Method and system for identifying status of verifiable credential
Decentralized management of credential status using a distributed ID (DID) with integrated status information addresses the inefficiencies of centralized management, reducing costs and time by eliminating the need for additional infrastructure, thus enhancing the efficiency of credential status updates.
Patent Information
- Application Number
- PCT/KR2025/001629
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-03
- Filing Date
- 2025-02-04
- Publication Date
- 2025-08-14
AI Technical Summary
Existing decentralized identity verification systems incur excessive costs and time for issuers to manage and update the status of credentials due to centralized management and reliance on separate status verification services, hindering efficient operations.
Implementing a method that manages credential status information using a distributed ID (DID) with an extended state field, allowing decentralized management and reducing the need for additional infrastructure or software, such as a download server, by integrating status information directly into the DID document.
This approach reduces time and cost associated with credential status management by enabling efficient, decentralized management of credential status through a distributed ID format, providing detailed metadata and eliminating the need for separate status verification systems.
Smart Images

Figure KR2025001629_14082025_PF_FP_ABST
Abstract
Description
Method and system for checking the status of a credential
[0001] The present invention relates to a method and system for verifying the status of a credential.
[0002] In recent years, there has been a surge in the use of decentralized identity systems, which empower users to control and manage their identities to ensure security and transparency without relying on central authorities such as governments or corporations.
[0003] A verifiable credential (VC) is a digital document containing information related to identity used in the decentralized identity verification process. The holder of the credential can present it to a third party (or verifier) as needed, and the validity can be verified based on the electronic signature of the issuer and the holder who issued the credential, thereby performing identity verification.
[0004] Meanwhile, even after a credential has been validly issued by the issuer, it can become invalid again for various reasons. Information related to this validity can be referred to as the credential's status. To ensure trustworthiness in identity verification performed using a credential, verifying the credential's status during the identity verification process is essential.
[0005] However, according to the above-mentioned prior art, as well as the technologies introduced to date, the status of the aforementioned credentials is managed through a separate list or status verification service, and in most cases, the issuer of the credentials manages this directly. These prior art technologies result in excessive costs and time for issuers to manage a large number of credentials and update their status, hindering efficient operations.
[0006] Accordingly, the inventor(s) of the present invention propose a method that can express various states of a credential in detail while improving management efficiency by managing information related to the state of a credential based on a distributed ID with an extended state field applied, instead of having the issuer directly manage information related to the state of a credential.
[0007] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0008] In addition, the present invention has another object of receiving information related to the issuance of a holder's credential from a holder node, issuing a credential based on the received information related to the issuance of the credential, and the credential includes a decentralized ID (DID) capable of querying a decentralized ID document (DID document) containing information about the status of the credential.
[0009] In addition, the present invention provides the effect of independently operating metadata for status information for each credential by expressing and managing information related to the status of the credential in the form of a distributed ID, and further provides more detailed information about the status of the credential by adding a field expressing the status of the credential in more detail to the aforementioned distributed ID.
[0010] In addition, another purpose of the present invention is to drastically reduce the time and cost required to manage the status of a credential by expressing and managing information related to the status of a credential in a distributed ID format without requiring the issuer to separately operate infrastructure or software such as a download server to manage the status of the credential.
[0011] A representative configuration of the present invention to achieve the above purpose is as follows.
[0012] According to one aspect of the present invention, a method is provided, comprising the steps of receiving information related to the issuance of a credential of a holder from a holder node, and issuing a credential based on the received information related to the issuance of the credential, wherein the credential includes a distributed ID (DID) capable of querying a distributed ID document (DID document) including information about the status of the credential.
[0013] According to another aspect of the present invention, a method is provided, comprising the steps of: checking the validity period of a credential based on the credential of a holder; and checking information on the status of the credential in response to the validity period not having expired, wherein the credential includes a decentralized ID (DID) capable of querying a decentralized ID document (DID document) including information on the status of the credential.
[0014] According to another aspect of the present invention, a system is provided, including a receiving unit that receives information related to the issuance of a holder's credential from a holder node, and an issuing unit that issues a credential based on the received information related to the issuance of the credential, wherein the credential includes a distributed ID (DID) that can query a distributed ID document (DID document) that includes information about the status of the credential.
[0015] According to another aspect of the present invention, a system is provided, including a validity period verification unit for verifying the validity period of a credential based on a holder's credential, and a status information verification unit for verifying information on the status of the credential in response to the validity period not having expired, wherein the credential includes a distributed ID (DID) capable of searching a distributed ID document (DID document) including information on the status of the credential.
[0016] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0017] According to the present invention, by expressing and managing information related to the status of a credential in the form of a distributed ID, it is possible to provide the effect of independently operating metadata for status information for each credential, and furthermore, by adding a field expressing the status of the credential in more detail to the above-described distributed ID, it is possible to provide more detailed information regarding the status of the credential.
