Method and system for supporting context-based use of verifiable presentation

A context-aware system optimizes credential presentation and transmission by automatically selecting communication methods based on situational analysis, addressing the limitations of existing systems and enhancing user convenience and security.

WO2025170225A1PCT designated stage Publication Date: 2025-08-14HOPAE INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/000777
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-11-14
Filing Date
2025-01-14
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing methods for presenting and transmitting verifiable credentials are inconvenient and limited in their ability to support diverse verification environments, requiring users to manually select communication technologies and lacking flexibility.

Method used

A context-aware system that automatically selects and recommends the optimal method for presenting and transmitting verifiable credentials using various communication technologies based on situational analysis, allowing simultaneous activation of multiple methods for seamless interaction.

Benefits of technology

Enhances user convenience and responsiveness to diverse verification environments by optimizing credential presentation and transmission, ensuring efficient and secure interactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025000777_14082025_PF_FP_ABST
    Figure KR2025000777_14082025_PF_FP_ABST
Patent Text Reader

Abstract

Provided, according to one aspect of the present invention, is a method for supporting use of a verifiable presentation (VP), the method comprising the steps of: determining at least one of a type of a verifiable presentation to be presented at a first time point, a presentation method of the verifiable presentation, and a transmission method of the verifiable presentation, on the basis of contextual information for verification associated with a holder node at the first time point; and requesting verification of the verifiable presentation from a verifier node on the basis of the determined at least one of the type of the verifiable presentation to be presented at the first time point, the presentation method of the verifiable presentation, and the transmission method of the verifiable presentation.
Need to check novelty before this filing date? Find Prior Art

Description

Methods and systems for supporting the use of context-based proof presentation

[0001] The present invention relates to a method and system for supporting the use of context-based proof presentation.

[0002] Recently, the method of proving the qualifications required to receive desired services is rapidly becoming digitalized. This method is performed by presenting verifiable credentials (VC), which are digital representations of specific qualifications held by the holder, in the form of a verifiable presentation (VP), and having the verifier verify this.

[0003] Traditionally, the presentation and transmission of proofs utilizes a variety of communication technologies, including QR, camera, NFC, Bluetooth, UWB, and WiFi. This has led to inconveniences for users, who must select and configure the optimal method for each situation. Furthermore, the fixed use of a single method has limited its ability to support all verification environments.

[0004] Accordingly, the present invention proposes a method or system that automatically selects and provides an optimal method appropriate to the situation in the process of presenting and transmitting proof by utilizing various communication technologies including the above-described communication technologies.

[0005] The present invention utilizes the context-aware functionality built into the user's device's digital wallet to analyze the current situation and recommend or automatically activate the most appropriate proof presentation type and transmission method. Furthermore, multiple methods can be activated simultaneously as needed, enabling rapid authentication, increased user convenience, and flexible response to diverse verification environments. This allows users to utilize the optimal proof presentation and transmission method without additional setup, enabling seamless interaction with verifiers.

[0006] In conclusion, when utilizing the present invention, it is expected that there will be improvements in various aspects, such as convenience in the process of presenting and transmitting proof presentation, responsiveness to the verification environment, and security. In addition, it is expected that flexible implementation tailored to the characteristics of the service will be possible by utilizing various technical options, thereby increasing the usability of proof presentation-based services and accelerating their popularization.

[0007] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.

[0008] In addition, the present invention determines at least one of the type of proof presentation to be presented at a first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation based on verification situation information related to the holder node at a first time point, and requests verification of the proof presentation to a verifier node based on at least one of the type of proof presentation to be presented at the determined first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation.

[0009] In addition, another purpose of the present invention is to provide a verification method that can maximize user convenience by automatically selecting and recommending to the user the type of credential or proof presentation to be presented and the optimal presentation and transmission method based on surrounding situation information during the process of presenting the credential, or by exchanging feedback with the user during the process of presenting the credential.

[0010] A representative configuration of the present invention to achieve the above purpose is as follows.

[0011] According to one aspect of the present invention, a method is provided, including a step of determining at least one of a type of proof presentation to be presented at a first time point, a presentation method of the proof presentation, and a transmission method of the proof presentation based on verification situation information related to a holder node at a first time point, and a step of requesting verification of the proof presentation to a verifier node based on at least one of the type of proof presentation to be presented at the determined first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation.

[0012] According to another aspect of the present invention, a system is provided, including a determining unit that determines at least one of a type of proof presentation to be presented at a first time point, a presentation method of the proof presentation, and a transmission method of the proof presentation based on verification situation information related to a holder node at a first time point, and a verification request unit that requests verification of the proof presentation to a verifier node based on at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation determined.

[0013] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.

[0014] According to the present invention, at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation is determined based on verification situation information related to the holder node at the first time point, and verification of the proof presentation can be requested to the verifier node based on at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation determined.

[0015] In addition, according to the present invention, in the process of presenting a credential, the type of credential or proof presentation to be presented and the optimal presentation and transmission method are automatically selected and recommended to the user based on the surrounding situation information, or the user's convenience is maximized by exchanging feedback with the user in the process of presenting the credential.

[0016] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the use of proof presentation according to one embodiment of the present invention.

