing the NFT or VC in the blockchain (step S13). The transaction information includes the issuer ID, public key, etc.

[0174] The terminal 30 (certificate acquisition control unit 212) stores the received certificate in the digital wallet. For example, when a student requests the university to issue a student ID using the terminal 30 they possess, the VC or NFT of the student ID is stored in the digital wallet. Transaction information (issuing university ID, public key, etc.) related to the student ID is stored in the blockchain.

[0175] When the terminal 30 (usage control unit 213) selects the certificate used by the user, it provides the selected certificate and the biometric information of the digital wallet account holder to the service provider. The terminal 30 provides the certificate and biometric information to the business operator terminal 20 of the service provider using a two-dimensional barcode, short-range wireless communication means, etc. (certificate presentation; step S14).

[0176] The business operator terminal 20 of the service provider (service provision control unit 402) verifies the reliability of the received certificate using the transaction information recorded in the blockchain (certificate verification; step S15). The business operator terminal 20 verifies that the certificate has not been tampered with and that it is issued by a reliable issuer using the transaction information obtained from the blockchain. Also, the business operator terminal 20 acquires biometric information by photographing the user in front of it.

[0177] The business operator terminal 20 performs authentication processing using the biometric information acquired from the terminal 30 and the biometric information acquired from the user in front of it. When the verification of the reliability of the certificate and the authentication of the user are successful, the business operator terminal 20 provides the service to the user (service provision; step S16).

[0178] As described above, when opening a digital wallet, the terminal 30 according to the first embodiment uses a reliable certificate issued by a public institution such as a My Number card as the root of trust. The terminal 30 performs identity verification using the biometric information obtained from the certificate (root of trust) and the biometric information of the digital wallet opener. The terminal 30 ensures that the digital wallet opener and the digital wallet nominee are the same through this identity verification (authentication process using two biometric information). With such a configuration, for example, it is impossible for others to open a digital wallet by forging the nominee (it is impossible to open a digital wallet using someone else's certificate). Also, the service provider verifies that the user using the digital wallet through biometric authentication matches the digital wallet nominee. If the digital wallet user does not match the digital wallet nominee, the service provider does not trust the certificate provided by the digital wallet. That is, it is ensured that the service user matches the digital wallet nominee (the authenticity regarding the match between the service user and the digital wallet nominee is ensured). In this way, by also performing an authentication process at the service provider, after the digital wallet is activated, it is possible to prevent the situation where the user hands over the terminal 30 to others and the others use the digital wallet certificate. Also, after biometric authentication by the service provider, the certificate stored in the digital wallet is used for student discount applications, attendance management, etc.

[0179] Also, when the terminal 30 obtains a certificate from the certificate issuer, it performs a comparison using the basic information obtained from the identity certificate and the basic information obtained from the certificate. Through this comparison, the terminal 30 verifies (confirms) that the issued certificate is not a certificate issued to someone other than the digital wallet nominee. Since the certificate that has successfully passed this verification is stored in the digital wallet, the authenticity of the digital wallet is ensured, and the authenticity of the digital content (certificate) provided from the digital wallet is also ensured.

[0180] Next, the hardware of each device constituting the information processing system will be described. FIG. 16 is a diagram showing an example of the hardware configuration of the terminal 30.

[0181] The terminal 30 can be configured by an information processing device (so-called computer) and has the configuration illustrated in FIG. 16. For example, the terminal 30 includes a processor 311, a memory 312, an input / output interface 313, a communication interface 314, and the like. The components such as the processor 311 are connected by an internal bus or the like and are configured to be communicable with each other.

[0182] However, the configuration shown in FIG. 16 is not intended to limit the hardware configuration of the terminal 30. The terminal 30 may include hardware not shown, or may not include the input / output interface 313 as necessary. Also, the number of components such as the processor 311 included in the terminal 30 is not intended to be limited to the example shown in FIG. 16. For example, a plurality of processors 311 may be included in the terminal 30.

