Server device, terminal, server device control method and program
The server device and terminal system addresses the challenge of users changing devices by associating biometric information with terminal IDs for identity verification and reissuing certificates, ensuring secure and convenient access to accounts.
Patent Information
- Application Number
- JP2025541609
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-17
- Estimated Expiration
- 2045-05-27
AI Technical Summary
Existing systems fail to address the issue of users being unable to log in to their accounts when they change devices due to device authentication, leading to inconvenience and potential fraudulent activities.
A server device and terminal system that stores user biometric information and terminal IDs in association, allowing for identity verification and reissuing certificates to new devices using biometric matching, ensuring seamless account access across device changes.
Enables convenient and secure transfer of digital credentials across different terminals by updating terminal IDs and reissuing certificates, enhancing user convenience and preventing fraudulent activities.
Smart Images

Figure 0007740609000001 
Figure 0007740609000002 
Figure 0007740609000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a server device, a terminal, a method for controlling a server device, and a storage medium. [Background technology]
[0002] In a system that authenticates users using digital certificates, there is a technique for resuming services when a user loses their terminal.
[0003] For example, Patent Document 1 describes a system that reduces the user's procedural burden until service resumption without managing secret information on the server side, and enables personal authentication for multiple services even after a terminal is lost. The authentication server device in Patent Document 1 is a server connected to a registration terminal, an authentication terminal, and a service providing server via a network. The authentication server includes a storage device and a processing device. The processing device revokes a public key and private key recovery information stored in the registration terminal notified by the user. The processing device also acquires a backup public key and private key recovery information from the storage device and issues a public key certificate for the backup public key. The processing device also receives a private key recovery information acquisition request from the authentication terminal, which includes terminal information and reading sensor information of the registration terminal. The processing device also acquires backup private key recovery information for the user from the private key recovery information stored in the storage device and transmits it to the authentication terminal. The processing device also receives the backup private key recovery information and a signature value generated by a private key generated from biometric information read by the authentication terminal from the authentication terminal. The processing device also verifies the signature value with the backup public key certificate stored in the storage device, and transmits the verification result to the service providing server. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 6841781 Summary of the Invention [Problem to be solved by the invention]
[0005] In recent years, fraudulent activities such as creating multiple accounts on ticket sales sites from the same smartphone or other device have become a problem. To prevent such fraudulent activities, ticket sales sites have introduced device authentication. However, when device authentication is introduced, a new problem arises: if a user changes their smartphone or other device, they will be unable to log in to their account from the new device.
[0006] It should be noted that Patent Document 1 merely discloses a technique for establishing personal authentication for multiple services even after a user has lost their device. Therefore, even if the technique disclosed in Patent Document 1 is applied, it is not possible to solve the above problem.
[0007] A primary object of the present invention is to provide a server device, a terminal, a method for controlling a server device, and a storage medium that contribute to improving convenience for users who receive services using terminal authentication. [Means for solving the problem]
[0008] According to a first aspect of the present invention, there is provided a storage means for storing information relating to a certificate issued to a user, the biometric information of the user, and the terminal ID of the first terminal, in association with each other, the certificate including at least biometric information of a user and a terminal ID of a first terminal used by the user, and a storage means for storing information relating to the certificate issued to the user, the biometric information of the user, and the terminal ID of the first terminal, when a certificate reissue request including the certificate issued to the user, the biometric information of the user, and the terminal ID of the second terminal is received from a second terminal used by the user, the storage means storing information relating to the certificate issued to the user, the biometric information of the user, and the terminal ID of the second terminal in association with each other ... a server device comprising: an identity verification means for performing identity verification using biometric information included in a request; and a reissuance means for, if the identity verification is successful, performing a matching process using the biometric information used for the identity verification and the stored biometric information to identify a user who wishes to have a certificate reissued, updating the terminal ID of the first terminal stored in association with the biometric information of the identified user to the terminal ID of the second terminal, and reissuing the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal.
[0009] According to a second aspect of the present invention, there is provided a terminal comprising: an acquisition means for acquiring a certificate issued by a service provider, the certificate including at least the terminal ID of another terminal and biometric information of a user; and a reissue control means for sending a certificate reissue request including the acquired certificate, the biometric information of the user, and the terminal ID of the terminal to a server device of the service provider.
[0010] According to a third aspect of the present invention, there is provided a control method for a server device, the control method comprising: storing, in a server device, information relating to a certificate issued to the user, the user's biometric information, and the terminal ID of the first terminal, the certificate including at least biometric information of a user and the terminal ID of the first terminal used by the user, in association with each other; and upon receiving a certificate reissue request from a second terminal used by the user, the server device performing identity verification using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; and, if the identity verification is successful, performing a matching process using the biometric information used for the identity verification and the stored biometric information, thereby identifying the user who wishes to have the certificate reissued; updating the terminal ID of the first terminal, which is stored in association with the biometric information of the identified user, to the terminal ID of the second terminal; and reissuing the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal.
[0011] According to a fourth aspect of the present invention, a computer installed in a server device is provided with a process for storing information about a certificate issued to a user, the information including at least biometric information of the user and a terminal ID of a first terminal used by the user, in association with the biometric information of the user and the terminal ID of the first terminal, and a process for storing, when a certificate reissue request including the certificate issued to the user, the biometric information of the user and the terminal ID of the second terminal is received from a second terminal used by the user, the biometric information obtained from the certificate included in the certificate reissue request and the terminal ID of the second terminal. a process of performing identity verification using biometric information included in a request, and, if the identity verification is successful, performing a matching process using the biometric information used for the identity verification with the stored biometric information to identify a user who wishes to have a certificate reissued, updating the terminal ID of the first terminal stored in correspondence with the biometric information of the identified user to the terminal ID of the second terminal, and reissuing the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal. [Effects of the Invention]
[0012] According to each aspect of the present invention, a server device, a terminal, a method for controlling a server device, and a storage medium are provided that contribute to improving the convenience of users who receive services using terminal authentication. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart illustrating the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 4]FIG. 4 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 5] FIG. 5 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 7] FIG. 7 is a diagram illustrating an example of a processing configuration of a terminal according to an embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. [Figure 9] FIG. 9 is a diagram illustrating an example of a member management database according to an embodiment of the present disclosure. [Figure 10] FIG. 10 is a flowchart illustrating an example of the operation of the reissue control unit according to an embodiment of the present disclosure. [Figure 11] FIG. 11 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 12] FIG. 12 is a diagram illustrating an example of a hardware configuration of a server device according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0014] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0015] A server device 100 according to an embodiment includes a storage unit 101, an identity verification unit 102, and a reissue unit 103 (see FIG. 1). The storage unit 101 stores information about a certificate issued to a user, the information including at least the user's biometric information and the terminal ID of a first terminal used by the user, in association with the user's biometric information and the terminal ID of the first terminal (step S1 in FIG. 2). The identity verification unit 102 receives a certificate reissue request from a second terminal used by the user, the certificate including the user's biometric information and the terminal ID of the second terminal (step S2). The identity verification unit 102 performs identity verification using biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request (step S3). If identity verification is successful, the reissue unit 103 identifies the user who requests a certificate reissue by performing a matching process using the biometric information used for identity verification and the stored biometric information (step S4). The reissuing means 103 updates the terminal ID of the first terminal stored in association with the biometric information of the identified user to the terminal ID of the second terminal, and reissues the certificate in which the terminal ID of the first terminal has been updated to the terminal ID of the second terminal (step S5).
