Terminal, terminal control method and program

The terminal's access control mechanism using trust lists addresses the risk of minors misusing digital certificates by ensuring secure and attribute-based certificate acquisition and provision, enhancing security and user convenience.

JP7758263B1Active Publication Date: 2025-10-22NEC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025548362
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-06-02
Publication Date
2025-10-22
Estimated Expiration
2045-06-02

AI Technical Summary

Technical Problem

Existing certificate verification technologies do not adequately address the risk of minors providing digital certificates to criminal groups, potentially leading to identity disclosure and associated crimes or accidents.

Method used

A terminal equipped with acquisition and usage control means to manage certificate access based on user attributes, using trust lists to ensure safer acquisition and provision of digital certificates.

Benefits of technology

Enables safer acquisition and use of certificates by enforcing access control based on user attributes, enhancing security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007758263000001
    Figure 0007758263000001
  • Figure 0007758263000002
    Figure 0007758263000002
  • Figure 0007758263000003
    Figure 0007758263000003
Patent Text Reader

Abstract

A terminal is provided that contributes to realizing safer acquisition and use of certificates. The terminal comprises an acquisition means, a selection means, an acquisition control means, and a usage control means. The acquisition means acquires at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of certificates stored in the digital wallet. The selection means selects a list to be used for access control from the at least one list based on user attributes. The acquisition control means executes access control using the selected list when acquiring a certificate to be stored in the digital wallet. The usage control means executes access control using the selected list when providing a certificate stored in the digital wallet to an external party.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a terminal, a terminal control method, and a storage medium. [Background technology]

[0002] Techniques exist for verifying electronic certificates.

[0003] For example, Patent Document 1 states that the present invention aims to improve the accuracy of verifying the authenticity of a certificate. The information processing device in Patent Document 1 has a storage unit. The storage unit stores a first private key corresponding to a third certificate issued to an administrator and a second private key corresponding to a second certificate issued to a system, in association with each other. In response to a verification request, the information processing device acquires a combination of a first public key and a second public key. The information processing device refers to the storage unit and determines whether the acquired combination is authentic. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] International Publication No. 2023 / 145027 Summary of the Invention [Problem to be solved by the invention]

[0005] In recent years, there are many services that utilize digital certificates. Digital certificates often contain personal information about users. For example, there is a concern that minors could be involved in crimes or accidents if they provide such digital certificates to criminal groups and disclose their identities.

[0006] It should be noted that Patent Document 1 merely discloses a technique related to the verification of electronic certificates. Therefore, even if the technique disclosed in Patent Document 1 is applied, the above problems cannot be solved.

[0007] A primary object of the present invention is to provide a terminal, a terminal control method, and a storage medium that contribute to realizing safer acquisition and use of certificates. [Means for solving the problem]

[0008] According to a first aspect of the present invention, there is provided a terminal comprising: an acquisition means for acquiring at least one list used for access control regarding the acquisition of certificates to be stored in a digital wallet and the provision of certificates stored in the digital wallet; a selection means for selecting a list to be used for access control from the at least one list based on user attributes; an acquisition control means for executing access control using the selected list when acquiring certificates to be stored in the digital wallet; and a usage control means for executing access control using the selected list when providing certificates stored in the digital wallet to an external party.

[0009] According to a second aspect of the present invention, there is provided a method for controlling a terminal, comprising: an acquisition step of acquiring at least one list used for access control related to the acquisition of certificates to be stored in a digital wallet and the provision of certificates stored in the digital wallet; a selection step of selecting a list to be used for access control from the at least one list based on user attributes; an acquisition control step of executing access control using the selected list when acquiring certificates to be stored in the digital wallet; and a usage control step of executing access control using the selected list when providing certificates stored in the digital wallet to an external party.

[0010] According to a third aspect of the present invention, there is provided a computer-readable storage medium that stores a program for causing a computer mounted on a terminal to execute the following: an acquisition process for acquiring at least one list used for access control regarding the acquisition of certificates to be stored in a digital wallet and the provision of certificates stored in the digital wallet; a selection process for selecting a list to be used for access control from the at least one list based on user attributes; an acquisition control process for executing access control using the selected list when acquiring certificates to be stored in the digital wallet; and a usage control process for executing access control using the selected list when providing certificates stored in the digital wallet to an external party. [Effects of the Invention]

[0011] According to each aspect of the present invention, a terminal, a terminal control method, and a storage medium are provided that contribute to realizing safer acquisition and use of certificates. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart illustrating the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 4] FIG. 4 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 5] FIG. 5 is a diagram illustrating an example of a trust list according to an embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 7]FIG. 7 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram illustrating an example of a processing configuration of a terminal according to an embodiment of the present disclosure. [Figure 9] FIG. 9 is a flowchart illustrating an example of the operation of the acquisition control unit according to an embodiment of the present disclosure. [Figure 10] FIG. 10 is a flowchart illustrating an example of the operation of the usage control unit according to an embodiment of the present disclosure. [Figure 11] FIG. 11 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. [Figure 12] FIG. 12 is a diagram illustrating an example of a processing configuration of a service server according to an embodiment of the present disclosure. [Figure 13] FIG. 13 is a diagram illustrating an example of a processing configuration of a management server according to an embodiment of the present disclosure. [Figure 14] FIG. 14 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 15] FIG. 15 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 16] FIG. 16 is a diagram illustrating an example of a hardware configuration of a terminal according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0013] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0014] A terminal 100 according to one embodiment includes an acquisition means 101, a selection means 102, an acquisition control means 103, and a usage control means 104 (see FIG. 1). The acquisition means 101 acquires at least one list used for access control related to the acquisition of a certificate to be stored in a digital wallet and the provision of the certificate stored in the digital wallet (step S1 in FIG. 2). The selection means 102 selects a list to be used for access control from the at least one list based on the attributes of the user (step S2). The acquisition control means 103 executes access control using the selected list when acquiring a certificate to be stored in the digital wallet (executing access control at acquisition; step S3). The usage control means 104 executes access control using the selected list when providing a certificate stored in the digital wallet to an external party (executing access control at provision; step S4).

[0015] For example, the terminal 100 acquires multiple trust lists and selects a trust list from the acquired trust lists according to the user's attributes. The terminal 100 uses the selected trust list to perform access control related to the acquisition and provision of certificates (e.g., credential certificates). For example, if the user is a minor, the terminal 100 selects a trust list for minors and performs access control using the selected trust list. Alternatively, if the user is a student, the terminal 100 selects a trust list for students and performs access control using the selected trust list. The terminal 100 acquires a trust list from a public institution such as a national or local government and performs access control according to the user's attribute information, thereby achieving safer acquisition and use of certificates. Furthermore, the terminal 100 ensures user convenience by selecting a trust list to use for access control according to the user's attributes. For example, in the above example, minors (users under 18 years of age) and students (university students) have different levels of understanding and judgment regarding various phenomena, and therefore also differ in the ways in which certificates are used. The terminal 100 selects a trust list that is suitable for the user's situation, capabilities, etc., thereby achieving both safe use of the credential certificate and user convenience.

[0016] Specific embodiments will be described in more detail below with reference to the drawings.

[0017] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0018] [System Configuration] As shown in FIG. 3, the information processing system according to the first embodiment includes at least one certificate issuer, at least one service provider, and an access administrator.

[0019] A certificate issuer is an entity that issues certificates to users. For example, a certificate issuer may issue a certificate that certifies the "identity" or "attributes" of a user. For example, a certificate issuer may issue an identification card that certifies the user's name, gender, date of birth, address, etc. Or, a certificate issuer may issue a certificate that certifies the user's "rights" or "qualifications."

[0020] For example, a public institution that issues identification documents such as driver's licenses, passports, and My Number cards corresponds to a certificate issuer. Alternatively, a university or company that issues graduation certificates or employment certificates corresponds to a certificate issuer. Alternatively, an organization that issues certificates related to technology, language, etc. corresponds to a certificate issuer.

[0021] Each certificate issuer is equipped with a server device 10. The server device 10 is a server that performs the processes and operations necessary to carry out the business of the certificate issuer. The server device 10 may be managed and operated by the certificate issuer, or may be outsourced to another business entity. The server device 10 may be installed within the certificate issuer's premises, or may be installed on a network (cloud).

