Terminal, system, terminal control method, and storage medium
The terminal and system address the concern of unauthorized biometric information acquisition by acquiring, verifying, and storing biometric information certificates within smartphones, thereby enhancing personal information security.
Patent Information
- Application Number
- PCT/JP2024/037719
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-30
- Filing Date
- 2024-10-23
- Publication Date
- 2025-06-05
AI Technical Summary
There is a concern about unauthorized acquisition of biometric information proof certificates stored in smartphones or similar devices, particularly due to the increasing awareness of personal information protection and the rise of self-sovereign systems.
A terminal and system that acquire a biometric information certification certificate, perform identity verification using the acquired certificate and user biometric information, and store the certificate when verification is successful, thereby preventing unauthorized acquisition.
The solution effectively prevents unauthorized storage of biometric information certificates by ensuring that only valid biometric information is associated with the certificate, thus enhancing personal information security.
Smart Images

Figure JP2024037719_05062025_PF_FP_ABST
Abstract
Description
Terminal, system, terminal control method and storage medium
[0001] The present invention is based on the priority claim of Japanese Patent Application No. 2023-202542 (filed November 30, 2023), the entire contents of which are incorporated herein by reference. The present invention relates to a terminal, a system, a terminal control method, and a program.
[0002] There are technologies for authenticating users.
[0003] For example, the personal authentication system disclosed in Patent Document 1 includes a user terminal and a service provider device that are connected to each other so that they can communicate with each other. In the user terminal, a matching unit matches biometric information input from a sensor with registered biometric information pre-registered in a registered biometric information storage unit, and sends the result to the service provider device as a personal authentication processing result. At this time, a processing certificate generation unit generates certificate information that guarantees the details of the authentication processing or the accuracy of the authentication, and sends it to the service provider device. In the service provider device, a processing certificate verification unit connects various user terminals that perform personal authentication processing using the personal authentication processing result and the certificate information, thereby realizing a system that can provide services according to different levels of accuracy of the personal authentication processing.
[0004] International Publication No. 2007 / 023756
[0005] As disclosed in Patent Literature 1, biometric information is used to verify the identity of a user. Recently, due to growing awareness of personal information protection, systems in which users themselves manage their information (self-sovereign systems) have begun to become widespread. For example, digital content such as identification cards is now being stored in digital wallets on smartphones and other devices. While it is anticipated that biometric certificates will be stored in such digital wallets, there are concerns about fraudulent storage of other people's biometric certificates in digital wallets.
[0006] The main object of the present invention is to provide a terminal, a system, a terminal control method, and a program that contribute to preventing the fraudulent acquisition of biometric information certificates stored in smartphones and the like.
[0007] According to a first aspect of the present invention, there is provided a terminal comprising: an acquisition means for acquiring a biometric certificate from a certificate issuer that holds the user's biometric information, the biometric certificate being a certificate attesting to the biometric information of a recipient, the biometric certificate including the biometric information of the recipient; a verification means for performing identity verification using the biometric information obtained from the acquired biometric certificate and the user's biometric information; and a storage means for storing the acquired biometric certificate when it is determined that the identity verification is successful.
[0008] According to a second aspect of the present invention, there is provided a system including a server device and a terminal managed by a certificate issuer that holds the biometric information of a user, wherein the terminal is equipped with an acquisition means for acquiring from the server device a biometric certificate that certifies the biometric information of the person to whom the certificate is issued and that includes the biometric information of the person to whom the certificate is issued, a verification means for performing identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user, and a storage means for storing the acquired biometric certificate when it is determined that the identity verification is successful.
[0009] According to a third aspect of the present invention, there is provided a method for controlling a terminal, which includes acquiring, at a terminal, a biometric certificate that certifies the biometric information of a recipient from a certificate issuer that holds the biometric information of the user, and which performs identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user, and which stores the acquired biometric certificate if it is determined that the identity verification is successful.
[0010] According to a fourth aspect of the present invention, there is provided a program for causing a computer installed in a terminal to execute the following processes: acquiring a biometric certificate from a certificate issuer that holds the user's biometric information, the biometric certificate being a certificate certifying the biometric information of the person to whom the certificate is issued, the biometric certificate including the biometric information of the person to whom the certificate is issued; performing identity verification using the biometric information obtained from the acquired biometric certificate and the user's biometric information; and, if the identity verification is determined to be successful, storing the acquired biometric certificate.
[0011] According to each aspect of the present invention, there are provided a terminal, a system, a terminal control method, and a program that contribute to preventing the fraudulent acquisition of a biometric certificate stored in a smartphone or the like. Note that the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to the effects described above.
[0012] FIG. 1 is a diagram illustrating an overview of an embodiment. FIG. 2 is a flowchart illustrating an operation of an embodiment. FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating an example of a display of a terminal according to an embodiment of the present disclosure. FIG. 5 is a diagram illustrating an example of an operation of the information processing system according to an embodiment of the present disclosure. FIG. 6 is a diagram illustrating an example of an operation of the information processing system according to an embodiment of the present disclosure. FIG. 7 is a diagram illustrating an example of an operation of the information processing system according to an embodiment of the present disclosure. FIG. 8 is a diagram illustrating an example of an operation of the information processing system according to an embodiment of the present disclosure. FIG. 9 is a diagram illustrating an example of a processing configuration of a terminal according to an embodiment of the present disclosure. FIG. 10 is a flowchart illustrating an example of an operation of an acquisition control unit according to an embodiment of the present disclosure. FIG. 11 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure. FIG. 12 is a diagram illustrating an example of a processing configuration of a carrier terminal according to an embodiment of the present disclosure. FIG. 13 is a flowchart illustrating an example of an operation of a service provision control unit according to an embodiment of the present disclosure. FIG. 14 is a sequence diagram illustrating an example of an operation of the information processing system according to an embodiment of the present disclosure. FIG. 15 is a sequence diagram illustrating an example of an operation of the information processing system according to an embodiment of the present disclosure. FIG. 16 is a diagram illustrating an example of a processing configuration of a terminal according to a modified example of an embodiment of the present disclosure. Fig. 17 is a diagram illustrating an example of a display of a terminal according to a modified example of an embodiment of the present disclosure. Fig. 18 is a diagram illustrating an operation of an information processing system according to a modified example of an embodiment of the present disclosure. Fig. 19 is a diagram illustrating an example of a display of a terminal according to a modified example of an embodiment of the present disclosure. Fig. 20 is a diagram illustrating an example of a display of a terminal according to a modified example of an embodiment of the present disclosure. Fig. 21 is a diagram illustrating an operation of an information processing system according to an embodiment of the present disclosure. Fig. 22 is a diagram illustrating an example of a hardware configuration of a terminal according to the present disclosure.
[0013] First, an overview of one embodiment will be described. Note that the reference numerals in the drawings are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. Connection lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Note that in this specification and drawings, elements that can be similarly described may be assigned the same reference numerals to avoid redundant explanation.
[0014] A terminal 100 according to one embodiment includes an acquisition unit 101, a verification unit 102, and a storage unit 103 (see FIG. 1). The acquisition unit 101 acquires a biometric certificate, which is a certificate attesting to the biometric information of a recipient and includes the biometric information of the recipient, from a certificate issuer that holds the user's biometric information (step S1 in FIG. 2). The verification unit 102 performs identity verification using the biometric information obtained from the acquired biometric certificate and the user's biometric information (step S2). If it is determined that identity verification is successful, the storage unit 103 stores the acquired biometric certificate (step S3).
[0015] When the terminal 100 acquires a biometric certificate, it performs identity verification (identity verification of the user operating the terminal 100) using the biometric information certified by the certificate. If identity verification is successful, the terminal 100 accepts the biometric certificate acquired from the certificate issuer. For example, the terminal 100 stores the acquired biometric certificate in a digital wallet. As a result, a biometric certificate is prevented from being stored in a smartphone or the like of a user whose biometric information differs from the biometric information certified by the biometric certificate. In other words, unauthorized acquisition of a biometric certificate stored in a smartphone or the like is prevented.
[0016] Specific embodiments will be described in more detail below with reference to the drawings.
[0017] First Embodiment The first embodiment will be described in more detail with reference to the drawings.
[0018] [System Configuration] As shown in FIG. 3, the information processing system according to the first embodiment includes at least one certificate issuer and at least one service provider.
[0019] A certificate issuer is an entity that issues certificates to users. For example, a certificate issuer issues a certificate that certifies the "identity" or "attributes" of a user. For example, a certificate issuer issues an identification card that certifies the user's name, gender, date of birth, address, etc.
[0020] Alternatively, a certificate issuer may issue a "biometric certificate" that certifies the "biometric information" of a user's physical characteristics. The biometric certificate certifies that the biometric information included in the certificate is the biometric information of the person to whom it is issued. In other words, the certificate issuer certifies that the biometric information included in the biometric certificate is the biometric information of the person to whom it is issued.
[0021] Examples of biometric information include data (features) calculated from physical characteristics unique to an individual, such as a face, fingerprint, voiceprint, veins, retina, or iris pattern. Alternatively, the biometric information may be image data such as a face image or fingerprint image. The biometric information may be any information that includes the user's physical characteristics. In this disclosure, a case where biometric information related to a person's "face" (a face image or features generated from a face image) is used will be described.
[0022] Alternatively, a certificate issuer may issue a certificate that certifies a user's "rights" or "qualifications." For example, a certificate issuer may issue a "service entitlement certificate" that certifies that a user has the qualification (right) to receive a specified service.
[0023] For example, a public institution that issues identification documents such as driver's licenses, passports, and My Number cards corresponds to a certificate issuer. Alternatively, a company or university that holds facial images of users (employees, students) corresponds to a certificate issuer.
[0024] Alternatively, a business that provides services to users (customers) may be a certificate issuer. For example, a ticket seller that sells airline tickets, train tickets, concert tickets, etc. may be a certificate issuer.
[0025] It should be noted that tickets sold by ticket vendors correspond to the service entitlement certificates mentioned above. In the following explanation, the certificate related to the ticket required for a user to receive a service may be referred to as a "ticket certificate." A ticket certificate is one type of service entitlement certificate.
[0026] Each certificate issuer is equipped with a server device 10. The server device 10 is a server that performs the processes and operations necessary to carry out the business of the certificate issuer. The server device 10 may be managed and operated by the certificate issuer, or may be outsourced to another business entity. The server device 10 may be installed within the certificate issuer's premises, or may be installed on a network (cloud).
[0027] A service provider is a business that provides services to users. As mentioned above, a ticket seller that sells tickets to users is a service provider. Alternatively, a business that operates a theme park or holds a concert is a service provider. Alternatively, a business that operates transportation such as a train, bus, or airplane is a service provider. Alternatively, a business such as a retail store or restaurant is a service provider. Service providers are not limited to private companies, and public institutions such as city halls are also included in the service providers disclosed in this application.
[0028] Depending on the type and business model of the service provider, the same business may operate both as a certificate issuer and as a service provider.
