Reliability evaluation device, reliability evaluation system, and reliability evaluation method

The reliability evaluation device and system address the limitations of existing methods by allowing flexible policy setting and privacy protection, ensuring secure and context-specific reliability assessments in supply chains.

JP7863029B2Active Publication Date: 2026-05-20HITACHI LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
HITACHI LTD
Filing Date
2022-11-09
Publication Date
2026-05-20

AI Technical Summary

Technical Problem

Existing reliability evaluation methods, such as those described in Patent Document 1, lack flexibility in setting evaluation policies and fail to protect the privacy of subjects being evaluated, as they use predetermined trust policies and directly expose confidential information.

Method used

A reliability evaluation device and system that includes a supply chain graph unit, evidence management unit, policy management unit, and reliability evaluation unit, allowing for flexible evaluation policies and protecting privacy by excluding sensitive information during the evaluation process.

Benefits of technology

Enables reliability evaluation in supply chains based on customizable policies while safeguarding the privacy of evaluated subjects, providing transparent and context-specific assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007863029000001
    Figure 0007863029000001
  • Figure 0007863029000002
    Figure 0007863029000002
  • Figure 0007863029000003
    Figure 0007863029000003
Patent Text Reader

Abstract

To provide reliability evaluation means that can evaluate reliability based on an evaluation policy flexibly defined by a verifier according to situation and context of an evaluation target while protecting privacy of the evaluation target for reliability.SOLUTION: A reliability evaluation device includes: a supply chain graph unit that obtains a supply chain graph showing a relation between a plurality of subjects in a supply chain; an evidence management unit that obtains evidence supporting a credential of a subject from a credential holder who manages the subject; a policy management unit that stores an evaluation policy that defines an evaluation criterion for evaluating the evidence; and a reliability evaluation unit that generates and outputs a reliability evaluation result indicating the reliability of the credential for the subject in the supply chain graph by evaluating the evidence according to the evaluation policy.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a reliability evaluation device, a reliability evaluation system, and a reliability evaluation method.

Background Art

[0002] When a company promotes its business, it may not be able to carry out the business alone and may form an inter-company network. A typical example of such an inter-company network is a supply chain.

[0003] A supply chain is composed of business entities such as suppliers, assemblers, manufacturers, makers, resellers, and buyers that actually conduct commercial transactions. The procurement and shipment at each company are continuously connected, and it is a network for proceeding from raw material procurement to final product sales. A supply chain can be understood as a continuous system that encompasses the procurement, production management, development, logistics, distribution, and sales of physical goods such as manufactured products, as well as data and raw materials related to services provided via the Internet or the like. In a supply chain, supply chain management is known as a management method for integrally managing orders received and placed with business partners and the operations of internal departments using a computer.

[0004] In such a supply chain, problems may occur regarding the quality of manufactured products, compliance with regulations, security of services, etc. For example, a decrease in the quality of manufactured products, violation of environmental standards, leakage of confidential information, etc. can be considered. Therefore, in supply chain management, in order to guarantee quality assurance, regulation compliance, security, etc., an evaluation of the reliability in the supply chain is required.

[0005] Conventionally, several proposals have been made for evaluating the reliability of software assets. For example, in US Patent Application Publication No. 2019 / 030357 (Patent Document 1), The document describes a technique that includes "traversing a configuration graph of software assets using one or more processors, accessing trust records corresponding to multiple software assets in the configuration graph viewed by traversing the configuration graph, and for each of the multiple configuration software assets viewed by traversing, evaluating the reliability of the software asset using one or more processors based on the trust record corresponding to the software asset, wherein the trust record is exposed to a tamper-proof and immutable distributed data store." [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] U.S. Patent Application Publication No. 2019 / 030357 [Overview of the project] [Problems that the invention aims to solve]

[0007] Patent Document 1, mentioned above, describes a means for evaluating the reliability of software assets based on reliability records relating to the components of said software assets.

[0008] However, in the method described in Patent Document 1, the trust policy used to evaluate trust records is predetermined according to the type and role of the software asset and cannot be edited by the verifier performing the trust record evaluation. As a result, it is not possible to set detailed evaluation policies based on the situation, background, and context of the subject of the reliability evaluation, which limits the flexibility and effectiveness of the reliability evaluation.

[0009] Furthermore, in the method described in Patent Document 1, the information (trust records) obtained from the distributed data store is used directly to evaluate reliability, meaning that confidential information contained in that information is also passed on to the verifier. Moreover, the protection of the privacy of those who provide the information used for reliability evaluation (such as credential holders) has not been considered.

[0010] Therefore, this disclosure aims to provide a reliability evaluation method that allows for reliability evaluation in the supply chain, while protecting the privacy of those being evaluated, and enabling reliability evaluation based on evaluation policies flexibly defined by the verifier according to the circumstances and context of those being evaluated. [Means for solving the problem]

[0011] To solve the above problems, one representative reliability evaluation device of the present invention comprises a processor and a memory, wherein the memory includes a supply chain graph unit that acquires a supply chain graph showing the relationships between multiple subjects in the supply chain, The system includes an evidence management unit that obtains evidence supporting credentials relating to the subject from a credential holder managing the subject, a policy management unit that stores an evaluation policy that defines evaluation criteria for evaluating the evidence, and a processing instruction for causing the processor to function as a reliability evaluation unit that evaluates the evidence in accordance with the evaluation policy, thereby generating and outputting a reliability evaluation result indicating the reliability of the credentials relating to the subject in the supply chain graph. [Effects of the Invention]

[0012] According to this disclosure, it is possible to provide a reliability evaluation method that allows for reliability evaluation in the supply chain based on evaluation policies flexibly defined by the verifier according to the situation and context of the subject being evaluated, while protecting the privacy of the subject being evaluated. Other issues, configurations, and effects will be clarified by the description of the embodiments for carrying out the invention below. [Brief explanation of the drawing]

[0013] [Figure 1] Figure 1 shows a computer system for carrying out an embodiment of the present disclosure. [Figure 2] Figure 2 shows an example of the configuration of a reliability evaluation system according to the present disclosure. [Figure 3] Figure 3 shows an example of a supply chain graph according to an embodiment of this disclosure. [Figure 4] Figure 4 shows an example of the overall flow of the reliability management process in an embodiment of this disclosure. [Figure 5] Figure 5 shows an example of the flow of the reliability evaluation process according to the embodiment of this disclosure. [Figure 6] Figure 6 shows an example of the flow of evidence verification processing according to the embodiment of this disclosure. [Figure 7] Figure 7 shows an example of the flow of the evaluation policy application process according to the embodiment of this disclosure. [Figure 8] Figure 8 shows an example of the configuration of an evidence graph according to the embodiment of this disclosure. [Figure 9] Figure 9 shows an example of a user interface according to an embodiment of this disclosure. [Modes for carrying out the invention]

[0014] Embodiments of the present invention will be described below with reference to the drawings. However, the present invention is not limited to these embodiments. Furthermore, in the drawings, identical parts are denoted by the same reference numerals. Also, terms such as "first," "second," "third," etc. may be used in this disclosure to describe various elements or components, but it will be understood that these elements or components should not be limited by these terms. These terms are only used to distinguish one element or component from another. Thus, the first element or component discussed below could also be referred to as the second element or component without departing from the teachings of the inventive concept.

