Information processing device, system, control method and program for the information processing device
The terminal solution addresses the issue of unauthorized certificate use by integrating biometric verification and usage control, ensuring the legitimacy of certificate holders in self-sovereign systems.
Patent Information
- Application Number
- JP2025545480
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-09-13
- Filing Date
- 2024-06-26
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2044-06-26
AI Technical Summary
Existing systems do not verify that the user who receives a certificate stored on their smartphone and the user who uses that certificate are the same person, leading to concerns about unauthorized use of certificates in self-sovereign systems.
A terminal equipped with a storage means for biometric information and certificates, and a usage control means to provide designated biometric information and certificates to service providers, ensuring one-to-one authentication.
Prevents unauthorized use of certificates by verifying the identity of the certificate holder, thus ensuring the legitimacy of service provision.
Smart Images

Figure 0007910687000001 
Figure 0007910687000002 
Figure 0007910687000003
Abstract
Description
Technical Field
[0001] The present invention is based on the claim of priority of Japanese Patent Application: Japanese Patent Application No. 2023-148273 (filed on September 13, 2023), and the entire description of the application is incorporated herein by reference. The present invention relates to a terminal, a system, a method for controlling a terminal, and a program.
Background Art
[0002] There are technologies related to user authentication.
[0003] For example, Patent Document 1 describes that it is possible to realize combined authentication of ID authentication and face authentication without registering the face image data of a visitor in the system. The mobile terminal of Patent Document 1 generates a two-dimensional code from an authentication ID acquired in advance from an information management device and the feature amount of the face image of the visitor, and displays the two-dimensional code on the screen. The entrance / exit control device acquires the authentication ID issued in advance by the information management device, and acquires the authentication ID read from the two-dimensional code displayed on the mobile terminal and the feature amount of the face image of the visitor. The entrance / exit control device collates the authentication ID acquired from the two-dimensional code with the authentication ID issued by the information management device, and further collates the feature amount of the face image of the visitor acquired from the two-dimensional code with the feature amount of the face image of the visitor photographed by a camera that photographs the visitor entering or leaving the room.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] As disclosed in Patent Document 1, servers on a network often centrally manage the IDs of users (users receiving services). However, in recent years, due to increased awareness of personal information protection, systems in which users themselves manage their own information (self-sovereign systems) have begun to spread.
[0006] In a self-sovereign system, electronic certificates and other data are stored on devices such as smartphones owned by individuals. When a user receives a service, the certificate stored on that smartphone is provided to the service provider.
[0007] In the system described above, it is assumed that the user who receives the certificate stored on their smartphone and the user who uses that certificate (the user who provides the certificate to the service provider) are the same person. However, existing systems do not verify that the certificate recipient and the certificate user are the same person. As a result, there are concerns that certificates may be misused.
[0008] The primary objective of this invention is to provide a terminal, a system, a terminal control method, and a program that contribute to preventing the unauthorized use of certificates and the like stored in smartphones and the like. [Means for solving the problem]
[0009] According to a first aspect of the present invention, a terminal is provided that includes a storage means for storing the user's biometric information acquired when the digital wallet is opened, and for storing a certificate issued by a certificate issuer in the digital wallet, and a usage control means for providing a service provider with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider.
[0010] A second aspect of the present invention provides a system comprising: a device of a service provider; a terminal owned by a user; the terminal having a storage means that stores the user's biometric information acquired when opening a digital wallet and stores a certificate issued by a certificate issuer in the digital wallet; and a usage control means that provides the device of the service provider with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider.
[0011] A third aspect of the present invention provides a terminal control method comprising: a storage step of storing the user's biometric information acquired when the digital wallet is opened, and storing a certificate issued by a certificate issuer in the digital wallet; and a usage control step of providing a service provider with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider.
[0012] According to a fourth aspect of the present invention, a program is provided for a computer installed in a terminal to perform a storage process that stores the user's biometric information acquired when the digital wallet is opened, and stores a certificate issued by a certificate issuer in the digital wallet, and a usage control process that provides a service provider with at least the stored biometric information and a certificate stored in the digital wallet that is specified by the service provider. [Effects of the Invention]
[0013] From each perspective of the present invention, a terminal, a system, a terminal control method, and a program are provided that contribute to preventing the unauthorized use of certificates and the like stored in smartphones and the like. However, the effects of the present invention are not limited to those described above. The present invention may produce other effects in lieu of or in conjunction with the effects described above. [Brief explanation of the drawing]
[0014] [Figure 1] Figure 1 is a diagram for explaining an overview of an embodiment. [Figure 2] Figure 2 is a flowchart showing the operation of an embodiment. [Figure 3] Figure 3 is a diagram showing an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 4] Figure 4 is a diagram showing an example of a display of a terminal according to an embodiment of the present disclosure. [Figure 5] Figure 5 is a diagram for explaining the operation of an information processing system according to an embodiment of the present disclosure. [Figure 6] Figure 6 is a diagram for explaining the operation of an information processing system according to an embodiment of the present disclosure. [Figure 7] Figure 7 is a diagram showing an example of a processing configuration of a terminal according to an embodiment of the present disclosure. [Figure 8] Figure 8 is a flowchart showing an example of the operation of an authentication unit according to an embodiment of the present disclosure. [Figure 9] Figure 9 is a flowchart showing an example of the operation of an acquisition control unit according to an embodiment of the present disclosure. [Figure 10] Figure 10 is a diagram showing an example of a processing configuration of a server device according to an embodiment of the present disclosure. [Figure 11] Figure 11 is a diagram showing an example of a processing configuration of a service server according to an embodiment of the present disclosure. [Figure 12] Figure 12 is a flowchart showing an example of the operation of a service provision control unit according to an embodiment of the present disclosure. [Figure 13] Figure 13 is a sequence diagram showing an example of the operation of an information processing system according to an embodiment of the present disclosure. [Figure 14] Figure 14 is a sequence diagram showing an example of the operation of an information processing system according to an embodiment of the present disclosure. [Figure 15] Figure 15 is a diagram for explaining the operation of an information processing system according to a modified example of an embodiment of the present disclosure. [Figure 16]FIG. 16 is a diagram showing an example of the display of a terminal according to a modification of an embodiment of the present disclosure. [Figure 17] FIG. 17 is a diagram showing an example of the hardware configuration of a terminal according to the present disclosure.
Embodiments for Carrying Out the Invention
[0015] First, an overview of an embodiment will be described. Note that the reference numerals in the drawings appended to this overview are for convenience of each element as an example to assist understanding, and the description of this overview is not intended to be limiting in any way. Also, unless otherwise specified, the blocks described in each drawing represent a configuration of functional units, not a configuration of hardware units. The connection lines between the blocks in each figure include both bidirectional and unidirectional ones. The one-way arrow schematically shows the flow of the main signal (data) and does not exclude bidirectionality. In this specification and the drawings, for elements that can be similarly described, duplicate description can be omitted by assigning the same reference numerals.
[0016] A terminal 100 according to an embodiment includes a storage unit 101 and a usage control unit 102 (see FIG. 1). The storage unit 101 stores the biometric information of the user acquired at the time of opening the digital wallet, and stores the certificate issued by the certificate issuer in the digital wallet (step S1 in FIG. 2). The usage control unit 102 provides at least the stored biometric information and the certificate stored in the digital wallet and specified by the service provider to the service provider (step S2).
[0017] Terminal 100 uses biometric information to verify the user's identity when opening a digital wallet. If the verification is successful, terminal 100 stores the biometric information used when opening the digital wallet. When a user receives a service from a service provider, terminal 100 provides the stored biometric information to the service provider. The service provider can perform one-to-one authentication using the biometric information obtained from terminal 100 (biometric information used when opening the digital wallet) and the biometric information of the user in front of them (the owner of terminal 100). By authenticating the user who wishes to receive the service, the service provider can confirm that the person to whom the certificate stored in the digital wallet was issued and the person requesting the service are the same person. As a result, fraudulent activities such as attempting to receive services using someone else's smartphone are prevented. In other words, the unauthorized use of certificates stored in smartphones, etc., is prevented.
[0018] Specific embodiments will be described in more detail below with reference to the drawings.
[0019] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.
[0020] [System Configuration] As shown in Figure 3, the information processing system according to the first embodiment includes at least one certificate issuer and at least one service provider.
