Verification system, verification method, verification program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2026-08-14
AI Technical Summary
【0011】 本発明の一態様に係る検証システムにおいて、第1端末はメッセージングアプリにより容易にVCを取得することができるとともに、第2端末はそのVCを検証することができるので、例えば、第2端末のユーザは、第1端末のユーザが本人であるか否かを容易に確認することができる。
Smart Images

Figure 0007905143000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a verification system, a verification method, and a verification program capable of verifying an individual.
Background Art
[0002] In recent years, there is a technology for applying using DID as user identification when receiving Web services or the like. Patent Document 1 discloses a technology in which a service provider uses an electronic certificate to obtain necessary information when obtaining user credentials (user information).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, for example, it is not easy to confirm whether a person who delivers a package by courier service actually belongs to the courier company of that package. In the case of the technology described in Patent Document 1, although the service provider can confirm user information, there is a problem that the user side cannot confirm whether the service provider is genuine.
[0005] Therefore, the present invention has been made in view of the above problems, and an object thereof is to provide a verification system that can easily verify that the object to be verified is genuine.
Means for Solving the Problems
[0006] A verification system according to one aspect of the present invention comprises: a request unit that requests the issuance of a VC to a DID associated with a first terminal via a messaging application; an issuing unit that issues a VC to the first terminal in response to the request from the request unit; an association unit that associates the issued VC with the DID; an offering unit that presents the VC via a messaging application; and a verification unit that has a second terminal, different from the first terminal, verify the presented VC.
[0007] In the verification system described above, the first terminal may be equipped with a display unit, and the presentation unit may present the VC by displaying a two-dimensional barcode indicating the VC on the display unit; the second terminal may be equipped with a reading unit that reads the two-dimensional barcode, and the verification unit may verify the VC identified from the two-dimensional barcode read by the reading unit.
[0008] In the verification system described above, the first user of the first terminal is a user who plans to visit the second user of the second terminal, the DID associated with the first terminal is the DID of the first user, the first user displays the VC on the display unit via a messaging application, and the second user verifies the VC using the verification unit of the second terminal to confirm whether or not the first user is the real person.
[0009] In the above verification system, the DID associated with the first terminal is the DID of the first user's family, the second terminal is the terminal of the second user associated with the place the family visits, the first user displays the VC on the display unit via a messaging application, and the second user verifies the relationship between the family and the first user by having the verification unit of the second terminal verify the VC.
[0010] In the above verification system, the DID associated with the first terminal is the DID of the first user's pet of the first terminal, and the pet's DID is associated with information on its vaccination history. The second terminal is the veterinarian's terminal, and the verification unit of the second terminal may verify the VC to confirm whether or not it is the pet of the first user, and also to confirm the pet's vaccination history. [Effects of the Invention]
[0011] In a verification system according to one aspect of the present invention, the first terminal can easily acquire a voice message (VC) via a messaging application, and the second terminal can verify that VC. For example, the user of the second terminal can easily confirm whether the user of the first terminal is the person in question. [Brief explanation of the drawing]
[0012] [Figure 1] This is a system diagram showing an example of the system configuration of the verification system. [Figure 2] This is a block diagram showing an example configuration of the first terminal. [Figure 3] The second parameter is a block diagram showing an example of its structure. [Figure 4] Block diagram showing an example configuration of a VC issuing device. [Figure 5] This is a block diagram showing an example configuration of a DID issuing device. [Figure 6] This is a sequence diagram illustrating an example of inter-device communication in a verification system. [Figure 7] This flowchart shows an example of the operation of the first terminal. [Figure 8] This flowchart shows an example of the operation of a VC issuing device. [Figure 9] This flowchart shows an example of the operation of the second terminal. [Figure 10] (a) and (b) are diagrams showing examples of displays on the first terminal. [Modes for carrying out the invention]
[0013] The verification system 1 according to the present invention will be described in detail below with reference to the drawings.
[0014] <Embodiment> <Overview of the Verification System> As shown in FIG. 1, in the verification system, the first terminal 100, the second terminal 200, the VC (Verifiable Credentials) issuing device 300, and the DID issuing device 400 are communicably connected via the network 500. Although not shown in FIG. 1, a plurality of information processing terminals that hold information related to DID and function as nodes of the blockchain are connected to the network 500. The system shown in FIG. 1 is an example of a verification system capable of verifying the identity (verifying that a person is the real person). If the user 10A of the first terminal 100 and the user 10B of the second terminal 200 already hold DID, the DID issuing device 400 may not be necessary. Also, regarding the blockchain, detailed explanations are omitted as existing technologies are used.
[0015] In the verification system according to the present embodiment, it is assumed that the user 10A of the first terminal 100 visits the user 10B of the second terminal 200. As an example, it is assumed that the user 10A is a delivery person of a delivery company and delivers a package to the user 10B. In the current delivery industry, the user 10B cannot know who the user 10A is, and also cannot know whether the user 10A is indeed a person belonging to the delivery company. Therefore, for example, when a delivery company suddenly visits, there is a problem that even if the delivery company is a disguise of a suspicious person, the user 10B will not be able to notice.
