Method and system for supporting use of verifiable credential

The system addresses inefficient credential verification by prioritizing information exchange between holders and verifiers, ensuring efficient communication and data minimization through a simplified protocol for verifiable credentials.

WO2025170283A1PCT designated stage Publication Date: 2025-08-14HOPAE INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/001577
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-01-24
Filing Date
2025-01-31
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing technologies do not provide efficient communication between holders of verifiable credentials and verifiers, leading to inefficient information exchange and lack of data minimization in credential verification processes.

Method used

A system and method for requesting and providing information necessary for proof of qualification based on preset priorities, utilizing a communication protocol that supports selective disclosure and efficient management of credential schema information, enabling efficient communication and data minimization between holders and verifiers.

Benefits of technology

Enables efficient communication and management of verifiable credentials, supporting selective disclosure and data minimization, while allowing multiple credential requests and prioritized information sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025001577_14082025_PF_FP_ABST
    Figure KR2025001577_14082025_PF_FP_ABST
Patent Text Reader

Abstract

According to an aspect of the present invention, provided is a method for supporting use of verifiable credentials, the method comprising the steps of: requesting, from a holder node, information necessary for verification of credentials of the holder node; and obtaining, from the holder node, the information necessary for the verification of the credentials on the basis of a predetermined priority with respect to the verification of the credentials.
Need to check novelty before this filing date? Find Prior Art

Description

Methods and systems for supporting the use of verifiable credentials

[0001] The present invention relates to methods and systems for supporting the use of verifiable credentials.

[0002] With the recent rise in interest in Self-Sovereign Identity (SSI), there has been active discussion on how to prove one's eligibility for desired services using verifiable credentials (VCs; abbreviated as "credentials" hereafter). This method essentially involves an issuer issuing a digital credential that certifies a specific entity, such as an individual or organization, as possessing a specific qualification. This credential is then held by the entity. The holder of the credential then presents this to a verifier in the form of a verifiable presentation (VP; abbreviated as "presentation" hereafter), which the verifier then verifies.

[0003] As an example of the prior art in this regard, a technology disclosed in Korean Patent Publication No. 10-2023-0143410 can be cited, which is characterized by including the steps of: analyzing the ID issuance history recorded in the decentralized ID management contract in response to a request for issuance of a 'decentralized ID' from a user to inquire whether the user has a decentralized ID already issued; issuing a new decentralized ID to the user if there is no decentralized ID already issued as a result of the inquiry; and, when the new decentralized ID delivered to the user is recorded in the user's electronic wallet, registering the issued decentralized ID in the decentralized ID storage and updating the issuance details of the decentralized ID by recording them in the ID issuance history.

[0004] As methods of proving the qualifications of users (holders) using credentials become more actively used, the need for efficient communication between holders of various credentials and verifiers verifying them increases. However, the technologies introduced so far, including the above-mentioned conventional technologies, do not provide an appropriate solution to this problem.

[0005] Accordingly, the inventor(s) of the present invention propose a technology that supports efficient communication between a holder and a verifier by requesting information necessary for proof of the holder node's qualifications from the holder node and obtaining information necessary for proof of qualifications from the holder node based on a preset priority for proof of qualifications.

[0006] <Prior Art Literature>

[0007] Patent Document

[0008] (Patent Document 0001) Korean Patent Publication No. 10-2023-0143410 (October 12, 2023)

[0009] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.

[0010] In addition, the present invention has another purpose of requesting information necessary for proof of qualification of a holder node from a holder node and obtaining information necessary for proof of qualification from the holder node based on a preset priority with respect to proof of qualification.

[0011] In addition, another object of the present invention is to receive a request for information necessary for proof of qualification of a holder node from a verifier node, and to provide the information necessary for proof of qualification to the verifier node based on a preset priority with respect to proof of qualification.

[0012] In addition, another object of the present invention is to support efficient communication between a holder and a verifier.

[0013] In addition, another object of the present invention is to provide a system that can efficiently manage and share credentials of SD (Selective Disclosure) attributes.

[0014] In addition, another object of the present invention is to enable a holder and a verifier to communicate through a simplified communication protocol.

[0015] In addition, another purpose of the present invention is to support sharing of only necessary information between holders and verifiers by complying with the data minimization principle.

[0016] In addition, another object of the present invention is to efficiently manage credential schema (VC schema) information and enable efficient access to the information.

[0017] In addition, another object of the present invention is to enable multiple credential requests and to support selection of credentials (or claims included therein) based on preset priorities.

[0018] A representative configuration of the present invention to achieve the above purpose is as follows.

