System and method for providing cross-context identity verification and legal identity

The global identity management system addresses the challenge of verifying identities across different contexts by generating legal identities within the service provider's domain, allowing foreigners to access online services and enhancing international service competition.

WO2025173847A1PCT designated stage Publication Date: 2025-08-21MIN GYENGGWON
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/014362
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-16
Filing Date
2024-09-24
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Current identity verification systems are limited to a single context and cannot verify identities across different countries or regions, preventing foreigners from accessing online services that require legal identification, such as online medical care, online contracts, and online finance.

Method used

A global identity management system that facilitates cross-context identity verification by receiving identity assertions and credentials from a requesting entity, verifying them through local identity providers, and generating a legal identity within the context of the service provider's domain, enabling access to online services across different contexts.

Benefits of technology

Enables foreigners to access online services based on their legal identity in other countries, promoting international online service competition and maximizing consumer welfare by providing cross-context identity verification and legal identity provision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024014362_21082025_PF_FP_ABST
    Figure KR2024014362_21082025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a system and a method for providing cross-context identity verification and legal identity. The method is a method for providing identity verification and legal identity between two entities of a relying party (RP) in a particular domain and a request entity (RE) in another domain, and comprises steps in which a global identity management system (idM): receives an identity claim and credential information for the RE within a context provided by a domain of a region which is the same as that of the RE; requests credential verification from an identity provide system (idP) matched to the credential information received for the RE and receives same; requests provision of identity information about the RE from the corresponding idP and receives same; verifies the identity of the RE; and, only for the verified identity, generates a legal identity requested by the RP within a context provided by a domain of a region which is the same as that of the RE, and transmits same to the RP.
Need to check novelty before this filing date? Find Prior Art

Description

Systems and methods for providing cross-context identity verification and legal identity

[0001] The present invention relates to a system and method for providing cross-context identity verification and legal identity, which provides cross-context identity verification and legal identity to enable domestic customers to use online services based on legal identity in other countries or regions, or to enable domestic customers to use online services based on legal identity in other countries or regions.

[0002] Nowadays, there are numerous online services, including online commerce services, online content provision services, online contract services, online financial services, and online medical services.

[0003] Service providers offering online services request identity from customers to identify and control access. Customers respond to the identity request by submitting an identity claim and credentials. The service provider then verifies the identity directly by verifying the credentials, or requests verification from an identity verification system, verifies the results, and then verifies the identity. In this case, the identity verification system may provide separate identity information to the service provider.

[0004] Likewise, the identity verification and identity information provision required to use online services may vary depending on the type of online service and customer base. The list of required credentials may also vary depending on the type of online service. While there may be variations across countries and regions, the nature of online services generally requires online methods for identity verification and identity information provision.

[0005] Typically, identity verification online within the context of a specific domain is accomplished through one or more identity provider (idP) systems. These identity provider systems electronically generate and / or register identity information of a data subject within a single context, then verify credentials in a specific medium via telecommunications transmission and reception, providing verification results and / or associated identity information. Furthermore, they refer to systems that verify credentials transmitted externally via telecommunications transmission and reception, and provide verification results and / or identity information. For example, identity provider systems can include government agencies' systems and government-approved systems, such as credit card companies, banks, and telecommunications companies. Specific media may include identification cards, passports, travel documents, credit cards, communication devices, and storage media.

[0006] For example, in the case of identification cards, not only were they issued in paper or card form, but recently they have been digitized and issued in a portable form on mobile devices.

[0007] In the case of passports, in addition to the existing paper passports, personal identification information printed on paper is embedded in an IC chip, and personal identification information can be read by scanning the IC chip with a separate reader.

[0008] In this way, in the process of verifying the transmission and reception method of communication and the media-type credentials such as ID cards or passports, and receiving the verification results and / or identity information, customers who wish to use online services electronically transmit their identity claims and credentials within the context provided by the service provider's domain, such as by scanning their ID card or passport on a reader or duplicating the media information. Accordingly, the service provider verifies their identity by requesting credential verification from an identity provider system (idP), such as a government agency system, within that context and receiving the verification results and / or identity information associated with the credential.

[0009] In other words, this series of identity verification processes presupposes that the service user, service provider, and identity provider system (idP) all exist within a single context. Identity verification and identity information provision across two or more different contexts is impossible. Currently, no process exists that enables identity verification and identity information provision across different contexts.

[0010] In the process of receiving identity information after verifying the method of transmission and reception in communication and the credentials transmitted from the outside, a customer who wants to use an online service electronically transmits an identity claim and credentials by entering information through a terminal within the context provided by the domain of the same area as the service provider, and the service provider requests credential verification from an identity provision system (idP), such as a government agency system, within that context and receives the verification result and / or identity information linked to the credential. Since this series of identity verification processes also assumes that the service user, the service provider, and the identity provision system (idP) all exist within a single context, there is no identity verification and identity information provision process required for online services across two or more different contexts.

[0011] The International Civil Aviation Organization (ICAO) has operated the MRTD protocol since 1980 to achieve its goal of national identity verification, and the eMRTD protocol and computer system since 2000. These protocols continue to be recognized as internationally recognized identity verification standards. However, the identity verification process implemented by ICAO assumes direct movement of individuals between countries or regions. Therefore, it proposes an identity verification method within a single context, i.e., the context provided by each country or region's domain for each movement. Therefore, even though the protocol provides internationally unified identity list information and credential verification methods, it does not provide or implement an identity verification process for identity claims across two or more different contexts. Therefore, even if a service user scans or copies their MRTD, eMRTD, passport, or other media to provide identity claims and credentials to a service provider within a foreign country or region's domain, identity verification cannot be performed within the context provided by the foreign country or region's domain according to the protocol.