[0016] In the future, it is expected that there will be more and more scenarios where identity verification is required, so the emergence of a verification system that enables anyone to easily verify their identity is demanded.
[0017] In the verification system 1 in this embodiment, when the user 10A of the first terminal 100 visits the user 10B of the second terminal 200, the user 10A requests the issuance of a VC from the VC issuing device 300 via the messaging app installed on the first terminal 100. The VC issuing device 300 issues a VC to the user 10A of the first terminal 100 in response to the request. The VC issued by the VC issuing device 300 may be time-limited according to the date and time when the user 10A visits the user 10B. The VC is managed by blockchain technology in association with the DID issued by the DID issuing device 400 to the user 10A. When the user 10A of the first terminal 100 visits the user 10B, the user 10A displays information about the VC issued by the VC issuing device 300 via the messaging app. Here, the first terminal 100 displays information about the VC in the form of a two-dimensional barcode (which may be, for example, a QR code (registered trademark), but is not limited thereto). The user 10B causes the two-dimensional barcode displayed on his or her second terminal 200 to be read, verifies the VC of the first terminal 100 based on the information embedded in the two-dimensional barcode, and verifies whether the user 10A is the person himself or herself. Thereby, even if the user 10A is an unknown person to the user 10B, the user 10B can confirm the identity of the user 10A without complicated processing.
[0018] Hereinafter, each device and its respective operations will be described in detail.
[0019] FIG. 2 is a block diagram showing a configuration example of the first terminal 100. As shown in FIG. 2, the first terminal 100 includes a communication unit 110, an input unit 120, an output unit 130, a storage unit 140, and a control unit 150. The first terminal 100 is a terminal carried by a user and is a computer system including a processor and a memory implemented by a smartphone, a tablet terminal, a mobile phone, or the like.
[0020] The communication unit 110 is a communication interface that has the function of performing communication with an external device via wireless communication. The communication unit 110 may use any communication protocol as long as it can perform communication with an external device. For example, the communication unit 110 transmits a VC request specified by the control unit 150 to the VC issuing device 300. The communication unit 110 also receives a VC issued by the VC issuing device 300 and transmits it to the control unit 150. Furthermore, the communication unit 110 associates the issued VC with the DID of user 10A of the first terminal 100, for example, according to instructions from the control unit 150.
[0021] The input unit 120 is an input interface that receives input from the user of the first terminal 100. The input unit 120 may be implemented by, for example, a touch panel, but is not limited to this, and may also be implemented by input devices such as a keyboard or mouse, or a microphone. The input unit 120 transmits the received input content to the control unit 150. For example, the input unit 120 receives input content for a messaging application and transmits it to the control unit 150.
[0022] The output unit 130 is an output interface that outputs information according to instructions from the control unit 150. The output unit 130 may be implemented, for example, by displaying text or images on a monitor or touch panel, or by outputting audio on a speaker or the like. The output unit 130 outputs (displays), for example, the display screen of a messaging application or information related to VC.
[0023] The storage unit 140 has the function of storing various programs and data necessary for the operation of the first terminal 100. The storage unit 140 may be implemented by, for example, an HDD, SSD, flash memory, etc., but is not limited to these. The storage unit 140 may store a messaging application 141 for exchanging messages with other users, such as so-called chat, and a program that associates VCs issued by the VC issuing device 300 with the DID of user 10A of the first terminal 100. The storage unit 140 may include ROM and RAM. The storage unit 140 may also be implemented by cloud storage. The messaging application 141 may be an existing messaging application, but it may be an application program with added functions such as a function to request the issuance of VCs, a function to read VCs, a function to convert VCs into two-dimensional barcodes, and a function to verify VCs.
[0024] The control unit 150 is a processor that has the function of controlling each part of the first terminal 100. The control unit 150 realizes the functions of the first terminal 100 by executing various programs stored in the storage unit 140.
[0025] The control unit 150 executes a program stored in the memory unit 140, thereby executing a messaging application and realizing the function of presenting a VC to the user 10B of the second terminal 200.
[0026] Furthermore, the control unit 150 implements the functions of the request unit 151, the matching unit 152, and the presentation unit 153.
[0027] The request unit 151 requests the VC issuing device 300 to issue a VC to user 10A of the first terminal 100 via the communication unit 110. The request unit 151 is triggered by the input of a message requesting the issuance of a VC from user 10A via the input unit 120 to the messaging application 141, and requests the VC issuing device 300 to issue the VC.
[0028] The mapping unit 152 maps the VC information received from the VC issuing device 300 via the communication unit 110 to the DID of user 10A of the first terminal 100 on the network 500 using blockchain technology.
[0029] The display unit 153 outputs (displays) information about the issued VC to the output unit 130 (display unit) on the display screen of the messaging application 141 in accordance with instructions from the user 10A. The display unit 153 may convert the information indicating the VC issued by the VC issuing device 300 into a two-dimensional barcode and display the two-dimensional barcode on the chat screen of the messaging application 141 to present the VC to another person (second terminal 200).
