Information processing system, information processing device, processing method, and storage medium
The system addresses the challenge of invalidated biometric information in VCs by using cancelable keys for reissuing certificates, ensuring continuous authentication and verification through secure reissuance processes.
Patent Information
- Application Number
- PCT/JP2024/012295
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-10-02
AI Technical Summary
Existing systems using biometric information in Verifiable Credentials (VCs) face issues with the inability to effectively manage and reissue certificates once the biometric information is invalidated, leading to potential loss of functionality.
Implementing an information processing system that issues and reissues certificates using cancelable keys and biometric information, allowing for the generation of new keys when the previous ones are compromised or expired, ensuring continuous verification and authentication.
Enables secure and efficient reissuance of certificates based on the status of cancelable keys, maintaining authentication and verification capabilities even when biometric information is compromised.
Smart Images

Figure JP2024012295_02102025_PF_FP_ABST
Abstract
Description
Information processing system, information processing device, processing method, and storage medium
[0001] The present disclosure relates to an information processing system, an information processing device, a processing method, and a storage medium.
[0002] Patent Document 1 discloses a technology for ensuring the authenticity of content provided by a digital wallet.
[0003] Paragraph 0030 of Patent Document 1 describes that by installing an application for realizing a digital wallet on a terminal 30 owned by a user and opening a digital wallet on the terminal 30, various digital content such as electronic money, identification documents such as student ID cards, passports, and driver's licenses, various ticket information such as airline tickets and boarding passes, and vaccination certificates can be stored on the terminal 30. Furthermore, paragraph 0136 of Patent Document 1 discloses that when a certificate issuer issues a face certificate, i.e., a face VC, as a Verifiable Credential (VC), the user provides face information to the issuer and requests the issuance of the face VC, and the issuer compares the presented face with face information it holds and issues the face VC if they match. Furthermore, paragraph 0136 of Patent Document 1 discloses that the user provides the issued face VC to a service provider, and the service provider uses the face VC to authenticate the user.
[0004] Patent No. 7371818
[0005] When biometric information is used in a Verifiable Credential (VC) as described above, there is a possibility that the person in question will no longer be able to use the biometric information once it is invalidated.
[0006] An object of the present disclosure is to provide an information processing system, an information processing device, a processing method, and a storage medium that solve the above-mentioned problems.
[0007] An information processing system according to one aspect of the present disclosure includes an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by a designated issuing device and biometric information of the user, and when reissuing the certificate, the issuing means reissues the certificate held by the user using a second cancelable key issued by the designated issuing device and the biometric information of the user.
[0008] An information processing system according to one aspect of the present disclosure includes an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by the user's terminal and the user's biometric information when the service is provided, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the user's terminal and the user's biometric information when the certificate is reissued.
[0009] An information processing device according to one aspect of the present disclosure includes an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by a designated issuing device and biometric information of the user, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the designated issuing device and the biometric information of the user when reissuing the certificate.
[0010] An information processing device according to one aspect of the present disclosure includes an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by the user's terminal and the user's biometric information when the service is provided, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the user's terminal and the user's biometric information when the certificate is reissued.
[0011] A processing method according to one aspect of the present disclosure issues a certificate held by a user receiving a service using a first cancelable key issued by a designated issuing device and biometric information of the user, and when reissuing the certificate, reissues the certificate held by the user using a second cancelable key issued by the designated issuing device and the biometric information of the user.
[0012] A processing method according to one aspect of the present disclosure issues a certificate held by a user receiving a service using a first cancelable key issued by the user's terminal and the user's biometric information when receiving the service, and reissues the certificate held by the user using a second cancelable key issued by the user's terminal and the user's biometric information when reissuing the certificate.
[0013] A storage medium according to one aspect of the present disclosure causes a computer to function as an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by a designated issuing device and biometric information of the user, and the issuing means stores a program that reissues the certificate held by the user using a second cancelable key issued by the designated issuing device and the user's biometric information when the certificate is reissued.
