Information processing device, system, and control method and program for information processing device

The information processing device and system automate certificate re-provisioning with user consent, addressing the burden of frequent re-registration by integrating a storage and control unit to manage certificates, enhancing user experience in online services.

JP7776051B1Active Publication Date: 2025-11-26NEC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025551607
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-11-26
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

Existing technologies require users to frequently re-register and update certificates and documents to maintain online services, placing a burden on users.

Method used

An information processing device and system that automatically re-provisions certificates when user consent is given, reducing the need for manual re-submission by integrating a storage unit and control unit to manage and provide certificates to service providers.

Benefits of technology

Reduces the burden on users by automating the re-provisioning of certificates, thereby simplifying the maintenance of online services and enhancing user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007776051000001
    Figure 0007776051000001
  • Figure 0007776051000002
    Figure 0007776051000002
  • Figure 0007776051000003
    Figure 0007776051000003
Patent Text Reader

Abstract

An information processing device that contributes to reducing the burden on users receiving services is provided. The information processing device includes a storage means and a control means. The storage means stores at least one certificate issued to the user. When a request is made for the re-submission of a certificate of the same type as a certificate provided to a service provider, among the at least one certificate, the control means provides the requested re-submission certificate to the business requesting the re-submission of the certificate, if the user agrees to the re-submission of a certificate of the same type as the certificate provided to the service provider.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, a system, a control method for an information processing device, and a storage medium. [Background technology]

[0002] There are technologies related to the utilization of credentials (VCs; Verifiable Credentials).

[0003] For example, the communication terminal of Patent Document 1 includes a VC storage unit, a VC transmission unit, and a VC reception unit. The VC storage unit stores a VC (Verifiable Credential) related to a user. The VC transmission unit transmits a VC to a service backend that provides a service used by the user based on an instruction from the user. The VC reception unit receives a VC from the service backend that proves the user's use of the service. The VC transmission unit transmits the VC to a service backend that is different from the service backend that transmitted the VC received by the VC reception unit. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 7454031 Summary of the Invention [Problem to be solved by the invention]

[0005] Advances in communication technology and information processing technology have enabled a variety of services to be provided online. These online services require users to update their registration information at regular intervals in order to continue providing appropriate services. In response to these requests, users must re-register and update certificates and other documents that prove their identity and qualifications. However, responding to these requests for continued service places a burden on users.

[0006] Note that Patent Document 1 merely discloses transmitting a VC received from a service backend to another service backend. Therefore, even if the technology disclosed in Patent Document 1 is applied, the above problem cannot be solved.

[0007] A primary object of the present invention is to provide an information processing device, a system, a control method for an information processing device, and a storage medium that contribute to reducing the burden on users receiving services. [Means for solving the problem]

[0008] According to a first aspect of the present invention, there is provided an information processing device comprising: a storage means for storing at least one certificate issued to a user; and a control means for, when a user is requested to re-submit a certificate of the same type as a certificate provided to a service provider, providing the requested certificate to a business requesting the re-submission of the certificate if the user agrees to the re-submission of a certificate of the same type as the certificate provided to the service provider.

[0009] According to a second aspect of the present invention, there is provided a system including a terminal carried by a user, a service server that provides a service to the user, and a wallet server that realizes a web wallet that stores at least one certificate issued to the user, wherein the service server requests the user to provide a first certificate necessary for providing the service, the terminal obtains consent from the user to provide the first certificate requested to the service server, and when the user agrees to a second certificate of the same type as the first certificate requested to be automatically re-provisioned to the service server, sets information in the wallet server to realize the automatic re-provision of the second certificate, the service server requests the wallet server to re-provision the second certificate, and the wallet server provides the second certificate to the service server based on the set information.

[0010] According to a third aspect of the present invention, there is provided a control method for an information processing device that stores at least one certificate issued to a user, and when a request is made to re-submit a certificate of the same type as a certificate provided to a service provider, if the user agrees to the re-submission of a certificate of the same type as the certificate provided to the service provider, provides the certificate requested to be re-submitted to a business requesting the re-submission of the certificate.

[0011] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium for storing a program for causing a computer to execute the following processes: storing at least one certificate issued to a user; and, when a request is made for the re-submission of a certificate of the same type as the certificate provided to the service provider, providing the requested certificate to a business requesting the re-submission of the certificate, if the user agrees to the re-submission of a certificate of the same type as the certificate provided to the service provider. [Effects of the Invention]

[0012] According to each aspect of the present invention, an information processing device, a system, a control method for an information processing device, and a storage medium are provided that contribute to reducing the burden on users receiving services. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram for explaining an outline of an embodiment. [Figure 2] FIG. 2 is a flowchart illustrating the operation of one embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 4] FIG. 4 is a diagram illustrating an example of a display on a terminal according to an embodiment of the present disclosure. [Figure 5]FIG. 5 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 7] FIG. 7 is a diagram illustrating an example of a display on a terminal according to an embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram for explaining the operation of the information processing system according to the embodiment of the present disclosure. [Figure 9] FIG. 9 is a diagram illustrating an example of a processing configuration of a terminal according to an embodiment of the present disclosure. [Figure 10] FIG. 10 is a flowchart illustrating an example of the operation of the acquisition control unit according to an embodiment of the present disclosure. [Figure 11] FIG. 11 is a flowchart illustrating an example of the operation of the usage control unit according to an embodiment of the present disclosure. [Figure 12] FIG. 12 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. [Figure 13] FIG. 13 is a diagram illustrating an example of a processing configuration of a service server according to an embodiment of the present disclosure. [Figure 14] FIG. 14 is a diagram illustrating an example of a customer management database according to an embodiment of the present disclosure. [Figure 15] FIG. 15 is a diagram illustrating an example of a processing configuration of a wallet server according to an embodiment of the present disclosure. [Figure 16] FIG. 16 is a diagram illustrating an example of a user management database according to an embodiment of the present disclosure. [Figure 17] FIG. 17 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 18] FIG. 18 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 19] FIG. 19 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure. [Figure 20]FIG. 20 is a diagram illustrating an example of a display on a terminal according to a modified example of the embodiment of the present disclosure. [Figure 21] FIG. 21 is a diagram illustrating an example of a hardware configuration of a terminal according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0014] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.

[0015] An information processing device 100 according to one embodiment includes a storage unit 101 and a control unit 102 (see FIG. 1). The storage unit 101 stores at least one certificate issued to a user (step S1 in FIG. 2). When a user is requested to resubmit a certificate of the same type as the certificate provided to the service provider, among the at least one certificate, the control unit 102 provides the requested certificate to the business requesting the resubmission of the certificate, if the user agrees to the resubmission of a certificate of the same type as the certificate provided to the service provider (step S2).

[0016] If the user agrees to the re-provision of a certificate of the same type as the certificate provided to the service provider, the information processing device 100 automatically re-provisions that certificate. In other words, if the user agrees to the re-provision of a certificate that they agreed to provide to the service provider, that certificate will be automatically provided to the service provider. This reduces the burden on the user receiving the service.

[0017] Specific embodiments will be described in more detail below with reference to the drawings.

[0018] [First embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0019] [System Configuration] As shown in FIG. 3, the information processing system according to the first embodiment includes at least one certificate issuer, at least one service provider, and at least one wallet operator.

[0020] A certificate issuer is an entity that issues certificates to users. For example, a certificate issuer may issue a certificate that certifies the "identity" or "attributes" of a user. For example, a certificate issuer may issue an identification card that certifies the user's name, gender, date of birth, address, etc. Or, a certificate issuer may issue a certificate that certifies the user's "rights" or "qualifications."

[0021] For example, a public institution that issues identification documents such as driver's licenses, passports, and My Number cards corresponds to a certificate issuer. Alternatively, a university or company that issues graduation certificates or employment certificates corresponds to a certificate issuer. Alternatively, an organization that issues certificates related to technology, language, etc. corresponds to a certificate issuer.

[0022] Each certificate issuer is equipped with a server device 10. The server device 10 is a server that performs the processes and operations necessary to carry out the business of the certificate issuer. The server device 10 may be managed and operated by the certificate issuer, or may be outsourced to another business entity. The server device 10 may be installed within the certificate issuer's premises, or may be installed on a network (cloud).

[0023] A service provider is a business that provides services to users. Service providers are not limited to private companies, and public institutions such as city halls are also included in the service providers disclosed in this application.

[0024] Depending on the type and business model of the service provider, the same business may operate both as a certificate issuer and as a service provider.