[0022] A service provider is an entity (group or organization) that provides services to users. Service providers are not limited to private companies; public institutions such as city halls are also included in the service providers disclosed in this application. Depending on the industry and business type of the service provider, the same business may operate as both a certificate issuer and a service provider.

[0023] The service provider includes a service server 20 for providing services to users. For example, the service server 20 provides services to users via a website.

[0024] An access administrator is an entity (group or organization) that controls and manages the acquisition of certificates by users and the use of certificates. For example, public institutions such as the national or local government, or businesses commissioned by the national government, etc., act as access administrators.

[0025] The access administrator is provided with a management server 30. The management server 30 is a server that performs the processes and operations necessary to carry out the duties of the access administrator. The management server 30 may be managed and operated by the access administrator, or may be outsourced to another business operator. The management server 30 may be installed in the building of the access administrator, or may be installed on a network (on the cloud).

[0026] The management server 30 restricts the certificate issuers from which a user can request the issuance of a certificate, and restricts the service providers to which a user can submit a certificate. The management server 30 implements access control (access restriction) related to certificates.

[0027] A user carries a terminal 40. For example, the user operates the terminal 40 to request (demand) the issuance of a certificate from a certificate issuer. The user also uses the terminal 40 to provide the service provider with the certificate that the service provider requests.

[0028] 3 are connected to a network. Specifically, the server device 10, the service server 20, the management server 30, and the terminal 40 are connected to the network by wired or wireless communication means.

[0029] The configuration of the information processing system shown in Fig. 3 is an example and is not intended to be limiting. For example, the certificate issuer's server device 10, the service provider's service server 20, and the access administrator's management server 30 may belong to different networks. Alternatively, each certificate issuer may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10. Similarly, each service provider may include multiple service servers 20. Alternatively, the access administrator may include multiple management servers 30.

[0030] [General operation] Next, the general operation of the information processing system according to the first embodiment will be described.

[0031] <Preparing your digital wallet> The user terminal 40 has a digital wallet function. A digital wallet is an electronic information storage service that guarantees information security such as data integrity, reliability, and availability.

[0032] A user installs an application to realize a digital wallet on their terminal 40. By opening a digital wallet on terminal 40, the user can store various digital content on terminal 40, such as electronic money, identification documents such as student ID cards, passports and driver's licenses, and various ticket information such as airline tickets and boarding passes.

[0033] Digital wallets store VCs (Verifiable Credentials), whose contents can be verified online. In the following explanation, VCs will be referred to as "credential certificates." Specific certificates issued as credential certificates will be represented by adding "VCs" after the name of the certificate. For example, a membership card issued as a credential certificate will be represented as "membership card VCs."

[0034] <Identity Verification> Terminal 40 performs identity verification using an identification card issued by a public institution such as a national government agency when the digital wallet application is launched for the first time, etc. For example, terminal 40 performs identity verification of the user when opening a digital wallet.

[0035] For example, the terminal 40 performs identity verification using an identification document that contains the biometric information of the holder, such as a My Number card or a passport. The terminal 40 uses the My Number card or the passport as a root of trust.

[0036] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, and iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In this disclosure, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.

[0037] The terminal 40 acquires information about the holder (issuer) of the identification card from the user's identification card. For example, the terminal 40 acquires information about the holder of the My Number card from the IC (Integrated Circuit) chip of the My Number card.

[0038] Specifically, the terminal 40 acquires basic information of the cardholder (the so-called four basic pieces of information: name, sex, date of birth, and address) and biometric information (face image) of the cardholder.

[0039] Furthermore, the terminal 40 acquires biometric information of the user (the person who opened the digital wallet). For example, the terminal 40 acquires a facial image by photographing the user.

[0040] Terminal 40 performs a matching process (authentication process) using the biometric information acquired from the identification card and the biometric information of the user. If the authentication process (one-to-one authentication) is successful, terminal 40 opens a digital wallet. Terminal 40 confirms through the matching process (authentication process) using the biometric information that the person in whose name the identification card was issued and the user opening the digital wallet on terminal 40 are the same person.

[0041] If the identity verification is successful, the terminal 40 stores the name, sex, date of birth, and address read from the My Number card.

[0042] <Getting the trust list> When a user opens a digital wallet, the user obtains a credential certificate to be stored in the digital wallet. At that time, the terminal 40 obtains a "trust list" from the management server 30 and performs access control using the obtained trust list.

[0043] The terminal 40 is configured so that the access control can be set to on or off. For example, the initial value of the setting is set to on. Alternatively, a parent can set the access control setting of the terminal 40 used by their child to on.

[0044] If access control is set to ON, when the terminal 40 launches the digital wallet application, it obtains at least one trust list from the management server 30. Each trust list contains information about entities (e.g., certificate issuers) to which the user can request the issuance of a credential certificate, and information about entities (e.g., service providers) to which the user can provide a credential certificate.

[0045] The terminal 40 transmits a list provision request to the management server 30 to obtain at least one trust list (see FIG. 4).

[0046] Here, each trust list is set with a use, an application destination, a purpose, etc. For example, the management server 30 transmits a trust list for minors, a trust list for students, etc. to the terminal 40. Fig. 5 is a diagram showing an example of a trust list for minors.

[0047] 5, each trust list includes the name of the certificate issuer or service provider, an organization code, and access restrictions (certificate issuance request allowed, certificate provision allowed, certificate issuance request and provision allowed), etc. Furthermore, each trust list also includes the address of the server (server device 10, service server 20), etc. The organization code is an ID for uniquely identifying the certificate issuer or service provider.

[0048] The trust list is generated by the access administrator. The person in charge of the certificate issuer or service provider informs the access administrator (the person in charge of the access administrator) of the details of their organization's activities, name, server (homepage) address, etc.

[0049] The access administrator's staff will review and examine certificate issuers and service providers based on the acquired activity information. The access administrator's staff will reflect the review results in each trust list. For example, the staff will not include service providers that do not allow minors to receive services in the trust list for minors. The staff will determine the content of access restrictions based on the service provider's business activities and set them in the trust list.

[0050] For example, each time an access administrator obtains information from a certificate issuer or the like, the access administrator updates each trust list and registers the updated trust list in the management server 30.

[0051] Furthermore, the access administrator's staff registers the certificate issuer, the name of the service provider, the organization code, etc. in the management server 30. The server device 10, the service server 20, and the terminal 40 access the management server 30 periodically or at a predetermined timing to obtain the names, organization codes, etc. of their own organization and other organizations.

[0052] The terminal 40 selects a trust list to be used for access control from the acquired lists (plurality of trust lists).

[0053] At that time, the terminal 40 determines the user's attributes. For example, the terminal 40 determines the user's attributes based on the gender and date of birth stored during the identity verification. Alternatively, the terminal 40 determines the user's attributes using information obtained from the credentials stored in the digital wallet. For example, if a student ID card VCs is stored in the digital wallet, the terminal 40 sets the user's attributes to "student."

[0054] The terminal 40 selects a trust list to be applied to access control based on the determined user attribute (user attribute information) and the purpose of each trust list.

[0055] For example, if the user is a minor, the terminal 40 selects a trust list for minors as the trust list to be used for access control, or if the user is a student, the terminal 40 selects a trust list for students as the trust list to be used for access control.

[0056] <Obtaining Credentials> Next, the acquisition of the credential certificate will be explained. Here, the operation of the information processing system will be explained assuming that the access control of the terminal 40 is on.

[0057] Prior to requesting the issuance of a credential certificate, the user's terminal 40 generates a pair of a public key and a private key, and also generates a decentralized identifier (DID).

[0058] The terminal 40 registers the generated DID (user DID; holder DID) and public key in the blockchain (step S01 in FIG. 6).

[0059] The terminal 40 acquires information about the certificate issuer requesting the issuance of a credential certificate. For example, the terminal 40 acquires the name and organization code of the certificate issuer that has the authority to issue the credential certificate that the user wishes to obtain, using a GUI (Graphical User Interface) or the like. For example, a user who wishes to obtain an identification card VCs inputs the name of their local government into the terminal 40. Or, a user who wishes to obtain a student ID card VCs inputs the name of their university, etc. into the terminal 40.