[0018] In addition, according to the present invention, the issuer does not need to separately operate infrastructure or software, such as a download server for status verification, to verify the status of a credential, and by expressing and managing information related to the status of a credential in a distributed ID format, the time and cost required for managing information related to the status of a credential can be drastically reduced.
[0019] FIG. 1 is a diagram schematically showing the entire configuration of a credentialing system according to one embodiment of the present invention.
[0020] FIG. 2 is a drawing detailing the internal configuration of a credential issuance system according to one embodiment of the present invention.
[0021] FIG. 3 is a drawing detailing the internal configuration of a credential verification system according to one embodiment of the present invention.
[0022] FIG. 4 is a diagram schematically illustrating a configuration of a blockchain network and a plurality of nodes included therein according to one embodiment of the present invention.
[0023] <Explanation of symbols>
[0024] 100: Communications network
[0025] 200: Credential Issuance System
[0026] 210: Receiver
[0027] 220: Publications Department
[0028] 230: 1st Communications Department
[0029] 240: First Control Unit
[0030] 300: Credential Verification System
[0031] 310: Validity Check Section
[0032] 320: Status information confirmation unit
[0033] 330: 2nd Communications Department
[0034] 340: Second Control Unit
[0035] 400: Device
[0036] 500: Multiple nodes
[0037] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0038] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0039] Composition of the entire system
[0040] FIG. 1 is a diagram schematically showing the entire configuration of a credentialing system according to one embodiment of the present invention.
[0041] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a credential issuance system (200), a credential verification system (300), and a device (400).
[0042] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0043] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.
[0044] Next, a credential issuance system (200) according to an embodiment of the present invention is a credential issuance system by an issuer node, which receives information related to the issuance of a credential of a holder from a holder node, issues a credential based on the received information related to the issuance of the credential, and the credential may perform a function including a decentralized ID (DID) that can look up a decentralized ID document (DID document) including information about the status of the credential. Meanwhile, the credential issuance system (200) may be a digital device having a memory means and a microprocessor and having a computing capability, and specifically, may be one of a plurality of nodes (500) constituting a distributed ledger as shown in FIG. 4, and more specifically, may be a node corresponding to an issuer among the plurality of nodes (500) constituting the distributed ledger (i.e., an issuer node), or may be equipped to include an issuer node that is one of the plurality of nodes (500) constituting the distributed ledger.
[0045] The configuration and function of the credential issuance system (200) according to the present invention will be described in detail below.
[0046] Next, a credential verification system (300) according to one embodiment of the present invention is a credential verification system by a verifier node, which verifies the validity period of a credential based on the credential of the holder, verifies information on the status of the credential in response to the validity period not having expired, and the credential can perform a function including a decentralized ID (DID) that can look up a decentralized ID document (DID document) including information on the status of the credential. Meanwhile, such a credential verification system (300) may be a digital device having a memory means and a microprocessor and having a computing ability, and specifically, may be one of a plurality of nodes (500) constituting a distributed ledger as shown in FIG. 4, and more specifically, may be a node corresponding to a verifier among the plurality of nodes (500) constituting the distributed ledger (i.e., a verifier node), or may be provided to include a verifier node that is one of the plurality of nodes (500) constituting the distributed ledger.
[0047] The configuration and function of the credential verification system (300) according to one embodiment of the present invention will be described in detail below.
[0048] Next, a device (400) according to one embodiment of the present invention is a digital device that includes a function to communicate after connecting to a credential issuance system (200) or a credential verification system (300), and any digital device that has a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (400) according to the present invention.
[0049] In addition, according to one embodiment of the present invention, the device (400) may further include an application program for performing a function according to the present invention. Such an application may exist in the form of a program module within the device (400). Meanwhile, the nature of such a program module may be generally similar to the receiving unit (210), the issuing unit (220), the first communication unit (230), and the first control unit (240) of the credential issuing system (200) described below, or the validity period confirmation unit (310), the status information confirmation unit (320), the second communication unit (330), and the second control unit (340) of the credential verification system (300). Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform a function substantially identical to or equivalent thereto, as necessary.
[0050] In addition, the device (400) according to one embodiment of the present invention may be equipped to correspond to at least one node among the plurality of nodes (500) constituting the distributed ledger illustrated in FIG. 4. Specifically, the device (400) according to one embodiment of the present invention may be equipped to correspond to at least one of an issuer node, a verifier node, and a holder node among the plurality of nodes (500) constituting the distributed ledger illustrated in FIG. 4. More specifically, the device (400) according to one embodiment of the present invention may be equipped to correspond to a holder node, which is one of the plurality of nodes (500) constituting the distributed ledger, or to include a holder node, and accordingly, a user (holder) may communicate with the distributed ledger and other nodes included therein by using the device (400) described above. Meanwhile, the fact that the above-described device (400) includes a node may specifically mean that the device (400) is executing the node, and the fact that the device (400) is executing the node may mean that it is executing software (or node software) that functions as part of a distributed ledger network.
[0051] Next, the entire system according to one embodiment of the present invention may be configured to include a communication network (100) and a plurality of nodes (500) as illustrated in FIG. 4.
