Information processing method, information processing program, and information processing device

The method associates personal IDs with public certificates to provide region-limited services, enhancing service accessibility and reliability using electronic certificates.

JP7810741B2Active Publication Date: 2026-02-03DAI NIPPON PRINTING CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024036018
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-08
Publication Date
2026-02-03
Estimated Expiration
2043-08-30

AI Technical Summary

Technical Problem

Existing systems do not provide for area-limited services using public certificates like My Number cards.

Method used

An information processing method that associates a personal ID valid in a specified region with a public ID or unique identifier from a public certificate, enabling region-limited services by processing received IDs.

Benefits of technology

Enables the provision of area-limited services, allowing users to access region-specific services and payments using electronic certificates, reducing the need for dedicated cards and enhancing data reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007810741000001
    Figure 0007810741000001
  • Figure 0007810741000002
    Figure 0007810741000002
  • Figure 0007810741000003
    Figure 0007810741000003
Patent Text Reader

Abstract

To provide an information processing method, an information processing program, and an information processing device which make it implementable to provide a region limited service.SOLUTION: The information processing method associates a personal ID effective in a predetermined region with a public ID given to a public certificate or a unique identifier generated from the public certificate. In a case where the public ID or the identifier is received, a computer executes processing of providing a service limited to the region, based on the personal ID associated with the received public ID or the identifier.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing method, an information processing program, and an information processing device that use public certificates to provide area-limited services. [Background technology]

[0002] Public certificates such as driver's licenses, health insurance cards, passports, and personal identification number cards are issued by public institutions, and therefore the information written on them is highly reliable. For this reason, public certificates are also widely recognized as identification documents. In particular, personal identification number cards, commonly known as My Number cards, are capable of storing electronic certificates. For this reason, in recent years, the use of My Number cards in various services has been attracting attention. Patent Document 1 discloses that in a procedure information linkage system that performs various procedures at various businesses in response to user requests, public personal authentication using My Number cards is performed to verify the identity of users.

[0003] Furthermore, assuming the widespread use of My Number, the idea of ​​a digital garden city has been proposed, and there is a demand for localized resident services and information provision for tourists based on a regional data collaboration platform. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2023-49133 Summary of the Invention [Problem to be solved by the invention]

[0005] However, the prior art does not take into consideration the provision of area-limited services. The present invention has been made in light of this situation. It is an object of the present invention to provide an information processing method, an information processing program, and an information processing device that realize the provision of area-limited services. [Means for solving the problem]

[0006] An information processing method according to one embodiment of the present application associates and stores a personal ID valid in a specified region with a public ID assigned to a public certificate or a unique identifier generated from the public certificate, and when the public ID or identifier is received, a computer executes a process to provide the region-limited service based on the personal ID associated with the received public ID or identifier. [Effects of the Invention]

[0007] In one aspect of the present application, it is possible to provide area-limited services. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is an explanatory diagram illustrating an example of the configuration of a service providing system. [Figure 2] FIG. 2 is a block diagram illustrating an example of a hardware configuration of a server. [Figure 3] FIG. 2 is a block diagram illustrating an example of the hardware configuration of a user terminal. [Figure 4] FIG. 2 is a block diagram showing an example of the hardware configuration of a store terminal. [Figure 5] FIG. 10 is an explanatory diagram illustrating an example of a user DB. [Figure 6] FIG. 10 is an explanatory diagram illustrating an example of an association DB. [Figure 7] FIG. 10 is an explanatory diagram showing an example of a period DB. [Figure 8] FIG. 10 is an explanatory diagram showing an example of a confirmation date DB. [Figure 9] 10 is a flowchart illustrating an example of a procedure for a linking process. [Figure 10] 10 is a flowchart illustrating an example of a procedure for serial number acquisition processing. [Figure 11] 10 is a flowchart illustrating an example of a procedure for serial number acquisition processing. [Figure 12] 10 is a flowchart illustrating an example of a payment process. [Figure 13]10 is a flowchart illustrating an example of a payment process. [Figure 14] 10 is a flowchart illustrating another example of a procedure for payment processing. [Figure 15] 10 is a flowchart illustrating another example of a procedure for payment processing. [Figure 16] FIG. 10 is an explanatory diagram illustrating an example of a service DB. [Figure 17] 10 is a flowchart illustrating an example of a procedure for a target person determination process. [Figure 18] 10 is a flowchart illustrating an example of a procedure for a target person determination process. [Figure 19] 10 is a flowchart illustrating an example of a procedure for information providing processing. [Figure 20] 10 is a flowchart illustrating an example of a procedure for login processing. [Figure 21] 10 is a flowchart illustrating an example of a procedure for login processing. [Figure 22] 10 is a flowchart illustrating an example of a procedure for login processing. DETAILED DESCRIPTION OF THE INVENTION

[0009] (Embodiment 1) An embodiment will be described below with reference to the drawings. Fig. 1 is an explanatory diagram showing an example of the configuration of a service providing system. The service providing system 100 includes a server 1, a user terminal 2, and a store terminal 3. Although one user terminal 2 and one store terminal 3 are shown, there may be multiple of each. The server 1, the user terminal 2, and the store terminal 3 are connected to each other via a network N so that they can communicate with each other.

[0010] The server 1, user terminal 2, and store terminal 3 can communicate with the certification authority CA and can verify the validity of public certificates. The server 1, user terminal 2, and store terminal 3 can also communicate with multiple cloud services CS, such as payment services operated by payment service providers. This allows users to receive a variety of services.

