Method and system for supporting conditional and automatic activation of verifiable presentation
The system automatically activates holder nodes using contextual data to enhance user convenience and security in presenting verifiable credentials, addressing the inconvenience and misuse issues of manual activation.
Patent Information
- Application Number
- PCT/KR2025/000854
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-11-14
- Filing Date
- 2025-01-15
- Publication Date
- 2025-08-14
AI Technical Summary
Existing methods for presenting verifiable credentials require manual activation by users, which is inconvenient and lacks personalization, leading to suboptimal user experience and potential misuse.
A system that automatically activates a holder node based on contextual information such as geolocation, GPS, WiFi, and time zone, using machine learning to set user-customized activation conditions and prevent misuse.
Enhances user convenience by automating credential presentation while ensuring security and personalization, minimizing manual intervention and reducing the risk of unauthorized use.
Smart Images

Figure KR2025000854_14082025_PF_FP_ABST
Abstract
Description
Method and system for supporting conditional automatic activation of proof presentation
[0001] The present invention relates to a method and system for supporting conditional automatic activation of proof presentation.
[0002] Recently, the method of proving the qualifications required to receive desired services is rapidly becoming digitalized. This method is performed by presenting verifiable credentials (VC), which are digital representations of specific qualifications held by the holder, in the form of a verifiable presentation (VP), and having the verifier verify this.
[0003] Previously, when attempting to use credentials or proof presentations contained in a holder node, users had to manually unlock and activate them to request verification, which was inconvenient. Therefore, the present invention proposes a method to automatically activate a holder node based on various contextual information and conditions related to the use of the holder node's proof presentation, such as geolocation, GPS, WiFi, Bluetooth, and time zone, thereby improving user usability and convenience.
[0004] Through the present invention, convenience of use can be maximized by automatically proceeding with the activation of the holder node and verification request of proof presentation based on preset activation conditions, and further, a more personalized service can be provided by providing customized activation conditions for the user by considering more diverse information such as the user's behavioral pattern, surrounding environment, and biometric authentication information through machine learning technology.
[0005] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0006] In addition, the present invention aims to obtain situation information regarding the use of a proof presentation of a holder node, and to activate a holder node by referring to the obtained situation information regarding the use of a proof presentation of a holder node and a preset activation condition of the holder node.
[0007] In addition, the present invention aims to maximize user convenience and provide a safe service by automatically performing verification of proof presentation under specific conditions based on various situational information regarding the use of proof presentation of a holder node, thereby setting activation conditions of the holder node in a user-customized manner and preventing misuse of the holder node at the same time.
[0008] A representative configuration of the present invention to achieve the above purpose is as follows.
[0009] According to one aspect of the present invention, a method is provided, comprising: obtaining situational information regarding the use of a proof presentation by a holder node; and activating a holder node by referring to the obtained situational information regarding the use of the proof presentation by the holder node and a preset activation condition of the holder node.
[0010] According to another aspect of the present invention, a system for supporting the use of a proof presentation (VP) is provided, comprising: an activation unit for activating a holder node by referring to a similarity between the status information of the holder node and a preset activation condition of the holder node; and a verification request unit for requesting a verification of at least one proof presentation included in the holder node to a verifier node in response to the activation of the holder node.
[0011] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0012] According to the present invention, it is possible to obtain situation information regarding the use of a proof presentation of a holder node, and to activate a holder node by referring to the obtained situation information regarding the use of a proof presentation of a holder node and a preset activation condition of the holder node.
[0013] In addition, the present invention maximizes user convenience and simultaneously prevents misuse of the holder node, thereby providing a safe service by setting activation conditions of the holder node in a user-customized manner based on various situational information regarding the use of the proof presentation of the holder node and automatically performing verification of the proof presentation under specific conditions based on the activation conditions.
[0014] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the use of proof presentation according to one embodiment of the present invention.
[0015] FIG. 2 is a drawing showing in detail the internal configuration of a proof presentation use support system according to one embodiment of the present invention.
[0016] FIG. 3 is a diagram schematically illustrating a configuration of a blockchain network and a plurality of nodes included therein according to one embodiment of the present invention.
[0017] <Explanation of symbols>
[0018] 100: Communications network
[0019] 200: Proof-of-Use Support System
[0020] 210: Situational Information Acquisition Unit
[0021] 220: Activation section
[0022] 230: Verification Request Department
[0023] 240: Security Department
[0024] 250: Feedback transmitter
[0025] 260: Feedback receiving unit
[0026] 270: Communications Department
[0027] 280: Control unit
[0028] 300: Device
[0029] 400: Multiple nodes
[0030] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0031] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0032] Composition of the entire system
[0033] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the use of proof presentation according to one embodiment of the present invention.
[0034] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a proof presentation use support system (200), and a device (300).
[0035] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0036] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.
[0037] Next, the system (200) for supporting the use of proof presentation according to one embodiment of the present invention can communicate with a device (300) to be described later via a communication network (100). In addition, the system (200) for supporting the use of proof presentation according to one embodiment of the present invention can obtain situational information regarding the use of proof presentation by a holder node, and perform a function of activating the holder node by referring to the obtained situational information regarding the use of proof presentation by the holder node and the preset activation conditions of the holder node.
[0038] Meanwhile, the proof presentation use support system (200) may be a digital device equipped with a memory means and a microprocessor and having computational capabilities, and may be one of a plurality of nodes (400) constituting the distributed ledger illustrated in FIG. 3, and more specifically, may include a holder node among the plurality of nodes (400) constituting the distributed ledger, or may correspond to a holder node among the plurality of nodes (400).
