Method and system for supporting use of did based multi-method
By identifying and transmitting a second method-specific identifier within a DID, the solution enhances the scalability and flexibility of the DID ecosystem, facilitating integration with third-party services.
Patent Information
- Application Number
- PCT/KR2025/001710
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-04
- Filing Date
- 2025-02-05
- Publication Date
- 2025-08-14
AI Technical Summary
Existing DID technologies face limitations in scalability and flexibility due to depletion of method-specific identifiers, restricting the ecosystem's growth and compatibility with third-party services.
The proposed solution involves identifying a second method and its specific identifier within a first method of a DID, transmitting this identifier to a corresponding node, and receiving a DID document to enhance scalability and flexibility, while maintaining compatibility with conventional structures.
This approach improves the scalability and flexibility of the DID ecosystem, enabling additional identification functions and easier integration with third-party services.
Smart Images

Figure KR2025001710_14082025_PF_FP_ABST
Abstract
Description
Method and system for supporting multi-method use based on DID
[0001] The present invention relates to a method and system for supporting DID-based multi-method use.
[0002] With the recent rise in interest in Self-Sovereign Identity (SSI), there has been active discussion on how to prove one's eligibility for desired services using verifiable credentials (VCs; abbreviated as "credentials" hereafter). This method essentially involves an issuer issuing a digital credential that certifies a specific entity, such as an individual or organization, as possessing a specific qualification. This credential is then held by the entity. The holder of the credential then presents this to a verifier in the form of a verifiable presentation (VP; abbreviated as "presentation" hereafter), which the verifier then verifies.
[0003] As an example of the prior art in this regard, a technology disclosed in Korean Patent Publication No. 10-2023-0143410 can be cited, which is characterized by including the steps of: analyzing the ID issuance history recorded in the decentralized ID management contract in response to a request for issuance of a 'decentralized ID' from a user to inquire whether the user has a decentralized ID already issued; issuing a new decentralized ID to the user if there is no decentralized ID already issued as a result of the inquiry; and, when the new decentralized ID delivered to the user is recorded in the user's electronic wallet, registering the issued decentralized ID in the decentralized ID storage and updating the issuance details of the decentralized ID by recording them in the ID issuance history.
[0004] A credential or presentation may include a Decentralized Identifier (DID) that identifies the subject of the credential (e.g., issuer, holder, etc.).
[0005] Figure 3 is a diagram exemplifying the structure of a conventional DID. As illustrated in Figure 3, a conventional DID (400) may be composed of a method (410) and a method-specific identifier (420), excluding the "did:" section indicating a schema. Among these, the method (410) is allocated through application and has a limited number of characters, so it is likely to be quickly depleted, like a domain name. Furthermore, if available methods are exhausted, the scalability and flexibility of the DID ecosystem may be limited.
[0006] However, the technologies introduced so far, including the above-mentioned conventional technologies, do not provide an appropriate solution to this problem.
[0007] Accordingly, the inventor(s) of the present invention propose a technology for improving the scalability and flexibility of the DID ecosystem by identifying a second method and a second method-specific identifier among first method-specific identifiers based on a first method of a DID, transmitting the second method-specific identifier to a node associated with the second method, receiving a DID document identified by the second method-specific identifier from the node associated with the second method, and providing the DID document to a provider node that provided the DID.
[0008] <Prior Art Literature>
[0009] <Patent Document>
[0010] (Patent Document 0001) Korean Patent Publication No. 10-2023-0143410 (October 12, 2023)
[0011] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0012] In addition, the present invention has another purpose of identifying a second method and a second method-specific identifier among first method-specific identifiers based on a first method of a DID, transmitting the second method-specific identifier to a node associated with the second method, receiving a DID document identified by the second method-specific identifier from the node associated with the second method, and providing the DID document to a provider node that provided the DID.
[0013] In addition, another purpose of the present invention is to improve the scalability and flexibility of the DID ecosystem.
[0014] In addition, another purpose of the present invention is to establish a flexible identification system for various subjects.