[0011] Server 1 provides area-limited services or performs information processing for providing such services. Area-limited services include services provided in a specific area only to residents of that area, and services provided in a specific area but without restrictions on the recipients. Server 1 is composed of a server computer, a workstation, a PC (Personal Computer), etc. Server 1 may also be composed of a multicomputer consisting of multiple computers, a virtual machine virtually constructed by software, or a quantum computer. Furthermore, the functions of Server 1 may be realized as a cloud service.

[0012] 2 is a block diagram showing an example of the hardware configuration of the server 1. The server 1 includes a control unit 11, a main memory unit 12, an auxiliary memory unit 13, a communication unit 14, and a reading unit 15. Each component is connected by a bus B.

[0013] The control unit 11 has one or more arithmetic processing devices such as a central processing unit (CPU), a micro-processing unit (MPU), a graphics processing unit (GPU), etc. The control unit 11 reads and executes a control program 1P (information processing program, program product) stored in the auxiliary storage unit 13, thereby realizing a functional unit that performs various information processing, control processing, etc. related to the server 1.

[0014] The main memory unit 12 is a static random access memory (SRAM), a dynamic random access memory (DRAM), a flash memory, etc. The main memory unit 12 mainly temporarily stores data required for the control unit 11 to execute arithmetic processing.

[0015] The auxiliary storage unit 13 is a hard disk or an SSD (Solid State Drive) or the like, and stores a control program 1P and various DBs (Databases) required for the control unit 11 to execute processing. The auxiliary storage unit 13 stores a user DB 131, a link DB 132, a period DB 133, a confirmation date DB 134, and a service DB 135. The auxiliary storage unit 13 may be separate from the server 1 and may be an external storage device externally connected. The various DBs and the like stored in the auxiliary storage unit 13 may be stored in a database server or cloud storage different from the server 1. The service DB 135 is not essential in this embodiment.

[0016] The communication unit 14 communicates with the user terminal 2, the store terminal 3, the certificate authority CA, and the cloud service CS via the network N. In addition, the control unit 11 may use the communication unit 14 to download the control program 1P from another computer via the network N or the like, and store it in the auxiliary storage unit 13.

[0017] The reading unit 15 reads the portable storage medium 1a including a CD (Compact Disc)-ROM and a DVD (Digital Versatile Disc)-ROM. The control unit 11 may read the control program 1P from the portable storage medium 1a via the reading unit 15 and store it in the auxiliary storage unit 13. The control unit 11 may also read the control program 1P from the semiconductor memory 1b.

[0018] The user terminal 2 is a terminal used by an end user and is configured as a smartphone, a tablet computer, or the like.

[0019] 3 is a block diagram showing an example of the hardware configuration of a user terminal 2. The user terminal 2 includes a control unit 21, a main memory unit 22, an auxiliary memory unit 23, a communication unit 24, a display panel 25, and an operation unit 26. Each component is connected by a bus B.

[0020] The control unit 21 has one or more arithmetic processing units such as a CPU, an MPU, a GPU, etc. The control unit 21 provides various functions by reading and executing a control program 2P (program, program product) stored in the auxiliary storage unit 23.

[0021] The main memory unit 22 is an SRAM, a DRAM, a flash memory, etc. The main memory unit 22 mainly temporarily stores data necessary for the control unit 21 to execute arithmetic processing.

[0022] The auxiliary storage unit 23 is a hard disk or SSD, etc., and stores various data necessary for the control unit 21 to execute processing. The auxiliary storage unit 23 may be an external storage device that is separate from the user terminal 2 and externally connected. The various DBs, etc. stored in the auxiliary storage unit 23 may be stored in a database server or cloud storage.

[0023] The communication unit 24 communicates with the server 1, the cloud service CS, or the certification authority CA via the network N. In addition, the control unit 21 may use the communication unit 24 to download the control program 2P from another computer via the network N or the like, and store the control program 2P in the auxiliary storage unit 23.

[0024] The display panel 25 includes a liquid crystal display panel or an organic EL (electroluminescence) display panel. The display panel 25 displays a notification screen output by the server 1. The operation unit 26 is a keyboard, a mouse, a trackpad, or the like. The display panel 25 and the operation unit 26 may be integrated to form a touch panel display. The user terminal 2 may display on an external display device such as a display.

[0025] The store terminal 3 is a terminal used in a store that provides services via the service providing system 100. For example, the store terminal 3 is used in a retail store that provides payment services limited to a service area via the service providing system 100.

[0026] The store terminal 3 is configured as a smartphone, a tablet computer, a notebook computer, etc. The store terminal 3 may be configured as a POS (Point of Sale) register.

[0027] 4 is a block diagram showing an example of the hardware configuration of a store terminal. The store terminal 3 includes a control unit 31, a main memory unit 32, an auxiliary memory unit 33, a communication unit 34, a display panel 35, an operation unit 36, an imaging unit 37, and a short-range communication unit 38. Each component is connected by a bus B. The control unit 31, the main memory unit 32, the auxiliary memory unit 33, the communication unit 34, the display panel 35, and the operation unit 36 ​​are similar to the control unit 21, the main memory unit 22, the auxiliary memory unit 23, the communication unit 24, the display panel 25, and the operation unit 26 of the user terminal 2, respectively, and therefore description thereof will be omitted.

[0028] The imaging unit 37 is, for example, a CCD camera or a CMOS camera, and acquires image data by photoelectrically converting an optical signal input via a CCD or CMOS, etc. The control unit 31 and the imaging unit 37 may also cooperate to realize the function of a POS (Point Of Sales) register, such as reading barcodes attached to products sold in a store and acquiring the sales price.