[0021] A certificate issuer is the entity that issues certificates to users. Specifically, a certificate issuer is an organization or other entity that has the authority to issue certificates that prove a user's "qualifications." For example, a certificate issuer may issue certificates that prove a user's identity, certificates that prove a user's affiliation (or past affiliation), or certificates that prove a user's abilities.
[0022] For example, public institutions that issue identification documents such as driver's licenses, passports, and My Number cards are considered certificate issuers. Alternatively, companies that issue employment certificates to their employees or former employees, and educational institutions such as universities and vocational schools that issue graduation certificates to graduates are considered certificate issuers. Furthermore, organizations and associations that issue certificates proving qualifications or language skills required for specific jobs are also considered certificate issuers.
[0023] Each certificate issuer has a server device 10. The server device 10 is a server that performs the processing and operations necessary to carry out the certificate issuer's business. The server device 10 may be managed and operated by the certificate issuer, or its management and operation may be entrusted to another business operator, etc. The server device 10 may be installed in the certificate issuer's building, or it may be installed on a network (on the cloud).
[0024] Certificate issuers issue certificates upon request from users. For example, a company issues employment certificates (certificates of employment, certificates of work) upon request from its employees.
[0025] A service provider is a business that provides services to users. For example, businesses that provide job change support (job matching) services or employment support (job matching) services are examples of service providers. Alternatively, general companies that utilize job change support services or employment support services to conduct interviews with job seekers or job seekers are also examples of service providers.
[0026] Alternatively, banks, securities companies, and other entities that provide financial services are cited as examples of service providers. Alternatively, operators of transportation services such as railways, buses, and airplanes are also considered service providers. Furthermore, retail stores, restaurants, and other businesses are also considered service providers. Service providers are not limited to private companies; public institutions such as city halls, as well as organizations such as NGOs (Non-Governmental Organizations) and NPOs (Non-Profit Organizations), are also included as service providers in this disclosure.
[0027] Depending on the industry and business type of the service provider, the same company may act as both a certificate issuer and a service provider.
[0028] Service providers require users to present at least one certificate related to their company's (organization's) business or other relevant information. For example, a job placement service provider would require service users to provide an employment certificate, a graduation certificate, etc.
[0029] Each service provider is equipped with a service server 20 and a service terminal 21 for providing services to users. For example, the service server 20 provides services to users via a website.
[0030] Alternatively, employees of the service provider may operate the service provider terminal 21 to provide services to users. The service provider terminal 21 may be a personal computer, a tablet, a POS (Point of Sale) terminal, or a digital signage terminal.
[0031] Alternatively, the service server 20 and the service provider terminal 21 may be connected, and the service provider's employees may provide services to users while referring to information stored on the service server 20 via the service provider terminal 21.
[0032] When providing services to a user, the service server 20 and the service provider terminal 21 verify at least one certificate presented by the user. Through certificate verification, the service server 20 and the service provider terminal 21 confirm that the certificate underlying the provision of services to the user has not been tampered with and that it was issued by a legitimate issuing body. If the certificate verification is successful, the service is provided to the user.
[0033] The user possesses terminal 30. For example, the user operates terminal 30 to request a certificate from a certificate issuer. The user also uses terminal 30 to provide the service provider with the certificates requested by the service provider (e.g., employment certificate, graduation certificate).
[0034] Each device shown in Figure 3 is connected to a network. Specifically, the server device 10, service server 20, carrier terminal 21, and terminal 30 are connected to the network by wired or wireless communication means.
[0035] The configuration of the information processing system shown in Figure 3 is illustrative and not intended to limit its configuration. For example, each certificate issuer may include multiple server devices 10. Similarly, each service provider may include multiple service servers 20 and multiple service provider terminals 21.
[0036] [General operation] Next, we will describe the general operation of the information processing system according to the first embodiment.
[0037] <Preparing your digital wallet> The user's terminal 30 is equipped with a digital wallet function. A digital wallet is an electronic information storage service that guarantees information security, including data integrity, reliability, and availability.
[0038] The user installs an application on their device 30 to create a digital wallet. By opening a digital wallet on device 30, the user can store various digital content on device 30, such as electronic money, student IDs, identification documents such as passports and driver's licenses, various ticket information such as airline tickets and boarding passes, and vaccination certificates.
[0039] For example, the user's terminal 30 stores digital content as shown in Figure 4. The digital content stored on terminal 30 includes official identification documents such as passports and driver's licenses, as well as employment certificates and graduation certificates issued by companies and universities.
[0040] Terminal 30 performs identity verification using an identification document issued by a public institution such as a government agency when the digital wallet application is launched for the first time. Terminal 30 also verifies the user's identity when the digital wallet is opened.
[0041] For example, terminal 30 verifies the user's identity using an identification document containing the holder's biometric information, such as a My Number Card or passport. Terminal 30 uses the My Number Card or passport as the Root of Trust.
[0042] Examples of biometric information include data (feature quantities) calculated from individual physical characteristics such as face, fingerprints, voiceprints, veins, retina, and iris patterns. Alternatively, biometric information may be image data such as face images or fingerprint images. Biometric information only needs to include information about the user's physical characteristics. This disclosure describes the case where biometric information related to a person's "face" (face image or feature quantities generated from a face image) is used.
[0043] Terminal 30 obtains information about the holder (issuer) of the identification document from the user's identification document. For example, terminal 30 obtains information about the holder of the My Number Card from the IC (Integrated Circuit) of the My Number Card.
[0044] Specifically, terminal 30 acquires the basic information (so-called basic four pieces of information; name, gender, date of birth, and address) of the My Number Card holder and the biometric information (facial image) of the holder. Terminal 30 stores the basic information and biometric information read from the My Number Card internally.
[0045] Furthermore, terminal 30 acquires the user's (digital wallet account holder's) biometric information. For example, terminal 30 acquires and stores a facial image by taking a photograph of the user.
[0046] Terminal 30 performs a matching process (authentication process) using biometric information obtained from the identification document and the user's biometric information. If the authentication process (one-to-one authentication) is successful, Terminal 30 opens a digital wallet. Terminal 30 verifies, through a matching process (authentication process) using biometric information, that the person who issued the identification document and the user using Terminal 30's digital wallet are the same person.
[0047] <Issuance of Certificates> The user obtains digital content to be stored in the digital wallet. For example, the user operates terminal 30 to request a certificate issuer to issue a certificate. For example, the user requests (demands) an employment certificate from their current employer or former employer.
[0048] Specifically, a digital wallet application requests an employment certificate from a company that issues certificates. The certificate issuer then issues Verifiable Credentials (VCs) as certificates, which can be verified online. In the following explanation, VCs will be referred to as "credential certificates."
[0049] Prior to requesting the issuance of a credential certificate, the user's terminal 30 generates a public key and a private key pair. The terminal 30 also generates a decentralized identifier (DID). The terminal 30 registers the generated DID (user ID; holder ID) and public key on the blockchain (step S01 in Figure 5).
[0050] Furthermore, the user's terminal 30 presents its user ID and requests the certificate issuer (server device 10) to issue a credential certificate. Specifically, the terminal 30 sends a "certificate issuance request" to the certificate issuer's server device 10, which includes information about the certificate to be issued, information identifying the user (e.g., employee number or student ID), and the user ID (step S02).
[0051] The server device 10 generates and stores the issuer's DID (Issuer ID), private key, and public key in advance.
[0052] Upon receiving a certificate issuance request, the certificate issuer determines whether the user requesting the issuance of a credential certificate (VCs) is eligible to receive the certificate. For example, server device 10 determines whether the user who wishes to obtain an employment certificate is currently employed by the company (or was employed by the company).
[0053] If the user is eligible to receive a credential certificate, the server device 10 generates a credential certificate (VCs) that includes the issuer ID and user ID.
[0054] Specifically, the server device 10 generates metadata including the type of credential certificate, the name of the issuing organization, the date and time of issuance, etc., along with the credential information itself and a credential certificate (VCs) that includes the issuer's public key information and digital signature, etc. The credential information itself contains specific information that the issuer certifies (for example, information regarding the employee's employment status).
[0055] The server device 10 sends the generated credential certificate to the user's (the user who will be the certificate holder; the person who requested the certificate) terminal 30 (certificate issuance; step S03).