[0015] In addition, another object of the present invention is to provide additional identification functions while maintaining compatibility with conventional DID structures.
[0016] In addition, another object of the present invention is to improve the ease of connection with third-party services.
[0017] A representative configuration of the present invention to achieve the above purpose is as follows.
[0018] According to one aspect of the present invention, a method is provided, comprising: identifying a second method and a second method-specific identifier among first method-specific identifiers based on a first method of a DID; transmitting the second method-specific identifier to a node associated with the second method; and receiving a DID document identified by the second method-specific identifier from the node associated with the second method and providing the DID document to a provider node that provided the DID.
[0019] According to another aspect of the present invention, a system for supporting DID-based multi-method use is provided, comprising: an identification unit for identifying a second method and a second method-specific identifier among first method-specific identifiers based on a first method of a DID; a transmission unit for transmitting the second method-specific identifier to a node associated with the second method; and a provision unit for receiving a DID document identified by the second method-specific identifier from a node associated with the second method and providing the DID document to a provider node that provided the DID.
[0020] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0021] According to the present invention, based on the first method of the DID, a second method and a second method-specific identifier are identified among the first method-specific identifiers, the second method-specific identifier is transmitted to a node associated with the second method, a DID document identified by the second method-specific identifier is received from the node associated with the second method, and the DID document is provided to a provider node that provided the DID.
[0022] In addition, according to the present invention, the scalability and flexibility of the DID ecosystem can be improved.
[0023] In addition, according to the present invention, it is possible to build a flexible identification system for various subjects.
[0024] In addition, according to the present invention, it is possible to provide additional identification functions while maintaining compatibility with conventional DID structures.
[0025] In addition, according to the present invention, it is possible to improve the ease of linking with third-party services.
[0026] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting DID-based multi-method use according to one embodiment of the present invention.
[0027] FIG. 2 is a drawing detailing the internal configuration of a multi-method support system according to one embodiment of the present invention.
[0028] Fig. 3 is a drawing exemplarily showing the structure of a conventional DID.
[0029] FIG. 4 is a drawing exemplarily showing the structure of an extended DID according to one embodiment of the present invention.
[0030] <Explanation of symbols>
[0031] 100: Communications network
[0032] 200: Multi-method support system
[0033] 210: Identification section
[0034] 220: Transmission Department
[0035] 230: Provider
[0036] 240: Communications Department
[0037] 250: Control Unit
[0038] 300: Device
[0039] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be understood to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0040] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0041] Composition of the entire system
[0042] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting DID-based multi-method use according to one embodiment of the present invention.
[0043] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a multi-method support system (200), and a device (300).
[0044] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0045] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.
[0046] Next, a multi-method support system (200) according to one embodiment of the present invention can perform a function of identifying a second method and a second method-specific identifier among first method-specific identifiers based on a first method of a DID, transmitting the second method-specific identifier to a node associated with the second method, receiving a DID document identified by the second method-specific identifier from the node associated with the second method, and providing the DID document to a provider node that provided the DID.
[0047] The configuration and function of the multi-method support system (200) according to the present invention will be described in detail below.
[0048] Next, a device (300) according to one embodiment of the present invention is a digital device that includes a function for communicating after being connected to a multi-method support system (200), and any digital device having a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (300) according to the present invention.
[0049] In particular, the device (300) may include an application (not shown) that supports a user to receive a service according to the present invention from the multi-method support system (200). Such an application may be downloaded from the multi-method support system (200) or an external application distribution server (not shown). Meanwhile, the characteristics of such an application may be generally similar to the identification unit (210), transmission unit (220), provision unit (230), communication unit (240), and control unit (250) of the multi-method support system (200), which will be described later. Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform functions substantially identical to or equivalent thereto, as necessary.
[0050] Next, a node (not shown) according to one embodiment of the present invention is a contact point or connection point that can communicate with another node through a communication network (100), and may be a concept including a physical node such as a server, computer, laptop, smart phone, tablet PC, etc. (i.e., a digital device equipped with memory means and equipped with a microprocessor to have computational capabilities) or a logical node by an application, program module, virtual machine, etc. (i.e., a virtual node).