[0029] The short-range communication unit 38 performs communication in accordance with the NFC (Near Field Communication) standard. The short-range communication unit 38 reads an electronic certificate from a certificate card in which an IC (Integrated Circuit) chip storing electronic data of an official certificate and a wireless antenna are embedded. Note that the short-range communication unit 38 may also be capable of communication in accordance with the Bluetooth (registered trademark) standard, the IrDA (Infrared Data Association) standard, the Wi-Fi (registered trademark) standard, etc.

[0030] Next, the databases used in the service providing system 100 will be described. FIG. 5 is an explanatory diagram showing an example of a user DB. The user DB 131 stores information on end users, mainly local residents or tourists visiting the area. The user DB 131 includes a user ID column, a name column, an address column, a gender column, a date of birth column, a phone number column, an email column, and a type column. The user ID column stores a user ID (personal ID) that can uniquely identify a user. The user ID is assigned by the service providing system 100. The name column stores the user's name. The address column stores the user's current address. The gender column stores the user's gender. The date of birth column stores the user's date of birth. The phone number column stores the user's contact phone number. It is desirable that the stored phone number be a mobile phone number that can use SMS (Short Message Service). The email column stores the user's contact email address. The type column stores the user's type. For example, the type could be resident or tourist. Residents refer to residents who live in the area targeted by the service providing system 100. Tourists refer to people who live outside the area and visit the area primarily for tourist purposes.

[0031] FIG. 6 is an explanatory diagram showing an example of an association DB. Association DB 132 is a database that stores user IDs and other IDs in association with each other. Association DB 132 includes a user ID column, a serial number column, and a payment ID column. The user ID column stores user IDs. The serial number column stores the issue number assigned to an electronic certificate, known as a serial number (public ID). For example, the electronic certificate is a user authentication electronic certificate or a signature electronic certificate stored on a personal identification number card, known as a My Number card. Note that it is desirable to store a hashed value (identifier) ​​of the stored serial number to avoid misuse in the event of leakage. The payment ID column stores payment IDs. The payment ID is an ID used when a user uses a payment service. If a user receives a service other than a payment service, the ID used when using that service may be stored in association DB 132.

[0032] Fig. 7 is an explanatory diagram showing an example of a period DB. The period DB 133 stores, for each service, a period during which the electronic certificate is exempt from the revocation check. The period DB 133 includes a service column and an exemption period column. The service column stores the service name that identifies the service, etc. The exemption period column stores the period (check exemption period) during which the check process may be omitted after the validity of the electronic certificate is confirmed.

[0033] FIG. 8 is an explanatory diagram showing an example of a confirmation date DB. The confirmation date DB 134 stores the date on which the last revocation check of the electronic certificate was performed for each user. The confirmation date DB 134 includes a user ID column and a confirmation date column. The user ID column stores the user ID. The confirmation date column stores the date on which the last revocation check of the electronic certificate was performed. Note that the period DB 133 and the confirmation date DB 134 are not essential components in this embodiment, but are essential components in variant example 1, which will be described later.

[0034] Next, information processing performed in the service providing system 100 will be described. Before describing the information processing, the following assumptions for information processing will be described. It is assumed that a user who wishes to receive various services via the service providing system 100 uses the user terminal 2 to access the server 1 and register as a user. That is, the user is assigned a user ID by the service providing system 100, and the user terminal 2 stores the user ID. The user is also registered to use a payment service whose availability is limited to certain regions, and is assigned a payment ID to be used when using the payment service, and the user terminal 2 stores the payment ID.

[0035] FIG. 9 is a flowchart showing an example of the procedure for the linking process. The linking process links a user ID with the serial number of an electronic certificate, and also links the user ID with the IDs of various services to which the user has been granted. The process shown in FIG. 9 shows an example of a payment service as the various services. The user operates the user terminal 2 and specifies the service to be linked. In this case, it is a payment service, and the ID is a payment ID. The control unit 21 of the user terminal 2 sends the user ID and payment ID to the server 1 (step S1). The control unit 11 of the server 1 receives the user ID and payment ID (step S2). The control unit 11 acquires user information from the user DB 131 (step S3). The control unit 11 sends the user information and payment ID to the payment service (step S4). The payment service receives the user information and payment ID (step S5). The payment service authenticates the user (step S6). The payment service compares the user information it holds with the received user information, and if the name, date of birth, etc. match, the authentication is deemed successful. User information management may be performed collectively by the service providing system 100. In this case, step S3 is unnecessary, and user information is not sent or received in steps S4 and S5. The authentication in step S6 is deemed successful if the received payment ID is an issued ID, and is deemed unsuccessful if it is not an issued ID. The payment service transmits the authentication result to the server 1 (step S7). The control unit 11 of the server 1 receives the authentication result (step S8). The control unit 11 determines whether the authentication result is successful (step S9). If the control unit 11 determines that the authentication result is successful (YES in step S9), it links the user ID and the payment ID and stores them in the linked DB 132 (step S10). The control unit 11 transmits a linking completion notification to the user terminal 2 (step S11). The control unit 21 of the user terminal 2 receives the completion notification and displays that fact on the display panel 25 (step S12). The control unit 21 ends the processing. If the control unit 11 determines that the authentication result is a failure (NO in step S9), it sends an error to the user terminal 2 (step S13). The control unit 21 of the user terminal 2 receives the error and displays on the display panel 25 that the linking has failed (step S14). The control unit 21 ends the processing.

