Credential data generation system, credential data generation method, and program

The credential data generation system allows consumers to provide only necessary information using two-dimensional codes and communication, addressing unnecessary data provision and reducing service provider risks and workload.

JP7758240B1Active Publication Date: 2025-10-22TOPPAN HOLDINGS INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025053256
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-10-22
Estimated Expiration
2045-03-27

AI Technical Summary

Technical Problem

Existing systems provide consumers with personal data beyond what is necessary for using a service, leading to unnecessary risks and workload for service providers.

Method used

A credential data generation system that allows consumers to provide only mandatory and optional information necessary for service usage, using two-dimensional codes for mandatory information and communication for optional information, with verification and management by an intermediate certification authority.

Benefits of technology

Enables consumers to provide only necessary information, reducing service provider risks and workload while ensuring secure and efficient data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007758240000001_ABST
    Figure 0007758240000001_ABST
Patent Text Reader

Abstract

To provide a credential data generation system, a credential data generation method, and a program that, when a consumer uses a specific service, enables the consumer to provide only the information necessary to use the service, and enables the service provider to reduce the risk and workload caused by managing the provided information. [Solution] A credential data generation system comprising: a memory unit that stores personal data of users of the service; a request information setting unit that sets request information indicating information necessary to use the service; a personal data acquisition unit that acquires personal data corresponding to the request information from the memory unit when the user uses the service; an information provision processing unit that provides the personal data to the provider as provision information that the user provides to the provider; and an information reception processing unit that displays the provision information on the provider's terminal.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a credential data generation system, a credential data generation method, and a program. [Background technology]

[0002] Conventionally, when consumers use a particular service, they may be asked by the service provider to provide personal information or other information necessary for using the service. For example, the service provider may require consumers to present or submit identification documents for the purpose of verifying their identity or age. In this case, by presenting or submitting their identification documents, consumers end up providing the service provider with information that is not actually necessary for using the service.

[0003] For example, when verifying age, a user may present a driver's license to a service provider. In this case, the service user only needs to have the service provider verify the photograph and date of birth contained in the driver's license. However, the service provider can also verify other information contained in the driver's license. On the other hand, service providers can only verify identity using information that is unnecessary for providing the service. This means that service providers face unnecessary risks and tasks, such as the risk of leakage due to the retention of unnecessary information and the need to mask unnecessary information.

[0004] In recent years, with the digitalization of society, personal data including not only personal information but also information on consumers' attributes, careers, qualifications, etc., has come to be managed digitally. Accordingly, various technologies have been proposed that enable consumers to provide personal data to service providers as information necessary for using a particular service when using the service. For example, Patent Document 1 listed below discloses a technology in which a service user sets a permitted range of use of personal information in advance, and the service provider can view personal information within the permitted range of use. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent No. 7290359 Summary of the Invention [Problem to be solved by the invention]

[0006] However, with the technology described in Patent Document 1, all personal data within the set permitted scope of use is provided to the service provider, which has remained an issue, as consumers may end up providing the service provider with personal data that is not actually necessary for using the service.

[0007] In view of the above-mentioned problems, the object of the present invention is to provide a credential data generation system, credential data generation method, and program that, when a consumer uses a specific service, allows the consumer to provide only the information necessary to use the service, and that enables the service provider to reduce the risks and workload associated with managing the information provided. [Means for solving the problem]

[0008] In order to solve the above-mentioned problems, a credential data generation system according to one aspect of the present invention includes a storage unit that stores personal data of a user of a service; a request information setting unit that sets request information indicating information that a provider of the service requests the user to provide as information necessary for using the service; a personal data acquisition unit that acquires the personal data corresponding to the request information from the storage unit when the user uses the service; an information provision processing unit that provides the personal data acquired from the storage unit to the provider as provided information to be provided to the provider so that the user can use the service; and an information reception processing unit that acquires the provided information and displays it on a terminal of the provider. the information set as the request information includes mandatory information that must be provided and optional information that may be provided voluntarily, the mandatory information being information necessary for using a main service, and the optional information being information necessary for using a service that is not a main service but becomes available by providing information; the information provision processing unit comprises: a user code generation unit that generates a two-dimensional code including personal data corresponding to the mandatory information from the personal data acquired by the personal data acquisition unit as a user code to be used by the user to provide the mandatory information to the provider, and displays the generated two-dimensional code on the user's terminal; and a data transmission unit that transmits the personal data corresponding to the optional information from the personal data acquired by the personal data acquisition unit from the user's terminal to the provider's terminal; and the information reception processing unit comprises: a code reading unit that reads the user code presented by the user at a storefront using the provider's terminal, and displays the mandatory information on the provider's terminal; and a data receiving unit that receives the optional information transmitted from the user's terminal at the provider's terminal. A credential data generation system.

[0009] A credential data generation method according to one aspect of the present invention includes a storage step of storing personal data of a user of a service in a storage unit; a request information setting step of setting request information indicating information that a provider of the service requests the user to provide as information necessary for using the service; a personal data acquisition step of acquiring the personal data corresponding to the request information from the storage unit when the user uses the service; an information provision processing step of providing the personal data acquired from the storage unit to the provider as provided information to be provided to the provider so that the user can use the service; and an information reception processing step of acquiring the provided information and displaying it on a terminal of the provider. the information set as the request information includes mandatory information that must be provided and optional information that may be provided voluntarily, the mandatory information being information necessary for using a main service, and the optional information being information necessary for using a service that is not a main service but becomes available by providing information; the information providing process includes a user code generation process for generating a two-dimensional code including personal data corresponding to the mandatory information among the personal data acquired by the personal data acquisition process as a user code to be used by the user to provide the mandatory information to the provider, and displaying the generated two-dimensional code on the user's terminal; and a data transmission process for transmitting personal data corresponding to the optional information among the personal data acquired by the personal data acquisition process from the user's terminal to the provider's terminal; the information receiving process includes a code reading process for reading the user code presented by the user into the provider's terminal at a storefront, and displaying the mandatory information on the provider's terminal; and a data receiving process for receiving the optional information transmitted from the user's terminal at the provider's terminal. A computer-implemented method for generating credential data.