[0025] The service provider includes a service server 20 for providing services to users. For example, the service server 20 provides services to users via a website.

[0026] A wallet provider is a business that provides web wallet services to users. The wallet provider has a wallet server 30 for providing the web wallet services to users. The wallet server 30 realizes a web wallet that stores at least one certificate (electronic certificate) issued to a user.

[0027] A user carries terminal 40. For example, the user operates terminal 40 to request (demand) the issuance of a certificate from a certificate issuer. The user also uses terminal 40 to provide the service provider with information, etc., that the service provider requests.

[0028] 3 are connected to a network. Specifically, the server device 10, the service server 20, the wallet server 30, and the terminal 40 are connected to the network by wired or wireless communication means.

[0029] The configuration of the information processing system shown in Fig. 3 is an example and is not intended to be limiting. For example, the server device 10 of each certificate issuer, the service server 20 of the service provider, and the wallet server 30 of the wallet operator may belong to different networks. Alternatively, each certificate issuer may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10. Similarly, each service provider may include multiple service servers 20, and the wallet operator may include multiple wallet servers 30.

[0030] [General operation] Next, the general operation of the information processing system according to the first embodiment will be described.

[0031] <Preparing your digital wallet> Users use digital wallets, which are electronic information storage services that guarantee information security, including data integrity, reliability, and availability.

[0032] A user uses an online wallet service (web wallet). The user operates a terminal 40 to access a wallet server 30 of a wallet operator. The user creates an account on the wallet server 30.

[0033] The wallet server 30 generates a pair of public and private keys to be used by a user who has created an account. Furthermore, the wallet server 30 generates a decentralized identifier (DID) corresponding to the public key and private key, and assigns a wallet address to the user. The wallet server 30 stores the public key, private key, user DID, and wallet address in the account.

[0034] A user who has created an account on the wallet server 30 can access the web wallet from a web browser or dedicated application installed on the terminal 40.

[0035] By opening a digital wallet (web wallet), users can store various digital content in that digital wallet, such as identification documents such as My Number cards and student ID cards, tickets such as airline tickets and concert tickets, and credit cards. Users access the online digital wallet using a web browser or similar to store and retrieve digital content.

[0036] <Acquisition of digital content> A user who opens a digital wallet acquires digital content to be stored in the digital wallet.

[0037] A user operates terminal 40 to request a certificate issuer to issue a certificate. Specifically, terminal 40 requests the certificate issuer to issue a certificate. The certificate issuer issues VCs (Verifiable Credentials), whose contents can be verified online, as the certificate. In the following explanation, VCs will be referred to as "credential certificate."

[0038] Furthermore, specific certificates issued as credential certificates are indicated by adding "VCs" after the name of the certificate. For example, a My Number Card issued as a credential certificate is indicated as a "My Number Card VCs."

[0039] By obtaining a credential certificate from each certificate issuer, the user's digital wallet stores digital content such as that shown in Figure 4. In the following explanation, unless otherwise specified, the content stored in the digital wallet is a credential certificate.

[0040] <Getting Credentials> First, the acquisition of credentials will be described.

[0041] The terminal 40 registers the DID (user DID; holder DID) and public key generated by the wallet server 30 in the blockchain (step S01 in FIG. 5). The terminal 40 accesses the wallet server 30 and obtains the user DID, public key, private key, and wallet address generated by the wallet server 30. The terminal 40 registers the obtained user DID and public key in the blockchain.

[0042] Furthermore, the user's terminal 40, while presenting the user DID, requests the certificate issuer (server device 10) to issue a credential certificate. Specifically, the terminal 40 transmits a "certificate issuance request" to the server device 10, which includes information about the certificate to be issued (for example, the type of credential certificate), information specifying the subject to be certified by the credential certificate, the user DID, etc. (step S02).

[0043] The server device 10 generates and stores in advance the DID of the issuer (issuer DID), the private key, and the public key.

[0044] Upon receiving the certificate issuance request, the certificate issuer determines whether or not it is possible to issue the credential certificate desired by the user.

[0045] If the credential certificate desired by the user can be issued, the server device 10 generates a credential certificate including the issuer DID and the user DID.

[0046] Specifically, the server device 10 generates a credential certificate including metadata including the type of credential certificate, the name of the issuing organization, the date and time of issue, the validity period, etc., the assertion (qualification information, claim), and proofs such as the issuer's public key information and electronic signature, etc. The assertion describes specific information to be certified by the issuer.

[0047] The server device 10 provides the generated credential certificate to the terminal 40 of the user (the user who will become the certificate holder; the person requesting the issuance of the certificate) (step S03).

[0048] Specifically, the server device 10 stores the generated credential certificate in online storage. The server device 10 generates a certificate acquisition URL from the URL (Uniform Resource Locator) of the storage destination of the credential certificate. The server device 10 transmits an affirmative response (response to the certificate issuance request) including the generated certificate acquisition URL to the terminal 40.

[0049] Furthermore, the server device 10 registers the issuer DID and the generated public key, etc. in the blockchain (step S04). Alternatively, the server device 10 may register the status (valid, invalid) of the issued credential certificate, a credential ID that uniquely identifies the credential certificate, the issuer DID, etc. in a VDR (Verifiable Data Registry).

[0050] The terminal 40 accesses the certificate acquisition URL included in the positive response and acquires the credential certificate. The terminal 40 stores the acquired credential certificate in the digital wallet. The terminal 40 sends the acquired credential certificate to the wallet server 30, and stores the credential certificate in the digital wallet.

[0051] For example, a user may request the issuance of a graduation certificate VC from the university from which the user graduated. Alternatively, the user may request the issuance of an employment certificate VC from the company where the user works. Alternatively, a user who holds a credit card may request the issuance of a credit card VC from the credit card company. The terminal 40 stores the acquired certificate VC in a digital wallet.

[0052] <Enjoying the service> A user creates an account with a service provider from which the user wishes to receive services. Here, the operation of the information processing system will be explained using the example of a case where a user creates an account with an EC (Electronic Commerce) commerce company for online shopping.

[0053] A user operates a terminal 40 to access a service server 20 of an e-commerce business operator. The user registers information such as name, gender, date of birth, address, login information (ID, password), telephone number, and email address in the service server 20. The service server 20 generates a user ID for the user and stores the generated user ID in association with the name, gender, etc. (creates an account).

[0054] When an account is created, the service server 20 acquires information required to provide services to the user. For example, the service server 20 acquires a credit card VCs required for payment of product prices and the like.

[0055] Specifically, the service server 20 transmits an "information request" to the terminal 40 possessed by the user (step S11 in FIG. 6). The information request includes the type of credential certificate and the business code required for the e-commerce business to provide the service.

[0056] The business code is an ID for identifying a service provider (business) participating in the information processing system. For example, the business code may be a MAC (Media Access Control) address or an IP (Internet Protocol) address of the service server 20.

[0057] For example, the information request includes the type of credential the user is asked to provide, such as "credit card VCs," and the business code of the e-commerce business.

[0058] When receiving the information request, the terminal 40 obtains the credential certificate corresponding to the type of credential certificate included in the request from the digital wallet. For example, the terminal 40 obtains the credit card VCs from the wallet server 30.

[0059] When the terminal 40 is able to acquire the credential certificate designated by the service provider from the digital wallet, the terminal 40 acquires consent from the user to provide the acquired credential certificate to the service provider.

[0060] Furthermore, if the user agrees to the provision of the credential certificate, when the same service provider requests the terminal 40 to provide a credential certificate of the same type as the credential certificate provided above, the terminal 40 obtains consent to provide the requested credential certificate from among the credential certificates stored in the digital wallet without obtaining the user's permission.

[0061] For example, when the service provider requests the terminal 40 to re-issue credit card VCs, the terminal 40 obtains consent to provide the service provider with the credit card VCs stored in the digital wallet (credit card VCs with updated expiration dates, etc.) without the user's consent. For example, the terminal 40 obtains consent to the automatic provision of the credential certificate by using a GUI (Graphical User Interface) as shown in FIG.

[0062] The terminal 40 transmits a response to the information provision request to the service server 20 (step S12 in FIG. 6).

[0063] If the credential certificate specified by the service provider is not stored in the digital wallet or if the user refuses to provide the credential certificate, the terminal 40 sends a negative response to the service server 20 indicating that the credential certificate cannot be provided.