[0029] Each service provider has a service server 20 and a provider terminal 21 for providing services to users. For example, the service server 20 provides services to users via a website. For example, the service server 20 provides online services to users without requiring instructions or operations from employees of the service provider (the service server 20 automatically and autonomously provides the services).
[0030] Alternatively, an employee of the service provider provides the service to the user by operating the business operator terminal 21. The business operator terminal 21 may be a terminal such as a personal computer, a tablet terminal, a POS (Point of Sale) terminal, or a signage terminal.
[0031] Alternatively, the service server 20 and the business operator terminal 21 may be connected, and employees of the service provider may provide services to users while referring to information stored in the service server 20 via the business operator terminal 21.
[0032] A user possesses a terminal 30. For example, the user operates the terminal 30 to request (demand) the issuance of a certificate from a certificate issuer. The user also uses the terminal 30 to provide the service provider with the certificate (e.g., a service entitlement certificate; a ticket certificate) that the service provider requests.
[0033] 3 are connected to a network. Specifically, the server device 10, the service server 20, the operator terminal 21, and the terminal 30 are connected to the network by wired or wireless communication means.
[0034] The configuration of the information processing system shown in FIG. 3 is an example and is not intended to be limiting. For example, the server device 10 of each certificate issuer and the device of the service provider (service server 20, business operator terminal 21) may belong to different networks. Alternatively, each certificate issuer may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10. Similarly, each service provider may include multiple service servers 20 and multiple business operator terminals 21.
[0035] [Overall Operation] Next, an overall operation of the information processing system according to the first embodiment will be described.
[0036] <Preparing a Digital Wallet> The user terminal 30 has a digital wallet function. A digital wallet is an electronic information storage service that guarantees information security such as data integrity, reliability, and availability.
[0037] A user installs an application for realizing a digital wallet on their terminal 30. By opening a digital wallet on terminal 30, the user can store various digital content on terminal 30, such as identification cards such as employee ID cards and student ID cards, ticket certificates such as airline tickets and concert tickets, biometric certificates, electronic money, and credit card information.
[0038] <Acquisition of Digital Content> A user who opens a digital wallet acquires digital content to be stored in the digital wallet.
[0039] A user operates terminal 30 to request a certificate issuer to issue a certificate. Specifically, a digital wallet application requests a certificate issuer to issue a certificate. Some or all certificate issuers issue verifiable credentials (VCs) as certificates, whose contents can be verified online. In the following explanation, VCs will be referred to as "credential certificates."
[0040] By obtaining certificates from each certificate issuer, the user's terminal 30 stores digital content such as that shown in Fig. 4. The digital content stored in the terminal 30 includes a biometric certificate, a passport, a driver's license, a service entitlement certificate (ticket certificate), electronic money, etc.
[0041] When a user opens a digital wallet, the user first obtains a biometric certificate related to the user's biometric information. The user obtains a biometric certificate (VC) that is issued as a credential certificate. The user then obtains an identification card such as an employee ID card or a service entitlement certificate. For example, the user obtains a service entitlement certificate (VC) that is issued as a credential certificate.
[0042] In the following explanation, unless otherwise specified, biometric certificates and service entitlement certificates are considered to be credential certificates.
[0043] <Procedure for obtaining a credential certificate> First, the acquisition of a credential certificate will be explained. The procedure common to the acquisition of a biometric certificate and a service entitlement certificate will be explained as the procedure for obtaining a credential certificate. After that, the procedures that differ between the acquisition of a biometric certificate and a service entitlement certificate will be explained.
[0044] Prior to requesting the issuance of a credential certificate, the user's terminal 30 generates a pair of a public key and a private key. The terminal 30 also generates a decentralized identifier (DID). The terminal 30 registers the generated DID (user ID; holder ID) and public key in the blockchain (step S01 in FIG. 5).
[0045] Furthermore, the user's terminal 30 presents the user ID and requests the certificate issuer (server device 10) to issue a credential certificate. Specifically, the terminal 30 transmits a "certificate issuance request" to the server device 10, which includes information about the certificate to be issued (e.g., the type of credential certificate), information specifying the subject to be certified by the credential certificate, the user ID, etc. (Step S02).
[0046] The server device 10 generates and stores in advance the DID (issuer ID), private key, and public key of the issuer.
[0047] Upon receiving the certificate issuance request, the certificate issuer determines whether or not it is possible to issue the credential certificate desired by the user.
[0048] If the credential certificate desired by the user can be issued, the server device 10 generates a credential certificate including the issuer ID and the user ID.
[0049] Specifically, the server device 10 generates a credential certificate that includes metadata including the credential certificate type, issuing organization name, issuance date and time, validity period, etc., a credential information body, and the issuer's public key information, digital signature, etc. Note that the credential information body describes specific information certified by the issuer.
[0050] The server device 10 transmits the generated credential certificate to the terminal 30 of the user (the user who will become the certificate holder; the person requesting the issuance of the certificate) (certificate issuance; step S03).
[0051] Furthermore, the server device 10 registers the issuer ID and the generated public key, etc. in the blockchain (step S04).
[0052] The terminal 30 stores the received credential certificate in the digital wallet. When storing the credential certificate in the digital wallet, the terminal 30 verifies the identity of the user.
[0053] <Acquisition of Biometric Certificate> A user operates terminal 30 to request the issuance of a biometric certificate from the company, university, etc. to which the user belongs. In other words, the company, university, etc. becomes the issuer of the biometric certificate. Here, a case will be described in which the user requests the company where the user works to issue a biometric certificate related to a "facial image." Terminal 30 acquires a biometric certificate related to a person's face.
[0054] The user's terminal 30 sets "biometric certificate" as the type of certificate to be requested, and sets "employee number" and "facial image" as information identifying the subject to be certified, and sends a "certificate issuance request" for the biometric certificate to the server device 10 (see FIG. 6). Note that the information identifying the subject to be certified may be the user's name or a combination of the user's name and date of birth, etc.
[0055] When requesting the issuance of a biometric certificate, the information identifying the subject to be certified by the biometric certificate includes information identifying the person to whom the biometric certificate is to be issued (e.g., employee number) and the type of biometric information to be certified by the biometric certificate (e.g., facial image).
[0056] If the user requesting the issuance of a biometric certificate is an employee of the company (if there is an employee corresponding to the employee number), the server device 10 generates a biometric certificate (face certificate; face VCs) using the employee's facial image. Note that the credential information body of the biometric certificate stores the facial image acquired when the employee joined the company (the facial image registered in the server device 10 after identity verification at the time of joining the company).
[0057] The server device 10 transmits the generated biometric information certificate (face information certificate; face VCs) to the terminal 30 .
[0058] Upon receiving the biometric information certificate, the terminal 30 performs identity verification of the user. At that time, the terminal 30 acquires the user's biometric information. Specifically, the terminal 30 instructs the user to take a selfie and acquires a facial image of the user.
[0059] The terminal 30 performs identity verification using a face image obtained from the biometric certificate and a face image obtained by taking a selfie. If identity verification is successful, the terminal 30 stores the biometric certificate (face VCs) in the digital wallet.
[0060] If the terminal 30 fails to verify the identity of the user, it discards the acquired biometric information certificate.
[0061] In this way, when the terminal 30 acquires a biometric certificate, it checks whether the biometric information certified by the certificate matches the biometric information of the user (operator) of the terminal 30. If the two sets of biometric information match (if identity verification is successful), the terminal 30 accepts the biometric certificate acquired from an organization or group such as a company or university. As a result, fraudulent attempts by a user to acquire another person's biometric certificate and store that biometric certificate in their own digital wallet are prevented. In other words, spoofing is prevented by the simple method of performing identity verification when storing biometric information in the digital wallet. In this way, the terminal 30 stores the biometric information of the digital wallet holder in the digital wallet as a biometric certificate (a biometric certificate issued as a credential certificate).
[0062] <Acquisition of a service entitlement certificate> When the biometric certificate is stored in the digital wallet, the user acquires a credential certificate other than the biometric certificate. Here, we will explain the example of a user acquiring a service entitlement certificate for a concert ticket from a ticket seller.
[0063] It is assumed that the user has an account with the ticket seller and has already purchased a ticket using that account. When the user purchases a ticket, a ticket ID that identifies the purchased ticket is issued to the ticket purchaser.
[0064] The user's terminal 30 sets the type of certificate to be requested to be issued to "service entitlement certificate" and the information identifying the subject of certification by the service entitlement certificate to "ticket ID," and then sends a "certificate issuance request" regarding the service entitlement certificate to the server device 10 (see Figure 7).
[0065] If a ticket has been purchased by the user who desires to issue a service entitlement certificate (if the ticket ID is valid), the server device 10 generates a service entitlement certificate (ticket certificate) using the ticket information purchased by the ticket purchaser. The entitlement information body of the service entitlement certificate stores information about the ticket purchased by the user (e.g., concert name, concert date and time, concert venue, seat type, etc.).
[0066] The server device 10 transmits the generated service entitlement certificate (ticket certificate) to the terminal 30 .
[0067] Upon receiving the service entitlement certificate (ticket certificate), the terminal 30 performs identity verification of the user. At that time, the terminal 30 acquires the user's biometric information. Specifically, the terminal 30 instructs the user to take a selfie and acquires a facial image of the user.
[0068] The terminal 30 performs identity verification using a face image obtained from a biometric information certificate (face VCs) stored in the digital wallet and a face image obtained by taking a selfie. If identity verification is successful, the terminal 30 stores a service entitlement certificate in the digital wallet.
[0069] If the identity verification fails, the terminal 30 discards the service entitlement certificate.
[0070] In this way, when the terminal 30 acquires the service entitlement certificate, it performs identity verification. This identity verification confirms the identity of the user who has been issued the biometric certificate and the operator of the terminal 30 (the recipient of the service entitlement certificate). As a result, fraud such as a user borrowing another person's terminal 30 and storing a certificate for a ticket (service entitlement certificate) that the user purchased in the digital wallet of the borrowed terminal 30 is prevented. In this way, the terminal 30 stores the service entitlement certificate (service entitlement certificate issued as a credential certificate) of the digital wallet holder in the digital wallet.
[0071] <Enjoying services> By storing the biometric certificate and service entitlement certificate in the digital wallet, the user can receive services from the service provider. In doing so, the user presents the certificate required by the service provider or the certificate necessary for the service provider to provide the service. For example, when attempting to enter a concert venue, the user presents the service entitlement certificate (ticket certificate) to the concert organizer.
[0072] The operation of the information processing system will be explained below using the example of a user entering a concert venue. A business operator terminal 21 is installed at the entrance to the concert venue. An employee of the concert operator operates the business operator terminal 21 to determine whether or not a visitor is allowed to enter. The business operator terminal 21 and terminal 30 communicate with each other via a short-range wireless communication method such as Bluetooth (registered trademark).
[0073] When a user wishes to enter a concert venue, the business operator terminal 21 requests the terminal 30 to perform identity verification. For example, the business operator terminal 21 transmits an "identity verification request" to the terminal 30 (step S11 in FIG. 8).