[0010] A program according to one aspect of the present invention causes a computer to function as: a storage means for storing personal data of a user of a service in a storage unit; a request information setting means for setting request information indicating information that a provider of the service requests the user to provide as information necessary for using the service; a personal data acquisition means for acquiring the personal data corresponding to the request information from the storage unit when the user uses the service; an information provision processing means for providing the personal data acquired from the storage unit to the provider as provided information to be provided to the provider in order for the user to use the service; and an information reception processing means for acquiring the provided information and displaying it on a terminal of the provider. The information set as the request information includes mandatory information that must be provided and optional information that may be provided voluntarily, the mandatory information is information necessary for using a service that is provided primarily, and the optional information is information necessary for using a service that is not a main service but becomes available by providing information, and the information provision processing means generates a two-dimensional code including personal data corresponding to the mandatory information among the personal data acquired by the personal data acquisition means as a user code to be used by the user to provide the mandatory information to the provider, and a data transmitting means for transmitting, from the user's terminal to the provider's terminal, personal data corresponding to the optional provision information among the personal data acquired by the personal data acquiring means. The information receiving processing means functions as a code reading means for displaying, at a storefront, on the provider's terminal the required provision information acquired by reading, at the provider's terminal, the user code presented by the user, and a data receiving means for receiving, at the provider's terminal, the optional provision information transmitted from the user's terminal. It is a program. [Effects of the Invention]

[0011] According to the present invention, when a consumer uses a specific service, the consumer can provide only the information necessary to use the service, and the service provider can reduce the risks and workload associated with managing the information provided. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram showing an overview of a credential data generation service according to the present embodiment. [Figure 2] 1 is a block diagram showing an example of the configuration of a credential data generation system according to an embodiment of the present invention. [Figure 3] 1 is a block diagram showing an example of a functional configuration of a credential data generation device according to an embodiment of the present invention; [Figure 4] FIG. 10 is a diagram showing an example of a provider code presentation screen according to the present embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of a user home screen according to the present embodiment. [Figure 6] FIG. 10 is a diagram showing an example of a request information display screen according to the embodiment. [Figure 7] FIG. 10 is a diagram showing an example of a user code presentation screen (without transmission data) according to the present embodiment. [Figure 8] FIG. 10 is a diagram showing an example of a user code presentation screen (with transmission data) according to the present embodiment. [Figure 9] FIG. 10 is a diagram showing an example of a provided information display screen (verification required) according to the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a provided information display screen (verification not required) according to the present embodiment. [Figure 11] FIG. 10 is a sequence diagram showing an example of a processing flow in a credential data generation service according to the present embodiment. [Figure 12] FIG. 10 is a block diagram showing an example of the functional configuration of a credential data generation device in a modified example of the present embodiment. [Figure 13] 10A and 10B are diagrams showing an example of a request information display screen and a group creation screen in a modified example of the embodiment. [Figure 14] FIG. 10 is a diagram showing an example of a request information display screen for group members in a modified example of the embodiment. [Figure 15] FIG. 10 is a sequence diagram showing an example of the processing flow in a credential data generation service in a modified example of the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0014] <1. Overview of the Credential Data Generation Service> An overview of the credential data generation service according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an overview of the credential data generation service according to this embodiment.

[0015] The credential data generation service SA shown in FIG. 1 is a service that allows, when a service user U uses a service provided by a service provider P, to exchange only the information necessary to use the service between the provider P and the user U. Note that the credential data generation service SA and the service provided by the provider P are different services. The provider P is, for example, a service provider or other service provider, but is not limited to such an example. The user U is, for example, a consumer, but is not limited to such an example.

[0016] The credential data generation service SA is used, for example, for age verification and credential verification. Age verification is performed, for example, when selling alcohol or tobacco, or when entering a restaurant such as an izakaya. Credential verification is performed, for example, when presenting a driver's license when renting a car, presenting a student ID card when using a student discount at a movie theater, karaoke, or beauty salon, or presenting various information from your student days (such as the school you attended, the club activities you were involved in, etc.) when job hunting.

[0017] The credential data generation platform PF shown in Fig. 1 is a platform for exchanging information between a provider P and a user U in a credential data generation service SA. The credential data generation platform PF provides a provider application AP1 and a user application AP2.

[0018] The provider application AP1 is an application that enables the provider P to use the credential data generation platform PF. Using the provider application AP1, the provider P performs processes such as requesting necessary information from the user U (information request process), receiving necessary information from the user U (information receiving process), and verifying the information received from the user U (verification process).

[0019] In the information request process, the provider P can register request information indicating information that the provider P requests the user U to provide as information necessary for using the service. The content of the request information can vary depending on the content of the service. The request information can be, for example, information (e.g., attribute information) that can be used to confirm whether the user U meets the criteria for using the service, or information (e.g., qualification information) that can be used to confirm whether the user U has the qualifications necessary to use the service. The attribute information can be, for example, the age of the user U. The qualification information can be, for example, a student ID card, employee ID card, driver's license, disability certificate, etc. that the user U holds.

[0020] The provider P can register, as the requested information, information that must be provided (hereinafter also referred to as "mandatory information") and information that is optional to provide (hereinafter also referred to as "optional information"). Mandatory information is, for example, information necessary to use the main service (basic service). Optional information is, for example, information that is not one of the main services provided but is necessary to use a service that becomes available if the information is provided, or information that the provider P uses for marketing purposes.

[0021] As an example, in the case of a service that allows users to receive a discount by proving that they are a student (student ID discount service), the required information is information indicating "student status," and the optional information is "usage status of the student ID discount service" and "membership information for the student ID discount service." In this case, user U can receive a discount by providing the required information. User U can also receive, for example, a further discount by providing the optional information.

[0022] The request information may be set by input by the provider P or may be set by a function of the provider application AP1. The provider application AP1 can set the request information by, for example, referring to a service catalog database DB1 and a terms of use database DB2 and extracting information to be set from the service catalog and terms of use of the service for which the request information is to be set.

[0023] The credential data generation platform PF also provides a service catalog database DB1 and a terms of use database DB2, which are referenced by the provider application AP1. The service catalog database DB1 stores information (hereinafter also referred to as "service information") about services provided by a provider P using the credential data generation platform PF. The terms of use database DB2 stores the terms of use for services provided by a provider P using the credential data generation platform PF.

[0024] Furthermore, in the information request process, the provider P can create a two-dimensional code (hereinafter also referred to as a "provider code") used to provide the requested information to the user U. The provider P can create a provider code including the requested information using the provider app AP1. The provider P can present the created provider code to the user U and have the user U read it on their terminal (hereinafter also referred to as a "user terminal"), thereby presenting the requested information to the user U. The provider code may be presented to the user U, for example, by being placed on a medium such as printed paper in the store, or may be presented to the user U by being displayed on the provider P's terminal (hereinafter also referred to as a "provider terminal").

[0025] In the information receiving process, the provider P can receive information provided by the user U (hereinafter also referred to as "provided information") by reading the user code presented by the user U with the provider terminal. The user code is a two-dimensional code used by the user U to provide the provided information to the provider P. The user code includes, for example, mandatory information. Therefore, the provider P can receive the mandatory information from the user U by reading the user code. The optional information is transmitted from the user terminal to the provider terminal via communication. Therefore, the provider P can receive the optional information from the user U by receiving the optional information from the user terminal with the provider terminal.

[0026] In the verification process, if the provided information received from the user U is associated with certificate information indicating that the authenticity of the target data has been proven, the provider P can verify the certificate information. The certificate information is, for example, VC (Verifiable Credentials: verifiable digital certificate). VC is information indicating a digital certificate that can be verified online, such as information in which the issuer of the certificate has digitally signed data related to the target of certification. VC includes, for example, verification request information and verification request result information. Furthermore, VC may include a history of exchange of verification request information and verification request result. Note that the certificate information may also be a VP (Verifiable Presentation) in which multiple VCs are bundled together.

