Information processing method, program, and information processing device

Zero-knowledge proofs enable secure verification of positional relationships without exposing user or target locations, addressing data privacy concerns in location-based processing.

WO2025150377A1PCT designated stage expired Publication Date: 2025-07-17SONY GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/044933
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-12
Filing Date
2024-12-19
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Existing technologies for processing based on user position often require acquiring and handling sensitive location information, leading to potential data breaches and unnecessary exposure of personal or confidential information.

Method used

A method using zero-knowledge proofs to verify the positional relationship between a user's location and a target location without disclosing the actual positions, employing techniques like zk-SNARKs and commitment values to ensure privacy.

Benefits of technology

Accurately verifies positional relationships while protecting sensitive location information, preventing unauthorized access and maintaining data privacy, even in blockchain systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024044933_17072025_PF_FP_ABST
    Figure JP2024044933_17072025_PF_FP_ABST
Patent Text Reader

Abstract

[Problem] To accurately verify positional relationship without acquiring position information itself. [Solution] Provided is an information processing method that is executed by a computer, the method including receiving a zero-knowledge proof generated by a proof device, and verifying the authenticity of content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first position and a second position are in a prescribed positional relationship.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, program, and information processing device

[0001] The present disclosure relates to an information processing method, a program, and an information processing device.

[0002] In recent years, technologies for executing some kind of processing based on a user's location have become widespread. For example, Patent Literature 1 discloses a system for granting a user a reward based on location information acquired by a user terminal.

[0003] JP 2023-131476 A

[0004] However, the location information acquired by a user terminal or the like may be information that should be protected, such as personal information or confidential information.

[0005] According to one aspect of the present disclosure, there is provided a computer-implemented information processing method including receiving a zero-knowledge proof generated by a proof device and verifying the authenticity of content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first location and a second location are in a predetermined positional relationship.

[0006] According to another aspect of the present disclosure, there is provided an information processing device comprising: a communication unit that receives a zero-knowledge proof generated by a proof device; and a verification unit that verifies the authenticity of the content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first position and a second position are in a predetermined positional relationship.

[0007] According to another aspect of the present disclosure, there is provided an information processing device comprising: a communication unit that receives a zero-knowledge proof generated by a proof device; and a verification unit that verifies the authenticity of the content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first position and a second position are in a predetermined positional relationship.

[0008] 1 is a diagram illustrating an overview of an information processing method according to an embodiment of the present disclosure. FIG. 1 is a diagram illustrating an overview of an information processing method according to the embodiment. FIG. 2 is a block diagram illustrating an example of a functional configuration of a proving device 10 according to the embodiment. FIG. 3 is a block diagram illustrating an example of a functional configuration of a verification device 20 according to the embodiment. FIG. 4 is a sequence diagram illustrating an example of a flow of generation and verification of a zero-knowledge proof Z0 based on Euclidean distance when a point P2 does not correspond to information to be protected according to the embodiment. FIG. 5 is a sequence diagram illustrating an example of a flow of generation and verification of a zero-knowledge proof Z0 based on Euclidean distance when a point P2 corresponds to information to be protected according to the embodiment. FIG. 6 is a sequence diagram illustrating an example of a flow of generation and verification of a zero-knowledge proof Z0 based on a geohash value when a point P2 does not correspond to information to be protected according to the embodiment. FIG. 7 is a sequence diagram illustrating an example of a flow of generation and verification of a zero-knowledge proof Z0 based on a set of multiple geohash values ​​when a point P2 does not correspond to information to be protected according to the embodiment. FIG. 8 is a sequence diagram illustrating an example of a flow of generation and verification of a zero-knowledge proof Z0 based on a set of multiple geohash values ​​when a point P2 corresponds to information to be protected according to the embodiment. 1 is a diagram for explaining a case where the proving device 10 according to the embodiment generates a zero-knowledge proof Z0 that proves that point P1 is within a predetermined area A1. FIG. 1 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on first location information to which a signature is attached in a secure area according to the embodiment. FIG. 2 is a diagram for explaining a configuration example when the information processing method according to the embodiment is applied to proving fan activity. FIG. 3 is a diagram for explaining an example of the content that the zero-knowledge proof Z0 proves when the information processing method according to the embodiment is applied to proving fan activity. FIG. 4 is a sequence diagram showing an example of the flow when the information processing method according to the embodiment is applied to proving fan activity.FIG. 1 is a diagram for explaining a case where the information processing method according to the embodiment is applied to risk-based authentication of a smart contract wallet 17. FIG. 2 is a block diagram showing an example hardware configuration of an information processing device 90 according to the embodiment. FIG. 3 is a diagram for explaining an issue when user location information according to the embodiment is information that should be protected. FIG. 4 is a diagram for explaining an issue when user location information and a target location according to the embodiment are both information that should be protected. FIG. 5 is a diagram for explaining a method for verifying a user's location using a two-dimensional code installed at a target location according to the embodiment.

[0009] Preferred embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. In this specification and drawings, components having substantially the same functional configurations are designated by the same reference numerals, and redundant description will be omitted.

[0010] In addition, in this specification and drawings, when multiple identical components are to be described separately, letters or the like may be added to the end of the reference numerals. On the other hand, when it is not necessary to distinguish between multiple identical components, the letters or the like may be omitted and a description common to all of the multiple identical components may be given.

[0011] The description will be given in the following order: 1. Embodiment 1.1. Overview 1.2. Functional configuration example 1.3. Functional details 1.4. Application example 2. Hardware configuration example 3. Summary

[0012] <1. Embodiment> <<1.1. Overview>> As described above, in recent years, technology for executing some kind of processing based on the location of a user has become widespread.

[0013] For example, there are services that grant privileges or points to a user when the user's location is close to a certain target location, and services that authenticate the user based on the distance between the user's location and a certain target location.

[0014] The above-described services can be realized, for example, by using location information acquired by a mobile device carried by a user.

[0015] As an example, a server installed by a company providing a service may receive location information from a mobile device via a network and compare that location information with the location information of the target location to determine whether or not a process such as granting authorization can be performed.

[0016] However, the user's location information (location information acquired by a mobile device carried by the user) may be personal information, confidential information, or other information that must be protected.

[0017] FIG. 19 is a diagram for explaining the problem that arises when user location information is information that needs to be protected.

[0018] 19 shows a user 55 located at point P1 and a mobile device 50 carried by the user 55. Also shown in FIG. 19 is a server 60 that performs a predetermined process when the location of the user 55, i.e., the location of point P1, is close to point P2, which is a target location.