[0016] The server device 100 acquires the biometric information of a user who wishes to have a certificate reissued, the terminal ID of the terminal, and the certificate to be reissued from the terminal of the user. The acquired certificate includes the biometric information of the user (the certificate recipient) and the terminal ID of the terminal used by the certificate recipient when the certificate was issued. The server device 100 performs identity verification using the biometric information obtained from the certificate to be reissued and the biometric information obtained from the terminal. By performing identity verification, the server device 100 confirms that the certificate recipient actually wishes to have a certificate reissued. If identity verification is successful, the server device 100 performs a matching process using the biometric information used for identity verification and pre-stored biometric information to identify the user who wishes to have a certificate reissued. The server device 100 updates the terminal ID stored in association with the biometric information of the identified user to the terminal ID acquired from the terminal. The server device 100 then reissues the certificate to the user with the updated terminal ID. Such operation of the server device 100 improves convenience for users who change their terminal model, such as a smartphone, because the user can store the certificate obtained on the previous terminal in the new terminal after the change.
[0017] Specific embodiments will be described in more detail below with reference to the drawings.
[0018] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.
[0019] [System Configuration] As shown in FIG. 3, the information processing system according to the first embodiment includes a server device 10 and a carrier terminal 20.
[0020] For example, the server device 10 is a server managed and operated by a business that sells tickets to users. The server device 10 is a server for carrying out the main business of the business. The server device 10 may be installed in the business's building or on a network (cloud).
[0021] The provider terminal 20 is a terminal installed at a location where services are provided to users. For example, the provider terminal 20 is installed at an event venue where music, sports, etc. are held. For example, an employee of the event organizer uses the provider terminal 20 to determine whether a user attempting to enter the event venue has a valid ticket.
[0022] A user carries a terminal 30. For example, the user operates the terminal 30 to access the server device 10.
[0023] 3 are connected to a network. Specifically, the server device 10, the operator terminal 20, and the terminal 30 are connected to the network by wired or wireless communication means.
[0024] The configuration of the information processing system shown in Fig. 3 is an example and is not intended to be limiting. For example, a certificate issuer may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10.
[0025] [General operation] Next, the general operation of the information processing system according to the first embodiment will be described.
[0026] <Preparing your digital wallet> The user terminal 30 has a digital wallet function. A digital wallet is an electronic information storage service that guarantees information security, such as data integrity, reliability, and availability.
[0027] A user installs an application to realize a digital wallet on their terminal 30. By opening a digital wallet on terminal 30, the user can store various digital content on terminal 30, such as electronic money, identification documents such as student ID cards, passports and driver's licenses, and ticket information such as airline tickets and boarding passes.
[0028] By opening a digital wallet, users can store various digital content in the digital wallet, such as identification documents such as My Number cards, employee ID cards, and student ID cards, tickets such as airline tickets and concert tickets, electronic money, and credit cards.
[0029] Digital wallets store VCs (Verifiable Credentials), whose contents can be verified online. In the following explanation, VCs will be referred to as "credential certificates." Specific certificates issued as credential certificates will be represented by adding "VCs" after the name of the certificate. For example, a membership card issued as a credential certificate will be represented as "membership card VCs."
[0030] The user must perform a preliminary procedure to store the credential certificate in the digital wallet. Specifically, in response to the user's operation, the terminal 30 generates a pair of a public key and a private key. The terminal 30 also generates a decentralized identifier (DID).
[0031] The terminal 30 registers the generated DID (user DID; holder DID) and public key in the blockchain. By registering the user DID and public key in the blockchain, the user can store the credential certificate in a digital wallet.
[0032] <Create an account> A user who wishes to purchase a ticket for a concert or the like accesses the server device 10 and registers as a member (creates an account) (step S01 in FIG. 4).
[0033] The server device 10 acquires the user's name, sex, date of birth, address, biometric information, terminal ID, user DID, etc. from a website or the like for member registration.
[0034] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, and iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In the embodiment disclosed herein, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.
[0035] The terminal ID is unique identification information assigned to the terminal 30 owned by the user. The terminal ID may be any information as long as it is a unique ID. For example, the terminal ID may be set in the terminal 30 in advance by the manufacturer. Alternatively, the terminal ID may be generated by an application or the like installed on the terminal 30. For example, the terminal ID may be generated when the terminal 30 is started up for the first time.
[0036] When the server device 10 acquires the name, biometric information, terminal ID, etc. of the user who wishes to create an account, it searches the member management database that manages the accounts and determines whether a terminal ID identical to the acquired terminal ID is stored in the member management database.
[0037] If the same terminal ID is stored in the member management database, the server device 10 rejects the account creation. The server device 10 rejects the creation of multiple accounts from the same terminal 30.
[0038] If the same terminal ID is not stored in the member management database, the server device 10 creates an account for the user. The server device 10 stores the user's name, gender, biometric information, terminal ID, etc. in the account.
[0039] Furthermore, the server device 10 issues an "identification certificate" that proves that the user is a member of the company's service. More specifically, the server device 10 issues a membership card to the user. At this time, the server device 10 issues the membership card in the form of a credential certificate.
[0040] Specifically, the server device 10 issues a membership card VCs that certifies all or part of the information stored in the user's account. More specifically, the server device 10 issues a membership card VCs that certifies at least the user's biometric information (facial image) and terminal ID.
[0041] The server device 10 generates and stores in advance the DID of the issuer (issuer DID), the private key, and the public key. The server device 10 generates a membership card VCs that includes the issuer DID and the user DID.
[0042] The server device 10 generates a credential certificate including metadata such as the type of credential certificate, the name of the issuing organization, the date and time of issue, and the validity period, as well as the asserted content (qualification information, claims), and proofs such as the issuer's public key information and electronic signature. Note that the type of credential certificate is set to "membership card," and the asserted content includes the user's facial image and terminal ID.
[0043] The server device 10 provides the generated membership card VCs to the user terminal 30 (step S02).
[0044] For example, the server device 10 stores the generated membership card VCs in online storage. The server device 10 generates a certificate acquisition URL from the URL (Uniform Resource Locator) of the storage destination of the membership card VCs. The server device 10 provides the generated certificate acquisition URL to the terminal 30.
[0045] Furthermore, the server device 10 registers the issuer DID and the generated public key etc. in the blockchain (step S03). Alternatively, the server device 10 may register the status (valid, invalid) of the issued membership card VCs, a credential ID that uniquely identifies the membership card VCs, the issuer DID etc. in a VDR (Verifiable Data Repository).
[0046] The terminal 30 accesses the provided certificate acquisition URL and acquires the membership card VCs. The terminal 30 stores the acquired membership card VCs in the digital wallet.
[0047] <Purchase tickets> A user who has opened an account can purchase tickets for events such as music, sports, etc. The server device 10 sells tickets via a ticket sales website or the like.