[0027] The provided information (personal data) for which a VC is issued is, for example, credentials. When a provider P verifies a VC, the provider application AP1 requests the intermediate certification authority ICA to verify the VC. The intermediate certification authority ICA is a system that has the function of retaining credentials that have been authenticated once and providing certified credentials without re-authentication as long as they are within their validity period. Therefore, when the intermediate certification authority ICA receives a verification request from the provider application AP1, it verifies the validity of the VC of the target credentials based on the credentials it retains. If the verification result shows that the VC is no longer valid, the intermediate certification authority ICA can issue a new valid VC by requesting the certification authority CA to authenticate the credentials.

[0028] The user application AP2 is an application that allows the user U to use the credential data generation platform PF. The user U uses the user application AP2 to perform processes such as confirming the information requested by the provider P (request information confirmation process), selecting the information to be provided to the provider P (provided information selection process), and providing the information to the provider P (information provision process).

[0029] The credential data generation platform PF also provides a personal data store PDS, which is referenced by the user application AP2. A personal data store PDS is provided for each user U to manage the personal data of the user U. The personal data managed in the personal data store PDS includes, for example, name, address, telephone number, email address, payment information, financial information, document information such as identification documents, educational history, company history, credential information, and device-related information such as cookies.

[0030] In the requested information confirmation process, the user U can confirm the requested information for the service to be used by reading the provider code presented by the provider P into the user terminal. On the user terminal that reads the provider code, the required information and optional information that the provider P has requested to be provided are displayed.

[0031] In the information selection process, the user U can select the information to be provided to the provider P from the requested information displayed on the user terminal. The information selected by the user U here is obtained from the personal data store PDS by the user application AP2.

[0032] In the information provision process, the user U can create a user code. The user U can create a user code that includes information to be provided using the user application AP2. The user U can provide the information to be provided to the provider P by presenting the created user code to the provider P and having it read by the provider terminal. Note that the user code includes information that must be provided among the information to be provided. The optional information to be provided is provided from the user U to the provider P by being transmitted from the user terminal to the provider terminal via communication.

[0033] <2. Configuration of the credential data generation system> The outline of the credential data generation service SA according to this embodiment has been described above. Next, the configuration of the credential data generation system according to this embodiment will be described with reference to Fig. 2. Fig. 2 is a block diagram showing an example of the configuration of the credential data generation system according to this embodiment.

[0034] The credential data generation system 1 shown in Fig. 2 is a system for realizing the credential data generation platform PF described with reference to Fig. 1. As shown in Fig. 2, the credential data generation system 1 includes a provider terminal 10, a user terminal 20, a credential data generation device 30, and a certificate authority device 40.

[0035] The network NW may be configured to transmit and receive information using, for example, a LAN (Local Area Network), a WAN (Wide Area Network), a telephone network (such as a mobile phone network or a fixed telephone network), a regional IP (Internet Protocol) network, or the Internet.

[0036] (1) Provider terminal 10 The provider terminal 10 is a terminal used by the provider P. The provider terminal 10 is, for example, a smartphone, a tablet terminal, or a PC (Personal Computer). The provider terminal 10 is connected to the user terminal 20 and the credential data generation device 30 via a network NW so as to be able to send and receive various information.

[0037] Various screens are displayed on the provider terminal 10 by the provider application AP1. The functions of the provider application AP1 may be provided by installing an application on the provider terminal 10 (i.e., a native application), or may be provided by a web system (i.e., a web application). In the case of a web system, the functions of the provider application AP1 are provided via a web browser.

[0038] (2) User terminal 20 The user terminal 20 is a terminal used by the user U. The user terminal 20 is, for example, a smartphone, a tablet terminal, or a PC. The user terminal 20 is connected to the provider terminal 10 and the credential data generation device 30 via the network NW so as to be able to send and receive various information.

[0039] Various screens are displayed on the user terminal 20 by the user application AP2. The functions of the user application AP2 may be provided by installing an application on the user terminal 20 (i.e., a native application), or may be provided by a web system (i.e., a web application). In the case of a web system, the functions of the user application AP2 are provided via a web browser.

[0040] (3) Credentials data generation device 30 The credential data generation device 30 is a device for managing the credential data generation platform PF. The credential data generation device 30 is configured by, for example, one or more PCs or server devices (e.g., cloud servers). The credential data generation device 30 is connected to the provider terminal 10, the user terminal 20, and the certificate authority device 40 via the network NW so as to be able to send and receive various information.

[0041] (4) Certificate Authority Device 40 The certificate authority device 40 is a device that functions as a certificate authority CA. The certificate authority device 40 is configured by, for example, one or more PCs or server devices (e.g., cloud servers). The certificate authority device 40 is connected to the credential data generation device 30 via a network NW so as to be able to send and receive various information.

[0042] <3. Functional configuration of the credential data generation device> The configuration of the credential data generation system 1 according to this embodiment has been described above. Next, the functional configuration of the credential data generation device 30 according to this embodiment will be described with reference to FIG. 3. FIG. 3 is a block diagram showing an example of the functional configuration of the credential data generation device 30 according to this embodiment. As shown in FIG. 3, the credential data generation device 30 includes a communication unit 31, a storage unit 32, and a control unit 33.

[0043] (1) Communications Department 31 The communication unit 31 has a function of transmitting and receiving various information. The communication unit 31 is communicably connected to the provider terminal 10, the user terminal 20, and the certificate authority device 40 via the network NW, and transmits and receives various information.

[0044] (2) Storage section 32 The storage unit 32 has a function of storing various information. The storage unit 32 is configured by a storage medium provided as hardware in the credential data generation device 30, such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, an electrically erasable programmable read only memory (EEPROM), a random access read / write memory (RAM), a read only memory (ROM), or any combination of these storage media. As shown in Fig. 3, the storage unit 32 includes a personal data storage unit 321, a service catalog storage unit 322, and a terms of use storage unit 323.

[0045] (2-1) Personal Data Storage Unit 321 The personal data storage unit 321 has a function of storing personal data of the service user U. The personal data storage unit 321 functions as the personal data store PDS described with reference to FIG.

[0046] (2-2) Service catalog storage unit 322 The service catalog storage unit 322 has a function of storing a service catalog of services provided by the provider P. The service catalog storage unit 322 functions as the service catalog database DB1 described with reference to FIG.

[0047] (2-3) Terms of Use Storage Unit 323 The terms of use storage unit 323 has a function of storing the terms of use of the service provided by the provider P. The terms of use storage unit 323 functions as the terms of use database DB2 described with reference to FIG.

[0048] (3) Control unit 33 The control unit 33 has a function of controlling the overall operation of the credential data generation device 30. The control unit 33 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) provided as hardware in the credential data generation device 30 to execute a program. As shown in FIG. 3 , the control unit 33 includes a provider application unit 34, a user application unit 35, and an intermediate certification authority unit 36.

[0049] (3-1) Provider Application Section 34 The provider application unit 34 has a function of performing processing related to the provider application AP1. The provider application unit 34 functions as the provider application AP1 described with reference to Fig. 1. As shown in Fig. 3, the provider application unit 34 includes an information request processing unit 341, an information reception processing unit 342, and a verification unit 343.

[0050] (3-1-1) Information request processing unit 341 The information request processing unit 341 has a function for performing information request processing by the provider P. As shown in FIG. 3, the information request processing unit 341 includes a request information setting unit 3411, a storage unit 3412, and a provider code generation unit 3413.

