Method and system for decentralized identification using login information

A decentralized identity verification system using verifiable credentials and decentralized identity addresses account management and privacy issues by issuing and verifying credentials based on login information, ensuring secure and diverse authentication.

WO2025170217A1PCT designated stage Publication Date: 2025-08-14HOPAE INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/000531
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-01
Filing Date
2025-01-09
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing authentication methods require separate accounts for each service, leading to account management difficulties and privacy issues due to reliance on centralized identity providers, resulting in personal information leaks.

Method used

A decentralized identity verification system using verifiable credentials (VC) and decentralized identity (DID) that issues and verifies credentials based on login information, maintaining compatibility with existing systems while minimizing personal data collection.

Benefits of technology

Provides a highly reliable authentication system that diversifies authentication levels, enhances security, and prevents personal information leakage by using decentralized identity management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025000531_14082025_PF_FP_ABST
    Figure KR2025000531_14082025_PF_FP_ABST
Patent Text Reader

Abstract

According to one aspect of the present invention, a method by which an issuer issues an identification is provided, the method comprising the steps of: receiving login information of a holder by an issuer node; issuing a verifiable credential (VC) on the basis of the received login information; and transmitting the issued VC to a holder node.
Need to check novelty before this filing date? Find Prior Art

Description

Decentralized identity verification method and system using login information

[0001] The present invention relates to a decentralized identity verification method and system using login information.

[0002] Recently, the method of proving the qualifications required for a specific individual to receive the services he or she desires has been rapidly becoming electronic.

[0003] However, the existing authentication method has problems such as the need to create separate accounts for each service, which makes it difficult to manage accounts and passwords, and the user's identity information is dependent on the identity provider (IdP), which frequently leads to privacy violations such as personal information leaks.

[0004] Therefore, there is a significant industry demand for a decentralized identity verification method that can prove necessary credentials using only minimal information and allows users to manage their own identity by integrating identity information distributed across multiple credential providers.

[0005] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.

[0006] In addition, another purpose of the present invention is to provide a highly reliable decentralized identity verification system that can diversify authentication levels while maintaining high compatibility with existing authentication systems and collecting minimal personal information by issuing verifiable credentials (VC) using login information and using decentralized identity (DID) as an identifier.

[0007] A representative configuration of the present invention to achieve the above purpose is as follows.

[0008] According to one aspect of the present invention, a method for issuing an identity certificate by an issuer is provided, the method including the steps of receiving login information of a holder to an issuer node, issuing a verifiable credential (VC) based on the received login information, and transmitting the issued credential (VC) to the holder node.

[0009] According to another aspect of the present invention, a method for verifying an identity by a verifier is provided, the method including the steps of receiving a verifiable presentation (VP) generated from a verifiable credential (VC) issued based on login information of a holder as a verifier node, the step of confirming whether the received VP includes all information necessary for verification, and the step of verifying the VP confirmed to include all information necessary for verification.

[0010] According to another aspect of the present invention, a system for issuing an identity certificate by an issuer is provided, the system including an information receiving unit for receiving login information of a holder to an issuer node, a credential issuing unit for issuing a verifiable credential (VC) based on the received login information, and a credential transmitting unit for transmitting the issued credential (VC) to the holder node.

[0011] According to another aspect of the present invention, a system for verifying identity by a verifier is provided, comprising: a verifiable presentation receiving unit for receiving a verifiable presentation (VP) generated from a credential (VC) issued based on a holder's login information to a verifier node; a verification unit for verifying whether the received VP includes all information required for verification; and a verification unit for verifying the VP confirmed to include all information required for verification.

[0012] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.

[0013] According to the present invention, by issuing a verifiable credential (VC) using login information and using a decentralized identity (DID) as an identifier, a highly reliable decentralized identity authentication system can be provided that collects minimal personal information while maintaining high compatibility with existing authentication systems and diversifying authentication levels.

[0014] FIG. 1 is a diagram schematically showing the overall configuration of a decentralized identity verification system according to one embodiment of the present invention.

[0015] FIG. 2 is a drawing detailing the internal configuration of an identity verification issuance system according to one embodiment of the present invention.

[0016] FIG. 3 is a drawing detailing the internal configuration of an identity verification system according to one embodiment of the present invention.

[0017] FIG. 4 is a diagram schematically illustrating a configuration of a blockchain network and a plurality of nodes included therein according to one embodiment of the present invention.