[0030] The above is an example of the configuration of the first terminal 100. Note that the user 10A of the first terminal 100 may have a DID already stored, or the control unit 150 may request the issuance of a DID from the DID issuing device 400 and obtain it. The DID of user 10A contains information about user 10A (for example, the user's name, age, gender, and appearance photo, but is not limited to these).
[0031] <Configuration of the second terminal 200> Figure 3 is a block diagram showing an example configuration of the second terminal 200. As shown in Figure 3, the second terminal 200 comprises a communication unit 210, an input unit 220, an output unit 230, a storage unit 240, and a control unit 250. The second terminal 200 is a computer system equipped with a processor and memory, which can be implemented using a smartphone, tablet terminal, mobile phone, etc. The second terminal 200 may be the same type of device as the first terminal 100. The second terminal 200 is a terminal used by a user 10B who is different from user 10A of the first terminal 100.
[0032] The communication unit 210 is a communication interface that has the function of performing communication with an external device via wireless communication. The communication unit 210 may use any communication protocol as long as it can perform communication with an external device. For example, the communication unit 210 may exchange messages with the first terminal 100 via the messaging application 241 as information specified by the control unit 250.
[0033] The input unit 220 is an input interface that receives input from the user of the second terminal 200. The input unit 220 may be implemented by, for example, a touch panel, but is not limited to this, and may also be implemented by input devices such as a keyboard or mouse, voice input devices such as a microphone, imaging devices such as a camera, etc. The input unit 220 transmits the received input content to the control unit 250. For example, the input unit 220 receives input content for the messaging application from user 10B and transmits it to the control unit 250. The input unit 220 also transmits information of a two-dimensional barcode read by a camera to the control unit 250. The two-dimensional barcode may be an encoded representation of information indicating a VC presented by the first terminal 100.
[0034] The output unit 230 is an output interface that outputs information according to instructions from the control unit 250. The output unit 230 may be implemented, for example, by displaying text or images on a monitor or touch panel, or by outputting audio on a speaker or the like. The output unit 230 outputs, for example, the execution result related to a predetermined process performed by the first terminal 100.
[0035] The storage unit 240 has the function of storing various programs and data necessary for the operation of the second terminal 200. The storage unit 240 may be implemented by, for example, an HDD, SSD, flash memory, etc., but is not limited to these. The storage unit 240 may store a messaging application 241 for exchanging messages with other users, such as in a chat, and a program for verifying presented VCs. The messaging application 241 may be an existing messaging application that is capable of exchanging messages with the messaging application 141 of the first terminal 100, but may be an application program with added functions for requesting the issuance of VCs, reading VCs, converting VCs into two-dimensional barcodes, and verifying VCs. The storage unit 240 may include ROM and RAM. Furthermore, the storage unit 240 may be implemented by cloud storage.
[0036] The control unit 250 is a processor that has the function of controlling each part of the second terminal 200. The control unit 250 realizes the functions of the second terminal 200 by executing various programs stored in the memory unit 240.
[0037] The control unit 250 may also include a reading unit 251 and a verification unit 252.
[0038] The reading unit 251 uses the camera, which acts as the input unit 120, to read a two-dimensional barcode as information about the VC displayed on the first terminal 100. The reading unit 251 may read information about the VC as one of the functions of the messaging application 241.
[0039] The verification unit 252 verifies the VC based on the information about the VC read by the reading unit 251. By verifying the acquired VC, the verification unit 252 can verify whether the user 10A of the first terminal 100 is indeed the person in question. In other words, the verification unit 252 can verify whether the user 10A of the first terminal 100 is genuine.
[0040] More specifically, the verification unit 252 reads the VC information embedded in the read two-dimensional barcode and identifies the DID contained in the VC. This VC is issued by the VC issuing device 300 to user 10A's DID, and the DID contained in the VC is user 10A's DID. The verification unit 252 then obtains the public key associated with the identified DID from the DID issuing device 400. This public key may also be obtained from the public key associated with the DID on the blockchain. The verification unit 252 uses the public key obtained from the DID issuing device 400 to verify whether the VC was issued from user 10A's DID on the first terminal 100. As an example, the verification unit 252 determines whether the obtained public key matches the public key contained in the VC read from the VC information read by the reading unit 251. If they do not match, the verification unit 252 may terminate the process at this point and notify the output unit 230 (display a warning message) that the user 10A of the first terminal 100 may not be the person in question.
[0041] If the public keys match, the verification unit 252 uses the public key to verify the signature contained in the VC read by the reading unit 251. This signature is a signature encrypted by user 10A of the first terminal 100 using their own private key and issued by the VC issuing device 300, and is verified using the public key. Note that this verification is the same as before, so a detailed explanation is omitted. At this time, the verification unit 252 may further verify whether the VC or public key has been tampered with on the blockchain, and if there is a possibility of tampering, it may notify the output unit 230 (display a warning message) of information indicating that user 10A of the first terminal 100 may not be the real person (this may also be information indicating that the information may have been tampered with). Existing technology may be used to verify whether or not tampering has occurred on the blockchain. If the signature can be verified, the verification unit 252 has the output unit 230 output information indicating that user 10A of the first terminal 100 is indeed the real person. The output format of the information may be images, text, or audio.
