Identity management system, identity management method, and program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2024-06-28
- Publication Date
- 2026-04-02
AI Technical Summary
Current identity management systems in virtual spaces face challenges in efficiently managing qualifications and effectively utilizing identity characteristics, leading to inefficiencies in authentication and authorization processes for both real users and avatars in metaverses.
An identity management system that includes a qualification management unit for storing and verifying credential information, featuring a feature word processing unit that extracts and visualizes characteristic word relationships to enhance identity authentication and authorization, allowing for efficient management and utilization of identity characteristics.
This solution enables efficient management of qualifications and effective utilization of identity characteristics, improving authentication and authorization processes, thereby enhancing user experience and convenience in virtual environments.
Abstract
Description
Identity management system, identity management method, and program
[0001] The present invention relates to an identity management system, an identity management method, and a program. This application claims priority based on Japanese Patent Application No. 2023-107259 filed in Japan on June 29, 2023, and Japanese Patent Application No. 2023-135662 filed in Japan on August 23, 2023, the contents of which are incorporated herein by reference.
[0002] 2. Description of the Related Art There is known a technology that enables an avatar in a virtual space to perform actions such as purchasing a virtual object in response to a user's operation (see, for example, Patent Document 1).
[0003] Japanese Patent Application Publication No. 2022-117111
[0004] When a real user acts in real space or when an avatar corresponding to that real user or another user acts in virtual space, credentials (proof of identity, required conditions for certain matters, authority, etc.) are required in various situations, and the credentials presented may vary. Considering this, it is preferable to efficiently manage the credentials related to the existence (identity) of real users, avatars, etc.
[0005] Each real user in the real world has a different personality. Also, the avatars that exist in the virtual world (metaverse) corresponding to each real user have different personalities depending on the personalities of the corresponding real users and their past actions in the virtual world. Considering this, it would be desirable to be able to effectively utilize information about the characteristics of identities such as real users and avatars in the identity activity space, as this would improve interest and convenience.
[0006] The present invention aims to enable efficient management of qualifications related to identities and to enable effective utilization of the characteristics of identities in the activity space of the identities.
[0007] A first aspect of the present invention that solves the above-mentioned problems is an identity management system that includes a qualification management unit that stores, in a memory unit, a specified number of pieces of qualification information, including one or more pieces of qualification information that are assigned to an identity as a real user existing in real space and indicate that the user has specified qualifications, and one or more pieces of qualification information that are assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in association with one information storage medium held by the real user.
[0008] A second aspect of the present invention is the identity management system according to the first aspect, wherein the qualification information includes identification information that proves the identity of the identity.
[0009] A third aspect of the present invention is the identity management system according to the first or second aspect, wherein the credential information includes authenticity proof information that proves the authenticity of the identity.
[0010] A fourth aspect of the present invention is an identity management system described in any one of the first to three aspects, wherein the qualification management unit outputs qualification information selected by a real user through an operation on the corresponding user terminal from the qualification information stored in the memory unit as qualification information to be used for qualification confirmation of the identity that is the subject of qualification confirmation.
[0011] A fifth aspect of the present invention is an identity management method in an identity management system, comprising a qualification management step in which a qualification management unit stores in a memory unit a predetermined number of pieces of qualification information, including one or more pieces of qualification information assigned to an identity as a real user existing in real space and indicating that the identity has predetermined qualifications, and one or more pieces of qualification information assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in association with one information storage medium held by the real user.
[0012] A sixth aspect of the present invention is a program for causing a computer in an identity management system to function as a qualification management unit that stores in a memory unit a specified number of pieces of qualification information, including one or more pieces of qualification information assigned to an identity as a real user existing in real space and indicating that the user has specified qualifications, and one or more pieces of qualification information assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in association with a single information storage medium held by the real user.
[0013] A seventh aspect of the present invention that solves the above-mentioned problems is an identity management system that includes a memory unit that stores identity individual information that corresponds to an identity as a real user existing in real space and an identity as an avatar that can exist in the metaverse and is individualized corresponding to the identity, and a feature word processing unit that extracts feature words and identifies relationships between the feature words corresponding to the identity based on the content of the identity individual information stored in the memory unit, and generates feature word relationship information that indicates the identified relationships.
[0014] An eighth aspect of the present invention is the identity management system according to the seventh aspect, wherein the characteristic word processing unit, when extracting the characteristic words, scores the characteristic words based on the identity individual information.
[0015] A ninth aspect of the present invention is an identity management system of the seventh or eighth aspect, in which the feature word processing unit generates feature word relationship display information that can visualize and present the relationships between feature words indicated by the feature word relationship information.
[0016] A tenth aspect of the present invention is the identity management system of the ninth aspect, wherein the feature word processing unit causes the results of feature word scoring to be displayed in a predetermined manner in the feature word relationship display information.
[0017] An eleventh aspect of the present invention is an identity management system of any one of the seventh to tenth aspects, in which the characteristic word processing unit generates, for one identity, multiple characteristic word relationship information corresponding to different characteristics of the identity.
[0018] A twelfth aspect of the present invention is an identity management system of any one of the seventh to eleventh aspects, in which the feature word processing unit generates integrated feature word relationship information that integrates multiple feature word relationship information.
[0019] A thirteenth aspect of the present invention is an identity management system of the eleventh aspect, in which the feature word processing unit generates the integrated feature word relationship information so as to reconstruct it using a portion of a plurality of feature word relationship information selected from the plurality of feature word relationship information used to generate the integrated feature word relationship information.
[0020] A fourteenth aspect of the present invention is an identity management system of any one of the seventh to thirteenth aspects, further comprising a matching unit that makes a determination regarding matching of multiple identities based on the similarity of characteristic word relationship information corresponding to each of the multiple identities that are the target of matching.
[0021] A fifteenth aspect of the present invention is an identity management system of the fourteenth aspect, in which the feature word processing unit generates integrated feature word relationship information that integrates feature word relationship information for each identity matched by the matching unit.
[0022] A sixteenth aspect of the present invention is an identity management method in an identity management system, comprising a feature word processing step in which a feature word processing unit extracts feature words and identifies relationships between feature words corresponding to the identities based on the content of the identity individual information stored in a memory unit, which corresponds to an identity as a real user existing in real space and an identity as an avatar that can exist in the metaverse, and generates feature word relationship information indicating the identified relationships.
[0023] A 17th aspect of the present invention is a program for causing a computer provided by an identity management system to function as a feature word processing unit that extracts feature words and identifies relationships between feature words corresponding to an identity based on the content of the identity individual information stored in a memory unit, which corresponds to an identity as a real user existing in real space and an identity as an avatar that can exist in the metaverse, and which is individual in correspondence with the identity, and generates feature word relationship information indicating the identified relationships.
[0024] According to the present invention, the management of qualifications related to identities can be performed efficiently, and the characteristics of identities can be effectively utilized in the activity space of the identities.
[0025] 1 is a diagram showing an example of the overall configuration of an avatar management system according to the first embodiment. FIG. 2 is a diagram showing an example of the configuration of an avatar generation system according to the embodiment. FIG. 3 is a diagram showing a schematic diagram of the flow of avatar generation according to the embodiment. FIG. 4 is a diagram showing an example of the configuration of an avatar management device according to the embodiment. FIG. 5 is a diagram showing an example of end user information according to the embodiment. FIG. 6 is a diagram showing an example of avatar information according to the embodiment. FIG. 7 is a diagram showing an example of a metafile according to the embodiment. FIG. 8 is a diagram showing an example of information stored in a user VC storage unit according to the embodiment in association with a real user. FIG. 9 is a diagram showing an example of information stored in an avatar VC storage unit according to the embodiment in association with a real user. FIG. 10 is a diagram showing an example of the structure of issuer information according to the embodiment. FIG. 11 is a diagram showing an example of the structure of wallet management information according to the embodiment. FIG. 12 is a sequence diagram showing an example of processing procedures executed by the avatar management system according to the embodiment in relation to avatar generation, registration, and registration of avatar authentication information. FIG. 13 is a diagram showing an example of credential information management according to the embodiment. FIG. 14 is a diagram showing an example of operation procedures of an end user terminal corresponding to age authentication of a real user according to the embodiment. FIG. 15 is a diagram showing an example of operation procedures of an end user terminal corresponding to age authentication of a real user according to the embodiment. FIG. 16 is a diagram showing an example of operation procedures of an end user terminal corresponding to age authentication of a real user according to the embodiment. FIG. 1 is a sequence diagram showing an example of a processing procedure executed by an end user terminal, an avatar management device, and a service providing system in response to avatar qualification verification according to the present embodiment. FIG. 2 is a diagram showing an example of the overall configuration of an identity management system according to a second embodiment. FIG. 3 is a diagram showing an example of the configuration of an avatar generation system according to the present embodiment. FIG. 4 is a diagram showing a schematic diagram of the flow of avatar generation according to the present embodiment. FIG. 5 is a diagram showing an example of the hardware configuration of an identity management device according to the present embodiment. FIG. 6 is a diagram showing an example of the functional configuration of an identity management device according to the present embodiment. FIG. 7 is a diagram showing an example of end user information according to the present embodiment. FIG. 8 is a diagram showing an example of avatar information according to the present embodiment. FIG. 9 is a diagram showing an example of a metafile according to the present embodiment.FIG. 1 is a diagram showing an example of information stored in a user VC storage unit according to the present embodiment in association with an avatar. FIG. 2 is a diagram showing an example of information stored in an avatar VC storage unit according to the present embodiment in association with a real user. FIG. 3 is a diagram showing an example of the structure of wallet management information according to the present embodiment. FIG. 4 is a diagram showing an example of the structure of identity history information according to the present embodiment. FIG. 5 is a diagram showing an example of the structure of issuer information according to the present embodiment. A sequence diagram showing an example of processing procedures executed by an identity management system according to the present embodiment in association with the generation and registration of avatar authentication information. A diagram showing an example of a wallet management mode according to the present embodiment. A diagram showing an example of an identity management screen according to the present embodiment. A diagram showing an example of a display mode of trait expression information according to the present embodiment. A diagram showing an example of a display mode of trait expression information according to the present embodiment. A flowchart showing an example of processing procedures executed by an identity management device according to the present embodiment in association with the generation of trait expression information. A flowchart showing an example of processing procedures executed by a service providing system and an identity management device according to the present embodiment in association with the display of an identity trait graph. A flowchart showing an example of processing procedures executed by an identity management device according to the present embodiment in association with identity matching.
[0026] <First Embodiment> Fig. 1 shows an example of the overall configuration of an avatar management system (an example of a qualification management system) 2 according to this embodiment. The avatar management system (an example of a qualification management system) 2 is included in an identity management system 1. The avatar management system 2 according to this embodiment includes, as components, an avatar generation system 100, a user interface environment 200, an avatar management device 400, a network service environment 500, a VC (Verifiable Credentials: identification information) issuing system 600, and a DPKI system 700. The components of these systems are connected to each other via a network.
[0027] Avatar generation system 100 is a system that generates avatars to be used in network service environment 500. FIG. 2 shows an example configuration of avatar generation system 100. Avatar generation system 100 shown in the figure includes multiple avatar material providing systems 110 and one integrated system 120. Each avatar material providing system 110 is a system that generates a predetermined avatar material from among the materials (avatar materials) that make up an avatar, and provides the generated avatar material. Avatar material providing systems 110 may, for example, each be operated by a predetermined avatar material provider (company).
[0028] The integration system 120 acquires necessary avatar materials from the avatar materials provided by the avatar material providing system 110, and generates an avatar by integrating (combining) the acquired avatar materials.
[0029] In the avatar generation system 100, the avatar material providing system 110 and the integrated system 120 may be connected via a network. The number of avatar material providing systems 110 in the avatar generation system 100 is not particularly limited as long as it is one or more. The number of integrated systems 120 is also not particularly limited as long as it is one or more.
[0030] FIG. 3 schematically illustrates the flow of avatar generation in the avatar generation system 100. The avatar in this embodiment may be, for example, a two-dimensional or three-dimensional (3D) character, or a three-dimensional real avatar of a person. In explaining the diagram, an example will be given in which a three-dimensional real avatar of a person is generated. A real avatar is an avatar that realistically reproduces the appearance of an actual person PS based on information obtained by capturing an image of the person PS from which the avatar is generated.
[0031] The avatar generation system 100 shown in the figure is an example equipped with six avatar material provision systems 110-1 to 110-6. Avatar material provision system 110-1 generates 3D face (head) material as avatar material and provides the generated face material MT-1. Avatar material provision system 110-2 generates body material MT-2 as avatar material and provides the generated body material MT-2. Here, body material MT-2 is the portion of the human body excluding the head. Avatar material provision system 110-2 may also generate body material MT-2 in a state where the body is wearing clothing. Avatar material provision system 110-3 generates audio material MT-3 as avatar material and provides the generated audio material MT-3. Audio material MT-3 is material for the sounds made by the avatar. The avatar material provision system 110-4 generates emotion material MT-4 as avatar material and provides the generated emotion material MT-4. The emotion material MT-4 includes, for example, information for changing the facial expression of the facial material and the movement of the body material MT-2 according to a predetermined emotion. The emotion material MT-4 enables the avatar to express emotion. The avatar material provision system 110-5 generates movement material MT-5 as avatar material and provides the generated movement material MT-5. The movement material MT-5 includes information for imparting movement to the avatar. For example, if the avatar is a weather forecaster appearing in web content about weather forecasts, the movement material MT-5 generated corresponding to the weather forecaster can be used to impart a movement corresponding to the weather forecaster, such as pointing at a weather chart. The avatar material provision system 110-6 generates space material MT-6 as avatar material and provides the generated space material MT-6. Spatial material MT-6 is the material of the space in which the avatar exists.
[0032] In the avatar generation system 100 shown in the figure, avatar material provision system 110-1 captures an image of a source person PS to generate face material MT-1 for the person PS. Also, avatar material provision system 110-2 captures an image of the source person PS to generate body material MT-2 for the person PS. Also, avatar material provision system 110-3 generates audio material MT-3 using data recording the audio of the source person PS. Then, integration system 120 acquires the avatar materials (face material MT-1, body material MT-2, audio material MT-3, emotion material MT-4, movement material MT-5, and spatial material MT-6) generated by each of avatar material provision systems 110-1 to 110-6. Integration system 120 integrates the acquired avatar materials to generate the avatar AVT.
[0033] The avatar AVT does not need to use all of the avatar materials (face materials, body materials, voice materials, emotion materials, movement materials, and spatial materials) illustrated in the figure. In other words, the avatar AVT may generate an avatar using, for example, some of the avatar materials illustrated in the figure. Which avatar materials are used to generate an avatar may be changed depending on, for example, the network service in which the generated avatar will be used or the metaverse environment in which the avatar will exist.
[0034] Returning to FIG. 1 for the explanation, the user interface environment 200 is an environment that provides a user interface to end users who use the network service environment 500. Specifically, the user interface environment 200 includes one or more end user terminals 300 corresponding to one or more end users. The end user terminals 300 are terminals used by end users to receive network services provided by the network service environment 500. The end user terminals 300 can connect to the service providing system 510 in response to an operation by the end user, and can output applications and content corresponding to the network services provided by the connected service providing system 510 by displaying, sound, etc. The end user terminals 300 may be personal computers, smartphones, tablet terminals, etc.
[0035] In the following explanation, end users may be referred to as "real users." "Real users" is the name used when treating end users as user-related entities that exist in real space, and is used to contrast them with end-user avatars that exist in virtual space as the same user-related entities.
[0036] The avatar management device 400 manages avatars. Specifically, the avatar management device 400 stores the avatars generated by the avatar generation system 100 as objects to be managed. The avatar management device 400 uploads the avatars stored as objects to be managed to the network service environment 500. The network service environment 500 provides network services using the avatars provided by the network service environment 500 to end users.
[0037] The avatar management device 400 also assigns authenticity certification information to the avatars under its management, enabling the authenticity of the avatars to be confirmed. In response to an authenticity inquiry (authenticity confirmation request) about an avatar used in a network service provided to the end user terminal 300, the avatar management device 400 determines the authenticity of the avatar that is the subject of the inquiry, and transmits the determination result to the end user terminal 300.
[0038] The avatar management device 400 also causes the VC issuing system 600 to issue information (avatar identification information) as identification used to identify the avatar itself as a management target. The avatar management device 400 stores the issued avatar identification information, thereby managing the avatar. Specifically, in response to an avatar identification request from a network service in the network service environment 500, the avatar management device 400 transmits the avatar identification information of the avatar to be identified to the network service that has made the identification request. At this time, the avatar management device 400 can affix a signature (digital signature) to (encrypt) the identification information to be transmitted using a private key associated with the target avatar.
