Display system, display method, and program

The display system simplifies attribute verification by integrating digital and physical methods on a user terminal, ensuring authenticity through displayed proof information, addressing the need for separate card presentation.

JP7716060B1Active Publication Date: 2025-07-31POCKET SIGN CO LTD
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
JP2024164413
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-09-20
Publication Date
2025-07-31
Estimated Expiration
2044-09-20

AI Technical Summary

Technical Problem

Users often need to present physical identity verification cards in addition to digital authentication, complicating the process of proving their attributes for various services.

Method used

A display system and method that utilizes a user terminal to display proof information, including a user's face photo, proof information, and provider information, generated to ensure authenticity, using a user information acquisition unit, proof information acquisition unit, and display control unit to manage and present this information.

Benefits of technology

Simplifies the process of proving user attributes by integrating digital and physical verification methods, ensuring authenticity and reducing the need for separate physical card presentation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007716060000001_ABST
    Figure 0007716060000001_ABST
Patent Text Reader

Abstract

A display system and the like are provided that suitably displays information for verifying a user's attributes. [Solution] In a display system 110, a user information acquisition unit 111 acquires image data of a user's facial photograph officially certified by an institution related to a national or local government, linking it with user information of the user authenticated by an authentication organization of a public personal authentication service. A certification information acquisition unit 112 acquires information to display as certification information from an information management device that manages related information related to the user. A provider information acquisition unit 113 acquires provider information regarding the provider of the certification information from the information management device. A certification image generation unit 114 generates a certification image to certify that the image displayed on the user terminal is authentic. A display control unit 115 displays the facial photograph, certification information, provider information, and certification image on the display unit of the user terminal.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a display system, a display method, and a program. [Background technology]

[0002] IC cards that can be used for identity verification and various services such as local government services are becoming widespread. For example, My Number cards store digital certificates and applications (APs) that can be used not only by local governments but also by private businesses. In addition, technology has been proposed that allows information stored on identity verification cards such as My Number cards to be retrieved and used by user devices such as mobile devices.

[0003] For example, in the technology described in Patent Document 1, after receiving authentication information input into a user terminal, a reading unit reads an identity verifiable medium and transmits the authentication information, and once authentication is completed, an information acquisition unit acquires information from a first information source and a second information source. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 7478404 Summary of the Invention [Problem to be solved by the invention]

[0005] However, when a user proves his or her attributes for a specific service, etc., in addition to the information acquired by the user terminal, there is a possibility that the user will have to separately present a card or the like to prove the user's attributes.

[0006] In view of the above-mentioned problems, the present disclosure aims to provide a display system and the like that suitably displays information for certifying the attributes of a user. [Means for solving the problem]

[0007] The display system according to the present disclosure causes a user terminal to display proof information for the user to prove their attributes. The display system includes a user information acquisition unit, a proof information acquisition unit, a provider information acquisition unit, a proof image generation unit, and a display control unit. The user information acquisition unit acquires the image data of the user's face photo publicly guaranteed by an organization related to a country or a local public entity, in association with the user information of the user authenticated by the authentication organization of the public personal authentication service. The proof information acquisition unit acquires information for display as proof information from an information management device that manages related information related to the user. The provider information acquisition unit acquires provider information regarding the provider of the proof information from the information management device. The proof image generation unit generates a proof image for proving that the image to be displayed on the user terminal is genuine. The display control unit causes the display unit of the user terminal to display the face photo, the proof information, the provider information, and the proof image.

[0008] In the display system that causes a user terminal to display proof information for the user to prove their attributes, the display method according to the present disclosure is executed by a computer as follows. The computer acquires the image data of the user's face photo publicly guaranteed by an organization related to a country or a local public entity, in association with the user information of the user authenticated by the authentication organization of the public personal authentication service. The computer acquires information for display as proof information from an information management device that manages related information related to the user. The computer acquires provider information regarding the provider of the proof information. The computer generates a proof image for proving that the image to be displayed on the user terminal is genuine. The computer causes the display unit of the user terminal to display the face photo, the proof information, the provider information, and the proof image.

[0009] The program according to the present disclosure causes a computer to execute the following display method in a display system that causes a user terminal to display proof information for the user to prove their attributes. The display method includes a user information acquisition step, a proof information acquisition step, a provider information acquisition step, a proof image generation step, and a display control step. The user information acquisition step acquires image data of a user's face photo guaranteed publicly by an organization related to a country or a local public entity, and associates it with the user information of the user authenticated by the authentication institution of the public personal authentication service. The proof information acquisition step acquires information for display as proof information from an information management device that manages related information related to the user. The provider information acquisition step acquires provider information regarding the provider of the proof information. The proof image generation step generates a proof image for proving that the image displayed on the user terminal is genuine. The display control step causes a display unit of the user terminal to display the face photo, the proof information, the provider information, and the proof image.

Advantages of the Invention

[0010] According to the present disclosure, it is possible to provide a display system, a display method, and a program that suitably display information for proving the attributes of a user.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

[0012] The present invention will be described below through embodiments of the invention, but the invention according to the claims is not limited to the following embodiments. Furthermore, not all of the configurations described in the embodiments are necessarily essential means for solving the problems. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Note that in each drawing, the same elements are given the same reference numerals, and duplicate explanations are omitted as necessary.

[0013] First Embodiment (Proof System 1) The configuration of the certification system 1 will be described with reference to FIG. 1. FIG. 1 is a block diagram of the certification system 1 according to the first embodiment. The certification system 1 is a system for a user using the certification system 1 to prove his / her own attributes to others. In this disclosure, the user's own attributes may also be referred to as user attributes or user attributes. The user attributes may include the user's demographic attributes or psychographic attributes. Specifically, the user attributes may include the user's gender, age, and family structure. The user attributes may include the user's address and the organization or group to which the user belongs. The user attributes may include the user's hobbies and preferences. The certification system 1 mainly includes an authentication system 10, a first business management system 40, a second business management system 50, an information management device 20, a certificate validation system 30, and a user terminal 100. These components are communicatively connected via a network N1.

[0014] The authentication system 10 cooperates with the certificate verification system 30 to authenticate a user who uses the user terminal 100. The authentication system 10 also accesses an information management device 20 that stores information related to the authenticated user (i.e., related information 21), and manages the related information 21.

[0015] The authentication system 10 is operated, for example, by a predetermined platform operator. The platform operator is, for example, a private business operator that meets certain standards related to information security, etc., and operates the authentication system 10 after receiving certification from the competent minister. In this case, the platform operator that operates the authentication system 10 is entrusted with the signature verification work for the public personal authentication service by the businesses that operate the first business management system 40 and the second business management system 50, respectively. The platform operator, for example, provides other businesses with a platform that uses the My Number card, which is the identity verification medium 200, as a means of identity verification.

[0016] The information management device 20 includes a non-volatile storage device that stores user-related information 21. The related information 21 may include the user's personal information. The related information 21 may include, for example, information called the four basic pieces of information. The four basic pieces of information are the user's name, date of birth, address, and gender. The related information 21 may also include the user's telephone number, email address, etc. The related information 21 may also include information about points that the user can use in a specific area, the user's occupation, and family composition. The related information 21 may also include information about medicines or cosmetics that the user uses. The related information 21 may also be referred to as user-related information 21.

[0017] The related information 21 includes management information for managing the information about the user described above. The management information includes information about the access rights and item types corresponding to each item of the information about the user. That is, the information management device 20 manages the information about the user based on the defined management information.

