Information processing method and system
The system simplifies identity verification across services by using zero-knowledge proofs and blockchain to manage encrypted identity information, addressing user privacy concerns and process complexity.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- SONY GROUP CORP
- Filing Date
- 2024-11-28
- Publication Date
- 2026-04-28
AI Technical Summary
Identity verification processes are cumbersome and invasive, often requiring users to provide personal information, which raises privacy concerns.
An information processing system utilizing a blockchain system, user terminals, and identity verification processing devices that perform zero-knowledge proofs to simplify identity verification by generating and verifying proof information based on random numbers, ensuring privacy protection.
Simplifies identity verification processes across multiple services while protecting user privacy by managing encrypted identity verification information on a blockchain, allowing users to prove their verified status without disclosing personal information.
Smart Images

Figure 0007852693000001 
Figure 0007852693000002 
Figure 0007852693000003
Abstract
Description
[Technical Field]
[0001] This disclosure concerns information processing. method , and system Regarding. [Background technology]
[0002] In recent years, the range of services requiring identity verification has expanded significantly. Users need to go through the identity verification process for each individual service before they can begin using it. [Prior art documents] [Patent Documents]
[0003] [Patent Document 1] Patent No. 6504639 [Patent Document 2] Japanese Patent Publication No. 2004-229071 [Overview of the project] [Problems that the invention aims to solve]
[0004] Identity verification processes can be cumbersome and inconvenient for users. Furthermore, these processes may require the provision of personal information, necessitating the protection of user privacy.
[0005] Therefore, this disclosure describes information processing that can simplify the identity verification process when using services that require identity verification, while protecting the privacy of service users. method , and system I propose this. [Means for solving the problem]
[0006] To solve the above problems, a form of information processing related to this disclosure method teeth, In a system consisting of a user terminal and a service provider terminal that provides services to the user terminal, Information processing that provides services method And, On the user terminal of a user requesting a service from a service provider terminal, based on the user's identity verification information in the identity verification processing device. Identity verification process is complete. This involves performing a zero-knowledge proof process called Prove, which generates proof information (Proof) based on identity verification information and random numbers. and, The service provider terminal receives the proof information Proof, obtained by performing a zero-knowledge proof Prove process transmitted from the user terminal, and performs a zero-knowledge proof Verify process to determine whether the proof information Proof was generated based on random numbers from the user terminal that has completed the identity verification process. and As a result of the zero-knowledge verification process, if it is proven that the user has completed the identity verification process at the identity verification processing device, the process to provide the requested service to the user terminal will be executed at the service provider terminal. and 、 to include 。
Brief Description of the Drawings
[0007] [Figure 1] It is a diagram showing an example of an information processing system according to an embodiment. [Figure 2] It is a diagram showing an example of the functional configuration of a user terminal according to an embodiment. [Figure 3] It is a diagram showing an example of the functional configuration of a personal identification processing device according to an embodiment. [Figure 4] It is a diagram showing an example of the functional configuration of a settlement processing device according to an embodiment. [Figure 5] It is a diagram showing an example of a procedure of processing related to personal identification processing and registration of encrypted information according to an embodiment. [Figure 6] It is a diagram showing an example of a procedure of processing related to generation and verification of proof information according to an embodiment. [Figure 7] It is a diagram showing an example of a procedure of user registration processing according to an embodiment. [Figure 8] It is a diagram showing an example of a procedure of user registration processing according to an embodiment. [Figure 9] It is a diagram showing an example of a procedure of money transfer processing according to an embodiment. [Figure 10] It is a diagram showing an example of a procedure of processing related to personal identification processing and registration of encrypted information according to a modification example. [Figure 11] It is a diagram showing an example of a procedure of loan review processing according to a modification example. [Figure 12] It is a diagram showing an outline of the use of a plurality of personal identification service providers according to a modification example. [Figure 13] It is a flowchart showing an example of a procedure of verification processing of a provider according to a modification example. [Figure 14] It is a hardware configuration diagram showing an example of a computer that realizes the functions of a settlement processing device.
Modes for Carrying Out the Invention
[0008] Embodiments of this disclosure will be described in detail below with reference to the drawings. In each of the following embodiments, the same reference numerals may be used for components that are the same part or have substantially the same function, and redundant descriptions may be omitted. For example, if there is no need to distinguish between user terminals 10a, 10b, and 10c, they will simply be referred to as user terminal 10.
[0009] Furthermore, this disclosure will be explained in the order of the items shown below. 1. Introduction 2. Example of Functional Configuration 3. Example of processing procedure 4. Variations 5. Others 6. Effects 7. Hardware Configuration
[0010] <<1. Introduction>> Financial institutions are legally obligated to verify the identity of customers conducting specific transactions. Therefore, banks and similar institutions operate on the premise that transactions take place between accounts where identity verification has been completed. On the other hand, while distributed ledger systems using blockchain technology to manage cryptocurrency transaction history allow for anonymous transactions, identity verification is required by law when converting cryptocurrency to fiat currency. For this reason, many cryptocurrency exchanges require identity verification when converting cryptocurrency to fiat currency.
[0011] Furthermore, a wide range of services require identity verification, including credit card issuance, buying and selling of used goods, and online payment and money transfer services. Using these services requires a complex identity verification process for each individual service.
[0012] For example, as part of the identity verification process, users may be required to upload a copy of their identification document to the service provider's system, fill out documents sent by the service provider, and return them to the service provider by mail. Alternatively, as part of the identity verification process, users may be required to upload a copy of their identification document along with their bank account information. Furthermore, as part of the identity verification process, users may be required to upload an image of their identification document, as well as a video recording of both themselves and their identification document. In this way, the identity verification process is often cumbersome for users.
[0013] Furthermore, identity verification often involves providing personal information such as identification documents and bank account details, which can cause considerable anxiety among users from a privacy protection standpoint.
[0014] Therefore, in this embodiment, we propose an information processing device and an information processing method that can simplify identity verification when using services that require identity verification, while protecting user privacy.
[0015] <<2. Example of Functional Configuration>> Figure 1 shows an example of an information processing system according to the embodiment. As shown in Figure 1, the information processing system 1 is composed of a blockchain system 2, user terminals 10a, 10b, 10c, an identity verification processing device 30, and a payment processing device 100. The configuration of the information processing system 1 according to the embodiment is not limited to the example shown in Figure 1, and may, for example, be composed of multiple identity verification processing devices 30 and multiple payment processing devices 100.
[0016] The blockchain system 2, user terminal 10, identity verification processing device 30, and payment processing device 100 are connected to a predetermined communication network 3. The communication network 3 includes LAN (Local Area Network), WAN (Wide Area Network), telephone networks (mobile phone networks, fixed telephone networks, etc.), regional IP (Internet Protocol) networks, the Internet, etc. The blockchain system 2, user terminal 10, identity verification processing device 30, and payment processing device 100 can communicate via wired or wireless connections through the communication network 3.
[0017] Blockchain system 2 performs processing related to the blockchain. For example, in blockchain system 2, the identity verification processing device 30 manages each block, which is a collection of data related to the user identity verification process of the user terminal 10, as a blockchain composed of these blocks linked together in processing order.
[0018] User terminal 10 is a user device used by users who are users of various services that require identity verification. For example, user terminal 10a is used by user Ua, user terminal 10b is used by user Ub, and user terminal 10c is used by user Uc. User terminal 10 can be implemented as an information processing device such as a mobile phone including a smartphone, a tablet device, a desktop PC, a notebook PC, or a PDA (Personal Digital Assistant).
[0019] The identity verification processing device 30 is an information processing device operated by an identity verification service provider that provides an online identity verification service, also known as eKYC (electronic Know Your Customer). The identity verification processing device 30 is implemented using a desktop PC, a notebook PC, a server, etc.
[0020] The payment processing device 100 is an information processing device operated by a business that provides online payment services. The payment processing device 100 functions as an example of an information processing device that provides a service requiring identity verification processing for use. The payment processing device 100 is implemented using a desktop PC, a notebook PC, a server, etc.
[0021] Furthermore, services requiring identity verification are not necessarily limited to payment services. For example, various financial services such as credit card issuance and account opening, as well as insurance services, asset management and investment services, and social lending services could also be included.
[0022] <2-1. Blockchain System> Blockchain system 2 generates and manages a blockchain consisting of data blocks grouped into predetermined units, using various conventional blockchain technologies such as "Hyperledger Fabric" as appropriate. Blockchain system 2 may have any configuration as long as it can implement the processing according to the embodiment of this disclosure.
[0023] The blockchain of Blockchain System 2 may take various forms, such as public (public chain) or private (private chain).
[0024] Regarding the consensus algorithm in blockchain system 2, various conventional technologies may be used as appropriate, as needed. Examples of consensus algorithms include PBFT (Practical Byzantine Fault Tolerance), PoC (Proof of Consensus), PoS (Proof of Stake), and PoI (Proof of Importance). When using PBFT (Practical Byzantine Fault Tolerance), a core node is required to function as a specific administrator for consensus building.
[0025] Blockchain system 2 performs processing related to the blockchain. For example, in blockchain system 2, the identity verification processing device 30 manages each block, which is a collection of data related to the user identity verification process of the user terminal 10, as a blockchain composed of these blocks linked together in processing order.
[0026] In the example shown in Figure 1, blockchain system 2 is composed of multiple nodes 20 (20a, 20b, 20c, 20d). The number of nodes constituting blockchain system 2 is not limited to the example shown in Figure 1; it may include fewer than four nodes or five or more nodes.