[0018] <Explanation of symbols>

[0019] 100: Communications network

[0020] 200: Identity Verification Issuance System

[0021] 210: Information Receiving Unit

[0022] 220: Credential Issuance Department

[0023] 230: 1st Communications Department

[0024] 240: First Control Unit

[0025] 300: Identity Verification System

[0026] 310: Proof presentation receiving unit

[0027] 320: Confirmation Department

[0028] 330: Verification Department

[0029] 340: Second Communications Department

[0030] 350: Second Control Unit

[0031] 400: Device

[0032] 500: Multiple nodes

[0033] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.

[0034] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.

[0035] Composition of the entire system

[0036] FIG. 1 is a drawing schematically showing the overall configuration of an entire system (or, an identity verification system) for performing identity verification according to one embodiment of the present invention.

[0037] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), an identity verification system (200), an identity verification system (300), and a device (400).

[0038] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.

[0039] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part.

[0040] Next, an identity certificate issuance system (200) according to one embodiment of the present invention is an identity certificate issuance system by an issuer, and can perform a function of receiving a holder's login information as an issuer node, issuing a credential (verifiable credential, VC) based on the received login information, and transmitting the issued credential (VC) to the holder node. Meanwhile, the identity certificate issuance system (200) may be a digital device having a memory means and a microprocessor to provide computational capabilities, and may be one of a plurality of nodes (500) constituting a distributed ledger to be described specifically, and more specifically, may be an issuer node among the plurality of nodes (500) constituting the distributed ledger, or may include an issuer node.

[0041] The configuration and function of the identity verification issuance system (200) according to one embodiment of the present invention will be described in detail below.

[0042] Next, the identity verification system (300) according to one embodiment of the present invention is a system for verifying identity by a verifier, and can perform a function of receiving a verifiable presentation (VP) generated from a verifiable credential (VC) issued based on the login information of a holder as a verifier node, confirming whether the received VP includes all information necessary for verification, and verifying the confirmed VP in response to the fact that the received VP includes all information necessary for verification. Meanwhile, the identity verification system (300) may be a digital device having a memory means and a microprocessor and having a computing capability, and specifically, may be one of a plurality of nodes (500) constituting the distributed ledger illustrated in FIG. 4, and more specifically, may be a verifier node among the plurality of nodes (500) constituting the distributed ledger, or may include a holder node.

[0043] The configuration and function of the identity verification system (300) according to one embodiment of the present invention will be described in detail below.

[0044] Next, a device (400) according to one embodiment of the present invention is a digital device that includes a function for communicating after connecting to an identity verification system (200) or an identity verification system (300). Any digital device having a memory means and a microprocessor and computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (400) according to the present invention.

[0045] In addition, according to one embodiment of the present invention, the device (400) may further include an application program for performing a function according to the present invention. Such an application may exist in the form of a program module within the device (400). Meanwhile, the nature of such a program module may be generally similar to the information receiving unit (210), the credential issuing unit (220), the first communication unit (230), and the first control unit (240) of the identity certificate issuing system (200), which will be described later, or the certificate presentation receiving unit (310), the confirmation unit (320), the verification unit (330), the second communication unit (340), and the second control unit (350) of the identity certificate verification system (300). Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform a function substantially identical to or equivalent thereto, as necessary.

[0046] In addition, the device (400) according to one embodiment of the present invention may be one of a plurality of nodes (500) constituting the distributed ledger illustrated in FIG. 4, and more specifically, may be a holder node among the nodes constituting the distributed ledger, or may include a holder node.

[0047] Next, the entire system according to one embodiment of the present invention may be configured to include a communication network (100) and a plurality of nodes (500) as illustrated in FIG. 4.

[0048] Each node included in the plurality of nodes (500) according to one embodiment of the present invention is a contact point or connection point that can communicate with other nodes via a communication network (100), and may be a concept including a physical node such as a server, a computer, a laptop, a smart phone, a tablet PC, etc. (i.e., a digital device having a memory means and a microprocessor to provide computational capabilities) or a logical node such as an application, a program module, a virtual machine, etc. (i.e., a virtual node). For example, as described above, the plurality of nodes (500) according to one embodiment of the present invention may include at least one of an issuer node (not shown), a holder node (not shown), and a verifier node (not shown) to be described later.

[0049] Meanwhile, in accordance with one embodiment of the present invention, a plurality of nodes (500) may include an identity certificate issuance system (200) and / or an identity certificate verification system (300) in the form of program modules such as applications and widgets, in order to perform verification based on distributed ledger technology (DLT). In addition, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).