[0183] The processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or a DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs including an operating system (OS; Operating System).

[0184] The memory 312 is a RAM (Random Access Memory), a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), or the like. The memory 312 stores an OS program, an application program, and various data.

[0185] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display or the like. The input device is a device that receives user operations such as a keyboard and a mouse.

[0186] The communication interface 314 is a circuit, a module, or the like that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card) or the like.

[0187] The functions of the terminal 30 are realized by various processing modules. The processing modules are realized, for example, when the processor 311 executes a program stored in the memory 312. Further, the program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory one such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. Further, the above program can be downloaded via a network or updated using a storage medium storing the program. Furthermore, the above processing module may be realized by a semiconductor chip.

[0188] Note that the server device 10, the business operator terminal 20, etc. can also be configured by an information processing device in the same manner as the terminal 30, and the basic hardware configuration is the same as that of the terminal 30, so the description thereof is omitted.

[0189] The terminal 30, which is an information processing device, is equipped with a computer, and the functions of the terminal 30 can be realized by causing the computer to execute a program. Further, the terminal 30 executes a control method of the terminal 30 according to the program. Similarly, the server device 10 is equipped with a computer, and the functions of the server device 10 can be realized by causing the computer to execute a program. Further, the server device 10 executes a control method of the server device 10 according to the program.

[0190] [Modification Example] Note that the configuration, operation, etc. of the information processing system described in the above embodiment are examples, and are not intended to limit the configuration of the system or the like.

[0191] When the terminal 30 collates the basic information (e.g., name, gender, date of birth, address) obtained from the identity certificate with the basic information obtained from the certificate, it may consider variations in the notation of each item constituting the basic information. For example, the terminal 30 may calculate the degree of match between the two pieces of basic information as a collation score in consideration of variations in the notation of the name and address. For example, the terminal 30 may obtain the degree of match between the two pieces of basic information using a learning model obtained by machine learning. The terminal 30 may perform threshold processing on the obtained degree of match (collation score), and if the collation score is equal to or less than a predetermined value, the obtained certificate may be discarded.

[0192] In the above embodiment, the case where identity verification (verifying the match between the name of the identity certificate and the digital wallet account opener) is performed using biometric information obtained from the identity certificate has been described. However, the identity verification may be performed using the electronic certificate stored in the identity certificate. Specifically, the terminal 30 obtains electronic certificates (electronic signature certificate, user authentication electronic certificate) from the My Number card held by the user. The terminal 30 transmits the obtained electronic signature certificate to the certification authority (J-LIS; Japan Agency for Local Authority Information Systems) and requests the certification authority to verify the validity of the electronic certificate. If the electronic certificate is valid, the terminal 30 determines that the identity verification has been successful.

[0193] When opening a digital wallet, the terminal 30 may set an expiration date (valid period) for the opened digital wallet. The terminal 30 may set the expiration date of the digital wallet according to the identity certificate used for identity verification and the expiration date of the identity certificate. For example, when a passport valid for 5 years is used for identity verification, the terminal 30 sets the valid period of the digital wallet to 5 years. Alternatively, when a passport valid for 10 years or a My Number Card valid for 10 years is used for identity verification, the terminal 30 sets the valid period of the digital wallet to 10 years. Alternatively, the terminal 30 may set different valid periods for the digital wallet when a passport is used for identity verification and when a My Number Card is used for identity verification. Alternatively, the terminal 30 may determine the expiration date of the digital wallet according to the remaining valid period of the identity certificate instead of the expiration date at the time of issuance of the identity certificate. For example, when an identity certificate with a remaining period of 3 years is used for identity verification, the terminal 30 sets the expiration date of the digital wallet to 3 years. When an identity certificate with a remaining period of 5 years is used for identity verification, the terminal 30 sets the expiration date of the digital wallet to 5 years.