[0048] The server device 10 stores information about the sold ticket (ticket information; for example, ticket ID, event name, event date and time, event location, etc.) in the user's account. Furthermore, the server device 10 issues ticket VCs. The server device 10 issues ticket VCs that use ticket information as proof using the same procedure as for membership card VCs. The terminal 30 stores the ticket VCs in its digital wallet.
[0049] <Using Membership Card VCs> When logging in to their account, the user presents the membership card VCs to the server device 10. For example, the user logs in to their account when purchasing a new ticket.
[0050] When the terminal 30 accesses the login page, the server device 10 requests the terminal 30 to present the membership card VCs. Specifically, the server device 10 transmits a "membership card request" to the terminal 30 (see FIG. 5).
[0051] In response to receiving the membership card provision request, the terminal 30 transmits the membership card VCs stored in the digital wallet to the server device 10. Specifically, the terminal 30 selects the membership card VCs stored in the digital wallet. Then, the terminal 30 signs the selected membership card VCs using a private key corresponding to the user's DID (user ID).
[0052] The terminal 30 sends an affirmative response including the signed membership card VCs and the terminal ID to the server device 10. If the membership card VCs cannot be provided, the terminal 30 sends a negative response (response to the membership card provision request) indicating this to the server device 10.
[0053] The server device 10 verifies the membership card VCs acquired from the terminal 30. Specifically, the server device 10 verifies the signature of the holder and the signature of the issuer attached to the membership card VCs. By verifying these signatures, the server device 10 confirms that the membership card VCs acquired from the user has not been tampered with and that it is a membership card issued by a trusted issuer (the service provider itself).
[0054] Furthermore, the server device 10 determines whether the terminal ID received from the terminal 30 (the terminal ID included in the acknowledgement) matches the terminal ID obtained from the membership card VCs. If the two terminal IDs do not match, the server device 10 rejects the user's login.
[0055] If the two terminal IDs match, the server device 10 searches the member management database using the terminal ID written on the membership card VCs as a key to determine whether or not a corresponding entry exists. If a corresponding entry exists, the server device 10 permits the user to log in. If a corresponding entry does not exist, the server device 10 denies the user's login.
[0056] <Using Ticket VCs> When entering an event venue, the user presents the Ticket VCs at the entrance of the event venue. For example, an employee of the event organizer requests the user to present the Ticket VCs at the entrance of the event venue.
[0057] The user operates the terminal 30 to select a ticket VC from among multiple digital contents stored in the digital wallet. The terminal 30 attaches a signature to the selected ticket VC and converts the ticket VC with the signature into a two-dimensional code. The terminal 30 displays the two-dimensional code.
[0058] An employee of the event organizer operates the business operator terminal 20 to read the two-dimensional code and obtains the ticket VCs by decoding the two-dimensional code. The business operator terminal 20 verifies the ticket VCs and displays the verification results and information written on the ticket VCs (e.g., the event name, the event date and time, and the event venue). The employee determines whether or not to allow the user to enter based on the displayed information.
[0059] Alternatively, the business operator terminal 20 may transmit the acquired ticket VCs to the server device 10 and request the server device 10 to determine whether or not the user who presented the ticket VCs should be allowed to enter. For example, when the ticket control unit 303 permits a user to enter, it stores the ticket ID included in the ticket VCs presented by the permitted user in a used ticket list. When determining whether or not to permit a user to enter, the server device 10 refers to the used ticket list, and if the ticket ID included in the ticket VCs presented by the user is listed in the used ticket list, it denies the user entry. The server device 10 prohibits multiple users from entering an event venue or the like based on a single ticket VC.
[0060] <Reissuance of Membership Card VCs> The user backs up the credentials stored in the digital wallet of the terminal 30. Specifically, the terminal 30 stores the credentials stored in the digital wallet in online storage or the like in response to an operation by the user.
[0061] The user may change the terminal 30 (so-called model change). In this case, the user needs to restore the backed-up credentials to the new terminal 30.
[0062] In this case, the terminal ID written on the restored membership card VCs is set to the terminal ID of the old model, so the user cannot log in to the account using the restored membership card VCs. Therefore, the user needs to request the server device 10 to reissue the membership card VCs.
[0063] For example, in response to an operation by the user, terminal 30 requests server device 10 to reissue membership card VCs. Terminal 30 transmits a membership card reissue request to server device 10, which includes the membership card VCs to be reissued (membership card VCs restored from online storage), biometric information (for example, a facial image obtained by taking a selfie), and a terminal ID (terminal ID of a new model) (see FIG. 6).
[0064] The server device 10 verifies the membership card VCs included in the membership card reissue request. If the verification of the membership card VCs is successful, the server device 10 performs identity verification using the membership card VCs and biometric information (selfie face image).
[0065] If the verification of the membership card VCs and identity confirmation are successful, the server device 10 identifies the user requesting reissue of the membership card VCs. Specifically, the server device 10 performs a matching process using the biometric information used for identity confirmation and multiple pieces of biometric information stored in the member management database, and identifies the user (user account) requesting reissue of the membership card VCs.
[0066] The server device 10 rewrites the terminal ID stored in the identified account with the terminal ID (terminal ID included in the membership card reissue request) sent from the new terminal 30. Furthermore, the server device 10 issues a new membership card VCs having the same contents as the already issued membership card VCs.
[0067] Specifically, server device 10 invalidates the issued membership card VCs and reissues a membership card VCs with the same contents. Server device 10 sends a response (response to the membership card reissue request) including a certificate acquisition URL for the reissued membership card VCs to terminal 30. Terminal 30 accesses the certificate acquisition URL and acquires the reissued membership card VCs. Terminal 30 stores the reissued membership card VCs in its digital wallet.
[0068] If the server device 10 fails to reissue the membership card VCs, it sends a negative response indicating that to the terminal 30. The terminal 30 notifies the user that the reissue (restore) of the membership card VCs has failed.
[0069] Next, details of each device included in the information processing system according to the first embodiment will be described.
[0070] [Device] Examples of the terminal 30 include a smartphone, a mobile phone, a game console, a mobile terminal device such as a tablet, a computer (personal computer, laptop computer), etc. The terminal 30 can be any equipment or device that can accept user operations and communicate with the server device 10, etc.
[0071] 7 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 30 according to an embodiment of the present disclosure. Referring to FIG. 7, the terminal 30 includes a communication control unit 201, an acquisition control unit 202, a usage control unit 203, and a storage unit 204.
[0072] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0073] The acquisition control unit 202 is a means for controlling the acquisition of a credential certificate.
[0074] Specifically, the acquisition control unit 202 controls the acquisition of membership cards VCs and ticket VCs.
[0075] First, the acquisition control unit 202 generates a pair of a public key and a private key, and a user DID, which is a distributed identifier. The acquisition control unit 202 registers the generated user DID and public key in the blockchain.
[0076] When a user completes a prescribed procedure on a website for membership registration or a website for purchasing tickets, a certificate acquisition URL for acquiring membership card VCs or ticket VCs is provided from the server device 10. For example, a button linked to the certificate acquisition URL is displayed on the website.
[0077] When the user presses the button, the acquisition control unit 202 accesses the certificate acquisition URL and acquires the credential certificate (membership card VCs, ticket VCs) issued by the server device 10. The acquisition control unit 202 stores the acquired credential certificate in the digital wallet.
