Method and system for verifiying verifiable presentation in offline environment
The method and system allow for reliable offline verification of proof presentations by using a verifier node with stored information, addressing the challenge of online verification requirements and enhancing privacy and efficiency.
Patent Information
- Application Number
- PCT/KR2025/099239
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-10-11
- Filing Date
- 2025-02-04
- Publication Date
- 2025-08-14
AI Technical Summary
Existing verification methods for proof presentations require a verifier to be online, making valid verification impossible in offline environments, and there is a need for a method to reliably verify proof presentations while protecting privacy and maximizing verification speed and efficiency.
A method and system for verifying proof presentations in an offline environment using a verifier node equipped with a verification information storage that performs verification without an internet connection, utilizing a receiving unit to receive and a verification unit to verify proof presentations using stored information.
Enables reliable verification of proof presentations in offline situations, maximizing verification speed and efficiency while minimizing the collection of personal information and ensuring privacy.
Smart Images

Figure KR2025099239_14082025_PF_FP_ABST
Abstract
Description
Method and system for verifying proof presentation in an offline environment
[0001] The present invention relates to a method and system for verifying a proof presentation (VP) in an offline environment.
[0002] Recently, the method of proving the qualifications required for a specific individual to receive the services he or she desires has been rapidly becoming electronic.
[0003] Proof of such qualifications is achieved by the verifier receiving the verifiable presentation (VP) presented by the holder and verifying its validity. However, all previous verification methods for VP required the verifier to be online, which had the problem of making valid verification impossible when the verifier was in an offline environment.
[0004] Accordingly, there is a strong industry demand for a method to reliably verify proof of presentation (VP) even in offline situations.
[0005] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0006] In addition, another purpose of the present invention is to provide a verification method that can reliably verify a proof presentation (VP) presented by a holder even in an offline state, thereby maximizing verification speed and verification efficiency, while protecting privacy by collecting the holder's personal information to a minimum.
[0007] According to one aspect of the present invention, a method for verifying a proof presentation (VP) in an offline environment is provided, comprising the steps of receiving a proof presentation (VP) from a holder node to a verifier node, and verifying the received proof presentation (VP) using information stored in a verification information storage included in the verifier node, wherein the receiving step and the verification step are performed while the verifier node is offline.
[0008] According to another aspect of the present invention, a proof presentation (VP) verification system in an offline environment is provided, comprising: a receiving unit that receives a proof presentation (VP) from a holder node to a verifier node; and a verification unit that verifies the received proof presentation (VP) using information stored in a verification information storage included in the verifier node, wherein the reception by the receiving unit and the verification by the verification unit are performed while the verifier node is offline.
[0009] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0010] Another object of the present invention is to provide a verification method that can reliably verify a proof of presentation (VP) presented by a holder even in an offline state, thereby maximizing verification speed and efficiency, while protecting privacy by collecting the holder's personal information to a minimum.
[0011] FIG. 1 is a diagram schematically illustrating the overall configuration of a system for verifying a proof presentation (VP) in an offline state according to one embodiment of the present invention.
[0012] FIG. 2 is a drawing detailing the internal configuration of an offline proof presentation (VP) verification system according to one embodiment of the present invention.
[0013] FIG. 3 is a diagram schematically illustrating a configuration of a blockchain network and a plurality of nodes included therein according to one embodiment of the present invention.
[0014] <Explanation of symbols>
[0015] 100: Communications network
[0016] 200: Offline Proof-of-Purpose (VP) Verification System
[0017] 210: Receiver
[0018] 220: Verification Department
[0019] 230: Communications Department
[0020] 240: Control Unit
[0021] 300: Device
[0022] 400: Multiple nodes
[0023] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0024] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0025] Composition of the entire system
[0026] FIG. 1 is a drawing schematically showing the overall configuration related to a proof presentation (VP) verification system in an offline environment (or, an offline proof presentation (VP) verification system (200)) according to one embodiment of the present invention.
[0027] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), an offline proof presentation (VP) verification system (200), and a device (300).
[0028] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0029] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part.
