system
The personal identification information utilization system addresses inefficiencies in identity verification by managing and confirming up-to-date user information, enhancing the efficiency and security of identity verification processes.
Patent Information
- Application Number
- JP2024161991
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2026-02-25
- Estimated Expiration
- 2040-12-28
AI Technical Summary
Identity verification processes are inefficient due to outdated user information, leading to errors and increased time and effort when starting to use new services, as the registered information is not updated and may not match the user's current details.
A personal identification information utilization system that includes a data holder device and a management device to manage the transfer of personal identification information, with authentication, confirmation, and relay mechanisms to ensure accurate and up-to-date information is provided to data users, allowing users to confirm and update their information before transmission.
The system enhances the efficiency of identity verification by preventing the use of outdated information, reducing errors, and ensuring secure, efficient identity verification processes.
Smart Images

Figure 0007819735000001 
Figure 0007819735000002 
Figure 0007819735000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a personal identification information utilization system, a management device, a personal identification information utilization method, a management method, and a program. [Background technology]
[0002] When starting to use a certain service provided by a certain business operator, identity verification may be required, for example, when opening an account at a bank, securities company, etc.
[0003] Non-Patent Document 1 discloses a technology for efficiently performing identity verification online. In this technology, when a user who has an account at a certain bank opens an account at a certain securities company, the identity is verified by comparing the identity verification information managed by the bank with the identity verification information provided by the user.
[0004] A related technique is disclosed in Patent Document 1. Patent Document 1 discloses an identity verification system having an identity verification request server, an identity verification infrastructure server, and identity guarantee servers of multiple mobile terminal communication carriers.
[0005] The identity verification request server receives a request from a user terminal and transmits a request for identity verification of the user of the user terminal to the identity verification infrastructure server. The identity verification request server then receives address information of the authentication result performed by the identity guarantee server and obtains the authentication result using the address information.
[0006] The identity verification infrastructure server receives an instruction to select one of the identity assurance servers from the user terminal, and generates a first password based on a request from the identity assurance server selected by the instruction, transmits the generated first password to the mobile terminal, and authenticates whether the second password entered from the user terminal matches the first password.
[0007] The identity assurance server stores user information for each mobile terminal user that provides communication services. If the first password and the second password match, the identity assurance server authenticates the user information entered from the user terminal by referencing the stored user information and stores the authentication result as the identity verification result. The identity assurance server then transmits the address information of the stored authentication result to the identity verification request server via the identity verification infrastructure server. [Prior art documents] [Patent documents]
[0008] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-208856 [Non-patent literature]
[0009] [Non-Patent Document 1] "Introducing the Identity Verification Support (Individual) API Service and Its Use Cases," [online], July 11, 2019, Mitsubishi UFJ Bank, [Retrieved November 20, 2020], Internet<https: / / developer.portal.bk.mufg.jp / node / 3874> Summary of the Invention [Problem to be solved by the invention]
[0010] The efficiency of identity verification work can be improved by utilizing the technology of Non-Patent Document 1. However, the present inventors have found the following problems.
[0011] Each user's identity verification information is not fixed and may change due to various factors, such as moving, changing jobs, or changing phone numbers. Identity verification information registered with banks and other institutions may not be updated and may remain outdated. For example, when opening an account at a securities company, if identity verification using such outdated identity verification information is performed and compared with identity verification information submitted by the user, an error will naturally occur. Users who do not fully understand the identity verification mechanism realized by the technology in Non-Patent Document 1 will not understand why an error occurred and will be unable to find a solution. As a result, identity verification requires a great deal of time and effort. While the following description is based on the examples of a bank and a securities company for ease of understanding, the subject matter of the present invention is not limited to these fields.
[0012] An object of the present invention is to improve the efficiency of the identity verification process that is required when starting to use a certain service. [Means for solving the problem]
[0013] According to the present invention, a data holder device that stores personal identification information of a plurality of users; and a management device that manages the transfer of the personal identification information between the data holder device and a data user device, The data holder device an authentication means for communicating with the end user's terminal that has transitioned to the login screen based on the transition information transmitted from the management device, receiving the login information, and performing authentication processing based on the login information; a confirmation means for reading out the personal identification information of the logged-in user from a storage means when the authentication process is successful, outputting the information to the terminal of the end user, and prompting the end user to confirm the personal identification information; an identity verification information transmitting means for transmitting the confirmed identity verification information to the management device when receiving confirmation information from the end user's terminal indicating that the identity verification information has been confirmed; and The management device There is provided a personal identification information utilization system having a relay means for transmitting the personal identification information received from the device of the data holder to the device of the data user.
[0014] Further, according to the present invention, a transition information transmitting means for outputting transition information for transitioning the end user's terminal to a login screen for logging in to the data storage device; a confirmation means for receiving the personal identification information of the logged-in user from the device of the data holder when the terminal of the end user that has transitioned to the login screen based on the transition information has successfully logged in to the device of the data holder via the login screen, and outputting the information to the terminal of the end user to prompt the user to confirm the personal identification information; a relay means for transmitting the confirmed identity verification information to the device of the data user when confirmation information indicating that the identity verification information has been confirmed is received from the terminal of the end user; A management device is provided having:
[0015] Further, according to the present invention, The method is executed by a personal identification information utilization system having a data holder device that stores personal identification information of a plurality of users, and a management device that manages the transfer of the personal identification information between the data holder device and a data utilization device, The data holder device communicate with the end user's terminal that has transitioned to the login screen based on the transition information transmitted from the management device, receive the login information, and perform authentication processing based on the login information; If the authentication is successful in the authentication process, the personal identification information of the logged-in user is read from the storage means, and output to the terminal of the end user, prompting the end user to confirm the personal identification information; Upon receiving confirmation information from the end user's terminal indicating that the identity verification information has been verified, the management device transmits the verified identity verification information; The management device There is also provided a method for using personal identification information, which transmits the personal identification information received from the device of the data holder to the device of the data user.