[0017] FIG. 2 is a drawing showing in detail the internal configuration of a proof presentation use support system according to one embodiment of the present invention.

[0018] FIG. 3 is a diagram schematically illustrating a configuration of a blockchain network and a plurality of nodes included therein according to one embodiment of the present invention.

[0019] <Explanation of symbols>

[0020] 100: Communications network

[0021] 200: Proof-of-Use Support System

[0022] 210: Decision

[0023] 220: Verification Request Department

[0024] 230: Security Department

[0025] 240: Feedback transmitter

[0026] 250: Feedback receiving unit

[0027] 260: Communications Department

[0028] 270: Control Unit

[0029] 300: Device

[0030] 400: Multiple nodes

[0031] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.

[0032] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.

[0033] Composition of the entire system

[0034] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the use of proof presentation according to one embodiment of the present invention.

[0035] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a proof presentation use support system (200), and a device (300).

[0036] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.

[0037] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part.

[0038] Next, the proof presentation use support system (200) according to one embodiment of the present invention can communicate with the device (300) described later through the communication network (100). In addition, the proof presentation use support system (200) according to one embodiment of the present invention can determine at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation described above, and the transmission method of the proof presentation described above based on verification situation information related to the holder node at the first time point, and can perform a function of requesting verification of the proof presentation to the verifier node based on at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation determined above. Meanwhile, the proof presentation use support system (200) may be a digital device equipped with a memory means and a microprocessor to have a computing capability, and specifically, may be one of a plurality of nodes constituting the distributed ledger illustrated in FIG. 3, and more specifically, may include a holder node among a plurality of nodes (400) constituting the distributed ledger.

[0039] The configuration and function of the proof presentation use support system (200) according to one embodiment of the present invention will be described in detail below.

[0040] Next, a device (300) according to one embodiment of the present invention is a digital device that includes a function for communicating after connecting to a certificate presentation support system (200), and any digital device that has a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (300) according to the present invention.

[0041] In addition, according to one embodiment of the present invention, the device (300) may further include an application program for performing a function according to the present invention. Such an application may exist in the form of a program module within the device (300). Meanwhile, the nature of such a program module may be generally similar to the decision unit (210), verification request unit (220), security unit (230), feedback transmission unit (240), feedback reception unit (250), communication unit (260), and control unit (270) of the certificate presentation use support system (200) described below. Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform a function substantially identical to or equivalent thereto, as necessary.

[0042] In addition, the device (300) according to one embodiment of the present invention may be one of a plurality of nodes (400) constituting the distributed ledger illustrated in FIG. 3, and more specifically, may be a holder node among the nodes constituting the distributed ledger, or may include a holder node, and the holder node described above may include all or part of the proof presentation use support system (200) according to one embodiment of the present invention.

[0043] However, as described above, the node (including the issuer node, holder node, and verifier node) according to one embodiment of the present invention is one of multiple nodes constituting a distributed ledger (or blockchain network), and this is merely an example and is not limiting. In other words, the node according to one embodiment of the present invention may refer to any type of reliable storage means that serves as a participant that verifies and stores data and exchanges information with other nodes to maintain the integrity and consistency of the entire system.

[0044] Next, the entire system according to one embodiment of the present invention may be configured to include a communication network (100) and a plurality of nodes (400) as illustrated in FIG. 3.

[0045] Each node included in a plurality of nodes (400) according to one embodiment of the present invention is a contact point or connection point that can communicate with other nodes through a communication network (100), and may be a concept including a physical node such as a server, computer, laptop, smart phone, tablet PC, etc. (i.e., a digital device equipped with memory means and equipped with a microprocessor to have computational capabilities) or a logical node such as an application, program module, virtual machine, etc. (i.e., a virtual node).

[0046] Specifically, each node included in the plurality of nodes (400) according to one embodiment of the present invention may be a digital wallet in itself or may include a digital wallet. A digital wallet is a software or hardware device that allows a user to securely store and manage digital assets, authentication information, identity information, etc., and refers to a means for storing various data and enabling the use of the stored data as needed. For example, an issuer node may refer to a digital wallet owned by an issuer, a holder node may refer to a digital wallet owned by a holder, and a verifier node may refer to a digital wallet owned by a verifier. The above-described holder node (or digital wallet owned by a holder) may include a proof presentation support system (200) according to one embodiment of the present invention.

[0047] According to one embodiment of the present invention, the issuer node, the holder node, and the verifier node may correspond to each node included in a plurality of nodes (400).

[0048] Meanwhile, in order to support the use of proof presentation based on distributed ledger technology (DLT), a plurality of nodes (400) according to one embodiment of the present invention may include a proof presentation use support system (200) according to the present invention in the form of a program module such as an application or widget. In addition, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).

[0049] Distributed ledger technology (DLT), according to one embodiment of the present invention, may refer to a method of storing and managing data distributedly across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledgers described above include, but are not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).

[0050] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which information to be stored on the network is jointly verified by a plurality of nodes (400) participating in the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of a private blockchain and a public blockchain.

[0051] Configuration of a system that supports the use of proof presentation

[0052] Below, the internal configuration and functions of each component of the proof presentation use support system (200) that performs important functions for implementing the present invention will be examined.