[0027] Each node 20 constituting the blockchain system 2 is an information processing device that performs various processes such as block generation and blockchain sharing. Each node 20 is equipped with a communication unit, for example, a NIC (Network Interface Card) or communication circuit, and is connected to a communication network 3 (such as the Internet) by wire or wireless. Each node 20 sends and receives information with other devices such as an identity verification processing device 30 and a payment processing device 100 via the communication network 3. Each node 20 communicates information related to the blockchain with other nodes 20.
[0028] Each node 20 has a control unit, which is implemented in, for example, a microcomputer. The microcomputer is equipped with a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit), and a storage device such as ROM (Read Only Memory) or RAM (Random Access Memory). The ROM stores a program for controlling each part of the node 20. The processor, such as the CPU, executes the program stored in the ROM, thereby enabling the microcomputer to control the node 20. The RAM is used as a memory area necessary for the execution of calculations by the processor, such as the CPU. Each node 20 also has a storage unit, which is implemented in, for example, a semiconductor memory element such as RAM (Random Access Memory) or flash memory, or a storage device such as a hard disk or optical disc. Each node 20 stores the blockchain in its storage unit. The control unit may be implemented in an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).
[0029] Each node 20 performs processing for each block of the blockchain related to the identity verification process performed by the identity verification processing device 30 to be shared. Each block related to the identity verification process includes user identification information uniquely assigned to each user of the user terminal 10 that has completed the identity verification process (verified user), and encrypted information obtained by encrypting the identity verification information used in the identity verification process.
[0030] Furthermore, each node 20 performs the process of extracting corresponding information and sending it to the requesting party in response to a request from an external device such as a user terminal 10 or a payment processing device 100. For example, when each node 20 receives a request to acquire encrypted information from an external device such as a user terminal 10 or a payment processing device 100, it sends encrypted information corresponding to the user identification information included in the acquisition request to the requesting party. That is, each node 20 appropriately uses various technologies such as a block (blockchain) explorer related to blockchain searching to search for information corresponding to the request from the requesting party from the blockchain stored in the memory unit, and sends the retrieved (extracted) information to the requesting party. Note that the blockchain system 2 may also include a service provider that performs various processes such as acquiring corresponding information from the nodes 20 and sending it to the requesting party in response to a request from an external device.
[0031] In the information processing system 1 according to Embodiment 1, the blockchain system 2 manages data related to the user identity verification process of the user terminal 10, thereby preventing tampering with identity verification data and facilitating data recovery.
[0032] <2-2. User Terminals> Figure 2 is a diagram showing an example of the functional configuration of a user terminal according to the embodiment. As shown in Figure 2, the user terminal 10 includes a communication unit 11, an input unit 12, an output unit 13, an imaging unit 14, a positioning unit 15, a detection unit 16, a storage unit 17, and a control unit 18.
[0033] The communication unit 11 is implemented, for example, by a NIC (Network Interface Card) or a communication module. This communication unit 11 is connected to the communication network 3 by wire or wireless, and transmits and receives information between the blockchain system 2, the identity verification processing unit 30, the payment processing unit 100, etc., via the communication network 3. The information transmitted and received by the communication unit 11 includes encrypted information, random numbers, and user identification information received from the identity verification processing unit 30, as well as proof information ([Proof]) to be transmitted to the payment processing unit 100. The encrypted information is information obtained by encrypting the identity verification information used in the identity verification process. The random numbers are information received by the communication unit 11 only when the identity verification process has been completed in the identity verification processing unit 30. The proof information ([Proof]) is information used to prove, by zero-knowledge proof, that the user is an identity-verified user who has completed the identity verification process. This includes identity verification information used in the identity verification process, and proof information ([Proof]) used to prove, by zero-knowledge proof, that the user is an identity-verified user who has completed the identity verification process.
[0034] The input unit 12 is equipped with a keyboard, mouse, etc., and accepts various operations from the user on the user terminal 10. Operations accepted by the input unit 12 from the user terminal 10 include operations to request identity verification from the identity verification processing device 30 and operations to request the use of payment services from the payment processing device 100. The input unit 12 may also be equipped with an audio input device such as a microphone, and accepts input such as the user's voice.
[0035] The output unit 13 is equipped with a display, speakers, etc., and outputs various information. The information output by the output unit 13 includes a user interface for identity verification processing provided by the identity verification processing device 30, and a user interface for using payment services provided by the payment processing device 100.
[0036] The imaging unit 14 is equipped with a device such as a camera and captures images. The imaging unit 14 can acquire identity verification information that can be handled in the identity verification process, such as an image of the user's identification document or a video including the user and their identification document.
[0037] The positioning unit 15 is equipped with GPS (Global Positioning System) and other technologies to acquire the location of the user terminal 10. The positioning unit 15 can acquire location information of the user's home or parents' home, etc., as personal identification information that can be handled in the personal identification process.
[0038] The detection unit 16 is equipped with an accelerometer, a gyroscope, a biosensor, and other sensors to detect various types of information that interact with the user terminal 10. The detection unit 16 can acquire biometric information such as feature quantities corresponding to the user's gait, heart rate waveforms, and fingerprint feature points as identity verification information that can be handled in the identity verification process.
[0039] The storage unit 17 stores programs and data for realizing various processing functions executed by the control unit 18. The storage unit 17 is implemented by, for example, semiconductor memory elements such as RAM (Random Access Memory) and flash memory, or storage devices such as hard disks and optical discs. The programs stored in the storage unit 17 include programs for realizing the processing corresponding to each part of the control unit 18. One of the functions provided by this program is a function that causes the user terminal 10 to execute the process for identity verification using zero-knowledge proof, which is described below.
[0040] As shown in Figure 2, the storage unit 17 has an identity verification information storage unit 17a and a secret information storage unit 17b.
[0041] The identity verification information storage unit 17a stores identity verification information used in the identity verification process. The identity verification information stored in the identity verification information storage unit 17a includes image information of identification documents such as driver's licenses, health insurance cards, and My Number cards (My Number notification cards), as well as various personal information such as credit card numbers, financial institution account information, address, name, age, date of birth, and telephone number. In addition, the identity verification information storage unit 17a may also store various biometric information acquired by the detection unit 16 and location information acquired by the positioning unit 15 as identity verification information. The various personal information stored in the identity verification information storage unit 17a functions as confidential information that can only be known by verified users who have completed the identity verification process.
[0042] The secret information storage unit 17b stores a random number that is transmitted from the identity verification processing unit 30 to the user terminal 10, provided that the identity verification process is completed. The random number stored in the secret information storage unit 17b is generated by the identity verification processing unit 30. The random number generated by the identity verification processing unit 30 is a secret value associated with the user of the user terminal 10 that requested the identity verification process. This random number is used to generate proof information ([Proof]) to prove, by zero-knowledge proof, that the user is an identity-verified user who has completed the identity verification process.
[0043] The control unit 18 executes various processes in the user terminal 10. The control unit 18 is implemented by a microcomputer or the like. The microcomputer is implemented by a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit). It is equipped with a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit), and a storage device such as ROM (Read Only Memory) or RAM (Random Access Memory). The ROM stores a program for controlling each part of the user terminal 10. The CPU or other processor executes the program stored in the ROM, thereby realizing control of the user terminal 10 by the microcomputer. The RAM is used as a memory area necessary for the execution of calculations by the CPU or other processor. The program for controlling each part of the user terminal 10 may also be stored in the storage unit 17, and the processor executes the program stored in the storage unit 17, thereby realizing control of the user terminal 10 by the microcomputer. The control unit 18 may also be implemented by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).
[0044] As shown in Figure 2, the control unit 18 includes an identity verification request unit 18a and a service request unit 18b.
[0045] The identity verification request unit 18a requests the identity verification processing unit 30 to perform identity verification processing. When the identity verification request unit 18a sends an identity verification request to the identity verification processing unit 30, it may include the identity verification information to be used in the identity verification request. Alternatively, after sending an identity verification request to the identity verification processing unit 30 to request identity verification processing, the identity verification request unit 18a may send the identity verification information again in response to the request returned by the identity verification processing unit 30. Image information of identification documents such as a driver's license, health insurance card, or My Number Card (My Number Notification Card) may be used as identity verification information.
[0046] When the identity verification process is completed in the identity verification processing device 30, the identity verification request unit 18a receives a random number transmitted from the identity verification processing device 30, along with user identification information uniquely assigned to each verified user, provided that the identity verification process is complete. The identity verification request unit 18a associates the user identification information with the random number received from the identity verification processing device 30 and stores it in the storage unit 17.
[0047] The service request unit 18b requests the payment processing unit 100 to provide various services by sending a service request. When the service request unit 18b sends a service request to the payment processing unit 100, it uses proof information ([Proof]) to prove that it is a verified user who has completed the identity verification process, using zero-knowledge proof. The service request unit 18b requests the payment processing unit 100 to provide services by sending a service request to the payment processing unit 100 that includes the user identification information assigned by the identity verification processing unit 30 and the proof information.
[0048] The service request unit 18b executes a "ZKP (Zero-Knowledge Proof)-Prove" process to generate proof information ([Proof]) for verifying that the user is a verified identity using zero-knowledge proof when requesting the payment processing unit 100 to provide services. The "ZKP-Prove" process includes a "WitnessRedution" process.
[0049] The "WitnessRedution" process is performed based on identity verification information (personal information) and random numbers, which are information that only verified users can know, and encrypted information managed as public information in blockchain system 2. Identity verification information is obtained from identity verification information storage unit 17a. Random numbers are obtained from secret information storage unit 17b. Encrypted information is obtained from blockchain system 2 based on user identification information linked to the random numbers obtained from secret information storage unit 17b. The encrypted information managed in blockchain system 2 is information generated in the identity verification process when the identity verification processing unit 30 encrypts the identity verification information using random numbers.