[0056] Furthermore, the server device 10 registers the issuer ID and the public key generated above on the blockchain (step S04).
[0057] Terminal 30 stores the received credential certificates (VCs) in its digital wallet. For example, if terminal 30 requests an employment certificate from its employer, it stores its own employment-related credential certificates (VCs) in its digital wallet.
[0058] <Using Certificates> Users will present the service provider with any certificates requested by that service provider. For example, a user considering a career change will present an employment certificate and a graduation certificate to a job placement service provider.
[0059] The following explanation of the information processing system's operation will use the example of a user receiving job placement support services.
[0060] First, the user registers to receive job placement support services. The user operates terminal 30 to access the service server 20 of the job placement support service provider.
[0061] When a user requests the service, the service server 20 obtains biometric information (face image) stored in the terminal 30 and biometric information (face image) of the operator operating the terminal 30. For example, the service server 20 sends a "biometric information provision request" to the terminal 30 (step S11 in Figure 6).
[0062] Upon receiving a request for biometric information, terminal 30 takes a photograph of the operator operating the device and acquires biometric information (facial image). Terminal 30 transmits the acquired biometric information and pre-registered biometric information (facial image used for identity verification) to the service server 20 (step S12).
[0063] The service server 20 verifies the user's identity by performing one-to-one authentication using the two acquired biometric pieces of information. If the user's identity is verified (one-to-one authentication is successful), the service server 20 requests the terminal 30 to provide the necessary information (certificates) to provide the job placement support service. For example, the service server 20 may request the submission of an employment certificate, a graduation certificate, or certificates related to various qualifications or language skills.
[0064] Specifically, the service server 20 sends a "certificate request" to the terminal 30 (step S13). This certificate request contains information about at least one certificate necessary for the job placement service provider to provide its services. For example, the certificate request specifies the type of certificate the job placement service provider requests.
[0065] Upon receiving a certificate request, terminal 30 sends the credential certificates (VCs) stored in the digital wallet to the service server 20. Specifically, terminal 30 selects a specified credential certificate from among several credential certificates stored in the digital wallet. Then, terminal 30 signs the selected credential certificate using the private key corresponding to the user's DID (User ID). Terminal 30 sends at least one signed credential certificate to the service server 20 (step S14).
[0066] The service server 20 retrieves the issuer ID and user ID contained in the received credential certificate. Furthermore, the service server 20 retrieves the public key corresponding to the retrieved issuer ID and the public key corresponding to the retrieved user ID from the blockchain (step S15).
[0067] Subsequently, the service server 20 verifies at least one credential certificate received from the terminal 30. Specifically, the service server 20 verifies the signature of the holder and the signature of the issuer attached to the credential certificate. By verifying these signatures, the service server 20 confirms that the credential certificate obtained from the user (the holder of the credential certificate) has not been tampered with and that it is a certificate issued by a trusted issuer.
[0068] Once the service server 20 successfully verifies the acquired credential certificates (e.g., employment certificate, graduation certificate, etc.), it provides services to the user (becomes ready to provide services to the user). For example, the service server 20 of a job placement service provider provides information on companies that are suitable for the user's work history. Alternatively, the service server 20 provides the user with information on job placement events jointly held by multiple companies (event date, time, location, etc.).
[0069] Users who receive information from a job placement service provider (the provider's service server 20) visit the companies or event venues that are introduced to them.
[0070] Business terminals 21 are installed at each booth in the companies visited and at the event venue (booths of companies participating in the job fair).
[0071] The company conducts interviews with the job seekers. Specifically, company representatives use the service terminal 21 to conduct interviews with the job seekers. In this case, the service terminal 21, like the service server 20, verifies the user's identity and obtains the necessary certificates (credential certificates) to provide the service (interviews with job seekers).
[0072] The operator terminal 21 and terminal 30 communicate with each other using short-range wireless communication means such as Bluetooth (registered trademark). The operator terminal 21 obtains two pieces of biometric information necessary for identity verification by sending a request for biometric information to terminal 30.
[0073] Furthermore, the service provider terminal 21 obtains at least one credential certificate necessary for providing the service by sending a certificate request to terminal 30. The service provider terminal 21 verifies the credential certificate using the public key obtained from the blockchain. If the credential certificate is successfully verified, the company's representative conducts an interview with the job applicant, referring to the information contained in the credential certificate.
[0074] Next, we will describe the details of each device included in the information processing system according to the first embodiment.
[0075] [Terminal] Figure 7 shows an example of the processing configuration (processing module) of terminal 30 according to the embodiment disclosed herein. Referring to Figure 7, terminal 30 comprises a communication control unit 201, an identity verification unit 202, an acquisition control unit 203, a usage control unit 204, and a storage unit 205.
[0076] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes the data received from other devices to other processing modules. The communication control unit 201 transmits the data obtained from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 201. The communication control unit 201 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.
[0077] Furthermore, the communication control unit 201 also supports short-range wireless communication such as Bluetooth®. The communication control unit 201 communicates with the carrier terminal 21 using short-range wireless communication.
[0078] The digital wallet application is implemented by the identity verification module 202, the acquisition control module 203, and the usage control module 204. A detailed explanation of the installation of the digital wallet application is omitted, as its installation is obvious to those skilled in the art.
[0079] The identity verification unit 202 is a means of verifying the identity of the digital wallet creator. The identity verification unit 202 verifies the identity of the creator of the digital wallet using biometric information obtained from the identification document and the biometric information of the creator of the digital wallet. More specifically, the identity verification unit 202 confirms that the creator of the digital wallet and the name on the identification document issued by a public institution are the same person.
[0080] Figure 8 is a flowchart illustrating an example of the operation of the identity verification unit 202. The operation of the identity verification unit 202 will be explained with reference to Figure 8.
[0081] The identity verification unit 202 obtains information about the holder of the identification document from the identification document held by the user when the digital wallet is opened (initial startup). For example, the identity verification unit 202 obtains basic information and biometric information of the holder of the identification document from the IC (Integrated Circuit) chip embedded in the My Number Card or passport (step S101).
[0082] For example, when a My Number Card is used as identification, the identity verification unit 202 obtains the PIN for the user authentication electronic certificate using a GUI (Graphical User Interface) or the like. Alternatively, when a passport is used as identification, the identity verification unit 202 obtains the information written in the MRZ (Machine Readable Zone) on the passport using OCR (Optical Character Recognition) technology.
[0083] The identity verification unit 202 reads information from the IC chip using the acquired PIN (a 4-digit number) and the information written in the MRZ as a password. The identity verification unit 202 stores the basic information (name, gender, date of birth, address) and biometric information (face information, face image) of the holder of the identification document (My Number Card, passport, etc.) read from the identification document in the storage unit 205 (step S102).
[0084] Furthermore, the identity verification unit 202 acquires the biometric information of the user (the user of terminal 30; the digital wallet account holder) (step S103). For example, the identity verification unit 202 prompts the user to take a picture of their face using a GUI or the like (acquiring a facial image through a selfie).
[0085] The identity verification unit 202 obtains biometric information from an identification document and, upon obtaining biometric information of the user operating the device, performs a matching process using the biometric information obtained from the identification document and the user's biometric information (step S104). The identity verification unit 202 determines whether the two sets of biometric information are substantially identical.
[0086] Specifically, the identity verification unit 202 generates feature quantities from each of the two biometric pieces of information (for example, a facial image).
[0087] Regarding the feature generation process, existing technologies can be used, so a detailed explanation will be omitted. For example, the identity verification unit 202 extracts the eyes, nose, mouth, etc., from the face image as feature points. Then, the identity verification unit 202 calculates the position of each feature point and the distance between each feature point as features (generating a feature vector consisting of multiple features).
[0088] Next, the identity verification unit 202 performs a matching process (authentication process) using the two generated feature quantities. Specifically, the identity verification unit 202 calculates the similarity between corresponding face images using the two feature quantities. Based on the result of thresholding the calculated similarity, the identity verification unit 202 determines whether the two images are face images of the same person. The similarity can be calculated using methods such as the chi-squared distance or the Euclidean distance. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0089] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the identity verification unit 202 determines that the matching process was successful. If the similarity is less than or equal to the predetermined value, the identity verification unit 202 determines that the matching process failed.