[0019] For example, the server 60 can receive location information LP1 of point P1 acquired by the mobile device 50 and determine whether or not a specified process can be executed by comparing the location information LP1 of point P1 with location information LP2 of point P2 that is stored in advance.

[0020] However, if the location information of the user 55, i.e., the location information LP1 of the point P1, is information that should be protected, the server 60 will acquire the information that should be protected. Furthermore, if it can be proven that the user 55 is close to the point P2 by information other than the location information LP1 of the point P1, the server 60 will acquire information that should be protected but that should not be acquired, which is undesirable from the viewpoint of information protection.

[0021] It is also possible that not only the user's location but also the target location is an object to be protected.

[0022] FIG. 20 is a diagram for explaining the problem that arises when both the user's location information and the target location are information that should be protected.

[0023] 20, like Fig. 19, shows a user 55 located at point P1 and a mobile device 50 carried by the user 55. Also, like Fig. 19, Fig. 20 shows a server 60 that performs a predetermined process when the position of the user 55, i.e., the position of point P1, is close to point P2, which is a target position.

[0024] For example, the server 60 receives location information LP1 of point P1 acquired by the mobile device 50, and can determine whether or not a specified process can be executed by comparing the location information LP1 of point P1 with location information LP2 of point P2 previously received from the mobile device 50.

[0025] However, if the location information of user 55 and the location information LP2 of point P2 are information that should be protected, server 60 will end up acquiring the two pieces of information that should be protected. Furthermore, if it can be proven that user 55 is close to point P2 by information other than location information LP1 of point P1 and the location information of point P2, server 60 will end up acquiring the two pieces of information that should be protected, which is not originally necessary from the perspective of information protection.

[0026] In addition, if the server 60 is a computer that forms a blockchain, the information that the server 60 obtains and that needs to be protected may be accessible to all users who use the blockchain.

[0027] As described above with reference to Figures 19 and 20, when the user's location, target location, etc. are information that needs to be protected, a method is desired for verifying the relationship between the two locations without using the user's location, target location, etc. themselves.

[0028] As a method for verifying the relationship between the user's position and the target position without using the position itself, for example, a method using a two-dimensional code placed at the target position can be mentioned.

[0029] FIG. 21 is a diagram for explaining a method for verifying a user's location using a two-dimensional code placed at a target location.

[0030] 21 illustrates a live music venue as an example of the target location. A two-dimensional code C1 is also installed at the live music venue.

[0031] When the server 60 shown in Figure 21 receives an issuance request R1 based on a two-dimensional code C1, it assumes that the user carrying the sending mobile device is located at the live venue and issues a participation certificate NFT (Non-Fungible Token) N1 proving participation in the live performance.

[0032] However, the image of the two-dimensional code C1 can be easily captured using a mobile device or the like, and can also be spread.

[0033] Here, as shown in FIG. 21, consider a case where a user 57 located at a live venue photographs a two-dimensional code C1 using a mobile device 52 and sends the image to a mobile device 50 carried by a user 55.

[0034] In this case, even though the user 55 is not at the live venue, the user 55 can use the mobile device 50 to send an issuance request R1 based on the two-dimensional code C1 and obtain the participation proof NFT N1.

[0035] As described above with reference to FIG. 21, if position information is not used, it may be difficult to correctly verify the relationship between the user's position and the target position.

[0036] An information processing method according to one embodiment of the present disclosure has been conceived with a focus on the above-described problems, and makes it possible to verify positional relationships with high accuracy without acquiring the positional information itself.

[0037] Hereinafter, an overview of an information processing method according to an embodiment of the present disclosure will be described with reference to FIGS. 1 and 2. FIG.

[0038] 1 and 2 are diagrams for explaining an overview of an information processing method according to an embodiment of the present disclosure.

[0039] In the example shown in FIGS. 1 and 2, the information processing method according to this embodiment is executed by the verification device 20.

[0040] The verification device 20 according to the present embodiment executes an information processing method that includes receiving the zero-knowledge proof Z0 generated by the proving device 10 and verifying the authenticity of the content indicated by the zero-knowledge proof Z0. Furthermore, one of the features of the zero-knowledge proof Z0 according to an embodiment of the present disclosure is that it indicates that a first position and a second position have a predetermined positional relationship.

[0041] As shown in FIGS. 1 and 2, the certification device 10 according to this embodiment may be, for example, a mobile device carried by a user 15.

[0042] The proof device 10 according to this embodiment executes an information processing method that includes, for example, acquiring a first position, generating a zero-knowledge proof Z0 that indicates that the acquired first position and a second position are in a predetermined positional relationship, and transmitting the generated zero-knowledge proof to the verification device 20.

[0043] In the following, a case where the first position is the position of the certification device 10 will be mainly described as an example.

[0044] If the authentication device 10 is a mobile device carried by the user 15 , the location of the authentication device 10 can be considered as the location of the user 15 .

[0045] On the other hand, the second location may be any location of interest.

[0046] The proving device 10 according to this embodiment generates a zero-knowledge proof Z0 using the acquired first position (the position of the proving device 10) and second position.

[0047] The zero-knowledge proof Z0 according to this embodiment is data (certificate, file used for proof, etc.) that proves a certain fact without providing the verification device 20 with any knowledge other than that fact.

[0048] The fact (content) that the zero-knowledge proof Z0 according to this embodiment proves may be, for example, that the first position and the second position have a predetermined positional relationship.

[0049] More specifically, the content that the zero-knowledge proof Z0 according to this embodiment proves may be, for example, that the first location and the second location are close to each other (nearby).

[0050] The proof device 10 according to this embodiment may generate the zero-knowledge proof Z0 using an algorithm such as zk-SNARK (Zero-Knowledge Succinct Non-interactive Arguments of Knowledge).

[0051] The point P1 according to this embodiment is an example of a first position, and the point P2 according to this embodiment is an example of a second position.

[0052] FIG. 1 shows an example in which location information of point P1 (location of the certification device 10) is information that must be protected, while location information of point P2 is shared in advance between the certification device 10 and the verification device 20.

[0053] In this example, the proving device 10 generates a zero-knowledge proof Z0 based on the acquired location information of the point P1 and the location information of the point P2, and transmits the generated zero-knowledge proof Z0 to the verifying device 20.

[0054] Note that the content that the zero-knowledge proof Z0 in FIG. 1 proves may be that "point P1 and point P2 are close to each other."