[0050] The "WitnessRedution" process can generate polynomials that cannot be generated in polynomial time without confidential information (Witness) known only to the user, such as random numbers and identity verification information. In other words, in the "WitnessRedution" process, the correct "polynomial h" cannot be generated unless the random numbers and the encrypted information match.
[0051] The service request unit 18b can, for example, generate a "polynomial h" generated by the "WitnessRedution" process as proof information for proving, using a zero-knowledge proof, that the user is a verified user who has completed the identity verification process. Note that the algorithm used to generate proof information for proving that the user is a verified user who has completed the identity verification process using a zero-knowledge proof is not limited to the one used to generate "polynomial h". Various algorithms can be used to generate proof information for proving that the user is a verified user who has completed the identity verification process using a zero-knowledge proof.
[0052] <2-3. Identity Verification Processing Device> Figure 3 is a diagram showing an example of the functional configuration of an identity verification processing device according to the embodiment. As shown in Figure 3, the identity verification processing device 30 comprises a communication unit 31, a storage unit 32, and a control unit 33.
[0053] The communication unit 31 is implemented, for example, by a NIC (Network Interface Card). This communication unit 31 is connected to the communication network 3 by wire or wireless connection and transmits and receives information with the blockchain system 2 and the user terminal 10 via the communication network 3. The information transmitted and received by the communication unit 31 includes identity verification information received from the user terminal 10, user identification information and random numbers transmitted to the user terminal 10, and encrypted information transmitted to the blockchain system 2. The identity verification information is information used for the user verification process of the user terminal 10. The user identification information is information uniquely assigned to verified users who have completed the identity verification process. The random numbers are confidential information transmitted to the user terminal 10 on the condition that the identity verification process is completed. The encrypted information is information obtained by encrypting the identity verification information using random numbers.
[0054] The storage unit 32 stores programs and data for realizing various processing functions executed by the control unit 33. The storage unit 32 is implemented by, for example, semiconductor memory elements such as RAM (Random Access Memory) and flash memory, or storage devices such as hard disks and optical discs. The programs stored in the storage unit 32 include programs for realizing processing corresponding to each part of the control unit 33. One of the functions provided by this program is a function for causing the identity verification processing device 30 to execute the identity verification process described below.
[0055] The control unit 33 executes various processes in the identity verification processing device 30. The control unit 33 is implemented by a microcomputer or the like. The microcomputer is implemented by a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit). It is equipped with a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit), and a storage device such as ROM (Read Only Memory) or RAM (Random Access Memory). The ROM stores a program for controlling each part of the identity verification processing device 30. The CPU or other processor executes the program stored in the ROM, thereby enabling the microcomputer to control the identity verification processing device 30. The RAM is used as a memory area necessary for the execution of calculations by the CPU or other processor. The program for controlling each part of the identity verification processing device 30 may also be stored in the storage unit 32, and the processor executes the program stored in the storage unit 32, thereby enabling the microcomputer to control the identity verification processing device 30. The control unit 33 may also be implemented by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).
[0056] As shown in Figure 3, the control unit 33 comprises an identity verification processing unit 33a and a registration processing unit 33b.
[0057] The identity verification processing unit 33a performs online identity verification processing in response to an identity verification request received from the user terminal 10.
[0058] Specifically, when the identity verification processing unit 33a receives an identity verification request from the user terminal 10, it establishes, for example, a communication session for identity verification processing and, through the established communication session, sends a request to the user terminal 10 to upload identity verification information to be used for identity verification.
[0059] Next, the identity verification processing unit 33a performs identity verification using the identity verification information uploaded by the user terminal 10. The identity verification processing unit 33a also generates a random number associated with the user of the user terminal 10 that requested the identity verification process. This random number is a secret value associated with the user of the user terminal 10 that requested the identity verification process. This random number can be any information associated with the user of the user terminal 10 that requested the identity verification process, and various types of information can be used.
[0060] Next, the identity verification processing unit 33a generates encrypted information by encrypting the identity verification information uploaded by the user terminal 10 using the generated random number. For example, the identity verification processing unit 33a calculates a hash value using the identity verification information and the random number as input, and uses the calculated hash value as the encrypted information.
[0061] The registration processing unit 33b executes the registration process for the blockchain system 2. When the identity verification processing unit 33a generates encrypted information, the registration processing unit 33b generates unique user identification information to be assigned to the user of the user terminal 10 that is the source of the identity verification process. The registration processing unit 33b then associates the user identification information with the encrypted information and registers it with the blockchain system 2. As a result, the user identification information and encrypted information are set up in the blockchain system 2 as public information to prove that the identity verification process has been completed using zero-knowledge proofs.
[0062] Furthermore, the registration processing unit 33b sends back user identification information and a random number associated with the user of the user terminal 10 that requested the identity verification process to the user terminal 10 that requested the identity verification process. This sets up a random number on the user terminal 10 that will be used to generate proof information to prove, by zero-knowledge proof, that the user is a verified user who has completed the identity verification process.
[0063] <2-4. Payment Processing Device> Figure 4 is a diagram showing an example of the functional configuration of a payment processing device according to the embodiment. As shown in Figure 4, the payment processing device 100 includes a communication unit 110, a storage unit 120, and a control unit 130.
[0064] The communication unit 110 is implemented, for example, by a NIC (Network Interface Card). This communication unit 110 is connected to the communication network 3 by wire or wireless connection and transmits and receives information with the blockchain system 2 and the user terminal 10 via the communication network 3. The information transmitted and received by the communication unit 110 includes proof information ([Proof]) received from the user terminal 10 and encrypted information obtained from the blockchain system 2. Proof information ([Proof]) is information used to prove, by zero-knowledge proof, that the user is a verified user who has completed the identity verification process. Encrypted information is encrypted information obtained by encrypting the identity verification information used by the user of the user terminal 10 in the identity verification process.
[0065] The storage unit 120 stores programs and data for realizing various processing functions executed by the control unit 130. The storage unit 120 is implemented, for example, by semiconductor memory elements such as RAM (Random Access Memory) and flash memory, or by storage devices such as hard disks and optical discs. The programs stored in the storage unit 120 include programs for realizing processing corresponding to each part of the control unit 130. One of the functions provided by this program is a function for causing the payment processing device 100 to execute the verification process described below.
[0066] The control unit 130 executes various processes in the payment processing device 100. The control unit 130 is implemented by a microcomputer or the like. The microcomputer is implemented by a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit). It is equipped with a processor such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit), and a storage device such as ROM (Read Only Memory) or RAM (Random Access Memory). The ROM stores a program for controlling each part of the payment processing device 100. The processor such as the CPU executes the program stored in the ROM, thereby realizing control of the payment processing device 100 by the microcomputer. The RAM is used as a memory area necessary for the execution of calculations by the processor such as the CPU. The program for controlling each part of the payment processing device 200 may also be stored in the storage unit 120, and the processor executes the program stored in the storage unit 120, thereby realizing control of the payment processing device 100 by the microcomputer. The control unit 130 may also be implemented by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).
[0067] As shown in Figure 4, the control unit 130 includes an acquisition unit 131, a verification unit 132, and a supply unit 133.
[0068] The acquisition unit 131 obtains certification information generated using confidential information that only verified users can know, from the user making the service request. Here, the certification information is proof, by zero-knowledge proof, that the user is a verified user who has completed the identity verification process, and is enclosed with the service request sent from the user terminal 10. The acquisition unit 131 also obtains user identification information enclosed with the service request along with the certification information. The confidential information that only verified users can know includes, for example, the identity verification information used in the identity verification process, and random numbers associated with the user of the user terminal 10 that made the request for the identity verification process.
[0069] The verification unit 132 performs a verification process ("ZKP-Verify" process) of the proof information obtained by the acquisition unit 131 using encrypted information that has been encrypted using confidential information and is managed in the blockchain system 2. The encrypted information managed in the blockchain system 2 is the encrypted identity verification information used in the identity verification process of verified users. The encrypted information is generated by the identity verification processing device 30 by encrypting the identity verification information using random numbers generated by the identity verification processing device 30 itself, and is registered in the blockchain system 2 by the identity verification processing device 30.
[0070] The "ZKP-Verify" process is executed by obtaining encrypted information associated with the user identification information obtained by the acquisition unit 131 from the blockchain system 2. The "ZKP-Verify" process verifies whether the proof information obtained from the user terminal 10 was created based on random numbers, which are secret information known only to the verified user. Specifically, for example, if a "polynomial h" is generated as proof information on the user terminal 10, the "ZKP-Verify" process compares the calculation result based on the encrypted information obtained from the blockchain system 2 with the proof information. The "ZKP-Verify" process then verifies whether the proof information was generated from the correct "polynomial h". In other words, the "ZKP-Verify" process proves whether the service request is from a verified user whose identity verification process has been completed.
[0071] In the "ZKP-Verify" process, if the verification proves that the certification information was generated from a correct "polynomial h", the verification result is derived that the user of user terminal 10, the service requester, is the genuine verified user. A correct "polynomial h" means a polynomial generated using the same random numbers as those used to generate the encrypted information. On the other hand, if the verification in the "ZKP-Verify" process fails to prove that the certification information was generated from a correct "polynomial h", the verification result is derived that the user of user terminal 10, the source of the certification information, is not the genuine verified user.