[0015] First, referring to FIG. 1, a computer system 100 for implementing embodiments of the present disclosure will be described. The mechanisms and apparatuses of the various embodiments disclosed herein may be applied to any suitable computing system. The main components of computer system 100 include one or more processors 102, a memory 104, a terminal interface 112, a storage interface 113, an I / O (input / output) device interface 114, and a network interface 115. These components may be interconnected via a memory bus 106, an I / O bus 108, a bus interface unit 109, and an I / O bus interface unit 110.

[0016] Computer system 100 may include one or more general-purpose programmable central processing units (CPUs) 102A and 102B collectively referred to as processor 102. In certain embodiments, computer system 100 may comprise multiple processors, and in other embodiments, computer system 100 may be a single CPU system. Each processor 102 executes instructions stored in memory 104 and may include an on-board cache.

[0017] In one embodiment, the memory 104 may include a random access semiconductor memory, a storage device, or a storage medium (either volatile or non-volatile) for storing data and programs. The memory 104 may store all or part of the programs, modules, and data structures that implement the functions described herein. For example, the memory 104 may store the reliability evaluation application 150. In one embodiment, the reliability evaluation application 150 may include instructions or descriptions for executing the functions described below on the processor 102.

[0018] In one embodiment, the reliability evaluation application 150 may be implemented in hardware via semiconductor devices, chips, logic gates, circuits, circuit cards, and / or other physical hardware devices instead of or in addition to a processor-based system. In one embodiment, the reliability evaluation application 150 may include data other than instructions or descriptions. In one embodiment, a camera, a sensor, or other data input device (not shown) may be provided to communicate directly with the bus interface unit 109, the processor 102, or other hardware of the computer system 100.

[0019] The computer system 100 may include a bus interface unit 109 that facilitates communication between the processor 102, the memory 104, the display system 124, and the I / O bus interface unit 110. The I / O bus interface unit 110 may be coupled to an I / O bus 108 for transferring data between various I / O units. The I / O bus interface unit 110 may communicate with a plurality of I / O interface units 112, 113, 114, and 115, also known as I / O processors (IOPs) or I / O adapters (IOAs), via the I / O bus 108.

[0020] The display system 124 may include a display controller, a display memory, or both. The display controller can provide video, audio, or both data to the display device 126. The computer system 100 may also include one or more devices such as sensors configured to collect data and provide that data to the processor 102.

[0021] For example, the computer system 100 may include biometric sensors that collect heart rate data and stress level data, environmental sensors that collect humidity data, temperature data, pressure data, etc., and motion sensors that collect acceleration data, movement data, etc. Other types of sensors can also be used. The display system 124 may be connected to a display device 126 such as a standalone display screen, television, tablet, or portable device.

[0022] The I / O interface unit has the function of communicating with various storage or I / O devices. For example, the terminal interface unit 112 can be fitted with user I / O devices 116 such as user output devices like video display devices and speaker televisions, and user input devices such as keyboards, mice, keypads, touchpads, trackballs, buttons, light pens, or other pointing devices. The user may use the user interface to operate the user input device to input data and instructions to the user I / O device 116 and the computer system 100, and to receive output data from the computer system 100. The user interface may be displayed on a display device, played back by a speaker, or printed via a printer, for example, through the user I / O device 116.

[0023] The storage interface 113 allows for the mounting of one or more disk drives or direct-access storage devices 117 (typically magnetic disk drive storage devices, but may be arrays of disk drives configured to appear as a single disk drive or other storage devices). In some embodiments, the storage device 117 may be implemented as any secondary storage device. The contents of memory 104 may be stored in the storage device 117 and read from the storage device 117 as needed. The I / O device interface 114 may provide an interface to other I / O devices such as printers and fax machines. The network interface 115 may provide a communication path so that the computer system 100 and other devices can communicate with each other. This communication path may be, for example, a network 130.

[0024] In one embodiment, the computer system 100 may be a device that receives requests from other computer systems (clients) that do not have a direct user interface, such as a multi-user mainframe computer system, a single-user system, or a server computer. In another embodiment, the computer system 100 may be a desktop computer, a portable computer, a laptop computer, a tablet computer, a pocket computer, a telephone, a smartphone, or any other suitable electronic device.

[0025] Next, with reference to Figure 2, a reliability evaluation system according to an embodiment of this disclosure will be described.

[0026] Figure 2 shows an example of the configuration of a reliability evaluation system 200 according to an embodiment of this disclosure. The reliability evaluation system 200 is a system for performing reliability evaluations in a supply chain, while protecting the privacy of the items being evaluated, and based on evaluation policies flexibly defined by the verifier according to the situation and context of the items being evaluated. As shown in Figure 2, the reliability evaluation system 200 mainly includes an issuer device 210, a holder device 220, a subject 225, a distributed ledger 230, a reliability evaluation device 240, and a communication network 250. In the reliability evaluation system 200, the issuer device 210, the holder device 220, the distributed ledger 230, and the reliability evaluation device 240 may be connected to each other via the communication network 250.

[0027] The issuer device 210 is a device used by an issuer to issue credentials relating to Subject 225, which will be described later. Here, credentials are official certifying information that demonstrates attributes, abilities, and claims relating to Subject 225, such as qualifications, experience, certificates, and letters of credentialism. The issuer may be a company or an inspection agency, and may issue credentials relating to Subject 225 using a credential issuance platform such as Blockcerts. The issuer may also make a decision on whether or not to issue credentials relating to Subject 225 based on evidence provided by Subject 225 and the holder device 220 that supports such credentials. The issuer device 210 may register credentials issued for a specific subject 225, as well as evidence supporting such credentials, in a distributed ledger 230, as described later.