[0018] The information management device 20 accepts access from the authentication system 10, the first business management system 40, and the second business management system 50. The information management device 20 stores the related information 21 in a manner that allows the authentication system 10, the first business management system 40, and the second business management system 50 to read and write at least a portion of the related information 21. At this time, the information management device 20 controls access from the authentication system 10, the first business management system 40, and the second business management system 50 based on the above-mentioned management information.

[0019] The information management device 20 may be a so-called cloud storage or cloud server. The information management device 20 can also be referred to as a common data infrastructure for managing related information 21 accessible by the authentication system 10, the first business management system 40, and the second business management system 50. In the present disclosure, the common data infrastructure may also be referred to as a registry.

[0020] The certificate verification system 30 is a system that verifies that the authentication procedure performed by the user using the user terminal 100 is genuine. For example, the certificate verification system 30 receives information about the user transmitted by the user terminal 100 and verifies that this information is genuine. Specifically, the certificate verification system 30 performs verification processing by, for example, comparing the information corresponding to the user's authentication stored in advance with the information provided from the user terminal 100. The information provided from the user terminal 100 may include, for example, signature information or key information. The certificate verification system 30 feeds back the result of the verification to at least one of the user terminal 100 or the authentication system 10.

[0021] The certificate verification system 30 may, for example, perform authentication of a public personal authentication service operated by a local public entity information system organization (J-LIS). The public personal authentication service is a means of identity verification used when conducting administrative procedures such as online applications and notifications using the Internet. The authentication authority of the public personal authentication service authenticates users who use the public personal authentication service. That is, the certificate verification system 30, as the authentication authority of the public personal authentication service, receives information to be authenticated from a predetermined organization such as a local government and answers whether the received information is valid. The information to be authenticated is, for example, an electronic certificate. Note that the public personal authentication service is used not only for procedures by the state or local governments but also for procedures by private businesses. For example, the operator operating the authentication system may be a local government or a private business. Similarly, the first business operator managing the first business management system 40 may be a local government or a private business. The second business operator managing the second business management system 50 may be a local government or a private business.

[0022] The first business management system 40 is a system managed by a first business operator that provides a first service to a user via a user terminal 100. The first business management system 40 is a system using a computer, a server, or the cloud. The first business management system 40 provides the first service to the user by using at least a part of the related information 21 stored in the information management device 20.

[0023] The second business management system 50 is a system managed by a second business operator that provides a second service to a user via a user terminal 100. The second business management system 50 is a system using a computer, a server, or the cloud. The second business management system 50 provides the second service to the user by using at least a part of the related information 21 stored in the information management device 20.

[0024] The first service and the second service are, for example, point services related to stores used by the user. Also, the first service and the second service may be services related to a predetermined organization to which the user belongs. The first service and the second service may be information providing services related to disaster prevention, or services for managing information on medicines used by the user. Also, the first service and the second service may be administrative services of the local government where the user lives.

[0025] The first business management system 40 and the second business management system 50 can provide the above-described services via an application installed on the user terminal 100. The application may be dedicated application software, a web application that can be used via a browser, or the website itself.

[0026] The first operator and the second operator who operate the first business management system 40 and the second business management system 50 respectively may be referred to as service provider operators. When providing the services they each operate to users, the service provider operators use the authentication of users using the personally identifiable medium 200 as a means of personal identification. Also, the platform operator and the service provider operator can appropriately use the information stored in the information management device 20 under certain conditions.

[0027] The user terminal 100 is a mobile terminal used by a user who desires to prove their own attributes using the proof system 1. The user terminal 100 is, for example, a smartphone, a tablet terminal, a mobile phone, a notebook PC, or the like. The user terminal 100 may be a wearable device such as a smartwatch having a communication function and a display unit. The user terminal 100 can be communicably connected to each component of the proof system 1 via the network N1.

[0028] The user terminal 100 has means for reading user information and image data from the personally identifiable medium 200. The means for reading user information and image data may be, for example, short-range wireless communication such as NFC (Near Field Communication). The means for reading user information and image data may be, for example, wired communication in which the user terminal 100 and the personally identifiable medium 200 communicate by coming into contact with each other.

[0029] The above-mentioned user information is personal information of a user that can be obtained by authenticating the user. User information is information about a user that can be obtained from the identity verifiable medium 200. User information is typically information about an electronic certificate stored in the user's identity verifiable medium 200. Information about the electronic certificate may be the electronic certificate itself or the serial number of the electronic certificate. Personal information is information about a living individual that can identify a specific individual based on name, date of birth, address, facial photograph, etc. Personal information may be the four basic pieces of information or information other than these four pieces of information. User information can also be personal information that can be obtained by performing authentication using a signature electronic certificate that can be used for a public personal authentication service. Alternatively, user information may be personal information that can be obtained by using a card information input assistance application or a card information confirmation application.

[0030] The image data described above is an image of the user's face, i.e., data of the user's facial photograph. The image data stored in the identity verification medium 200 is officially certified by an institution related to a national or local government. The user terminal 100 acquires this image data and displays the acquired image data as certification information, thereby certifying the user's attributes. Note that the certification system 1 may display alternative image data different from the acquired image data instead of or in addition to the acquired image data. In this case, the alternative image data includes a facial photograph of the user. Whether the image data includes a facial photograph of the user can be determined by calculating the facial features of the user from the image data. That is, in this case, the user terminal 100 has a function to calculate the features of the facial image included in the image data. Alternatively, the user terminal 100 may have a function to extract alternative image data using a function to calculate the features of the facial image included in the image data. In this way, the user terminal 100 can extract image data including the user's facial image from image data previously stored in the user terminal 100. As a result, for example, when the image data acquired from the personal identification medium 200 is monochrome, the certification system 1 can display a color image stored in the user terminal 100. Alternatively, the certification system 1 can display image data of a facial image with a higher resolution than the image data acquired from the personal identification medium 200. The substitute image data may be stored in the information management device 20.

[0031] The identity verifiable medium 200 is a medium that stores at least user information and image data in a format that can be read by the user terminal 100. The identity verifiable medium 200 is used, for example, to verify identity in services provided by local government agencies or private businesses. More specifically, the identity verifiable medium 200 is, for example, a My Number card. The identity verifiable medium 200 may be a medium other than a My Number card, as long as it stores image data of a publicly certified face photograph of the user.

[0032] When the user terminal 100 has a function to read information on the personal identification medium 200 by NFC, it has an antenna and communication function compatible with NFC of the personal identification medium 200. When the user terminal 100 reads information on the personal identification medium 200 by a camera that reads barcodes, the personal identification medium 200 displays a barcode including user information and image data in a photographable manner.

[0033] The above describes the outline of the configuration of the certification system 1. When using the certification system 1, the user causes the user terminal 100 to display information that certifies the user's attributes (i.e., certification information). To realize the above functions, the user causes the user terminal 100 to read information from the identity verifiable medium 200. The user also causes the user terminal 100 to acquire information stored in the information management device 20. The user terminal 100 displays the information acquired from the identity verifiable medium 200 and the information management device 20 as certification information.

[0034] The above describes the outline of the configuration of the certification system 1, but the certification system 1 is not limited to the above configuration. For example, the authentication system 10 may be configured to include an information management device 20. Furthermore, the platform operator that operates the authentication system 10 and the operator that operates the first business management system 40 or the second business management system 50 may be the same entity.