[0074] When the terminal 30 receives the identity verification request, the terminal 30 captures biometric information (face image) of the operator operating the terminal 30. The terminal 30 then performs identity verification using the captured biometric information and biometric information obtained from the biometric information certificate stored in the digital wallet.
[0075] The terminal 30 transmits the identity verification result (identity verification successful, identity verification failed) to the business operator terminal 21 (step S12).
[0076] When the business operator terminal 21 receives the successful identity verification, it requests the terminal 30 to provide the information (service entitlement certificate) necessary to provide the service to the user.
[0077] Specifically, the business operator terminal 21 transmits a "certificate request" to the terminal 30 (step S13). The certificate request contains information about at least one or more service entitlements required for the service provider to provide the service. For example, the certificate request contains information specifying the service entitlement certificate that the service provider requests to be provided. For example, when the business operator terminal 21 requests the provision of a ticket certificate, information such as the concert name, the date and time of the concert, and the venue of the concert is included in the certificate request.
[0078] In response to receiving the certificate provision request, the terminal 30 transmits the certificate (service entitlement certificate) stored in the digital wallet to the business operator terminal 21. Specifically, the terminal 30 selects a specified certificate (service entitlement certificate) from among the multiple certificates stored in the digital wallet.
[0079] Thereafter, the terminal 30 signs the selected service entitlement certificate using the private key corresponding to the user's DID (user ID), and transmits the signed service entitlement certificate to the provider terminal 21 (step S14).
[0080] The business operator terminal 21 verifies the validity of the received service entitlement certificate. At that time, the business operator terminal 21 acquires a public key from the blockchain (step S15). Details regarding the verification of the validity of the service entitlement certificate will be described later.
[0081] If the terminal 30 has successfully verified the identity of the user and the acquired service entitlement certificate is valid, the provider terminal 21 provides the service to the user. For example, the provider terminal 21 notifies an employee of the service provider that the user is permitted to enter the concert venue.
[0082] The operation of the information processing system when a user receives a service from a service provider has been described above using the example of the service provider using the business operator terminal 21. Even if the service provider uses the service server 20, the basic operation of the information processing system when a user receives a service from the service provider is the same. The service server 20 requests the terminal 30 to perform identity verification. After that, upon receiving notification that identity verification has been successful, the service server 20 obtains from the terminal 30 a service entitlement certificate required for providing the service.
[0083] In this way, the terminal 30 performs identity verification using the biometric certificate stored in the digital wallet before providing the service entitlement certificate to the service provider. As a result, fraudulent practices in which a user who is not eligible to receive a service falsely claims to be eligible to receive the service and receives the service from the service provider are prevented. In other words, simple identity verification at the time of service provision prevents fraudulent impersonation.
[0084] Next, details of each device included in the information processing system according to the first embodiment will be described.
[0085] 9 is a diagram illustrating an example of a processing configuration (processing module) of the terminal 30 according to an embodiment of the present disclosure. Referring to FIG. 9, the terminal 30 includes a communication control unit 201, an acquisition control unit 202, a usage control unit 203, and a storage unit 204.
[0086] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 201. The communication control unit 201 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0087] The communication control unit 201 also supports short-range wireless communication such as Bluetooth (registered trademark) and NFC (Near Field Communication). The communication control unit 201 communicates with the operator terminal 21 using short-range wireless communication.
[0088] The digital wallet application is realized by the modules of the acquisition control unit 202 and the usage control unit 203. Note that detailed explanation of the installation of the digital wallet application will be omitted as the installation of the digital wallet application is obvious to those skilled in the art.
[0089] The acquisition control unit 202 is a means for controlling the acquisition of credential certificates including biometric certificates and service entitlement certificates. The acquisition control unit 202 requests a certificate issuer to issue a certificate selected by the user, and stores the certificate acquired from the certificate issuer in the digital wallet.
[0090] The acquisition control unit 202 has a function as an acquisition unit and a function as a confirmation unit.
[0091] When acquiring a biometric certificate, the acquisition means acquires a biometric certificate that certifies the biometric information of the person to whom the certificate is issued and that includes the biometric information of the person to whom the certificate is issued from a certificate issuer that holds the biometric information of the user. The verification means performs identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user.
[0092] When acquiring a service entitlement certificate, the acquisition means acquires the service entitlement certificate from the certificate issuer, which certifies that the user is entitled to receive the service. In response to the acquisition of the service entitlement certificate, the verification means performs identity verification using the biometric information obtained from the stored biometric information certificate and the biometric information of the user.
[0093] 10 is a flowchart showing an example of the operation of the acquisition control unit 202. The operation of the acquisition control unit 202 according to the embodiment of the present disclosure will be described with reference to FIG.
[0094] When a user who has opened a digital wallet starts the digital wallet application and performs a predetermined operation (for example, pressing the certificate issuance button), the acquisition control unit 202 controls the acquisition of the credential certificate desired by the user.
[0095] First, the acquisition control unit 202 generates a pair of a public key and a private key and a user ID (user DID), which is a distributed identifier. The acquisition control unit 202 registers the generated user ID and public key in the blockchain (registering the public key, etc.; step S101).
[0096] Next, the acquisition control unit 202 acquires information necessary for requesting issuance of a credential certificate using a GUI or the like (acquisition of necessary information; step S102).
[0097] Specifically, the acquisition control unit 202 acquires information about the certificate issuer that has the authority to issue the credential certificate that the user desires (e.g., company name, university name, ticket seller name), the type of certificate desired (e.g., biometric certificate, service entitlement certificate), etc. Furthermore, the acquisition control unit 202 acquires information that the certificate issuer uses to identify the subject of certification (e.g., employee number and face image, ticket ID, etc.).
[0098] The acquisition control unit 202 notifies the certificate issuer of the acquired necessary information and user ID. Specifically, the acquisition control unit 202 notifies the certificate issuer of the type of credential certificate, information for identifying the certificate subject, and the user ID.
[0099] The acquisition control unit 202 sends a "certificate issuance request" including the type of credential certificate, information identifying the certificate subject, user ID, etc. to the server device 10 of the certificate issuer selected by the user (step S103).
[0100] The acquisition control unit 202 receives a response (positive response or negative response) to the certificate issuance request from the server device 10 (step S104).
[0101] If a negative response is received indicating that the certificate issuance has failed (step S105, No branch), the acquisition control unit 202 notifies the user that the credential certificate has not been issued (notification of non-issuance; step S106).
[0102] If an affirmative response indicating that the certificate has been successfully issued is received (step S105, branch Yes), the acquisition control unit 202 executes identity verification of the user (step S107).
[0103] When the user requests the issuance of a biometric information certificate, the acquisition control unit 202 acquires biometric information from the biometric information certificate included in the positive response received from the server device 10. That is, the acquisition control unit 202 acquires biometric information (face image) from the main body of the qualification information of the biometric information certificate.
[0104] When the user requests the issuance of a certificate (service entitlement certificate) other than a biometric certificate, the acquisition control unit 202 acquires biometric information (face image) from the biometric certificate stored in the digital wallet.
[0105] When the biometric information is acquired from the received or stored biometric certificate, the acquisition control unit 202 acquires the biometric information of the user (the operator of the terminal 30). For example, the acquisition control unit 202 prompts the user to take a picture of their own face using a GUI (Graphical User Interface) or the like (acquiring a face image by taking a selfie).
[0106] The acquisition control unit 202 executes a matching process (authentication process; one-to-one authentication) using the biometric information obtained from the biometric information certificate and the biometric information of the user. The acquisition control unit 202 determines whether the two pieces of biometric information substantially match.
[0107] Specifically, the acquisition control unit 202 generates feature amounts from each of the two face images.
[0108] Since existing technology can be used for the process of generating feature amounts, detailed description thereof will be omitted. For example, the acquisition control unit 202 extracts the eyes, nose, mouth, etc. from the face image as feature points. Then, the acquisition control unit 202 calculates the positions of the feature points and the distances between the feature points as feature amounts (generating a feature vector consisting of multiple feature amounts).
[0109] Next, the acquisition control unit 202 executes a matching process (authentication process) using the two generated feature amounts. Specifically, the acquisition control unit 202 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the acquisition control unit 202 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
[0110] If the similarity is greater than a predetermined value (if the distance is shorter than a predetermined value), the acquisition control unit 202 determines that the identity verification has been successful. If the similarity is equal to or less than the predetermined value, the acquisition control unit 202 determines that the identity verification has failed.
[0111] If the identity verification fails (step S108, No branch), the acquisition control unit 202 notifies the user that the credential certificate cannot be stored in the digital wallet (notification of non-storage; step S109). The acquisition control unit 202 also discards the acquired credential certificates (biometric information certificate, service entitlement certificate). Note that when the credential certificates are discarded, the acquisition control unit 202 may notify the server device 10, which is the sender of the credential certificates, of this fact.
[0112] If the identity verification is successful (step S108, branch Yes), the acquisition control unit 202 stores the credential certificate (biometric information certificate, service entitlement certificate) received from the certificate issuer in the digital wallet (step S110).
[0113] The usage control unit 203 is a means for controlling the usage of digital content (credentials) stored in the digital wallet.
[0114] The usage control unit 203 performs identity verification using biometric information obtained from the biometric information certificate stored in the digital wallet, and if identity verification is successful, it functions as a providing means to provide the stored service entitlement certificate to the service provider.
[0115] The usage control unit 203 performs identity verification in response to a request from the service provider, and provides a certificate stored in the digital wallet that is specified by the service provider.
[0116] Specifically, the usage control unit 203 processes the identity verification request and the certificate provision request received from the service provider's device (service server 20, business operator terminal 21).
[0117] When receiving the personal identification request, the usage control unit 203 acquires biometric information (for example, a facial image) of the operator of the device using a GUI, etc. The usage control unit 203 takes a picture of the operator's face by taking a selfie.
[0118] The usage control unit 203 performs identity verification using the acquired biometric information and biometric information obtained from the biometric information certificate stored in the digital wallet. The usage control unit 203 performs identity verification in the same way as the acquisition control unit 202.
[0119] The usage control unit 203 notifies the business operator terminal 21, etc. of the identity verification result (identity verification successful, identity verification failed). If identity verification is successful, the usage control unit 203 transmits a positive response indicating that to the business operator terminal 21, etc. If identity verification is unsuccessful, the usage control unit 203 transmits a negative response indicating that to the business operator terminal 21, etc.
[0120] In this way, the usage control unit 203, in response to a request from the service provider, performs identity verification using biometric information obtained from a biometric certificate acquired in advance and the biometric information of the operator operating the device.
[0121] Upon receiving the certificate provision request, the usage control unit 203 selects a credential certificate (service entitlement certificate) designated by the service provider from among the multiple credential certificates stored in the digital wallet, and then signs the selected service entitlement certificate using a private key corresponding to the user's DID (user ID).