[0028] The holder device 220 is a device used by a holder who manages the credentials issued by the issuer device 210. The holder here may be a company, organization, or individual, and may request the issuer device 210 to issue credentials for subject 225, store the credentials issued for subject 225, and present them to a third party as needed. In one embodiment, the holder here may be the same entity as the issuer described above.

[0029] Subject 225 is the subject of reliability evaluation. Subject 225 may include, but is not particularly limited to, specific parts manufactured in the manufacturing industry, specific services provided in the service industry, or people or animals. As described above, credentials relating to Subject 225 are issued by the issuer device 210 and managed by the holder device 220. Furthermore, as will be described later, the relationships between multiple Subjects 225 in the supply chain may be represented by a supply chain graph. In one embodiment, Subject 225 may be the same entity as the issuer holder described above.

[0030] The distributed ledger 230 is a data store agreed to be replicated, shared, and synchronized across multiple geographically different locations, countries, institutions, etc. The distributed ledger 230 may store information such as subject ID information 231 that uniquely identifies the subject 225, credential and evidence information 232 that shows credentials issued by the issuer device 210 and evidence supporting such credentials, a schema 233 that defines the structure of the data, and an evaluation policy 234 for evaluating credentials.

[0031] The reliability evaluation device 240 is a device for performing a reliability evaluation on the subject 225. As shown in Figure 2, the reliability evaluation device 240 may include a supply chain graph unit 242, an evidence management unit 244, a policy management unit 246, and a reliability evaluation unit 248. In one embodiment, the reliability evaluation device 240 may be implemented by the computer system 100 shown in Figure 1. In this case, the functions of each functional unit included in the reliability evaluation device 240, such as the supply chain graph unit 242, the evidence management unit 244, the policy management unit 246, and the reliability evaluation unit 248, may be implemented by software modules in the reliability evaluation application 150 shown in Figure 1.

[0032] The supply chain graph unit 242 is a functional unit for obtaining a supply chain graph that shows the relationships between multiple subjects 225 in the supply chain.

[0033] The evidence management unit 244 is a functional unit for obtaining evidence from the holder device 220 that corroborates the credentials relating to subject 225.

[0034] The policy management unit 246 is a functional unit for storing and managing evaluation policies that define evaluation criteria for evaluating the evidence obtained regarding subject 225.

[0035] The reliability evaluation unit 248 is a functional unit that generates and outputs reliability evaluation results indicating the reliability of the credentials related to subject 225 in the supply chain graph by evaluating the evidence obtained for subject 225 in accordance with the evaluation policy obtained from the policy management unit 246.

[0036] The communication network 250 may include, for example, a local area network (LAN), a wide area network (WAN), a satellite network, a cable network, a Wi-Fi network, or any combination thereof.

[0037] For the sake of explanation, Figure 2 shows a configuration including one issuer device 210, one holder device 220, one subject 225, one distributed ledger 230, and one reliability evaluation device 240, but this disclosure is not limited to this configuration. For example, if the issuer and the holder are the same entity, the issuer device 210 and the holder device 220 may be implemented in a single device. Furthermore, while Figure 2 shows a configuration including one subject 225, please note that in actual supply chains, there are numerous subjects, and each subject consists of multiple components (second subject, third subject, etc.).

[0038] As described above, the reliability evaluation system 200 configured in this way allows for reliability evaluation based on evaluation policies flexibly defined by the verifier according to the situation and context of the subject being evaluated, while protecting the privacy of the subject being evaluated.

[0039] Next, with reference to Figure 3, a supply chain graph according to an embodiment of this disclosure will be described.

[0040] Figure 3 is a diagram showing an example of a supply chain graph 300 according to the embodiment of this disclosure. Transaction relationships in a supply chain can be shown in graph format. A data structure that shows transaction relationships in a supply chain in graph format is called a "supply chain graph".

[0041] More specifically, a supply chain graph can show the constituent relationships of subjects traded within a supply chain. These subjects are not particularly limited; they may include physical objects such as specific parts manufactured in the manufacturing industry, logical objects such as specific services or data provided in the service industry, or living beings (e.g., humans, animals). In some supply chains, the final subject provided to the supply chain may consist of multiple secondary subjects. These secondary subjects, in turn, may consist of tertiary subjects. Each subject in a supply chain can be classified into a predetermined subject level based on its constituent relationships with other subjects.

[0042] As an example, consider the supply chain graph 300 shown in Figure 3. As shown in Figure 3, the supply chain graph 300 consists of a first subject level 310 containing the final subject provided to the supply chain, a second subject level 320 containing the subject used to realize the subject of the first subject level 310, and a third subject level 330 containing the subject used to realize the subject of the second subject level 320. The subject at each subject level may be associated with an identifier (C1, X1, Z1) that uniquely identifies the subject. For the sake of explanation, Figure 3 shows a supply chain consisting of three subject levels. However, this disclosure is not limited to this, and in practice, the number of subjects and subject levels included in the supply chain may be determined arbitrarily, depending on the processes and other factors that realize those subjects.

[0043] Furthermore, in the supply chain graph 300, the structural relationships between each subject are indicated by arrows. Here, the subject at the starting point of an arrow means that it is used to realize the subject at the ending point of the arrow. For example, in order to realize subject Z1, subjects X1, X2, and X3 are used. And in order to realize subject X1, subjects C1 and C2 are used. And in order to realize subject X2, subjects C1, C2, and C3 are used. Here, the expression "to realize" means to create a predetermined subject in accordance with its type, such as by assembling, manufacturing, generating, developing, or providing it.

[0044] Thus, by using a supply chain graph, the constituent relationships of the subjects provided in a supply chain can be easily modeled. Furthermore, as mentioned above, the supply chain graph shown in Figure 3 may be used in various fields, such as the supply of parts manufactured in the manufacturing industry, the education and training of personnel, and the development of services and data provided in the service industry. As an example, in one embodiment, the supply chain graph may be used to represent the development of software elements in SBOM (Software Bill-of-Materials).

[0045] Next, with reference to Figure 4, the overall flow of the reliability management process according to the embodiment of this disclosure will be described.

[0046] Figure 4 shows an example of the overall flow of the reliability management process 400 in an embodiment of the present disclosure. The reliability management process 400 is a process for evaluating the reliability of credentials relating to a specific subject in the supply chain, and consists of a credential issuance process 450 and a reliability evaluation process 500. The reliability management process 400 may also be performed by the devices and functional units of the reliability evaluation system 200 described above, with reference to Figure 2.