[0014] A storage medium according to one aspect of the present disclosure causes a computer to function as an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and the user's biometric information when the service is received, and the issuing means stores a program that reissues the certificate held by the user using a second cancelable key issued by the terminal of the user and the user's biometric information when the certificate is reissued.
[0015] FIG. 1 is a system configuration diagram of an information processing system of the present disclosure. FIG. 1 is a hardware configuration diagram of an information processing device according to an embodiment of the present disclosure. FIG. 1 is a first diagram showing functional blocks of an issuing system according to an embodiment of the present disclosure. FIG. 1 is a first diagram showing functional blocks of a terminal according to an embodiment of the present disclosure. FIG. 1 is a first diagram showing functional blocks of a service providing system according to an embodiment of the present disclosure. FIG. 1 is a first diagram showing a processing flow of an information processing system according to an embodiment of the present disclosure. FIG. 2 is a second diagram showing a processing flow of an information processing system according to an embodiment of the present disclosure. FIG. 2 is a second diagram showing functional blocks of an issuing system according to an embodiment of the present disclosure. FIG. 2 is a second diagram showing functional blocks of a terminal according to an embodiment of the present disclosure. FIG. 3 is a third diagram showing a processing flow of an information processing system according to an embodiment of the present disclosure. FIG. 4 is a diagram showing functional blocks of an information processing device according to an embodiment of the present disclosure. FIG. 1 is a first diagram showing a processing flow of an information processing device according to an embodiment of the present disclosure. FIG. 2 is a second diagram showing a processing flow of an information processing device according to an embodiment of the present disclosure.
[0016] Hereinafter, an information processing system, an information processing device, a processing method, a program, and a storage medium according to the present disclosure will be described with reference to the drawings.
[0017] Fig. 1 is a system configuration diagram of an information processing system according to the present disclosure. As shown in Fig. 1, the information processing system 100 is configured by a communication-connected issuing system 1 managed by a certificate issuer (Issuer), a terminal 2 managed by a user (Holder) who holds the certificate, a management device 3 managed by an administrator who manages a public key corresponding to the issuer's private key used to issue the certificate, and a service providing system 4 managed by a service provider (Verifier) who provides services to users who have verified the certificate. The administrator who manages the public key may be, for example, a Verifiable Data Registry (VDR).
[0018] As an example, the issuing system 1 is communicatively connected to the terminal 2, and the issuing system 1 is communicatively connected to the management device 3. The terminal 2 is communicatively connected to the management device 3. The terminal 2 and the management device 3 are communicatively connected to the service providing system 4, respectively.
[0019] In an example of the information processing system 100 disclosed herein, a user first submits a service registration request using the terminal 2 (step S1). The service providing system 4 then issues a cancelable key used to issue a certificate and transmits it to the terminal 2 (step S2). The cancelable key may be defined as a key designed in the system to generate an "irreversibly converted feature" using a feature generated from biometric information and a "key," and to cancel the key when the "irreversibly converted feature" is used for verification or matching. Even if the "irreversibly converted feature" is invalidated due to a leak or other reason, a new "irreversibly converted feature" can be generated using a new cancelable key, thereby canceling the existing "irreversibly converted feature." The terminal 2 then transmits an issuance request including a facial image (photograph) and the cancelable key to the issuing system 1 (step S3). The issuing system 1 generates a certificate using the facial image, the cancelable key, and the issuer's private key and transmits it to the terminal 2 (step S4). The issuing system 1 transmits a public key corresponding to the private key to the management device 3 (step S5). The management device 3 manages and stores the public key. When the terminal 2 receives the certificate from the issuing system 1, it notifies the service providing system 4 that the certificate has been issued (step S6). This completes preparations for the service provision by the service providing system 4.
[0020] After the above processing, the service providing system 4 receives a certificate from the terminal 2 when providing some service. The service providing system 4 receives a public key from the management device 3 to verify the electronic signature included in the certificate. The service providing system 4 uses the public key to verify whether the certificate has been tampered with. A known technique may be used to verify the electronic signature using this public key to verify whether the certificate has been tampered with. The service providing system 4 may perform the verification based on the contents of the certificate. Once the verification is complete, the service providing system 4 provides the service to the user. The service providing system 4 may authenticate the user. For example, the service providing system 4 may determine that the authentication is successful if the certificate generated at the time of authentication using the user's biometric information and the cancellable key matches the certificate obtained from the terminal 2.