[0060] The terminal 40 determines whether or not it is possible to request the certificate issuer to issue a credential certificate based on the trust list selected according to the user's attributes and the certificate issuer information obtained from the user.

[0061] For example, if the name of the certificate issuer obtained from the user is listed in the selected trust list and the access restriction content is set to "request and provision allowed" or "request allowed," the terminal 40 can request the certificate issuer to issue a credential certificate. On the other hand, if the name of the certificate issuer obtained from the user is not listed in the selected trust list or the access restriction content is set to "provision allowed," the terminal 40 cannot request the certificate issuer to issue a credential certificate.

[0062] If the terminal 40 is unable to request the certificate issuer to issue a credential certificate, the terminal 40 notifies the user of this fact.

[0063] If it is possible to request the certificate issuer to issue a credential certificate, the terminal 40 requests the certificate issuer (server device 10) to issue a credential certificate while presenting the user DID. Specifically, the terminal 40 transmits to the server device 10 a "certificate issuance request" including information about the certificate to be issued (for example, the type of credential certificate), information specifying the subject to be certified by the credential certificate, the user DID, etc. (step S02).

[0064] The server device 10 generates and stores in advance the DID of the issuer (issuer DID), the private key, and the public key.

[0065] Upon receiving the certificate issuance request, the certificate issuer determines whether or not it is possible to issue the credential certificate desired by the user.

[0066] If the credential certificate desired by the user can be issued, the server device 10 generates a credential certificate including the issuer DID and the user DID.

[0067] Specifically, the server device 10 generates a credential certificate including metadata including the type of credential certificate, the name of the issuing organization, the date and time of issue, the validity period, etc., the assertion (qualification information, claim), and proofs such as the issuer's public key information and electronic signature, etc. The assertion describes specific information to be certified by the issuer.

[0068] The server device 10 provides the generated credential certificate to the terminal 40 of the user (the user who will become the certificate holder; the person requesting the issuance of the certificate) (step S03).

[0069] Specifically, the server device 10 stores the generated credential certificate in online storage. The server device 10 generates a certificate acquisition URL from the URL (Uniform Resource Locator) of the storage destination of the credential certificate. The server device 10 transmits an affirmative response (response to the certificate issuance request) including the generated certificate acquisition URL to the terminal 40.

[0070] Furthermore, the server device 10 registers the issuer DID and the generated public key, etc. in the blockchain (step S04). Alternatively, the server device 10 may register the status (valid, invalid) of the issued credential certificate, a credential ID that uniquely identifies the credential certificate, the issuer DID, etc. in a VDR (Verifiable Data Registry).

[0071] The terminal 40 accesses the certificate acquisition URL included in the positive response to acquire the credential certificate, and stores the acquired credential certificate in the digital wallet.

[0072] For example, a user may request the issuance of a graduation certificate VC from the university from which the user graduated. Alternatively, the user may request the issuance of an employment certificate VC from the company where the user works. Alternatively, a user with qualifications related to technology, language, etc. may request the issuance of a qualification certificate VC from a certification organization for the qualification. The terminal 40 stores the acquired certificate VC in a digital wallet.

[0073] <Use of Credentials> When a user receives a service from a service provider, the user submits a credential certificate to the service provider in response to a request from the service provider. Here, the operation of the information processing system will be described assuming that the access control of terminal 40 is on.

[0074] For example, a user who purchases a commuter pass with a student discount provides their student ID card VCs to a railway company, etc. In this case, the user accesses the service server 20 of the railway company and applies for the purchase of a student commuter pass.

[0075] In response to the application, the service server 20 transmits a "certificate request" to the user terminal 40 (step S11 in FIG. 7). The certificate request includes information on the credential certificate required by the service provider to provide the service. For example, in the above example, "student ID card VCs" is set in the certificate request as the credential certificate required to provide the service.

[0076] The service server 20 transmits to the terminal 40 a certificate provision request including its own organization code and information on the credential certificate required for providing the service.

[0077] The terminal 40 determines whether or not it is possible to provide the credential certificate to the service provider based on the trust list selected according to the user's attributes and the organization code included in the certificate request.

[0078] If the organization code of the service provider is listed in the selected trust list and the access restriction content is set to "request and provision allowed" or "provision allowed", the terminal 40 can provide the credential to the service provider. On the other hand, if the organization code of the service provider is not listed in the selected trust list or the access restriction content is set to "request allowed", the terminal 40 cannot provide the credential to the service provider.

[0079] If the terminal 40 cannot provide the credential certificate to the service provider, the terminal 40 notifies the user to that effect. Furthermore, the terminal 40 transmits to the service server 20 a negative response (response to the credential provision request) indicating that the specified credential certificate cannot be provided.

[0080] If the terminal 40 can provide the credential to the service provider, the terminal 40 attempts to acquire the credential specified by the service provider from the digital wallet. In the above example, the terminal 40 attempts to acquire the student ID card VCs.

[0081] If the specified credential certificate cannot be acquired, the terminal 40 transmits to the service server 20 a negative response (response to the certificate provision request) indicating that the specified credential certificate cannot be provided.

[0082] If the specified credential certificate is acquired, the terminal 40 signs at least the credential certificate acquired from the digital wallet using the private key corresponding to the user DID.

[0083] The terminal 40 transmits the signed credential certificate and the user DID to the service server 20 (step S12). The terminal 40 presents the credential certificate and the user DID to the service server 20 as verifiable presentations (VPs).

[0084] The service server 20 verifies the acquired credential certificate. At that time, the service server 20 acquires the public keys of the holder and issuer of the credential certificate from the blockchain (step S13).

[0085] If the acquired credential certificate is successfully verified, the service server 20 provides the service to the user. In the above example, the service server 20 sells a student discount commuter pass.

[0086] Note that a description of the case where the access control of the terminal 40 is off will be omitted because the operation of the information processing system when the access control is off will be clear to those skilled in the art from the above description.

[0087] Next, details of each device included in the information processing system according to the first embodiment will be described.

[0088] [Device] Examples of the terminal 40 include a smartphone, a mobile phone, a game console, a mobile terminal device such as a tablet, a computer (personal computer, laptop computer), etc. The terminal 40 can be any equipment or device that can accept user operations and communicate with the server device 10, etc.

[0089] 8 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 40 according to an embodiment of the present disclosure. Referring to FIG. 8, the terminal 40 includes a communication control unit 201, a personal identification unit 202, a list control unit 203, an acquisition control unit 204, a usage control unit 205, and a storage unit 206.

[0090] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0091] The identity verification unit 202 is a means for verifying the identity of the digital wallet creator. Specifically, the identity verification unit 202 verifies the identity of the user attempting to open a digital wallet by using the biometric information of the user attempting to open a digital wallet and the biometric information obtained from an identification card. More specifically, the identity verification unit 202 verifies that the creator of the digital wallet and the holder (issuer) of the identification card issued by a public institution are the same person.

[0092] The personal identification unit 202 acquires information about the holder of the identification card from the identification card held by the user when the digital wallet is opened (when the digital wallet is started for the first time), etc. For example, the personal identification unit 202 acquires basic information and biometric information about the holder of the identification card from an IC (Integrated Circuit) chip mounted on a My Number card or passport.

[0093] For example, when a My Number card is used as an identification card, the personal identification unit 202 acquires the personal identification number of the electronic certificate for user authentication using a GUI (Graphical User Interface) or the like. Alternatively, when a passport is used as an identification card, the personal identification unit 202 acquires information written in a Machine Readable Zone (MRZ) written on the face of the passport using OCR (Optical Character Recognition) technology.

[0094] The personal identification unit 202 uses the acquired personal identification number (four-digit number) or the information written in the MRZ as a password to read information from the IC chip.

[0095] Furthermore, the identity verification unit 202 acquires biometric information of the user (user of the terminal 40; creator of the digital wallet). For example, the identity verification unit 202 prompts the user to take a picture of their own face using a GUI or the like (acquiring a facial image by taking a selfie, so to speak).

