Mobile certificate issuance and verification methods, and servers and systems performing the method
Patent Information
- Application Number
- KR1020230189247
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-12-22
Smart Images

Figure R1020230189247_ABST
Abstract
Description
Technology Field
[0001] A method for issuing and verifying a mobile certificate, and a server and system for performing the same, are disclosed. More specifically, a technology for issuing and verifying a mobile certificate that can manage related data separately is disclosed. Background Technology
[0003] Recently, identity authentication based on mobile data, such as mobile e-wallets and mobile identity verification, is being utilized in various ways. These technologies offer excellent convenience and accessibility, and enable rapid authentication.
[0004] Conventional certificate issuance and verification technologies store and manage personal information on a central server by service providers according to centralized procedures. This method can lead to issues such as data ownership disputes, privacy infringement, fraud, and theft.
[0005] Furthermore, all information required for service provision is effectively stored within a single physical server. To use the service, users must perform identity authentication through separate sign-ups, which creates a problem where the data subject (user) must rely on the service provider. The problem to be solved
[0007] It can perform the issuance and verification of mobile certificates. It can provide independent and decentralized identity authentication. means of solving the problem
[0009] A method for issuing and verifying a mobile certificate according to one embodiment may include: an action of registering public information required for verification in an issuer module; an action of issuing an electronic certificate regarding a holder module in the issuer module; an action of storing the electronic certificate in the holder module; an action of requesting certificate information from the holder module in a verifier module; an action of transmitting the certificate information to the verifier module in the holder module; and an action of verifying the certificate information in the verifier module.
[0010] According to one embodiment, the issuance and verification method can be implemented based on a blockchain system.
[0011] According to one embodiment, the electronic certificate may include the electronic signatures of the issuer module and the owner module.
[0012] According to one embodiment, the certification information may be generated from the owner module based on the electronic certificate.
[0013] According to one embodiment, the verification may be performed based on a combination of the public information and the proof information.
[0014] According to one embodiment, the public information or the certification information may include information regarding the issuer module, the owner module, or the verifier module.
[0015] According to one embodiment, the operation of issuing the electronic certificate or the operation of verifying the certificate information may be performed based on security information of a trust registry, and the trust registry may manage the security information.
[0017] A server for issuing and verifying a mobile certificate according to one embodiment includes one or more processors and a memory for storing instructions, and the processor may be configured to perform the following operations when the instructions are executed: an operation of registering public information required for verification in an issuer module, an operation of issuing an electronic certificate regarding an owner module in the issuer module, an operation of storing the electronic certificate in the owner module, an operation of requesting certificate information from the owner module in a verifier module, an operation of transmitting the certificate information to the verifier module in the owner module, and an operation of verifying the certificate information in the verifier module.
[0019] According to one embodiment, a system for issuing and verifying a mobile certificate includes an issuer module that issues an electronic certificate and registers public information necessary for verification, an owner module that stores the electronic certificate, and a verifier module that verifies the certificate information, wherein the certificate information may be transmitted from the owner module to the verifier module based on a request from the verifier module, and the electronic certificate may be related to the owner module.
[0020] According to one embodiment, the issuance and verification system may be implemented based on a blockchain system.
[0021] According to one embodiment, the electronic certificate may include the electronic signatures of the issuer module and the owner module.
[0022] According to one embodiment, the certification information may be generated from the owner module based on the electronic certificate.
[0023] According to one embodiment, the verification may be performed based on a combination of the public information and the proof information.
[0024] According to one embodiment, the public information or the certification information may include information regarding the issuer module, the owner module, or the verifier module.