[0039] The configuration and function of the proof presentation use support system (200) according to one embodiment of the present invention will be described in detail below.
[0040] Next, a device (300) according to one embodiment of the present invention is a digital device that includes a function for communicating after connecting to a certificate presentation support system (200), and any digital device that has a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (300) according to the present invention.
[0041] In addition, according to one embodiment of the present invention, the device (300) may further include an application program for performing a function according to the present invention. Such an application may exist in the form of a program module within the device (300). Meanwhile, the nature of such a program module may be generally similar to the situation information acquisition unit (210), activation unit (220), verification request unit (230), security unit (240), feedback transmission unit (250), feedback reception unit (260), communication unit (270), and control unit (280) of the certificate presentation use support system (200) described below. Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform a function substantially identical to or equivalent thereto, as necessary.
[0042] In addition, the device (300) according to one embodiment of the present invention may be one of a plurality of nodes (400) constituting the distributed ledger illustrated in FIG. 3, and more specifically, may be a holder node among the nodes constituting the distributed ledger, or may include a holder node, and the holder node described above may include all or part of the proof presentation use support system (200) according to one embodiment of the present invention.
[0043] However, as described above, the node (including the issuer node, the holder node, and the verifier node) according to one embodiment of the present invention is one of a plurality of nodes (400) constituting a distributed ledger (or blockchain network) is merely an example and is not limited thereto. That is, the node according to one embodiment of the present invention may refer to any type of reliable storage means that serves as a participant that verifies and stores data and exchanges information with other nodes to maintain the integrity and consistency of the entire system.
[0044] Next, the entire system according to one embodiment of the present invention may be configured to include a communication network (100) and a plurality of nodes (400) as illustrated in FIG. 3.
[0045] Each node included in a plurality of nodes (400) according to one embodiment of the present invention is a contact point or connection point that can communicate with other nodes through a communication network (100), and may be a concept including a physical node such as a server, computer, laptop, smart phone, tablet PC, etc. (i.e., a digital device equipped with memory means and equipped with a microprocessor to have computational capabilities) or a logical node such as an application, program module, virtual machine, etc. (i.e., a virtual node).
[0046] Specifically, each node included in the plurality of nodes (400) according to one embodiment of the present invention may be a digital wallet in itself or may include a digital wallet. A digital wallet is a software or hardware device that allows a user to securely store and manage digital assets, authentication information, identity information, etc., and refers to a means for storing various data and enabling the use of the stored data as needed. For example, an issuer node may refer to a digital wallet owned by an issuer, a holder node may refer to a digital wallet owned by a holder, and a verifier node may refer to a digital wallet owned by a verifier. The above-described holder node (or digital wallet owned by a holder) may include a proof presentation support system (200) according to one embodiment of the present invention.
[0047] Accordingly, in this specification, the term “holder node” should be understood as a concept encompassing all digital wallets or devices (300) that include the holder node, and the same applies to issuer nodes and verifier nodes.
[0048] According to one embodiment of the present invention, the issuer node, the holder node, and the verifier node may correspond to each node included in a plurality of nodes (400).
[0049] Meanwhile, in order to support the use of proof presentation based on distributed ledger technology (DLT), a plurality of nodes (400) according to one embodiment of the present invention may include a proof presentation use support system (200) according to the present invention in the form of a program module such as an application or widget. In addition, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).
[0050] A distributed ledger according to one embodiment of the present invention may refer to a method of storing and managing data distributedly across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledger described above includes, but is not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).
[0051] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which information to be stored on the network is jointly verified by a plurality of nodes (400) participating in the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of a private blockchain and a public blockchain.
[0052] Configuration of a system that supports the use of proof presentation
[0053] Below, the internal configuration and functions of each component of the proof presentation use support system (200) that performs important functions for implementing the present invention will be examined.
[0054] FIG. 2 is a drawing showing in detail the internal configuration of a proof presentation use support system (200) according to one embodiment of the present invention.
[0055] As illustrated in FIG. 2, a system (200) for supporting the use of a certificate presentation according to one embodiment of the present invention may be configured to include a situation information acquisition unit (210), an activation unit (220), a verification request unit (230), a security unit (240), a feedback transmission unit (250), a feedback reception unit (260), a communication unit (270), and a control unit (280). According to one embodiment of the present invention, at least some of the situation information acquisition unit (210), the activation unit (220), the verification request unit (230), the security unit (240), the feedback transmission unit (250), the feedback reception unit (260), the communication unit (270), and the control unit (280) may be program modules that communicate with an external system (not shown). These program modules may be included in the system (200) for supporting the use of a certificate presentation in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. Additionally, these program modules may be stored in a remote storage device capable of communicating with the proof presentation support system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described below, according to the present invention.
[0056] Meanwhile, although the proof presentation use support system (200) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the proof presentation use support system (200) may be realized within a device (300) or a server (not shown) or included within an external system (not shown) as needed.
[0057] First, the situation information acquisition unit (210) according to one embodiment of the present invention can perform a function of acquiring situation information regarding the use of the proof presentation of the holder node.
[0058] The contextual information regarding the use of a proof presentation by a holder node according to one embodiment of the present invention should be understood as a concept encompassing (1) information related to the holder node itself, and (2) all contextual information related to the process of requesting verification using the credentials or proof presentation included in the holder node.
[0059] Specifically, “all situational information” in the above-described (2) may mean information related to the holder (or user of the holder node) or the holder node in the process of requesting verification.