[0072] The service provider 133 executes processing to provide services to the user using the user terminal 10 of the service requester, provided that the verification process by the verification unit 132 proves that the user requesting the service has completed the identity verification process. The service provider 133 may also notify the service requester that the verification process has been completed successfully.
[0073] <<3. Example of Processing Procedure>> <3-1. Procedures for verifying identity and registering encrypted information> The procedure for identity verification and registration of encrypted information according to the embodiment will be explained using Figure 5. Figure 5 is a diagram showing an example of the procedure for identity verification and registration of encrypted information according to the embodiment.
[0074] As shown in Figure 5, the user terminal 10 sends an identity verification request to the identity verification processing device 30 to request that the identity verification process be performed (step S11). When the user terminal 10 sends the identity verification request, for example, it can include identity verification information to be used in the identity verification process.
[0075] Upon receiving the identity verification request, the identity verification processing device 30 performs the identity verification process (step S12). The identity verification processing device 30 also generates secret information (random number) associated with the user of the user terminal 10 that requested the identity verification process (step S13).
[0076] Next, the identity verification processing device 30 uses the secret information, which is a random number ([Secret]), generated in step S13 to generate encrypted information ([Encrypted PII]) obtained by encrypting the identity verification information used in the identity verification process of step S12 (step S14).
[0077] After generating encrypted information ([Encrypted PII]), the identity verification processing device 30 sends a registration request for the encrypted information to the blockchain system 2 (step S15). When sending the registration request for the encrypted information, the identity verification processing device 30 generates user identification information ([PII-ID]) unique to the user of the user terminal 10, which is an identity-verified user, and includes it in the registration request along with the encrypted information ([Encrypted PII]). In the blockchain system 2, the user identification information ([PII-ID]) and the encrypted information ([Encrypted PII]) are managed in a mutually linked state.
[0078] Then, the identity verification processing device 30 sends back the secret information, a random number ([Secret]), generated in step S13 to the user terminal 10 (step S16). When the identity verification processing device 30 sends back the secret information, a random number ([Secret]), to the user terminal 10, it also sends the user identification information ([PII-ID]).
[0079] When the user terminal 10 receives a secret random number ([Secret]) from the identity verification processing device 30, it associates it with the user identification information ([PII-ID]) received along with the secret information and stores it in the storage unit 17 (step S17). This completes the procedures for identity verification and registration of encrypted information in the information processing system 1.
[0080] As described above, according to the information processing system 1 of this embodiment, encrypted information ([Encrypted PII]) obtained by encrypting the identity verification information used in the identity verification process is managed as public information in the blockchain system 2. This makes it possible to share the encrypted information managed in the blockchain system 2 with multiple services that require identity verification. Therefore, service users can simplify the procedures for using multiple services that require identity verification with just one identity verification by the identity verification service. On the other hand, service providers can obtain and use the encrypted information from the blockchain system 2 as needed, eliminating the need to go through the procedure of obtaining identity verification information from service users, thus simplifying the identity verification procedure.
[0081] <3-2. Procedures for generating and verifying certification information> The procedure for generating and verifying proof information according to the embodiment will be explained using Figure 6. Figure 6 is a diagram showing an example of the procedure for generating and verifying proof information according to the embodiment.
[0082] As shown in Figure 6, when the user terminal 10 requests service use from the payment processing device 100, it performs a "ZKP-Prove" process (step S21) to generate proof information ([Proof]) to prove that it has been verified by zero-knowledge proof. The "ZKP-Prove" process is performed based on identity verification information ([PII]), a random number ([Secret]), and encryption information ([Encrypted PII]). The encryption information ([Encrypted PII]) is obtained from the blockchain system 2 based on the user identification information ([PII-ID]).
[0083] When the user terminal 10 generates proof information ([Proof]) through the "ZKP-Prove" process, it sends a service usage request to the payment processing device 100 (step S22). The user terminal 10 includes, for example, the proof information ([Proof]) generated in step S21 and the user identification information ([PII-ID]) assigned by the identity verification processing device 30 in the service usage request.
[0084] Upon receiving a service request, the payment processing device 100 performs a verification process ("ZKP-Verify" process) of the proof information ([Proof]) included in the service request (step S23). The "ZKP-Verify" process is performed by obtaining encrypted information ([Encrypted PII]) associated with the user identification information ([PII-ID]) obtained by the acquisition unit 131 from the blockchain system 2. The "ZKP-Verify" process verifies whether the proof information obtained from the user terminal 10 was created based on a random number, which is secret information known only to the verified user. In other words, the "ZKP-Verify" process proves whether the service request is from a verified user who has completed the identity verification process. Once it is proven that the user requesting the service has completed the identity verification process, the payment processing device 100 performs the process to provide the service to the user requesting the service. This completes the procedure for generating and verifying proof information in the information processing system 1.
[0085] As described above, according to the information processing system 1 of this embodiment, encrypted information ([Encrypted PII]) obtained by encrypting the identity verification information used in the identity verification process is managed as public information in the blockchain system 2. That is, since the identity verification information managed as public information in the blockchain system 2 is encrypted, the privacy of service users can be protected. Furthermore, by using zero-knowledge proofs, service users can prove to the service provider that they have been verified without making the identity verification information itself public, using proof information corresponding to the encrypted information managed in the blockchain system 2. On the other hand, the service provider can obtain the encrypted information required for identity verification from the encrypted information managed in the blockchain system 2 and verify whether or not the service user has been verified using zero-knowledge proofs. Therefore, the identity verification procedure can be simplified for both service users and service providers while protecting the privacy of service users.
[0086] <3-3. User Registration Process> The procedure for user registration processing according to the embodiment will be explained using Figure 7. Figure 7 is a diagram showing an example of the procedure for user registration processing according to the embodiment. The procedure shown in Figure 7 can be performed, for example, when a user of user terminal 10 uses a service provided by payment processing device 100.
[0087] As shown in Figure 7, when the user terminal 10 sends a user registration request to the payment processing device 100, it executes the "ZKP-Prove" process (step S31). The "ZKP-Prove" process is the same as the example shown in Figure 6 above, and is a process for generating proof information ([Proof]) to prove that the user's identity has been verified by zero-knowledge proof. The "ZKP-Prove" process is executed based on identity verification information ([PII]), a random number ([Secret]), and encryption information ([Encrypted PII]). The encryption information ([Encrypted PII]) is obtained from the blockchain system 2 based on the user identification information ([PII-ID]).
[0088] When the user terminal 10 generates proof information ([Proof]) through the "ZKP-Prove" process, it sends a user registration request to the payment processing device 100 (step S32). The user terminal 10 includes, for example, the proof information ([Proof]) generated in step S31 and the user identification information ([PII-ID]) assigned by the identity verification processing device 30 in the user registration request.
[0089] Upon receiving a user registration request, the payment processing device 100 performs a verification process ("ZKP-Verify" process) of the proof information ([Proof]) included in the user registration request (step S33). The "ZKP-Verify" process is performed by obtaining encrypted information ([Encrypted PII]) associated with the user identification information ([PII-ID]) obtained by the acquisition unit 131 from the blockchain system 2. The "ZKP-Verify" process verifies whether the proof information ([Proof]) obtained from the user terminal 10 was created based on a random number ([Secret]), which is secret information known only to the verified user. In other words, the "ZKP-Verify" process proves whether or not the user registration request is from a verified user whose identity verification process has been completed.
[0090] Once it is confirmed that the user of user terminal 10, which is the source of the user registration request, has completed the identity verification process, the payment processing device 100 sends a request for input of basic user information for user registration to user terminal 10 (step S34). When sending the request for input of basic user information, the payment processing device 100 includes session information to identify the session established with user terminal 10 in the request for input of basic user information. The payment processing device 100 obtains the basic user information from user terminal 10, for example, through an input form provided to the user of user terminal 10 via such session.
[0091] When the user terminal 10 receives a request to input user basic information, it notifies the user that it has received the request to input user basic information and accepts the input of user basic information from the user (step S35).
[0092] Once the user has finished entering their basic user information, the user terminal 10 sends a request to register the basic user information to the payment processing device 100 through the session established by the payment processing device 100 (step S36). The request to register the basic user information includes session information to identify the session established by the payment processing device 100.
[0093] Upon receiving a request to register basic user information, the payment processing device 100 executes the user registration process (step S37). The above is an example of the procedure for the user registration process executed in the information processing system 1.
[0094] Thus, according to the information processing system 1 of this embodiment, when a user registers to use the service, the service user can prove that they have been verified by zero-knowledge proof without disclosing their personal identification information itself. Furthermore, the service provider can appropriately obtain and use encrypted information from the blockchain system 2 when verifying the identity of a user during the user registration process. As a result, identity verification during user registration for using the service can be simplified for both the service user and the service provider while protecting the privacy of the service user.
[0095] <3-4. Anonymous User Registration Process> The procedure for user registration processing according to the embodiment will be explained using Figure 8. Figure 8 is a diagram showing an example of the procedure for user registration processing according to the embodiment. The procedure shown in Figure 8 can be performed, for example, when a user of user terminal 10 uses a service provided by payment processing device 100.
[0096] As shown in Figure 8, when the user terminal 10 sends an anonymous user registration request to the payment processing device 100, it performs the "ZKP-Prove" process (step S41). The "ZKP-Prove" process is the same as the example shown in Figure 6 above, and is a process for generating proof information ([Proof]) to prove that the user's identity has been verified by zero-knowledge proof. The "ZKP-Prove" process is performed based on identity verification information ([PII]), a random number ([Secret]), and encryption information ([Encrypted PII]). The encryption information ([Encrypted PII]) is obtained from the blockchain system 2 based on the user identification information ([PII-ID]).