[0030] Next, the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention can perform communication with a device (300) to be described later via a communication network (100). In addition, the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention receives a proof presentation (VP) from a holder node to a verifier node, verifies the received proof presentation (VP) using information stored in a verification information storage included in the verifier node, and the reception by the receiving unit (210) and the verification by the verification unit (220) can perform functions that are performed while the verifier node is offline. Meanwhile, such an offline proof presentation (VP) verification system (200) may be a digital device equipped with a memory means and a microprocessor to provide computational capabilities, and may be one of a plurality of nodes (400) constituting the distributed ledger illustrated in FIG. 3, and more specifically, may include a verifier node or a holder node among the plurality of nodes (400) constituting the distributed ledger.
[0031] The configuration and function of the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention will be described in detail below.
[0032] Next, a device (300) according to one embodiment of the present invention is a digital device that includes a function for communicating after connecting to an offline proof presentation (VP) verification system (200), and any digital device having a memory means and a microprocessor and computing capability, such as a smart phone, tablet, smart watch, smart band, smart glasses, desktop computer, notebook computer, workstation, PDA, web pad, mobile phone, etc., can be adopted as the device (300) according to the present invention.
[0033] In addition, according to one embodiment of the present invention, the device (300) may further include an application program for performing a function according to the present invention. Such an application may exist in the form of a program module within the device (300). Meanwhile, the nature of such a program module may be generally similar to the receiving unit (210), the verification unit (220), the communication unit (230), and the control unit (240) of the offline proof presentation (VP) verification system (200) described below. Here, at least a part of the application may be replaced with a hardware device or firmware device that can perform functions substantially identical to or equivalent thereto, as necessary.
[0034] In addition, the device (300) according to one embodiment of the present invention may be one of a plurality of nodes (400) constituting the distributed ledger illustrated in FIG. 3, and more specifically, may be a holder node among the nodes constituting the distributed ledger, or may include a holder node.
[0035] Next, the entire system according to one embodiment of the present invention may be configured to include a communication network (100) and a plurality of nodes (400) as illustrated in FIG. 3.
[0036] Each node included in a plurality of nodes (400) according to one embodiment of the present invention is a contact point or connection point that can communicate with other nodes through a communication network (100), and may be a concept including a physical node such as a server, computer, laptop, smart phone, tablet PC, etc. (i.e., a digital device equipped with memory means and equipped with a microprocessor to have computational capabilities) or a logical node such as an application, program module, virtual machine, etc. (i.e., a virtual node).
[0037] Specifically, each node included in the plurality of nodes (400) according to one embodiment of the present invention may be a digital wallet in itself or may include a digital wallet. A digital wallet is a software or hardware device that allows a user to securely store and manage digital assets, authentication information, identity information, etc., and refers to a means for storing various data and enabling the use of the stored data as needed. For example, a holder node may refer to a digital wallet owned by a holder, and a verifier node may refer to a digital wallet owned by a verifier. The digital wallet owned by the verifier described above may include an offline proof presentation (VP) verification system according to one embodiment of the present invention.
[0038] According to one embodiment of the present invention, a holder node (not shown) and a verifier node (not shown) may correspond to each node included in a plurality of nodes (400).
[0039] Meanwhile, in accordance with one embodiment of the present invention, a plurality of nodes (400) may include an offline proof presentation (VP) verification system (200) according to the present invention in the form of a program module such as an application or widget to perform verification based on distributed ledger technology (DLT). In addition, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).
[0040] Distributed ledger technology (DLT), according to one embodiment of the present invention, may refer to a method of storing and managing data distributed across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledgers described above include, but are not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).
[0041] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which information to be stored on the network is jointly verified by a plurality of nodes (400) participating in the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of a private blockchain and a public blockchain.
[0042] Configuration of an offline proof-of-purchase (VP) verification system
[0043] Below, the internal configuration and functions of each component of the offline proof presentation (VP) verification system (200) that performs important functions for implementing the present invention will be examined.