[0064] When the user agrees to provide the credential certificate designated by the service provider, the terminal 40 signs the acquired credential certificate. Specifically, the terminal 40 signs the credential certificate to be provided to the service provider using a private key corresponding to the user DID. In the above example, the terminal 40 signs the credit card VCs.

[0065] If the user agrees to provide the credentials, the terminal 40 presents the credentials and the user DID to the service server 20 as verifiable presentations (VPs).

[0066] Here, the terminal 40 sets different data in the affirmative response (response indicating that the credential can be provided) to be sent to the service server 20 depending on whether the user has consented to the automatic provision of the credential.

[0067] Specifically, if the user refuses the automatic provision of the credentials, the terminal 40 sends an affirmative response to the service server 20, which includes the signed credentials and the user DID.

[0068] If the user agrees to the automatic provision of the credential certificate, the terminal 40 sends an affirmative response to the service server 20, including the signed credential certificate, the user DID and the wallet address.

[0069] In this way, the terminal 40 notifies the service server 20 whether or not the user has consented to the automatic provision of the credential certificate, depending on whether or not the wallet address is present.

[0070] The service server 20 receives a response (positive response, negative response) to the information request.

[0071] If a negative response is received, the service server 20 notifies the user that the service cannot be provided because the necessary information cannot be acquired, for example.

[0072] If an affirmative response is received, the service server 20 verifies the credential certificate included in the affirmative response. At this time, the service server 20 obtains the public key from the blockchain. Details regarding credential certificate verification will be described later.

[0073] If the credential verification is successful, the service server 20 provides the service to the user. For example, the service provider (service server 20) settles the price of the product using information obtained from the credit card VCs.

[0074] Furthermore, if the wallet address is not included in the acknowledgement, the service server 20 considers that the user has refused to automatically provide credentials (e.g., credit card VCs), and stores this information in the user's account.

[0075] If the acknowledgement includes a wallet address, the service server 20 considers the user to have consented to the automatic provision of credentials (e.g., credit card VCs), and stores this information and the wallet address in the user's account.

[0076] If the user agrees to the automatic provision of the credential certificate, the terminal 40 sets the wallet server 30 so that the service provider can automatically obtain the credential certificate.

[0077] Terminal 40 accesses wallet server 30 (wallet address) and sets the business code of the service provider for which automatic provision is permitted and the type of credential certificate for which automatic provision is permitted in wallet server 30 (step S13 in FIG. 6). Terminal 40 transmits information on the business code and the type of credential certificate to wallet server 30 along with the user's wallet address.

[0078] The wallet server 30 stores a combination of the business code of the service provider for which automatic provision is permitted and the type of credential certificate for which automatic provision is permitted, in the user's account corresponding to the wallet address.

[0079] <Automatic provision of credentials> The service provider (service server 20) requests the user to resubmit the credential certificate as necessary. For example, the service server 20 periodically or at a predetermined timing checks the expiration dates of the credential certificates acquired from the user, and identifies the credential certificates whose expiration dates are approaching and their holders.

[0080] For example, when the expiration date of the credit card VCs approaches, the service server 20 requests the user (terminal 40) to reissue the credit card VCs.

[0081] If the user has not consented to the automatic provision of credentials (e.g., credit card VCs), the service server 20 will request the user to re-register (re-provision) the credentials when the user logs in to the account. Alternatively, the service server 20 may send a message to the user's email address, telephone number, etc., urging the user to re-register the credentials.

[0082] If the user has agreed to the automatic provision of a credential certificate, the service server 20 requests the wallet server 30 to provide the credential certificate that the user has agreed to be automatically provided. Specifically, the service server 20 sends a "certificate provision request" to the wallet server 30, which includes the user's wallet address, its own company's business code, and the type of credential certificate that is requested to be provided (see FIG. 8).

[0083] The wallet server 30 determines whether the business code and type of credential certificate included in the certificate provision request are stored in the user's account corresponding to the wallet address included in the request.

[0084] If the combination of business code and credential certificate type is not stored, the wallet server 30 transmits a negative response to the service server 20 indicating that the specified credential certificate cannot be provided. Alternatively, even if the combination of business code and credential certificate type is set, if the specified credential certificate is not stored in the digital wallet, the wallet server 30 transmits a negative response to the service server 20.

[0085] Once a combination of business code and credential certificate type has been set and the specified credential certificate (valid certificate) is stored in the digital wallet, the wallet server 30 transmits the specified credential certificate to the service server 20. The wallet server 30 signs the specified credential certificate using a private key corresponding to the user's user DID, and transmits an affirmative response including the signed credential certificate and the user DID to the service server 20.

[0086] The service server 20 verifies the acquired credential certificate, and if the credential certificate verification is successful, the service server 20 continues to provide the service to the user.

[0087] In this manner, the service server 20 requests the user to provide the first certificate (e.g., credit card VCs) required for the provision of the service. The terminal 40 obtains consent from the user to provide the requested first certificate to the service server 20. Furthermore, if the user consents to the automatic re-provision of a second certificate (e.g., updated credit card VCs) of the same type as the requested first certificate to the service server 20, the terminal 40 sets information in the wallet server 30 to realize the automatic re-provision of the second certificate. The service server 20 requests the wallet server 30 to re-provision the second certificate. The wallet server 30 provides the second certificate to the service server 20 based on the set information.

[0088] Next, details of each device included in the information processing system according to the first embodiment will be described.

[0089] [Device] Examples of the terminal 40 include a smartphone, a mobile phone, a game console, a mobile terminal device such as a tablet, a computer (personal computer, laptop computer), etc. The terminal 40 can be any equipment or device that can accept user operations and communicate with the server device 10, etc.

[0090] 9 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 40 according to an embodiment of the present disclosure. Referring to FIG. 9, the terminal 40 includes a communication control unit 201, an acquisition control unit 202, a usage control unit 203, and a storage unit 204.

[0091] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0092] Note that a description of functions for creating an account in the wallet server 30 and the service server 20 will be omitted, as details regarding account creation are obvious to those skilled in the art and are not within the scope of the present disclosure.

[0093] Control related to the digital wallet is executed by the modules of the acquisition control unit 202 and the usage control unit 203. The user registers login information for accessing the wallet server 30 in advance in the terminal 40. The acquisition control unit 202 and the usage control unit 203 access (log in to) the wallet server 30 using the login information.

[0094] The acquisition control unit 202 is a means for controlling the acquisition of credential certificates. The acquisition control unit 202 requests a certificate issuer to issue a certificate selected by the user, and stores the certificate acquired from the certificate issuer in the digital wallet.

[0095] The acquisition control unit 202 accesses the wallet server 30 in response to a user operation or the like, and acquires the user DID, public key, private key, and wallet address generated by the wallet server 30.

[0096] 10 is a flowchart showing an example of the operation of the acquisition control unit 202. The operation of the acquisition control unit 202 according to the embodiment of the present disclosure will be described with reference to FIG.

[0097] When the user performs a predetermined action (for example, pressing the certificate issuance button), the acquisition control unit 202 controls the acquisition of the credential certificate desired by the user.

[0098] First, the acquisition control unit 202 registers the user DID and public key acquired from the wallet server 30 in the blockchain (registering the public key, etc.; step S101).

[0099] Next, the acquisition control unit 202 acquires items necessary for requesting issuance of a credential certificate using a GUI (Graphical User Interface) or the like (acquisition of necessary items; step S102).

[0100] Specifically, the acquisition control unit 202 acquires information about the certificate issuer that has the authority to issue the credential certificate that the user desires to receive (for example, the name of the local government, company, or university), the type of certificate desired, etc. Furthermore, the acquisition control unit 202 acquires information that the certificate issuer uses to identify the subject of certification (for example, an employee number, a student ID number, or a name or a combination of a name and date of birth, etc.).

[0101] The acquisition control unit 202 notifies the certificate issuer of the acquired required items and user DID. Specifically, the acquisition control unit 202 notifies the certificate issuer of the type of credential certificate, information for identifying the certificate subject, and the user DID.

[0102] The acquisition control unit 202 transmits a "certificate issuance request" including the type of credential certificate, information specifying the certificate subject, the user DID, etc. to the server device 10 of the certificate issuer selected by the user (step S103).

[0103] The acquisition control unit 202 receives a response (positive response, negative response) to the certificate issuance request from the server device 10 (step S104).

[0104] If a negative response indicating that the certificate issuance has failed is received (step S105, No branch), the acquisition control unit 202 notifies the user that the credential certificate has not been issued (notification of non-issuance; step S106).