[0078] Detailed explanations regarding user operations on the member registration website and the generation of terminal IDs will be omitted, as the operations required for member registration are obvious to those skilled in the art and are not within the scope of the present disclosure.
[0079] Furthermore, the acquisition control unit 202 has functions related to backing up, restoring, reissuing, etc. of credentials.
[0080] For example, every time the acquisition control unit 202 stores digital content (credentials) in the digital wallet, it stores a copy of the stored digital content in online storage or the like. In this case, the user sets an ID and password for accessing the online storage in the terminal 30. The acquisition control unit 202 accesses the online storage using the set ID and password and stores a copy of the digital content (credentials).
[0081] The acquisition control unit 202 acquires digital content backed up in online storage or the like in response to a predetermined operation by the user (for example, pressing a restore button). In this case, the user sets an ID and password for accessing the online storage on the new terminal 30 after changing the model. The acquisition control unit 202 accesses the online storage using the set ID and password and acquires the digital content stored in the online storage.
[0082] The acquisition control unit 202 requests the certificate issuer to reissue the credentials that include the terminal ID in the assertion of the credentials restored from the online storage or the like.
[0083] More specifically, since the terminal ID of the terminal 30 before the model change is set in the restored membership card VCs, the acquisition control unit 202 requests the server device 10 to reissue the membership card VCs.
[0084] The acquisition control unit 202 may request the server device 10 to reissue the membership card VCs in response to a predetermined action by the user (for example, an action to select a membership card VCs and instruct the reissue of the selected membership card VCs). Alternatively, the acquisition control unit 202 may automatically select credentials (for example, membership card VCs) whose claim content includes a terminal ID, and request the server device 10 to reissue the selected membership card VCs.
[0085] The acquisition control unit 202 sends a membership card reissue request to the server device 10, which includes the membership card VCs (a copy of the membership card VCs) to be reissued, biometric information (for example, a facial image obtained by taking a selfie), and terminal ID (terminal ID of the user's own terminal).
[0086] The acquisition control unit 202 receives a response (positive response, negative response) to the membership card reissue request from the server device 10.
[0087] If a positive response is received, the acquisition control unit 202 accesses the certificate acquisition URL included in the response and acquires the reissued membership card VCs. The acquisition control unit 202 stores the acquired membership card VCs in the digital wallet.
[0088] If a negative response is received, the acquisition control unit 202 notifies the user that reissuance of the membership card VCs has failed.
[0089] In this way, the acquisition control unit 202 has the functions of acquisition means and reissue control means. The acquisition means acquires a certificate issued by the service provider that includes at least the terminal ID of the other terminal and the user's biometric information. For example, the acquisition means acquires a membership card VCs that the terminal 30 before changing models stored in online storage. The reissue control means sends a certificate reissue request (membership card reissue request) that includes the acquired certificate, the user's biometric information, and the terminal ID of its own terminal to the server device 10 of the service provider (ticket sales company). The reissue control means acquires a certificate (membership card VCs) in which the terminal ID of the other terminal 30 has been updated to the terminal ID of its own terminal.
[0090] The usage control unit 203 is a means for controlling the usage of digital content (credentials) stored in the digital wallet.
[0091] For example, the usage control unit 203 processes a membership card provision request received from the server device 10. Upon receiving the membership card provision request, the usage control unit 203 selects a membership card VCs stored in the digital wallet. Then, the usage control unit 203 signs the selected membership card VCs using a private key corresponding to the user's DID (user DID).
[0092] The usage control unit 203 sends an affirmative response including the signed membership card VCs and the terminal ID to the server device 10. If the membership card VCs is not stored in the digital wallet, the usage control unit 203 sends a negative response to the server device 10 indicating that the membership card VCs cannot be provided.
[0093] Alternatively, the usage control unit 203 may convert the credential certificate selected by the user into a two-dimensional code and provide the credential certificate to an external party. For example, the usage control unit 203 may attach a signature to the ticket VCs selected by the user and convert the ticket VCs with the signature into a two-dimensional code. The terminal 30 displays the two-dimensional code.
[0094] The storage unit 204 is a means for storing information necessary for the operation of the terminal 30 .
[0095] [Server device] 8 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure. Referring to FIG. 8, the server device 10 includes a communication control unit 301, an account control unit 302, a ticket control unit 303, a reissue control unit 304, and a storage unit 305.
[0096] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 30. The communication control unit 301 also transmits data to the terminal 30. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0097] The account control unit 302 is a means for controlling the user's account.
[0098] The account control unit 302 acquires the name, sex, date of birth, address, biometric information, terminal ID, user DID, etc. from a website for member registration, etc. For example, the account control unit 302 displays a GUI (Graphical User Interface) on the terminal 30 to acquire the name, biometric information (for example, a facial image), terminal ID, user DID, etc.
[0099] When a facial image is acquired, the account control unit 302 generates feature quantities from the acquired facial image. Since existing technology can be used for the feature quantity generation process, a detailed description thereof will be omitted. For example, the account control unit 302 extracts the eyes, nose, mouth, etc. from the facial image as feature quantities. The account control unit 302 then calculates the positions of the feature quantities and the distances between the feature quantities as feature quantities (generating a feature vector consisting of multiple feature quantities).
[0100] After generating the feature amount, account control unit 302 searches the member management database using the terminal ID acquired from the user as a key, and determines whether the same terminal ID is already stored in the member management database.
[0101] If the same terminal ID is stored in the member management database, the account control unit 302 rejects the account creation. In this case, the account control unit 302 notifies the user that multiple accounts cannot be created from the same smartphone, for example.
[0102] If the same terminal ID is not stored in the member management database, account control unit 302 adds a new entry to the member management database. Account control unit 302 stores the name, sex, date of birth, address, biometric information (feature amount), terminal ID, user DID, etc. in the added entry (see FIG. 9). Note that the member management database shown in FIG. 9 is an example and is not intended to limit the items to be stored. For example, a "face image" may be registered in the member management database as biometric information.
[0103] When the user's account is created, the account control unit 302 issues a membership card to the user. The account control unit 302 issues a membership card VCs.
[0104] The account control unit 302 generates a credential certificate including the issuer DID and the user DID (the DID of the person to whom the certificate is to be issued; the user DID acquired from the user) as a membership card VCs.
[0105] Specifically, the account control unit 302 generates a credential certificate that includes metadata including the credential certificate type, issuing organization name, issuance date and time, validity period, etc., a claim, and a proof consisting of the issuer's public key information, digital signature, etc. The digital signature affixed to the credential certificate is issued using a private key corresponding to the issuer DID generated in advance.
[0106] The account control unit 302 sets the type of the credential certificate to "membership card" and generates a credential certificate as a membership card VCs, the claim of which includes the user's face image and terminal ID.
[0107] The account control unit 302 stores the credential ID of the generated membership card VCs in association with the contents of the membership card VCs (for example, the issue date and time, validity period, facial image, terminal ID, etc.). The account control unit 302 also stores the credential ID of the generated membership card VCs in the corresponding user account.
[0108] The account control unit 302 stores the generated membership card VCs in online storage (storage on the cloud), etc. The account control unit 302 generates a certificate acquisition URL from the URL of the storage location of the membership card VCs.