[0035] (User terminal 100) Next, the configuration of the user terminal 100 will be described with reference to Fig. 2. Fig. 2 is a block diagram of the user terminal 100 including the display system 110 according to the first embodiment. The user terminal 100 has, as its main components, the display system 110, a communication unit 121, a display unit 122, an input reception unit 123, a login unit 125, and an onboarding start function unit 140.

[0036] (display system 110) The display system 110 has a function of causing the user terminal to display authentication information for the user to prove their own attributes. The display system 110 includes a user information acquisition unit 111, an authentication information acquisition unit 112, a provider information acquisition unit 113, an authentication image generation unit 114, and a display control unit 115.

[0037] The user information acquisition unit 111 acquires the image data of the user's face photo publicly guaranteed by an organization related to the state or a local public entity, and associates it with the user information of the user authenticated by the authentication institution of the public personal authentication service.

[0038] Specifically, for example, the user information acquisition unit 111 acquires the image data stored in the personal confirmation possible medium 200 by the user terminal 100 communicating with the personal confirmation possible medium 200. At this time, the user information acquisition unit 111 acquires the image data in a state associated with the user information authenticated by the authentication institution of the public personal authentication service. Thereby, the user information acquisition unit 111 suitably acquires genuine image data.

[0039] The authentication information acquisition unit 112 acquires information for display as authentication information from the information management device 20 that manages the related information 21 related to the user. That is, the authentication information acquisition unit 112 acquires items to be displayed on the user terminal 100 as authentication information from among the related information 21 stored in the information management device 20 via the network N1. Note that the user information acquisition unit 111 may also acquire user information when acquiring the image data. In this case, the authentication information acquisition unit 112 may also add the user information acquired by the user information acquisition unit 111 together with the image data to the information for display as authentication information. Also in this case, the user terminal 100 may register the user information acquired by the user information acquisition unit 111 in the information management device 20.

[0040] The items to be displayed as the certification information on the user terminal 100 may be set in advance. The items to be displayed as the certification information on the user terminal 100 may be set, for example, according to the first service or the second service. That is, in this case, the display system 110 may be set to acquire the certification information associated with which service.

[0041] Specifically, for example, in the display system 110, a user may desire to have the user terminal 100 display certification information related to a service operated by a first or second business operator that is accessible to the information management device 20. In this case, the certification information acquisition unit 112 acquires, from the information management device 20, information set by the business operator as certification information.

[0042] The provider information acquisition unit 113 acquires provider information related to the provider of the certification information from the information management device 20. That is, the provider information acquisition unit 113 refers to the related information 21 of the information management device 20 and acquires information related to the provider of the certification information acquired by the certification information acquisition unit 112 from the related information 21. In this disclosure, the provider refers to the source of the information acquired by the certification information acquisition unit 112 as certification information. The provider may be the provider or the information source or service from which the information was acquired. In this disclosure, the provider refers to the person who registered the information acquired by the certification information acquisition unit 112 as certification information in the information management device 20. For example, if the certification information is related to a first service, the provider is a first business operator. If the certification information acquisition unit 112 acquires multiple pieces of information, there may be multiple providers. An example of an information source is a My Number card. An example of a service that serves as an information source is My Number Portal or other administrative services provided by local governments. An example of a service that serves as an information source may also include private services. An example of information sourced from My Number Portal is family register information.

[0043] The proof image generation unit 114 generates a proof image for proving that the image to be displayed on the user terminal is authentic. By displaying the proof image generated by the proof image generation unit 114 on the same screen as the proof information, the display system 110 makes it easier for a third party to recognize that the proof information is authentic. For example, when a person other than the user tries to plagiarize and use the proof information, the image containing the information related to the plagiarism can be distinguished from the genuine one.

[0044] The proof image is, for example, characters, color tones, or images that change according to time. That is, in this case, the proof image generation unit 114 generates characters, color tones, or images that change according to time as the proof image at regular intervals.

[0045] The proof image may be an image of a two-dimensional code that changes according to time. In this case, a reading device used by a person who checks the user's attributes reads the proof image. That is, in this case, the proof image generation unit 114 generates a two-dimensional code that is a proof image and changes according to time so that it can be read by a reading device that determines that the proof information is authentic.

[0046] The display control unit 115 causes the display unit 122 of the user terminal 100 to display the face photo, the proof information, the source information, and the proof image. That is, the display control unit 115 generates an image for proving the user's attributes and causes the generated image to be displayed on the display unit 122 of the user terminal 100. Here, the display control unit 115 may cause the display unit 122 to display the face photo of the above-mentioned alternative image data as the face photo. That is, in this case, the display control unit 115 causes the display unit 122 to display the face photo of the alternative image data corresponding to the face photo of the user acquired in association with the user information. Thereby, the display system 110 can display a face photo suitable for proving the user's attributes.

[0047] In addition, when the certification image generation unit 114 generates characters, color tones, or images that change according to time at regular intervals, the display control unit 115 sequentially causes the display unit 122 to display the updated certification images. By causing the display unit 122 to display characters, color tones, or images that change according to time at regular intervals, the display system 110 can suitably present that the certification information is authentic.

[0048] Further, when the certification image generation unit 114 generates an image of a two-dimensional code that changes according to time, the display control unit 115 sequentially causes the display unit 122 to display the updated image of the two-dimensional code. When causing the display unit 122 to display an image of a two-dimensional code that changes according to time, the display system 110 can suitably present information indicating that the certification information is authentic to a reading device.

[0049] (Other configurations of the user terminal 100) The communication unit 121 transmits and receives various information to and from the authentication system 10, the information management device 20, the certificate verification system 30, etc. via the network N1. The communication unit 121 also performs short-range wireless communication with the personal identification medium 200.

[0050] The display unit 122 displays various information on a display including a liquid crystal panel or an organic electroluminescence. The display unit 122 in the present disclosure displays an image generated by the display control unit 115. The image generated by the display control unit 115 includes an image for proving the attributes of the user. That is, the "image for proving the attributes of the user" includes a face photo of the user, certification information, source information, and a certification image. In other words, the display unit 122 displays a face photo, certification information, source information, and a certification image.

[0051] The input reception unit 123 receives an input from a user who operates the user terminal 100. The input reception unit 123 receives an operation from the user via, for example, a switch included in the user terminal 100 and a touch panel superimposed on the display of the display unit 122.

[0052] When the user's authentication registration is completed, the login unit 125 performs the user login process for the application installed on the user terminal 100. The login unit 125 may use the pre-registered authentication information in the login process. The onboarding start function unit 140 performs processes for user authentication and user authentication registration from the start of the authentication process.

[0053] The functional configuration of the user terminal 100 has been described above. Note that the communication between the user terminal 100 and the personal confirmation medium 200 is not limited to short-range wireless communication. The communication between the user terminal 100 and the personal confirmation medium 200 may be wired communication when the user terminal 100 and the personal confirmation medium 200 come into contact. Also, the user terminal 100 can supply the image data acquired by the user information acquisition unit 111 or the alternative image data corresponding to this image data to the information management device 20 and register it as related information 21 in the information management device 20. In this case, by storing the image data in the information management device 20 and acquiring the stored image data from the information management device 20, the display system 110 can repeatedly use the face photo stored in the information management device 20. Also, when the user newly captures or registers image data that can be alternative image data, the display system 110 may use the newly captured or registered alternative image data instead of the image data acquired in the past or the alternative image data registered in the past. The display system 110 causes the image data to be displayed on the display unit 122 after storing the image data in the information management device 20. However, the display system 110 may cause the image data to be displayed on the display unit 122 before storing the image data in the information management device 20.