[0050] Distributed ledger technology (DLT), according to one embodiment of the present invention, may refer to a method of storing and managing data in a distributed manner across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledgers described above include, but are not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).

[0051] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which information to be stored on the network is jointly verified by a plurality of nodes (500) participating in the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of a private blockchain and a public blockchain.

[0052] Composition of the identity verification issuance system

[0053] Below, the internal configuration and functions of each component of the identity verification issuance system (200) that performs important functions for implementing the present invention will be examined.

[0054] FIG. 2 is a drawing detailing the internal configuration of an identity verification issuance system (200) according to one embodiment of the present invention.

[0055] As illustrated in FIG. 2, an identity certificate issuing system (200) according to one embodiment of the present invention may include an information receiving unit (210), a credential issuing unit (220), a first communication unit (230), and a first control unit (240). According to one embodiment of the present invention, at least some of the information receiving unit (210), the credential issuing unit (220), the first communication unit (230), and the first control unit (240) of the identity certificate issuing system (200) may be program modules that communicate with an external system (not shown). These program modules may be included in the identity certificate issuing system (200) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may be stored in a remote memory device that can communicate with the identity certificate issuing system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.

[0056] Meanwhile, although the identity certificate issuance system (200) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the identity certificate issuance system (200) may be realized within a device (400) or a server (not shown) or included within an external system (not shown) as needed.

[0057] First, according to one embodiment of the present invention, the information receiving unit (210) can perform a function of receiving the login information of the holder to the issuer node.

[0058] Continuing, a "holder" according to one embodiment of the present invention may refer to an entity possessing a verifiable credential (VC), as described below. The holder receives various pieces of identity information or credentials (VC) from an issuer, stores and manages them, and, if necessary, presents the VC to a verifier in the form of a verifiable presentation (VP), as described below, to request verification.

[0059] According to one embodiment of the present invention, an issuer may refer to an entity that creates and issues a certificate of authenticity (VC) at the request of a specific entity (e.g., the holder described above), and may also be referred to as an issuer. The issuer may add its own electronic signature (or digital signature) to the issued certificate of authenticity (VC). The electronic signature described above guarantees the integrity and authenticity of the certificate of authenticity (VC), and a verifier described below may be used to verify or validate it.

[0060] Specifically, the "issuer" according to one embodiment of the present invention may generally refer to a trustworthy institution or entity, such as an educational institution (e.g., a university), a government agency, a public institution, a company, etc., but should be understood as a general concept that includes all entities capable of issuing the aforementioned credentials (VCs). Meanwhile, as will be described below, the trustworthiness of each institution or entity can be evaluated by a verifier using a method or means according to one embodiment of the present invention, and thus, the trustworthiness may be high, low, or different.

[0061] An issuer node according to one embodiment of the present invention may mean one of the plurality of nodes (500) described above, a node corresponding to an issuer or a node owned by the issuer, and may mean the identity certificate issuance system (200) itself according to one embodiment of the present invention, or may mean a part (or a part of a sub-component) included in the identity certificate issuance system (200).

[0062] Specifically, an issuer node according to one embodiment of the present invention may refer to an account owned by an issuer in a distributed ledger (e.g., a blockchain network). An account in a distributed ledger may represent ownership of digital assets, tokens, cryptocurrencies, etc., and may refer to a unit that can perform transactions. Each account has a unique identifier that uniquely identifies it on the distributed ledger, and this identifier may represent a form of a public key. In addition, according to one embodiment of the present invention, a private key may be digital information set in correspondence with the above account, and may be composed of at least one of letters, symbols, and numbers. For example, according to one embodiment of the present invention, the above private key may be similar to a conventional secret key or private key, and may have a symmetric key or asymmetric key relationship with the identifier of the account discussed above.

[0063] An identity certificate issuance system (200) according to one embodiment of the present invention can issue a credential (VC) using only the holder's login information. Specifically, the login information according to one embodiment of the present invention is a concept that includes all information related to the login action, including the holder's login method, login time, and login target. The identity certificate issuance system (200) according to one embodiment of the present invention can issue a credential (VC) using all or part of the various types of information included in the holder's login information described above.

[0064] The information receiving unit (210) according to one embodiment of the present invention can further receive at least one of the holder's personal information and authentication information along with the holder's login information.

[0065] An identity certificate issuance system (200) according to one embodiment of the present invention can issue an identity certificate by using at least one of the holder's personal information and authentication information along with the holder's login information.