[0090] If the matching process is successful (step S105, Yes branch), the identity verification unit 202 grants the user permission to use the digital wallet (permission to use; step S106). In other words, if the identity verification unit 202 succeeds in the authentication process (one-to-one authentication), it opens a digital wallet.
[0091] The identity verification unit 202, upon successful matching (authentication) using biometric information, treats the person who issued the identification document and the user of terminal 30 as the same person. When the digital wallet is first launched, it is determined whether the person who issued the identification document and the user of terminal 30 are the same person. If the person who issued the identification document and the person who opened the digital wallet are the same person, terminal 30 makes the digital wallet application available.
[0092] If the matching process fails (step S105, No branch), the identity verification unit 202 does not allow the user to use the digital wallet (rejection of use; step S107). In other words, if the authentication process (one-to-one authentication) fails, the user cannot use the digital wallet (cannot open a digital wallet).
[0093] Thus, the identity verification unit 202 determines that identity verification has been successful when it successfully performs authentication using biometric information obtained from the identification document and the biometric information of the person opening the digital wallet. If identity verification is successful, the digital wallet is opened.
[0094] The acquisition control unit 203 is a means for controlling the acquisition of credential certificates (VCs). The acquisition control unit 203 requests the certificate issuer to issue the certificate selected by the user and stores the certificate obtained from the certificate issuer in the digital wallet.
[0095] Figure 9 is a flowchart showing an example of the operation of the acquisition control unit 203. The operation of the acquisition control unit 203 according to the embodiment disclosed herein will be explained with reference to Figure 9.
[0096] When a user who has opened a digital wallet launches the digital wallet application and performs a predetermined action (for example, pressing the certificate issuance button), the acquisition control unit 203 performs control related to the acquisition of the credential certificate desired by the user.
[0097] First, the acquisition control unit 203 generates a public key and private key pair, and a distributed identifier, which is a user ID (user's DID). The acquisition control unit 203 registers the generated user ID and public key on the blockchain (registering the public key, etc.; step S201).
[0098] Next, the acquisition control unit 203 uses a GUI or the like to acquire the information necessary for requesting the issuance of a credential certificate (acquisition of necessary information; step S202).
[0099] Specifically, the acquisition control unit 203 acquires information about the certificate issuer authorized to issue the credential certificate the user wishes to obtain, the type of certificate desired, etc. Alternatively, the acquisition control unit 203 may acquire information that the certificate issuer can use to identify the user (e.g., employee number or student ID number).
[0100] The acquisition control unit 203 notifies the certificate issuer of the necessary information and user ID that it has acquired. Specifically, the acquisition control unit 203 notifies the certificate issuer of the type of credential certificate, information to identify the recipient of the certificate (e.g., employee number or student ID number), and the user ID. The acquisition control unit 203 sends a "certificate issuance request" including the type of credential certificate, information to identify the recipient, and the user ID to the server device 10 of the certificate issuer selected by the user (step S203).
[0101] The acquisition control unit 203 may also sign the information included in the certificate issuance request using the private key corresponding to the public key registered on the blockchain.
[0102] The acquisition control unit 203 receives a response (affirmative response, negative response) to the certificate issuance request from the server device 10 (step S204).
[0103] If a negative response indicating that the certificate was not issued is received (step S205, No branch), the acquisition control unit 203 notifies the user that the credential certificate was not issued (notification of non-issuance; step S206).
[0104] If an affirmative response indicating that the certificate has been successfully issued is received (step S205, Yes branch), the acquisition control unit 203 stores the credential certificate received from the certificate issuer in the digital wallet (step S207). At this time, the acquisition control unit 203 may also notify the user that the credential certificate has been issued.
[0105] The acquisition control unit 203 may verify the signature attached to the credential certificate obtained from the certificate issuer. In this case, the acquisition control unit 203 obtains the public key corresponding to the issuer ID written on the credential certificate from the blockchain. The acquisition control unit 203 uses the obtained public key to verify the signature attached to the credential certificate, and if the verification is successful, it may store the credential certificate in a digital wallet.
[0106] In this manner, the acquisition control unit 203 acquires a credential certificate from the certificate issuer and stores the acquired credential certificate in the digital wallet. If the acquisition control unit 203 successfully verifies the signature of the acquired credential certificate, it may also store the acquired credential certificate in the digital wallet.
[0107] The usage control unit 204 is a means for controlling the use of digital content (credential certificates) stored in the digital wallet. The usage control unit 204 provides the service provider with at least biometric information stored in the terminal 30 and certificates stored in the digital wallet that are specified by the service provider.
[0108] Specifically, the user control unit 204 processes biometric information provision requests and certificate provision requests received from the service provider's equipment (service server 20, service provider terminal 21).
[0109] Upon receiving a request for biometric information, the user control unit 204 acquires the biometric information (e.g., facial image) of the device operator using a GUI or the like. The user control unit 204 then takes a picture of the operator's face, essentially a selfie.
[0110] The user control unit 204 transmits the acquired biometric information and the biometric information used for identity verification when opening the digital wallet to the service provider's device. The biometric information used for identity verification when opening the digital wallet may be biometric information obtained from an identification document or biometric information obtained by taking a photograph of the user.
[0111] If the two pieces of biometric information described above can be obtained, the user control unit 204 sends an affirmative response containing the two pieces of biometric information to the service provider's device. If at least one of the two pieces of biometric information described above cannot be obtained, the user control unit 204 sends a negative response to the service provider's device indicating that biometric information cannot be provided.
[0112] In this manner, the user control unit 204 provides the service provider with biometric information obtained from an identification document or biometric information of the person opening the digital wallet, as well as biometric information of the operator operating the device, in response to a request from the service provider.
[0113] Upon receiving a certificate request, the user control unit 204 selects a credential certificate specified by the service provider from among multiple credential certificates stored in the digital wallet. Subsequently, the user control unit 204 signs the selected credential certificate using the private key corresponding to the user's DID (User ID).
[0114] Furthermore, the user control unit 204 signs the credential certificate submitted to the service provider using the private key (the private key corresponding to the user ID) generated when issuing the credential certificate requested by the service provider. For example, if a certificate of employment is requested, the user control unit 204 signs the certificate of employment (credential employment certificate) using the private key corresponding to the user ID sent to the server device 10 of the employer company. Alternatively, if a certificate of graduation is requested, the user control unit 204 signs the certificate of graduation (credential graduation certificate) using the private key corresponding to the user ID sent to the server device 10 of the graduating university.
[0115] If the credential certificate specified by the service provider is available, the user control unit 204 sends an affirmative response containing the signed credential certificate (at least one credential certificate) to the service provider's device. If the credential certificate specified by the service provider is not available, the user control unit 204 sends a negative response to the service provider's device indicating that the credential certificate cannot be provided.
[0116] The storage unit 205 is a means for storing information necessary for the operation of the terminal 30. The storage unit 205 stores the user's biometric information obtained when the digital wallet was opened, and also stores certificates issued by certificate issuers via the digital wallet. Furthermore, the storage unit 205 stores information about each certificate issuer (name of the certificate issuer, address of the server device 10, etc.).
[0117] [Server equipment] Figure 10 is a diagram showing an example of the processing configuration (processing module) of the server device 10 according to the embodiment disclosed herein. Referring to Figure 10, the server device 10 comprises a communication control unit 301, a certificate issuance unit 302, and a storage unit 303.
[0118] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from terminal 30. The communication control unit 301 also transmits data to terminal 30. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 301. The communication control unit 301 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.
[0119] The certificate issuing unit 302 is a means of issuing credential certificates to users. The certificate issuing unit 302 processes the "certificate issuance request" received from the terminal 30.
[0120] Upon receiving a certificate issuance request, the certificate issuance unit 302 searches a database (not shown in Figure 10, etc.) that stores user information, using information to identify the recipient of the certificate included in the certificate issuance request (for example, employee number or student ID number) as a key.
[0121] If the above search fails (i.e., the corresponding user is not registered in the database), the certificate issuing unit 302 sends a negative response to the terminal 30 indicating that the certificate issuance failed.
[0122] If the above search is successful, the certificate issuing unit 302 determines whether or not it is possible to issue a credential certificate to the user based on the information stored in the database and the type of credential certificate that the user wishes to issue as included in the certificate issuance request. In other words, the certificate issuing unit 302 determines whether or not the user who wishes to issue a credential certificate is qualified to receive the certificate.