[0019] According to one aspect of the present invention, a method is provided, comprising the steps of requesting information necessary for proof of qualification of a holder node from a holder node, and obtaining information necessary for proof of qualification from the holder node based on a predetermined priority with respect to proof of qualification.

[0020] According to another aspect of the present invention, a method is provided, comprising the steps of receiving a request for information necessary for proof of qualification of a holder node from a verifier node, and providing the information necessary for proof of qualification to the verifier node based on a predetermined priority with respect to proof of qualification.

[0021] According to another aspect of the present invention, a system is provided, including an information request unit that requests a holder node for information necessary for proof of qualification of the holder node, and an information acquisition unit that obtains information necessary for proof of qualification from the holder node based on a predetermined priority with respect to proof of qualification.

[0022] According to another aspect of the present invention, a system is provided, including a request receiving unit that receives a request for information necessary for proving the qualification of a holder node from a verifier node, and an information providing unit that provides the verifier node with information necessary for proving the qualification based on a predetermined priority with respect to the proving of the qualification.

[0023] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.

[0024] According to the present invention, it is possible to request information necessary for proof of qualification of a holder node from a holder node, and to obtain information necessary for proof of qualification from the holder node based on a preset priority with respect to proof of qualification.

[0025] In addition, according to the present invention, it is possible to receive a request for information necessary for proving the qualifications of a holder node from a verifier node, and provide the information necessary for proving the qualifications to the verifier node based on a preset priority with respect to proving the qualifications.

[0026] In addition, according to the present invention, it is possible to support efficient communication between a holder and a verifier.

[0027] In addition, according to the present invention, it is possible to provide a system that can efficiently manage and share credentials of SD attributes.

[0028] Additionally, according to the present invention, the holder and the verifier can communicate through a simplified communication protocol.

[0029] Additionally, according to the present invention, only necessary information is shared between the holder and the verifier by adhering to the data minimization principle.

[0030] In addition, according to the present invention, it is possible to efficiently manage credential schema information and enable efficient access to the information.

[0031] Additionally, the present invention enables multiple credential requests and supports selection of credentials (or claims included therein) based on preset priorities.

[0032] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the use of verifiable credentials according to one embodiment of the present invention.

[0033] FIG. 2 is a drawing detailing the internal configuration of a verifier system according to one embodiment of the present invention.

[0034] FIG. 3 is a drawing detailing the internal configuration of a holder-side system according to one embodiment of the present invention.

[0035] FIG. 4 and FIG. 5 are diagrams exemplarily showing a process of obtaining information necessary for proving the qualifications of a holder node according to one embodiment of the present invention.

[0036] <Explanation of symbols>

[0037] 100: Communications network

[0038] 200: Verifier side system

[0039] 210: Information Request Department

[0040] 220: Information Acquisition Department

[0041] 300: Holder-side system

[0042] 310: Request receiving unit

[0043] 320: Information Department

[0044] 230, 330: Communications Department

[0045] 240, 340: Control unit

[0046] 400: Issuer's system

[0047] 500: Device

[0048] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.

[0049] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.

[0050] Composition of the entire system

[0051] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the use of verifiable credentials according to one embodiment of the present invention.

[0052] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a verifier-side system (200), a holder-side system (300), an issuer-side system (400), and a device (500).

[0053] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.

[0054] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.

[0055] Next, a node (not shown) according to one embodiment of the present invention, for example, an issuer node, a holder node, a verifier node, etc., is a contact point or connection point that can communicate with other nodes through a communication network (100), and may be a concept including a physical node such as a server, a computer, a laptop, a smart phone, a tablet PC, etc. (i.e., a digital device equipped with a memory means and equipped with a microprocessor to have computational capabilities), or a logical node by an application, a program module, a virtual machine, etc. (i.e., a virtual node).

[0056] Specifically, according to one embodiment of the present invention, a node may be a digital wallet in itself, or may be a concept that includes a digital wallet. A digital wallet is a software or hardware device that allows users to securely store and manage digital assets, authentication information, identity information, etc., and refers to a means for storing various data while enabling the use of the stored data as needed. For example, an issuer node, a holder node, and a verifier node may refer to digital wallets owned by an issuer, holder, and verifier, respectively, or digital wallets running on the devices of an issuer, holder, and verifier.

[0057] According to one embodiment of the present invention, these nodes may refer to each node that is interconnected to form a distributed ledger network. According to one embodiment of the present invention, these nodes may include a verifier system (200), a holder system (300), and / or an issuer system (400), which will be described later, in the form of program modules such as applications and widgets to support the use of credentials based on distributed ledger technology (DLT). Furthermore, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).

