Information processing system, information processing method, and information processing program

The information processing system allows users to choose and transmit permitted personal information elements with hash values, addressing the lack of user control in conventional systems and ensuring secure authentication.

JP7851793B2Active Publication Date: 2026-04-27유겐가이샤티아이에스
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
유겐가이샤티아이에스
Filing Date
2022-06-02
Publication Date
2026-04-27

AI Technical Summary

Technical Problem

Conventional authentication systems do not allow users to arbitrarily select the personal information disclosed during identity verification, limiting user control over their certificate submission.

Method used

An information processing system that includes a user device, verifier device, and issuer device, allowing users to select and transmit permitted personal information elements along with their hash values, while hiding unauthorized elements, and verifying the legitimacy of the user and issuer based on these transmissions.

Benefits of technology

Enables users to selectively disclose personal information during authentication, ensuring user control and verification integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007851793000001
    Figure 0007851793000001
  • Figure 0007851793000002
    Figure 0007851793000002
  • Figure 0007851793000003
    Figure 0007851793000003
Patent Text Reader

Abstract

To allow a user who is to be authenticated to freely select personal information to be disclosed as a certificate when required to submit a particular certificate for identity authentication.SOLUTION: An information processing system includes a user device and a verifier device. The user device includes: an acquisition unit that obtains hash values which are calculated for respective combinations of each of a plurality of elements indicating contents of personal information and a public key corresponding to the element; a reception unit that receives specification of an element to be permitted to be provided to the verifier among the elements; and a transmission unit that transmits, to the verifier device, a combination corresponding to the element to be permitted among the combinations, and does not transmit, to the verifier device, a combination corresponding to an element not to be permitted to be provided and instead, transmits, to the verifier device, a hash value corresponding to the element not to be permitted among the hash values. The verifier device includes a verification unit that performs verification based on the transmitted combination and hash value.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, an information processing method, and an information processing program.

Background Art

[0002] In recent years, the spread of communication networks has advanced, and services via communication networks are actively provided. When using such services, users may be required to prove their identity through various authentication processes. For example, when logging in to a service, when transmitting and receiving a transaction indicating a transaction or the like in blockchain technology, or when conducting a transaction or the like in a metaverse space, in order to prove that the user himself / herself is truly acting, the user performs authentication.

[0003] For example, in Patent Document 1, a certificate-issuing institution transmits a first transaction in which certificate information created based on a certificate-issuing requirement specification is stored to a blockchain network, and a user side acquires the certificate information from the identified first transaction by identifying the first transaction on the blockchain. A system is disclosed.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the above prior art, in a situation where a specific certificate is required to be submitted for authentication, the user who receives the authentication may not always be able to arbitrarily select the personal information to be disclosed as the certificate.

[0006] For example, the conventional technologies described above provide a mechanism to address potential problems that may arise when certificates are digitized, but they do not mention or suggest any control over how users can arbitrarily select the personal information to be disclosed as a certificate during the authentication process.

[0007] For these reasons, with the conventional technology described above, when users are required to submit a specific certificate for identity verification, they may not necessarily be able to arbitrarily select the personal information they disclose as the certificate.

[0008] This application was made in view of the above, and aims to provide an information processing system, information processing method, and information processing program that allow a user undergoing authentication to arbitrarily select the personal information to be disclosed as a certificate in situations where the submission of a specific certificate is required for identity verification. [Means for solving the problem]

[0009] The information processing system according to the present application is an information processing system that includes a user device which is a device of a user that uses a certificate, and a verifier device which is a device of a verifier that verifies the certificate, and comprises: an acquisition unit that acquires a hash value calculated for each combination of an element indicating the content of the user's personal information and a public key corresponding to the element; an acceptance unit that receives from the user the designation of permitted elements from among the elements that are permitted to be provided to the verifier; and a transmission unit that transmits the combinations corresponding to the permitted elements from among the combinations to the verifier device, while not transmitting the combinations corresponding to unauthorized elements that are not permitted to be provided to the verifier device, but instead transmits the hash value of the unauthorized first element from among the hash values ​​to the verifier device, and the verifier device is characterized in that it comprises a verification unit that verifies the legitimacy of the user being the provider that provided the elements, based on the combinations and hash values ​​transmitted by the transmission unit. [Effects of the Invention]

[0010] According to one embodiment of the system, in a situation where a user is required to submit a specific certificate for identity verification, the user undergoing verification can arbitrarily select the personal information to be disclosed as the certificate. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 shows an example of an information processing system according to an embodiment. [Figure 2] Figure 2 shows a specific example (1) of the information processing procedure according to the embodiment. [Figure 3] Figure 3 shows a specific example (2) of the information processing procedure according to the embodiment. [Figure 4] Figure 4 shows an example of the configuration of a user device according to an embodiment. [Figure 5] Figure 5 shows an example of the configuration of an issuer device according to this embodiment. [Figure 6] Figure 6 shows an example of the configuration of a verifier device according to the embodiment. [Figure 7] Figure 7 is an explanatory diagram illustrating the information processing method performed in response to a certificate issuance request. [Figure 8] Figure 8 is an explanatory diagram illustrating the information processing method (1) used when a token is generated in response to a certificate issuance request. [Figure 9] Figure 9 is an explanatory diagram illustrating the information processing method (2) used when a token is generated in response to a certificate issuance request. [Figure 10] Figure 10 is an explanatory diagram illustrating the information processing method (3) used when a token is generated in response to a certificate issuance request. [Figure 11] Figure 11 shows an example of a unique information database. [Figure 12] Figure 12 is an explanatory diagram illustrating the information processing methods used in response to the provision of personal information. [Figure 13] Figure 13 is an explanatory diagram illustrating the verification process based on the provided information. [Figure 14]FIG. 14 is a block diagram showing an example of the hardware configuration of an information processing apparatus according to an embodiment.

Embodiment for Carrying Out the Invention

[0012] Hereinafter, an example of a mode (hereinafter referred to as “embodiment”) for implementing an information processing system, an information processing method, and an information processing program will be described in detail with reference to the drawings. Note that the information processing system, the information processing method, the verification apparatus, and the verification program are not limited by this embodiment. In the following embodiments, the same parts are denoted by the same reference numerals, and redundant descriptions are omitted.

[0013] [Embodiment] [1. Introduction] Currently, in many systems, personal information is held on the server side. Therefore, a system (e.g., a verifier) that wants to obtain personal information acquires the access right to the server from a user (holder of personal information) who attempts to receive a service by presenting personal information, and then accesses the server to obtain personal information.

[0014] However, in the above system, the user cannot confirm whether the server is providing correct information, and also cannot confirm whether the personal information obtained by the verifier is correct.

[0015] Therefore, in the information processing system according to the proposed technology of the present application, the user side transmits basic personal information (name, date of birth, address, email address, etc.) and a public key to the issuer side to request the issuance and registration of a token. The issuer side creates a token from the information to be issued to the user (e.g., vaccine information, various license information, etc.) and the information requested from the user, creates a signature value from the data obtained by concatenating the date and time and the token, and registers the token, the signature date and time, and the signature value in the blockchain.

[0016] In this scenario, the information processing system requires the verifier to request personal information from the user. The user specifies which personal information they are willing to provide to the verifier, and provides the verifier with a set of the specified personal information and its corresponding public key, while providing any information they do not wish to share in a hashed state.

[0017] The verifiers will verify the legitimacy of the holders and issuers based on information obtained from the holders and the tokens themselves.

[0018] According to this information processing system, in situations where users are required to submit a specific certificate for identity verification, the user seeking authentication can arbitrarily select the personal information to disclose as part of the certificate. In other words, users can create a certificate containing only the personal information they deem acceptable to disclose and provide it to the verifier to receive authentication based on the certificate.

[0019] [2. System Configuration] First, the configuration of the system according to the embodiment will be explained using Figure 1. Figure 1 is a diagram showing an example of an information processing system according to the embodiment. Figure 1 shows information processing system 1 as an example of an information processing system according to the embodiment.

[0020] As shown in Figure 1, the information processing system 1 includes a user device 10, an issuer device 20, and a verifier device 30. The user device 10, the issuer device 20, and the verifier device 30 may be connected to each other via a network N, either by wired or wireless means.

[0021] The user device 10 is an information processing device belonging to the user of personal information (for example, a user who submits a certificate containing their personal information to receive a specific service and seeks to be authenticated). For example, the user device 10 accesses the issuer device 20 and the verifier device 30 in response to instructions from the user.

[0022] The issuer device 20 is an information processing device belonging to the issuer that manages the user's personal information and issues a certificate containing the personal information according to the user's needs (for example, when the user is asked to submit personal information in order to receive a specific service).

[0023] The verifier device 30 is an information processing device belonging to the verifier (for example, a provider of a specific service to a user) that requests personal information from the user and performs verification of the certificate based on the submitted personal information.

[0024] Furthermore, as shown in Figure 1, the user device 10, issuer device 20, and verifier device 30 may be cloud computers, i.e., server devices, that perform processing on the cloud side.

[0025] [3. About Actors] Next, we will describe the actors, who are individuals or organizations that have a role in the information processing system 1 according to this embodiment.

[0026] As mentioned above, actors include users, verifiers, and issuers. A user may be, for example, a person whose identity is verified when using a particular service. Examples of such users include employees whose identity is verified when logging into an internal company system, or travelers whose identity is verified when using transportation services such as airplanes or trains.

[0027] Furthermore, the verifier may be, for example, an organization that provides a specific service and requests the aforementioned users seeking to receive that service to submit a certificate containing personal information. Examples of such verifiers include airlines, railway companies, entertainment facilities (amusement parks, museums, etc.), and retail stores.