[0105] If a positive response indicating that the certificate has been successfully issued is received (step S105, Yes branch), the acquisition control unit 202 accesses the certificate acquisition URL included in the positive response and acquires the credential certificate issued by the certificate issuer (step S107).

[0106] The acquisition control unit 202 stores the acquired credential certificate in the digital wallet (step S108). The acquisition control unit 202 transmits the acquired credential certificate to the wallet server 30.

[0107] For example, a user may obtain a graduation certificate VC from the university from which the user graduated, an employment certificate VC from the company currently employed, or a qualification certificate VC from a qualification certification organization. The acquisition control unit 202 stores the obtained credential certificate in a digital wallet.

[0108] The usage control unit 203 is a means for controlling the use of digital content (credentials) stored in the digital wallet. Specifically, the usage control unit 203 processes information provision requests received from the service server 20 of the service provider.

[0109] 11 is a flowchart showing an example of the operation of the usage control unit 203. The operation of the usage control unit 203 according to the embodiment of the present disclosure will be described with reference to FIG.

[0110] Upon receiving the information provision request, the usage control unit 203 accesses the wallet server 30. The usage control unit 203 attempts to acquire the credential certificate designated by the service provider from among the multiple credential certificates stored in the digital wallet (attempt to acquire certificate; step S201).

[0111] If the specified credential certificate cannot be acquired (step S202, No branch), the usage control unit 203 transmits a negative response indicating that the credential certificate cannot be provided to the service server 20 (step S203).

[0112] If the specified credential certificate is acquired (step S202, Yes branch), the usage control unit 203 acquires consent from the user to provide the acquired credential certificate to the service provider (acquire consent to provision; step S204).

[0113] If consent to provide the credential certificate to the service provider is not obtained (step S205, No branch), the usage control unit 203 transmits a negative response indicating that the credential certificate cannot be provided to the service server 20 (step S203).

[0114] If consent to provide the credential certificate to the service provider is obtained (step S205, Yes branch), when the same service provider requests the re-provision of a credential certificate of the same type as the credential certificate provided above, the usage control unit 203 obtains consent to provide the requested credential certificate from among the credential certificates stored in the digital wallet without obtaining the user's permission (obtain consent for automatic provision; step S206).

[0115] For example, the usage control unit 203 obtains consent for the automatic provision of the credential certificate using a GUI (Graphical User Interface) as shown in FIG.

[0116] Regardless of whether or not the automatic provision is agreed upon, the usage control unit 203 transmits an affirmative response indicating that the credential certificate can be provided to the service server 20 (step S207).

[0117] Specifically, the usage control unit 203 signs the credential certificate read from the digital wallet. The usage control unit 203 signs the credential certificate specified by the service provider using the private key corresponding to the user DID.

[0118] If the user does not agree to the automatic provision, the usage control unit 203 sends an affirmative response to the service server 20, which includes the signed credential certificate and the user DID.

[0119] If the user agrees to the automatic provision, the usage control unit 203 sends an affirmative response to the service server 20, including the signed credential certificate, the user DID, and the wallet address.

[0120] Furthermore, if the user agrees to the automatic provision of the credential certificate, the usage control unit 203 notifies the wallet server 30 of the business code of the service provider for which automatic provision is permitted and the type of credential certificate for which automatic provision is permitted. The usage control unit 203 performs settings in the wallet server 30 to realize automatic provision (setting for automatic provision; step S208).

[0121] The storage unit 204 is a means for storing information necessary for the operation of the terminal 40 .

[0122] [Server device] 12 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure. Referring to FIG. 12, the server device 10 includes a communication control unit 301, a certificate issuing unit 302, and a storage unit 303.

[0123] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 40. The communication control unit 301 also transmits data to the terminal 40. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0124] The certificate issuing unit 302 is a means for issuing a credential certificate to a user. The certificate issuing unit 302 processes a “certificate issuance request” received from the terminal 40.

[0125] When a certificate issuance request is received, the certificate issuing unit 302 searches a database (not shown in Figure 12, etc.) that stores user information using information for identifying the subject of certification included in the certificate issuance request (e.g., employee number, etc.) as a key.

[0126] If the search fails, the certificate issuing unit 302 transmits a negative response to the terminal 40 indicating that the certificate issuance has failed.

[0127] If the search is successful, the certificate issuing unit 302 determines, as necessary, whether or not the credential certificate desired by the user can be issued.

[0128] For example, when a user requests the issuance of an employment certificate VCs, the certificate issuing unit 302 determines whether the user satisfies the requirements for receiving the issuance of an employment certificate VCs.

[0129] Note that detailed explanation regarding the determination of whether or not a credential certificate is issued will be omitted, as the requirements for issuing individual credential certificates are different from the gist of the disclosure of this application.

[0130] If a credential certificate cannot be issued to the user, the certificate issuing unit 302 transmits a negative response to the terminal 40 indicating that the certificate issuance has failed (certificate issuance is not possible).

[0131] If a credential certificate can be issued to the user, the certificate issuing unit 302 generates a credential certificate to be issued to the user. The certificate issuing unit 302 generates a credential certificate including the issuer DID and the user DID (the DID of the person to whom the certificate is to be issued; the user DID included in the certificate issuance request).

[0132] Specifically, the certificate issuing unit 302 generates a credential certificate including metadata including the type of credential certificate, the name of the issuing organization, the date and time of issue, the validity period, etc., the assertion (claim), and a proof consisting of the issuer's public key information, digital signature, etc. The digital signature affixed to the credential certificate is issued using a private key corresponding to the issuer DID generated in advance.

[0133] The certificate issuing unit 302 stores the generated credential certificate in online storage (storage on the cloud) or the like. The certificate issuing unit 302 generates a certificate acquisition URL from the URL of the storage destination of the credential certificate. The certificate issuing unit 302 transmits an affirmative response including the generated certificate acquisition URL to the terminal 40. Furthermore, the certificate issuing unit 302 registers the issuer DID, public key, etc., generated in advance, in the blockchain.

[0134] The storage unit 303 is a means for storing information necessary for the operation of the server device 10.

[0135] [Service Server] 13 is a diagram illustrating an example of a processing configuration (processing module) of the service server 20 according to the embodiment of the present disclosure. Referring to FIG. 13, the service server 20 includes a communication control unit 401, a service provision control unit 402, and a storage unit 403.

[0136] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the terminal 40. The communication control unit 401 also transmits data to the terminal 40. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0137] The service provision control unit 402 is a means for executing control relating to the services provided to the user.

[0138] The service provision control unit 402 has a function of creating an account for the user.

[0139] The service provision control unit 402 acquires information such as name, sex, date of birth, address, login information (ID, password), telephone number, and email address from a user who accesses a predetermined website (for example, a user registration site). Furthermore, the service provision control unit 402 assigns a user ID to the user.

[0140] The service provision control unit 402 stores the user ID, name, login information, contact information, etc. in the customer management database (see FIG. 14). Note that the customer management database shown in FIG. 14 is an example and is not intended to limit the items to be stored. For example, the customer management database may also store biometric information of the user (e.g., a facial image).

[0141] The service provision control unit 402 acquires information required to provide a service to a user at a predetermined timing. For example, after creating an account, the service provision control unit 402 acquires a credential certificate required to provide the service. For example, the service provision control unit 402 acquires a credit card VCs for payment.

[0142] The service provision control unit 402 transmits an "information provision request" to the terminal 40 carried by the user. The information provision request includes the type of credential certificate and the business code required for the service provider to provide the service.

[0143] The service provision control unit 402 receives a response (positive response, negative response) to the information provision request.

[0144] If a negative response is received, the service provision control unit 402 notifies the user that the service cannot be provided because the necessary information cannot be acquired. Alternatively, the service provision control unit 402 presents the user with alternatives for providing the service. For example, if a credit card VCs cannot be obtained, the service provision control unit 402 may suggest payment by electronic money.

[0145] If an affirmative response is received, the service provision control unit 402 verifies the credentials included in the affirmative response.

[0146] The service provision control unit 402 verifies at least one of three items related to the validity of the credential certificate.

[0147] The first item is the verification of the digital signature attached to the credential certificate.

[0148] In this case, the service provision control unit 402 acquires the issuer DID and user DID written in the credential certificate. The service provision control unit 402 acquires a public key corresponding to the acquired issuer DID from the blockchain. Similarly, the service provision control unit 402 acquires a public key corresponding to the acquired user DID from the blockchain.