[0016] Further, according to the present invention, The computer outputting transition information for transitioning the end user's terminal to a login screen for logging in to the data holder device; When the end user's terminal, which has transitioned to the login screen based on the transition information, successfully logs in to the device of the data holder via the login screen, receives the personal identification information of the logged-in user from the device of the data holder, outputs it to the end user's terminal, and prompts the end user to confirm the personal identification information; A management method is provided in which, upon receiving confirmation information from the end user's terminal indicating that the personal identification information has been confirmed, the confirmed personal identification information is sent to the device of the data user.
[0017] Further, according to the present invention, Computer, transition information transmission means for outputting transition information for transitioning the end user's terminal to a login screen for logging in to the data storage device; a confirmation means for receiving the personal identification information of the logged-in user from the device of the data holder when the terminal of the end user that has transitioned to the login screen based on the transition information has successfully logged in to the device of the data holder via the login screen, and outputting the information to the terminal of the end user to prompt the user to confirm the personal identification information; a relay means for transmitting the confirmed identity verification information to the device of the data user when confirmation information indicating that the identity verification information has been confirmed is received from the terminal of the end user; A program is provided to function as a [Effects of the Invention]
[0018] According to the present invention, the efficiency of the identity verification process required when starting to use a certain service is improved. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a diagram for explaining an overview of a personal identification information utilization system according to an embodiment of the present invention; [Figure 2] FIG. 2 is a diagram for explaining an example of a processing flow of the personal identification information utilization system of the present embodiment. [Figure 3] 10A and 10B are diagrams for explaining an example of screen transitions realized in the personal verification information utilization system of the present embodiment. [Figure 4] FIG. 2 is a functional block diagram of a management device according to an embodiment of the present invention; [Figure 5] FIG. 2 is a functional block diagram of an example of a data holding device according to the present embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of a hardware configuration of the device according to the present embodiment. [Figure 7] FIG. 2 is a functional block diagram of a management device according to the present embodiment; [Figure 8] FIG. 2 is a diagram for explaining an example of a processing flow of the personal identification information utilization system of the present embodiment. [Figure 9] FIG. 2 is a functional block diagram of an example of a data holding device according to the present embodiment. [Figure 10] FIG. 2 is a functional block diagram of a management device according to an embodiment of the present invention; [Figure 11] FIG. 2 is a functional block diagram of a management device according to the present embodiment; DETAILED DESCRIPTION OF THE INVENTION
[0020] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In all the drawings, like components are designated by like reference numerals, and the description thereof will be omitted as appropriate.
[0021] First Embodiment "overview" First, an outline of the personal identification information utilization system of this embodiment will be described with reference to FIG.
[0022] The data user and data holder shown in the figure are entities that provide services that require identity verification at the start of use. Data user and data holder are, for example, banks, securities companies, etc., and services that require identity verification at the start of use include account opening, etc. Note that the examples given here are merely examples and are not limited to these.
[0023] The identity verification platform manages the exchange of identity verification information between the data user and the data holder. The device of the data user and the identity verification platform can share data via, for example, a specified API. The device of the data holder and the identity verification platform can also share data via, for example, a specified API.
[0024] The personal identification information utilization system of this embodiment executes a step of presenting personal identification information held by a data holder to a user and prompting the user to confirm the contents before the information is provided to the data user. Then, the personal identification information confirmed by the user is provided to the data user.
[0025] Such an identity verification information utilization system can effectively prevent the inconvenience of identity verification information that has been left out of date being provided to a data user. This can prevent inconveniences (such as errors in matching identity verification information submitted by a user) that arise from the transmission and reception of identity verification information with outdated content. As a result, the identity verification process required when starting to use a certain service becomes more efficient.
[0026] "Functional configuration of the system for using personal identification information" Next, the configuration of the identity verification information utilization system of this embodiment will be described in detail with reference to Fig. 2. The management device 10 corresponds to the identity verification platform shown in Fig. 1. The data holder device 20 is a device managed and used by the data holder shown in Fig. 1. The data user device 30 is a device managed and used by the data user shown in Fig. 1. The end user terminal 40 is a device managed and used by the user shown in Fig. 1, and examples thereof include a smartphone, a tablet terminal, a personal computer, a smartwatch, and a mobile phone.
[0027] First, as shown in (1), the end user's terminal 40 and the data user's device 30 communicate with each other, and a service start application is sent from the end user's terminal 40 to the data user's device 30. Examples of how this transmission can be achieved include, but are not limited to, processing via a web page or an application.
[0028] Figure 3 shows an example of a screen displayed on the end user's terminal 40. (1) to (8) and (11) in Figure 3 are screens presented from the data user device 30, and (9) and (10) in Figure 3 are screens presented from the data holder device 20. Note that the screen in Figure 3 is merely an example, and the content displayed on each screen, the display order of each screen, whether or not each screen is displayed, etc. can be changed within the scope that can realize the effects of the present invention.
[0029] In this figure, the data user and data holder are banks, securities companies, etc., and it is assumed that the service that requires identity verification at the start of use is account opening. When the account opening button is operated on the screen of (1) in Figure 3, a service start application is sent from the end user's terminal 40 to the data user's device 30.
[0030] Next, as shown in FIG. 2(2), the data user device 30 that has accepted the service start application transmits a request to the management device 10 for a list of data holder devices 20 that can provide personal identification information.