[0052] Each node included in the plurality of nodes (500) according to one embodiment of the present invention is a contact point or connection point that can communicate with other nodes via a communication network (100), and may be a concept including a physical node such as a server, a computer, a laptop, a smart phone, a tablet PC, etc. (i.e., a digital device having a memory means and a microprocessor to provide computational capabilities) or a logical node such as an application, a program module, a virtual machine, etc. (i.e., a virtual node). For example, as described above, the plurality of nodes (500) according to one embodiment of the present invention may include at least one of an issuer node (not shown), a holder node (not shown), and a verifier node (not shown) to be described later.
[0053] Meanwhile, a plurality of nodes (500) according to one embodiment of the present invention may include a credential issuance system (200) and / or a credential verification system (300) according to the present invention in the form of program modules such as applications and widgets to perform verification based on distributed ledger technology (DLT). In addition, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).
[0054] Distributed ledger technology (DLT), according to one embodiment of the present invention, may refer to a method of storing and managing data distributedly across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledgers described above include, but are not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).
[0055] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which information to be stored on the network is jointly verified by a plurality of nodes (500) participating in the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of private and public blockchains.
[0056] Configuration of the credential issuance system
[0057] Below, the internal configuration and functions of each component of the credential issuance system (200) that performs important functions for implementing the present invention will be examined.
[0058] FIG. 2 is a drawing detailing the internal configuration of a credential issuance system (200) according to one embodiment of the present invention.
[0059] As illustrated in FIG. 2, a credential issuing system (200) according to one embodiment of the present invention may be configured to include a receiving unit (210), an issuing unit (220), a first communication unit (230), and a first control unit (240). According to one embodiment of the present invention, at least some of the receiving unit (210), the issuing unit (220), the first communication unit (230), and the first control unit (240) may be program modules that communicate with an external system (not shown). These program modules may be included in the credential issuing system (200) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may be stored in a remote memory device that can communicate with the credential issuing system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, which will be described later, according to the present invention.
[0060] Meanwhile, although the credential issuing system (200) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the credential issuing system (200) may be realized within a device (400) or a server (not shown) or included within an external system (not shown) as needed.
[0061] First, the receiving unit (210) according to one embodiment of the present invention can perform a function of receiving information related to the issuance of a holder's credentials from a holder node.
[0062] Verifiable credentials (VC), according to one embodiment of the present invention, should be understood as a concept encompassing all verifiable and trustworthy credentials issued in digital format. Credentials contain information about an individual or organization's specific qualifications, identity, academic background, career history, etc., and their reliability can be guaranteed through various verifiable methods. As described above, they can be issued, stored, and verified through distributed ledger (or blockchain) technology.
[0063] Specifically, a credential according to one embodiment of the present invention may be a digital credential created based on a standard defined in accordance with the "W3C verifiable credentials data model", but is not limited thereto, and various technical standards and open sources may all be utilized in creating a credential and constructing a credential system according to one embodiment of the present invention.
[0064] Information related to the issuance (or issuance) of a credential according to one embodiment of the present invention should be understood as a concept encompassing all types of information necessary to issue a credential. Specifically, information related to the issuance of a credential may include information provided by the holder to the issuer (e.g., the holder's identity information and unique identifier, etc.) and information about the issuer issuing the credential (e.g., information about the issuer, a unique identifier, the issuer's electronic signature, the issuer's certificate, etc.). However, the information related to the issuance of a credential described above is merely an example, and the information related to the issuance of a credential according to one embodiment of the present invention is not limited thereto, and may vary depending on the purpose of issuing the credential, specific usage patterns, and security requirements.
[0065] According to one embodiment of the present invention, a "holder" may refer to an entity possessing a credential. The holder receives, stores, and manages various identification information or credentials issued by an issuer, and may request verification from a verifier based on the credentials as needed. Meanwhile, according to one embodiment of the present invention, a "holder node" may refer to a node among the multiple nodes (500) described above that corresponds to the holder or is owned by the holder.
[0066] An issuer according to one embodiment of the present invention may refer to an entity that creates and issues a credential at the request of a specific entity (e.g., the holder described above), and may also be referred to as an issuer. The issuer may add its own electronic signature (or digital signature) to the credential it issues, and the electronic signature described above may ensure the integrity and authenticity of the credential, and may be used by a verifier described below to verify or validate the credential. Meanwhile, an issuer node according to one embodiment of the present invention may refer to a node corresponding to or owned by the issuer among the plurality of nodes (500) described above.
[0067] Next, the issuing unit (220) according to one embodiment of the present invention can perform a function of issuing a credential based on information related to the issuance of the received credential.
[0068] According to one embodiment of the present invention, issuing a credential may refer to an act in which the issuer, as a trusted institution, creates a verifiable digital document, i.e., a credential, for a specific individual or organization (i.e., the holder), and then provides it after guaranteeing its authenticity through an electronic signature. Meanwhile, the issuance of a credential by the aforementioned issuing unit (220) may have the same meaning as the issuance of a credential by the issuer or credential issuing system (200).