[0042] Note that the user 10B of the second terminal 200 may hold a DID in advance, or the control unit 250 of the second terminal 200 may obtain the DID of the user 10B from the DID issuing device 400. Information regarding the user 10A (for example, but not limited to, the user's name, age, gender, appearance photo, etc.) is registered in the DID of the user 10B. Also, in this embodiment, the DID of the user 10B is not essential.
[0043] The above is a configuration example of the second terminal 200.
[0044] <Configuration of the VC Issuing Device 300> FIG. 4 is a block diagram showing a configuration example of the VC issuing device 300. As shown in FIG. 4, the VC issuing device 300 includes a communication unit 310, an input unit 320, an output unit 330, a storage unit 340, and a control unit 350. The VC issuing device 300 is a computer system including a processor and a memory realized by a server device, and has a function of issuing a VC.
[0045] The communication unit 310 is a communication interface having a function of performing communication with an external device by wireless communication. The communication unit 310 may use any communication protocol as long as communication with an external device can be executed. The communication unit 310, for example, receives a VC issuing request from the first terminal 100 and transmits it to the control unit 350. Also, the communication unit 310, for example, transmits a VC to the first terminal 100 as information specified by the control unit 350.
[0046] The input unit 320 is an input interface that receives an input from a user of the VC issuing device 300. The input unit 320 may be realized by, for example, a touch panel or the like, but is not limited thereto, and may be realized by an input device such as a keyboard or a mouse, a microphone, or the like. The input unit 320 transmits the received input content to the control unit 350.
[0047] The output unit 330 is an output interface that outputs information according to instructions from the control unit 350. The output unit 330 may be implemented, for example, by displaying text or images on a monitor or touch panel, or by outputting audio on a speaker or the like. The output unit 330 may also output information about the issued VC.
[0048] The storage unit 340 has the function of storing various programs and data necessary for the operation of the VC issuing device 300. The storage unit 340 may be implemented by, for example, an HDD, SSD, flash memory, etc., but is not limited to these. The storage unit 340 may store programs, etc., for issuing VCs by computer processing in response to VC issuance requests from the first terminal 100. The storage unit 340 may include ROM and RAM. Furthermore, the storage unit 340 may be implemented by cloud storage.
[0049] The control unit 350 is a processor that has the function of controlling each part of the control unit 350. The control unit 350 realizes the function of a VC issuing device 300 by executing various programs stored in the storage unit 340.
[0050] The control unit 350 functions as a VC issuing unit 351.
[0051] The VC issuing unit 351 has a function of issuing a VC in response to a VC issuance request received by the communication unit 310. The VC issued by the VC issuing unit 351 is information indicating that the target of the DID related to the device that made the VC issuance request is indeed true (the person is genuine, the item is genuine). When receiving a VC issuance request, the VC issuing unit 351 may issue a VC after determining whether the DID making the VC issuance request is indeed the person himself / herself. This determination may be made, for example, by determining whether there is a predetermined relevance between the DID that made the VC issuance request and the device that made the VC issuance request, or by confirming with another server device or the like that holds information about the DID whether the DID making the VC issuance request is indeed the person (genuine item) himself / herself, but is not limited to these determination methods. The VC issuing unit 351 may issue a VC when it is determined to be true in this determination. The VC issuing unit 351 transmits the issued VC to the device that made the VC issuance request via the communication unit 310.
[0052] The above is the configuration of the VC issuing device 300.
[0053] <Configuration of the DID issuing device 400> FIG. 5 is a block diagram showing a configuration example of the DID issuing device 400. As shown in FIG. 5, the DID issuing device 400 includes a communication unit 410, an input unit 420, an output unit 430, a storage unit 440, and a control unit 450. As described above, the DID issuing device 400 is a computer system including a processor and a memory realized by a server device.
[0054] The communication unit 410 is a communication interface having a function of performing communication with an external device by wireless communication. The communication unit 410 may use any communication protocol as long as communication with an external device can be executed. The communication unit 410 transmits the information received from the first terminal 100 or the second terminal 200 to the control unit 450. Also, the communication unit 410 transmits, as information designated by the control unit 450, for example, information about the issued DID to the first terminal 100 or the second terminal 200.
[0055] The input unit 420 is an input interface that receives input from the user of the first terminal 100. The input unit 420 may be implemented by, for example, a touch panel, but is not limited to this, and may also be implemented by input devices such as a keyboard or mouse, or a microphone. The input unit 420 transmits the received input content to the control unit 450.
[0056] The output unit 430 is an output interface that outputs information according to instructions from the control unit 450. The output unit 430 may be implemented, for example, by displaying text or images on a monitor or touch panel, or by outputting audio on a speaker or the like. The output unit 430 outputs, for example, information related to the issued DID.