[0021] When providing a service, the service providing system 4 may receive a certificate from the terminal 2 and then receive a public key from the management device 3 to decrypt the encrypted certificate. The service providing system 4 may then verify whether the certificate can be decrypted using the public key. In this case, the service providing system 4 may perform the verification based on the contents of the decrypted certificate. Once the verification is complete, the service providing system 4 may provide the service to the user.
[0022] Depending on the status of the cancelable key, the certificate may need to be reissued. For example, if the cancelable key is lost or leaked to the outside, the reliability of the certificate generated using such a cancelable key will decrease, making it desirable to reissue the certificate. Therefore, when the service providing system 4 detects the need for reissue based on the status of the cancelable key, it transmits a reissue request to the terminal 2. Note that the terminal 2 may detect the need for reissue based on the status of the cancelable key. Alternatively, the issuing system 1 may detect the need for reissue based on the status of the cancelable key. Alternatively, another device may detect the need for reissue based on the status of the cancelable key. The status of the cancelable key may be, for example, that the cancelable key has been lost or leaked, but may also be other states. The status of the cancelable key may be when a predetermined period has passed since the issuance of the cancelable key, or when a predetermined device has determined that the cancelable key should be deleted. When the service providing system 4 detects the need for certificate reissue, it generates a new cancelable key and transmits an issuance request including the new cancelable key to the terminal 2. The terminal 2 sends an issuance request including the cancellable key to the issuing system 1. The issuing system 1 reissues the certificate using the new cancellable key and private key.
[0023] Through the above processing, even if a certificate needs to be reissued based on the status of the cancelable key, it becomes possible to easily issue a certificate that can be verified by the information processing system that verifies the service providing system 4, etc.
[0024] The generation and issuance of the cancelable key may be performed by the terminal 2 or the issuing system 1. In this case, the terminal 2 or the issuing system 1 transmits the generated cancelable key in some form to the service providing system 4, which stores it. The cancelable key may be different for each service provider who operates a different service providing system 4. The cancelable key may also be different for each user.
[0025] The processing of the information processing system 1 described above is one example in which the issuing system 1 issues a certificate held by a user using a first cancelable key issued by the service providing system 4 and the biometric information of the user receiving the service when receiving the service, and when reissuing the certificate, the issuing system 1 reissues the certificate held by the user using a second cancelable key issued by the service providing system 4 and the user's biometric information.
[0026] Alternatively, the processing of the information processing system 1 described above is one example in which, when receiving a service, the issuing system 1 issues a certificate held by the user using a first cancelable key issued by the terminal 2 held by the user receiving the service and the user's biometric information, and when reissuing the certificate, the issuing system 1 reissues the certificate held by the user using a second cancelable key issued by the terminal 2 held by the user and the user's biometric information.
[0027] Alternatively, the processing of the information processing system 1 described above is one example in which the issuing system 1 issues a certificate held by a user using a first cancelable key issued by one information processing device and the user's biometric information stored by the other information processing device when receiving a service, and when reissuing the certificate, the issuing system 1 reissues the certificate held by the user using a second cancelable key issued by one information processing device and the user's biometric information stored by the other information processing device.
[0028] 2 is a hardware configuration diagram of an information processing device according to an embodiment of the present disclosure. The issuing system 1 and the service providing system 4 are computer systems configured with one or more information processing devices 10. As shown in FIG. 2, the information processing device 10 is a computer equipped with various hardware components such as a CPU (Central Processing Unit) 101, a ROM (Read Only Memory) 102, a RAM (Random Access Memory) 103, a storage device 104, a communication module 105, and a sensor 106. The terminal 2 and the management device 3 are also computers equipped with the same functions as the information processing device 10.