[0066] Personal information, according to one embodiment of the present invention, refers to all information regarding a specific individual's body, identity, property, social status, or identity. Because it can identify or specify a specific individual, either on its own or in combination with other information, it is closely related to the individual's privacy and security. Specifically, personal information according to one embodiment of the present invention includes, but is not limited to, name, email address, phone number, etc.

[0067] According to one embodiment of the present invention, personal authentication information may refer to data used by a specific entity to verify its identity, or any information related to an act of accessing a specific service by authenticating itself using the aforementioned data. Specifically, information related to an act of accessing a specific service by authenticating itself may include, but is not limited to, the authentication entity, the authentication time, or the authentication method.

[0068] Next, according to one embodiment of the present invention, the credential issuing unit (220) can perform a function of issuing a verifiable credential (VC) based on received login information.

[0069] A verifiable credential (VC), according to one embodiment of the present invention, encompasses all verifiable and trustworthy credentials issued in digital format. A VC contains information about an individual or organization's specific qualifications, identity, academic background, career history, and other relevant information. Its reliability can be guaranteed through various verifiable methods. As described above, VCs can be issued, stored, and verified through distributed ledger (or blockchain) technology.

[0070] Specifically, a credential (VC) according to one embodiment of the present invention may be a digital credential (VC) generated according to the "W3C verifiable credentials data model", but is not limited thereto, and various technical standards and open sources may all be utilized in generating a credential (VC) and constructing an identity verification system according to one embodiment of the present invention.

[0071] Furthermore, the identity verification system according to one embodiment of the present invention can be implemented by selecting and combining the technical standards and open source used for each component, within a range that does not compromise its performance and security. Thus, an optimal implementation method can be designed by considering the system environment, constraints, costs, technical expertise, etc., thereby facilitating the introduction of the identity verification system according to one embodiment of the present invention even into legacy systems. Furthermore, by adjusting the portion implemented through open source, implementation costs can be reduced.

[0072] Meanwhile, a credential (VC) is a data structure representing a digital credential and may include multiple sub-elements (i.e., claims) to ensure the authenticity and integrity of the credential (VC). Specifically, these sub-elements include, but are not limited to, '@context' (which defines the meaning and structure of the data), 'type' (which is the type of VC), 'credentialSubject' (which contains information about the subject of the VC), 'issuer' (which is the entity that issued the VC), 'issuanceDate' (which is the date or time the VC was issued), 'expirationDate' (which is the validity period or expiration date or time of the VC), 'proof' (which is digital signature information that ensures the authenticity and integrity of the VC), 'id' (which is a unique identifier for the VC itself), 'status' (which is information about the status of the VC), 'evidence' (which is additional evidence supporting the authenticity of the VC), and 'termsOfUse' (which is the terms of use of the VC).

[0073] Meanwhile, each field included in the above-described 'credentialSubject' can be referred to as a claim, which is information asserted by the issuer regarding a specific subject (e.g., holder). Specifically, all identity information to be proven through the identity verification system according to one embodiment of the present invention can be expressed as data in a digital environment, and each unit of identity information expressed as the above-described data can be referred to as a claim. Specifically, a claim can be structured as "subject - attribute - value." The subject can refer to the object of the claim, the property can refer to the type of identity, and the value can refer to a specific value of the property. For example, when creating a claim to prove that "A was born on 20xx / yy / zz," the subject is A, the attribute is the date of birth, and the value corresponds to the date 20xx / yy / zz.

[0074] Meanwhile, the above-described claim can be used to prove various information. For example, the above-described claim includes, but is not limited to, an identity proof claim ("The holder was born on yy / zz / 20xx"), an education proof claim ("The holder graduated from xx University, Department xx"), or an employment proof claim ("The holder works at xx Company, Job yy"), and any type of information that the issuer asserts or seeks to prove is included in the claim.

[0075] Meanwhile, according to one embodiment of the present invention, one claim can be combined with another claim and other information can be added to create a graph of information.

[0076] Meanwhile, login information, personal information, or user authentication information according to one embodiment of the present invention may be included as a claim in the 'credentialSubject' field described above in the verifiable credential (VC) according to one embodiment of the present invention.

[0077] A credential (VC) issued according to one embodiment of the present invention may include a decentralized identity (DID) of the holder and the issuer as identifiers for the holder and the issuer, respectively.