[0036] 10 and 11 are flowcharts showing an example of the serial number acquisition process. The serial number acquisition process is executed after the linking process. However, the serial number acquisition process only needs to be executed once before the electronic certificate expires. The user may start the serial number acquisition process on the user terminal 2, or may request that it be started on the store terminal 3 when first using a service for which the linking process has been completed. The following explanation will be given assuming that the process is started on the store terminal 3. The control unit 31 of the store terminal 3 displays a message on the display panel 35 prompting the user to hold the certificate card over the card. If the store terminal 3 is capable of outputting audio, it may output an audio message. The user holds the certificate card over the short-range communication unit 38. The control unit 31 reads the signature electronic certificate from the certificate card via the short-range communication unit 38 (step S31). The control unit 31 displays a message on the display panel 35 prompting the user to enter the PIN for the signature electronic certificate. The user enters the PIN using the operation unit 36. The control unit 31 acquires the PIN (step S32). The control unit 31 determines whether the PIN is correct (step S33). If the control unit 31 determines that the PIN is incorrect (NO in step S33), it outputs a message prompting the user to re-enter the PIN and returns the process to step S32. If the control unit 31 determines that the PIN is correct (YES in step S33), it sends the serial number of the signature electronic certificate to the certification authority CA (step S34). Sending the serial number indicates a request to confirm the validity of the signature electronic certificate. The certification authority CA receives the serial number (step S35). The certification authority CA checks whether the signature electronic certificate has been revoked and sends the confirmation result to the store terminal 3 (step S36). The control unit 31 of the store terminal 3 receives the confirmation result (step S37). The control unit 31 determines whether the signature electronic certificate is valid based on the confirmation result (step S38). If the control unit 31 determines that the signature digital certificate is not valid (NO in step S38), it displays an error message (step S39) and ends the process.If the control unit 31 determines that the signature electronic certificate is valid (YES in step S38), the process moves to FIG. 11, where it sends a request for the serial number of the user-certification electronic certificate, including the serial number of the signature electronic certificate, to the certification authority CA (step S40). The certification authority CA receives the request (step S41). The certification authority CA sends the serial number of the user-certification electronic certificate to the store terminal 3 (step S42). The control unit 31 of the store terminal 3 receives the serial number (step S43). The control unit 31 acquires the four basic pieces of information (name, address, gender, and date of birth) from the signature electronic certificate (step S44). The control unit 31 sends the serial number of the user-certification electronic certificate and the four basic pieces of information to the server 1 (step S45). The control unit 11 of the server 1 receives and stores the serial number of the user-certification electronic certificate and the four basic pieces of information (step S46). The control unit 11 hashes the serial number of the user authentication electronic certificate and stores it in the linked DB 132, and stores the four basic information in the user DB 131. The control unit 11 determines whether the user is a resident based on the user's address. If the control unit 11 determines that the user is a resident, it sets the value of the type column in the user DB 131 to resident. If the control unit 11 determines that the user is not a resident, it sets the value of the type column in the user DB 131 to tourist. The control unit 11 sends a completion notification to the store terminal 3 (step S47). The control unit 31 of the store terminal 3 receives the completion notification and displays that fact on the display panel 35 (step S48). The control unit 31 ends the processing.

[0037] 12 and 13 are flowcharts showing an example of the procedure for payment processing. The payment processing is performed when a user electronically pays for the purchase of a product at a store. The user holds their certificate card over the short-range communication unit 38 of the store terminal 3. The control unit 31 of the store terminal 3 reads the user-certificate electronic certificate from the certificate card via the short-range communication unit 38 (step S61). The control unit 31 displays a message on the display panel 35 prompting the user to enter a PIN for the user-certificate electronic certificate. The user enters the PIN using the operation unit 36. The control unit 31 acquires the PIN (step S62). The control unit 31 determines whether the PIN is correct (step S63). If the control unit 31 determines that the PIN is incorrect (NO in step S63), it outputs a message prompting the user to re-enter the PIN, and returns the process to step S62. If the control unit 31 determines that the PIN is correct (YES in step S63), it sends the serial number of the user-certification electronic certificate to the certification authority CA (step S64). Sending the serial number indicates a request to confirm the validity of the user-certification electronic certificate. The certification authority CA receives the serial number (step S65). The certification authority CA checks whether the user-certification electronic certificate has been revoked and sends the confirmation result to the shop terminal 3 (step S66). The control unit 31 of the shop terminal 3 receives the confirmation result (step S67). The control unit 31 determines whether the user-certification electronic certificate is valid or not based on the confirmation result (step S68). If the control unit 31 determines that the user-certification electronic certificate is invalid (NO in step S68), it displays an error message (step S69) and ends the process. If the control unit 31 determines that the user-certification electronic certificate is valid (YES in step S68), it sends the serial number of the user-certification electronic certificate to the server 1 (step S70). The control unit 11 of the server 1 receives the serial number (step S71). Moving on to Fig. 13, the control unit 11 acquires a payment ID from the associated DB 132 based on the received serial number and transmits it to the store terminal 3 (step S72). Since the serial number is hashed and stored in the associated DB 132, the control unit 11 performs a search using the hashed version of the received serial number as a search key. The control unit 31 of the store terminal 3 receives the payment ID (step S73).The control unit 31 sends a payment request (payment information) including the payment ID and payment amount to the payment service (step S74). The payment service receives the payment request (step S75). The payment service executes the payment (step S76). The payment service determines whether the payment is successful (step S77). If the payment service determines that the payment is successful (YES in step S77), it sends a success notification to the store terminal 3 (step S78). The control unit 31 of the store terminal 3 receives the success notification and displays it on the display panel 35 (step 79). At that time, the control unit 31 may print a receipt with the purchased product, price, payment amount, etc. printed on it using an external printer, etc. The control unit 31 ends the processing. If the payment service determines that the payment is unsuccessful (NO in step S77), it sends an error notification to the store terminal 3 (step S80). The control unit 31 of the store terminal 3 receives the error and displays it on the display panel 35 (step 81). The control unit 31 ends the processing. It is assumed that the payment service here is available only in limited areas, and therefore only store terminals 3 used by stores within the area are able to execute payment processing.