[0058] Here, according to one embodiment of the present invention, a distributed ledger may refer to a method of storing and managing data distributedly across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledgers described above include, but are not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).

[0059] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which multiple nodes participating in the network jointly verify information to be stored on the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of private and public blockchains.

[0060] Meanwhile, according to one embodiment of the present invention, the nodes described above may be interconnected to form a distributed ledger network. This is merely an example and is not intended to be limiting. In other words, a node according to one embodiment of the present invention may refer to any type of reliable storage medium that serves as a participant in verifying and storing data and exchanging information with other nodes to maintain the integrity and consistency of the entire system.

[0061] Next, the verifier side system (200) according to one embodiment of the present invention may perform a function of requesting information necessary for proof of qualification of the holder node from the holder node and obtaining information necessary for proof of qualification from the holder node based on a preset priority with respect to proof of qualification.

[0062] According to one embodiment of the present invention, the verifier side system (200) may mean a system including a verifier node or included in a verifier node, or may mean the verifier node itself.

[0063] The configuration and function of the verifier system (200) according to the present invention will be described in detail below.

[0064] Next, the holder-side system (300) according to one embodiment of the present invention can perform a function of receiving a request for information necessary for proof of qualification of the holder node from the verifier node, and providing the information necessary for proof of qualification to the verifier node based on a preset priority with respect to proof of qualification.

[0065] According to one embodiment of the present invention, the holder-side system (300) may mean a system including a holder node or included in a holder node, or may mean the holder node itself.

[0066] The configuration and function of the holder-side system (300) according to the present invention will be described in detail below.

[0067] Next, the issuer system (400) according to one embodiment of the present invention can perform the function of generating credentials and issuing them to holder nodes. Typically, an issuer is a trusted institution or organization with the authority to verify information about an individual or organization and issue credentials proving such information. Examples of such issuers include, but are not limited to, various institutions such as universities, government agencies, financial institutions, and employers.

[0068] According to one embodiment of the present invention, the issuer-side system (400) may mean a system including or included in an issuer node, or may mean the issuer node itself.

[0069] Next, a device (500) according to one embodiment of the present invention is a digital device that includes a function to connect to and communicate with a verifier-side system (200), a holder-side system (300), and / or an issuer-side system (400), and any digital device that has a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (500) according to the present invention.

[0070] In particular, the device (500) may include an application (not shown) that supports a user to receive a service according to the present invention from a verifier-side system (200), a holder-side system (300), and / or an issuer-side system (400). Such an application may be downloaded from the verifier-side system (200), the holder-side system (300), the issuer-side system (400), and / or an external application distribution server (not shown). Meanwhile, the nature of such an application may be generally similar to the information request unit (210), the information acquisition unit (220), the communication unit (230), and the control unit (240) of the verifier-side system (200), which will be described later, and the request reception unit (310), the information provision unit (320), the communication unit (330), and the control unit (340) of the holder-side system (200). Here, the application may be replaced by a hardware device or firmware device that can perform substantially the same or equivalent functions as required, at least in part.

[0071] According to one embodiment of the present invention, such a device (500) may mean one of a plurality of nodes (e.g., issuer node, holder node, verifier node, etc.) that are interconnected to form a distributed ledger network.

[0072] Configuration of the verifier-side system

[0073] Below, the internal configuration and functions of each component of the verifier system (200) that performs important functions for implementing the present invention will be examined.

[0074] FIG. 2 is a drawing detailing the internal configuration of a verifier system (200) according to one embodiment of the present invention.

[0075] As illustrated in FIG. 2, a verifier system (200) according to one embodiment of the present invention may be configured to include an information request unit (210), an information acquisition unit (220), a communication unit (230), and a control unit (240). According to one embodiment of the present invention, at least some of the information request unit (210), the information acquisition unit (220), the communication unit (230), and the control unit (240) may be program modules that communicate with an external system (not shown). These program modules may be included in the verifier system (200) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may be stored in a remote memory device that can communicate with the verifier system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, which will be described later, according to the present invention.

[0076] Meanwhile, although the verifier system (200) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the verifier system (200) may be realized within a device (500) or a server (not shown) or included within an external system (not shown) as needed.

[0077] First, the information request unit (210) according to one embodiment of the present invention can perform a function of requesting information necessary for proving the qualifications of the holder node from the holder node.

[0078] FIGS. 4 and 5 are diagrams exemplifying a process for obtaining information necessary for proving the qualifications of a holder node according to one embodiment of the present invention. Hereinafter, with reference to FIGS. 4 and / or 5 , the process by which a verifier node (700) obtains information necessary for proving the qualifications of a holder node (600) will be described.