[0096] The personal identification unit 202 acquires biometric information from an identification card and, upon acquiring the biometric information of the user operating the device, executes a matching process using the biometric information acquired from the identification card and the biometric information of the user. The personal identification unit 202 determines whether the two pieces of biometric information substantially match.

[0097] Specifically, the personal identification unit 202 generates feature amounts from each of the two pieces of biometric information (for example, face images).

[0098] Since existing technology can be used for the process of generating feature amounts, detailed description thereof will be omitted. For example, the personal identification unit 202 extracts the eyes, nose, mouth, etc. from the face image as feature points. Then, the personal identification unit 202 calculates the positions of the feature points and the distances between the feature points as feature amounts (generating a feature vector consisting of multiple feature amounts).

[0099] Next, the personal identification unit 202 executes a matching process (authentication process) using the two generated feature amounts. Specifically, the personal identification unit 202 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the personal identification unit 202 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.

[0100] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the identity verification unit 202 determines that identity verification has been successful. If the similarity is equal to or less than the predetermined value, the identity verification unit 202 determines that identity verification has failed.

[0101] If identity verification is successful, the identity verification unit 202 approves the opening of a digital wallet. If identity verification is unsuccessful, the identity verification unit 202 denies the opening of a digital wallet. Furthermore, if identity verification is successful, the identity verification unit 202 stores the name, gender, date of birth, and address read from the My Number card or the like.

[0102] The list control unit 203 is a means for executing control relating to the trust list.

[0103] List control unit 203 has a function as an acquisition means and a function as a selection means. The acquisition means acquires at least one list (trust list) used for access control related to the acquisition of certificates to be stored in the digital wallet and the provision of certificates stored in the digital wallet. The selection means selects a list to be used for access control from at least one list based on the attributes of the user.

[0104] For example, when the setting related to access control is on, the list control unit 203 acquires the trust list from the management server 30. Note that a detailed description of the setting of access control will be omitted. The terminal 40 can acquire the setting of access control from the user or a related person of the user (for example, a parent of a child) using a GUI or the like.

[0105] For example, when a digital wallet application is started, the list control unit 203 transmits a list provision request to the management server 30. The list control unit 203 stores at least one trust list received from the management server 30.

[0106] Furthermore, the list control unit 203 selects a trust list to be used for access control from the acquired multiple trust lists. Specifically, the list control unit 203 determines the attributes of the user and selects a trust list to be used for access control using the determined attributes.

[0107] For example, the list control unit 203 determines the user's attributes from the gender and date of birth obtained during identity verification by the identity verification unit 202. Alternatively, the list control unit 203 determines the user's attributes from the digital content (credentials) stored in the digital wallet. For example, if a student ID card VCs is stored in the digital wallet, the list control unit 203 sets the user's attribute to "student."

[0108] The list control unit 203 selects a trust list to be used for access control based on the determined user attributes and the purpose of each trust list.

[0109] For example, if the user is a minor, the list control unit 203 selects a trust list for minors, or if the user is a student, the list control unit 203 selects a trust list for students.

[0110] The list control unit 203 may select multiple trust lists as trust lists to be used for access control depending on the attributes of the user. For example, if the user is a minor and a student, the list control unit 203 may select a trust list for minors and a trust list for students as trust lists to be used for access control.

[0111] In this way, the list control unit 203 obtains the at least one list (trust list) from the management server 30 operated by a predetermined organization (for example, an access administrator). Furthermore, the list control unit 203 may generate user attributes using information obtained from the identification card used for identity verification. Alternatively, the list control unit 203 may determine user attributes based on information obtained from digital content stored in the digital wallet, and select a list to be used for access control based on the determined attributes and the respective uses of the at least one list.

[0112] The acquisition control unit 204 is a means for controlling the acquisition of credential certificates. Specifically, when acquiring a certificate to be stored in the digital wallet, the acquisition control unit 204 executes access control using the list selected by the list control unit 203. More specifically, the acquisition control unit 204 requests the certificate issuer to issue the certificate selected by the user, and stores the certificate acquired from the certificate issuer in the digital wallet.

[0113] 9 is a flowchart showing an example of the operation of the acquisition control unit 204. The operation of the acquisition control unit 204 according to the embodiment of the present disclosure will be described with reference to FIG.

[0114] When a user who has opened a digital wallet performs a predetermined operation (for example, pressing a certificate issuance button) on the terminal 40, the acquisition control unit 204 controls the acquisition of the credential certificate desired by the user.

[0115] First, the acquisition control unit 204 generates a pair of a public key and a private key, and a user DID, which is a distributed identifier. The acquisition control unit 204 registers the generated user DID and public key in the blockchain (registering the public key, etc.; step S101).

[0116] Next, the acquisition control unit 204 acquires items necessary for requesting issuance of a credential certificate using a GUI (Graphical User Interface) or the like (acquisition of necessary items; step S102).

[0117] Specifically, the acquisition control unit 204 acquires information about the certificate issuer that has the authority to issue the credential certificate that the user desires to receive (for example, the name of the local government, company, or university), the type of certificate desired, etc. Furthermore, the acquisition control unit 204 acquires information that the certificate issuer uses to identify the subject of certification (for example, an employee number, a student ID number, or a name or a combination of a name and date of birth, etc.).

[0118] When the certificate issuer name, etc. is acquired, the acquisition control unit 204 determines whether or not it is possible to request the certificate issuer to issue a certificate (step S103). The acquisition control unit 204 executes access control (access restriction) using the trust list selected by the list control unit 203.

[0119] Specifically, if the name of the certificate issuer obtained from the user is listed in the selected trust list and the access restriction content is set to "request and provision allowed" or "request allowed," the acquisition control unit 204 determines that the issuance of a credential certificate is allowed. On the other hand, if the name of the certificate issuer obtained from the user is not listed in the selected trust list or the access restriction content is set to "provision allowed," the acquisition control unit 204 determines that the issuance of a credential certificate is not allowed.

[0120] If multiple trust lists are selected, the acquisition control unit 204 determines whether or not a credential certificate issuance request is possible using each trust list. If the acquisition control unit 204 determines that an issuance request is possible for at least one trust list, the user can request the certificate issuer selected by the user to issue a certificate.

[0121] If the certificate issuer cannot be requested to issue a credential certificate (step S104, No branch), the acquisition control unit 204 notifies the user that a credential certificate will not be issued (step S105).

[0122] If it is possible to request the certificate issuer to issue a credential certificate (step S104, Yes branch), the acquisition control unit 204 notifies the certificate issuer of the acquired necessary items and the user DID. Specifically, the acquisition control unit 204 notifies the certificate issuer of the type of credential certificate, information for identifying the certificate subject, and the user DID.

[0123] The acquisition control unit 204 transmits a "certificate issuance request" including the type of credential certificate, information specifying the certificate subject, the user DID, etc. to the server device 10 of the certificate issuer selected by the user (step S106).

[0124] The acquisition control unit 204 receives a response (positive response, negative response) to the certificate issuance request from the server device 10 (step S107).

[0125] If a negative response indicating that the certificate issuance has failed is received (step S108, No branch), the acquisition control unit 204 notifies the user that the credential certificate has not been issued (notification of non-issuance; step S105).

[0126] If a positive response indicating that the certificate has been successfully issued is received (step S108, Yes branch), the acquisition control unit 204 accesses the certificate acquisition URL included in the positive response and acquires the credential certificate issued by the certificate issuer (step S109).

[0127] The acquisition control unit 204 stores the acquired credentials in the digital wallet (step S110).

[0128] For example, a user may obtain a graduation certificate VC from the university from which the user graduated, an employment certificate VC from the company currently employed, or a qualification certificate VC from a qualification certification organization. The acquisition control unit 204 stores the obtained credential certificate in a digital wallet.

[0129] The usage control unit 205 is a means for controlling the use of digital content (credentials) stored in the digital wallet. Specifically, the usage control unit 205 executes access control using the list selected by the list control unit 203 when providing the certificate stored in the digital wallet to an external party.

[0130] Specifically, the usage control unit 205 processes a certificate provision request received from the service server 20 of the service provider.