[0053] FIG. 2 is a drawing showing in detail the internal configuration of a proof presentation use support system (200) according to one embodiment of the present invention.

[0054] As illustrated in FIG. 2, a certificate presentation use support system (200) according to one embodiment of the present invention may include a decision unit (210), a verification request unit (220), a security unit (230), a feedback transmission unit (240), a feedback reception unit (250), a communication unit (260), and a control unit (270). According to one embodiment of the present invention, at least some of the decision unit (210), the verification request unit (220), the security unit (230), the feedback transmission unit (240), the feedback reception unit (250), the communication unit (260), and the control unit (270) of the certificate presentation use support system (200) may be program modules that communicate with an external system (not shown). These program modules may be included in the certificate presentation use support system (200) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. Additionally, these program modules may be stored in a remote storage device capable of communicating with the proof presentation support system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described below, according to the present invention.

[0055] Meanwhile, although the proof presentation use support system (200) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the proof presentation use support system (200) may be realized within a device (300) or a server (not shown) or included within an external system (not shown) as needed.

[0056] First, according to one embodiment of the present invention, the decision unit (210) may perform a function of determining at least one of the type of proof presentation to be presented at the first time point, the presentation method of the above-described proof presentation, and the transmission method of the above-described proof presentation based on verification situation information related to the holder node at the first time point.

[0057] A verifiable presentation (VP) according to one embodiment of the present invention may be all or part of a credential (VC), which is a set of metadata that can be used in a credential mechanism operating on the web, or may be a set of multiple credentials. A credential is issued and owned by a holder from an issuer, and a verifiable presentation is presented by the holder to a verifier and used to prove a specific qualification. When the above-described proof presentation is transmitted to the verifier for verification, the type of proof presentation to be presented (or the type of claim to be presented), the method of presenting it (i.e., the presentation method), and the method of transmitting the data (i.e., the transmission method) must be determined. These elements need to be independently determined as an optimal method for various environments in order to maximize the accuracy and efficiency of verification and the convenience of users (mainly holders).

[0058] The proof presentation according to one embodiment of the present invention is a data structure used to present a credential to a verifier, and as described above, may be all or part of the credential, or a set of multiple credentials. Specifically, this may mean (1) selecting and combining one or more of the multiple claims (i.e., items to be proven) included in a single credential, or (2) creating a credential by combining multiple credentials. Accordingly, when a credential is converted into the form of a proof presentation and submitted to a verifier, the holder can present only the desired data (or claims) or the data (or claims) required for verification for verification, and the verifier can use only the desired data (or claims) for verification by specifying the data (or claims) required for verification.

[0059] According to one embodiment of the present invention, a credential encompasses all verifiable and trustworthy credentials issued in digital format. Credentials include information about an individual or organization's specific qualifications, identity, academic background, career history, etc., and their reliability can be guaranteed through various verifiable methods. As described above, they can be issued, stored, and verified through distributed ledger (or blockchain) technology. Meanwhile, a credential is a data structure representing a digital credential and may include multiple sub-elements (i.e., claims) to ensure its authenticity and integrity.

[0060] According to one embodiment of the present invention, a "holder" may refer to an entity possessing a credential or proof presentation. The holder receives, stores, and manages various identification information or credentials issued by an issuer. If necessary, the holder may present the credentials to a verifier in the form of the aforementioned proof presentation to request verification.

[0061] According to one embodiment of the present invention, an issuer may refer to an entity that creates a credential and issues it to the holder. Typically, an issuer is a trusted institution or organization with the authority to verify information about an individual or organization and issue a credential that verifies that information. Issuers may include various institutions, such as universities, government agencies, financial institutions, and employers.

[0062] According to one embodiment of the present invention, a verifier may refer to an entity that verifies the authenticity and integrity of a credential by verifying the aforementioned credentials. The verifier can verify the credentials or identity of the owner (i.e., holder) of the credential in a reliable manner.

[0063] As described above, according to one embodiment of the present invention, the holder, issuer, and verifier may correspond to the holder node, issuer node, and verifier node included in the plurality of nodes (400) according to one embodiment of the present invention, respectively.

[0064] According to one embodiment of the present invention, the first point in time may refer to a point in time included in the process of using the credential presentation support system according to one embodiment of the present invention. Specifically, according to one embodiment of the present invention, the first point in time may refer to a point in time or a time interval included in the verification request step of requesting or attempting verification using a credential or credential presentation.

[0065] The context information for verification according to one embodiment of the present invention should be understood as a concept encompassing all surrounding context information related to the process of requesting verification using a credential or proof presentation. Specifically, the context information for verification according to one embodiment of the present invention may refer to information related to a holder or a holder node during the process of requesting verification using a credential or proof presentation. More specifically, the information related to the holder or holder node described above may include both (1) information regarding the status or situation of the holder or holder node, and (2) information related to the process of requesting verification of a credential or proof presentation by the holder or holder node.