[0078] An identifier according to one embodiment of the present invention refers to an element used to uniquely identify a specific object. Specifically, the identifier for the issuer refers to an identifier included in a verifiable credential (VC), which may refer to a unique identifier of the issuer who issued the verifiable credential (VC). For example, the 'issuer' field of the credential (VC) may include the issuer's distributed ID as an identifier for the issuer, thereby clearly identifying the issuer of the credential (VC).

[0079] Meanwhile, a credential (VC) may also include the holder's decentralized ID. However, this is included in the 'credentialSubject' field of the credential (VC) as the subject proving through the VC. This should be distinguished from the case where the holder's decentralized ID is included in the 'holder' field when the submitter's decentralized ID is included as the submitter's identifier in a verifiable presentation (VP) described later (since the submitter and the holder are generally the same). In other words, the holder's decentralized ID is included in the 'credentialSubject' field of the VC, and may also be included in the 'holder' field of a VP that includes all or part of the VC.

[0080] Meanwhile, an identifier according to one embodiment of the present invention may be encrypted using asymmetric encryption. The aforementioned asymmetric encryption may refer to an encryption method using a private key and a public key.

[0081] Specifically, a private key according to one embodiment of the present invention is not disclosed and is personally stored by the owner, and a public key corresponding to the private key is disclosed to the outside through a method such as storing or registering in a distributed ledger (or blockchain network).

[0082] Continuing, the private key can be used to encrypt specific data (e.g., login information, personal information, or authentication information according to one embodiment of the present invention), and the public key can be used to decrypt data encrypted via the private key.

[0083] A decentralized identity (DID), according to one embodiment of the present invention, refers to a digital identifier that individuals or organizations can manage independently (i.e., decentralized) without the intervention of a centralized authority. Using a decentralized ID, users can create and manage their own decentralized IDs without relying on a centralized identity provider, and use them to prove their identity.

[0084] Specifically, when a user creates a decentralized ID, a private key and a public key pair are also generated, and the decentralized ID can be used as a unique identifier linking the user to the aforementioned key pair. More specifically, the generated public key is included in a DID document (described below), and the DID document is registered (uploaded) to a distributed ledger (or blockchain network) and made publicly accessible.

[0085] Continuing, since the credential (VC) according to one embodiment of the present invention can include the above-described distributed ID as an identifier, when a verifier wishes to prove the authenticity or integrity of the above-described credential (VC), he / she can access the DID document registered in the distributed ledger using the distributed ID and prove it through the private key of the holder or issuer included in the DID document.

[0086] That is, the identity verification system according to one embodiment of the present invention has the excellent effect of maintaining the security of information used for identity verification through the aforementioned asymmetric encryption method, and also preventing personal information leakage by the identity verification issuer (or issuer) by utilizing a distributed ID method that registers identifiers in a distributed ledger. Furthermore, since the identity verification system according to one embodiment of the present invention can perform identity verification using only login information, it can provide an identity verification means with enhanced security and convenience.

[0087] Next, the identity verification issuance system (200) according to one embodiment of the present invention may further include an information management unit (not shown).

[0088] According to one embodiment of the present invention, the information management unit (not shown) may perform a function of checking the integrity of a credential (VC) in response to the issuance of the credential (VC) by the credential issuing unit (220) and deleting some or all of the information related to the holder from the issuer node.

[0089] For example, it can be assumed that the issuer issuing a credential (VC) already possesses the personal information of the holder, including the account and password, as an entity providing a specific service. When using the identity verification issuance system (200) of the present invention, the credential (VC) can be issued using the login information using the account and password described above. However, when the credential (VC) is issued, the holder's personal information is no longer necessary for the holder's identity verification because the existing account and password have been replaced. Furthermore, since the issuer continues to retain the holder's personal information in the issuer node, there is a need to eliminate the risk of personal information leakage, etc. Therefore, part or all of the information can be deleted in response to the issuance of the credential (VC). Meanwhile, the act of deleting the information described above is managed as a single transaction with the credential (VC) issuance process, so that the entire process either succeeds or fails, thereby preventing data integrity from being compromised, such as when the information described above is not deleted from the issuer node even though the credential (VC) has been issued.

[0090] Meanwhile, deletion of some or all of the information related to the holder in the issuer node can be automatically performed by the information management department without separate external instructions.

[0091] Continuing, the information management unit (not shown) according to one embodiment of the present invention may perform a function of storing a log of the deletion process in the aforementioned issuer node. Specifically, the information management unit (not shown) according to one embodiment of the present invention may delete some or all of the relevant information in response to the issuance of a credential (VC) and separately store a log of the deletion process itself. The log of the deletion process may be used as evidence of whether or not personal information has been deleted (e.g., as legal evidence in a legal dispute related to a personal information leak).