[0057] The storage unit 440 has the function of storing various programs and data necessary for the operation of the first terminal 100. The storage unit 440 may be implemented by, for example, an HDD, SSD, flash memory, etc., but is not limited to these. The storage unit 440 may store a program that receives a DID issuance request and issues a DID to the target that made the issuance request. The storage unit 440 may also store the issued DID and the public key information used with that DID in association. The storage unit 440 may include ROM and RAM. Furthermore, the storage unit 440 may be implemented by cloud storage.
[0058] The control unit 450 is a processor that has the function of controlling each part of the first terminal 100. The control unit 450 realizes the functions of the first terminal 100 by executing various programs stored in the memory unit 440.
[0059] The control unit 450 may function as a DID issuing unit 451.
[0060] The DID issuing unit 451 issues a DID in accordance with the DID issuance request received via the communication unit 410. When a DID issuance request is received, the DID issuing unit 451 issues a unique DID that does not overlap with any previously issued DIDs. The DID may be issued to a user, a user's pet, or any object, but is not limited to these.
[0061] The DID issuing unit 451 issues a unique DID in accordance with the DID issuance request and transmits the information of the issued DID to the device that made the DID issuance request via the communication unit 410. The issued DID is also associated with the information of the device to be issued included in the DID issuance request and stored on the network 500 using blockchain technology.
[0062] The above is an example of the configuration of the DID issuing device 400.
[0063] Note that a block diagram-based explanation of each information processing terminal that functions as a blockchain node will be omitted. An information processing terminal acting as a node can be any conventional computer system with a processor and memory capable of communicating with network 500.
[0064] First, using Figure 6, we will explain an example of the interaction between devices in the verification system, from VC issuance to presentation and verification. Figure 6 is a sequence diagram showing an example of interaction between the first terminal 100, the second terminal 200, and the VC issuing device 300.
[0065] As shown in Figure 6, the first terminal 100 contacts the second terminal 200 via the messaging application 141 to inform it of the scheduled date and time of the visit (step S601). Note that this process is not mandatory.
[0066] The first terminal 100 requests the VC issuing device 300 to issue a VC (step S602). That is, the first terminal 100 receives a message requesting the issuance of a VC from the user of the first terminal 100 via the messaging application 141 (this may also be done by selecting a menu item to request the issuance of a VC or by pressing an execution button), and requests the VC issuing device 300 to issue a VC.
[0067] Then, the VC issuing device 300 issues a VC to the first terminal 100 (step S603). This VC serves as information that the VC issuing device 300 uses to prove that the user of the first terminal 100 is indeed the person in question.
[0068] When the first terminal 100 receives a VC from the VC issuing device 300, it associates the received VC with the DID of the first terminal 100's user and stores it on the network 500 (blockchain node) using blockchain technology.
[0069] Subsequently, the user of the first terminal 100 visits the user of the second terminal 200. At this time, the user of the first terminal 100 presents the VC to the user of the second terminal 200 by displaying the VC from the messaging app 141 on the display screen of their first terminal 100 (step S604).
[0070] The user of the second terminal 200 verifies the presented VC using the second terminal 200 (step S605). This allows the user of the second terminal 200 to determine whether the user of the first terminal 100 is the real person and whether they can be trusted.
[0071] Next, Figure 7 will be used to explain the operation of the first terminal 100 shown in Figure 6, Figure 8 will be used to explain the operation of the VC issuing device 300 shown in Figure 6, and Figure 9 will be used to explain the operation of the second terminal 200 shown in Figure 6. Figure 7 is a flowchart showing an example of the operation of the first terminal 100, Figure 8 is a flowchart showing an example of the operation of the VC issuing device 300, and Figure 9 is a flowchart showing an example of the operation of the second terminal 200.
[0072] As shown in Figure 7, the user of the first terminal 100 launches the messaging application 141 and informs the user of the second terminal 200 of the visit date and time via the messaging application 141 (step S701). This step may be omitted.
[0073] The user of the first terminal 100 inputs a message requesting the issuance of a VC to the messaging application 141 via the input unit 120. In response, the request unit 151 analyzes the input content using text analysis (which may utilize an LLM (Large Language Model) or existing character recognition technology). The request unit 151 then requests the VC issuing device 300 to issue a VC via the communication unit 110 (step S702). That is, the request unit 151 transmits a VC issuance request via the communication unit 110, which includes at least the DID of the user of the first terminal 100. The VC issuance request may also include information on the date and time of the visit when user 10A visits user 10B. In response, the VC issuing device 300 issues a VC.
[0074] The communication unit 110 receives the VC issued by the VC issuing device 300 (step S703). The communication unit 110 transmits the received VC to the control unit 150. The control unit 150 associates the received VC with the DID associated with the user of the first terminal 100 (step S704). That is, the matching unit 152 of the control unit 150 associates the information of the received VC with the DID on the network 500 via blockchain through the communication unit 110.
[0075] Subsequently, when the scheduled visit time arrives, user 10A of the first terminal 100 visits user 10B. At that time, user 10 of the first terminal 100 launches the messaging application 141 and presents the VC obtained from the VC issuing device 300 by outputting (displaying) it on the output unit 130 (display unit) (step S705), thus completing the process. As a result, user 10B, the recipient, can verify the presented VC using their second terminal 200 and confirm whether user 10A is indeed the person they claim to be.