[0012] Moreover, since the MRTD, eMRTD, and passport identification lists have fixed items and scopes, there is a disadvantage in that the service users and service providers must find a way to obtain the identification information necessary for the service each time an online service is provided.

[0013] Meanwhile, among identities, a set of information sufficient to identify the identity owner for the purpose of legal responsibility within a legal jurisdiction is called legal identity. It is a legal identity within the context provided by the same country or same regional domain, and is practically held by a national or local citizen or a foreigner who has entered the country so as to be consistent with the scope of national sovereignty or regional composition.

[0014] The development of online services has enabled service providers to offer services to foreigners outside their home country. However, these services currently do not require legal identification of foreign customers, and thus, there has been no demand or development for technology to verify the identity of foreigners in other countries. However, online services such as e-commerce and e-content subscriptions do not require unique identification, and only store payment information.

[0015] However, as new, high-quality online services are emerging and require legal identification for all customers, there is a growing need for systems and services that act as intermediaries to create and provide legal identification across two or more different contexts so that foreigners from other countries can access these services.

[0016] As a specific example, foreign patients currently visiting South Korea are unable to access the Personal Medical Information Access System, a South Korean online public information service, due to their lack of identity verification. This is because the system is restricted to those with legal identities in South Korea, which means either South Korean citizens or registered foreigners residing in South Korea for more than 90 days. However, even if foreign patients receive treatment in South Korea for a short period of time or receive remote care abroad, their personal medical information is processed and stored as their personal medical information in South Korea, and therefore, they should be able to access it. South Korea's Medical Act prohibits discrimination based on nationality, so services that would normally be accessible to "patients" are not available because identity verification is not possible.

[0017] As another example, international online contracts require procedures to verify legal identities between nationals and foreigners. However, there is no established national protocol for online contracts between nationals and foreigners regarding the list of legal identities, methods for providing legal identities, etc. Each online contract may require different lists of legal identities, methods for providing legal identities, and legal identities guarantees. Furthermore, no solution has been developed to address this issue.

[0018] As another example, in the case of online finance, most countries' financial institutions require a detailed list of legal identities and a highly secure method of providing legal identification due to Know Your Customer (KYC) rules. Foreign nationals are unable to provide such a list or method, effectively blocking access to online financial services in other countries. Consequently, they are unable to sign up for overseas banks or financial service platforms. While remote account opening within a country has recently become possible, there is no cross-national protocol to expand this practice to other countries. Furthermore, the legal identities, methods, and legal identification guarantees required by financial institutions within each country are inconsistent, hindering any solutions.

[0019] The present invention is intended to solve the above problems, and the technical task of the present invention is to devise a method for verifying the identity within the context provided by the domain to which the service user belongs, while providing legal identity within the context provided by the domain to which the service provider belongs, in order to provide online services based on legal identity, such as online medical care, online contracts, and online finance, on a national and regional basis, and through this method, the online service provider verifies the legal identity of the service user and provides the corresponding online service.

[0020] In addition, the technical task to be achieved in the present invention is to design a system that verifies the identity of a service user within the context provided by the domain to which the service user belongs and provides the legal identity within the context provided by the domain to which the service provider belongs, in order to provide a legal identity-based online service on a national and regional basis, and to implement the system so that the service provider can verify the legal identity of the service user and provide the online service.

[0021] In order to solve the technical problem described above, a method for providing cross-context identity verification and legal identity according to an embodiment of the present invention is a method for providing identity verification and legal identity between two entities, a relaying party (RP) in a specific domain and a request entity (RE) in another domain, the method comprising: (A) a step in which a global identity management system (idM) receives an identity assertion and credential information for a request entity within a context provided by a domain in the same domain as the request entity; (B) a step in which the global identity management system requests credential verification from an identity providing system (idP) belonging to a domain in the same domain as the request entity, the identity providing system matching the credential information received for the request entity, and receives a verification result; (C) a step in which the global identity management system requests the identity provision system that matches the credential information received for the requesting entity to provide identity information for the requesting entity and receives the identity information in response to the request; (D) a step in which the global identity management system verifies the identity of the requesting entity using information received from the outside and information processed internally; (E) a step in which the global identity management system generates a legal identity requested by the relying party within a context provided by a domain cooperating with the relying party, limited to the verified identity, and transmits the legal identity to the relying party.

[0022] In the above step (A), the global identity management system may directly receive the identity claim and credential information for the requesting entity from the requesting entity terminal, or the requesting entity terminal may transmit the identity claim and credential information for the requesting entity to a trusted party terminal and receive it from the trusted party terminal.

[0023] At this time, when receiving the identity claim and credential information for the requesting entity directly from the requesting entity terminal, the identification information for the trusted party that requested the identity verification may be additionally received from the requesting entity terminal.

[0024] In addition, the method according to an embodiment of the present invention further includes, before step (B), a step of determining whether the global identity management system can self-verify the identity claim and credential information received for the requesting entity; if the determination result indicates that self-verification is possible, a step of the global identity management system self-verifying the identity claim for the requesting entity using a method of processing credential information and a verifiable data registry or a method of comparing identity information in an internal storage; and if the determination result indicates that self-verification is impossible, step (B) is performed.

[0025] In addition, in the above step (B), the global identity management system stores the received verification result in an internal storage, uses it to create a legal identity, and provides it as reference material for identity verification of the requesting entity in the future.

[0026] In addition, in the above step (C), the global identity management system stores the identity information of the received requesting entity in an internal storage, uses it to create a legal identity, or provides it as reference material for identity verification of the requesting entity in the future.