[0109] The account control unit 302 provides the generated certificate acquisition URL to the terminal 30. For example, the account control unit 302 displays a button on a website for member registration that is linked to the certificate acquisition URL. Furthermore, the account control unit 302 registers the issuer DID, public key, etc., that were generated in advance, in the blockchain.
[0110] If a user loses their membership status, the account control unit 302 invalidates the membership card VCs issued to that user. The account control unit 302 writes the credential ID, etc. of the membership card VCs to be invalidated in the membership card VCs revocation list.
[0111] In this way, the account control unit 302 has a function as an issuing means. The issuing means acquires the user's biometric information and the terminal ID of the first terminal 30 (the terminal 30 before the model change) from the first terminal 30. The issuing means generates a membership card VCs using the acquired user's biometric information and the terminal ID of the first terminal 30, and provides the generated certificate to the first terminal 30. The issuing means controls the first terminal 30 to acquire the certificate.
[0112] The account control unit 302 controls access to the account using the membership card VCs. For example, when the terminal 30 accesses the login page, the account control unit 302 requests the terminal 30 to provide the membership card VCs. Specifically, the account control unit 302 sends a "membership card provision request" to the terminal 30.
[0113] The account control unit 302 receives a response (positive response, negative response) to the membership card request from the terminal 30.
[0114] If a negative response is received indicating that the membership card VCs cannot be provided, the account control unit 302 denies the user from logging in to the account.
[0115] When an affirmative response including the signed membership card VCs and the terminal ID is received, the account control unit 302 verifies the acquired membership card VCs.
[0116] The account control unit 302 verifies at least one of three items related to the validity of the membership card VCs.
[0117] The first item is the verification of the electronic signature attached to the membership card VCs.
[0118] In this case, the account control unit 302 acquires the issuer DID and user DID written on the membership card VCs. The account control unit 302 acquires the public key corresponding to the acquired issuer DID from the blockchain. Similarly, the account control unit 302 acquires the public key corresponding to the acquired user DID from the blockchain.
[0119] The account control unit 302 verifies the signature of the holder (user wishing to log in to the account) and the signature of the issuer attached to the membership card VCs. By verifying these signatures, the account control unit 302 confirms that the membership card VCs obtained from the user has not been tampered with and is a certificate issued by a trustworthy issuer (its own organization).
[0120] The account control unit 302 determines that verification of the membership card VCs has been successful if it has successfully verified the signatures of the holder and issuer of the membership card VCs. The account control unit 302 determines that verification of the membership card VCs has been unsuccessful if it has failed to verify the signature of at least one of the holder and issuer of the membership card VCs.
[0121] The second item is to verify that the membership card VCs have not been set to invalid.
[0122] In this case, the account control unit 302 accesses the blockchain or VDR using the credential ID and issuer DID and confirms that the received membership card VCs is not listed on the certificate issuer's revocation list. The account control unit 302 confirms that the membership card VCs obtained from the user has not been invalidated by the issuer (its own organization) before the expiration date of the membership card VCs.
[0123] If the membership card VCs is not listed on the revocation list, the account control unit 302 determines that the verification of the membership card VCs was successful. If the membership card VCs is listed on the revocation list, the account control unit 302 determines that the verification of the acquired membership card VCs was unsuccessful.
[0124] The third item is to verify that the validity period (expiration date) of the membership card VCs has not expired.
[0125] The account control unit 302 checks the validity period set in the membership card VCs. If the validity period set in the membership card VCs has not expired, the account control unit 302 determines that the verification of the acquired membership card VCs has been successful. If the validity period set in the membership card VCs has expired, the account control unit 302 determines that the verification of the acquired membership card VCs has failed.
[0126] If the account control unit 302 determines that "verification was successful" in all or some of the first to third items, it determines that the verification of the membership card VCs obtained from the user was successful.
[0127] If the account control unit 302 determines that "verification failed" in all or some of the first to third items, it determines that verification of the membership card VCs obtained from the user has failed.
[0128] If the verification of the membership card VCs fails, the account control unit 302 denies the user from logging in to the account. The account control unit 302 denies login using membership card VCs that may have been tampered with or invalid membership card VCs.
[0129] If the verification of the membership card VCs is successful, the account control unit 302 determines whether the terminal ID received from the terminal 30 (the terminal ID included in the positive response) matches the terminal ID obtained from the membership card VCs. If the two terminal IDs do not match, the server device 10 rejects the user's login. The fact that the two terminal IDs do not match means that a third party who has not been issued a membership card VCs may have fraudulently obtained the membership card VCs and is attempting to log in to the account.
[0130] If the two terminal IDs match, the account control unit 302 searches the member management database using the terminal ID written on the membership card VCs as a key to determine whether or not a corresponding entry exists. If a corresponding entry exists, the account control unit 302 allows the user to log in. If a corresponding entry does not exist, the account control unit 302 denies the user's login.
[0131] The ticket control unit 303 is a means for controlling ticket sales. The ticket control unit 303 sells tickets to users who have logged in to their accounts via a ticket sales website or the like.
[0132] The ticket control unit 303 stores information about the sold ticket (ticket information; for example, ticket ID, event name, event date and time, event location, etc.) in the user's account. Furthermore, the ticket control unit 303 issues ticket VCs. The ticket control unit 303 issues ticket VCs that use ticket information as proof using the same procedure as membership card VCs.
[0133] A detailed explanation of ticket sales will be omitted here, as the details of online ticket sales are obvious to those skilled in the art and are not within the scope of the present disclosure.
[0134] The reissue control unit 304 is a means for controlling the reissue of membership cards VCs. The reissue control unit 304 processes membership card reissue requests received from the terminal 30.
[0135] 10 is a flowchart showing an example of the operation of the reissue control unit 304 according to an embodiment of the present disclosure. The operation of the reissue control unit 304 will be described with reference to FIG.
[0136] When a membership card reissue request is received, the reissue control unit 304 verifies the membership card VCs included in the request (step S101). The reissue control unit 304 verifies the membership card VCs in the same way as the account control unit 302.
[0137] If the verification of the membership card VCs fails (step S102, No branch), the reissue control unit 304 transmits a negative response indicating that the membership card VCs cannot be reissued to the terminal 30 (step S103).
[0138] If the verification of the membership card VCs is successful (step S102, Yes branch), the reissue control unit 304 executes identity verification using the membership card VCs and biometric information (self-portrait face image) (step S104).
[0139] Specifically, the reissue control unit 304 determines whether the biometric information (facial image of the account holder) obtained from the membership card VCs substantially matches the biometric information (selfie facial image) of the user requesting reissue of the membership card VCs using the terminal 30, and performs identity verification.
[0140] The reissue control unit 304 generates feature amounts from each of the face image and the self-portrait face image acquired from the membership card VCs.
[0141] Next, the reissue control unit 304 executes a matching process (one-to-one matching) using the two generated feature amounts. Specifically, the reissue control unit 304 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the reissue control unit 304 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0142] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the reissue control unit 304 determines that the identity verification is successful. If the similarity is equal to or less than the predetermined value, the reissue control unit 304 determines that the identity verification is unsuccessful.