[0025] According to one embodiment, the system for issuing and verifying a mobile certificate further includes a trust registry that manages security information, and the electronic certificate is issued based on the security information, and the certificate information can be verified based on the security information. Effects of the invention
[0027] The issuance and verification of mobile certificates can be performed. Independent and decentralized identity authentication can be provided. Brief explanation of the drawing
[0029] FIG. 1 illustrates a system for issuing and verifying mobile certificates according to one embodiment. FIGS. 2a and 2b are block diagrams of a server performing a method for issuing and verifying a mobile certificate according to one embodiment. FIG. 3 is a flowchart illustrating a method for issuing and verifying a mobile certificate according to one embodiment. Figure 4a is a sequence diagram illustrating a scenario for issuing a mobile certificate according to one example. Figure 4b is a sequence diagram illustrating a verification scenario of a mobile certificate according to one example. Specific details for implementing the invention
[0030] Specific structural or functional descriptions of the embodiments are disclosed for illustrative purposes only and may be modified and implemented in various forms. Accordingly, actual implementations are not limited to the specific embodiments disclosed, and the scope of this specification includes modifications, equivalents, or substitutions included in the technical concept described by the embodiments.
[0031] Terms such as "first" or "second" may be used to describe various components, but these terms should be interpreted solely for the purpose of distinguishing one component from another. For example, the first component may be named the second component, and similarly, the second component may be named the first component.
[0032] When it is stated that a component is "connected" to another component, it should be understood that it may be directly connected to or joined to that other component, or that there may be other components in between.
[0033] The singular expression includes the plural expression unless the context clearly indicates otherwise. In this specification, terms such as "comprising" or "having" are intended to specify the existence of the described features, numbers, steps, actions, components, parts, or combinations thereof, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0034] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this specification.
[0035] Hereinafter, embodiments will be described in detail with reference to the attached drawings. In the description with reference to the attached drawings, identical components are given the same reference numeral regardless of the drawing number, and redundant descriptions thereof will be omitted.
[0037] FIG. 1 illustrates a system for issuing and verifying mobile certificates according to one embodiment.
[0038] Referring to FIG. 1, the mobile certificate issuance and verification system (100) may include an issuer module (110), a holder module (120), and a verifier module (130). In one embodiment, the mobile certificate issuance and verification system (100) may be implemented based on a blockchain system.
[0039] The issuer module (110) may issue an electronic certificate and register public information required for verification. The issuer module (110) may register public information required for verification (e.g., public key) in the system (100) and allow the owner module (120) or the verifier module (130) to look it up. For example, the public information may be registered on a public blockchain. The issuer module (110) may issue an electronic certificate. In one embodiment, the electronic certificate may be a certificate regarding the owner module (120). In one embodiment, the electronic certificate may include the electronic signatures of the issuer module (110) and the owner module (120). Verification of the authenticity of the electronic certificate may be performed based on the dual electronic signatures of the issuer module (110) and the owner module (120). In one embodiment, the public information may include information about the issuer module (110), the owner module (120), or the verifier module (130). For example, the issuer module (110) may be a trusted institution such as a government agency, a university, or a bank. The electronic certificate issued by the issuer module (110) may be an identification card, a passport, a degree certificate, or a financial certificate.
[0040] The owner module (120) may store electronic certificates. The owner module (120) may store electronic certificates issued by the issuer module (110) in a storage (e.g., an app storage on a mobile device). The owner module (120) may generate certificate information. The owner module (120) may transmit, provide, or disclose certificate information to the verifier module (130). In one embodiment, the certificate information may be part or all of the information included in the electronic certificate. The certificate information may be generated based on the electronic certificate. In one embodiment, the certificate information may include information about the issuer module (110), the owner module (120), or the verifier module (130). For example, the owner module (120) may be a subject receiving the electronic certificate, such as an individual user.
[0041] The verifier module (130) can verify the proof information. The verifier module (130) may request the owner module (120) to transmit, provide, or disclose the proof information. The verifier module (130) may perform verification based on a combination of the disclosed information and the proof information (e.g., a comparison of whether they match). For example, the verifier module (130) may be a company, government agency, or other service provider providing services. The verifier module (130) may verify the authenticity or validity of the proof information transmitted, provided, or disclosed by the owner module (120).