[0122] The usage control unit 203 signs the service entitlement certificate using a private key (a private key corresponding to the user ID) generated when the service entitlement certificate requested by the service provider is issued. For example, when a user enters a concert venue, the usage control unit 203 signs the ticket certificate (service entitlement certificate) using a private key corresponding to the user ID transmitted to the server device 10 of the ticket seller.
[0123] If the service entitlement certificate designated by the service provider can be provided, the usage control unit 203 transmits an affirmative response including the signed service entitlement certificate to the business operator terminal 21, etc. If the service entitlement certificate designated by the service provider cannot be provided, the usage control unit 203 transmits a negative response indicating that the service entitlement certificate cannot be provided to the business operator terminal 21, etc.
[0124] The storage unit 204 is a means for storing information necessary for the operation of the terminal 30. The storage unit 204 stores certificates issued by each certificate issuer in a digital wallet.
[0125] When the acquisition control unit 202 determines that the identity verification is successful, the storage unit 204 stores the biometric information certificate acquired by the acquisition control unit 202. When the acquisition control unit 202 determines that the identity verification is successful, the storage unit 204 stores the service entitlement certificate acquired by the acquisition control unit 202.
[0126] In this way, the memory unit 204 stores a biometric information certificate, which is a certificate that proves that the information is the biometric information of the person to whom it is issued and contains the biometric information of the person to whom it is issued, and a service entitlement certificate, which proves that the user is eligible to receive a service.
[0127] Furthermore, the storage unit 204 stores information about each certificate issuer (such as the name of the certificate issuer and the address of the server device 10).
[0128] 11 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure. Referring to FIG. 11, the server device 10 includes a communication control unit 301, a certificate issuing unit 302, and a storage unit 303.
[0129] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 30. The communication control unit 301 also transmits data to the terminal 30. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 301. The communication control unit 301 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0130] The certificate issuing unit 302 is a means for issuing a credential certificate to a user. The certificate issuing unit 302 processes a “certificate issuance request” received from the terminal 30.
[0131] When a certificate issuance request is received, the certificate issuance unit 302 searches a database (not shown in Figure 11, etc.) that stores user information using information for identifying the subject of certification included in the certificate issuance request (e.g., employee number, facial image, ticket ID) as a key.
[0132] If the certificate issuing unit 302 fails in the search (for example, the corresponding user's facial image is not registered in the database, or the corresponding ticket ID does not exist), it sends a negative response to the terminal 30 indicating that the certificate issuance has failed.
[0133] If the search is successful, the certificate issuing unit 302 determines, as necessary, whether or not the credential certificate desired by the user can be issued.
[0134] For example, when a biometric certificate is requested, the certificate issuing unit 302 determines that a biometric certificate cannot be issued for a face image that has not been updated for a long period of time. Note that the certificate issuing unit 302 may determine that a biometric certificate can be issued if the face image is registered in the database, regardless of the registration period of the face image.
[0135] Alternatively, if the ticket purchased by the ticket purchaser is valid (for example, if the concert has not yet started), the certificate issuing unit 302 determines that a ticket certificate (service entitlement certificate) can be issued. On the other hand, if the concert has already started, the certificate issuing unit 302 determines that a ticket certificate cannot be issued.
[0136] Note that detailed explanations regarding the management of employees and tickets will be omitted, as such explanations are outside the scope of the present disclosure.
[0137] If a credential certificate cannot be issued to the user, the certificate issuing unit 302 transmits a negative response to the terminal 30 indicating that the certificate issuance has failed (certificate issuance is not possible).
[0138] If it is possible to issue a credential certificate to the user, the certificate issuing unit 302 generates a certificate (credential certificate; for example, a biometric information certificate or a service entitlement certificate) to be issued to the user. The certificate issuing unit 302 generates a credential certificate including an issuer ID and a user ID (DID of the person to whom the certificate is to be issued; the user ID included in the certificate issuance request).
[0139] Specifically, the certificate issuing unit 302 generates a credential certificate (VCs) that includes metadata including the type of credential certificate, the issuing organization name, the date and time of issue, the validity period, etc., the qualification information body, the issuer's public key information, the digital signature, etc. The digital signature affixed to the credential certificate is issued using a private key corresponding to the issuer ID generated in advance.
[0140] The certificate issuing unit 302 transmits the generated credential certificate to the terminal 30. Furthermore, the certificate issuing unit 302 registers the issuer ID, public key, etc., which have been generated in advance, in the blockchain.
[0141] The storage unit 303 is a means for storing information necessary for the operation of the server device 10. A database for storing information necessary for issuing a credential certificate (e.g., employee ID number, facial image, etc.) is constructed in the storage unit 303.
[0142] 12 is a diagram illustrating an example of a processing configuration (processing module) of the provider terminal 21 according to an embodiment of the present disclosure. Referring to FIG. 12, the provider terminal 21 includes a communication control unit 401, a service provision control unit 402, and a storage unit 403.
[0143] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the terminal 30. The communication control unit 401 also transmits data to the terminal 30. The communication control unit 401 passes data received from other devices to other processing modules. The communication control unit 401 transmits data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data to and from other devices via the communication control unit 401. The communication control unit 401 has a function as a receiving unit that receives data from other devices and a function as a transmitting unit that transmits data to other devices.
[0144] The service provision control unit 402 is a means for executing control relating to the services provided to the user.
[0145] When a user requests the provision of a service, the service provision control unit 402 requests the terminal 30 to verify the identity of the user. If the identity verification is successful, the service provision control unit 402 obtains a certificate (e.g., a ticket certificate) required to provide the service.
[0146] The operation of the service provision control unit 402 will be described with reference to FIG.
[0147] The service provision control unit 402 transmits a request for identity verification to the user's terminal 30 (step S201). The service provision control unit 402 requests the terminal 30 to perform identity verification in response to an operation by an employee of the service provider or the like.
[0148] When a negative response (identity verification failed) is received from the terminal 30 (step S202, No branch), the service provision control unit 402 notifies the user, employees of the service provider, etc. that the service cannot be provided due to a failure in identity verification (step S203).
[0149] When an affirmative response (identification success) is received from the terminal 30 (step S202, branch Yes), the service provision control unit 402 acquires information (service entitlement certificate) necessary to provide the service to the user.
[0150] Specifically, the service provision control unit 402 transmits a "certificate provision request" to the terminal 30 (step S204). The service provision control unit 402 transmits the certificate provision request to the terminal 30, including information specifying the required service credential certificate (for example, if a ticket certificate is required to provide the service, information such as the concert name, the date and time of the concert, etc.).
[0151] If a negative response (certificate cannot be provided) is received from the terminal 30 (step S205, No branch), the service provision control unit 402 notifies the user, etc. that the service cannot be provided because the necessary information cannot be obtained (step S203).
[0152] If a positive response (a response including a service entitlement certificate) is received from the terminal 30 (step S205, Yes branch), the service provision control unit 402 verifies the validity of the service entitlement certificate included in the positive response (verify validity; step S206).
[0153] The service provision control unit 402 verifies at least one of the four items related to the validity of the service entitlement certificate.
[0154] The first item is verification of the electronic signature attached to the service entitlement certificate.
[0155] In this case, the service provision control unit 402 acquires the issuer ID and user ID written on the service entitlement certificate. The service provision control unit 402 acquires a public key corresponding to the acquired issuer ID from the blockchain. Similarly, the service provision control unit 402 acquires a public key corresponding to the acquired user ID from the blockchain.
[0156] The service provision control unit 402 verifies the signature of the holder (user desiring to receive the service) and the signature of the issuer attached to the service credential. By verifying these signatures, the service provision control unit 402 confirms that the service credential acquired from the user (holder of the service credential) has not been tampered with and is a certificate issued by a reliable issuer.
[0157] If the service provision control unit 402 succeeds in verifying the signatures of the holder and issuer of the service credential, it determines that the service credential is valid.
[0158] The second item is verification that the service entitlement certificate has not been set to invalid.
[0159] In this case, the service provision control unit 402 accesses the blockchain and confirms that the received service credential is not listed in the certificate issuer's revocation list. The service provision control unit 402 confirms that the service credential obtained from the user has not been invalidated by the issuer before its expiration date arrives.
[0160] If the service entitlement certificate is not written in the invalidation list, the service provision control unit 402 determines that the acquired service entitlement certificate is valid.
[0161] The third item is verification that the validity period (expiration date) of the service entitlement certificate has not expired.
[0162] The service provision control unit 402 checks the validity period set in the service entitlement certificate. If the validity period set in the service entitlement certificate has not expired, the service provision control unit 402 determines that the acquired service entitlement certificate is valid.
[0163] The fourth item is verification of the qualification information attested by the service entitlement certificate.
[0164] In this case, the service provision control unit 402 reads the qualification information (e.g., ticket information) from the qualification information body contained in the service enjoyment certificate, and determines whether the user has the authority (qualification) to receive the service based on the qualification information.
[0165] For example, if the concert date, time, and concert venue obtained from the ticket information are correct, the service provision control unit 402 determines that the user has the authority to receive the service (qualification to enter the concert venue). On the other hand, if the concert date, time, and concert venue obtained from the ticket information are incorrect, the service provision control unit 402 determines that the user does not have the authority to receive the service (qualification to enter the concert venue).
[0166] If the user has the authority to receive the service, the service provision control unit 402 determines that the acquired service entitlement certificate is valid.
[0167] The service provision control unit 402 determines that the service entitlement certificate obtained from the user is valid if it determines that the service entitlement certificate is valid in a predetermined item from items 1 to 4, depending on the business and type of the company (service provider).
[0168] For example, the service provision control unit 402 determines that the acquired service enjoyment credential is valid (accepts the service enjoyment credential) when it is determined that the "service enjoyment credential is valid" in each of the four items. Alternatively, the service provision control unit 402 may determine that the acquired service enjoyment credential is valid when it is determined that the "service enjoyment credential is valid" in two items, the first item and the fourth item.
[0169] If the service entitlement certificate is not valid (step S207, No branch), the service provision control unit 402 notifies the user or the like that the service cannot be provided because the service entitlement certificate is invalid (step S203).
[0170] If the service entitlement certificate is valid (step S207, Yes branch), the service provision control unit 402 provides the service to the user (step S208).
[0171] For example, the service provision control unit 402 notifies the user or an employee of the service provider that they are allowed to enter the concert venue.
[0172] A detailed description of the individual service offerings will be omitted, as a detailed description of the services unique to each service provider is outside the scope of the present disclosure.
[0173] The storage unit 403 is a means for storing information necessary for the operation of the business operator terminal 21 .
[0174] [Service Server] Detailed description of the configuration and operation of the service server 20 will be omitted. The basic configuration and operation of the service server 20 can be the same as the configuration and operation of the operator terminal 21. The operator terminal 21 communicates with the terminal 30 via short-range wireless communication such as Bluetooth (registered trademark) to acquire a credential certificate. In contrast, the service server 20 communicates with the terminal 30 via a communication network such as the Internet to acquire a credential certificate. If the terminal 30 has successfully authenticated its identity and successfully verified the validity of the credential certificate (service enjoyment qualification certificate) required to provide the service, the service server 20 provides the service to the user.