[0047] First, in step S410, the owner device 220 transmits a credential issuance request to the issuer device 210 requesting the issuance of credentials for the subject (hereinafter, "the first subject"). This credential issuance request may include the type of credentials desired and evidence to demonstrate the subject's compliance with those credentials. As an example, an automobile manufacturer (owner) that manufactures an automobile (subject) may submit information on the automobile's exhaust gas volume (evidence) obtained by an inspection agency that conducts vehicle exhaust gas tests to the certification authority (issuer) of the environmental compliance standards in order to demonstrate the automobile's compliance with the environmental compliance standards (credentials).

[0048] Next, in step S420, the issuer device 210 verifies the credential issuance request received from the holder device 220, and if it determines to issue credentials for the first subject, it issues the credentials and transmits them to the holder device 220 and the distributed ledger 230. Here, as described above, the issuer device 210 may determine whether or not to issue credentials for the subject based on evidence provided by the holder device 220 and supporting those credentials. Alternatively, the issuer device 210 may transmit the evidence of the credentials along with the credentials to the distributed ledger 230.

[0049] Next, in step S430, the distributed ledger 230 registers the credentials and evidence of those credentials received from the issuer device 210. As a result, the credentials and evidence of those credentials issued by the issuer device 210 are stored in a tamper-proof and immutable manner.

[0050] Next, in step S440, the reliability evaluation device 240 sends a credential verification request to the holder device 220 requesting verification of credentials relating to the first subject.

[0051] Next, in step S450, the holder device 220 requests the distributed ledger 230 to send the evidence registered in the distributed ledger 230 in step S430 in order to respond to the credential proof request. Then, in step S460, the distributed ledger 230 sends the requested evidence to the holder device 220, and in step S470, the holder device 220 retrieves the evidence from the distributed ledger 230.

[0052] Next, in step S480, the holder device 220 transmits the evidence and credentials acquired in step S470 to the reliability evaluation device 240. Here, when transmitting the evidence, the holder device 220 may transmit data with some of the evidence excluded to the reliability evaluation device 240. This allows the holder device 220 to exclude, for example, personal information or confidential information from the evidence transmitted to the reliability evaluation device 240, thereby protecting the privacy of the first subject.

[0053] Next, in step S490, the reliability evaluation device 240 evaluates the reliability of the first subject's credentials based on the evidence obtained from the holder device 220. Here, the reliability evaluation device 240 may use an evaluation policy specified to the user, such as a user of the reliability evaluation device 240, in order to evaluate the reliability of the first subject's credentials. Details of the reliability evaluation process 500 will be explained later, so we will omit the explanation here.

[0054] According to the reliability management process 400 described above, in the supply chain, reliability assessments can be conducted based on evaluation policies flexibly defined by the verifier according to the situation and context of the subject being assessed, while protecting the privacy of the subject being assessed.

[0055] Next, with reference to Figure 5, the flow of the reliability evaluation process according to the embodiment of this disclosure will be described.

[0056] Figure 5 shows an example of the flow of the reliability evaluation process 500 according to the embodiment of this disclosure. The reliability evaluation process 500 is a process for obtaining evidence of credentials and evaluating the reliability of credentials using the obtained evidence, and substantially corresponds to the reliability evaluation process 500 shown in Figure 4.

[0057] As mentioned above, in a supply chain, the subject subject to reliability assessment is composed of multiple secondary subjects, and these secondary subjects are composed of tertiary subjects, and so on. The constituent relationships of subjects can continue intermittently down to many subject levels. Furthermore, the reliability of the subject being evaluated is influenced by the reliability of the secondary and tertiary subjects (hereinafter referred to as "constituent subjects") used to realize that subject. Therefore, it is desirable to consider constituent subjects when evaluating the reliability of a particular subject. However, depending on the subject, the holders of the credentials may differ. Therefore, the reliability evaluation process 500 according to the embodiment of this disclosure shown in Figure 5 involves obtaining evidence of the subject from each of the holders of the constituent subjects of the subject to be evaluated for reliability, and evaluating the reliability of the subject based on the obtained evidence. For the sake of explanation, we will show an example involving three holders, but in reality, the number of holders is not particularly limited.

[0058] First, in step S505, the supply chain graph unit 242 of the reliability evaluation device 240 acquires a supply chain graph showing the flow of realization (manufacturing, development, provision, etc.) of the subject to reliability evaluation (hereinafter referred to as the "first subject"). Here, the reliability evaluation device 240 may, for example, use an existing supply chain graph method to generate a supply chain graph based on information about buyers and suppliers related to the first subject and its constituent subjects, or it may acquire a pre-created supply chain from a predetermined database or the like.

[0059] Next, in step S510, the policy management unit 246 of the reliability evaluation device 240 acquires an evaluation policy for evaluating the reliability of the first subject. This evaluation policy is information that defines evaluation criteria for evaluating evidence supporting the subject's credentials, and may be created, for example, by a user (verifier). In one embodiment, this evaluation policy may be information that determines the validity of the evidence depending on the source, acquisition route, context, content, etc. For example, when evaluating compliance of an automobile with environmental compliance standards, the policy management unit 246 may use evaluation criteria that specify the exhaust gas standards required of the automobile and the form and content of the information that is permitted to demonstrate compliance with said exhaust gas standards as the evaluation policy.

[0060] Next, in step S515, the reliability evaluation device 240 sends a first credential verification request, which requests verification of the credentials of the first subject, to the first holder device 501, which is the holder's terminal managing the first subject.

[0061] Next, in step S520, the first holder device 501 receives the first credential verification request from the reliability evaluation device 240.

[0062] Next, in step S525, the first holder device 501 obtains first evidence from the distributed ledger 230 or the like to support the credentials of the first subject, and sends a second credential verification request to the second holder device 502, which is the terminal of the holder managing the second subject, requesting proof of the credentials of the second subject, which is a constituent subject of the first subject.

[0063] Next, in step S530, the second holder device 502 receives a second credential verification request from the first holder device 501.

[0064] Next, in step S535, the second holder device 502 obtains second evidence from the distributed ledger 230 or the like to support the credentials of the second subject, and sends a third credential verification request to the third holder device (not illustrated in Figure 5), which is the terminal of the holder managing the third subject, requesting proof of the credentials of the third subject, which is a constituent subject of the second subject.