[0131] 10 is a flowchart showing an example of the operation of the usage control unit 205. The operation of the usage control unit 205 according to the embodiment of the present disclosure will be described with reference to FIG.

[0132] When receiving a certificate provision request from the service server 20, the usage control unit 205 determines whether or not to provide a credential certificate using the trust list selected by the list control unit 203 (step S201).

[0133] Specifically, if the organization code of a service provider is entered in the trust list and the access restriction content is set to "request and provision allowed" or "provision allowed," the usage control unit 205 can provide a credential to the service provider. On the other hand, if the organization code of a service provider is not entered in the selected trust list or the access restriction content is set to "request allowed," the usage control unit 205 cannot provide a credential to the service provider.

[0134] If the credential certificate cannot be provided to the service provider (step S202, No branch), the usage control unit 205 transmits a negative response (response to the certificate provision request) indicating this to the service server 20 (step S203). At that time, the usage control unit 205 may notify the user that the credential certificate cannot be provided to the service provider.

[0135] If the credential certificate can be provided to the service provider (step S202, branch Yes), the usage control unit 205 attempts to acquire the credential certificate specified by the service provider from the digital wallet (attempt to acquire certificate; step S204).

[0136] If the credential certificate cannot be acquired from the digital wallet (step S205, No branch), the usage control unit 205 transmits a negative response to the service server 20 indicating that the credential certificate cannot be provided (step S203).

[0137] If the credential certificate can be acquired from the digital wallet (step S205, Yes branch), the usage control unit 205 transmits the credential certificate designated by the service provider to the service server 20.

[0138] Specifically, the usage control unit 205 signs the credential certificate obtained from the digital wallet using the private key corresponding to the user DID, and then transmits an affirmative response including the signed credential certificate and the user DID to the service server 20 (step S206).

[0139] The storage unit 206 is a means for storing information necessary for the operation of the terminal 40 .

[0140] [Server device] 11 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure. Referring to FIG. 11, the server device 10 includes a communication control unit 301, a certificate issuing unit 302, and a storage unit 303.

[0141] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 40. The communication control unit 301 also transmits data to the terminal 40. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0142] The certificate issuing unit 302 is a means for issuing a credential certificate to a user. The certificate issuing unit 302 processes a “certificate issuance request” received from the terminal 40.

[0143] Upon receiving a certificate issuance request, the certificate issuing unit 302 searches a database (not shown in Figure 11, etc.) that stores user information using information for identifying the subject of certification included in the certificate issuance request (e.g., employee number, etc.) as a key.

[0144] If the search fails, the certificate issuing unit 302 transmits a negative response to the terminal 40 indicating that the certificate issuance has failed.

[0145] If the search is successful, the certificate issuing unit 302 determines, as necessary, whether or not the credential certificate desired by the user can be issued.

[0146] For example, when a user requests the issuance of an employment certificate VCs, the certificate issuing unit 302 determines whether the user satisfies the requirements for receiving the issuance of an employment certificate VCs.

[0147] Note that detailed explanation regarding the determination of whether or not a credential certificate is issued will be omitted, as the requirements for issuing individual credential certificates are different from the gist of the disclosure of this application.

[0148] If a credential certificate cannot be issued to the user, the certificate issuing unit 302 transmits a negative response to the terminal 40 indicating that the certificate issuance has failed (certificate issuance is not possible).

[0149] If a credential certificate can be issued to the user, the certificate issuing unit 302 generates a credential certificate to be issued to the user. The certificate issuing unit 302 generates a credential certificate including the issuer DID and the user DID (the DID of the person to whom the certificate is to be issued; the user DID included in the certificate issuance request).

[0150] Specifically, the certificate issuing unit 302 generates a credential certificate including metadata including the type of credential certificate, the name of the issuing organization, the date and time of issue, the validity period, etc., the assertion (claim), and a proof consisting of the issuer's public key information, digital signature, etc. The digital signature affixed to the credential certificate is issued using a private key corresponding to the issuer DID generated in advance.

[0151] The certificate issuing unit 302 stores the generated credential certificate in online storage (storage on the cloud) or the like. The certificate issuing unit 302 generates a certificate acquisition URL from the URL of the storage destination of the credential certificate. The certificate issuing unit 302 transmits an affirmative response including the generated certificate acquisition URL to the terminal 40. Furthermore, the certificate issuing unit 302 registers the issuer DID, public key, etc., generated in advance, in the blockchain.

[0152] The storage unit 303 is a means for storing information necessary for the operation of the server device 10.

[0153] [Service Server] 12 is a diagram illustrating an example of a processing configuration (processing module) of the service server 20 according to the embodiment of the present disclosure. Referring to FIG. 12, the service server 20 includes a communication control unit 401, a service provision control unit 402, and a storage unit 403.

[0154] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the terminal 40. The communication control unit 401 also transmits data to the terminal 40. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0155] The service provision control unit 402 is a means for executing control regarding the services provided to the user. More specifically, when the user requests the provision of a service, the service provision control unit 402 acquires information necessary for providing the service.

[0156] The service provision control unit 402 transmits a "certificate provision request" to the terminal 40. The service provision control unit 402 transmits to the terminal 40 a certificate provision request including the type of credential certificate and the organization code required for providing the service.

[0157] If a negative response (response to the certificate provision request) is received from the terminal 40, the service provision control unit 402 notifies the user or the like that the service cannot be provided because the necessary information (necessary credential certificate) cannot be acquired.

[0158] When an affirmative response is received from the terminal 40, the service provision control unit 402 verifies the credentials included in the affirmative response.

[0159] The service provision control unit 402 verifies at least one of three items related to the validity of the credential certificate.

[0160] The first item is the verification of the digital signature attached to the credential certificate.

[0161] In this case, the service provision control unit 402 acquires the issuer DID and user DID written in the credential certificate. The service provision control unit 402 acquires a public key corresponding to the acquired issuer DID from the blockchain. Similarly, the service provision control unit 402 acquires a public key corresponding to the acquired user DID from the blockchain.

[0162] The service provision control unit 402 verifies the signature of the holder (user who provides the credential certificate) and the signature of the issuer attached to the credential certificate. By verifying these signatures, the service provision control unit 402 confirms that the credential certificate obtained from the user has not been tampered with and that it has been issued by a trustworthy issuer.

[0163] The service provision control unit 402 determines that the credential certificate verification is successful if the signatures of the credential certificate holder and issuer are verified successfully. The service provision control unit 402 determines that the credential certificate verification is unsuccessful if the signature of at least one of the credential certificate holder and issuer is verified unsuccessfully.

[0164] The second item is verification that the credential has not been revoked.

[0165] In this case, the service provision control unit 402 accesses the blockchain or VDR using the credential ID and issuer DID and confirms that the received credential certificate is not listed in the certificate issuer's revocation list. The service provision control unit 402 confirms that the credential certificate obtained from the user has not been invalidated by the issuer before its expiration date.

[0166] If the credential certificate is not listed in the revocation list, the service provision control unit 402 determines that the verification of the credential certificate has been successful. If the credential certificate is listed in the revocation list, the service provision control unit 402 determines that the verification of the acquired credential certificate has failed.

[0167] The third item is to verify that the validity period (expiration date) of the credential certificate has not expired.

[0168] The service provision control unit 402 checks the validity period set in the credential certificate. If the validity period set in the credential certificate has not expired, the service provision control unit 402 determines that the verification of the acquired credential certificate has been successful. If the validity period set in the credential certificate has expired, the service provision control unit 402 determines that the verification of the acquired credential certificate has failed.

[0169] If the service provision control unit 402 determines that "verification was successful" in all or part of the first to third items, it determines that the credential certificate obtained from the user has been verified successfully. For example, if the service provision control unit 402 determines that the verification was successful in each of the first to third items, it determines that the credential certificate has been verified successfully.

[0170] If it is determined that all or some of the first to third items have failed verification, the service provision control unit 402 determines that the verification of the credential certificate acquired from the user has failed. For example, if it is determined that one of the first to third items has failed verification, it is determined that the verification of the credential certificate has failed.

[0171] If the credential verification fails, the service provision control unit 402 notifies the user or the like that the service cannot be provided because a valid credential cannot be acquired.