[0051] (3-1-1-1) Request information setting section 3411 The request information setting unit 3411 has a function for the provider P to set request information. The request information setting unit 3411 sets request information indicating information that the provider P requests the user U to provide as information necessary for using the service. The request information setting unit 3411 may set request information input by the provider P, or may set the request information by referring to the service catalog database DB1 and the terms of use database DB2 and extracting information to be set from the service catalog and terms of use of the service for which the request information is to be set.

[0052] (3-1-1-2) Storage unit 3412 The storage unit 3412 has a function of storing and holding the request information set by the request information setting unit 3411 .

[0053] (3-1-1-3) Provider code generation unit 3413 The donor code generation unit 3413 has a function for the provider P to create a donor code. The donor code generation unit 3413 generates a two-dimensional code including the request information stored in the storage unit 3412 as a donor code used by the provider P to provide the request information to the user U. The donor code generation unit 3413 may display the generated donor code on the donor terminal 10, or may print it on a medium such as paper.

[0054] (3-1-2) Information receiving processing unit 342 The information reception processing unit 342 has a function for the provider P to perform information reception processing. The information reception processing unit 342 acquires provided information provided by the user U and displays it on the provider terminal 10. As shown in FIG. 3 , the information reception processing unit 342 includes a code reading unit 3421 and a data receiving unit 3422.

[0055] (3-1-2-1) Code reader 3421 The code reading unit 3421 has a function for reading a user code so that the provider P can acquire the provided information. The code reading unit 3421 reads the user code presented by the user U into the provider terminal 10, and displays the acquired provided information on the provider terminal 10.

[0056] (3-1-2-2) Data receiving unit 3422 The data receiving unit 3422 has a function for the provider terminal 10 to receive data from the user terminal 20 so that the provider P can obtain the provided information. The data receiving unit 3422 receives the provided information transmitted from the user terminal 20 at the provider terminal 10.

[0057] (3-1-3) Verification Section 343 The verification unit 343 has a function for the provider P to verify the provided information provided by the user U. When the provided information acquired by the information reception processing unit 342 includes a VC, the verification unit 343 requests the intermediate certification authority 36 to verify the VC, and causes the provider terminal 10 to display the verification result of the VC by the intermediate certification authority 36.

[0058] (3-2) User Application Section 35 The user application unit 35 has a function of performing processing related to the user application AP2. The user application unit 35 functions as the user application AP2 described with reference to Fig. 1. As shown in Fig. 3, the user application unit 35 includes a request information confirmation unit 351, a personal data acquisition unit 352, and an information provision processing unit 353.

[0059] (3-2-1) Request information confirmation section 351 The request information confirmation unit 351 has a function for the user U to confirm the request information presented by the provider P. When the user U uses a service, the request information confirmation unit 351 acquires the request information set for the service and displays it on the user terminal 20. For example, the request information confirmation unit 351 displays on the user terminal 20 the request information acquired by the user U reading the provider code presented by the provider P into the user terminal 20.

[0060] (3-2-2) Personal data acquisition unit 352 The personal data acquisition unit 352 has a function of acquiring personal data provided from the user U to the provider P as information to be provided. When the user U uses a service, the personal data acquisition unit 352 acquires personal data corresponding to requested information from the storage unit 32. For example, the personal data acquisition unit 352 acquires personal data corresponding to information selected by the user U from the requested information displayed on the user terminal 20 from the personal data storage unit 321 of the storage unit 32. This allows the user U to provide only the information that he or she has selected of his or her own volition from the information that the provider P requests him or her to provide. If the acquired personal data is a VC (or VP), the personal data acquiring unit 352 also acquires information such as the expiration date of the VC (or VP). The acquired personal data may include certified credential information. In response to a request from the provider P, the personal data acquiring unit 352 can acquire and provide not only the certified credential information but also information indicating the certifying source that issued (certified) the credential information.

[0061] (3-2-3) Information provision processing unit 353 The information provision processing unit 353 has a function for the user U to provide information to the provider P. The information provision processing unit 353 provides the provider with personal data acquired as information to be provided by the user U to the provider P in order for the user U to use the service. As shown in FIG. 3 , the information provision processing unit 353 includes a user code generation unit 3531 and a data transmission unit 3532.

[0062] (3-2-3-1) User code generation unit 3531 The user code generation unit 3531 has a function for the user U to create a user code. The user code generation unit 3531 generates a two-dimensional code including personal data (provided information) acquired by the personal data acquisition unit 352 as a user code used by the user U to provide provided information to the provider P. The user code generation unit 3531 displays the generated user code on the user terminal 20.

[0063] The user code generation unit 3531 may generate a user code that includes a VC (or VP) as the provided information. In this case, the user code generation unit 3531 generates a user code that also includes information such as the expiration date of the VC (or VP). The user code generation unit 3531 may also process the personal data acquired by the personal data acquisition unit 352 into zero-knowledge proof information indicating information that can be provided by a zero-knowledge proof, and provide the zero-knowledge proof information to the provider P as the provided information. By providing the zero-knowledge proof information, the user U can reduce the amount of information that he or she provides to the provider P compared to when providing the personal data as is, and it is also possible to prevent the leakage of personal information.

[0064] The user code generation unit 3531 may also set a valid reading period for the generated user code. This sets an expiration date for the presented user code, making it possible to prevent fraudulent use.

[0065] (3-2-3-2) Data transmission unit 3532 The data transmission unit 3532 has a function for the user terminal 20 to transmit data to the provider terminal 10 so that the user U can provide the provided information. The data transmission unit 3532 causes the user terminal 20 to transmit the provided information to the provider terminal 10. The provided information transmitted and received by communication between the user terminal 20 and the provider terminal 10 includes information that is not essential for using the service (optional provided information). Depending on the content of the requested information, the amount of data that can be included in the two-dimensional code may be too large. For this reason, the optional provided information is set as information that is not to be included in the two-dimensional code.

[0066] (3-3) Intermediate Certification Authority 36 The intermediate certification authority 36 has a function of performing processing as an intermediate certification authority ICA. The intermediate certification authority 36 verifies the VC for which a verification request is received from the verification unit 343. If the validity of the VC is confirmed as a result of the verification, the intermediate certification authority 36 issues the VC as a VC indicating that the authenticity of the personal data provided as the provided information has been proven. Note that if the validity of the VC cannot be confirmed as a result of the verification, the intermediate certification authority 36 may request the certification authority device 40 to authenticate the provided information and issue a new valid VC.

[0067] <4.Screen display> The functional configuration of the credential data generation device 30 according to this embodiment has been described above. Next, screen displays according to this embodiment will be described with reference to Figs.

[0068] (1) Provider code display screen The donor code presentation screen according to this embodiment will be described with reference to Fig. 4. Fig. 4 is a diagram showing an example of the donor code presentation screen according to this embodiment. The donor code presentation screen G1 shown in Fig. 4 is a screen on which the donor P presents a donor code to the user U. The donor code presentation screen G1 shown in Fig. 4 includes an area R1, an area R2, and a donor code CD1.