[0054] Regarding the functions of the above-described user terminal 100, the authentication system 10, in cooperation with the onboarding start function unit 140, registers the user's authentication information in the information management device 20 after successful authentication in user authentication registration. Here, user authentication registration means, for example, registering that the user is a person who uses at least a part of the proof system 1. The authentication information includes user-specific information such as an electronic signature used in the authentication process or information associated therewith. Preferably, the authentication information includes an electronically signed document encoded by a predetermined algorithm.

[0055] The user performs authentication of the user via the user terminal 100 by means of an onboarding start process using the personal confirmation medium 200. When the authentication is successful, the authentication system 10 registers the user's authentication information in the information management device 20. When the user's authentication information is registered, the user can log in to services related to the proof system 1 in subsequent operations, and various services become available. By performing user authentication registration using such a public personal authentication service, the proof system 1 prevents unauthorized registration.

[0056] Also, after the user authentication registration is completed, the authentication system 10 determines whether the information obtained from the personal confirmation medium 200 is genuine. More specifically, for example, the authentication system 10 collates the information obtained from the personal confirmation medium 200 with the authentication information registered in the information management device 20.

[0057] (Hardware Configuration Example) FIG. 3 is a block diagram illustrating the hardware configuration of a computer. The above-described user terminal 100 may have the configuration shown in FIG. 3. The computer 1000 has a bus 1010, a processor 1020, a memory 1030, a storage device 1040, an input / output interface 1050, and a network interface 1060.

[0058] Bus 1010 is a data transmission path for the processor 1020, the memory 1030, the storage device 1040, the input / output interface 1050, and the network interface 1060 to transmit and receive data from each other. However, the method of connecting the processor 1020 and the like to each other is not limited to bus connection.

[0059] The processor 1020 is a circuit including an arithmetic device such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit).

[0060] The memory 1030 is a main memory device realized using, for example, RAM (Random Access Memory).

[0061] The storage device 1040 is an auxiliary storage device such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), a flash memory, or a ROM (Read Only Memory). The storage device 1040 stores a program for realizing the functions of the present disclosure.

[0062] The processor 1020 reads out this program to the memory 1030 and executes it. Thereby, the processor 1020 executes the functions corresponding to this program. In other words, the program stored in the memory 1030 causes the computer 1000 to execute the functions of the present disclosure.

[0063] The input / output interface 1050 connects the computer 1000 to a predetermined input / output device. The input / output device is, for example, an input device such as a keyboard, an output device such as a display, or an input / output device in which a touch panel is superimposed on the display.

[0064] The network interface 1060 is an interface for connecting the computer 1000 to a predetermined communication network.

[0065] The computer 1000 has been described above, but in addition to the above configuration, the computer 1000 may have an information input device that allows a user to input various information to the computer 1000 through operation. The information input device is, for example, a keyboard, a mouse, or a touch panel. The computer 1000 may also have a display, a speaker, a vibration motor, an LED (light-emitting diode), or the like for displaying various information to the user.

[0066] (Software configuration of user terminal 100) Next, an overview of the software configuration of the user terminal 100 will be described with reference to Fig. 4. Fig. 4 is a block diagram showing the software hierarchy of the user terminal 100. The user terminal 100 has at least an operating system, an authentication application, a first application, and a second application.

[0067] The operating system is the basic software in the user terminal 100. The operating system is the foundation for the operation of multiple application software programs.

[0068] The authentication application is application software that operates based on the functions of the operating system. The authentication application performs functions related to the services operated by the platform operator. For example, the authentication application authenticates a user who uses the identity verification medium 200. The authentication application also has a function to display an image that certifies the user's attributes in the services provided by the platform operator.

[0069] The authentication application serves as the basis for the operation of the first application and the second application. That is, the authentication application can be referred to as a super application. A super application is an application that encompasses multiple different functions within a single application. The authentication application provides services operated by the platform operator to the user, and in addition, provides the first service operated by the first operator through the first application and the second service operated by the second operator through the second application.

[0070] The first application and the second application each function based on the authentication application. The first application and the second application can also be referred to as mini-applications that operate on top of the super application. For example, the first application may have a function of displaying an image for proving the attributes of the user in the first service. Similarly, the second operator may have a function of displaying an image for proving the attributes of the user in the second service through the second application. Note that the service as a mini-application may be provided by the platform operator.

[0071] (Software Configuration of the Personal Identification Medium 200) Next, with reference to FIG. 5, an overview of the software configuration of the personal identification medium 200 will be described. FIG. 5 is a block diagram showing the software hierarchy of the personal identification medium 200. The personal identification medium 200 shown in FIG. 5 is a My Number card. Note that the My Number card is one embodiment of the personal identification medium 200. The My Number card mainly has an operating system, an official personal authentication application, a face matter confirmation application, and a face matter input assistance application.

[0072] The operating system is the basic software that runs the IC chip (Integrated Circuit) on the My Number Card. The operating system is also called the card OS (Operating System). The operating system is the foundation for the operation of the official personal authentication application, the card information confirmation application, and the card information input assistance application. In other words, the official personal authentication application, the card information confirmation application, and the card information input assistance application use the operating system as a foundation to achieve the following operations:

[0073] A public personal authentication application is an application that allows a user to authenticate themselves using their own digital certificate in a public personal authentication service that uses a My Number card. A public personal authentication application is used to verify the identity of a user in online services. More specifically, a public personal authentication application is used to log in to My Number Portal, an online portal for administrative procedures. Alternatively, a public personal authentication application is used to log in to services provided by private businesses.

[0074] The card information confirmation application is an application for confirming the card information printed on the My Number card. The card information confirmation application reads the card information, including the four basic pieces of information, stored in the IC chip mounted on the My Number card and displays it on the user terminal 100. The card information confirmation application can also display on the user terminal 100 the user's facial photograph stored in the IC chip mounted on the My Number card.

[0075] The card information input assistance application is an application that uses the information on the face of the My Number card to assist with various procedures and input into forms. The card information input assistance application reads the card information from the My Number card's IC chip and automatically reflects it in the application's input fields.

[0076] Note that the IC chip installed in the My Number card stores an electronic certificate for user authentication and an electronic certificate for signature as two electronic certificates issued to an individual in the public personal authentication service. The electronic certificate for user authentication is used to prove that the user operating it is the actual person when logging in to the My Portal or using the public certificate delivery procedure at a convenience store. The electronic certificate for signature has four pieces of information: name, address, date of birth, and gender, and is used to apply an electronic signature to and send an electronic document or the like. The platform operator operating the authentication system 10 uses these two electronic certificates for the authentication procedure.

[0077] (Image Data Acquisition Routine) Next, with reference to FIG. 6, the process by which the display system 110 of the user terminal 100 acquires image data will be described. FIG. 6 is a flowchart of the image data acquisition method. Here, the process shown in FIG. 6 is referred to as an image data acquisition routine. The image data acquisition routine includes processes of configurations other than the display system 110 in the user terminal 100.