[0055] The verification device 20 can verify the authenticity of the content indicated by the zero-knowledge proof Z0 received from the proving device 10 based on the known location information of the point P2.

[0056] On the other hand, FIG. 2 shows an example in which both the location information of the point P1 and the location information of the point P2 are information that should be protected.

[0057] In this example, the proving device 10 first generates a commitment value CP2 for the location information of the point P2, and transmits the generated commitment value CP2 for the location information of the point P2 to the verification device 20.

[0058] The commitment value CP2 of the location information of point P2 may be a value obtained by encrypting the location information of point P2 using a random number. Note that, hereinafter, generating a commitment value for certain information using a random number may be referred to as "commitmentization."

[0059] Next, the proof device 10 generates a zero-knowledge proof Z0 based on the location information of point P1, the location information of point P2, and the commitment value CP2 of the location information of point P2, and transmits the generated zero-knowledge proof Z0 to the verification device 20.

[0060] Note that the content that the zero-knowledge proof Z0 in FIG. 2 proves may be that "point P1 and point P2 are close to each other."

[0061] The verification device 20 can verify the authenticity of the content indicated by the zero-knowledge proof Z0 based on the commitment value CP2 of the received location information of the point P2.

[0062] The outline of the information processing method according to this embodiment has been described above.

[0063] According to the information processing method described above, it is possible to verify the positional relationship with high accuracy without acquiring the positional information itself.

[0064] Therefore, even if the verification device 20 is a computer that forms the blockchain, it is possible to prevent information that needs to be protected from being leaked.

[0065] <<1.2. Example of Functional Configuration>> Next, an example of the functional configuration of the information processing system according to this embodiment will be described. The information processing system according to this embodiment includes a certification device 10 and a verification device 20.

[0066] FIG. 3 is a block diagram showing an example of the functional configuration of the certification device 10 according to this embodiment.

[0067] The certification device 10 according to this embodiment may be a mobile device carried by a user, such as a smartphone, a tablet, or a wearable device.

[0068] As shown in FIG. 3, the certification device 10 according to this embodiment includes a control unit 110, a location information acquisition unit 120, and a communication unit .

[0069] (Control Unit 110) The control unit 110 according to this embodiment controls the operation of each component included in the certification device 10.

[0070] The functions of the control unit 110 according to this embodiment are realized by various processors.

[0071] Furthermore, the control unit 110 according to this embodiment includes a generation unit 115 as shown in FIG.

[0072] (Generation Unit 115) The generation unit 115 according to this embodiment generates a zero-knowledge proof Z0.

[0073] For example, the generation unit 115 according to this embodiment may generate a zero-knowledge proof Z0 indicating that the first position and the second position have a predetermined relationship based on the position of the proof device 10 (an example of a first position) and an arbitrary second position.

[0074] (Location Information Acquisition Unit 120) The location information acquisition unit 120 according to this embodiment acquires location information of the certification device 10. In the following, a case where the location information acquisition unit 120 acquires the coordinates of the certification device 10 using a Global Navigation Satellite System (GNSS) will be mainly assumed as an example.

[0075] However, the acquisition of location information by the location information acquisition unit 120 is not limited to the above example.

[0076] The location information acquisition unit 120 may acquire location information using a positioning technique that uses, for example, Wi-Fi (registered trademark), Bluetooth (registered trademark) beacons, or the like, or may acquire location information using a cellular positioning technique.

[0077] (Communication Unit 130 ) The communication unit 130 according to this embodiment communicates information with the verification device 20 via the network 30 .

[0078] The communication unit 130 according to this embodiment transmits, for example, the zero-knowledge proof Z0 generated by the generation unit 115 to the verification device 20.

[0079] FIG. 4 is a block diagram showing an example of the functional configuration of the verification device 20 according to this embodiment.

[0080] The verification device 20 according to this embodiment is an example of a computer that executes the information processing method according to this embodiment.

[0081] The verification device 20 according to this embodiment may be, for example, a computer that forms a blockchain.

[0082] As shown in FIG. 4, the verification device 20 according to this embodiment includes a control unit 210, a processing unit 220, and a communication unit 230.

[0083] (Control Unit 210) The control unit 210 according to this embodiment controls the operation of each component included in the verification device 20.

[0084] The functions of the control unit 210 according to this embodiment are realized by various processors.

[0085] Furthermore, the control unit 210 according to this embodiment includes a verification unit 215 as shown in FIG.

[0086] (Verification Unit 215) The verification unit 215 according to this embodiment verifies the authenticity of the content indicated by the zero-knowledge proof Z0.

[0087] For example, if the second information is not information that needs to be protected, the verification unit 215 according to this embodiment may verify the authenticity of the content indicated by the zero-knowledge proof Z0 based on the location information of the second location that is shared in advance with the certification device 10.

[0088] Also, for example, if the second information is information that needs to be protected, the verification unit 215 in this embodiment may verify the authenticity of the content indicated by the zero-knowledge proof Z0 based on the commitment value related to the second position received from the certification device 10.

[0089] (Processing Unit 220) The processing unit 220 according to this embodiment executes a predetermined process based on the result of the verification by the verification unit 215.

[0090] More precisely, the processing unit 220 according to this embodiment executes a predetermined process when the verification unit 215 recognizes that the content indicated by the zero-knowledge proof Z0 is true.

[0091] The predetermined processing executed by the processing unit 220 may be designed as appropriate depending on the service, application, etc. to which the information processing method according to this embodiment is applied.

[0092] For example, the predetermined process executed by the processing unit 220 according to this embodiment may be issuing an NFT.

[0093] Furthermore, for example, the predetermined process executed by the processing unit 220 according to this embodiment may be issuing a commuter pass.

[0094] Furthermore, for example, the predetermined processing executed by the processing unit 220 according to this embodiment may be activating a smart contract wallet.

[0095] A specific example of the predetermined processing executed by the processing unit 220 according to this embodiment will be described later.

[0096] (Communication Unit 230) The communication unit 230 according to this embodiment performs information communication with the certification device 10 via the network 30.

[0097] For example, the communication unit 230 according to this embodiment receives the zero-knowledge proof Z0 from the proof device 10.

[0098] Furthermore, for example, the communication unit 230 according to this embodiment receives a commitment value related to the second position from the certification device 10 .

[0099] The functional configuration of the information processing system according to the present embodiment has been described above. Note that the functional configuration described above with reference to Figures 3 and 4 is merely an example, and the functional configuration of the information processing system according to the present embodiment is not limited to this example.