[0038] This embodiment provides the following advantages: Users can use services that are only available in certain regions, such as payment services. Furthermore, in payment services, users can make payments using a certificate card such as a My Number card, eliminating the need to carry around a dedicated card medium for using the service. Because the certificate card stores an electronic certificate issued by a public institution, stores can obtain highly reliable data for the four basic pieces of information.

[0039] User registration in the service providing system 100 may be in a provisional registration state until the serial number acquisition process is executed for the first time. Furthermore, since the serial number acquisition process can acquire the user's name, address, gender, and date of birth certified by a public institution, the user may be in a provisional registration state and not be able to use the payment service until the serial number acquisition process is executed in the payment service.

[0040] (Variation 1) 12 and 13, the user-certificate digital certificate is checked each time it is issued to see if it has expired, which places a heavy burden on the certification authority CA if the number of payments increases. In this variation, if the validity of the user-certificate digital certificate can be confirmed, the verification is waived for a specified period of time.

[0041] 14 and 15 are flowcharts showing another example of the procedure for the payment process. In the following explanation, differences from the payment process explained with reference to FIGS. 12 and 13 will be mainly described.

[0042] The control unit 31 of the store terminal 3 reads the user-certification electronic certificate from the certificate card (step S91). The control unit 31 acquires the PIN entered by the user (step S92). The control unit 31 determines whether the PIN is correct (step S93). If the control unit 31 determines that the PIN is incorrect (NO in step S93), it outputs a message prompting the user to re-enter the PIN, and returns the process to step S92. If the control unit 31 determines that the PIN is correct (YES in step S93), it transmits a hashed version of the serial number of the user-certification electronic certificate to the server 1 (step S94). The control unit 11 of the server 1 receives the hashed serial number (step S95). The control unit 11 determines whether the validity of the user-certification electronic certificate needs to be verified (step S96).

[0043] The determination is made in the following procedure. The control unit 11 searches the linked DB 132 using the hashed serial number as a search key, and acquires the corresponding user ID. The control unit 11 searches the confirmation date DB 134 using the acquired user ID as a search key, and acquires the date on which the electronic certificate was last revocation checked. The control unit 11 searches the period DB 133, and acquires the period for which validity check is exempt. If the service type is acquired in step S95, the control unit 11 acquires the period corresponding to that type, and if the service type is not acquired, the control unit 11 acquires the default period. The control unit 11 determines whether validity check is necessary or not based on the current date, the date of check, and the exemption period.

[0044] If the control unit 11 determines that the validity of the user-certificate electronic certificate does not need to be checked (NO in step S96), the process proceeds to step S105 in FIG. 15. If the control unit 11 determines that the validity of the user-certificate electronic certificate needs to be checked (YES in step S96), the control unit 11 transmits a message to the shop terminal 3 indicating that it needs to be checked (step S97). The control unit 31 of the shop terminal 3 receives the message indicating that it needs to be checked (step S98). Moving on to FIG. 15, the control unit 31 transmits the serial number of the user-certificate electronic certificate to the certification authority CA (step S99). The certification authority CA receives the serial number (step S100). The certification authority CA checks whether the user-certificate electronic certificate has been revoked and transmits the confirmation result to the shop terminal 3 (step S101). The control unit 31 of the shop terminal 3 receives the confirmation result (step S102). The control unit 31 determines whether the user-certificate electronic certificate is valid based on the confirmation result (step S103). If the control unit 31 determines that the user-certificate electronic certificate is invalid (NO in step S103), it displays an error message (step S104) and terminates the process. If the control unit 31 determines that the user-certificate electronic certificate is valid (YES in step S103), it transmits the hashed serial number of the user-certificate electronic certificate to the server 1 (step S105). At this time, the control unit 31 also transmits a flag indicating whether or not the validity of the user-certificate electronic certificate has been confirmed. The control unit 11 of the server 1 receives the hashed serial number (step S106). The control unit 11 determines whether or not to update the confirmation date based on the flag (step S107). If the control unit 11 determines not to update the confirmation date (NO in step S107), it proceeds to step S109. If the control unit 11 determines to update the confirmation date (YES in step S107), it updates the confirmation date of the record for the corresponding user in the confirmation date DB 134 to the current date (step S108). The control unit 11 acquires a payment ID from the linked DB 132 based on the received hashed serial number and transmits it to the store terminal 3 (step S109). The control unit 31 of the store terminal 3 receives the payment ID (step S110). The control unit 31 executes step 74 and subsequent steps in Figure 13. The subsequent processing has been described above, so a description thereof will be omitted.

[0045] In this modified example, once the validity of a user authentication certificate has been confirmed, further confirmation is omitted for a predetermined period of time thereafter, thereby reducing the burden on the certification authority CA that performs revocation confirmation.