[0069] Continuing, a credential issued by the issuing unit (220) according to one embodiment of the present invention may include a decentralized ID (DID) that can query a decentralized ID document (DID document) containing information regarding the status of the credential.
[0070] Information regarding the status of a credential according to one embodiment of the present invention may refer to any type of information related to the status of the credential, including whether the credential is currently valid (or, at the time of verification) and thus usable for verification. Since the validity of a credential can change even after it has been issued, verifying the status of the credential at the time of verification ensures the validity and reliability of the identity verification process using the credential.
[0071] Meanwhile, information about the status of a conventional credential was included in a field of the credential (e.g., the "credentialStatus" field), and specifically, it was recorded in the form of an external URL containing an endpoint for checking the status of the credential in that field. The aforementioned external URL cannot be used to check the status of the credential on its own, but can function as a connection link to a status registry (e.g., a database) outside the distributed ledger network operated by the issuer. In other words, in order to check the status of a conventional credential, the issuer had to directly and continuously manage and update the status registry implemented outside the distributed ledger. This resulted in various problems, such as a loss of information about the status of the credential and the integration of the distributed ledger, or the disappearance of the method for checking the status of the credential in the event that the issuer no longer operates the status registry. Consequently, the efficiency of the issuer's credential management was significantly reduced.
[0072] Furthermore, even when the verifier wants to verify the above credentials, it must first download all of the large amount of information included in the above status registry and find the status information corresponding to the credentials to be verified among them, which has the disadvantage of low efficiency in verification by the verifier.
[0073] On the other hand, the credential issuance system (200) or credential verification system (300) according to one embodiment of the present invention can solve all of the conventional problems mentioned above by expressing the status of the credential in a manner described below.
[0074] A credential issued through a credential issuance system (200) according to one embodiment of the present invention may include a decentralized ID (DID) that can query a decentralized ID document (DID) containing information regarding the status of the credential. That is, unlike in the past, information related to the status of the credential may be included in the decentralized ID document, and the credential may include a decentralized ID that can query the corresponding decentralized ID document. That is, unlike in the past, where a large amount of information contained in a status registry had to be downloaded, in the present invention, the status of the credential can be sufficiently managed and confirmed based on only a small amount of data in the form of a decentralized ID.
[0075] A decentralized identifier (DID) according to one embodiment of the present invention is a concept that refers to a digital identifier that can be managed by an individual or organization on their own without the intervention of a centralized organization (i.e., decentralized), and may refer to an identifier that is uniquely defined without duplication throughout the entire scope of a decentralized identity management system and can be used to identify a specific subject. Generally, holders and issuers have unique decentralized IDs so that they can be distinguished from other holders and issuers. A credential according to one embodiment of the present invention may include, in addition to the decentralized ID corresponding to such holders and issuers, a decentralized ID that can retrieve a decentralized ID document containing information regarding the status of the credential, which will be described later.
[0076] A decentralized identity document (DID document) according to one embodiment of the present invention may refer to a data set containing various information describing a subject corresponding to a decentralized identity (e.g., a decentralized identity document including information regarding the status of the holder, issuer, or credential according to one embodiment of the present invention). Generally, a decentralized identity document may have a graph-based data structure expressed using JSON-LD, but is not limited thereto and may have various data structures.
[0077] Meanwhile, a decentralized ID document can be associated with a decentralized ID by a software called a DID resolver, which receives a decentralized ID as input and searches for and returns a decentralized ID document associated with the decentralized ID. The DID resolver can resolve the decentralized ID and query a distributed ledger, database, or other network associated with the DID method to obtain the corresponding decentralized ID document. That is, an issuer according to one embodiment of the present invention can implement a decentralized ID document including information regarding the status of a credential and include a decentralized ID capable of querying the decentralized ID document in the credential, and a user (or a verifier) can query the decentralized ID document including information regarding the status of the credential based on the decentralized ID through the DID resolver to confirm the status of the credential.
[0078] Continuing, information regarding the status of a credential included in a distributed ID document according to one embodiment of the present invention may include first status information and second status information.
[0079] Meanwhile, the first status information may include information related to whether the credential is active, and the second status information may include information related to the credential's inactive status.
[0080] Specifically, the first status information according to one embodiment of the present invention may indicate whether the credential is activated or deactivated. That is, unlike the second status information, which will be described later, which indicates the type or state of the deactivation, the first status information may simply include information regarding whether the credential is activated or deactivated.
[0081] According to one embodiment of the present invention, the second status information may indicate the type or nature of the inactive status of a credential, in response to the credential being inactive. Specifically, a credential may become inactive for various reasons after being validly issued, and the specific cause of the inactive status may be included in the second status information.
[0082] More specifically, the information related to the above-described inactive status may include information on which inactive status the credential is in among suspended, expired, revoked, and compromised due to security issues.