[0143] If the identity verification fails (step S105, No branch), the reissue control unit 304 sends a negative response indicating that the membership card VCs cannot be reissued to the terminal 30 (step S103). If the identity verification fails, the reissue control unit 304 determines that a person other than the account holder (membership card holder) is requesting the reissue of the membership card VCs, and denies the reissue of the membership card VCs.
[0144] If the identity verification is successful (step S105, branch Yes), the reissue control unit 304 identifies the user requesting the reissue of the membership card VCs (step S106).
[0145] The reissue control unit 304 sets the features generated from the facial image used for identity verification (a facial image obtained from the membership card VCs or a selfie facial image) as the target for matching, and performs a matching process (1:N matching; N is a positive integer, the same below) between the features and the features registered in the member management database.
[0146] The reissue control unit 304 calculates the similarity between the feature to be compared and each of the multiple feature values on the registration side. The reissue control unit 304 identifies the user of the entry having the feature value with the highest similarity to the feature value to be compared among the multiple feature values registered in the member management database as the user requesting the reissue of membership card VCs.
[0147] Once the user is identified, the reissue control unit 304 rewrites the terminal ID stored in the identified entry (account) to the terminal ID sent from the new terminal 30 (the terminal ID included in the membership card reissue request) (updates the terminal ID; step S107).
[0148] Thereafter, the reissue control unit 304 issues a new membership card VCs having the same contents as the already issued membership card VCs (reissue of membership card VCs; step S108).
[0149] Specifically, the reissue control unit 304 invalidates the membership card VCs that has already been issued, and reissues a membership card VCs with the same contents.
[0150] For example, the reissue control unit 304 uses the credential ID stored in the account of the user identified by the matching process using biometric information to obtain the contents of the membership card VCs already issued to that user. The reissue control unit 304 generates a new membership card VCs using the obtained contents. The reissue control unit 304 generates a membership card VCs that includes a new terminal ID (the terminal ID of the terminal 30 after the model change) and the user's biometric information.
[0151] Alternatively, the reissue control unit 304 may rewrite the terminal ID included in the claims of the membership card VCs obtained from the terminal 30 to the terminal ID included in the membership card reissue request (the terminal ID of the terminal 30 after the model change) and generate a new membership card VCs.
[0152] The reissue control unit 304 reissues the membership card VCs by sending an affirmative response including a certificate acquisition URL for the generated new membership card VCs to the terminal 30. The reissue control unit 304 stores the credential ID etc. of the reissued membership card VCs (new membership card VCs).
[0153] As described above, the reissue control unit 304 functions as both an identity verification means and a reissue means. The identity verification means receives a certificate reissue request (membership card reissue request) from the second terminal 30 (terminal 30 after the model change) used by the user, the certificate (membership card VCs) issued to the user, the user's biometric information, and the terminal ID of the second terminal. The identity verification means performs identity verification using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request. If the identity verification is successful, the reissue means identifies the user who wishes to have the certificate reissued by performing a matching process using the biometric information used for identity verification and the biometric information stored in the member management database. The reissue means updates the terminal ID of the first terminal 30 (terminal 30 before the model change), which is stored in association with the biometric information of the identified user, to the terminal ID of the second terminal. Furthermore, the reissue means reissues the certificate in which the terminal ID of the first terminal 30 has been updated to the terminal ID of the second terminal 30.
[0154] In this way, the reissue control unit 304 reissues the membership card VCs obtained from the terminal 30 when the terminal ID stored in the account identified by the matching process differs from the terminal ID included in the membership card reissue request.
[0155] Furthermore, the reissue control unit 304 has a function as a verification means for verifying the certificate included in the certificate reissue request.
[0156] The storage unit 305 is a means for storing information necessary for the operation of the server device 10. The storage unit 305 stores information about a certificate issued to a user, which is a certificate including at least the user's biometric information and the terminal ID of the first terminal 30 used by the user, in association with the user's biometric information and the terminal ID of the first terminal 30. The information about the certificate issued to a user is, for example, the credential ID of the certificate. Alternatively, the information about the certificate issued to a user is the content described on the certificate.
[0157] [Operator terminal] Examples of the business operator terminal 20 include mobile terminal devices such as smartphones, mobile phones, game consoles, and tablets, as well as computers (personal computers, laptop computers). The business operator terminal 20 can be any equipment or device that can accept operations from employees of the event organizer and communicate with the server device 10. The configuration of the business operator terminal 20 is clear to those skilled in the art, so a detailed description will be omitted.
[0158] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described.
[0159] 11 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. With reference to FIG. 11, the operation of the information processing system according to the first embodiment regarding the reissuance of the membership card VCs will be described.
[0160] The terminal 30 transmits a membership card reissue request including the user's biometric information, terminal ID, and membership card VCs to the server device 10 (step S01).
[0161] The server device 10 verifies the acquired membership card VCs (step S02).
[0162] If the server device 10 has successfully verified the membership card VCs, it performs identity verification using biometric information (step S03).
[0163] If the identity verification is successful, the server device 10 updates the terminal ID stored in the user's account (step S04).
[0164] The server device 10 reissues the membership card VCs using the updated terminal ID (step S05).
[0165] The terminal 30 stores the reissued membership card VCs in the digital wallet (step S06).
[0166] Next, a modified example of the first embodiment will be described.
[0167] <Variation 1> In the above embodiment, the server device 10 issues membership cards VCs as identity certificates. However, the server device 10 may issue other types of identity certificates. For example, the server device 10 may issue employee cards VCs that certify that the user is an employee of the company. Alternatively, the server device 10 may issue work history VCs that certify the work history of employees. Alternatively, the server device 10 may issue warranty certificates VCs for products sold by the company. In other words, the server device 10 issues certificates for services that can be provided or products that can be sold to one terminal 30.
[0168] <Variation 2> When reissuing membership card VCs, server device 10 may confirm that the terminal ID obtained from membership card VCs acquired from terminal 30 is different from the terminal ID included in the membership card reissue request. If the two terminal IDs are different, reissue control unit 304 may permit reissue of membership card VCs. In other words, reissue control unit 304 may refuse to reissue a membership card from terminal 30 that was issued (provided) membership card VCs.
[0169] <Variation 3> In the above embodiment, the reissue control unit 304 identifies a user who wishes to have their membership card VCs reissued by a matching process using biometric information. However, the reissue control unit 304 may also identify a user who wishes to have their membership card VCs reissued by using a terminal ID obtained from the membership card VCs acquired from the terminal 30 (the membership card VCs provided to the terminal 30 before the model change).
[0170] If the reissue control unit 304 successfully verifies the membership card VCs obtained from the terminal 30 and successfully confirms the identity of the user who wishes to have the membership card VCs reissued, it may identify the person who wishes to have the membership card VCs reissued using the terminal ID obtained from the obtained membership card VCs.
[0171] <Variation 4> The server device 10 may perform identity verification of the user when creating an account for the user. For example, the account control unit 302 acquires from the user an identification card VCs such as a driver's license or a passport and a selfie face image. The account control unit 302 may set as a condition for creating an account that identity verification using the face image acquired from the identification card VCs and the selfie face image is successful.