[0060] More specifically, the contextual information regarding the use of the proof presentation of the holder node may refer to information about the surrounding state or situation of the holder node collected by various sensors included in the holder node. The types of sensors described above and the surrounding conditions or circumstances collected therefrom include (a) various information related to the location or coordinates of the holder node (latitude, longitude, altitude, speed, direction of movement, etc.) collected by technologies such as GeoLocation or GPS, (b) various information related to linear acceleration, inclination, gravity, shock, vibration, position change, or movement of the holder node (or holder) collected by an acceleration sensor, (c) various information related to angular velocity, rotational direction, or (holder's) attitude change of the holder node collected by a gyroscope, (d) various information related to the distance between the holder node and other objects, contact, presence of surrounding objects, blockage of light by surrounding objects, or movement of surrounding objects collected by a proximity sensor, (e) various information related to light intensity (illuminance), change in light intensity, color of light, or spectrum of light collected by an illuminance sensor, (f) the type of communication means used or used by the holder node (e.g., WiFi or Bluetooth, etc.), and the specific communication network connected. (g) Information related to the type of presentation medium (e.g., QR, camera, etc.) used or used by the holder node; (h) Information related to the temperature around the holder node detected by the temperature sensor; (i) Information related to the pressure applied to the holder node detected by the pressure sensor;(j) Information related to sound or sound pressure in the surroundings of the holder node detected by a sound sensor, and (k) Information related to contact or pressure of an object against the holder node detected by a touch sensor, etc., may be included in the contextual information regarding the use of the holder node's proof presentation, including but not limited to any type of sensor or information collected therefrom.
[0061] A verifiable presentation (VP) according to one embodiment of the present invention may be generated from all or part of a verifiable credential (VC), a set of metadata usable in a credentialing mechanism operating on the web, or may be generated as a set of multiple credentials. In this case, "all or part of the credential" may mean that the VP includes at least one of the multiple claims contained in the credential.
[0062] Continuing, a credential is issued and held by the holder from an issuer, and a proof presentation is presented by the holder to a verifier and used to prove a specific qualification. When transmitting the proof presentation described above to a verifier for verification and use, the type of proof presentation to be used (or the type of claim to be presented) must be determined among the various proof presentations available for verification requests. Since the type of proof presentation to be presented varies depending on various circumstances, the optimal type must be determined in a way that maximizes user convenience, taking into account factors such as verification accuracy, efficiency, and the user's intent or purpose.
[0063] The proof presentation according to one embodiment of the present invention is a data structure used to present a credential to a verifier, and as described above, may be all or part of the credential, or a set of multiple credentials. Specifically, this may mean (1) selecting and combining one or more of the multiple claims (i.e., items to be proven) included in a single credential, or (2) creating a credential by combining multiple credentials. Accordingly, when a credential is converted into the form of a proof presentation and submitted to a verifier, the holder can present only the desired data (or claims) or the data (or claims) required for verification for verification, and the verifier can use only the desired data (or claims) for verification by specifying the data (or claims) required for verification.
[0064] According to one embodiment of the present invention, a credential encompasses all verifiable and trustworthy credentials issued in digital format. Credentials include information about an individual or organization's specific qualifications, identity, academic background, and career history. Their reliability can be guaranteed through various verifiable methods. As described above, they can be issued, stored, and verified through distributed ledger (or blockchain) technology. Meanwhile, a credential is a data structure representing a digital credential and may include multiple sub-elements (i.e., claims) to ensure its authenticity and integrity.
[0065] According to one embodiment of the present invention, a "holder" may refer to an entity possessing a credential or proof presentation. The holder receives, stores, and manages various identification information or credentials issued by an issuer. If necessary, the holder may present the credentials to a verifier in the form of the aforementioned proof presentation to request verification.
[0066] According to one embodiment of the present invention, an issuer may refer to an entity that creates a credential and issues it to the holder. Typically, an issuer is a trusted institution or organization with the authority to verify information about an individual or organization and issue a credential that verifies that information. Issuers may include various institutions, such as universities, government agencies, financial institutions, and employers.
[0067] According to one embodiment of the present invention, a verifier may refer to an entity that verifies the authenticity and integrity of a credential by verifying the aforementioned credentials. The verifier can verify the credentials or identity of the owner (i.e., holder) of the credential in a reliable manner.
[0068] As described above, according to one embodiment of the present invention, the holder, issuer, and verifier may correspond to the holder node, issuer node, and verifier node included in the plurality of nodes (400) according to one embodiment of the present invention, respectively.
[0069] Next, the activation unit (220) according to one embodiment of the present invention can perform a function of activating the holder node by referring to information regarding the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node.
[0070] According to one embodiment of the present invention, activating a holder node may mean releasing a lock for maintaining the security of the holder node (or a device (300) including the holder node, etc.) and switching it to a usable state. Specifically, activating a holder node according to one embodiment of the present invention may mean releasing the lock (or locked state) of the device (300) including the holder node so that the credentials or proof presentation included in the holder node can be used (i.e., verification of the credentials or proof presentation can be requested).
[0071] Specifically, the holder node (or the device (300) including it, etc.) may be locked using various means such as (1) a password, (2) a PIN, (3) a pattern, (4) biometric information such as a fingerprint, face, iris, or voice, but is not limited thereto, and any type of locking means may be used without limitation.
[0072] Meanwhile, the activation of the holder node should be distinguished from the verification request for proof presentation by the verification request unit (230) described later as a different process or action, and specifically, the activation (i.e., unlocking) of the holder node described above may be performed first, and then the verification request for proof presentation may be made.