[0046] (Variation 2) The payment processing in this modified example is almost the same as the procedures shown in Figures 12 and 13, but the method of determining whether the user-certificate electronic certificate is valid is different. In this modified example, the store terminal 3 obtains a certificate revocation list (CRL) provided daily by the certification authority CA. In Figure 12, steps S64 to S67 are unnecessary. In step S68, the control unit 31 determines whether the user-certificate electronic certificate is valid based on the certificate revocation list. If the control unit 31 is unable to obtain the certificate revocation list, it executes the processing of the first embodiment or modified example 1 described above.

[0047] In this modification, as in the first modification, it is possible to reduce the burden on the certification authority CA that performs revocation checks.

[0048] (Embodiment 2) This embodiment relates to an embodiment that can limit users to whom a service is provided. Fig. 16 is an explanatory diagram showing an example of a service DB. Service DB 135 stores conditions for users to whom a service is provided. Service DB 135 includes a service ID column, a name column, a target column, and a geographical range column. The service ID column stores a service ID that can uniquely identify a service. The name column stores the name of the service. The target column stores the type of user to whom the service is provided. The geographical range column stores the target geographical range when the target user type is a resident.

[0049] 17 and 18 are flowcharts showing an example of the procedure for the target person determination process. The target person determination process is a process for determining whether a user is a target person when a service limited to the target person is provided. The following explanation describes a case where the determination is made at the store receiving the service. The user holds the certificate card over the short-range communication unit 38 of the store terminal 3. The control unit 31 of the store terminal 3 reads the signature electronic certificate from the certificate card via the short-range communication unit 38 (step S121). The control unit 31 displays a message on the display panel 35 prompting the user to enter a personal identification number for the signature electronic certificate. The user enters the personal identification number using the operation unit 36. The control unit 31 acquires the personal identification number (step S122). The control unit 31 determines whether the personal identification number is correct (step S123). If the control unit 31 determines that the personal identification number is incorrect (NO in step S123), it outputs a message prompting the user to re-enter the personal identification number, and returns the process to step S122. If the control unit 31 determines that the PIN is correct (YES in step S123), it transmits the service ID of the service the user is about to receive to the server 1 (step S124). The control unit 11 of the server 1 receives the service ID (step S125). The control unit 11 searches the service DB 135 using the service ID as a search key to acquire information about the service recipient (step S126). Based on the acquired information, the control unit 11 determines whether or not verification of the recipient is required (step S127). Verification is required if the recipient of the service is limited to residents. If the recipient of the service is everyone and there are no limiting conditions, verification is not required. If the control unit 11 determines that verification of the recipient is not required (NO in step S127), the process proceeds to step S140 in FIG. 18. If the control unit 11 determines that verification of the recipient is required (YES in step S127), it transmits a message to the store terminal 3 indicating that verification is required (step S128). The control unit 31 of the store terminal 3 receives the message indicating that verification is required (step S129). 18, the control unit 31 transmits the serial number of the digital signature certificate to the certificate authority CA (step S130). The certificate authority CA receives the serial number (step S131). The certificate authority CA checks whether the digital signature certificate has expired, and transmits the result of the check to the store terminal 3 (step S132).The control unit 31 of the store terminal 3 receives the confirmation result (step S133). The control unit 31 determines whether the digital signature certificate is valid or not based on the confirmation result (step S134). If the user moves, the previous digital signature certificate becomes invalid, and a new digital signature certificate is issued at the new address and stored in the certificate card. If the control unit 31 determines that the digital signature certificate is invalid (NO in step S134), it displays an error message (step S141) and terminates the process. If the control unit 31 determines that the digital signature certificate is valid (YES in step S134), it sends a confirmation request to the server 1 including the user's address and service ID obtained from the digital signature certificate (step S135). The control unit 11 of the server 1 receives the confirmation request (step S136). The control unit 11 uses the service ID as a search key to compare the information about the service recipient obtained from the service DB 135 with the user's address to determine whether the user is a recipient of the service, and transmits the result to the store terminal 3 (step 137). The control unit 31 of the store terminal 3 receives the result (step S138). The control unit 31 determines whether the user is a recipient based on the result (step S139). If the control unit 31 determines that the user is a recipient (YES in step 139), it provides the service (step S140) and terminates the process. If the control unit 31 determines that the user is not a recipient (NO in step 139), it displays that the user is not a recipient (step S142) and terminates the process. The result indicating that the user is a recipient transmitted from the server 1 is an example of a command to provide the service.

[0050] In this embodiment, it is possible to provide services to limited target individuals. For example, a health management service for residents is envisioned as a service to limited target individuals.