[0069] Area R1 indicates the services that user U can receive by providing the provided information. As an example, area R1 indicates a student ID discount service that allows user U to receive a discount if user U is a student.

[0070] Area R2 is an area showing a message instructing the user to read in the donor code CD1. The donor code CD1 does not necessarily have to be presented on the donor code presentation screen G1, but may also be presented printed on paper.

[0071] (2) User home screen A user home screen according to this embodiment will be described with reference to Fig. 5. Fig. 5 is a diagram showing an example of a user home screen according to this embodiment. The user home screen G2 shown in Fig. 5 is a screen for displaying the home (top screen) of the user application AP2. The user home screen G2 shown in Fig. 5 includes a button B1, an area R3, and an area R4.

[0072] The button B1 is an operator for displaying a screen for reading a provider code. When the button B1 is pressed, the screen display of the user terminal 20 switches from the user home screen G2 to a screen for reading a provider code.

[0073] Area R3 shows basic information about user U. For example, area R3 shows basic information about user U, such as name "Taro X", date of birth "January 1, 2008", address "Tokyo", and occupation "high school student", along with a photo of the user.

[0074] Area R4 shows the credential information that user U has registered in the user application AP2 (credential data generation service SA). Area R4 shows, as examples, registered credential information such as a student ID card, a disability certificate, and membership information for xx services. Area R4 displays, for example, a card showing each credential information. The card may be displayed in a design created for the user application AP2, or in a design similar to that of the actual card. User U can display the credential information he or she wants to check by selecting the displayed card by touching, swiping, or other operations.

[0075] (3) Request information display screen The requested information display screen according to this embodiment will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the requested information display screen according to this embodiment. The requested information display screen G3 shown in Fig. 6 is a screen for displaying requested information. The requested information display screen G3 shown in Fig. 6 includes an area R5, an area R6, an area R7, and a button B2.

[0076] Area R5 indicates the service that is requesting the provision of necessary information from user U. As an example, area R5 indicates that the provision of information is being requested from "xx service."

[0077] Area R6 is an area showing the contents of the requested information. As examples, area R6 shows "information necessary for using the basic service" (mandatory information) and "information necessary for additional discounts (optional)" as requested information. As an example of "information necessary for using the basic service," provider P is requesting information indicating "student status," and the purpose of use of this information is also shown. It is also shown that "school name" and "name" are not required as information indicating "student status." Furthermore, as an example of "information necessary for additional discounts (optional)," provider P is requesting information indicating "usage status of xx service" and "membership information for xx service," and the purpose of use of this information is also shown.

[0078] Area R7 is an area where user U selects information to provide to provider P. Area R7 displays, for example, each of the requested information shown in area R6 and an operator (e.g., a check box) for selecting whether or not to provide each piece of requested information. User U can select whether or not to provide each piece of requested information by operating the operator corresponding to each piece of requested information.

[0079] Button B2 is an operator for generating a user code and transmitting data after obtaining permission from user U to provide information. If information corresponding to "information necessary for using basic services" is selected as information that can be provided in area R7, pressing button B2 generates a user code that includes that information. If information corresponding to "information required for additional discounts (optional)" is selected as information that can be provided in area R7, pressing button B2 transmits that information from user application AP2 (user terminal 20) to provider application AP1 (provider terminal 10).

[0080] (4) User code presentation screen The user code presentation screen according to this embodiment will be described with reference to Figures 7 and 8. The user code presentation screen G4 shown in Figures 7 and 8 is a screen on which the user U presents the user code to the provider P. The user code presentation screen includes, for example, a screen for when there is no transmission data and a screen for when there is transmission data.

[0081] (4-1) When there is no data to send 7 is a diagram showing an example of a user code presentation screen (without transmission data) according to this embodiment. The user code presentation screen G4-1 shown in FIG. 7 includes an area R8, an area R9, a user code CD2, and an area R10.

[0082] Area R8 of the user code presentation screen G4-1 is an area showing the provided information. As an example, area R8 displays the student ID card that user U has authorized to be provided. As shown in area R8, of the information contained in the student ID card, only the information necessary for using the service is displayed in a visible state, and information not necessary for using the service is masked and displayed in an invisible state. In the example shown in FIG. 7, only the issue date and expiration date are displayed in a visible state. Meanwhile, the school name, student ID number, name, and date of birth are masked and displayed in an invisible state.

[0083] Area R9 on the user code presentation screen G4-1 displays a message instructing the user to read the user code CD2. Note that area R9 may also display a message indicating that specific information is not included. In the example shown in FIG. 7, it is clearly indicated that the school name and name are not included.

[0084] Area R10 of the user code presentation screen G4-1, like area R4 of the user home screen G2, is an area showing the credential information that the user U has registered in the user application AP2 (credential data generation service SA).

[0085] (4-2) When there is data to send 8 is a diagram showing an example of a user code presentation screen (with transmission data) according to this embodiment. The user code presentation screen G4-2 shown in FIG. 8 includes an area R8, an area R9, a user code CD2, and an area R10.

[0086] The information displayed in areas R8 and R9 of the user code presentation screen G4-2 is the same as the information displayed in areas R8 and R9 of the user code presentation screen G4-1.

[0087] Area R10 of the user code presentation screen G4-2 shows the provided information that was not included in the user code CD2 and was transmitted from the user terminal 20 to the provider terminal 10 via communication. In the example shown in Fig. 8, it is shown that "xx service usage status" and "xx service membership information" were transmitted.

[0088] (5) Provided information display screen The provided information display screen according to this embodiment will be described with reference to Fig. 9 and Fig. 10. The provided information display screen G5 shown in Fig. 9 and Fig. 10 is a screen for the provider P to check the provided information provided by the user U. The provided information display screen includes, for example, a screen for when verification is required and a screen for when verification is not required.

[0089] (5-1) When verification is necessary 9 is a diagram showing an example of a provided information display screen (verification required) according to this embodiment. The provided information display screen G5-1 shown in FIG. 9 includes an area R11, an area R12, an area R13, and a button B3.

[0090] An area R11 of the provided information display screen G5-1 is an area indicating that there is information provided by the user U to the provider P.

[0091] Area R12 of the provided information display screen G5-1 is an area showing the provided information provided by user U. Area R12 shows, as an example, information confirmed from a two-dimensional code (user code) and information sent directly from the user terminal 20. The information confirmed from the two-dimensional code shows "Student ID: *** High School," "Issue date: April 1, 2023," and "Expiration date: March 31, 2027" as information necessary for providing the service. The directly sent information shows "xx service usage status" and "xx service membership information" as information (optional) necessary for a separate discount.

[0092] Area R13 of the provided information display screen G5-1 is an area that shows information that needs to be verified among the provided information provided by user U. As an example, area R13 shows, as information that needs to be verified, "Student ID: *** High School," "Issue date: April 1, 2023," and "Expiration date: March 31, 2027," which are information necessary for providing the service of information confirmed from the two-dimensional code.

[0093] The button B3 on the provided information display screen G5-1 is an operator for starting verification of the provided information. When the button B3 is pressed, a request is made to the intermediate authentication authority 36 to verify the provided information.