[0149] The service provision control unit 402 verifies the signature of the holder (user desiring to receive the service) and the signature of the issuer attached to the credential certificate. By verifying these signatures, the service provision control unit 402 confirms that the credential certificate obtained from the user (credential certificate holder) has not been tampered with and that it has been issued by a reliable issuer.

[0150] The service provision control unit 402 determines that the credential certificate verification is successful if the signatures of the credential certificate holder and issuer are verified successfully. The service provision control unit 402 determines that the credential certificate verification is unsuccessful if the signature of at least one of the credential certificate holder and issuer is verified unsuccessfully.

[0151] The second item is verification that the credential has not been revoked.

[0152] In this case, the service provision control unit 402 accesses the blockchain or VDR using the credential ID and issuer DID, and confirms that the credential certificate corresponding to the received credential certificate is not listed in the certificate issuer's revocation list. The service provision control unit 402 confirms that the corresponding credential certificate obtained from the user has not been invalidated by the issuer before the expiration date of the credential certificate.

[0153] If the credential certificate is not listed in the revocation list, the service provision control unit 402 determines that the verification of the corresponding credential certificate has been successful. If the credential certificate is listed in the revocation list, the service provision control unit 402 determines that the verification of the acquired credential certificate has failed.

[0154] The third item is to verify that the validity period (expiration date) of the credential certificate has not expired.

[0155] The service provision control unit 402 checks the validity period set in the credential certificate. If the validity period set in the credential certificate has not expired, the service provision control unit 402 determines that the verification of the acquired credential certificate has been successful. If the validity period set in the credential certificate has expired, the service provision control unit 402 determines that the verification of the acquired credential certificate has failed.

[0156] If the service provision control unit 402 determines that "verification was successful" in all or part of the first to third items, it determines that the credential certificate obtained from the user has been verified successfully. For example, if the service provision control unit 402 determines that the verification was successful in each of the first to third items, it determines that the credential certificate has been verified successfully.

[0157] If it is determined that all or some of the first to third items have failed verification, the service provision control unit 402 determines that the verification of the credential certificate acquired from the user has failed. For example, if it is determined that one of the first to third items has failed verification, it is determined that the verification of the credential certificate has failed.

[0158] If the credential verification is successful, the service provision control unit 402 provides the service to the user. For example, the service provision control unit 402 settles the price of the product using information obtained from the credit card VCs. If the credential verification fails, the service provision control unit 402 is unable to obtain the information necessary to provide the service, and therefore notifies the user that the service cannot be provided.

[0159] Furthermore, the service provision control unit 402 determines whether the user has consented to the automatic provision of the credential certificate, depending on whether the wallet address is included in the positive response.

[0160] If the wallet address is not included in the positive response, the service provision control unit 402 considers that the user has refused automatic provision of the credential certificate. In this case, the service provision control unit 402 sets "not permitted" in the automatic provision field of the customer management database.

[0161] If the positive response includes a wallet address, the service provision control unit 402 considers that the user has agreed to the automatic provision of the credential certificate. In this case, the service provision control unit 402 sets "Yes" in the automatic provision field of the customer management database. The service provision control unit 402 also stores the wallet address included in the positive response in the wallet address field.

[0162] Regardless of whether or not the user has consented to automatic provision, the service provision control unit 402 stores information about the credential certificate acquired from the user (for example, the file name and storage location of the credential certificate) in the account.

[0163] The service provision control unit 402 periodically or at a predetermined timing reacquires the credential certificate obtained from the user. For example, the service provision control unit 402 reacquires the credential certificate based on a preset policy. Alternatively, the service provision control unit 402 may reacquire the credential certificate based on an instruction from an employee of the service provider, etc.

[0164] For example, the service provision control unit 402 reacquires a credential certificate of the same type as the expiring credential certificate a predetermined period of time (e.g., one month) before the expiration date of the credential certificate. Alternatively, the service provision control unit 402 reacquires a credential certificate of the same type as the expiring credential certificate (invalidated credential certificate) after the expiration date of the credential certificate has arrived.

[0165] The service provision control unit 402 refers to the customer management database and identifies the credential to be reacquired and its owner.

[0166] If the identified user does not agree to the automatic provision of the credential certificate, the service provision control unit 402 requests the user to re-register (re-provision) the credential certificate. For example, the service provision control unit 402 requests the user to re-register the credential certificate when the user logs in to the account, or sends a message to the user's email address or the like to urge the user to re-register the credential certificate.

[0167] If the user has consented to the automatic provision of a credential certificate, the service provision control unit 402 requests the wallet server 30 to provide the credential certificate that the user has consented to be automatically provided. Specifically, the service provision control unit 402 sends to the wallet server 30 a "certificate provision request" that includes the user's wallet address, the company's business code, and the type of credential certificate that is requested to be provided.

[0168] The service provision control unit 402 receives a response (positive response or negative response) to the certificate provision request from the wallet server 30.

[0169] If a negative response (credentials cannot be provided) is received, the service provision control unit 402 notifies the user, for example, that re-acquisition of credentials has failed.

[0170] When a positive response (credential certificate can be provided) is received, the service provision control unit 402 verifies the credential certificate included in the positive response. If the credential certificate verification is successful, the service provision control unit 402 stores the credential certificate and provides the service to the user.

[0171] The storage unit 403 is a means for storing information necessary for the operation of the service server 20 .

[0172] [Wallet Server] 15 is a diagram illustrating an example of a processing configuration (processing module) of the wallet server 30 according to the embodiment of the present disclosure. Referring to FIG. 15, the wallet server 30 includes a communication control unit 501, a wallet control unit 502, and a storage unit 503.

[0173] The communication control unit 501 is a means for controlling communication with other devices. For example, the communication control unit 501 receives data (packets) from the terminal 40. The communication control unit 501 also transmits data to the terminal 40. The communication control unit 501 passes data received from other devices to other processing modules. The communication control unit 501 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 501. The communication control unit 501 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.

[0174] The wallet control unit 502 is a means for controlling the digital wallet (web wallet).

[0175] The wallet control unit 502 has a function for creating an account for a user.

[0176] The wallet control unit 502 acquires information such as name, gender, date of birth, address, login information (ID, password), telephone number, and email address from a user who accesses a specified website (e.g., a user registration site).

[0177] The wallet control unit 502 generates a pair of public and private keys to be used by the user, as well as a user DID. Furthermore, the wallet control unit 502 assigns a wallet address to the user who created the account, and stores it in the user management database together with the user's name, login information, public key, private key, user DID, etc. (See FIG. 16).

[0178] The user management database shown in FIG. 16 is merely an example and is not intended to limit the items stored therein.

[0179] When the wallet control unit 502 receives a credential certificate from the terminal 40 of the user who has logged in to the account, the wallet control unit 502 stores the acquired credential certificate. In addition, the wallet control unit 502 transmits the stored credential certificate in response to a request from the terminal 40 of the user who has logged in to the account.

[0180] The wallet control unit 502 processes the combination of the business code and credential type (information required for automatic provision) received from the terminal 40. The wallet control unit 502 stores the business code of the service provider that is permitted to be automatically provided and the credential type that is permitted to be automatically provided in the user's entry.

[0181] The wallet control unit 502 processes the certificate provision request received from the service server 20 .

[0182] The wallet control unit 502 searches the user management database using the wallet address included in the certificate request as a key to identify the corresponding entry. If the search fails, the wallet control unit 502 sends a negative response to the service server 20 indicating that the credential certificate cannot be provided.

[0183] If the search is successful, the wallet control unit 502 determines whether the combination of the business code and credential type included in the certificate provision request is set in the identified user's account. That is, when a credential of the same type as the credential provided to the service provider is requested to be provided again, the wallet control unit 502 determines whether the user agrees to the re-provision of a credential of the same type as the credential provided to the service provider.

[0184] If the combination of business code and credential certificate type is not set (if the user has not agreed to automatic provision), the wallet control unit 502 sends a negative response to the service server 20 indicating that the specified credential certificate cannot be provided.

[0185] If a combination of business code and credential certificate type is set, the wallet control unit 502 determines whether a credential certificate corresponding to the credential certificate type included in the certificate provision request is stored (stored in the digital wallet).

[0186] If the credential certificate is not stored, the wallet control unit 502 sends a negative response to the service server 20 indicating that the wallet control unit 502 cannot provide the specified credential certificate.

[0187] If the credential certificate is stored, the wallet control unit 502 sends the credential certificate specified by the service provider in the certificate provision request to the service server 20. The wallet control unit 502 signs the credential certificate using the private key stored in the user's account, and sends an affirmative response including the signed credential certificate and the user DID to the service server 20.

