Method and system for assisting issuance of verifiable credential
The system facilitates efficient issuance of new VCs by allowing holders to request and automatically issue new credentials using existing ones, streamlining the process and reducing time and effort.
Patent Information
- Application Number
- PCT/KR2025/099244
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-01-31
- Filing Date
- 2025-02-04
- Publication Date
- 2025-08-14
AI Technical Summary
Existing methods for obtaining verifiable credentials (VCs) are cumbersome and time-consuming, requiring holders to directly obtain credentials from issuers when needed by verifiers, without leveraging existing credentials they already possess.
A system and method that allows holders to request new VCs based on existing VCs, determining automatic issuance and providing necessary information to issuers and verifiers for verification, using a request receiving unit, automatic issuance determination unit, and response unit to streamline the process.
Enables convenient and efficient issuance of new VCs by automating the process based on existing credentials, reducing time and effort for holders.
Smart Images

Figure KR2025099244_14082025_PF_FP_ABST
Abstract
Description
Method and system for supporting the issuance of verifiable credentials
[0001] The present invention relates to a method and system for supporting the issuance of verifiable credentials.
[0002] With the recent rise in interest in Self-Sovereign Identity (SSI), there has been active discussion on how to prove one's eligibility for desired services using verifiable credentials (VCs; abbreviated as "credentials" hereafter). This method essentially involves an issuer issuing a digital credential that certifies a specific entity, such as an individual or organization, as possessing a specific qualification. This credential is then held by the entity. The holder of the credential then presents this to a verifier in the form of a verifiable presentation (VP; abbreviated as "presentation" hereafter), which the verifier then verifies.
[0003] As an example of the prior art in this regard, a technology disclosed in Korean Patent Publication No. 10-2023-0143410 can be cited, which is characterized by including the steps of: analyzing the ID issuance history recorded in the decentralized ID management contract in response to a request for issuance of a 'decentralized ID' from a user to inquire whether the user has a decentralized ID already issued; issuing a new decentralized ID to the user if there is no decentralized ID already issued as a result of the inquiry; and, when the new decentralized ID delivered to the user is recorded in the user's electronic wallet, registering the issued decentralized ID in the decentralized ID storage and updating the issuance details of the decentralized ID by recording them in the ID issuance history.
[0004] If the holder does not possess the credentials requested by the verifier, the holder must obtain the credentials directly from the issuer and present them to the verifier. This process is not only quite cumbersome but also time-consuming.
[0005] Accordingly, the inventor(s) of the present invention propose a technology that supports a holder to conveniently receive a new VC by receiving a request from a holder node for information regarding the issuance of a new VC that the holder node does not hold, determining whether or not to automatically issue the new VC based on information regarding at least one existing VC held by the holder node, and responding to the holder's request based on the result of the determination.
[0006] <Prior Art Literature>
[0007] Patent Document
[0008] (Patent Document 0001) Korean Patent Publication No. 10-2023-0143410 (October 12, 2023)
[0009] The purpose of the present invention is to solve all of the problems of the above-mentioned prior art.
[0010] In addition, the present invention has another purpose of receiving a request from a holder node for information regarding the issuance of a new VC that the holder node does not hold, determining whether to automatically issue the new VC based on information regarding at least one existing VC held by the holder node, and responding to the holder's request based on the result of the determination.
[0011] In addition, the present invention requests provision of information regarding the issuance of a new VC not held based on information regarding at least one existing VC held, and in response to receiving information for automatically issuing a new VC using the at least one existing VC, provides information regarding the at least one existing VC to an issuer node, and provides information regarding the new VC issued from the issuer node to a verifier node to have the new VC verified.
[0012] In addition, another purpose of the present invention is to support holders to conveniently obtain a new VC.
[0013] A representative configuration of the present invention to achieve the above purpose is as follows.
[0014] According to one aspect of the present invention, a method is provided, comprising: a step of receiving a request from a holder node for providing information regarding the issuance of a new VC not held by the holder node; a step of determining whether or not to automatically issue the new VC based on information regarding at least one existing VC held by the holder node; and a step of responding to the request based on a result of the determination.
[0015] According to another aspect of the present invention, a method is provided, comprising: a step of requesting provision of information regarding the issuance of a new VC not held based on information regarding at least one existing VC held; a step of providing information regarding the at least one existing VC to an issuer node in response to receiving information for automatically issuing the new VC using the at least one existing VC; and a step of providing information regarding the new VC issued from the issuer node to a verifier node to verify the new VC.