[0051] (Embodiment 3) This embodiment relates to a form in which information is provided according to the type of user. In this embodiment, the user terminal 2 is equipped with a short-range communication unit, just like the store terminal 3. FIG. 19 is a flowchart showing an example of the procedure for information provision processing. The user holds their certificate card over the short-range communication unit of the user terminal 2. The control unit 21 of the user terminal 2 reads the signature digital certificate from the certificate card via the short-range communication unit (step S161). The control unit 21 displays a message on the display panel 25 prompting the user to enter a personal identification number for the signature digital certificate. The user enters the personal identification number using the operation unit 26. The control unit 21 acquires the personal identification number (step S162). The control unit 21 determines whether the personal identification number is correct (step S163). If the control unit 21 determines that the personal identification number is incorrect (NO in step S163), it outputs a message prompting the user to re-enter the personal identification number, and returns the process to step S162. If the control unit 21 determines that the PIN is correct (YES in step S163), it transmits the serial number of the digital signature certificate to the certification authority CA (step S164). The certification authority CA receives the serial number (step S165). The certification authority CA checks whether the digital signature certificate has been revoked and transmits the confirmation result to the user terminal 2 (step S166). The control unit 21 of the user terminal 2 receives the confirmation result (step S167). The control unit 21 determines whether the digital signature certificate is valid or not based on the confirmation result (step S168). If the control unit 21 determines that the digital signature certificate is invalid (NO in step S168), it displays an error message (step S175) and ends the process. If the control unit 21 determines that the digital signature certificate is valid (YES in step S168), it transmits an information request including the address obtained from the digital signature certificate to the server 1 (step S169). The control unit 11 of the server 1 receives the request (step S170). The control unit 11 acquires information for the user based on the address (step S171). The control unit 11 searches the service DB 135 to acquire services available to the user. The control unit 11 may access an information portal or the like to acquire information about the user's residential area. Furthermore, the control unit 11 may access a site operated by the city, ward, town, or village where the user resides based on the address to acquire information.The date of birth may also be obtained from the digital signature certificate and used when obtaining information. For example, it may be possible to provide notifications of coming-of-age ceremonies or Respect for the Aged Day celebrations only to the intended recipients. The control unit 11 transmits the obtained information to the user terminal 2 (step S172). The control unit 21 of the user terminal 2 receives the information (step S173). The control unit 21 displays the information on the display panel 25 (step S174), and ends the process.

[0052] In this embodiment, it is possible to provide information selected according to the type of user (resident, tourist), such as providing vaccination tickets only to residents, or distributing coupons that can be used at restaurants only to tourists.

[0053] In this embodiment, the user terminal 2 is used to obtain information, but this is not limiting. A store terminal 3 may be used, or a kiosk terminal installed in a convenience store or public facility may be used.

[0054] (Fourth embodiment) Similar to the second embodiment, this embodiment relates to an embodiment in which it is possible to limit users to whom a service is provided. In this embodiment, a client-server system is used in which a service server external to the service providing system 100 provides a service to a user. When a user logs in to a service, the service providing system 100 determines whether the user is a target user.

[0055] 20, 21, and 22 are flowcharts showing an example of the login process procedure. The user operates the user terminal 2 to request login to a service. The control unit 21 of the user terminal 2 sends the login request to the service server (step S191). The service server receives the login request (step S192). The service server sends a redirect command to the user terminal 2 to redirect processing to the server 1 (step S193). The control unit 21 of the user terminal 2 receives the redirect command (step S194). The control unit 21 sends an authentication request to the server 1 (step S195). The control unit 11 of the server 1 receives the authentication request (step S196). The control unit 11 sends an authentication screen to the user terminal 2 (step S197). The control unit 21 of the user terminal 2 receives the authentication screen (step S198). The user holds their certificate card over the short-range communication unit of the user terminal 2 in accordance with the instructions on the authentication screen. The control unit 21 reads the certificate card (step S199). The user inputs the PIN for the digital signature certificate using the operation unit 26. The control unit 21 acquires the PIN (step S200). Moving to FIG. 21, the control unit 21 determines whether the PIN is correct (step S201). If the control unit 21 determines that the PIN is incorrect (NO in step S201), it outputs a message prompting the user to re-enter the PIN, and returns the process to step S200. If the control unit 21 determines that the PIN is correct (YES in step S201), it sends the serial number of the digital signature certificate to the certification authority CA (step S202). The certification authority CA receives the serial number (step S203). The certification authority CA checks whether the digital signature certificate has been revoked, and sends the check result to the user terminal 2 (step S204). The control unit 21 of the user terminal 2 receives the check result (step S205). The control unit 21 determines whether the digital signature certificate is valid based on the check result (step S206). If the control unit 21 determines that the signature digital certificate is invalid (NO in step S206), it displays an error message (step S207) and terminates the process. If the control unit 21 determines that the signature digital certificate is valid (YES in step S206), it transmits the four basic information pieces obtained from the signature digital certificate to the server 1 (step S208).At that time, the control unit 21 also transmits an identifier of the service provided by the service server, for example, a service ID. The control unit 11 of the server 1 receives the basic four information (step S209). The control unit 11 confirms whether the user is a target of the service based on the basic four information and transmits the confirmation result to the user terminal 2 (step S210). The control unit 21 of the user terminal 2 receives the confirmation result (step S211). Moving to FIG. 22, the control unit 21 determines whether the user is a target of the service based on the confirmation result (step S212). If the control unit 21 determines that the user is not a target of the service (NO in step S212), it displays a "No" screen on the display panel 25 indicating that the service cannot be provided (step S213), and ends the process. If the control unit 21 determines that the user is a target of the service (YES in step S212), it transmits an authentication completion to the service server (step S214). This authentication is an example of a command to provide the service. The service server receives the authentication completion (step S215). The service server creates a screen to be displayed after login is complete, for example, a top screen (step S216). The service server sends the screen to the user terminal 2 (step S217). The control unit 21 of the user terminal 2 receives the screen and displays it on the display panel 25 (step S218). The control unit 21 ends the processing. The user can operate the screen displayed on the display panel 25 to receive services from the service server.

[0056] This embodiment has the following advantages: When a user logs in to a service server external to the service providing system 100, the service providing system 100 performs the authentication process on behalf of the user, thereby making it possible to limit the users to whom the service is provided by using the four basic pieces of information from the digital signature certificate.