[0039] The avatar management device 400 may also manage wallets (an example of an information storage medium). Wallets here may include those that store assets in a cryptocurrency usage environment, as well as those that manage, for example, credential information (authenticity certification information, identity verification information (VC)) of real users and avatars related to a single end user. Furthermore, wallets may also include wallets used for various services such as payments provided by platform providers, wallets used for two-dimensional code payment apps, and the like. The avatar management device 400 may manage wallet data using a blockchain.
[0040] The network service environment 500 is an environment that provides one or more network services. Specifically, the network service environment 500 includes one or more service providing systems 510 that provide predetermined network services. The service providing systems 510 may be configured as, for example, web servers or application servers that are constructed according to the content of the network services to be provided.
[0041] The network services provided by the service providing system 510 may be websites, network games, web conferencing systems, etc. that use avatars. Furthermore, network services that use avatars in this way may include those that allow avatars to exist in a metaverse, which is a three-dimensional virtual space, and act in the metaverse. Specifically, network services include a marketplace service in which avatars can purchase products, etc., from stores, etc. in the metaverse, a service that allows avatars to directly buy and sell with each other in the metaverse, a service that allows celebrities or specific characters to exist in the metaverse, as well as services such as providing weather forecasts using avatars as weather forecasters, medical consultations using avatars as doctors, and fortune telling using avatars as fortune tellers. The service providing system 510 may be capable of providing multiple network services. A service providing system 510 that provides a metaverse as a network service may provide multiple metaverses.
[0042] The VC issuing system 600 is a system that issues identification information in response to an issuance request. The VC issuing system 600 may be configured, for example, by one or more devices connected to a network. The VC issuing system 600 of this embodiment is capable of issuing identification information that proves the identity of an end user (real user), and is also capable of issuing identification information that proves the identity of an avatar itself that is managed by the avatar management device 400.
[0043] The VC issuing system 600 may be capable of issuing a plurality of identification information corresponding to a plurality of different issuers (issuers).
[0044] The VC issuing system 600 can issue identification information (official identification information) of official issuers. An official issuer is, for example, an institution operated by the government, an institution authorized by the government, or an institution with a certain level of social credibility. Specifically, official issuers include, for example, an institution that issues licenses according to specified qualifications, authorized companies, educational institutions, local governments, financial institutions, etc. For example, official identification information used for payments in the metaverse may be issued by a financial institution. Furthermore, official identification information for entry into a specific facility in the metaverse may be issued by a company, educational institution, local government agency, etc. that operates the facility.
[0045] The VC issuing system 600 also issues identification information (private identification information) for private issuers. A private issuer may be, for example, a private organization such as a volunteer group, a civic sports group, or a school club. The private identification information issued by such a private issuer can certify, for example, that an avatar belongs to the corresponding private organization, or that a certificate or license issued by the corresponding private organization has been granted to the avatar.
[0046] Furthermore, private issuers may include, for example, fans (supporters) of an artist. The private identification information issued by a fan of an artist can be attached to, for example, an avatar of the artist, thereby proving that the avatar of the artist is supported by the fan.
[0047] Additionally, a private issuer may include an end user. For example, an end user as a private issuer may issue a friend certificate with private identification information. An avatar with the friend certificate's private identification information can prove that it is a friend with the avatar of the private issuer, for example, the end user.
[0048] The private issuer may be, for example, the operator of the service providing system 510. As an example, the service providing system 510 as a private issuer may issue private identification information of a good standing. The avatar of the end user to which the private identification information of a good standing is assigned can prove that the end user has not engaged in any fraudulent activities and is of good standing in the metaverse provided by the service providing system 510, for example.
[0049] The private issuer may also include an event organizer, etc. As an example, the private issuer may issue private identification information as a ticket for an event held in the metaverse of a specific service providing system 510. An avatar that has been given private identification information as a ticket can prove that it is eligible to participate in the event held in the metaverse of the specific service providing system 510.
[0050] As can be seen from the example of the private issuer above, private identification information can function as proof of the identity of an avatar or a user corresponding to an avatar, based on interpersonal relationships and personal evaluations. Another example of issuance of identification information based on interpersonal relationships is private identification information based on connections in a social networking system (SNS). In this case, the private identification information may prove that a certain user or avatar is a friend of a friend of the private issuer in the SNS. Another example of private identification information based on personal evaluation is private identification information based on the user's evaluation as a user (seller, buyer) in a network service where transactions between individuals are conducted. Another example of private identification information based on evaluations by other individuals is private identification information that can be issued based on information indicating the user's trustworthiness (trustworthiness information) provided by a service that evaluates the user's trustworthiness by inputting information such as the user's age, gender, occupation, and purchasing history.
[0051] The identification information issued by the VC issuing system 600 in this embodiment may correspond to, for example, a VC (Verifiable Credential). In the following description, a case where the identification information in this embodiment corresponds to a VC will be taken as an example. Therefore, in the following description, the identification information issued by the VC issuing system 600 may be referred to as a VC.
[0052] In this embodiment, the identification information that certifies the identity of the avatar itself is referred to as avatar identification information (avatar VC) to distinguish it from the identification information that certifies the identity of the real user (end user) (user identification information (user VC)). When there is no particular distinction between avatar identification information and user identification information, they are referred to as identification information or VC.
[0053] The DPKI system 700 manages public keys in accordance with the DPKI (Decentralized Public Key Infrastructure). When issuing identification information as a VC, the VC issuing system 600 of this embodiment generates a pair of public and private keys corresponding to an issuer DID, which is a DID (Decentralized Identifier) that uniquely identifies an issuing institution. It also generates a pair of public and private keys corresponding to an owner DID (end user DID or avatar DID), which is a DID that uniquely identifies the owner (end user or avatar) of the identification information. The VC issuing system 600 registers the generated public keys (public key corresponding to the issuer DID and public key corresponding to the owner DID) in the DPKI system 700. The DPKI system 700 stores the registered public keys in association with the respective issuer DID and owner DID.
[0054] The DPKI system 700 may be configured to register a public key by storing the public key in a blockchain. The DPKI system 700 may also be configured with devices that function as nodes corresponding to the blockchain that stores the public key.
[0055] When the service providing system 510 needs to verify the identity of a holder, it obtains a public key associated with the holder DID of the holder from the DPKI system 700. The service providing system 510 can determine whether the identification information is valid (identity verification) by using the obtained public key to decrypt the identification information.
[0056] 4 shows an example of the configuration of avatar management device 400. The functions of avatar management device 400 shown in the figure are realized by a central processing unit (CPU) included in avatar management device 400 executing a program. Avatar management device 400 shown in the figure includes a communication unit 401, a control unit 402, and a storage unit 403.
[0057] The communication unit 401 performs communication via a network.
[0058] The control unit 402 executes various controls in the avatar management device 400. The control unit 402 in the figure includes an avatar registration unit 421, an authenticity certification information management unit 422 (an example of a qualification management unit), an avatar provision control unit 423, a VC management unit 424 (an example of a qualification management unit), and a wallet management unit 425.
[0059] The avatar registration unit 421 registers the avatars generated by the avatar generation system 100 as management targets. Here, avatar registration is performed by storing avatar information (described later) of the avatars to be managed in the avatar information storage unit 432. The avatars registered by the avatar registration unit 421 can be used by the service providing system 510 in the network service environment 500 in the network services it provides.
[0060] The authenticity certification information management unit 422 manages the authenticity certification information of the avatar. Specifically, the authenticity certification information management unit 422 assigns authenticity certification information to the avatar to be registered. Authenticity certification information will be described later. In addition, in response to an authenticity confirmation request from the end user terminal 300, the authenticity certification information management unit 422 may determine the authenticity of the avatar whose authenticity is to be confirmed, using the authenticity certification information assigned to the registered avatar. The authenticity certification information management unit 422 may transmit the determination result regarding the authenticity to the end user terminal 300 that sent the authenticity confirmation request.
[0061] The avatar provision control unit 423 executes control related to the provision (transmission of avatar information) of registered avatars to the service provision system 510. The avatar management device 400 and each service provision system 510 may be connected via an API, and the avatar provision control unit 423 may be configured to transmit avatar data to the service provision system 510 while connected online.
[0062] The VC management unit 424 manages the VCs (identification information) of identities that exist in real space or the metaverse and are to be managed. The VCs managed by the VC management unit 424 manage user identification information (user VC) corresponding to the identities as real users and avatar identification information (avatar VC) corresponding to the identities as avatars. The VC management unit 424 requests the VC issuing system 600 via a network to issue identification information for the identities (real users or avatars). The VC issuing system 600 issues identification information for the target identities in response to the request. The VC issuing system 600 transmits the issued identification information and corresponding private keys (private key corresponding to the issuer DID and private key corresponding to the holder DID) to the avatar management device 400. The VC management unit 424 associates the transmitted identification information (avatar identification information or user identification information) with the private key and stores them in the avatar VC storage unit 433 or the user VC storage unit 434 .
[0063] The wallet management unit 425 manages wallets used by real users and avatars.
[0064] The storage unit 403 stores various types of information supported by the avatar management device 400. The storage unit 403 includes an end user information storage unit 431, an avatar information storage unit 432, an avatar VC storage unit 433, a user VC storage unit 434, and a wallet management information storage unit 435.
[0065] The end-user information storage unit 431 stores end-user information, which is information about end users who have registered one or more avatars corresponding to them in the avatar management device 400.
[0066] 5 shows an example of end user information corresponding to one end user. The end user information in FIG. 5 includes fields for an end user ID and user profile information. The end user ID field stores an end user ID that uniquely identifies the corresponding end user. The user profile information field stores user profile information for the corresponding end user. The user profile information may include, for example, the end user's name, gender, address, etc.
[0067] The avatar information storage unit 432 stores avatar information. FIG. 6 shows an example of avatar information stored in the avatar information storage unit 432. The avatar information storage unit 432 in FIG. 6 includes an object data storage unit 4321, a material group data storage unit 4322, and a metafile storage unit 4323. Avatar information corresponding to one avatar includes, for example, object data, material group data, and a metafile. The object data storage unit 4321 stores object data for each registered avatar. The material group data storage unit 4322 stores material group data for each registered avatar. The metafile storage unit 4323 stores metafiles for each registered avatar. The object data, material group data, and metafiles corresponding to the same avatar are associated with each other by the same avatar ID among the object data storage unit 4321, material group data storage unit 4322, and metafile storage unit 4323.
[0068] Specifically, the object data A, material group data A, and metafile A stored in the object data storage unit 4321, material group data storage unit 4322, and metafile storage unit 4323 corresponding to avatar A are associated with each other by an avatar ID [00000A] that uniquely identifies avatar A.
[0069] The object data is data of the actual object as the corresponding avatar, and is formed by combining components such as a head, body, etc. that are generated using predetermined avatar materials.
[0070] The material group data is data that includes one or more avatar materials that add a predetermined aspect to the avatar entity represented by the object data. The material group data may include, for example, audio materials, emotional materials, movement materials, spatial materials, etc. The material group data allows the avatar object to speak, change facial expressions, move, and exist in a virtual space with a predetermined design.
[0071] A metafile contains one or more pieces of metadata to be assigned to the corresponding avatar. Fig. 7 shows an example of a metafile corresponding to one avatar. The metafile in Fig. 7 contains metadata such as an avatar ID, source information, creator information, authentication code, authorized user information, avatar format, and behavior history information.
[0072] The avatar ID is an identifier that uniquely identifies an avatar in the avatar information stored in the avatar information storage unit 432. The avatar ID may be issued by the avatar registration unit 421 when registering a corresponding avatar. As described above, the avatar ID associates object data, material group data, and metafiles that correspond to the same avatar.
[0073] The generator information is information about the original person (generator) of the corresponding avatar. The generator information may include, as information items, a generator ID, profile information of the generator, etc. The generator information may be provided by the avatar generation system 100. If the generator is an end user, the end user ID of the corresponding end user may be used as the generator ID.
[0074] The creator information is information about the creator of the corresponding avatar. The creator may be, for example, an organization such as a company or an individual that corresponds to the integrated system 120 that generated the corresponding avatar in the avatar generation system 100.
[0075] The authentication code is a code that the avatar management device 400 issues in association with the avatar to be provided when the service providing system 510 receives an avatar provided by the avatar management device 400 (transmission of avatar information) from the avatar management device 400.
[0076] The authorized user information is information about an authorized user. The authorized user is a person who has the right to use the corresponding avatar. The authorized user may be an end user who created the avatar. In this case, the authorized user can make the avatar created by the authorized user exist in the metaverse provided by the service providing system 510 and cause it to act within the metaverse in response to, for example, the operation of the end user terminal 300. The authorized user may also be the operator of a specific service providing system 510. The authorized user information is information indicating such an authorized user. Specifically, the authorized user information may be a user account, such as an authorized user ID, username, and password, registered by the authorized user. If the authorized user is an end user, the authorized user ID may be the end user ID. Furthermore, the authorized user information may include, in addition to the original authorized user (primary authorized user), such as the end user who created the avatar, authorized users (secondary authorized users), such as other end users who have been granted usage rights.
[0077] The avatar format indicates the corresponding avatar format, such as the file format and specifications of the avatar.
[0078] The behavior history information is information indicating the history of behavior of a corresponding avatar in the metaverse provided by each service providing system 510. The behavior history information of each avatar may be acquired from each service providing system 510 by, for example, the avatar provision control unit 423.
[0079] Returning to Fig. 4 for the explanation, the avatar VC storage unit 433 stores avatar identification information (avatar VC) for each registered avatar. The avatar VC storage unit 433 also stores private keys associated with the avatar identification information (private keys corresponding to issuer DIDs and private keys corresponding to avatar DIDs).
[0080] 8 shows an example of information (avatar identification information and private key) stored in the avatar VC storage unit 433 corresponding to one avatar. As shown in the figure, the avatar VC storage unit 433 stores avatar identification information and a private key corresponding to the avatar DID in association with the avatar VC_ID and avatar ID. The avatar VC_ID is an identifier uniquely assigned to the corresponding avatar identification information. In this way, by associating the avatar identification information and private key with the avatar ID, the avatar identification information and private key can be associated and managed for the avatar information of the corresponding avatar.
[0081] The avatar identification information includes fields for VC type, issuer DID, avatar DID, and avatar-related information. The VC type field stores information indicating the type (model, format) of the identification information. The issuer DID field stores the issuer DID indicating the issuer of the avatar identification information. The avatar DID field stores the avatar DID of the corresponding avatar. The avatar-related information field stores avatar-related information of the corresponding avatar. The content of the information included in the avatar-related information is not particularly limited, but may include, for example, information such as rights and qualifications acquired by the avatar by taking action in the metaverse. The avatar-related information may also include behavioral history information similar to that stored in the avatar information.
[0082] At least one of the avatar identification information and the private key may be stored in the blockchain under the control of the VC management unit 424 of the avatar management device 400. When both the avatar identification information and the private key are stored in the blockchain, the avatar VC storage unit 433 may be omitted.
[0083] Returning to Fig. 4 for the explanation, the user VC storage unit 434 stores user identification information (user VC) for each end user (real user) registered (stored) in the end user information storage unit 431. The user VC storage unit 434 also stores private keys (private keys corresponding to issuer DIDs and private keys corresponding to user DIDs) associated with the user identification information.
[0084] 9 shows an example of information (user identification information and private key) stored in the user VC storage unit 434 corresponding to one real user. As shown in the figure, the user VC storage unit 434 stores user identification information and a private key corresponding to the user DID in association with the user VC_ID and user ID. The user VC_ID is an identifier uniquely assigned to the corresponding user identification information. In this way, by associating the user identification information and private key with the user ID, the user identification information and private key can be associated and managed with the user information of the corresponding real user (end user).
[0085] The user identification information includes fields for VC type, issuer DID, user DID, and user-related information. The user-related information stores user-related information for the corresponding real user. The content of the information included in the user-related information is not particularly limited, but may include, for example, information on rights, qualifications, etc. acquired by the real user as a result of the corresponding real user's actions in real space (shopping, traveling to a specified location, etc.). The user-related information may also include behavioral history information about the corresponding real user's actions in real space.
[0086] At least one of the user identification information and the private key may be stored in the blockchain under the control of the VC management unit 424 of the avatar management device 400. When both the user identification information and the private key are stored in the blockchain, the user VC storage unit 434 may be omitted.