[0065] Next, in step S540, the second holder device 502 receives third evidence from the third holder device to corroborate the credentials of the third subject. Note that the process for obtaining the third piece of evidence on the third holder device is omitted here, but it may be obtained from the distributed ledger 230, etc., similar to the first and second holder devices.

[0066] Next, in step S545, the second holder device 502 transfers the second evidence obtained in step S535 and the third evidence obtained in step S540 to the first holder device 501. Here, when transmitting the evidence, the second holder device 502 may transmit data to the first holder device 501 with some of the second evidence excluded. In this way, the second holder device 502 can exclude, for example, personal information or confidential information from the evidence transmitted to the reliability evaluation device 240, thereby protecting the privacy of the second subject.

[0067] Next, in step S550, the first holder device 501 receives from the second holder device 502 a second piece of evidence to support the credentials of the second subject and a third piece of evidence to support the credentials of the third subject.

[0068] Next, in step S555, the first holder device 501 transfers the first evidence obtained in step S525, and the second and third pieces of evidence obtained in step S550, to the reliability evaluation device 240. Here, when transmitting the evidence, the first holder device 501 may send data to the reliability evaluation device 240 with some of the first evidence excluded. In this way, the first holder device 501 can exclude, for example, personal information or confidential information from the evidence sent to the reliability evaluation device 240, thereby protecting the privacy of the first subject.

[0069] Next, in step S560, the reliability evaluation device 240 receives from the first holder device 501 a first piece of evidence to support the credentials of the first subject, a second piece of evidence to support the credentials of the second subject, and a third piece of evidence to support the credentials of the third subject.

[0070] Next, in step S565, the evidence management unit 244 of the reliability evaluation device 240 generates an evidence graph corresponding to the first subject based on the first evidence, second evidence, third evidence received in step S560 and the supply chain graph generated in step S505. This evidence graph is a data structure that shows in graph form the evidence supporting the credentials of the first subject and its constituent subjects that are the subject of the reliability evaluation. For details on the composition of the evidence graph, please refer to Figure 8, which will be explained later; therefore, the explanation will be omitted here.

[0071] Next, in step S570, the reliability evaluation unit 248 of the reliability evaluation device 240 verifies the evidence in the evidence graph generated in step S565, thereby associating the evidence verification information with each node in the evidence graph. Details regarding the process of verifying evidence in the evidence graph will be explained later in Figure 6, so the explanation is omitted here.

[0072] Next, in step S575, the reliability evaluation unit 248 of the reliability evaluation device 240 applies the evaluation policy acquired in step S510 to the evidence verification information associated with each node in the evidence graph in step S570, thereby associating a reliability score with each node in the evidence graph.

[0073] Here, the reliability evaluation unit 248 may analyze the evidence graph based on the evaluation policy to determine the relevance of each node in the evidence graph for evaluating the reliability of the subject being evaluated. Subsequently, the reliability evaluation unit 248 may remove from the evidence graph any nodes whose relevance does not meet a predetermined relevance criterion. Here, relevance refers to the degree to which a node relates to the reliability of the subject being evaluated, and serves as an indicator for determining whether a particular node is useful for reliability evaluation according to a particular evaluation policy. In one embodiment, the relevance of a node to the subject being evaluated may be determined by similarity determination based on natural language processing, or it may be determined based on user input. Details regarding the process of applying evaluation policies to the evidence verification information associated with each node in the evidence graph will be described later in Figure 7, so the explanation is omitted here.

[0074] Next, in step S580, the reliability evaluation unit 248 of the reliability evaluation device 240 generates a reliability evaluation result for the first subject by aggregating the reliability scores associated with each node in the evidence graph in step S570.

[0075] More specifically, in step S580, the reliability evaluation unit 248 may identify each node corresponding to the constituent subject of the subject subject to reliability evaluation in the evidence graph, and multiply the reliability scores associated with the identified nodes to generate an overall reliability score as a reliability evaluation result, which indicates the reliability of the credentials of the subject subject to reliability evaluation.

[0076] In one embodiment, the reliability evaluation unit 248 may use the average reliability score of the nodes corresponding to the constituent subjects of the subject to be evaluated as the reliability evaluation result, or it may use the reliability score of each node as is as the reliability evaluation result.

[0077] In this way, the reliability of the subject being evaluated can be calculated based on the reliability of each constituent subject in the supply chain. Furthermore, by calculating the reliability for each subject in the supply chain, it becomes possible to understand the impact that each individual subject has on the final reliability evaluation result, enabling a highly transparent reliability evaluation.

[0078] In the reliability assessment process 500 described above, the evidence provided by subject credential holders in the supply chain is evaluated based on the evaluation policy defined by the verifier. This allows for the establishment of appropriate evaluation criteria tailored to the background and circumstances of the supply chain, as well as flexible reliability assessments from different perspectives by different verifiers. This allows, for example, verifier A to adopt evaluation criteria based on the supplier's renewable energy usage, while verifier B can adopt evaluation criteria based on carbon neutrality.

[0079] Furthermore, in the reliability assessment process 500 described above, the credential holder can exclude any information from the evidence that supports their credentials when sending it to the verifier. This allows for the reliability of the subject's credentials to be assessed while protecting the subject's privacy.

[0080] Next, with reference to Figure 6, the evidence verification process according to the embodiment of this disclosure will be described.

[0081] Figure 6 shows an example of the flow of the evidence verification process 600 according to an embodiment of this disclosure. The evidence verification process 600 shown in Figure 6 is a process for verifying evidence supporting the credentials of each subject in the supply chain graph, and may be performed by the reliability evaluation unit 248 of the reliability evaluation device 240 shown in Figure 2. Furthermore, the evidence verification process 600 shown in Figure 6 substantially corresponds to step S570 in the reliability evaluation process 500 shown in Figure 5.

[0082] First, in step S610, the reliability evaluation unit 248 searches the evidence graph and generates evidence verification information indicating the validity of the evidence by performing a predetermined evidence verification method on the evidence associated with each node corresponding to the subject. Here, effectiveness is a measure of the degree to which specific evidence supports the credentials of a particular subject, and may be expressed as a binary indicator such as "effective" or "ineffective," or as a numerical value within the range of "0 to 100" (higher values ​​indicate higher effectiveness). In one embodiment, the evidence verification information may include information such as the source, acquisition method, context, and content of the evidence, in addition to the effectiveness of the evidence.

