Search system, search method, and program

The search system addresses the ambiguity in service accessibility for SSI users by managing and matching service identification information with user-related data from digital certificates, thereby clearly defining available services for users.

WO2025104890A1PCT designated stage expired Publication Date: 2025-05-22NT T INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/041347
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In the context of Self Sovereign Identity (SSI), it is unclear what services a user can access based on their attributes and qualifications, due to the multitude of service providers acting as verifiers.

Method used

A search system that manages service identification information and user-related information, allowing users to receive specific service identification information corresponding to their digital certificates, thereby clarifying available services.

Benefits of technology

The system effectively clarifies which services a user can receive by matching user-related information from digital certificates with available service information, enhancing user accessibility to relevant services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023041347_22052025_PF_FP_ABST
    Figure JP2023041347_22052025_PF_FP_ABST
Patent Text Reader

Abstract

The purpose of the present disclosure is to clarify what kinds of services are available to a user. To this end, the present disclosure is a search system for searching for a predetermined service among a plurality of services, the search system comprising: an available service management unit for associating and managing service identification information for identifying a service and user-related information required for a user to be able to use the service; a reception unit for receiving predetermined user-related information from the user terminal of a predetermined user; and a transmission unit for transmitting, to the user terminal, predetermined service identification information corresponding to the predetermined user-related information in the available service management unit.
Need to check novelty before this filing date? Find Prior Art

Description

Search system, search method, and program

[0001] The present disclosure relates to a search system, a search method, and a program.

[0002] Self-Sovereign Identity (SSI) has been attracting attention in recent years. SSI is an identity management concept (idea) that aims to enable users to manage their own identifiers and identities themselves, without relying on a centralized identity provider (IdP), and to present only information selected at the users' own discretion to recipients such as service providers (Non-Patent Documents 1 and 2).

[0003] Here, the verification mechanism using SSI will be briefly explained using Fig. 8. Fig. 8 is a schematic diagram showing the verification mechanism using SSI. In the world of SSI, there are three parties: Holder, Issuer, and Verifier.

[0004] Holders are users such as students or working adults who create and hold their own decentralized identifiers such as DIDs (Decentralized Identifiers) and register them in databases (DBs) such as distributed repositories or blockchains.

[0005] The Issuer issues digital certificates to schools, hospitals, government institutions, etc., and issues digital certificates such as Verifiable Credentials (VCs) that include the user's distributed identifier, etc., obtained from the user, registers them in a DB, and hands them over to the user. In this case, the Issuer, for example, certifies attribute information such as the user's name and qualification information such as the name of the company to which the user belongs, and then issues a digital certificate (e.g., VC) that includes the attribute information and qualification information.

[0006] The Verifier is a service provider such as a company, and uses a database to verify the attributes and qualifications of the Holder based on the digital certificate presented by the Holder, and determines whether or not to provide the service to the Holder.

[0007] W3C DID (https: / / www.w3.org / TR / did-core / )W3C VC (https: / / www.w3.org / TR / vc-data-model / )

[0008] However, because there are many service providers that act as verifiers, there is a problem in that it is unclear what services can be provided depending on the user's attributes, qualifications, etc.

[0009] The present invention has been made in view of the above circumstances, and has as its object to clarify what services can be provided to a user.

[0010] In order to solve the above problem, the invention of claim 1 is a search system that searches for a specified service from among a plurality of services, and has an available service management unit that associates and manages service identification information for identifying a service with user-related information necessary for a user to use the service, a receiving unit that receives the specified user-related information from the user terminal of the specified user, and a transmitting unit that transmits specified service identification information corresponding to the specified user-related information in the available service management unit to the user terminal.

[0011] As described above, the present invention has the effect of making it clear what services a user can receive.

[0012] FIG. 1 is a schematic diagram of a communication system according to this embodiment, which performs verification using SSI. FIG. 2 is an electrical hardware configuration diagram of a search system, etc. FIG. 3 is a functional configuration diagram of a search system in an embodiment. FIG. 4 is a conceptual diagram of a service type DB. FIG. 5 is a conceptual diagram of an individual activity history DB. FIG. 6 is a sequence diagram showing processing of a communication system according to this embodiment. FIG. 7 is a conceptual diagram showing available service information. FIG. 8 is a schematic diagram showing a mechanism for verification using SSI.

[0013] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0014] [Outline of System of Embodiment] First, an outline of the configuration of a communication system of this embodiment will be described with reference to Fig. 1. Fig. 1 is a schematic diagram of a communication system according to this embodiment.