[0172] <Variation 5> The server device 10 may perform identity verification when a user logs in to an account using the membership card VCs. In this case, upon receiving a membership card provision request from the server device 10, the terminal 30 transmits the user's face image (selfie face image), membership card VCs, and terminal ID to the server device 10.
[0173] The account control unit 302 performs identity verification using a facial image obtained from the membership card VCs and a selfie image of the user. The account control unit 302 may permit login if identity verification is successful, membership card VCs is successfully verified, and the two terminal IDs (the terminal ID obtained from the membership card VCs and the terminal ID received from the terminal 30) match.
[0174] <Variation 6> When opening a digital wallet, the terminal 30 may perform identity verification of the person who opened the digital wallet. The terminal 30 may open the digital wallet if identity verification using an identification document such as a passport is successful.
[0175] <Variation 7> The server device 10 may issue ticket VCs to the user, the ticket VCs being certified based on the user's biometric information and terminal ID. In this case, when the user uses the ticket VCs (when the user enters an event venue), the terminal 30 may provide the user's selfie face image, ticket VCs, and terminal ID to the provider terminal 20. If the provider terminal 20 successfully verifies the ticket VCs, successfully verifies the user's identity using the face image, and the terminal ID obtained from the ticket VCs matches the terminal ID acquired from the terminal 30, the provider terminal 20 may permit the user to enter the event venue.
[0176] In other words, the operator terminal 20 may allow the user who purchased the ticket to enter the event venue if the user presents ticket VCs (valid ticket VCs) using the terminal 30 used to purchase the ticket.
[0177] <Variation 8> When the ticket VCs include a terminal ID, the terminal 30 may request the server device 10 to reissue the ticket VCs. When the user changes the model, the new terminal 30 may transmit a ticket reissue request to the server device 10, which includes the ticket VCs restored from online storage or the like, the user's facial image, and the terminal ID of the terminal itself.
[0178] The reissue control unit 304 may reissue tickets VCs in the same manner as membership cards VCs.
[0179] As described above, the terminal 30 according to the first embodiment registers the user's biometric information and terminal ID with the server device 10 when receiving a service from a service provider. The server device 10 issues a certificate to the user, including the acquired biometric information and terminal ID. The terminal 30 backs up the certificate issued to the user as appropriate. When the user changes their device, the new terminal 30 acquires the backed-up certificate and transmits the acquired certificate, the user's biometric information, and the terminal ID of the terminal to the server device 10, requesting a certificate reissue. The server device 10 performs identity verification using biometric information obtained from the certificate to be reissued and biometric information acquired from the terminal 30. By performing identity verification, the server device 10 confirms that the certificate holder and the person requesting certificate reissue are the same person. If identity verification is successful, the server device 10 performs a matching process using the biometric information used for identity verification and pre-stored biometric information to identify the user requesting certificate reissue. The server device 10 updates the terminal ID stored in association with the biometric information of the identified user to the acquired terminal ID. Furthermore, the server device 10 reissues the certificate with the updated terminal ID to the user. As a result, the user can store the certificate acquired on the terminal 30 before changing the model in the new terminal 30 after changing the model. The information processing system enables a certificate to be reissued through a simple procedure even when a user who receives a service using terminal authentication changes the model of a smartphone or the like.
[0180] As explained above, in the information processing system disclosed herein, a certificate (membership card VCs) is generated and issued using a terminal ID, which is a unique ID for each terminal 30, and biometric information of the person to whom the certificate is to be issued. Furthermore, in the information processing system disclosed herein, the terminal ID is stored inside the user's terminal 30, in the content claimed in the membership card VCs, and in the member management database of the server device 10. In the information processing system, the terminal 30 and the server device 10 each use the terminal ID to resolve problems that may arise when the terminal 30 undergoing terminal authentication is changed.
[0181] Next, the hardware of each device constituting the information processing system will be described. Fig. 12 is a diagram showing an example of the hardware configuration of the server device 10.
[0182] The server device 10 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 12. For example, the server device 10 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0183] 12 is not intended to limit the hardware configuration of the server device 10. The server device 10 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the server device 10 is not intended to be limited to the example shown in FIG. 12, and for example, the server device 10 may include multiple processors 311.
[0184] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0185] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0186] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.
[0187] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0188] The functions of the server device 10 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by semiconductor chips.
[0189] The business operator terminal 20 and the terminal 30 can also be configured by information processing devices, similar to the server device 10, and their basic hardware configurations are no different from that of the server device 10, so a description thereof will be omitted.
[0190] Server device 10, which is an information processing device, is equipped with a computer, and functions of server device 10 can be realized by having the computer execute a program. Furthermore, server device 10 executes a control method for server device 10 by the program. Similarly, terminal 30 is equipped with a computer, and functions of terminal 30 can be realized by having the computer execute a program. Furthermore, terminal 30 executes a control method for terminal 30 by the program.
[0191] [Variations] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0192] In the above embodiment, the terminal 30 is configured to store a copy of the acquired credential certificate in online storage or the like every time the terminal 30 acquires the credential certificate. However, the terminal 30 may back up the credential certificate in online storage or the like in response to an explicit instruction from the user. Alternatively, the terminal 30 may back up a credential certificate selected by the user in online storage or the like.
[0193] Alternatively, the terminal 30 may back up the credential certificate in a storage medium such as a USB (Universal Serial Bus) memory, etc. When restoring the credential certificate, the terminal 30 may obtain the credential certificate from the USB memory.
[0194] The server device 10 may provide the certificate acquisition URL of the membership card VCs to the terminal 30 by email or the like, rather than providing the certificate acquisition URL to the terminal 30 via a website for member registration or the like. For example, the server device 10 may send a message including the certificate acquisition URL to the email address registered by the user in his / her account.
[0195] In the above embodiment, the digital wallet used by the user is configured inside the terminal 30. However, the digital wallet may also be configured online. That is, the terminal 30 may use a web wallet.
[0196] In the above embodiment, the server device 10 operated by the service provider issues a credential certificate that does not require a certification authority for certificate verification. However, the server device 10 may also issue a certificate that requires a certification authority (a certificate based on a public key infrastructure).
[0197] Some functions of the server apparatus 10 and the terminal 30 may be implemented in another apparatus, device, etc. More specifically, the above-described "reissue control unit (reissue control means)" and the like may be implemented in any of the apparatuses included in the system.
[0198] The form of data transmission and reception between each device (for example, server device 10, terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable that encrypted data be transmitted and received.
[0199] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0200] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0201] The above explanation makes clear the industrial applicability of the present invention, and the present invention is suitably applicable to information processing systems including service providers that provide services to users using certificates stored in digital wallets.
[0202] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.
[0203] [Appendix 1] a storage means for storing information about a certificate issued to a user, the certificate including at least biometric information of the user and a terminal ID of a first terminal used by the user, in association with the biometric information of the user and the terminal ID of the first terminal; an identity verification means for, when receiving a certificate reissue request including the certificate issued to the user, the user's biometric information, and the terminal ID of the second terminal from a second terminal used by the user, verifying the identity of the user using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; a reissuing means for, if the identity verification is successful, identifying a user who desires a certificate reissue by executing a matching process using the biometric information used for the identity verification and the stored biometric information, updating the terminal ID of the first terminal stored in association with the biometric information of the identified user to the terminal ID of the second terminal, and reissuing the certificate in which the terminal ID of the first terminal has been updated to the terminal ID of the second terminal; A server device comprising:
[0204] [Appendix 2] 2. The server device according to claim 1, further comprising a verification unit that verifies the certificate included in the certificate reissue request.
