Information management system and personal information server

The IC card and personal information server system addresses the challenges of data management in self-sovereign identity systems by enabling secure, user-friendly biometric authentication and decentralized data management, ensuring safe handling of personal information.

JP7770828B2Active Publication Date: 2025-11-17KK TOSHIBA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021151866
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-17
Publication Date
2025-11-17
Estimated Expiration
2041-09-17

AI Technical Summary

Technical Problem

Individuals unfamiliar with smartphones and PCs face challenges in managing their own data using self-sovereign identity systems, and there are concerns about securely storing private keys due to potential attacks on these devices.

Method used

An information management system utilizing an IC card with a sensor, memory, and processor, and a personal information server with a communication unit and processor, enabling biometric authentication and decentralized data management, ensuring secure storage and transfer of personal information.

Benefits of technology

Facilitates secure and user-friendly management of personal information by individuals, allowing them to handle their data without complex operations and protecting against data leaks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007770828000001
    Figure 0007770828000001
  • Figure 0007770828000002
    Figure 0007770828000002
  • Figure 0007770828000003
    Figure 0007770828000003
Patent Text Reader

Abstract

To provide an information management system that safely operates information managed for every individual without complicated operations, an authentication device, and a personal information server.SOLUTION: An information management system has an authentication device 2, a personal information server 4, and a window terminal 5. A sensor 20 of the authentication device 2 acquires biological information on a person. When biological collation between the biological information acquired by the sensor and biological information stored in memory is successful, the authentication device 2 outputs information indicating the place of the personal information server 4 to the window terminal 5. A communication unit of the personal information server 4 communicates with the window terminal 5. Data memory of the personal information server 4 stores personal information on a holder of the authentication device 2. In response to a request from the window terminal 5 connected with the authentication device 2, the personal information server 4 supplies, to the window terminal 5, the personal information on the holder of the authentication device 2 stored in the data memory.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] An embodiment of the present invention is an information management system. and Regarding personal information servers. [Background technology]

[0002] In recent years, self-sovereign identity systems have been under consideration. Self-sovereign identity systems are systems based on the concept of individuals managing their own data, rather than the traditional centralized data management. Self-sovereign identity systems assume that personal credentials will be received and provided using mobile devices such as smartphones or personal computers (PCs).

[0003] In conventional centralized systems, data is centrally managed by the platform provider, which poses significant risks in terms of privacy and data protection, such as the risk of a security attack on the centrally managed data resulting in the leakage of personal information of a large number of people or the unauthorized use of large amounts of data by third parties.In contrast, a self-sovereign identity system is expected to reduce risks related to data protection by decentralizing the management of information, allowing individuals to handle their own data, and by enabling one-to-one data transfers with trusted parties.

[0004] However, many individuals, including the elderly, are unfamiliar with operating information devices such as smartphones and PCs. It is thought that individuals who are unfamiliar with using such devices will find it difficult to manage their own data using a self-sovereign identity system. Therefore, to realize a self-sovereign identity system, it is considered necessary to operate it using an easy-to-understand user interface. Furthermore, in a self-sovereign identity system, users themselves must securely manage and store information such as private keys. Assuming an operation in which users themselves securely store information, there is a concern that keys may be leaked due to attacks such as computer viruses on smartphones and PCs owned by users. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2001-312477 Summary of the Invention [Problem to be solved by the invention]

[0006] To solve the above problems, we developed an information management system that can safely manage information managed by individuals without complicated operations. and Provides a personal information server. [Means for solving the problem]

[0007] According to an embodiment, the information management system includes: IC card and Decentralized management of information for each individual The IC card has a sensor, a memory, an interface, and a first processor. The personal information server has a communication unit, a data memory, and a second processor. The sensor acquires biometric information of a person. The memory stores the biometric information of the holder. The interface is a terminal device. Card reader / writer includedThe first processor outputs information indicating the location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched. Network interface provided by The data memory communicates with IC card The second processor stores the personal information of the holder of IC card The data memory stores the data in response to a request from the terminal device to which the IC card The personal information of the holder of the card is supplied to the terminal device. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram showing an example of a system configuration for issuing an IC card as an authentication device used in an information management system according to an embodiment. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of an IC card as an authentication device used in the information management system according to the embodiment. [Figure 3] FIG. 3 is a block diagram showing an example of the configuration of a registration device for issuing an IC card as an authentication device used in the information management system according to the embodiment. [Figure 4] FIG. 4 is a sequence diagram illustrating an issuing process for issuing an IC card as an authentication device used in the information management system according to the embodiment. [Figure 5] FIG. 5 is a diagram showing an example of a system configuration in which an information management system according to an embodiment provides information on a holder of an IC card as an authentication device. [Figure 6] FIG. 6 is a block diagram showing an example of the configuration of a personal information server that is a repository of IC card holders in the information management system according to the embodiment. [Figure 7] FIG. 7 is a sequence diagram for explaining an authentication procedure between an IC card, a personal information server, and a service terminal in an information management system according to an embodiment. [Figure 8]FIG. 8 is a sequence diagram for explaining a process in which the information management system according to the embodiment provides the information of the holder of the IC card stored in the personal information server to the service terminal. [Figure 9] FIG. 9 is a sequence diagram for explaining the process in which the information management system according to the embodiment stores information from the service terminal in a personal information server that is a repository for the holder of the IC card. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, embodiments will be described with reference to the drawings. First, a procedure for issuing (registering) an authentication device used in an information management system according to an embodiment will be described. FIG. 1 is a diagram schematically illustrating an example of a system configuration for issuing (registering) an IC card 2 as an authentication device that can be used in an information management system according to an embodiment. In the configuration example shown in FIG. 1, the information management system includes a terminal (user terminal) 1, an IC card 2, a registration device 3, a personal information server 4, and the like.

[0010] The IC card 2 is an example of an authentication device that has a function of performing biometric authentication. The IC card 2 as an authentication device is issued to each individual and has a function of authenticating the holder by biometric information.

[0011] The IC card 2 as an authentication device is equipped with a biometric sensor 20 for acquiring biometric information as authentication information acquired from a person. In this embodiment, the IC card 2 as an authentication device will be described as a fingerprint authentication card (fingerprint sensor card) equipped with a fingerprint sensor that reads a fingerprint, which is an example of biometric information, as the biometric sensor 20. The IC card 2 performs fingerprint authentication (biometric authentication) to verify the identity of the holder (registered person) by comparing the fingerprint read by the fingerprint sensor (biometric sensor) 20 with the fingerprint of the holder (registered person) that is registered in advance in the memory of the IC card 2.