[0175] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described.
[0176] 14 is a sequence diagram illustrating an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding certificate issuance will be described with reference to FIG.
[0177] The terminal 30 generates a public key, a private key, and a user ID, and registers the user ID and public key in the blockchain (step S21).
[0178] The terminal 30 transmits a certificate issuance request including the user ID to the server device 10 of the certificate issuer (step S22).
[0179] The server device 10 generates qualification information for the user (the person to whom the credential certificate is to be issued) and generates a credential certificate including the generated qualification information (step S23). The server device 10 generates a credential certificate including the user ID and the issuer ID and having a digital signature attached.
[0180] The server device 10 transmits the generated credential certificate to the terminal 30 (step S24).
[0181] The terminal 30 performs identity verification (step S25).
[0182] When the terminal 30 receives a biometric certificate, the terminal 30 performs identity verification using the biometric information recorded on the received biometric certificate and the biometric certificate obtained by taking a selfie. When the terminal 30 receives a service entitlement certificate, the terminal 30 performs identity verification using the biometric information recorded on the biometric certificate stored therein and the biometric certificate obtained by taking a selfie.
[0183] If the identity verification is successful, the terminal 30 stores the credential certificate in the digital wallet (step S26).
[0184] 15 is a sequence diagram illustrating an example of the operation of the information processing system according to the embodiment of the present disclosure. The operation of the information processing system according to the first embodiment regarding the use of a certificate will be described with reference to FIG.
[0185] The service provider's device (business operator terminal 21 in FIG. 15) transmits a request for personal identification to terminal 30 (step S31).
[0186] The terminal 30 performs identity verification using biometric information obtained from the biometric certificate stored in the terminal 30 and biometric information obtained by photographing the operator of the terminal 30, and transmits the identity verification result to the server device 10 (step S32).
[0187] When the business operator terminal 21 receives the successful identity verification, it transmits a certificate provision request specifying the required service entitlement certificate to the terminal 30 (step S33).
[0188] The terminal 30 reads out the service entitlement certificate designated by the service provider from the digital wallet, and transmits the signed service entitlement certificate to the business operator terminal 21 (step S34).
[0189] The business operator terminal 21 determines the validity of the acquired service entitlement certificate (step S35).
[0190] If the service entitlement certificate is valid, the business operator terminal 21 provides the service to the user (step S36).
[0191] Next, a modification of the first embodiment will be described.
[0192] <Modification 1> The terminal 30 may verify the identity of the user when the digital wallet is used for the first time, etc. In this case, the terminal 30 includes an identity verification unit 205 (see FIG. 16).
[0193] The identity verification unit 205 is a means for verifying the identity of the creator of a digital wallet. The identity verification unit 205 verifies the identity of the creator of the digital wallet by using biometric information obtained from the identification card and the biometric information of the creator who opens the digital wallet. More specifically, the identity verification unit 205 verifies that the creator of the digital wallet and the holder (issuer) of the identification card issued by a public institution are the same person.
[0194] The identity verification unit 205 acquires biometric information from an identification card held by the user when the digital wallet is opened (first startup) or at any time. For example, the identity verification unit 205 acquires biometric information from an IC (Integrated Circuit) chip mounted on a My Number card or passport. Alternatively, the identity verification unit 205 may instruct the user to take a photo of the identification card and acquire biometric information from image data showing the identification card.
[0195] Furthermore, the personal identification unit 205 acquires biometric information of the user. For example, the personal identification unit 205 acquires a face image by taking a selfie.
[0196] The identity verification unit 205 acquires biometric information from the identification card and, upon acquiring the biometric information of the user operating the device, performs identity verification using the two pieces of biometric information. If identity verification is successful, the identity verification unit 205 considers that the person who was issued the identification card and the user of the terminal 30 are the same person, and permits the user to use the digital wallet.
[0197] The terminal 30 may generate a biometric certificate using biometric information acquired when opening a digital wallet, etc. In this case, the identity verification unit 205 passes the biometric information acquired from an identification card or biometric information obtained by a selfie to the acquisition control unit 202. The acquisition control unit 202 generates a biometric certificate using the biometric information and stores it in the digital wallet. In this way, when identity verification using an identification card is successful, the terminal 30 may generate a biometric certificate using the biometric information obtained from the identification card or the biometric information obtained by a selfie.
[0198] Alternatively, the terminal 30 may transmit biometric information acquired from an identification card when opening a digital wallet or the like to the server device 10, and request the server device 10 to issue a biometric certificate using the biometric information acquired from the identification card. Specifically, the terminal 30 transmits a certificate issuance request including the biometric information acquired from the identification card to the server device 10. In response to receiving the certificate issuance request, the server device 10 generates a biometric certificate using the biometric information acquired from the identification card. The server device 10 transmits the generated biometric certificate to the terminal 30. In this way, a biometric certificate may be issued using biometric information read by the terminal 30 from an official identification card or the like in response to a user's operation, instead of biometric information held by an organization such as a company or university.
[0199] <Modification 2> In the above embodiment, the terminal 30 stores in the digital wallet biometric information recorded on a biometric information certificate obtained from a company, etc. However, the terminal 30 may store in the digital wallet biometric information obtained from an identification document such as a My Number card or a passport.
[0200] When the acquisition control unit 202 receives a biometric information certificate from the server device 10 of a company or the like, it acquires the biometric information (facial image) included in the biometric information certificate. The acquisition control unit 202 performs one-to-one matching using the biometric information stored when the digital wallet was opened (biometric information obtained from an identification card issued by a public institution) and the biometric information obtained from the biometric information certificate.
[0201] If the one-to-one matching is successful (if the two pieces of biometric information are substantially the same), the acquisition control unit 202 stores the biometric information certificate in the digital wallet.
[0202] Alternatively, when requested by a service provider to perform identity verification, the usage control unit 203 of the terminal 30 may perform identity verification using biometric information obtained from an identification card (biometric information stored when the digital wallet was opened).
[0203] <Modification 3> When the server device 10 receives a request for issuing a biometric certificate, the server device 10 may perform identity verification of the user. When requesting issuance of a biometric certificate, the terminal 30 transmits a certificate issuance request to the server device 10, the request including image data showing an identification card held by the user, for example.
[0204] The certificate issuing unit 302 of the server device 10 extracts biometric information from image data of an identification card. The certificate issuing unit 302 performs one-to-one matching using the extracted biometric information and biometric information managed in the company's database (biometric information of employees identified by employee numbers, etc.).
[0205] If the one-to-one matching is successful (if the two pieces of biometric information are substantially the same), the certificate issuing unit 302 issues a biometric information certificate using one of the two pieces of biometric information.
[0206] <Modification 4> When providing a service to a user, the service provider may obtain a biometric certificate from the terminal 30. For example, a ticket seller may obtain a biometric certificate when selling a ticket.
[0207] In this case, the service server 20 of the ticket seller designates the biometric information certificate as the certificate required to provide the service, and transmits a certificate provision request to the terminal 30 .
[0208] The service server 20 acquires a biometric certificate from the terminal 30 by transmitting a certificate provision request. The service server 20 confirms the validity of the acquired biometric certificate. After confirming the validity of the biometric certificate, the service server 20 acquires biometric information (e.g., a facial image) from the certificate. The service server 20 stores the acquired facial image. For example, the service server 20 of a ticket seller stores the ticket information and the facial image in association with each other in the user's account.
[0209] The service server 20 can provide services to the user by utilizing the acquired biometric information. For example, the service server 20 may issue a ticket with a facial image attached.
[0210] Furthermore, when the ticket seller acts as a certificate issuer of the ticket certificate, the service server 20 operates as the server device 10. In this case, the service server 20 (server device 10) may issue to the user a ticket certificate (service enjoyment credential) that includes a facial image of the ticket purchaser in the credential information.
[0211] When a ticket certificate (service entitlement certificate including facial information) with a facial image (facial information) is acquired, the acquisition control unit 202 of the terminal 30 may perform identity verification using biometric information obtained from the ticket certificate with facial information and biometric information obtained by a selfie. If identity verification is successful, the acquisition control unit 202 may store the ticket certificate with facial information in the digital wallet.
[0212] Alternatively, the user may obtain a ticket certificate from a ticket seller (the server device 10 of the ticket seller) and then provide the biometric information certificate to the ticket seller. After successfully verifying the validity of the obtained biometric information certificate, the service server 20 may store the biometric information included in the biometric information certificate in the account.
[0213] <Modification 5> In the above embodiment, it has been described that the identity verification result is provided from the user to the service provider via a communication means such as the Internet or Bluetooth (registered trademark). However, the identity verification result may also be provided from the user to the service provider (business terminal 21) by being displayed on the screen of the terminal 30.
[0214] For example, when providing a service to a user, an employee of the service provider orally informs the user that identity verification is required to receive the service. The user operates the terminal 30 to perform a predetermined operation (for example, pressing an identity verification button). The terminal 30 then performs the identity verification described above in response to the user's operation.
[0215] The terminal 30 displays the identity verification result (identity verification successful, identity verification failed). An employee of the service provider or the like checks the displayed identity verification result and determines whether to continue providing the service to the user.
[0216] Alternatively, if the user's identity is successfully verified, the terminal 30 may display the biometric information (face image) used for the identity verification together with the identity verification result (see FIG. 17 ). In this case, the terminal 30 may employ a screenshot prevention / detection mechanism such as a countdown timer. Such an operation by the terminal 30 can prevent a user who has successfully verified their identity from handing the terminal 30 over to another person and having that other person use the terminal 30 fraudulently.
[0217] <Variation 6> Not only the identity verification result but also a service entitlement certificate (credential certificate) may be provided from the user to the service provider by a means other than communication means such as the Internet or Bluetooth (registered trademark). For example, the service entitlement certificate may be provided from the user (terminal 30) to the service provider (business operator terminal 21) by a means such as a two-dimensional barcode (see FIG. 18 ).
[0218] For example, when the user's identity is successfully verified, an employee of the service provider or the like will communicate to the user the certificate required to receive the service. The user operates the terminal 30 to select the communicated service entitlement certificate (ticket certificate). The terminal 30 affixes a signature to the selected service entitlement certificate and converts the signed service entitlement certificate into a two-dimensional barcode. The terminal 30 displays the two-dimensional barcode.
[0219] An employee of the service provider operates the business operator terminal 21 to read the two-dimensional barcode, and decodes the two-dimensional barcode to obtain a service entitlement certificate.
[0220] <Variation 7> When the user terminal 30 receives a request for identity verification from the service provider's device (service server 20, business operator terminal 21), the user terminal 30 may determine the validity of the biometric information certificate (biometric information certificate stored in the digital wallet) from which the biometric information is read.
[0221] The user terminal 30 may determine whether the validity period of the biometric certificate used for identity verification has not expired, whether the biometric certificate is not registered on an expiration list, etc. If the biometric certificate is valid, the terminal 30 may read biometric information from the certificate to verify the identity of the user.