[0097] When the user terminal 10 generates proof information ([Proof]) through the "ZKP-Prove" process, it sends an anonymous user registration request to the payment processing device 100 (step S42). The user terminal 10 includes, for example, the proof information ([Proof]) generated in step S41 and the user identification information ([PII-ID]) assigned by the identity verification processing device 30 in the anonymous user registration request.
[0098] Upon receiving a user registration request, the payment processing device 100 performs a verification process ("ZKP-Verify" process) of the proof information ([Proof]) included in the user registration request (step S43). The "ZKP-Verify" process is performed by obtaining encrypted information ([Encrypted PII]) associated with the user identification information ([PII-ID]) obtained by the acquisition unit 131 from the blockchain system 2. The "ZKP-Verify" process verifies whether the proof information ([Proof]) obtained from the user terminal 10 was created based on a random number ([Secret]), which is secret information known only to the verified user. In other words, the "ZKP-Verify" process proves whether or not the anonymous user registration request is from a verified user whose identity verification process has been completed.
[0099] When it is confirmed that the user of user terminal 10, which is the source of the anonymous user registration request, has completed the identity verification process, the payment processing device 100 executes the anonymous user registration process (step S44). The payment processing device 100 generates an anonymous ID and an anonymous session ID unique to the user who is the source of the anonymous user registration request, and manages them in association with the user identification information ([PII-ID]) included in the anonymous user registration request. The anonymous session ID is information used to identify the anonymous session.
[0100] Following the anonymous user registration process, the payment processing device 100 transmits anonymous session information to the user terminal 10 (step S45). The anonymous session information includes an anonymous ID and an anonymous session ID.
[0101] The user terminal 10, upon receiving the anonymous session information, saves the anonymous session information (step S46) and uses the anonymous session information to send a service usage request to the payment processing device 100 (step S47).
[0102] Upon receiving a service request, the payment processing device 100 verifies the anonymous session information included in the service request (step S48). If the payment processing device 100 successfully verifies the anonymous session information, it provides the service to the user terminal 10 through the anonymous session.
[0103] Thus, according to the information processing system 1 of this embodiment, when an anonymous user registration request is made for the use of the service, the service user can prove that their identity has been verified by zero-knowledge proof without disclosing their identity verification information itself. Furthermore, the service provider can appropriately obtain and use encrypted information from the blockchain system 2 when verifying the identity of the anonymous user registration request. For this reason, identity verification in anonymous user registration when using the service can be simplified for both the service user and the service provider while protecting the privacy of the service user.
[0104] <3-5. Remittance Processing> The procedure for the remittance process according to the embodiment will be explained using Figure 9. Figure 9 is a diagram showing an example of the procedure for the remittance process according to the embodiment.
[0105] As shown in Figure 9, when the user terminal 10 sends a remittance request to the payment processing device 100, it performs the "ZKP-Prove" process (step S51). The "ZKP-Prove" process is the same as the example shown in Figure 6 above, and is a process for generating proof information ([Proof]) to prove that the user's identity has been verified by zero-knowledge proof. The "ZKP-Prove" process is performed based on identity verification information ([PII]), a random number ([Secret]), and encryption information ([Encrypted PII]). The encryption information ([Encrypted PII]) is obtained from the blockchain system 2 based on the user identification information ([PII-ID]).
[0106] When the user terminal 10 generates proof information ([Proof]) through the "ZKP-Prove" process, it sends a remittance request to the settlement processing device 100 (step S52). The user terminal 10 includes, for example, the proof information ([Proof]) generated in step S51, the user identification information ([PII-ID]) assigned by the identity verification processing device 30, and information regarding the remittance of digital currency in the remittance request.
[0107] Upon receiving a remittance request, the payment processing device 100 performs a verification process ("ZKP-Verify" process) of the proof information ([Proof]) included in the user registration request (step S53). The "ZKP-Verify" process is performed by obtaining encrypted information ([Encrypted PII]) associated with the user identification information ([PII-ID]) obtained by the acquisition unit 131 from the blockchain system 2. The "ZKP-Verify" process verifies whether the proof information ([Proof]) obtained from the user terminal 10 was created based on a random number ([Secret]), which is secret information known only to the verified user. In other words, the "ZKP-Verify" process proves whether the remittance request is from a verified user whose identity verification process has been completed.
[0108] Once it is confirmed that the user of user terminal 10, which is the source of the user registration request, has completed the identity verification process, the payment processing device 100 executes the remittance process for the digital currency included in the remittance request (step S54).
[0109] Thus, according to the information processing system 1 of this embodiment, when using the remittance service provided by the payment processing device 100, the service user can prove that their identity has been verified by zero-knowledge proof without disclosing their identity verification information itself. Furthermore, the service provider can appropriately obtain and use encrypted information from the blockchain system 2 when verifying the identity of the user in order to respond to a remittance request. As a result, identity verification in the remittance service can be simplified for both the service user and the service provider while protecting the privacy of the service user.
[0110] <<4. Variation>> <4-1. Registering your credit score> In the above embodiment, when registering the encrypted user information of the user terminal 10 with the blockchain system 2, the credit score of the user terminal 10 may also be registered. Figure 10 shows an example of the procedure for identity verification and registration of encrypted information according to a modified example. The procedure shown in Figure 10 is basically the same as the procedure shown in Figure 5, but differs from the procedure shown in Figure 5 in that the credit score of the user of the user terminal 10 is registered with the blockchain system 2.
[0111] In other words, as shown in Figure 10, the user terminal 10 sends an identity verification request to the identity verification processing device 30 to request the execution of identity verification processing (step S61). When the user terminal 10 sends the identity verification request, for example, it can include identity verification information to be used for identity verification processing.
[0112] Upon receiving an identity verification request, the identity verification processing device 30 performs identity verification (step S62). The identity verification processing device 30 also generates secret information (random numbers) associated with the user of the user terminal 10 that requested the identity verification (step S63). In addition, during the identity verification process, the identity verification processing device 30 performs a credit score calculation process to calculate the credit score of the user of the user terminal 10. The credit score is used, for example, in the loan screening process in the payment processing device 100 (see Figure 11).
[0113] Next, the identity verification processing device 30 uses the secret information, which is a random number ([Secret]), generated in step S13 to generate encrypted information ([Encrypted PII]) by encrypting the identity verification information used in the identity verification process of step S62 (step S64).
[0114] After generating encrypted information ([Encrypted PII]), the identity verification processing device 30 sends a registration request for the encrypted information to the blockchain system 2 (step S65). When sending the registration request for the encrypted information, the identity verification processing device 30 generates user identification information ([PII-ID]) unique to the user of the user terminal 10, which is an identity-verified user, and includes it in the registration request along with the encrypted information ([Encrypted PII]) and the credit score. In the blockchain system 2, the user identification information ([PII-ID]), the encrypted information ([Encrypted PII]), and the credit score are managed in a mutually linked state.
[0115] Then, the identity verification processing device 30 sends back the secret information, a random number ([Secret]), generated in step S63 to the user terminal 10 (step S66). When the identity verification processing device 30 sends back the secret information, a random number ([Secret]), to the user terminal 10, it also sends the user identification information ([PII-ID]).
[0116] When the user terminal 10 receives a random number ([Secret]), which is confidential information, from the identity verification processing device 30, it associates it with the user identification information ([PII-ID]) received along with the confidential information and stores it in the storage unit 17 (step S67).
[0117] <4-2. Loan Application Processing> The procedure for the remittance process according to the embodiment will be explained using Figure 11. Figure 11 is a diagram showing an example of the procedure for the loan screening process according to the modified example.
[0118] As shown in Figure 11, when the user terminal 10 sends a remittance request to the payment processing device 100, it performs the "ZKP-Prove" process (step S71). The "ZKP-Prove" process is the same as the example shown in Figure 6 above, and is a process for generating proof information ([Proof]) to prove that the user's identity has been verified by zero-knowledge proof. The "ZKP-Prove" process is performed based on identity verification information ([PII]), a random number ([Secret]), and encryption information ([Encrypted PII]). The encryption information ([Encrypted PII]) is obtained from the blockchain system 2 based on the user identification information ([PII-ID]).
[0119] When the user terminal 10 generates proof information ([Proof]) through the "ZKP-Prove" process, it sends a loan application request to the settlement processing device 100 (step S72). The user terminal 10 includes, for example, the proof information ([Proof]) generated in step S71 and the user identification information ([PII-ID]) assigned by the identity verification processing device 30 in the loan application request.
[0120] Upon receiving a loan application request, the payment processing device 100 performs a verification process ("ZKP-Verify" process) of the proof information ([Proof]) included in the loan application request (step S73). The "ZKP-Verify" process is performed by obtaining encrypted information ([Encrypted PII]) associated with the user identification information ([PII-ID]) obtained by the acquisition unit 131 from the blockchain system 2. The "ZKP-Verify" process verifies whether the proof information ([Proof]) obtained from the user terminal 10 was created based on a random number ([Secret]), which is secret information known only to the verified user. In other words, the "ZKP-Verify" process proves whether the remittance request is from a verified user whose identity verification process has been completed.
[0121] Once it is confirmed that the user of user terminal 10, which is the source of the loan application, has completed the identity verification process, the payment processing unit 100 executes the loan application process based on the credit score of the user of user terminal 10 (step S74). The credit score is obtained from the blockchain system 2 based on the user identification information ([PII-ID]).