[0100] For example, each of the proving device 10 and the verification device 20 may further include a storage unit, an operation unit, a display unit, etc., which are not shown.

[0101] Furthermore, for example, the verification unit 215 and the processing unit 220 may be implemented in different computers.

[0102] The functional configuration of the information processing system according to this embodiment can be flexibly modified according to specifications, operation, and the like.

[0103] <<1.3. Detailed Functions>> Next, the details of the functions of the information processing system according to this embodiment will be described.

[0104] First, the generation and verification of the zero-knowledge proof Z0 will be explained in more detail.

[0105] As described above, the content indicated by the zero-knowledge proof Z0 according to this embodiment may be that the first location and the second location are close to each other.

[0106] Here, the proximity of the first position to the second position may be defined as the first position and the second position being within a predetermined distance.

[0107] Furthermore, in this case, the predetermined distance may be defined by the Euclidean distance, the Manhattan distance, or the like.

[0108] Hereinafter, with reference to FIGS. 5 and 6, a processing flow when the zero-knowledge proof Z0 indicates that the first position and the second position are within a predetermined Euclidean distance will be described.

[0109] FIG. 5 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on Euclidean distance when point P2 (an example of a second location) does not correspond to information to be protected.

[0110] In the example shown in FIG. 5, first, the location information and threshold value of the point P2 are shared between the proving device 10 and the verification device 20 (S101).

[0111] The location information and threshold value of point P2 may be transmitted from the verification device 20 to the proving device 10, or may be transmitted from the proving device 10 to the verification device 20.

[0112] Next, the proof device 10 generates a zero-knowledge proof Z0 based on the location information and threshold of point P2 shared in step S101 and the location information of point P1 (the location of the proof device 10, an example of the first location) acquired (S102).

[0113] The content that the zero-knowledge proof Z0 generated in step S102 proves may be that the distance between point P1 and point P2 is less than or equal to a threshold value.

[0114] The proving device 10 transmits the zero-knowledge proof Z0 generated in step S102 to the verifying device 20 (S103).

[0115] The verification device 20 verifies the zero-knowledge proof Z0 received in step S103 based on the location information of the point P2 and the threshold value shared in step S101 (S104).

[0116] Next, the verification device 20 performs processing based on the result of the verification in step S104 (S105).

[0117] FIG. 6 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on Euclidean distance when point P2 corresponds to information that needs to be protected.

[0118] In the example shown in FIG. 6, first, the proving device 10 transmits a commitment value related to the location information of the point P2 to the verification device 20 (S201).

[0119] Next, the proving device 10 generates a zero-knowledge proof Z0 based on the location information of point P1, the location information of point P2, a threshold value, and the commitment value related to the location information of point P2 transmitted in step S201 (S202).

[0120] The content that the zero-knowledge proof Z0 generated in step S202 proves may be that the distance between point P1 and point P2 is less than or equal to a threshold value.

[0121] The proving device 10 transmits the zero-knowledge proof Z0 generated in step S202 to the verifying device 20 (S203).

[0122] The verification device 20 verifies the zero-knowledge proof Z0 received in step S203 based on the commitment value related to the location information of the point P2 received in step S201 (S204).

[0123] Next, the verification device 20 performs processing based on the result of the verification in step S104 (S205).

[0124] The flow of generating and verifying the zero-knowledge proof Z0 based on the Euclidean distance has been described above.

[0125] According to the process described above, it is possible to prove that the distance between points P1 and P2 is within a predetermined distance without using the position information of points P1 and P2 themselves.

[0126] Next, with reference to FIGS. 7 and 8, a flow of generating and verifying a zero-knowledge proof Z0 based on a geohash value will be described.

[0127] The content that the zero-knowledge proof Z0 according to this embodiment proves may be that the first location and the second location are within a predetermined area.

[0128] In this case, the predetermined area may be defined by a geohash.

[0129] Geohashing is a geocoding method that divides the Earth into multiple rectangular areas and converts the latitude and longitude of the center of each rectangular area into a uniquely identifiable value (geohash value). The size of each rectangular area can be set arbitrarily by adjusting parameters.

[0130] FIG. 7 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on a geohash value in a case where point P2 does not correspond to information that should be protected.

[0131] In the example shown in FIG. 7, first, the geohash value of point P2 is shared between the proving device 10 and the verification device 20 (S301).

[0132] The geohash value of point P2 may be transmitted from the verification device 20 to the proving device 10, or may be transmitted from the proving device 10 to the verification device 20.

[0133] Next, the proving device 10 generates a zero-knowledge proof Z0 based on the geohash value of the point P2 shared in step S301 and the geohash value of the point P1 obtained (S302).

[0134] The content that the zero-knowledge proof Z0 generated in step S302 proves may be that the geohash value of point P1 = the geohash value of point P2.

[0135] The proving device 10 transmits the zero-knowledge proof Z0 generated in step S302 to the verifying device 20 (S303).

[0136] The verification device 20 verifies the zero-knowledge proof Z0 received in step S303 based on the geohash value of the point P2 shared in step S301 (S304).

[0137] Next, the verification device 20 performs processing based on the result of the verification in step S304 (S305).

[0138] FIG. 8 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on a geohash value when point P2 corresponds to information that needs to be protected.

[0139] In the example shown in FIG. 8, first, the proving device 10 transmits the commitment value of the geohash value of point P2 to the verification device 20 (S401).

[0140] Next, the proof device 10 generates a zero-knowledge proof Z0 based on the geohash value of point P1, the geohash value of point P2, and the commitment value of the geohash value of point P2 sent in step S401 (S402).

[0141] The content that the zero-knowledge proof Z0 generated in step S402 proves may be that the geohash value of point P1 = the geohash value of point P2.

[0142] The proving device 10 transmits the zero-knowledge proof Z0 generated in step S402 to the verifying device 20 (S403).

[0143] The verification device 20 verifies the zero-knowledge proof Z0 received in step S403 based on the commitment value of the geohash value of point P2 received in step S401 (S404).

[0144] Next, the verification device 20 performs processing based on the result of the verification in step S404 (S405).

[0145] The flow of generating and verifying a zero-knowledge proof Z0 based on a geohash value has been described above with reference to FIGS.

[0146] According to the process described above, it is possible to prove that both points P1 and P2 are within a predetermined area without using the position information of points P1 and P2 themselves.