[0092] Continuing, the information management unit (not shown) according to one embodiment of the present invention checking the integrity of the credential (VC) may mean an act of checking that there is no change or tampering in the issuance history of the credential (VC).

[0093] Specifically, checking the integrity of a credential (VC) can be performed by (1) including the content of the credential (VC) in the form of a hash value in a separate field of the credential (VC) (e.g., 'infoHash' field) in response to the credential issuing unit (220) issuing the VC, and (2) storing the log of the credential (VC) issuance (e.g., issuance date, VC identifier, main claims) in the form of a hash value in the issuer node, and then comparing (1) and (2) described above to check for a mismatch. Since the information management unit (not shown) according to one embodiment of the present invention checks the integrity of the credential (VC) in the form of the hash value described above, even if it deletes some or all of the relevant information in response to the issuance of the VC and does not have the actual information, it can continue to verify the integrity of the credential (VC).

[0094] Meanwhile, the above-described integrity check (or integrity audit) can be performed periodically (daily or weekly, etc.).

[0095] Next, the first communication unit (230) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the information receiving unit (210) and the credential issuing unit (220).

[0096] Finally, the first control unit (240) according to one embodiment of the present invention can perform a function of controlling the flow of data between the information receiving unit (210), the credential issuing unit (220), and the first communication unit (230). That is, the first control unit (240) according to one embodiment of the present invention can control the flow of data from / to the outside of the identity certificate issuing system (200) or the flow of data between each component of the identity certificate issuing system (200), thereby controlling the information receiving unit (210), the credential issuing unit (220), and the first communication unit (230) to perform their respective unique functions.

[0097] Composition of the identity verification system

[0098] Below, the internal configuration and functions of each component of the identity verification system (300) that performs important functions for implementing the present invention will be examined.

[0099] FIG. 3 is a drawing detailing the internal configuration of an identity verification system (300) according to one embodiment of the present invention.

[0100] As illustrated in FIG. 3, an identity verification system (300) according to one embodiment of the present invention may include a certificate presentation receiving unit (310), a verification unit (320), a verification unit (330), a second communication unit (340), and a second control unit (350). According to one embodiment of the present invention, at least some of the certificate presentation receiving unit (310), the verification unit (320), the verification unit (330), the second communication unit (340), and the second control unit (350) of the identity verification system (300) may be program modules that communicate with an external system (not shown). These program modules may be included in the identity verification system (300) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may be stored in a remote memory device that can communicate with the identity verification system (300). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.

[0101] Meanwhile, although the identity verification system (300) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the identity verification system (300) may be realized within a device (400) or a server (not shown) or included within an external system (not shown) as needed.

[0102] First, according to one embodiment of the present invention, the proof presentation receiving unit (310) can perform a function of receiving a verifiable presentation (VP) generated from a verifiable credential (VC) issued based on the login information of the holder to a verifier node.

[0103] A verifiable presentation (VP) according to one embodiment of the present invention is a data structure used to present a credential (VC) to a verifier, and may be generated by (1) selecting and combining one or more of a plurality of claims included in a single credential (VC), or (2) combining a plurality of credential (VC). Accordingly, when a credential (VC) is converted into the form of a verifiable presentation (VP) and submitted to a verifier, the holder can present only the desired data (or claim) or the data (or claim) required for verification for verification, and the verifier can use only the desired data (or claim) for verification by specifying the data (or claim) required for verification.

[0104] According to one embodiment of the present invention, a verifier may refer to an entity that verifies the authenticity and integrity of a credential (VC) by verifying the aforementioned credentials. The verifier can verify the credentials or identity of the owner (i.e., holder) of the credential (VC) in a reliable manner.

[0105] A verifier node according to one embodiment of the present invention may mean one of the plurality of nodes (500) described above, a node corresponding to a verifier, or a node owned by a verifier, and may mean the identity verification system (300) itself according to one embodiment of the present invention, or may mean a part (or a part of a sub-component) included in the identity verification system (300).

[0106] A proof presentation (VP) according to one embodiment of the present invention may include a decentralized identity (DID) of the submitter as an identifier for the submitter.

[0107] As described above, since the holder of a credential (VC) and the submitter of a proof presentation (VP) can generally be the same, the credential presentation (VP) may include (1) a decentralized ID in the 'credentialSubject' field to identify the holder, the entity to whom the credential (VC) was issued, and (2) a decentralized ID in the 'holder' field to identify the submitter of the proof presentation (VP) generated through the credential (VC) (i.e., the holder's decentralized ID).