[0028] Furthermore, the issuer may be, for example, an organization that issues certificates of personal information required by the user to the user who is requested to submit such a certificate. Examples of such issuers include local governments and medical institutions.

[0029] Furthermore, according to the above example, one scenario in which the information processing system 1 is applied is when a traveler (an example of a user) who is trying to book an airplane ticket for an overseas trip is asked by the airline (an example of a verifier) ​​to submit a vaccination certificate, and therefore requests the issuance of a vaccination certificate from a health center (an issuer). In the following embodiment, the information processing realized by the information processing system 1 will be explained using such a scenario as an example.

[0030] Furthermore, the applications of Information Processing System 1 are not limited to the examples given above. Other applications include situations where applicants are required to submit documents such as a driver's license, health insurance card, or My Card. In addition, Information Processing System 1 can be applied to any situation requiring personal authentication, such as entrance examinations, employment examinations, or medical consultations at designated medical institutions.

[0031] [4. Specific Examples of Information Processing According to the Embodiment] The information processing according to this embodiment is implemented in the information processing system 1 using methods corresponding to the programs installed in the user device 10, the issuer device 20, and the verifier device 30. Figures 2 and 3 illustrate specific methods for such information processing.

[0032] Furthermore, Figures 2 and 3 illustrate specific examples of information processing procedures, using a scenario in which user U1 (traveler) who is trying to book an airplane ticket for overseas travel is asked by verifier V3 (airline) to submit proof of vaccination, and then requests the issuance of a certificate of vaccination from issuer P2 (health center).

[0033] First, Figure 2 illustrates the series of information processing steps from issuance request to integrated token generation and registration to the blockchain. Figure 2 shows a specific example (1) of the information processing procedure according to the embodiment.

[0034] In the example in Figure 2, user U1 is asked by verifier V3 to submit a certificate proving that they have been vaccinated (vaccination certificate). In this case, user U1 uses their terminal device T to request issuer P2 to issue a vaccination certificate.

[0035] The terminal device T may be implemented as, for example, a smartphone, tablet, notebook PC, desktop PC, mobile phone, PDA, etc., and may also have an application installed to enable the sending and receiving of information between it and the issuer device 20 and the verifier device 30. Such an application may be implemented as a dedicated application for accessing the issuer device 20 and the verifier device 30, or it may be a general-purpose application such as a browser.

[0036] Returning to the explanation in Figure 2, terminal device T transmits a request for issuance of a vaccination certificate to user device 10 in response to user U1's operation (step S21).

[0037] User device 10 holds various basic personal information of users, such as name, date of birth, and nationality. In other words, personal identification information may be pre-registered with user device 10 by each user.

[0038] When user device 10 receives an issuance request from terminal device T, it sends an issuance request to issuer device 20 that includes a first element indicating the specific content of user U1's personal identification information (e.g., name, date of birth, ...) (step S22). Specifically, user device 10 obtains an individual public key corresponding to user U1 for each first element and sends a first combination, which is the combination of the first element and the public key, to issuer device 20.

[0039] Figure 2 shows an example in which the user device 10 transmits to the issuer device 20, as a first combination, a combination of a first element representing the name "Suzuki Taro" and the public key PK11, and a combination of a first element representing the date of birth "1980-11-22" and the public key PK12.

[0040] Although not shown in Figure 2, the user device 10 may also acquire and transmit to the issuer device 20 a number of public keys corresponding to the number of second elements issued by the issuer device 20, which represent the content of the vaccination status certified for user U1.

[0041] When issuer device 20 receives an issuance request, it generates a single integrated token based on the first combination and unique information that issuer P2 holds about user U1 (step S23). Here, the unique information that issuer P2 holds about user U1 is, in the example of Figure 2, vaccine information indicating the vaccination status of user U1. The vaccine information includes a second element that indicates the details of the vaccination status (e.g., number of doses, last vaccination date, ...) that can be verified for user U1.

[0042] Therefore, the issuer device 20 obtains a second combination, which is a combination of a second element and a public key, by associating each of the second elements with an individual public key corresponding to user U1. The public key used here may be the one transmitted from user device 10 in step S22.

[0043] Figure 2 shows an example in which the issuer device 20 generates a second combination, which is a combination of a second element "two" indicating the number of vaccinations and the public key PK21, and a combination of a second element "2021-10-20" indicating the last vaccination date and the public key PK22.

[0044] In this state, the issuer device 20 inputs the first combination into the hash function H(m) and calculates a hash value for each first combination. Then, the issuer device 20 generates the first token "token1" by inputting concatenated information, which is the sum of each hash value, into the hash function H(m). In the example in Figure 2, the issuer device 20 is assumed to have calculated the hash value "Hash11" based on the first combination of the first element "Suzuki Taro" representing the name and the public key PK11. Furthermore, the issuer device 20 is assumed to have calculated the hash value "Hash12" based on the first combination of the first element "1980-11-22" representing the date of birth and the public key PK12.

[0045] Furthermore, the issuer device 20 inputs the second combination into the hash function H(m) and calculates a hash value for each second combination. The issuer device 20 then inputs concatenated information, which is the sum of each hash value, into the hash function H(m) to generate a second token, "token2". In the example in Figure 2, the issuer device 20 calculates the hash value "Hash21" based on the second combination of the second element "two", which indicates the number of vaccinations, and the public key PK21. The issuer device 20 also calculates the hash value "Hash22" based on the second combination of the second element "2021-10-20", which indicates the last vaccination date, and the public key PK22.

[0046] The issuer device 20 then generates a single integrated token "token12" by inputting concatenated information, which is the concatenation of the first token "token1" and the second token "token2", into the hash function H(m).

[0047] Furthermore, the issuer device 20 calculates the signature value "SIN#P2" based on the private key corresponding to issuer P2, the current date and time "signTime#P2" for performing the digital signature, and the integration token "token12" (step S24). For example, the issuer device 20 calculates the signature value "SIN#P2" by inputting concatenated information, which is the current date and time "signTime#P2" and the integration token "token12", into the function Sig(p,m), and encrypting the resulting hash value with the private key.

[0048] Then, the issuer device 20 registers the integrated token "token12", the current date and time "signTime#P2", and the signature value "SIN#P2", which serves as proof of issuer P2, with the blockchain BC (step S25). Although not shown in Figure 2, the issuer device 20 also registers the public key that is paired with the private key (the private key corresponding to issuer P2) used in the encryption in step S24.

[0049] Furthermore, in step S23, the issuer device 20 responds to the user device 10 with hash values ​​calculated for the first combination and the second combination, respectively (step S26). The issuer device 20 also responds with a second element of information that will be certified to user U1 regarding the vaccination status. The response of the second element is essentially equivalent to issuing a vaccination certificate to user U1.

[0050] Up to this point, we have used Figure 2 to explain the series of information processing steps from issuance request to integrated token generation to registration on the blockchain. In this way, once registration on the blockchain BC is complete and the user device 10 has obtained hash values ​​for each element of user U1's personal information, user U1 can request authentication of legitimacy from the verifier device 30.

[0051] For example, user U1 can request authentication using terminal device T. As shown in Figure 2, terminal device T, in response to user U1's operation, requests verification of the vaccination certificate as authentication of legitimacy (step S3).

[0052] From here, we will explain the processing procedure performed in Step 3 in more detail using Figure 3. Figure 3 illustrates a series of information processing steps from the provision of personal information to the verification process based on the provided information. Figure 3 is a diagram showing a specific example (2) of the information processing procedure according to the embodiment.

[0053] First, user U1 uses terminal device T to specify the first element of the first set of elements that is permitted to be provided to verifier V3, and also specifies the second element of the second set of elements that is permitted to be provided to verifier V3.

[0054] In such a case, terminal device T transmits the first element to be permitted and the second element to be permitted to user device 10 in response to the operation of user U1. For example, suppose user U1 thinks that it is acceptable to disclose his own name, one of the first elements, to verifier V3, and designates the first element representing his name, "Suzuki Taro," as the element to be permitted. Also, suppose user U1 thinks that it is acceptable to disclose the number of vaccinations, one of the second elements, to verifier V3, and designates the second element representing the number of vaccinations, "two," as the element to be permitted. In such a case, terminal device T transmits the first element "Suzuki Taro" and the second element "two" to user device 10.

[0055] In such a case, the user device 10 receives a designation from user U1 to permit the first element "Suzuki Taro" and the second element "two" (step S31).

[0056] The user device 10 extracts combinations from the first combination and the second combination that correspond to the elements designated as permitted, while not extracting combinations that correspond to elements not designated as permitted, and instead extracts hash values ​​(step S32).

[0057] In the example shown in Figure 1, the user device 10 extracts a first combination of the first element "Suzuki Taro" and the public key PK11 when the first element "Suzuki Taro" is designated as an authorized user. The user device 10 also extracts a second combination of the second element "two" and the public key PK21 when the second element "two" is designated as an authorized user.

[0058] On the other hand, the user device 10 does not extract combinations that are not permitted, such as the first combination of the first element "1980-11-22" and the public key PK12, or the second combination of the second element "2021-10-20" and the public key PK22. Instead, it extracts the hash values ​​("Hash12", "Hash22", etc.) corresponding to these combinations.

[0059] Furthermore, the user device 10 calculates the signature value "SIN#U1" based on the private keys associated with each of the public keys (i.e., public key PK11 and public key PK21) corresponding to the combination extracted in step S32, the current date and time "signTime#U1" specified by user U1, and the integration token "token12" (step S33). For example, the user device 10 calculates the signature value "SIN#U1" by inputting concatenated information obtained by linking the current date and time "signTime#U1" and the integration token "token12" into the function Sig(p,m), and encrypting the resulting hash value with the private key. The signature value "SIN#U1" proves the identity of user U1.