[0094] (5-2) When verification is not required 10 is a diagram showing an example of a provided information display screen (verification not required) according to this embodiment. The provided information display screen G5-2 shown in FIG. 10 includes an area R11, an area R12, and a button B4.

[0095] The information displayed in the region R11 of the provided information display screen G5-2 is the same as the information displayed in the region R11 of the provided information display screen G5-1.

[0096] In the area R12 of the provided information display screen G5-2, in addition to the provided information provided by the user U, the verification result is displayed.

[0097] The button B4 on the provided information display screen G5-2 is an operator for starting the provision of a service. When the button B4 is pressed, the provision of the service to the user U begins. Note that if the service is not provided via the user terminal 20, the provider P may verbally inform the user U that use of the service has been permitted.

[0098] <5. Processing flow> The screen display according to this embodiment has been described above. Next, the processing flow according to this embodiment will be described with reference to Fig. 11. Fig. 11 is a sequence diagram showing an example of the processing flow in the credential data generation service SA according to this embodiment.

[0099] 11, first, request information is registered on the provider side (step S101). The provider P performs an operation for registering the request information using the provider application AP1 on the provider terminal 10. In response to the operation from the provider P, the request information setting unit 3411 of the credential data generation device 30 sets the request information.

[0100] Next, a two-dimensional code (provider code) is generated on the provider side (step S102). The provider P operates the provider application AP1 on the provider terminal 10 to perform an operation for generating a two-dimensional code. In response to the operation from the provider P, the provider code generation unit 3413 in the credential data generation device 30 generates a two-dimensional code including the request information.

[0101] Next, the two-dimensional code is presented on the provider side (step S103). When the user U uses the service, the provider P operates the provider application AP1 on the provider terminal 10 to perform an operation for presenting the two-dimensional code. In response to the operation from the provider P, the credential data generation device 30 causes the provider code generation unit 3413 to display a provider code presentation screen G1 on the provider terminal 10.

[0102] Next, the user reads (reads) the two-dimensional code (provider code) (step S201). The user U operates the user application AP2 on the user terminal 20 to perform an operation to read the two-dimensional code. In response to the operation from the user U, the request information confirmation unit 351 of the credential data generation device 30 reads the two-dimensional code. After reading the two-dimensional code, the request information confirmation unit 351 causes the user terminal 20 to display a request information display screen G3.

[0103] Next, the user confirms and selects the requested information (step S202). The user U checks the requested information display screen G3 displayed in the user application AP2 on the user terminal 20 and performs an operation to select the information to be provided to the provider P. In response to the operation from the user U, the personal data acquisition unit 352 in the credential data generation device 30 acquires the target personal data from the personal data store PDS. Note that the personal data acquired here does not necessarily have to be the personal data itself. For example, the personal data acquisition unit 352 may acquire information indicating that "the credential information is stored as a VC in the personal data store PDS." Such personal data acquisition is performed in the case of a service in which the provider P does not need to know the details of the credential information, and it is sufficient to provide the provider P with information indicating that the provider P has credential information, such as a driver's license or a disability certificate, as a VP(VC). At this time, if the information that needs to be provided is not registered in the personal data store PDS, the user U operates the user application AP2 to add the necessary information (step S203). The personal data acquisition unit 352 also acquires the information added by the user U as information to be provided.

[0104] Next, the user side obtains permission from the user U to provide the obtained information to the provider P (step S204). After obtaining permission, a VC (or VP) is issued (step S205). When the personal data obtaining unit 352 obtains personal data, the user code generating unit 3531 issues the obtained personal data as a VC (or VP). At this time, the user code generating unit 3531 issues a VC for personal data that corresponds to mandatory provision information among the personal data obtained as information to be provided.

[0105] Next, a two-dimensional code (user code) is generated on the user side (step S206). The user code generation unit 3531 generates a user code that includes the provision information (required provision information) issued as the VC (or VP) as provision information.

[0106] Next, the two-dimensional code is presented on the user side (step S207). After the user code generation unit 3531 generates the two-dimensional code, the user code generation unit 3531 displays a user code presentation screen G4 on the user terminal 20. The user U presents the two-dimensional code displayed on the user code presentation screen G4 to the provider P.

[0107] In addition, if information to be provided (e.g., optional information to be provided) is selected or added in steps S202 and S203, the data transmission unit 3532 transmits the selected or added information to the provider terminal 10 after obtaining permission in step S204 (step S208).

[0108] Next, the provider side reads (reads) the two-dimensional code (user code) (step S301). The provider P operates the provider application AP1 on the provider terminal 10 to perform an operation for reading the two-dimensional code. In response to the operation from the provider P, the code reading unit 3421 in the credential data generation device 30 reads the two-dimensional code.

[0109] Furthermore, if there is provided information transmitted from the user terminal 20 in step S208, the provided information is received by the data receiving unit 3422 in the credential data generation device 30 (step S302).

[0110] After reading the two-dimensional code and receiving the data, the code reading unit 3421 causes the provider terminal 10 to display a provided information display screen G5 showing the read provided information and the received provided information (step S303).

[0111] Next, the provider side verifies the VC (step S304). The provider P checks the provided information display screen G5 displayed on the provider terminal 10, and if there is provided information that needs to be verified, performs an operation to verify the provided information. In response to the operation of the provider P, the verification unit 343 of the credential data generation device 30 requests the intermediate certification authority unit 36 ​​to verify the provided information.

[0112] If there is no information to be provided that requires verification in step S303, or after the verification in step S304 is completed, the provider P confirms that there is no problem in providing the service, and starts providing the service to the user U (step S305).

[0113] The processing flow according to this embodiment has been described above. As described above, the credential data generation system 1 of this embodiment includes a memory unit 32 that stores personal data of a service user U, a request information setting unit 3411 that sets request information indicating information that the service provider P requests the user to provide as information necessary for using the service, a personal data acquisition unit 352 that acquires personal data corresponding to the request information from the memory unit 32 when the user U uses the service, an information provision processing unit 353 that provides the personal data acquired from the memory unit 32 to the provider P as provision information to be provided to the provider P so that the user U can use the service, and an information reception processing unit 342 that acquires the provision information and displays it on the provider P's terminal.

[0114] With this configuration, the provider P can prompt the user U to provide only the information necessary to use the service (i.e., the information the provider wants the user U to provide). The user U can check the information necessary to use the service presented by the provider P, and select and provide only the information that is acceptable to provide. This allows the provider P to confirm conditions such as identity verification without receiving unnecessary information from the user U, and also eliminates the need for processes such as masking sensitive information contained in identity verification documents.

[0115] Therefore, when a consumer uses a specific service, the credential data generation system 1 allows the consumer to provide only the information necessary to use the service, and enables the service provider to reduce the risks and workload associated with managing the information provided.

[0116] Furthermore, the credential data generation system 1 can provide information necessary for using a service without creating an account, etc. This allows consumers to use legitimate services without the hassle of registering, etc.

[0117] In addition, the credential data generation system 1 uses the credential information stored in the personal data store, allowing the provider to confirm whether the conditions for using the service are met without having to check the identity verification document itself.