[0029] 3 is a first diagram showing functional blocks of an issuing system according to an embodiment of the present disclosure. The issuing system 1 performs the functions of a control unit 11, a transmission / reception unit 12, a certificate issuing unit 13, and a registration unit 14. These functions are provided to the issuing system 1 by one or more information processing devices 10 that constitute the issuing system 1 starting up programs.
[0030] 4 is a first diagram illustrating functional blocks of a terminal according to an embodiment of the present disclosure. The terminal 2 performs the functions of a control unit 21, a transmission / reception unit 22, and a certificate management unit 23. These functions are provided to the terminal 2 by the terminal 2 starting a program.
[0031] 5 is a first diagram showing functional blocks of a service providing system according to an embodiment of the present disclosure. The service providing system 4 performs the functions of a control unit 41, an acquisition unit 42, a key generation unit 43, a verification unit 44, an authentication unit 45, and a service providing unit 46. These functions are provided to the service providing system 4 by one or more information processing devices 10 constituting the service providing system 4 starting a program.
[0032] (First Embodiment) FIG. 6 is a first diagram showing the processing flow of the information processing system. FIG. 7 is a second diagram showing the processing flow of the information processing system. Next, the processing of the information processing system will be described with reference to FIGS. 6 and 7. First, the control unit 21 of the terminal 2 transmits a service registration request to the service providing system 4 based on a user's operation (step S101). Then, the key generation unit 43 of the service providing system 4 generates a cancelable key (first cancelable key) used to issue a certificate (step S102). The transmission / reception unit 42 of the service providing system 4 transmits the generated cancelable key to the terminal 2 (step S103). The transmission / reception unit 22 of the terminal 2 receives the cancelable key. The certificate management unit 23 acquires a facial image of the user from a storage unit or the like (step S104). The certificate management unit 23 of the terminal 2 transmits an issuance request including the facial image and the cancelable key to the issuing system 1 (step S105).
[0033] The certificate issuing unit 13 of the issuing system 1 generates a certificate using the facial image, the cancelable key, and the issuer's private key (step S106). Note that the certificate in this disclosure is, as an example, a cancelable face VC (Verifiable Credential). The certificate may be information obtained by inputting the user's facial feature information obtained from the facial image and the cancelable key into a VC generation algorithm and encrypting it with the private key. The certificate may be information obtained by converting feature information obtained from a facial image or biometric information other than a facial image, such as a fingerprint or iris, with the cancelable key, inputting the converted feature information into a VC generation algorithm, and then adding an electronic certificate signed with the private key to the information, such as the facial image. The certificate may be information obtained by inputting the facial image or feature information obtained from biometric information other than a facial image, such as a fingerprint or iris, and the cancelable key into a VC generation algorithm and encrypting it with the private key. Note that the certificate issuing unit 13 may perform authentication using biometric information such as a facial image of the user when issuing a certificate, and issue a certificate to the user using the facial image (biometric information) only if the authentication is successful. The transceiver unit 12 of the issuing system 1 transmits the certificate to the terminal 2 (step S107). The terminal 2 records the certificate in a storage device (step S108). The registration unit 14 of the issuing system 1 transmits a public key corresponding to the private key to the management device 3 (step S109). The management device 3 records the public key in a DB (database) (step S110).
[0034] When the certificate management unit 23 of the terminal 2 receives the certificate from the issuing system 1, it sends a certificate issuance completion notification to the service providing system 4 (step S111). The control unit 41 of the service providing system 4 associates the terminal ID that identifies the user's terminal 2 with the user name, the cancelable key used to generate the certificate, and the like, and records them in a database or the like (step S112). This completes preparations for service provision by the service providing system 4.