[0073] According to one embodiment of the present invention, the fact that the activation condition of the holder node is preset may mean that the activation condition is set at a time point that precedes at least one of the time point when the situation information acquisition unit (210) included in the proof presentation use support system (200) according to one embodiment of the present invention acquires situation information, the time point when the activation unit (220) activates the holder node, and the time point when the verification request unit (230) requests the verification of the proof presentation to the verifier node.
[0074] Meanwhile, the activation condition may mean a specific value or a specific range of at least one of the contextual information regarding the use of the proof presentation of the various holder nodes listed above (i.e., a specific value of the contextual information regarding the use of the proof presentation of multiple holder nodes may be used as the activation condition). For example, (1) if the activation condition is "the holder node is located at zz, yy-dong, xx-gu, Seoul", the activation condition uses a specific value of the location of the holder node as the activation condition; (2) if the activation condition is "the holder node connects to a specific WiFi "zz" on the yy floor of xx company", the activation condition uses a specific type of communication network (a specific value) to which the holder node is connected as the activation condition; and (3) if the activation condition is "the holder node is located within 1 m to 5 m of a specific object, and the ambient temperature is between 25°C and 30°C", the activation condition uses a specific value of the location of the holder node and a specific range of the ambient temperature of the holder node as the activation condition. However, the above-described (1) to (3) are only extremely limited examples of activation conditions of preset holder nodes that can be used in the present invention, and specific values or specific ranges for all types of situational information (or combinations thereof) can be used as activation conditions.
[0075] Meanwhile, the activation unit (220) according to one embodiment of the present invention activates the holder node by referring to the information on the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node, which may mean that the activation unit (220) compares the activation conditions of the preset holder node described above with the information on the use of the proof presentation of the current holder node, and selects whether to activate the holder node based on the comparison result.
[0076] Meanwhile, the above-described comparison result may indicate whether the activation conditions of the preset holder node and the information on the use of the proof presentation of the current holder node match. Here, whether or not it matches may be determined based on various criteria, such as (1) determining that there is a match if all of the preset activation conditions and one or more conditions included in the information on the use of the proof presentation of the holder node (i.e., the situational information on the use of the proof presentation described above) match, (2) determining that there is a match if a predetermined number or a threshold or more of one or more conditions included in the preset activation conditions and the information on the use of the proof presentation of the holder node match, (3) determining that there is a match if there are multiple preset activation conditions, sequentially determining whether or not other conditions are satisfied based on the condition that one condition is satisfied, and determining that there is a match if each condition matches, or (4) calculating the similarity as a number separately through a similarity calculation mechanism and determining that there is a match if the similarity exceeds a predetermined level or threshold. The above-described similarity calculation may be performed using, but is not limited to, a mechanism capable of calculating similarity, such as cosine similarity, Jaccard similarity, Levenshtein distance, or Euclidean distance, or a computer program utilizing such a mechanism.
[0077] Meanwhile, the criteria for determining whether there is a match described above are exemplary and are not limited thereto, and it is obvious to those skilled in the art that various criteria for determining whether there is a match can be set and used as needed.
[0078] Continuing, the activation unit (220) according to one embodiment of the present invention may periodically refer to the situation information regarding the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node.
[0079] As described above, the fact that the activation unit (220) according to one embodiment of the present invention periodically refers to the activation condition may mean, for example, (1) referring to the activation condition at a (pre-set) regular cycle, (2) referring to the activation condition according to a cycle that changes according to a (pre-set) specific rule, or (3) referring to the activation condition at every (pre-set) specific time. The above-described regular cycle, specific rule, or specific time may be manually changed by the user, or may be changed by a learning model learned to derive an optimal cycle, rule, or specific time based on situational information about the use of the proof presentation of the holder node and information about the use of the proof presentation without the user's intervention.
[0080] Specifically, in accordance with one embodiment of the present invention, in response to a plurality of proof presentations, the activation conditions of the holder node can be independently set for each of the plurality of proof presentations.
[0081] The multiple proof presentations according to one embodiment of the present invention may mean that there are two or more types of proof presentations included in the holder node of the present invention. That is, even if the holder node only has one credential, the case where multiple proof presentations are generated from it (i.e., where multiple proof presentations are generated by combining one or more claims included in the credential) is also included in the case of multiple proof presentations described above.
[0082] Continuing, the type of proof presentation according to one embodiment of the present invention may refer to a type of multiple proof presentations that can be generated from credentials held by the holder (or included in the holder node), and may refer to a proof presentation that is to be requested for verification using the proof presentation use support system (200) according to one embodiment of the present invention. For example, a situation may be assumed in which a holder holding a resident registration card and a driver's license as credentials attempts to prove his or her identity. At this time, the holder may select (1) a resident registration card, (2) a driver's license, (3) a combination thereof, or (4) some of the multiple claims included in each credential, convert them into a proof presentation, and request verification. In this case, the proof presentation generated from the selected credentials as in (1) to (4) described above may be referred to as a "type of proof presentation."
[0083] Continuing, in accordance with one embodiment of the present invention, where multiple proof presentations are included in a holder node, identical or different conditions can be independently set for each proof presentation. That is, multiple proof presentations can independently have identical or different activation conditions.
[0084] For example, as in the example described above, we can assume a situation where the holder holds both a resident registration card and a driver's license as credentials. In this situation, (1) for the resident registration card, the activation condition may be set to be that the location information of the holder node matches the address of a (pre-set) regular bar, while (2) for the driver's license, the activation condition may be set to be that the user activates a car sharing application. Furthermore, different activation conditions may be independently set for not only the type of credential or credential presentation, but also for each claim (or any combination of claims derived therefrom) within each credential (or credential presentation).