[0060] Then, the user device 10 sends the information extracted in step S32, the current date and time "signTime#U1", and the signature value "SIN#U1" to the verifier device 30 (step S34).

[0061] The verifier device 30 performs a validity verification process for the vaccination certificate based on the information extracted in step S32, the current date and time "signTime#U1", and the signature value "SIN#U1" (step S35). Specifically, the verifier device 30 performs a first verification process to verify that user U1 is the provider that provided the elements (elements designated as authorized) transmitted from user device 10. The verifier device 30 also performs a second verification process to verify that issuer P2 is the issuer of the vaccination certificate that proves the elements (elements designated as authorized) transmitted from user device 10.

[0062] For example, in the first verification process, the verifier device 30 calculates a hash value by inputting the first combination of the first element "Suzuki Taro" and the public key PK11 into the hash function H(m). Then, the verifier device 30 generates the first verification token "token♯1" by inputting concatenated information, which is the calculated hash value and the hash value extracted in place of the first combination that was not designated as permitted, into the hash function H(m).

[0063] Furthermore, the verifier device 30 calculates a hash value by inputting the second combination of the second element "two" and the public key PK21 into the hash function H(m). Then, the verifier device 30 generates a second verification token "token♯2" by inputting concatenated information, which is the calculated hash value and the hash value extracted in place of the second combination that was not designated as permitted, into the hash function H(m).

[0064] The verifier device 30 then inputs concatenated information, obtained by concatenating the first verifier token "token#1" and the second verifier token "token#2", into the hash function H(m) to generate a single unified verifier token "token#12".

[0065] Furthermore, the verifier device 30 obtains a hash value by decrypting the signature value "SIN#U1" using a single combined public key obtained by adding together the public keys PK11 and PK21 transmitted from the user device 10. Then, the verifier device 30 verifies the identity of user U1 based on a comparison of this hash value with the verification integration token "token#12".

[0066] Furthermore, in the second verification process, the verifier device 30 determines whether the integrated token "token12" registered on blockchain BC matches the verification integrated token "token#12".

[0067] If the verifier device 30 finds that the integrated token "token12" and the verification integrated token "token#12" match, it obtains a hash value by decomposing the signature value "SIN#P2" using the public key (which is a pair of public keys corresponding to the issuer P2) registered on blockchain BC. The verifier device 30 then verifies the identity of issuer P2 based on a comparison of this hash value with the verification integrated token "token#12".

[0068] [5. Configuration of the device] From here, we will describe each device according to the embodiment using Figures 4 to 6. Specifically, we will describe the user device 10, the issuer device 20, and the verifier device 30.

[0069] [5-1. User Equipment Configuration] First, the user device 10 according to the embodiment will be described using Figure 4. Figure 4 is a diagram showing an example of the configuration of the user device 10 according to the embodiment. As shown in Figure 4, the user device 10 has a communication unit 11, a storage unit 12, and a control unit 13.

[0070] (Regarding Communications Section 11) The communication unit 11 is implemented, for example, by a NIC (Network Interface Card). The communication unit 11 is connected to the network by wire or wireless connection and transmits and receives information, for example, between the issuer device 20 and the verifier device 30.

[0071] (Regarding memory unit 12) The storage unit 12 is implemented by, for example, semiconductor memory elements such as RAM (Random Access Memory) and flash memory, or storage devices such as hard disks and optical discs. The storage unit 12 has a personal identification information database 12a and a unique information database 12b.

[0072] (Regarding the personal identification information database 12a) The personal identification information database 12a stores personal identification information such as name, date of birth, and nationality as basic personal information of the user. The specific content of personal identification information such as name, date of birth, and nationality corresponds to the first element. The personal identification information database 12a stores personal identification information for each user, but in the following embodiment, an example of content focused on user U1 is shown. Note that personal identification information is an example of personal information.

[0073] (Regarding the unique information database 12b) The unique information database 12b stores unique information that the issuer possesses about the user. Examples of unique information include vaccination information, driver's license information, medication history information, educational background information, work history information, and qualification information (e.g., driver's license, language license). Taking vaccination information as an example, the specific content of unique information such as the number of vaccinations, the date of the last vaccination, and the date of issuance of the vaccination certificate corresponds to the second element. The unique information database 12b stores unique information for each user, but in the following embodiment, an example of content focused on the issuer P2, which is the health center that administered the vaccination, and the user U1 is shown. Note that unique information is an example of personal information.

[0074] (Regarding the control unit 13) The control unit 13 is implemented by a CPU (Central Processing Unit) or MPU (Micro Processing Unit), which executes various programs stored in the internal memory of the user device 10 using RAM as the working area. Alternatively, the control unit 13 can be implemented by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).

[0075] As shown in Figure 4, the control unit 13 includes a first element transmission unit 13a, a second element reception unit 13b, an acquisition unit 13c, a designation reception unit 13d, an extraction unit 13e, a calculation unit 13f, and a user information transmission unit 13g, and realizes or executes the information processing functions and operations described below. Note that the internal configuration of the control unit 13 is not limited to the configuration shown in Figure 4, and other configurations are also possible as long as they perform the information processing described later. Also, the connection relationships of the various processing units in the control unit 13 are not limited to the connection relationships shown in Figure 4, and other connection relationships are also possible.

[0076] (Regarding the first element transmission unit 13a) The first element transmission unit 13a transmits the first element to the issuer device 20 in response to a certificate issuance request (for example, a vaccination certificate) received from a user. Specifically, the first element transmission unit 13a transmits to the issuer device 20 a first combination which is a pair of the first element and the public key corresponding to the first element. The first element transmission unit 13a may, for example, perform the processing described in step S22 of Figure 2.

[0077] Furthermore, the first element transmission unit 13a may also obtain and transmit to the issuer device 20 a number of public keys corresponding to the number of second elements issued by the issuer device 20, which are second elements indicating the content of unique information certified about the user.

[0078] (Regarding the second element receiving section 13b) The second element receiving unit 13b receives information about the certificate issued by the issuer. Specifically, the second element receiving unit 13b receives the hash values ​​calculated by the issuer device 20 for the first combination and the second combination, respectively. The second element receiving unit 13b also receives a second element that indicates the content that the issuer certifies to the user. The second element receiving unit 13b may, for example, perform processing corresponding to the process described in step S26 of Figure 2.

[0079] (Regarding acquisition section 13c) The acquisition unit 13c acquires a hash value calculated for each combination of an element indicating the content of the user's personal information and the public key corresponding to that element.

[0080] For example, the acquisition unit 13c acquires a first hash value calculated for each combination, which is a pair of a first element representing the content of the personal identification information registered by the user and a public key corresponding to the first element.

[0081] Furthermore, the acquisition unit 13c acquires a second hash value calculated for each combination, which is a pair of a second element representing the content that the issuer certifies about the user and the public key corresponding to the second element.

[0082] (Regarding designated reception desk 13d) The designated reception unit 13d receives from the user the designation of elements that indicate the content of the user's personal information and which elements are permitted to be provided to the verifier.

[0083] For example, the designation reception unit 13d receives from the user the designation of the first element to be permitted to be provided to the verifier, as part of the designation of the elements to be permitted. The designation reception unit 13d also receives from the user the designation of the second element to be permitted to be provided to the verifier, as part of the designation of the elements to be permitted. The designation reception unit 13d may, for example, execute the process described in step S31 of Figure 3.

[0084] (Regarding the extraction unit 13e) The extraction unit 13e performs extraction processing according to the information received by the designated reception unit 13d. For example, the extraction unit 13e extracts combinations of elements indicating the content of the user's personal information and the corresponding public keys that correspond to those elements, while not extracting combinations that correspond to unauthorized elements that are not permitted to be provided. Instead, it extracts the hash values ​​corresponding to the unauthorized elements. The extraction unit 13e may, for example, perform the processing described in step S32 of Figure 3.

[0085] (Regarding calculation section 13f) The calculation unit 13f calculates a signature value to verify the user. The calculation unit 13f may, for example, perform the process described in step S33 of Figure 3.

[0086] (Regarding user information transmission section 13g) The user information transmission unit 13g transmits the information extracted by the extraction unit 13e and the information calculated by the calculation unit 13f to the verifier device 30.

[0087] For example, the user information transmission unit 13g transmits to the verifier device 30 combinations of elements indicating the content of the user's personal information and the corresponding public key for elements that are permitted, while for combinations corresponding to unauthorized elements that are not permitted to be provided, it does not transmit to the verifier device 30, but instead transmits the hash value corresponding to the unauthorized element to the verifier device 30.

[0088] For example, the user information transmission unit 13g transmits to the verifier device 30 combinations of the first combinations that correspond to the first element that is permitted, while not transmitting to the verifier device 30 combinations that correspond to the unauthorized first element that is not permitted to be provided. Instead, it transmits the hash value corresponding to the unauthorized first element to the verifier device 30.

[0089] Furthermore, the user information transmission unit 13g transmits to the verifier device 30 combinations of the second combinations that correspond to the authorized second element, while not transmitting to the verifier device 30 combinations that correspond to the unauthorized second element that is not permitted to be provided. Instead, it transmits the hash value corresponding to the unauthorized second element to the verifier device 30. The user information transmission unit 13g may, for example, perform the processing described in step S34 of Figure 3.

[0090] [5-2. Configuration of the Issuer Device] Next, the issuer device 20 according to the embodiment will be described with reference to Figure 5. Figure 5 is a diagram showing an example of the configuration of the issuer device 20 according to the embodiment. As shown in Figure 5, the issuer device 20 has a communication unit 21, a storage unit 22, and a control unit 23.