[0188] In this way, when a request is made to resubmit at least one certificate of the same type as the certificate provided to the service provider, the wallet control unit 502 determines whether the user agrees to the resubmission of the same type of certificate as the certificate provided to the service provider. If the user agrees to the resubmission, the wallet control unit 502 provides the certificate requested to be resubmitted to the business (service provider, service server 20) requesting the resubmission of the certificate.

[0189] The storage unit 503 is a means for storing information necessary for the operation of the wallet server 30. The storage unit 503 stores at least one certificate (for example, a credential certificate) issued to a user.

[0190] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described.

[0191] 17 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding the issuance of a credential certificate will be described with reference to FIG.

[0192] The terminal 40 registers the user DID and the public key in the block chain (step S21).

[0193] The terminal 40 transmits a certificate issuance request including the user DID to the server device 10 of the certificate issuer (step S22).

[0194] The server device 10 generates assertions (claims, qualification information) of the user (the party to whom the credential certificate is to be issued) and generates a credential certificate including the assertions (step S23). The server device 10 generates a credential certificate including the user DID and issuer DID and having a digital signature attached.

[0195] The server device 10 stores the generated credential certificate in an online storage or the like, thereby providing the credential certificate to the terminal 40 (step S24).

[0196] The terminal 40 acquires the credential certificate in accordance with the certificate acquisition URL, and stores the acquired credential certificate in the digital wallet (step S25).

[0197] 18 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding the use of a credential will be described with reference to FIG.

[0198] The service server 20 of the service provider transmits an information request specifying the credentials required to provide the service to the terminal 40 (step S31).

[0199] The terminal 40 acquires whether or not the user agrees to the provision of the credential certificate. At that time, the terminal 40 also acquires whether or not the user agrees to the automatic provision of the credential certificate.

[0200] When the user agrees to provide the credential certificate, the terminal 40 transmits the credential certificate designated by the service server 20 to the service server 20 (step S32).

[0201] The service server 20 verifies the acquired credential certificate (step S33). If the credential certificate verification is successful, the service server 20 provides the service to the user.

[0202] 19 is a sequence diagram illustrating an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding automatic provision of a credential certificate will be described with reference to FIG.

[0203] If the user agrees to the automatic provision of the credential certificate, the service server 20 transmits a certificate provision request to the wallet server 30 (step S41).

[0204] If the combination of the business code and credential certificate type included in the certificate provision request is stored in the user's account, the wallet server 30 transmits the credential certificate specified by the service server 20 to the service server 20 (step S42). For example, the wallet server 30 transmits to the service server 20 a credential certificate (e.g., credit card VCs) whose validity period, etc. have been updated.

[0205] If the service server 20 successfully verifies the acquired credentials, it continues to provide the service to the user.

[0206] Next, a modified example of the first embodiment will be described.

[0207] <Variation 1> In the above embodiment, a case has been described in which the settings for automatic provision of a credential certificate are made in the wallet server 30. However, the settings for automatic provision of a credential certificate may also be made in the terminal 40.

[0208] In this case, a wallet application resides in the terminal 40, and the terminal 40 is always in a state where it can communicate with each service server 20. Furthermore, when the user agrees to the automatic provision of the credential certificate, the acquisition control unit 202 of the terminal 40 stores the settings related to the automatic provision (a combination of the business code and the type of credential certificate).

[0209] When it becomes necessary to reacquire a credential certificate, the service server 20 transmits a certificate provision request to the terminal 40. The service server 20 transmits the certificate provision request to the terminal 40, which includes the business code and the type of credential certificate to be re-provided.

[0210] If the combination of the business code and credential certificate type included in the certificate provision request is set, the usage control unit 203 accesses the wallet server 30 and acquires a credential certificate of the same type as the specified credential certificate. The usage control unit 203 attaches a signature to the acquired credential certificate and transmits it together with the user DID to the service server 20. The usage control unit 203 transmits an affirmative response including the signed credential certificate and the user DID to the service server 20.

[0211] <Variation 2> When obtaining consent for automatic provision of credentials, the terminal 40 may obtain various options for automatic provision.

[0212] For example, the acquisition control unit 202 may display a GUI that allows the user to select the scope of credential disclosure after the "Agree" button shown in Fig. 7 is pressed. For example, the acquisition control unit 202 may specify the scope of credential disclosure desired by the user using a GUI such as that shown in Fig. 20.

[0213] "Limited to the same business" is a setting that automatically provides credentials only when the service provider to which the credentials were provided requests the provision of the same type of credential again. For example, when credit card VCs are provided to service provider A, if this option is selected, credit card VCs will be automatically provided to service provider A, but credit card VCs will not be automatically provided to other businesses.

[0214] "Provided to related services" is a setting that automatically provides credentials when a service provider that provides the same type of service as the service provider to which the credentials are provided requests the provision of the same type of credential. For example, when credit card VCs are provided to EC service provider A, if this option is selected, credit card VCs will be automatically provided not only to EC service provider A but also to other EC service providers.

[0215] "Always Provide" is a setting in which the same type of credential as the credential for which this option is selected is automatically provided regardless of the service provider requesting automatic provision. For example, when credit card VCs are provided to service provider A, if this option is selected, the credit card VCs will be automatically provided to any service provider (business) including service provider A.

[0216] The acquisition control unit 202 transmits the user's selection (automatic provision option) together with the business code and the type of credential certificate to the wallet server 30. The wallet server 30 stores the received automatic provision option in the user's account.

[0217] When the wallet control unit 502 of the wallet server 30 receives the request for providing the credential, it determines whether or not to provide the credential in accordance with the automatic provision option stored in the account.

[0218] When "limited provision to the same business operator" is set, the wallet control unit 502 performs the operation already explained in the first embodiment.

[0219] If "Provided for related services" is set, the wallet control unit 502 determines whether the service provider corresponding to the business code included in the certificate provision request is related to the service provider corresponding to the business code set in the account. For example, the wallet control unit 502 references table information that stores business codes for each business type, and if two business codes are stored in the same table information, determines that the businesses of the two service providers are related. If it is determined that the businesses (services) of the two service providers are related, the wallet control unit 502 transmits the corresponding credential certificate to the sender of the certificate provision request if the type of credential certificate included in the certificate provision request is registered in the account as a target for automatic provision.

[0220] If "always provided" is set, the wallet control unit 502 determines whether the type of credential certificate stored in the account matches the type of credential certificate included in the certificate provision request. If the two credential certificate types match, the wallet control unit 502 transmits the credential certificate requested by the service provider (service server 20) to the service server 20 that is the sender of the certificate provision request.

[0221] The user may register a wallet address when creating an account on the service server 20. When it becomes necessary to reacquire a credential certificate, the service server 20 may transmit a certificate provision request for the credential certificate that needs to be reacquired to the wallet server 30. When the service provision control unit 402 of the service server 20 receives a negative response (unable to provide the credential certificate) from the wallet server 30, it may request the user to re-register the credential certificate, etc.

[0222] In this way, the wallet control unit 502 determines whether or not to provide the certificate requested to be re-submitted to the business requesting the re-submission of the certificate based on the settings regarding the disclosure scope of certificates of the same type as the certificate provided to the service provider.

[0223] More specifically, when a service provider requests the re-submission of a certificate of the same type as the certificate that was provided to the service provider, the wallet control unit 502 provides the requested re-submission certificate to the service provider. The wallet control unit 502 performs this operation when "Limited provision to the same business" is set.

[0224] Alternatively, when a business operator related to the service provider requests the re-provision of a certificate of the same type as the certificate provided to the service provider, the wallet control unit 502 provides the requested re-provision to the business operator related to the service provider. The wallet control unit 502 performs this operation when "Provide for related services" is set.

[0225] Alternatively, the wallet control unit 502 provides the requested certificate to any business that requests the certificate to be re-submitted. The wallet control unit 502 performs this operation when "always provide" is set.

[0226] As explained above, the scope of disclosure of the requested resubmission of the credential is not limited to the same business (service provider).

[0227] <Variation 3> The user may grant access rights to the credential certificate, thereby realizing automatic provision of the credential certificate. In this case, the wallet server 30 may provide a function (service) that allows the user to grant access rights to each credential certificate.

[0228] Specifically, wallet server 30 displays a list of credentials held by a user who has logged in to an account on terminal 40 of the user. The user operates terminal 40 to select from the list the credentials to be automatically provided.