[0042] In one embodiment, the system (100) may further include a trust registry. The trust registry may receive and manage additional information that the system (100) intends to manage. For example, the trust registry may register and manage security information. The security information may be information related to the issuer module (110). For example, the security information may include a list, detailed information, etc. of the issuer module (110). The security information may be data such as decentralized identifier (DID) information used to ensure reliability in the process of issuing and verifying electronic certificates, or an identifier of security information for electronic certificate verification registered in a trust anchor (or an entry in a tenant list), and may be stored in the trust registry when a registration request is made in advance by the issuer module (110). This registration process can be implemented, for example, in such a way that the issuer module (110) records information that can identify itself and security information in a verifiable form in a trust anchor and provides it to the trust registry, and the trust registry stores this information and then allows each module to query the security information. This is obvious to those skilled in the art in the technical field of DID and electronic certificate management that registers / queries public keys and trust anchors. In one embodiment, the electronic certificate may be issued based on security information, and the certificate information may be verified based on security information. For example, the issuer module (110) may record security information (e.g., DID, certificate schema ID, electronic certificate definition document ID, etc.) as verification material in the trust anchor and then register this security information in the trust registry so that the owner module (120) and the verifier module (130) can query it. The issuer module (110) may cooperate with the owner module (120) at the time of issuance to issue an electronic certificate containing a double electronic signature to the owner module (120).However, at this time, the secret value involved in the owner's electronic signature is not disclosed to the issuer module (110) or the verifier module (130), thereby protecting the owner's privacy. Additionally, the double electronic signature can serve as a basis for the verifier module (130) to subsequently verify that the electronic certificate was issued to a specific owner module (120). For example, the verifier module (130) may request a certificate from the owner module (120) based on the security information of the issuer module (110) registered in the trust registry. The owner module (120) may submit to the verifier module (130) the validity certificate information attached using the secret value used at the time of issuance. To determine the validity of the certificate information generated by the owner module (120), the verifier module (130) may verify the security information of the issuer module (110) described in the certificate request generated by itself by querying the trust anchor. At this time, the verifier module (130) can verify validity using only the security information disclosed by the issuer module (110) without knowing the secret value of the owner module (120). This method of issuing electronic certificates and verifying certification information is obvious to those skilled in the art in the field of electronic identity certification technology. The trust registry may be replaced with other configurations or omitted depending on the configuration and design of the system (100).
[0043] In one embodiment, the system (100) may further include an issuer / verifier agent. The issuer / verifier agent may manage modules newly added to the system (100) (e.g., another issuer module, an owner module, or a verifier module, etc.). For example, the issuer / verifier agent may create and manage virtual agents for the newly added modules. For example, the creation and management of virtual agents by the issuer / verifier agent may be performed during the onboarding process. The issuer / verifier agent may be replaced with a different configuration or omitted depending on the configuration and design of the system (100).
[0044] In one embodiment, no separate interaction may be performed between the issuer module (110) and the verifier module (130). Based on independent operation between the issuer module (110) and the verifier module (130), the privacy of the owner module (120), certification information, or electronic certificate may be protected. The owner module (120) may not transmit, provide, or disclose the entire electronic certificate. The owner module (120) may transmit, provide, or disclose only the necessary information by separately generating certification information. Tracking by the issuer module (110) or access by the verifier module (130) to the electronic certificate may be protected.
[0045] In one embodiment, the system (100) may manage a key that can be used in the issuance or verification process. The key may be managed based on the integration of a hardware security module (HSM), or may be managed based on the encryption of the server itself without using an HSM. In one embodiment, the tenants of the system (100) may be physically separated and allocated, and may be provided through a cloud subscription service. In one embodiment, even if a failure occurs in the system (100), the issuance or verification process may continue to be performed based on peer-to-peer communication. Based on the mobile certificate issuance and verification system according to the present invention, autonomous and flexible mobile certificate issuance and verification may be performed.