[0012] The authentication device according to the embodiment is not limited to a fingerprint sensor card, which is an IC card equipped with a fingerprint sensor. For example, the authentication device may be a portable electronic device that performs biometric authentication using biometric information other than a fingerprint, or may be hardware such as a smartphone.

[0013] In this embodiment, it is assumed that the holder of the IC card 2 has a personal information server 4 that manages information such as the holder's personal information and qualification information. The personal information server 4 is called a repository. The personal information server 4 manages information in a decentralized manner for each individual, constituting a self-sovereign identity system in which each individual handles their own data. Unlike a centralized data management system in which a platform provider collectively manages data, the self-sovereign identity system improves data privacy protection by securely transferring data such as personal qualification information managed in a decentralized manner by each individual's personal information server 4 using personal authentication by an authentication device.

[0014] A personal information server 4 is provided for each holder of an IC card 2 who is the subject of management of personal information such as qualification information. The personal information server 4 stores personal information such as qualification information as information about the holder of the IC card 2. The personal information server 4 has the function of securely communicating with the IC card 2 by mutual authentication with the IC card 2 as an authentication device. The personal information server 4, which is a repository for the holder of the IC card 2, is connected to a network. The location (server location) of the personal information server is indicated by an address on the network such as a URL.

[0015] The terminal 1 is an information processing device that has a card interface that communicates with an IC card 2 as an authentication device and a network interface that communicates with a registration device 3. The terminal 1 may be any device that can mediate communication between the IC card and the registration device 3. Furthermore, the terminal 1 is not limited to a device that has a card interface (card reader / writer) that communicates with the IC card 2, but may also have an interface for connecting to a card reader / writer as an external device. The terminal 1 is assumed to be, for example, a user terminal such as a smartphone, tablet PC, or personal computer (PC) operated by the user himself / herself.

[0016] The registration device 3 has a function of communicating with external devices via a network, and is a device that manages an HSM (Hardware Security Module) 3A in which personal information is registered. The registration device 3 is, for example, a server operated by a public institution, and manages the HSM 3A that stores personal information including biometric (fingerprint) information of each individual managed by the public institution and the URL (server location such as address) of the repository.

[0017] The HSM 3A is a device that securely stores information. In this embodiment, the HSM 3A has a function of performing fingerprint matching (biometric authentication) between stored registered fingerprint information and fingerprint information acquired by the IC card 2 provided via the terminal 1 and the registration device 3. The HSM 3A also has a function of generating a key pair of a private key and a public key and securely storing the private key.

[0018] Next, the configuration of a control system in the IC card 2 as an authentication device according to the embodiment will be described. FIG. 2 is a block diagram showing an example of the configuration of an IC card 2 as an authentication device according to the embodiment. The IC card 2 is an authentication device that is activated (made operable) by power supplied from an external device. The IC card 2 is also called a smart card. As shown in FIG. 2, the IC card 2 has a main body C. The main body C is formed into a card shape from plastic or the like. A control module M is embedded within the main body C of the IC card 2. The control module M is formed integrally with one or more IC chips with a communication interface connected thereto.

[0019] 2, the control module M includes a processor 21, a ROM 22, a RAM 23, a data memory 24, and a communication interface 25. In the main body C of the IC card 2, the control module M is connected to a display 26 and a fingerprint sensor 20 as a biometric sensor.

[0020] The processor 21 includes circuits that execute various processes. The processor 21 is, for example, a CPU (Central Processing Unit). The processor 21 controls the entire IC card 2. The processor 21 realizes various processing functions by executing programs stored in the ROM 22 or the data memory 24. However, some or all of the various functions executed by the processor 21, which will be described later, may be realized by hardware circuits.

[0021] The ROM 22 is a non-volatile memory that functions as a program memory. Control programs, control data, etc. are stored in the ROM 22 in advance. The ROM 22 is incorporated into the IC card 2 during the manufacturing stage with the control programs, control data, etc. stored therein. The control programs and control data stored in the ROM 22 are incorporated in advance according to the specifications of the IC card 2. For example, the ROM 22 stores a program that causes the processor 21 to execute processing in response to commands received from an external device (card reader / writer).

[0022] The RAM 23 is a volatile memory that functions as a working memory. The RAM 23 also functions as a buffer that temporarily stores data being processed by the processor 21. For example, the RAM 23 functions as a communication buffer that temporarily stores data to be transmitted and received between the processor 21 and an external device via the communication interface 25.

[0023] The data memory 24 is a non-volatile memory to which data can be written and rewritten. The data memory 24 is configured, for example, with an EEPROM (registered trademark) (Electrically Erasable Programmable Read Only Memory). Programs and various data according to the operational use of the IC card 2 are written to the data memory 24. Program files or data files are defined in the data memory 24, and control programs and various data are written to these files. Some or all of the areas of the data memory 24 are tamper-resistant, and data can be stored securely. For example, information such as key information is stored in the storage area of ​​the data memory 24 that can securely store data.

[0024] The data memory 24 has a storage area 24a that stores biometric information of the holder of the IC card 2. If the IC card 2 is a fingerprint sensor card that acquires biometric information using a fingerprint, fingerprint information as the biometric information of the holder, that is, the user, is written in the storage area 24a of the IC card 2. In the present embodiment described below, it is assumed that the IC card 2 is held by the user with fingerprint information as the holder's biometric information written in the storage area 24a of the data memory 24.

[0025] The communication interface 25 has a communication control unit and an interface unit, and constitutes a communication unit. The communication interface 25 is an interface for communicating with a card interface (card reader / writer) provided in a terminal device such as the terminal 1 and the counter terminal 5 (see FIG. 5) or a card reader / writer connected to the terminal device via an interface. The communication interface 25 realizes a communication function using a communication method corresponding to the card interface provided in the terminal device (terminal 1 and the counter terminal 5). The communication interface 25 may also be configured to support multiple communication methods (for example, contact communication and contactless communication).

[0026] When the IC card 2 is realized as a contactless IC card, the communication interface 25 constitutes a communication unit that communicates contactlessly (wirelessly) with a card interface provided in the terminal device or a card reader / writer (RW) connected to the terminal device via an interface. In this case, the communication interface 25 has an antenna that transmits and receives radio waves, and is composed of a modulation circuit for generating radio waves to be transmitted from the antenna, a demodulation circuit for generating a signal from the radio waves received by the antenna, etc.

[0027] Furthermore, when the IC card 2 is realized as a contact-type IC card, the communication interface 25 constitutes a communication unit that contacts and communicates with a card interface provided in the terminal device or a card RW connected to the terminal device via an interface. In this case, the communication interface 25 is provided with a contact unit that makes physical and electrical contact with a contact unit provided in the card RW, and is constituted by a communication control circuit and the like that controls the transmission and reception of signals via the contact unit.