[0079] Specifically, according to one embodiment of the present invention, information required to prove the qualification of the holder node (600) may mean information required to prove that the holder node (600) has a specific qualification using at least one credential (610, 620 and / or 630) held by the holder node (600), or information required for the verifier node (700) to verify that the holder node (600) has such qualification. According to one embodiment of the present invention, such specific qualifications may include, but are not limited to, possession of a specific certificate, being an adult, belonging to a specific organization, being a corporation, or having performed an activity that satisfies specific conditions, but may be variously changed within a scope that can achieve the purpose of the present invention.

[0080] According to one embodiment of the present invention, the information request unit (210) may generate a request (710) by specifying information necessary for proving the qualification of the holder node (600), and request the request to the holder node (600) (S420). According to one embodiment of the present invention, at least one credential and / or at least one claim (a credential including the claim may or may not be specified) may be specified as information necessary for proving the qualification of the holder node (600) or as a means for obtaining the information. Referring to FIG. 4, for example, the information request unit (210) according to one embodiment of the present invention may request either credentials A and C, or either A and C, issued from an issuer node called K as information necessary for proving the qualification of the holder node (600) or as a means for obtaining the information (S420). In this case, it should be understood that the issuer does not necessarily need to be specified when specifying at least one credential and / or at least one claim.

[0081] According to one embodiment of the present invention, the request (710) generated as described above may include, but is not limited to, an ID for identifying the request, a timestamp, information about the requester (verifier), etc. In addition, according to one embodiment of the present invention, in order to minimize the amount of communication between the holder node (600) and the verifier node (700), the request (710) may be converted into a compressed binary format and transmitted to the holder node (600).

[0082] The information request unit (210) according to one embodiment of the present invention can simultaneously request multiple elements (i.e., information required for proof of qualification; for example, multiple credentials, multiple claims, etc.) by making such a request in a vectorized format. If proof of qualification of the holder node (600) is possible with only some of the requested multiple elements (for example, in the above example, proof of qualification of the holder node (600) is possible with only one of credentials A and C issued by an issuer node called K), the information required for proof of qualification of the holder node (600) can be acquired based on a preset priority for the multiple elements. According to one embodiment of the present invention, the preset priority for proof of qualification of the holder node (600) may be set by the verifier node (700).

[0083] Specifically, when a verifier node (700) according to one embodiment of the present invention requests multiple elements (e.g., credentials, claims, etc.) as information necessary for proving the qualifications of a holder node (600), the verifier node (700) may set a priority for proving the qualifications of the holder node (600) by assigning a numerical value (e.g., a value between 1 and 100) to each element or associating conditional priority logic (e.g., IF-THEN-ELSE logic) with respect to the multiple elements. The information request unit (210) according to one embodiment of the present invention may provide a user (verifier) ​​with an interface that allows the verifier node (700) to set such priorities.

[0084] In addition, the information request unit (210) according to one embodiment of the present invention may provide the holder node (600) with information regarding whether each element included in the information required for proof of qualification of the holder node (600) must be provided or can be provided optionally.

[0085] Meanwhile, the information request unit (210) according to one embodiment of the present invention may request information necessary for verifying the qualifications of the holder node (600) by providing the holder node (600) with basic information regarding the information necessary for verifying the qualifications of the holder node (600) (S420). Here, according to one embodiment of the present invention, the basic information may include access information for a schema repository.

[0086] Specifically, referring to FIG. 5, a schema repository (800) according to one embodiment of the present invention may refer to a space that stores credential schema (VC schema) information, which is schema information for each credential. According to one embodiment of the present invention, the schema may follow a standardized SD-JWT format, and the schema information may include, for example, information about an issuer, a schema version, a schema ID, a type or data structure of data (claims) included in a credential, which of the data (claims) included in the credential is an SD attribute (i.e., whether selective information disclosure is possible), which of the data (claims) included in the credential is optional, and the like, but is not limited thereto.

[0087] According to one embodiment of the present invention, the information request unit (210), the information acquisition unit (220), the request reception unit (310), and / or the information provision unit (320) can obtain information by querying the schema repository (800) using a RESTful API. In addition, according to one embodiment of the present invention, the schema repository (800) can provide functions such as schema change history tracking, rollback, and real-time schema update notification to the information request unit (210), the information acquisition unit (220), the request reception unit (310), and / or the information provision unit (320). By utilizing (querying) the schema repository (800) based on the schema ID in this way, dynamic data interpretation that can flexibly respond to schema changes can be enabled.