[0091] (Regarding Communications Section 21) The communication unit 21 is implemented, for example, by a NIC (Network Interface Card). The communication unit 21 is connected to the network by wire or wireless connection and transmits and receives information between, for example, the user device 10 and the verifier device 30.

[0092] (Regarding memory unit 22) The storage unit 22 is implemented by, for example, a semiconductor memory element such as RAM or flash memory, or a storage device such as a hard disk or optical disc. The storage unit 22 has a personal identification information database 22a and a unique information database 22b.

[0093] (Regarding the personal identification information database 22a) The personal identification information database 22a stores personal information, i.e., personal identification information, received from the user device 10. Specifically, the personal identification information database 22a stores a first combination, which is a pair of a first element and a public key corresponding to the first element.

[0094] (Regarding the unique information database 22b) The unique information database 22b stores unique information that the issuer holds about the user (for example, vaccination information, driver's license information, etc.). In other words, the unique information database 22b stores information about the certificates issued to the user.

[0095] (Regarding control unit 23) The control unit 23 is implemented by a CPU or MPU, which executes various programs stored in the internal memory of the issuer device 20 using RAM as the working area. Alternatively, the control unit 23 can be implemented by an integrated circuit such as an ASIC or FPGA.

[0096] As shown in Figure 5, the control unit 23 includes an element receiving unit 23a, a generation unit 23b, a calculation unit 23c, and a registration unit 23d, and realizes or executes the information processing functions and operations described below. Note that the internal configuration of the control unit 23 is not limited to the configuration shown in Figure 5, and other configurations are also possible as long as they perform the information processing described later. Furthermore, the connection relationships of the various processing units in the control unit 23 are not limited to the connection relationships shown in Figure 5, and other connection relationships are also possible.

[0097] (Regarding element receiving section 23a) The element receiving unit 23a receives information transmitted from the user device 10. Specifically, the element receiving unit 23a receives a first combination, which is a pair of a first element and a public key corresponding to the first element.

[0098] Furthermore, the element receiving unit 23a may also receive a number of public keys corresponding to the number of second elements issued by the issuer device 20, which are second elements indicating the content of unique information certified about the user.

[0099] (Regarding the generation unit 23b) The generation unit 23b generates tokens based on the information received by the element receiving unit 23a. For example, the generation unit 23b generates a first token by inputting concatenated information, which is obtained by concatenating each of the first hash values ​​calculated for each first combination, into a predetermined hash function. The generation unit 23b also generates a second token by inputting concatenated information, which is obtained by concatenating each of the second hash values ​​calculated for each second combination, into a predetermined hash function. Then, the generation unit 23b generates a unified token by inputting concatenated information, which is obtained by concatenating the first token and the second token, into a predetermined hash function. The generation unit 23b may, for example, perform the process described in step S23 of Figure 2.

[0100] (Regarding calculation unit 23c) The calculation unit 23c calculates a signature value to prove the issuer. For example, the calculation unit 23c calculates the issuer's signature value, which is the hash value generated based on the integration token encrypted using the issuer's private key. The calculation unit 23c may, for example, perform the process described in step S24 of Figure 2.

[0101] (Regarding registration section 23d) The registration unit 23d registers the issuer's signature value, the issuer's public key, and the integration token on the blockchain (distributed ledger) BC. The registration unit 23d may also register the date and time the signature value was calculated by the calculation unit 23c, i.e., the current date and time when the digital signature was made, on the blockchain BC. By registering the date and time when the digital signature was made, for example, it is possible to prevent the reuse of the public key by a verifier. In other words, the current date and time serves to define the expiration date of the public key.

[0102] [5-3. Configuration of the Verifier's Device] Next, the verifier device 30 according to the embodiment will be described with reference to Figure 6. Figure 6 is a diagram showing an example of the configuration of the verifier device 30 according to the embodiment. As shown in Figure 6, the verifier device 30 has a communication unit 31, a storage unit 32, and a control unit 33.

[0103] (Regarding Communications Section 31) The communication unit 31 is implemented, for example, by a NIC (Network Interface Card). The communication unit 31 is connected to the network by wire or wireless connection and transmits and receives information between, for example, the user device 10 and the issuer device 20.

[0104] (Regarding memory unit 32) The storage unit 32 is implemented by, for example, a semiconductor memory element such as RAM or flash memory, or a storage device such as a hard disk or optical disc. The storage unit 32 has a provided information database 32a.

[0105] (Regarding the provided information database 32a) The provided information database 32a stores information provided by the user (i.e., elements subject to authorization). Specifically, the provided information database 32a stores information transmitted by the user information transmission unit 13g of the user device 10.

[0106] (Regarding the control unit 33) The control unit 33 is implemented by a CPU or MPU, which executes various programs stored in the internal memory of the verifier device 30 using RAM as the working area. Alternatively, the control unit 33 can be implemented by an integrated circuit such as an ASIC or FPGA.

[0107] As shown in Figure 6, the control unit 33 includes an information receiving unit 33a, a generation unit 33b, and a verification unit 33c, and realizes or executes the information processing functions and operations described below. Note that the internal configuration of the control unit 33 is not limited to the configuration shown in Figure 6, and other configurations are also possible as long as they perform the information processing described later. Furthermore, the connection relationships of the various processing units in the control unit 33 are not limited to the connection relationships shown in Figure 6, and other connection relationships are also possible.

[0108] (Regarding Information Reception Section 33a) The information receiving unit 33a receives information provided by the user (i.e., information about the permitted elements). Specifically, the information receiving unit 33a receives information transmitted by the user information transmission unit 13g of the user device 10.

[0109] (Regarding the generation unit 33b) The generation unit 33b generates tokens based on the information received by the provided information receiving unit 33a. For example, for each first combination transmitted by the user information transmission unit 13g, the generation unit 33b generates a first verification token by inputting concatenated information, which is obtained by concatenating the hash value calculated using the first element and public key of the permitted items included in the first combination with the first hash value transmitted by the user information transmission unit 13g, into a predetermined hash function. The generation unit 33b also generates a second verification token by inputting concatenated information, which is obtained by concatenating the hash value calculated using the second element and public key of the permitted items included in the second combination with the second hash value transmitted by the user information transmission unit 13g, into a predetermined hash function for each second combination transmitted by the user information transmission unit 13g. Finally, the generation unit 33b generates a single integrated verification token by inputting concatenated information, which is obtained by concatenating the first verification token and the second verification token, into a predetermined hash function. The generation unit 33b may, for example, perform the process described in step S35 of Figure 3.

[0110] (Regarding verification section 33c) The verification unit 33c verifies the certificate. For example, the verification unit 33c verifies the legitimacy of the provider that provided the elements based on the combination and hash value transmitted by the user information transmission unit 13g.

[0111] For example, the verification unit 33c verifies the identity of the provider who provided the elements based on the first combination and first hash value transmitted by the user information transmission unit 13g. For example, the verification unit 33c verifies the legitimacy of the provider who provided the elements based on the second combination and second hash value transmitted by the user information transmission unit 13g. Specifically, the verification unit 33c obtains a hash value by decrypting the user's digital signature using a single combined public key obtained by adding up all the public keys contained in each of the first combinations transmitted by the user information transmission unit 13g and each of the second combinations transmitted by the user information transmission unit 13g, and verifies the user's legitimacy based on a comparison of the obtained hash value with the hash value representing the verification integration token.

[0112] Furthermore, if the integrated token registered on blockchain BC matches the integrated token used for verification, the verification unit 33c may use the issuer's public key to decrypt the issuer's digital signature to obtain a hash value, and further verify the legitimacy of the issuer based on a comparison of the obtained hash value with the hash value representing the integrated token used for verification.

[0113] The verification unit 33c may, for example, execute the process described in step S35 of Figure 3.

[0114] [6. Specific methods related to the verification process] From here, we will explain the specific methods of information processing according to the embodiment using Figures 7 to 13. Figures 7 to 10 explain the specific methods of a series of information processing steps from issuance request to integrated token generation to registration to the blockchain. Figures 12 and 13 explain a series of information processing steps from provision of personal information to verification processing based on the provided information.

[0115] Figures 7 to 13 provide more specific details about the contents of Figures 2 and 3. Therefore, the examples in Figures 7 to 13 illustrate the information processing method using a scenario in which user U1, who is trying to book an airplane ticket, is asked by verifier V3 to submit a vaccination certificate, and then requests issuer P2 to issue the vaccination certificate.

[0116] [6-1. From Issuance Request to Registration on the Blockchain] First, we will use Figure 7 to specifically explain the process performed in step S22 of Figure 2. Figure 7 is an explanatory diagram illustrating the information processing method performed in response to a certificate issuance request.

[0117] Figure 7(a) shows the data structure of the personal identification information database 12a corresponding to user U1. In the example in Figure 7(a), the personal identification information database 12a has items such as "user ID", "combination ID", "element name", "first element", and "public key".

[0118] A "User ID" is identification information that identifies an individual user undergoing authentication. Figure 7(a) shows an example where a User ID "U1" identifying user U1 is registered.

[0119] The "Combination ID" is identification information that identifies the first combination, which is a pair of the "First Element" and the "Public Key". The "Element Name" is information about the name of the "First Element". The "First Element" is information that indicates the first element corresponding to the "Element Name".

[0120] Figure 7(a) shows an example in which the first elements corresponding to user U1 are pre-registered in the personal identification information database 12a, including the first element "Suzuki Taro" indicating user U1's name, the first element "1980-11-22" indicating user U1's date of birth, and the first element "Japan" indicating user U1's nationality. Such registration may be performed in advance by user U1.