[0044] FIG. 2 is a drawing detailing the internal configuration of an offline proof presentation (VP) verification system (200) according to one embodiment of the present invention.
[0045] As illustrated in FIG. 2, an offline proof presentation (VP) verification system (200) according to one embodiment of the present invention may include a receiving unit (210), a verification unit (220), a communication unit (230), and a control unit (240). According to one embodiment of the present invention, at least some of the receiving unit (210), the verification unit (220), the communication unit (230), and the control unit (240) of the offline proof presentation (VP) verification system (200) may be program modules that communicate with an external system (not shown). These program modules may be included in the offline proof presentation (VP) verification system (200) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may also be stored in a remote memory device capable of communicating with the offline proof presentation (VP) verification system (200). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.
[0046] Meanwhile, although the offline proof presentation (VP) verification system (200) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the offline proof presentation (VP) verification system (200) may be realized within a device (300) or a server (not shown) or included within an external system (not shown) as needed.
[0047] First, according to one embodiment of the present invention, the receiving unit (210) can perform a function of receiving a proof presentation (VP) from a holder node to a verifier node.
[0048] A verifiable presentation (VP) according to one embodiment of the present invention is a data structure used to present a verifiable credential (VC) to a verifier, and may be generated by (1) selecting and combining one or more of a plurality of claims (i.e., items to be proven) included in a single credential (VC), or (2) combining a plurality of credentials (VCs). Accordingly, when a credential (VC) is converted into the form of a proof presentation (VP) and submitted to a verifier, the holder can present only the desired data (or claim) or the data (or claim) required for verification for verification, and the verifier can use only the desired data (or claim) for verification by specifying the data (or claim) required for verification.
[0049] According to one embodiment of the present invention, a verifier may refer to an entity that verifies the authenticity and integrity of a credential (VC) by verifying the aforementioned credentials. The verifier can verify the credentials or identity of the owner (i.e., holder) of the credential (VC) in a reliable manner.
[0050] A verifier node according to one embodiment of the present invention may mean one of the plurality of nodes (400) described above, a node corresponding to a verifier, or a node owned by a verifier, and may mean the offline proof presentation (VP) verification system (200) itself according to one embodiment of the present invention, or may mean a part (or a part of a sub-component) included in the offline proof presentation (VP) verification system (200).
[0051] A proof presentation (VP) according to one embodiment of the present invention may include a decentralized identity (DID) of the submitter as an identifier for the submitter. Typically, the holder of a credential (VC) and the submitter of a proof presentation (VP) may be the same person. Therefore, the proof presentation (VP) may include both (1) a decentralized ID for identifying the holder, the entity to whom the credential (VC) was issued, and (2) a decentralized ID (i.e., the holder's decentralized ID) for identifying the submitter of the proof presentation (VP) generated using the credential (VC).
[0052] According to one embodiment of the present invention, a "holder" may refer to an entity possessing a certificate of authenticity (VC). The holder receives, stores, and manages various identification information or certificates (VCs) issued by an issuer. As needed, the holder may present the VCs to a verifier in the form of a proof presentation (VP) to request verification.
[0053] According to one embodiment of the present invention, a credential (VC) encompasses all verifiable and trustworthy credentials issued in digital format. A credential (VC) contains information about an individual or organization's specific qualifications, identity, academic background, career history, etc., and its reliability can be guaranteed through various verifiable methods. As described above, the VC can be issued, stored, and verified through distributed ledger (or blockchain) technology. Meanwhile, a credential (VC) is a data structure representing a digital credential and may include multiple sub-elements (i.e., claims) to ensure the authenticity and integrity of the VC.
[0054] A verifiable credential (VC) according to one embodiment of the present invention may be issued by an issuer (or issuer node). An issuer node (not shown) according to one embodiment of the present invention may correspond to each node included in a plurality of nodes (400), such as the holder node (not shown) and verifier node (not shown) described above. Alternatively, an issuer (or issuer node) according to one embodiment of the present invention may be, or may be included in, the credential (VC) issuance system illustrated in FIG. 1.