[0088] Continuing, according to one embodiment of the present invention, the basic information regarding information required for proof of qualification of the holder node (600) may refer to information that is absolutely necessary for the information providing unit (330) to be described later to obtain detailed information regarding information required for proof of qualification of the holder node (600) through the schema repository (800). For example, such basic information may include necessary elements (e.g., specific credentials, specific claims, etc.) and access information for the schema repository (e.g., URL of the schema repository), and may also include information regarding the version of the schema (or schema repository), the schema ID (i.e., identification information of the schema to be referenced), etc., but is not limited thereto.

[0089] The information request unit (210) according to one embodiment of the present invention provides only basic information regarding information necessary for proving the qualification of the holder node (600) to the holder node (600), and enables the information provision unit (330) to obtain detailed information regarding information necessary for proving the qualification of the holder node (600) through an external schema repository, thereby enabling efficient communication to be performed (communication volume to be minimized) between the holder node (600) and the verifier node (700).

[0090] If necessary, the information request unit (210) according to one embodiment of the present invention may obtain some of the basic information as described above through the schema repository (800) (S410) before requesting information necessary for proof of qualification of the holder node (600) (S420).

[0091] Next, the information acquisition unit (220) according to one embodiment of the present invention can perform a function of acquiring information necessary for proof of qualification from the holder node (600) based on a preset priority with respect to proof of qualification of the holder node (600) (S440).

[0092] Specifically, the information acquisition unit (220) according to one embodiment of the present invention can acquire information required for proof of the qualification of the holder node (600) from the holder node (600) (S440). At this time, the acquired information may be determined by the holder node (600) according to a priority set in advance with respect to proof of the qualification of the holder node (600). As described above, this priority may be set by the verifier node (700), and in some cases, may be set by the holder node (600).

[0093] Additionally, according to one embodiment of the present invention, there may be a case where the priority set by the holder node (600) and the priority set by the verifier node (700) conflict. In such a case, the information acquisition unit (220) according to one embodiment of the present invention may acquire information necessary for proving the qualifications of the holder node (600) based on the priority determined based on auxiliary criteria regarding the priority (S440). This will be described in detail later.

[0094] Continuing, the information required for proof of qualification of the holder node (600) obtained by the information acquisition unit (220) according to one embodiment of the present invention (which may refer to basic information and / or detailed information regarding the information required for proof of qualification of the holder node (600) described above and below depending on the context) may be data in a verifiable presentation (VP; 640) format, or data converted into a compressed binary format to minimize the amount of communication between the holder node (600) and the verifier node (700).

[0095] Referring to FIG. 4, for example, an information request unit (210) according to one embodiment of the present invention may request either one of credentials A and C issued from an issuer node K as information necessary for proving the qualification of a holder node (600) (S420). In addition, an information acquisition unit (220) according to one embodiment of the present invention may obtain information on either one of credentials A and C from the holder node (600) as information necessary for proving the qualification based on a preset priority (which may be set by the holder node (600) and / or the verifier node (700) as described above) with respect to proving the qualification of the holder node (600) (S440).

[0096] Referring again to FIG. 5, when the information request unit (210) according to one embodiment of the present invention requests information necessary for the verification of the qualification of the holder node (600) by providing the holder node (600) with basic information regarding information necessary for the verification of the qualification of the holder node (600) (S420), the information acquisition unit (220) according to one embodiment of the present invention may acquire detailed information regarding information necessary for the verification of the qualification of the holder node (600) obtained (S430) through the schema repository (800) from the holder node (600) (S440), or may acquire detailed information regarding information necessary for the verification of the qualification through the schema repository (800) based on the information necessary for the verification of the qualification obtained (S440) from the holder node (600) (S450).

[0097] In this case, when the information acquisition unit (220) according to one embodiment of the present invention acquires detailed information about information required for verification of the corresponding qualification through the schema storage (800) based on information required for verification of the corresponding qualification acquired from the holder node (600) (S440), the information required for verification of the corresponding qualification acquired from the holder node (600) (S440) may include a schema ID.

[0098] Here, the information acquisition unit (220) according to one embodiment of the present invention, in response to not being able to acquire detailed information about information necessary for verification of the qualification of the holder node (600) through the local cache of the verifier node (700) based on information necessary for verification of the qualification of the holder node (600) acquired from the holder node (600) (S440), can acquire detailed information about information necessary for verification of the qualification through the schema repository (800) (S450).

[0099] That is, the information acquisition unit (220) according to one embodiment of the present invention first checks whether detailed information regarding information required for verification of the qualification of the holder node (600) can be acquired through the local cache of the verifier node (700), and only if it cannot be acquired, can the detailed information regarding information required for verification of the qualification be acquired through the schema repository (800) (S450). If necessary, the local cache of the verifier node (700) and the external schema repository (800) can be synchronized at an appropriate time, thereby enabling communication with the schema repository (800) to be performed more efficiently.