[0172] If the credential verification is successful, the service provision control unit 402 provides the service to the user.

[0173] Note that detailed explanations of individual services provided by the service provision control unit 402 will be omitted, as details of individual services are outside the scope of the present disclosure.

[0174] The storage unit 403 is a means for storing information necessary for the operation of the service server 20 .

[0175] [Administration Server] 13 is a diagram illustrating an example of a processing configuration (processing module) of the management server 30 according to an embodiment of the present disclosure. Referring to FIG. 13, the management server 30 includes a communication control unit 501, a list management unit 502, and a storage unit 503.

[0176] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the terminal 40. The communication control unit 501 also transmits data to the terminal 40. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0177] The list management unit 502 is a means for controlling and managing the trust list.

[0178] The list management unit 502 acquires a trust list from a person in charge or the like. For example, the list management unit 502 acquires the trust list via a storage medium such as a USB (Universal Serial Bus) memory. The list management unit 502 stores the acquired trust list.

[0179] When the list management unit 502 receives a list provision request from the terminal 40, it transmits the stored trust list (at least one trust list) to the terminal 40.

[0180] The storage unit 503 is a means for storing information necessary for the operation of the management server 30 .

[0181] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described.

[0182] 14 is a sequence diagram illustrating an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding the issuance of a credential certificate will be described with reference to FIG.

[0183] The terminal 40 generates a public key, a private key, and a user DID, and registers the user DID and the public key in the blockchain (step S21).

[0184] The terminal 40 executes access control using the trust list selected based on the user's attributes (step S22).

[0185] If the user is able to request the issuance of a credential certificate from a certificate issuer that has the authority to issue the credential certificate that the user wishes to obtain, the terminal 40 sends a certificate issuance request including the user DID to the certificate issuer's server device 10 (step S23).

[0186] The server device 10 generates assertions (claims, qualification information) of the user (the party to whom the credential certificate is to be issued) and generates a credential certificate including the assertions (step S24). The server device 10 generates a credential certificate including the user DID and issuer DID and having a digital signature attached.

[0187] The server device 10 stores the generated credential certificate in an online storage or the like, thereby providing the credential certificate to the terminal 40 (step S25).

[0188] The terminal 40 acquires the credential certificate in accordance with the certificate acquisition URL, and stores the acquired credential certificate in the digital wallet (step S26).

[0189] 15 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding the use of a credential will be described with reference to FIG.

[0190] The service server 20 of the service provider transmits a certificate provision request specifying the credential certificate required for providing the service to the terminal 40 (step S31).

[0191] The terminal 40 executes access control using the trust list selected based on the attributes of the user (step S32).

[0192] If the service provider can provide the credential certificate, the terminal 40 acquires the credential certificate specified by the service provider from the digital wallet, and transmits the acquired credential certificate to the service server 20 (step S33).

[0193] The service server 20 verifies the acquired credentials (step S34).

[0194] If the credential certificate is successfully verified, the service server 20 provides the service to the user (step S35).

[0195] Next, a modified example of the first embodiment will be described.

[0196] <Variation 1> In the above embodiment, the terminal 40 determines the attributes of the user related to age and status, and selects a trust list based on the determined attributes. However, the terminal 40 may select a trust list using attributes other than age and status.

[0197] For example, the list control unit 203 may use a user's attribute related to nationality to select a trust list. Specifically, if passport VCs are stored in the digital wallet, the list control unit 203 identifies the user's nationality from the passport VCs.

[0198] The list control unit 203 selects a trust list according to the nationality of the user as the trust list to be used for access control. For example, if the user is Japanese, the list control unit 203 selects a trust list for Japanese people, and if the user is American, the list control unit 203 selects a trust list for Americans.

[0199] In this way, the list control unit 203 may determine the user's attributes related to at least one of the user's age, nationality, and status based on information obtained from the digital content stored in the digital wallet.

[0200] <Variation 2> The terminal 40 may determine the attributes of the user based on information acquired from an external source. For example, the list control unit 203 may acquire user information (personal information) from an identity provider (IDP) or a system of an organization to which the user belongs (e.g., a university, a company, etc.), and determine the attributes of the user based on the acquired information.

[0201] For example, the list control unit 203 may acquire the gender and age of the user from the ID provider. Alternatively, the list control unit 203 may transmit the student ID number or the like to a server of the university to which the user belongs and acquire information such as the faculty and department to which the user belongs.

[0202] The list control unit 203 can determine more detailed user attributes (more detailed attribute information) by acquiring user information from an external server, etc. Furthermore, the list control unit 203 can select a trust list that is more suitable for the user based on the detailed user attributes. For example, if the user belongs to department A2 of university A1, the list control unit 203 can select a trust list prepared for students belonging to department A2 of university A1 as the trust to be used for access control.

[0203] <Variation 3> Alternatively, the terminal 40 may obtain a trust list generated by a private company from a server operated by the private company. For example, the private company may provide a service that allows users or their relatives (e.g., guardians) to generate trust lists.

[0204] In this case, the parent accesses a specified server and generates a trust list consisting of certificate issuers that allow the child to obtain credentials and service providers to which the child can receive credentials. The parent then sets a URL linked to the generated trust list on the terminal 40 used by the child.

[0205] The list control unit 203 of the terminal 40 accesses the set URL and acquires the trust list created by the guardian. The terminal 40 may execute access control using the trust list created by the guardian.

[0206] In this way, the list control unit 203 may acquire a list created by a user (for example, a parent) other than the user (for example, a child) of the terminal 40.

[0207] <Variation 4> The terminal 40 may acquire a trust list from each of the management server 30 and another server. For example, the terminal 40 may also acquire a trust list from the service server 20. That is, the list control unit 203 may acquire at least one list from the management server 30 operated by a predetermined institution. Furthermore, the list control unit 203 may acquire a list generated by a service provider from which the user receives a service, from the service server 20 operated by the service provider.

[0208] For example, a company may use a trust list for access control of terminals 40 used by its employees. For example, a terminal 40 loaned to an employee by a company may execute access control using a trust list generated by the company.

[0209] In this case, the list control unit 203 acquires the trust list from the service server 20 that realizes employee attendance management, etc. The acquisition control unit 204 and the usage control unit 205 execute access control using the trust list generated by the company.

[0210] When the list control unit 203 acquires trust lists from both the management server 30 and another server (for example, the service server 20), the list control unit 203 may preferentially select the trust list acquired from the other server as the trust list to be used for access control. That is, when the list control unit 203 acquires a trust list from the service server 20, the list control unit 203 may preferentially select the trust list generated by the service provider as the trust list to be used for access control over the trust list acquired from the management server 30.

[0211] <Variation 5> The terminal 40 may determine the user's attributes (attribute information) based on the contract information of the service to which the user has subscribed (the service to be provided). For example, the list control unit 203 reads out credentials related to the service to which the user has subscribed, such as membership cards VCs and contracts VCs, stored in the digital wallet. The list control unit 203 acquires contract information from the read out credentials.

[0212] For example, when a user is receiving a job change support service, the list control unit 203 obtains the grade of the service (e.g., high class, middle class, low class) that the user has applied for from the membership card VCs or contract VCs of the job change support service.

[0213] For example, when a user and a service provider conclude a contract, a trust list corresponding to each grade may be provided to the user (terminal 40). For example, a high-class trust list, a middle-class trust list, and a low-class trust list may be distributed to each user (contractor).

[0214] The list control unit 203 selects the trust list corresponding to the grade with which the user has a contract as the trust list to be used for access control. For example, a high-class trust list lists many companies hiring as recipients of resume VCs. On the other hand, a low-class trust list lists a small number of companies hiring as recipients of resume VCs.

[0215] <Variation 6> A service provider may distribute a trust list to a user when providing the service to the user. The service provider may also generate a trust list appropriate for the service it provides and provide it to the user.

[0216] For example, consider the case where an employee of a company applies for year-end tax adjustment. In this case, the employee operates terminal 40 to access a portal site provided by the company and applies for year-end tax adjustment. The company's service server 20 (portal site) instructs the user to download a trust list.

[0217] Users download a trust list, which contains a list of insurance companies that can issue the credential certificates necessary for claiming life insurance premium deductions, and businesses (companies where employees work) that can submit year-end tax adjustment VCs.