[0147] Although FIGS. 7 and 8 show an example in which a predetermined area is defined using a single geohash value, the predetermined area may be defined by a set of multiple geohash values.

[0148] FIG. 9 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on a set of multiple geohash values ​​in a case where point P2 does not correspond to information that needs to be protected.

[0149] In the example shown in FIG. 9, first, the point P2 and the set {h} of geohash values ​​around the point P2 are shared between the proving device 10 and the verification device 20 (S501).

[0150] The set {h} may be transmitted from the verification device 20 to the proof device 10 , or may be transmitted from the proof device 10 to the verification device 20 .

[0151] Next, the proving device 10 generates a zero-knowledge proof Z0 based on the geohash value of the point P1 and the set {h} shared in step S501 (S502).

[0152] The zero-knowledge proof Z0 generated in step S502 may prove that the geohash value of point P1 is included in the set {h}.

[0153] The proving device 10 transmits the zero-knowledge proof Z0 generated in step S502 to the verifying device 20 (S503).

[0154] The verification device 20 verifies the zero-knowledge proof Z0 received in step S503 based on the set {h} shared in step S501 (S504).

[0155] Next, the verification device 20 performs processing based on the result of the verification in step S504 (S505).

[0156] FIG. 10 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on a set of multiple geohash values ​​when point P2 corresponds to information that needs to be protected.

[0157] In the example shown in FIG. 10, first, the proving device 10 transmits the geohash values ​​of point P2 and the vicinity of point P2, and a set of commitment values ​​{comm(h, r)} based on random numbers to the verification device 20 (S601).

[0158] Next, the proving device 10 generates a zero-knowledge proof Z0 based on the geohash value of the point P1 and the set {comm(h, r)} transmitted in step S601 (S602).

[0159] The zero-knowledge proof Z0 generated in step S602 may prove that the geohash value of point P1 is included in the set {h}.

[0160] The proving device 10 transmits the zero-knowledge proof Z0 generated in step S602 to the verifying device 20 (S603).

[0161] The verification device 20 verifies the zero-knowledge proof Z0 received in step S603 based on the set {comm(h, r)} received in step S601 (S604).

[0162] Next, the verification device 20 performs processing based on the result of the verification in step S604 (S605).

[0163] The flow of generating and verifying a zero-knowledge proof Z0 based on a set of multiple geohash values ​​has been described above with reference to FIGS.

[0164] According to the process described above, it is possible to prove that the geohash value of point P1 matches the geohash value of any of the elements of the set without using the geohash value of point P1 itself.

[0165] Furthermore, as described above, the size of the rectangular area of ​​the geohash can be set arbitrarily by adjusting the parameters, and therefore areas of a wide variety of shapes can be formed by appropriately setting the parameters.

[0166] The generation and verification of the zero-knowledge proof Z0 that proves the positional relationship between point P1 and point P2 has been described above with reference to FIGS.

[0167] On the other hand, the content that the zero-knowledge proof Z0 according to this embodiment proves is not necessarily limited to the positional relationship with the point P2.

[0168] For example, as shown in FIG. 11, the proving device 10 may generate a zero-knowledge proof Z0 that proves that a point P1 is within a predetermined area A1.

[0169] In this case, the predetermined area A1 may be defined by a circle of any size, a geohash value, a set of geohash values, or the like.

[0170] The verification device 20 can verify the zero-knowledge proof Z0 based on the information of the predetermined area A1 that has been shared in advance or the commitment value related to the predetermined area A1 that has been received from the proving device 10.

[0171] Next, a countermeasure against tampering with location information according to this embodiment will be described.

[0172] As described above, according to the zero-knowledge proof Z0 of this embodiment, it is possible to prove the first location without disclosing the location information of the first location itself.

[0173] However, if the location information of the first location is tampered with, the reliability of the proof content by the zero-knowledge proof Z0 will be lost.

[0174] To prevent such a situation, a signature may be added to the location information of the first location according to this embodiment. Furthermore, the proving device 10 according to this embodiment may generate a zero-knowledge proof Z0 based on the location information of the first location to which the signature is added.

[0175] In the above, the first location in this embodiment has been mainly described as the current location obtained by the certification device 10, but the first location in this embodiment may also be, for example, a location indicating the base of the user requesting the issuance of the zero-knowledge proof Z0.

[0176] Examples of the user's location include a home, a workplace, a school, etc. Since such locations generally do not change frequently over time, a signature may be assigned by a trusted third party. If the first location is a location indicating the user's location, once a signature is assigned, a zero-knowledge proof Z0 can be generated based on the location information of the signed first location at any time thereafter as long as the location does not change.

[0177] On the other hand, if the first location is the current location acquired by the certification device 10, it is difficult for a third party to provide a signature each time.

[0178] Therefore, the certification device 10 according to this embodiment may add a signature to the location information of the first location within the secure area that the certification device 10 itself has.

[0179] Examples of the secure area include a secure enclave, a hardware security module, and a trusted platform module.

[0180] FIG. 12 is a sequence diagram showing an example of the flow of generating and verifying a zero-knowledge proof Z0 based on the first location information to which a signature is attached in the secure area according to this embodiment.

[0181] In the example shown in FIG. 12, first, the certification device 10 creates a pair of a private key and a public key in the secure area (S701).

[0182] Next, the proving device 10 transmits the public key generated in step S701 to the verifying device 20 (S702).

[0183] Next, the proving device 10, in the secure area, adds a signature to the location information of the point P1 using the private key generated in step S701 (S703).

[0184] Thereafter, the proving device 10 generates a zero-knowledge proof based on the location information of the point P1 to which the signature was added in step S703 (S704).

[0185] The content that the zero-knowledge proof Z0 generated in step S704 proves may be, for example, that the point P1 is within a predetermined area and that a signature has been added to the location information of the point P1.

[0186] Next, the proving device 10 transmits the commitment value of the location information of the point P1 and the zero-knowledge proof Z0 to the verifying device 20 (S705).

[0187] The verification device 20 verifies the authenticity of the zero-knowledge proof Z0 received in step S705 based on the public key received in step S702 and the commitment value of the location information of point P1 received in step S705 (S706).

[0188] Next, the verification device 20 performs processing based on the result of the verification in step S706 (S707).

[0189] According to the processing described above, it is possible to prevent tampering with location information and ensure the reliability of the zero-knowledge proof Z0.

[0190] <<1.4. Application Examples>> Next, more specific application examples of the information processing method according to this embodiment will be described.

[0191] First, an example in which the information processing method according to this embodiment is applied to proof of fan activity will be described.