[0055] Meanwhile, as illustrated in FIG. 1, an issuer node or a credential (VC) issuing system including the issuer node may also be (non-essentially) included in the overall system for verifying a proof presentation (VP) in an offline state, together with a communication network (100), an offline proof presentation (VP) verification system (200), and a device (300).
[0056] A credential (VC) issued according to one embodiment of the present invention may include a decentralized identity (DID) of the holder and the issuer as identifiers for the holder and the issuer, respectively.
[0057] Meanwhile, a proof presentation (VP) according to one embodiment of the present invention can be generated from a holder's credential (VC). Specifically, the holder possesses a credential (VC) issued by a trusted issuer and can present it to a verifier to verify a desired item. In this case, instead of presenting the credential (VC) itself, the holder can generate a proof presentation (VP) from the credential (VC) and provide it to the verifier to selectively verify various items included in the VC. By providing the proof presentation (VP) to the verifier, the holder can provide only the specific information desired to the verifier.
[0058] An offline proof presentation (VP) verification system (200) according to one embodiment of the present invention may include a verification information storage described below together with a verifier node.
[0059] An offline or offline state (environment) according to one embodiment of the present invention may refer to a state in which a device or system (e.g., a holder node, an offline proof presentation (VP) verification system, and a verifier node according to one embodiment of the present invention) operates independently without external connection. Specifically, an offline or offline state (environment) according to one embodiment of the present invention may refer to a state in which a device or system is not connected to the Internet or a network.
[0060] It should be understood that an offline environment according to one embodiment of the present invention includes any environment in which an offline proof presentation (VP) verification system (200) including a verifier node is in an offline environment and verification of a proof presentation (VP) is performed offline.
[0061] However, verifying a proof presentation (VP) in an offline environment according to one embodiment of the present invention may also include verifying the proof presentation (VP) in an environment where the holder node is in the offline environment together with the offline proof presentation (VP) verification system (200).
[0062] For example, in an environment without Internet connection, a situation may be assumed in which a holder requests a proof by providing a proof presentation (VP) to a verifier. The holder may generate a proof presentation (VP) from his / her own credential (VC) stored in a physical device (e.g., device (300)) and request a proof from the verifier using a technology that enables offline communication without an Internet connection, such as Bluetooth, NFC (near field communication), Wi-Fi Direct, Zigbee, LoRa (long range), and UWB (ultra-wideband) (all of the above examples may be included in the communication network (100)). On the other hand, the verifier must obtain verification information to verify the received proof presentation (VP). Generally, such verification information must be obtained by accessing a distributed ledger (e.g., blockchain, etc.) online. Therefore, a situation arises in which verification is impossible in an offline environment as described above. However, since the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention is equipped with a means for accessing reliable verification information even in an offline environment (i.e., a verification information storage described below), the proof presentation (VP) can be validly verified even in a situation such as the example described above.
[0063] Continuing, according to one embodiment of the present invention, the verification unit (220) may perform a function of verifying the received proof presentation (VP) using information stored in a verification information storage included in the verifier node.
[0064] The verification information according to one embodiment of the present invention should be understood as a concept encompassing all information necessary to verify a proof presentation (VP) received by the receiving unit (210). Specifically, the verification information according to one embodiment of the present invention may include first verification information and second verification information, which will be described in detail later.
[0065] The verification information repository according to one embodiment of the present invention is a concept that includes all types of means for storing collected verification information, and may refer to a physical or logical space for storing and managing verification information. Meanwhile, the verification information repository can provide verification information to the verifier node even when the verifier node is in an offline environment. For example, since the offline proof presentation (VP) verification system (200) is a device including a verification node, the verification information repository may be a physical storage connected to the device including the aforementioned verification node. The aforementioned physical storage includes, but is not limited to, a hard disk drive, a solid-state drive (SSD), an external hard drive, an optical disk, a USB flash drive, and the like.
[0066] Meanwhile, the verification information storage according to one embodiment of the present invention may be a storage with hardware-based security functions. The verification information storage according to one embodiment of the present invention can prevent the leakage of stored verification information by utilizing a hardware-based security mechanism with stronger security capabilities than software security. Specifically, the above-described security functions may be implemented through, but are not limited to, a hardware security module (HSM) or a secure element (SE).