[0066] More specifically, the verification situation information described above may refer to information on the surrounding state or situation of the holder node collected by various sensors included in the holder node (or a digital wallet or device including the holder node). The types of sensors described above and the surrounding conditions or circumstances collected therefrom include (a) various information related to the location or coordinates of the holder node collected by GPS (latitude, longitude, altitude, speed, direction of movement, etc.), (b) various information related to linear acceleration, inclination, gravity, shock, vibration, position change, or movement of the holder node (or the holder) collected by an acceleration sensor, (c) various information related to the angular velocity, rotational direction, or (holder's) attitude change of the holder node collected by a gyroscope, (d) various information related to the distance between the holder node and other objects, contact, presence or absence of surrounding objects, blockage of light by surrounding objects, or movement of surrounding objects collected by a proximity sensor, (e) various information related to the intensity of light (illuminance), change in intensity of light, color of light, or spectrum of light collected by an illuminance sensor, (f) the type of communication means used or used by the holder node (e.g., WiFi or Bluetooth, etc.) or communication status (e.g., signal strength, transmission related to the connection status of WiFi) (g) information related to the type of presentation medium used or used by the holder node; (h) information related to the temperature around the holder node detected by the temperature sensor; (i) information related to the pressure applied to the holder node detected by the pressure sensor; (j) information related to the sound or sound pressure of the surrounding environment of the holder node detected by the sound sensor; and (k) information related to the contact or pressure of an object against the holder node detected by the touch sensor.Any type of sensor or information collected therefrom that can be used to improve the efficiency of verification of a credential or proof presentation (e.g., verification speed, verification accuracy, or user (holder) convenience, etc.) may be included in the verification context information.

[0067] The type of proof presentation according to one embodiment of the present invention refers to a type of proof presentation that can be generated from one or more credentials held by a holder, and may refer to a proof presentation that requests verification using a proof presentation support system according to one embodiment of the present invention. For example, let's assume a situation where a holder holding a resident registration card and a driver's license as credentials wants to prove his or her identity. At this time, the holder can select (1) a resident registration card, (2) a driver's license, (3) a combination thereof, or (4) some of the multiple claims included in each credential, convert them into a proof presentation, and request verification. In this case, the proof presentation generated from the credentials selected as in (1) to (4) described above may be referred to as a "type of proof presentation."

[0068] The presentation method according to one embodiment of the present invention may refer to a plurality of means that can be used to present credentials or proof. Specifically, the presentation methods described above include, but are not limited to, a method using a QR code, a method using a camera, a method using a smart card with a built-in chip, a biometric recognition method using biometric data (e.g., fingerprints, irises, faces, voices, etc.), a method presenting a barcode, a method using a text message (SMS) or email containing an authentication code or link for authentication, a method using a dedicated application (including a mobile application), a method using a web browser, a method using a cloud storage link, and a method using a social media account.

[0069] The transmission method according to one embodiment of the present invention may refer to a communication means for transmitting a credential or proof presentation from a holder node to a verifier node. Specifically, the above-described transmission method includes, but is not limited to, WiFi, Bluetooth, NFC (near field communication), cellular networks such as 4G and 5G, Ethernet, RFID (radio frequency identification), and Zigbee / Z-Wave (low power wireless communication), and various types of transmission means may all be included in the transmission method according to one embodiment of the present invention.

[0070] According to one embodiment of the present invention, a decision unit (210) may determine at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation based on the verification situation information related to the holder node at the first time point. Specifically, according to one embodiment of the present invention, a decision unit (210) may receive and analyze the various verification situation information described above to determine the type of proof presentation, the presentation method thereof, and the transmission method thereof that are most suitable for the situation at the first time point (e.g., the current time point at which verification of the proof presentation is required). Meanwhile, as described below, the types, presentation methods, and transmission methods of the proof presentation described above may each be independently selected one by one, or a plurality of types or methods may be selected and combined and used simultaneously.

[0071] Continuing, for example, we can assume a situation where a resident registration card, a company entry / exit card, and an apartment entry / exit card are stored in the holder node. At this time, the proof presentation use support system according to an embodiment of the present invention can (1) select the company entry / exit card (or, a claim necessary for entry among multiple claims included therein) as the "type of proof presentation to be presented" in response to verification context information that the user (or, holder) of the holder node has arrived at work and is located in the company lobby, (2) select the "transmission method" as WiFi (or, among multiple company WiFis, select the WiFi with the strongest signal in the lobby, etc.) in response to verification context information that the connection to the company WiFi is smooth in the company lobby, and (3) select the "presentation method" as QR code in response to verification context information that the presentation method that can be recognized by the entry / exit device located in the company lobby is a QR code and that there is a history of using the presentation method in the past (second time). Meanwhile, the selection of the proof presentation support system according to the above-described embodiment of the present invention can be performed without user intervention (i.e., automatically) as needed. The above-described examples are merely a few examples of how the proof presentation support system according to the embodiment of the present invention can be used, and it is obvious to those skilled in the art that the proof presentation support system according to the embodiment of the present invention can be applied to any situation, condition, or scenario where proof presentation can be utilized.

[0072] As another example, let's assume a situation where a user of the aforementioned holder node enters the company lobby but cannot connect to the company's WiFi due to a malfunction or other reason. In such a situation, the certificate presentation support system according to one embodiment of the present invention may change the "transmission method" from the previously primarily used WiFi to a different method (e.g., Bluetooth or NFC) in response to verification context information indicating that the connection to the company's WiFi is not smooth (which can be collected as a result of attempting to connect to the company's WiFi). Furthermore, such a change in method may also be performed without user intervention (i.e., automatically) as needed.