[0015] As shown in FIG. 1, a communication system 10 of this embodiment is constructed by a search system 30, a service providing system 50, a user terminal 70, and an issuing system 90.

[0016] The search system 30 is constructed by one or more computers and searches for a predetermined service among a plurality of services. More specifically, the search system 30 searches for services available to the user in order to clarify what services the user can receive according to the digital certificate held by the user, and provides the user with available service information including the search results.

[0017] The service providing system 50 is constructed by one or more computers, and provides services such as an EC (Electronic Commerce) site, a company's job application site, a community site, etc. Currently, there are many service providing systems 50, but only one is shown in FIG.

[0018] The user terminal 70 is a computer and a communication terminal used by a user as a Holder. The user terminal 70 may be a laptop PC, desktop PC, tablet terminal, smartphone, smartwatch, or the like. There may be many user terminals 70, but only one is shown in FIG. 1 . The storage area (Digital Identity Wallet) of the user terminal 70 may also store a DID, which is a distributed identifier created by the user himself / herself. Note that the user terminal does not necessarily have to be a terminal located in the user's hand; for example, a configuration in which terminal functions are provided on a cloud platform and the user operates the terminal via remote access is also conceivable.

[0019] The issuing system 90 is constructed by one or more computers and is managed by a certificate issuer acting as an issuer, who issues digital certificates such as VCs and provides them to users. There are many issuing systems 90, but only one is shown in Figure 1.

[0020] Digital certificates include, for example, certificates issued by local governments, driver's licenses, resident registration cards, employee ID cards, student ID cards, transcripts, qualification certificates, diplomas, business cards, financial statements, trademarks, residence cards, and guarantees. Digital certificates include digital certificate identification information, digital certificate type, user attribute information, user qualification information, and certification information. In particular, if a link between a user and a digital certificate is required, a user identifier (such as a distributed identifier) ​​may also be included. The "digital certificate type" indicates the type of digital certificate, such as a certificate issued by a local government, a driver's license, or a resident registration card. The "attribute information" includes the name (which may be anonymous), age, address, and so on. The "qualification information" includes the organization or group to which the user belongs, such as a school or company, school grades, and national qualifications. The "certification information" includes information about the proof issued by the certificate issuer and is used for verification by the Verifier service provider system 50. At least one of the user's attributes (information) and qualifications (information) can also be referred to as "user-related information."

[0021] The search system 30, the service providing system 50, the user terminal 70, and the issuing system 90 can communicate with each other via a communication network 100 such as the Internet or a LAN (Local Area Network). The communication network 100 may be connected wirelessly or by wire. The service providing system 50, the user terminal 70, and the issuing system 90 can access a distributed DB (distributed repository, blockchain, etc.) as shown in FIG. 8.

[0022] [Hardware Configuration] <Hardware Configuration of Search System> Next, the electrical hardware configuration of the search system 30 will be described with reference to Fig. 2. Fig. 2 is a diagram showing the electrical hardware configuration of the search system and the like.

[0023] The computer serving as the search system 30 in FIG. 2 includes a drive device 1000, an auxiliary storage device 1002, a memory device 1003, a CPU 1004, an interface device 1005, a display device 1006, an input device 1007, an output device 1008, and the like, all of which are interconnected by a bus BS.

[0024] The program that realizes the processing on the computer is provided by a recording medium 1001, such as a CD-ROM or a memory card. When the recording medium 1001 storing the program is set in the drive device 1000, the program is installed from the recording medium 1001 to the auxiliary storage device 1002 via the drive device 1000. However, the program does not necessarily have to be installed from the recording medium 1001, but may be downloaded from another computer via the communication network 100. The auxiliary storage device 1002 stores the installed program as well as necessary files, data, etc.

[0025] The memory device 1003 reads and stores the program from the auxiliary storage device 1002 when an instruction to start the program is received. The CPU 1004 realizes the functions related to the device in accordance with the program stored in the memory device 1003. The interface device 1005 is used as an interface for connecting to a communication network, etc. The display device 1006 displays a GUI (Graphical User Interface) or the like according to the program. The input device 1007 is composed of a keyboard, mouse, buttons, a touch panel, etc., and is used to input various operation instructions. The output device 1008 outputs the results of calculations.

[0026] The service providing system 50, the user terminal 70, and the issuing system 90 have the same hardware configuration as the search system 30, and therefore a description thereof will be omitted.