[0047] FIGS. 2a and 2b are block diagrams of a server performing a method for issuing and verifying a mobile certificate according to one embodiment.
[0048] Referring to FIG. 2a, a server (200) that performs the issuance and verification method of a mobile certificate may include a communication unit (210), a processor (220), and a memory (230). Referring to FIG. 2b, the server (200) may further include an issuer module (110) (e.g., the issuer module (110) of FIG. 1), an owner module (120) (e.g., the owner module (120) of FIG. 1), and a verifier module (130) (e.g., the verifier module (130) of FIG. 1).
[0049] The communication unit (210) can transmit and receive data by being connected to the processor (220), memory (230), issuer module (110), owner module (120), and verifier module (130). The communication unit (210) can transmit and receive data by being connected to other external devices. In the following, the expression "transmit and receive A" may indicate transmitting and receiving "information or data representing A".
[0050] The communication unit (210) may be implemented as a circuitry within the server (200). For example, the communication unit (210) may include an internal bus and an external bus. As another example, the communication unit (210) may be an element connecting the server (200) and an external device. The communication unit (210) may be an interface. The communication unit (210) may receive data from an external device and transmit the data to the processor (220), memory (230), issuer module (110), owner module (120), and verifier module (130).
[0051] The processor (220) may be configured to perform, when the above instruction is executed, an operation of registering public information required for verification in the issuer module (110), an operation of issuing an electronic certificate regarding the owner module (120) in the issuer module (110), an operation of storing the electronic certificate in the owner module (120), an operation of requesting certification information for the owner module (120) in the verifier module (130), an operation of transmitting certification information to the verifier module (130) in the owner module (120), and an operation of verifying the certification information in the verifier module (130).
[0052] The processor (220) can process data received by the communication unit (210) and data stored in memory (230). The "processor" may be a data processing device implemented in hardware having a circuit having a physical structure for executing desired operations. For example, the desired operations may include code or instructions included in a program. For example, the data processing device implemented in hardware may include a microprocessor, a central processing unit, a processor core, a multi-core processor, a multiprocessor, an Application-Specific Integrated Circuit (ASIC), or a Field Programmable Gate Array (FPGA).
[0053] The processor (220) can execute computer-readable code (e.g., software) stored in memory (e.g., memory (230)) and instructions triggered by the processor (220).
[0054] The memory (230) can store data received by the communication unit (210) and data processed by the processor (220), the issuer module (110), the owner module (120), and the verifier module (130). For example, the memory (230) can store a program (or application, software). The program to be stored may be a set of syntax that is coded to perform the issuance and verification method of a mobile certificate and is executable by the processor (220), the issuer module (110), the owner module (120), and the verifier module (130).
[0055] In one example, the memory (230) may include one or more volatile memory, non-volatile memory and RAM (Random Access Memory), flash memory, hard disk drive and optical disk drive.
[0056] Memory (230) can store a set of instructions (e.g., software) that operate the server (200). The set of instructions that operate the server (200) can be executed by a processor (220), an issuer module (110), an owner module (120), and a verifier module (130).
[0058] FIG. 3 is a flowchart illustrating a method for issuing and verifying a mobile certificate according to one embodiment.
[0059] The following operations 310 to 370 may be performed by a system (e.g., the system (100) of FIG. 1) or a server (e.g., the server (200) of FIG. 2a to 2b). For example, the system (100) may include an issuer module (e.g., the issuer module (110) of FIG. 1), an owner module (e.g., the owner module (120) of FIG. 1), and a validator module (e.g., the validator module (130) of FIG. 1). In one embodiment, the system (100) may be implemented based on a blockchain system. For example, the server (200) may include a communication unit (e.g., the communication unit (210) of FIG. 2a), a processor (e.g., the processor (220) of FIG. 2a), a memory (e.g., the memory (230) of FIG. 2a), an issuer module (110), an owner module (120), and a verifier module (130). In one embodiment, the system (100) or the server (200) may further include a trust registry that manages security information.