[0073] The system for supporting the use of proof presentation according to one embodiment of the present invention collects, recognizes, stores, or analyzes verification context information as described above to recognize the context information of the holder node, and based on this, selects or determines at least one of the type, presentation method, and transmission method of the proof presentation to be presented. This selection or decision process may be performed using one or more technologies selected from a plurality of technologies, such as on-device AI, cloud computing, or a simple algorithm, based on factors such as the context and device performance. For example, in an environment where communication conditions are consistently smooth and the holder node can stably connect to an external network, the above-described decision process may be performed primarily using cloud computing, whereas in an environment where communication conditions are not smooth, the decision process may be performed using on-device AI built into the holder node (or a device including the holder node).

[0074] Continuing, according to one embodiment of the present invention, the transmission method of the proof presentation may be one or a combination of two or more selected from a plurality of transmission methods, and the presentation method of the proof presentation may be one or a combination of two or more selected from a plurality of presentation methods.

[0075] According to one embodiment of the present invention, the meaning of the transmission method or presentation method of the proof presentation being one selected from a plurality of transmission methods and a plurality of presentation methods may mean that the transmission method and presentation method to be used are each selected based on the verification situation information as described above.

[0076] Meanwhile, according to one embodiment of the present invention, the fact that the transmission method or presentation method of the proof presentation is a combination of two or more selected from a plurality of transmission methods and a plurality of presentation methods may mean that two or more transmission methods or presentation methods are selected and used in combination at the same time.

[0077] For example, the camera method and the QR code method can be used simultaneously in combination by simultaneously displaying a QR code on one side of the screen that the camera is capturing, or by overlaying the QR code by making it semi-transparent. As another example, in response to a situation where WiFi communication is possible but connection failures frequently occur, WiFi communication and Bluetooth can be used simultaneously in combination (i.e., the two transmission methods are used simultaneously to send the proof presentation twice). The proof presentation use support system according to one embodiment of the present invention can derive an optimal proof presentation use method in response to a wider variety of verification environments by combining and using multiple transmission methods or presentation methods as needed.

[0078] Meanwhile, when using multiple means simultaneously as described above (i.e., simultaneous activation of multiple methods), additional data communication volume or power consumption required for verification may occur. In response to such a situation, a low-power communication protocol may be applied as needed in a certificate presentation use support system according to an embodiment of the present invention, or a method may be applied to selectively disable methods that have not been used for a certain period of time or longer by analyzing the usage history for a certain period of time (the length of the certain period of time may be changed as needed) to minimize the data communication volume or power consumption required for verification. In addition to the methods listed above, various low-power technologies that can manage the efficiency of verification may be applied for the above-described power consumption minimization, and the applied low-power technologies may be adaptively changed based on various information including the verification situation information described above.

[0079] Meanwhile, in response to the simultaneous use of multiple transmission methods, identical or different standard security protocols can be applied to each transmission method (i.e., each proof-presentation transmission channel), thereby ensuring data integrity and confidentiality. The aforementioned standard security protocols may include, but are not limited to, FIDO (Fast Identity Online) or TLS (Transport Layer Security).

[0080] Continuing, the decision unit (210) according to one embodiment of the present invention may further determine at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation to be presented at the first time point, and the transmission method of the proof presentation to be presented at the first time point based on at least one of the verification situation information related to the holder node at the second time point, the type of proof presentation presented at the second time point, the presentation method used at the second time point, and the transmission method used at the second time point, and the second time point described above may precede the first time point in time.

[0081] According to one embodiment of the present invention, the second point in time may refer to a point in time or a time interval that precedes the second point in time described above, and specifically, may refer to a point in time or a time interval that precedes the first point in time and at which verification of the proof presentation has been requested. For example, while the first point in time may be the current point in time at which verification is requested (or is about to be requested) by presenting the proof presentation, the second point in time may refer to a history of past requests for verification by presenting the proof presentation.

[0082] According to one embodiment of the present invention, the verification situation information related to the holder node at the second point in time, the type of proof presentation presented at the second point in time, the presentation method used at the second point in time, and the transmission method used at the second point in time may all be included in the above-described "history of requesting verification by presenting proof presentation in the past", and may respectively mean the verification situation information when verification of a past proof presentation was requested, the type of proof presentation presented in the past, the presentation method used in the past, and the transmission method used in the past.

[0083] The fact that the decision unit (210) according to one embodiment of the present invention can determine at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation to be presented at the first time point, and the transmission method of the proof presentation to be presented at the first time point based on at least one of the verification situation information related to the holder node at the second time point, the type of proof presentation presented at the second time point, the presentation method used at the second time point, and the transmission method used at the second time point may specifically mean that, in order to determine at least one of the type of proof presentation to be used at the present (at the first time point), the presentation method thereof, and the transmission method, the use history of the proof presentation in the past (at the second time point) is taken into consideration along with the verification situation information at the present (at the first time point).