[0222] In this way, the usage control unit 203 of the terminal 30 may verify the validity of the biometric information certificate stored in the digital wallet, and if the stored biometric information certificate is valid, perform identity verification.
[0223] In the above embodiment, the service provider verifies the validity of the service entitlement certificate acquired from the user. Here, all or part of the validity verification of the service entitlement certificate may be executed by the terminal 30.
[0224] For example, among the four verification items, the terminal 30 may verify that the service entitlement certificate designated by the service provider is not registered in the revocation list and that the validity period of the service entitlement certificate has not expired. If the terminal 30 fails these verifications, it may notify the service provider (the business operator terminal 21, the service server 20) that it cannot provide the service entitlement certificate designated by the service provider. Specifically, if the terminal 30 fails the above verifications, it may send a negative response to the certificate provision request.
[0225] In this way, the usage control unit 203 may verify the validity of the service entitlement certificate stored in the digital wallet, and if the stored service entitlement certificate is valid, provide the service entitlement certificate to the service provider.
[0226] Alternatively, the usage control unit 203 may notify the service provider of the result of determining the validity of the service entitlement certificate (ticket certificate) (whether the service entitlement certificate is valid or invalid). The usage control unit 203 may notify the service provider of the determination result using a short-range wireless communication means such as Bluetooth (registered trademark). Alternatively, the usage control unit 203 may notify the service provider of the determination result of the validity of the service entitlement certificate by displaying it on a screen or the like. For example, the usage control unit 203 may display a screen as shown in FIG. 19. The user presents the terminal 30 displaying the screen as shown in FIG. 19 to an employee of the service provider or the like. In this way, the terminal 30 may determine the validity of the service entitlement certificate and notify the service provider of the result. Furthermore, the terminal 30 may notify the service provider of the result of identity verification and the result of the determination of the validity of the service entitlement certificate simultaneously, as shown in FIG. 19.
[0227] <Modification 9> In the above embodiment, the case has been described in which the service provider (service server 20, business operator terminal 21) requests the terminal 30 to perform identity verification and then requests the terminal 30 to provide a service entitlement certificate. However, the service provider's device (service server 20, business operator terminal 21) may request the terminal 30 to submit the identity verification result and the service entitlement certificate at the same time.
[0228] Specifically, the business operator terminal 21 etc. does not send a request for identity verification, but sends a request for certificate provision to the terminal 30. The terminal 30 that receives the request for certificate provision executes identity verification of the user. If identity verification is successful, the terminal 30 sends the business operator terminal 21 etc. a service entitlement certificate specified by the service provider.
[0229] In this way, the terminal 30 may perform identity verification using biometric information obtained from a biometric information certificate, even if identity verification is not explicitly requested by the service provider (service server 20, business operator terminal 21). If identity verification is successful, the terminal 30 provides the service provider with a service entitlement certificate designated by the service provider.
[0230] <Modification 10> In the above embodiment, it has been described that the identity verification of the user is performed by the terminal 30. However, the identity verification may be performed by a device of the service provider (the service server 20, the business operator terminal 21).
[0231] In this case, the business operator terminal 21 or the like transmits a "biometric information provision request" to the terminal 30 instead of a personal identification request.
[0232] When the terminal 30 receives the biometric information provision request, it transmits the biometric information obtained from the biometric information certificate and the biometric information obtained by taking a selfie of the user to the business operator terminal 21 or the like.
[0233] Alternatively, the terminal 30 may transmit the biometric information certificate stored in the digital wallet and the biometric information obtained by taking a selfie to the operator terminal 21 or the like.
[0234] The business operator terminal 21 or the like performs identity verification using the acquired two pieces of biometric information, and if identity verification is successful, requests the terminal 30 to provide a service entitlement certificate.
[0235] Alternatively, when a service is provided by the business operator terminal 21, the business operator terminal 21 may photograph the user (the holder of the terminal 30) to acquire biometric information. In this case, the terminal 30 may transmit the biometric information certificate stored in the digital wallet (or the biometric information obtained from the certificate) to the business operator terminal 21 in response to a biometric information provision request received from the business operator terminal 21.
[0236] The business operator terminal 21 may perform identity verification using a facial image obtained by photographing the user in front of the user and the facial image on the biometric information certificate acquired from the terminal 30. After successful identity verification, the business operator terminal 21 transmits a certificate provision request to the terminal 30.
[0237] Alternatively, the terminal 30 may display the biometric information (facial image) recorded on the biometric certificate in response to receiving the biometric information provision request. An employee of the service provider may compare the facial image displayed on the display of the terminal 30 with the face of the user in front of the user to verify the identity of the user.
[0238] <Modification 11> When acquiring a biometric certificate from a certificate issuer, the acquisition control unit 202 of the terminal 30 may determine the validity of the acquired biometric certificate. If the acquired biometric certificate is valid, the acquisition control unit 202 may store the acquired biometric certificate in a digital wallet. For example, if the validity period of the acquired biometric certificate has not expired and the biometric certificate is not registered in the revocation list, the acquisition control unit 202 may accept the biometric certificate received from the server device 10.
[0239] As described above, when the terminal 30 according to the first embodiment acquires a biometric certificate, it performs identity verification using the biometric information certified by the certificate and the biometric information of the user (operator) of the terminal 30. If identity verification is successful, the terminal 30 accepts the biometric certificate acquired from the certificate issuer. As a result, even if a user operates his / her own terminal 30 to request the issuance of another person's biometric certificate and acquires the other person's biometric certificate, the other person's biometric certificate will not be stored in the terminal 30. In other words, because the biometric information of the user of the terminal 30 and the other person's biometric certificate are different, fraudulent storage of another person's biometric certificate in the user's own digital wallet by the user is prevented.
[0240] Furthermore, when the terminal 30 acquires the service entitlement certificate from the certificate issuer, it performs identity verification using the biometric certificate acquired in advance. This identity verification confirms the identity of the user who received the biometric certificate and the user of the terminal 30. As a result, fraudulent acts such as a user borrowing another person's terminal 30 and storing a certificate (service entitlement certificate) for a ticket they purchased in the digital wallet of the borrowed terminal 30 are prevented.
[0241] Furthermore, when a user receives a service, the terminal 30 performs identity verification using the biometric certificate stored in the digital wallet. If identity verification is successful, the terminal 30 provides the service credential to the service provider. As a result, a user who is not eligible to receive a service is prevented from borrowing a terminal 30 from another person on which that other person's service credential is stored and receiving the service from the service provider. In this way, by performing identity verification, the terminal 30 prevents fraudulent use (spoofing) of the service credential stored in the digital wallet.
[0242] Second Embodiment Next, a second embodiment will be described in detail with reference to the drawings.
[0243] In the second embodiment, a case where identity verification using biometric information obtained from a biometric certificate is omitted will be described. The terminal 30 according to the second embodiment provides a simple identity verification means (alternative identity verification means) that replaces identity verification using a biometric certificate when a service entitlement certificate is presented.
[0244] The configuration of the authentication system according to the second embodiment can be the same as that of the first embodiment, and therefore the description corresponding to Fig. 3 will be omitted. Also, the processing configurations of the server device 10, the business operator terminal 21, the terminal 30, and the like according to the second embodiment can be the same as those of the first embodiment, and therefore the description thereof will be omitted.
[0245] The following description will focus on the differences between the first and second embodiments.
[0246] When frequently requested by a service provider to perform identity verification, the terminal 30 may perform other simplified identity verification in response to the request instead of performing identity verification using a biometric certificate (formal identity verification). The terminal 30 may omit formal identity verification using biometric information by performing simplified identity verification.
[0247] An example of simple identity verification is identity verification using a password. For example, consider a case where a password required to unlock the terminal 30 is set in the terminal 30.
[0248] When a service provider requests identity verification, the usage control unit 203 of the terminal 30 determines whether or not predetermined conditions (identity verification omission conditions) for omitting formal identity verification are met.
[0249] For example, a condition for omitting identity verification is "receiving an identity verification request from the same service provider within a predetermined period after successful legitimate identity verification." For example, for one hour after successful identity verification, legitimate identity verification can be omitted for identity verification requests from the same service provider.
[0250] In addition, when requesting identity verification or certificate provision, the service provider's device (service server 20, business operator terminal 21) according to the second embodiment notifies the terminal 30 of a business operator ID for identifying the service provider. The terminal 30 uses the business operator ID to determine whether identity verification has been requested from the same service provider.
[0251] When a service provider requests identity verification, the usage control unit 203 of the terminal 30 executes the formal identity verification, and if the identity verification is successful, notifies the service provider of that fact. If identity verification is subsequently requested by the same service provider within a predetermined time period since the successful formal identity verification, the usage control unit 203 omits the formal identity verification.
[0252] The usage control unit 203 performs another simple identity verification instead of the formal identity verification. For example, the usage control unit 203 performs identity verification by inputting a password (see FIG. 20). If the password authentication using the password is successful, the usage control unit 203 notifies the service provider of the success of identity verification.
[0253] In this way, the usage control unit 203 has a function as a verification means that, in response to a request for identity verification from a service provider, performs first identity verification using biometric information obtained from the biometric information certificate and notifies the service provider of the result of the first identity verification. When the service provider requests identity verification again, the usage control unit 203 (verification means) performs second identity verification that is different from the first identity verification and notifies the service provider of the result of the second identity verification.
[0254] The usage control unit 203 can execute the second identity verification instead of the first identity verification when a predetermined condition is satisfied. For example, the usage control unit 203 may execute the second identity verification instead of the first identity verification when the service provider requests execution of identity verification again before a predetermined time has elapsed since the first identity verification was successful.
[0255] Another example of simplified identity verification is identity verification using a biometric authentication device provided in the terminal 30. For example, a fingerprint reading device can be used as another simplified identity verification method. For example, fingerprint authentication may be applied to unlocking the terminal 30. In this case, the usage control unit 203 performs identity verification using fingerprint authentication when identity verification is requested by the same service provider within a predetermined time period following successful formal identity verification using a biometric certificate, as in the case where a password is set in the terminal 30.
[0256] Various conditions can be set as the conditions (conditions for omitting identity verification) for the use control unit 203 to perform other simplified identity verification. For example, as described above, other simplified identity verification may be performed when identity verification is requested before a predetermined time has elapsed (e.g., before one hour has elapsed) since identity verification using a biometric certificate was successful.
[0257] Alternatively, a period during which actual identity verification can be omitted may be set according to the number of times identity verification using a biometric certificate is successful within a predetermined period. For example, if identity verification using a biometric certificate is successful three or more times within three hours, the usage control unit 203 may execute simplified identity verification for one hour after the third successful identity verification (formal identity verification is omitted for one hour).
[0258] Alternatively, the usage control unit 203 may change the number of successful attempts to verify identity using a biometric certificate within the predetermined period for omitting formal identity verification depending on the service provider. For example, the number of attempts to omit formal identity verification for service A may be set to "3," and the number of attempts to omit formal identity verification for service B may be set to "5."