[0060] In operation 310, the issuer module (110) may register public information necessary for verification. In one embodiment, the public information may include information about the issuer module (110), the owner module (120), or the validator module (130). For example, the public information may be registered on a public blockchain.
[0061] In operation 320, the issuer module (110) may issue an electronic certificate regarding the owner module (120) to the owner module (120). In one embodiment, the electronic certificate may include the electronic signature of the issuer module (110) or the owner module (120). In one embodiment, the operation of issuing the electronic certificate may be performed based on security information of the trust registry.
[0062] In operation 330, the owner module (120) can store an electronic certificate.
[0063] In operation 340, the verifier module (130) may request proof information from the owner module (120). In one embodiment, the proof information may be part or all of the information included in the electronic certificate.
[0064] In operation 350, the owner module (120) can generate certification information. In one embodiment, the certification information may be generated based on an electronic certificate. In one embodiment, the certification information may include information about the issuer module (110), the owner module (120), or the verifier module (130).
[0065] In operation 360, the owner module (120) can transmit proof information to the verifier module (130).
[0066] In operation 370, the verifier module (130) can verify the certification information. In one embodiment, the verification of the certification information may be performed based on a combination of public information and certification information. In one embodiment, the operation of verifying the certification information may be performed based on security information of the trust registry.
[0067] Based on the method of issuing and verifying mobile certificates, the issuer module (110) and the verifier module (130) are not dependent on each other and can operate independently. The issuer module (110) and the verifier module (130) can perform their respective operations autonomously without being controlled by a specific central authority. The owner module (120), as a data subject, can manage electronic certificates and certification information and use them as needed. Based on the method of issuing and verifying mobile certificates, only minimal certification information is used, and personal information can be protected.
[0069] Figure 4a is a sequence diagram illustrating a scenario for issuing a mobile certificate according to one example.
[0070] Referring to FIG. 4a, a scenario for issuing a mobile certificate can be implemented based on a combination of a user (400), a mobile app (410), a mobile webview (412), a lil (420), a lil server (422), a solution backend (430), a service backend (440), a server agent (442), a singlex SMS (450), an IDP (460), and a U-service (470). In one embodiment, the user (400), the mobile app (410), the mobile webview (412), and the lil (420) can constitute an owner module (e.g., the owner module (120) of FIG. 1).
[0071] In one embodiment, the user (400) can apply for a mobile employee ID card for the U-Service (470). The user (400) can add a certificate to the Mobile App (410), and the Mobile App (410) can run a webview for the Mobile Webview (412). The Mobile Webview (412) can view a list of companies for the Solution Backend (430), and the user (400) can select a specific company (e.g., LGCNS) for the Mobile Webview (412). The Solution Backend (430) can view a list of issued certificates for the Mobile Webview (412). The user (400) can select a mobile employee ID card of a specific company for the Mobile Webview (412). The Mobile Webview (412) can move to lil (420). The user (400) can perform a login for lil (420). lil (420) can request authentication from lil Server (422), and lil Server (422) can issue a token to Mobile Webview (412). Service Backend (440) can request user (400) information from Mobile Webview (412). Service Backend (440) can request user (400) information from lil Server (422). lil Server (422) can send a user (400) response to Service Backend (440). Service Backend (440) can check whether an application is possible for IDP (460). Service Backend (440) can send an error message to Mobile Webview (412) if an application is not possible, and can respond with user (400) information if an application is possible.Mobile Webview (412) can request mobile phone number authentication from Service Backend (440). Service Backend (440) can request Singlex SMS (450) to generate an authentication code. Singlex SMS (450) can send an authentication code SMS to User (400). User (400) can enter the authentication code into Mobile Webview (412). Singlex SMS (450) can respond to Service Backend (440) with the authentication request generation. Service Backend (440) can respond to Mobile Webview (412) with mobile phone number authentication. Mobile Webview (412) can request Service Backend (440) to verify the authentication code. Singlex SMS (450) can request and respond to Service Backend (440) with verification code verification. Service Backend (440) can respond to Mobile Webview (412) with verification code verification. The Mobile Webview (412) can request issuance from the Mobile App (410). The Mobile App (410) can request tenant information lookup from the Solution Backend (430), and the Solution Backend (430) can respond to the tenant information lookup to the Mobile App (410). The Mobile App (410) can request issuance from the Service Backend (440). The Service Backend (440) can request issuance of employee information, card ID acquisition, etc. from the IDP (460). The Service Backend (440) can generate a credential offer and an obb invitation to the Server Agent (442).The Service Backend (440) can process the issuance completion for the IDP (460). The Mobile Webview (412) can delete the connection with the Mobile App (410). The connection of the Mobile App (410) and the connection of the Server Agent (442) can be managed separately. The configuration and implementation method of the mobile certificate issuance scenario is not limited to the described embodiments.