[0084] Meanwhile, the type of proof presentation presented at the second point in time, the presentation method used at the second point in time, the transmission method used at the second point in time, etc. can be collectively referred to as past behavior data (or past data, past patterns, or past proof presentation usage history), and by using this in the proof presentation usage support system according to one embodiment of the present invention, the decision unit can make a decision by reflecting even past behavior patterns.

[0085] For example, if the history of using the NFC method as a transmission method a certain number of times or a threshold or more in a specific situation at a second point in time (the past) is included in the past behavioral data, and the verification situation information at the first point in time has a high similarity to the specific situation information at the second point in time, it may be determined that the same transmission method as that used at the second point in time is also used at the first point in time, and the similarity described above may be converted into a number, and the importance of the past behavioral data may be calculated to be high / low in proportion / inversely proportional thereto, and the transmission method at the first point in time may be determined based on the calculated importance. However, the past behavioral data is not limited to the examples described above, and may be used in various ways to determine the type of proof presentation to be presented at the first point in time, the presentation method of the proof presentation at the first point in time, and the transmission method of the proof presentation at the first point in time.

[0086] Next, according to one embodiment of the present invention, the verification request unit (220) may perform a function of requesting verification of a proof presentation to a verifier node based on at least one of the type of proof presentation to be presented at the first time point determined by the decision unit (210), the presentation method of the proof presentation, and the transmission method of the proof presentation.

[0087] According to one embodiment of the present invention, the request for verification of the proof presentation by the verification request unit (220) to the verifier node may mean requesting the verifier node (or verifier) ​​to confirm that the proof presentation (or the credential that is the basis for generating the proof presentation) determined by the decision unit is authentic (i.e., authenticity), has not been tampered with (i.e., integrity), and has been issued and presented by a trustworthy entity. This verification process may be performed by verifying, through the holder's public key, whether the proof presentation was actually presented by the holder of the proof, and verifying, through the issuer's public key, that the credential was issued by a trustworthy issuer and has not been tampered with.

[0088] Continuing, the aforementioned public key can be registered (uploaded) to a distributed ledger (e.g., a blockchain network) in a file format called a DID document, making it publicly accessible. At this time, the roles of the private key and its counterpart, the public key, are strictly separated. The private key is used solely to prove the ownership (identity) of the user (holder) and is not leaked externally. This minimizes information disclosure, preventing privacy violations while still allowing for the verification of one's identity. Furthermore, integrity can be guaranteed based on the inherent immutability of data in the distributed ledger.

[0089] Meanwhile, sensitive information (i.e., information containing personal information that may infringe on privacy if leaked) generated during the verification request process of the above-described proof presentation can be stored in a separate security area (e.g., TEE (trusted execution environment), HSM (hardware security module), TPM (trusted platform module), SGX (intel software guard extensions), SE (secure element), Enclave, Sandboxing, VBS (virtualization-based security), etc.) and then immediately deleted when use is complete (e.g., when verification becomes unnecessary due to verification completion or a verification request being stopped), thereby preventing leakage of sensitive information and strengthening security.

[0090] Next, the security unit (230) according to one embodiment of the present invention may perform a function of requesting approval from the user or stopping the verification request before requesting verification of the proof presentation to the verifier node in response to a difference between the verification situation information related to the holder node at the first time point and the verification situation information related to the holder node at the second time point being greater than a predetermined level or threshold.

[0091] According to one embodiment of the present invention, a user may be the owner (i.e., holder) of a holder node, or a user of a device (300) including the aforementioned holder node, and may refer to a (legitimate) holder of a credential or proof presentation stored in the holder node. Accordingly, the past behavioral data mentioned in connection with the second point in time above may refer to the past behavioral data of the user (i.e., various information related to the user's past credential or proof presentation usage history and proof request history).

[0092] According to one embodiment of the present invention, the difference between the verification context information at the first time point and the second time point being equal to or greater than a predetermined level or threshold may mean that the similarity derived by comparing the verification context information at the first time point and the second time point is lower than a specific level. Specifically, the similarity derived by comparing the verification context information at the first time point and the second time point described above is lower than a specific level may mean (a) that at least one of the type, presentation method, and transmission method of the proof presentation to be presented at the first time point is changed compared to one or more of the verification request histories of the plurality of second time points, and (b) that one or more of the verification request histories of the plurality of second time points is comprehensively analyzed to derive a meaningful usage pattern from the usage history (or, the behavior of the user), and that the similarity calculated between the derived usage pattern and the type, presentation method, and transmission method of the proof presentation to be presented at the first time point is lower than a specific level.

[0093] Meanwhile, among the verification request histories of the multiple second time points described above, one or more verification request histories may be selected and used based on a specific criterion (for example, based on being temporally close to the first time point).

[0094] Continuing, the difference in the verification situation information between the first and second points described above being above a certain level or threshold may mean that an abnormal situation (different from past usage patterns) has occurred, such as, for example, a situation in which the user's (i.e., holder's) behavior has drastically changed, or a situation in which an entity other than the user (without authorization) attempts to use the user's credentials or proof presentation without the user's permission.