[0192] FIG. 13 is a diagram for explaining a configuration example in which the information processing method according to this embodiment is applied to proof of fan activity.

[0193] As shown in FIG. 13, in this example, the control unit 210, the verification unit 215, and the processing unit 220 may operate in a smart contract 25 on the blockchain.

[0194] Here, we consider a use case in which, when a user 15 who is a fan of a certain artist or the like is proven to be at a live venue 40 where an event is being held, a participation proof NFT N1 is issued to a smart contract wallet 17 owned by the user 15.

[0195] Proof of participation NFT N1 may be used, for example, to measure engagement in user 15's fan activities.

[0196] A user 15 who has come to a live venue 40 uses a proof device 10 to send a zero-knowledge proof Z0 and an issuance request R1.

[0197] The verification unit 215 verifies the authenticity of the received zero-knowledge proof Z0, and if the verification result is true, instructs the processing unit 220 to issue a participation proof NFT N1.

[0198] 14 is a diagram illustrating an example of what is proven by the zero-knowledge proof Z0 when the information processing method according to this embodiment is applied to proof of fan activity. In this example, a proof based on Euclidean distance is assumed.

[0199] In FIG. 14, point P2 indicates the center (or the center of gravity) of the live music venue 40. The coordinates of point P2 are (x 2 , y 2 )

[0200] 14, a point P1 indicates the position of the certification device 10 acquired by the certification device 10. The coordinates of the point P1 are (x 1 , y 1 )

[0201] In this case, the certification device 10 calculates the coordinates (x 1 , y 1 ) and the coordinates of point P2 (x 2 , y 2 ) is equal to or smaller than a predetermined threshold d.

[0202] In this example, the coordinates of the point P2 (x 2 , y 2 ) does not correspond to the information to be protected, and the coordinates of point P2 (x2 , y 2 ) and the threshold d are assumed to be shared between the proof device 10 and the smart contract 25.

[0203] FIG. 15 is a sequence diagram showing an example of the processing flow when the information processing method according to this embodiment is applied to proof of fan activity.

[0204] In the example shown in FIG. 15, first, the proof device 10 and the smart contract 25 pre-set parameters to be used for generating or verifying the zero-knowledge proof Z0 (S801).

[0205] For example, when using zk-SNARK to generate and verify the zero-knowledge proof Z0, the proof device 10 prepares a proving key provingKey, and the smart contract 25 prepares a verification key verificationKey.

[0206] In addition, the coordinates of the point P2 (x 2 , y 2 ) and threshold d are shared (S802).

[0207] After step S802, the certification device 10 calculates the coordinates (x 1 , y 1 ) is obtained (S803).

[0208] Next, the certification device 10 generates a random number r and calculates the coordinates (x 1 , y 1 ) (S804).

[0209] At this time, the proving device 10 may perform calculations using the following formula, for example, to generate the commitment value comm: Comm in the following formula represents commitment.

[0210] comm=Comm(x 1 , y 1 , r)

[0211] It should be noted that the random number r does not need to be stored after the commitment value comm is generated.

[0212] Next, the proving device 10 generates a zero-knowledge proof Z0 (S805).

[0213] The proving device 10 may generate the zero-knowledge proof Z0 by performing a calculation using the following formula, for example. In the formula below, the zero-knowledge proof Z0 is represented as proof. In the formula below, Prove indicates a calculation using the provingKey.

[0214] proof=Prove(x 1 , y 1 , x 2 , y 2 , r, comm)

[0215] The zero-knowledge proof Z0 generated in step S805 is a proof where comm is the coordinates (x 1 , y 1 ) is correctly generated.

[0216] Furthermore, the zero-knowledge proof Z0 generated in step S805 is the coordinates (x 1 , y 1 ) and the coordinates of point P2 (x 2 , y 2 ) is equal to or smaller than a predetermined threshold d, that is, the following formula is satisfied:

[0217] (x 1 -x 2 ) 2 +(y 1 -y 2 ) 2 ≦d 2

[0218] The proving device 10 calculates the coordinates (x 1 , y 1 ) and the zero-knowledge proof Z0 generated in step S805 (S806).

[0219] The smart contract 25 uses the coordinates (x 2 , y 2 ), the threshold value d, the coordinates (x 1 , y1 ) and verifies the authenticity of the zero-knowledge proof Z0 received in step S806 (S807).

[0220] At this time, the smart contract 25 may perform calculations using the following formula. In the formula below, the zero-knowledge proof Z0 is represented as proof. In the formula below, Verify indicates calculations using verificationKey.

[0221] result=Verify(proof, x 2 , y 2 , d, comm)

[0222] If the verification result result is true, the smart contract 25 issues a participation proof NFT N1 to the smart contract wallet of the user 15 (S808).

[0223] An example in which the information processing method according to this embodiment is applied to proof of fan activity has been described above.

[0224] Next, an example will be described in which the information processing method according to this embodiment is applied to the issuance of a commuter pass (hereinafter referred to as a commuter pass).

[0225] In this example, we consider a use case in which a railway or bus operator issues a commuter pass and verifies whether the nearest station from the applicant's home declared by the applicant is correct.

[0226] In this example, the first location is the applicant's home address, and the second location is the nearest station declared by the applicant.

[0227] FIG. 16 is a sequence diagram showing an example of the flow when the information processing method according to this embodiment is applied to the issuance of a commuter pass.

[0228] In the example shown in FIG. 16, first, the applicant uses the mobile device 50 to present the nearest station and request the issuance of a digital certificate to the certification device 10 installed at the school or workplace where the applicant commutes (S901).

[0229] If the proving device 10 confirms that the applicant's pre-stored home address and the nearest station acquired in step S901 are close to each other, it generates a zero-knowledge proof Z0 that proves this fact (S902).

[0230] Then, the proving apparatus 10 issues a digital certificate including the zero-knowledge proof Z0 generated in step S902 to the mobile device 50 (S903).

[0231] The applicant uses the mobile device 50 to present a digital certificate including the zero-knowledge proof Z0 to the verification device 20 installed by the railway operator (S904).

[0232] The verification device 20 verifies the authenticity of the zero-knowledge proof Z0 included in the digital certificate received in step S904 (S905).

[0233] If the verification result in step S905 is true, the verification device 20 issues a mobile commuter pass to the mobile device 50 (S906).

[0234] According to the process described above, the applicant can purchase a mobile commuter pass without disclosing his / her home address to the railway operator.