[0122] Thus, according to the information processing system 1 of this embodiment, when using the loan service provided by the payment processing device 100, the service user can prove that their identity has been verified by zero-knowledge proof without disclosing their identity verification information itself. Furthermore, when verifying the identity of a loan application, the service provider can appropriately obtain and use a credit score along with encrypted information from the blockchain system 2. For this reason, in identity verification in a remittance service, the privacy of the service user can be protected while simplifying identity verification for both the service user and the service provider.
[0123] <4-3. Use of multiple identity verification service providers> For services requiring identity verification, it is conceivable that the use of a specific provider among multiple providers offering identity verification services may be mandatory, or that the available providers may be restricted depending on the social credibility of the providers. Therefore, users of user terminal 10, who are service users, may each perform identity verification processing using multiple providers offering identity verification services, and the results of the identity verification processing by each provider may be managed in the blockchain system 2. Figure 12 is a diagram illustrating an overview of the use of multiple identity verification service providers in a modified example.
[0124] As shown in Figure 12, for example, user Ua of user terminal 10a can use identity verification service providers X, Y, and Z by sending identity verification requests to each of them (see, for example, Figure 5).
[0125] Identity verification service providers X, Y, and Z each exist as businesses capable of performing identity verification processing according to the identity verification methods required by each service that requires identity verification. The level of authentication required for identity verification by each service may be determined by arbitrary criteria, such as whether multi-factor authentication or multi-factor authentication (MFA) is required, or whether legally prescribed methods are required.
[0126] For example, a service that does not require multi-factor authentication for identity verification can be classified as a service with a low required level of authentication ("authentication level: low"). A service that requires multi-factor authentication for identity verification can be classified as a service with a medium required level of authentication ("authentication level: medium"). A service that requires identity verification as mandated by law can be classified as a service with a high required level of authentication ("authentication level: high"). In the example shown in Figure 12, identity verification service providers X, Y, and Z are businesses capable of performing identity verification according to the requirements of services with a low required level of authentication, services with a medium required level of authentication, and services with a high required level of authentication, respectively.
[0127] In services that do not require multi-factor authentication for identity verification (services with "authentication level: low"), it is expected that basic personal information such as name, address, and date of birth will be used in the identity verification process. Furthermore, it is expected that the information provided by the user will be used unconditionally as a method of identity verification.
[0128] A service provider offering a service that does not require multi-factor authentication for identity verification (a "low authentication level" service) is expected to require service users to undergo identity verification by an identity verification service provider X. For example, if payment service provider A offers a service that does not require multi-factor authentication for identity verification (a "low authentication level" service), it is expected that user Ua will be required to undergo identity verification by an identity verification service provider X.
[0129] Therefore, user Ua of user terminal 10a requests identity verification processing from identity verification service provider X. The identity verification processing device 30X operated by identity verification service provider X performs identity verification processing for user Ua. The identity verification processing device 30X processes the encrypted information obtained as a result of the identity verification processing ([Encrypted PII X ]), and user identification information ([PII-ID) uniquely assigned to user Ua. X Send the identity verification registration request to blockchain system 2.
[0130] When blockchain system 2 receives an identity verification registration request from identity verification processing device 30X, it provides the identity verification service provider X, which is the source of the identity verification registration request, with a unique business ID ([eKYC business ID x Blockchain system 2 issues and allocates information indicating that the user has been verified, such as user identification information ([PII-ID). X ]) and encrypted information ([Encrypted PII X ]) and business ID ([eKYC business ID x ]) and are managed by linking them together.
[0131] When user Ua of user terminal 10a uses the services provided by payment service provider A, the user identification information ([PII-ID X ) assigned by identity verification service provider X is used to send a service request to payment service provider A. Payment service provider A can verify the service request based on the user identification information ([PII-ID X ) included in the service request and obtain encrypted information ([Encrypted PII X ) and the operator ID ([eKYC operator ID x ) from blockchain system 2.
[0132] Services requiring multi-factor authentication for identity verification (services with "Medium Authentication Level") are expected to use a combination of several pieces of information from knowledge, possession, and biometric data in the identity verification process. For example, knowledge can include passwords, PIN codes, and security questions; possession can include mobile phones (phone numbers and email addresses), hardware tokens, and IC cards; and biometric data can include fingerprints, vein patterns, and voiceprints. As for identity verification methods, one example is to log in using knowledge, then send an email with an authentication code to the registered email address, and confirm receipt of the email by presenting the authentication code. Login to the service can be performed using any identity verification algorithm set by the user. Examples of identity verification algorithms include matching name and password, matching name and multiple secret questions, matching name and facial image location, and matching name and fingerprint. As for login methods, name and password matching, name and multiple secret questions matching, name and facial image matching, and name and fingerprint matching can be adopted. In addition to the above, other data that can be handled as part of the identity verification algorithm include confidential information such as card numbers, combinations of publicly available information, sensing data, My Number (Japanese social security number), and credit card information. Examples of combinations of publicly available information include family names, home address and phone number, parents' home address and phone number, and parents' maiden names. Examples of sensing data include fingerprints as mentioned above, location information of specific places such as home, and biometric information such as iris, face, and gait.
[0133] An identity verification algorithm can appropriately employ conditional expressions such as exact match, fuzzy match, greater than / less than comparison, and inclusion relationships, depending on the data it handles. For identity verification algorithms handling passwords, secret questions, or biometric information, exact match can be used as the conditional expression. For identity verification algorithms handling biometric information or secret questions, fuzzy match can be used as the conditional expression. For identity verification algorithms handling location information, for example, an inclusion relationship such as whether the location information is included in a specific area can be used as the conditional expression. The combination of data handled and conditional expressions in the identity verification algorithm can also be AND or OR conditions.
[0134] A service provider offering a service that requires multi-factor authentication for identity verification (a service with "Medium Authentication Level") is expected to require service users to undergo identity verification by identity verification service provider Y. For example, if payment service provider B offers a service that requires multi-factor authentication for identity verification (a service with "Medium Authentication Level"), it is expected that user Ua will be required to undergo identity verification by identity verification service provider Y.
[0135] Therefore, user Ua of user terminal 10a requests identity verification processing from identity verification service provider Y. The identity verification processing device 30Y operated by identity verification service provider Y performs identity verification processing for user Ua. The identity verification processing device 30Y processes the encrypted information obtained as a result of the identity verification processing ([Encrypted PII Y ]), and user identification information ([PII-ID) uniquely assigned to user Ua. Y Send the identity verification registration request to blockchain system 2.
[0136] When blockchain system 2 receives an identity verification registration request from identity verification processing device 30Y, it provides the identity verification service provider Y, which is the source of the identity verification registration request, with a unique business ID ([eKYC business ID YBlockchain system 2 issues and allocates [PII-ID]) as information indicating that the user has been verified. Y ]) and encrypted information ([Encrypted PII Y ]) and business ID ([eKYC business ID Y ]) and are managed by linking them together.
[0137] When user Ua of user terminal 10a uses a service provided by payment service provider B, the user identification information ([PII-ID) assigned by identity verification service provider Y is used. Y Using the user identification information ([PII-ID) included in the service request, a service request is sent to payment service provider A. Payment service provider A sends a service request to payment service provider A. Y Based on ]), encrypted information ([Encrypted PII) is taken from blockchain system 2. Y ]) and business ID ([eKYC business ID Y ]) can be obtained and the service request can be verified.
[0138] Services that require identity verification as stipulated by law (services with "High Authentication Level") are expected to use a combination of identity verification documents with a photograph and identity verification documents without a photograph, such as a health insurance card or a copy of a resident registration certificate, in the identity verification process. Examples of identity verification documents with a photograph include My Number Cards, driver's licenses, and passports. Examples of identity verification documents without a photograph include health insurance cards and copies of resident registration certificates. Furthermore, methods of identity verification are expected to include uploading identity verification documents and videos showing the identity verification documents and the person, or mailing copies of identity verification documents.
[0139] Service providers offering services that require identity verification as stipulated by law (services with "high authentication level") are expected to require service users to undergo identity verification by identity verification service provider Z. For example, if payment service provider C offers a service that requires identity verification as stipulated by law (a service with "high authentication level"), it is expected that C will require user Ua to undergo identity verification by identity verification service provider Z.
[0140] Therefore, user Ua of user terminal 10a requests identity verification processing from identity verification service provider Z. The identity verification processing device 30Z operated by identity verification service provider Z performs identity verification processing for user Ua. The identity verification processing device 30Z then processes the encrypted information obtained as a result of the identity verification processing ([Encrypted PII Z ]), and user identification information ([PII-ID) uniquely assigned to user Ua. Z Send the identity verification registration request to blockchain system 2.
[0141] When blockchain system 2 receives an identity verification registration request from identity verification processing device 30Z, it provides the identity verification service provider Y, the source of the identity verification registration request, with a unique business ID ([eKYC business ID Z Blockchain system 2 issues and allocates [PII-ID]) as information indicating that the user has been verified. Z ]) and encrypted information ([Encrypted PII Z ]) and business ID ([eKYC business ID Z ]) and are managed by linking them together.
[0142] When user Ua of user terminal 10a uses a service provided by payment service provider C, the user identification information ([PII-ID) assigned by identity verification service provider Z is used. Z Using the user identification information ([PII-ID) included in the service request, a service request is sent to payment service provider C. Payment service provider C then sends a service request to payment service provider C. ZBased on ]), encrypted information ([Encrypted PII) is taken from blockchain system 2. Z ]) and business ID ([eKYC business ID Z ]) can be obtained and the service request can be verified.