[0027] [Functional Configuration of Search System] Next, the functional configuration of the search system will be described with reference to Fig. 3. Fig. 3 is a functional configuration diagram of the search system in the embodiment.

[0028] 3, the search system 30 includes a transmitting unit 31, a receiving unit 33, a storage unit 35, and a search unit 37. Each of these units has a function realized by an instruction from the CPU 1004 in FIG. 2 based on a program.

[0029] Furthermore, the auxiliary storage device 1002 or the memory device 1003 in FIG. 2 has a service type DB 41 and an available service DB 42 built therein.

[0030] 3, the search system 30 includes the DBs 41 and 42, but may also include a server or the like that stores at least one of the DBs 41 and 42. The service type DB 41 and the available service DB 42 are examples of a service type management unit and an available service management unit, respectively.

[0031] <DB Description> (Service Type DB) FIG. 4 is a conceptual diagram showing a service type DB. As shown in FIG. 4, the service type DB 41 manages the access destination of the site providing the service and the type of service in association with each other. The access destination may be the IP address or URL (Uniform Resource Locator) of the site, or a distributed identifier of the operator of the service providing system 50. Note that when multiple different services are provided by the same service provider, each service ID is different. The service type DB is used to manage information related to services to make search results easier for users to understand, and may manage any service-related information, such as the service type, the service name, or the name of the company operating the service.

[0032] (Available Service DB) Fig. 5 is a conceptual diagram of the available service DB 42. As shown in Fig. 5, the available service DB 42 manages service-related information such as service IDs, availability conditions, and service types, as well as access destinations, in association with each other.

[0033] The service ID is an example of service identification information for identifying a service. The service ID is, for example, a distributed identifier of the operator of the service providing system 50 or the service, or the domain name of the site that provides the service.

[0034] The availability conditions are the conditions necessary to use the service, and indicate the policy of each service (for example, "the type of digital certificate must be a resident registration card," "the issuer of the digital certificate must be the Japanese government," "the digital certificate must include the name and address (any digital certificate that can verify the name and address)," etc.). Also, depending on the service, multiple types of digital certificates may be required. Figure 5 shows that a transcript and a certificate of qualifications are required to use a job application entry service. Although not shown in Figure 5, there may be cases where three or more types of digital certificates are required.

[0035] <Functional Configuration> Next, each functional configuration of the search system 30 will be described with reference to Fig. 3. Fig. 3 is a functional configuration diagram of the search system.

[0036] The transmitting unit 31 transmits data (information) to the service providing system 50 and the user terminal 70 via the communication network 100 .

[0037] The receiving unit 33 receives data (information) from the service providing system 50 and the user terminal 70 via the communication network 100 .

[0038] The storage unit 35 stores the information on the availability conditions received by the receiving unit 33 from the service providing system 50 in the available service DB 42 .

[0039] The search unit 37 searches the available service DB 42 using the combination of the digital certificate and service type received from the user terminal 70 by the receiving unit 33 as a search key, thereby retrieving the corresponding service ID and access destination. The service type is an example of service-related information, which is search auxiliary information used to limit (filter) the search target. In addition to the service type, this search auxiliary information also includes the name of the service operating company, etc.

[0040] For example, if a resident card, a transcript, and a qualification certificate are sent from the user terminal 70 as digital certificates, and a local community, a job application, and EC are sent as service types, the search unit 37 reads out the service ID "d0001" and the access destination "aaaa" corresponding to the resident card and the local community from the available service DB 42. Furthermore, the search unit 37 reads out the service ID "d0002" and the access destination "bbbb" corresponding to the transcript, the qualification certificate, and the job application from the available service DB 42.

[0041] Also, for example, if a transcript is sent from the user terminal 70 as a digital certificate and a job application entry is sent as a type of service, in Figure 5, not only a transcript but also a qualification certificate is required as a condition for use, so the search unit 37 does not read out the service ID "d0002" and the access destination "bbbb" from the available service DB 42.

[0042] 5, there is no combination of resident card and EC from user terminal 70, so search unit 37 does not read out the service ID and access destination from available service DB 42. In the case of a service for which an availability condition is set such as "the digital certificate must contain the name and address (it must be any digital certificate that can verify the name and address)," the information contained in the received digital certificate is analyzed to confirm whether the name and address are included, and if so, the service ID and access destination are read out from available service DB 42.

[0043] [Processing or Operation of the Embodiment] Next, processing or operation of the present embodiment will be described in detail with reference to Fig. 6 and Fig. 7. Fig. 6 is a sequence diagram showing processing of the communication system of the present embodiment.