[0085] Specifically, according to one embodiment of the present invention, the activation condition of a preset holder node can be automatically set or changed by a learning model learned based on the relationship between the situational information regarding the use of the proof presentation of the holder node and the information regarding the use of the proof presentation.
[0086] Since the situational information regarding the use of the proof presentation of the holder node according to one embodiment of the present invention has already been described above, description thereof is omitted to avoid excessive duplication.
[0087] Information regarding the use of proof presentation according to one embodiment of the present invention may mean a history of the holder node being activated or verification of proof presentation being requested at a time or point in time preceding at least one of the time points at which the situation information acquisition unit (210) included in the proof presentation use support system (200) according to one embodiment of the present invention acquires situation information, the time point at which the activation unit (220) activates the holder node, and the time point at which the verification request unit (230) requests verification of proof presentation to the verifier node, and various pieces of information related to the history.
[0088] Specifically, (1) using the learning model described above, a user's past usage pattern of proof presentation can be extracted from one or more histories that requested verification of proof presentation, and activation conditions can be set based on this, and (2) using the learning model described above, a usage pattern can be extracted from the usage history after setting the activation conditions, and the preset activation conditions can be changed based on this (for example, in response to a usage pattern extracted, such as a usage pattern that has changed by a certain level (or, above a threshold), the activation conditions can be changed to suit this usage pattern).
[0089] For example, suppose a user enters a company that requires the presentation of a company ID card as proof of entry (i.e., there are numerous instances of the user using the ID card as proof of entry in the company lobby). Based on this usage history, the user's "holder node being located in the company lobby" could be set as an activation condition.
[0090] In the above situation, even if the lobby is later changed to a public space that the general public can enter, and the entry condition is changed to presenting a company ID at each department entrance, since the activation condition has not yet been changed, even if the user's holder node is located at the department entrance, the holder node is not automatically activated, and the user manually operates the holder node to submit the company ID as proof at the department entrance to enter.
[0091] However, even in this situation, if the system (200) for supporting the use of proof presentation according to one embodiment of the present invention is used, even if the user does not manually change the activation condition, the learning model can change the activation condition of the above-described proof presentation (i.e., the company pass) to "the holder node is positioned at the department entrance" by using the usage history of "activating the company pass by being located at the department entrance" as information regarding the use of the proof presentation (without manual intervention of the user). Through this, the optimal activation condition can be set or changed to the optimal activation condition through the learning model without the user having to manually change the activation condition of the holder node every time the usage pattern changes.
[0092] However, it is obvious to those skilled in the art that, in addition to using a method of automatically changing or optimizing activation conditions using a learning model as described above, activation conditions may also be manually set by a user, or preset activation conditions may also be manually changed by a user.
[0093] Next, the proof presentation use support system (200) according to one embodiment of the present invention may further include a verification request unit (230).
[0094] A verification request unit (230) according to one embodiment of the present invention may perform a function of requesting a verifier node to verify at least one proof presentation included in the holder node in response to the holder node being activated.
[0095] According to one embodiment of the present invention, the request for verification of the proof presentation by the verification request unit (230) to the verifier node may mean requesting the verifier node (or verifier) to confirm that the proof presentation (or the credential that is the basis for generating the proof presentation) determined by the decision unit is authentic (i.e., authenticity), has not been tampered with (i.e., integrity), and has been issued and presented by a trustworthy entity. This verification process may be performed by verifying, through the holder's public key, whether the proof presentation was actually presented by the holder of the proof, and verifying, through the issuer's public key, that the credential was issued by a trustworthy issuer and has not been tampered with.
[0096] Continuing, the aforementioned public key can be registered (uploaded) to a distributed ledger (e.g., a blockchain network) in a file format called a DID document, making it publicly accessible. At this time, the roles of the private key and its counterpart, the public key, are strictly separated. The private key is used solely to prove the ownership (identity) of the user (holder) and is not leaked externally. This minimizes information disclosure, preventing privacy violations while still allowing for the verification of one's identity. Furthermore, integrity can be guaranteed based on the inherent immutability of data in the distributed ledger.
[0097] Meanwhile, sensitive information (i.e., information containing personal information that may infringe on privacy if leaked) generated during the verification request process of the above-described proof presentation can be stored in a separate security area (e.g., TEE (trusted execution environment), HSM (hardware security module), TPM (trusted platform module), SGX (intel software guard extensions), SE (secure element), Enclave, Sandboxing, VBS (virtualization-based security), etc.) and then immediately deleted when use is complete (e.g., when verification becomes unnecessary due to verification completion or a verification request being stopped), thereby preventing leakage of sensitive information and strengthening security.
[0098] Specifically, the verification request unit (230) according to one embodiment of the present invention may request verification of a proof presentation in response to the user's approval.
[0099] A user according to one embodiment of the present invention may mean an owner (i.e., a holder) of a holder node, or a user of a device (300) including the holder node described above, and a (legitimate) holder of a credential or proof presentation stored in the holder node.
[0100] User approval according to one embodiment of the present invention may mean any type of action that a user intentionally permits or agrees to in order to allow a specific action or access right at the holder node.
[0101] Specifically, a user's authorization to use a proof presentation according to one embodiment of the present invention may mean authorization to use (i.e., send a verification request to a verifier node) at least one proof presentation among the proof presentations included in the holder node in response to the holder node being activated (i.e., the proof presentation selected to request verification from the verifier).