[0118] Furthermore, in the credential data generation system 1, providers can set the data they require from consumers in several stages (for example, required information, optional information, etc.). This allows providers to develop services according to the information provided by consumers, enabling them to provide more appropriate services.

[0119] <6. Variations> The above describes the embodiment. Next, modifications of the embodiment will be described. The modifications described below may be applied to the embodiment alone or in combination with the embodiment. Furthermore, the modifications may be applied in place of the configuration described in the embodiment, or may be applied in addition to the configuration described in the embodiment.

[0120] In the above-described embodiment, information on various rights (tickets, coupons, etc.) suitable for the service may be incorporated into the two-dimensional code and used.

[0121] Furthermore, in the above-described embodiment, an example has been described in which, when user U uses a service, personal data acquisition unit 352 acquires from personal data storage unit 321 personal data corresponding to information selected by user U from request information displayed on user terminal 20, but the present invention is not limited to such an example. For example, when user U uses a service, personal data acquisition unit 352 may acquire from personal data storage unit 321 personal data corresponding to information that user U has previously agreed to be provided from request information set for the service. This saves user U the trouble of having to select personal data to provide each time he or she uses a service.

[0122] Furthermore, in the above-described embodiment, an example in which a user U uses a service alone has been described, but the present invention is not limited to such an example. A user U may use a service in a group consisting of multiple users. In this case, the provider P needs to obtain information from each of the multiple users U. However, it is time-consuming for the provider P to request information from each user U and obtain permission to provide the information. Therefore, the credential data generation system 1 may be configured so that the provider P can request information from a representative of the group, and the representative can compile the information of the group members and provide it to the provider P all at once. This reduces the time and effort required of the provider P when users U use a service in a group.

[0123] Here, an example in which users U use a service in a group will be described with reference to Figures 12 to 15. In the following, it is assumed that one user U among multiple users U (members) included in one group is set as a representative user, and the other users U are set as mere members. In addition, only the differences from the above-described embodiment will be described below.

[0124] 12 is a block diagram showing an example of the functional configuration of a credential data generation device 30a in a modification of this embodiment. As shown in Fig. 12, the credential data generation device 30a further includes a data receiving unit 3533 and a group processing unit 3534 in addition to the functional configuration of the credential data generation device 30 in the above-described embodiment.

[0125] When user U is set as the representative of a specific group, the data receiving unit 3533 has a function that allows the representative's user terminal 20 to receive information provided by members from the member's user terminal 20. This function allows the representative to consolidate the information provided by members. For this purpose, the data transmitting unit 3532 has a function that causes the member's user terminal 20 to transmit the information provided by members to the representative's user terminal 20.

[0126] The group processing unit 3534 has a function for performing processing (group processing) for users U to use a service as a group. The group processing unit 3534 performs processing such as group creation, member addition, and request information sharing as group processing. The group creation processing is processing in which a representative user U creates a group for multiple users U to use a service. The member addition processing is processing in which the representative user U adds member users U to the created group. The request information sharing processing is processing in which the representative user U shares request information from a provider P of the service to be used with member users U. The member user U communicates the provided information and its permission to provide it to the representative user U based on the requested information shared by the representative. This allows the representative user U to compile the provided information of the member users U.

[0127] Fig. 13 is a diagram showing an example of a requested information display screen and a group creation screen in a modified example of this embodiment. The requested information display screen G3a shown in Fig. 13 is similar to the requested information display screen G3 described with reference to Fig. 6, but differs in that it further includes a button B5.

[0128] Button B5 is an operator that allows user U to create a group and share the requested information with its members. When user U presses button B5, the screen transitions to group creation screen G6. In addition, user U who pressed button B5 is set as the representative.

[0129] The group creation screen G6 shown in Fig. 13 is a screen for the representative to perform group processing. The group creation screen G6 shown in Fig. 13 includes areas R14, R15, R16, R17, R18, buttons B6, and B7.

[0130] Area R14 shows the title of the screen and reads "Create a Group." Area R15 shows the content of the requested information and is similar to area R6 of the requested information display screen G3 described with reference to FIG. 6. The requested information displayed in area R15 is the requested information to be shared with members. Area R16 shows instructions for creating a group. Area R16, for example, shows instructions for creating a group to share the requested information and adding members. Area R17 is an area for setting a group name and adding members. The member addition function is realized, for example, by adding contacts or a friend function. Button B6 is an operator that allows the representative to share the requested information with members. When the representative presses button B6, the requested information is shared with the members added in area R17. Area R18 shows the permission status of the members. Area R18 is displayed, for example, as a pop-up. For example, if permission has been given, area R18 will display "XX Taro (representative): given," and if permission has not been given, it will display "XX Hanako (member): not given." Button B7 is an operator for generating a user code for the group and transmitting data. Button B7 can be pressed once permission has been given by all members of the group.

[0131] Fig. 14 is a diagram showing an example of a request information display screen for group members in a modified example of this embodiment. The request information display screen G3b shown in Fig. 14 is similar to the request information display screen G3 described with reference to Fig. 6, but differs in that it includes a button B8 instead of button B2.

[0132] Button B8 is an operator for obtaining permission from the member to provide information and sending the provided information to the representative. If the member consents to the provision of the information shown in area R6, he or she presses button B8. This sends the information provided by the member to the representative.

[0133] Fig. 15 is a sequence diagram showing an example of the processing flow in the credential data generation service SA in a modified example of this embodiment. Note that the processing on the provider side, steps S401 to S403 and steps S601 to S605 shown in Fig. 15, are the same as the processing on the provider side, steps S101 to S103 and steps S301 to S305, which were explained with reference to Fig. 11. Below, we will explain steps S501 to S510, which are the processing on the user side.

[0134] As shown in FIG. 15, first, the representative reads (reads) the two-dimensional code (provider code) (step S501). Next, the representative checks the requested information (step S502). At this time, if the information that needs to be provided is not registered in the personal data store PDS, the representative adds the necessary information (step S503).

[0135] Next, group processing is executed (step S504). The representative performs operations on the group creation screen G6 to create a group, add members, share requested information, etc. The group processing unit 3534 receives the operations by the representative and executes group processing.

[0136] The members who have shared the requested information through group processing consent to the provision of the provided information on the requested information display screen G3b and transmit the provided information to the representative (step S505). The representative receives the information sent from the members (step S506). The subsequent processing from step S507 to step S511 is the same as the processing from step S204 to step S208 described with reference to FIG.