[0229] The wallet control unit 502 of the wallet server 30 generates a URL for accessing the selected credential certificate. The wallet control unit 502 generates a URL that is linked to the selected credential certificate (the storage location of the credential certificate). The wallet control unit 502 transmits the generated URL to the terminal 40.

[0230] The user operates terminal 40 to access service server 20 of the service provider from which the user wishes to receive a service. The user registers the URL generated by wallet server 30 in service server 20. Service server 20 stores the URL in the user's account.

[0231] For example, a user selects resume VCs or credential certificate VCs stored in a digital wallet and obtains the URLs of the resume VCs, etc. from the wallet server 30. Furthermore, the user registers the URLs of the resume VCs, etc. with the service server 20 that provides a job change support service. A user who utilizes a job change support service registers the URLs of the resume VCs, etc. with the service server 20 of the job change support service when registering their profile.

[0232] When the service server 20 needs resume VCs to provide a service, it accesses the URL registered in the account and acquires the resume VCs. For example, the service provision control unit 402 provides the acquired resume VCs to the hiring company.

[0233] Even if the credential certificate (e.g., resume VCs) stored in the digital wallet is updated, the URL corresponding to the credential certificate is not updated. That is, the service server 20 can obtain the updated credential certificate (resume VCs) by accessing the same URL.

[0234] In this way, the user can not only set the re-provision of the credential certificate but also grant the service provider access rights to the credential certificate. That is, the user may set the wallet server 30 and the service server 20 to automatically provide the credential certificate via a URL.

[0235] The user can set various conditions for the wallet server 30 regarding the automatic provision of the credential certificate via a URL.

[0236] Specifically, the user accesses an account on the wallet server 30 and sets up the automatic provision of a credential certificate via the above URL. For example, the wallet control unit 502 of the wallet server 30 accepts a setting such as permitting a request for the automatic provision of a credential certificate via a URL only once within a predetermined time period (e.g., one hour or 24 hours).

[0237] Alternatively, the wallet control unit 502 may accept a setting such as permitting a request for automatic provision of a credential via a URL only a predetermined number of times (for example, once or twice). Alternatively, the wallet control unit 502 may accept a setting such that automatic provision of a credential is permitted only during the validity period of the original credential (the credential when the URL was first issued).

[0238] Alternatively, the wallet control unit 502 may accept a setting to automatically provide a credential certificate only when an updated credential certificate is requested to be provided again while the original credential certificate is invalid, or may accept a setting to automatically provide a credential certificate only when the same type of credential certificate has been rewritten.

[0239] The URL for automatically providing the credential certificate can be accessed by the service provider to which the URL is set. In the above example, a business providing a job change support service can access the URL of resume VCs, etc., and obtain the resume VCs, etc. Businesses, etc. for which a URL is not set can access the URL via the service server 20 of the business to which the URL is set.

[0240] For example, a company hiring a job seeker requests the service server 20 of a business that provides job change support services to provide resume VCs by specifying the job seeker. In response to the request, the service server 20 obtains the resume VCs according to a pre-set URL. The service server 20 provides the obtained resume VCs to the company hiring a job seeker.

[0241] In this way, the wallet control unit 502 sets an access right to a credential certificate selected by the user from at least one or more credential certificates, and issues information for accessing the credential certificate for which the access right has been set. More specifically, the wallet control unit 502 issues a URL linked to the credential certificate for which the access right has been set, as information for accessing the credential certificate for which the access right has been set.

[0242] <Variation 4> A user may grant access rights to a credential certificate held by the user to a specific device. For example, when a face authentication terminal (a face authentication device manufactured by a specific manufacturer) requests the wallet server 30 to provide a credential certificate (e.g., credit card VCs), the credential certificate may be provided to the face authentication terminal.

[0243] In this case, the face authentication terminal transmits to the wallet server 30 a certificate provision request including the face image of the user (person to be authenticated), the manufacturer's business code, and the type of credential certificate (credit card VCs) requested to be provided.

[0244] The wallet server 30 identifies the person to be authenticated by performing a matching process using the facial image registered in the account and the facial image included in the certificate provision request. If the combination of the business code and credential type included in the certificate provision request is set in the account of the identified person to be authenticated, the wallet control unit 502 of the wallet server 30 sends the credential certificate (credit card VCs) requested by the face authentication terminal to the face authentication terminal. The face authentication terminal provides services to the user using the acquired credential certificate.

[0245] <Variation 5> The user's terminal 40 may perform identity verification of the user when opening a digital wallet. For example, the terminal 40 may perform identity verification using a My Number card or the like.

[0246] As described above, the wallet server 30 according to the first embodiment automatically re-provisions a certificate of the same type as the certificate provided to the service provider if the user agrees to the re-provision of the same type of certificate. For example, when the expiration date of a credit card VC acquired from a user approaches, the service server 20 automatically acquires updated credit card VCs or credit card VCs issued by other credit card companies. The user does not need to re-register the credential certificate with the service provider (service server 20). As a result, the burden on the user is reduced.

[0247] When a user receives various online services, the user must register certificates and other information that prove his or her identity and qualifications with the service provider. To ensure continuous or appropriate service provision, the service provider requests the user to update the registered information (credentials) at predetermined intervals. In response to such requests, the user must re-register or update the certificates that prove his or her identity. However, such certificate re-registration has been a burden on the user. Therefore, when a credential certificate to be provided to a service provider is requested to be re-provided, the terminal 40 obtains consent to automatically re-provision the credential. If the user consents to automatic provision, the terminal 40 sets information (business code and credential type) to realize the automatic provision in the wallet server 30. If the user consents to automatic provision, the wallet server 30 automatically provides the credential certificate designated by the service provider to the service provider.

[0248] Next, the hardware of each device constituting the information processing system will be described. Fig. 21 is a diagram showing an example of the hardware configuration of the terminal 40.

[0249] The terminal 40 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 21. For example, the terminal 40 has a processor 311, a memory 312, an input / output interface 313, a communication interface 314, etc. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.

[0250] However, the configuration shown in Fig. 21 is not intended to limit the hardware configuration of the terminal 40. The terminal 40 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the terminal 40 is not intended to be limited to the example shown in Fig. 21, and for example, the terminal 40 may include multiple processors 311.

[0251] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).

[0252] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.

[0253] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations such as a keyboard or a mouse.

[0254] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).

[0255] The functions of the terminal 40 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by a semiconductor chip.

[0256] The server device 10, the service server 20 and the wallet server 30 can also be configured by information processing devices, just like the terminal 40, and their basic hardware configurations are no different from those of the terminal 40, so a description thereof will be omitted.

[0257] Terminal 40, which is an information processing device, is equipped with a computer, and functions of terminal 40 can be realized by causing the computer to execute a program. Terminal 40 also executes a control method for terminal 40 using the program. Similarly, wallet server 30, which is an information processing device, is equipped with a computer, and functions of wallet server 30 can be realized by causing the computer to execute a program. Wallet server 30 also executes a control method for wallet server 30 using the program.

[0258] [Variations] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.

[0259] The wallet server 30 or terminal 40 that receives the certificate provision request may provide the service provider with the same credential certificate as a credential certificate that has already been provided. In other words, the same type of credential certificate in the present disclosure includes a credential certificate that is identical to a credential certificate that has already been provided. For example, the service server 20 of a hospital requests the wallet server 30 or terminal 40 to re-provide health insurance card VCs every time the month changes. The wallet server 30 or terminal 40 that receives this request provides the service provider with the same health insurance card VCs as the previously provided health insurance card VCs.

[0260] The wallet server 30 etc. may provide a credential certificate issued by a different issuer to a service provider requesting automatic provision of a credential certificate. For example, if the service provider requests re-provision of My Number Card VCs, the wallet server 30 etc. may provide the service provider with passport VCs. This is because My Number Card VCs and passport VCs can be considered the same type of credential certificate from the perspective of identification.

[0261] The wallet server 30 or the like may use generative artificial intelligence (AI) such as a large language model (LLM) to identify credentials of the same type as the credentials requested by the service provider. For example, consider a case where the wallet server 30 or the like is requested to re-issue credit card VCs and multiple credit card VCs are stored in the digital wallet. In this case, the wallet server 30 or the like may select the credit card VC with the longest expiration date and provide it to the service provider.

[0262] When the wallet server 30 has automatically provided a credential, the wallet server 30 may notify the user of this. The wallet server 30 may send a message to the terminal 40 including the name of the credential provided by the automatic provision and the name of the recipient. Alternatively, the wallet server 30 may accumulate a history of the automatic provision and transmit the history to the terminal 40 at a predetermined timing (for example, at the end of the month).