[0083] Furthermore, the evidence verification method used here may be selected depending on the type of evidence. For example, if an electronic signature is used as evidence for certain credentials, the reliability evaluation unit 248 may perform cryptographic authentication (such as public-key cryptography) on the electronic signature as the evidence verification method and assign a digital certificate issued by a certification authority as the RoT (Root of Trust) of the credentials.

[0084] Next, in step S620, the reliability evaluation unit 248 associates the evidence verification information generated in step S610 with the corresponding node in the evidence graph. For example, the reliability evaluation unit 248 may associate the first evidence verification information generated by verifying the first evidence corresponding to the first node in the evidence graph with the first node. In this way, each node in the evidence graph is associated with the verification results of the evidence supporting the credentials of the subject that the node represents.

[0085] According to the evidence verification process 600 described above, by verifying the credential evidence of each subject in the supply chain, it becomes possible to perform a reliability assessment that considers not only the subject being evaluated for reliability but also the constituent subjects of that subject.

[0086] Next, with reference to Figure 7, the evaluation policy application process according to the embodiment of this disclosure will be described.

[0087] Figure 7 shows an example of the flow of the evaluation policy application process 700 according to the embodiment of this disclosure. The evaluation policy application process 700 shown in Figure 7 is a process for evaluating evidence verification information indicating the validity of credential evidence based on an evaluation policy defined by the user, etc., and may be performed by the reliability evaluation unit 248 of the reliability evaluation device 240 shown in Figure 2. Furthermore, the evaluation policy application process 700 shown in Figure 7 substantially corresponds to step S575 in the reliability evaluation process 500 shown in Figure 5.

[0088] First, in step S710, the reliability evaluation unit 248 searches the evidence graph and applies the evaluation policy acquired by the policy management unit 246 based on user input to the evidence verification information and ingress edges associated with each node.

[0089] More specifically, when applying an evaluation policy to a particular node, the reliability evaluation unit 248 may search a predefined database of evaluation policies for an evaluation policy corresponding to the subject represented by that node. Subsequently, the reliability evaluation unit 248 may analyze the evidence graph based on the retrieved evaluation policy to determine the relevance of each node in the evidence graph for evaluating the reliability of the subject being evaluated. Next, the reliability evaluation unit 248 may remove nodes from the evidence graph whose relevance does not meet predetermined relevance criteria.

[0090] Next, the reliability evaluation unit 248 analyzes the evidence verification information associated with each node in the evidence graph, which excludes nodes whose relevance does not meet predetermined relevance criteria, based on an evaluation policy, to determine whether each node meets the evaluation criteria defined by the evaluation policy (source of evidence, acquisition path, context, constituent relationship with other subjects, content, etc.).

[0091] Next, the reliability evaluation unit 248 calculates a reliability score indicating the reliability of the subject credentials corresponding to the node, based on the consistency between the retrieved evaluation policy and the evidence verification information. This reliability score may be expressed as a binary index such as "0" or "1" ("0" means unreliable, and "1" means reliable), or as a numerical value within the range of "0 to 100" (higher numbers indicate higher reliability).

[0092] Next, in step S720, the reliability evaluation unit 248 associates the reliability score generated in step S710 with the node in the evidence graph. For example, the reliability evaluation unit 248 may associate the first reliability score calculated by verifying the first evidence corresponding to the first node in the evidence graph with the first node. Thus, each node in the evidence graph is associated with a reliability score that indicates the reliability of the subject credentials represented by that node.

[0093] Let's consider an example of evaluating the first evidence verification information associated with the first node based on an evaluation policy. Assume that the evaluation policy applied to the first subject represented by the first node defines the evaluation criterion as "the first subject has the second subject as a constituent subject in the supply chain." In this case, the reliability evaluation unit 248 searches the evidence graph and analyzes the evidence verification information associated with the first node and the structure of the evidence graph to determine whether the first subject has the second subject as a constituent subject in the supply chain.

[0094] If the first subject has the second subject as a constituent subject in the supply chain, the reliability evaluation unit 248 associates a reliability score of "1", indicating "reliable", with the first node for the credentials of the said subject. On the other hand, if the first subject does not have the second subject as a constituent subject in the supply chain, the reliability evaluation unit 248 associates a reliability score of "0", indicating "unreliable", with the first node for the credentials of the said subject. In this way, the reliability score of a subject can be calculated based on the presence or absence of specific constituent relationships.

[0095] According to the evaluation policy application process 700 described above, the evidence verification results associated with each node in the evidence graph, which excludes nodes whose relevance does not meet the predetermined relevance criteria, can be evaluated based on the evaluation policy defined by the verifier. In this way, verifiers can define their own evaluation criteria for each subject, depending on the source, acquisition method, context, and content of the credential evidence for that subject. This allows for the establishment of appropriate evaluation criteria tailored to the background and circumstances of the supply chain, as well as flexible reliability assessments from different perspectives by different verifiers.

[0096] Furthermore, when evaluating the reliability of an evidence graph, excluding specific nodes or groups of nodes from the graph allows for the exclusion of subjects irrelevant to reliability in a given situation or context, enabling reliability evaluation in the situation or context desired by the verifier.

[0097] Next, with reference to Figure 8, an evidence graph according to an embodiment of this disclosure will be described.

[0098] Figure 8 shows an example of the configuration of an evidence graph 900 according to an embodiment of this disclosure. As described above, the evidence graph 900 according to the embodiment is a data structure that shows evidence in graph format that supports the credentials of a first subject subject to reliability evaluation and its constituent subjects. More specifically, the first subject and the constituent subjects for realizing the first subject in the supply chain may each be represented as different nodes, and the relationships between subjects in the supply chain graph may be represented as edges. In addition, each node in the evidence graph may be associated with the credentials of that node and the evidence that supports those credentials.

[0099] As an example, consider the evidence graph 900 shown in Figure 8. As shown in Figure 8, the evidence graph 900, similar to the supply chain graph 300 described with reference to Figure 3, consists of a first subject level 910 containing nodes representing the final subject provided to the supply chain, a second subject level 920 containing nodes representing the subject used to realize the subject of the first subject level 910, and a third subject level 930 containing nodes representing the subject used to realize the subject of the second subject level 920. The subject nodes in each subject level may be associated with identifiers (C1, X1, Z1) that uniquely identify the subject. For the sake of explanation, Figure 8 shows an evidence graph consisting of three subject levels, but this disclosure is not limited to this. In practice, the number of subjects and subject levels included in the supply chain may be determined arbitrarily, depending on the processes that realize those subjects.