[0143] In this way, user Ua, a service user, can simplify the identity verification process when using a service, even if the identity verification required by the service differs, by having the identity verification process carried out by each different identity verification service provider. On the other hand, each payment service provider A to C, a service provider, can obtain and verify from blockchain system 2 whether the identity verification required by each service has been carried out, thereby simplifying identity verification while protecting the privacy of service users.
[0144] In the example shown in Figure 12, user Ua may obtain the information of the identity verification service providers designated by payment service providers A to C from each provider in advance before requesting the service, or may obtain it from each provider at the time of requesting the service.
[0145] <4-4. Verification by the business operator> As shown in Figure 12 above, in blockchain system 2, multiple pieces of encrypted information associated with the same user are managed, each linked to unique user identification information and the business ID that performed the identity verification process. Therefore, blockchain system 2 needs to prevent the forgery of business IDs. Below, an example of a method for verifying business IDs is described. Figure 13 is a flowchart showing an example of the procedure for business verification processing related to a modified example.
[0146] As shown in Figure 13, when the blockchain system 2 receives an identity verification registration request from the identity verification processing device 30, it verifies the signature attached to the identity verification registration request (step S81). The signature is generated by the identity verification processing device 30 using a signing key it possesses. The signature corresponds to, for example, the private key contained in the signing key. The blockchain system 2 obtains the public key for verifying the signature of the identity verification processing device 30 from a trusted database and attempts to decrypt the signature.
[0147] If the blockchain system 2 successfully verifies the signature (step S81; Yes), it determines whether the signer matches the business ID ([eKYC business ID]) associated with the signature verification public key in the trusted database (step S82). In other words, it determines whether the combination of the signer of the identity verification registration request and the business is correct.
[0148] If blockchain system 2 determines that the business ID matches (step S82; Yes), it performs the registration of encrypted information in response to the identity verification registration request (step S83) and terminates the process shown in Figure 13.
[0149] On the other hand, if blockchain system 2 determines that the business ID does not match (step S82; No), it rejects the identity verification registration request (step S84) and terminates the process shown in Figure 13.
[0150] Furthermore, in step S81, if the blockchain system 2 fails to verify the signature (step S81; No), it proceeds to the processing procedure in step S84. That is, the blockchain system 2 rejects the identity verification registration request (step S84) and terminates the process shown in Figure 13.
[0151] Furthermore, in the processing procedure shown in Figure 13 above, an X.509 certificate may be used as the signature attached to the identity verification registration request. The correctness of the combination of the signatory of the identity verification registration request and the business operator may then be determined by checking whether the business ID matches the owner ([Subject]) of the X.509 certificate.
[0152] <<5. Others>> The processing in the information processing system 1 according to the above embodiment can be used for various services that require identity verification. For example, it can be used for identity verification when entering concerts and events, identity verification in various contracts, and identity verification in various services such as student discounts. Furthermore, by linking it with the processing of various game applications, it can be used for processes related to the progress of the game, such as obtaining secret information to trigger events or as a key to reach secret locations, and as a condition for generating a user secret key that is only generated when identity verification is successful.
[0153] Furthermore, among the processes described in each of the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by known methods. In addition, the processing procedures, specific names, and information including various data and parameters shown in the above document and drawings can be changed at will unless otherwise specified. For example, the various information shown in each figure is not limited to the information shown.
[0154] Furthermore, the components of each illustrated device are functionally conceptual and do not necessarily need to be physically configured as shown. In other words, the specific forms of distribution and integration of each device are not limited to those shown, and all or part of them can be functionally or physically distributed and integrated in any unit according to various loads and usage conditions. For example, the identity verification processing device 30 and the payment processing device 100 shown in Figure 1 may be integrated. That is, identity verification processing and payment processing may be realized by a single information processing device.
[0155] Furthermore, the embodiments and modifications described above can be combined as appropriate, provided that the processing content is not inconsistent.
[0156] Furthermore, the effects described herein are merely illustrative and not limiting, and other effects may also occur.
[0157] <<6. Effects>> As described above, the payment processing device 100 related to this disclosure is an information processing device that provides a service requiring identity verification processing upon use, and comprises an acquisition unit 131, a verification unit 132, and a provision unit 133. The acquisition unit 131 acquires from the user who requested the service the certification information generated using secret information that only a verified user would know, which is proof that the user is a verified user who has completed identity verification processing, using zero-knowledge proof. The secret information is, for example, a secret value (e.g., a random number) associated with the user of the user terminal 10 that requested the identity verification processing. The verification unit 132 performs verification processing of the certification information acquired by the acquisition unit 131 using encrypted information that is encrypted using the secret information and managed in the blockchain system 2. The encrypted information is identity verification information used in the identity verification processing of a verified user encrypted with a random number. The provision unit 133 performs processing to provide the service to the user who requested the service, on the condition that the verification processing by the verification unit 132 proves that the user is a verified user. Thus, according to the embodiment of this disclosure, encrypted information obtained by encrypting identity verification information can be managed as public information in blockchain system 2 and shared among service providers of services that require identity verification for use. Therefore, the identity verification procedure for services that require identity verification for use can be simplified. Furthermore, according to the embodiment of this disclosure, not the identity verification information itself, but the encrypted information obtained by encrypting the identity verification information is managed as public information in blockchain system 2. Therefore, the privacy of service users of services that require identity verification for use can be protected.
[0158] Furthermore, in this disclosure, the confidential information is a secret value (e.g., a random number) associated with the user of user terminal 10, which is the source of the identity verification process. This allows for the setup of information to prove, using a zero-knowledge proof, that identity verification has been completed.
[0159] Furthermore, in the blockchain system 2 described in this disclosure, encrypted information is managed in conjunction with user identification information uniquely assigned to each verified user. The acquisition unit 131 acquires user identification information along with proof information, and the verification unit uses the user identification information acquired by the acquisition unit 131 to acquire encrypted information from the blockchain system 2. This allows for the management of information for proving that identity verification has been completed using zero-knowledge proofs for each user, and enables easy acquisition of information corresponding to the user making the service request.
[0160] Furthermore, in this disclosure, the acquisition unit 131 acquires a user registration request from the user terminal 10 used by the verified user, which requests user registration for the service. The provision unit 133 executes the user registration process for the verified user using the session information returned to the verified user, provided that the verification process by the verification unit 132 proves that the identity verification process has been completed. This simplifies user registration for verified users.
[0161] Furthermore, in this disclosure, the acquisition unit 131 acquires an anonymous user registration request from the user terminal 10 used by the verified user, which requests anonymous user registration for the service. The provision unit 133, on the condition that the verification process by the verification unit 132 proves that the identity verification process has been completed, uses the anonymous session information returned to the verified user to execute the anonymous user registration process for the verified user. This simplifies the anonymous user registration process for verified users.
[0162] Furthermore, in this disclosure, the acquisition unit 131 acquires remittance requests for the cashless service provided as a service from the user terminal 10 used by the verified user. The provision unit 133 executes the remittance process corresponding to the remittance request, provided that the verification process by the verification unit 132 proves that the identity verification process has been completed. This simplifies remittances for verified users.
[0163] Furthermore, in the blockchain system 2 described in this disclosure, a credit score calculated during the identity verification process is managed in conjunction with the user identification information. The acquisition unit 131 acquires a loan application request for the loan service provided as a service from the user terminal 10 used by the verified user. The provision unit 133 executes a loan application process in response to the loan application request using the credit score linked to the user identification information, provided that the verification process by the verification unit 132 proves that the identity verification process has been completed. This simplifies the loan application process for verified users.
[0164] Furthermore, in this disclosure, encrypted information is generated separately by each business operator that performs identity verification processing using different methods. In addition, in blockchain system 2, encrypted information associated with the same verified user is managed in conjunction with user identification information uniquely assigned to verified users by each business operator and business operator identification information unique to the business operator. This allows for the management of identity verification results from multiple business operators for the same user, and the payment processing device 100 can perform verification regarding the user requesting the service using the identity verification results from the business operator it requests.
[0165] Furthermore, in this disclosure, the identity verification process performed by each business operator is carried out using different methods corresponding to the authentication level required by the service. As a result, the payment processing device 100 can perform verification of the user requesting the service using the results of identity verification performed by the business operator corresponding to the authentication level it requires.
[0166] Furthermore, in this disclosure, when encrypted information is registered in blockchain system 2 by each business operator, the request for such registration is verified by signature information between each business operator and blockchain system 2. This prevents tampering with business operator identification information and impersonation of business operators.
[0167] The effects described above are not necessarily limited to those described herein and may include at least one of the effects described herein, or other effects.
[0168] <<7. Hardware Configuration>> The payment processing device 100 according to each embodiment described above is implemented by a computer 1000 having a configuration such as that shown in Figure 14. Figure 14 is a hardware configuration diagram showing an example of a computer that implements the functions of a payment processing device. The computer 1000 has a CPU 1100, RAM 1200, ROM (Read Only Memory) 1300, HDD (Hard Disk Drive) 1400, communication interface 1500, and input / output interface 1600. The various parts of the computer 1000 are connected by a bus 1050.
[0169] The CPU 1100 operates based on programs stored in the ROM 1300 or HDD 1400, and controls various parts. For example, the CPU 1100 loads the programs stored in the ROM 1300 or HDD 1400 into the RAM 1200 and executes processing corresponding to various programs.
[0170] ROM1300 stores boot programs such as the BIOS (Basic Input Output System) executed by CPU1100 when computer 1000 starts up, as well as programs that depend on the computer 1000's hardware.