[0027] In addition, the above step (D) causes the global identity management system to store the verified identity in an internal storage, use it to create a legal identity, and provide it as reference material for identity verification of the requesting entity in the future.

[0028] In addition, the method according to an embodiment of the present invention may further include, before step (A), a step in which the global identity management system creates and stores, as system metadata, information acquired about one or more identity provision systems that provide credential verification or identity information in each domain; a step in which the global identity management system creates and stores separate system metadata by combining at least one of the system metadata and metadata for creating and providing a global scope of identity; and a step in which the global identity management system creates and stores, according to the previously stored system metadata and the request of a relying party within a specific domain, trusted party RP metadata necessary for creating and providing a legal identity.

[0029] Meanwhile, a system for providing cross-context identity verification and legal identity according to an embodiment of the present invention comprises: a data transmission / reception unit for receiving information when transmitting an identity assertion and credential for a Request Entity (RE) within the context of a request entity in a specific domain and a same area; a verification unit for verifying, based on the identity assertion and credential information for the request entity, an identity providing system URI matching the credential information received for the request entity among identity providing systems (idPs) belonging to the domain and the same area of ​​the request entity, requesting credential verification and identity information to the corresponding identity providing system through the data transmission / reception unit, and receiving the verification result and identity information to verify the identity of the request entity; And, as the identity information verified by the verification unit, an identity information processing unit that creates a legal identity required by the relaying party (RP) within the context provided by the domain of the same area as the trusting party and transmits it to the terminal of the trusting party through the data transmission and reception unit.

[0030] The above data transmission and reception unit can receive the identity claim and credential information for the requesting entity directly from the requesting entity terminal or from the terminal of the trusted party.

[0031] The above data transmission and reception unit, when receiving directly from the request entity terminal, receives identification information including URI information of the terminal of the trusted party along with the identity claim and credential information for the request entity.

[0032] The above verification unit determines whether self-verification is possible for the identity claim and credential information received for the requesting entity, and if self-verification is possible as a result of the determination, self-verifies the identity claim for the requesting entity using a method in which the global identity management system processes credential information and a verifiable data registry or a method in which it compares it with identity information in an internal storage unit, and if self-verification is impossible as a result of the determination, requests identity verification to the identity provision system and verifies the identity based on the received verification result and / or identity information.

[0033] In addition, the system according to an embodiment of the present invention may further include an identity information storage unit for storing a credential verification result and / or identity information received through the verification unit, storing a verification result of identity verification through the verification unit or the identity information processing unit, and generating and storing a legal identity.

[0034] In addition, the system according to an embodiment of the present invention further includes a metadata processing unit that generates data regarding a plurality of identity provision systems that provide credential verification and identity information in each domain as system metadata in order to receive identity information, verify identity, and generate legal identity, combines the system metadata with at least one of metadata for generating and providing global identity, and generates separate system metadata, and generates the generated system metadata and trusted party metadata required for generating and providing legal identity according to a request from the trusted party.

[0035] In addition, the system according to an embodiment of the present invention may further include a system metadata storage unit for storing system metadata generated through the metadata processing unit.

[0036] In addition, the system according to an embodiment of the present invention may further include a trusted party metadata storage unit for storing trusted party metadata generated through the metadata processing unit.

[0037] According to this embodiment of the present invention, cross-context identity verification and legal identity provision are possible, so that there is an effect that goes beyond identity verification within a single context or legal identity provision within a single context, and identity verification and legal identity provision are possible across different contexts.

[0038] In addition, according to an embodiment of the present invention, a service provider (relying party) providing an online service requiring a legal identity can receive legal identity for a service customer (requesting entity) in another country or region, thereby enabling foreigners and outsiders to use online services based on their own legal identity, and conversely, enabling customers in their own country to access online services based on legal identity in another country or region.

[0039] Furthermore, according to an embodiment of the present invention, by providing legal identity-based online services that are currently limited to customers within a country or region on a national and regional basis, it has the effect of introducing international online service competition and thereby maximizing consumer welfare.

[0040] FIG. 1 is a diagram illustrating a network connection configuration of a system that provides cross-context identity verification and legal identity according to an embodiment of the present invention.

[0041] FIG. 2 is a diagram showing a global identity management system of a system according to an embodiment of the present invention.

[0042] FIGS. 3 to 5 are diagrams showing the structure of metadata stored in a global identity management system according to an embodiment of the present invention.

[0043] FIG. 6 is a diagram illustrating a method for constructing a metadata dictionary definition of a method for providing cross-context identity verification and legal identity according to an embodiment of the present invention.

[0044] FIG. 7 and FIG. 8 are flowcharts illustrating identity assertion and credential transmission in a method for providing cross-context identity verification and legal identity according to an embodiment of the present invention.

[0045] FIG. 9 is a flowchart specifically illustrating a method for providing cross-context identity verification and legal identity according to an embodiment of the present invention.

[0046] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In the description with reference to the accompanying drawings, identical or corresponding components are assigned the same drawing numbers, and redundant descriptions thereof will be omitted.

[0047] Before explaining the configuration and operating principles of the present invention, the terms used in the present invention are defined. The expression and meaning of each term are based on the international ITU X.1252 (2021), W3C Verifiable Credentials Data Model 1.1 (2022), and domestic TTAK.IT - X.1252 (2021) and TTAK.OT-12.0021 (2022).

[0048] - Entity: Something that has a separate and distinct reality and can be identified within a context.

[0049] - Context: An environment with defined boundary conditions in which entities exist and interact.