[0078] In step S101, the user information acquisition unit 111 requests the input of a personal identification number (PIN) for personal identification and a personal identification number for image data acquisition. In response to this, the user terminal 100 displays a message on the display unit 122 prompting the user to input the personal identification number (PIN) and the personal identification number for image data acquisition. The user information acquisition unit 111 may accept the input of the personal identification number (PIN) and the personal identification number for image data acquisition simultaneously (for example, on one screen of the user terminal 100), or may accept them at different times. Here, the personal identification number is typically the personal identification number for the digital certificate for signature or the personal identification number for the digital certificate for user authentication. The personal identification number for image data acquisition is, for example, the personal identification number for the card details confirmation application. A typical combination of personal identification numbers requested by the user information acquisition unit 111 is the personal identification number for the digital certificate for user authentication and the personal identification number for the card details confirmation application. The personal identification number for personal identification may also be referred to as first authentication information. The personal identification number for obtaining image data may also be referred to as second authentication information.

[0079] In step S102, the user terminal 100 accepts a personal identification number for personal identification and a personal identification number for image data acquisition. That is, the user terminal 100 accepts, for example, a personal identification number for a user authentication electronic certificate and a personal identification number for a card information confirmation application.

[0080] In step S103, the user information acquisition unit 111 requests reading of the personal identification medium 200. In response to this, the user terminal 100 displays on the display unit 122 a message urging the user to bring the user terminal 100 and the personal identification medium 200 closer to each other.

[0081] In step S104, the user terminal 100 performs a reading process on the identity verifiable medium 200. Here, the user terminal 100 transmits a personal identification number for identity verification and a personal identification number for image data acquisition to the identity verifiable medium 200. If authentication on the identity verifiable medium 200 is successful using the personal identification number transmitted by the user terminal 100, the identity verifiable medium 200 transmits user information to the user terminal 100. The user information is, for example, the four basic pieces of information of the user. The user terminal 100 receives the user information from the identity verifiable medium 200. The user terminal 100 supplies the received user information to the authentication system 10. Note that if authentication on the identity verifiable medium 200 fails, the process may be terminated.

[0082] In the communication between the above-mentioned user terminal 100 and the identity verifiable medium 200, the user information acquisition unit 111 may acquire as user information at least a portion of personal information (e.g., the four basic pieces of information) that can be acquired by performing authentication using a signature electronic certificate that can be used in public personal authentication services.

[0083] Furthermore, in the communication between the user terminal 100 and the identity verifiable medium 200 described above, the user information acquisition unit 111 may acquire, as user information, at least a portion of personal information that can be acquired by using a card details input assistance application. Similarly, the user information acquisition unit 111 may acquire, as user information, at least a portion of personal information that can be acquired by using a card details confirmation application. Note that the user terminal 100 may perform a process of registering the user information acquired through communication between the user terminal 100 and the identity verifiable medium 200 in the related information 21.

[0084] In step S105, the user information acquisition unit 111 determines whether the authentication of the authentication system 10 has been successful. Here, the case where the authentication of the authentication system 10 is successful means, firstly, that the authentication of the user by the authentication institution of the public personal authentication service is successful based on the user information of the user, and the authentication system 10 has received information indicating the success of the personal identification. The case where the authentication is successful means, secondly, that the personal identification of the user is successful by comparing the authentication information stored in the information management device 20 with the user information obtained this time.

[0085] If it is determined that the authentication of the authentication system 10 is successful (step S105: YES), the user information acquisition unit 111 proceeds to step S106. If it is determined that the authentication of the authentication system 10 is not successful (step S105: NO), the display system 110 ends the image data acquisition routine.

[0086] In step S106, the user information acquisition unit 111 acquires image data. That is, the user information acquisition unit 111 acquires the image data of the user's face photo guaranteed publicly by an organization related to a country or a local public entity, and associates it with the user information of the user authenticated by the authentication institution of the public personal authentication service. Associating with the user information of the user means, for example, acquiring the image data corresponding to the user information used for authentication in step S105. Corresponding to the user information means, for example, being stored in the same information source as the user information. In this case, the same information source as the user information is, for example, the personal confirmation possible medium 200. To acquire the image data from the same information source as the user information, for example, it is preferable to acquire the image data together within the period of the session in which the user is authenticated. In this case, more specifically, the user information acquisition unit 111 acquires, for example, the image data of the user's face photo from the coupon item confirmation application. In this way, the user information acquisition unit 111 acquires the image data of the face photo in association with the user information of the user whose authentication has succeeded. As a result, the display system 110 suitably acquires the face photo of the user for whom personal confirmation has been performed. In other words, the display system 110 prevents acquiring a non-genuine face photo from a medium different from the personal confirmation possible medium 200 for which personal confirmation has been performed. When the user information acquisition unit 111 acquires the image data, the display system 110 proceeds to step S107.

[0087] In step S107, the display system 110 determines whether to shift to the display routine. The display routine is a process of causing the display unit 122 to display the certification data including the acquired image data. Whether to shift to the display routine may prompt the user to make a selection, for example, in the application that the user terminal 100 is operating.

[0088] If it is determined not to transfer to the display routine (step S107: NO), the display system 110 ends the image data acquisition routine. If it is determined to transfer to the display routine (step S107: YES), the display system 110 starts the display routine. The display routine will be described later.

[0089] The above describes the process of the user information acquisition unit 111 acquiring image data. Note that the image data acquisition routine is not limited to the above-described process. For example, when the user has not performed an authentication procedure, the information management device 20 does not have authentication information indicating that the user has been authenticated. In this case, the user terminal 100 operates the onboarding start function unit 140 to perform an onboarding procedure. At this time, the user information acquisition unit 111 may acquire image data in the process of reading the personal identification medium 200 that can be used for identity verification in the onboarding procedure. However, even when acquiring image data in the onboarding procedure, the user terminal 100 performs the same processing as steps S101 to S106 described above.

[0090] In the above-described process, the user information acquisition unit 111 acquires user information from the personal identification medium 200 through an authentication procedure performed via short-range wireless communication between the tangible personal identification medium 200 and the user terminal 100. The user information acquisition unit 111 also acquires image data from the personal identification medium 200 through an authentication procedure performed via short-range wireless communication. Specifically, for example, the user information acquisition unit 111 acquires user information from the my number card through an authentication procedure performed via NFC (registered trademark) between the tangible my number card and the user terminal 100. The user information acquisition unit 111 also acquires image data from the my number card through an authentication procedure performed via NFC.

[0091] In the above process, the user information acquisition unit 111 acquires, as user information, at least a part of personal information that can be acquired by performing authentication using a signature digital certificate. The user information acquisition unit 111 may also acquire, as user information, at least a part of personal information that can be acquired by using a card information input assistance application or a card information confirmation application.

[0092] In the above-mentioned processing, if the authentication procedure is successful through a single reading process performed by bringing the identity verifiable medium 200 and the user terminal close to each other once, the user information acquisition unit 111 acquires image data from the identity verifiable medium 200 within the period of the reading process.

[0093] (Reading process status) FIG. 7 is a diagram showing a state in which the user terminal 100 communicates with the personal identification medium 200. A typical example of the personal identification medium 200 is a My Number card. The user brings the near-field wireless communication antenna unit of the user terminal 100 close to the personal identification medium 200. Thereby, the user terminal realizes communication with the personal identification medium 200. In communication with the personal identification medium 200, the user terminal supplies the personal identification medium 200 with first authentication information (a password for personal identification) and second authentication information (a password for acquiring image data). The personal identification medium stores, in an IC chip, first information from a first information source corresponding to the first authentication information. Here, when the first authentication information is the password of an electronic certificate for user authentication, the first information source is a public personal authentication application, and the first information is, for example, the user's electronic signature. The personal identification medium stores, in an IC chip, second information from a second information source corresponding to the second authentication information. When the second authentication information is the password of a face value confirmation application, the second information source is the face value confirmation application, and the second information is image data of the user's face photo. The personal identification medium receives the first authentication information and the second authentication information from the user terminal, and authenticates the two received authentication information (the first authentication information, the second authentication information). When the authentication is successful, the personal identification medium supplies the user terminal with the first information and the second information corresponding to the received authentication information.