[0100] According to one embodiment of the present invention, the information acquisition unit (220) can decrypt and verify the integrity of the information obtained from the holder node (600) when the information required to prove the qualification of the holder node (600) is obtained from the holder node (600) (S440). In addition, if the information obtained from the holder node (600) follows the JSON-LD format, the data can be normalized by processing the JSON-LD context.

[0101] In addition, if necessary, the information acquisition unit (220) according to one embodiment of the present invention can query the schema repository (800) using the schema ID and verify the consistency between the information acquired from the holder node (600) and the schema. In addition, the information acquisition unit (220) according to one embodiment of the present invention can verify the validity of the credential by confirming the digital signature and the identity of the issuer based on the information acquired from the holder node (600). If the credential is determined to be valid, the information acquisition unit (220) according to one embodiment of the present invention can extract and use necessary information (e.g., claim information) based on the information acquired from the holder node (600).

[0102] Next, the communication unit (230) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the information request unit (210) and the information acquisition unit (220).

[0103] Finally, the control unit (240) according to one embodiment of the present invention can perform a function of controlling the flow of data between the information request unit (210), the information acquisition unit (220), and the communication unit (230). That is, the control unit (240) according to one embodiment of the present invention can control the flow of data from / to the outside of the verifier system (200) or the flow of data between each component of the verifier system (200), thereby controlling the information request unit (210), the information acquisition unit (220), and the communication unit (230) to perform their own functions.

[0104] Configuration of the holder-side system

[0105] Below, the internal configuration and functions of each component of the holder-side system (300) that performs important functions for implementing the present invention will be examined.

[0106] FIG. 3 is a drawing showing in detail the internal configuration of a holder-side system (300) according to one embodiment of the present invention.

[0107] As illustrated in FIG. 3, a holder-side system (300) according to one embodiment of the present invention may be configured to include a request receiving unit (310), an information providing unit (320), a communication unit (330), and a control unit (340). According to one embodiment of the present invention, at least some of the request receiving unit (310), the information providing unit (320), the communication unit (330), and the control unit (340) may be program modules that communicate with an external system (not shown). These program modules may be included in the holder-side system (300) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may be stored in a remote memory device that can communicate with the holder-side system (300). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, which will be described later, according to the present invention.

[0108] Meanwhile, although the holder-side system (300) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the holder-side system (300) may be realized within a device (500) or a server (not shown) or included within an external system (not shown) as needed.

[0109] First, the request receiving unit (310) according to one embodiment of the present invention can perform a function of receiving a request (710) for information required for proof of qualification of a holder node (600) from a verifier node (700) (S420).

[0110] If necessary, the request receiving unit (310) according to one embodiment of the present invention may receive basic information (710) regarding information required to prove the qualifications of the holder node (600) from the verifier node (700) (S420). Here, according to one embodiment of the present invention, the above basic information may include access information regarding a schema repository. Since the basic information regarding information required to prove the qualifications of the holder node (600) and the schema repository have been described above, a redundant description will be omitted.

[0111] Specifically, when the request receiving unit (310) according to one embodiment of the present invention receives basic information (710) regarding information required for proof of qualification of a holder node (600) from a verifier node (700) (S420), it can, if necessary, obtain detailed information regarding information required for proof of qualification through an external schema storage (800) based on the received basic information (710) (S430).

[0112] Here, the request receiving unit (310) according to one embodiment of the present invention, in response to not being able to obtain detailed information about information required for verification of the qualification of the holder node (600) through the local cache of the holder node (600) based on basic information (710) about information required for verification of the qualification of the holder node (600) received from the verifier node (700), can obtain detailed information about information required for verification of the qualification obtained through the schema repository (800) (S430).

[0113] That is, the request receiving unit (310) according to one embodiment of the present invention first checks whether detailed information regarding information required for verification of the qualification of the holder node (600) can be obtained through the local cache of the holder node (600), and only if it cannot be obtained, can the detailed information regarding information required for verification of the qualification be obtained through the schema repository (800) (S430). If necessary, the local cache of the holder node (600) and the external schema repository (800) can be synchronized at an appropriate time, thereby enabling communication with the schema repository (800) to be performed more efficiently.

[0114] According to one embodiment of the present invention, when referencing a schema repository (800), the request receiving unit (310) can verify whether the schema version received from the verifier node (700) matches the schema version on the schema repository (800). In addition, if there is a match, the detailed information described above can be acquired through the schema repository (800) by performing mapping of necessary information using the schema ID (S430).