[0028] The biometric sensor 20 is an example of an authentication information acquisition unit that acquires authentication information. The biometric sensor 20 is a sensor that acquires a person's biometric information as authentication information to be used in authentication processing. In this embodiment, the biometric sensor 20 is a fingerprint sensor that reads a user's fingerprint information (fingerprint image). The fingerprint sensor 20 as a biometric sensor is provided so that the fingerprint reading sensor is exposed on the surface of the card body C, and reads the fingerprint of a person's finger that is held over the exposed sensor portion. Fingerprint matching is performed by comparing the fingerprint information read by the fingerprint sensor 20 with fingerprint information stored in the memory area 24a of the data memory 24.

[0029] The biometric sensor 20 is not limited to a fingerprint sensor, but may be a sensor that acquires biometric information other than a fingerprint (for example, palm print, vein pattern, iris pattern, etc.). When a sensor that acquires biometric information other than a fingerprint is provided, the IC card 2 may be provided with a function for performing biometric authentication corresponding to the biometric information acquired by the sensor (for example, an IC chip that performs palm print matching, vein matching, iris matching, etc.).

[0030] Next, a description will be given of the configuration of the registration device 3 for issuing (registering) the IC card 2 as an authentication device used in the information management system according to the embodiment. FIG. 3 is a block diagram showing an example of the configuration of the registration device 3 in the issuing system according to the embodiment. As shown in FIG. 3, the registration device 3 includes a processor 31, a ROM 32, a RAM 33, a data memory , a communication unit , and an interface .

[0031] The processor 31 executes various processes by executing programs. The processor 31 is, for example, a CPU (Central Processing Unit). The processor 31 is connected to each unit in the registration device 3 via a system bus, and transmits and receives data to and from each unit. The processor 31 cooperates with the ROM 32 and RAM 33 to execute operations such as control and data processing in the registration device 3.

[0032] The ROM (Read Only Memory) 32 is a non-volatile memory that stores programs and control data for implementing the basic operations of the registration device 3. The RAM (Random Access Memory) 33 is a volatile memory that temporarily stores data and functions as a working memory when the processor 31 executes a program.

[0033] The data memory 34 is a storage unit that stores various types of data. The data memory 34 is configured as a non-volatile memory that allows data to be rewritten. For example, the data memory 34 stores an OS program, application programs, operation setting information, and the like.

[0034] The communication unit 35 is a communication interface for communicating with an external device. The communication unit 35 may communicate wirelessly or may communicate via a wired connection. In this embodiment, the communication unit 35 communicates with the terminal 1 used by the user via a wide area network such as the Internet. The processor 31 executes secure communication with the IC card 2 via the terminal 1 using the communication unit 35.

[0035] The interface 36 is an interface for accessing the HSM 3A. The interface 36 may be any interface that complies with the interface standard of the HSM 3A. Here, the HSM 3A may be a device connected to the registration device 3 via the interface 36.

[0036] The HSM 3A securely stores information including fingerprint information as biometric information of the holder of the IC card 2 and the address (URL) of the repository. The HSM 3A also has the function of performing biometric matching between the biometric information input from the registration device 3 and the stored biometric information, and outputting the biometric matching results. The HSM 3A can perform biometric matching without outputting the stored biometric information to an external device, thereby achieving secure biometric matching.

[0037] Next, an issuance process for issuing (registering) the IC card 2 used in the information management system according to this embodiment will be described. FIG. 4 is a sequence diagram for explaining an example of the operation of an issuance process for issuing (registering) an IC card 2 serving as an authentication device as an IC card 2 that can be used in an information management system. 4, it is assumed that the IC card 2 stores the fingerprint information of the holder, and that the HSM 3A stores the fingerprint information and the URL of the repository related to the holder of the IC card 2. It is also assumed that the IC card 2 and the HSM 3A have the function of securely communicating with each other via the terminal 1 and the registration device 3.

[0038] The processor 21 of the IC card 2 connects to the terminal 1 via the communication I / F 25 and communicates with the registration device 3 using the network communication function of the terminal 1. When the processor 21 of the IC card 2 establishes communication with the registration device 3 via the terminal 1, it performs mutual authentication between the IC card 2 and the HSM 3A (ST11).

[0039] If the mutual authentication between the IC card 2 and the HSM 3A is successful, the processor 21 of the IC card 2 transmits the fingerprint information of the holder of the IC card 2, which is stored in the storage area 24a of the data memory 24, to the HSM 3A of the registration device 3 (ST12). The HSM 3A performs a fingerprint comparison between the fingerprint information acquired from the IC card 2 and the registered fingerprint information stored therein (ST13). If the comparison between the fingerprint information acquired from the IC card 2 and the registered fingerprint information is successful, the HSM 3A notifies the IC card 2 of the successful comparison via the registration device 3 and the terminal 1 (ST14).

[0040] After the HSM 3A has successfully performed fingerprint matching on the fingerprint information obtained from the IC card 2, it generates a key pair consisting of a private key and a public key (ST15). After generating the key pair, the HSM 3A securely stores (registers) the generated private key (ST16). After registering the private key, the HSM 3A transmits the public key to the IC card 2 (ST19).

[0041] On the other hand, when the processor 21 of the IC card 2 receives a notification that the fingerprint matching in the HSM 3A for the fingerprint read by the fingerprint sensor 20 has been successful, the processor 21 generates a key pair of a private key and a public key (ST17). After generating the key pair, the processor 21 stores (registers) the generated private key in a secure storage area in the data memory 24 (ST18). After storing the private key, the processor 21 transmits the public key corresponding to the stored private key to the HSM 3A (ST19).

[0042] In other words, after successful mutual authentication, the IC card 2 and HSM 3A each generate a key pair consisting of a private key and a public key if the fingerprint information acquired by the IC card 2 matches the fingerprint information stored in the HSM 3A. The IC card 2 and HSM 3A store the private keys they have generated and exchange the public keys corresponding to those private keys. The IC card 2 and HSM 3A can encrypt and verify data by using the key pairs they have each generated.

[0043] When HSM3A acquires the public key generated by IC card 2, it uses its private key to digitally sign the public key generated by IC card 2 and the URL of the repository of the holder of IC card 2 (ST20). When the public key with the digital signature and the URL are generated, HSM3A transmits the generated public key with the digital signature and the URL to IC card 2 (ST21).

[0044] The IC card 2 receives the public key with the digital signature generated by the HSM 3A and the URL via the communication interface 25. When the processor 21 of the IC card 2 receives the public key with the digital signature and the URL from the HSM 3A, it stores the public key with the digital signature by the HSM 3A and the URL in the data memory 24 (ST22). The processor 21 of the IC card 2 verifies the public key generated by the IC card 2 and digitally signed by the HSM 3A, thereby confirming that the URL (the URL of the holder's repository) received together with the public key generated by itself is correct.