[0073] Figure 4b is a sequence diagram illustrating a verification scenario of a mobile certificate according to one example.
[0074] Referring to FIG. 4b, a verification scenario for a mobile certificate can be implemented based on a combination of a user (400), a mobile app (410), a customer service (480), a solution registry (432), a service backend (440), and an agent (444). In one embodiment, the user (400) and the mobile app (410) can configure an owner module (e.g., the owner module (120) of FIG. 1).
[0075] In one embodiment, a user (400) can access a QR page for Customer Service (480). Customer Service (480) can request a verification QR from Service Backend (440). Service Backend (440) can return QR data to Customer Service (480). The user (400) can perform a QR scan for Mobile App (410). Mobile App (410) can request a verification condition from Solution Registry (432), and Solution Registry (432) can request a verification condition from Service Backend (440). Service Backend (440) can generate a proof-request for Agent (444) and generate an OOB invitation. Agent (444) can invite the Service Backend (440) to an obb invitation, and the Service Backend (440) can respond to the Solution Registry (432) with a verification condition, and the Solution Registry (432) can respond to the Mobile App (410) with a verification condition. The Service Backend (440) can verify and delete the connection to Agent (444). The Service Backend (440) can request verification from Customer Service (480), Customer Service (480) can request a verification result from the Service Backend (440), and the Service Backend (440) can respond to the Customer Service (480) with a verification result. The configuration and implementation method of the mobile certificate issuance scenario is not limited to the described embodiments.
[0077] The embodiments described above may be implemented as hardware components, software components, and / or combinations of hardware and software components. The devices, methods, and components described in the embodiments may be implemented using a general-purpose computer or a special-purpose computer, such as, for example, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a programmable logic unit (PLU), a microprocessor, or any other device capable of executing and responding to instructions. The processing unit may execute an operating system (OS) and software applications executed on said operating system. Additionally, the processing unit may access, store, manipulate, process, and generate data in response to the execution of software. For ease of understanding, the processing unit may be described as being used as a single unit, but those skilled in the art will understand that the processing unit may include multiple processing elements and / or multiple types of processing elements. For example, the processing unit may include multiple processors or one processor and one controller. In addition, other processing configurations, such as parallel processors, are also possible.
[0078] Software may include computer programs, code, instructions, or a combination of one or more of these, and may configure a processing unit to operate as desired or command the processing unit independently or collectively. Software and / or data may be permanently or temporarily embodied in any type of machine, component, physical device, virtual equipment, computer storage medium or device, or transmitted signal wave in order to be interpreted by the processing unit or to provide instructions or data to the processing unit. Software may be distributed over networked computer systems and may be stored or executed in a distributed manner. Software and data may be stored on computer-readable recording media.
[0079] The method according to the embodiment may be implemented in the form of program instructions that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program instructions, data files, data structures, etc., either alone or in combination, and the program instructions recorded on the medium may be those specifically designed and configured for the embodiment or those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc.
[0080] The hardware device described above may be configured to operate as one or more software modules to perform the operation of the embodiment, and vice versa.