[0076] As shown in Figure 8, the communication unit 310 of the VC issuing device 300 receives a VC issuance request from the first terminal 100 (step S801). The communication unit 310 transmits the received VC issuance request to the control unit 350.
[0077] When the VC issuing unit 351 of the control unit 350 receives a request to issue a VC, it issues a VC for the DID of the user of the first terminal 100 that made the request (step S802). At this time, the VC issuing unit 351 may also authenticate the user of the first terminal 100 before issuing the VC.
[0078] The VC issuing unit 351 transmits the issued VC to the device that made the VC issuance request, i.e., the first terminal 100, via the communication unit 210 (step S803), and terminates the process.
[0079] As shown in Figure 9, the second terminal 200 receives notification from the first terminal 100 via the messaging application 241 regarding the date and time of the visit by user 10A (step S901). Specifically, the communication unit 210 receives information indicating the date and time of the visit as information for display on the messaging application 241, transmits the received information to the control unit 250, and the control unit 250 causes the output unit 230 to output the transmitted information indicating the date and time of the visit on the messaging application 241.
[0080] Subsequently, user 10B of the second terminal 200 accepts the visit of user 10A. User 10B instructs the second terminal 200 to scan the two-dimensional barcode of the VC displayed on the first terminal 100. That is, the reading unit 251 of the control unit 250 reads the displayed two-dimensional barcode (step S902). The reading unit 251 transmits the information of the read VC to the verification unit 252.
[0081] When the verification unit 252 receives a VC, it verifies the transmitted VC (step S903). The verification unit 252 then outputs the verification result to the output unit 230 (step S904) and terminates the process. Specifically, if the verification of the VC fails, information indicating that user 10A may not be the person in question is displayed on the monitor of the second terminal 200. If the verification of the VC is successful, information indicating that user 10A is the person in question and is highly likely to be trustworthy is displayed on the monitor of the second terminal 200.
[0082] This allows for easy authentication of both user 10A on the first terminal 100 and user 10B on the second terminal 200, without requiring complex operations.
[0083] <Example Display> Figures 10(a) and 10(b) show examples of the display of the messaging application 141. Figure 10(a) shows an example of the display of the messaging application 141 on the first terminal 100 when acquiring a VC, and Figure 10(b) shows an example of the display when user 10A of the first terminal 100 presents a VC to user 10B of the second terminal 200 via the messaging application 141.
[0084] As shown in Figure 10(a), the chat screen 1000 is displayed as the display screen of the messaging application 141. The chat screen 100 may be a chat screen between user 10A of the first terminal 100 and the VC issuing device 300. The messaging application 141 analyzes the message 1001 input from the input unit 120 of the first terminal 100, and when it recognizes that the message content is a request for the issuance of a VC, the messaging application 141 automatically sends a VC issuance request to the VC issuing device 300. At this time, the messaging application 141 may also display a predetermined (or generated by LLM, etc.) reply message 1002 to user 10A's message 1001. With this configuration, user 10A of the first terminal 100 can obtain a VC simply by writing to the messaging application 141. At this time, the expiration date of the VC may also be set by specifying the date and time. In the illustrated case, the VC issuing device 300 may issue VCs that are valid until May 20, 2025.
[0085] Furthermore, as shown in Figure 10(b), user 10A displays a two-dimensional barcode 15 on the display screen of the first terminal 100 via the messaging application 141, indicating the VC issued by the VC issuing device 300. The illustration shows an example where a message 1011 indicating that a delivery company has delivered the package is displayed, along with a two-dimensional barcode. User 10B reads the two-dimensional barcode displayed on the first terminal 100 to obtain the VC and verifies it. As a result, user 10B can, for example, confirm that the other party (user 10A) is indeed the person they claim to be, and thus trust the other party.
[0086] <Specific example> Let's explain some specific examples of how the above VC (Vision Criteria) presentation can be used.
[0087] <Specific Example 1> For example, user 10A of the first terminal 100 may be some kind of business that needs to visit user 10B. The verification system shown in the above embodiment may be used to verify the identity of the business. User 10A may be, but is not limited to, a delivery person, postal worker, cleaning company, electrical contractor, gas inspector, etc. User 10B may be a recipient of a delivery or mail. The delivery person (user 10A) obtains a VC from the VC issuing device 300 in advance via the messaging application 141 from the first terminal 100, and presents the VC when visiting user 10B. For example, the VC is presented to the camera of the intercom at user 10B's front door, and user 10B reads the two-dimensional barcode captured by the camera with the second terminal 200, and the second terminal 200 verifies the VC. If user 10B's second terminal 200 successfully verifies the VC presented by the first terminal 100, user 10B can confidently welcome user 10A.