[0083] The aforementioned suspension status may refer to a state in which the use of a credential is temporarily restricted. Specifically, suspension may refer to a temporary inactivity state in which the credential is currently unusable but may be reactivated in the future. This suspension status may be set by the credential user (holder or issuer) to secure time to resolve potential issues, such as unauthorized use or data modification of the credential. For example, (1) a user may temporarily deactivate a credential after losing it from their wallet, placing it in a suspended state, or (2) a university (issuer) may temporarily suspend a credential before correcting the incorrect data on a student's transcript.
[0084] The expiration status described above may mean that the credential has reached the end of its validity period and can no longer be used. This expiration period may be determined by the expiration date set by the issuer. This expiration status may be permanent, requiring the user to replace the expired credential or obtain a new one. The expiration period of a credential may be applied to enhance security by preventing the use of outdated information and to update information that changes over time. Meanwhile, a valid credential may have a defined expiration period at the time of issuance, and the status may automatically transition to the expired state when the current date exceeds that expiration period.
[0085] The revocation status described above may refer to a state in which a credential is no longer valid by the issuing issuer. An issuer may revoke a credential if it determines that the previously issued credential is unreliable or should no longer be used for any reason. For example, a credential may be revoked if the holder has lost the credential, if the information in the credential has been altered or contains errors, or if the holder or user of the credential has violated any of the issues set by the credential, thereby requiring the credential to be deactivated. While revocation status is primarily determined by the issuer, the reasons for revoking a credential may overlap with those for the aforementioned suspension status.
[0086] The aforementioned invalidation due to security issues can primarily refer to a credential being deactivated due to security issues, such as when the private key of the credential holder or issuer has been leaked, allowing for signature forgery; when the system issuing the credential has been hacked, potentially tampering with the credential; when the credential itself has been forged or its digital signature has been invalidated; or when sensitive personal information contained in the credential has been leaked, potentially causing damage. Compared to other deactivation states, the invalidation due to security issues poses significant risks, such as the potential for forgery or tampering and the potential for privacy violations. Therefore, distinguishing this status from other deactivation states can provide richer information to those involved in the use of the credential. For example, this rich information could include information related to the credibility of the issuer of the credential, which can be calculated by aggregating information on the number or frequency of credentials invalidated due to security issues.
[0087] Meanwhile, in the second state information according to one embodiment of the present invention, one type of inactive state corresponding to a currently inactive credential may be selected and included among the types of inactive states described above.
[0088] Next, the credential issuance system (200) according to one embodiment of the present invention may further include an authority management unit (not shown).
[0089] An authority management unit (not shown) according to one embodiment of the present invention can perform a function of managing authority of a credential.
[0090] Specifically, the authority management unit (not shown) according to one embodiment of the present invention managing the authority of a credential may mean managing the authority to modify a distributed ID document containing information regarding the status of the credential described above based on a smart contract (i.e., an authority management contract). Meanwhile, the authority management unit described above manages the authority itself to modify a distributed ID document containing information regarding the status of the credential, and may be distinguished from an information modification unit that can manage or modify information regarding the status of the credential included in the distributed ID document described below.
[0091] A smart contract for the authority management of the aforementioned credentials can refer to a condition-based automatic execution program on a distributed ledger that can automatically perform specific tasks according to established rules without human intervention or additional approval.
[0092] Continuing, a permission management contract according to one embodiment of the present invention is a type of smart contract, which can perform the following functions: (1) registering different management keys for each issuer, and verifying the management key in response to an attempt to modify a decentralized ID document including information on the status of a credential to verify the authority of the subject attempting to modify it; (2) delegating or revoking the authority to modify a decentralized ID document including information on the status of a credential; (3) supporting multi-signature as needed; and (4) tracking the management history of the authority to modify a decentralized ID document including information on the status of a credential (i.e., the history of setting and / or changing the authority).
[0093] The multi-signature described above is a type of electronic signature that requires multiple signatories to jointly sign a transaction or piece of data for it to be considered valid. The multi-signature described above can enhance the security and reliability of credentials.
[0094] Meanwhile, the various functions of the above-described authority management contract can be performed by executing the authority management contract at the request of a subject with legitimate authority (e.g., an issuer).
[0095] Additionally, the "key" described above may refer to a cryptographic key used in an electronic signature and authentication system, specifically a public key and a private key used to identify whether a person has the authority to modify a distributed ID document containing information about the status of a credential.
[0096] Next, the credential issuance system (200) according to one embodiment of the present invention may further include an information modification unit (not shown).
[0097] An information modification unit (not shown) according to one embodiment of the present invention can perform a function of modifying information regarding the status of a credential included in a distributed ID document.
[0098] Modifying information regarding the status of a credential included in a distributed ID document by an information modification unit according to one embodiment of the present invention may mean modifying information regarding the status of a credential included in the above-described distributed ID based on a smart contract (i.e., a state change contract).
[0099] Continuing, a state change contract according to one embodiment of the present invention, as a type of smart contract, can fundamentally perform a function of changing the content (i.e., the status of a credential) of a distributed ID document containing information regarding the status of a credential according to one embodiment of the present invention, either automatically or through input by an entity with modification authority. The entity with modification authority described above may refer to an issuer node, but is not limited thereto and may also include any type of node.