[0016] According to another aspect of the present invention, a system is provided, including a request receiving unit that receives a request from a holder node to provide information regarding the issuance of a new VC not held by the holder node, an automatic issuance determining unit that determines whether or not to automatically issue the new VC based on information regarding at least one existing VC held by the holder node, and a response unit that responds to the request based on the result of the determination.
[0017] According to another aspect of the present invention, a system is provided, including an information request unit that requests provision of information regarding the issuance of a new VC that is not held based on information regarding at least one existing VC held, and an information provision unit that, in response to receiving information for automatically issuing the new VC using the at least one existing VC, provides information regarding the at least one existing VC to an issuer node, and provides information regarding the new VC issued from the issuer node to a verifier node to have the new VC verified.
[0018] In addition, a non-transitory computer-readable recording medium recording another method for implementing the present invention, another system, and a computer program for executing the method are further provided.
[0019] According to the present invention, a request is made from a holder node to provide information regarding the issuance of a new VC that the holder node does not hold, and a decision is made as to whether or not to automatically issue the new VC based on information regarding at least one existing VC held by the holder node, and a response is made to the holder's request based on the result of the decision.
[0020] In addition, according to the present invention, in response to requesting provision of information regarding the issuance of a new VC not held based on information regarding at least one existing VC held, and receiving information for automatically issuing a new VC using the at least one existing VC, information regarding the at least one existing VC is provided to an issuer node, and information regarding a new VC issued from the issuer node is provided to a verifier node, so that the new VC can be verified.
[0021] In addition, according to the present invention, the holder can conveniently receive a new VC.
[0022] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the issuance of verifiable credentials according to one embodiment of the present invention.
[0023] FIG. 2 is a drawing showing in detail the internal configuration of an issuance support system according to one embodiment of the present invention.
[0024] FIG. 3 is a drawing detailing the internal configuration of a holder-side system according to one embodiment of the present invention.
[0025] <Explanation of symbols>
[0026] 100: Communications network
[0027] 200: Verifier side system
[0028] 300: Holder-side system
[0029] 310: Information Request Department
[0030] 320: Information Department
[0031] 330: Communications Department
[0032] 340: Control Unit
[0033] 400: Issuer's system
[0034] 500: Device
[0035] 600: Issuance Support System
[0036] 610: Request receiving unit
[0037] 620: Automatic Issuance Decision Department
[0038] 630: Response
[0039] 640: Communications Department
[0040] 650: Control Unit
[0041] The following detailed description of the present invention refers to the accompanying drawings, which illustrate specific embodiments in which the present invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present invention. It should be understood that the various embodiments of the present invention, while different from each other, are not necessarily mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified and implemented from one embodiment to another without departing from the spirit and scope of the present invention. Furthermore, it should be understood that the positions or arrangements of individual components within each embodiment may also be modified without departing from the spirit and scope of the present invention. Accordingly, the following detailed description is not to be taken in a limiting sense, and the scope of the present invention is to be construed to encompass the scope of the claims and all equivalents thereof. Like reference numerals in the drawings represent the same or similar elements throughout the several aspects.
[0042] Hereinafter, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings so that a person having ordinary skill in the art to which the present invention pertains can easily practice the present invention.
[0043] Composition of the entire system
[0044] FIG. 1 is a diagram schematically illustrating the configuration of an entire system for supporting the issuance of verifiable credentials according to one embodiment of the present invention.
[0045] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a verifier-side system (200), a holder-side system (300), an issuer-side system (400), a device (500), and an issuance support system (600).
[0046] First, the communication network (100) according to one embodiment of the present invention can be configured regardless of the communication mode such as wired communication or wireless communication, and can be configured with various communication networks such as a local area network (LAN), a metropolitan area network (MAN), and a wide area network (WAN). Preferably, the communication network (100) referred to herein may be the well-known Internet or the World Wide Web (WWW). However, the communication network (100) is not necessarily limited thereto, and may include at least a portion of a well-known wired or wireless data communication network, a well-known telephone network, or a well-known wired or wireless television communication network.