[0137] The above describes the modified examples of the embodiment. In addition, some or all of the functions of the credential data generation system 1, the provider terminal 10, the user terminal 20, the credential data generation device 30, and the certification authority device 40 in the above-described embodiment may be implemented by a computer. In this case, a program for implementing this function may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read into a computer system and executed. Note that the term "computer system" here includes hardware such as an OS and peripheral devices. Furthermore, the term "computer-readable recording medium" refers to portable media such as a flexible disk, optical magnetic disk, ROM, CD-ROM, and storage devices such as a hard disk built into a computer system. Furthermore, "computer-readable recording medium" may also include something that dynamically stores a program for a short period of time, such as a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, or something that stores a program for a certain period of time, such as volatile memory within a computer system that serves as a server or client in that case. Furthermore, the above program may be one that realizes part of the above-mentioned functions, or may be one that can realize the above-mentioned functions in combination with a program already recorded in a computer system, or may be one that is realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0138] The embodiments of the present invention have been described in detail above with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes can be made within the scope of the gist of the present invention. [Explanation of symbols]

[0139] 1...Credential data generation system, 10...Provider terminal, 20...User terminal, 30...Credential data generation device, 31...Communication unit, 32...Memory unit, 33...Control unit, 34...Provider application unit, 35...User application unit, 36...Intermediate certification authority unit, 40...Certification authority device, 321...Personal data memory unit, 322...Service catalog memory unit, 323...Terms of use memory unit, 341...Information request processing unit, 342...Information reception processing unit, 343...Verification unit, 351...Request information confirmation unit, 352...Personal data acquisition unit, 353...Information provision processing unit, 3411...Request information setting unit, 3412...Storage unit, 3413...Provider code generation unit, 3421...Code reading unit, 3422...Data receiving unit, 3531...User code generation unit, 3532...Data transmitting unit, NW...Network

Claims

1. a storage unit for storing personal data of users of the service; a request information setting unit that sets request information indicating information that a provider of the service requests the user to provide as information necessary for using the service; a personal data acquisition unit that acquires the personal data corresponding to the request information from the storage unit when the user uses the service; an information provision processing unit that provides the personal data acquired from the storage unit to the provider as provision information to be provided to the provider so that the user can use the service; an information receiving processing unit that acquires the provided information and displays it on the terminal of the provider; Equipped with The information set as the requested information includes mandatory information that must be provided and optional information that may be provided voluntarily, The required information is information necessary for using the main service provided, The optional information to be provided is information that is not a main service provided, but is necessary for using a service that becomes available by providing the information, The information provision processing unit a user code generating unit that generates a two-dimensional code including personal data corresponding to the mandatory provision information among the personal data acquired by the personal data acquiring unit as a user code to be used by the user to provide the mandatory provision information to the provider, and displays the generated two-dimensional code on the user's terminal; a data transmission unit that transmits, from the user's terminal to the provider's terminal, personal data corresponding to the voluntary provision information among the personal data acquired by the personal data acquisition unit; Equipped with The information receiving processing unit a code reading unit that reads the user code presented by the user at a storefront with a terminal of the provider and displays the required provision information on the terminal of the provider; a data receiving unit that receives the voluntary provision information transmitted from the user terminal at the provider terminal; Equipped with Credentials data generation system.

2. a request information confirmation unit that acquires the request information set in the service and displays it on the user's terminal when the user uses the service; Furthermore, the personal data acquisition unit acquires, from the storage unit, the personal data corresponding to information selected by the user from the request information displayed on the terminal; The credential data generation system of claim 1 .

3. a provider code generation unit that generates a two-dimensional code including the requested information as a provider code used by the provider to provide the requested information to the user; Furthermore, the request information confirmation unit, when the user uses the service, reads the provider code presented by the provider into the user's terminal, and displays the request information on the user's terminal. The credential data generation system of claim 2 .

4. an intermediate certification authority that issues a VC indicating that the authenticity of the personal data provided as the provided information has been certified; Furthermore, the user code generation unit generates the user code including the VC as the provided information. The credential data generation system of claim 3 .

5. a verification unit that, when the VC is included in the provided information acquired by the information reception processing unit, requests the intermediate certification authority to verify the VC in response to an operation by the provider at the storefront, and displays the verification result of the VC by the intermediate certification authority on the provider's terminal; The credential data generation system of claim 4 further comprising:

6. the user code generation unit processes the acquired personal data into zero-knowledge proof information indicating information that can be provided by zero-knowledge proof, and provides the zero-knowledge proof information to the provider as the provided information; The credential data generation system of claim 3 .

7. The information provision processing unit: a group processing unit that creates a group for multiple users to use a service in response to an operation by a representative user, adds the users to the created group as members, and shares request information from a provider of the service to be used with the members; a data receiving unit that receives information provided by the member from the terminal of the member when the user is set as the representative of a specific group; The credential data generation system of claim 1 further comprising:

8. a storage step of storing personal data of the service user in a storage unit; a request information setting step of setting request information indicating information that a provider of the service requests the user to provide as information necessary for using the service; a personal data acquisition step of acquiring the personal data corresponding to the request information from the storage unit when the user uses the service; an information providing process step of providing the personal data acquired from the storage unit to the provider as information to be provided to the provider so that the user can use the service; an information receiving process for acquiring the provided information and displaying it on the provider's terminal; Including, The information set as the requested information includes mandatory information that must be provided and optional information that may be provided voluntarily, The required information is information necessary for using the main service provided, The optional information to be provided is information that is not a main service provided, but is necessary for using a service that becomes available by providing the information, The information providing process includes: a user code generating process for generating a two-dimensional code including personal data corresponding to the mandatory provision information among the personal data acquired by the personal data acquiring process as a user code to be used by the user to provide the mandatory provision information to the provider, and displaying the generated two-dimensional code on the user's terminal; a data transmission step of transmitting, from the user's terminal to the provider's terminal, personal data corresponding to the voluntary provision information among the personal data acquired by the personal data acquisition step; Including, The information receiving process includes: a code reading step of reading the user code presented by the user at a storefront with a terminal of the provider and displaying the required provision information obtained by the user code on the terminal of the provider; a data receiving step of receiving the optional information transmitted from the user terminal at the provider terminal; Including, A computer-implemented method for generating credential data.

9. Computer, a storage means for storing personal data of service users in a storage unit; a request information setting means for setting request information indicating information that a provider of the service requests the user to provide as information necessary for using the service; a personal data acquisition means for acquiring the personal data corresponding to the request information from the storage unit when the user uses the service; an information provision processing means for providing the personal data acquired from the storage unit to the provider as provision information to be provided to the provider in order for the user to use the service; an information receiving processing means for acquiring the provided information and displaying it on the terminal of the provider; It functions as The information set as the requested information includes mandatory information that must be provided and optional information that may be provided voluntarily, The required information is information necessary for using the main service provided, The optional information to be provided is information that is not a main service provided, but is necessary for using a service that becomes available by providing the information, The information provision processing means a user code generating means for generating a two-dimensional code including personal data corresponding to the mandatory provision information among the personal data acquired by the personal data acquiring means as a user code to be used by the user to provide the mandatory provision information to the provider, and for displaying the generated two-dimensional code on the user's terminal; a data transmission means for transmitting the personal data corresponding to the optional information to be provided from the user's terminal to the provider's terminal, the personal data being acquired by the personal data acquisition means; It functions as The information receiving and processing means a code reading means for reading the user code presented by the user at a storefront with a terminal of the provider and displaying the required provision information on the terminal of the provider; a data receiving means for receiving the optional information transmitted from the user terminal at the provider terminal; To function as, program.

Citation Information

Patent Citations

  • Personal information account banking

    JP2016085676A

  • Guarantee control method, information processing device, and guarantee control program

    JP7222436B2

  • Personal information management device, personal information management system, personal information management method, and computer-readable recording medium having the same recorded thereon

    JP7290359B2

  • JPP7222436B