[0102] Specifically, a situation where user approval is required may mean that, as described above, after the holder node is (automatically) activated, there is a separate step of requesting user approval when requesting verification of a proof presentation by the verification request unit (230). Specifically, even if the holder node is activated (or unlocked) by the activation unit (220) according to one embodiment of the present invention, the verification request unit (230) may further include a step of requesting the user's approval for the verification request before requesting verification of the proof presentation. That is, in this case, only the activation step of the holder node is performed automatically, and since the user's approval is requested before requesting verification for a proof presentation selected or recommended by the activation unit (220), the verification request for the proof presentation itself is performed manually (i.e., the verification request is made only when user approval is received). For example, a situation where the holder node activation condition is satisfied can be assumed. In this situation, the holder node is automatically unlocked, and further, the selection of the proof presentation to be verified can be performed automatically. However, since the verification request unit (230) requests the user's approval before finally requesting verification of the proof presentation, the actual verification request for the proof presentation is made only if the user approves. In this way, when the user's approval is requested immediately before the verification request, the user can make the final verification request with only a minimal and simple approval action (e.g., tapping the approval button displayed on the display of the device (300), etc.), so the user does not need to manually activate the holder node and select the proof presentation to be presented, which increases convenience. At the same time, the user can know without missing information about the proof presentation being used, which can have the effect of making personal information management easier.
[0103] In addition, as described above, when the verification request unit (230) requests the user's approval, a function may be implemented to recommend the optimal proof presentation suitable for the situation to the user by notifying the user of the optimal proof presentation available in the current situation along with the approval request. In this case, it is possible to recommend one optimal proof presentation, but it is also possible to present multiple available proof presentations, and in the case of presenting multiple presentations, the priority of the multiple recommended proof presentations may be displayed based on information about the user's (previous) use of proof presentations and the user's proof presentation usage pattern that can be derived therefrom (for example, displaying the ranking based on the number of times used, etc.).
[0104] Additionally, the verification request unit (230) according to one embodiment of the present invention can request verification of proof presentation without user approval.
[0105] Specifically, after the holder node of the present invention is (automatically) activated, when requesting verification of the proof presentation by the verification request unit (230) (or before making the request), separate user approval may not be requested, and in this case, the proof presentation use support system (200) according to one embodiment of the present invention can be used to automatically perform a verification request for the proof presentation in addition to the activation of the holder node. By not requesting user approval for the verification request, the actions that the user must take to present the proof presentation can be minimized. For example, if the activation condition is that the holder node be located in the company lobby, the user only needs to be in possession of the holder node and be located in the company lobby, and the processes of "unlocking the holder node," "selecting a company pass as the optimal proof presentation," and "requesting verification of the selected proof presentation" are all automatically performed without separate intervention by the user, so the user can enter the company right away.
[0106] On the other hand, if the verification request does not require user approval, then when the holder node is activated, the verification request (i.e., presentation) of the (optimal) proof presentation is followed, so in this case, the activation of the holder node may immediately mean the activation of the credentials or proof presentation contained in the holder node.
[0107] Next, the proof presentation use support system (200) according to one embodiment of the present invention may further include a security unit (240).
[0108] The security unit (240) according to one embodiment of the present invention may perform a function of requesting approval from a user or stopping activation of a holder node in response to an activation condition of a holder node being automatically set or changed.
[0109] Specifically, the security unit (240) can prevent unauthorized use (e.g., misuse or theft by others) of credentials or proofs owned by the user by activating a function for maintaining security when activation conditions are automatically set or set items are automatically changed (e.g., when automatically changed by the learning model described above), thereby minimizing the risk of hacking or external manipulation and protecting the user's sensitive personal information.
[0110] Meanwhile, the above-described security maintenance function may be implemented in a manner that specifically requests the user's approval for changes in activation conditions or suspends the activation of the holder node without requesting approval, but is not limited thereto.
[0111] Continuing, according to one embodiment of the present invention, the security unit (240) may (1) stop the activation of the holder node if the user is requested to approve the activation condition of the holder node being automatically set or changed but approval is not received, or (2) stop the activation of the holder node immediately without an approval request process in response to the activation condition of the holder node being automatically set or changed (or an attempt to change it).
[0112] In the case of (1) described above, by notifying the user of a change in the activation conditions and requesting approval thereof, it is possible to prevent a situation in which the user is unaware of the change in the activation conditions, and in the case of (2) described above, by preventing the activation conditions from being changed, the holder node is automatically activated only under the initially set activation conditions, thereby preventing the occurrence of an abnormal situation and thereby maintaining security.
[0113] In addition to stopping the activation of the holder node as described above, the method of stopping or canceling the verification process before the verification of the credential is completed, such as canceling the verification request process that was in progress before the verification request (i.e., before sending the proof presentation to the verifier node) (i.e., immediately stopping the verification process), or requesting cancellation of the verification request before the verification is completed at the verifier node even after the verification request (i.e., after sending the proof presentation to the verifier node), is also included without limitation in the method of stopping or canceling the verification process according to one embodiment of the present invention.
[0114] Continuing, it can be assumed that the holder node (or, the aforementioned learning model, etc.) generally stores and analyzes information regarding the use of the proof presentation, derives the user's usage pattern, and sets the activation condition based on this. In this case, even if the user's usage pattern changes, if the level of change in the usage pattern does not exceed a predetermined level or threshold, the security unit (240) may not activate the function for maintaining security described above even if the activation condition changes to reflect the change in the usage pattern. In other words, if the change in the usage pattern is within a predetermined level (threshold), the activation condition may automatically change in accordance with the change in the user's usage pattern.