[0047] For example, the communication network (100) may be a wireless data communication network that implements conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., at least in part. As another example, the communication network (100) may be an optical communication network that implements conventional communication methods such as LiFi (Light Fidelity), etc., at least in part.
[0048] Next, a node (not shown) according to one embodiment of the present invention, for example, an issuer node, a holder node, a verifier node, etc., is a contact point or connection point that can communicate with other nodes through a communication network (100), and may be a concept including a physical node such as a server, a computer, a laptop, a smart phone, a tablet PC, etc. (i.e., a digital device equipped with a memory means and equipped with a microprocessor to have computational capabilities), or a logical node by an application, a program module, a virtual machine, etc. (i.e., a virtual node).
[0049] Specifically, according to one embodiment of the present invention, a node may be a digital wallet in itself, or may be a concept that includes a digital wallet. A digital wallet is a software or hardware device that allows users to securely store and manage digital assets, authentication information, identity information, etc., and refers to a means for storing various data while enabling the use of the stored data as needed. For example, an issuer node, a holder node, and a verifier node may refer to digital wallets owned by an issuer, holder, and verifier, respectively, or digital wallets running on the devices of an issuer, holder, and verifier.
[0050] According to one embodiment of the present invention, these nodes may refer to each node that is interconnected to form a distributed ledger network. According to one embodiment of the present invention, these nodes may include a verifier system (200), a holder system (300), and / or an issuer system (400), which will be described later, in the form of program modules such as applications and widgets to support the use of credentials based on distributed ledger technology (DLT). Furthermore, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown).
[0051] Here, according to one embodiment of the present invention, a distributed ledger may refer to a method of storing and managing data distributedly across multiple nodes without centralized authority, while maintaining data integrity and security. Specifically, the distributed ledger described above includes, but is not limited to, blockchain, tangle, hashgraph, and directed acyclic graph (DAG).
[0052] Specifically, the distributed ledger according to one embodiment of the present invention may be a blockchain (or blockchain network). The blockchain network described above may be a network in which multiple nodes participating in the network jointly verify information to be stored on the network, and the verified information is recorded and shared on the network, thereby ensuring the integrity and reliability of the recorded information without relying on an authorized third party. For example, according to one embodiment of the present invention, such a blockchain network may be a network that has at least some characteristics similar to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of private and public blockchains.
[0053] Meanwhile, according to one embodiment of the present invention, the nodes described above may be interconnected to form a distributed ledger network. This is merely an example and is not intended to be limiting. In other words, a node according to one embodiment of the present invention may refer to any type of reliable storage medium that serves as a participant in verifying and storing data and exchanging information with other nodes to maintain the integrity and consistency of the entire system.
[0054] Next, the verifier system (200) according to one embodiment of the present invention can perform a function of verifying the credential based on information regarding the credential provided from the holder node.
[0055] According to one embodiment of the present invention, the verifier side system (200) may mean a system including a verifier node or included in a verifier node, or may mean the verifier node itself.
[0056] Next, the holder-side system (300) according to one embodiment of the present invention may perform a function of requesting provision of information regarding the issuance of a new VC not held based on information regarding at least one existing VC held, and, in response to receiving information for automatically issuing a new VC using the at least one existing VC, providing information regarding the at least one existing VC to an issuer node and providing information regarding the new VC issued from the issuer node to a verifier node to have the new VC verified.
[0057] According to one embodiment of the present invention, the holder-side system (300) may mean a system including a holder node or included in a holder node, or may mean the holder node itself.
[0058] The configuration and function of the holder-side system (300) according to the present invention will be described in detail below.
[0059] Next, the issuer system (400) according to one embodiment of the present invention can perform the function of generating credentials and issuing them to holder nodes. Typically, an issuer is a trusted institution or organization with the authority to verify information about an individual or organization and issue credentials proving such information. Examples of such issuers include, but are not limited to, various institutions such as universities, government agencies, financial institutions, and employers.
[0060] According to one embodiment of the present invention, the issuer-side system (400) may mean a system including or included in an issuer node, or may mean the issuer node itself.
[0061] Next, the issuance support system (600) according to one embodiment of the present invention may receive a request from a holder node for information regarding the issuance of a new VC that the holder node does not hold, determine whether to automatically issue the new VC based on information regarding at least one existing VC held by the holder node, and perform a function of responding to the holder's request based on the result of the determination.