[0044] <Acquisition of availability conditions> S11: The transmitter 31 of the search system 30 transmits a request for availability conditions of the service to the access destination for each service type stored in advance in the service type DB 41. As a result, the service providing system 50 receives the request for availability conditions.

[0045] S12: The service providing system transmits use condition information including the service ID and use conditions of the service being operated by the service providing system to the search system 30. As a result, the receiving unit 33 of the search system 30 receives the use condition information.

[0046] Note that processes S11 and S12 are a method in which the search system 30 actively accesses the service providing system 50 to collect use condition information. In this case, the search system 30 may use a dedicated protocol prepared by the search system 30 for collecting use conditions, or a dedicated protocol for requesting use conditions provided by the service providing system 50. It is also possible to use an existing protocol for requesting and presenting a digital certificate in SSI format between the holder and the verifier.

[0047] Alternatively, the service providing system 50 may voluntarily transmit the availability condition information to the search system 30. That is, in order to collect the availability condition information, the search system 30 passively waits for the availability condition information from the service providing system 50.

[0048] Regardless of the collection method, the type of service may be added to the use condition information. In this case, the service type DB 41 does not need to manage the type of service.

[0049] S13: In the search system 30, the storage unit 35 associates the availability condition information (service ID and availability conditions) received in processing S12 with the type of service and access destination corresponding to the availability condition information received in processing S12 in the service type DB 41, and stores the information in the available service DB 42.

[0050] <Issuance of a digital certificate> S14: The user terminal 70 sends a request for issuance of a digital certificate to the issuing system 90. This issuance request includes the user's own distributed identifier created by the user of the user terminal 70, but it does not necessarily have to include it. In response, the issuing system 90 receives the issuance request for a digital certificate.

[0051] S15: The issuing system issues a digital certificate and transmits the digital certificate to the user terminal 70, which then receives the digital certificate.

[0052] S16: The user terminal 70 stores the digital certificate received in step S15 in a predetermined storage area (Digital Identity Wallet) constructed in the auxiliary storage device 1002 or memory device 1003 of the user terminal 70.

[0053] <Search for available services> S17: The user terminal 70 sends a request for available services to the search system 30. This request includes multiple types of digital certificates collected by repeatedly performing steps S14 to S16 with multiple issuing systems 90, and information on the types of services to be used to narrow down the search. The receiving unit 33 of the search system 30 then receives the request for available services. Note that this request may also include a single or multiple types of digital certificates collected by performing steps S14 to S16 with a single issuing system 90, and information on the types of services to be used to narrow down the search.

[0054] S18: In the search system 30, the search unit 37 searches the available service DB 42 using the digital certificate (usable conditions) and service type received from the user terminal 70 by the receiving unit 33 as search keys, thereby reading out the corresponding service ID and access destination. Note that the available service DB 42 may not contain a corresponding service ID and access destination.

[0055] S19: The transmitter 31 transmits available service information as shown in Fig. 7 to the user terminal 70 as a response to step S17. As a result, the user terminal 70 receives the available service information. The available service information will now be described with reference to Fig. 7.

[0056] FIG. 7 is a conceptual diagram showing available service information. As shown in FIG. 7, the available service information includes comments to the user and search results. Note that comments to the user do not necessarily need to be included in the available service information. Similar to the available service DB 42, the search results indicate information such as the service ID, availability conditions, service type, and access destination. As a result, the user of the user terminal 70 can see what services are available with the digital certificate they own by displaying and viewing the available service information as shown in FIG. 7.

[0057] <Using a service> S20: At the user's option, the user terminal 70 accesses a site that allows use of a service using the user's own digital certificate. In this case, the user terminal 70 also transmits the digital certificate required to use the service. This allows the user to receive the desired service.

[0058] [Major Effects of the Embodiment] As described above, according to the present embodiment, the search system 30 can provide the user with available service information regarding services that can be used with the digital certificate held by the user. In particular, the search system 30 has the effect of being able to clarify what services the user can receive, based on user-related information, which is at least one of the user's attribute information and qualification information, contained in the digital certificate.

[0059] [Supplementary Note] The present invention is not limited to the above-described embodiment, and may have the following configurations or processes (operations).

[0060] (1) In the above embodiment, in step S17, the user terminal 70 transmits a digital certificate to the search system 30. However, this is not limited to this. For example, a portion of the user-related information (at least one of the user's attributes (information) and qualifications (information)) included in the digital certificate may be transmitted. In this case, the available service DB 42 manages the user-related information as a condition for use, in addition to or instead of a digital certificate such as a resident certificate.