[0045] Next, a process of providing the qualification information stored in the personal information server 4, which is a repository for the holder of the IC card 2 in the information management system according to the embodiment, and a process of registering the qualification information in the personal information server 4 will be described. FIG. 5 is a diagram schematically illustrating an example of a system configuration for providing information held by the personal information server 4 using an IC card 2 in an information management system according to an embodiment. In the configuration example shown in FIG. 5, the information management system includes an IC card 2, a personal information server 4, a service terminal 5, and the like.

[0046] As shown in Fig. 2, the IC card 2 has a configuration including a fingerprint sensor 20 as a biometric sensor. The IC card 2 shown in Fig. 5 is an example of an authentication device issued through an issuance procedure by a registration device 3. The IC card 2 is an authentication device that has a fingerprint authentication (fingerprint matching) function as biometric authentication to confirm that the holder is the person in question, and holds information indicating a personal information server 4 that is a repository for the holder.

[0047] The counter terminal 5 is an information processing device equipped with a card interface that communicates with the IC card 2 as an authentication device and a network interface that communicates with the personal information server 4 via a network. The counter terminal 5 has a function of mediating communication between the IC card 2 and the personal information server 4. The counter terminal 5 connects the IC card 2 presented by the user to the card interface and acquires information such as qualification information related to the holder of the IC card 2 held by the personal information server 4. For example, the counter terminal 5 acquires the qualification information of the holder of the IC card 2 held by the personal information server 4 and performs procedures for various services for that person based on the acquired qualification information. The counter terminal 5 may also perform procedures for registering (writing) information such as qualification information related to the holder of the IC card 2 to the personal information server 4. For example, the counter terminal 5 requests that the qualification information related to the holder of the IC card 2 be written to the personal information server 4, which is the repository for that person.

[0048] The personal information server 4 is a repository of the holder of the IC card 2. As described above, the personal information server 4 manages information (for example, personal information such as qualification information) relating to the holder of the IC card 2. In response to a request from a terminal device to which the IC card 2 is connected, the personal information server 4 provides the stored information on the holder of the IC card 2. In addition, in response to a request from the terminal device to which the IC card 2 is connected, the personal information server 4 registers (saves) new information such as qualification information as information on the holder of the IC card 2.

[0049] FIG. 6 is a block diagram showing an example of the configuration of the personal information server 4 in the information management system according to the embodiment. As shown in FIG. 6, the personal information server 4 includes a processor 41, a ROM 42, a RAM 43, a data memory 44, and a communication unit 45.

[0050] The processor 31 executes various processes by executing programs. The processor 31 is, for example, a CPU (Central Processing Unit). The processor 31 transmits and receives data to and from each part of the personal information server 4 via a system bus. The processor 41 cooperates with the ROM 42 and RAM 43 to execute operations such as control and data processing in the personal information server 4.

[0051] The ROM (Read Only Memory) 42 is a non-volatile memory that stores programs and control data for realizing the basic operations of the personal information server 4. The RAM (Random Access Memory) 43 is a volatile memory that temporarily stores data and functions as a working memory when the processor 41 executes a program.

[0052] The data memory 44 is a storage unit that stores various types of data. The data memory 44 is configured as a non-volatile memory that allows data to be rewritten. For example, the data memory 44 stores an OS program, application programs, operation setting information, and the like.

[0053] The communication unit 45 is a communication interface for communicating with an external device. The communication unit 45 may communicate wirelessly or may communicate via a wired connection. In this embodiment, the communication unit 45 communicates with the counter terminal 5 via a wide area network such as the Internet. The processor 41 executes secure communication with the IC card 2 via the counter terminal 5 using the communication unit 45.

[0054] Next, an information providing process for providing information held by the personal information server 4 using the IC card 2 in the information management system according to this embodiment will be described. 7 and 8 are sequences for explaining an example of the operation of the information providing process (reading process) for providing the service terminal 5 with the qualification information of the holder of the IC card 2 held by the personal information server 4. FIG. 7 and 8, it is assumed that the holder of IC card 2 presents the qualification information stored in personal information server 4, which is necessary to start a service, to counter terminal 5 operated by a clerk at the service provider's counter. As a specific example, it is assumed that when the holder of IC card 2 opens an account at a financial institution, the qualification information stored in personal information server 4, which is necessary to open the account, is presented to counter terminal 5 operated by a clerk at the financial institution.

[0055] In response to a request from the user, a clerk at the counter who accepts the service start procedure inputs an instruction to start the service start procedure into the operation unit (not shown) of the counter terminal 5, and causes the user to present the IC card 2, which serves as an authentication device, to an interface (not shown) for IC cards of the counter terminal 5. When the user presents the IC card 2 to the counter terminal 5, the counter terminal 5 supplies a fingerprint matching command to the IC card 2 (ST31).

[0056] The IC card 2 receives the fingerprint matching command from the counter terminal 5 via the communication interface 25. Upon receiving the fingerprint matching command, the processor 21 of the IC card 2 reads the fingerprint using the fingerprint sensor 20 and performs fingerprint matching to match the fingerprint read by the fingerprint sensor 20 with the fingerprint of the card holder stored in the memory area 24a (ST32).

[0057] When processor 21 of IC card 2 executes fingerprint matching in response to the fingerprint matching command, it transmits the fingerprint matching result to counter terminal 5. Here, it is assumed that fingerprint matching in IC card 2 is successful. When fingerprint matching is successful, processor 21 notifies counter terminal 5 that fingerprint matching was successful in response to the fingerprint matching command (ST33).

[0058] When the counter terminal 5 receives a notification from the IC card 2 that the fingerprint matching was successful, it displays that the fingerprint matching was successful on a display unit (not shown) of the counter terminal 5. This allows the staff member operating the counter terminal 5 to confirm that the person presenting the IC card 2 is the actual holder of the IC card 2. After confirming that the person is the actual holder of the IC card 2, the staff member uses the operation unit of the counter terminal 5 to instruct the IC card 2 to acquire information indicating the storage location (repository) of information relating to the holder of the IC card 2. In response to the operation instruction, the counter terminal 5 supplies a read command to the IC card 2 requesting the reading of information indicating the holder's repository (here, the URL of the repository) (ST34).

[0059] The IC card 2 receives a read command requesting the reading of the URL of the repository from the counter terminal 5 via the communication interface 25. Upon receiving the read command, the processor 21 of the IC card 2 reads the URL of the repository specified to be read by the command from the data memory 24. The processor 21 generates response data for the read command, which sets the URL of the repository read from the data memory 24, and transmits the generated response data to the counter terminal 5 (ST35).