[0095] Accordingly, according to one embodiment of the present invention, the security unit (230) can maintain security in preparation for the occurrence of various abnormal situations described above by requesting approval from the user or stopping the verification request before requesting verification of the proof presentation to the verifier node in response to the difference between the verification situation information related to the holder node at the first time point and the verification situation information related to the holder node at the second time point being greater than a predetermined level or threshold.

[0096] As described above, in more detail about the situation in which a verification request is stopped, the security unit (230) can prevent the use of credentials or proof presentation by an unauthorized person by canceling or stopping the verification request process that was in progress before the verification request (i.e., before transmitting the proof presentation to the verifier node) in response to the occurrence of the above-described abnormal situation, or by requesting cancellation of the verification request before the verification is completed at the verifier node even after the verification request (i.e., after transmitting the proof presentation to the verifier node).

[0097] Meanwhile, according to one embodiment of the present invention, stopping a verification request by the security unit (230) means stopping a verification request without manual intervention of the user (or holder), and should be distinguished from stopping a verification request by receiving feedback from the user by the feedback receiving unit (250) described below.

[0098] Next, the proof presentation use support system (200) according to one embodiment of the present invention may further include a feedback transmission unit (240).

[0099] According to one embodiment of the present invention, the feedback transmission unit (240) may perform a function of informing the user of information about at least one of the type of proof presentation to be presented at the first time point determined by the decision unit (210), the presentation method of the proof presentation described above, and the transmission method of the proof presentation described above.

[0100] Specifically, information about at least one of the type of proof presentation to be presented at the first point in time, the presentation method of the proof presentation, and the transmission method of the proof presentation described above may mean (1) at least one of the type of proof presentation determined to be presented at the first point in time, the presentation method determined to be used at the first point in time, and the transmission method determined to be used at the first point in time, (2) information that there was a request for verification of the proof presentation (or the fact of use of a credential or proof presentation) at the first point in time, and (3) the fact itself or the changed content that at least one of the type of proof presentation determined to be presented at the first point in time, the presentation method determined to be used at the first point in time, and the transmission method determined to be used at the first point in time has changed in response to a change compared to the past (or second point in time) behavior data described above.

[0101] In the case of (1) described above, for example, if the holder node transmits the company pass in the form of a QR code via WiFi, the feedback transmission unit (240) can inform the user that the type of proof presented is a company pass, the presentation method is a QR code, and the transmission method is WiFi.

[0102] In the case of (2) described above, for example, if the holder node transmits the company pass in the form of a QR code via WiFi, the feedback transmission unit (240) can inform the user that the company pass was used as proof of identification.

[0103] In the case of (3) described above, for example, if the holder node has a history of transmitting a company pass in a QR code format via WiFi at a second time point, and it is decided to transmit the company pass in a QR code format via Bluetooth at a first time point in the same or similar situation, the feedback transmission unit (240) can notify the user of the fact that the transmission method has been changed and the changed content (i.e., that the transmission method has been changed to Bluetooth).

[0104] Meanwhile, notifying the user of the above-described information can be performed using various feedback methods, including visual elements (e.g., displaying it on a display included in a device including the holder node or another (holder-owned) device connected to a device including the holder node), auditory elements (e.g., outputting a notification sound through a speaker of the device including the holder node or another (holder-owned) device connected to a device including the holder node), or tactile elements (e.g., outputting a vibration through a vibration generating device of the device including the holder node or another (holder-owned) device connected to a device including the holder node), and it is also possible to perform the above-described information using a combination of two or more of the above-described methods (e.g., outputting a sound at the same time as displaying information on a display). In addition, by corresponding different notification methods according to the type of information, it is possible to convey information about the type of credential presentation to be presented, the presentation method, and the transmission method to the user based solely on the type of notification (e.g., outputting different notification sounds depending on the type of credential or credential presentation to be presented).

[0105] Meanwhile, the function of notifying the user of the above-described information may be activated or deactivated depending on the user's choice.

[0106] Next, the proof presentation use support system (200) according to one embodiment of the present invention may further include a feedback receiving unit (250).

[0107] According to one embodiment of the present invention, the feedback receiving unit (250) may perform a function of changing information on at least one of the type of proof presentation to be presented at a first time point determined by the decision unit (210) based on a preset user input, the presentation method of the proof presentation, and the transmission method of the proof presentation, or stopping a verification request.

[0108] A preset user input according to one embodiment of the present invention is one or more specific actions set at a time or point in time prior to a first point in time, wherein the one or more specific actions described above correspond to specific functions of a certificate presentation use support system according to one embodiment of the present invention, a holder node including the system described above, or a device including the system described above, such that a user can activate or deactivate a linked specific function by performing a specific action (i.e., a user input). Specifically, a user can preset a specific action for activating a specific function at a time prior to the first point in time, and activate or deactivate the specific function by performing the specific action at the first point in time.