[0031] For example, the user may select "identity verification using identity verification information held by data holder device 20" (operating the bank API linkage button in the figure) on a screen for selecting an identity verification method as shown in (6) of Fig. 3, and then, in response to the user's agreement to the terms of use as shown in (7) of Fig. 3 (operating the consent button in the figure), data user device 30 may send the request to management device 10. Note that, as an example, screens (6) and (7) of Fig. 3 are displayed after various procedures have been performed on screens (2) to (5) of Fig. 3.
[0032] Next, as shown in (3) of FIG. 2, the management device 10 transmits to the data user device 30 a list of data holder devices 20 that can provide personal identification information.
[0033] For example, a combination of entities that can send and receive personal identification information is determined in advance (personal identification information can be sent and received between Bank A and Bank B, but not between Bank A and Bank C, etc.), and combination information indicating this combination is registered in the management device 10. Then, based on the combination information, the management device 10 identifies the data holding entity's device 20 that can provide personal identification information to the data user entity's device 30 that has sent the request (2), and sends a list of them to the data user entity's device 30.
[0034] Next, as shown in (4) of Fig. 2, the data user device 30 transmits a list of data holders that can provide personal identification information to the end user terminal 40. As a result, as shown in (8) of Fig. 3, the list of data holders that can provide personal identification information is displayed on the end user terminal 40.
[0035] Next, the end user terminal 40 accepts a user input to select one item from the list. In the following embodiment, an example will be described in which two or more items can be selected. The user selects from the list an entity (e.g., a bank where the user already has an account) with which the user's personal identification information is registered. Then, as shown as (5) in FIG. 2, information indicating the selection is sent from the end user terminal 40 to the data user device 30.
[0036] Next, as shown in (6) of FIG. 2, the data user device 30 transmits information indicating the selection received in (5) of FIG. 2 to the management device 10.
[0037] Next, as shown in (7) of FIG. 2, the management device 10 transmits transition information to the data user device 30 for redirecting the end user terminal 40 to a login screen for logging in to the selected data holder device 20. Next, as shown in (8) of FIG. 2, the data user device 30 transmits the transition information received in (7) of FIG. 2 to the end user terminal 40. Based on the received transition information, the end user terminal 40 transitions to a login screen for logging in to the data holder device 20. As a result, as shown in (9) of FIG. 3, the login screen of the data holder device 20 is displayed on the end user terminal 40. Note that, here, it is sufficient to be able to redirect the end user terminal 40 to the login screen of the selected data holder device 20, and the means for realizing this are not limited to those exemplified here.
[0038] Next, as shown in (9) of FIG. 2, the end user terminal 40 transmits the login information (ID (identifier), password, etc.) entered by the user to the data holder device 20.
[0039] Next, if the login is successful, as shown as (10) in Figure 2, the data holder device 20 reads out the user's personal identification information stored in the data holder device 20, outputs it to the end user's terminal 40, and prompts the end user to confirm the personal identification information.
[0040] For example, an information confirmation screen such as that shown in (10) of FIG. 3 is displayed on the end user's terminal 40. Note that part of the personal identification information may be hidden on the information confirmation screen. For example, some of the characters may be obscured, such as "Japan Tai●, ●● Ward, Tokyo...". This can prevent the information from being spied on or illegally obtained.
[0041] Furthermore, if the content of the personal identification information displayed on the information confirmation screen differs from the current content, the user may be notified to prompt the user to make a change. The personal identification information may also be changeable on the information confirmation screen. That is, if the displayed information confirmation information remains outdated, the user may be able to change the personal identification information from the information confirmation screen. When the data holder device 20 accepts an operation to change the personal identification information from the information confirmation screen, it updates the user's personal identification information stored in its own device based on the input content. The data holder device 20 then outputs the changed personal identification information to the end user's terminal 40 and prompts the end user to confirm the personal identification information.
[0042] Next, if the user confirms that the personal identification information is correct (if the confirmation button (10) in Figure 3 is operated), the end user's terminal 40 sends input information indicating this to the data holder device 20, as shown as (11) in Figure 2.
[0043] Thereafter, as shown in (12) of Fig. 2, the data holder device 20 transmits a notification of identity authentication to the management device 10. Then, as shown in (13) of Fig. 2, the management device 10 transmits the notification of identity authentication to the end user terminal 40.
[0044] Thereafter, as shown by (14) in Fig. 2, the end user's terminal 40 transmits a request to acquire personal information to the data user's device 30. Next, as shown by (15) in Fig. 2, the data user's device 30 transmits the received request to acquire personal information to the management device 10. Then, as shown by (16) in Fig. 2, the management device 10 transmits a request for personal verification information to the data holder's device 20.
[0045] When the data holder device 20 receives a request for personal identification information from the management device 10, it transmits the personal identification information confirmed by the user to the management device 10, as shown as (17) in Fig. 2. Note that if the personal identification information is changed on the information confirmation screen, the data holder device 20 transmits the changed personal identification information to the management device 10.
[0046] Next, as shown by (18) in FIG. 2 , the management device 10 transmits the received identity verification information to the data user device 30. Preferably, the management device 10 does not store the received identity verification information in its own nonvolatile storage device, but simply relays it between the data holder device 20 and the data user device 30. Avoiding unnecessary storage of identity verification information in multiple locations can prevent the identity verification information from being leaked or illegally acquired. Furthermore, the data holder can safely provide the identity verification information it manages to an external party. Furthermore, the management device 10 may convert the format of the identity verification information received from the data holder device 20 into a unified format and then transmit the converted identity verification information to the data user device 30. Details of the unified format are not particularly limited. For example, the unified format for a date of birth may be "YYYY-MM-DD" or the like. In this case, a date of birth expressed in a format such as "January 1, 1990" or "19900101" will be converted to "1990-01-01".