[0060] When the counter terminal 5 receives the response data including the URL of the repository from the IC card 2, it accesses the URL of the repository obtained from the IC card 2. As a result, communication over the network begins between the personal information server 4, which is the repository of the holder of the IC card 2, and the counter terminal 5.

[0061] The processor 41 of the personal information server 4 receives access from the counter terminal 5 via the communication unit 45 and establishes a session with the counter terminal 5 (ST36). When the session with the counter terminal 5 is established, the processor 41 of the personal information server 4 receives terminal identification information that identifies the counter terminal 5 from the counter terminal 5 (ST37).

[0062] When the processor 41 of the personal information server 4 receives the terminal identification information of the counter terminal 5, it performs mutual authentication with the IC card 2 connected to the counter terminal 5 specified by the received terminal identification information (ST38). The personal information server 4 and the IC card 2 perform mutual authentication to authenticate each other by communicating via the network and the counter terminal 5. If the mutual authentication is successful, the processor 41 of the personal information server 4 and the processor 21 of the IC card 2 establish a secure channel via the counter terminal 5 (ST39).

[0063] When a secure channel with the IC card 2 is established, the processor 41 of the personal information server 4 acquires a public key ID indicating the public key of the counter terminal 5 from the counter terminal 5 (ST40). Upon acquiring the public key ID of the counter terminal 5, the processor 41 of the personal information server 4 acquires the public key of the counter terminal 5 indicated by the public key ID (ST41). Upon acquiring the public key of the counter terminal 5, the processor 41 of the personal information server 4 transmits a command to the IC card 2 requesting the generation of a key pair (ST42).

[0064] The IC card 2 receives a command requesting the generation of a key pair from the personal information server 4 through the communication interface 25 and the service terminal 5. When the command requesting the generation of a key pair from the personal information server 4 is received, the processor 21 of the IC card 2 generates a key pair of a private key and a public key (ST43). After generating the key pair, the processor 21 stores the generated private key and a public key ID indicating the public key in the data memory 24 (ST44).

[0065] Processor 21 stores at least the private key in a secure memory area in data memory 24. After storing the private key and the public key ID, processor 41 of IC card 2 transmits the public key and the public key ID to personal information server 4 by secure communication with personal information server 4 via counter terminal 5 (ST45).

[0066] The personal information server 4 receives the public key and public key ID from the IC card 2 via the counter terminal 5. The processor 41 of the personal information server 4 stores the public key received from the IC card 2 in the data memory 44 (ST46). After saving the public key of the IC card 2, the processor 41 of the personal information server 4 transmits the public key ID indicating the public key of the IC card 2 to the counter terminal 5 via the communication unit 45 over the network (ST47).

[0067] The counter terminal 5 acquires a public key ID indicating the public key of the IC card 2 from the personal information server 4 (ST48). This allows the counter terminal 5 to acquire the public key of the IC card 2 made public by the personal information server 4. In this state, the counter terminal 5 becomes able to acquire information about the holder of the IC card 2 managed by the personal information server 4.

[0068] That is, after acquiring the public key ID of the IC card, the counter terminal 5 identifies information (qualification information) that should be acquired as information about the person in order to start providing services such as opening an account to the holder of the IC card 2 (ST51). For example, the counter terminal 5 displays the qualification information to be acquired on the display unit. The counter clerk checks the qualification information to be acquired displayed on the display unit and issues an instruction to acquire the qualification information using the operation unit. When the qualification information to be acquired is identified, the counter terminal 5 transmits a read request including identification information (qualification information identifier) ​​indicating the qualification information to be acquired to the personal information server 4 (ST52).

[0069] The personal information server 4 receives a request to read the qualification information of the holder of the IC card 2 from the counter terminal 5 via the communication unit 45 (ST53). When the processor 41 of the personal information server 4 receives the request to read the qualification information from the counter terminal 5, it acquires the qualification information requested to be read (ST53).

[0070] The processor 41 of the personal information server 4 identifies the qualification information to be read by the qualification information identifier included in the read request, and reads the identified qualification information from the information about the holder of the IC card 2 stored in the data memory 44. After reading the requested qualification information, the processor 41 transmits the qualification information read from the data memory 44 to the IC card 2 with which a secure channel has been established (ST54).

[0071] The IC card 2 receives the qualification information of the holder of the IC card 2, which the personal information server 4 reads from the data memory 44 through secure communication with the personal information server 4. When the processor 21 of the IC card 2 receives the qualification information from the personal information server 4, it attaches an electronic signature to the received qualification information (ST55). Here, the processor 21 attaches an electronic signature to the qualification information received from the personal information server 4 using the private key stored in the data memory 24 in the above-mentioned ST44. After attaching the signature to the qualification information from the personal information server 4, the processor 21 transmits the signed qualification information with the attached electronic signature to the personal information server 4 (ST56).

[0072] The personal information server 4 receives the qualification information signed by the IC card 2 through secure communication with the IC card 2. When the processor 41 of the personal information server 4 receives the signed qualification information from the IC card 2, the processor 41 stores the received signed qualification information in the RAM 43 or the data memory 44.

[0073] The processor 41 of the personal information server 4 issues a one-time token while holding the qualification information signed by the IC card 2 (ST56). After issuing the one-time token, the processor 41 encrypts the one-time token by secure messaging with the IC card 2 and transmits it to the IC card 2 (ST57).

[0074] The IC card 2 receives the encrypted one-time token from the personal information server 4 via the counter terminal 5 using secure messaging. When the processor 21 of the IC card 2 receives the encrypted token using secure messaging from the personal information server 4, it decrypts the received data to obtain the one-time token (ST58). The processor 21 also checks the authenticator of the secure messaging from the personal information server (ST59).

[0075] The processor 21 of the IC card 2 confirms the authenticator of the secure messaging from the personal information server 4, and then supplies the token (one-time token) acquired from the personal information server 4 to the service terminal 5 (ST60).

[0076] The counter terminal 5 acquires the one-time token decrypted by the IC card 2 from the IC card 2 connected to the card interface. The counter terminal 5 transmits the one-time token acquired from the IC card 2 to the personal information server 4 (ST61). This one-time token is data issued, encrypted, and transmitted to the IC card 2 by the personal information server 4. The counter terminal 5 acquires the one-time token encrypted by the personal information server 4 after the IC card 2 decrypts it. Therefore, if the encryption by the personal information server 4 and the decryption by the IC card 2 are performed correctly, the one-time token transmitted by the counter terminal 5 to the personal information server 4 will match the one-time token originally generated by the personal information server 4.