[0194] Alternatively, the terminal 30 may set a limit on the number of times the digital wallet can be used. For example, when the terminal 30 detects that the digital wallet has been activated more than a predetermined number of times within a predetermined period, it determines that the digital wallet has been misused by the user. In this case, the terminal 30 does not activate the digital wallet and prohibits the user from using the digital wallet.

[0195] When the terminal 30 presents the biometric information and certificate of the digital wallet account holder to the service provider, some information may be presented to the service provider by means other than the two-dimensional barcode. For example, as shown in FIG. 17, the terminal 30 may display a two-dimensional barcode obtained by converting a face image (biometric information) and a certificate or the like on the same screen. Alternatively, the terminal 30 may display a face image and a two-dimensional barcode obtained by converting the face image and the certificate on the same screen. An employee of the service provider may perform identity verification of the user by using the face of the user presenting the certificate and the face image displayed on the terminal 30.

[0196] In Modification 1 of the First Embodiment 1, taking the case where a student attends a class held at a university as an example, the case where the collation process of biometric information required when the service provider provides a service to the user is executed on the user's terminal 30 was described. However, the collation process may be performed on the user's terminal 30 other than for attendance confirmation of classes held at a university. That is, when the collation process of the face image obtained by photographing and the pre-registered face is successful on the terminal 30 possessed by the user, the terminal 30 issues (displays) a two-dimensional barcode including "successful face authentication" and "corresponding certificate information". The operator terminal 20 may read the issued two-dimensional barcode and obtain information such as a certificate necessary for performing identity verification and providing a service. In this case, on the operator terminal 20, the collation process using the face image and photographing (acquisition of the face image) of the user are not necessary. Therefore, the operator terminal 20 only needs to be equipped with a barcode reader and does not need a camera. In order to prevent the use by a user who is not the digital wallet account holder, the terminal 30 may perform a display as shown in FIG. 17 (displaying a two-dimensional barcode and a face image on the same screen). That is, by visually verifying the identity by an employee of the service provider or the like, after the identity verification is completed, it is possible to prevent fraud such that the terminal 30 is handed from the digital wallet account holder to another person and the terminal 30 is presented to the service provider.

[0197] In addition, when the biometric information verification process necessary for the service provider to provide services to the user is executed on the user's terminal 30, the terminal 30 may limit the display of the two-dimensional barcode for a predetermined time. For example, the terminal 30 may be able to display the two-dimensional barcode only within a predetermined time after successful biometric authentication.

[0198] Some functions of the terminal 30 may be implemented in another device, apparatus, etc. More specifically, as long as any of the devices included in the system implements the "identity verification unit (identity verification means)", "certificate acquisition control unit (certificate acquisition control means)", etc. described above.

[0199] The form of data transmission and reception between each device (for example, the server device 10, the terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Between these devices, the user's personal information, etc. is transmitted and received, and in order to appropriately protect this information, it is desirable that encrypted data is transmitted and received.

[0200] In the flowcharts (flowcharts, sequence diagrams) used in the above description, a plurality of steps (processes) are described in order, but the execution order of the steps executed in the embodiment is not limited to the order of the description. In the embodiment, for example, each process can be executed in parallel, and the order of the illustrated steps can be changed within a range that does not substantially affect the content.

[0201] The above embodiments have been described in detail for the purpose of facilitating the understanding of the disclosure of the present application, and it is not intended that all the configurations described above are necessary. In addition, when a plurality of embodiments are described, each embodiment may be used alone or in combination. For example, it is also possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace other configurations for a part of the configuration of the embodiment.

[0202] From the above description, the industrial applicability of the present invention is clear. However, the present invention is preferably applicable to an information processing system including a service provider that provides services to users using certificates stored in a digital wallet.