[0047] The data user device 30 acquires personal identification information from the end user terminal 40, as shown in (19) of Fig. 2. For example, a screen for photographing a personal identification document, as shown in (11) of Fig. 3, is displayed on the end user terminal 40, and the personal identification information is acquired from the screen. The timing of the process in (19) of Fig. 2 is arbitrary and is not particularly limited.
[0048] Then, the data user device 30 performs a process of comparing the identity verification information received from the data holder device 20 with the identity verification information received from the end user terminal 40. This comparison process may be a process of presenting the two pieces of identity verification information to an operator, prompting the operator to perform a verification operation, and accepting input of the comparison result, or a process of having a computer compare the two pieces of identity verification information.
[0049] The means for linking the various pieces of information transmitted and received between devices to the user who has applied to start the service is not particularly limited, and any known means can be employed.
[0050] "Functional configuration of management device 10" Next, the functional configuration of the management device 10 will be described with reference to the functional block diagram of Fig. 4. As shown in the figure, the management device 10 includes a list information transmission unit 11, a transition information transmission unit 12, and a relay unit 13.
[0051] The list information transmitting unit 11 transmits list information indicating a list of data holding subject devices 20 that can provide personal identification information to the data using subject device 30.
[0052] When the transition information sending unit 12 receives selection information indicating the data holding entity device 20 selected from the list shown in the list information from the data using entity device 30, it outputs transition information for transitioning the end user's terminal 40 to a login screen for logging in to the selected data holding entity device 20.
[0053] The relay unit 13 transmits the personal identification information received from the data holder device 20 to the data user device 30. It is preferable that the relay unit 13 does not store the personal identification information received from the data holder device 20 in a non-volatile storage device of its own device, but relays the information between the data holder device 20 and the data user device 30.
[0054] "Functional configuration of data holding device 20" Next, the functional configuration of data holder device 20 will be described using the functional block diagram of Fig. 5. As shown in the figure, data holder device 20 has an authentication unit 21, a confirmation unit 22, and an identity verification information transmission unit 23. Data holder device 20 stores identity verification information for multiple users.
[0055] The authentication unit 21 communicates with the end user's terminal 40 that has transitioned to the login screen based on the transition information transmitted from the management device 10, receives the login information, and performs authentication processing based on the login information.
[0056] If authentication is successful in the authentication process, the confirmation unit 22 reads out the identity verification information of the logged-in user from the storage means and outputs it to the end user's terminal 40 to prompt the user to confirm the identity verification information. The confirmation unit 22 can display an information confirmation screen on the end user's terminal 40, on which the identity verification information is displayed and on which part of the identity verification information is hidden. The confirmation unit 22 may also be able to accept changes to the identity verification information output to the end user's terminal 40.
[0057] When the personal identification information transmitting unit 23 receives confirmation information from the end user terminal 40 indicating that the personal identification information has been confirmed, the personal identification information transmitting unit 23 transmits the confirmed personal identification information to the management device 10. When the confirmation unit 22 accepts a change in the personal identification information, the personal identification information transmitting unit 23 transmits the changed personal identification information to the management device 10.
[0058] "Device hardware configuration" An example of the hardware configuration of each device constituting the personal identification information utilization system will be described. The personal identification information utilization system has a management device 10 and a data holder device 20. The personal identification information utilization system may further have a data user device 30. The personal identification information utilization system may also have an end user terminal 40.
[0059] 6 is a diagram showing an example of the hardware configuration of each device. Each functional unit of each device is realized by any combination of hardware and software, centered around a central processing unit (CPU) of any computer, memory, programs loaded into memory, a storage unit such as a hard disk that stores the programs (this can store programs that are pre-loaded when the device is shipped, as well as programs downloaded from storage media such as CDs (compact discs) or servers on the Internet), and a network connection interface. Those skilled in the art will understand that there are many variations in the methods and devices used to realize these functions.
[0060] As shown in FIG. 6, each device has a processor 1A, memory 2A, input / output interface 3A, peripheral circuit 4A, and bus 5A. The peripheral circuit 4A includes various modules. The notification system does not need to have the peripheral circuit 4A. Each device may be composed of multiple physically and / or logically separated devices, or may be composed of a single device that is physically and logically integrated. In the former case, each of the multiple devices that make up each device may have the above hardware configuration.
[0061] The bus 5A is a data transmission path for the processor 1A, memory 2A, peripheral circuit 4A, and input / output interface 3A to transmit and receive data to and from each other. The processor 1A is an arithmetic processing device such as a CPU or a GPU (Graphics Processing Unit). The memory 2A is a memory such as a RAM (Random Access Memory) or a ROM (Read Only Memory). The input / output interface 3A includes an interface for acquiring information from an input device, an external device, an external server, an external sensor, etc., and an interface for outputting information to an output device, an external device, an external server, etc. Examples of input devices include a keyboard, a mouse, a microphone, etc. Examples of output devices include a display, a speaker, a printer, a mailer, etc. The processor 1A can issue commands to each module and perform calculations based on the results of those calculations.
[0062] "Action and effect" The personal identification information utilization system of this embodiment executes a step of presenting personal identification information held by a data holder to a user and prompting the user to confirm the contents before the information is provided to the data user. Then, the personal identification information confirmed by the user is provided to the data user.
[0063] Such an identity verification information utilization system can effectively prevent the inconvenience of identity verification information that has been left out of date being provided to a data user. This can prevent inconveniences (such as errors in matching identity verification information submitted by a user) that arise from the transmission and reception of identity verification information with outdated content. As a result, the identity verification process required when starting to use a certain service becomes more efficient.
[0064] Furthermore, the personal identification information utilization system of this embodiment presents personal identification information held by the data holder to the user and, in the process of prompting the user to confirm the content, can display the personal identification information and an information confirmation screen on the end user's terminal in which part of the personal identification information is hidden, thereby preventing the information from being spied on or illegally obtained.