[0077] The personal information server 4 transmits the one-time token encrypted by secure messaging to the IC card 2, and then receives the one-time token (one-time token challenge data) from the counter terminal 5. When the processor 41 of the personal information server 4 receives the one-time token from the counter terminal 5, it verifies whether the one-time token received from the counter terminal 5 matches the one-time token issued by the personal information server 4 and transmitted to the IC card 2 by secure messaging (ST62).

[0078] If the token received from the counter terminal 5 matches the one-time token issued by the processor 41 of the personal information server 4, the processor 41 stores historical information indicating that the qualification information will be provided to the counter terminal 5 in the data memory 44 (ST63), and transmits the signed qualification information signed by the IC card 2 stored in the RAM or the like to the counter terminal 5 (ST64).

[0079] The counter terminal 5 transmits the one-time token received from the IC card 2 to the personal information server 4, and then receives the signed qualification information signed by the IC card 2 from the personal information server 4. When the counter terminal 5 receives the signed qualification information by the IC card 2 from the personal information server 4, it acquires the public key of the IC card 2 using the public key ID acquired from the personal information server 4 in ST48. The counter terminal 5 acquires the qualification information of the holder of the IC card 2 by decrypting the qualification information signed by the IC card 2 using the public key of the IC card 2 (ST65).

[0080] According to the above process, by connecting the IC card held by the user to the counter terminal and performing fingerprint authentication, the information of the IC card holder stored in the personal information server can be provided to the counter terminal. As a result, the user can provide the counter terminal with information such as the user's qualification information stored in the personal information server by simply performing fingerprint authentication with the IC card, without performing any complicated operations, and the counter terminal can display the user's qualification information on its display.

[0081] Furthermore, according to the above-described embodiment, after the personal information server has confirmed that the IC card holder is the holder through fingerprint authentication, it transmits the qualification information of the IC card holder requested from the counter terminal to the IC card. The IC card transmits signed qualification information, which is obtained by digitally signing the qualification information received from the personal information server, to the personal information server. The personal information server provides the IC card-signed qualification information acquired from the IC card to the counter terminal. The counter terminal receives the IC card-signed qualification information from the personal information server and acquires the qualification information using the IC card's public key. In other words, the information management system according to the embodiment can provide the qualification information stored in the personal information server to the counter terminal after digitally signing it with an IC card that has been used to verify the identity of the holder through biometric authentication, and can securely provide the qualification information stored in the personal information server to the counter terminal.

[0082] Furthermore, according to the above-described embodiment, the personal information server issues a one-time token and transmits the issued one-time token to the IC card via secure messaging. The IC card decrypts the one-time token received from the personal information server via secure messaging and transmits the decrypted one-time token to the counter terminal. The counter terminal transmits the one-time token decrypted by the IC card to the personal information server. If the one-time token received from the counter terminal is correct, the personal information server provides information about the IC card holder to the counter terminal. This makes it possible to provide information stored by the personal information server to the counter terminal after confirming that the one-time token transmitted by the counter terminal is a legitimate one-time token obtained via an IC card whose identity has been verified by biometric authentication.

[0083] Next, an information providing process for providing information held by the personal information server 4 using the IC card 2 in the information management system according to this embodiment will be described. FIG. 9 is a sequence diagram for explaining an example of the operation of a storage process in which the qualification information from the counter terminal 5 is stored as the qualification information of the holder of the IC card 2 held by the personal information server 4. In FIG. 9 assumes a process of registering (writing) new information about the holder of the IC card 2 in the personal information server 4 using the counter terminal 5. As a specific example, a process of registering newly acquired qualification information by the holder of the IC card 2 in the personal information server 4, which serves as a repository for the holder of the IC card 2, using the counter terminal 5 is assumed.

[0084] The process shown in Fig. 9 is executed after the process shown in Fig. 7 described above. That is, the IC card 2 held by the user who registers qualification information in the personal information server 4 is connected to the counter terminal 5. The counter terminal 5 and the IC card 2 execute the same processes as ST31 to 35 shown in Fig. 7. As a result, the counter terminal 5 confirms that the IC card 2 is held by the actual person through fingerprint matching, and then acquires the URL of the repository of the holder.

[0085] The counter terminal 5 and the personal information server 4 indicated by the repository URL establish a communication session through processing similar to ST36 shown in Figure 7, and the personal information server 4 obtains terminal identification information of the counter terminal 5 through processing similar to ST36 shown in Figure 7.

[0086] Furthermore, the IC card 2 and the personal information server 4 establish a secure channel by performing mutual authentication using the same process as ST38-37 shown in Fig. 7. This enables the IC card 2 and the personal information server 4 to execute secure messaging, which allows them to send and receive data that cannot be deciphered by external devices including the counter terminal 5.

[0087] Furthermore, the personal information server 4 acquires the public key of the service terminal 5 by the same process as in ST40-41 shown in FIG. 7, the IC card 2, which has established a secure channel with the personal information server 4, generates a key pair in response to a request from the personal information server 4 and stores the private key. The public key of the IC card 2 is registered in the personal information server 4 and the counter terminal 5.

[0088] After acquiring the public key of the IC card 2, the counter terminal 5 is specified (ST71) with the qualification information (information to be written) to be registered (stored) in the personal information server 4, which is the repository of the holder of the IC card 2. Here, it is assumed that the counter terminal 5 is in a state where it holds the new qualification information of the holder of the IC card 2 to be registered in the personal information server 4.

[0089] For example, the counter terminal 5 displays on a display unit the qualification information to be registered (stored) in the personal information server 4, which is the repository of the holder of the IC card 2. The counter clerk checks the qualification information to be registered in the repository displayed on the display unit and instructs the operation unit to save the qualification information. When the qualification information to be registered in the repository is specified, the counter terminal 5 transmits a request to write the qualification information to be registered (write information) to the personal information server 4 (ST72).

[0090] The personal information server 4 receives a request to write qualification information as information relating to the holder of the IC card 2 from the counter terminal 5 via the communication unit 45. When the processor 41 of the personal information server 4 receives the request to write qualification information from the counter terminal 5, it issues a one-time token (ST73). After issuing the one-time token, the processor 41 encrypts the one-time token using secure messaging with the IC card 2 and transmits it to the IC card 2 (ST74).

[0091] The IC card 2 receives the encrypted one-time token by secure messaging from the personal information server 4. When the processor 21 of the IC card 2 receives data including the one-time token encrypted by secure messaging from the personal information server 4, it decrypts the encrypted one-time token included in the received data (ST75). The processor 21 also checks the authenticator of the secure messaging from the personal information server 4 (ST76).

[0092] After verifying the authenticator of the secure messaging from the personal information server 4, the processor 21 of the IC card 2 supplies the decrypted one-time token included in the data received from the personal information server 4 to the service terminal 5 (ST77).