[0259] In this way, the usage control unit 203 may perform the second identity verification instead of the first identity verification during a second period determined depending on the number of successful first identity verification attempts during the first period. In this case, the number of successful first identity verification attempts during the first period may be determined for each of the multiple service providers in order to set the second period.
[0260] Alternatively, the service provider may notify the terminal 30 of conditions under which formal identity verification can be omitted (identity verification omission conditions). For example, when the business operator terminal 21 transmits an identity verification request to the terminal 30, the business operator terminal 21 may notify the terminal 30 of the identity verification omission conditions.
[0261] <Specific Example> The operation of the information processing system according to the second embodiment will be specifically described.
[0262] For example, as shown in Fig. 21, a business operator terminal 21-1 is installed at the entrance of a concert hall, and a business operator terminal 21-2 is installed at a shop inside the concert hall.
[0263] When entering a concert venue, a user provides a ticket certificate (service entitlement certificate) to the operator terminal 21-1. The user also purchases merchandise at a shop and provides the electronic money (electronic money account ID) stored in the digital wallet and credit card information to the operator terminal 21-2.
[0264] When entering the concert venue and when purchasing goods at the shop, users are required to verify their identity in response to requests from the business operator terminals 21-1 and 21-2. The same business operator ID is set for the business operator terminals 21-1 and 21-2.
[0265] When a user first enters a concert venue, the terminal 30 performs regular identity verification (identity verification using a biometric information certificate). When the user purchases an item at a shop, if the identity verification omission condition is met, the terminal 30 omits regular identity verification and performs simple identity verification (for example, password authentication).
[0266] Alternatively, when the user leaves the concert hall and re-enters the hall, the user re-submits the ticket certificate to the business operator terminal 21-1. At that time, if the conditions for omitting identity verification are met, the terminal 30 omits the formal identity verification and performs other simplified identity verification.
[0267] Next, a modified example of the second embodiment will be described.
[0268] <Modification 1> When the identity verification omission condition is satisfied, the terminal 30 may also omit execution of simplified identity verification. Alternatively, a condition for omitting simplified identity verification (identity verification complete omission condition) may be set in the terminal 30.
[0269] For example, simplified identity verification may be omitted for an extremely short period (e.g., three minutes) after successful formal identity verification, or for a predetermined period after simplified identity verification is performed.
[0270] <Modification 2> The identity verification omission condition (or the identity verification complete omission condition) may be set with a condition using location information of the terminal 30. For example, when identity verification is requested by the same service provider within a predetermined range centered on the place (location) where legitimate identity verification was successful, the terminal 30 may substitute simplified identity verification for the second and subsequent identity verifications.
[0271] Alternatively, the condition for omitting identity verification may be configured by combining the location information of the terminal 30 and the time element of the formal identity verification. For example, the terminal 30 may omit the formal identity verification within a predetermined range and for a predetermined time after the formal identity verification is successful, and perform simplified identity verification instead.
[0272] The conditions for omitting personal identification are determined depending on the business content and business form of the service provider, the content of the service entitlement certificates handled, and the like.
[0273] <Variation 3> The above-mentioned initial formal identity verification (first identity verification) may be performed using a combination of multiple authentication methods. For example, formal identity verification may be performed using a combination of biometric authentication using a biometric certificate and password authentication using a password. That is, the initial formal identity verification may be performed using multimodal authentication, which combines two or more authentication methods. In this case, simplified identity verification (second identity verification) performed from the second time onwards may be performed using a single authentication method (single-modal authentication), such as biometric authentication using a biometric certificate or password authentication. Furthermore, if formal identity verification is performed using multimodal authentication, simplified identity verification may be omitted. Furthermore, if formal identity verification is performed using single-modal authentication, simplified identity verification may be omitted.
[0274] <Modification 4> In the second embodiment, a case has been described in which formal identity verification is performed first, and then simplified identity verification is performed when predetermined conditions are satisfied. However, the formal identity verification and simplified identity verification may be performed in the reverse order. That is, depending on the service or business type provided by the service provider, it may be preferable to perform simplified identity verification first and then formal identity verification. In such a case, the terminal 30 may first perform simplified identity verification and then perform formal identity verification.
[0275] Alternatively, the service provider's device (service server 20, business operator terminal 21) may notify the terminal 30 of the execution order of formal identity verification and simplified identity verification. At that time, the service provider's device may also notify the terminal 30 of the conditions for switching the identity verification method.
[0276] As described above, when a service provider requests identity verification, the terminal 30 according to the second embodiment performs formal identity verification using biometric information acquired in advance. The terminal 30 notifies the service provider of the result of the formal identity verification. When identity verification is requested again by the service provider and predetermined conditions are met, the terminal 30 performs simplified identity verification that differs from the formal identity verification. The terminal 30 notifies the service provider of the result of the simplified identity verification. As a result, even when identity verification is repeatedly requested by the same service provider, the user only needs to perform simplified identity verification. In other words, the burden on users who enjoy services that require identity verification is reduced.
[0277] Next, the hardware of each device constituting the information processing system will be described. Fig. 22 is a diagram showing an example of the hardware configuration of the terminal 30.
[0278] The terminal 30 can be configured by an information processing device (so-called computer), and has the configuration exemplified in Fig. 22. For example, the terminal 30 includes a processor 311, a memory 312, an input / output interface 313, and a communication interface 314. The components such as the processor 311 are connected by an internal bus or the like, and are configured to be able to communicate with each other.
[0279] However, the configuration shown in Fig. 22 is not intended to limit the hardware configuration of the terminal 30. The terminal 30 may include hardware not shown, and may not include the input / output interface 313 as necessary. Furthermore, the number of processors 311 and the like included in the terminal 30 is not intended to be limited to the example shown in Fig. 22, and for example, the terminal 30 may include multiple processors 311.
[0280] The processor 311 is a programmable device such as a central processing unit (CPU), a micro processing unit (MPU), or a digital signal processor (DSP). Alternatively, the processor 311 may be a device such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). The processor 311 executes various programs including an operating system (OS).
[0281] The memory 312 is a random access memory (RAM), a read only memory (ROM), a hard disk drive (HDD), a solid state drive (SSD), etc. The memory 312 stores an OS program, application programs, and various data.
[0282] The input / output interface 313 is an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display, etc. The input device is, for example, a device that accepts user operations, such as a keyboard or a mouse.
[0283] The communication interface 314 is a circuit, module, etc. that communicates with other devices. For example, the communication interface 314 includes a network interface card (NIC).
[0284] The functions of the terminal 30 are realized by various processing modules. The processing modules are realized, for example, by the processor 311 executing a program stored in the memory 312. The program can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. That is, the present invention can also be embodied as a computer program product. The program can be downloaded via a network or updated using a storage medium storing the program. The processing modules can also be realized by a semiconductor chip.
[0285] The server device 10, the service server 20, the business terminal 21, etc. can also be configured by information processing devices in the same way as the terminal 30, and their basic hardware configurations are no different from those of the terminal 30, so a description thereof will be omitted.
[0286] Terminal 30, which is an information processing device, is equipped with a computer, and functions of terminal 30 can be realized by causing the computer to execute a program. Terminal 30 also executes a control method for terminal 30 using the program. Similarly, server device 10 is equipped with a computer, and functions of server device 10 can be realized by causing the computer to execute a program. Server device 10 also executes a control method for server device 10 using the program.
[0287] [Modification] The configuration, operation, etc. of the information processing system described in the above embodiment are merely examples, and are not intended to limit the configuration, etc. of the system.
[0288] In the above embodiment, the server device 10 of the certificate issuer issues a credential certificate that does not require a certification authority for certificate verification. However, the server device 10 may also issue a certificate that requires a certification authority (certificate based on a public key infrastructure).
[0289] In the above embodiment, the operation of the information processing system has been described mainly using a biometric certificate relating to a "face" as an example. It goes without saying that the information processing system can handle biometric certificates relating to biometric information other than a face. For example, the terminal 30 may acquire biometric certificates relating to biometric information such as a fingerprint or voiceprint (fingerprint VCs, voiceprint VCs) and store them in a digital wallet. Alternatively, the terminal 30 may perform identity verification using a biometric certificate such as a fingerprint or voiceprint when a user receives a service.
[0290] The terminal 30 may obtain biometric certificates relating to the same biometric information from different certificate issuers and store multiple biometric certificates certifying the same biometric information in the digital wallet. For example, the terminal 30 may obtain biometric certificates relating to a face from each of certificate issuers A and B.
[0291] Alternatively, the terminal 30 may obtain biometric certificates relating to different types of biometric information from the same certificate issuer and store the biometric certificates relating to the different types of biometric information obtained from the same certificate issuer in the digital wallet. For example, the terminal 30 may obtain a biometric certificate relating to a face and a biometric certificate relating to a fingerprint from certificate issuer A.
[0292] The service provider's device (service server 20, business operator terminal 21) may specify a biometric certificate to be used by the terminal 30 for identity verification. For example, the business operator terminal 21 or the like may instruct the terminal 30 to perform identity verification using a biometric certificate related to a face (face VCs). In this case, the business operator terminal 21 or the like may transmit an identity verification request including the type of biometric information to the terminal 30.
[0293] The terminal 30 may notify the service provider's device (service server 20, business operator terminal 21) of information (detailed information) regarding the biometric certificate used for identity verification. For example, the terminal 30 may transmit information regarding the type of biometric information attested by the biometric certificate, the issuer of the biometric certificate, etc., along with the identity verification result to the business operator terminal 21, etc. Even if the identity verification result indicates success, the business operator terminal 21 may refuse to provide services to the user depending on the type of information used for identity verification and the issuer of the biometric certificate. The business operator terminal 21 may reject identity verification results that do not satisfy its own security policy, etc. For example, when service providers such as financial institutions and insurance companies provide services related to account opening and insurance applications, identity verification is required using a biometric certificate issued by a public institution, such as a passport or My Number card, rather than a biometric certificate issued by a private company. In this way, conditions regarding the issuer of the biometric certificate may be set depending on the content of the service provided by the service provider to the user.
[0294] The terminal 30 may execute control according to the issuer of the biometric certificate when obtaining the service entitlement from the certificate issuer or when providing the service entitlement to the service provider. For example, the terminal 30 may not provide the service entitlement (ticket certificate) to the service provider unless identity verification using a biometric certificate issued by a trusted issuer is successful.
[0295] In the above embodiment, the use of a biometric certificate and a service entitlement certificate has been mainly described. In the information processing system disclosed herein, an identification certificate can also be used in the same way as a service entitlement certificate. For example, when the terminal 30 receives an identification certificate from a certificate issuer, it may perform identity verification using the biometric certificate. As with the service entitlement certificate, if identity verification using the biometric certificate is successful, the terminal 30 may store the acquired identification certificate in a digital wallet.
[0296] Alternatively, the terminal 30 may perform identity verification using a biometric certificate when providing the identification card to the service provider. In this case, the terminal 30 may also provide the identification card stored in the digital wallet to the service provider if identity verification using the biometric certificate is successful, similar to the case of the service entitlement card.