[0218] The terminal 40 acquires a credential certificate for receiving a life insurance premium deduction from the server device 10 of an insurance company listed on the trust list, and generates year-end adjustment VCs using the acquired credential certificate. The terminal 40 transmits the generated year-end adjustment VCs to the submission destination (service server 20 of the affiliated company) listed on the trust list.

[0219] <Variation 7> The terminal 40 may select a trust list acquired from another server as the trust list to be used for access control regardless of the user's attributes. For example, the list control unit 203 may select a trust list created by a guardian as the trust list to be used for access control regardless of the user's age, etc.

[0220] Alternatively, the list control unit 203 may select a trust list downloaded from the company's service server 20 as the trust list to be used for access control regardless of the user's age, etc. In other words, the service provider (service server 20) may specify the trust list to be used by the terminal 40 for access control.

[0221] As described above, the terminal 40 according to the first embodiment acquires multiple trust lists from the management server 30 and selects a trust list from the acquired trust lists according to the user's attributes. The terminal 40 uses the selected trust list to perform access control related to the acquisition and provision of credential certificates. Because trust lists are generated by public institutions such as national and local governments, the risk of a user's personal information or credential certificate falling into the hands of criminal groups is reduced. This reduces the risk of a user's personal information or credential certificate falling into the hands of criminal groups. This reduces the risk of a user's personal information or credential certificate falling into the hands of criminal groups. This reduces the risk of a user's personal information or credential certificate falling into the hands of criminal groups. Furthermore, the terminal 40 selects a trust list to be used for access control according to the user's attributes, thereby ensuring user convenience. Users' comprehension and judgment abilities vary depending on factors such as age, and the manner in which users utilize their credential certificates also varies. By selecting a trust list appropriate for each user according to the user's abilities, the terminal 40 can achieve both safe credential use and user convenience. The information processing system according to the first embodiment also enables parents to control access to their children's terminals 40 (parental control). Furthermore, the information processing system can also realize access control by a company on employee terminals 40. That is, the information processing system according to the first embodiment can realize access control for both personal use and corporate use.

[0222] Next, the hardware of each device constituting the information processing system will be described. Fig. 16 is a diagram showing an example of the hardware configuration of the terminal 40.

[0223] The terminal 40 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 16. For example, the terminal 40 has a processor 311, a memory 312, an input / output interface 313, a communication interface 314, etc. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0224] However, the configuration shown in Fig. 16 is not intended to limit the hardware configuration of the terminal 40. The terminal 40 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the terminal 40 is not intended to be limited to the example shown in Fig. 16, and for example, the terminal 40 may include multiple processors 311.

[0225] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0226] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0227] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0228] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0229] The functions of the terminal 40 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by a semiconductor chip.

[0230] The server device 10, the service server 20, and the management server 30 can also be configured using information processing devices, just like the terminal 40, and their basic hardware configurations are no different from those of the terminal 40, so a description thereof will be omitted.

[0231] Terminal 40, which is an information processing device, is equipped with a computer, and functions of terminal 40 can be realized by having the computer execute a program. Terminal 40 also executes a control method for terminal 40 using the program. Similarly, server device 10 is equipped with a computer, and functions of server device 10 can be realized by having the computer execute a program. Server device 10 also executes a control method for server device 10 using the program.

[0232] [Variations] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0233] In the above embodiment, the terminal 40 acquires a credential from a certificate issuer from which the terminal 40 is permitted to acquire a credential according to the trust list. However, the terminal 40 may acquire a credential from a certificate issuer from which the terminal 40 is prohibited from acquiring a credential according to the trust list. In this case, the terminal 40 notifies the user that the terminal 40 is about to acquire a credential from a certificate issuer not listed in the trust list, and obtains consent from the user to acquire a credential from a certificate issuer outside the trust list. If consent is obtained from the user, the terminal 40 may acquire a credential from a certificate issuer outside the list. Note that the terminal 40 may provide a credential to a service provider outside the trust list in a similar manner.

[0234] Alternatively, when attempting to obtain a credential from a certificate issuer outside the trust list, the terminal 40 may obtain the credential from the certificate issuer outside the list when permission from a pre-registered user is obtained. For example, a terminal 40 used by a child may obtain a credential from a certificate issuer outside the list when parental consent is obtained. Similarly, the terminal 40 may provide a credential to a service provider outside the list when parental consent is obtained. The terminal 40 may obtain consent from other users to access businesses outside the list by sending a message to a pre-registered email address or phone number.

[0235] In the above embodiment, the trust list used in the information processing system is a whitelist. However, the trust list may be a blacklist. The terminal 40 may perform access control such that it does not obtain credentials from certificate issuers listed on the blacklist and does not provide credentials to service providers listed on the blacklist.

[0236] In the above embodiment, a case has been described in which a list of certificate issuers from which credentials can be obtained and a list of service providers from which credentials can be provided are described in one trust list. However, the list of certificate issuers and the list of service providers may be described in different trust lists.

[0237] In the information processing system, a trust list for each credential (type of credential) may be used. For example, the trust list may define certificate issuers that can obtain identity certificates VCs and service providers that can provide identity certificates VCs.

[0238] In the above embodiment, the case has been described in which the terminal 40 acquires a trust list from the management server 30 and selects a trust list to be used for access control based on the attributes of the user. However, the terminal 40 may transmit the attributes (attribute information) of the user to the management server 30, and the management server 30 may select a trust list to be used for access control based on the attributes of the user. The management server 30 may transmit the selected trust list to the terminal 40.

[0239] The terminal 40 may not acquire a trust list even if the access control setting is on. For example, if the user is not a minor, or if the user changes from a minor to an adult, the terminal 40 may stop access control and not acquire a trust list from the management server 30. In other words, the terminal 40 may not acquire a trust list according to the attributes of the user and may not execute access control.

[0240] The terminal 40 may be configured so that another user can remotely switch the access control settings. For example, the parent's terminal 40 may switch the access control settings by sending a setting switching message to the child's terminal 40.

[0241] In the above embodiment, the case where the credential certificate is provided to the service provider (service server 20) online has been described. However, the credential certificate may also be provided to the service provider offline. For example, the terminal 40 converts the credential certificate into a two-dimensional code and displays the two-dimensional code. The service provider's operator terminal (not shown in FIG. 3, etc.) restores the two-dimensional code and obtains the credential certificate. If the operator terminal successfully verifies the obtained credential certificate, it may provide the service to the user.

[0242] In the above embodiment, the digital wallet used by the user is configured inside the terminal 40. However, the digital wallet may also be configured online. That is, the terminal 40 may use a web wallet.

[0243] In the above embodiment, the server device 10 operated by the service provider issues a credential certificate that does not require a certification authority for certificate verification. However, the server device 10 may also issue a certificate that requires a certification authority (a certificate based on a public key infrastructure).

[0244] Some functions of the server apparatus 10 and the terminal 40 may be implemented in another apparatus, device, etc. More specifically, the above-described "list control unit (list control means)" and the like may be implemented in any of the apparatuses included in the system.

[0245] The form of data transmission and reception between each device (for example, server device 10, terminal 40) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable that encrypted data be transmitted and received.

[0246] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0247] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0248] The above explanation makes clear the industrial applicability of the present invention, and the present invention is suitably applicable to information processing systems including service providers that provide services to users using certificates stored in digital wallets.

[0249] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.

[0250] [Appendix 1] an acquisition means for acquiring at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of the certificates stored in the digital wallet; a selection means for selecting a list to be used for access control from the at least one list based on a user attribute; an acquisition control means for executing access control using the selected list when acquiring a certificate to be stored in the digital wallet; a usage control means for executing access control using the selected list when providing the certificate stored in the digital wallet to an external party; A terminal comprising:

[0251] [Appendix 2] The terminal described in Appendix 1, wherein the selection means determines the user's attributes based on information obtained from the digital content stored in the digital wallet, and selects a list to be used for the access control based on the determined attributes and the intended use of each of the at least one list.

[0252] [Appendix 3] The terminal described in Appendix 2, wherein the selection means determines the user's attributes regarding at least one of the user's age, nationality, and status based on information obtained from digital content stored in the digital wallet.