[0051] Specifically, according to one embodiment of the present invention, a node may be a digital wallet in itself, or may be a concept including a digital wallet. A digital wallet is a software or hardware device that allows a user to securely store and manage digital assets, authentication information, identity information, etc., and refers to a means for storing various data while allowing the stored data to be used as needed. For example, a provider node may refer to a digital wallet owned by a provider or a digital wallet running on a provider's device (300).
[0052] According to one embodiment of the present invention, these nodes may refer to each node that is interconnected to form a distributed ledger network. According to one embodiment of the present invention, these nodes may include a multi-method support system (200) in the form of program modules such as applications and widgets to support the use of credentials and / or DIDs based on distributed ledger technology (DLT). Furthermore, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).
[0053] Here, according to one embodiment of the present invention, a distributed ledger may refer to a method of storing and managing data distributedly across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledgers described above include, but are not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).
[0054] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which multiple nodes participating in the network jointly verify information to be stored on the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of private and public blockchains.
[0055] Meanwhile, according to one embodiment of the present invention, the nodes described above may be interconnected to form a distributed ledger network. This is merely an example and is not intended to be limiting. In other words, a node according to one embodiment of the present invention may refer to any type of reliable storage medium that serves as a participant in verifying and storing data and exchanging information with other nodes to maintain the integrity and consistency of the entire system.
[0056] Configuration of a multi-method support system
[0057] Below, the internal configuration and functions of each component of the multi-method support system (200) that performs important functions for implementing the present invention will be examined.
[0058] FIG. 2 is a drawing showing in detail the internal configuration of a multi-method support system (200) according to one embodiment of the present invention.
[0059] As illustrated in FIG. 2, a multi-method support system (200) according to one embodiment of the present invention may be configured to include an identification unit (210), a transmission unit (220), a provision unit (230), a communication unit (240), and a control unit (250). According to one embodiment of the present invention, at least some of the identification unit (210), the transmission unit (220), the provision unit (230), the communication unit (240), and the control unit (250) may be program modules that communicate with an external system (not shown). These program modules may be included in the multi-method support system (200) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may also be stored in a remote memory device capable of communicating with the multi-method support system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described below, according to the present invention.
[0060] Meanwhile, although the multi-method support system (200) has been described above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the multi-method support system (200) may be realized within a device (300) or a server (not shown) or included within an external system (not shown) as needed.
[0061] First, the identification unit (210) according to one embodiment of the present invention can perform a function of identifying a second method and a second method-specific identifier among the first method-specific identifiers based on the first method of the DID.
[0062] Specifically, the identification unit (210) according to one embodiment of the present invention may receive a DID from a provider node that provides the DID. According to one embodiment of the present invention, the provider node is an entity that provides a DID to prove identity or qualification, and may be a concept corresponding to an issuer, holder, or verifier in a credential ecosystem, for example.
[0063] Referring to FIG. 3, as described above, a conventional DID (400) may be composed of a method (410) and a method-specific identifier (420), excluding the "did:" portion. In the present invention, by subdividing the method-specific identifier (420) among the components of the conventional DID (400), an extended DID structure is proposed as illustrated in FIG. 4. FIG. 4 is a diagram exemplarily showing the structure of such an extended DID.
[0064] Referring to FIG. 4 together, an extended DID (500) according to one embodiment of the present invention may be composed of a first method (510), a second method (520), and a second method-specific identifier (530), excluding the "did:" portion. Optionally, the extended DID (500) may further include at least one additional identifier (540), and in this case, the identification unit (210) according to one embodiment of the present invention may further identify the at least one additional identifier (540). Among these, the second method (520) and the second method-specific identifier (530), or at least one additional identifier (540) in combination, may be referred to as a first method-specific identifier.