[0087] Returning to FIG. 4 for the explanation, the wallet management information storage unit 435 stores wallet management information. The wallet management information corresponding to one wallet is information for integrating and managing the credential information of the identities (real user, avatar) corresponding to one end user. FIG. 10 shows an example of wallet management information corresponding to one wallet. The wallet management information corresponding to one wallet has fields for a wallet ID, an identity list, and a credential information list. The wallet ID field stores a wallet ID that is an identifier that uniquely identifies the corresponding wallet. The identity list stores identity IDs (user ID, avatar ID) that indicate identities that can use the corresponding wallet. The credential information list stores credential IDs (user VC_ID, avatar VC_ID, authenticity certificate ID, etc.) for each credential (VC, authenticity certificate, etc.) that is managed as being included in the corresponding wallet. Wallet management information with such a structure makes it possible to comprehensively manage, for example, credential information (authenticity certificate information, VC, etc.) assigned to each identity (real user, avatar) corresponding to one end user as credential information stored in a wallet held by one end user. Also, it becomes possible to share the credential information stored in the wallet between identities indicated by identity IDs (user ID, avatar ID) stored in an identity list.
[0088] The wallet management information may be stored in a blockchain under the control of wallet management unit 425 of avatar management device 400. In this case, wallet management information storage unit 435 may be omitted.
[0089] The avatar management device 400 may be configured as a single device, or may be realized by multiple devices connected to each other over a network and each assigned a specific function, and then the multiple devices working together to perform processing.
[0090] The VC issuing system 600 may also store a database related to issuers (issuer database). FIG. 11 shows an example of the structure of a record (issuer information) stored in the issuer database corresponding to one issuer. The issuer information in the figure includes fields for issuer ID, issuer profile, and issuing VC. The issuer ID field stores the issuer ID of the corresponding issuer. The issuer profile field stores the issuer profile. The issuer profile is information indicating the profile of the issuer. As shown in the figure, the issuer profile may include fields such as issuer type and issuer name. The issuer type field stores information indicating, for example, the type of the corresponding issuer, whether it is a public issuer or a private issuer. The issuer name field stores the name of the corresponding issuer (issuer name). The issuing VC field stores information regarding identification information issued by the corresponding issuer as the issuer.
[0091] An example of a processing procedure executed by the avatar management system (qualification management system) 2 of this embodiment in relation to the registration (user registration) of an end user (real user) will be described with reference to the sequence diagram of Figure 12. The registration of an end user according to the example processing procedure in this figure is a registration for enabling the end user corresponding to an avatar to be managed as a real user, which is one of identities.
[0092] Step S100: The end user operates the end user terminal 300 owned by the end user to perform the end user registration procedure so that the end user himself / herself is registered in the avatar management device 400. In the end user registration procedure, the end user may input predetermined information items such as a user account and a user name to be included in the user profile information. In response to the end user registration procedure from the end user terminal 300, the avatar management device 400 generates end user information for the corresponding end user and stores the generated end user information in the generated end user information storage unit 431.
[0093] Step S102: In addition, the end user may carry out a procedure for issuing user identification information (user VC) corresponding to the end user in response to the user registration in step S100. In this case, the end user accesses the end user terminal 300 to the VC issuing system 600 and performs an operation for the procedure for issuing user identification information (user VC) corresponding to the end user. The end user terminal 300 executes a process corresponding to the user identification information issuance procedure in response to the operation. As a process for the issuance procedure, the end user terminal 300 may send an issuance request to the VC issuing system 600 together with information on predetermined items in the user profile information. The issuance request may also include information specifying the type of user identification information to be issued (e.g., driver's license, passport, insurance card, etc.).
[0094] Step S104: The VC issuing system 600 generates user identification information in response to the issuing request received in response to step S102. At this time, the VC issuing system 600 generates (issues) a user DID indicating the corresponding end user, and generates a pair of a public key and a private key corresponding to the user DID. Then, the VC issuing system 600 signs (encrypts) the generated user identification information using the private key generated in response to the issuer DID indicating the issuing organization that it corresponds to.
[0095] Step S106: The VC issuing system 600 registers the user identification information generated in step S104 in the avatar management device 400. Specifically, the VC issuing system 600 transmits the user identification information signed with a private key corresponding to the issuer DID granted to the corresponding issuing institution, and the private key corresponding to the user DID of the corresponding end user, to the avatar management device 400. In the avatar management device 400, the VC management unit 424 stores the user identification information and the private key corresponding to the user DID received from the VC issuing system 600 in the user VC storage unit 434, in association with the avatar ID of the corresponding avatar.
[0096] Step S108: The VC issuing system 600 also registers the public keys (the effector key corresponding to the issuer DID and the public key corresponding to the user DID) generated together with the user identification information in step S104 in the DPKI system 700. The issuance of user identification information in steps S102 to S108 may be performed each time it becomes necessary to issue new user identification information after the user registration.
[0097] Next, with reference to the sequence diagram of Figure 12, an example of a processing procedure executed by avatar management system 2 of this embodiment in relation to avatar generation, registration, and avatar authentication information registration will be described. Step S200: An end user operates their own end user terminal 300 to access avatar generation system 100 and perform an avatar generation operation. End user terminal 300 transmits an avatar generation instruction corresponding to the avatar generation operation to avatar generation system 100.
[0098] Step S202: The avatar generation system executes a process to generate an avatar in response to the avatar generation instruction.
[0099] Step S204: The end user operates the end user terminal 300 to perform an avatar registration procedure so that the generated avatar is registered in the avatar management device 400. In the avatar registration procedure, the end user specifies the avatar to be registered and specifies the avatar management device 400 as the registration destination of the specified avatar.
[0100] Step S206: In response to the avatar registration procedure in step S204, avatar generation system 100 and avatar management device 400 execute processing corresponding to avatar registration. First, avatar generation system 100 uploads avatar information for the avatar designated as the registration target in the avatar registration procedure to avatar management device 400. Avatar registration unit 421 of avatar management device 400 stores the uploaded avatar information in avatar information storage unit 432.
[0101] Also, in step S206, the authenticity certification information management unit 422 of the avatar management device 400 assigns authenticity certification information to the avatar currently being registered. The authenticity certification information is information that certifies the authenticity of the avatar itself, which exists in the metaverse or the like of the service providing system 510. Here, the authenticity of an avatar means that the avatar is not a fake or has been tampered with, and is legitimate. Examples of an invalid (illegitimate) avatar include an avatar that has been tampered with, for example, by replacing avatar materials such as facial elements with fake materials that are different from the original, and an avatar that has been copied without the permission of a person who holds certain rights to the avatar, such as the creator.
[0102] Specifically, the authenticity certification information management unit 422 may assign authenticity certification information to the target avatar by adding an electronic watermark (an example of authenticity certification information) and a digital authenticity certificate (an example of authenticity certification information) as follows.
[0103] The authenticity certification information management unit 422 adds information unique to the target avatar, such as an avatar ID, to the object data of the target avatar as a digital watermark. The digital watermark added to the object data of the avatar in this way is preferably imperceptible, but may also be perceptible.
[0104] The authenticity certificate information management unit 422 also assigns a digital authenticity certificate to the target avatar. In this case, the authenticity certificate information management unit 422 may assign an authenticity certificate to the target avatar that certifies the creator of the target avatar, the storage location (URL) of the target avatar, the service providing system 510 that uses the target avatar, and the like. For example, the authenticity certificate may be issued by an authenticity certificate issuing site (not shown) on the network, when the authenticity certificate information management unit 422 executes a predetermined transaction with the issuing site. Such an authenticity certificate may be managed on the network, for example, in association with the avatar ID of the target avatar (an example of information unique to the avatar to be registered). As an example, the authenticity certificate assigned to the avatar by the authenticity certificate information management unit 422 may be a non-fungible token (NFT) managed on a blockchain. In this case, the authenticity proof information management unit 422 may assign an authenticity certificate to the avatar using, for example, an external NFT platform. The authenticity proof information management unit 422 may also assign an authenticity certificate generated using quantum-resistant cryptography or quantum-resistant blockchain to the avatar. The authenticity certificate assigned to the avatar by the authenticity proof information management unit 422 may be a soulbound token (SBT), which is a non-transferable NFT. In this case, the authenticity proof information management unit 422 may assign an SBT to the avatar as authenticity proof information instead of an NFT, or may assign both an NFT and an SBT to the avatar. When assigning an NFT and an SBT to the avatar as authenticity proof information, the authenticity proof information management unit 422 may select and use either the NFT or the SBT to prove the authenticity of the avatar, or may use both the NFT and the SBT.
[0105] In step S206, the authenticity certification information management unit 422 also issues a unique authentication code to the avatar currently being registered. The authentication code is provided to the service providing system 510, which provides network services using the target avatar, along with the avatar data of the target avatar. The authentication code is used to determine the authenticity of the avatar in response to a request from an end user, as described below. Since the authentication code is uniquely associated with the target avatar, an avatar ID may be used, for example. However, to enhance security against, for example, the identification of the avatar or registration information that may include the user's personal information, it is preferable to use a code generated independently of the avatar ID as the authentication code. The authenticity certification information management unit 422 adds the issued authentication code as one piece of metadata in the metafile associated with the target avatar and stored in the metafile storage unit 4323 ( FIG. 7 ).
[0106] Step S208: The end user, who is the creator of the avatar registered in step S206, accesses the end user terminal 300 to the VC issuing system 600 and performs an operation for issuing avatar identification information. The end user terminal 300 executes the issuance procedure in response to the operation. As part of the issuance procedure, the end user terminal 300 may transmit an issuance request to the VC issuing system 600 along with the avatar information that is the target of the avatar identification information. The issuance request may also include information specifying the avatar identification information to be issued (issuance certificate specification information). In response to the issuance request, the VC issuing system 600 may determine the avatar identification information to be issued to the target avatar. In transmitting the issuance request, the end user terminal 300 may first acquire avatar information from the avatar management device 400 and then transmit the acquired avatar information to the VC issuing system 600. Alternatively, the end user terminal 300 may specify the avatar to be transmitted to the avatar management device 400 and have the avatar management device 400 transmit the avatar information to the VC issuing system 600.
[0107] Step S210: In response to the issuance request from the end user terminal 300 in step S208, the VC issuing system 600 generates avatar identification information that certifies the identity of the avatar based on the avatar information received together with the issuance request in step S208. At this time, the VC issuing system 600 generates (issues) an avatar DID indicating the corresponding avatar, and generates a public key / private key pair corresponding to the avatar DID. Then, the VC issuing system 600 signs (encrypts) the generated avatar identification information using the private key generated corresponding to the issuer DID indicating the issuing organization that it supports. The VC issuing system 600 may include at least a portion of the content of the received avatar information in the identity information.
[0108] Step S212: The VC issuing system 600 registers the avatar identification information in the avatar management device 400. Specifically, the avatar identification information (an example of signed identification information) signed with a private key corresponding to the issuer DID granted to the corresponding issuing institution and the private key corresponding to the avatar DID of the corresponding avatar are transmitted to the avatar management device 400. The VC management unit 424 of the avatar management device 400 stores the avatar identification information and the private key corresponding to the avatar DID received from the VC issuing system 600 in the avatar VC storage unit 433 in association with the avatar ID of the corresponding avatar.
[0109] Step S214: The VC issuing system 600 also registers the public keys (public key corresponding to the issuer DID and public key corresponding to the avatar DID) generated together with the avatar identification information in step S210 in the DPKI system 700.
[0110] In the avatar management system 2 of this embodiment, the processing procedure shown in FIG. 12 allows a real user and an avatar to be registered as identities corresponding to a single end user. After registration, credential information can be assigned (issued) to the identities. That is, a user identification card can be assigned (issued) to the real user, and avatar identification information and authenticity certification information can be assigned to the avatar. The wallet management unit 425 of the avatar management device 400 can then set a credential information wallet WL, which is a wallet that collectively stores the credential information assigned to the identities (real user, avatar), for each end user. That is, the wallet management unit 425 assigns a wallet ID to each end user. The wallet management unit 425 generates wallet management information corresponding to the assigned wallet ID as follows: For example, the wallet management unit 425 stores the identity ID (user ID, avatar ID) for each corresponding identity in a field of the shared ID list, in association with the assigned wallet ID. Furthermore, the wallet management unit 425 stores a list item of the credentials assigned to the corresponding identity in a field of the shared credentials list, in association with the assigned wallet ID. The wallet management unit 425 stores the wallet management information generated in this manner in the wallet management information storage unit 435. Note that the shared ID list may store identity IDs of some of all identities corresponding to one end user. Also, the shared credentials list may store some of the credentials selected from all of the credentials assigned to each identity corresponding to one end user.
[0111] FIG. 13 shows an example of the mode of identities and credentials managed by wallet management information corresponding to one end user. This figure illustrates an example of wallet management implemented under an avatar management application AP installed on an end user terminal 300. This figure shows an example in which a real user and three avatars, A, B, and C, are registered as identities that can use a credentials wallet WL corresponding to the end user. That is, the shared ID list field of the wallet management information stores the user ID of the corresponding real user and the avatar IDs of the three avatars, A, B, and C. Furthermore, the credentials wallet WL corresponding to the real user and the three avatars, A, B, and C, stores user identification information (user VC) corresponding to the real user and avatar identification information (avatar VC) corresponding to avatar A, B, and C, respectively. Furthermore, the credential information wallet WL in the figure holds authenticity proof information such as NTF or SBT assigned to Avatar A, Avatar B, or Avatar C, respectively, as in token 1 to token 5. These identity proof information (VC) and tokens (authenticity proof information) are stored in the shared credential information list field of the corresponding wallet management information. Tokens such as NFTs and SBTs may include, for example, driver's licenses, membership cards, admission passes indicating admission to a specific location, and tickets indicating participation in a specific event. In this manner, in this embodiment, by associating a credential information wallet WL with one end user, it becomes possible to collectively manage the credential information of multiple identities corresponding to one end user.
[0112] In accordance with the above-described ability to manage the qualification information of multiple identities corresponding to one end user in a centralized manner, the end user terminal 300 can present the identities and qualification information corresponding to the end user as follows.
[0113] 14A shows an example of an identity management screen displayed on the display unit of the end-user terminal 300. The identity management screen in the figure includes an identity selection area AR1, a qualification information selection area AR2, and a service selection area AR3.
[0114] The identity selection area AR1 is an area where an operation to select an identity to be authenticated, enter the metaverse, etc. is performed. In the identity selection area AR1, buttons BT1 corresponding to real users and multiple avatars are arranged as identities corresponding to end users. In the figure, the button BT1 labeled "Real ID" corresponds to a real user, and the buttons BT1 labeled "Business," "Culture," and "Game" correspond to avatars, respectively.
[0115] The credential information selection area AR2 is an area where an operation is performed to select credential information that a real user uses to verify their credential in real space or that an avatar uses to verify their credential in the metaverse.
[0116] The credential selection area AR2 includes an identification information (VC) area AR21 and an authenticity certification information area AR22. The identification information area AR21 is an area where an operation to select credential information as identification information is performed. In the identification information area AR21, buttons BT21 corresponding to each piece of identification information are arranged as options. The authenticity certification information area AR22 is an area where an operation to select credential information as authenticity certification information is performed. In the authenticity certification information area AR22, buttons BT22 corresponding to each piece of identification information are arranged as options.
[0117] The service selection area AR3 is an area where an operation is performed to select a service to be used by an identity from among services provided in the real world (real services) and services provided in the metaverse (network services). Real services may include services that allow the use of predetermined cashless payments such as credit cards. In the service selection area AR3, buttons BT3 corresponding to each service are arranged.
[0118] Here, when an end user, as a real user in real space, uses a service with an age restriction, such as purchasing alcohol at a store, age verification is required. In other words, a certain age or older is required to be eligible to use the service. In such a case, the end user can use the avatar management system 2 of this embodiment to handle age verification as follows. In this case, the end user performs an operation (operation on button BT1) in the identity selection area AR1 of the identity management screen of FIG. 14A to select a real user as the user to be used for the service. The end user also performs an operation (operation on button BT3) in the service selection area AR3 of the identity management screen to select the service to be used this time as a real user. Furthermore, the end user also performs an operation (operation on button BT2) in the qualification information selection area AR2 to select qualification information that can prove the age required for the service to be used this time.
[0119] In response to the above operation, the display on the display unit of the end user terminal 300 transitions from the state shown in Fig. 14A to a qualification information screen showing the contents of the qualification information selected by the operation on the qualification information selection area AR2, as shown in Fig. 14B, for example. At this time, on the display unit of the end user terminal 300, a code symbol CD generated based on the selected qualification information is displayed below the qualification information screen. The code symbol CD is a code symbol of information (age verification information) that proves that the real user is over the age required by the target service.