[0121] A "public key" is a public key associated with each of the "first elements," and is a unique public key. A "public key" is, for example, a byte array (sequence) represented in hexadecimal with a length of 32 bytes. Also, the first character of a "public key" may be "02" or "03".

[0122] Here, when the first element transmission unit 13a receives a request to issue a vaccination certificate, it associates a "public key" with each of the "first elements". For example, the first element transmission unit 13a obtains a first combination, which is a combination of a "first element" and a "public key", by generating a "public key" with unique content corresponding to each of the "first elements".

[0123] Figure 7(a) shows an example in which the first element transmission unit 13a obtains the public key "PK1-11" corresponding to the first element "Suzuki Taro" and issues "11" as a "combination ID" to identify the information (first combination) that combines the first element "Suzuki Taro" and the public key "PK1-11".

[0124] Figure 7(a) shows an example in which the first element transmission unit 13a obtains the public key "PK1-12" corresponding to the first element "1980-11-22", and then issues "12" as a "combination ID" to identify the information (first combination) that combines the first element "1980-11-22" and the public key "PK1-12".

[0125] In the example shown in Figure 7(a), each "public key" has a corresponding "private key".

[0126] Furthermore, the first element transmission unit 13a may also acquire a number of public keys corresponding to the number of second elements issued by the issuer device 20, which are second elements indicating the content of the vaccination status certified for user U1. This point will be explained in Figure 7(b).

[0127] Figure 7(b) shows the data structure of the unique information database 22b corresponding to user U1. In the example in Figure 7(b), the unique information database 22b has items such as "user ID", "combination ID", "element name", "second element", and "public key".

[0128] The "User ID" is identification information that identifies the individual user undergoing authentication. Figure 7(b) shows an example where the User ID "U1" identifying user U1 is registered.

[0129] The "Combination ID" is identification information that identifies the second combination, which is a pair of the "Second Element" and the "Public Key". The "Element Name" is information about the name of the "Second Element". The "Second Element" is information that indicates the second element corresponding to the "Element Name".

[0130] As shown in the example in Figure 7(b), the unique information database 22b stores a second element that proves that the number of times user U1 has received the vaccine is "2 times", the "last vaccination date" is "2021-10-20", and the "issuance date" is "2022-03-01", the date on which the vaccination certificate was issued to user U1.

[0131] In this example, it is understood that issuer P2 issues m vaccination certificates containing the second element to user U1. For example, if the first element transmission unit 13a refers to the unique information database 22b and recognizes that issuer P2 issues m vaccination certificates containing the second element, it may obtain m "public keys" as shown in Figure 7(b).

[0132] Figure 7(b) shows an example in which the first element transmission unit 13a obtains the public keys "PK2-21", "PK2-22", ..., "Public Key PK2-2m", etc. Each of these public keys also has a corresponding "private key". Furthermore, these m "public keys" are unique public keys that are linked to each of the "second elements". Also, the "public key" is, for example, a byte array represented in hexadecimal with a length of 32 bytes. The first character of the "public key" may be "02" or "03".

[0133] In this state, the first element transmission unit 13a transmits the first combination and m public keys to the issuer device 20. According to the example in Figure 7, the first element transmission unit 13a transmits the first combination #11, the first combination #12, the first combination #13, ... the first combination #1n to the issuer device 20. The first element transmission unit 13a also transmits the public key "PK2-21", the public key "PK2-22", ... the public key "Public Key PK2-2m" to the issuer device 20.

[0134] The transmitted information is received by the element receiving unit 23a of the issuer device 20. The issuer device 20 may associate the "public key" received by the element receiving unit 23a with each of the "second elements" as shown in Figure 7(b). Figure 7(c) shows an example of the personal identification information database 12a after it has been updated from the state shown in Figure 7(a), but this example will be described later.

[0135] Next, we will explain in detail the process performed in step S23 of Figure 2 using Figures 8 to 10.

[0136] When the generation unit 23b receives information from the element receiving unit 23a, it executes a process to generate a token. Specifically, the generation unit 23b executes a process to generate one integrated token. For example, the generation unit 23b generates a first token and a second token, and uses these tokens to generate an integrated token. Figures 8 to 10 illustrate this sequence of events.

[0137] The generation unit 23b inputs the first combination into the hash function H(m) and calculates a hash value for each first combination. Then, the generation unit 23b inputs concatenated information, which is the sum of each hash value, into the hash function H(m) to generate the first token. This point will be explained using Figure 8. Figure 8 is an explanatory diagram illustrating the information processing method (1) when a token is generated in response to a certificate issuance request.

[0138] According to the example in Figure 8(a), the generation unit 23b calculates a hash value for each of the first combinations #11, #12, #13, ..., #1n.

[0139] Let's take the first combination #11 as an example. For example, the generator 23b defines the concatenated information obtained by concatenating the first element "Suzuki Taro" and the public key "PK1-11" associated with it as the input information m for the hash function H(m). Then, the generator 23b inputs the input information m into the hash function H(m), as shown in Figure 8(a), H( <pk1-11>The formula ||bytes("Suzuki Taro")) is solved. Figure 8(a) shows an example in which the generation unit 23b solves this formula and calculates the hash value "Hash1-11".

[0140] Using a similar method, the generation unit 23b determines the concatenated information obtained by concatenating the first element contained in the first combination #12, the first combination #13, ..., the first combination #1n as input information m, and calculates the hash function H(m).

[0141] Note that the hash value calculated in Figure 8(a) is, for example, a byte array with a length of 32 bytes.

[0142] Next, as shown in Figure 8(b), the generation unit 23b determines the concatenated information, which is the sum of the hash values ​​calculated for each of the first combinations #11, #12, #13, ..., #1n, as the input information m for the hash function H(m). Then, the generation unit 23b inputs the input information m into the hash function H(m), as shown in Figure 8(b), H( <hash1-11> || <hash1-12> ||···|| <hash1-1n>The calculation formula is solved as follows. Figure 8(b) shows an example in which the generation unit 23b calculates the first token "token1" as a result of solving this formula. The first token "token1" is, for example, a byte array of length 32 bytes.

[0143] Furthermore, the generation unit 23b inputs the second combination into the hash function H(m) and calculates a hash value for each second combination. Then, the generation unit 23b generates a second token by inputting concatenated information, which is the sum of each hash value, into the hash function H(m). This point will be explained using Figure 9. Figure 9 is an explanatory diagram illustrating the information processing method (2) when a token is generated in response to a certificate issuance request.

[0144] According to the example in Figure 9(a), the generation unit 23b calculates a hash value for each of the second combinations #21, #22, #23, ..., #2m.

[0145] Let's take the second combination #21 as an example. For example, the generator 23b defines the concatenated information obtained by concatenating the second element "two" and the public key "PK2-21" associated with it as the input information m for the hash function H(m). Then, the generator 23b inputs the input information m into the hash function H(m), as shown in Figure 9(a), H( <pk2-21>The formula ||bytes("two")) is solved. Figure 9(a) shows an example in which the generation unit 23b solves this formula and calculates the hash value "Hash2-21".

[0146] Using a similar method, the generator 23b determines the concatenated information obtained by concatenating the second element contained in the second combination #22, the second combination #23, ... the second combination #2m as input information m, and calculates the hash function H(m).

[0147] Note that the hash value calculated in Figure 9(a) is, for example, a byte array with a length of 32 bytes.

[0148] Next, as shown in Figure 9(b), the generation unit 23b determines the concatenated information obtained by concatenating the hash values ​​calculated for each of the second combinations #21, #22, #23, ..., #2m as input information m to the hash function H(m). Then, the generation unit 23b inputs the input information m to the hash function H(m), as shown in Figure 9(b), H( <hash2-21> || <hash2-22> ||···|| <hash2-2m>The calculation formula is solved as follows. Figure 9(b) shows an example in which the generation unit 23b calculates the second token "token2" as a result of solving this formula. The second token "token2" is, for example, a byte array of length 32 bytes.

[0149] As explained in Figures 8 and 9, once the generation unit 23b has generated the first token and the second token, it uses these tokens to generate an integrated token. Specifically, the generation unit 23b generates a single integrated token by inputting concatenated information, which is the concatenation of the first token and the second token, into the hash function H(m). This point will be explained using Figure 10. Figure 10 is an explanatory diagram illustrating the information processing method (3) when a token is generated in response to a certificate issuance request.

[0150] As shown in Figure 10(a), the generation unit 23b generates an integrated token using the first token "token1" and the second token "token2". Specifically, the generation unit 23b defines the concatenated information obtained by concatenating the first token "token1" and the second token "token2" as the input information m for the hash function H(m). Then, the generation unit 23b inputs the input information m into the hash function H(m), as shown in Figure 10(a), H( <token1> || <token2>The calculation formula is solved as follows. Figure 10(a) shows an example in which the generation unit 23b calculates the integrated token "token12" as a result of solving this formula. The integrated token "token12" is, for example, a byte array of length 32 bytes.

[0151] Here, when the integrated token is generated by the generation unit 23b, the calculation unit 23c uses the integrated token to calculate a signature value, which is the digital signature of issuer P2. Next, the method for calculating the signature value will be explained using Figure 10. A specific example of the method for calculating the signature value is shown in Figure 10(b). The example in Figure 10(b) specifically explains the process performed in step S24 of Figure 2.

[0152] The calculation unit 23c calculates a signature value that will be the digital signature of issuer P2 based on the private key corresponding to issuer P2, the current date and time for digital signing, and the integration token. Figure 10(b) shows an example where the private key corresponding to issuer P2 is "SK#P2", the current date and time for digital signing is "signTime#P2", and the signature value is calculated using the function Sig(p,m), which outputs a signature value according to the input.