[0100] In addition, a state change contract according to one embodiment of the present invention can be made lightweight by only allowing it to perform the function of modifying a distributed ID document containing information about the status of a credential.
[0101] Meanwhile, a state change contract according to one embodiment of the present invention may perform the following functions: (1) a function of changing the status of multiple credentials at once through batch processing, (2) a function of automatically changing the status of credentials (i.e., changing to an expired status) without external input based on information about the expiration date of the credentials, (3) a function of queuing requests for state changes in a temporary storage (queue) and processing requests all at once when a certain amount of requests are collected in the temporary storage or a specific condition is met, and (4) a function of issuing a corresponding event when a state change occurs and allowing other entities (e.g., other issuer nodes, owner nodes, or verifier nodes, etc.) to subscribe to and be notified of the event.
[0102] Meanwhile, a distributed ID document containing information regarding the status of a credential according to one embodiment of the present invention may further include metadata regarding the credential or status information. Furthermore, the metadata described above may be recorded in the distributed ID document containing information regarding the status of the credential, and may be recorded differently for each individual credential.
[0103] Meanwhile, metadata regarding status information may refer to information that provides additional descriptions or properties of the status information itself, in addition to the status information itself. For example, if the status information for a specific credential is in a revoked state and includes information such as "The holder of the credential is a minor, so the credential is in a revoked state, but in order to verify the current credential, it is necessary to reconfirm whether the holder has reached adulthood as of now," then "revocation status" may be the status information itself, and "The holder of the credential is a minor, so the credential is in a revoked state, but in order to verify the current credential, it is necessary to reconfirm whether the holder has reached adulthood as of now" may be metadata.
[0104] The above-described metadata may be added as needed by any entity authorized to modify a distributed identity document containing information about the status of the credential.
[0105] Meanwhile, in the case where the status information of a credential is managed in the form of an external URL recorded in one field of the credential as in the past, in order to check the status information of the credential, the external URL described above must be downloaded, and then the status information of the required credential must be searched for among the status information of multiple credential items included in the external URL. In this case, the metadata for the status information is applied uniformly to all status information downloaded through the external URL. However, as described above, the status information and the metadata for the status information according to one embodiment of the present invention are included in a distributed ID document including information about the status of the credential, so that only the distributed ID of the required credential is individually retrieved, and therefore, the metadata can be individually added for each credential.
[0106] Next, the first communication unit (230) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the receiving unit (210) and the issuing unit (220).
[0107] Finally, the first control unit (240) according to one embodiment of the present invention can perform a function of controlling the flow of data between the receiving unit (210), the issuing unit (220), and the first communication unit (230). That is, the first control unit (240) according to one embodiment of the present invention can control the flow of data from / to the outside of the credential issuing system (200) or the flow of data between each component of the credential issuing system (200), thereby controlling the receiving unit (210), the issuing unit (220), and the first communication unit (230) to perform their respective unique functions.
[0108] Configuration of the credential verification system
[0109] Below, the internal configuration and functions of each component of the credential verification system (300) that performs important functions for implementing the present invention will be examined.
[0110] FIG. 3 is a drawing detailing the internal configuration of a credential verification system (300) according to one embodiment of the present invention.
[0111] As illustrated in FIG. 3, a credential verification system (300) according to one embodiment of the present invention may include a validity period verification unit (310), a status information verification unit (320), a second communication unit (330), and a second control unit (340). According to one embodiment of the present invention, at least some of the validity period verification unit (310), the status information verification unit (320), the second communication unit (330), and the second control unit (340) of the credential verification system (300) may be program modules that communicate with an external system (not shown). These program modules may be included in the credential verification system (300) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known storage devices. In addition, these program modules may also be stored in a remote storage device that can communicate with the credential verification system (300). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.
[0112] Meanwhile, although the credential verification system (300) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the credential verification system (300) may be realized within a device (400) or a server (not shown) or included within an external system (not shown) as needed.
[0113] First, the validity period confirmation unit (310) according to one embodiment of the present invention can perform a function of confirming the validity period of a certificate based on the holder's certificate.
[0114] A verifier according to one embodiment of the present invention may refer to an entity that verifies the authenticity and integrity of a credential by performing verification based on the aforementioned credential. The verifier can verify the qualifications or identity of the owner (i.e., holder) of the credential in a reliable manner. Meanwhile, a verifier node according to one embodiment of the present invention may refer to a node among the plurality of nodes (500) described above that corresponds to the verifier or is owned by the verifier.
[0115] Specifically, the verifier performing verification based on the aforementioned credentials according to one embodiment of the present invention may mean that the holder node performs verification using a verifiable presentation (VP) generated based on the credentials. The aforementioned VP is a data structure used to present the credentials to the verifier, and may be generated by (1) selecting and combining one or more of the multiple claims included in a single credential, or (2) combining multiple credentials.