[0062] The configuration and function of the issuance support system (600) according to the present invention will be described in detail below.
[0063] Next, a device (500) according to one embodiment of the present invention is a digital device that includes a function for communicating after connecting to a verifier-side system (200), a holder-side system (300), an issuer-side system (400), and / or an issuance support system (600). Any digital device having a memory means, a microprocessor, and a computing capability, such as a smart phone, a tablet, a smart watch, a smart band, smart glasses, a desktop computer, a notebook computer, a workstation, a PDA, a web pad, a mobile phone, etc., can be adopted as the device (500) according to the present invention.
[0064] In particular, the device (500) may include an application (not shown) that supports a user to receive a service according to the present invention from a verifier-side system (200), a holder-side system (300), an issuer-side system (400), and / or an issuance support system (600). Such an application may be downloaded from the verifier-side system (200), the holder-side system (300), the issuer-side system (400), the issuance support system (600), and / or an external application distribution server (not shown). Meanwhile, the nature of such an application may be generally similar to the request receiving unit (610), the automatic issuance determining unit (620), the response unit (630), the communication unit (640), and the control unit (650) of the issuance support system (600), which will be described later, and the information requesting unit (310), the information providing unit (320), the communication unit (330), and the control unit (340) of the holder-side system (300). Here, the application may be replaced by a hardware device or firmware device that can perform substantially the same or equivalent functions as required, at least in part.
[0065] According to one embodiment of the present invention, such a device (500) may mean one of a plurality of nodes (e.g., issuer node, holder node, verifier node, etc.) that are interconnected to form a distributed ledger network.
[0066] Composition of the issuance support system
[0067] Below, the internal configuration and functions of each component of the issuance support system (600) that performs important functions for implementing the present invention will be examined.
[0068] FIG. 2 is a drawing showing in detail the internal configuration of an issuance support system (600) according to one embodiment of the present invention.
[0069] As illustrated in FIG. 2, the issuance support system (600) according to one embodiment of the present invention may be configured to include a request receiving unit (610), an automatic issuance determination unit (620), a response unit (630), a communication unit (640), and a control unit (650). According to one embodiment of the present invention, at least some of the request receiving unit (610), the automatic issuance determination unit (620), the response unit (630), the communication unit (640), and the control unit (650) may be program modules that communicate with an external system (not shown). These program modules may be included in the issuance support system (600) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may also be stored in a remote memory device that can communicate with the issuance support system (600). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, as described later in accordance with the present invention.
[0070] Meanwhile, although the issuance support system (600) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the issuance support system (600) may be realized within a device (500) or a server (not shown) or included within an external system (not shown) as needed.
[0071] First, the request receiving unit (610) according to one embodiment of the present invention can perform a function of receiving a request from a holder node to provide information regarding the issuance of a new VC that the holder node does not possess.
[0072] Specifically, according to one embodiment of the present invention, a verifier node may request information regarding a specific credential (VC) that can prove that a holder node possesses a specific qualification, in order to verify that the holder node possesses that specific qualification. According to one embodiment of the present invention, such specific qualifications may include, but are not limited to, possession of a specific qualification, being an adult, belonging to a specific organization, being a corporation, or performing activities that satisfy specific conditions. These qualifications may be varied within the scope of achieving the objectives of the present invention.
[0073] According to one embodiment of the present invention, a holder node (specifically, an information request unit (310) described below) that has received a request for information about a specific credential (VC) from a verifier node can determine whether at least one existing VC it owns includes the specific VC (i.e., whether the holder node owns the specific VC). In response to determining that the holder node (specifically, the information request unit (310) described below) does not include the specific VC, the holder node can request the request receiving unit (610) to provide information about the issuance of a new VC (i.e., the specific VC) that the holder node does not own based on the information about the at least one existing VC.
[0074] According to one embodiment of the present invention, the information regarding the issuance of a new VC requested by the request receiving unit (610) from the holder node may mean information regarding a method by which the holder node can be issued the new VC from the issuer node. According to one embodiment of the present invention, information regarding a VC or claim required to be issued a new VC (a credential including the claim may or may not be specified), information regarding an action to be performed by the holder node to be issued a new VC, information regarding a means (e.g., an API) required to perform the action, etc. may correspond to information regarding a method by which a new VC can be issued, but is not limited thereto.