[0035] When receiving a service, the user operates the terminal 2 to instruct the terminal 2 to transmit a certificate. The certificate management unit 23 of the terminal 2 detects the certificate transmission instruction (step S113). The certificate management unit 23 of the terminal 2 transmits the certificate to the service providing system 4 (step S114). Upon receiving the certificate, the verification unit 44 of the service providing system 4 acquires a public key stored in the management device 3 in association with the ID included in the certificate (step S115). This ID may be a decentralized identifier (DID) included in the cancelable face VC. The verification unit 44 verifies whether the certificate acquired from the terminal 2 has been tampered with by using the public key acquired from the management device 3 (step S116). If the ID is a decentralized identifier (DID) included in the cancelable face VC, the public key is recorded in association with the DID in the blockchain, and the verification unit 44 may acquire this public key to verify whether the certificate has been tampered with. In the process of step S116, the verification unit 44 may perform verification by decrypting the certificate acquired from the terminal 2 with the private key. In this verification, the verification unit 44 may acquire a facial image of the user from the terminal 2, input biometric (facial) feature information acquired from the facial image and the cancelable key into a VC generation algorithm to generate a certificate for verification, compare the certificate for verification with the certificate held by the user acquired from the terminal 2, and determine that the verification is successful if they match. The verification unit 44 may perform verification by other processes. If it is determined that the verification is successful, the service providing unit 46 provides the service (step S117).
[0036] When providing this service, the authentication unit 45 of the service providing system 4 may perform user authentication. In this case, the authentication unit 45 acquires a facial image generated by photographing the user's face using a camera or the like connected to the communication line, and inputs feature information in the facial image and the cancelable key into a VC generation algorithm to generate a certificate for authentication. The authentication unit 45 performs authentication by comparing the certificate for authentication with the certificate held by the user obtained from the terminal 2 (step S118). The authentication unit 45 may determine that authentication is successful if the certificate for authentication matches the certificate held by the user obtained from the terminal 2.
[0037] Assume that the control unit 41 of the service providing system 4 detects a certificate reissue for some reason (step S119). The reason may be certificate leakage, loss or accidental deletion of the certificate, expiration of the cancelable key used to generate the certificate, detection of an instruction to delete the cancelable key, or detection of an instruction to reissue the cancelable key. The certificate reissue may also be detected by another system or device. For example, the issuing system 1 may detect the certificate reissue based on an operational instruction from an administrator and directly notify the service providing system 4 of the detection of the certificate reissue. The key generation unit 43 then generates a new cancelable key (second cancelable key) (step S120). The transceiver unit 42 of the service providing system 4 transmits the newly generated cancelable key to the terminal 2 (step S121). The certificate management unit 23 of the terminal 2 acquires the user's facial image from a storage unit or the like (step S122). The certificate management unit 23 of the terminal 2 transmits an issuance request including the face image and the new cancelable key to the issuing system 1 (step S123).
[0038] The certificate issuing unit 13 of the issuing system 1 regenerates the certificate using the facial image, the new cancelable key, and the issuer's private key (step S124). The certificate issuing unit 13 may perform authentication using biometric information such as the user's facial image when issuing the certificate, and issue a certificate for the user using the facial image (biometric information) only if the authentication is successful. The transceiver unit 12 of the issuing system 1 transmits the certificate to the terminal 2 (step S125). The terminal 2 records the new certificate in a storage device (step S126). The registration unit 14 of the issuing system 1 transmits the public key corresponding to the private key to the management device 3 (step S127). The management device 3 records the public key in a DB (database) (step S128).
[0039] When the certificate management unit 23 of the terminal 2 receives the certificate from the issuing system 1, it sends a certificate issuance completion notification to the service providing system 4 (step S129). The control unit 41 of the service providing system 4 associates the terminal ID that identifies the user's terminal 2 with the user name, the cancelable key (second cancelable key) used to generate the new certificate, and the like, and records them in a database or the like (step S130). This completes preparation for service provision by the service providing system 4.
[0040] According to the above-described process, the certificate may be repeatedly reissued when the control unit 41 (a processing unit having the function of a reissue detection unit) of the service providing system 4 detects that a certificate has been reissued. This makes it possible to easily issue a certificate that can be verified by an information processing system such as the service providing system 4, even when a certificate needs to be reissued based on the state of the cancellable key.