[0116] The validity period of a credential according to one embodiment of the present invention may refer to the period (i.e., the start or end point) during which the credential can be validly used. The validity period may include the issue date (start point) and the expiration date (end point). The validity period of a credential is typically defined by the issue date and expiration date, but may also be defined solely by the expiration date.
[0117] That is, according to one embodiment of the present invention, the verifier node checking the validity period of a credential may refer to the validity period of the credential and the current date to determine whether the validity period of the credential has expired. This validity period verification may be performed by referencing information regarding the validity period recorded in a field of the credential (e.g., issuanceDate or expirationDate) and the current date.
[0118] Next, the status information verification unit (320) according to one embodiment of the present invention can perform a function of verifying information regarding the status of a credential in response to the fact that the validity period of the holder's credential has not expired.
[0119] Specifically, the status information verification unit (320) according to one embodiment of the present invention first verifies the validity period of the above-described validity period verification unit (310) before verifying the status information, and verifies the status information only when the validity period has not expired, thereby minimizing the time or calculation required to verify the status of a credential.
[0120] That is, by taking advantage of the fact that credentials have a limited validity period by default, the status of the credential (or validity at the current point in time) can be checked first based only on the validity period and current date of the credential, thereby reducing the computational time or computational costs (e.g., fees such as gas).
[0121] Continuing, a credential verified by a credential verification system (300) according to one embodiment of the present invention or a credential whose status information is verified by a status information verification unit (320) may include a distributed ID (DID) that can search for a distributed ID document (DID document) that includes information about the status of the credential.
[0122] Continuing, information regarding the status of a credential included in a distributed ID document according to one embodiment of the present invention may include first status information and second status information.
[0123] Meanwhile, the status information confirmation unit (320) according to one embodiment of the present invention can perform a function of first confirming the first status information and then confirming the second status information in response to confirmation that the credential is inactive.
[0124] Continuing, the first status information may include information related to whether the credential is active, and the second status information may include information related to the credential's inactive status.
[0125] Specifically, information regarding the inactivity status may include information regarding whether the credential is in an inactive state among suspended, expired, revoked, and compromised due to a security issue.
[0126] The distributed ID document, which contains information about the status of the credential, the distributed ID and related details have already been described in detail, so their description is omitted to avoid excessive duplication.
[0127] Next, the credential verification system (300) according to one embodiment of the present invention may further include a verification unit (not shown).
[0128] Specifically, a verification unit (not shown) according to one embodiment of the present invention can ultimately perform a function of verifying the validity of a credential. That is, the verification unit can perform a function of verifying the object to be verified (e.g., the identity of the holder, etc.) using a credential confirmed to be valid, separately from the process of verifying the status (validity) of the credential described above (the process of retrieving a distributed ID document containing information regarding the status of the credential).
[0129] Next, the second communication unit (330) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the validity period confirmation unit (310) and the status information confirmation unit (320).
[0130] Lastly, the second control unit (340) according to one embodiment of the present invention can perform a function of controlling the flow of data between the validity period verification unit (310), the status information verification unit (320), and the second communication unit (330). That is, the second control unit (340) according to one embodiment of the present invention can control the flow of data from / to the outside of the credential verification system (300) or the flow of data between each component of the credential verification system (300), thereby controlling the validity period verification unit (310), the status information verification unit (320), and the second communication unit (330) to perform their own unique functions.
[0131] Example of the issuance and verification process
[0132] Below, we will describe examples of the process for issuing and verifying credentials according to the present invention. However, the examples described below are merely illustrative, and specific details may be modified as long as they are consistent with the purpose of the present invention.
[0133] (1) Issuing credentials and setting initial status
[0134] The issuer node can receive information related to the issuance of a credential from the holder and issue the credential based on this information. During the issuance process, the issuer node can assign a unique decentralized ID to the credential, which can be used to query a decentralized ID document containing information about the credential's status. During this process, the issuer can also register a key corresponding to the issuer's management authority over the aforementioned decentralized ID document. Furthermore, the initial status of the credential can be set to activated during the issuance process.
[0135] (2) Status management
[0136] After a credential is issued, a process for managing its status can be performed as needed. Managing the credential's status can be performed based on the aforementioned status change contract, and the authority to change the status itself can be managed based on the aforementioned permission management contract.
[0137] (3) Status check during verification phase
[0138] In response to a request for credential verification, the verifier node first checks whether the credential has expired based on the information about the validity period and the current date. If it is determined that the credential has not yet expired, the verifier node can further verify the status of the credential by retrieving a distributed ID document containing information about the status of the credential. When retrieving a distributed ID document containing information about the status of the credential, the first status information can be checked first. If the first status information is "activated," a result indicating that the credential is valid can be returned (output) and the verification process can be terminated. On the other hand, if the first status information is "deactivated," the verifier node can further check the second status information along with information indicating that the credential is invalid, additionally returning (outputting) information about the type of deactivation status of the credential, and then the verification process can be terminated. Meanwhile, additional metadata regarding the status information described above can also be checked in this step.