[0120] The end user performs an operation on the code symbol CD displayed below the qualification information screen. In response to the operation on the code symbol CD, the display unit of the end user terminal 300 transitions to displaying an enlarged code symbol CD, as shown in FIG. 14C . The end user presents the enlarged code symbol CD to, for example, a store clerk. The clerk has the presented code symbol CD read by a code reader. The store terminal acquires the age verification information indicated by the read code symbol CD and notifies the end user, by display or the like, that the end user meets the age requirement. The clerk can confirm from the notification that the end user meets the age requirement and take action to provide the service.
[0121] Referring to the flowchart of Figure 15, an example of a processing procedure executed by the end user terminal 300 and the avatar management device 400 in response to the age authentication of real users shown in Figures 14A, 14B, and 14C above will be described.
[0122] Step S300: In this case, the end user performs an operation to select a real user in the identity selection area AR1 on the identity management screen (FIG. 14A). In response to this operation, the end user terminal 300 selects the real user as the identity to be used for this service.
[0123] Step S302: The end user also performs an operation to select a service to be used this time in the service selection area AR3 on the identity management screen. The end user terminal 300 identifies the service to be used this time in response to the operation.
[0124] Step S304: The end user also performs an operation in the credential information selection area AR2 on the identity management screen to select credential information that can prove that the end user meets the age requirements for the service to be used this time. The end user terminal 300 identifies the selected credential information in response to the operation.
[0125] Step S306: The end user terminal 300 transmits a credential information request requesting the credential information identified in step S304 to the avatar management device 400. The credential information request may include, for example, a wallet ID associated with the end user and a credential information ID indicating the credential information identified in step S304.
[0126] Step S308: In this case, the credential information specified in the credential information request sent in step S306 is user identification information. In this case, the VC management unit 424 in the avatar management device 400 acquires the user identification information specified in the received credential information request from the user VC storage unit 434, and transmits the acquired user identification information to the end-user terminal 300.
[0127] Step S310: The end-user terminal 300 receives the user identification information transmitted in step S308 and refers to the age of the end user (real user) indicated in the received user identification information. Based on the referred age, the end-user terminal 300 generates age verification information indicating that the end-user meets the age requirements for the service to be used (the service selected in step S302), and generates a code symbol indicating the generated age verification information. The age verification information may indicate that the age requirements are met, or may indicate a specific age.
[0128] Step S312: The end-user terminal 300 displays the code symbol generated in step S310 on the display unit.
[0129] Next, an example of a processing procedure executed by the avatar management system 2 of this embodiment in relation to verifying the eligibility of an avatar acting in the metaverse will be described with reference to the sequence diagram of Figure 16. Step S400: In this case, the end user performs an operation in the identity selection area AR1 on the identity management screen (Figure 14A) to select one avatar to act in the metaverse. The end user terminal 300 selects the avatar selected by this operation as the identity to be acted in the metaverse.
[0130] Step S402: The end user accesses the service providing system 510 that provides a metaverse corresponding to the intended use of the target avatar using the end user terminal 300. The end user performs an avatar collaboration operation to make the avatar exist in the accessed service providing system 510. The end user terminal 300 notifies the accessed service providing system 510 of the avatar ID of the target avatar to exist in the metaverse as avatar collaboration control in response to the avatar collaboration operation.
[0131] Step S404: The service providing system 510 requests avatar information for the avatar identified by the notified avatar ID from the avatar management device 400. The avatar provision control unit 423 of the avatar management device 400 transfers the avatar based on the requested avatar information to the requesting service providing system 510. The service providing system 510 then places the transferred avatar in the metaverse. At this time, the end user terminal 300 accessing the service providing system 510 displays a message indicating that the target avatar exists in the metaverse.
[0132] Step S406: Here, the avatar that has been placed in the metaverse in step S404 is controlled by the avatar provision control unit 423 to act in the metaverse. That is, in this case, the avatar acts spontaneously, without the end user's operation of the end user terminal 300. The avatar provision control unit 423 may control the avatar to act spontaneously based on a predetermined plan (scenario). Alternatively, the avatar provision control unit 423 may control the avatar to act spontaneously using AI (artificial intelligence). In this case, the avatar provision control unit 423 may control the avatar to act using a trained model that has learned how to act in response to the avatar's attributes, such as occupation and personality, the metaverse environment in which the avatar exists, the content of communication with other avatars, and the like. Note that in step S406, the end user may perform an operation to cause the target avatar present in the service provision system 510 to act.
[0133] Step S408: Here, while the avatar is acting in the metaverse, a situation occurs in which it is necessary to confirm the avatar's qualifications (a situation requiring qualification confirmation). As a specific example, when an avatar attempts to participate in a certain event, it is necessary to confirm whether or not the avatar has a ticket that allows participation in the event, as a qualification for participation.
[0134] Step S410: In response to the occurrence of a situation requiring qualification confirmation, the service providing system 510, which acts as the qualification confirmer, transmits a qualification confirmation request to the end user terminal 300 corresponding to the target avatar. The qualification confirmation request may include the avatar ID of the target avatar as information for identifying the target avatar.
[0135] Step S412: In response to receiving the credential confirmation request, the end user terminal 300 may notify the end user, for example, by displaying a message, that credential confirmation of the target avatar is required. The end user receives the notification and recognizes that credential confirmation of the target avatar is required. In this case, the end user performs an operation in the credential information selection area AR2 of the identity management screen ( FIG. 14A ) displayed on the end user terminal 300 to select the credential information to be used for the currently required credential confirmation. The end user terminal 300 then transmits a credential confirmation request to the service providing system 510, including the credential information ID of the credential information selected by the operation.
[0136] Step S414: In response to receiving the qualification confirmation request, the service providing system 510 transmits a qualification information request to the avatar management device 400. The qualification information request includes the qualification information ID included in the received qualification confirmation request.
[0137] Step S416: The avatar management device 400 acquires the credential information indicated by the credential information ID included in the credential information request transmitted in step S414. If the credential information specified by the credential information ID included in the credential information request is authenticity proof information (authenticity certificate), the authenticity proof information management unit 422 may acquire the specified credential information from a network (e.g., a blockchain). Alternatively, if the credential information specified by the credential information ID included in the credential information request is avatar identification information (avatar VC), the VC management unit 424 may acquire the corresponding avatar VC from the avatar VC storage unit 433. Furthermore, when the VC management unit 424 acquires the avatar VC as the credential information, the VC management unit 424 may sign (encrypt) the avatar VC using a private key corresponding to the avatar DID associated with the avatar identification information in the avatar VC storage unit 433.
[0138] Step S418: The authenticity certificate information management unit 422 or the VC management unit 424 transmits the qualification information (authenticity certificate information or avatar identification information) acquired in step S420 to the service providing system 510. When the avatar identification information is transmitted, the corresponding issuer DID and avatar DID may be added to the transmitted avatar identification information.
[0139] Step S420: The service providing system 510 performs a credential verification process using the credential information transmitted in step S418. If the received credential information is a token (authenticity certification information), the service providing system 510 may, for example, verify the contents of the authenticity certification information and determine whether the target avatar has legitimate credentials. Alternatively, if the received credential information is avatar identification information, the service providing system 510 may transmit a public key request to the DPKI system 700 requesting a public key corresponding to the received avatar identification information. The public key request includes the issuer DID and avatar DID attached to the received avatar identification information. The DPKI system 700 obtains from the blockchain a public key corresponding to the issuer DID and a public key corresponding to the avatar DID, respectively, included in the received public key request. The DPKI system 700 transmits the two public keys (the public key corresponding to the issuer DID and the public key corresponding to the avatar DID) acquired upon receiving the avatar identification information in step S418 to the service providing system 510 that sent the public key request. The service providing system 510 uses the two transmitted public keys to decrypt the received avatar identification information. If the decryption is successful, the received avatar identification information is valid, and the identity of the target avatar is authenticated. If the decryption is unsuccessful, the received avatar identification information is invalid, and the identity of the target avatar cannot be authenticated.
[0140] Step S420: The service providing system 510 executes processing according to the confirmation result in step S420.
[0141] Note that by storing and managing the credential information corresponding to one end user in the credential information wallet WL as shown in Fig. 13, it becomes easy to arbitrarily associate the credential information with the identity (real user, avatar) corresponding to the end user. As a result, for example, the credential information assigned to each identity corresponding to an end user can be shared and used between identities.
[0142] In the above embodiment, an example was given in which an identity (real user, avatar) exists corresponding to one end user. However, in this embodiment, for example, avatars that can be associated with multiple specific or unspecified end users may exist. In this case, the avatar provision control unit 423 may be configured to enable voluntary actions corresponding to all or some of the multiple end users. In this case, the avatar provision control unit 423 may be configured to enable the avatar to act in response to avatar operations performed based on the consensus of multiple end users or avatar operations performed by some end users. In such a case, for example, multiple real user credentials corresponding to multiple end users and a credential information wallet WL storing a predetermined number of avatar credentials may be managed corresponding to multiple end users. In this embodiment, the end user does not need to be limited to an individual. In this embodiment, the end user may be, for example, an organization or group such as a company or organization.
[0143] The avatar management system 2 of this embodiment is not limited to the configuration shown in the above embodiment. For example, the end user terminal 300 may include certain functional units in the avatar management device 400 shown in FIG. 4. For example, by providing the end user terminal 300 with functions such as a wallet management unit 425 and a wallet management information storage unit 435 related to the credential information wallet WL, the end user terminal 300 can collectively manage the credential information of the corresponding end users.
[0144] Note that a program for implementing the functions of the above-described avatar generation system 100, end-user terminal 300, avatar management device 400, service providing system 510, VC issuing system 600, and DPKI system 700 may be recorded on a computer-readable recording medium, and the program may be loaded into a computer system and executed to perform the processing of the above-described avatar generation system 100, end-user terminal 300, avatar management device 400, service providing system 510, VC issuing system 600, and DPKI system 700. Here, "loading a program recorded on a recording medium into a computer system and executing it" includes installing the program into a computer system. The term "computer system" herein includes hardware such as an OS and peripheral devices. The term "computer system" may also include multiple computer devices connected via a network, including communication lines such as the Internet, a WAN, a LAN, and a dedicated line. Furthermore, the term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as HDDs and SSDs built into computer systems. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM. Recording media also include internal or external recording media accessible from a distribution server for distributing the program. The program code stored on the distribution server's recording medium may be different from the program code in a format executable by a terminal device. In other words, the format in which the program is stored on the distribution server is not important as long as it can be downloaded from the distribution server and installed in a format executable by a terminal device. Note that the program may be divided into multiple parts, downloaded at different times, and then combined on a terminal device, or each of the divided programs may be distributed by a different distribution server.Furthermore, the term "computer-readable recording medium" also includes a storage medium that stores a program for a certain period of time, such as volatile memory (RAM) within a computer system that acts as a server or client when the program is transmitted over a network. The program may also be a program that realizes part of the above-mentioned functions. Furthermore, the program may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already stored in the computer system.
[0145] <Notes> (1) One aspect of this embodiment is a qualification management system (identity management system) that includes a qualification management unit that stores a predetermined number of pieces of qualification information, including one or more pieces of qualification information that are assigned to an identity as a real user existing in real space and indicate that the user has predetermined qualifications, and one or more pieces of qualification information that are assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in a memory unit in association with one information storage medium held by the real user.
[0146] (2) One aspect of this embodiment is the qualification management system described in (1), wherein the qualification information may include identification information that proves the status of the identity.
[0147] (3) One aspect of this embodiment is the qualification management system described in (1) or (2), wherein the qualification information may include authenticity certification information that proves the authenticity of the identity.
[0148] (4) One aspect of this embodiment is a qualification management system described in any one of (1) to (3), in which the qualification management unit may output qualification information selected by a real user through an operation on the corresponding user terminal from among the qualification information stored in the memory unit as qualification information to be used for qualification verification of the identity that is the subject of qualification verification.
[0149] (5) One aspect of this embodiment is a qualification management method (identity management method) in a qualification management system (identity management system), which includes a qualification management step in which a qualification management unit stores in a memory unit a specified number of pieces of qualification information, including one or more pieces of qualification information assigned to an identity as a real user existing in real space and indicating that the real user has specified qualifications, and one or more pieces of qualification information assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in association with one information storage medium held by the real user.
[0150] (6) One aspect of this embodiment is a program for causing a computer in a qualification management system (identity management system) to function as a qualification management unit that stores, in a storage unit, a predetermined plurality of credentials among one or more credentials assigned to an identity as a real user existing in the real space and indicating that the identity has predetermined qualifications, and one or more credentials assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in association with one information storage medium owned by the real user. (7) One aspect of this embodiment is a non-volatile storage medium having recorded thereon a program for causing a computer in a qualification management system (identity management system) to function as a qualification management unit that stores, in a storage unit, a predetermined plurality of credentials among one or more credentials assigned to an identity as a real user existing in the real space and indicating that the identity has predetermined qualifications, and one or more credentials assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse, in association with one information storage medium owned by the real user.
[0151] Second Embodiment FIG. 17 illustrates an example of the overall configuration of an identity management system (an example of an identity management system) 1A according to this embodiment. In this embodiment, identities include avatars that exist and act in the metaverse. Such avatars may act in response to end-user operations or instructions, as well as avatars that can act autonomously without the operation of a corresponding end-user (e.g., AI avatars) using, for example, artificial intelligence (AI). The metaverse is a virtual space (an example of an activity space) constructed on a network. In this embodiment, identities may also include end users who are associated with avatars and act in real space (an example of an activity space). In the following description, end users as identities may be referred to as "real users." The term "real user" refers to an end user as a user-related entity existing in real space, and is used to contrast it with an end-user-related avatar existing in virtual space as the same user-related entity. In this embodiment, identities may also include organizations such as companies and groups. The identity of such an organization may include a real organization that exists in the real world and an organization that exists in the metaverse and is associated with the real organization. Furthermore, the identity in this embodiment may include a real user, a real organization, an avatar, etc., as an IP (Intellectual Property) holder that holds intellectual property (IP) such as two-dimensional or three-dimensional images, text, music, etc.
[0152] The identity management system 1A of this embodiment includes, as components, an avatar generation system 100, a user interface environment 200, an identity management device 400A, a network service environment 500, a VC (Verifiable Credentials) issuing system 600, and a DPKI system 700. The components of these systems are connected to each other via a network.
[0153] Avatar generation system 100 is a system that generates avatars to be used in network service environment 500. FIG. 18 shows an example configuration of avatar generation system 100. Avatar generation system 100 shown in the figure includes multiple avatar material providing systems 110 and one integrated system 120. Each avatar material providing system 110 is a system that generates a predetermined avatar material from among the materials (avatar materials) that make up an avatar, and provides the generated avatar material. Avatar material providing systems 110 may, for example, each be operated by a predetermined avatar material provider (company).
[0154] The integration system 120 acquires necessary avatar materials from the avatar materials provided by the avatar material providing system 110, and generates an avatar by integrating (combining) the acquired avatar materials.
[0155] In the avatar generation system 100, the avatar material providing system 110 and the integrated system 120 may be connected via a network. The number of avatar material providing systems 110 in the avatar generation system 100 is not particularly limited as long as it is one or more. The number of integrated systems 120 is also not particularly limited as long as it is one or more.
[0156] FIG. 19 schematically illustrates the flow of avatar generation in the avatar generation system 100. The avatar in this embodiment may be, for example, a two-dimensional or three-dimensional (3D) character, or a three-dimensional real avatar of a person. In explaining the diagram, an example will be given in which a three-dimensional real avatar of a person is generated. A real avatar is an avatar that realistically reproduces the appearance of an actual person PS based on information obtained by capturing an image of the person PS from which the avatar is generated.
[0157] The avatar generation system 100 shown in the figure is an example equipped with six avatar material provision systems 110-1 to 110-6. Avatar material provision system 110-1 generates 3D face (head) material as avatar material and provides the generated face material MT-1. Avatar material provision system 110-2 generates body material MT-2 as avatar material and provides the generated body material MT-2. Here, body material MT-2 is the portion of the human body excluding the head. Avatar material provision system 110-2 may also generate body material MT-2 in a state where the body is wearing clothing. Avatar material provision system 110-3 generates audio material MT-3 as avatar material and provides the generated audio material MT-3. Audio material MT-3 is material for the sounds made by the avatar. The avatar material provision system 110-4 generates emotion material MT-4 as avatar material and provides the generated emotion material MT-4. The emotion material MT-4 includes, for example, information for changing the facial expression of the facial material and the movement of the body material MT-2 according to a predetermined emotion. The emotion material MT-4 enables the avatar to express emotion. The avatar material provision system 110-5 generates movement material MT-5 as avatar material and provides the generated movement material MT-5. The movement material MT-5 includes information for imparting movement to the avatar. For example, if the avatar is a weather forecaster appearing in web content about weather forecasts, the movement material MT-5 generated corresponding to the weather forecaster can be used to impart a movement corresponding to the weather forecaster, such as pointing at a weather chart. The avatar material provision system 110-6 generates space material MT-6 as avatar material and provides the generated space material MT-6. Spatial material MT-6 is the material of the space in which the avatar exists.