[0108] Next, according to one embodiment of the present invention, the verification unit (320) can perform a function of verifying whether the received proof presentation (VP) includes all information required for verification.

[0109] According to one embodiment of the present invention, the verification unit (320) confirms that the received proof presentation (VP) includes all the information necessary for verification, which means that the verifier can determine the type and amount of information required when verifying the holder's qualifications and providing a specific service through it. For example, if the verifier wants to provide a product delivery service to the holder, the verifier may only request address information for delivery and not request other unnecessary information such as name and personal contact information. In this situation, the verification unit (320) can only confirm that the received proof presentation (VP) of the holder includes address information for delivery, and can forward the proof presentation (VP) to the next step, which is the verification step, in response to the confirmation.

[0110] As another example, the verification unit (320) according to one embodiment of the present invention may, in response to a received proof presentation (VP) not containing all the information required for verification, suggest to the submitter (i.e., holder) of the proof presentation (VP) to submit additional required data, claims, or credentials (VC).

[0111] Next, according to one embodiment of the present invention, the verification unit (330) can perform a function of verifying a verified proof presentation (VP) in response to the fact that the received proof presentation (VP) includes all information necessary for verification.

[0112] According to one embodiment of the present invention, verifying a proof presentation (VP) may refer to a process of confirming that the VP and the credential (VC) contained therein are authentic (i.e., authenticity), have not been tampered with (i.e., integrity), and have been issued and presented by a trustworthy entity. This verification process may be performed by verifying, through the public key of the holder contained in the proof presentation (VP), whether the VP was actually presented by the holder of the corresponding proof, and verifying, through the public key of the issuer, that the credential (VC) was issued by a trustworthy issuer and has not been tampered with.

[0113] Specifically, a verification unit according to one embodiment of the present invention can perform a function of verifying the authenticity and integrity of a proof presentation (VP) using an issuer's DID document and a holder's DID document recorded in a distributed ledger.

[0114] As described above, in the process of verifying the authenticity and integrity of the proof presentation (VP), the public keys of the holder and issuer are used. By recording or storing these public keys in the form of a DID document on a distributed ledger (e.g., blockchain), the authenticity and integrity of the proof presentation (VP) can be verified without the intervention of a centralized institution, and thus, it can be used as a decentralized identity verification method.

[0115] Specifically, a credential (VC) or proof presentation (VP) according to one embodiment of the present invention includes a distributed ID of an issuer and a holder, and when a verifier wishes to verify the credential (VC) or proof presentation (VP), the verifier can use the distributed ID to find a DID document recorded in a distributed ledger and obtain a public key. Meanwhile, the credential (VC) or proof presentation (VP) includes an electronic signature (or digital signature) generated by the issuer and the holder using their own private key (secret key), and the verifier can verify the credential (VC) or proof presentation (VP) by verifying whether the electronic signature was generated using the private key of the issuer and the holder through the obtained public key. The above-described electronic signature may be included in the 'proof' field of the credential (VC) or proof presentation (VP).

[0116] Meanwhile, since DID documents contain metadata in addition to the public key, verifiers can use this metadata to verify that a credential (VC) or proof presentation (VP) is within its validity period and meets all required conditions. For example, a verifier can verify the validity of a credential (VC) by checking the "issuanceDate" and "expirationDate" of the credential (VC) contained in the metadata and confirming that the current date does not exceed the "expirationDate."

[0117] Specifically, the proof presentation receiving unit (310) according to one embodiment of the present invention can select a proof presentation (VP) to be verified based on the reliability of the proof presentation (VP).

[0118] Specifically, a verifier can determine whether to pass a received Proof Presentation (VP) to the next step (i.e., verifying that all the information required for verification is included) by evaluating and calculating the trustworthiness of the Proof Presentation (VP) or the trustworthiness of the issuer of the Credential (VC) used to generate the VP. The trustworthiness can be evaluated using predetermined criteria established by the verifier, and the trustworthiness can be utilized in such a way as to independently manage a registry of trusted authentication methods based on the calculated trustworthiness and only trust and verify credentials (VC) issued using authentication methods included in the aforementioned list.

[0119] Meanwhile, the aforementioned trust level can be adjusted by applying different criteria depending on the type of service, thereby adjusting the level of information required for authentication (identity verification). For example, for financial services, trust can be set to only rely on FIDO (Fast Identity Online) second-factor authentication or credentials (VCs) issued with public certificates. Meanwhile, for services like gaming, which require a relatively low level of authentication, trust can also be set to rely on mobile phone SMS authentication, thereby adjusting the required level of authentication.