[0057] In this embodiment, the four basic pieces of information are used to determine whether a user is eligible for service provision in only two ways, but the present invention is not limited to this. All users are eligible for service provision, but local residents and other users may be charged different fees. Furthermore, when multiple types of services are provided, local residents may be eligible for all services, but other users may be eligible for only some of the services.

[0058] The technical features (constituent elements) described in each embodiment can be combined with each other, and by combining them, new technical features can be formed. The embodiments disclosed herein are to be considered as illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims. Furthermore, although the claims are written in a format in which a claim cites two or more other claims (multiple claim format), this is not limited to this format. Multiple claims citing at least one other claim (multi-multi claim format) may also be written. [Explanation of symbols]

[0059] 100: Service provision system 1: Server 11: Control section 12: Main memory 13: Auxiliary storage section 131: User DB 132: Collaborative DB 133: Period DB 134: Confirmation date DB 135: Service DB 14: Communications Department 15: Reading unit 1P: Control program 1a: Portable storage medium 1b: Semiconductor memory 2: User terminal 21: Control unit 22: Main memory 23: Auxiliary storage section 24: Communications Department 25: Display panel 26:Operation section 2P: Control program 3: Store terminal 31: Control unit 32: Main memory 33: Auxiliary storage section 34: Communications Department 35: Display panel 36:Operation section 37: Imaging unit 38: Near field communication department B: Bus CA: Certificate Authority CS: Cloud Services N: Network

Claims

1. storing, in association with each other, a personal ID valid in a predetermined region and a public ID assigned to the public certificate or a unique identifier generated from the public certificate, the public ID being transmitted from the certificate authority when the validity of the public certificate is confirmed by the certificate authority; When the public ID or the identifier is received together with a request for the area-limited service, the area-limited service is provided based on the personal ID associated with the received public ID or the identifier, receiving from the certificate authority the validity of public certificates for each of the public IDs or identifiers, or receiving from the certificate authority a list of invalid public certificates; determining whether the public certificate to which the received public ID or identifier is assigned is valid based on the validity received for each public ID or identifier or based on the list; If the public certificate is determined to be valid, the service is provided based on the personal ID associated with the public ID or identifier assigned to the public certificate. An information processing method in which processing is performed by a computer.

2. determining the type of user to whom the personal ID is assigned based on the address obtained from the official certificate; If it is determined that the user type is a local resident, a command is output to instruct the user type to provide a different service from that provided to other types of users. The information processing method according to claim 1 , wherein the processing is executed by the computer.

3. selecting the service based on user attributes obtained from the public certificate; Send information about the selected service 3. The information processing method according to claim 1, wherein the processing is executed by the computer.

4. The service is a payment service, receiving the official ID or the identifier and the payment amount from a store in the area; generating payment information including the payment amount based on the received public ID or the personal ID corresponding to the identifier; Send the generated payment information to the payment provider 3. The information processing method according to claim 1, wherein the processing is executed by the computer.

5. storing a confirmation date on which the validity of the public certificate associated with the public ID or the identifier was confirmed in a storage unit in association with the public ID or the identifier; storing the service and the confirmation exemption period in a storage unit in association with each other; receiving the public ID or the identifier together with a request for the service; acquiring a confirmation date of the public ID or the public certificate associated with the identifier and the confirmation exemption period associated with the received service; If it is determined that the date falls within the confirmation exemption period based on the current date and the acquired confirmation date, the service is provided without making a valid confirmation request.

3. The information processing method according to claim 1, wherein the processing is executed by the computer.

6. storing, in association with each other, a personal ID valid in a predetermined region and a public ID assigned to the public certificate or a unique identifier generated from the public certificate, the public ID being transmitted from the certificate authority when the validity of the public certificate is confirmed by the certificate authority; When the public ID or the identifier is received together with a request for the area-limited service, the area-limited service is provided based on the personal ID associated with the received public ID or the identifier, receiving from the certificate authority the validity of public certificates for each of the public IDs or identifiers, or receiving from the certificate authority a list of invalid public certificates; determining whether the public certificate to which the received public ID or identifier is assigned is valid based on the validity received for each public ID or identifier or based on the list; If the public certificate is determined to be valid, the service is provided based on the personal ID associated with the public ID or identifier assigned to the public certificate. An information processing program that causes a computer to execute a process.

7. An information processing device including a control unit, storing, in association with each other, a personal ID valid in a predetermined region and a public ID assigned to the public certificate or a unique identifier generated from the public certificate, the public ID being transmitted from the certificate authority when the validity of the public certificate is confirmed by the certificate authority; When the public ID or the identifier is received together with a request for the area-limited service, the area-limited service is provided based on the personal ID associated with the received public ID or the identifier, receiving from the certificate authority the validity of public certificates for each of the public IDs or identifiers, or receiving from the certificate authority a list of invalid public certificates; determining whether the public certificate to which the received public ID or identifier is assigned is valid based on the validity received for each public ID or identifier or based on the list; If the public certificate is determined to be valid, the service is provided based on the personal ID associated with the public ID or identifier assigned to the public certificate. The control unit executes the process.

Citation Information

Patent Citations

  • Mobile communication apparatus and control method

    JP2004297149A

  • Information provision program, information processing device and information provision method

    JP2019133224A

  • Information processing apparatus, information processing system, information processing method, and program

    JP2022059864A

  • Data processing device and data processing method

    JP2022154916A

  • Information management server, information management method, and program

    JP2023049133A