[0115] Next, the information provision unit (320) according to one embodiment of the present invention can perform a function of providing the verifier node (700) with information necessary for proof of qualification based on a preset priority regarding proof of qualification of the holder node (600) (S440).

[0116] Specifically, according to one embodiment of the present invention, the priority for proof of qualification of the holder node (600) may be set by the verifier node (700). In this case, the information providing unit (320) according to one embodiment of the present invention may determine which credentials or claims to provide information to the verifier node (700) by performing matching with the credentials or claims held by the holder node (600) based on the priority value or conditional priority logic included in the information received from the verifier node (700).

[0117] According to one embodiment of the present invention, the priority for proof of qualification of the holder node (600) may be set by the holder node (600). Specifically, the holder node (600) may set the priority for proof of qualification of the holder node (600) by assigning a numerical value (e.g., a value between 1 and 100) to the qualification it holds or the claims included therein, or by associating conditional priority logic (e.g., IF-THEN-ELSE logic).

[0118] According to one embodiment of the present invention, an AI-based model may be utilized to determine these priorities. Furthermore, according to one embodiment of the present invention, an interface that allows the holder node (600) to set these priorities may be provided to the user (holder).

[0119] Meanwhile, the information provision unit (320) according to one embodiment of the present invention, in response to a conflict between the priority set by the holder node (600) and the priority set by the verifier node (700), may provide the verifier node (700) with information necessary for proving the qualification of the holder node (600) according to a priority determined based on an auxiliary criterion regarding priority.

[0120] Specifically, according to one embodiment of the present invention, when both the holder node (600) and the verifier node (700) set priorities regarding the proof of the qualifications of the holder node (600), there may be cases where the information (e.g., information regarding a specific credential or a specific claim) determined according to the priority set by the holder node (600) and the information determined according to the priority set by the verifier node (700) are different, resulting in a conflict in priorities. In such cases, the information providing unit (320) according to one embodiment of the present invention may determine which information to provide based on auxiliary criteria regarding priorities. According to one embodiment of the present invention, the auxiliary criteria may include, but are not limited to, for example, the frequency of use of the credential or claim, the recency, the size of data to be provided when information regarding the credential or claim must be provided to the verifier node (700), and the like. Any criteria that are different from the criteria for determining priorities that caused the conflict may correspond to auxiliary criteria.

[0121] According to one embodiment of the present invention, the information provision unit (320) can extract necessary information (e.g., claim information) when the information (e.g., credentials) to be provided to the verifier node (700) is determined as described above. At this time, if necessary, zero-knowledge proof (ZKP) technology can be used to minimize (or limit) the information provided to the verifier node (700).

[0122] And, the information providing unit (320) according to one embodiment of the present invention may configure response data in order to respond to the request (710) received from the verifier node (700) (i.e., to provide the verifier node (700) with information necessary for proving the qualification of the holder node (600). According to one embodiment of the present invention, such response data may be data in JSON-LD format, and a signature may be added to ensure integrity. The response data configured in this way may be compressed or encrypted, and may be transmitted to the verifier node (700) using a protocol such as OPENID4VC or DIDComm (S440).

[0123] Next, the communication unit (330) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the request receiving unit (310) and the information providing unit (320).

[0124] Finally, the control unit (340) according to one embodiment of the present invention can perform a function of controlling the flow of data between the request receiving unit (310), the information providing unit (320), and the communication unit (330). That is, the control unit (340) according to one embodiment of the present invention can control the flow of data from / to the outside of the holder-side system (300) or the flow of data between each component of the holder-side system (300), thereby controlling the request receiving unit (310), the information providing unit (320), and the communication unit (330) to perform their respective unique functions.

[0125] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0126] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.

[0127] Therefore, the idea of ​​the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of ​​the present invention.

Claims

1. As a method to support the use of verifiable credentials, A step of requesting the holder node for information necessary to prove the qualification of the holder node, and A step of obtaining information required for proof of qualification from the holder node based on a predetermined priority with respect to proof of qualification method.

2. In paragraph 1, In the above request step, the information required for the verification of the qualification is requested by providing the holder node with basic information regarding the information required for the verification of the qualification, wherein the basic information includes access information for the schema storage, In the above acquisition step, detailed information about information required for verification of the qualification acquired through the schema repository is acquired from the holder node, or detailed information about information required for verification of the qualification is acquired through the schema repository based on the information required for verification of the qualification acquired from the holder node. method.

3. In paragraph 2, In the above acquisition step, in response to not being able to acquire detailed information about the information required for the verification of the qualification through the local cache of the verifier node based on the information required for the verification of the qualification acquired from the holder node, detailed information about the information required for the verification of the qualification is acquired through the schema repository. method.