[0081] Although the embodiments described above have been explained with reference to limited drawings, those skilled in the art can apply various technical modifications and variations based thereon. For example, appropriate results can be achieved even if the described techniques are performed in a different order than described, and / or if the components of the described system, structure, device, circuit, etc. are combined or assembled in a form different from described, or replaced or substituted by other components or equivalents.
[0082] Therefore, other implementations, other embodiments, and equivalents to the claims also fall within the scope of the claims set forth below.
Claims
Claim 1 A method for issuing and verifying a mobile certificate, comprising: an action of registering public information required for verification on a public blockchain in an issuer module; an action of issuing an electronic certificate regarding a holder module in the issuer module, wherein the electronic certificate includes the electronic signatures of the issuer module and the holder module; an action of storing the electronic certificate in the holder module; an action of requesting certification information from the holder module in a verifier module; an action of transmitting the certification information generated based on the electronic certificate to the verifier module in the holder module; and an action of verifying the certification information based on a combination of the public information and the certification information in the verifier module, wherein the issuer module and the verifier module are each operated by physically separated tenant allocations. Claim 2 In claim 1, the issuance and verification method is a method for issuing and verifying a mobile certificate implemented based on a blockchain system. Claim 3 delete Claim 4 delete Claim 5 delete Claim 6 A method for issuing and verifying a mobile certificate according to claim 1, wherein the public information or the certification information includes information regarding the issuer module, the owner module, or the verifier module. Claim 7 A method for issuing and verifying a mobile certificate according to claim 1, wherein the operation of issuing the electronic certificate or the operation of verifying the certificate information is performed based on security information of a trust registry—the trust registry manages the security information. Claim 8 A computer-readable recording medium containing a program that performs the method of any one of paragraphs 1, 2, 6, and 7. Claim 9 A server for issuing and verifying mobile certificates, comprising one or more processors; and memory for storing instructions, wherein the processors are configured to perform, when the instructions are executed: an operation of registering public information required for verification in a public blockchain in an issuer module; an operation of issuing an electronic certificate regarding an owner module in an issuer module - the electronic certificate includes the electronic signatures of the issuer module and the owner module -; an operation of storing the electronic certificate in an owner module; an operation of requesting certification information from the owner module in a verifier module; an operation of transmitting the certification information generated based on the electronic certificate to the verifier module in an owner module; and an operation of verifying the certification information based on a combination of the public information and the certification information in a verifier module - the issuer module and the verifier module are each operated by physically separated tenant allocations. Claim 10 A system for issuing and verifying mobile certificates, wherein the system comprises: an issuer module that issues an electronic certificate and registers public information necessary for verification on a public blockchain; an owner module that stores the electronic certificate—the electronic certificate relates to the owner module, and the electronic certificate includes the electronic signatures of the issuer module and the owner module—; and a verifier module that verifies certificate information generated based on the electronic certificate based on a combination of the public information and the certificate information, wherein the certificate information is transmitted from the owner module to the verifier module based on a request from the verifier module—the issuer module and the verifier module are each operated by physically separated tenant allocations—a system for issuing and verifying mobile certificates. Claim 11 In Clause 10, the above-mentioned issuance and verification system is a mobile certificate issuance and verification system implemented based on a blockchain system. Claim 12 delete Claim 13 delete Claim 14 delete Claim 15 In paragraph 10, the above-mentioned public information or above-mentioned certification information comprises information regarding the above-mentioned issuer module, the above-mentioned owner module, or the above-mentioned verifier module, a system for issuing and verifying mobile certificates. Claim 16 A system for issuing and verifying mobile certificates according to claim 10, further comprising a trust registry managing security information, wherein the electronic certificate is issued based on the security information, and the certificate information is verified based on the security information.
Citation Information
Patent Citations
Service provider certificate management
KR1020180016398A
Method for mobile identification card authentication service using decentralized identifier based on blockchain networks and user device executing mobile identification card authentication service
KR1020220028870A