[0067] A hardware security module (HSM) according to one embodiment of the present invention is a dedicated hardware device that protects and manages important data such as encryption keys, and means a device that provides physical security by using various physical security mechanisms and strong authentication mechanisms.
[0068] A secure element (SE) according to one embodiment of the present invention is an independent security chip or security module capable of safely storing and processing highly sensitive data, and is mainly a means that can be embedded in various devices such as smartphones, credit cards, and IoT devices to protect sensitive data such as encryption keys, payment information, and biometric authentication data.
[0069] According to one embodiment of the present invention, a verification information repository may be constructed temporally earlier than the time of verifying the VP. Specifically, the verification information repository is initially constructed by collecting verification information when in an online environment, and after the construction, when the environment of an offline VP verification system (200) including the verification information repository changes to offline (for example, when the Internet environment becomes unstable and the Internet connection is disconnected, or when the offline VP verification system (200) is moved to a location without Internet connection, etc.), the situation of verifying the VP in the offline environment may correspond to a case where the verification information repository described above is constructed temporally earlier than the time of verifying the VP.
[0070] However, the above-described situation is only one example, and the time point of construction of the verification information storage is not limited by the above-described example, and it should be understood that anything is possible as long as the time point at which the verification information storage is first collected is before the time point at which the proof presentation (VP) is verified.
[0071] A verification information repository according to one embodiment of the present invention can collect verification information from various sources. Examples of the aforementioned sources include, but are not limited to, issuer nodes, distributed ledgers (blockchain networks), web servers, and cloud computing. Verification information can be collected from various sources as needed.
[0072] Meanwhile, the collection of verification information by the verification information repository may be performed (1) according to a set cycle (such as a fixed cycle or a cycle that changes as set in advance), and (2) may be performed in response to the offline proof presentation (VP) verification system (200) including the verification information repository becoming an online environment, as described below. In the case of (2) described above, this includes cases where collection is performed once in response to becoming an online environment, or cases where collection is performed in response to becoming an online environment according to a set cycle (such as a fixed cycle or a cycle that changes as set in advance). However, the above-described contents are all merely examples of methods for collecting verification information by the verification information repository, and it is obvious to those skilled in the art that any collection method can be used as long as it is consistent with the purpose of the present invention.
[0073] According to one embodiment of the present invention, verifying a proof presentation (VP) may refer to a process of confirming that the VP and the credential (VC) are authentic (i.e., authentic), unaltered (i.e., integrity), and issued and presented by a trustworthy entity. This verification process may be performed by verifying, through the public key of the holder included in the proof presentation (VP), that the VP was actually presented by the holder of the corresponding proof, and verifying, through the public key of the issuer, that the credential (VC) was issued by a trustworthy issuer and unaltered.
[0074] Specifically, since the verification unit (220) according to one embodiment of the present invention can verify the authenticity and integrity of a proof presentation (VP) using the issuer's DID document and the holder's DID document recorded in the information collected and stored in the verification information storage described above, there is no need to access a distributed ledger to perform verification (i.e., there is no need for an online environment), and verification can be performed immediately in response to a verification request for a proof presentation (VP) even if the verifier node is in an offline environment.
[0075] Continuing, according to one embodiment of the present invention, a verification information repository may be constructed by at least one of collecting verification information and updating the verification information in response to a verifier node being online.
[0076] An online state (environment) according to one embodiment of the present invention may refer to a state in which a device or system (e.g., an offline proof presentation (VP) verification system (200) according to one embodiment of the present invention, a verifier node, etc.) is connected to the Internet or an external network. Furthermore, an online state (environment) according to one embodiment of the present invention may be defined as a state other than the aforementioned offline state (environment).