[0094] As described above, when the authentication procedure is successful by a single reading process performed by bringing the user terminal 100 and the personal identification medium 200 close to each other once, the display system 110 may acquire image data from the personal identification medium 200 within the period of the reading process. In this case, by bringing the user terminal 100 and the personal identification medium 200 close to each other once, the user terminal acquires information corresponding to each of the two passwords described above from the personal identification medium 200. Note that when the authentication procedure is successful by a single reading process, the display system 110 may acquire user information from the personal identification medium 200 in addition to the image data within the period of the reading process.

[0095] (Display method) Next, the processing executed by the display system 110 will be described with reference to Fig. 8. Fig. 8 is a flowchart of a display method according to the first embodiment. The flowchart shown in Fig. 8 shows the processing executed by the display system 110 when a user causes the user terminal 100 to display certification information for certifying the user's attributes.

[0096] In step S110, the display system 110 determines whether the user terminal 100 has acquired the image data. If the user terminal 100 has not determined that the image data has been acquired (step S110: NO), the display system 110 proceeds to step S111. If the user terminal 100 has determined that the image data has been acquired (step S110: YES), the display system 110 proceeds to step S120.

[0097] In step S111, the display system 110 determines whether or not to acquire image data. Specifically, for example, the display system 110 displays on the display unit 122 a message inquiring whether or not to acquire image data, and accepts an instruction from the user. If the display system 110 does not determine that image data will be acquired in response to the instruction from the user (step S111: NO), the display system 110 ends the display routine. On the other hand, if the display system 110 determines that image data will be acquired in response to the instruction from the user (step S111: YES), the display system 110 proceeds to the image data acquisition routine and starts the image data acquisition routine shown in FIG. 6.

[0098] In step S120, the certification information acquisition unit 112 acquires information to be displayed as certification information from the information management device 20 that manages related information 21 related to the user. The certification information acquisition unit 112 supplies the acquired related information 21 to the display control unit 115. Note that the user information acquisition unit 111 may also acquire user information when acquiring image data. In this case, the certification information acquisition unit 112 may add the user information acquired by the user information acquisition unit 111 together with the image data to the information to be displayed as certification information.

[0099] In step S130, the provider information acquisition unit 113 acquires provider information relating to the provider of the certification information from the information management device 20. The provider information acquisition unit 113 supplies the acquired certification information to the display control unit 115.

[0100] In step S140, the proof image generation unit 114 generates a proof image for certifying that the image displayed on the user terminal is authentic. The proof image generation unit 114 supplies the generated proof image to the display control unit 115.

[0101] In step S150, the display control unit 115 displays the facial photograph, the authentication information, the provider information, and the authentication image on the display unit 122 of the user terminal. More specifically, the display control unit 115 generates a display image including the facial photograph, the authentication information, the provider information, and the authentication image received from the above-mentioned components. The display control unit 115 then displays this display image on the display unit 122.

[0102] (Related information 21) Next, the related information 21 will be described with reference to Fig. 9. Fig. 9 is a table showing the related information 21 stored in the information management device 20. The table of related information 21 shown in Fig. 9 includes "item number," "configurator," "access authority," "definition," and user number in the vertical direction, and the defined information is shown in the order of item number in the horizontal direction.

[0103] "Item number" is a number assigned to each set item. "Setter" indicates the name of the business that set the information content of the corresponding item number. The setter is the person who defined the information of the corresponding item number in the related information 21. In this disclosure, the setter can also be referred to as the provider or source of the provider. "Access rights" indicates the business that can access the information set for each item number. "Definition" indicates the type of information defined for each item. The user number is a number assigned to each of the multiple users who use the certification system 1.

[0104] In the related information 21, for example, item number #001 is information set by the platform operator, all operators have access rights, and the defined information is "name information." Item number #002 is information set by the first operator, the first operator and the second operator have access rights, and the defined information is "address." Similarly, item number #003 is information set by the first operator, the first operator has access rights, and the defined information is "family composition." Item number #004 is information set by the second operator, the second operator has access rights, and the defined information is "medication information."

[0105] Regarding the information set as described above, for example, for user number 0001, the name information is "**Ichiro" and the address is "A prefecture, B city...", and similarly, the family structure and medication information of user number 0001 are also registered. For user number 0002, the name information is "**Hanako" and the address is "C prefecture, D city...", and family structure and medication information are also registered. For user number 0003, the name information is "**Taro" and the address is "E prefecture, F city...", and family structure and medication information are also registered.

[0106] The related information 21 has been described above. A user using the certification system 1 uses the related information 21, for example, as shown below. For example, assume that "**Ichiro," whose user number is 0001, owns the user terminal 100. Assume also that the user desires to display an identification card that certifies his or her attributes in the first service on the user terminal 100. In this case, the certification information acquisition unit 112 of the display system 110 acquires information to be displayed as certification information from the related information 21 described above. In this case, the certification information acquisition unit 112 acquires information that can be displayed as certification information from information accessible to the first business providing the first service. In the above description, access authority is set for each item, but access authority may also be set for each item and for each user. The related information 21 may include information regarding the provider, which is the source of each registered information.

[0107] (Image displayed) Next, an example of an image displayed on the display unit 122 of the user terminal 100 will be described with reference to Fig. 10. Fig. 10 is a diagram showing an image displaying certification information. Fig. 10 shows a display image 150. The display image 150 is an image displaying certification information in an authentication application. The display image 150 includes a virtual card area 160, a facial photograph 170, and a certification image 180.

[0108] The virtual card area 160 includes provider information 161 and certification information 162. The facial photograph 170 is obtained by the user terminal 100 from the identity verifiable medium 200. The facial photograph 170 is a facial photograph of the user officially certified by an institution related to a national or local government. The provider information 161 includes one or more providers related to the provision of certification information. The provider information 161 may include two or more providers. The provider information 161 may also include providers corresponding to each of multiple pieces of certification information.

[0109] The certificate image 180 includes a time display 181, a moving image 182, and a two-dimensional code 183. The time display 181 is a character string that changes according to the time. The moving image 182 is an image whose color tone or shape changes according to the time. The two-dimensional code 183 is a two-dimensional code that changes according to the time. More specifically, for example, the information in the two-dimensional code 183 includes time information that is updated every second.

[0110] The display system 110 can appropriately certify the user's attributes by displaying an image including a suitably guaranteed authentic facial photograph and certification information on the user terminal 100. Furthermore, by displaying the above-mentioned image on the user terminal 100, the user using the certification system 1 can easily present the user's attributes for various services.

[0111] The identification image 180 may display at least one of the above-mentioned time display 181, moving image 182, and two-dimensional code 183. The image displaying the identification information may have a background 151 whose color tone changes according to the time.

[0112] The above image is an example of displaying certification information for a super app service provided by a platform operator. However, the image displaying the certification information may also be an image that certifies the user's attributes for a mini app that functions on the super app. The authentication application of the user terminal 100 may be configured to be able to switch between the certification information for the super app, the certification information for the first service, and the certification information for the second service. By being able to switch between displaying the certification information for multiple different services, the display system 110 can prevent the user from having to deal with complicated information used to certify multiple different attributes.