[0065] Comparing the conventional DID (400) and the extended DID (500), the first method (510) corresponds to the method (410) of the conventional DID (400), and the second method (520) and the second method-specific identifier (530), or in addition, at least one additional identifier (540), i.e., the first method-specific identifier may be a concept corresponding to the method-specific identifier (420) of the conventional DID (400).
[0066] The identification unit (210) according to one embodiment of the present invention can distinguish the second method (520) and the second method-specific identifier (530), or at least one additional identifier (540) from the first method-specific identifier by using a delimiter. According to one embodiment of the present invention, this delimiter may be a colon (":") as illustrated in FIG. 4, but is not limited thereto and may be variously changed within a scope that can achieve the purpose of the present invention. For example, other symbols, spaces, etc. than a colon may also correspond to the delimiter, and a specific number of characters may correspond to this delimiter.
[0067] Continuing, and more specifically, for example, an extended DID (500) according to one embodiment of the present invention may have the following form:
[0068] (i) did:hopae:ABC:4F2EA83
[0069] In (i), hopae may correspond to the first method (510), ABC may correspond to the second method (520), and 4F2EA83 may correspond to the second method specific identifier (530).
[0070] As another example, an extended DID (500) according to one embodiment of the present invention may be in the form of including the following additional identifiers:
[0071] (ii) did:hopae:ABC:4F2EA83:user123
[0072] (iii) did:hopae:ABC:4F2EA83:user123:ABCD1234
[0073] In (ii), hopae may correspond to the first method (510), ABC may correspond to the second method (520), 4F2EA83 may correspond to the second method-specific identifier (530), and user123 may correspond to the additional identifier (540). As in (iii), the additional identifiers (540) may be plural, and in (iii), user123 and ABCD1234 may correspond to the additional identifiers (540).
[0074] According to one embodiment of the present invention, among the extended DIDs (500), the second method (520) may be set by a node associated with the first method (510). Here, the node associated with the first method (510) may mean a node corresponding to a subject that defines a method for interpreting the first method-specific identifier, and may be a concept that includes at least a part of the configuration and functions of the multi-method support system (200).
[0075] For example, in (i) above, a node corresponding to a subject that has registered "hopae", which is the first method (510), in the DID system and defined a method of interpreting the first method-specific identifier may be a node associated with the first method (510). Then, a node corresponding to a subject that wishes to use "ABC" as the second method (520), i.e., a node associated with the second method (520), may request the use of "ABC" from the node associated with the first method (510), thereby setting "ABC" as the second method (520). This may correspond to a node associated with the second method (520) purchasing or renting the second method (520) from a node associated with the first method (510), similar to a domain name.
[0076] Continuing with the example, a subject who can use "ABC" as a second method (520) can request the generation of a DID to a node associated with the first method (510) based on "hopae" as the first method (510) and "ABC" as the second method (520). At this time, the subject who can use "ABC" as the second method (520) can generate "4F2EA83" as a second method-specific identifier (530) using an identifier generation module (e.g., programming code, smart contract, etc.) that it has set (or registered) (at least one additional identifier (540) can be generated as needed) and transmit it to the node associated with the first method (510). That is, according to one embodiment of the present invention, the second method-specific identifier (530) may be generated by a node associated with the second method (520). The node associated with the first method (510) receives the second method-specific identifier (530) from the node associated with the second method (520), and can ultimately generate a DID in the form of (i) above using the identifier generation module set by itself (i.e., the node associated with the first method (510)).
[0077] Continuing with the example, the identification unit (210) according to one embodiment of the present invention can receive the DID (did:hopae:ABC:4F2EA83) generated as described above from the provider node. The DID received in this way can be input into a DID resolver and interpreted through a DID interpretation module (e.g., programming code, smart contract, etc.) set by a node associated with the first method (510). The identification unit (210) according to one embodiment of the present invention can identify the second method (520), "ABC", and the second method-specific identifier (530), "4F2EA83", in the DID. That is, according to one embodiment of the present invention, the second method (520) and the second method-specific identifier (530) can be identified by the node associated with the first method.
[0078] Next, the transmission unit (220) according to one embodiment of the present invention can perform a function of transmitting a second method-specific identifier (530) to a node associated with the second method (520).