[0065] Furthermore, in the identity verification information utilization system of this embodiment, in the step of presenting identity verification information held by the data holder to the user and prompting confirmation of the information, changes to the identity verification information can be accepted. If the change is accepted, the changed identity verification information can be transmitted from the device of the data holder to the device of the data user. Because the identity verification information can be changed in the above step, the user can avoid the trouble of opening a separate page to change the identity verification information or redoing the procedure for starting service use that was previously performed from the beginning after the change.
[0066] Furthermore, in the identity verification information utilization system of this embodiment, the management device 10 does not store the identity verification information received from the data holder device in its own nonvolatile storage device, but can simply relay the information between the data holder device 20 and the data user device 30. By avoiding storing the identity verification information in many places unnecessarily, it is possible to suppress the inconvenience of identity verification information being leaked or illegally obtained. Furthermore, the data holder can provide the identity verification information it manages to an external party with peace of mind.
[0067] <Second embodiment> The personal identification information utilization system of this embodiment differs from the first embodiment in that it is possible to select multiple data holders from among multiple data holder devices 20 that can provide personal identification information to the data user device 30. For example, on the screen shown in (8) of Fig. 3, the user can select multiple data holders.
[0068] An example of a functional block diagram of the management device 10 of this embodiment is shown in Fig. 7. As shown in the figure, the management device 10 has a list information transmission unit 11, a transition information transmission unit 12, a relay unit 13, and a determination unit 14.
[0069] When the transition information transmission unit 12 receives selection information indicating that multiple data holders have been selected ((6) in Figure 2), it outputs multiple pieces of transition information for transitioning the end user's terminal 40 to multiple login screens for logging in to each of the devices 20 of the selected multiple data holders ((7) in Figure 2).
[0070] As a result, the end user's terminal 40 is redirected to the login screen of each of the selected data holders. The user then inputs login information via each login screen ((9) in FIG. 2). If the login is successful, each data holder's device 20 outputs personal identification information to the end user's terminal 40 ((10) in FIG. 2), as described in the first embodiment, and then transmits the confirmed personal identification information to the management device 10 ((13) in FIG. 2).
[0071] When the determination unit 14 receives personal identification information from each of the multiple data holder devices 20, it determines whether the multiple pieces of personal identification information match each other. If the multiple pieces of personal identification information do not match each other, the determination unit 14 notifies the multiple data holder devices 20 that are the senders of the multiple pieces of personal identification information of this fact. This allows the data holder devices 20 to recognize that the information they manage may be incorrect.
[0072] Furthermore, if the plurality of pieces of personal identification information do not match each other, the determination unit 14 determines the most reliable piece of personal identification information from the plurality of pieces of personal identification information, and can transmit the determined personal identification information to the data user's device 30 ((14) in FIG. 2). Note that if the plurality of pieces of personal identification information match each other, the determination unit 14 can transmit the determined personal identification information to the data user's device 30.
[0073] For example, the identity verification information received from the data holder device 20 may include information indicating the update date of the information, and the determination unit 14 may determine that the identity verification information with the most recent update date is the most reliable.
[0074] Additionally, the identity verification information received from the data holder device 20 may include information indicating the latest date on which the identity verification process (process (9) in FIG. 3) was performed. Then, the determination unit 14 may determine that the identity verification information with the latest date on which the verification process was performed is the most reliable.
[0075] Additionally, the personal identification information received from the data holder device 20 may include information indicating the number of times the above-mentioned personal identification information verification process (process (9) in FIG. 3) has been performed. Then, the determination unit 14 may determine that the personal identification information for which the verification process has been performed the greatest number of times has the highest reliability.
[0076] Other configurations of the personal verification information utilization system of this embodiment are the same as those of the first embodiment.
[0077] As described above, the personal identification information utilization system of this embodiment achieves the same effects as those of the first embodiment. Furthermore, the personal identification information utilization system of this embodiment can collect personal identification information from devices 20 of multiple data holders, and if the contents of the information do not match, the information with the highest reliability can be transmitted to device 30 of the data user. This can effectively prevent the inconvenience of providing personal identification information that has been left with outdated contents to the data user.
[0078] Furthermore, according to the personal identification information utilization system of this embodiment, if the personal identification information collected from a plurality of data holder devices 20 does not match, the management device 10 can notify the plurality of data holder devices 20 that are the senders of the plurality of pieces of personal identification information of that fact. This allows the data holder devices 20 to recognize that the information they manage may be incorrect.
[0079] <Third embodiment> "overview" The personal identification information utilization system of this embodiment differs from the first embodiment in that the process of the user confirming the personal identification information (screen presentation of (10) in Figure 2 and (10) in Figure 3) is performed by the management device 10 rather than the data-holding device 20.
[0080] "Functional configuration of the system for using personal identification information" Next, the configuration of the personal identification information utilization system of this embodiment will be described in detail with reference to Fig. 8. The process flow from (1) to (9) is the same as the process flow from (1) to (9) in Fig. 2 described in the first embodiment. That is, as shown in (9) in Fig. 3, the process flow is the same as that of the first embodiment up to the point where a login screen for logging in to the device 20 of the data holder selected by the user is displayed on the end user's terminal 40 and the login process is executed.
[0081] If the login to the data holder device 20 is successful, the data holder device 20 transmits a notification of identity authentication to the management device 10, as shown as (10) in Fig. 8. Thereafter, the management device 10 transmits a request for identity verification information to the data holder device 20, as shown as (11) in Fig. 8. Upon receiving the request from the management device 10, the data holder device 20 reads out the identity verification information of the user stored in the data holder device 20, and transmits the read identity verification information to the management device 10, as shown as (12) in Fig. 8.