[0050] Domain: An environment in which an entity can utilize a single set of attributes for identification and other purposes. A domain provides context.

[0051] - Attribute: Information linked to an entity that specifies the characteristics of the entity.

[0052] - Identity: A representation of an entity composed of one or more attributes that enable the entity or entities to be sufficiently distinguished within a given context.

[0053] - Legal identity: A set of information sufficient to identify the owner of an identity for purposes of legal accountability, at least within one legal jurisdiction.

[0054] - Claim: A digital declaration by an entity about an identity attribute made by itself or another entity.

[0055] - Credential: A set of data submitted as evidence of claimed identity and qualifications.

[0056] Verifiable data registry: A system that mediates the creation and verification of identifiers, keys, and other related data required for the use of verifiable credentials, such as verifiable credential schemas, revocation registries, and issuer public keys. Examples of verifiable data registries include trusted databases, decentralized databases, government ID databases, and distributed ledgers. It's not uncommon for multiple types of verifiable data registries to be used within a single ecosystem.

[0057] - Identity verification: A process of comparing the provided identity claim with previously verified information to confirm the accuracy of the claimed identity.

[0058] - Identity assurance: The level of confidence or trust in the association between an entity and the submitted identity information.

[0059] - Request Entity (RE): An entity that makes an identity representation or assertion to a relying party in a request situation.

[0060] - Relaying Party (RP): An entity that relies on the identity representation or assertion made by the requesting or declaring entity in a request situation.

[0061] - Identity Provider (idP): An entity that verifies, maintains, and manages the identity information of other entities, and creates or assigns identity information.

[0062] - Agent: An entity that acts on behalf of another entity

[0063] - Identity Management (idM): A set of functions and capabilities used to guarantee identity information (e.g., identifiers, credentials, attributes), guarantee the identity of entities, and support business and security applications.

[0064]

[0065] FIG. 1 is a diagram illustrating a network connection configuration of a system providing cross-context identity verification and legal identity according to an embodiment of the present invention.

[0066] As illustrated in FIG. 1, a system according to an embodiment of the present invention is implemented by including a global identity management system (100), a trusted party terminal (200) possessed or managed by a trusted party (RP, 20), a requesting entity terminal (300) possessed or managed by a requesting entity (RE, 30), and an identity providing system (identity provider system, 400).

[0067] Each terminal or system may be a terminal capable of user input, such as a PC or mobile terminal, or a server or server device that has pre-built data and can retrieve and provide data upon request. For example, the requesting entity terminal (300) may be a PC, laptop, personal mobile terminal, etc., and the global identity management system (100), trusted party terminal (200), and identity provision system (400) may be implemented in the form of a server or server device.

[0068] The trusted party (20) referred to in the present invention is a service provider that provides online services based on legal identity. Examples include service providers that provide online medical services, online contract services, and online financial services.

[0069] The requesting entity (30) is a service user who subscribes to or requests a service based on a legal identity provided by a trusted party (20), and is an entity that is identified and interacts between a context different from the context provided by the domain to which the trusted party belongs.

[0070] In the present invention, a relying party (20) can request a legal identity within a context provided by a domain in the same area as the relying party from a requesting entity (30) that subscribes to a relying party legal identity-based service or requests a service. Then, the requesting entity (30) transmits the identity assertion and credential within the context provided by the domain in the same area as the requesting entity to the global identity management system (100) through the requesting entity terminal (300). The global identity management system (100) verifies the identity within the context provided by the domain to which the requesting entity (30) belongs, and generates and provides a legal identity within the context provided by the domain to which the relying party (20) belongs, thereby ultimately allowing the relying party (20) to verify the legal identity of the requesting entity (30) and provide a legal identity-based online service.

[0071] Here, "domain" refers to both physical and legal space. In line with the definitions mentioned in the previous definition, it refers to the tangible and intangible space containing entities that can be identified both physically and legally.

[0072] A context is an environment in which a set of attributes can be used to identify and other purposes when an entity belongs to a specific domain.

[0073] The global identity management system (100) is a global context system that can effectively transmit and receive identity-related data, verify identity, and create identity with one or more entities within each context provided by a plurality of domains. In order to implement the service of the present invention, it performs an intersecting role as an agent for each entity within the context provided by a specific domain in stages. Specifically, as a relying party agent within the context provided by a domain in the same area as the requesting entity (30), it receives an identity assertion and credential transmitted from the requesting entity terminal (300) and verifies the identity of the requesting entity. Meanwhile, as an identity provision system agent within the context provided by the domain in the same area as the relying party (20), it creates and provides a legal identity requested by the relying party (20) based on the verified identity information.

[0074] The identity provision system (400) is an information processing system within a specific domain that provides credential verification and identity information within the context provided by the specific domain. In an embodiment of the present invention, the global identity management system (100) can acquire and integrate data, such as a credential verification method and identity list information generated and / or provided by the identity provision system (400) in one or more domains, thereby performing the role of an identity provision system on a global scale.

[0075] Meanwhile, the identity provision system (400) includes multiple identity providers according to various credential types. The identity provision system (400) may be independently constructed for each identity provider, or the multiple identity providers may be integrated and constructed into a single system. For example, identity providers may include government agencies such as the Ministry of the Interior and Safety, or institutions authorized by government agencies to verify identities, such as financial institutions, card companies, and telecommunications companies. Each government agency and each institution may separately construct an identity provision system (400) for verifying credentials and providing identity information.

[0076] As illustrated in FIG. 1, a global identity management system (100) according to an embodiment of the present invention is globally connected to a trusted party terminal (200), a requesting entity terminal (300), and an identity provision system (400) belonging to one or more domains through a network.