[0079] Continuing with the example described above, the transmission unit (220) according to one embodiment of the present invention can transmit "4F2EA83", which is a second method-specific identifier (530), to a node associated with the second method (520). At this time, if there is at least one additional identifier in the extended DID (500) as in (ii) or (iii) above, the at least one additional identifier can also be transmitted to the node associated with the second method (520) or the node associated with the additional identifier (which may mean a third-party system that is a subject identified by the additional identifier). According to one embodiment of the present invention, the at least one additional identifier transmitted in this way can be appropriately processed by the node associated with the second method (520) or the node associated with the additional identifier, as needed.
[0080] Next, the provision unit (230) according to one embodiment of the present invention may perform a function of receiving a DID document identified by a second method-specific identifier (530) from a node associated with a second method (520) and providing the received DID document to a provider node that provided the DID (500).
[0081] Specifically, when a second method-specific identifier (530) is transmitted to a node associated with the second method (520) as described above, a DID document corresponding to the second method-specific identifier (530) (i.e., a DID document identified by the second method-specific identifier (530)) may be returned to the provider (230) according to one embodiment of the present invention through an identifier usage module (e.g., programming code, smart contract, etc.) set by the node associated with the second method (520). Then, the provider (230) according to one embodiment of the present invention may provide the DID document thus returned (received) to the provider node that provided the DID (500).
[0082] Next, the communication unit (240) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the identification unit (210), the transmission unit (220), and the provision unit (230).
[0083] Finally, the control unit (250) according to one embodiment of the present invention can perform a function of controlling the flow of data between the identification unit (210), the transmission unit (220), the provision unit (230), and the communication unit (240). That is, the control unit (250) according to one embodiment of the present invention can control the flow of data from / to the outside of the multi-method support system (200) or the flow of data between each component of the multi-method support system (200), thereby controlling the identification unit (210), the transmission unit (220), the provision unit (230), and the communication unit (240) to perform their own functions.
[0084] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed by various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0085] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0086] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. As a method to support the use of multiple methods based on DID, A step of identifying a second method and a second method-specific identifier among the first method-specific identifiers based on the first method of the DID (Decentralized Identifier), A step of transmitting the second method-specific identifier to a node associated with the second method, and A step of receiving a DID document identified by the second method-specific identifier from a node associated with the second method, and providing the DID document to a provider node that provided the DID. method.
2. In paragraph 1, The above second method specific identifier is generated by a node associated with the second method. method.
3. In paragraph 1, The second method and the second method-specific identifier are identified by a node associated with the first method. method.
4. In paragraph 1, In the above identification step, at least one additional identifier is further identified among the first method specific identifiers, In the above transmission step, at least one additional identifier is further transmitted to a node associated with the second method or a node associated with the additional identifier. method.
5. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1.
6. As a system to support the use of multiple methods based on DID, An identification unit that identifies a second method and a second method-specific identifier among the first method-specific identifiers based on the first method of the DID (Decentralized Identifier), A transmission unit that transmits the second method-specific identifier to a node associated with the second method, and A providing unit that receives a DID document identified by the second method-specific identifier from a node associated with the second method and provides the DID document to a provider node that provided the DID. System.
7. In paragraph 6, The above second method specific identifier is generated by a node associated with the second method. System.
8. In paragraph 6, The second method and the second method-specific identifier are identified by a node associated with the first method. System.
9. In paragraph 6, The above identification unit further identifies at least one additional identifier among the first method-specific identifiers, The above transmission unit further transmits at least one additional identifier to a node associated with the second method or a node associated with the additional identifier. System.
Citation Information
Patent Citations
Artwork management method, computer, and program
JP2023143661A
Artificial disc for spinal disease
KR1020240150167A
Method for creating decentralized identity able to manage user authority and system for managing user authority using the same
KR102410006B1
Method and apparatus for automatic website login using Decentralized Identifier(DID)
KR102600516B1
Display device for rear driver notification
KR102690303B1