[0100] In one embodiment, the evidence graph 900 may be generated based on a supply chain graph (for example, the supply chain graph 300 described with reference to Figure 3) and evidence supporting the credentials of each subject. For example, the evidence management unit 244 may generate a supply chain graph showing the flow of realization (manufacturing, development, provision, etc.) of the reliability evaluation supply chain graft, and then generate the evidence graph by associating the evidence obtained for each subject in the supply chain graph with the corresponding node. As a result, as shown in the evidence graph 900, each node representing a subject is associated with evidence 945 supporting the credentials of that subject.

[0101] In this way, generating evidence graphs makes it easy to model the relationships between subjects traded in a supply chain and the evidence supporting the credentials of each subject. Furthermore, by applying evaluation policies to such evidence graphs, it becomes possible to perform reliability assessments that take into account the evidence for each subject's credentials and the constituent relationships between subjects.

[0102] Next, with reference to Figure 9, this figure shows an example of a user interface according to an embodiment of the present disclosure.

[0103] Figure 9 shows an example of a user interface 1000 according to an embodiment of this disclosure. The user interface 1000 shown in Figure 9 is a user interface for allowing the user to define an evaluation policy and for presenting the reliability evaluation results to the user, and may be managed by the policy management unit 246 or reliability evaluation unit 248 of the reliability evaluation device 240 shown in Figure 2.

[0104] As shown in Figure 9, the user interface 1000 includes an evaluation policy management screen 1010 and a reliability evaluation results screen 1020.

[0105] The Evaluation Policy Management Screen 1010 is a screen for defining evaluation policies that define evaluation criteria for assessing the reliability of subject credentials. On the Evaluation Policy Management Screen 1010, users can select a specific subject, view its constituent subjects, and define an evaluation policy for that subject. Furthermore, when defining an evaluation policy, users can specify the context to which the evaluation policy applies.

[0106] Here, "context" refers to information indicating the situation or circumstances to which the evaluation policy should be applied. For example, if the subject subject to reliability evaluation is used in a first region, it is desirable to evaluate its reliability based on the first evaluation criteria corresponding to that first region. However, if the same subject is used in a second region, it is desirable to evaluate its reliability based on the second evaluation criteria corresponding to that second region. Therefore, in the evaluation policy management screen 1010, these regions can be registered as different contexts, and an appropriate evaluation policy can be set for each context to perform reliability evaluations that take the subject's context into account.

[0107] The reliability evaluation results screen 1020 is a screen that displays the reliability evaluation results generated by evaluating the reliability of the subject credentials based on a predetermined evaluation policy. As shown in Figure 9, in one embodiment, the reliability evaluation results screen 1020 may display a supply chain graph and information on the reliability score generated for each subject in the supply chain graph as the reliability evaluation results.

[0108] The reliability evaluation means according to the embodiments of this disclosure have been described above. As described above, one aspect of the reliability evaluation means according to the embodiments of this disclosure relates to evaluating the reliability of subject credentials by evaluating evidence provided by subject credential holders in the supply chain based on an evaluation policy defined by the verifier. In this way, verifiers can define their own evaluation criteria for each subject, depending on the source, acquisition method, context, and content of the credential evidence for that subject. This allows for the establishment of appropriate evaluation criteria tailored to the background and circumstances of the supply chain, as well as flexible reliability assessments from different perspectives by different verifiers.

[0109] Furthermore, in one embodiment of the reliability evaluation means according to the embodiments of this disclosure, the credential holder can exclude any information from the evidence when transmitting the evidence supporting the credentials to the verifier. This makes it possible to evaluate the reliability of the subject's credentials while protecting the subject's privacy.

[0110] Furthermore, in one embodiment of the reliability evaluation means according to the present disclosure, when performing a reliability evaluation on an evidence graph, specific nodes or groups of nodes can be excluded from the evidence graph. In this way, by excluding subjects that are irrelevant to reliability in specific situations or contexts, it becomes possible to perform reliability evaluations in situations or contexts desired by the verifier.

[0111] Based on the above, this disclosure provides a reliability evaluation method that allows for reliability evaluation in the supply chain, while protecting the privacy of those being evaluated, and enabling reliability evaluation based on evaluation policies flexibly defined by the verifier according to the situation and context of those being evaluated.

[0112] The above describes, as an example, how the reliability evaluation means according to the embodiments of this disclosure may be implemented as an apparatus, system, and method. However, this disclosure is not limited thereto, and may be implemented as, for example, a computer program. This computer program may be introduced into a computer system implementing the reliability evaluation means according to the embodiments of this disclosure via a network and / or via a portable storage medium from a storage medium of an external device.

[0113] For example, one embodiment of the present disclosure is a reliability evaluation computer program in a computer system including a memory for storing processing instructions and a processor, wherein the processing instructions stored in the memory are used to generate an evidence graph in which a first subject among the plurality of subjects is represented as a first node, a second subject related to the first subject in the supply chain is represented as a second node connected to the first node, a first evidence supporting the first credentials for the first subject is associated with the first node, and a second evidence supporting the second credentials for the second subject is associated with the second node, and the first subject is evaluated. Steps include defining a first evaluation policy that defines evaluation criteria for evaluating the second subject, a second evaluation policy that defines evaluation criteria for evaluating the second subject, a step of generating first evidence verification information indicating the validity of the first evidence associated with the first node by performing a predetermined evidence verification method on the first node in the evidence graph, and associating the first evidence verification information with the first node, a step of calculating a first reliability score indicating the reliability of the first credentials relating to the first subject by evaluating the first evidence verification information associated with the first node based on the first evaluation policy, and associating the calculated first reliability score with the first node, a step of generating second evidence verification information indicating the validity of the second evidence associated with the second node by performing a predetermined evidence verification method on the second node in the evidence graph, and associating the second evidence verification information with the second node, and evaluating the second evidence verification information associated with the second node based on the second evaluation policy.This reliability evaluation computer program is characterized by causing the processor to perform the following steps: calculate a second reliability score indicating the reliability of the second credentials with respect to the second subject, associate the calculated second reliability score with the second node, and generate and output a reliability evaluation result indicating the reliability of the first credentials with respect to the first subject based on the calculated first reliability score and the second reliability score.