[0093] The counter terminal 5 receives the one-time token decrypted by the IC card 2 from the IC card 2 connected to the card interface. When the counter terminal 5 receives the one-time token from the IC card 2, it attaches a signature to the qualification information to be registered (stored) in the personal information server 4, which serves as a repository, as information about the holder of the IC card 2 (ST78). The counter terminal 5 holds a private key corresponding to the public key notified to the personal information server 4, and uses the private key to attach an electronic signature to the qualification information to be stored in the personal information server 4.

[0094] When the counter terminal 5 electronically signs the qualification information to be registered using its own private key, it sends the one-time token (one-time token challenge data) obtained from the IC card 2, a qualification information identifier that identifies the qualification information, and data including the signed qualification information to the personal information server 4 (ST79).

[0095] After transmitting the one-time token to the IC card 2 by secure messaging, the personal information server 4 receives data including the one-time token, signature information identifier, and signed qualification information from the counter terminal 5. When the processor 41 of the personal information server 4 receives the data including the one-time token from the counter terminal 5, it verifies whether the one-time token received from the counter terminal 5 matches the one-time token issued by the personal information server 4 itself and transmitted to the IC card 2 by secure messaging (ST80).

[0096] If the one-time token received from the counter terminal 5 matches the one-time token issued by the processor 41 of the personal information server 4, the processor 41 stores in the data memory 44 history information indicating that the credential information requested to be registered by the counter terminal 5 is to be written (ST81). The processor 41 decrypts the signed credential information received from the counter terminal 5 with the public key of the counter terminal 5, and writes it to the data memory 44 as the credential information of the holder of the IC card 2 (ST82). After writing the credential information (written information), the processor 41 notifies the counter terminal 5 that the credential information requested to be registered has been successfully written (ST83).

[0097] According to the above process, by connecting the IC card possessed by the user to the counter terminal and performing fingerprint authentication, the counter terminal can write new information about the IC card holder to the personal information server. As a result, the user can save information such as the user's new qualification information displayed on the display unit of the counter terminal to the personal information server simply by performing fingerprint authentication with the IC card without performing any complicated operations.

[0098] Furthermore, according to the above-described embodiment, after confirming that the person is the holder of the IC card through fingerprint authentication, the counter terminal requests the personal information server indicated by the repository URL obtained from the IC card to write new credential information (write information) for the IC card holder. The counter terminal digitally signs the credential information to be registered in the personal information server using its own private key, and transmits the digitally signed and signed credential information to the personal information server. The personal information server writes credential information based on the signed credential information received from the counter terminal using the counter terminal's public key as information about the IC card holder. As a result, the information management system according to the embodiment can safely supply information such as new credential information to be stored as information about the IC card holder by the counter terminal connected to the IC card whose identity has been confirmed through biometric authentication to the personal information server, and can safely store the information in the personal information server.

[0099] Furthermore, according to the above-described embodiment, the personal information server, upon receiving an information writing request from the counter terminal, issues a one-time token and transmits the issued one-time token to the IC card via secure messaging. The IC card decrypts the one-time token received from the personal information server via secure messaging and transmits the decrypted one-time token to the counter terminal. The counter terminal transmits the one-time token from the IC card and the qualification information to be registered (writing information) to the personal information server. If the one-time token received from the counter terminal is correct, the personal information server writes the qualification information requested by the counter terminal to be written as information about the holder of the IC card. In this way, the personal information server can verify that the one-time token from the counter terminal is a legitimate one-time token obtained via an IC card that has been identified by biometric authentication, and then write and store the writing information requested by the counter terminal to the personal information server.

[0100] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. The following additionally describes the contents of the claims as originally filed in this application. [1] An information management system having an authentication device and a personal information server, The authentication device a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with the terminal device; a data memory for storing personal information of the owner of the authentication device; and a second processor that supplies personal information of the owner of the authentication device stored in the data memory to the terminal device in response to a request from the terminal device to which the authentication device is connected. Information management system. [2] the second processor of the personal information server issues a one-time token, and if data received from the terminal device after transmitting the one-time token to the authentication device by secure messaging matches the issued one-time token, transmits the personal information to the terminal device; the first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; [1] The information management system described in [1]. [3] the first processor of the authentication device digitally signs the personal information of the holder received from the personal information server, and transmits the signed personal information to the personal information server; The second processor of the personal information server discloses the public key of the authentication device obtained from the authentication device to the terminal device, and transmits the personal information of the owner of the authentication device stored in the data memory to the authentication device in response to a request from the terminal device, and then supplies the signed personal information electronically signed by the authentication device to the terminal device. [1] The information management system described in [1]. [4] the first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; the second processor of the personal information server issues the one-time token, transmits the one-time token to the authentication device by secure messaging, and then transmits the signed personal information to the terminal device if challenge data of the one-time token received from the terminal device matches the issued one-time token; [3] The information management system described in [3]. [5] The authentication device has a card-shaped main body, the sensor of the authentication device is a fingerprint sensor that reads a fingerprint as biometric information, and the first processor of the authentication device outputs information indicating the location of the personal information server to the terminal device when fingerprint matching between the fingerprint information acquired by the fingerprint sensor and the fingerprint information stored in the memory is successful. An information management system according to any one of [1] to [4]. [6] a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a terminal device; a processor that outputs to the terminal device information indicating the location of a personal information server that stores personal information of the holder when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; An authentication device having: [7] a communication unit that communicates with a terminal device to which an authentication device that performs biometric matching between biometric information acquired by the sensor and biometric information of a registered owner is connected; a data memory for storing personal information of the owner of the authentication device; a processor that, when biometric matching of the owner of the authentication device connected to the terminal device is successful, supplies personal information of the owner of the authentication device stored in the data memory to the terminal device in response to a request from the terminal device; A personal information server having: [8] An information management system having an authentication device and a personal information server, The authentication device a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with the terminal device; a data memory for storing personal information of the owner of the authentication device; a second processor that writes writing information supplied from the terminal device to which the authentication device is connected in response to a writing request from the terminal device into the data memory as personal information of the owner of the authentication device, Information management system. [9] the first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; the second processor of the personal information server issues the one-time token, transmits the one-time token to the authentication device by secure messaging, and then, if challenge data of the one-time token received from the terminal device matches the issued one-time token, writes the write information from the terminal device to the data memory; [8] The information management system described in [8].

[10] the second processor of the personal information server acquires signed written information that the terminal device has digitally signed on the written information, verifies the signed written information using a public key of the terminal device, and then writes the written information to the data memory. [8] The information management system described in [8].

[11] the first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; the second processor of the personal information server issues the one-time token, transmits the one-time token to the authentication device by secure messaging, and then, if challenge data of the one-time token received from the terminal device matches the issued one-time token, verifies the signed write information from the terminal device using the public key of the terminal device and then writes the write information to the data memory;

[10] The information management system described in

[10] .