[0075] Meanwhile, the request receiving unit (610) according to one embodiment of the present invention may increase the response priority for the request of the holder node in response to determining that a new VC not held by the holder node is related to payment.
[0076] Specifically, when a request receiving unit (610) according to one embodiment of the present invention receives a request from a holder node to provide information regarding the issuance of a new VC, the request receiving unit (610) can determine whether the new VC is a VC required for payment. If the new VC is determined to be related to payment (e.g., a credit card VC of Company A), the request receiving unit (610) according to one embodiment of the present invention can increase the response priority for the request so that it can be processed more quickly than other requests unrelated to payment (which may be requests from other holder nodes).
[0077] According to one embodiment of the present invention, the request receiving unit (610) can, when a new VC is determined to be related to payment, link and verify the financial data of the holder node in real time to quickly process the request. In this case, according to one embodiment of the present invention, the financial data of the holder node may also be managed in the form of credentials (e.g., income verification VC, credit score VC).
[0078] Next, the automatic issuance determination unit (620) according to one embodiment of the present invention may perform a function of determining whether to automatically issue a new VC not held by a holder node based on information about at least one existing VC held by the holder node.
[0079] Specifically, the request receiving unit (610) according to one embodiment of the present invention may receive information about at least one existing VC held by the holder node when receiving a request for information about the issuance of a new VC from the holder node. In addition, the automatic issuance determining unit (620) according to one embodiment of the present invention may determine, based on the information received in this manner, whether the holder node can automatically be issued the new VC using the at least one existing VC, and may determine a method for automatically or manually issuing the new VC.
[0080] More specifically, the automatic issuance determination unit (620) according to one embodiment of the present invention may determine whether a new VC can be automatically issued by processing a request from a holder node by referring to a VC database that may include information such as conditions for issuing a new VC, a VC template required for issuing a new VC and / or an intermediate VC (to be described later), and an API required for issuing a new VC (e.g., an API for communicating with an issuer node that can issue the new VC). Here, the VC template may guide information that must be included in the new VC and / or the intermediate VC (e.g., information included in a claim of another VC and / or information obtained therefrom).
[0081] According to one embodiment of the present invention, at least a portion of such VC database may be in the form of a relationship graph, i.e., a graph composed of nodes representing VCs and edges representing relationships between two VCs (e.g., precedence / succession relationships between two VCs (nodes)). The automatic issuance determination unit (620) according to one embodiment of the present invention may search for an optimal path (i.e., the best method for issuing a new VC) for issuing a new VC by using at least one existing VC held by a holder node while traversing such a relationship graph. This optimal path may, in some cases, include intermediate VCs required for issuing a new VC and the issuance order thereof.
[0082] For example, the automatic issuance determination unit (620) according to one embodiment of the present invention may determine an optimal path as a method for issuing a new VC, which is determined by various criteria, such as a path that takes the shortest time to issuing a new VC among several paths for issuing a new VC (e.g., a path with the fewest number of new VCs to be issued), a path with the least data consumption, a path that allows an existing VC with a high priority to be used first, etc.
[0083] If all of the VCs (corresponding to nodes) included in the optimal path thus searched are included in the existing VCs held by the holder node, or if some of the VCs included in the optimal path are not included in the existing VCs held by the holder node, but some of the VCs can be automatically issued using the existing VCs held by the holder node, the automatic issuance determination unit (620) according to one embodiment of the present invention can determine that automatic issuance of a new VC not held by the holder node is possible.
[0084] For example, in a situation where a holder node needs to be issued a new VC "D", if the holder node can obtain VC "D" by providing information about existing VCs "A" and "B" held by the holder node to the issuer node, the automatic issuance determination unit (620) according to an embodiment of the present invention can determine that automatic issuance of the new VC "D" is possible. For another example, in a situation where a holder node needs to be issued a new VC "D", and VCs "A" and "C" are required to obtain the new VC "D", if the holder node can obtain VC "C" as an intermediate VC for obtaining VC "D" by using existing VCs "B" (or "A" and "B") held by the holder node, the automatic issuance determination unit (620) according to an embodiment of the present invention can determine that automatic issuance of the new VC "D" is possible.