[0123] For example, the certificate issuing unit 302 will determine that an employment certificate can be issued if a request for issuance of an employment certificate is made and the timing of the request is appropriate. Conversely, the certificate issuing unit 302 will determine that an employment certificate cannot be issued if a prescribed period of time has elapsed since the user recorded in the database left their job.
[0124] Further details regarding the issuance of individual credential certificates (e.g., graduation certificates, language proficiency certificates, etc.) are omitted here, as providing detailed explanations regarding the issuance of individual certificates would be outside the scope of this disclosure.
[0125] If it is not possible to issue a credential certificate to the user, the certificate issuing unit 302 sends a negative response to the terminal 30 indicating certificate issuance failure (certificate issuance not possible).
[0126] If it is possible to issue a credential certificate to the user, the certificate issuing unit 302 generates a certificate to be issued to the user (credential certificate; VCs). The certificate issuing unit 302 generates a credential certificate that includes the issuer ID and the user ID (DID of the recipient of the certificate; user ID included in the certificate issuance request).
[0127] Specifically, the certificate issuing unit 302 generates a credential certificate (VCs) that includes metadata such as the type of credential certificate, the name of the issuing organization, and the date and time of issuance, as well as the credential information itself and the issuer's public key information and digital signature. The digital signature attached to the credential certificate is performed using a private key corresponding to the issuer ID that was generated in advance.
[0128] The certificate issuing unit 302 sends the generated credential certificate to the terminal 30. Furthermore, the certificate issuing unit 302 registers the previously generated issuer ID and public key, etc., on the blockchain.
[0129] The storage unit 303 is a means for storing information necessary for the operation of the server device 10. A database for storing information necessary for issuing credential certificates (for example, an employee's employee number, department, date of joining the company, etc.) is built in the storage unit 303.
[0130] [Service Server] Figure 11 is a diagram showing an example of the processing configuration (processing module) of a service server 20 according to the embodiment disclosed herein. Referring to Figure 11, the service server 20 comprises a communication control unit 401, a service provision control unit 402, and a storage unit 403.
[0131] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from terminal 30. The communication control unit 401 also transmits data to terminal 30. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data with other devices via the communication control unit 401. The communication control unit 401 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.
[0132] The service provision control unit 402 is a means for performing control related to the services provided to the user.
[0133] When a user accesses a designated webpage or similar and requests the provision of a service, the service provision control unit 402 verifies the user's identity and obtains the necessary certificates (credential certificates) for providing the service. The service provision control unit 402 performs identity verification and obtains credential certificates before providing the service to the user.
[0134] The operation of the service provision control unit 402 will be explained with reference to Figure 12.
[0135] The service provision control unit 402 sends a biometric information request to the user's terminal 30 (step S301). Specifically, the service provision control unit 402 requests the terminal 30 to provide the biometric information stored in the terminal 30 (biometric information used for identity verification; biometric information used when opening the digital wallet).
[0136] When the terminal 30 receives a negative response (unable to provide biometric information) (step S302, No branch), the service provision control unit 402 notifies the user that the service cannot be provided because identity verification failed (step S303).
[0137] When the service provision control unit 402 receives an affirmative response (a response containing two biometric pieces of information) from terminal 30 (step S302, Yes branch), it verifies the user's identity (step S304). The service provision control unit 402 verifies the user's identity by determining whether the two biometric pieces of information are substantially the same.
[0138] The identity verification process performed by the service provision control unit 402 can be the same as that performed by the identity verification unit 202 of the terminal 30, so the explanation is omitted.
[0139] If identity verification fails (step S305, No branch), the service provision control unit 402 notifies the user that the service cannot be provided because identity verification failed (step S303).
[0140] If identity verification is successful (Step S305, Yes branch), the service provision control unit 402 obtains the information (certificates) necessary to provide services to the user. For example, the service provision control unit 402 of a service provider offering job placement assistance services obtains employment certificates, graduation certificates, various qualifications, language proficiency certificates, etc.
[0141] Specifically, the service provision control unit 402 sends a "certificate provision request" to the terminal 30 (step S306). The service provision control unit 402 sends a certificate provision request to the terminal 30 that includes information about at least one certificate necessary for the service provider to provide the service (e.g., the type of certificate).
[0142] If a negative response (unable to provide certificate) is received from terminal 30 (step S307, No branch), the service provision control unit 402 notifies the user that it cannot provide the service because it cannot obtain the necessary information (step S303).
[0143] If the service provision control unit 402 receives an acknowledgment (a response including a credential certificate) from terminal 30 (step S307, Yes branch), it verifies the credential certificate included in the acknowledgment (step S308).
[0144] Specifically, the service provision control unit 402 obtains the issuer ID and user ID listed on the credential certificate. The service provision control unit 402 obtains the public key corresponding to the obtained issuer ID from the blockchain. Similarly, the service provision control unit 402 obtains the public key corresponding to the obtained user ID from the blockchain.
[0145] The service provision control unit 402 verifies the signature of the holder (the user requesting the service) and the signature of the issuer attached to the credential certificate. If multiple credential certificates are obtained from the terminal 30, the service provision control unit 402 verifies the signatures of the holder and issuer for each of the multiple credential certificates.
[0146] If the verification of the credential certificate fails (step S309, No branch), the service provision control unit 402 notifies the user that it cannot provide the service because it cannot obtain the necessary information (step S303).
[0147] If the credential certificate is successfully verified (step S309, Yes branch), the service provision control unit 402 provides the service to the user (step S310).
[0148] For example, the service provision control unit 402 of a job placement service provider generates an account by associating the user's basic information (basic information; for example, name, gender, date of birth, address, etc.) with information obtained from the credential certificate (work history, educational background, etc.). Once the account is generated, the service provision control unit 402 performs matching using the user's information with information from companies participating in the job placement service (companies that are hiring). The service provision control unit 402 then presents the user with the matching results (information about potential employers).
[0149] Further detailed explanations regarding individual service provision are omitted. This is because detailed explanations of services specific to each service provider would be inconsistent with the purpose of this disclosure.
[0150] The storage unit 403 is a means for storing information necessary for the operation of the service server 20. For example, the storage unit 403 stores the types of services provided to users and the types of certificates required to provide those services in association with each other.
[0151] [Carrier terminal] A detailed explanation of the configuration and operation of the service provider terminal 21 is omitted. The basic configuration and operation of the service provider terminal 21 can be the same as that of the service server 20. The service provider terminal 21 communicates with terminal 30 using short-range wireless communication such as Bluetooth® to obtain biometric information and credential certificates. Once the service provider terminal 21 successfully verifies the user's identity and credential certificates, the service provider provides services to the user.
[0152] [System operation] Next, the operation of the information processing system according to the first embodiment will be described.
[0153] Figure 13 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment disclosed herein. Referring to Figure 13, the operation of the information processing system according to the first embodiment concerning certificate issuance will be described.
[0154] Terminal 30 generates a public key, a private key, and a user ID, and registers the user ID and public key on the blockchain (step S21).
[0155] Terminal 30 sends a certificate issuance request including the above-mentioned user ID to the certificate issuer's server device 10 (step S22).
[0156] The server device 10 generates the user's (the recipient of the credential certificate) credentials and generates a credential certificate containing the generated credentials (step S23). The server device 10 generates a credential certificate that includes the user ID and issuer ID and is digitally signed.
[0157] The server device 10 sends the generated credential certificate to the terminal 30 (step S24).
[0158] Terminal 30 stores the credential certificate in its digital wallet (step S25).
[0159] Figure 14 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment of the present disclosure. Referring to Figure 14, the operation of the information processing system according to the first embodiment concerning certificate provision will be described.
[0160] The service provider's device (service server 20 in Figure 14) sends a request for biometric information to terminal 30 (step S31).
[0161] Terminal 30 transmits biometric information stored in its own device and biometric information obtained by photographing the operator of its own device to the service server 20 (step S32).
[0162] The service server 20 performs identity verification using the two biometric pieces of information (step S33).
[0163] If identity verification is successful, the service server 20 sends a certificate provision request to the terminal 30 specifying the required credential certificate (step S34).
[0164] Terminal 30 reads the credential certificate specified by the service provider from the digital wallet and sends the read credential certificate to the service server 20 (step S35).