[12] The authentication device has a card-shaped main body, the sensor of the authentication device is a fingerprint sensor that reads a fingerprint as biometric information, and the first processor of the authentication device outputs information indicating the location of the personal information server to the terminal device when fingerprint matching between the fingerprint information acquired by the fingerprint sensor and the fingerprint information stored in the memory is successful. [8] to

[11] . An information management system according to any one of [8] to

[11] .

[13] a communication unit that communicates with a terminal device to which an authentication device that performs biometric matching between biometric information acquired by the sensor and biometric information of a registered owner is connected; a data memory for storing personal information of the owner of the authentication device; A personal information server having: a processor that writes writing information supplied from the terminal device in response to a writing request from the terminal device into the data memory as personal information of the owner of the authentication device when biometric matching of the owner is successful in the authentication device connected to the terminal device. [Explanation of symbols]

[0101] 2...IC card (authentication device), 4...personal information server, 5...counter terminal (terminal device), 20...fingerprint sensor (sensor, biometric sensor), 21...processor (first processor), 24...data memory, 24a...storage area (memory), 25...communication interface, 41...processor (second processor), 44...data memory, 45...communication unit, C...main body.

Claims

1. An information management system having an IC card and a personal information server that manages information for each individual in a distributed manner, The IC card is a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a card reader / writer included in the terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with a network interface included in the terminal device; a data memory for storing personal information of the holder of the IC card; a second processor that supplies the personal information of the holder of the IC card stored in the data memory to the terminal device in response to a request from the terminal device to which the IC card is connected, Information management system.

2. An information management system having an authentication device and a personal information server, The authentication device a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with the terminal device; a data memory for storing personal information of the owner of the authentication device; a second processor that supplies personal information of the owner of the authentication device stored in the data memory to the terminal device in response to a request from the terminal device to which the authentication device is connected, the second processor of the personal information server issues a one-time token, and if data received from the terminal device after transmitting the one-time token to the authentication device by secure messaging matches the issued one-time token, transmits the personal information to the terminal device; the first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; Information management system.

3. An information management system having an authentication device and a personal information server, The authentication device a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with the terminal device; a data memory for storing personal information of the owner of the authentication device; a second processor that supplies personal information of the owner of the authentication device stored in the data memory to the terminal device in response to a request from the terminal device to which the authentication device is connected, the first processor of the authentication device digitally signs the personal information of the holder received from the personal information server, and transmits the signed personal information to the personal information server; The second processor of the personal information server discloses the public key of the authentication device obtained from the authentication device to the terminal device, and transmits the personal information of the owner of the authentication device stored in the data memory to the authentication device in response to a request from the terminal device, and then supplies the signed personal information electronically signed by the authentication device to the terminal device. Information management system.

4. The first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; the second processor of the personal information server issues the one-time token, transmits the one-time token to the authentication device by secure messaging, and then transmits the signed personal information to the terminal device if challenge data of the one-time token received from the terminal device matches the issued one-time token; The information management system according to claim 3 .

5. the sensor is a fingerprint sensor that reads a fingerprint as biometric information, the first processor outputs information indicating the location of the personal information server to the terminal device when fingerprint matching between the fingerprint information acquired by the fingerprint sensor and the fingerprint information stored in the memory is successful; 5. The information management system according to claim 1.

6. A personal information server that manages information for each individual in a distributed manner, a communication unit that communicates with a card reader / writer included in a terminal device to which an IC card is connected, the IC card performing biometric matching between the biometric information acquired by the sensor and the biometric information of a registered holder; a data memory for storing personal information of the holder of the IC card; a processor that supplies personal information of the holder of the IC card stored in the data memory to the terminal device in response to a request from the terminal device when biometric matching of the holder of the IC card connected to the terminal device is successful; A personal information server having:

7. An information management system having an IC card and a personal information server that manages information for each individual in a distributed manner, The IC card is a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a card reader / writer included in the terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with a network interface included in the terminal device; a data memory for storing personal information of the holder of the IC card; a second processor that writes write information supplied from the terminal device to which the IC card is connected in response to a write request from the terminal device into the data memory as personal information of the holder of the IC card, Information management system.

8. An information management system having an authentication device and a personal information server, The authentication device a sensor for acquiring biometric information of a person; a memory for storing biometric information of the holder; an interface for connecting to a terminal device; a first processor that outputs information indicating a location of the personal information server to the terminal device when biometric information acquired by the sensor and biometric information stored in the memory are successfully matched; The personal information server a communication unit that communicates with the terminal device; a data memory for storing personal information of the owner of the authentication device; a second processor that writes writing information supplied from the terminal device to which the authentication device is connected in response to a writing request from the terminal device into the data memory as personal information of the owner of the authentication device, The first processor of the authentication device transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; the second processor of the personal information server issues the one-time token, transmits the one-time token to the authentication device by secure messaging, and then, if challenge data of the one-time token received from the terminal device matches the issued one-time token, writes the write information from the terminal device to the data memory; Information management system.

9. the second processor of the personal information server acquires signed written information that the terminal device has digitally signed on the written information, verifies the signed written information using a public key of the terminal device, and then writes the written information to the data memory; The information management system according to claim 7.

10. the first processor of the IC card transmits to the terminal device a one-time token issued by the personal information server, the one-time token being obtained by decrypting data received from the personal information server via secure messaging; the second processor of the personal information server issues the one-time token, transmits the one-time token to the IC card by secure messaging, and then, if challenge data of the one-time token received from the terminal device matches the issued one-time token, verifies the signed write information from the terminal device using the public key of the terminal device and then writes the write information to the data memory; The information management system according to claim 9.

11. the sensor is a fingerprint sensor that reads a fingerprint as biometric information, the first processor outputs information indicating the location of the personal information server to the terminal device when fingerprint matching between the fingerprint information acquired by the fingerprint sensor and the fingerprint information stored in the memory is successful; 11. The information management system according to claim 7.

12. A personal information server that manages information for each individual in a distributed manner, a communication unit that communicates with a terminal device that includes a card reader / writer to which an IC card is connected, the IC card performing biometric matching between the biometric information acquired by the sensor and the biometric information of a registered owner; a data memory for storing personal information of the holder of the IC card; a processor that writes write information supplied from the terminal device in response to a write request from the terminal device into the data memory as personal information of the holder of the IC card when biometric matching of the holder of the IC card connected to the terminal device is successful; A personal information server having:

Citation Information

Patent Citations

  • System, device, and method for authentication

    JP2001312477A

  • Fingerprint authenticating device and authenticating system

    JP2003085149A

  • IC card system

    JP2005122402A

  • Information processing device and method, and program

    WO2013054747A1