[0077] In this way, when a requesting entity (30) within a specific domain transmits an identity claim and credential within the context provided by a domain in the same area through a requesting entity terminal (300), the global identity management system (100) can verify the identity of the requesting entity with only the credential transmitted together with the identity claim, or can request the identity provision system (400) to verify the credential and provide identity information, and then receive the verification result and identity information to verify the identity of the requesting entity.

[0078] In addition, the global identity management system (100) creates a legal identity in the form of information that the trusted party (20) is defined to receive from the global identity management system (100) in advance based on the verified identity between the context provided by the above-mentioned context and the context provided by the domain of the same region and a different trusted party (20), and provides the legal identity to the trusted party terminal (200).

[0079] The detailed configuration and operating principles of the global identity management system (100) for this purpose are described.

[0080] Figure 2 is a configuration diagram showing a global identity management system (100) of a system according to an embodiment of the present invention.

[0081] The global identity management system (100) includes a data transmission and reception unit (110), a metadata processing unit (120), an identity information processing unit (130), a verification unit (140), an internal storage unit including a system metadata storage unit (150), a trusted party metadata storage unit (160), and an identity information storage unit (170).

[0082] The global identity management system (100) processes data regarding an identity provision system (400 in FIG. 1) and a trusted party (20 in FIG. 1) in a specific domain to establish a metadata dictionary definition. This is performed by the metadata processing unit (120). To this end, the global identity management system (100) includes a pre-established agreement procedure between trusted parties (20 in FIG. 1), and generates metadata in a format desired by the trusted parties based on the agreement.

[0083] Referring to FIG. 2, the metadata processing unit (120) obtains data regarding one or more identity provision systems (400) within each domain, creates system metadata, and stores it in the system metadata storage unit (150).

[0084] The metadata generated in relation to the identity provision system (400) includes one or more of the following: an idP domain name, a name of the identity provision system (400), a URI of the identity provision system (400), identity list information generated and / or provided by the identity provision system (400), a credential verification method of the identity provision system (400), and a verifiable data registry within the context provided by the domain, as shown in FIG. 3.

[0085] Here, the idP domain name can be a country name or a region name, and the idP name mentioned in FIG. 3 can be the name of a government agency, telecommunications company, bank, card company, etc. within the domain. The idP URI is the Internet address of the identity provision system within the domain, and the idP-generated identity list information is an identity list generated by the identity provision system within the domain for one or more requesting entities (30), and includes one or more of an identifier (ID), nationality, location, name, age, gender, affiliation, photo, and biometric information. The idP-provided identity list information is an identity list provided within a context provided by the identity provision system within the domain for one or more requesting entities (30), and may include, for example, one or more of an identifier (ID), nationality, location, name, age, gender, affiliation, photo, and biometric information. A context-specific verifiable data registry is a system that mediates the creation and verification of identifiers, keys, and other related data required for the use of verifiable credentials, such as verifiable credential schemas, revocation registries, and issuer public keys, within a specific context. Examples of verifiable data registries include trusted databases, decentralized databases, government ID databases, and distributed ledgers.

[0086] Referring back to FIG. 2, the metadata processing unit (120) combines one or more of the system metadata regarding one or more identity provision systems (400) within one or more domains generated by the above procedure, and the metadata for generating and providing global identities to generate separate system metadata, and additionally stores the same in the system metadata storage unit (150). The metadata stored in this way includes at least one or more of the following information: an idM-linked idP domain name, identity list information generated and / or provided by the global identity management system (100), an identity verification method of the global identity management system (100), identity guarantee information of the global identity management system (100), electronic signature information of the global identity management system (100), and a verifiable data registry in the global scope, as shown in FIG. 4.

[0087] Referring back to FIG. 2, the metadata processing unit (120) generates relying party (RP) metadata regarding the legal identity to be generated and provided to the relying party (20) according to the system metadata generated by the above procedure and the request of the relying party (20) within a specific domain, and stores the same in the relying party (RP) metadata storage unit (160). The metadata stored in this way includes one or more of the RP domain name, the RP name, the URI of the RP terminal, the legal identity list information required by the RP, the legal identity guarantee information required by the RP, the electronic signature information of the global identity management system (idM), and the context-verifiable data registry provided by the domain, as shown in FIG. 5.

[0088] When the pre-definition and construction of metadata are completed in this way, and the trusting party terminal (200) requests the requesting entity (30) that subscribes to the trusting party legal identity-based service or requests the service, the legal identity within the context provided by the domain in the same area as the trusting party is requested, the requesting entity (30) responds by transmitting the identity claim and credential information to the global identity management system (100) through the requesting entity terminal (300).

[0089] Specifically, in the global identity management system (100), the data transmission and reception unit (110) receives identity assertion and credential information for the requesting entity within the context provided by the domain to which the requesting entity (30) belongs from the requesting entity terminal (300 in FIG. 1) or the trusted party terminal (200 in FIG. 1).

[0090] Here, an identity assertion means a digital declaration made by a requesting entity (30) through a requesting entity terminal (300 in Fig. 1) regarding an identity attribute created by itself or another entity in response to a legal identity request from a relying party (20).

[0091] Credential information refers to a set of data transmitted as evidence of a claimed identity, and is information in the form of a secret key-based authentication technology, public key-based authentication technology, biometric authentication technology, distributed ledger-based authentication technology, or media security-based authentication technology with domestically and internationally standardized standards. Credential information transmitted along with an identity claim refers to all data generated using the aforementioned technical methods and enabling verification of the claimed identity.