[0203] Some or all of the above embodiments may be described as follows in the appended claims, but are not limited thereto. [Appended Claim 1] Identity verification means for performing identity verification of the person opening the digital wallet using biometric information obtained from an identity certificate and biometric information of the person opening the digital wallet. Storage means for storing, as biometric information of the digital wallet nominee, the biometric information obtained from the identity certificate or the biometric information of the person opening the digital wallet when the identity verification is successful. A terminal comprising the above. [Appended Claim 2] The terminal according to Appended Claim 1, wherein the identity verification means determines that the identity verification is successful when the first authentication process using the biometric information obtained from the identity certificate and the biometric information of the person opening the digital wallet is successful. [Appended Claim 3] The terminal according to Appended Claim 2, further comprising certificate acquisition control means for receiving the certificate from the certificate issuer by requesting the certificate issuer to issue the certificate, and storing the received certificate in the digital wallet when the basic information regarding the nominee of the identity certificate obtained from the identity certificate matches the basic information regarding the nominee of the received certificate obtained from the received certificate. [Appended Claim 4] The terminal according to Appended Claim 3, further comprising usage control means for providing the certificate stored in the digital wallet and the biometric information of the digital wallet nominee to the service provider when the user receives a service from the service provider. [Appended Claim 5] When a user receives a service from a service provider, a second authentication process is executed using the biometric information of the digital wallet holder and the biometric information of the user. When the second authentication process is successful, the certificate stored in the digital wallet is used. The terminal according to Supplementary Note 3 further includes usage control means. [Supplementary Note 6] The usage control means When receiving a beacon from a beacon transmitter installed in a classroom of an educational institution, the second authentication process is executed. When the second authentication process is successful, it is determined whether the user is eligible to take the class conducted in the classroom based on the student ID stored in the digital wallet. The terminal according to Supplementary Note 5. [Supplementary Note 7] The identity certificate is a My Number card or a passport. The terminal according to any one of Supplementary Notes 1 to 6. [Supplementary Note 8] The biometric information is a face image or a feature amount generated from the face image. The terminal according to Supplementary Note 7. [Supplementary Note 9] A terminal, An operator terminal used when a service provider provides a service to a user, including The terminal Performs identity verification of the person opening the digital wallet using the biometric information obtained from the identity certificate and the biometric information of the person opening the digital wallet. Identity verification means, When the identity verification is successful, the biometric information obtained from the identity certificate or the biometric information of the person opening the digital wallet is stored as the biometric information of the digital wallet holder. Storage means, Usage control means for providing the content stored in the digital wallet and the biometric information of the digital wallet holder to the operator terminal, A system comprising. [Supplementary Note 10] In the terminal, Verify the identity of the person opening the digital wallet using the biometric information obtained from the identity certificate and the biometric information of the person opening the digital wallet, When the identity verification is successful, store the biometric information obtained from the identity certificate or the biometric information of the person opening the digital wallet as the biometric information of the digital wallet holder, a method for controlling a terminal. [Appendix 11] On the computer installed in the terminal, Execute a process of verifying the identity of the person opening the digital wallet using the biometric information obtained from the identity certificate and the biometric information of the person opening the digital wallet, When the identity verification is successful, execute a process of storing the biometric information obtained from the identity certificate or the biometric information of the person opening the digital wallet as the biometric information of the digital wallet holder, A computer-readable storage medium that stores a program for causing the above to be executed.

[0204] It should be noted that each disclosure of the above-cited prior art documents is incorporated herein by reference. As described above, the embodiments of the present invention have been described, but the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications can be made without departing from the scope and spirit of the present invention. That is, the present invention naturally includes all disclosures including the claims, various modifications and corrections that can be made by those skilled in the art according to the technical idea.