[0114] Although embodiments of the present invention have been described above, the present invention is not limited to the embodiments described above, and various modifications are possible without departing from the spirit of the present invention. [Explanation of Symbols]

[0115] 200 Reliability Evaluation Systems 210 Issuer device 220 Holder Device 225 Subjects 230 Distributed Ledger 240 Reliability evaluation device 242 Supply Chain Graph Section 244 Evidence Management Department 246 Policy Management Department 248 Reliability Evaluation Department

Claims

1. A reliability evaluation device, Equipped with a processor and memory, The aforementioned memory is A supply chain graph unit that obtains a supply chain graph showing the relationships between multiple subjects in a supply chain, An evidence management unit obtains evidence supporting the credentials relating to the subject from the credential holder who manages the subject, A policy management unit that stores evaluation policies that define evaluation criteria for evaluating the aforementioned evidence, A reliability evaluation unit generates and outputs a reliability evaluation result indicating the reliability of the credentials relating to the subject in the supply chain graph by evaluating the evidence in accordance with the evaluation policy. A reliability evaluation device characterized by including processing instructions for causing the processor to function.

2. The aforementioned evidence management unit, Based on the supply chain graph and the evidence supporting the credentials relating to the subject, an evidence graph corresponding to the subject is generated. The aforementioned evidence graph is, The first subject among the plurality of subjects is represented as a first node, and the second subject related to the first subject in the supply chain is represented as a second node connected to the first node. The first node corresponds to the first evidence supporting the first credentials relating to the first subject, The second node is associated with the second piece of evidence supporting the second credential relating to the second subject. A reliability evaluation apparatus according to claim 1, characterized in that

3. The aforementioned policy management department, If, among the aforementioned multiple subjects, the first subject is designated as the subject of reliability evaluation, a first evaluation policy is defined that defines a first evaluation criterion for evaluating the first subject based on user input. The reliability evaluation apparatus according to claim 2, characterized in that

4. The reliability evaluation unit, By performing a predetermined evidence verification method on the first node in the evidence graph, first evidence verification information indicating the validity of the first evidence associated with the first node is generated, and the first evidence verification information is associated with the first node. By evaluating the first evidence verification information associated with the first node based on the first evaluation policy, a first reliability score indicating the reliability of the first credentials with respect to the first subject is calculated, and the calculated first reliability score is associated with the first node. The reliability evaluation apparatus according to claim 3, characterized in that

5. The reliability evaluation unit, By performing a predetermined evidence verification method on the second node in the evidence graph, second evidence verification information indicating the validity of the second evidence associated with the second node is generated, and the second evidence verification information is associated with the second node. By evaluating the second evidence verification information associated with the second node based on the second evaluation policy, a second reliability score indicating the reliability of the second credentials with respect to the second subject is calculated, and the calculated second reliability score is associated with the second node. Based on the calculated first reliability score and the second reliability score, a reliability evaluation result is generated that indicates the reliability of the first credentials with respect to the first subject. The reliability evaluation apparatus according to claim 4, characterized in that

6. The reliability evaluation unit, By analyzing the evidence graph based on the first evaluation policy, the relevance of the second subject to evaluating the reliability of the first subject is determined. If the correlation calculated for the second subject does not meet the predetermined correlation criteria, the second node is removed from the evidence graph, and then the reliability evaluation result showing the reliability of the first credential with respect to the first subject is generated. The reliability evaluation apparatus according to claim 5, characterized in that

7. An issuer device that issues credentials for a subject, A holder device that manages the subject and holds the credentials issued by the issuer device, A distributed ledger storing the aforementioned credentials and evidence supporting those credentials, A reliability evaluation system in which a reliability evaluation device for evaluating the reliability of the subject's credentials is connected via a communication network, The reliability evaluation device is, Equipped with a processor and memory, The aforementioned memory is A supply chain graph unit that obtains a supply chain graph showing the relationships between multiple subjects in a supply chain, An evidence management unit that stores the evidence in the distributed ledger and that supports the credentials relating to the subject, and acquires the evidence from the holder device that manages the subject, A policy management unit that stores evaluation policies that define evaluation criteria for evaluating the aforementioned evidence, A reliability evaluation unit generates and outputs a reliability evaluation result indicating the reliability of the credentials relating to the subject in the supply chain graph by evaluating the evidence in accordance with the evaluation policy. A reliability evaluation system characterized by including processing instructions for causing the processor to function as described above.

8. A device comprising a processor and memory, The aforementioned memory is A supply chain graph unit that obtains a supply chain graph showing the relationships between multiple subjects in a supply chain, An evidence management unit obtains evidence supporting the credentials relating to the subject from the credential holder who manages the subject, A policy management unit that stores evaluation policies that define evaluation criteria for evaluating the aforementioned evidence, A reliability evaluation unit generates and outputs a reliability evaluation result indicating the reliability of the credentials relating to the subject in the supply chain graph by evaluating the evidence in accordance with the evaluation policy. A reliability evaluation method in a reliability evaluation apparatus, characterized by including processing instructions for causing the processor to function as follows: The supply chain graph unit includes the steps of obtaining a supply chain graph showing the relationships between multiple subjects in the supply chain, The evidence management unit obtains evidence from the credential holder who manages the subject that supports the credentials relating to the subject, The evidence management unit generates an evidence graph in which, based on the supply chain graph and the evidence supporting the credentials relating to the subject, a first subject among the plurality of subjects is represented as a first node, a second subject related to the first subject in the supply chain is represented as a second node connected to the first node, the first evidence supporting the first credentials relating to the first subject is associated with the first node, and the second evidence supporting the second credentials relating to the second subject is associated with the second node. The policy management unit defines a first evaluation policy that defines evaluation criteria for evaluating the first subject, and a second evaluation policy that defines evaluation criteria for evaluating the second subject. The reliability evaluation unit performs a predetermined evidence verification method on the first node in the evidence graph to generate first evidence verification information indicating the validity of the first evidence associated with the first node, and associates the first evidence verification information with the first node. The reliability evaluation unit evaluates the first evidence verification information associated with the first node based on the first evaluation policy to calculate a first reliability score indicating the reliability of the first credentials relating to the first subject, and associates the calculated first reliability score with the first node. The reliability evaluation unit performs a predetermined evidence verification method on the second node in the evidence graph to generate second evidence verification information indicating the validity of the second evidence associated with the second node, and associates the second evidence verification information with the second node. The reliability evaluation unit evaluates the second evidence verification information associated with the second node based on the second evaluation policy to calculate a second reliability score indicating the reliability of the second credentials relating to the second subject, and associates the calculated second reliability score with the second node. The reliability evaluation unit generates and outputs a reliability evaluation result indicating the reliability of the first credential with respect to the first subject, based on the first reliability score and the second reliability score that it has calculated. A reliability evaluation method characterized by including the following.