[0092] Additionally, when the data transceiver (110) directly receives the identity claim and credential information from the requesting entity terminal (300), it may receive identification information, including the URI information of the relying party, along with the identity claim and credential information of the requesting entity. This is to transmit information that can identify the relying party, the recipient, in order to generate and provide legal identity information in the form requested by the relying party after verifying the identity claim.

[0093] The verification unit (140) verifies, from system metadata, the URI of an identity provision system that provides a credential verification method that matches the credential information transmitted by the requesting entity among identity provision systems (idPs) belonging to the same domain as the requesting entity (30) based on the identity assertion and credential information for the requesting entity received through the data transmission / reception unit (110), and requests credential verification and / or identity information within the context provided by the corresponding domain to the identity provision system through the data transmission / reception unit (110). Then, the identity of the requesting entity is verified by receiving the verification result and identity information.

[0094] At this time, the verification unit (140) determines whether self-verification of the identity claim and credential information for the received requesting entity is possible. This determination can be made by examining whether the credential information transmitted by the requesting entity can be self-verified by a verifiable data registry. A verifiable data registry refers to a data set that can verify the identity claim of the requesting entity as credential information.

[0095] If the judgment result shows that self-identity verification is possible, the verification unit (140) verifies the identity of the requesting entity's identity claim as a method of processing credential information and verifiable data registry.

[0096] If self-verification of identity is not possible as a result of the judgment, the verification unit (140) requests credential verification and / or provision of identity information to the identity provision system within each domain, which is confirmed from the system metadata matching the credential information, and then verifies the identity based on the received verification result and / or identity information.

[0097] Meanwhile, the verification unit (140) can store the received credential verification result, the identity information of the requesting entity, and at least one of the verified identities in the identity information storage unit (170).

[0098] The identity information processing unit (130) creates a legal identity within the context provided by the domain of the same area as the trusted party (30) based on the identity information stored in the identity information storage unit (170) and the trusted party metadata (RP metadata), and provides the legal identity to the trusted party terminal (200) through the data transmission / reception unit (110).

[0099] Meanwhile, the identity information processing unit (140) stores the generated legal identity in the identity information storage unit (170).

[0100] Each piece of information stored in the identity information storage unit (170) is provided as reference material for later identity verification of the same requesting entity (30) or provision of legal identity to the same trusted party (20).

[0101] The global identity management system (100) configured in this way stores information on a list of identities that can be created and / or provided, a credential verification method, etc., obtained from one or more identity provision systems (400) in one or more domains as primary system metadata, integrates each primary system metadata to store information on a list of identities that can be created and / or provided globally, an identity verification method, or identity guarantee information, etc., as secondary system metadata, and combines system metadata and information types required by a trusted party (20) in a specific domain to store them as RP metadata.

[0102] Thereafter, the global identity management system (100) receives identity assertion and credential information through the request entity terminal (300) within the context provided by the domain of the same region as the request entity (30), and then processes the data in conjunction with the identity provision system (400) belonging to the domain of the same region as the request entity (30). In addition, the global identity management system (100) has a system configuration that can generate a legal identity within the context provided by the domain of the same region as the trust party (20) and provide it to the trust party terminal (200).

[0103] FIG. 6 is a drawing illustrating a metadata construction method for implementing a system according to an embodiment of the present invention.

[0104] Prior to the invention of the present invention, a method for identity verification between a Relying Party (RP), a Requesting Entity (RE), and an Identity Provider (idP) belonging to different domains did not exist. This was due to the differences in the amount and quality of identity information required or provided in each context, making it difficult to devise a method for cross-context identity verification and legal identity provision. However, the implementation of identity verification and legal identity provision is made possible through the predefined metadata construction method of the present invention, described below.

[0105] First, in step S1, the global identity management system (100) acquires data regarding one or more identity provision systems (400) within each domain and creates and stores system metadata using the data.

[0106] Metadata generated and stored in relation to the identity provision system (400) may include one or more of the following: an idP domain name, a name of the identity provision system, a URI of the identity provision system, identity list information generated and / or provided by the identity provision system, a credential verification method of the identity provision system, and a context-verifiable data registry provided by a specific domain, as shown in FIG. 3.

[0107] Next, in step S2, the global identity management system (100) combines one or more of the system metadata regarding a plurality of identity provision systems (400) belonging to a plurality of domains created and stored in step S1 and the metadata for creating and providing global identities to create separate system metadata and stores it as system metadata.

[0108] The metadata thus generated and stored includes at least one piece of information from among the idM linked idP domain name, identity list information generated and / or provided by the global identity management system (idM), identity verification method of the global identity management system (idM), identity guarantee information of the global identity management system (idM), electronic signature information of the global identity management system (idM), and verifiable data registry on a global scale, as shown in FIG. 4.

[0109] Next, in step S3, the global identity management system creates and stores RP metadata required for creating and providing legal identity based on previously stored system metadata and the requests of trusted parties (20) within a specific domain.

[0110] The metadata stored in this way may include one or more of the RP domain name, the name of the relying party, the URI of the relying party terminal, the list of legal identity information requested by the relying party, the legal identity guarantee information requested by the relying party, the electronic signature information of the global identity management system (idM), and the verifiable data registry within the context provided by the domain, as exemplified in FIG. 5.

[0111] FIG. 7 and FIG. 8 are flowcharts illustrating identity assertion and credential transmission in a method for providing cross-context identity verification and legal identity according to an embodiment of the present invention.

[0112] Figures 7 and 8 correspond to the initial steps for performing identity verification between two entities, a relying party (20, RP) within the context provided by a specific domain and a requesting entity (30, RE) within the context provided by a specific domain.