[0158] In the avatar generation system 100 shown in the figure, avatar material provision system 110-1 captures an image of a source person PS to generate face material MT-1 for the person PS. Also, avatar material provision system 110-2 captures an image of the source person PS to generate body material MT-2 for the person PS. Also, avatar material provision system 110-3 generates audio material MT-3 using data recording the audio of the source person PS. Then, integration system 120 acquires the avatar materials (face material MT-1, body material MT-2, audio material MT-3, emotion material MT-4, movement material MT-5, and spatial material MT-6) generated by each of avatar material provision systems 110-1 to 110-6. Integration system 120 integrates the acquired avatar materials to generate the avatar AVT.
[0159] The avatar AVT does not need to use all of the avatar materials (face materials, body materials, voice materials, emotion materials, movement materials, and spatial materials) illustrated in the figure. In other words, the avatar AVT may generate an avatar using, for example, some of the avatar materials illustrated in the figure. The avatar materials used to generate an avatar may be changed depending on, for example, the network service in which the generated avatar will be used or the metaverse environment in which the avatar will exist.
[0160] Returning to FIG. 17 for the explanation, the user interface environment 200 is an environment that provides a user interface to end users who use the network service environment 500. Specifically, the user interface environment 200 includes one or more end user terminals 300 corresponding to one or more end users. The end user terminals 300 are terminals used by end users to receive network services provided by the network service environment 500. The end user terminals 300 can connect to the service providing system 510 in response to an operation by the end user, and can output applications and content corresponding to the network services provided by the connected service providing system 510 by displaying, sound, etc. The end user terminals 300 may be personal computers, smartphones, tablet terminals, etc.
[0161] The identity management device 400A manages identities (real users, avatars). The identity management device 400A stores the avatars generated by the avatar generation system 100 as identities to be managed. The identity management device 400A uploads the avatars stored as management targets to the network service environment 500. The network service environment 500 provides network services using the avatars provided by the network service environment 500 to end users.
[0162] The identity management device 400A also assigns authenticity certification information to the avatars under management, thereby enabling the authenticity of the avatars to be confirmed. In response to an authenticity inquiry (authenticity confirmation request) about an avatar used in a network service provided to the end user terminal 300, the identity management device 400A determines the authenticity of the avatar that is the subject of the inquiry, and transmits the determination result to the end user terminal 300.
[0163] Furthermore, the identity management device 400A causes the VC issuing system 600 to issue information (avatar identification information) as identification used to identify the avatar itself as a management target. The identity management device 400A can store the issued avatar identification information to manage it. Specifically, in response to an avatar identification request from a network service in the network service environment 500, the identity management device 400A transmits the avatar identification information of the avatar to be identified to the network service that has made the identification request. At this time, the identity management device 400A can affix a signature (digital signature) to (encrypt) the identification information to be transmitted using a private key associated with the target avatar.
[0164] The identity management device 400A may also manage a wallet (an example of an information storage medium). The wallet here may not only store assets in a cryptocurrency usage environment, but may also manage, for example, credential information (authenticity proof information, identity verification information (VC)) of a real user or avatar associated with one end user. The identity management device 400A may manage wallet data in a blockchain. The wallet may be configured as an application provided by the identity management device 400A.
[0165] The network service environment 500 is an environment that provides one or more network services. Specifically, the network service environment 500 includes one or more service providing systems 510 that provide predetermined network services. The service providing systems 510 may be configured as, for example, web servers or application servers that are constructed according to the content of the network services to be provided.
[0166] The network services provided by the service providing system 510 may include electronic commerce (EC) services used by real users, websites using avatars, network games, web conferencing systems, etc. Furthermore, network services using avatars in this manner may include those in which avatars exist in a metaverse, a three-dimensional virtual space, and act in the metaverse. Specific network services include services such as a marketplace in which avatars can purchase products from stores in the metaverse, services in which avatars can directly buy and sell goods between each other in the metaverse, and services in which celebrities or specific characters exist in the metaverse. Services such as providing weather forecasts using avatars as weather forecasters, medical consultations using avatars as doctors, and fortune telling using avatars as fortune tellers are also possible. The service providing system 510 may be capable of providing multiple network services. A service providing system 510 that provides a metaverse as a network service may provide multiple metaverses.
[0167] The VC issuing system 600 is a system that issues identification information in response to an issuance request. The VC issuing system 600 may be configured, for example, by one or more devices connected to a network. The VC issuing system 600 of this embodiment is capable of issuing identification information that proves the identity of an end user (real user), and is also capable of issuing identification information that proves the identity of an avatar itself that is managed by the identity management device 400A.
[0168] The VC issuing system 600 may be capable of issuing a plurality of identification information corresponding to a plurality of different issuers (issuers).
[0169] The VC issuing system 600 can issue identification information (official identification information) of official issuers. An official issuer is, for example, an institution operated by the government, an institution authorized by the government, or an institution with a certain level of social credibility. Specifically, official issuers include, for example, an institution that issues licenses according to specified qualifications, authorized companies, educational institutions, local governments, financial institutions, etc. For example, official identification information used for payments in the metaverse may be issued by a financial institution. Furthermore, official identification information for entry into a specific facility in the metaverse may be issued by a company, educational institution, local government agency, etc. that operates the facility.
[0170] The VC issuing system 600 also issues identification information (private identification information) for private issuers. A private issuer may be, for example, a private organization such as a volunteer group, a civic sports group, or a school club. The private identification information issued by such a private issuer can certify, for example, that an avatar belongs to the corresponding private organization, or that a certificate or license issued by the corresponding private organization has been granted to the avatar.
[0171] Furthermore, private issuers may include, for example, fans (supporters) of an artist. The private identification information issued by a fan of an artist can be attached to, for example, an avatar of the artist, thereby proving that the avatar of the artist is supported by the fan.
[0172] Additionally, a private issuer may include an end user. For example, an end user as a private issuer may issue a friend certificate with private identification information. An avatar with the friend certificate's private identification information can prove that it is a friend with the avatar of the private issuer, for example, the end user.
[0173] The private issuer may be, for example, the operator of the service providing system 510. As an example, the service providing system 510 as a private issuer may issue private identification information of a good standing. The avatar of the end user to which the private identification information of a good standing is assigned can prove that the end user has not engaged in any fraudulent activities and is of good standing in the metaverse provided by the service providing system 510, for example.
[0174] The private issuer may also include an event organizer, etc. As an example, the private issuer may issue private identification information as a ticket for an event held in the metaverse of a specific service providing system 510. An avatar that has been given private identification information as a ticket can prove that it is eligible to participate in the event held in the metaverse of the specific service providing system 510.
[0175] As can be seen from the example of the private issuer above, private identification information can function as proof of the identity of an avatar or a user corresponding to an avatar, based on interpersonal relationships and personal evaluations. Another example of issuance of identification information based on interpersonal relationships is private identification information based on connections in a social networking system (SNS). In this case, the private identification information may prove that a certain user or avatar is a friend of a friend of the private issuer in the SNS. Another example of private identification information based on personal evaluation is private identification information based on the user's evaluation as a user (seller, buyer) in a network service where transactions between individuals are conducted. Another example of private identification information based on evaluations by other individuals is private identification information that can be issued based on information indicating the user's trustworthiness (trustworthiness information) provided by a service that evaluates the user's trustworthiness by inputting information such as the user's age, gender, occupation, and purchasing history.
[0176] The identification information issued by the VC issuing system 600 in this embodiment may correspond to, for example, a VC (Verifiable Credential). In the following description, a case where the identification information in this embodiment corresponds to a VC will be taken as an example. Therefore, in the following description, the identification information issued by the VC issuing system 600 may be referred to as a VC.
[0177] In this embodiment, the identification information that certifies the identity of the avatar itself is referred to as avatar identification information (avatar VC) to distinguish it from the identification information that certifies the identity of the real user (end user) (user identification information (user VC)). When there is no particular distinction between avatar identification information and user identification information, they are referred to as identification information or VC.
[0178] The DPKI system 700 manages public keys in accordance with the DPKI (Decentralized Public Key Infrastructure). When issuing identification information as a VC, the VC issuing system 600 of this embodiment generates a pair of public and private keys corresponding to an issuer DID, which is a DID (Decentralized Identifier) that uniquely identifies an issuing institution. It also generates a pair of public and private keys corresponding to an owner DID (end user DID or avatar DID), which is a DID that uniquely identifies the owner (end user or avatar) of the identification information. The VC issuing system 600 registers the generated public keys (public key corresponding to the issuer DID and public key corresponding to the owner DID) in the DPKI system 700. The DPKI system 700 stores the registered public keys in association with the respective issuer DID and owner DID.
[0179] The DPKI system 700 may be configured to register a public key by storing the public key in a blockchain. The DPKI system 700 may also be configured with devices that function as nodes corresponding to the blockchain that stores the public key.
[0180] When the service providing system 510 needs to verify the identity of a holder, it obtains a public key associated with the holder DID of the holder from the DPKI system 700. The service providing system 510 can determine whether the identification information is valid (identity verification) by using the obtained public key to decrypt the identification information.
[0181] 20 shows the hardware configuration of an identity management device 400A. The identity management device 400A in the figure includes a communication device 4001, a ROM (Read Only Memory) 4002, a RAM (Random Access Memory) 4003, storage 4004, and a CPU (Central Processing Unit) 4005. The communication device 4001, ROM 4002, RAM 4003, storage 4004, and CPU 4005 are connected by a bus 4006.
[0182] The communication device 4001 is a device that supports communication via a network. The ROM 4002 stores non-rewritable data. The RAM 4003 temporarily stores data used in calculations performed by the CPU 4005. The storage 4004 is, for example, a hard disk drive (HDD) or a solid state drive (SSD), and stores various data, such as program data. The CPU 4005 executes programs stored in the storage 4004 to perform calculations corresponding to various controls and processes. Although not shown in the figure, the identity management device 400A may also be equipped with a graphics processing unit (GPU). It is also possible to provide functionality equivalent to that of the identity management device 400A using multiple network terminals that are distributed so as to be able to execute transactions in accordance with the blockchain.
[0183] 21 shows an example of the functional configuration of an identity management device 400A. The functions of the identity management device 400A in the figure are realized by a central processing unit (CPU) included in the identity management device 400A executing a program. The identity management device 400A in the figure includes a communication unit 401, a control unit 402A, and a storage unit 403A.
[0184] The communication unit 401 performs communication via a network.
[0185] The control unit 402A executes various controls in the identity management device 400A. The control unit 402A in the figure includes an avatar registration unit 421, an authenticity certification information management unit 422 (an example of a qualification management unit), an avatar provision control unit 423, a VC management unit 424 (an example of a qualification management unit), a wallet management unit 425, and a feature word processing unit 426.
[0186] The avatar registration unit 421 registers the avatars generated by the avatar generation system 100 as management targets. Here, avatar registration is performed by storing avatar information (described later) of the avatars to be managed in the avatar information storage unit 432. The avatars registered by the avatar registration unit 421 can be used by the service providing system 510 in the network service environment 500 in the network services it provides.
[0187] The authenticity certification information management unit 422 manages the authenticity certification information of the avatar. Specifically, the authenticity certification information management unit 422 assigns authenticity certification information to the avatar to be registered. Authenticity certification information will be described later. In addition, in response to an authenticity confirmation request from the end user terminal 300, the authenticity certification information management unit 422 may determine the authenticity of the avatar whose authenticity is to be confirmed, using the authenticity certification information assigned to the registered avatar. The authenticity certification information management unit 422 may transmit the determination result regarding the authenticity to the end user terminal 300 that sent the authenticity confirmation request.
[0188] The avatar provision control unit 423 executes control related to the provision (transmission of avatar information) of registered avatars to the service provision system 510. The identity management device 400A and each service provision system 510 may be connected via an API, and the avatar provision control unit 423 may be configured to transmit avatar data to the service provision system 510 while connected online.
[0189] The VC management unit 424 manages the VCs (identification information) of identities that exist in real space or the metaverse and are subject to management. The VCs managed by the VC management unit 424 manage user identification information (user VC) corresponding to the identities as real users and avatar identification information (avatar VC) corresponding to the identities as avatars. The VC management unit 424 requests the VC issuing system 600 via a network to issue identification information for the identities (real users or avatars). The VC issuing system 600 issues identification information for the target identities in response to the request. The VC issuing system 600 transmits the issued identification information and corresponding private keys (private key corresponding to the issuer DID and private key corresponding to the holder DID) to the identity management device 400A. The VC management unit 424 associates the transmitted identification information (avatar identification information or user identification information) with the private key and stores them in the avatar VC storage unit 433 or the user VC storage unit 434 .
[0190] The wallet management unit 425 manages wallets used by real users and avatars.
[0191] The characteristic word processing unit 426 extracts words as multiple characteristic words corresponding to the characteristics of each identity, and generates information (an example of characteristic word relationship information) that indicates the relationships between the extracted words (examples of characteristic words). The information generated in this way can be seen as expressing the characteristics of the corresponding identities by indicating the relationships between the extracted words, and therefore will hereinafter be referred to as "characteristic expression information." The characteristic word processing unit 426 is also capable of visualizing the generated characteristic expression information and displaying it on the end-user terminal 300.
[0192] The storage unit 403A stores various types of information supported by the identity management device 400A. The storage unit 403A includes an end user information storage unit 431, an avatar information storage unit 432, an avatar VC storage unit 433, a user VC storage unit 434, a wallet management information storage unit 435, an identity history information storage unit 436, and a trait expression information storage unit 437.
[0193] The end-user information storage unit 431 stores end-user information, which is information about an end user who has registered one or more avatars corresponding to the end user in the identity management device 400A.
[0194] 22 shows an example of end user information corresponding to one end user. The end user information in FIG. 22 includes fields for an end user ID and user profile information. The end user ID field stores an end user ID that uniquely identifies the corresponding end user. The user profile information field stores user profile information for the corresponding end user. The user profile information may include, for example, the end user's name, gender, address, etc.
[0195] The avatar information storage unit 432 stores avatar information. FIG. 23 shows an example of avatar information stored in the avatar information storage unit 432. The avatar information storage unit 432 in FIG. 23 includes an object data storage unit 4321, a material group data storage unit 4322, and a metafile storage unit 4323. Avatar information corresponding to one avatar includes, for example, object data, material group data, and a metafile. The object data storage unit 4321 stores object data for each registered avatar. The material group data storage unit 4322 stores material group data for each registered avatar. The metafile storage unit 4323 stores metafiles for each registered avatar. The object data, material group data, and metafiles corresponding to the same avatar are associated with each other by the same avatar ID among the object data storage unit 4321, material group data storage unit 4322, and metafile storage unit 4323.
[0196] Specifically, the object data A, material group data A, and metafile A stored in the object data storage unit 4321, material group data storage unit 4322, and metafile storage unit 4323 corresponding to avatar A are associated with each other by an avatar ID [00000A] that uniquely identifies avatar A.
[0197] The object data is data of the actual object as the corresponding avatar, and is formed by combining components such as a head, body, etc. that are generated using predetermined avatar materials.
[0198] The material group data is data that includes one or more avatar materials that add a predetermined aspect to the avatar entity represented by the object data. The material group data may include, for example, audio materials, emotional materials, movement materials, spatial materials, etc. The material group data allows the avatar object to speak, change facial expressions, move, and exist in a virtual space with a predetermined design.
[0199] A metafile contains one or more pieces of metadata to be assigned to the corresponding avatar. Fig. 24 shows an example of a metafile corresponding to one avatar. The metafile in Fig. 24 contains metadata such as an avatar ID, source information, creator information, authentication code, authorized user information, avatar format, and behavior history information.
[0200] The avatar ID is an identifier that uniquely identifies an avatar in the avatar information stored in the avatar information storage unit 432. The avatar ID may be issued by the avatar registration unit 421 when registering a corresponding avatar. As described above, the avatar ID associates object data, material group data, and metafiles that correspond to the same avatar.
[0201] The generator information is information about the original person (generator) of the corresponding avatar. The generator information may include, as information items, a generator ID, profile information of the generator, etc. The generator information may be provided by the avatar generation system 100. If the generator is an end user, the end user ID of the corresponding end user may be used as the generator ID.
[0202] The creator information is information about the creator of the corresponding avatar. The creator may be, for example, an organization such as a company or an individual that corresponds to the integrated system 120 that generated the corresponding avatar in the avatar generation system 100.