[0077] According to one embodiment of the present invention, what is meant by constructing a verification information repository through at least one of collecting verification information and updating verification information in response to a verifier node being online may mean (1) constructing an initial verification information repository through collecting verification information online, and additionally collecting new verification information along with updates of changes in response to a verification node being offline and then back online, or (2) constructing an initial verification information repository through collecting verification information online, and checking only changes in already collected verification information and only updating the changes whenever a verification node is offline and then back online.
[0078] Accordingly, a verification information storage according to one embodiment of the present invention can be constructed by collecting verification information in response to a verifier node being online, and after construction, can be managed in a manner of updating only changed information in response to a change in the verification information.
[0079] Verification information according to one embodiment of the present invention may include first verification information and second verification information.
[0080] The first verification information according to one embodiment of the present invention may refer to information directly necessary for verifying a received proof presentation (VP). Specifically, the first verification information may include identification information and encryption information of the holder. More specifically, in response to a situation where the holder's identifier is encrypted via asymmetric encryption and the public key is stored in a distributed ledger, the first verification information may include the holder's (or, additionally, the issuer's) public key, a decentralized identity (DID), and a DID document (including the decentralized ID) registered in the distributed ledger.
[0081] According to one embodiment of the present invention, the second verification information may indicate whether the credential (VC) used to generate the received proof presentation (VP) has been revoked (or its revocation status). A revoked credential (VC) means that it was initially issued validly but has since become invalid. Accordingly, a revoked VC may also mean that the proof presentation (VP) generated from it is invalid.
[0082] The revocation of the aforementioned VC can be declared by the issuer that issued the VC. For example, if a specific person's driver's license was issued as a VC and then became invalid or revoked due to expiration or illegal activity, the issuer that issued the VC can revoke (or declare the revocation) the driver's license.
[0083] Continuing, an offline proof presentation (VP) verification system (200) according to an embodiment of the present invention can perform verification by accessing a verification information storage to obtain first verification information of the corresponding proof presentation (VP) to verify an electronic signature, and further obtaining second verification information to refer to whether the corresponding proof presentation (VP) has been revoked, in order to verify a received proof presentation (VP). Accordingly, in response to the fact that the electronic signature of the received proof presentation (VP) is verified to be valid and not revoked, a conclusion can be drawn that the corresponding proof presentation (VP) is trustworthy (i.e., verification is completed).
[0084] Updating verification information according to one embodiment of the present invention may be performed only for second verification information.
[0085] Specifically, the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention may further include a second verification information monitoring unit (not shown) that only monitors whether the second verification information described above has changed. Specifically, the second verification information monitoring unit (not shown) may perform a function of monitoring whether the second verification information has changed in response to the offline proof presentation (VP) verification system (200) becoming a state in which the most recent revocation status can be confirmed (e.g., the offline proof presentation (VP) verification system (200) is online), and updating the corresponding information whenever a change occurs.
[0086] According to one embodiment of the present invention, a verification information repository collects and stores only enough verification information to effectively verify a proof presentation (VP), and does not collect any additional, unnecessary information. Therefore, by not collecting additional, unnecessary information beyond verification information, the privacy of the holder can be protected.
[0087] The scope of collection of verification information (i.e., the type of verification information to be collected) by the verification information storage described above can be specified in advance by the verifier or the user (administrator) of the verification node, and this collection scope can be changed as needed.
[0088] Specifically, a verification information storage according to one embodiment of the present invention can be constructed by collecting first verification information and second verification information at the time of construction in the initial construction stage, and can be managed in a manner that only the second verification information is updated after construction is completed.
[0089] Continuing, the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention may further include a re-verification unit (not shown).
[0090] A re-verification unit (not shown) according to one embodiment of the present invention can store a proof presentation (VP) verified in an offline state and perform a function of re-verifying the stored verified proof presentation (VP) in response to the verifier node becoming online.
[0091] Continuing, even if a proof presentation (VP) is verified as valid through an offline proof presentation (VP) verification system (200) according to one embodiment of the present invention, there may be a situation where an error occurs in verifying an invalid proof presentation (VP) as valid because the credential (VC) that generated the proof presentation (VP) is revoked immediately after verification and the revocation status is not updated. However, the offline proof presentation (VP) verification system (200) of the present invention does not immediately delete the proof presentation (VP) even if it has been verified, but stores it, and then, when it becomes online and the latest revocation status information becomes accessible, re-verifies the stored proof presentation (VP) based on the latest revocation status information, thereby preventing (or quickly responding to) the occurrence of the above-described error and increasing the reliability of the verification result.