[0082] Next, as shown as (13) in FIG. 8, the management device 10 outputs the identity verification information received from the data holder device 20 to the end user's terminal 40, prompting the end user to confirm the identity verification information. For example, the management device 10 generates an information verification screen as shown as (10) in FIG. 3 and displays it on the end user's terminal 40. Note that part of the identity verification information may be hidden on the information verification screen. For example, some of the characters may be obscured, such as "Japan Tai●, ●● Ward, Tokyo...". This can prevent the information from being intercepted or illegally obtained.
[0083] Furthermore, if the content of the personal identification information on the information confirmation screen differs from the current content, the user may be notified to prompt the user to make a change. Then, when an input to change the personal identification information is input on the information confirmation screen, the management device 10 may transition (redirect) the end user's terminal 40 to a screen (a screen for changing the personal identification information) of the data holder device 20. Furthermore, if the content of the personal identification information on the information confirmation screen differs from the current content, a screen for reselecting another data holder may be invoked. When an input to invoke the screen is made, the management device 10 notifies the data user device 30 of this fact. Then, as shown as (4) in FIG. 8, the data user device 30 performs processing from transmitting a list of data holders to which personal identification information can be provided to the end user's terminal 40 onward.
[0084] Next, if the user confirms that the personal identification information is correct, the end user's terminal 40 transmits input information indicating this to the management device 10, as shown by (14) in FIG.
[0085] Thereafter, as shown by (15) in FIG. 8 , the management device 10 transmits the identity verification information confirmed by the user to the data user device 30. The management device 10 may transmit the identity verification information received in (12) to the data user device 30, or may receive the identity verification information from the data holder device 20 again after receiving the input information in (14) and transmit the newly received identity verification information to the data user device 30. It is preferable that the management device 10 does not store the identity verification information received from the data holder device 20 in its own nonvolatile storage device, but simply relays the information between the data holder device 20 and the data user device 30. Avoiding unnecessary storage of identity verification information in multiple locations can prevent the identity verification information from being leaked or illegally acquired. Furthermore, the data holder can safely provide the identity verification information it manages to an external party. Furthermore, the management device 10 may convert the format of the identity verification information received from the data holder device 20 into a unified format, and then transmit the converted identity verification information to the data user device 30. The details of the unified format are not particularly limited. For example, the unified format for a date of birth may be "YYYY-MM-DD". In this case, a date of birth expressed in a format such as "January 1, 1990" or "19900101" is converted to "1990-01-01".
[0086] The data user device 30 acquires personal identification information from the end user terminal 40, as shown in (16) of Fig. 8. For example, a screen for photographing a personal identification document, as shown in (11) of Fig. 3, is displayed on the end user terminal 40, and the personal identification information is acquired from the screen. The timing of the process in (16) of Fig. 8 is arbitrary and is not particularly limited.
[0087] Then, the data user device 30 performs a process of comparing the identity verification information received from the data holder device 20 with the identity verification information received from the end user terminal 40. This comparison process may be a process of presenting the two pieces of identity verification information to an operator, prompting the operator to perform a verification operation, and accepting input of the comparison result, or a process of having a computer compare the two pieces of identity verification information.
[0088] "Functional configuration of data holding device 20" Next, the functional configuration of the data holder device 20 will be described using the functional block diagram of Fig. 9. As shown in the figure, the data holder device 20 has an authentication unit 21 and a personal identification information transmission unit 23.
[0089] The authentication unit 21 communicates with the end user's terminal 40 that has transitioned to the login screen based on the transition information transmitted from the management device 10, receives the login information, and performs authentication processing based on the login information. If the authentication processing is successful, the personal identification information transmission unit 23 reads the personal identification information of the logged-in user from the storage means and transmits it to the management device 10.
[0090] "Functional configuration of management device 10" Next, the functional configuration of the management device 10 will be described with reference to the functional block diagram of Fig. 10. As shown in the figure, the management device 10 includes a list information transmission unit 11, a transition information transmission unit 12, a relay unit 13, and a confirmation unit 15.
[0091] The list information transmitting unit 11 transmits list information indicating a list of data holding subject devices 20 that can provide personal identification information to the data using subject device 30.
[0092] The transition information transmission unit 12 outputs transition information for transitioning the end user's terminal 40 to a login screen for logging in to the data holder device 20. Specifically, when the transition information transmission unit 12 receives selection information indicating a data holder selected from the list indicated by the list information from the data user device 30, it outputs transition information for transitioning the end user's terminal 40 to a login screen for logging in to the selected data holder device 20.
[0093] When the end user's terminal 40, which has transitioned to the login screen based on the transition information, successfully logs in to the data holder device 20 via the login screen, the confirmation unit 15 receives the identity verification information of the logged-in user from the data holder device 20. Then, the confirmation unit 15 outputs the received identity verification information to the end user's terminal 40 to prompt the end user to confirm the identity verification information. The confirmation unit 15 can display an information verification screen on the end user's terminal 40, on which the identity verification information is displayed and on which part of the identity verification information is hidden.
[0094] When the relay unit 13 receives confirmation information from the end user's terminal 40 indicating that the identity verification information has been verified, the relay unit 13 transmits the verified identity verification information to the data user device 30. Note that it is preferable that the relay unit 13 does not store the identity verification information received from the data holder device 20 in the non-volatile storage device of its own device, but relays the information between the data holder device 20 and the data user device 30.
[0095] "Device hardware configuration" An example of the hardware configuration of each device constituting the personal verification information utilization system is the same as that of the first and second embodiments.
[0096] "Action and effect" The personal identification information utilization system of this embodiment achieves the same effects as those of the first embodiment. Furthermore, according to the personal identification information utilization system of this embodiment, the process of the user confirming the personal identification information described above can be performed by the management device 10, not by the data holder device 20. This reduces the processing load on the data holder device 20.