[0109] More specifically, the specific action described above may be a specific action of the user (holder). For example, the specific action may be a motion such as shaking the holder node or the device including it a specific number of times, or touching (tapping) the holder node or the device including it a specific number of times, and the function of immediately stopping the verification request for the proof presentation in response to performing the shaking motion a specific number of times may be activated, or the function of changing the type of credential or proof presentation to be requested for verification may be activated in response to performing the touching (tapping) motion a specific number of times. In this case, even if the holder node requests verification of a specific proof presentation to the verifier node, the user may shake the holder node or the device including it a specific number of times in response to receiving information about the verification request (e.g., information transmitted by the feedback transmitter (240) described above) to immediately stop the verification request before the verification request is completed, or may touch the device a specific number of times to change the type of credential or proof presentation to be requested for verification. In this way, the user can easily operate the proof presentation use support system (200), the holder node including the same, or the device including the holder node in real time by using the feedback receiving unit (250) according to one embodiment of the present invention.

[0110] Next, the communication unit (260) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the decision unit (210), the verification request unit (220), the security unit (230), the feedback transmission unit (240), and the feedback reception unit (250).

[0111] Finally, the control unit (270) according to one embodiment of the present invention can perform a function of controlling the flow of data between the decision unit (210), the verification request unit (220), the security unit (230), the feedback transmission unit (240), the feedback reception unit (250), and the communication unit (260). That is, the control unit (270) according to one embodiment of the present invention can control the flow of data from / to the outside of the proof presentation use support system (200) or the flow of data between each component of the proof presentation use support system (200), thereby controlling the decision unit (210), the verification request unit (220), the security unit (230), the feedback transmission unit (240), the feedback reception unit (250), and the communication unit (260) to perform their own functions.

[0112] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0113] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.

[0114] Therefore, the idea of ​​the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of ​​the present invention.

Claims

1. As a method to support the use of proof presentation (VP), A step of determining at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation based on the verification situation information related to the holder node at the first time point, and A step of requesting verification of a proof presentation to a verifier node based on at least one of the type of proof presentation to be presented at the determined first point in time, the presentation method of the proof presentation, and the transmission method of the proof presentation. method.

2. In paragraph 1, The presentation method of the above proof presentation is one or a combination of two or more selected from a plurality of presentation methods, and the transmission method of the above proof presentation is one or a combination of two or more selected from a plurality of transmission methods. method.

3. In paragraph 1, In the above decision step, at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation to be presented at the first time point, and the transmission method of the proof presentation to be presented at the first time point is determined based on at least one of the verification situation information related to the holder node at the second time point, the type of proof presentation presented at the second time point, the presentation method used at the second time point, and the transmission method used at the second time point, The above second point in time is temporally preceding the first point in time. method.

4. In paragraph 3, In response to the difference between the verification situation information related to the holder node at the first time point and the verification situation information related to the holder node at the second time point being greater than a threshold, further including a step of requesting approval from the user or stopping the verification request before requesting the verification of the proof presentation to the verifier node. method.

5. In paragraph 1, It further includes a step of informing the user of information about at least one of the type of proof presentation to be presented at the first point in time determined above, the presentation method of the proof presentation, and the transmission method of the proof presentation. method.

6. In paragraph 1, Further comprising a step of changing information on at least one of the type of proof presentation to be presented at the determined first point in time, the presentation method of the proof presentation, and the transmission method of the proof presentation, or stopping the verification request based on the preset user input. method.

7. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1.

8. As a system to support the use of proof presentation (VP), A decision unit that determines at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation, and the transmission method of the proof presentation based on the verification situation information related to the holder node at the first time point, and A verification request unit that requests a verifier node to verify a proof presentation based on at least one of the type of proof presentation to be presented at the first point in time determined above, the presentation method of the proof presentation, and the transmission method of the proof presentation. System.

9. In paragraph 8, The presentation method of the above proof presentation is one or a combination of two or more selected from a plurality of presentation methods, and the transmission method of the above proof presentation is one or a combination of two or more selected from a plurality of transmission methods. System.

10. In paragraph 8, The above decision unit determines at least one of the type of proof presentation to be presented at the first time point, the presentation method of the proof presentation to be presented at the first time point, and the transmission method of the proof presentation to be presented at the first time point based on at least one of the verification situation information related to the holder node at the second time point, the type of proof presentation presented at the second time point, the presentation method used at the second time point, and the transmission method used at the second time point, The above second point in time is temporally preceding the first point in time. System.

11. In paragraph 10, In response to the difference between the verification situation information related to the holder node at the first time point and the verification situation information related to the holder node at the second time point exceeding a threshold value, a security unit further includes requesting approval from the user or stopping the verification request before requesting verification of the proof presentation to the verifier node. System.

12. In paragraph 8, Further comprising a feedback transmission unit that informs the user of at least one of the type of proof presentation to be presented at the first point in time determined above, the presentation method of the proof presentation, and the transmission method of the proof presentation. System.

13. In paragraph 8, Further comprising a feedback receiving unit that changes information on at least one of the type of proof presentation to be presented at the determined first point in time, the presentation method of the proof presentation, and the transmission method of the proof presentation, or stops a verification request based on a preset user input. System.

Citation Information

Patent Citations

  • Apparatus and method for activating wireless communication function automatically for geo-fence, system and computer readable medium having computer program recorded including the same

    KR102272799B1

  • Mobile Hi-Pass Reduction System and Reduction Methods Using the Biometric Information of Smartphone

    KR102415528B1

  • Wine chiller

    KR102687773B1

  • Zone Oriented Applications, Systems and Methods

    US20130212130A1

  • KR20230088938A