[0139] (4) Effect
[0140] By performing the issuance and verification of credentials through the above-described process, the status verification process of credentials can be simplified by omitting the list or service for separate status information management. In addition, the status of credentials can be expressed in detail using secondary status information, and the status information of large quantities of credentials can be easily managed using authority management contracts and status change contracts, thereby reducing the time and cost burden on the issuer. Ultimately, by managing the status of credentials on a distributed ledger, consistency and integration with the identity verification system utilizing the distributed ID system can be improved, while sufficient transparency and traceability of status changes can be secured.
[0141] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0142] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0143] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. A method of issuing credentials by an issuer node, A step of receiving information related to the issuance of the holder's credentials from the holder node, and Including a step of issuing a credential based on information related to the issuance of the received credential, The above credentials include a decentralized ID (DID) that can query a decentralized ID document (DID document) containing information about the status of the credentials. method.
2. In paragraph 1, Information about the status of the credentials included in the above distributed ID document includes first status information and second status information. method.
3. In paragraph 2, The first status information includes information related to whether the credential is active, and the second status information includes information related to the credential's inactive status. method.
4. In paragraph 3, Information related to the above inactivity status includes information on whether the credential is in an inactive state among suspended, expired, revoked, and compromised due to security issues. method.
5. In paragraph 1, The above issuer node further includes a step of managing the authority of the above credentials. method.
6. In paragraph 1, The issuer node further comprises a step of modifying information regarding the status of the credentials included in the distributed ID document. method.
7. As a method of verifying credentials by a verifier node, A step for checking the validity period of a certificate based on the holder's certificate, and Including a step of checking information about the status of the credential in response to the above validity period not having expired, The above credentials include a decentralized ID (DID) that can query a decentralized ID document (DID document) containing information about the status of the credentials. method.
8. In paragraph 7, Information about the status of the credentials included in the above distributed ID document includes first status information and second status information. method.
9. In paragraph 8, The first status information includes information related to whether the credential is active, and the second status information includes information related to the credential's inactive status. method.
10. In paragraph 9, The information related to the above inactivity status includes information about whether the above credentials are inactive among suspended, expired, revoked, and compromised due to security issues. method.
11. In paragraph 8, In the step of checking information about the status of the credential in response to the above validity period not having expired, the first status information is checked first, and in response to the credential being confirmed to be inactive, the second status information is checked. method.
12. In paragraph 7, Further comprising a verification unit that verifies the validity of the credential based on at least one of the validity period of the credential and the information about the status of the credential included in the distributed ID document. method.
13. A non-transitory computer-readable recording medium recording a computer program for executing the method according to any one of paragraphs 1 and 7.
14. As a system for issuing credentials by issuer nodes, A receiving unit that receives information related to the issuance of a holder's credentials from a holder node, and Including an issuing unit that issues a certificate based on information related to the issuance of the received certificate, The above credentials include a decentralized ID (DID) that can query a decentralized ID document (DID document) containing information about the status of the credentials. System.
15. In paragraph 14, Information about the status of the credentials included in the above distributed ID document includes first status information and second status information. System.
16. In paragraph 15, The first status information includes information related to whether the credential is active, and the second status information includes information related to the credential's inactive status. System.
17. In paragraph 16, Information related to the above inactivity status includes information on whether the credential is in an inactive state among suspended, expired, revoked, and compromised due to security issues. System.
18. In paragraph 14, The above issuer node further includes an authority management unit that manages the authority of the above credentials. System.
19. In paragraph 14, The above issuer node further includes an information modification unit that modifies information about the status of the credentials included in the distributed ID document. System.
20. As a system for verifying credentials by a verifier node, A validity period verification unit that verifies the validity period of a certificate based on the holder's certificate, and Including a status information verification unit that verifies information about the status of the certificate in response to the above validity period not having expired, The above credentials include a decentralized ID (DID) that can query a decentralized ID document (DID document) containing information about the status of the credentials. System.
21. In paragraph 20, Information about the status of the credentials included in the above distributed ID document includes first status information and second status information. System.
22. In paragraph 21, The first status information includes information related to whether the credential is active, and the second status information includes information related to the credential's inactive status. System.
23. In paragraph 22, The information related to the above inactivity status includes information about whether the above credentials are inactive among suspended, expired, revoked, and compromised due to security issues. System.
24. In paragraph 21, The above status information verification unit first verifies the first status information, and then verifies the second status information in response to the credentials being confirmed to be inactive. System.
25. In paragraph 20, Further comprising a verification unit that verifies the validity of the credential based on at least one of the validity period of the credential and the information about the status of the credential included in the distributed ID document. System.
Citation Information
Patent Citations
Device, method, and graphical user interface for managing authentication credential for user account
JP2023175817A
Powder composition for removing oil from hair
KR1020230107008A
Processing apparatus
KR1020240064527A
Wafer lapping device and controlling method thereof
KR102248009B1
Method and system for implementing contents service based on blockchain
KR102442874B1