[0171] The HDD1400 is a recording medium readable by the computer 1000, which non-temporarily records programs executed by the CPU 1100 and data used by such programs. Specifically, the HDD1400 is a recording medium that records a program for implementing the antenna switching process shown in Figure 3, for example.
[0172] The communication interface 1500 is an interface for the computer 1000 to connect to an external network 1550 (e.g., the Internet). For example, the CPU 1100 can receive data from other devices or transmit data it generates to other devices via the communication interface 1500.
[0173] The input / output interface 1600 is an interface for connecting the input / output device 1650 and the computer 1000. For example, the CPU 1100 receives data from input devices such as a keyboard or mouse via the input / output interface 1600. The CPU 1100 also transmits data to output devices such as a display, speaker, or printer via the input / output interface 1600. The input / output interface 1600 may also function as a media interface for reading programs recorded on a predetermined recording medium (media). Examples of media include optical recording media such as DVDs (Digital Versatile Discs) and PDs (Phase Change Rewritable Disks), magneto-optical recording media such as MOs (Magneto-Optical Disks), tape media, magnetic recording media, or semiconductor memory.
[0174] For example, when the computer 1000 functions as a payment processing device 100 according to the embodiment, the CPU 1100 of the computer 1000 executes a program loaded onto the RAM 1200 (such as a program to implement the "ZKP-Verify" process). This enables various processing functions to be performed by the control unit 130 of the payment processing device 100. The HDD 1400 stores programs for implementing the processing of the payment processing device 100 according to this disclosure, as well as data stored in the storage unit 111. The CPU 1100 reads and executes program data 1450 from the HDD 1400, but as another example, these programs may be obtained from other devices via an external network 1550.
[0175] Furthermore, this technology can also be configured as follows. (1) An information processing device that provides services requiring identity verification, An acquisition unit obtains, from a user terminal used by the user requesting the service, the certification information for proving by zero-knowledge proof that the user is a verified user who has completed the aforementioned identity verification process, and which is generated using confidential information that only the verified user would know. A verification unit that performs verification processing of the certificate information obtained by the acquisition unit using encrypted information of the identity verification information used in the identity verification process of the verified user, which is encrypted using the aforementioned confidential information and managed in the blockchain system, On the condition that the verification process by the verification unit proves that the user is the verified user, the service provider unit executes a process to provide the service to the user who requested the service. An information processing device equipped with the following features. (2) The aforementioned confidential information, This is a secret value associated with the user of the user terminal that is the source of the identity verification process. The information processing device described in (1) above. (3) In the aforementioned blockchain system, The encrypted information is managed in association with user identification information uniquely assigned to each of the aforementioned verified users. The acquisition unit is, Along with the aforementioned certification information, the user identification information is obtained, The verification unit, The user identification information acquired by the acquisition unit is used to acquire the encrypted information from the blockchain system. The information processing device described in (2) above. (4) The acquisition unit is, A user registration request requesting user registration for the aforementioned service is obtained from the user terminal used by the verified user. The aforementioned supply unit is, On the condition that the verification process by the verification unit proves that the identity verification process has been completed, the user registration process corresponding to the user registration request is executed using the session information returned to the verified user. The information processing device described in (3) above. (5) The acquisition unit is, An anonymous user registration request requesting anonymous user registration for the aforementioned service is obtained from the user terminal used by the verified user. The aforementioned supply unit is, On the condition that the verification process by the verification unit proves that the identity verification process has been completed, the anonymous user registration process corresponding to the anonymous user registration request is executed using the anonymous session information returned to the verified user. The information processing device described in (3) above. (6) The acquisition unit is, The remittance request in the cashless service provided as the aforementioned service is obtained from the user terminal used by the verified user. The aforementioned supply unit is, On the condition that the verification process by the verification unit proves that the identity verification process has been completed, the remittance process corresponding to the remittance request is executed. The information processing device described in (3) above. (7) In the aforementioned blockchain system, The credit score calculated in the identity verification process is managed in conjunction with the user identification information. The acquisition unit is, A loan application request for receiving the loan service provided as the aforementioned service is obtained from the user terminal used by the verified user. The aforementioned supply unit is, If the verification process of the certification information in the verification unit proves that the identity verification process has been completed, then the credit score associated with the user identification information is used to execute the loan application review process corresponding to the loan application request. The information processing device described in (3) above. (8) The aforementioned encrypted information is Each business operator that performs the aforementioned identity verification process in a different way generates its own version. In the aforementioned blockchain system, The encrypted information associated with the same verified user is managed in conjunction with the user identification information uniquely assigned to the verified user by each business operator and the business operator identification information unique to each business operator. The information processing device described in (3) above. (9) The identity verification process carried out by each of the aforementioned businesses is: This is implemented using different methods depending on the level of authentication required by the service. The information processing device described in (8) above. (10) When the aforementioned business operator registers the encrypted information in the blockchain system, the request for such registration is verified by signature information between the aforementioned business operator and the blockchain system. The information processing device described in (9) above. (11) Information processing equipment that provides services requiring identity verification using identity verification information, Certification information for proving, by zero-knowledge proof, that the user is a verified user who has completed the aforementioned identity verification process, and which is generated using confidential information that only the verified user would know, is obtained from the user terminal used by the user requesting the service. Using the encrypted information of the identity verification information used in the identity verification process of the verified user, which is encrypted using the aforementioned confidential information and managed in the blockchain system, the verification process of the certificate information is performed. On the condition that the verification process proves that the user is the verified user, the process for providing the service to the user who requested the service will be executed. Information processing methods. [Explanation of Symbols]
[0176] 1. Information Processing System 2 Blockchain System 3. Communication Network 10 User terminals 11 Communications Department 12 Input section 13 Output section 14 Imaging Unit 15 Positioning Unit 16 Detection unit 17 Memory section 17a Identity Verification Information Storage Section 17b Confidential Information Storage Unit 18 Control Unit 18a Identity Verification Request Department 18b Service Request Section 20 nodes 30 Identity Verification Processing Device 31 Communications Department 32 Storage section 33 Control Unit 33a Identity Verification Processing Unit 33b Registration Processing Unit 100 Payment Processing Units 110 Communications Department 120 Storage section 130 Control Unit 131 Acquisition Department 132 Verification Department 133 Provision Department
Claims
1. In a system comprising a user terminal and a service provider terminal that provides services to the user terminal, an information processing method for providing services to the user terminal, In the user terminal of a user requesting a service from the service terminal, a zero-knowledge proof Prove process is executed to generate proof information Proof, which indicates that the identity verification process based on the user's identity verification information in the identity verification processing device has been completed, based on the identity verification information and a random number. The service provider terminal receives the proof information Proof, which is obtained by performing the zero-knowledge proof Prove process transmitted from the user terminal, and performs a zero-knowledge proof Verify process to determine whether the proof information Proof was generated based on a random number received by the user terminal after the identity verification process has been completed. If the result of the zero-knowledge verification process proves that the user has completed the identity verification process in the identity verification processing device, the process for providing the requested service to the user terminal is executed in the service provider terminal. Information processing methods including
2. The service provided by the aforementioned identity verification processing device is an eKYC service. The information processing method according to claim 1.
3. The aforementioned identity verification information is image information that includes personal information. The information processing method according to claim 2.
4. The aforementioned zero-knowledge proof Prove process includes a Witness Reduction process, The information processing method according to claim 1.
5. The aforementioned zero-knowledge proof Prove process is a process that generates a correct polynomial in polynomial time, on the condition that a random number, which is the user's secret information, matches encrypted information obtained by encrypting identity verification information using that random number. The information processing method according to claim 1.
6. The aforementioned zero-knowledge proof verification process verifies whether the proof information Proof obtained from the user terminal was generated based on random numbers. The information processing method according to claim 1.
7. The aforementioned zero-knowledge proof verification process proves that the proof information Proof obtained from the user terminal was generated from a correct polynomial. The information processing method according to claim 1.
8. The services requested by the user terminal are at least one of the following: money transfer processing, loan application processing, and game application services. The information processing method according to claim 1.
9. The aforementioned zero-knowledge proof Prove process is, The following is performed using the aforementioned identity verification information, the aforementioned random number, and the encrypted information obtained by encrypting the identity verification information using the aforementioned random number: The information processing method according to claim 1.
10. The service usage request transmitted from the user terminal to the service provider terminal includes the proof information and the user identification information assigned to the user of the user terminal by the identity verification processing device. The information processing method according to claim 9.
11. The aforementioned zero-knowledge proof verification process is, This is executed using encrypted information associated with the aforementioned user identification information. The information processing method according to claim 10.
12. A system consisting of a user terminal and a service provider terminal that provides services to the user terminal, The aforementioned user terminal is A service request unit executes a zero-knowledge proof Prove process, which generates proof information Proof indicating that the identity verification process based on the user's identity verification information in the identity verification processing device has been completed, based on the identity verification information and a random number. It has, The aforementioned service terminal is A verification unit receives proof information Proof obtained by performing the zero-knowledge proof Prove process transmitted from the user terminal, and performs a zero-knowledge proof Verify process to determine whether the proof information Proof was generated based on a random number received by the user terminal after the identity verification process has been completed. If the result of the zero-knowledge verification process proves that the user has completed the identity verification process in the identity verification processing device, the provisioning unit executes a process to provide the requested service to the user terminal. A system that has
Citation Information
Patent Citations
Authentication device and authentication method
JP1995336348A
Method, system, and program for providing anonymous information
JP2004229071A
Anonymous order system, apparatus and program
JP2007287104A
Service providing system and service providing method
JP6504639B1
Methods and systems for universal storage and access to user-owned credentials for trans-institutional digital authentication
US20180270065A1