[0203] The authentication code is a code that the identity management device 400A issues in association with the avatar to be provided when the service providing system 510 receives the provision of an avatar (transmission of avatar information) from the identity management device 400A.
[0204] The authorized user information is information about an authorized user. The authorized user is a person who has the right to use the corresponding avatar. The authorized user may be an end user who created the avatar. In this case, the authorized user can make the avatar created by the authorized user exist in the metaverse provided by the service providing system 510 and cause it to act within the metaverse in response to, for example, the operation of the end user terminal 300. The authorized user may also be the operator of a specific service providing system 510. The authorized user information is information indicating such an authorized user. Specifically, the authorized user information may be a user account, such as an authorized user ID, username, and password, registered by the authorized user. If the authorized user is an end user, the authorized user ID may be the end user ID. Furthermore, the authorized user information may include, in addition to the original authorized user (primary authorized user), such as the end user who created the avatar, authorized users (secondary authorized users), such as other end users who have been granted usage rights.
[0205] The avatar format indicates the corresponding avatar format, such as the file format and specifications of the avatar.
[0206] The behavior history information is information indicating the history of behavior of a corresponding avatar in the metaverse provided by each service providing system 510. The behavior history information of each avatar may be acquired from each service providing system 510 by, for example, the avatar provision control unit 423.
[0207] Returning to Fig. 21 for the explanation, the avatar VC storage unit 433 stores avatar identification information (avatar VC) for each registered avatar. The avatar VC storage unit 433 also stores private keys associated with the avatar identification information (private keys corresponding to issuer DIDs and private keys corresponding to avatar DIDs).
[0208] 25 shows an example of information (avatar identification information and private key) stored in the avatar VC storage unit 433 corresponding to one avatar. As shown in the figure, the avatar VC storage unit 433 stores avatar identification information and a private key corresponding to the avatar DID in association with the avatar VC_ID and avatar ID. The avatar VC_ID is an identifier uniquely assigned to the corresponding avatar identification information. In this way, by associating the avatar identification information and private key with the avatar ID, the avatar identification information and private key can be associated and managed for the avatar information of the corresponding avatar.
[0209] The avatar identification information includes fields for VC type, issuer DID, avatar DID, and avatar-related information. The VC type field stores information indicating the type (model, format) of the identification information. The issuer DID field stores the issuer DID indicating the issuer of the avatar identification information. The avatar DID field stores the avatar DID of the corresponding avatar. The avatar-related information field stores avatar-related information of the corresponding avatar. The content of the information included in the avatar-related information is not particularly limited, and may include, for example, information such as rights and qualifications acquired by the avatar by acting in the metaverse. The avatar-related information may also include behavioral history information similar to that stored in the avatar information.
[0210] At least one of the avatar identification information and the private key may be stored in the blockchain under the control of the VC management unit 424 of the identity management device 400A. When both the avatar identification information and the private key are stored in the blockchain, the avatar VC storage unit 433 may be omitted.
[0211] 21 for the explanation. The user VC storage unit 434 stores user identification information (user VC) for each end user (real user) registered (stored) in the end user information storage unit 431. The user VC storage unit 434 also stores private keys (private keys corresponding to issuer DIDs and private keys corresponding to user DIDs) associated with the user identification information.
[0212] 26 shows an example of information (user identification information and private key) stored in the user VC storage unit 434 corresponding to one real user. As shown in the figure, the user VC storage unit 434 stores user identification information and a private key corresponding to the user DID in association with the user VC_ID and user ID. The user VC_ID is an identifier uniquely assigned to the corresponding user identification information. In this way, by associating the user identification information and private key with the user ID, the user identification information and private key can be associated and managed with the user information of the corresponding real user (end user).
[0213] The user identification information includes fields for VC type, issuer DID, user DID, and user-related information. The user-related information stores user-related information for the corresponding real user. The content of the information included in the user-related information is not particularly limited, but may include, for example, information such as rights and qualifications acquired by the real user as a result of the corresponding real user's actions in real space (shopping, traveling to a specified location, etc.). The user-related information may also include behavioral history information about the corresponding real user's actions in real space.
[0214] At least one of the user identification information and the private key may be stored in the blockchain under the control of the VC management unit 424 of the identity management device 400A. When both the user identification information and the private key are stored in the blockchain, the user VC storage unit 434 may be omitted.
[0215] Returning to FIG. 21 for the explanation, the wallet management information storage unit 435 stores wallet management information. The wallet management information corresponding to one wallet is information for integrating and managing the credential information of the identities (real user, avatar) corresponding to one end user. FIG. 27 shows an example of wallet management information corresponding to one wallet. The wallet management information corresponding to one wallet has fields for a wallet ID, an identity list, and a credential information list. The wallet ID field stores a wallet ID that is an identifier that uniquely identifies the corresponding wallet. The identity list stores identity IDs (user ID, avatar ID) that indicate identities that can use the corresponding wallet. The credential information list stores credential IDs (user VC_ID, avatar VC_ID, authenticity certification information ID, etc.) for each credential (VC, authenticity certification information, etc.) that is managed as being included in the corresponding wallet. Wallet management information with such a structure makes it possible to comprehensively manage, for example, credential information (authenticity certificate information, VC, etc.) assigned to each identity (real user, avatar) corresponding to one end user as credential information stored in a wallet held by one end user. Also, it becomes possible to share the credential information stored in the wallet between identities indicated by identity IDs (user ID, avatar ID) stored in an identity list.
[0216] The wallet management information may be stored in the blockchain under the control of the wallet management unit 425 of the identity management device 400A. In this case, the wallet management information storage unit 435 may be omitted.
[0217] The identity history information storage unit 436 stores identity history information indicating the history of past actions for each identity (real user or avatar). The identity history information storage unit 436 may store the identity history information, for example, for each real user (end user), so that the identity history information of the real user (real user individual history information) is associated with the identity history information of one or more avatars (avatar individual history information) associated with the real user. The real user individual history information may be collected by the control unit 402A, for example, from the end user terminal 300 used by the corresponding end user, such as website usage history information and location information, and the collected information may be stored in the identity history information storage unit 436 as identity history information. Furthermore, the avatar individual history information may be acquired by the avatar provision control unit 423 from each service provision system 510, for example. The behavior history information in the metafile ( FIG. 24 ) of the avatar information stored in the metafile storage unit 4323 may be omitted, or each may exist separately.
[0218] 28 shows an example of management of identity history information stored in association with one real user by identity history information storage unit 436. As shown in the figure, the identity history information corresponding to one real user is managed such that real user individual history information and avatar individual history information for each avatar (avatar A, avatar B, etc.) are associated with the real user ID of the corresponding real user.
[0219] 28 shows an example in which one real user individual information is associated with one real user and one avatar individual history information is associated with each avatar. However, for example, for each category of behavior type, multiple real user individual information may be associated with one real user, or multiple avatar individual information may be associated with one avatar.
[0220] Returning to Fig. 21, the characteristic expression information storage unit 437 stores the characteristic expression information generated by the characteristic word processing unit 426.
[0221] The identity management device 400A may be configured from a single device, or may be realized by assigning specific functions to multiple devices connected to each other so that they can communicate over a network, and then having the multiple devices work together to perform processing.
[0222] The VC issuing system 600 may also store a database related to issuers (issuer database). FIG. 29 shows an example of the structure of a record (issuer information) stored in the issuer database corresponding to one issuer. The issuer information in the figure includes fields for issuer ID, issuer profile, and issuing VC. The issuer ID field stores the issuer ID of the corresponding issuer. The issuer profile field stores the issuer profile. The issuer profile is information indicating the profile of the issuer. As shown in the figure, the issuer profile may include fields such as issuer type and issuer name. The issuer type field stores information indicating, for example, the type of the corresponding issuer, whether it is a public issuer or a private issuer. The issuer name field stores the name of the corresponding issuer (issuer name). The issuing VC field stores information regarding identification information issued by the corresponding issuer as the issuer.
[0223] An example of a processing procedure executed by the identity management system (qualification management system) 1A of this embodiment in relation to the registration (user registration) of an end user (real user) will be described with reference to the sequence diagram of Fig. 30. The registration of an end user according to the example processing procedure in Fig. 30 is a registration for enabling the end user corresponding to an avatar to be managed as a real user, which is one of identities.
[0224] Step S100A: The end user operates the end user terminal 300 owned by the end user to perform an end user registration procedure so that the end user as the end user is registered in the identity management device 400A. In the end user registration procedure, the end user may input predetermined information items such as a user account and a username to be included in the user profile information. In response to the end user registration procedure from the end user terminal 300, the identity management device 400A generates end user information for the corresponding end user and stores the generated end user information in the generated end user information storage unit 431.
[0225] Step S102A: In addition, the end user may carry out a procedure for issuing user identification information (user VC) corresponding to the end user in response to the user registration in step S100A. In this case, the end user accesses the end user terminal 300 to the VC issuing system 600 and performs an operation for the procedure for issuing user identification information (user VC) corresponding to the end user. The end user terminal 300 executes a process corresponding to the user identification information issuance procedure in response to the operation. As a process for the issuance procedure, the end user terminal 300 may send an issuance request to the VC issuing system 600 together with information on predetermined items in the user profile information. The issuance request may also include information specifying the type of user identification information to be issued (e.g., driver's license, passport, insurance card, etc.).
[0226] Step S104A: The VC issuing system 600 generates user identification information in response to the issuing request received in response to step S102A. At this time, the VC issuing system 600 generates (issues) a user DID indicating the corresponding end user, and generates a pair of a public key and a private key corresponding to the user DID. Then, the VC issuing system 600 signs (encrypts) the generated user identification information using the private key generated in response to the issuer DID indicating the issuing organization that it corresponds to.
[0227] Step S106A: The VC issuing system 600 registers the user identification information generated in step S104A in the identity management device 400A. Specifically, the VC issuing system 600 transmits to the identity management device 400A the user identification information signed with a private key corresponding to the issuer DID granted to the corresponding issuing institution, and the private key corresponding to the user DID of the corresponding end user. In the identity management device 400A, the VC management unit 424 stores the user identification information and the private key corresponding to the user DID received from the VC issuing system 600 in the user VC storage unit 434 in association with the avatar ID of the corresponding avatar.
[0228] Step S108A: The VC issuing system 600 also registers the public keys (the effector key corresponding to the issuer DID and the public key corresponding to the user DID) generated together with the user identification information in step S104A in the DPKI system 700. The issuance of user identification information in steps S102A to S108A may be performed whenever it becomes necessary to issue new user identification information after the user registration.
[0229] Next, with reference to the sequence diagram of Figure 30, an example of a processing procedure executed by identity management system 1A of this embodiment in relation to avatar generation, registration, and registration of avatar authentication information will be described. Step S200A: An end user operates their own end user terminal 300 to access avatar generation system 100 and perform an avatar generation operation. End user terminal 300 transmits an avatar generation instruction corresponding to the avatar generation operation to avatar generation system 100.
[0230] Step S202A: The avatar generation system executes a process to generate an avatar in response to the avatar generation instruction.
[0231] Step S204A: The end user operates the end user terminal 300 to perform an avatar registration procedure so that the generated avatar is registered in the identity management device 400A. In the avatar registration procedure, the end user specifies the avatar to be registered and the identity management device 400A as the registration destination of the specified avatar.
[0232] Step S206A: In response to the avatar registration procedure in step S204A, avatar generation system 100 and identity management device 400A execute processing for avatar registration. First, avatar generation system 100 uploads avatar information for the avatar designated as the registration target in the avatar registration procedure to identity management device 400A. Avatar registration unit 421 of identity management device 400A stores the uploaded avatar information in avatar information storage unit 432.
[0233] Also, in step S206A, the authenticity certification information management unit 422 of the identity management device 400A assigns authenticity certification information to the avatar that is the target of this registration. The authenticity certification information is information that proves the authenticity of the avatar itself, which exists in the metaverse or the like of the service providing system 510. Here, the authenticity of an avatar means that the avatar is not a fake or has been tampered with, and is legitimate. Examples of an invalid (illegitimate) avatar include an avatar that has been tampered with, for example, by replacing avatar materials such as facial materials with fake materials that are different from the original, and an avatar that has been copied without the permission of a person who holds certain rights to the avatar, such as the creator.
[0234] Specifically, the authenticity certification information management unit 422 may assign authenticity certification information to the target avatar by adding an electronic watermark (an example of authenticity certification information) and a digital authenticity certificate (an example of authenticity certification information) as follows.
[0235] The authenticity certification information management unit 422 adds information unique to the target avatar, such as an avatar ID, to the object data of the target avatar as a digital watermark. The digital watermark added to the object data of the avatar in this way is preferably imperceptible, but may also be perceptible.
[0236] The authenticity certificate information management unit 422 also assigns a digital authenticity certificate to the target avatar. In this case, the authenticity certificate information management unit 422 may assign an authenticity certificate to the target avatar that certifies the creator of the target avatar, the storage location (URL) of the target avatar, the service providing system 510 that uses the target avatar, and the like. For example, the authenticity certificate may be issued by an authenticity certificate issuing site (not shown) on the network, when the authenticity certificate information management unit 422 executes a predetermined transaction with the issuing site. Such an authenticity certificate may be managed on the network, for example, in association with the avatar ID of the target avatar (an example of information unique to the avatar to be registered). As an example, the authenticity certificate assigned to the avatar by the authenticity certificate information management unit 422 may be a non-fungible token (NFT) managed on a blockchain. In this case, the authenticity proof information management unit 422 may assign an authenticity certificate to the avatar using, for example, an external NFT platform. The authenticity proof information management unit 422 may also assign an authenticity certificate generated using quantum-resistant cryptography or quantum-resistant blockchain to the avatar. The authenticity certificate assigned to the avatar by the authenticity proof information management unit 422 may be a soulbound token (SBT), which is a non-transferable NFT. In this case, the authenticity proof information management unit 422 may assign an SBT to the avatar as authenticity proof information instead of an NFT, or may assign both an NFT and an SBT to the avatar. When assigning an NFT and an SBT to the avatar as authenticity proof information, the authenticity proof information management unit 422 may select and use either the NFT or the SBT to prove the authenticity of the avatar, or may use both the NFT and the SBT.
[0237] In step S206A, the authenticity certification information management unit 422 also issues a unique authentication code to the avatar currently being registered. The authentication code is provided to the service providing system 510, which provides network services using the target avatar, along with the avatar data of the target avatar. The authentication code is used to determine the authenticity of the avatar in response to a request from an end user, as described below. Since the authentication code is uniquely associated with the target avatar, an avatar ID may be used, for example. However, to enhance security against, for example, the identification of the avatar or registration information that may include the user's personal information, it is preferable to use a code generated independently of the avatar ID as the authentication code. The authenticity certification information management unit 422 adds the issued authentication code as one piece of metadata in a metafile associated with the target avatar and stored in the metafile storage unit 4323 (FIG. 24).
[0238] Step S208A: The end user, who is the creator of the avatar registered in step S206A, accesses the VC issuing system 600 using the end user terminal 300 and performs an operation for issuing avatar identification information. The end user terminal 300 executes the issuance procedure in response to the operation. As the issuance procedure, the end user terminal 300 may transmit an issuance request to the VC issuing system 600 along with the avatar information that is the target of the avatar identification information. The issuance request may also include information specifying the avatar identification information to be issued (issuance certificate specification information). In response to the issuance request, the VC issuing system 600 may determine the avatar identification information to be issued to the target avatar. When sending the issuance request, the end user terminal 300 may first acquire avatar information from the identity management device 400A and then transmit the acquired avatar information to the VC issuing system 600, or may specify the avatar to be sent to the identity management device 400A and have the identity management device 400A transmit the avatar information to the VC issuing system 600.
[0239] Step S210A: In response to the issuance request from the end user terminal 300 in step S208A, the VC issuing system 600 generates avatar identification information that certifies the identity of the avatar based on the avatar information received together with the issuance request in step S208A. At this time, the VC issuing system 600 generates (issues) an avatar DID indicating the corresponding avatar, and generates a pair of a public key and a private key corresponding to the avatar DID. Then, the VC issuing system 600 signs (encrypts) the generated avatar identification information using the private key generated in correspondence with the issuer DID indicating the issuing organization that the VC issuing system 600 corresponds to. The VC issuing system 600 may include at least a portion of the content of the received avatar information in the avatar-related information.
[0240] Step S212A: The VC issuing system 600 registers the avatar identification information in the identity management device 400A. Specifically, the avatar identification information (an example of signed identification information) signed with a private key corresponding to the issuer DID granted to the corresponding issuing institution and the private key corresponding to the avatar DID of the corresponding avatar are transmitted to the identity management device 400A. The VC management unit 424 of the identity management device 400A stores the avatar identification information and the private key corresponding to the avatar DID received from the VC issuing system 600 in the avatar VC storage unit 433 in association with the avatar ID of the corresponding avatar.