[0253] [Appendix 4] The terminal according to any one of appendices 1 to 3, wherein the acquisition means acquires a list created by a user other than the user.

[0254] [Appendix 5] A terminal described in any one of Appendices 1 to 3, wherein the acquisition means acquires the at least one list from an administration server operated by a designated institution, and acquires a list generated by a service provider from a service server operated by the service provider from which the user receives services.

[0255] [Appendix 6] The terminal described in Appendix 5, wherein when the selection means obtains a list from the service server, it selects the list obtained from the service server as the list to be used for the access control in preference to the at least one list.

[0256] [Appendix 7] A terminal as described in any one of appendices 1 to 3, further comprising an identity verification means for verifying the identity of a user attempting to open the digital wallet using biometric information of the user attempting to open the digital wallet and biometric information obtained from an identification card.

[0257] [Appendix 8] The terminal according to claim 7, wherein the selection means generates attributes of the user using information obtained from an identification card used for the identity verification.

[0258] [Appendix 9] an acquiring step of acquiring at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of the certificates stored in the digital wallet; a selection step of selecting a list to be used for access control from the at least one list based on user attributes; an acquisition control step of executing access control using the selected list when acquiring a certificate to be stored in the digital wallet; a usage control step of executing access control using the selected list when providing the certificate stored in the digital wallet to an external party; A method for controlling a terminal, comprising:

[0259] [Appendix 10] A terminal control method as described in Appendix 9, wherein the selection process determines attributes of the user based on information obtained from digital content stored in the digital wallet, and selects a list to be used for the access control based on the determined attributes and the intended use of each of the at least one list.

[0260] [Appendix 11] A terminal control method as described in Appendix 10, wherein the selection process determines the user's attributes regarding at least one of the user's age, nationality, and status based on information obtained from digital content stored in the digital wallet.

[0261] [Appendix 12] 12. The terminal control method according to claim 9, wherein the acquiring step acquires a list created by a user other than the user.

[0262] [Appendix 13] A method for controlling a terminal described in any one of Appendices 9 to 11, wherein the acquisition process acquires the at least one list from an administration server operated by a designated institution, and acquires a list generated by a service provider from a service server operated by the service provider from which the user receives services.

[0263] [Appendix 14] A terminal control method as described in Appendix 13, wherein the selection process, when a list is obtained from the service server, selects the list obtained from the service server as the list to be used for the access control in priority to the at least one list.

[0264] [Appendix 15] A method for controlling a terminal as described in any one of appendices 9 to 11, further comprising an identity verification step of verifying the identity of a user attempting to open the digital wallet using biometric information of the user attempting to open the digital wallet and biometric information obtained from an identification card.

[0265] [Appendix 16] A terminal control method according to claim 15, wherein the selection step generates attributes of the user using information obtained from an identification card used for the identity verification.

[0266] [Appendix 17] The computer installed in the device an acquisition process for acquiring at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of the certificates stored in the digital wallet; a selection process for selecting a list to be used for access control from the at least one list based on user attributes; an acquisition control process that executes access control using the selected list when acquiring a certificate to be stored in the digital wallet; a usage control process for performing access control using the selected list when providing the certificate stored in the digital wallet to an external party; A computer-readable storage medium that stores a program for executing the above.

[0267] [Appendix 18] The storage medium described in Appendix 17, wherein the selection process determines the user's attributes based on information obtained from digital content stored in the digital wallet, and selects a list to be used for the access control based on the determined attributes and the intended use of each of the at least one list.

[0268] [Appendix 19] 19. The storage medium of claim 18, wherein the selection process determines attributes of the user relating to at least one of the user's age, nationality, and status based on information obtained from digital content stored in the digital wallet.

[0269] [Appendix 20] 20. The storage medium according to any one of appendices 17 to 19, wherein the acquisition process acquires a list created by a user other than the user.

[0270] [Appendix 21] A storage medium described in any one of Appendices 17 to 19, wherein the acquisition process acquires at least one list from an administrative server operated by a designated institution, and acquires a list generated by a service provider from a service server operated by the service provider from which the user receives services.

[0271] [Appendix 22] A storage medium as described in Appendix 21, wherein the selection process, when a list is obtained from the service server, selects the list obtained from the service server as the list to be used for the access control in priority to the at least one list.

[0272] [Appendix 23] A storage medium as described in any one of Appendices 17 to 19, further comprising an identity verification process that verifies the identity of a user attempting to open the digital wallet using biometric information of the user attempting to open the digital wallet and biometric information obtained from an identification card.

[0273] [Appendix 24] A storage medium as described in Appendix 23, wherein the selection process generates attributes of the user using information obtained from the identification card used for the identity verification.

[0274] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 8, which are dependent on Supplementary Note 1, may also be dependent on Supplementary Notes 9 and 17 in the same dependent relationship as Supplementary Notes 2 to 8. Furthermore, not limited to Supplementary Notes 1, 9, and 17, but within the scope of each of the above-mentioned embodiments, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems.

[0275] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0276] 10 Server device 20 Service Server 30 Management Server 40 terminals 100 devices 101 Acquisition method 102 Selection Method 103 Acquisition control measures 104 Usage control measures 201 Communication control unit 202 Identity Verification Department 203 List control section 204 Acquisition control section 205 Usage Control Unit 206 Memory section 301 Communication Control Unit 302 Certificate Issuance Department 303 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Service provision control unit 403 Storage section 501 Communication control unit 502 List Management Department 503 Storage section

Claims

1. an acquisition means for acquiring at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of the certificates stored in the digital wallet; a selection means for selecting a list to be used for access control from the at least one list based on a user attribute; an acquisition control means for executing access control using the selected list when acquiring a certificate to be stored in the digital wallet; a usage control means for executing access control using the selected list when providing the certificate stored in the digital wallet to an external party; A terminal comprising:

2. The terminal according to claim 1, wherein the selection means determines attributes of the user based on information obtained from the digital content stored in the digital wallet, and selects a list to be used for the access control based on the determined attributes and the intended use of each of the at least one list.

3. 3. The terminal according to claim 2, wherein the selection means determines attributes of the user relating to at least one of the user's age, nationality, and status based on information obtained from digital content stored in the digital wallet.

4. The terminal according to claim 1 , wherein the acquisition unit acquires a list created by a user other than the user.

5. The terminal according to any one of claims 1 to 3, wherein the acquisition means acquires the at least one list from a management server operated by a predetermined institution, and acquires a list generated by a service provider from a service server operated by the service provider from which the user receives services.

6. 6. The terminal according to claim 5, wherein when the selection means acquires a list from the service server, the selection means selects the list acquired from the service server as the list to be used for the access control in preference to the at least one list.

7. 4. The terminal according to claim 1, further comprising an identity verification means for verifying the identity of a user attempting to open the digital wallet using biometric information of the user attempting to open the digital wallet and biometric information obtained from an identification card.

8. 8. The terminal according to claim 7, wherein said selection means generates an attribute of said user using information obtained from an identification card used for said personal identification.

9. an acquiring step of acquiring at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of the certificates stored in the digital wallet; a selection step of selecting a list to be used for access control from the at least one list based on user attributes; an acquisition control step of executing access control using the selected list when acquiring a certificate to be stored in the digital wallet; a usage control step of executing access control using the selected list when providing the certificate stored in the digital wallet to an external party; A method for controlling a terminal, comprising:

10. The computer installed in the device an acquisition process for acquiring at least one list used for access control regarding acquisition of certificates to be stored in a digital wallet and provision of the certificates stored in the digital wallet; a selection process for selecting a list to be used for access control from the at least one list based on a user attribute; an acquisition control process that executes access control using the selected list when acquiring a certificate to be stored in the digital wallet; a usage control process for performing access control using the selected list when providing the certificate stored in the digital wallet to an external party; A program to execute.

Citation Information

Patent Citations

  • Information processing device, information processing method, and information processing program

    JP2024179937A

  • Terminal, system, terminal control method, and storage medium

    WO2025057526A1

  • Verification assistance method, verification assistance program, and information processing device

    WO2023145027A1