[0263] In the above embodiment, the digital wallet used by the user is configured online. However, the digital wallet may be configured inside the terminal 40.

[0264] In the above embodiment, the case where the certificate issuer server device 10 issues a credential certificate that does not require a certification authority for certificate verification has been described. However, the server device 10 may also issue a certificate that requires a certification authority (a certificate based on a public key infrastructure).

[0265] Some of the functions of the service server 20 and the terminal 40 may be implemented in another apparatus, device, etc. More specifically, the above-described "wallet control unit (wallet control means)" and the like may be implemented in any of the apparatuses included in the system.

[0266] The form of data transmission and reception between each device (for example, server device 10, terminal 40) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users and the like is transmitted and received between these devices, and in order to appropriately protect this information, it is desirable that encrypted data be transmitted and received.

[0267] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the execution order of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the illustrated steps can be changed to the extent that the content is not affected, such as by executing each process in parallel.

[0268] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.

[0269] The above explanation makes clear the industrial applicability of the present invention, and the present invention is suitably applicable to information processing systems including service providers that provide services to users using certificates stored in digital wallets.

[0270] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.

[0271] [Appendix 1] a storage means for storing at least one certificate issued to a user; a control means for, when a request is made for the re-submission of a certificate of the same type as the certificate provided to the service provider among said at least one certificate, and if said user agrees to the re-submission of a certificate of the same type as the certificate provided to said service provider, providing said certificate of the type requested to be re-submitted to the business requesting the re-submission of said certificate; An information processing device comprising:

[0272] [Appendix 2] The information processing device described in Appendix 1, wherein the control means determines whether or not to provide the certificate requested to be re-submitted to the business requesting the re-submission of the certificate based on settings regarding the disclosure scope of certificates of the same type as the certificate provided to the service provider.

[0273] [Appendix 3] The information processing device described in Appendix 2, wherein the control means, when the service provider requests the re-provision of a certificate of the same type as the certificate provided to the service provider, provides the service provider with the certificate that is requested to be re-provisioned.

[0274] [Appendix 4] An information processing device as described in Appendix 2, wherein the control means, when a business operator engaged in a business related to the service provider requests the re-provision of a certificate of the same type as the certificate provided to the service provider, provides the certificate requested to be re-provision to the business operator engaged in a business related to the service provider.

[0275] [Appendix 5] 3. The information processing device according to claim 2, wherein the control means provides the certificate requested to be re-submitted to any business that requests the certificate to be re-submitted.

[0276] [Appendix 6] An information processing device according to any one of appendices 1 to 5, wherein the control means sets an access right to a certificate selected by the user from among the at least one certificate, and issues information for accessing the certificate to which the access right has been set.

[0277] [Appendix 7] The information processing device described in Appendix 6, wherein the control means issues a URL (Uniform Resource Locator) linked to the certificate for which the access right has been set as information for accessing the certificate for which the access right has been set.

[0278] [Appendix 8] A device owned by the user, a service server that provides services to the user; a wallet server that realizes a web wallet that stores at least one certificate issued to the user; Including, the service server requests the user to provide a first certificate necessary for providing the service; the terminal obtains consent from the user to provide the first certificate requested to be provided to the service server, and when the user consents to the automatic re-provision of a second certificate of the same type as the first certificate requested to be provided to the service server, sets information in the wallet server to realize the automatic re-provision of the second certificate; the service server requests the wallet server to provide the second certificate again; The wallet server provides the second certificate to the service server based on the set information.

[0279] [Appendix 9] storing at least one certificate issued to the user; A control method for an information processing device, which, when a request is made for the re-provision of a certificate of the same type as the certificate provided to the service provider among the at least one certificate, provides the requested certificate to the business requesting the re-provision of the certificate if the user agrees to the re-provision of a certificate of the same type as the certificate provided to the service provider.

[0280] [Appendix 10] On the computer, storing at least one certificate issued to the user; a process of providing the certificate requested to be resubmitted to the business requesting the resubmission of the certificate when the user is requested to resubmit a certificate of the same type as the certificate provided to the service provider among the at least one certificate and the user has consented to the resubmission of a certificate of the same type as the certificate provided to the service provider; A computer-readable storage medium that stores a program for executing the above.

[0281] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 7 that are dependent on Supplementary Note 1 above may also be dependent on Supplementary Notes 9 and 10 in the same dependent relationship as Supplementary Notes 2 to 7. Furthermore, not limited to Supplementary Notes 1, 8, 9, and 10, some or all of the configurations described as Supplements may be made dependent on various hardware, software, various recording means for recording software, or systems, within the scope of each of the above-mentioned embodiments.

[0282] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof. [Explanation of symbols]

[0283] 10 Server device 20 Service Server 30 Wallet Server 40 terminals 100 Information processing device 101 Memory means 102 Control means 201 Communication control unit 202 Acquisition control section 203 Usage Control Unit 204 Storage section 301 Communication Control Unit 302 Certificate Issuance Department 303 Storage section 311 processor 312 memory 313 Input / Output Interface 314 Communication Interface 401 Communication control unit 402 Service provision control unit 403 Storage section 501 Communication control unit 502 Wallet control unit 503 Storage section

Claims

1. a storage means for storing at least one certificate issued to a user; a control means for, when the user agrees to automatically re-issuing a certificate of the same type as the certificate provided to the service provider, providing the certificate of the same type to a business that requests the re-issuance of the certificate of the same type; and Equipped with The control means determines whether to provide the same type of certificate to a business operator requesting the re-provision of the same type of certificate based on settings regarding the disclosure scope of the same type of certificate as the certificate provided to the service provider.

2. 2. The information processing device according to claim 1, wherein, when the service provider requests the re-provision of a certificate of the same type as the certificate provided to the service provider, the control means provides the requested re-provision to the service provider.

3. 2. The information processing device according to claim 1, wherein the control means, when requested by a business operator engaged in a business related to the service provider to re-provision a certificate of the same type as the certificate provided to the service provider, provides the certificate requested to be re-provision to the business operator engaged in a business related to the service provider.

4. 2. The information processing apparatus according to claim 1, wherein said control means provides the certificate requested to be resubmitted to any business that requests the certificate to be resubmitted.

5. 5. The information processing device according to claim 1, wherein the control means sets an access right to a certificate selected by the user from among the at least one certificate, and issues information for accessing the certificate to which the access right has been set.

6. 6. The information processing device according to claim 5, wherein the control means issues a URL (Uniform Resource Locator) linked to the certificate for which the access right is set as information for accessing the certificate for which the access right is set.

7. A device owned by the user, a service server that provides services to the user; a wallet server that realizes a web wallet that stores at least one certificate issued to the user; Including, the service server requests the user to provide a first certificate necessary for providing the service; the terminal obtains consent from the user to provide the first certificate requested to be provided to the service server, and, if the user consents to a second certificate of the same type as the first certificate requested to be provided being automatically re-provided to the service server, sets information in the wallet server for realizing the automatic re-provision of the second certificate; the service server requests the wallet server to provide the second certificate again; The wallet server provides the second certificate to the service server based on the set information.

8. storing at least one certificate issued to the user; A method for controlling an information processing device, wherein, when the user agrees to automatically re-issuing a certificate of the same type as a certificate provided to a service provider, the same certificate is provided to a business that requests the re-issuance of the same certificate, the method comprising: A control method for an information processing device that determines whether to provide a certificate of the same type as the certificate provided to the service provider to a business operator requesting the re-provision of the certificate of the same type, based on settings regarding the disclosure scope of the certificate of the same type as the certificate provided to the service provider.

9. On the computer, storing at least one certificate issued to a user; a process of providing a certificate of the same type as the certificate provided to the service provider, among the at least one certificate, to a business entity requesting the provision of the certificate, when the user has consented to the automatic re-provision of the certificate of the same type; A program for executing The computer, A program for executing a process to determine whether or not to provide a certificate of the same type to a business operator requesting the re-provision of a certificate of the same type as the certificate provided to the service provider, based on settings regarding the disclosure scope of the certificate of the same type.

Citation Information

Patent Citations

  • Online commerce system for personal information protection

    JP2004102872A

  • Communication device and computer program

    JP2010239444A

  • Information processing device, its control method and program

    JP2014137802A

  • Application program, information processing method, and terminal device

    JP2023168326A

  • Terminal, system, control method of terminal, and program

    JP2025088095A