[0165] The service server 20 verifies the acquired credential certificate (step S36).
[0166] If the credential certificate is successfully verified, the service server 20 provides the service to the user (step S37).
[0167] For example, when a user uses a job placement service, the job placement service provider verifies that the owner of terminal 30 and the applicant applying for the job placement service are the same person. The job placement service provider performs this verification using two biometric pieces of information. If the identity verification is successful, the job placement service provider requests the submission of personal information (name, gender, etc.) in addition to employment certificates, etc., for user registration. For example, the job placement service provider requests the submission of an employment certificate that proves that the user was employed by the target company. The job placement service provider uses the qualification information written on the acquired employment certificate to perform job matching and provide information to the user.
[0168] When a user arrives at a prospective employer or event venue, the business terminal 21 installed at the event venue or venue verifies the user's identity and obtains a credential certificate. In other words, when a user has an interview with a prospective employer or participates in an event, authentication is performed using a tablet or similar device installed at each location, and if authentication is successful, the credential certificate is provided to the company or event. That is, the user discloses their credentials (registration information; credential certificate) stored in the digital wallet of the terminal 30 only to the companies or events they have selected (companies or events they have opted to).
[0169] Alternatively, when a user (student) uses a job placement service, similar to a career change support service, the job placement service provider and the prospective employer will verify the user's identity and obtain credential documents. The user will provide each service provider with documents such as a certificate of enrollment, a certificate proving the content of internships during their enrollment, and a certificate proving the fact of studying abroad.
[0170] Next, a modified example of the first embodiment will be described.
[0171] <Example 1> In the above embodiment, the case in which the service provider's equipment (service server 20, service provider terminal 21) verifies the user's identity was described. This identity verification may also be performed on the user's terminal 30.
[0172] For example, the service provider's device sends a certificate request to terminal 30 without sending a biometric information request. Upon receiving the certificate request, terminal 30 takes a photograph of the user (the owner of terminal 30). Terminal 30 then performs identity verification (one-to-one authentication) using the biometric information obtained from the photograph and the biometric information acquired when opening the digital wallet.
[0173] If identity verification is successful, terminal 30 reads the credential certificate specified by the service provider from the digital wallet and transmits the read credential certificate to the service provider's device.
[0174] <Modification 2> In the above embodiment, the credential certificate was described as being provided from the user to the service provider via a communication method such as the internet or Bluetooth®. The credential certificate may also be provided from the user (holder) to the service provider (verifier) using a means such as a two-dimensional barcode (see Figure 15).
[0175] For example, when providing a service to a user, an employee of the service provider informs the user (verbally) of the necessary documents to receive the service. The user operates terminal 30 and selects the provided credential document. Terminal 30 signs the selected credential document and converts the signed credential document into a 2D barcode. Terminal 30 displays the 2D barcode.
[0176] Employees of the service provider operate the service provider terminal 21 to read the 2D barcode and obtain the credential certificate by decoding the 2D barcode.
[0177] The above 2D barcode may also include biometric information (facial image) obtained when opening the digital wallet. In this case, the business terminal 21 takes a photograph of the user in front of it and obtains a facial image. The business terminal 21 may perform identity verification using the obtained facial image and the facial image obtained from the 2D barcode.
[0178] Alternatively, the service provider terminal 21 may display a facial image obtained from a 2D barcode on its display. The service provider's employees may verify the identity of the user by comparing the facial image displayed on the display with the face of the user in front of them.
[0179] <Variation 3> When providing services to users, a Verifiable Presentation (VP) may be sent and received between the user and the service provider instead of a credential certificate. In other words, a portion of the VCs issued by the certificate issuer may be provided by the user (holder) to the service provider (verifier) as a verifiable presentation.
[0180] For example, if a graduation certificate contains a user's date of birth or address at the time of graduation, the service provider may not need that information. Similarly, users may not want to provide unnecessary personal information to external parties when receiving services. To address these needs, "selective minimum disclosure" using verifiable presentations (VPs) may be implemented.
[0181] To achieve the selective minimum disclosure described above, the certificate issuer of the credential certificate separates the data that they wish to include in the selective minimum disclosure from the data set and calculates the hash value of the separated data. The certificate issuer (server device 10) embeds the hash value of the separated data into the data set. The server device 10 signs the entire data set, including the hash value of the separated data, and generates a credential certificate.
[0182] When providing services to a user, the service provider's device notifies the terminal 30 of the required information along with the type of certificate required. For example, the service server 20 notifies the terminal 30 of the graduation certificate and required information (e.g., name, graduation year, department).
[0183] Terminal 30 presents the user with information obtained from the service provider (certificate type, required items). Terminal 30 also displays a GUI that allows the user to select which items to provide to the service provider from among the multiple items listed in the credential certificate. For example, terminal 30 uses a GUI like the one shown in Figure 16 to obtain the items in the certificate that the user has authorized to provide to the service provider.
[0184] Terminal 30 sends a VP (Verifiable Presentation) to the service server 20, which includes the selected items and is signed with the user's private key.
[0185] The service server 20 verifies the VP's signature, similar to how it does with credential certificates, and provides the service to the user if the verification is successful.
[0186] Alternatively, terminal 30 may automatically generate a VP (Virtual Property) with the certificate and required items specified by the service provider, and send the automatically generated VP to the service server 20.
[0187] <Modification 4> The above embodiment describes a case where a user (holder of a credential certificate) provides a service provider (verifier) with a credential certificate stored in a digital wallet. Some services provided by service providers do not require the specific details described in the credential certificate.
[0188] For example, some service providers require users to have their highest level of education, but do not require specific information such as the university or department they graduated from. There is no need to provide such service providers with a graduation certificate containing a lot of personal information.
[0189] Therefore, the information processing system disclosed in this application may use techniques such as zero-knowledge proofs to provide the service provider (verifier) with only the fact that the proposition held by the user (holder of the credential certificate) is true. In the above example, the user only needs to tell the service provider that they are a university graduate, and does not need to provide specific information such as the university they graduated from.
[0190] To implement the proof using the zero-knowledge proof described above, the user's terminal 30 and the service provider's equipment (service server 20, service provider terminal 21) exchange only the information required by the service provider using the interactive knowledge proof protocol.
[0191] <Modification 5> If the certificate specified by the service provider is not stored in the digital wallet, terminal 30 may obtain the missing certificate from the certificate issuer.
[0192] The usage control unit 204 of terminal 30 notifies the acquisition control unit 203 of the credential certificate (type of credential certificate) specified by the service provider's service server 20 or business terminal 21 but not stored in the digital wallet.
[0193] The acquisition control unit 203 acquires the notified certificate from the certificate issuer. Specifically, the acquisition control unit 203 sends the "certificate issuance request" described above to the server device 10.
[0194] When the acquisition control unit 203 obtains a credential certificate from the certificate issuer (server device 10), it stores the obtained credential certificate in the digital wallet. The acquisition control unit 203 also notifies the usage control unit 204 that the credential certificate has been stored in the digital wallet.
[0195] For example, if the employment certificate required to receive job placement services is not stored in the digital wallet, terminal 30 requests the employer to issue an employment certificate. Terminal 30 then sends the obtained employment certificate to the job placement service provider (the job placement service provider's service server 20).
[0196] As described above, the terminal 30 according to the first embodiment performs identity verification using biometric information when opening a digital wallet. If identity verification is successful, the biometric information used when opening the digital wallet is stored in the terminal 30. When a user wishes to receive services from a service provider, the service provider requests the biometric information stored in the terminal 30. The terminal 30 provides the service provider with at least the biometric information acquired when opening the digital wallet. The service provider performs one-to-one authentication using the biometric information acquired from the terminal 30 (biometric information acquired when opening the digital wallet) and the biometric information of the user in front of them (the owner of the terminal 30). If authentication is successful, the service provider can confirm that the recipient of the certificate stored in the digital wallet and the person requesting the service are the same person. Once it is confirmed that the recipient of the certificate and the person requesting the service are the same person, the service provider provides the service to the user using the certificate acquired from the terminal 30. As a result, unauthorized use of certificates stored in smartphones, etc., is prevented.