Explanation of Signs

[0205] 10 Server device 20 Operator terminal 30 Terminal 100 Terminal 101 Identity verification means 102 Storage means 201 Communication control unit 202 Digital wallet control unit 203 Storage unit 211 Personal confirmation section 212 Certificate acquisition control section 213 Usage control section 301 Communication control section 302 Certificate issuance section 303 Memory section 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 401 Communication control section 402 Service provision control section 403 Memory section

Claims

1. An identity verification unit that verifies the identity of a user who opens a digital wallet by using biometric information obtained from an identification card and the biometric information of the user who opens the digital wallet; a storage unit that stores a plurality of digital contents of the user and biometric information of the user whose identity verification has been determined to be successful; a transmission unit that transmits, when the user receives a service from a service provider, one or more digital contents included in the plurality of stored digital contents and the stored biometric information to an information processing device of the service provider. Terminal.

2. An identity verification unit that verifies the identity of a user who opens a digital wallet by using biometric information obtained from an identification card and the biometric information of the user who opens the digital wallet; a storage unit that stores a plurality of digital contents of the user and biometric information of the user whose identity verification has been determined to be successful; an authentication unit that executes an authentication process using the stored biometric information and the biometric information of the user when the user receives a service from a service provider; a transmission unit that transmits one or more digital contents included in the plurality of stored digital contents to the information processing device of the service provider when the authentication process is successful. Terminal.

3. The digital content includes at least one of a certificate, electronic money, ticket information, and coupon information related to the user. A terminal according to claim 1 or 2.

4. A terminal as described in claim 1 or 2, wherein the memory unit stores biometric information obtained from the identification card or biometric information of a user opening the digital wallet.

5. A terminal as described in claim 1 or 2, further comprising an acquisition means for receiving a certificate from a certificate issuer by requesting the certificate issuer to issue the certificate, and storing the received certificate in the digital wallet as the digital content if basic information about the certificate holder obtained from the identification card matches basic information about the certificate holder obtained from the received certificate.

6. A method for verifying the identity of a user who opens a digital wallet using biometric information obtained from an identification card and biometric information of the user who opens the digital wallet; storing the plurality of digital contents of the user and the biometric information of the user whose identity verification has been determined to be successful; When the user receives a service from a service provider, the user transmits one or more digital contents included in the plurality of stored digital contents and the stored biometric information to an information processing device of the service provider. How to control the device.

7. A method for verifying the identity of a user who opens a digital wallet using biometric information obtained from an identification card and biometric information of the user who opens the digital wallet; storing the plurality of digital contents of the user and the biometric information of the user whose identity verification has been determined to be successful; When the user receives a service from a service provider, an authentication process is executed using the stored biometric information and the biometric information of the user; If the authentication process is successful, transmitting one or more digital contents included in the stored plurality of digital contents to the information processing device of the service provider. How to control the device.

8. The computer installed in the terminal A process of verifying the identity of a user who opens a digital wallet using biometric information obtained from an identification card and biometric information of the user who opens the digital wallet; A process of storing a plurality of digital contents of the user and biometric information of the user whose identity verification has been determined to be successful; a process of transmitting, when the user receives a service from a service provider, one or more digital contents included in the plurality of stored digital contents and the stored biometric information to an information processing device of the service provider; A program that executes the following.

9. A computer installed in a terminal, A process of verifying the identity of a user who opens a digital wallet using biometric information obtained from an identification card and biometric information of the user who opens the digital wallet; A process of storing a plurality of digital contents of the user and biometric information of the user whose identity verification has been determined to be successful; an authentication process using the stored biometric information and the biometric information of the user when the user receives a service from a service provider; a process of transmitting one or more digital contents included in the plurality of stored digital contents to an information processing device of the service provider when the authentication process is successful; A program that executes the following.

Citation Information

Patent Citations

  • Unionpay card registration electronic wallet and payment method, terminal, equipment and medium

    CN112258177A

  • Individual authentication system, individual authenticating method, information processing device and program providing medium

    JP2002077147A

  • Server computer for service providing system on web and program for the system

    JP2003030560A

  • Attribute warrant management method and device

    JP2003345930A

  • Electronic ticket vending system and method

    JP2004295197A