[0153] In this example, the calculation unit 23c defines the secret key "SK#P2" corresponding to the issuer P2 as the secret key p for encryption using the function Sig(p,m). The calculation unit 23c also defines the concatenation information obtained by concatenating the current date and time "signTime#P2" and the integration token "token12" as the input information m for the function Sig(p,m).

[0154] For example, the calculation unit 23c calculates the signature value by inputting concatenated information, which is the current date and time "signTime#P2" and the integration token "token12", into the function Sig(p,m), and encrypting the resulting hash value with the secret key p. Specifically, as shown in Figure 10(b), the calculation unit 23c uses Sig(<SK♯P2> ,<signTime♯P2> || <token12>The calculation formula is solved as follows. Figure 10(b) shows an example in which the calculation unit 23c solves this formula and calculates the signature value "SIN#P2" of issuer P2. The signature value "SIN#P2" is, for example, a byte array of length 72 bytes.

[0155] Furthermore, when the signature value is generated by the calculation unit 23c, the registration unit 23d registers the generated signature value with the blockchain BC. Next, the signature value registration method will be explained using Figure 10. A specific example of the signature value registration method is shown in Figure 10(c). The example in Figure 10(c) specifically explains the process performed in step S25 of Figure 2.

[0156] The registration unit 23d registers the current date and time for the electronic signature, the signature value, the public key corresponding to the issuer P2's private key, and the integration token with blockchain BC. Specifically, as shown in Figure 10(c), the registration unit 23d registers the current date and time "signTime#P2", the signature value "SIN#P2", the public key "PK#P2", and the integration token "token12" with blockchain BC. Thus, according to the information processing of this embodiment, no actual data relating to user U1 is registered with blockchain BC.

[0157] So far, we have used Figures 7 to 10 to explain the specific methods of information processing from the issuance request to registration on the blockchain. Here, for example, the generation unit 23b may respond to the user device 10 with the hash values ​​calculated for the first combination and the second combination, respectively.

[0158] For example, the generation unit 23b calculates hash values ​​for each of the first combinations #11, #12, #13, ..., #1n, and may return these calculated hash values ​​to the user device 10. The returned information may be received by the second element receiving unit 13b, which uses the received hash values ​​to update the personal identification information database 12a. As a result, the data structure of the personal identification information database 12a is updated from the state shown in Figure 7(a) to, for example, the state shown in Figure 7(c).

[0159] Furthermore, the generation unit 23b also calculates hash values ​​for each of the second combinations #21, #22, #23, ..., #2m, and may return these hash values ​​to the user device 10. For example, the generation unit 23b may return the hash values ​​with the second elements used in their calculation associated with them. The returned information may be received by the second element receiving unit 13b, which then updates the unique information database 12b using the received hash values. As a result, a unique information database 12b with a data structure as shown in Figure 11 is obtained.

[0160] Figure 11 shows an example of the unique information database 12b. The response of the second element by the generation unit 23b is essentially equivalent to issuing a vaccination certificate to user U1, and once this is registered in user U1's unique information database 12b, user U1 will be able to view and submit the vaccination certificate.

[0161] [6-2. From the provision of personal information to verification processing] From here, we will use Figures 12 and 13 to explain the series of information processing steps from the provision of personal information to the verification process based on the provided information.

[0162] First, we will use Figure 12 to specifically explain the processing performed in steps S31 to S34 of Figure 3. Figure 12 is an explanatory diagram illustrating the information processing method performed in response to the provision of personal information.

[0163] User U1 uses terminal device T to specify the first element of the first set of elements that is permitted to be provided to verifier V3, and also specifies the second element of the second set of elements that is permitted to be provided to verifier V3.

[0164] In the example in Figure 12, user U1 decides that it is acceptable to disclose the name and date of birth among the first elements to verifier V3, and designates the first element representing the name, "Suzuki Taro," and the first element representing the date of birth, "1980-11-22," as permitted.

[0165] Furthermore, in the example in Figure 12, user U1 believes that the number of vaccinations and the date of the last vaccination among the second elements may be disclosed to verifier V3, and has designated the second element "two" indicating the number of vaccinations and the second element "2021-10-20" indicating the date of the last vaccination as permitted.

[0166] In this case, terminal device T transmits information indicating the content specified by user U1, that is, information indicating that the first element of the permitted content is the name "Suzuki Taro" and the date of birth "1980-11-22", to user device 10.

[0167] Furthermore, terminal device T transmits information to user device 10 indicating that the content specified by user U2 is the second element of the permitted item, namely the number of vaccinations "two" and the last vaccination date "2021-10-20".

[0168] The designation reception unit 13d of the user device 10 receives the designation of the first element to be permitted from user U1. According to the above example, the designation reception unit 13d receives information from the user device 10 indicating that the first element to be permitted is the name "Suzuki Taro" and the date of birth "1980-11-22".

[0169] Furthermore, the designated reception unit 13d receives the designation of the second element subject to authorization from user U1. According to the above example, the designated reception unit 13d receives information from user device 10 indicating that the second element subject to authorization is the number of vaccinations "two" and the last vaccination date "2021-10-20".

[0170] When the user device 10 receives a designation from the designation reception unit 13d, the extraction unit 13e of the user device 10 extracts information to be provided to the verifier V3 according to the content specified by the user U1. Specifically, the extraction unit 13e extracts information to be transmitted to the verifier device 30 from the personal identification information database 12a, in which the first element is registered, and the unique information database 12b, in which the second element is registered, according to the content specified by the user U1.

[0171] The extraction unit 13e extracts combinations of elements indicating the content of user U1's personal information and the corresponding public keys for elements that are permitted, but does not extract combinations for unauthorized elements that are not permitted to be provided. Instead, it extracts the hash values ​​corresponding to the unauthorized elements.

[0172] As shown in Figure 12(a), the extraction unit 13e extracts the first combination #11 of the first element "Suzuki Taro" and the public key "PK1-11" from the personal identification information database 12a in response to the first element "Suzuki Taro" being designated as an authorized target. Furthermore, the extraction unit 13e extracts the first combination #12 of the first element "1980-11-22" and the public key "PK1-12" from the personal identification information database 12a in response to the first element "1980-11-22" being designated as an authorized target.

[0173] On the other hand, the extraction unit 13e does not extract the first combinations corresponding to unauthorized first elements that are not permitted to be provided. Specifically, the extraction unit 13e does not extract the first combinations #13 to #1n. Instead, as shown in Figure 12(a), the extraction unit 13e extracts the hash values ​​"Hash1-13 to Hash1-1n" corresponding to the first combinations #13 to #1n, respectively, from the personal identification information database 12a.

[0174] Furthermore, as shown in Figure 12(b), the extraction unit 13e extracts a second combination #21 of the second element "two" and the public key "PK2-21" from the unique information database 12b, in response to the second element "two" being designated as an authorized target. Also, the extraction unit 13e extracts a second combination #22 of the second element "2021-10-20" and the public key "PK2-22" from the unique information database 12b, in response to the second element "2021-10-20" being designated as an authorized target.

[0175] On the other hand, the extraction unit 13e does not extract second combinations corresponding to unauthorized second elements that are not permitted to be provided. Specifically, the extraction unit 13e does not extract second combinations #23 to #2m. Instead, as shown in Figure 12(b), the extraction unit 13e extracts hash values ​​"Hash2-23 to Hash2-2m" corresponding to each of the second combinations #23 to #2m from the unique information database 12b.

[0176] Here, the calculation unit 13f of the user device 10 calculates the signature value, which will be the electronic signature of user U1, using the integrated token generated by the generation unit 23b. Next, the method for calculating the signature value will be explained using Figure 12. A specific example of the method for calculating the signature value is shown in Figure 12(c). The example in Figure 12(c) specifically explains the process performed in step S33 of Figure 3.

[0177] The calculation unit 13f calculates the signature value that will be the digital signature of user U1 based on the private key corresponding to user U1, the current date and time for performing the digital signature, and the integrated token. The private key corresponding to user U1 is the private key corresponding to each public key extracted by the extraction unit 13e for provision to the verifier V3.

[0178] According to the examples in Figures 12(a) and 12(b), the private keys corresponding to user U1 are the private keys corresponding to the public keys "PK1-11", "PK1-12", "PK2-21", and "PK2-22". More specifically, the private key corresponding to user U1 may be a single combined private key obtained by adding these four private keys together. Figure 12(c) shows an example where the private key corresponding to user U1 is "SK#U1".

[0179] Furthermore, Figure 12(c) shows an example where the current date and time for performing the digital signature is "signTime#U1", and the signature value is calculated using the function Sig(p,m), which outputs the signature value according to the input.

[0180] In this example, the calculation unit 13f defines the secret key "SK#U1" corresponding to user U1 as the secret key p for encryption using the function Sig(p,m). The calculation unit 13f also defines the concatenated information obtained by concatenating the current date and time "signTime#U1" and the integration token "token12" as the input information m for the function Sig(p,m).

[0181] For example, the calculation unit 13f calculates the signature value by inputting concatenated information, which is the current date and time "signTime#U1" and the integration token "token12", into the function Sig(p,m), and encrypting the resulting hash value with the secret key p. Specifically, as shown in Figure 12(c), the calculation unit 13f uses Sig(<SK♯U1> ,<signTime♯U1> || <token12>The calculation formula is solved as follows. Figure 12(c) shows an example in which the calculation unit 13f calculates the signature value "SIN#U1" of user U1 as a result of solving this formula. The signature value "SIN#U1" is, for example, a byte array of length 72 bytes.