[0205] [Appendix 3] The server device described in Appendix 2 further comprises an issuing means for acquiring biometric information of the user and a terminal ID of the first terminal from the first terminal, generating the certificate using the acquired biometric information of the user and the terminal ID of the first terminal, and providing the generated certificate to the first terminal.
[0206] [Appendix 4] The server device according to any one of Supplementary Notes 1 to 3, wherein the certificate is a credential certificate.
[0207] [Appendix 5] an acquisition means for acquiring a certificate issued by a service provider, the certificate including at least a terminal ID of the other terminal and biometric information of the user; a reissue control means for transmitting a certificate reissue request including the acquired certificate, the biometric information of the user, and the terminal ID of the user's own terminal to a server device of the service provider; A terminal comprising:
[0208] [Appendix 6] The terminal according to claim 5, wherein the reissue control means acquires the certificate in which the terminal ID of the other terminal has been updated to the terminal ID of the terminal itself.
[0209] [Appendix 7] The terminal according to claim 6, wherein the acquisition means acquires the certificate stored in a storage on a network by the other terminal.
[0210] [Appendix 8] The terminal according to any one of appendices 5 to 7, wherein the certificate is a credential certificate.
[0211] [Appendix 9] In the server device, a certificate including at least biometric information of a user and a terminal ID of a first terminal used by the user, wherein information about the certificate issued to the user, the biometric information of the user, and the terminal ID of the first terminal are stored in association with each other; when a certificate reissue request including the certificate issued to the user, the user's biometric information, and the terminal ID of the second terminal is received from a second terminal used by the user, the certificate reissue request performs identity verification using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; A control method for a server device, which, if the identity verification is successful, identifies the user who wishes to have the certificate reissued by performing a matching process using the biometric information used for the identity verification and the stored biometric information, updates the terminal ID of the first terminal stored in correspondence with the biometric information of the identified user to the terminal ID of the second terminal, and reissues the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal.
[0212] [Appendix 10] The computer installed in the server device a process of storing information about a certificate issued to the user, the certificate including at least biometric information of the user and a terminal ID of a first terminal used by the user, in association with the biometric information of the user and the terminal ID of the first terminal; a process of receiving a certificate reissue request including the certificate issued to the user, the user's biometric information, and the terminal ID of the second terminal from a second terminal used by the user, and performing identity verification using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; If the identity verification is successful, a process of identifying a user who desires to have a certificate reissued by executing a matching process using the biometric information used for the identity verification and the stored biometric information, updating the terminal ID of the first terminal stored in association with the biometric information of the identified user to the terminal ID of the second terminal, and reissuing the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal; A computer-readable storage medium that stores a program for executing the above.
[0213] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 4, which are dependent on Supplementary Note 1, may also be dependent on Supplementary Notes 9 and 10 in the same dependent relationship as Supplementary Notes 2 to 4. Furthermore, not limited to Supplementary Notes 1, 9, and 10, but within the scope of each of the above-mentioned embodiments, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems.
[0214] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]
[0215] 10 Server device 20 Operator terminal 30 devices 100 Server device 101 Memory means 102 Identity Verification Methods 103 Reissue Method 201 Communication control unit 202 Acquisition control section 203 Usage Control Unit 204 Storage section 301 Communication Control Unit 302 Account control section 303 Ticket Control Unit 304 Reissue control section 305 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface
Claims
1. a storage means for storing information about a certificate issued to a user, the certificate including at least biometric information of the user and a terminal ID of a first terminal used by the user, in association with the biometric information of the user and the terminal ID of the first terminal; an identity verification means for, when receiving a certificate reissue request including the certificate issued to the user, the user's biometric information, and the terminal ID of the second terminal from a second terminal used by the user, verifying the identity of the user using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; a reissuing means for, when the identity verification is successful, executing a matching process using the biometric information used for the identity verification and the stored biometric information to identify a user who desires to have a certificate reissued, updating the terminal ID of the first terminal stored in association with the biometric information of the identified user to the terminal ID of the second terminal, and reissuing the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal; A server device comprising:
2. 2. The server device according to claim 1, further comprising: a verifying unit that verifies the certificate included in the certificate reissue request.
3. 3. The server device according to claim 2, further comprising an issuing means for acquiring biometric information of the user and a terminal ID of the first terminal from the first terminal, generating the certificate using the acquired biometric information of the user and the terminal ID of the first terminal, and providing the generated certificate to the first terminal.
4. The server device according to claim 1 , wherein the certificate is a credential certificate.
5. an acquisition means for acquiring a certificate issued by a service provider and including at least a terminal ID of the other terminal and biometric information of the user; a reissue control means for transmitting a certificate reissue request including the acquired certificate, the biometric information of the user, and the terminal ID of the user's own terminal to the server device of the service provider; A terminal comprising:
6. 6. The terminal according to claim 5, wherein said reissue control means acquires said certificate in which the terminal ID of said other terminal has been updated to the terminal ID of said terminal itself.
7. The terminal according to claim 6 , wherein said acquiring means acquires said certificate stored in a storage on a network by said other terminal.
8. The terminal according to claim 5 , wherein the certificate is a credential certificate.
9. In the server device, a certificate including at least biometric information of a user and a terminal ID of a first terminal used by the user, wherein information about the certificate issued to the user, the biometric information of the user, and the terminal ID of the first terminal are stored in association with each other; when a certificate reissue request including the certificate issued to the user, the user's biometric information, and the terminal ID of the second terminal is received from a second terminal used by the user, the certificate reissue request performs identity verification using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; A control method for a server device, which, if the identity verification is successful, identifies the user who wishes to have the certificate reissued by performing a matching process using the biometric information used for the identity verification and the stored biometric information, updates the terminal ID of the first terminal stored in correspondence with the biometric information of the identified user to the terminal ID of the second terminal, and reissues the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal.
10. The computer installed in the server device a process of storing information about a certificate issued to a user, the certificate including at least biometric information of the user and a terminal ID of a first terminal used by the user, in association with the biometric information of the user and the terminal ID of the first terminal; a process of receiving a certificate reissue request including the certificate issued to the user, the user's biometric information, and the terminal ID of the second terminal from a second terminal used by the user, and performing identity verification using the biometric information obtained from the certificate included in the certificate reissue request and the biometric information included in the certificate reissue request; If the identity verification is successful, a process of identifying a user who desires to have a certificate reissued by executing a matching process using the biometric information used for the identity verification and the stored biometric information, updating the terminal ID of the first terminal stored in association with the biometric information of the identified user to the terminal ID of the second terminal, and reissuing the certificate with the terminal ID of the first terminal updated to the terminal ID of the second terminal; A program to execute.
Citation Information
Patent Citations
Verification program, verification method, and information processing apparatus
JP2023121536A
Device asserted verifiable credential
US20230179402A1
Authentication server device, authentication system, and authentication method
JP6841781B2