[0097] <Fourth embodiment> The personal identification information utilization system of this embodiment differs from the third embodiment in that it is possible to select multiple data holders from among multiple data holder devices 20 that can provide personal identification information to the data user device 30. For example, on the screen shown in (8) of Fig. 3, the user can select multiple data holders.
[0098] An example of a functional block diagram of the management device 10 of this embodiment is shown in Fig. 11. As shown in the figure, the management device 10 includes a list information transmission unit 11, a transition information transmission unit 12, a relay unit 13, a determination unit 14, and a confirmation unit 15.
[0099] When the transition information transmission unit 12 receives selection information indicating that multiple data holders have been selected ((6) in Figure 8), it outputs multiple pieces of transition information for transitioning the end user's terminal 40 to multiple login screens for logging in to each of the devices 20 of the selected multiple data holders ((7) in Figure 8).
[0100] As a result, the end user's terminal 40 is redirected to the login screen of each of the selected data holders. The user then inputs login information, etc., via each login screen ((9) in FIG. 8). If the login is successful, the device 20 of each data holder sends a notification of identity authentication ((10) in FIG. 8) and receives a request for identity verification information ((11) in FIG. 8), and then transmits identity verification information to the management device 10 ((12) in FIG. 8) as described in the third embodiment. The management device 10 then outputs the identity verification information received from the devices 20 of the multiple data holders to the end user's terminal 40, prompting the user to confirm the identity verification information ((13) in FIG. 8). For example, the management device 10 may generate an information confirmation screen that lists multiple pieces of personal identification information and display it on the end user's terminal 40, or may generate an information confirmation screen that sequentially displays multiple pieces of personal identification information and display it on the end user's terminal 40, or may generate an information confirmation screen with another configuration and display it on the end user's terminal 40.
[0101] The configuration of the determination unit 14 is the same as that described in the second embodiment, so a detailed description will be omitted here.
[0102] Other configurations of the personal verification information utilization system of this embodiment are the same as those of the third embodiment.
[0103] As described above, the personal identification information utilization system of this embodiment achieves the same effects as those of the third embodiment. Furthermore, the personal identification information utilization system of this embodiment achieves the same effects as those of the second embodiment by the determination unit 14 included in the management device 10.
[0104] Although the embodiments of the present invention have been described above with reference to the drawings, these are merely examples of the present invention, and various other configurations can also be adopted.
[0105] In this specification, "acquisition" includes at least one of the following: "the device retrieves data stored in another device or storage medium (active acquisition)" based on user input or program instructions, such as receiving data by making a request or inquiry to another device, or accessing and reading out another device or storage medium; "the device inputs data output from another device (passive acquisition)" based on user input or program instructions, such as receiving data that is distributed (or transmitted, push notification, etc.), and selecting and acquiring data from received data or information; and "the device generates new data by editing data (converting it to text, rearranging data, extracting some data, changing the file format, etc.), and then acquires the new data."
[0106] Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes. 1. A data storage device that stores the identity verification information of multiple users, and a management device that manages the transfer of the identity verification information between the data storage device and the data user device, The data holder device an authentication means for communicating with the end user's terminal that has transitioned to the login screen based on the transition information transmitted from the management device, receiving the login information, and performing authentication processing based on the login information; a confirmation means for reading out the personal identification information of the logged-in user from a storage means when the authentication process is successful, outputting the information to the terminal of the end user, and prompting the end user to confirm the personal identification information; an identity verification information transmitting means for transmitting the confirmed identity verification information to the management device when receiving confirmation information from the end user's terminal indicating that the identity verification information has been confirmed; and The management device A personal identification information utilization system having a relay means for transmitting the personal identification information received from the device of the data holder to the device of the data user. 2. The personal identification information utilization system described in 1, wherein the confirmation means displays an information confirmation screen on the end user's terminal on which the personal identification information is displayed and on which part of the personal identification information is hidden. 3. The confirmation means accepts a change to the personal identification information output to the end user's terminal, 3. The personal identification information utilization system according to 1 or 2, wherein the personal identification information transmission means transmits the changed personal identification information to the management device when the confirmation means accepts a change to the personal identification information. 4. The management device A personal identification information utilization system described in any one of 1 to 3, which does not store the personal identification information received from the data holder's device in a non-volatile memory device of its own device, but relays it between the data holder's device and the data user's device. 5. The management device a list information transmitting means for transmitting list information indicating a list of the data holders that can provide the personal identification information to the device of the data user; a transition information transmitting means for outputting, upon receiving from the device of the data user entity, selection information indicating the data holder selected from the list indicated by the list information, the transition information for transitioning the terminal of the end user to the login screen for logging in to the device of the selected data holder; 5. A system for using personal identification information according to any one of 1 to 4, comprising: 6. When the transition information transmission means receives the selection information indicating that a plurality of the data holders have been selected, the transition information transmission means outputs a plurality of pieces of transition information for transitioning the end user's terminal to a plurality of login screens for logging in to each of the devices of the selected plurality of data holders; The management device 6. The personal identification information utilization system according to 5, further comprising a determination means for determining whether the personal identification information matches each other when the personal identification information is received from each of the devices of the plurality of data holders. 7. The determination means 6. A personal identification information utilization system as described in 6, which, if the multiple pieces of personal identification information do not match each other, determines the most reliable piece of personal identification information from the multiple pieces of personal identification information and sends the determined personal identification information to the device of the data user. 8. The determination means 8. The personal identification information utilization system according to 6 or 7, wherein if the plurality of pieces of personal identification information do not match each other, the system notifies the devices of the plurality of data holders that are the senders of the plurality of pieces of personal identification information of that fact. 9. A transition information transmitting means for outputting transition information for transitioning the end user's terminal to a login screen for logging in to the data holding entity device; a confirmation means for receiving the personal identification information of the logged-in user from the device of the data holder when the terminal of the end user that has transitioned to the login screen based on the transition information has successfully logged in to the device of the data holder via the login screen, and outputting the information to the terminal of the end user to prompt the user to confirm the personal identification information; a relay means for transmitting the confirmed identity verification information to the device of the data user when confirmation information indicating that the identity verification information has been confirmed is received from the terminal of the end user; A management device having the above configuration. 