[0113] The above has described the first embodiment. In this embodiment, a My Number card is cited as an example of the personal identification possible medium 200. However, the personal identification possible medium 200 is not limited to this. The personal identification possible medium 200 may be, for example, a coin-shaped medium equipped with an IC chip storing an electronic certificate issued to an individual in a public personal authentication service. The personal identification possible medium 200 may be, for example, a portable medium having a USB (Universal Serial Bus) interface.

[0114] As described above, according to the present embodiment, a display system, a display method, and a program that preferably display information for proving the attributes of a user can be provided.

[0115] <Second Embodiment> Next, the second embodiment will be described. FIG. 11 is a block diagram of the user terminal 100 according to the second embodiment. The display system 110 according to the second embodiment is different from the above-described display system 110 in that it has a selection reception unit 116.

[0116] The selection reception unit 116 receives a selection from the user regarding the information to be displayed as proof information among the related information 21 related to the user. That is, the selection reception unit 116 presents to the user a plurality of related information associated with the service related to the attribute that the user wants to prove among the related information 21 in a selectable manner. Then, the selection reception unit 116 receives the selection from the user. When the selection reception unit 116 receives the user's selection, it supplies the content of the received selection to the proof information acquisition unit 112.

[0117] The proof information acquisition unit 112 according to the present embodiment receives the content selected by the selection reception unit 116. The proof information acquisition unit 112 acquires the information selected by the user from the information management device 20.

[0118] FIG. 12 is a flowchart of the display method according to the second embodiment. The flowchart shown in FIG. 12 is different from the flowchart shown in FIG. 8 in that it has a step S112 between step S110 and step S120.

[0119] In step S110 of the present embodiment, the display system 110 determines whether the user terminal 100 has acquired image data. If it is determined that the user terminal 100 has not acquired image data (step S110: NO), the display system 110 proceeds to step S111. If it is determined that the user terminal 100 has acquired image data (step S110: YES), the display system 110 proceeds to step S112.

[0120] In step S112, the selection reception unit 116 receives a selection of information to be displayed as proof information. That is, the selection reception unit 116 receives a selection from the user regarding the information to be displayed as proof information. More specifically, for example, the selection reception unit 116 extracts information that can be selected from the related information 21 and causes it to be displayed on the display unit 122 in a manner that can be selected by the user. The selection reception unit 116 supplies the received content to the proof information acquisition unit 112.

[0121] In step S120, the proof information acquisition unit 112 receives the content related to the selection of the related information from the selection reception unit 116. Also, the proof information acquisition unit 112 acquires information to be displayed as proof information from the information management device 20. The proof information acquisition unit 112 supplies the acquired related information 21 to the display control unit 115.

[0122] The second embodiment has been described above. The display system 110 according to the present embodiment can flexibly display proof information by receiving the user's selection. In other words, the display system 110 can exclude items that the user does not wish to select from the proof information. Therefore, according to the present embodiment, it is possible to provide a display system, a display method, and a program that can flexibly and suitably display information for proving the user's attributes.

[0123] <Third Embodiment> Next, a third embodiment will be described. Fig. 13 is a block diagram of a user terminal 100 according to the third embodiment. A display system 110 according to this embodiment has a display information receiving unit 117 and an estimation unit 118 instead of the selection receiving unit 116.

[0124] The display information receiving unit 117 receives information related to the content to be displayed as the certification information. More specifically, for example, the display information receiving unit 117 receives information related to the content to be displayed as the certification information from an application provided by the platform operator, a first application provided by the first operator, etc. The display information receiving unit 117 supplies the received information to the estimation unit 118.

[0125] When the content to be displayed as the certification information does not match the related information, the estimation unit 118 estimates the content to be displayed as the certification information from the related information. For example, the estimation unit 118 receives items that need to be displayed as the certification information via the super app, the first application, or the second application. The estimation unit 118 also determines whether the content to be displayed as the certification information matches the related information. Furthermore, when the content to be displayed as the certification information does not match the related information, the estimation unit 118 extracts information related to the content to be displayed as the certification information from information stored as related information.

[0126] To achieve the above function, the estimation unit 118 may, for example, store in advance a database of languages having meanings similar to those of the related information. The estimation unit 118 may extract related information having languages having vectors similar to the language vectors of the items to be displayed as proof information. Alternatively, the estimation unit 118 may input the content to be displayed as proof information and the related information into a large-scale language model that has previously trained a large number of languages, and estimate the content of the proof information.

[0127] The certification information acquisition unit 112 according to this embodiment acquires, as certification information, related information relating to the above estimation from the information management device.

[0128] Next, a display method according to the present embodiment will be described with reference to FIG. 14. FIG. 14 is a flowchart of the display method according to the third embodiment. The flowchart shown in FIG. 14 differs in the processing between step S110 and step S120 from the flowchart shown in FIG. 8.

[0129] In step S110 of the present embodiment, the display system 110 determines whether the user terminal 100 has acquired image data. If it is determined that the user terminal 100 has not acquired image data (step S110: NO), the display system 110 proceeds to step S111. If it is determined that the user terminal 100 has acquired image data (step S110: YES), the display system 110 proceeds to step S113.

[0130] In step S113, the display information reception unit 117 receives the content to be displayed as proof information. More specifically, for example, the display information reception unit 117 receives information about the content to be displayed as proof information via a predetermined application. The display information reception unit 117 supplies the received content to the estimation unit 118.

[0131] In step S114, the estimation unit 118 determines whether the content to be displayed as proof information matches the related information. If it is determined that the content to be displayed as proof information matches the related information (step S114; YES), the display system 110 proceeds to step S120. If it is determined that the content to be displayed as proof information does not match the related information (step S114; NO), the display system 110 proceeds to step S115.

[0132] In step S115, the estimation unit 118 estimates information to be displayed as certification information based on the related information 21. More specifically, the certification information acquisition unit 112 extracts related information that is highly relevant to the information on the content to be displayed as certification information that is received by the display information reception unit 117. The estimation unit 118 then estimates the content to be displayed as certification information from the content to be displayed as certification information and the extracted related information, and supplies the estimation result to the certification information acquisition unit 112. After the estimation unit 118 supplies the estimation result to the certification information acquisition unit 112, the display system 110 proceeds to step S120.

[0133] The above describes the third embodiment. The display system 110 according to the third embodiment estimates the content to be displayed as the certification information from the information included in the related information, even if the content to be displayed as the certification information does not match the related information.

[0134] For example, if the related information stores the user's family structure and it is necessary to display whether the user is "married" or "single" as proof information, the estimation unit 118 estimates whether the user is married or single from the family structure.

[0135] Alternatively, if the related information includes a date of birth, and it is necessary to display "age" as proof information, the estimation unit 118 estimates the user's age from the date of birth and the current date.

[0136] In this way, the display system 110 can estimate and display the certification information even if information that exactly matches the certification information is not stored in the related information 21. That is, according to this embodiment, it is possible to provide a display system, a display method, and a program that suitably select and display information for proving a user's attributes. Note that the electronic certificate in the public personal authentication service may be installed in a smartphone. By installing the electronic certificate in the smartphone, the display system 110 can use the public personal authentication service even without the identity verifiable medium 200. In this case, the display system 110 can acquire image data using the electronic certificate installed in the smartphone.

[0137] The above-mentioned program includes a set of instructions (or software code) that, when loaded into a computer, causes the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include RAM, ROM, flash memory, SSD or other memory technology, CD-ROM, DVD (digital versatile disc), Blu-ray disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.