[0115] On the other hand, in response to a change in the user's usage pattern exceeding a predetermined level (threshold), the security unit (240) may request the user's approval for the change before the activation conditions are changed in accordance with the change in the usage pattern, or may suspend the activation of the holder node without requesting approval. In this case, the change in the user's usage pattern is judged to be an unusual change and may indicate misuse, theft, or an abnormal situation, and the automatic change in the activation conditions is prevented by the security unit (240).
[0116] As an example of the function of the security unit (240) described above, it can be assumed that a user has used proof presentation 5 times over the course of one month in Region A of Korea.
[0117] At this time, (1) if the proof presentation is used 10 times in Region B, Korea during the next month, "used in Region B, Korea more than a certain number of times" may be used as information on the use of the proof presentation, and based on this, the existing activation condition may be (automatically) changed from "the holder node is located in Region A" to "the holder node is located in Region B." At this time, the security department (240) may determine that the change in the usage pattern does not correspond to misuse, theft, or an abnormal situation of the proof presentation because the distance between Region A and Region B, Korea, is within the threshold based on location, and therefore, functions for maintaining security, such as requesting user approval or suspending activation, may not operate and the activation condition may be automatically changed.
[0118] (2) On the other hand, if the above-mentioned proof presentation is used (or a verification request is generated) 10 times a day in Mexico after the above-mentioned situation, the security department (240) may determine that the change in the usage pattern corresponds to misuse, theft, or an abnormal situation of proof presentation based on the fact that the distance between Korea Region A and Mexico exceeds the threshold (or the fact that the proof presentation was used at a time other than usual (such as dawn) based on Korea time), and may request approval from the user or suspend activation.
[0119] Meanwhile, the above-described example is only one embodiment, and the activation conditions and the criteria for determining whether there is theft or an abnormal situation may be changed as long as it is consistent with the purpose of the present invention.
[0120] Meanwhile, according to one embodiment of the present invention, by utilizing the security unit (240) while ensuring that the above-described activation conditions remain unchanged, the holder node can be prevented from being activated under conditions other than the preset activation conditions. For example, when using a financial certificate as proof of identity, to prevent theft due to hacking from overseas, the activation condition can be set to only allow activation between 9:00 AM and 4:00 PM (Korean time). This prevents activation of the holder node during the early morning hours of Korean time, thereby preventing theft from overseas.
[0121] Meanwhile, according to one embodiment of the present invention, stopping the activation of the holder node by the security unit (240) is to stop a verification request without manual intervention of the user (or holder), and should be distinguished from the case where the feedback receiving unit (260), which will be described later, stops a verification request by receiving feedback from the user.
[0122] Next, the proof presentation use support system (200) according to one embodiment of the present invention may further include a feedback transmission unit (250).
[0123] A feedback transmission unit (250) according to one embodiment of the present invention can perform a function of notifying a user of information about a proof presentation included in an activated holder node.
[0124] Specifically, the information about the proof presentation contained in the above-described activated holder node may (1) mean the type of proof presentation that has been decided to be presented, (2) mean that there has been a request for verification of the proof presentation (or the fact of use of a credential or proof presentation), and (3) mean that the fact of change itself or the changed content, if the activation conditions have been automatically changed.
[0125] Meanwhile, as described above, informing the user of information about the proof presentation included in the activated holder node can be performed using various types of feedback, including (1) visual elements (e.g., displaying on a display included in a device (300) including the holder node or another (holder-owned) device connected to the device (300) including the holder node), (2) auditory elements (e.g., outputting a notification sound through a speaker of the device (300) including the holder node or another (holder-owned) device connected to the device (300) including the holder node), or (3) tactile elements (e.g., outputting a vibration through a vibration generating device of the device (300) including the holder node or another (holder-owned) device connected to the device (300) including the holder node), and it is also possible to perform the operation using a combination of two or more of the above-described multiple methods (e.g., outputting a sound at the same time as displaying information on a display). In addition, by corresponding different notification methods to each type of information, it is possible to convey information about the type of proof presentation, presentation method, and transmission method to the user based solely on the type of notification (for example, outputting different notification sounds depending on the type of credential or proof presentation presented).
[0126] Meanwhile, the function of notifying the user of the above-described information may be activated or deactivated depending on the user's choice.
[0127] Next, the proof presentation use support system (200) according to one embodiment of the present invention may further include a feedback receiving unit (260).
[0128] A feedback receiving unit (260) according to one embodiment of the present invention may perform a function of changing information on a proof presentation included in the activated holder node or stopping a verification request based on a preset user input.
[0129] A preset user input according to one embodiment of the present invention may mean a specific action of / by one or more users set at a time point (hereinafter, a setting time point) preceding at least one of the time points (hereinafter, a use time point) among the time point at which the situation information acquisition unit (210) included in the proof presentation use support system (200) according to one embodiment of the present invention acquires situation information, the time point at which the activation unit (220) activates the holder node, and the time point at which the verification request unit (230) requests verification of the proof presentation to the verifier node.
[0130] One or more of the specific actions described above correspond to specific functions of the proof presentation use support system (200) according to one embodiment of the present invention, the holder node including the system described above, or the device (300) including the system described above, so that the user can activate or deactivate the associated specific function by performing a specific action (i.e., user input). Specifically, the user can preset a specific action for activating the specific function at the time of setting, and activate or deactivate the specific function by performing the specific action at the time of use.