[0235] In addition, railway operators can verify whether the nearest station from the applicant's home declared by the applicant is correct without obtaining the applicant's home address, which is information that must be protected.

[0236] Next, with reference to FIG. 17 , an example of applying the information processing method according to this embodiment to risk-based authentication of the smart contract wallet 17 will be described.

[0237] Here, we consider a use case in which risk-based authentication is performed, in which the smart contract wallet 17 is activated only if the current location (an example of a first location) of the user 15 who owns the smart contract wallet 17 is close to their home 45 (an example of a second location).

[0238] In this case, the user 15 uses the proof device 10 to generate a zero-knowledge proof Z0 that proves that the current location is close to the home 45, and sends it together with the operation request R2 of the smart contract wallet 17.

[0239] The verification unit 215 verifies the authenticity of the received zero-knowledge proof Z0, and if the verification result is true, controls the processing unit 220 to issue an active permission A2. Here, the active permission A2 may be a signal that activates the smart contract wallet 17 and makes it operable.

[0240] According to the process described above, risk-based authentication can be achieved without recording the current location of user 15 on the blockchain.

[0241] The application of the information processing method according to this embodiment has been described above using specific examples.

[0242] However, the scope of application of the information processing method according to this embodiment is not limited to the examples described above. Furthermore, the information processing method according to this embodiment can be flexibly modified depending on the service, application, etc. to which it is applied.

[0243] For example, in the above description, the main example was one in which the zero-knowledge proof Z0 proves that the first point P1 and the second point P2 are close to each other, but the zero-knowledge proof Z0 may also prove that the first point P1 and the second point P2 are not close to each other.

[0244] More specifically, the zero-knowledge proof Z0 may prove that the first location and the second location are separated by a predetermined distance or more, or may prove that the first location and the second location are located in different areas.

[0245] Furthermore, the content that the zero-knowledge proof Z0 proves is not limited to that relating to positions in real space, but may also relate to positions on an image.

[0246] For example, in biometric authentication such as fingerprint authentication, it is determined whether the coordinates of feature points extracted from an image match the coordinates of feature points registered in advance. For example, when the information processing method according to this embodiment is applied to fingerprint authentication, it is possible to prove that feature points are in the correct positions while keeping the fingerprint shape itself secret. It is expected that measurement errors can be improved by adjusting the threshold value, etc.

[0247] 2. Hardware Configuration Example Next, a hardware configuration example common to the certification device 10 and the verification device 20 according to an embodiment of the present disclosure will be described. Fig. 18 is a block diagram showing a hardware configuration example of an information processing device 90 according to an embodiment of the present disclosure. The information processing device 90 may be a device having a hardware configuration equivalent to that of each of the above devices.

[0248] 18 , the information processing device 90 includes, for example, a processor 871, a ROM 872, a RAM 873, a host bus 874, a bridge 875, an external bus 876, an interface 877, an input device 878, an output device 879, a storage 880, a drive 881, a connection port 882, and a communication device 883. Note that the hardware configuration shown here is an example, and some of the components may be omitted. Furthermore, the information processing device 90 may include further components other than those shown here.

[0249] (Processor 871) The processor 871 functions, for example, as an arithmetic processing device or control device, and controls the overall operation of each component or part of it based on various programs recorded in the ROM 872, RAM 873, storage 880, or removable storage medium 901.

[0250] (ROM 872, RAM 873) The ROM 872 is a means for storing programs to be read into the processor 871, data to be used for calculations, etc. The RAM 873 temporarily or permanently stores, for example, the programs to be read into the processor 871 and various parameters that change as appropriate when the programs are executed.

[0251] (Host bus 874, bridge 875, external bus 876, interface 877) The processor 871, ROM 872, and RAM 873 are connected to one another via, for example, a host bus 874 that is capable of high-speed data transmission. On the other hand, the host bus 874 is connected to, for example, an external bus 876 that has a relatively low data transmission speed via a bridge 875. Furthermore, the external bus 876 is connected to various components via an interface 877.

[0252] (Input Device 878) For example, a mouse, keyboard, touch panel, button, switch, lever, etc. are used as the input device 878. Furthermore, a remote controller (hereinafter referred to as a remote control) capable of transmitting control signals using infrared rays or other radio waves may also be used as the input device 878. The input device 878 also includes an audio input device such as a microphone.

[0253] (Output Device 879) The output device 879 is a device capable of visually or audibly notifying the user of acquired information, such as a display device such as a CRT (Cathode Ray Tube), LCD, or organic EL, an audio output device such as a speaker or headphones, a printer, a mobile phone, or a facsimile. The output device 879 according to the present disclosure also includes various vibration devices capable of outputting tactile stimulation.

[0254] (Storage 880) The storage 880 is a device for storing various types of data. For example, a magnetic storage device such as a hard disk drive (HDD), a semiconductor storage device, an optical storage device, or a magneto-optical storage device may be used as the storage 880.

[0255] (Drive 881) The drive 881 is a device that reads information recorded on a removable storage medium 901 such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, or writes information to the removable storage medium 901.

[0256] (Removable storage medium 901) The removable storage medium 901 is, for example, a DVD medium, a Blu-ray (registered trademark) medium, an HD DVD medium, various semiconductor storage media, etc. Of course, the removable storage medium 901 may also be, for example, an IC card equipped with a contactless IC chip, an electronic device, etc.

[0257] (Connection Port 882) The connection port 882 is a port for connecting an external device 902, such as a USB (Universal Serial Bus) port, an IEEE 1394 port, a SCSI (Small Computer System Interface), an RS-232C port, or an optical audio terminal.

[0258] (Externally Connected Device 902) The externally connected device 902 is, for example, a printer, a portable music player, a digital camera, a digital video camera, or an IC recorder.

[0259] (Communication device 883) The communication device 883 is a communication device for connecting to a network, such as a communication card for wired or wireless LAN, Bluetooth (registered trademark), or WUSB (Wireless USB), a router for optical communication, a router for ADSL (Asymmetric Digital Subscriber Line), or a modem for various types of communication.

[0260] 3. Summary As described above, the verification device 20 according to an embodiment of the present disclosure executes an information processing method that includes receiving the zero-knowledge proof Z0 generated by the proving device 10 and verifying the authenticity of the content indicated by the zero-knowledge proof Z0. Furthermore, one of the features of the zero-knowledge proof Z0 according to an embodiment of the present disclosure is that it indicates that a first position and a second position have a predetermined positional relationship.