[0197] Terminal 30 verifies the identity of the digital wallet owner using an identification document issued by a public institution at the time of digital wallet creation. If the verification is successful, terminal 30 stores the biometric information obtained at the time of digital wallet creation as the biometric information of the digital wallet owner. When a user receives a service from a service provider, terminal 30 provides the digital wallet owner's biometric information to the service provider. The service provider can verify whether the digital wallet owner providing the certificate and the user in front of them are the same person by performing an authentication process using the biometric information obtained from terminal 30 and the biometric information of the user who wishes to enjoy the service. As a result, even if someone other than the digital wallet owner tries to use the digital wallet owner's terminal 30 to receive services from the service provider, the service provider can detect the fraudulent activity. In other words, the authenticity of the certificate provided by the digital wallet is guaranteed.
[0198] Furthermore, terminal 30 provides the service provider with the credential certificates (VCs) obtained from the certificate issuer. By verifying the signature of the credential certificate obtained from terminal 30, the service provider can confirm that the credential certificate has not been tampered with and that it was issued by a legitimate certificate issuer. As a result, the service provider can provide appropriate services to users based on reliable information.
[0199] Furthermore, users can manage their own personal information (certificates) and provide the personal information (certificates) stored on terminal 30 only to service providers of their choosing. In this way, the information processing system disclosed in this application can provide a self-sovereign identity system in which the user themselves is the entity responsible for managing personal information. Users can choose the recipient of their information disclosure for each service they use.
[0200] Next, we will describe the hardware of each device that makes up the information processing system. Figure 17 shows an example of the hardware configuration of terminal 30.
[0201] Terminal 30 can be configured using an information processing device (a so-called computer), and has the configuration illustrated in Figure 17. For example, terminal 30 includes a processor 311, memory 312, input / output interface 313, and communication interface 314, etc. The components of the processor 311, etc., are connected by an internal bus or the like and are configured to communicate with each other.
[0202] However, the configuration shown in Figure 17 is not intended to limit the hardware configuration of terminal 30. Terminal 30 may include hardware not shown, and may not have an input / output interface 313 if necessary. Also, the number of processors 311 etc. included in terminal 30 is not intended to be limited to the example in Figure 17; for example, terminal 30 may include multiple processors 311.
[0203] The processor 311 is a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs, including an operating system (OS).
[0204] Memory 312 includes RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc. Memory 312 stores the OS program, application programs, and various data.
[0205] The input / output interface 313 is an interface for a display device or input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user input such as a keyboard or mouse.
[0206] The communication interface 314 is a circuit, module, etc., that communicates with other devices. For example, the communication interface 314 includes a NIC (Network Interface Card), etc.
[0207] The functions of terminal 30 are realized by various processing modules. These processing modules are realized, for example, by the processor 311 executing a program stored in memory 312. The program can also be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as semiconductor memory, hard disk, magnetic recording medium, or optical recording medium. In other words, the present invention can also be embodied as a computer program product. Furthermore, the program can be downloaded via a network or updated using the storage medium on which the program is stored. Moreover, the processing module may be realized by a semiconductor chip.
[0208] Furthermore, the server device 10, service server 20, and carrier terminal 21 can also be configured using information processing devices, similar to terminal 30. Since their basic hardware configurations are identical to those of terminal 30, a detailed explanation is omitted.
[0209] The terminal 30, which is an information processing device, is equipped with a computer, and its functions can be realized by having the computer execute a program. Furthermore, the terminal 30 executes a control method for the terminal 30 using this program. Similarly, the server device 10 is equipped with a computer, and its functions can be realized by having the computer execute a program. Furthermore, the server device 10 executes a control method for the server device 10 using this program.
[0210] [Differentiation] The configuration and operation of the information processing system described in the above embodiment are illustrative examples and are not intended to limit the system configuration.
[0211] In the above embodiment, the case was described in which the certificate issuer's server device 10 issues a credential certificate that does not require a Certificate Authority for certificate verification. However, the server device 10 may also issue a certificate that requires a Certificate Authority (a public key infrastructure-based certificate).
[0212] The service provider's equipment (service server 20, service provider terminal 21) may request the submission of biometric information and certificates simultaneously. Specifically, the service server 20, etc., does not send a request for biometric information, but first sends a request for certificate provision. Upon receiving the certificate provision request, the terminal 30 sends the biometric information necessary for identity verification and the specified credential certificate to the service server 20, etc.
[0213] If the service is provided by the service provider terminal 21, the service provider terminal 21 may take a photograph of the user (the owner of terminal 30) to obtain biometric information. In this case, terminal 30 should send the previously registered biometric information (biometric information used when opening the digital wallet) to the service provider terminal 21 in response to the biometric information request received from the service provider terminal 21. The service provider terminal 21 should perform identity verification using the facial image obtained by the photograph and the facial image obtained from terminal 30. After successful identity verification, the service provider terminal 21 sends a certificate request to terminal 30.
[0214] The above embodiment describes a case where identity verification (confirmation that the name on the identity document matches the name on the digital wallet) is performed using biometric information obtained from an identity document. However, this identity verification may also be performed using an electronic certificate stored in the identity document. Specifically, terminal 30 obtains an electronic certificate (signature electronic certificate, user authentication electronic certificate) from the My Number Card held by the user. Terminal 30 sends the obtained electronic signature certificate to a certification authority (J-LIS; Japan Agency for Local Authority Information Systems) and requests the certification authority to verify the validity of the electronic certificate. If the electronic certificate is valid, terminal 30 determines that identity verification has been successful.
[0215] Some functions of terminal 30 may be implemented in other devices or equipment. More specifically, it is sufficient if the "identity verification unit (identity verification means)", "acquisition control unit (acquisition control means)", etc. described above are implemented in any of the devices included in the system.
[0216] The form of data transmission and reception between each device (for example, server device 10, terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users is transmitted and received between these devices, and it is desirable that encrypted data be transmitted and received in order to properly protect this information.
[0217] In the flowcharts (sequence diagrams) used in the above description, multiple processes (processes) are shown in order, but the execution order of the processes performed in the embodiment is not limited to the order in which they are shown. In the embodiment, the order of the illustrated processes can be changed to the extent that it does not impair the content, for example, by executing each process in parallel.
[0218] The embodiments described above are explained in detail to facilitate understanding of the disclosure, and it is not intended that all the configurations described above are necessary. Furthermore, when multiple embodiments are described, each embodiment may be used individually or in combination. For example, it is possible to replace parts of the configuration of one embodiment with those of another embodiment, or to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of one embodiment with those of another.
[0219] As described above, the industrial applicability of the present invention is clear, and it is particularly applicable to information processing systems, etc., that include service providers who provide services to users using certificates stored in a digital wallet.