[0041] When receiving a service after the certificate has been reissued, the user operates the terminal 2 to instruct the terminal 2 to send the certificate. The certificate management unit 23 of the terminal 2 detects the certificate transmission instruction (step S131). The certificate management unit 23 of the terminal 2 transmits the certificate to the service providing system 4 (step S132). Upon receiving the certificate, the verification unit 44 of the service providing system 4 acquires a public key stored in the management device 3 in association with the ID included in the certificate (step S133). The verification unit 44 verifies whether the certificate acquired from the terminal 2 has been tampered with, using the public key acquired from the management device 3 (step S134). If the certificate is encrypted with a public key, the verification unit 44 may decrypt the certificate acquired from the terminal 2 with the private key to perform verification. In this verification, the verification unit 44 may acquire a facial image of the user from the terminal 2, input biometric (facial) feature information obtained from the facial image and the cancelable key into a VC generation algorithm to generate a certificate for verification, compare the certificate for verification with the certificate held by the user obtained from the terminal 2, and determine that the verification is successful if they match. The verification unit 44 may also perform verification by other processing. If it is determined that the verification is successful, the service providing unit 46 provides the service (step S135).
[0042] When providing this service, the authentication unit 45 of the service providing system 4 may perform user authentication. In this case, the authentication unit 45 acquires a facial image generated by photographing the user's face using a camera or the like connected to the communication line, and inputs feature information in the facial image and the cancelable key into a VC generation algorithm to generate a certificate for authentication. The authentication unit 45 performs authentication by comparing the certificate for authentication with the certificate held by the user obtained from the terminal 2 (step S136). The authentication unit 45 may determine that authentication is successful if the certificate for authentication matches the certificate held by the user obtained from the terminal 2.
[0043] Second Embodiment Fig. 8 is a second diagram showing functional blocks of an issuing system according to an embodiment of the present disclosure. Fig. 9 is a second diagram showing functional blocks of a terminal according to an embodiment of the present disclosure.
[0044] In the processing of the first embodiment, the service providing system 4 detects the need to reissue the cancellable key. The following processing shows an example in which the issuing system 1 detects the need to reissue the cancellable key. In the processing of the first embodiment, the service providing system 4 generates and issues the cancellable key. The following processing shows an example in which the terminal 2 generates and issues the cancellable key.
[0045] When the issuing system 1 detects the need to reissue a cancellable key, the issuing system 1 performs the function of a reissue detection unit 15 as shown in Fig. 8. When the terminal 1 generates a cancellable key, the issuing system 1 performs the function of a key generation unit 24 as shown in Fig. 8.
[0046] Fig. 10 is a third diagram showing the processing flow of the information processing system. Fig. 11 is a fourth diagram showing the processing flow of the information processing system. The processing of the information processing system will be described with reference to Figs. 10 and 11.
[0047] First, based on a user's operation, the control unit 21 of the terminal 2 sends a service registration request to the service providing system 4 (step S301). The control unit 41 of the service providing system 4 sends a request to issue a cancelable key to the terminal 2 (step S302). The transceiver unit 22 of the terminal 2 receives the request to issue a cancelable key. The key generation unit 24 of the terminal 2 generates a cancelable key (first cancelable key) to be used to issue a certificate (step S303). The certificate management unit 23 of the terminal 2 acquires a facial image of the user from a storage unit or the like (step S304). The certificate management unit 23 of the terminal 2 sends a request to issue a certificate including the cancelable key and the facial image to the issuing system 1 (step S305).
[0048] The transceiver 12 of the issuing system 1 receives the certificate issuance request. The certificate issuing unit 13 of the issuing system 1 generates a certificate using the facial image, the cancelable key, and the issuer's private key (step S306). Note that the certificate in this disclosure is, as an example, a cancelable face VC (Verifiable Credential). The certificate may be information obtained by inputting the user's facial feature information obtained from the facial image and the cancelable key into a VC generation algorithm and encrypting it with the private key. The certificate may be information obtained by converting feature information obtained from a facial image or biometric information other than a facial image, such as a fingerprint or iris, with the cancelable key, inputting the converted feature information into a VC generation algorithm, and then adding an electronic certificate signed with the private key to the facial image or other information. The certificate may be information obtained by inputting the facial image or biometric information other than a facial image, such as a fingerprint or iris, and the cancelable key into a VC generation algorithm and encrypting it with the private key. The transceiver 12 of the issuing system 1 transmits the certificate to the terminal 2 (step S307). The terminal 2 records the certificate in a storage device (step S308). The registration unit 14 of the issuing system 1 transmits a public key corresponding to the private key to the management device 3 (step S309). The management device 3 records the public key in a DB (database) (step S310).