[0092] The above-described verified proof presentation (VP) can be stored in an offline proof presentation (VP) verification system (200) or a storage included therein (a verification information storage or a separate storage).
[0093] Continuing, the offline proof presentation (VP) verification system (200) according to one embodiment of the present invention may further include a warning unit (not shown) that modifies the verification result in response to a change in whether the proof presentation (VP) has been re-verified by the re-verification unit (not shown) described above (i.e., it was valid at the time of verification, but was confirmed to be revoked as a result of re-verification), and notifies a user (e.g., at least one of the issuer, holder, and verifier) of the fact.
[0094] Next, the communication unit (230) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the receiving unit (210) and the verification unit (220).
[0095] Finally, the control unit (240) according to one embodiment of the present invention can perform a function of controlling the flow of data between the receiving unit (210), the verification unit (220), and the communication unit (230). That is, the control unit (240) according to one embodiment of the present invention can control the flow of data from / to the outside of the offline proof presentation (VP) verification system (200) or the flow of data between each component of the offline proof presentation (VP) verification system (200), thereby controlling the receiving unit (210), the verification unit (220), and the communication unit (230) to perform their own functions.
[0096] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0097] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0098] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. As a proof presentation (VP) verification method in an offline environment, A step of receiving a proof presentation (VP) from a holder node to a verifier node, and A step of verifying the received proof presentation (VP) using information stored in a verification information storage included in the verifier node, The above receiving step and the above verification step are performed while the verifier node is offline. method.
2. In paragraph 1, The above verification information storage is constructed by at least one of collecting verification information and updating verification information in response to the verifier node being online. method.
3. In the second paragraph, the verification information storage is constructed in advance of verifying the proof presentation (VP). method.
4. In paragraph 1, The above verification information storage is constructed by collecting verification information in response to the verifier node being online, and the constructed verification information storage is updated only with changed information in response to changes in the verification information. method.
5. In either paragraph 2 or paragraph 4, The above verification information includes first verification information and second verification information. method.
6. In paragraph 5, Updating the above verification information is only performed for the second verification information. method.
7. In paragraph 1, Further comprising a step of storing the verified proof presentation (VP) in the offline state and re-verifying the stored verified proof presentation (VP) in response to the verifier node becoming online. method.
8. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1.
9. As a proof presentation (VP) verification system in an offline environment, A receiving unit that receives a proof presentation (VP) from a holder node to a verifier node, and Includes a verification unit that verifies the received proof presentation (VP) using information stored in a verification information storage included in the verifier node, Reception by the above receiver and verification by the above verification unit are performed while the verifier node is offline. System.
10. In paragraph 9, The above verification information storage is constructed by at least one of collecting verification information and updating verification information in response to the verifier node being online. System.
11. In the 10th paragraph, the verification information storage is constructed in advance in time compared to verifying the proof presentation (VP). System.
12. In paragraph 9, The above verification information storage is constructed by collecting verification information in response to the verifier node being online, and the constructed verification information storage is updated only with changed information in response to changes in the verification information. System.
13. In either of paragraphs 10 or 12, The above verification information includes first verification information and second verification information. System.
14. In paragraph 13, Updating the above verification information is only performed for the second verification information. System.
15. In paragraph 9, It further includes a re-verification unit that stores the verified proof presentation (VP) in the offline state and re-verifies the stored verified proof presentation (VP) in response to the verifier node becoming online. System.
Citation Information
Patent Citations
Device, method, and graphical user interface for managing authentication credential for user account
JP2023175817A
Powder composition for removing oil from hair
KR1020230107008A
Processing apparatus
KR1020240064527A
Wafer lapping device and controlling method thereof
KR102248009B1
KR20210105068A