[0113] First, a request entity terminal of a request entity (30) residing or located in a specific domain (local A) can apply for service use to a trusted party (20) that provides a legal identity-based online service in a specific domain (local B).

[0114] Thereafter, the trusted party terminal (200) on the trusted party side requests legal identity for the request entity (30) within the context provided by the domain (local B) in the same area as the trusted party (20) (S100, S200).

[0115] In response to the above legal identity request, the requesting entity terminal (300) transmits identity claim and credential information within the context provided by the domain (local A) in the same area as the requesting entity to the trusting party terminal (200) (S110).

[0116] Thereafter, the trusted party terminal (200) transmits the identity claim and credential information for the requesting entity received from the requesting entity terminal (300) to the global identity management system (idM, 100) that is linked to the trusted party terminal (200) (S120).

[0117] Alternatively, in response to the legal identity request, the requesting entity terminal (300) may directly transmit identity claim and credential information to the global identity management system (idM, 100) that is linked to the trusted party terminal (200) (S210).

[0118] At this time, in step S210, the requesting entity terminal (300) can transmit additional identification information about the trusted party terminal (200) (S220).

[0119] Through this process, the global identity management system (100) receives identity claim and credential information or trusted party terminal (200) identification information for the requesting entity (30) within the context provided by the requesting entity (30) and the same domain (local A).

[0120] The subsequent operation in the global identity management system (100) refers to FIG. 9.

[0121] As illustrated in FIG. 9, the global identity management system (100) determines whether to request credential verification and / or identity information provision for the identity claim and credential information of the requesting entity (30) received from the requesting entity terminal (300) or the trusted party terminal (200) (S300).

[0122] This is the process by which the Global Identity Management System (idM) determines whether self-verification is possible. Based solely on the credentials submitted by the requesting entity, the system verifies whether they can be verified through the verifiable data registry. If verification is possible or if identity information already stored in idM exists, self-verification is considered possible. Conversely, if verification is impossible or if no identity information already stored in idM exists, self-verification is deemed impossible.

[0123] As a result of the judgment, if self-identity verification is possible, the identity claim of the requesting entity is verified using the method by which the global identity management system (idM) processes credential information and verifiable data registry or by using the method of comparing it with previously stored identity information (S340).

[0124] If self-identity verification is not possible as a result of the judgment, the global identity management system (idM) routinely performs step S310.

[0125] That is, the global identity management system (idM) requests credential verification to an identity provisioning system (idP) (URI of idP) that matches the credential information transmitted by the requesting entity (30) among the identity provisioning systems (idP) within the same domain (local A) as the requesting entity (S310). Along with the above request, the identity provisioning system may be requested to provide identity information for the requesting entity (30).

[0126] Thereafter, the global identity management system (idM) receives the credential verification result and / or the identity information of the requesting entity from the corresponding identity provision system (idP) (S320).

[0127] Thereafter, the global identity management system (idM) verifies the identity within the context provided by the domain of the requesting entity (30) and the domain of the same domain using at least one of the identity claim and credential information of the requesting entity transmitted from the requesting entity terminal (300) or the trusted party terminal (200), the verification result received from the identity provision system (400), and the identity information of the requesting entity or previously stored identity information (S330).

[0128] Thereafter, the global identity management system (idM) references the verified identity information and RP metadata to create and store a legal identity within the context provided by the domain of the trusting party and the local area (localB), and transmits it to the trusting party terminal (200) (S350, S360).

[0129] Alternatively, when the global identity management system (idM) performs an electronic signature on the legal identity provided to the trusted party terminal (200), the global identity management system (idM) registers the electronic signature public key in the context-verifiable data registry provided by the domain of the same region as the trusted party (20) so that the trusted party (20) can verify the electronic signature.

[0130] Although the preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above, and various modifications can be made by those skilled in the art without departing from the gist of the present invention as claimed in the claims. Furthermore, such modifications should not be understood individually from the technical idea or prospect of the present invention.

[0131] The system of the present invention can expand existing identity provision services within each domain beyond the country or region. By enabling identity verification across different domains, customers in the home country can access high-quality online services in other countries and regions. Conversely, foreigners can access online services in the home country. This allows online services previously limited to customers within the same country or region to be offered nationwide, thereby introducing international service competition. In particular, in the case of online medical services, even foreign patients visiting Korea can access the personal medical information access system simply by verifying their identity. Therefore, once an international protocol is established, the system has high potential for application in various online service industries that provide high-quality services through identity verification.

Claims

1. A method for providing identity verification and legal identity between two entities: a Relaying Party (RP) in a specific domain and a Request Entity (RE) in another domain. (A) A step in which a global identity management system (idM) receives identity assertion and credential information for the requesting entity within a context provided by a domain in the same region as the requesting entity; (B) A step in which the global identity management system requests credential verification from an identity providing system (idP) that matches the credential information received for the requesting entity among the identity providing systems (idP) belonging to the same domain as the requesting entity, and receives the verification result; (C) A step in which the global identity management system requests the identity provision system matching the credential information of the requesting entity to provide identity information about the requesting entity and receives the identity information in response to the request; (D) A step in which the global identity management system verifies the identity of the requesting entity using information received from the outside and information processed internally; (E) A step in which the global identity management system generates a legal identity requested by the relying party within the context provided by the domain of the relying party and the co-working party, limited to the verified identity, and transmits the legal identity to the relying party; A method for providing cross-context identity verification and legal identity including:

2. In paragraph 1, Step (A) above, A method for providing cross-context identity verification and legal identity, characterized in that the global identity management system directly receives the identity claim and credential information for the requesting entity from the requesting entity terminal, or the requesting entity terminal transmits the identity claim and credential information for the requesting entity to a relying party terminal and receives it from the relying party terminal.