[0182] As shown in the example in Figure 12(c), the calculation unit 13f generates a single combined secret key "SK#U1" by utilizing the additive homomorphism of elliptic curve cryptography. With this method, regardless of the pattern of elements disclosed by user U1 to verifier V3, it is only necessary to generate a single signature value "SK#U1", eliminating the need to generate a signature value for each element, for example. Therefore, the information processing according to this embodiment has the advantage of eliminating the complexity of electronic signatures.

[0183] Furthermore, as shown in Figure 12, the user information transmission unit 13g transmits the information extracted by the extraction unit 13e, the current date and time "signTime#U1", and the signature value "SIN#U1" to the verifier device 30. This process corresponds to the process in step S34 of Figure 3. As a result, the verifier device 30 can obtain the data structure shown in Figure 12 in the provided information database 32a.

[0184] Next, we will use Figure 13 to specifically explain the process performed in step S35 of Figure 3. Figure 13 is an explanatory diagram illustrating the method of verification processing based on the provided information.

[0185] When the verification unit 33c of the verifier device 30 receives information from user U1, it generates a verification token based on the provided information (various types of provided information registered in the provided information database 32a).

[0186] First, as shown in Figure 13(a), the verification unit 33c calculates a hash value based on the "provided element" and the "provided public key". Specifically, for each first combination transmitted by the user information transmission unit 13g, the verification unit 33c calculates a hash value using the first element and public key of the permitted object included in the first combination. Furthermore, for each second combination transmitted by the user information transmission unit 13g, the verification unit 33c calculates a hash value using the second element and public key of the permitted object included in the second combination.

[0187] According to the example in Figure 13(a), the verification unit 33c calculates a hash value based on the one authorized element "Suzuki Taro" included in the first combination #11 and the public key "PK1-11" associated with it. Specifically, the verification unit 33c calculates a hash value by inputting concatenation information (input information m), which is the concatenation of the first element "Suzuki Taro" and the public key "PK1-11", into the hash function H(m). Figure 13(a) shows an example in which the verification unit 33c calculates the hash value "Hash1-11".

[0188] Similarly, the verification unit 33c calculates a hash value based on the one authorized element "1980-11-22" included in the first combination #12 and the public key "PK1-12" associated with it. Specifically, the verification unit 33c calculates a hash value by inputting concatenation information (input information m), which is the concatenation of the first element "1980-11-22" and the public key "PK1-12", into the hash function H(m). Figure 13(a) shows an example in which the verification unit 33c calculates the hash value "Hash1-12".

[0189] The hash value calculation method used here is the same as the method explained in Figure 8(a).

[0190] Furthermore, as shown in the example in Figure 13(a), the verification unit 33c calculates a hash value based on the two permitted elements "two" included in the second combination #21 and the corresponding public key "PK2-21". Specifically, the verification unit 33c calculates a hash value by inputting concatenation information (input information m), which is the concatenation of the second element "two" and the public key "PK2-21", into the hash function H(m). Figure 13(a) shows an example in which the verification unit 33c calculates the hash value "Hash2-21".

[0191] Similarly, the verification unit 33c calculates a hash value based on the two permitted elements "2021-10-20" included in the second combination #22 and the corresponding public key "PK2-22". Specifically, the verification unit 33c calculates a hash value by inputting concatenated information (input information m), which is the concatenation of the second element "2021-10-20" and the public key "PK2-22", into the hash function H(m). Figure 13(a) shows an example of the verification unit 33c calculating the hash value "Hash2-22".

[0192] Next, as shown in Figure 13(b), the verification unit 33c inputs concatenated information (input information m), which is the sum of the hash values ​​calculated for the first combination #11 and the first combination #12, as well as the hash values ​​(Hash1-13 to Hash1-1n) that were sent instead of the first combinations because they were not designated as permitted, into the hash function H(m). Then, the verification unit 33c generates the first verification token by solving the calculation formula shown in Figure 13(b). Figure 13(b) shows an example in which the verification unit 33c calculates the first verification token "token #1". The token generation method used here is the same as the method explained in Figure 8(b).

[0193] Furthermore, as shown in Figure 13(b), the verification unit 33c inputs concatenated information (input information m), which is the sum of the hash values ​​calculated for the second combination #21 and the second combination #22, as well as the hash values ​​(Hash2-23 to Hash2-2m) that were sent instead of the second combination because they were not designated as permitted, into the hash function H(m). The verification unit 33c then generates a second verification token by solving the calculation formula shown in Figure 13(b). Figure 13(b) shows an example in which the verification unit 33c calculates the second verification token "token #2". The token generation method used here is the same as the method explained in Figure 9(b).

[0194] Then, as shown in Figure 13(c), the verification unit 33c generates a unified verification token using the first verification token "token #1" and the second verification token "token #2". Specifically, the verification unit 33c inputs concatenation information (input information m), which is the concatenation of the first verification token "token #1" and the second verification token "token #2", into the hash function H(m). Then, the verification unit 33c generates one unified verification token by solving the calculation formula shown in Figure 13(b). Figure 13(c) shows an example in which the verification unit 33c calculates the unified verification token "token #13". The token generation method used here is the same as the method explained in Figure 10(a).

[0195] The verification unit 33c performs a first verification process using the verification integration token "token#13" to verify that the provider of the element (the element designated as authorized) transmitted from the user device 10 is user U1. The verification unit 33c also performs a second verification process using the verification integration token "token#13" to verify that the issuer of the vaccination certificate that proves the element (the element designated as authorized) transmitted from the user device 10 is issuer P2.

[0196] For example, in the first verification process, the verification unit 33c obtains a combined public key by adding together the public keys (provided public keys) transmitted by the user information transmission unit 13g, specifically public keys PK1-11, 1-12, 2-21, and 2-22. The verification unit 33c then obtains a hash value by decrypting the signature value "SIN#U1" of user U1 using the combined public key. The verifier device 30 then verifies the identity of user U1 based on a comparison of this hash value with the hash value indicated by the verification integration token "token#12".

[0197] Furthermore, the verification unit 33c determines whether the integrated token "token12" registered on blockchain BC matches the verification integrated token "token#12". If the integrated token "token12" and the verification integrated token "token#12" match, the verification unit 33c obtains a hash value by decomposing the issuer P2's signature value "SIN#P2" using the public key PK#P2 registered on blockchain BC. The verifier device 30 then verifies the identity of issuer P2 based on a comparison of this hash value with the verification integrated token "token#12".

[0198] [7. Summary] Up to this point, we have explained in detail, using diagrams, the information processing implemented by Information Processing System 1. With Information Processing System 1, in situations where the submission of a specific certificate is required for identity verification, the user seeking authentication can arbitrarily select the personal information to be disclosed as part of the certificate. In other words, the user can create a certificate containing only the personal information they deem acceptable to disclose and provide this certificate to the verifier, thereby receiving authentication based on the certificate.

[0199] [8. Hardware Configuration] Next, an example of the hardware configuration of the information processing device (user device 10, issuer device 20, verifier device 30) according to the embodiment will be described. Figure 14 is a block diagram showing an example of the hardware configuration of the information processing device according to the embodiment. Referring to Figure 14, the information processing device includes, for example, a processor 801, a ROM 802, a RAM 803, a host bus 804, a bridge 805, an external bus 806, an interface 807, an input device 808, an output device 809, a storage device 810, a drive 811, a connection port 812, and a communication device 813. Note that the hardware configuration shown here is just an example, and some of the components may be omitted. Furthermore, it may also include components other than those shown here.

[0200] (Processor 801) The processor 801 functions, for example, as an arithmetic processing unit or a control unit, and controls the overall operation or part of the operation of each component based on various programs recorded in the ROM 802, RAM 803, storage 810, or removable recording medium 901.

[0201] (ROM802, RAM803) ROM 802 is a means of storing programs loaded into the processor 801 and data used for calculations. RAM 803 temporarily or permanently stores, for example, programs loaded into the processor 801 and various parameters that change as needed when executing those programs.

[0202] (Host bus 804, bridge 805, external bus 806, interface 807) The processor 801, ROM 802, and RAM 803 are interconnected, for example, via a host bus 804 capable of high-speed data transmission. On the other hand, the host bus 804 is connected to an external bus 806, which has a relatively low data transmission speed, via a bridge 805. The external bus 806 is also connected to various components via an interface 807.

[0203] (Input device 808) Input devices 808 may include, for example, a mouse, keyboard, touch panel, buttons, switches, and levers. Furthermore, a remote controller (hereinafter referred to as a remote control) capable of transmitting control signals using infrared or other radio waves may also be used as an input device 808. Additionally, input devices 808 may include audio input devices such as microphones.

[0204] (Output device 809) The output device 809 is a device capable of visually or audibly notifying the user of acquired information, such as a display device like a CRT (Cathode Ray Tube), LCD, or organic EL; an audio output device like a speaker or headphones; a printer, a mobile phone, or a facsimile. Furthermore, the output device 809 according to this embodiment includes various vibration devices capable of outputting tactile stimuli.

[0205] (Storage 810) Storage 810 is a device for storing various types of data. Examples of storage devices that can be used for storage 810 include magnetic storage devices such as hard disk drives (HDDs), semiconductor storage devices, optical storage devices, or magneto-optical storage devices.

[0206] (Drive 811) The drive 811 is a device that reads information recorded on a removable recording medium 901, such as a magnetic disk, optical disk, magneto-optical disk, or semiconductor memory, or writes information to the removable recording medium 901.

[0207] (Connection port 812) Connection port 812 is a port for connecting external devices 902, such as a USB (Universal Serial Bus) port, IEEE1394 port, SCSI (Small Computer System Interface), RS-232C port, or optical audio terminal.