[0061] (2) In the above embodiment, in step S17, the user terminal 70 transmits the service type to the search system 30. However, this service type does not have to be transmitted. In this case, the search unit 37 of the search system 30 uses only the digital certificate (or user-related information) as a search key, and therefore can notify the user of available services without being limited by service type. In this case, the available service DB 42 shown in FIG. 5 does not have to manage service types.

[0062] (3) In the above embodiment, in process 19, the search system 30 transmits available service information including a service ID, availability conditions, service type, and access rights to the user terminal. However, this is not limited to this. For example, if there is a single availability condition, such as "resident registration," the availability conditions may not be included in the available service information. Furthermore, the service type or access destination may not be included in the available service information. If the available service information does not include the service type, the available service DB 42 shown in FIG. 5 may not manage the service type. Furthermore, if the available service information does not include the service type, the available service DB 42 shown in FIG. 5 may not manage the service type. Furthermore, if the available service information does not include the access destination, the available service DB 42 shown in FIG. 5 may not manage the access destination.

[0063] (4) The search system 30 can be realized by a computer and a program, but this program can also be recorded on a (non-transitory) recording medium or provided via the communication network 100.

[0064] (5) In communications between the search system 30 and the service providing system 50 or the user terminal 70, other devices (such as a server or a router) may relay data. For the sake of simplicity, this specification describes, for example, that the transmitting unit 31 of the search system 30 transmits data (information) to the service providing system 50 or the user terminal 70, but this transmission process also includes cases where other devices relay data. Similarly, this specification describes that the receiving unit 33 of the search system 30 receives data (information) from the service providing system 50 or the user terminal 70, but this reception process also includes cases where other devices relay data.

[0065] (6) The CPU 1004 as the processor in FIG. 2 may be a single processor or may be multiple processors.

[0066] REFERENCE SIGNS LIST 10 Communication system 30 Search system 31 Transmission unit 33 Reception unit 35 Storage unit 37 Search unit 41 Service type DB 42 Available service DB 50 Service providing system 70 User terminal (an example of a communication terminal) 90 Issuance system 100 Communication network

Claims

1. A search system for searching for a specific service among a plurality of services, comprising: an available service management unit that manages service identification information for identifying a service in association with user-related information required for a user to use the service; a receiving unit that receives the specific user-related information from a user terminal of the specific user; and a transmitting unit that transmits specific service identification information corresponding to the specific user-related information in the available service management unit to the user terminal.

2. The search system described in claim 1, wherein the available service management unit manages the service identification information and the user-related information in association with service-related information regarding the service, the receiving unit receives the specified user-related information and specified service-related information from the user terminal, and the transmitting unit transmits the specified service identification information corresponding to the set of the specified user-related information and the specified service-related information in the available service management unit to the user terminal.

3. The search system described in claim 1, wherein the available service management unit manages the service identification information and the user-related information in association with an access destination for using the service, the receiving unit receives the specified user-related information from the user terminal, and the transmitting unit transmits to the user terminal the specified service identification information corresponding to the specified user-related information in the available service management unit and information indicating a specified access destination for using the specified service indicated by the specified service identification information.

4. The search system of claim 1, wherein the receiving unit receives multiple types of the specified user-related information from the user terminal, and the transmitting unit transmits the specified service identification information corresponding to any one of the multiple types of the user-related information in the available service management unit to the user terminal.

5. The search system described in claim 4, wherein the available service management unit manages multiple types of user-related information in association with a single service identification information, and the transmission unit transmits the specified service identification information that corresponds to any of the multiple types of user-related information in the available service management unit to the user terminal.

6. A search system as claimed in any one of claims 1 to 5, wherein the search system searches for a predetermined service among the plurality of services that is capable of providing the service to the user through verification using the user's self-sovereign identity.

7. A search method executed by a search system that searches for a specified service among a plurality of services, the search system having an available service management unit that associates and manages service identification information for identifying a service and user-related information necessary for a user to use the service, the search system executing a receiving process of receiving the specified user-related information from a user terminal of the specified user, and a transmitting process of transmitting, in the available service management unit, specified service identification information corresponding to the specified user-related information to the user terminal.

8. A program for causing a computer to execute the method according to claim 7.

Citation Information

Patent Citations

  • Substrate cleaning device and substrate cleaning method

    KR102667272B1