4. In paragraph 1, The above priorities are set by the validator nodes. method.

5. In paragraph 1, The above priority is set by the holder node. method.

6. In paragraph 5, In the above acquisition step, in response to a conflict between the priority set by the holder node and the priority set by the verifier node, information required for proof of the qualification is acquired according to a priority determined based on auxiliary criteria regarding priority. method.

7. As a method to support the use of verifiable credentials, A step of receiving a request for information required to prove the qualifications of a holder node from a verifier node, and A step of providing the verifier node with information necessary for proof of the qualification based on a predetermined priority with respect to proof of the qualification. method.

8. In paragraph 7, In the above receiving step, basic information regarding information required for proof of the qualification is received from the verifier node, wherein the basic information includes access information for a schema repository, In the above provision step, detailed information about information required for proof of the qualification obtained through the schema repository is provided to the verifier node based on basic information about information required for proof of the qualification received from the verifier node. method.

9. In paragraph 8, In the above provision step, in response to not being able to obtain detailed information about the information required for the verification of the qualification through the local cache of the holder node based on basic information about the information required for the verification of the qualification received from the verifier node, detailed information about the information required for the verification of the qualification obtained through the schema repository is provided to the verifier node. method.

10. In paragraph 7, The above priority is set by the verifier node. method.

11. In paragraph 7, The above priority is set by the holder node. method.

12. In paragraph 11, In the above provision step, in response to a conflict between the priority set by the holder node and the priority set by the verifier node, the information required for proof of the qualification is provided according to the priority determined based on the auxiliary criteria regarding the priority. method.

13. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1 or paragraph 7.

14. As a system to support the use of verifiable credentials, An information request unit that requests the holder node for information necessary to prove the qualification of the holder node, and An information acquisition unit that acquires information necessary for the verification of the qualification from the holder node based on a preset priority regarding the verification of the qualification. System.

15. In paragraph 14, The above information request unit requests information required for verification of the qualification by providing the holder node with basic information regarding information required for verification of the qualification, wherein the basic information includes access information for a schema repository. The above information acquisition unit acquires detailed information about information required for verification of the qualification acquired through the schema repository from the holder node, or acquires detailed information about information required for verification of the qualification through the schema repository based on the information required for verification of the qualification acquired from the holder node. System.

16. In paragraph 15, The above information acquisition unit, in response to not being able to acquire detailed information about information required for verification of the qualification through the local cache of the verifier node based on information required for verification of the qualification acquired from the holder node, acquires detailed information about information required for verification of the qualification through the schema repository. System.

17. In paragraph 14, The above priorities are set by the validator nodes. System.

18. In paragraph 14, The above priority is set by the holder node. System.

19. In paragraph 18, The above information acquisition unit, in response to a conflict between the priority set by the holder node and the priority set by the verifier node, acquires information necessary for proof of the qualification according to a priority determined based on auxiliary criteria regarding priority. System.

20. As a system to support the use of verifiable credentials, A request receiving unit that receives a request for information required to prove the qualifications of a holder node from a verifier node, and An information providing unit that provides the verifier node with information necessary for proving the qualification based on a predetermined priority regarding the proof of the qualification. System.

21. In paragraph 20, The request receiving unit receives basic information regarding information required for proof of the qualification from the verifier node, wherein the basic information includes access information for a schema repository, The above information providing unit provides detailed information about the information required for the verification of the qualification obtained through the schema repository to the verifier node based on basic information about the information required for the verification of the qualification received from the verifier node. System.

22. In paragraph 21, The information providing unit, in response to not being able to obtain detailed information about the information required for the verification of the qualification through the local cache of the holder node based on basic information about the information required for the verification of the qualification received from the verifier node, provides detailed information about the information required for the verification of the qualification obtained through the schema repository to the verifier node. System.

23. In paragraph 20, The above priority is set by the verifier node. System.

24. In paragraph 20, The above priority is set by the holder node. System.

25. In paragraph 24, The above information provider, in response to a conflict between the priority set by the holder node and the priority set by the verifier node, provides information necessary for proof of the qualification according to a priority determined based on auxiliary criteria regarding priority. System.

Citation Information

Patent Citations

  • Device, method, and graphical user interface for managing authentication credential for user account

    JP2023175817A

  • Sleep state feedback system providing feedback based on sleep pattern of glaucoma patient and sleep state feedback method using the same

    KR1020250112930A

  • Air vent of vihecle using natural wind

    KR102623696B1

  • KR20220097054A

  • KR20230058797A