[0049] When the certificate management unit 23 of the terminal 2 receives the certificate from the issuing system 1, it sends a certificate issuance completion notification to the service providing system 4 (step S311). The control unit 41 of the service providing system 4 associates the terminal ID that identifies the user's terminal 2 with the user name, the cancelable key used to generate the certificate, etc., and records them in a database or the like (step S312). This completes preparations for service provision by the service providing system 4.
[0050] When receiving a service, the user operates the terminal 2 to instruct the terminal 2 to send a certificate. The certificate management unit 23 of the terminal 2 detects the certificate transmission instruction (step S313). The certificate management unit 23 of the terminal 2 transmits the certificate to the service providing system 4 (step S314). Upon receiving the certificate, the verification unit 44 of the service providing system 4 acquires a public key stored in the management device 3 in association with the ID included in the certificate (step S315). The verification unit 44 verifies whether the certificate acquired from the terminal 2 has been tampered with, using the public key acquired from the management device 3 (step S316). If the certificate is encrypted with a public key, the verification unit 44 may decrypt the certificate acquired from the terminal 2 with the private key to perform verification. In this verification, the verification unit 44 may acquire a facial image of the user from the terminal 2, input biometric (facial) feature information obtained from the facial image and the cancelable key into a VC generation algorithm to generate a certificate for verification, compare the certificate for verification with the certificate held by the user obtained from the terminal 2, and determine that the verification is successful if they match. The verification unit 44 may also perform verification by other processing. If it is determined that the verification is successful, the service providing unit 46 provides the service (step S317).
[0051] When providing this service, the authentication unit 45 of the service providing system 4 may perform user authentication. In this case, the authentication unit 45 acquires a facial image generated by photographing the user's face using a camera or the like connected to the communication line, and inputs feature information in the facial image and the cancelable key into a VC generation algorithm to generate a certificate for authentication. The authentication unit 45 performs authentication by comparing the certificate for authentication with the certificate held by the user obtained from the terminal 2 (step S318). The authentication unit 45 may determine that authentication is successful if the certificate for authentication matches the certificate held by the user obtained from the terminal 2.
[0052] Assume that the reissue detection unit 15 of the issuing system 1 detects a certificate reissue for some reason (step S319). The reason may be leakage of the certificate stored in the service providing system 4 or a predetermined database when the issuing system 1 is connected to the service providing system 4 for communication, loss or erroneous deletion of the certificate, expiration of the cancelable key used to generate the certificate, detection of an instruction to delete the cancelable key, detection of an instruction to reissue the cancelable key, etc. Then, the reissue detection unit 15 transmits a reissue request for a new cancelable key (second cancelable key) to the terminal 2 (step S320).
[0053] The transceiver 22 of terminal 2 receives a reissue request for a new cancelable key (second cancelable key). The key generator 24 of terminal 2 generates a new cancelable key (second cancelable key) (step S321). The certificate manager 23 of terminal 2 acquires a facial image of the user from a storage unit or the like (step S322). The certificate manager 23 of terminal 2 transmits a reissue request including the facial image and the new cancelable key to the issuing system 1 (step S323).
[0054] The certificate issuing unit 13 of the issuing system 1 regenerates a certificate using the facial image, the new cancelable key, and the issuer's private key (step S324). The transceiver unit 12 of the issuing system 1 sends the certificate to the terminal 2 (step S325). The terminal 2 records the new certificate in its storage device (step S326). The registration unit 14 of the issuing system 1 sends a public key corresponding to the private key to the management device 3 (step S327). The management device 3 records the public key in a database (DB) (step S328). Note that in this process, the terminal 2 generates the cancelable key, but the issuing system 1 may also have a key generation unit and issue the cancelable key (first cancelable key or second cancelable key). In this case, the issuing system 1 may send the issued cancelable key to the management device 3, and the service providing system may obtain the cancelable key (first cancelable key or second cancelable key) via the management device 3 and use it for verification and authentication.