[0241] Step S214A: The VC issuing system 600 also registers the public keys (public key corresponding to the issuer DID and public key corresponding to the avatar DID) generated together with the avatar identification information in step S210A in the DPKI system 700.
[0242] In the identity management system 1A of this embodiment, the processing procedure shown in FIG. 29 allows a real user and an avatar to be registered as an identity corresponding to one end user. After registration, credential information can be assigned (issued) to the identity. That is, a user identification card can be assigned (issued) to the real user, and avatar identification information and authenticity certification information can be assigned to the avatar. The wallet management unit 425 of the identity management device 400A can then set a credential information wallet WL, which is a wallet that collectively stores the credential information assigned to the identities (real user, avatar) for each end user. That is, the wallet management unit 425 assigns one wallet ID to one end user. The wallet management unit 425 generates wallet management information corresponding to the assigned wallet ID as follows. For example, the wallet management unit 425 stores the identity ID (user ID, avatar ID) for each corresponding identity in a field of the shared ID list, in association with the assigned wallet ID. Furthermore, the wallet management unit 425 stores a list item of the credentials assigned to the corresponding identity in a field of the shared credentials list, in association with the assigned wallet ID. The wallet management unit 425 stores the wallet management information generated in this manner in the wallet management information storage unit 435. Note that the shared ID list may store identity IDs of some of all identities corresponding to one end user. Also, the shared credentials list may store some of the credentials selected from all of the credentials assigned to each identity corresponding to one end user.
[0243] FIG. 31 shows an example of the mode of identities and credentials managed by wallet management information corresponding to one end user. The figure shows an example of wallet management implemented under an avatar management-enabled application installed on an end user terminal 300. The figure shows an example in which a real user and three avatars, A, B, and C, are registered as identities that can use a credentials wallet WL corresponding to the end user. That is, the shared ID list field of the wallet management information stores the user ID of the corresponding real user and the avatar IDs of the three avatars, A, B, and C. The credentials wallet WL corresponding to the real user and the three avatars, A, B, and C, also stores user identification information (user VC) corresponding to the real user and avatar identification information (avatar VC) corresponding to Avatar A, Avatar B, and C, respectively. Furthermore, the credential information wallet WL in the figure holds authenticity proof information such as NTF or SBT assigned to Avatar A, Avatar B, or Avatar C, respectively, as in token 1 to token 5. These identity proof information (VC) and tokens (authenticity proof information) are stored in the shared credential information list field of the corresponding wallet management information. Tokens such as NFTs and SBTs may include, for example, driver's licenses, membership cards, admission passes indicating admission to a specific location, and tickets indicating participation in a specific event. In this manner, in this embodiment, by associating a credential information wallet WL with one end user, it becomes possible to collectively manage the credential information of multiple identities corresponding to one end user.
[0244] In accordance with the above-described ability to manage the qualification information of multiple identities corresponding to one end user in a centralized manner, the end user terminal 300 can present the identities and qualification information corresponding to the end user as follows.
[0245] 32 shows an example of an identity management screen displayed on the display unit of the end user terminal 300. The identity management screen in the figure may be displayed by a web browser installed in the end user terminal 300 accessing a web page of the identity management screen provided by, for example, the identity management device 400A. Alternatively, the identity management screen may be displayed by an application corresponding to identity management installed in the end user terminal 300. The identity management screen in the figure includes an identity selection area AR1, a qualification information selection area AR2, and a service selection area AR3.
[0246] The identity selection area AR1 is an area where an operation to select an identity to be authenticated, enter the metaverse, etc. is performed. In the identity selection area AR1, buttons BT1 corresponding to real users and multiple avatars are arranged as identities corresponding to end users. In the figure, the button BT1 labeled "Real ID" corresponds to a real user, and the buttons BT1 labeled "Business," "Culture," and "Game" correspond to avatars, respectively.
[0247] The credential information selection area AR2 is an area where an operation is performed to select credential information that a real user uses to verify their credential in real space or that an avatar uses to verify their credential in the metaverse.
[0248] The credential selection area AR2 includes an identification information (VC) area AR21 and an authenticity certification information area AR22. The identification information area AR21 is an area where an operation to select credential information as identification information is performed. In the identification information area AR21, buttons BT21 corresponding to each piece of identification information are arranged as options. The authenticity certification information area AR22 is an area where an operation to select credential information as authenticity certification information is performed. In the authenticity certification information area AR22, buttons BT22 corresponding to each piece of identification information are arranged as options.
[0249] The service selection area AR3 is an area where an operation is performed to select a service to be used by an identity from among services provided in the real world (real services) and services provided in the metaverse (network services). Real services may include services that allow the use of predetermined cashless payments such as credit cards. In the service selection area AR3, buttons BT3 corresponding to each service are arranged.
[0250] By operating such an identity management screen, an end user can act so that the identity corresponding to the end user (a real user, an avatar associated with the real user) can use various services.
[0251] In addition, each identity (real user, avatar) has different contents such as the content and type of identification information (VC) issued by the VC issuing system 600, authenticity proof information (NFT, SBT, etc.), identity history information, wallet data, user-related information, and avatar-related information. In other words, it can be said that each identity has its own characteristics as an individual or a single entity. Considering that each identity has its own characteristics, it is preferable to utilize information regarding the characteristics of identities in the real space where real users act and the metaverse where avatars act.
[0252] Therefore, in the identity management system 1A of this embodiment, characteristic expression information can be assigned to each identity as information indicating the characteristics of the identity. The characteristic expression information is information indicating the relationship between multiple words extracted from the identity individual information. The identity individual information may be, for example, the above-mentioned identification information (VC), authenticity proof information (NFT, SBT, etc.), wallet data, user-related information, avatar-related information, identity history information, etc. Such identity individual information can be treated as indicating the characteristics of the corresponding identity. Therefore, the characteristic expression information is information indicating the characteristics of the corresponding identity using words and the relationships between the words.
[0253] In this embodiment, the feature word processing unit 426 of the identity management device 400A may generate feature expression information and store it in the feature expression information storage unit 437. Then, the feature word processing unit 426 may generate an identity feature graph (an example of word relationship display information) that visualizes the feature expression information, and the generated identity feature graph may be displayed on the end user terminal 300 or the metaverse.
[0254] Figure 33 shows an example of the display form of an identity trait graph based on trait expression information generated corresponding to one identity A. The identity trait graph in the figure has a structure in which a main node MN corresponding to the words of "identity A" is the starting point, and sub-nodes SN corresponding to each word related to the main node MN are connected by edges based on the relationship with the main node MN or the relationship between the words.
[0255] In the identity trait graph, it is possible to arbitrarily change the node that corresponds to each word and becomes the main node MN from among the nodes corresponding to each word. Figure 34 shows an example of an identity trait graph in which the subnode SN corresponding to the word "programming" among the subnodes SN presented in the identity trait graph of Figure 33 has been changed to the main node MN. The identity trait graph of Figure 34 has been changed so that the connection relationships of the nodes starting from the main node MN are also reconstructed in accordance with the change in the main node MN from Figure 33.
[0256] In the identity trait graphs of Figures 33 and 34, the display of nodes may be changed depending on, for example, the importance of words, etc. Also, in the identity trait graph, the thickness, color, etc. of edges between nodes may be changed depending on the degree of relationship (connection).
[0257] An example of a processing procedure executed by the identity management device 400A in relation to the generation of trait expression information will be described with reference to the flowchart in Fig. 35. The processing in Fig. 35 is processing related to the generation of trait expression information for a real user or an avatar as one identity.
[0258] Step S300A: In the identity management device 400A, the characteristic word processing unit 426 collects identity individual information of the target identity. If the target identity is a real user, the collected identity individual information may include the user profile information of the corresponding end user ( FIG. 22 ), the user identification information of the target real user stored in the user VC storage unit 434 ( FIG. 26 ), the authenticity proof information associated with the target real user, wallet data, the target real user individual history information stored in the identity history information storage unit 436 ( FIG. 28 ), etc. If the target identity is an avatar, the collected identity individual information may include information stored in the metafile of the corresponding avatar ( FIG. 24 ), the user identification information of the target avatar stored in the avatar VC storage unit 433 ( FIG. 25 ), the authenticity proof information associated with the target avatar, wallet data, the target avatar individual history information stored in the identity history information storage unit 436 ( FIG. 28 ), etc.
[0259] Step S302A: The characteristic word processing unit 426 extracts candidate words to be included in the characteristic expression information from the identity individual information collected in step S300A.
[0260] Step S304A: The characteristic word processing unit 426 performs scoring (weighting) for each candidate word extracted in step S302A. The characteristic word processing unit 426 may perform scoring for each candidate word based on the frequency of appearance of the candidate word, the degree of reliability of the identity individual information from which the candidate word was extracted, the degree of co-occurrence between the candidate words, etc.
[0261] Step S306A: The characteristic word processing unit 426 selects words (target words) to be included in the characteristic expression information from among the candidate words based on the results of the scoring in step S304A.
[0262] Step S308A: The feature word processing unit 426 generates characteristic expression information in which each of the target words selected in step S306A is a node. When generating the characteristic expression information, the feature word processing unit 426 may use the results of the scoring in step S304A to set the relationship (connection) between nodes (between words), the strength of the connection, the importance of the words themselves, etc.
[0263] The feature word processing unit 426 may use AI (artificial intelligence) to perform the processes of steps S302A to S308A. In this case, the feature word processing unit 426 may perform processes such as word scoring, word extraction, and word association using deep learning, clustering, etc.
[0264] Step S310A: The characteristic word processing unit 426 stores the characteristic expression information generated in step S208A in the characteristic expression information storage unit 437. The characteristic expression information may have a structure that stores, for each word, information such as the strength of the relationship with other words and the importance of the word itself.
[0265] The feature word processing unit 426 may create an identity feature graph using the feature expression information stored in the feature expression information storage unit 437, and may control the created identity feature graph to be displayed and visualized in the end user terminal 300 or the metaverse provided by the service providing system 510. The identity feature graph is not limited to a format such as a co-occurrence network as shown in Figures 33 and 34. The identity feature graph may also be in a format that shows, for example, the degree of relationship of each word with respect to a main word or the credibility of each word using a bar graph.
[0266] 36, an example of a processing procedure executed by the service providing system 510 and the identity management device 400A in relation to displaying an identity attribute graph will be described. First, an example of a processing procedure executed by the service providing system 510 will be described. Step S400A: For example, in response to a real user's access to a network service from the end user terminal 300 or an avatar's activity in the metaverse, it becomes necessary to display an identity attribute graph corresponding to the real user or avatar. Therefore, the corresponding service providing system 510 sends an identity attribute graph request to the identity management device 400A. The identity attribute graph request includes a user ID or an avatar ID indicating the target identity.
[0267] Step S402A: The service providing system 510 receives the identity attribute graph sent from the identity management device 400A in response to the identity attribute graph request sent in step S400A.
[0268] Step S404A: The service providing system 510 displays the identity attribute graph received in step S402A on the network service.
[0269] Next, an example of the processing procedure executed by the identity management device 400A will be described: Step S500A: In the identity management device 400A, the characteristic word processing unit 426 receives the identity attribute graph request sent in step S400A.
[0270] Step S502A: The characteristic word processing unit 426 acquires, from the characteristic expression information storage unit 437, characteristic expression information of the real user or avatar indicated by the user ID or avatar ID included in the received identity characteristic graph request.
[0271] Step S504A: The feature word processing unit 426 creates an identity feature graph using the feature expression information acquired in step S502A. Note that the identity feature graph can be in multiple formats, and if a format is specified by the identity feature graph request, for example, the feature word processing unit 426 creates an identity feature graph in the specified format.
[0272] Step S506A: The characteristic word processing unit 426 transmits the created identity characteristic graph to the service providing system 510A.
[0273] Furthermore, the characteristic word processing unit 426 can provide the characteristic expression information stored in the characteristic expression information storage unit 437 to the metaverse. In the metaverse, the provided characteristic expression information is used for a predetermined purpose.
[0274] For example, trait expression information may be used to match identities together, such as when a business identity in the metaverse selects a suitable avatar for its business from among job seeker avatars in the same metaverse.
[0275] The flowchart in Figure 37 shows an example of a processing procedure executed by the identity management device 400A in response to the above-mentioned identity matching. The processing in Figure 37 is a process for determining the degree of matching between, for example, a company's identity and one identity when selecting a job seeker identity that matches the company's job vacancy. In addition, the processing in Figure 37 also matches companies existing in the metaverse with avatars.
[0276] Step S600A: Company A, which exists as one of the identities in the metaverse, makes a job offer to an agent operated in the same metaverse. In response to the job offer request, the agent makes a request to the identity management device 400A to select an avatar to be hired as an employee by company A. The agent registers information about avatars that wish to be matched with companies in order to find employment at the companies in a talent database. In the identity management device 400A, the avatar provision control unit 423 acquires, in response to the request for avatar selection, the characteristic expression information of one avatar from the characteristic expression information of the requesting company and the characteristic expression information of the applicant avatars registered in the agent's talent database.
[0277] Step S602A: The avatar provision control unit 423 calculates the degree of compatibility between the characteristic expression information of the requesting company acquired in step S600A and the characteristic expression information of the avatar, which is the human resource. In calculating the degree of compatibility, the characteristic word processing unit 426 may, for example, calculate the degree of similarity between the characteristic expression information of the requesting company and the characteristic expression information of the avatar, which is the applicant.
[0278] Here, the characteristic expression information of the company and the characteristic expression information of the avatar as a human resource used in step S602A may use words that are considered to be highly important in relation to the job offer as the main nodes, rather than the corresponding identity words as in Figure 33. For example, the characteristic expression information in Figure 34 can be considered as information provided by an avatar as an applicant when applying for a job. In other words, the characteristic expression information in Figure 34 is information that the avatar as an applicant has registered in the human resource database with the purpose of highlighting his or her programming skills.
[0279] Step S604A: The characteristic word processing unit 426 may perform a matching determination based on the compatibility calculated in step S602A. In other words, the characteristic word processing unit 426 may determine whether it is appropriate for the applicant's avatar to be employed by the requesting company.
[0280] The processing of steps S602A and S604A may be performed by, for example, the feature word processing unit 426 using AI.
[0281] Step S606A: The characteristic word processing unit 426 notifies the determination result in step S604A. In this case, the characteristic word processing unit 426 may notify the determination result to both the requested company and the applicant's avatar, or may notify the determination result to both the requested company and the applicant's avatar.
[0282] The requested company may decide whether to hire the applicant's avatar based on the notified judgment result. The applicant's avatar may also decide whether to decide on the matched company as their place of employment based on the notified judgment result. The characteristic word processing unit 426 may also decide whether to hire the applicant's avatar at the requesting company (i.e., whether a match has been established) based on the judgment result in step S604A.
[0283] Other examples of aspects and usage of the characteristic expression information in this embodiment will be described below. In this embodiment, the characteristic expression information corresponding to one identity may be generated as a single piece of information that comprehensively indicates the characteristics of the corresponding identity, or multiple pieces of information may be generated for each category of the characteristics of the corresponding identity.
[0284] In this embodiment, the characteristic word processing unit 426 may generate integrated characteristic expression information by integrating characteristic expression information of multiple identities for which matching has been established. As a specific example, when a marriage is established between two identities as a result of matching, integrated characteristic expression information may be generated by integrating the characteristic expression information of the two identities. Such integrated characteristic expression information indicates the characteristics of the household composed of the two identities. Furthermore, when a matching is established between a company identity and an applicant identity, and the company identity includes an identity working as an employee, the characteristic word processing unit 426 may generate integrated characteristic expression information by integrating the characteristic expression information of the company identity and one or more employee identities. Such integrated characteristic expression information represents the characteristics of the company that accurately reflect the characteristics of its employees.
[0285] Furthermore, the characteristic word processing unit 426 may generate integrated characteristic expression information using not only the identity for which a match has been established, but also the characteristic expression information of a plurality of identities that have been determined in advance as targets for integration.
[0286] Furthermore, when generating the integrated characteristic expression information, the characteristic word processing unit 426 may perform integration using partial characteristic expression information based on a group of words in the characteristic expression information. In this case, when generating the integrated characteristic expression information, the characteristic word processing unit 426 may use characteristic expression information including all words for one identity and partial characteristic expression information for another identity.