[0297] The terminal 30 may obtain the user's consent regarding the provision of the service entitlement certificate before providing the service entitlement certificate to the service provider. At that time, the terminal 30 may obtain the consent regarding the submission of the service entitlement certificate while clearly indicating the service entitlement certificate requested to be provided.
[0298] In the above embodiment, the case where the usage control unit 203 of the terminal 30 selects a service entitlement certificate designated by the service provider has been described. However, the user may operate the terminal 30 himself / herself to select a service entitlement certificate designated by the service provider. For example, when a service entitlement certificate required to receive a required service is orally communicated by an employee of the service provider, the usage control unit 203 may display a list of service entitlements stored in the digital wallet in response to the user's operation. The usage control unit 203 may enable the user to select a service entitlement certificate by displaying a list of service entitlements.
[0299] A biometric information certificate may include not only biometric information certified by the certificate issuer, but also personal information of the person to whom it is issued (basic information such as name, sex, date of birth, address, etc.).
[0300] In the above embodiment, a case has been described in which a user (terminal 30) requests the issuance of a biometric certificate from an organization or group such as a company or a university. However, the terminal 30 may request the issuance of a biometric certificate from the server device 10 of a public institution that stores the user's biometric information. Alternatively, when the terminal 30 is unable to obtain a biometric certificate from a company or the like, the terminal 30 may request the issuance of a biometric certificate from a public institution.
[0301] The service provider may request only identity verification from the terminal 30. For example, when providing a service to a user, if it is sufficient to confirm that the user belongs to a company or a university, the service provider may request only identity verification from the terminal 30. The service provider may determine that a user who has successfully verified their identity belongs to some organization or the like, and provide the service.
[0302] When transmitting a certificate issuance request to the server device 10 of the certificate issuer, the terminal 30 may sign the information included in the certificate issuance request using a private key corresponding to the public key registered in the blockchain. The certificate issuing unit 302 of the server device 10 may set successful verification of the signature as a condition for issuing a certificate (credential certificate).
[0303] When acquiring a credential certificate from the server device 10, the acquisition control unit 202 of the terminal 30 may notify the user that the credential certificate has been issued. The acquisition control unit 202 may also verify the signature attached to the credential certificate acquired from the certificate issuer. In this case, the acquisition control unit 202 acquires, from the blockchain, a public key corresponding to the issuer ID written in the credential certificate. The acquisition control unit 202 verifies the signature attached to the credential certificate using the acquired public key. The acquisition control unit 202 may set successful signature verification as a condition for storing the credential certificate in the digital wallet.
[0304] Some functions of the terminal 30 may be implemented in another apparatus, device, etc. More specifically, the above-described "acquisition control unit (acquisition control means)," "usage control unit (usage control means)," etc. may be implemented in any of the apparatuses included in the system.
[0305] The form of data transmission between each device (e.g., server device 10, terminal 30) is not particularly limited, but the data transmitted between these devices may be encrypted. Personal information of users and the like is transmitted between these devices, and in order to appropriately protect this information, it is desirable to transmit and receive encrypted data.
[0306] In the flow charts (flowcharts, sequence diagrams) used in the above explanation, multiple steps (processes) are described in order, but the order of execution of the steps executed in the embodiments is not limited to the order described. In the embodiments, the order of the steps shown in the drawings can be changed to the extent that the content is not affected, such as by executing each process in parallel.
[0307] The above-described embodiments have been described in detail to facilitate understanding of the present disclosure, and it is not intended that all of the above-described configurations are required. Furthermore, when multiple embodiments are described, each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with another configuration.
[0308] The above explanation makes clear the industrial applicability of the present invention, and the present invention is suitably applicable to information processing systems including service providers that provide services to users using certificates stored in digital wallets.
[0309] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.
[0310] [Supplementary Note 1] A terminal comprising: an acquisition means for acquiring a biometric certificate from a certificate issuer that holds the user's biometric information, the biometric certificate being a certificate attesting to the biometric information of a recipient, the biometric certificate including the biometric information of the recipient; a verification means for performing identity verification using the biometric information obtained from the acquired biometric certificate and the user's biometric information; and a storage means for storing the acquired biometric certificate if the identity verification is determined to be successful. [Supplementary Note 2] The terminal according to Supplementary Note 1, wherein the verification means performs identity verification using the biometric information obtained from the acquired biometric certificate and biometric information obtained by photographing the user. [Supplementary Note 3] The terminal according to Supplementary Note 2, wherein the acquisition means acquires the biometric certificate by transmitting to the certificate issuer a certificate issuance request including information identifying the recipient of the biometric certificate. [Supplementary Note 4] The terminal according to Supplementary Note 3, wherein the acquisition means transmits to the certificate issuer the certificate issuance request including the type of biometric information to be verified using the biometric certificate. [Supplementary Note 5] The terminal according to Supplementary Note 4, wherein the acquisition means acquires the biometric certificate as a credential certificate from the certificate issuer. [Supplementary Note 6] The terminal according to any one of Supplements 1 to 5, wherein the acquisition means acquires the biometric certificate related to a person's face. [Supplementary Note 7] The terminal according to any one of Supplements 1 to 5, wherein the storage means stores the acquired biometric certificate in a digital wallet. [Supplementary Note 8] The terminal according to Supplementary Note 7, wherein the acquisition means stores the acquired biometric certificate in the digital wallet if the acquired biometric certificate is valid. [Supplementary Note 9] The terminal according to Supplementary Note 8, wherein the biometric certificate is generated using biometric information acquired from an official identification card of the issuee.[Supplementary Note 10] A system including a server device and a terminal managed by a certificate issuer that holds biometric information of a user, wherein the terminal comprises: an acquisition means that acquires from the server device a biometric certificate that certifies the biometric information of a person to be issued with the certificate and that includes the biometric information of the person to be issued with the certificate; a verification means that performs identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user; and a storage means that stores the acquired biometric certificate if the identity verification is determined to be successful. [Supplementary Note 11] A terminal control method that comprises: in the terminal, acquiring a biometric certificate that certifies the biometric information of a person to be issued with the certificate and that includes the biometric information of the person to be issued with the certificate from a certificate issuer that holds the biometric information of the user, performing identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user, and storing the acquired biometric certificate if the identity verification is determined to be successful. [Supplementary Note 12] A program for causing a computer installed in a terminal to execute the following processes: acquiring a biometric certificate from a certificate issuer that holds the user's biometric information, the biometric certificate being a certificate attesting to the biometric information of the person to whom the certificate is issued, the biometric certificate including the biometric information of the person to whom the certificate is issued; performing identity verification using the biometric information obtained from the acquired biometric certificate and the user's biometric information; and, if the identity verification is determined to be successful, storing the acquired biometric certificate.
[0311] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 9 that are dependent on Supplementary Note 1 above may also be dependent on Supplementary Notes 10, 11, and 12 in the same dependent relationship as Supplementary Notes 2 to 9. Furthermore, not limited to Supplementary Notes 1, 10, 11, and 12, some or all of the configurations described as Supplements may be made dependent on various hardware, software, various recording means for recording software, or systems, within the scope of each of the above-mentioned embodiments.
[0312] The disclosures of the above-cited prior art documents are incorporated herein by reference. Although the embodiments of the present invention have been described above, the present invention is not limited to these embodiments. Those skilled in the art will understand that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. In other words, the present invention naturally includes various modifications and alterations that may be made by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concepts thereof.
[0313] 10 Server device 20 Service server 21 Operator terminal 21-1 Operator terminal 21-2 Operator terminal 30 Terminal 100 Terminal 101 Acquisition means 102 Confirmation means 103 Storage means 201 Communication control unit 202 Acquisition control unit 203 Usage control unit 204 Storage unit 205 Personal identification unit 301 Communication control unit 302 Certificate issuing unit 303 Storage unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 401 Communication control unit 402 Service provision control unit 403 Storage unit
Claims
1. A terminal comprising: an acquisition means for acquiring a biometric certificate containing the biometric information of a certificate recipient, the biometric information being used to certify the biometric information of the certificate recipient, from a certificate issuer that holds the biometric information of a user; a verification means for performing identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user; and a storage means for storing the acquired biometric certificate if it is determined that the identity verification is successful.
2. The terminal according to claim 1, wherein the verification means performs the identity verification using biometric information obtained from the acquired biometric certificate and biometric information obtained by photographing the user.
3. The terminal according to claim 2, wherein said acquiring means acquires said biometric certificate by transmitting to said certificate issuer a certificate issuance request including information identifying said person to whom said biometric certificate is to be issued.
4. The terminal according to claim 3, wherein said acquiring means transmits to said certificate issuer said certificate issuance request including a type of biometric information to be certified by said biometric information certificate.
5. The terminal according to claim 4, wherein said acquiring means acquires said biometric information certificate as a credential certificate from said certificate issuer.
6. The terminal according to any one of claims 1 to 5, wherein said acquiring means acquires said biometric certificate relating to a person's face.
7. A terminal according to any one of claims 1 to 5, wherein the storage means stores the acquired biometric certificate in a digital wallet.
8. The terminal according to claim 7, wherein said acquiring means stores said acquired biometric certificate in said digital wallet if said acquired biometric certificate is valid.
9. The terminal of claim 8, wherein the biometric certificate is generated using biometric information obtained from an official identification document of the person to whom the certificate is issued.
10. A system including a server device and a terminal managed by a certificate issuer which holds the biometric information of a user, wherein the terminal is equipped with: an acquisition means for acquiring from the server device a biometric certificate which is a certificate attesting to the biometric information of the person to whom the certificate is to be issued and which includes the biometric information of the person to whom the certificate is to be issued; a verification means for performing identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user; and a storage means for storing the acquired biometric certificate when it is determined that the identity verification is successful.
11. A method for controlling a terminal, comprising: acquiring, from a certificate issuer which holds the user's biometric information, a biometric certificate which certifies the biometric information of a person to whom the certificate is to be issued, the biometric certificate including the biometric information of the person to whom the certificate is to be issued; performing identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user; and, if it is determined that the identity verification is successful, storing the acquired biometric certificate.
12. A computer-readable storage medium storing a program for causing a computer installed in a terminal to execute the following processes: acquiring a biometric certificate containing the biometric information of the person to whom the certificate is issued, the biometric certificate being a certificate attesting to the biometric information of the person to whom the certificate is issued, from a certificate issuer that holds the biometric information of the user; performing identity verification using the biometric information obtained from the acquired biometric certificate and the biometric information of the user; and, if the identity verification is determined to be successful, storing the acquired biometric certificate.
Citation Information
Patent Citations
Identify authenticating system, user terminal, service provider apparatus, reliability assuring server, operating method of them and operating program of them
WO2007023756A1
Living-body information registering device, personal certification system utilizing living-body information, and living-body information registering method
JP2003208407A
Terminal, system, terminal control method and program
JP7371818B1
JP2023202542A