[0208] (Communication device 813) The communication device 813 is a communication device for connecting to a network, and may include, for example, a communication card for wired or wireless LAN, Bluetooth®, or WUSB (Wireless USB), a router for optical communication, a router for ADSL (Asymmetric Digital Subscriber Line), or a modem for various types of communication.

[0209] (Removable recording medium 901) The removable recording medium 901 may be, for example, DVD media, Blu-ray® media, HD DVD media, or various semiconductor storage media. Of course, the removable recording medium 901 may also be, for example, an IC card equipped with a contactless IC chip, or an electronic device.

[0210] (External connection device 902) External connected devices 902 include, for example, a printer, a portable music player, a digital camera, a digital video camera, or an IC recorder.

[0211] Taking the verifier device 30 as an example, the memory unit 32 is realized by ROM 802, RAM 803, and storage 810. Furthermore, the control unit 33 according to the embodiment, which is realized by the processor 801, reads and executes the control programs (for example, the verification program according to the embodiment) that realize the provided information receiving unit 33a, the generation unit 33b, and the verification unit 33c from ROM 802, RAM 803, etc.

[0212] [9. Other] Of the processes described above as being performed automatically, all or part of them may be performed manually. Furthermore, all or part of the processes described as being performed manually may be performed automatically using known methods. In addition, the processing procedures, specific names, and various data and parameters shown in the above documents and drawings may be changed at will unless otherwise specified. For example, the various information shown in each drawing is not limited to the information illustrated.

[0213] Furthermore, each component of the illustrated device is a functional concept and does not necessarily have to be physically configured as shown. In other words, the specific forms of distribution and integration of each device are not limited to those shown. Moreover, each component may be configured by functionally or physically distributing and integrating all or part of it in any unit, depending on various loads and usage conditions. In addition, the processes described above may be combined and executed as appropriate, within a non-contradictory range.

[0214] Although embodiments of the present application have been described in detail above with reference to several drawings, these are illustrative examples, and the present invention can be implemented in various other forms with modifications and improvements based on the knowledge of those skilled in the art, starting with the embodiments described in the disclosure section of the invention. [Explanation of Symbols]

[0215] 1. Information Processing System 10 User equipment 12 Storage section 12a Personal Identification Information Database 12b Unique Information Database 13 Control Unit 13a First element transmission unit 13b Second element receiving section 13c acquisition part 13d Designated Reception Desk 13e Extraction part 13f Calculation section 13g User Information Transmission Unit 20 Issuer device 22 Memory section 22a Personal Identification Information Database 22b Unique Information Database 23 Control Unit 23a Element receiving section 23b Generator 23c Calculation part 23d Registration Department 30 Verifier device 32 Storage section 32a Provided Information Database 33 Control Unit 33a Information Reception Department 33b Generator 33c Verification Department < / token1> < / hash2-22> < / hash2-21> < / hash1-12> < / hash1-11>

Claims

1. An information processing system including a user device, which is the device of a user who uses a certificate, and a verifier device, which is the device of a verifier who verifies the certificate, The user device is An acquisition unit that acquires a hash value calculated for each combination of an element indicating the content of the user's personal information and a public key corresponding to the element, A receiving unit that receives from the user the designation of the elements to be permitted to be provided to the verifier, Of the aforementioned combinations, the transmission unit transmits the combinations corresponding to the permitted elements to the verifier device, while, for combinations corresponding to unauthorized elements that are not permitted to be provided, it does not transmit them to the verifier device, but instead transmits the hash value of the hash value corresponding to the unauthorized element to the verifier device. It has, The aforementioned verifier device is A verification unit verifies the legitimacy of the provider who provided the elements being the user, based on the combination and hash value transmitted by the transmission unit. has An information processing system characterized by the following:

2. The acquisition unit is, As the hash value calculated for each of the above combinations, a first hash value is obtained for each first combination which is a pair of a first element representing the content of the personal identification information registered by the user and a public key corresponding to the first element. The aforementioned reception unit is As for the designation of the permitted elements, the user designates the first element from the first elements that is permitted to be provided to the verifier. The aforementioned transmitting unit Of the first combinations, the combinations corresponding to the first element that are permitted are transmitted to the verifier device, while the combinations corresponding to the unauthorized first element that are not permitted to be provided are not transmitted to the verifier device. Instead, the hash value of the first hash value corresponding to the unauthorized first element is transmitted to the verifier device. The verification unit, Based on the first combination and the first hash value transmitted by the transmitting unit, the legitimacy of the provider who provided the elements being the user is verified. The information processing system according to feature 1.

3. The aforementioned information processing system is It further includes an issuer device, which is an issuer device that issues certificates, The acquisition unit is, As the hash value calculated for each of the above combinations, a second hash value is obtained for each second combination, which is a pair of a second element indicating the content that the issuer certifies about the user and a public key corresponding to the second element. The aforementioned reception unit is As for the designation of the permitted elements, the user designates the second elements of the second elements that are permitted to be provided to the verifier. The aforementioned transmitting unit Of the second combinations, the combinations corresponding to the authorized second element are transmitted to the verifier device, while the combinations corresponding to the unauthorized second element that is not permitted to be provided are not transmitted to the verifier device. Instead, the hash value of the second hash value corresponding to the unauthorized second element is transmitted to the verifier device. The verification unit, Based on the second combination and the second hash value transmitted by the transmitting unit, the legitimacy of the provider who provided the elements being the user is verified. The information processing system according to feature 2.

4. The aforementioned issuer device is A generation unit generates a first token by inputting concatenated information, obtained by concatenating each of the first hash values ​​calculated for each of the first combinations, into a predetermined hash function; generates a second token by inputting concatenated information, obtained by concatenating each of the second hash values ​​calculated for each of the second combinations, into the predetermined hash function; and generates an integrated token by inputting concatenated information, obtained by concatenating the first token and the second token, into the predetermined hash function. A registration unit registers the hash value generated based on the integrated token, the issuer's digital signature encrypted using the issuer's private key, the issuer's public key, and the integrated token on the blockchain. Furthermore, it has The information processing system according to feature 3.

5. The aforementioned transmitting unit The string generated based on the aforementioned integrated token is further transmitted to the verifier device, encrypted using a private key associated with the public key corresponding to the element transmitted by the transmission unit, and containing the user's digital signature. The information processing system according to feature 4.

6. The aforementioned verifier device is The generation unit generates a first verification token by inputting concatenated information into a predetermined hash function for each of the first combinations transmitted by the transmission unit, which is obtained by concatenating the hash value calculated using the first element and public key of the permitted items included in the first combination with the first hash value transmitted by the transmission unit. The generation unit generates a second verification token by inputting concatenated information into a predetermined hash function for each of the second combinations transmitted by the transmission unit, which is obtained by concatenating the hash value calculated using the second element and public key of the permitted items included in the second combination with the second hash value transmitted by the transmission unit. The generation unit generates a single unified verification token by inputting concatenated information, which is obtained by concatenating the first verification token and the second verification token, into a predetermined hash function. It further possesses, The verification unit, The user's digital signature is decrypted using a single combined public key obtained by adding up all the public keys contained in each of the first combinations transmitted by the transmitting unit, and all the public keys contained in each of the second combinations transmitted by the transmitting unit, to obtain a hash value, and the user's legitimacy is verified based on a comparison between the obtained hash value and the hash value representing the verification integration token. The information processing system according to feature 5.

7. The verification unit, If the integrated token registered on the blockchain matches the verification integrated token, a hash value is obtained by decrypting the issuer's digital signature using the issuer's public key, and the legitimacy of the issuer is further verified based on a comparison of the obtained hash value with the hash value representing the verification integrated token. The information processing system according to feature 6.

8. An information processing method performed by an information processing system that includes a user device, which is the device of a user who uses a certificate, and a verifier device, which is the device of a verifier who verifies the certificate, The user device, Obtain a hash value calculated for each combination of an element indicating the content of the user's personal information and the public key corresponding to that element. The user specifies which of the aforementioned elements are permitted to be provided to the verifier. Of the aforementioned combinations, the combinations corresponding to the permitted elements are transmitted to the verifier device, while the combinations corresponding to unauthorized elements that are not permitted to be provided are not transmitted to the verifier device. Instead, the hash values ​​corresponding to the unauthorized elements are transmitted to the verifier device. The aforementioned verifier device, Based on the transmitted combination and the hash value, the legitimacy of the provider who provided the elements being the user is verified. An information processing method characterized by the following:

9. An information processing program comprising a first program executed by a user device, which is a device of a user that uses a certificate, and a second program executed by a verifier device, which is a device of a verifier that verifies the certificate, The first program described above is: A procedure for obtaining hash values ​​calculated for each combination of elements indicating the content of the user's personal information and the public key corresponding to those elements, A reception procedure for receiving from the user the designation of the elements to be permitted to be provided to the verifier, A transmission procedure in which, among the aforementioned combinations, combinations corresponding to the permitted elements are transmitted to the verifier device, while combinations corresponding to unauthorized elements that are not permitted to be provided are not transmitted to the verifier device, but instead the hash values ​​corresponding to the unauthorized elements are transmitted to the verifier device. The user device is instructed to execute the above, The second program described above is: A verification procedure that verifies the legitimacy of the provider who provided the elements being the user, based on the combination and hash value transmitted by the transmission procedure. The verification device is made to execute the above. An information processing program characterized by the following features.

Citation Information

Patent Citations

  • Electronic cash system

    JP2000113085A

  • Personal information browsing / update system and method

    JP2006285490A

  • Personal authentication device and personal authentication method

    JP2020010299A

  • Information processing device

    JP2020190803A

  • Information processing device, information processing method and program

    JP2022055385A