[0085] Conversely, in a situation where a holder node must be issued a new VC "D", if the holder node cannot immediately be issued a new VC "D" using existing VCs "A" and "B", and even if at least one intermediate VC (an intermediate VC for issuing VC "D") that can be issued using existing VCs "A" and "B" is issued, if the new VC "D" cannot be issued using the at least one intermediate VC and existing VCs "A" and / or "B", the automatic issuance determination unit (620) according to one embodiment of the present invention may determine that automatic issuance of the new VC "D" is impossible and must be issued manually.
[0086] Next, the response unit (630) according to one embodiment of the present invention can perform a function of responding to the request according to the result of the determination when the automatic issuance determination unit (620) determines whether or not to automatically issue a new VC that the holder node does not have.
[0087] Specifically, the response unit (630) according to one embodiment of the present invention, in response to the automatic issuance determination unit (620) determining that automatic issuance of a new VC not held by the holder node is possible, may provide the holder node with information for automatically issuing the new VC using at least one existing VC held by the holder node as a response to the request of the holder node. According to one embodiment of the present invention, the information for automatically issuing the new VC may include, but is not limited to, a VC template required for issuing a new VC and / or an intermediate VC, an intermediate VC and its issuance order required for issuing a new VC, and an API required for issuing a new VC and / or an intermediate VC.
[0088] As described above, when a new VC can be automatically issued using an intermediate VC, the information for automatically issuing a new VC may include information for automatically issuing an intermediate VC using at least one existing VC held by the holder node. According to one embodiment of the present invention, there may be multiple intermediate VCs, and in some cases, the multiple intermediate VCs may have an issuance order. For example, a first intermediate VC may be issued using an existing VC, and a second intermediate VC may be issued using the first intermediate VC.
[0089] Meanwhile, according to one embodiment of the present invention, the VC template required for issuing a new VC and / or intermediate VC may be generated by the issuer node setting a Selective Disclosure (SD) attribute for each claim using a predefined VC schema. According to one embodiment of the present invention, the VC schema may pre-determine which claims for each VC are selectively disclosed (i.e., which claims are capable of being selectively disclosed), and the issuer node may adjust the pre-determined selective disclosure attributes through an appropriate interface. By doing so, whether a specific claim of a VC is an SD attribute can be automatically determined based on the template without the issuer node having to manually set the SD attribute each time a VC is issued. This reduces the workload and error possibility of the issuer node when issuing a VC, and improves the efficiency of the VC ecosystem as a whole.
[0090] Meanwhile, the response unit (630) according to one embodiment of the present invention, in response to the automatic issuance determination unit (620) determining that automatic issuance of a new VC not held by the holder node is impossible, may provide the holder node with information regarding a VC that must be manually issued in order for the holder node to be issued the new VC, as a response to the request of the holder node. According to one embodiment of the present invention, the information regarding the VC that must be manually issued in order to be issued the new VC may include, but is not limited to, the simplest method for issuing the new VC and a step-by-step guide to issuing the new VC.
[0091] In addition, in a case where automatic issuance of a new VC is enabled by issuing an intermediate VC that must be manually issued by the holder node in order to be issued a new VC, the response unit (630) according to one embodiment of the present invention may provide information for automatically issuing a new VC to the holder node as described above.
[0092] Next, the communication unit (640) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the request receiving unit (610), the automatic issuance determination unit (620), and the response unit (630).
[0093] Finally, the control unit (650) according to one embodiment of the present invention can perform a function of controlling the flow of data between the request receiving unit (610), the automatic issuance determining unit (620), the response unit (630), and the communication unit (640). That is, the control unit (650) according to one embodiment of the present invention can control the flow of data from / to the outside of the issuance support system (600) or the flow of data between each component of the issuance support system (600), thereby controlling the request receiving unit (610), the automatic issuance determining unit (620), the response unit (630), and the communication unit (640) to perform their own functions.
[0094] Configuration of the holder-side system
[0095] Below, the internal configuration and functions of each component of the holder-side system (300) that performs important functions for implementing the present invention will be examined.
[0096] FIG. 3 is a drawing showing in detail the internal configuration of a holder-side system (300) according to one embodiment of the present invention.
[0097] As illustrated in FIG. 3, a holder-side system (300) according to one embodiment of the present invention may be configured to include an information request unit (310), an information provision unit (320), a communication unit (330), and a control unit (340). According to one embodiment of the present invention, at least some of the information request unit (310), the information provision unit (320), the communication unit (330), and the control unit (340) may be program modules that communicate with an external system (not shown). These program modules may be included in the holder-side system (300) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known memory devices. In addition, these program modules may be stored in a remote memory device that can communicate with the holder-side system (300). Meanwhile, these program modules include, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc. that perform specific tasks or execute specific abstract data types, which will be described later, according to the present invention.