3. In paragraph 2, When receiving identity claim and credential information for the above requesting entity directly from the requesting entity terminal, A method for providing cross-context identity verification and legal identity, characterized in that it further includes receiving identification information about a trusted party that requested the identity verification from the requesting entity terminal.

4. In paragraph 1, Before step (B) above, A step for determining whether the global identity management system can independently verify the identity claim and credential information received from the requesting entity; If the judgment result shows that self-verification is possible, the global identity management system further includes a step of self-verifying the identity claim of the requesting entity by using a method of processing credential information and a verifiable data registry or a method of comparing it with identity information in an internal storage unit; A method for providing cross-context identity verification and legal identity, characterized in that step (B) is performed when self-verification is impossible as a result of the above judgment.

5. In paragraph 1, Step (B) above, A method for providing cross-context identity verification and legal identity, characterized in that the global identity management system stores the received verification result in an internal storage, uses it to create a legal identity, or provides it as reference material for identity verification of the requesting entity at a later time.

6. In paragraph 1, Step (C) above, A method for providing cross-context identity verification and legal identity, characterized in that the global identity management system stores the identity information of the received requesting entity in an internal storage, uses it to create a legal identity, or provides it as reference material for identity verification of the requesting entity at a later time.

7. In paragraph 1, Step (D) above, A method for providing cross-context identity verification and legal identity, characterized in that the global identity management system stores the verified identity in an internal storage, uses it to create a legal identity, or provides it as reference material for identity verification of the requesting entity at a later time.

8. In paragraph 1, Prior to step (A) above, The above global identity management system generates and stores information acquired from one or more identity provision systems that provide credential verification or identity information in each domain as system metadata, The above global identity management system generates and stores separate system metadata by combining one or more of the system metadata and metadata for generating and providing global-scope identity, The above global identity management system creates and stores the trusted party RP metadata required for creating and providing legal identity according to the stored system metadata and the request of the trusted party within a specific domain. A method for providing cross-context identity verification and legal identity, characterized in that it further comprises:

9. A data transmission and reception unit that receives information when transmitting identity assertions and credentials for a Request Entity (RE) within the context of a request entity in a specific domain and the same domain; A verification unit that verifies the URI of an identity providing system (idP) that matches the credential information received for the requesting entity among identity providing systems (idPs) belonging to the same domain as the requesting entity based on the identity assertion and credential information for the requesting entity, requests credential verification and identity information to the corresponding identity providing system through the data transmission / reception unit, and receives the verification result and identity information to verify the identity of the requesting entity; and An identity information processing unit that generates a legal identity required by the relaying party (RP) within the context provided by the domain of the same area as the trusting party using the identity information verified by the above verification unit, and transmits the legal identity to the terminal of the trusting party through the data transmission / reception unit; A system that provides cross-context identity verification and legal identity, enabling identity verification between two entities in different domains through a global identity management system that includes .

10. In paragraph 9, The above data transmission and reception unit, A system for providing cross-context identity verification and legal identity, characterized in that the identity claim and credential information for the above-mentioned requesting entity are received directly from the requesting entity terminal or from the terminal of the above-mentioned trusted party.

11. In paragraph 10, The above data transmission and reception unit, A system for providing cross-context identity verification and legal identity, characterized in that when receiving directly from the request entity terminal, identification information including URI information of the terminal of the trusted party is further received together with the identity claim and credential information for the request entity.

12. In paragraph 9, The above verification department, Determine whether self-verification of identity is possible for the identity claim and credential information received from the above requesting entity, If the judgment result shows that self-verification is possible, the global identity management system self-verifies the identity claim of the requesting entity by using the method of processing credential information and verifiable data registry or comparing it with the identity information in the internal storage. A system for providing cross-context identity verification and legal identity, characterized in that when self-verification is impossible as a result of a judgment, identity verification is requested from the identity provision system and the identity is verified based on the received verification result and / or identity information.

13. In paragraph 9, An identity information storage unit for storing the credential verification result and / or identity information received through the above verification unit, storing the verification result of identity verification through the above verification unit or the identity information processing unit, and creating and storing a legal identity. A system for providing cross-context identity verification and legal identity, characterized by further including:

14. In paragraph 9, In order to receive identity information, verify identity, and create legal identity, a metadata processing unit that generates system metadata from data on multiple identity provision systems that provide credential verification and identity information in each domain, combines the system metadata with at least one of metadata for creating and providing global identity, and creates separate system metadata, and generates the generated system metadata and the relying party metadata required for creating and providing legal identity according to the request of the relying party. A system providing cross-context identity verification and legal identity, characterized by further including:

15. In paragraph 14, A system metadata storage unit for storing system metadata generated through the above metadata processing unit. A system for providing cross-context identity verification and legal identity, characterized by further including:

16. In paragraph 14, A trusted party metadata storage unit for storing trusted party metadata generated through the above metadata processing unit. A system providing cross-context identity verification and legal identity, characterized by further including:

Citation Information

Patent Citations

  • Method for identifying foreigner

    KR1020120119825A

  • Method and apparatus for providing authentication based on aggregated attribute in federated identity management

    KR1020160098976A

  • Monoclonal antibody that specifically binds to nectin-4 and use thereof

    KR1020250004494A

  • System and Method for Integrated Usage Personal Information Using Scrapping Technology Based on End-Users Consulation

    KR102296659B1

  • System and method for verifying identity and providing legal identity between contextes

    KR102703368B1