[0220] Some or all of the above embodiments may also be described as follows, but are not limited to the following:
[0221] [Note 1] A storage means that stores the user's biometric information obtained when opening a digital wallet, and also stores certificates issued by certificate issuers in the said digital wallet, A usage control means that provides the service provider with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider. A terminal equipped with the following features. [Note 2] The terminal described in Appendix 1 further comprises an identity verification means for verifying the identity of the person opening the digital wallet using biometric information obtained from an identification document and biometric information of the person opening the digital wallet. [Note 3] The terminal as described in Appendix 2, further comprising acquisition control means for requesting the certificate issuer to issue the certificate selected by the user, and storing the certificate obtained from the certificate issuer in the digital wallet. [Note 4] The terminal described in Appendix 3, wherein the usage control means provides the service provider with biometric information obtained from the identification document or biometric information of the person opening the digital wallet, and biometric information of the operator operating the device, in response to a request from the service provider. [Note 5] The acquisition control means is a terminal as described in Appendix 3, which acquires a credential certificate from the certificate issuer and stores the acquired credential certificate in the digital wallet. [Note 6] The terminal described in Appendix 5, wherein the acquisition control means, upon successful verification of the signature of the acquired credential certificate, stores the acquired credential certificate in the digital wallet. [Note 7] The service provider's equipment, The device owned by the user, Includes, The aforementioned terminal is A storage means that stores the user's biometric information obtained when the digital wallet is opened, and also stores the certificate issued by the certificate issuer in the digital wallet, A usage control means that provides the service provider's device with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider, A system that includes these features. [Note 8] The system described in Appendix 7 further includes an identity verification means that verifies the identity of the person opening the digital wallet using biometric information obtained from an identification document and biometric information of the person opening the digital wallet. [Note 9] The system as described in Appendix 8, further comprising acquisition control means for the terminal to request the certificate issuer to issue a certificate selected by the user, and to store the certificate obtained from the certificate issuer in the digital wallet. [Note 10] The system as described in Appendix 9, wherein the usage control means provides the service provider with biometric information obtained from the identification document or biometric information of the person opening the digital wallet, and biometric information of the operator operating the device, in response to a request from the service provider. [Note 11] The acquisition control means is the system described in Appendix 9, which acquires a credential certificate from the certificate issuer and stores the acquired credential certificate in the digital wallet. [Note 12] The acquisition control means, upon successful verification of the signature of the acquired credential certificate, stores the acquired credential certificate in the digital wallet, as described in Appendix 11. [Note 13] A storage step involves storing the user's biometric information obtained when opening a digital wallet, and also storing certificates issued by certificate issuers in the digital wallet. A usage control step that provides the service provider with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider. A method for controlling a terminal, comprising the following features. [Note 14] The terminal control method described in Appendix 13 further comprises an identity verification step, which involves verifying the identity of the person opening the digital wallet using biometric information obtained from an identification document and biometric information of the person opening the digital wallet. [Note 15] The terminal control method described in Appendix 14, further comprising an acquisition control step of requesting the certificate issuer to issue a certificate selected by the user, and storing the certificate obtained from the certificate issuer in the digital wallet. [Note 16] The terminal control method described in Appendix 15, wherein the usage control step provides the service provider with biometric information obtained from the identification document or biometric information of the person opening the digital wallet, and biometric information of the operator operating the device, in response to a request from the service provider. [Note 17] The acquisition control step is a terminal control method as described in Appendix 15, which involves acquiring a credential certificate from the certificate issuer and storing the acquired credential certificate in the digital wallet. [Note 18] The terminal control method described in Appendix 17, wherein the acquisition control step, upon successful verification of the signature of the acquired credential certificate, stores the acquired credential certificate in the digital wallet. [Note 19] On the computer installed in the terminal, The digital wallet stores the user's biometric information obtained when the digital wallet was opened, and also stores the certificate issued by the certificate issuer in the digital wallet; this is a storage process. A usage control process that provides the service provider with at least the stored biometric information and a certificate stored in the digital wallet that is designated by the service provider. A program to execute. [Note 20] The program described in Appendix 19 further performs an identity verification process to verify the identity of the person opening the digital wallet, using biometric information obtained from an identification document and biometric information of the person opening the digital wallet. [Note 21] The program described in Appendix 20, which further executes an acquisition control process that requests the certificate issuer to issue the certificate selected by the user, and stores the certificate obtained from the certificate issuer in the digital wallet. [Note 22] The aforementioned usage control process is the program described in Appendix 21, which, in response to a request from the service provider, provides the service provider with biometric information obtained from the identification document or biometric information of the person opening the digital wallet, and biometric information of the operator operating the device. [Note 23] The acquisition control process is the program described in Appendix 21, which acquires a credential certificate from the certificate issuer and stores the acquired credential certificate in the digital wallet. [Note 24] The acquisition control process is the program described in Appendix 23, which, upon successful verification of the signature of the acquired credential certificate, stores the acquired credential certificate in the digital wallet.
[0222] Furthermore, some or all of the configurations described in Appendices 2 to 6, which are dependent on Appendice 1 above, may also be dependent on Appendices 7, 13, and 19 in the same way as those described in Appendices 2 to 6. Moreover, not limited to Appendices 1, 7, 13, and 19, some or all of the configurations described as appendices may also be dependent on various hardware, software, various recording means for recording software, or systems, without departing from the embodiments described above.
[0223] Furthermore, each disclosure of the above-mentioned prior art documents cited herein is incorporated herein by reference. Although embodiments of the present invention have been described above, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. That is, the present invention naturally includes the entire disclosure, including the claims, and various modifications and alterations that can be made by those skilled in the art in accordance with the technical idea. [Explanation of Symbols]
[0224] 10 Server devices 20 Service Servers 21. Carrier terminals 30 devices 100 devices 101 Memory means 102 Usage control means 201 Communication Control Unit 202 Identity Verification Department 203 Acquisition Control Unit 204 Utilization Control Unit 205 Storage section 301 Communication Control Unit 302 Certificate Issuance Department 303 Storage section 311 Processors 312 memory 313 Input / Output Interfaces 314 Communication Interface 401 Communication Control Unit 402 Service Provisioning Control Unit 403 Storage section
Claims
1. When the first identity verification is determined to be successful by biometric authentication using first biometric information obtained from an identification document and second biometric information obtained by photographing the holder of a digital wallet, a storage means stores the first or second biometric information and stores the certificate issued by the certificate issuer in the digital wallet. A receiving means for receiving information about certificates specified by the service provider, If the certificate designated by the service provider is not stored in the digital wallet, the user control means obtains the designated certificate from a certificate issuer authorized to issue the designated certificate, performs a second identity verification using the stored first or second biometric information and a third biometric information obtained by photographing the user operating the device, and if the second identity verification is successful, provides the obtained certificate to the service provider. An information processing device equipped with the following features.
2. The information processing apparatus according to claim 1, wherein the receiving means receives an information provision request from a server operated by the service provider, the request for information provision including information regarding a certificate requested by the service provider.
3. The information processing apparatus according to claim 2, further comprising acquisition control means for requesting the certificate issuer to issue a certificate selected by the user, and storing the certificate obtained from the certificate issuer in the digital wallet.
4. The information processing apparatus according to claim 3, wherein the acquisition control means acquires a credential certificate from the certificate issuer and stores the acquired credential certificate in the digital wallet.
5. The information processing device according to claim 4, wherein the acquisition control means stores the acquired credential certificate in the digital wallet when it successfully verifies the signature of the acquired credential certificate.
6. The service provider's equipment, The device owned by the user, Includes, The aforementioned terminal stores the user's biometric information obtained when the digital wallet is opened, and also stores the certificate issued by the certificate issuer in the digital wallet. When the user requests the service, the service provider's device transmits a request for biometric information to the terminal. Upon receiving the request for biometric information, the terminal acquires the user's biometric information by photographing the user, and transmits the acquired biometric information and the stored biometric information to the service provider's device. The service provider's device performs identity verification using the biometric information received from the terminal and the biometric information stored in the terminal, and if the identity verification is successful, it sends a certificate request to the terminal specifying the certificate necessary for providing the service. The terminal is a system that, if the certificate specified by the service provider is not stored in the digital wallet, obtains the specified certificate from a certificate issuer authorized to issue the specified certificate and provides the obtained certificate to the service provider.
7. When the first identity verification is determined to be successful by biometric authentication using first biometric information obtained from an identification document and second biometric information obtained by photographing the holder of the digital wallet, a storage step is made in which the first or second biometric information is stored and the certificate issued by the certificate issuer is stored in the digital wallet. The receiving process involves receiving information about the certificate specified by the service provider. If the certificate designated by the service provider is not stored in the digital wallet, the service provider obtains the designated certificate from the certificate issuer authorized to issue the designated certificate, performs a second identity verification using the stored first or second biometric information and a third biometric information obtained by photographing the user operating the device, and if the second identity verification is successful, provides the obtained certificate to the service provider. A control method for an information processing device, comprising the above.
8. A computer mounted on an information processing device, If the first identity verification is determined to be successful through biometric authentication using first biometric information obtained from an identification document and second biometric information obtained by photographing the holder of the digital wallet, the first or second biometric information is stored, and the certificate issued by the certificate issuer is stored in the digital wallet, a storage process is performed. The receiving process involves receiving information about the certificate specified by the service provider. If the certificate specified by the service provider is not stored in the digital wallet, the service provider obtains the specified certificate from the certificate issuer authorized to issue the specified certificate, performs a second identity verification using the stored first or second biometric information and a third biometric information obtained by photographing the user operating the device, and if the second identity verification is successful, provides the obtained certificate to the service provider, a usage control process, A program to execute.
Citation Information
Patent Citations
Visitor management system and visitor management method
JP2022135182A
A system and method of dynamic issuance of privacy preserving credentials
US20150341340A1
Cooperation server, system, immune certificate generation method, and non-transitory computer-readable medium
WO2021240724A1
Method for managing electronic certificate on basis of biometric information
WO2022169273A1