[0131] More specifically, the specific action described above may be a specific action of the user (holder). For example, the specific action may be an action such as shaking the holder node or the device (300) including it a specific number of times, or touching (tapping) the holder node or the device (300) including it a specific number of times, and the function of immediately stopping the verification request for the proof presentation in response to performing the shaking action a specific number of times may be activated, or the function of changing the type of credential or proof presentation to be requested for verification may be activated in response to performing the touching (tapping) action a specific number of times. In this case, even if the holder node has requested the verification of a specific proof presentation to the verifier node, the user may shake the holder node or the device (300) including it a specific number of times in response to receiving information about the verification request (e.g., information transmitted by the feedback transmitter (250) described above) to immediately stop the verification request before the verification request is completed, or may touch the device (300) a specific number of times to change the type of credential or proof presentation to be requested for verification. In this way, the user can easily operate the proof presentation use support system (200), the holder node including the same, or the device (300) including the holder node in real time by using the feedback receiving unit (260) according to one embodiment of the present invention.
[0132] Next, the communication unit (270) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the situation information acquisition unit (210), the activation unit (220), the verification request unit (230), the security unit (240), the feedback transmission unit (250), and the feedback reception unit (260).
[0133] Finally, the control unit (280) according to one embodiment of the present invention can perform a function of controlling the flow of data between the situation information acquisition unit (210), the activation unit (220), the verification request unit (230), the security unit (240), the feedback transmission unit (250), the feedback reception unit (260), and the communication unit (270). That is, the control unit (280) according to one embodiment of the present invention can control the flow of data from / to the outside of the certificate presentation use support system (200) or the flow of data between each component of the certificate presentation use support system (200), thereby controlling the situation information acquisition unit (210), the activation unit (220), the verification request unit (230), the security unit (240), the feedback transmission unit (250), the feedback reception unit (260), and the communication unit (270) to perform their own functions.
[0134] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0135] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0136] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. As a method to support the use of proof presentation (VP), A step of obtaining situational information regarding the use of the proof presentation of the holder node; and A step of activating a holder node by referring to the situation information regarding the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node. method.
2. In paragraph 1, In response to the activation of the holder node, further comprising a step of requesting the verifier node to verify at least one proof presentation included in the holder node. method.
3. In paragraph 1, In the above activation step, the situation information regarding the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node are periodically referenced. method.
4. In paragraph 1, In response to the fact that there are multiple proof presentations, the activation conditions of the holder node are set independently for each of the multiple proof presentations. method.
5. In paragraph 1, The activation conditions of the above preset holder nodes are automatically set or changed by a learning model learned based on the relationship between the situational information on the use of the proof presentation of the holder node and the information on the use of the proof presentation. method.
6. In paragraph 5, Further comprising a step of requesting approval from the user or stopping the activation of the holder node in response to the activation condition of the holder node being automatically set or changed. method.
7. In paragraph 2, In the above verification request step, verification of the proof presentation is requested in response to the user's approval for use of at least one proof presentation. method.
8. In paragraph 2, In the above verification request step, verification of the proof presentation is requested without the user's approval for use of at least one proof presentation. method.
9. In paragraph 1, Further comprising a step of informing the user of information about the proof presentation included in the above activated holder node. method.
10. In paragraph 1, Further comprising a step of changing information about the proof presentation included in the activated holder node or stopping the verification request based on a preset user input. method.
11. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1.
12. As a system to support the use of proof presentation (VP), A context information acquisition unit that acquires context information regarding the use of the proof presentation of the holder node; and An activation unit that activates a holder node by referring to the situation information regarding the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node. System.
13. In paragraph 12, In response to the activation of the holder node, the verification request unit further includes a request for verification of at least one proof presentation included in the holder node to the verifier node. System.
14. In paragraph 12, The above activation unit periodically refers to the situation information regarding the use of the proof presentation of the acquired holder node and the activation conditions of the preset holder node. System.
15. In paragraph 12, In response to the fact that there are multiple proof presentations, the activation conditions of the holder node are set independently for each of the multiple proof presentations. System.
16. In paragraph 12, The activation conditions of the above preset holder nodes are automatically set or changed by a learning model learned based on the relationship between the situational information on the use of the proof presentation of the holder node and the information on the use of the proof presentation. System.
17. In paragraph 16, Further comprising a security unit that requests the user's approval or stops the activation of the holder node in response to the activation conditions of the holder node being automatically set or changed. System.
18. In paragraph 13, The above verification request unit requests verification of the proof presentation in response to the user's approval for use of at least one proof presentation. System.
19. In paragraph 13, The above verification request unit requests verification of the proof presentation without the user's approval for use of at least one proof presentation. System.
20. In paragraph 12, Further comprising a feedback transmitter that informs the user of information about the proof presentation included in the above activated holder node. System.
21. In paragraph 12, Further comprising a feedback receiving unit for changing information about the proof presentation included in the activated holder node or stopping the verification request based on a preset user input. System.
Citation Information
Patent Citations
Apparatus and method for activating wireless communication function automatically for geo-fence, system and computer readable medium having computer program recorded including the same
KR102272799B1
Method and artificial intelligence system to reduce the load generated during operation of non-face-to-face real-time interactive video solution
KR102357055B1
Mobile Hi-Pass Reduction System and Reduction Methods Using the Biometric Information of Smartphone
KR102415528B1
Zone Oriented Applications, Systems and Methods
US20130212130A1
KR20230088938A