[0120] Next, the second communication unit (340) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the proof presentation receiving unit (310), the confirmation unit (320), and the verification unit (330).

[0121] Finally, the second control unit (350) according to one embodiment of the present invention can perform a function of controlling the flow of data between the certificate presentation receiving unit (310), the confirmation unit (320), the verification unit (330), and the second communication unit (340). That is, the second control unit (350) according to one embodiment of the present invention can control the flow of data from / to the outside of the identity verification system (300) or the flow of data between each component of the identity verification system (300), thereby controlling the certificate presentation receiving unit (310), the confirmation unit (320), the verification unit (330), and the second communication unit (340) to perform their own functions.

[0122] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0123] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.

[0124] Therefore, the idea of ​​the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of ​​the present invention.

Claims

1. A method of issuing identification by an issuer, A step of receiving the holder's login information to the issuer node; A step of issuing a verifiable credential (VC) based on the received login information, and Including a step of transmitting the issued credentials to the holder node. method.

2. In paragraph 1, At least one of the holder's personal information and identity verification information is received in the above receiving step. method.

3. In paragraph 1, The above issued credentials include the decentralized identity (DID) of the holder and issuer as identifiers for the holder and issuer. method.

4. In paragraph 1, In response to the issuance of the above credentials, further comprising a step of verifying the integrity of the credentials and deleting some or all of the information related to the holder from the issuer node. method.

5. In paragraph 4, In the above deletion step, the log for deletion processing is stored in the issuer node. method.

6. As a method of verifying identity by a verifier, A step of receiving a verifiable presentation (VP) generated from a verifiable credential (VC) issued based on the holder's login information as a verifier node. A step of verifying that the above received proof presentation contains all the information required for verification, and A step of verifying the confirmed proof presentation in response to the fact that the received proof presentation contains all the information required for verification. method.

7. In paragraph 6, The above proof presentation includes the submitter's decentralized identity (DID) as an identifier for the submitter. method.

8. In paragraph 6, In the above verification step, the authenticity and integrity of the proof presentation are verified using the issuer's DID document and the holder's DID document recorded in the distributed ledger. method.

9. In paragraph 6, In the above receiving step, the proof presentation to be verified is selected based on the reliability of the proof presentation. method.

10. A non-transitory computer-readable recording medium recording a computer program for executing the method according to any one of paragraphs 1 and 6.

11. As a system for issuing identification certificates by issuers, An information receiving unit that receives the holder's login information from the issuer node; A credential issuing unit that issues a verifiable credential (VC) based on the received login information, and Including a credential transmission unit that transmits the issued credential to the holder node. System.

12. In paragraph 11, The above information receiving unit further receives at least one of the holder's personal information and identity verification information. System.

13. In paragraph 11, The above issued credentials include the decentralized identity (DID) of the holder and issuer as identifiers for the holder and issuer. System.

14. In paragraph 11, Further comprising an information management unit that verifies the integrity of the credential in response to the issuance of the credential and deletes some or all of the information related to the holder from the issuer node. System.

15. In paragraph 14, The above information management unit stores the log for deletion processing in the above issuer node. System.

16. As a verification system for identity verification by a verifier, A proof presentation receiving unit that receives a verifiable presentation (VP) generated from a verifiable credential (VC) issued based on the holder's login information as a verifier node; A verification unit that verifies whether the above received proof presentation contains all the information required for verification, and Including a verification unit that verifies the confirmed proof presentation in response to the fact that the received proof presentation contains all the information necessary for verification. System.

17. In paragraph 16, The above proof presentation includes the submitter's decentralized identity (DID) as an identifier for the submitter. System.

18. In paragraph 16, The above verification unit verifies the authenticity and integrity of the proof presentation using the issuer's DID document and the holder's DID document recorded in the distributed ledger. System.

19. In paragraph 16, The above proof presentation receiving unit selects the proof presentation to be verified based on the reliability of the proof presentation. System.

Citation Information

Patent Citations

  • Login authentication system and program for login authentication system

    JP2023172125A

  • Block Chain Using Methods With Web Login

    KR101975471B1

  • Augmentative and alterative communication system

    KR102112822B1

  • Method and apparatus for automatic website login using Decentralized Identifier(DID)

    KR102600516B1

  • KR20240002888A