[0088] <Specific Example 2> For example, user 10A of the first terminal 100 may be a family member or other related person who is being transported, and user 10B of the second terminal 200 may be the person providing the transport. More specifically, when user 10A puts their child on a school or cram school bus, they may use the above verification system to prove to the bus driver (e.g., the bus driver) that they are the parent of the child. In this case, user 10A obtains their child's DID from the DID issuing device 400 on behalf of the child via the messaging app 141, and requests the VC issuing device 300 to issue a VC for both their child's DID and their own DID. The VC may include information acknowledging that the two are parent and child. When the child boards the bus, the transporter, user 10B, may verify the VC displayed by user 10A (as the parent) on the messaging app 141 using their second terminal 200, and if the verification is successful and it is confirmed that the child is the biological parent, they may allow the child to board the bus.
[0089] Furthermore, the subjects are not limited to children; they could also be one's own parents, and the person providing transportation could, for example, be an employee of a facility for the elderly, such as a nursing home. Thus, the verification system may be used to guarantee the relationship between two or more individuals to a third party. In this example, user 10B is assumed to be a person providing transportation, such as a shuttle bus, but they could also be a person who is on standby (working) at the place where children or parents are left.
[0090] In this case, the transporting party (user 10B) may also obtain a VC (Vision Certificate), present it to user 10A, and after verifying that user 10B is indeed affiliated with the cram school or nursing home, user 10A may entrust their child or parent to the facility.
[0091] <Specific Example 3> As an example, the verification system may be used by a veterinarian to verify whether user 10A is the owner of a pet. In this case, user 10A requests the DID issuing device 400 to issue a DID for their pet from their first terminal 100. The DID assigned to the pet may be associated with information such as prescribed medications and treatments for that pet using blockchain technology. This association may be done by the pet owner (user 10A) from the first terminal 100, or by the veterinarian from their own terminal. Now, consider a scenario where user 10A takes their pet to a new veterinarian for examination. User 10A requests the VC issuing device 300 to issue a VC via the messaging application 141 from the first terminal 100. User 10A has the veterinarian's second terminal 200 read the two-dimensional barcode representing the VC obtained via the messaging application 141. The veterinarian's second terminal 200 can verify the read VC and confirm whether user 10A is the pet's owner. If the verification is successful, the second terminal 200 can also check the information linked to the pet's DID, allowing the veterinarian on the second terminal 200 to check the pet's treatment history, medication history, and medical history linked to the pet's DID. In other words, the treatment history and other information linked to the pet's DID can be used in a manner similar to an electronic medical record. For example, if a pet falls ill while traveling and the owner is unable to use their usual veterinary hospital and must go to a veterinary hospital in the travel destination, the veterinarian at that hospital can refer to this information during treatment, which is an advantage.
[0092] <Specific Example 4> For example, User 10A and User 10B may be parties who have entered into some kind of contract (which could be an agreement, a transaction, or something else).
[0093] In such cases, user 10A requests the VC issuing device 300 to issue a VC via the messaging application 141 of the first terminal 100, and user 10B also requests the VC issuing device 300 (which may be the same VC issuing device requested by the first terminal 100 or a different VC issuing device) via the messaging application 241 of the second terminal 200.
[0094] Furthermore, before entering into a contract, User 10A and User 10B may verify each other's VCs (Virtual Capital Components).
[0095] <Summary> In this way, when user 10A visits user 10B, the first terminal 100 presents the VC issued by the VC issuing device 300, and allows user 10B to verify it at the second terminal 200. If the verification is successful, it can give user 10B a sense of security and trust. The VC is issued at the first terminal 100 by user 10A entering a message from the messaging application 141 that user 10A normally uses, making it easy to obtain. Furthermore, at the second terminal 200, user 10B can verify the VC simply by reading the two-dimensional barcode related to the VC displayed at the first terminal 100, so the verification system can be provided as a verification system that anyone can easily use.
[0096] <Supplement> The verification system according to the above embodiment is not limited to the above embodiment, and the various configurations described above may be realized by other methods. Various modifications will be described below.
[0097] (1) In the above embodiment, the first terminal 100 is configured to convert the information related to the VC into a two-dimensional barcode, but this is not limited to this. The function of converting the VC into a two-dimensional barcode may be provided by the VC issuing device 300, and when the VC issuing device 300 transmits the information related to the VC to the first terminal 100, it may also transmit the information related to the VC along with display information indicating the two-dimensional barcode. Furthermore, since the VC issuing device 300 can also read information related to the VC from the two-dimensional barcode, it may transmit only the display information indicating the two-dimensional barcode to the first terminal 100.
[0098] (2) In the above embodiment, it was shown that a request for issuance of a VC is made via the messaging application 141. This is achieved by later adding functions for requesting the issuance of a VC, reading a VC, converting a VC into a two-dimensional barcode, and verifying a VC. In the above embodiment, although not specifically shown, the verification system may include a download server from which programs (which may also be called additional content, patches, etc.) for adding these functions can be downloaded. The first terminal 100 and the second terminal 200 may be configured to download and execute the program from the download server, thereby adding and executing the functions for requesting the issuance of a VC, reading a VC, converting a VC into a two-dimensional barcode, and verifying a VC to the messaging application 141 or messaging application 241.
[0099] (3) In the above embodiment, the verification of the VC by the second terminal 200 may be performed without going through the messaging application 241.