[0138] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications within the scope of the present disclosure that would be understandable to those skilled in the art are possible in the configuration and details of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate. In step S110 of the flowcharts shown in FIGS. 8, 12, and 14, the display system 110 acquires certification information if image data acquisition is successful. However, the display system 110 may acquire certification information from the information management device 20 before acquiring image data. Furthermore, the order of the processes of the user information acquisition unit 111 acquiring image data and user information, the certification information acquisition unit 112 acquiring certification information, the provider information acquisition unit 113 acquiring provider information, and the certification image generation unit 114 generating a certification image is not limited to the above.

[0139] Each drawing is merely an example for describing one or more embodiments. Each drawing may relate not only to one particular embodiment, but also to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate. [Explanation of symbols]

[0140] 1 Proof System 10 Authentication System 11 Communications Department 12 Authentication Section 13 Information acquisition department 14 Storage section 20 Information management device 21 Related Information 30 Certificate Validation System 40 First Business Management System 50 Second Business Management System 100 User Terminal 110 Display System 111 User Information Acquisition Unit 112 Proof Information Acquisition Unit 113 Provider Information Acquisition Unit 114 Proof Image Generation Unit 115 Display Control Unit 116 Selection Reception Unit 117 Display Information Reception Unit 118 Estimation Unit 121 Communication Unit 122 Display Unit 123 Input Reception Unit 125 Login Unit 140 Onboarding Start Function Unit 150 Display Image 151 Background 160 Virtual Card Area 161 Provider Information 162 Proof Information 170 Face Photo 180 Proof Image 181 Time Display 182 Moving Image 183 Two-Dimensional Code 200 Identity-Verifiable Medium 1000 Computer 1010 Bus 1020 Processor 1030 Memory 1040 Storage Device 1050 Input / Output Interface 1060 Network Interface N1 Network

Claims

A display system that causes a user who uses a certification system including an authentication system, an information management device, and a display system to display, on a user terminal, certification information for proving the user's attributes as a display image, when the authentication procedure of the user in a public personal authentication service performed via short-range wireless communication by a single reading process performed when a personal confirmation medium, which is a tangible object in the authentication system, and the user terminal approach each other once is successful, the user's face photo image data officially guaranteed by an organization related to the country or a local public entity is acquired from the personal confirmation medium within the period of the reading process, authentication is performed using a signature electronic certificate available for the public personal authentication service, or at least a part of the personal information that can be acquired by using a form item input assistance application or a form item confirmation application is acquired as user information, a user information acquisition unit; a certification information acquisition unit that manages related information related to the user and acquires the certification information from an information management device that registers the image data and the user information acquired by the user information acquisition unit as the related information; a provider information acquisition unit that acquires provider information regarding the provider of the certification information from the information management device; a certification image generation unit that generates a certification image that is an image that changes according to time and proves that the display image is genuine; a display control unit that generates the display image including the face photo, the certification information, the provider information, and the certification image and displays the display image on a display unit of the user terminal, The certification information acquisition unit adds the image data and the user information acquired by the user information acquisition unit to the certification information. Display system.

2. In the display system according to claim 1, further comprising a selection reception unit that receives a selection of the certification information from among the related information related to the user, The certification information acquisition unit acquires the information selected by the user from the information management device. Display system.

3. In the display system according to claim 1, when the user causes the user terminal to display the certification information regarding a service operated by a business operator accessible to the information management device, The certification information acquisition unit acquires, from the information management device, information set by the business operator as the certification information. Display system.

4. In the display system according to claim 1, the display control unit causes the display unit to display a face photo of the alternative image data corresponding to the face photo of the user obtained from the personal verification-enabled medium in which the user information was stored. Display system.

5. In the display system according to claim 1, when the user terminal supplies first authentication information and second authentication information to the personal verification-enabled medium by the reading process, and the personal verification-enabled medium authenticates the first authentication information and the second authentication information, the user information acquisition unit acquires the user information and the image data from the personal verification-enabled medium within the period of the reading process. Display system.

6. In the display system according to claim 1, when the content to be displayed as the certification information does not match the related information, it includes an estimation unit that estimates the content of the certification information from the related information. The certification information acquisition unit acquires, from the information management device, the related information corresponding to the estimation as the certification information. Display system.

7. In the display system according to any one of claims 1 to 5, the certification image generation unit generates, as the certification image, characters, color tones, or images that change according to time at regular intervals. The display control unit sequentially causes the display unit to display the updated certification image. Display system.

8. In the display system according to claim 6, the certification image generation unit generates a two-dimensional code, which is the certification image and changes according to time, for being read by a reading device that determines that the certification information is genuine. Display system.

9. In a display system that causes a computer to display, on a user terminal, as a display image, certification information for a user to prove their own attributes by using a certification system including an authentication system, an information management device, and a display system, When the authentication procedure of the user in the public personal authentication service performed via short - range wireless communication by a single reading process in which the personal confirmation - possible medium, which is a tangible object, and the user terminal approach each other once in the authentication system is successful, image data of the user's face photo publicly guaranteed by an organization related to the state or a local public entity is acquired from the personal confirmation - possible medium within the period of the reading process, authentication is performed using a signature - type electronic certificate available for the public personal authentication service, or at least a part of the personal information that can be acquired by using a form - item input assistance application or a form - item confirmation application is acquired as user information, while managing the related information related to the user, the proof information is acquired from the information management device that registers the acquired image data and the user information as the related information, the provider information regarding the provider of the proof information is acquired, a proof image that is an image that changes according to time and proves that the display image is genuine is generated, a display image including the face photo, the proof information, the provider information, and the proof image is generated and displayed on the display unit of the user terminal, the process of acquiring the proof information adds the acquired image data and the user information to the proof information, Display method.

10. In a display system in which a user using a proof system including an authentication system, an information management device, and a display system displays proof information for proving his / her own attributes as a display image on a user terminal, a user information acquisition step of, when the authentication procedure of the user in the public personal authentication service performed via short - range wireless communication by a single reading process in which the personal confirmation - possible medium, which is a tangible object, and the user terminal approach each other once in the authentication system is successful, acquiring image data of the user's face photo publicly guaranteed by an organization related to the state or a local public entity from the personal confirmation - possible medium within the period of the reading process, and performing authentication using a signature - type electronic certificate available for the public personal authentication service or acquiring at least a part of the personal information that can be acquired by using a form - item input assistance application or a form - item confirmation application as user information, A proof information acquisition step of acquiring the proof information from the information management device that manages related information related to the user and registers the image data and the user information acquired in the user information acquisition step as the related information; A proof information acquisition step of acquiring the proof information from the information management device that manages the related information related to the user; A provider information acquisition step of acquiring provider information regarding the provider of the proof information; A proof image generation step of generating a proof image that is an image that changes according to time and proves that the display image is authentic; A display control step of generating the display image including the face photo, the proof information, the provider information, and the proof image and displaying the display image on a display unit of the user terminal. In the proof information acquisition step, the image data and the user information acquired in the user information acquisition step are added to the proof information. A display method, which causes a computer to execute, Program.

Citation Information

Patent Citations

  • License information processing method and device, computer equipment and storage medium

    CN110807378A

  • Data processing method and device and electronic equipment

    CN116860157A

  • Identification system and method, user's portable terminal, and identification card management server and program

    JP2007058781A

  • IC card, portable terminal, and IC card processing system

    JP2015060407A

  • Information providing device, information providing system, information providing program, and information providing method

    JP2015146128A