[0098] Meanwhile, although the holder-side system (300) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the holder-side system (300) may be realized within a device (500) or a server (not shown) or included within an external system (not shown) as needed.
[0099]
[0100] First, the information request unit (310) according to one embodiment of the present invention can perform a function of requesting provision of information regarding the issuance of a new VC that is not held based on information regarding at least one existing VC held.
[0101] Specifically, the information request unit (310) according to one embodiment of the present invention may perform a function of requesting the request receiving unit (610) to provide information regarding the issuance of a new VC not held by the holder node based on information regarding at least one existing VC held by the holder node. Since detailed information regarding this has been described above, a redundant description will be omitted.
[0102] Next, the information providing unit (320) according to one embodiment of the present invention may, in response to receiving information for automatically issuing a new VC that is not held using at least one existing VC held, provide information about the at least one existing VC to the issuer node.
[0103] Specifically, the information providing unit (320) according to one embodiment of the present invention, in response to receiving information from the response unit (630) for automatically issuing a new VC not held by the holder node using at least one existing VC held by the holder node, may provide information about the at least one existing VC to the issuer node using an API for communicating with the issuer node.
[0104] At this time, the information providing unit (320) according to one embodiment of the present invention can provide the necessary information to the issuer node based on the VC template required for issuing a new VC and / or intermediate VC provided from the response unit (630), and the issuer node can issue the new VC and / or intermediate VC to the holder node based on the information provided from the information providing unit (320).
[0105] In addition, the information provision unit (320) according to one embodiment of the present invention can perform a function of providing information about a new VC issued from an issuer node as described above to a verifier node to have the new VC verified.
[0106] Next, the communication unit (330) according to one embodiment of the present invention can perform a function that enables data transmission and reception from / to the information request unit (310) and the information provision unit (320).
[0107] Finally, the control unit (340) according to one embodiment of the present invention can perform a function of controlling the flow of data between the information request unit (310), the information provision unit (320), and the communication unit (330). That is, the control unit (340) according to one embodiment of the present invention can control the flow of data from / to the outside of the holder-side system (300) or the flow of data between each component of the holder-side system (300), thereby controlling the information request unit (310), the information provision unit (320), and the communication unit (330) to perform their respective unique functions.
[0108] According to the various embodiments of the present invention described above, the following scenario may be possible when a user (which may correspond to a holder node) attempts to make a payment at an online shopping mall (which may correspond to a verifier node):
[0109] When an online shopping mall requests a user for a Company A credit card VC, the wallet (which may include the information request unit (310) or be included in the information request unit (310)) installed on the user's device (500) can determine whether the user holds a Company A credit card VC. If it is determined that the user does not hold a Company A credit card VC, the information request unit (310) can request the request receiving unit (610) to provide information regarding the issuance of a Company A credit card VC (i.e., a new VC) that the user does not hold. At this time, the request receiving unit (610) can determine that the Company A credit card VC is related to payment and increase the response priority.
[0110] Continuing, the automatic issuance determination unit (620) according to one embodiment of the present invention may determine that a Company A credit card VC can be automatically issued using the existing VC based on information about the income proof VC and credit score VC, which are existing VCs held by the user. In addition, the response unit (630) may provide the user with information for automatically issuing a Company A credit card VC using the existing VC. The information provision unit (320) automatically provides the income proof VC and the credit score VC to the issuer node (which may include an intermediate issuer node) based on the information provided by the response unit (630), and the Company A credit card VC issued through this process can be automatically presented to an online shopping mall for verification. If verification is normally completed by the online shopping mall, the user can proceed with payment using the Company A credit card.
[0111] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0112] Although the present invention has been described above with specific details such as specific components and limited examples and drawings, these are provided only to help a more general understanding of the present invention, and the present invention is not limited to the above examples, and those with ordinary knowledge in the technical field to which the present invention pertains can make various modifications and changes based on this description.
[0113] Therefore, the idea of the present invention should not be limited to the embodiments described above, and not only the scope of the patent claims described below but also all scopes equivalent to or equivalently modified from the scope of the patent claims are considered to fall within the scope of the idea of the present invention.