[0100] (4) In the above embodiment, the VC issuance process via the messaging application in the first terminal 100 and the VC verification process in the second terminal 200 are performed by the processors of the first terminal 100 and the second terminal 200 executing information processing programs to issue and verify the VC. However, this may be implemented in the device by logic circuits (hardware) or dedicated circuits formed on integrated circuits (IC (Integrated Circuit) chips, LSI (Large Scale Integration) etc. Furthermore, these circuits may be implemented by one or more integrated circuits, and the functions of the multiple functional units shown in the above embodiment may be implemented by a single integrated circuit. Depending on the degree of integration, LSIs may also be called VLSI, Super LSI, Ultra LSI, etc.
[0101] The above information processing program may be recorded on a recording medium readable by the processor, and the recording medium can be a "non-temporary tangible medium," such as tape, disk, card, semiconductor memory, or programmable logic circuit. Furthermore, the above information processing program may be supplied to the processor via any transmission medium capable of transmitting the information processing program (such as a communication network or broadcast wave). In other words, for example, the information processing program may be downloaded and executed from a network using an information processing device such as a smartphone. The present invention can also be realized in the form of a data signal embedded in a carrier wave, where the above information processing program is embodied by electronic transmission.
[0102] The above information processing program can be implemented using, for example, scripting languages such as ActionScript and JavaScript®, or object-oriented programming languages such as Objective-C, Java®, C++, Python®, and R. Furthermore, this applies not only to the first terminal 100 and the second terminal 200, but also to the VC issuing device 300 and the DID issuing device 400.
[0103] (5) The various configurations shown in the above embodiments and supplements may be combined as appropriate.
[0104] (6) The processes described in the above embodiments and supplements may be modified in terms of the content of the processes or the order of the processes, as long as the same results can be obtained. [Explanation of Symbols]
[0105] 100 Information Processing Devices 110 Communications Department 120 Input section 130 Output section 140 Storage section 150 Control Unit 151 Request part 152 Correspondence section 153 Presentation section 200 user terminals 210 Communications Department 220 Input section 230 Output section 240 Storage section 250 Control Unit 251 Reading Unit 252 Verification Department 300 VC issuing device 310 Communications Department 320 Input section 330 Output section 340 Storage section 350 Control Unit 351 VC Publishing Department 400 DID issuing devices 410 Communications Department 420 Input section 430 Output section 440 Storage section 450 Control Unit 451 DID Issuance Department
Claims
1. A request unit requests the issuance of a VC to the DID associated with the first terminal via a messaging application, An issuing unit that issues a VC to the first terminal in response to a request from the requesting unit, A mapping unit that associates the VC issued with the aforementioned DID, A presentation unit that presents the VC via the messaging application, A verification unit in which a second terminal, different from the first terminal, verifies the presented VC, Equipped with, The display unit displays the VC by displaying a two-dimensional barcode indicating the VC on the display unit of the first terminal. The second terminal includes a reader for reading the two-dimensional barcode, The verification unit verifies the VC identified from the two-dimensional barcode read by the reading unit, The first user of the first terminal is a user who plans to visit the second user of the second terminal, and the DID associated with the first terminal is the DID of the first user. Prior to the visit, the first user notifies the second user of the visit via the messaging app, The first user, during the visit, displays the VC on the display unit of the first terminal via the messaging application. The second user, by having the verification unit of the second terminal verify the VC, The first user who made the visit is verified to determine whether or not they are the person in question. Verification system.
2. The DID associated with the first terminal is the DID of the family of the first user of the first terminal, and the second terminal is the terminal of the second user associated with the place visited by the family. The first user displays the VC on the display unit via the messaging application. The second user verifies the relationship between the family and the first user by having the verification unit of the second terminal verify the VC. The verification system according to feature 1.
3. A verification method in a verification system comprising a first terminal, a second terminal, and a VC issuing device, The first terminal requests the VC issuing device to issue a VC to the DID associated with the first terminal via a messaging application; An issuance step in which the VC issuing device issues a VC to the first terminal in response to the request of the request step, The first terminal associates the VC issued to the DID with the first terminal, The first terminal presents the VC via the messaging application, The second terminal performs a verification step in which it verifies the presented VC, Execute, The presentation step involves presenting the VC by displaying a two-dimensional barcode indicating the VC on the display unit of the first terminal. The second terminal includes a reader for reading the two-dimensional barcode, The verification step verifies the VC identified from the two-dimensional barcode read by the reading unit, The first user of the first terminal is a user who plans to visit the second user of the second terminal, and the DID associated with the first terminal is the DID of the first user. Prior to the visit, the first user notifies the second user of the visit via the messaging app, The first user, during the visit, displays the VC on the display unit of the first terminal via the messaging application. The second user, by having the verification unit of the second terminal verify the VC, The first user who made the visit is verified to determine whether or not they are the person in question. Verification method.
Citation Information
Patent Citations
Visitor management system and visitor management method
JP2022135182A
Method and device for generating relational id based on distributed identifiers
JP2025086852A
User credential control system and user credential control method
JP7259971B2
JPP7259971B
Information sharing assistance system
WO2022038649A1