[0261] According to the above configuration, it is possible to verify the positional relationship with high accuracy without acquiring the positional information itself.

[0262] Although the preferred embodiments of the present disclosure have been described in detail above with reference to the accompanying drawings, the technical scope of the present disclosure is not limited to such examples. It is clear that a person skilled in the art of the present disclosure can conceive of various modified or altered examples within the scope of the technical idea described in the claims, and it is understood that these also naturally fall within the technical scope of the present disclosure.

[0263] Furthermore, the steps of the processes described in this disclosure do not necessarily have to be processed in chronological order according to the order shown in the flowcharts or sequence diagrams. For example, the steps of the processes of each device may be processed in an order different from the order shown, or may be processed in parallel.

[0264] Furthermore, the series of processes performed by each device described in this disclosure may be realized by a program stored in a non-transitory computer-readable storage medium. Each program is, for example, loaded into RAM when executed by a computer and executed by a processor such as a CPU. The storage medium may be, for example, a magnetic disk, an optical disk, a magneto-optical disk, or a flash memory. The program may also be distributed, for example, via a network, without using a storage medium.

[0265] Furthermore, the effects described herein are merely descriptive or exemplary and are not limiting. In other words, the technology according to the present disclosure may achieve other effects that are apparent to those skilled in the art from the description of this specification, in addition to or in place of the above-described effects.

[0266] Note that the following configurations also fall within the technical scope of the present disclosure. (1) An information processing method executed by a computer, comprising: receiving a zero-knowledge proof generated by a proof device; and verifying the authenticity of the content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first location and a second location are in a predetermined positional relationship. (2) The information processing method described in (1), wherein the zero-knowledge proof indicates that the first location and the second location are close to each other. (3) The information processing method described in (2), wherein the zero-knowledge proof indicates that the first location and the second location are within a predetermined distance. (4) The information processing method described in (3), wherein the predetermined distance is defined by Euclidean distance or Manhattan distance. (5) The information processing method described in (2), wherein the zero-knowledge proof indicates that the first location and the second location are within a predetermined area. (6) The information processing method described in (5), wherein the predetermined area is defined by a geohash. (7) The information processing method according to any one of (1) to (6), wherein the verifying verifies authenticity of the content indicated by the zero-knowledge proof based on location information related to the second location shared between the proving device and the information processing method according to any one of (1) to (6), further including receiving a commitment value related to the second location generated by the proving device, wherein the verifying verifies authenticity of the content indicated by the zero-knowledge proof based on the commitment value related to the second location. (9) The information processing method according to any one of (1) to (8), wherein the first location is the location of the proving device. (10) The information processing method according to any one of (1) to (8), wherein the first location is a location indicating a base of a user requesting issuance of the zero-knowledge proof. (11) The information processing method according to any one of (1) to (9), wherein the zero-knowledge proof is generated based on the first location to which a signature is attached.(12) The information processing method according to any one of (1) to (11), further comprising: executing a predetermined process based on a result of the verifying. (13) The information processing method according to (12), wherein the predetermined process includes issuing an NFT. (14) The information processing method according to (12), wherein the predetermined process includes issuing a commuter pass. (15) The information processing method according to (12), wherein the process includes activating a smart contract wallet. (16) The information processing method according to any one of (1) to (15), executed by a computer that forms a blockchain. (17) A program that causes a computer to function as an information processing device, comprising: a communication unit that receives a zero-knowledge proof generated by a proving device; and a verification unit that verifies the authenticity of content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first location and a second location are in a predetermined positional relationship. (18) An information processing device comprising: a communication unit that receives a zero-knowledge proof generated by a proof device; and a verification unit that verifies authenticity of content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first position and a second position are in a predetermined positional relationship.

[0267] REFERENCE SIGNS LIST 10 Certification device 110 Control unit 115 Generation unit 120 Location information acquisition unit 130 Communication unit 20 Verification device 210 Control unit 215 Verification unit 220 Processing unit 230 Communication unit

Claims

1. Receiving a zero-knowledge proof generated by a proof device and verifying the authenticity of the content indicated by the zero-knowledge proof, and the zero-knowledge proof indicates that a first position and a second position are in a predetermined positional relationship, an information processing method executed by a computer.

2. The information processing method according to claim 1, wherein the zero-knowledge proof indicates that the first position and the second position are close to each other.

3. The information processing method according to claim 2, wherein the zero-knowledge proof indicates that the first position and the second position are within a predetermined distance.

4. The information processing method according to claim 3, wherein the predetermined distance is defined by a Euclidean distance or a Manhattan distance.

5. The information processing method according to claim 2, wherein the zero-knowledge proof indicates that the first position and the second position are within a predetermined area.

6. The information processing method according to claim 5, wherein the predetermined area is defined by geohash.

7. The information processing method according to claim 1, wherein the verifying verifies the authenticity of the content indicated by the zero-knowledge proof based on the position information related to the second position shared with the proof device.

8. Further including receiving a commitment value related to the second position generated by the proof device, and the verifying verifies the authenticity of the content indicated by the zero-knowledge proof based on the commitment value related to the second position, the information processing method according to claim 1.

9. The information processing method according to claim 1, wherein the first position is the position of the proof device.

10. The information processing method according to claim 1, wherein the first position is a position indicating the base of a user who requests the issuance of the zero-knowledge proof.

11. The information processing method according to claim 1, wherein the zero-knowledge proof is generated based on the first position with a signature.

12. Further including executing a predetermined process based on the verification result by the verifying, the information processing method according to claim 1.

13. The information processing method according to claim 12, wherein the predetermined process includes the issuance of an NFT.

14. The information processing method according to claim 12, wherein the predetermined process includes the issuance of a regular commuter ticket.

15. The information processing method according to claim 12, wherein the process of the process includes the activation of a smart contract wallet.

16. The information processing method according to claim 1, which is executed by a computer forming a blockchain.

17. A program for causing a computer to function as an information processing apparatus, the computer including a communication unit that receives a zero-knowledge proof generated by a proof apparatus, and a verification unit that verifies the authenticity of the content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first position and a second position have a predetermined positional relationship.

18. An information processing apparatus including a communication unit that receives a zero-knowledge proof generated by a proof apparatus, and a verification unit that verifies the authenticity of the content indicated by the zero-knowledge proof, wherein the zero-knowledge proof indicates that a first position and a second position have a predetermined positional relationship.

Citation Information

Patent Citations

  • Location certifying system

    JP2008181166A