Claims
1. A method for supporting the issuance of verifiable credentials (VCs). A step of requesting information from a holder node regarding the issuance of a new VC that the holder node does not hold; A step of determining whether or not to automatically issue the new VC based on information about at least one existing VC held by the holder node, and Including a step of responding to the request based on the above judgment result. method.
2. In paragraph 1, In the above request step, in response to the new VC being judged to be related to payment, the response priority for the request is increased. method.
3. In paragraph 1, In the above judgment step, in response to determining that automatic issuance of the new VC is possible, in the response step, information for automatically issuing the new VC using the at least one existing VC is provided to the holder node. method.
4. In paragraph 3, In the above judgment step, the information for automatically issuing the new VC includes a VC template required for issuing at least one of the new VC and the intermediate VC, and the VC template is generated by setting the issuer node using a predefined schema. method.
5. In paragraph 3, The information for automatically issuing the new VC includes information for automatically issuing an intermediate VC using at least one existing VC, and the new VC can be automatically issued using the intermediate VC. method.
6. In paragraph 1, In response to the determination that automatic issuance of the new VC is impossible in the judgment step, information about a VC that must be manually issued in order to issue the new VC is provided to the holder node in the response step. method.
7. A method for supporting the issuance of verifiable credentials (VCs). A step of requesting the provision of information regarding the issuance of a new VC not held based on information regarding at least one existing VC held; In response to receiving information for automatically issuing the new VC using the at least one existing VC, a step of providing information about the at least one existing VC to the issuer node, and A step of verifying the new VC by providing information about the new VC issued from the issuer node to the verifier node. method.
8. In paragraph 7, In the above provision step, information about at least one existing VC is provided to an intermediate issuer node, and information about an intermediate VC issued from the intermediate issuer node is provided to a final issuer node. In the above verification step, information about the new VC issued from the final issuer node is provided to the verifier node to verify the new VC. method.
9. A non-transitory computer-readable recording medium recording a computer program for executing the method according to paragraph 1 or paragraph 7.
10. A system to support the issuance of verifiable credentials (VC). A request receiving unit that receives a request from a holder node to provide information on the issuance of a new VC that the holder node does not hold; An automatic issuance determination unit that determines whether or not to automatically issue the new VC based on information about at least one existing VC held by the holder node, and Including a response unit that responds to the request based on the above judgment result System.
11. In paragraph 10, The above request receiving unit, in response to determining that the new VC is related to payment, increases the response priority for the request. System.
12. In paragraph 10, In response to the automatic issuance judgment unit determining that automatic issuance of the new VC is possible, the response unit provides the holder node with information for automatically issuing the new VC using the at least one existing VC. System.
13. In paragraph 12, In the above judgment step, the information for automatically issuing the new VC includes a VC template required for issuing at least one of the new VC and the intermediate VC, and the VC template is generated by setting the issuer node using a predefined schema. System.
14. In paragraph 12, The information for automatically issuing the new VC includes information for automatically issuing an intermediate VC using at least one existing VC, and the new VC can be automatically issued using the intermediate VC. System.
15. In paragraph 10, In response to the automatic issuance judgment unit determining that automatic issuance of the new VC is impossible, the response unit provides the holder node with information about a VC that must be manually issued in order to receive the new VC. System.
16. A system to support the issuance of verifiable credentials (VC). An information requesting unit that requests the provision of information regarding the issuance of a new VC not held based on information regarding at least one existing VC held, and In response to receiving information for automatically issuing the new VC using the at least one existing VC, an information providing unit that provides information about the at least one existing VC to an issuer node and provides information about the new VC issued from the issuer node to a verifier node to verify the new VC. System.
17. In paragraph 16, The above information providing unit provides information about at least one existing VC to an intermediate issuer node, provides information about an intermediate VC issued from the intermediate issuer node to a final issuer node, and provides information about the new VC issued from the final issuer node to the verifier node to verify the new VC. System.
Citation Information
Patent Citations
Device, method, and graphical user interface for managing authentication credential for user account
JP2023175817A
Powder composition for removing oil from hair
KR1020230107008A
Processing apparatus
KR1020240064527A
Wafer lapping device and controlling method thereof
KR102248009B1
KR20220097054A