10. The management device described in 9, wherein the confirmation means displays an information confirmation screen on the end user's terminal on which the personal identification information is displayed and on which part of the personal identification information is hidden. 11. A management device according to claim 9 or 10, which does not store the personal identification information received from the data holder's device in a non-volatile storage device of its own device, but relays the information between the data holder's device and the data user's device. 12. The system further comprises a list information transmitting means for transmitting list information indicating a list of data holders that can provide personal identification information to the device of the data user; The transition information transmitting means A management device described in any one of 9 to 11, which, when receiving selection information indicating the data holding entity selected from the list shown in the list information from the device of the data user entity, outputs the transition information to transition the end user's terminal to the login screen for logging in to the device of the selected data holding entity. 13. When the transition information transmission means receives the selection information indicating that a plurality of the data holders have been selected, the transition information transmission means outputs a plurality of pieces of transition information for transitioning the end user's terminal to a plurality of login screens for logging in to each of the devices of the selected plurality of data holders; when the end user's terminal has successfully logged in to each of the plurality of data holder devices via each of the plurality of login screens, the confirmation means receives the personal identification information of the logged-in user from each of the plurality of data holder devices, outputs the information to the end user's terminal, and prompts the end user to confirm the personal identification information received from each of the plurality of data holder devices; The management device described in 12 further has a judgment means for, when receiving confirmation information from the end user's terminal indicating that the multiple pieces of personal identification information have been confirmed, determining whether the multiple pieces of confirmed personal identification information match each other. 14. The determination means: A management device described in 13, which, if the multiple pieces of personal identification information do not match each other, determines the most reliable piece of personal identification information from the multiple pieces of personal identification information and sends the determined personal identification information to the device of the data user. 15. The determination means: 15. The management device according to 13 or 14, wherein, when the plurality of pieces of personal identification information do not match each other, the management device notifies the plurality of data holder devices that are the senders of the plurality of pieces of personal identification information of that fact. 16. A personal identification information utilization system including a data holder device that stores personal identification information of multiple users, and a management device that manages the transfer of the personal identification information between the data holder device and the data user device, The data holder device communicate with the end user's terminal that has transitioned to the login screen based on the transition information transmitted from the management device, receive the login information, and perform authentication processing based on the login information; If the authentication is successful in the authentication process, the personal identification information of the logged-in user is read from the storage means, and output to the terminal of the end user, prompting the end user to confirm the personal identification information; Upon receiving confirmation information from the end user's terminal indicating that the identity verification information has been verified, the management device transmits the verified identity verification information; The management device The personal identification information utilization method includes transmitting the personal identification information received from the device of the data holder to the device of the data user. 17. The computer outputting transition information for transitioning the end user's terminal to a login screen for logging in to the data holder device; When the end user's terminal, which has transitioned to the login screen based on the transition information, successfully logs in to the device of the data holder via the login screen, receives the personal identification information of the logged-in user from the device of the data holder, outputs it to the end user's terminal, and prompts the end user to confirm the personal identification information; a management method for transmitting the confirmed personal identification information to the device of the data user when confirmation information indicating that the personal identification information has been confirmed is received from the terminal of the end user; 18. Computer, transition information transmission means for outputting transition information for transitioning the end user's terminal to a login screen for logging in to the data storage device; a confirmation means for receiving the personal identification information of the logged-in user from the device of the data holder when the terminal of the end user that has transitioned to the login screen based on the transition information has successfully logged in to the device of the data holder via the login screen, and outputting the information to the terminal of the end user to prompt the user to confirm the personal identification information; a relay means for transmitting the confirmed identity verification information to the device of the data user when confirmation information indicating that the identity verification information has been confirmed is received from the terminal of the end user; A program that functions as a [Explanation of symbols]
[0107] 10 Management device 11 List information transmission unit 12 Transition information transmitter 13 Relay Section 14 Judgment section 15 Confirmation Section 20 Data holder device 21 Authentication Section 22 Verification Department 23 Personal Identification Information Transmission Department 30 Data-using devices 40 End User Terminals 1A processor 2A Memory 3A input / output I / F 4A peripheral circuit 5A Bus
Claims
1. A system that can be used jointly by multiple banks, The system comprises: a means for linking user information inputted in a user terminal with the system via a first API; a means for linking information about the user between a device managed or used by the first bank and the system via a second API; a means for updating the user information managed by the first bank when the user information is changed on the user terminal after the information about the user acquired using the second API is displayed on the user terminal; A system comprising:
2. The system according to claim 1 , wherein the information about the user includes at least one of the user's name, address, and date of birth.
3. 3. The system according to claim 1, further comprising means for obtaining an identification document of the user via the user terminal.
4. The system according to claim 1 , further comprising means for transmitting information about the user to a second bank different from the first bank after the updating process.
5. A system described in any one of claims 1 to 4, wherein the process of updating the user information managed by the first bank is updated without going through the first API.
Citation Information
Patent Citations
Identity confirmation system and identity confirmation method
JP2012208856A
Business support system, business support server, business support method and banking operation processing method
JP2017091012A
Personal information storing device and personal information managing method
JP2019061468A
Secure mobile contact system (SMCS)
KR1020170041799A
Jailed environment restricting programmatic access to multi-tenant data
US20200372576A1