[0287] Furthermore, when the integrated trait expression information is generated by integrating trait expression information of three or more identities, the characteristic word processing unit 426 may select trait expression information of some of multiple identities from the integrated trait expression information based on the trait expression information of all identities in accordance with predetermined conditions to reconstruct the integrated trait expression information. As a specific example, for integrated trait expression information that integrates trait expression information of all avatars working at a company existing in the metaverse, avatars as employees of a specific department, sales office, etc. at the company are selected. The characteristic word processing unit 426 reconstructs the integrated trait expression information using the trait expression information of the employee avatar selected from the trait expression information of all employee avatars. The integrated trait expression information reconstructed in this manner represents the traits of the selected department, sales office, etc. at the company.
[0288] The characteristic expression information may be transferable between identities. The transfer may be by buying and selling or by lending and borrowing. As a result of transferring the characteristic expression information between identities, the content of the characteristic expression information associated with the identity changes, and therefore the characteristics of the identity also change. Such a change in characteristics may allow, for example, an identity such as an avatar to be given new skills, qualifications, etc.
[0289] Furthermore, in the metaverse, an avatar may act as its own characteristic the characteristics of an identity indicated by integrated characteristic expression information obtained by integrating the characteristic expression information of other identities with the characteristic expression information originally corresponding to itself. This allows the avatar in the metaverse to act using newly acquired qualifications. Furthermore, the avatar in the metaverse can act in a way that expresses itself with a different personality than before.
[0290] A modified example of this embodiment will be described below. For example, based on the content of the identity individual information, the identity management device 400A may identify identity elements that the target identity lacks in order to approach a desired identity image, and may make recommendations to the target identity so that the identified identity elements can be acquired. Specifically, if the goal of an avatar as the target identity is to achieve the highest rank in a certain artist's fan club, the identity management device 400A may analyze the corresponding identity individual information and determine that the target identity has attended few live performances by the artist. In this case, the identity management device 400A may recommend to the target identity that the target identity actively participate in the artist's live performances. In this case, the goal set for the identity may be set by the corresponding end user, or may be set by the avatar registration unit 421 or the like based on the avatar's activity history indicated by the content of the identity individual information.
[0291] Furthermore, the identity management device 400A may detect, among multiple avatars corresponding to one end user, avatars whose activity level is below a certain level or whose activity content overlaps, based on the behavioral history of the avatars indicated by the identity individual information corresponding to one end user. The identity management device 400A may recommend to the corresponding end user how to delete the detected avatar or how to make the avatar behave in the future.
[0292] Furthermore, for example, the wallet management unit 425 of the identity management device 400A may manage identities to allocate assets based on their characteristics. These characteristics may be derived by the wallet management unit 425 based on historical information and characteristic expression information of the identity to which assets are allocated. Specifically, consider a case where two avatars, A and B, acting autonomously by AI correspond to one end user, are configured to act in the metaverse to manage the assets of the corresponding end user. In this case, avatars A and B have different investment tendencies based on their past investment experiences. For example, avatar A excels at high-risk, high-return investments, while avatar B tends to invest by steadily accumulating funds. Therefore, the wallet management unit 425 of the identity management device 400A may determine the amount of assets held by the end user that avatars A and B will use for investment, based on the investment tendencies of avatars A and B, to ensure the most efficient investments. In determining such an investment amount, the wallet management unit 425 may use a trained model that has learned the relationship between the results of previous decisions on investment amounts for avatars and the investment effects of the avatars. Note that the wallet management unit 425 may also be configured to manage the investment amount that the end user has determined and allocated to the avatar corresponding to the end user.
[0293] Furthermore, the avatar provision control unit 423 of the identity management device 400A may determine a space (place, country, etc.) and time where the target identity is preferably active, based on the behavioral history and characteristic expression information of the target identity. In this case, the avatar provision control unit 423 may make the determination not only for the identity as an avatar, but also for the identity as a real user. As an example, if the target identity is an AI avatar performing entertainment activities in the metaverse, the avatar provision control unit 423 may determine the activity location and activity time of the target identity based on the number of fans and the fan reactions indicated by the behavioral history of the target identity, and the personality setting (character setting) of the target identity as an entertainer indicated by the characteristic expression information of the target identity. The avatar provision control unit 423 may suggest the determined activity location and activity time to the target identity that is an AI avatar. Alternatively, the avatar provision control unit 423 may control the target identity to be active based on the determined activity location and activity time. Furthermore, such determination of the activity location and activity time may be performed for, for example, multiple identities performing entertainment activities as a group. By having the identity operate according to the location and time of activity determined in this way, it becomes possible to attract a large audience to live performances and to find new, meaningful locations for activities.
[0294] Furthermore, for example, in real space, a person may change the traits and personality they express depending on the person they are communicating with. As a specific example, a person may change the traits and personality they express when communicating with a friend and when communicating with a business partner. With this as a background, while maintaining basic traits for the target identity, the traits presented to the other person may be changed depending on the identity of the person they are communicating with. Control for changing the traits of the target identity depending on the identity of the communication partner in this way may be achieved, for example, by having the feature word processing unit 426 refer to trait expression information and behavioral history of the identity as the communication partner in the metaverse. The feature word processing unit 426 determines the traits expressed by the target identity depending on the trait expression information and behavioral history of the referenced identity as the communication partner. Such trait determination may be achieved using a trained model that has learned traits appropriate for the trait expression information and behavioral history of the identity as the communication partner. The characteristic word processing unit 426 generates characteristic expression information (adapted characteristic expression information) that expresses the determined characteristic using characteristic expression information originally possessed by the target identity. The avatar provision control unit 423 may control the avatar as the target identity to behave, speak, etc. in accordance with the characteristic indicated by the generated adaptive characteristic expression information. Note that changing the characteristic of an identity using such adaptive characteristic expression information may also be applied to communication between real users. In this case, the characteristic word processing unit 426 may refer to the characteristic expression information and behavior history of the communication partner as a real user to determine the characteristic that the target real user should express, and may suggest to the target real user how to act in accordance with the determined characteristic.
[0295] Note that by storing and managing the credential information corresponding to one end user in the credential information wallet WL as shown in Fig. 31, it becomes easy to arbitrarily associate the credential information with the identity (real user, avatar) corresponding to the end user. As a result, for example, the credential information assigned to each identity corresponding to an end user can be shared and used between identities.
[0296] In the above embodiment, an example was given in which an identity (real user, avatar) exists corresponding to one end user. However, in this embodiment, for example, avatars that can be associated with multiple specific or unspecified end users may exist. In this case, the avatar provision control unit 423 may be configured to enable voluntary actions corresponding to all or some of the multiple end users. In this case, the avatar provision control unit 423 may be configured to enable the avatar to act in response to avatar operations performed based on the consensus of multiple end users or avatar operations performed by some end users. In such a case, for example, multiple real user credentials corresponding to multiple end users and a credential information wallet WL storing a predetermined number of avatar credentials may be managed corresponding to multiple end users. In this embodiment, the end user does not need to be limited to an individual. In this embodiment, the end user may be, for example, an organization or group such as a company or organization.
[0297] The identity management system 1A of this embodiment is not limited to the configuration shown in the above embodiment. For example, the end user terminal 300 may be provided with a predetermined functional unit in the identity management device 400A shown in Fig. 21. For example, by providing the end user terminal 300 with functions such as a wallet management unit 425 and a wallet management information storage unit 435 related to the credential information wallet WL, the end user terminal 300 can collectively manage the credential information of the corresponding end users.
[0298] Note that programs for implementing the functions of the above-described avatar generation system 100, end-user terminal 300, identity management device 400A, service providing system 510, VC issuing system 600, and DPKI system 700 may be recorded on a computer-readable recording medium, and the programs may be loaded into a computer system and executed to perform the processing of the above-described avatar generation system 100, end-user terminal 300, identity management device 400A, service providing system 510, VC issuing system 600, and DPKI system 700. Here, "loading a program recorded on a recording medium into a computer system and executing it" includes installing the program into a computer system. The term "computer system" as used herein includes hardware such as an OS and peripheral devices. The term "computer system" may also include multiple computer devices connected via a network, including communication lines such as the Internet, a WAN, a LAN, and a dedicated line. Furthermore, the term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as HDDs and SSDs built into computer systems. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM. Recording media also include internal or external recording media accessible from a distribution server for distributing the program. The program code stored on the distribution server's recording medium may be different from the program code in a format executable by a terminal device. In other words, the format in which the program is stored on the distribution server is not important as long as it can be downloaded from the distribution server and installed in a format executable by a terminal device. Note that the program may be divided into multiple parts, downloaded at different times, and then combined on a terminal device, or each of the divided programs may be distributed by a different distribution server.Furthermore, the term "computer-readable recording medium" also includes a storage medium that stores a program for a certain period of time, such as volatile memory (RAM) within a computer system that acts as a server or client when the program is transmitted over a network. The program may also be a program that realizes part of the above-mentioned functions. Furthermore, the program may be a so-called differential file (differential program) that can realize the above-mentioned functions in combination with a program already stored in the computer system.
[0299] <Notes> (1) One aspect of this embodiment is an identity management system that includes a memory unit that stores identity individual information that corresponds to an identity as a real user existing in the real world and an identity as an avatar that can exist in the metaverse and is individualized corresponding to the identity, and a feature word processing unit that extracts feature words and identifies relationships between the feature words corresponding to the identity based on the content of the identity individual information stored in the memory unit, and generates feature word relationship information that indicates the identified relationships.
[0300] (2) One aspect of this embodiment is the identity management system described in (1), wherein the characteristic word processing unit may score the characteristic words based on the identity individual information when extracting the characteristic words.
[0301] (3) One aspect of this embodiment is an identity management system described in (1) or (2), in which the feature word processing unit may generate feature word relationship display information that can visualize and present the relationships between feature words indicated by the feature word relationship information.
[0302] (4) One aspect of this embodiment is the identity management system described in (3), in which the feature word processing unit may display the results of feature word scoring in a predetermined manner in the feature word relationship display information.
[0303] (5) One aspect of this embodiment is an identity management system described in any one of (1) to (4), in which the characteristic word processing unit may generate, for one identity, multiple characteristic word relationship information corresponding to different characteristics of the identity.
[0304] (6) One aspect of this embodiment is an identity management system described in any one of (1) to (5), in which the feature word processing unit may generate integrated feature word relationship information that integrates multiple feature word relationship information.
[0305] (7) One aspect of this embodiment is the identity management system described in (6), wherein the feature word processing unit may generate the integrated feature word relationship information so as to reconstruct it using a portion of the feature word relationship information selected from the plurality of feature word relationship information used to generate the integrated feature word relationship information.
[0306] (8) One aspect of this embodiment is an identity management system described in any one of (1) to (7), which may further include a matching unit that makes a determination regarding the matching of multiple identities based on the similarity of characteristic word relationship information corresponding to each of the multiple identities that are the target of matching.
[0307] (9) One aspect of this embodiment is the identity management system described in (8), in which the feature word processing unit may generate integrated feature word relationship information that integrates feature word relationship information for each identity matched by the matching unit.
[0308] (10) One aspect of this embodiment is an identity management method in an identity management system, which includes a feature word processing step in which a feature word processing unit extracts feature words and identifies relationships between feature words corresponding to the identities based on the content of the identity individual information stored in a memory unit, which corresponds to an identity as a real user existing in real space and an identity as an avatar that can exist in the metaverse, and generates feature word relationship information indicating the identified relationships.
[0309] (11) One aspect of this embodiment is a program for causing a computer included in an identity management system to function as a feature word processing unit that extracts feature words and identifies relationships between feature words corresponding to an identity based on the content of identity individual information stored in a storage unit, the identity individual information corresponding to an identity as a real user existing in the real space and an avatar that can exist in the metaverse, and is individual corresponding to the identity, and generates feature word relationship information that indicates the identified relationships. (12) One aspect of this embodiment is a non-volatile storage medium that records a program for causing a computer included in an identity management system to function as a feature word processing unit that extracts feature words and identifies relationships between feature words corresponding to an identity based on the content of identity individual information stored in a storage unit, the identity individual information corresponding to an identity as a real user existing in the real space and an avatar that can exist in the metaverse, and is individual corresponding to the identity, and generates feature word relationship information that indicates the identified relationships.
[0310] According to the present invention, the management of qualifications related to identities can be performed efficiently, and the characteristics of identities can be effectively utilized in the activity space of the identities.
[0311] 1, 1A Identity management system 2 Avatar management system 100 Avatar generation system 110 Avatar material provision system 120 Integrated system 200 User interface environment 300 End user terminal 400 Avatar management device 400A Identity management device 401 Communication unit 402, 402A Control unit 403, 403A Storage unit 421 Avatar registration unit 422 Authenticity certification information management unit 423 Avatar provision control unit 424 VC management unit 425 Wallet management unit 431 End user information storage unit 432 Avatar information storage unit 433 Avatar VC storage unit 434 User VC storage unit 435 Wallet management information storage unit 500 Network service environment 510 Service provision system 600 VC issuing system 700 DPKI system
Claims
1. A credential management unit stores a predetermined number of credential pieces of information in a storage unit, associated with a single information storage medium owned by the real user. These include one or more credential pieces of information assigned to an identity as a real user existing in the real space, indicating that the user possesses a predetermined qualification, and one or more credential pieces of information assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse. An identity management system equipped with [features / equipment].
2. The aforementioned credentials include identification information that proves the identity of the aforementioned person. The identity management system according to claim 1.
3. The aforementioned credentials include authenticity certificates that prove the authenticity of the aforementioned identity. The identity management system according to claim 1 or 2.
4. The aforementioned qualifications management department, From among the credential information stored in the aforementioned memory unit, the credential information selected by the real user's operation on the corresponding user terminal is output as the credential information used to verify the identity of the identity to be verified. The identity management system according to claim 1.
5. An identity management method in an identity management system, The credential management step involves the credential management unit storing a predetermined number of credential pieces of information in a storage unit, associated with a single information storage medium owned by the real user. These include one or more credential pieces of information that indicate the user has a predetermined qualification and that are assigned to an identity as a real user existing in the real space, and one or more credential pieces of information that are assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse. An identity management method that includes the following features.
6. Computers in an identity management system A credential management unit stores a predetermined number of credential pieces of information in a storage unit, associated with a single information storage medium owned by the real user. These include one or more credential pieces of information assigned to an identity as a real user existing in the real space, indicating that the user possesses a predetermined qualification, and one or more credential pieces of information assigned to an identity as an avatar that corresponds to the real user and can exist in the metaverse. A program designed to function as such.
7. A memory unit that stores individual identity information corresponding to the identity of a real user existing in the real world and the identity of an avatar that can exist in the metaverse, and which is individual to the identity said, A feature word processing unit, based on the contents of the individual identity information stored in the memory unit, extracts feature words corresponding to the identity, identifies the relationships between the feature words, and generates feature word relationship information indicating the identified relationships. An identity management system equipped with [features / equipment].
8. The feature term processing unit performs scoring of the feature terms based on the individual identity information when extracting the feature terms. The identity management system according to claim 7.
9. The feature word processing unit generates feature word relationship display information that can visualize and present the relationships between feature words indicated by the feature word relationship information. The identity management system according to claim 7 or 8.
10. The feature word processing unit ensures that the result of the feature word scoring is shown in a predetermined manner in the feature word relationship display information. The identity management system according to claim 9.
11. The feature word processing unit generates a plurality of feature word relationship information corresponding to different characteristics of the identity, in response to a single identity. The identity management system according to claim 7.
12. The feature word processing unit generates integrated feature word relationship information by integrating multiple feature word relationship information. The identity management system according to claim 7.
13. The feature word processing unit generates the integrated feature word relationship information by reconstructing it using a selection of feature word relationship information from among the multiple feature word relationship information used to generate the integrated feature word relationship information. The identity management system according to claim 12.
14. The system further includes a matching unit that performs a determination regarding the matching of the multiple identities based on the similarity status of the characteristic word relationship information corresponding to each of the multiple identities targeted for matching. The identity management system according to claim 7.
15. The feature word processing unit generates integrated feature word relationship information by integrating the feature word relationship information for each identity matched by the matching unit. The identity management system according to claim 14.
16. An identity management method in an identity management system, A feature word processing unit performs a feature word processing step in which the feature word processing unit extracts feature words and identifies the relationships between feature words in relation to the identity, based on the content of the individual identity information which is individual in relation to the identity, and identifies the relationships between the feature words in relation to the identity, and generates feature word relationship information which indicates the identified relationships. An identity management method that includes the following features.
17. The computer used by the identity management system The feature word processing unit stores individual identity information in the memory unit, which corresponds to the identity of a real user existing in the real world and the identity of an avatar that can exist in the metaverse. Based on the content of the individual identity information which is individual to the identity, the feature word processing unit extracts feature words corresponding to the identity, identifies the relationships between the feature words, and generates feature word relationship information that shows the identified relationships. A program designed to function as such.