[0055] When the certificate management unit 23 of the terminal 2 receives the certificate from the issuing system 1, it sends a certificate issuance completion notification to the service providing system 4 (step S329). The control unit 41 of the service providing system 4 associates the terminal ID that identifies the user's terminal 2 with the user name, the cancelable key (second cancelable key) used to generate the new certificate, and the like, and records them in a database or the like (step S330). This completes preparation for service provision by the service providing system 4.
[0056] According to the above-described process, the reissue of the certificate may be repeated when the reissue detection unit 15 of the issuing system 1 detects the reissue of the certificate. This allows the service providing system 4 to easily issue a verifiable certificate even when the certificate needs to be reissued based on the status of the cancellable key.
[0057] When receiving a service after the certificate has been reissued, the user operates the terminal 2 to instruct the terminal 2 to send the certificate. The certificate management unit 23 of the terminal 2 detects the certificate transmission instruction (step S331). The certificate management unit 23 of the terminal 2 transmits the certificate to the service providing system 4 (step S332). Upon receiving the certificate, the verification unit 44 of the service providing system 4 acquires the public key stored in the management device 3 in association with the ID included in the certificate (step S333). The verification unit 44 verifies whether the certificate acquired from the terminal 2 has been tampered with, using the public key acquired from the management device 3 (step S334). If the certificate is encrypted with a public key, the verification unit 44 may decrypt the certificate acquired from the terminal 2 with the private key to perform verification. In this verification, the verification unit 44 may acquire a facial image of the user from the terminal 2, input biometric (facial) feature information obtained from the facial image and the cancelable key into a VC generation algorithm to generate a certificate for verification, compare the certificate for verification with the certificate held by the user obtained from the terminal 2, and determine that the verification is successful if they match. The verification unit 44 may also perform verification by other processing. If it is determined that the verification is successful, the service providing unit 46 provides the service (step S335).
[0058] When providing this service, the authentication unit 45 of the service providing system 4 may perform user authentication. In this case, the authentication unit 45 acquires a facial image generated by photographing the user's face using a camera or the like connected to the communication line, and inputs feature information in the facial image and the cancelable key into a VC generation algorithm to generate a certificate for authentication. The authentication unit 45 performs authentication by comparing the certificate for authentication with the certificate held by the user obtained from the terminal 2 (step S336). The authentication unit 45 may determine that authentication is successful if the certificate for authentication matches the certificate held by the user obtained from the terminal 2.
[0059] (Another Embodiment 1) FIG. 12 is a diagram showing functional blocks of an information processing device according to the present disclosure. FIG. 13 is a first diagram showing a processing flow of an information processing device according to the present disclosure. An information processing device 50 according to the present disclosure may include an issuing unit 51. The issuing unit 51 of the issuing system 1 (information processing device 50) acquires a first cancelable key issued by the service providing system 4 and biometric information of the user receiving the service when the user receives the service (step S501). The issuing unit 51 of the issuing system 1 issues a certificate held by the user using the first cancelable key issued by the service providing system 4 and the biometric information of the user receiving the service when the user receives the service (step S502). The issuing unit 51 of the issuing system 1 acquires a second cancelable key issued by the service providing system 4 and the biometric information of the user when reissuing the certificate (step S503). The issuing unit 51 of the issuing system 1 reissues a certificate held by the user using the second cancelable key issued by the service providing system 4 and the biometric information of the user when reissuing the certificate (step S504).
[0060] (Other Embodiment 2) FIG. 14 is a second diagram showing the processing flow of an information processing device according to the present disclosure. Alternatively, the issuing unit 51 of the issuing system 1 (information processing device 50) acquires a first cancelable key issued by the terminal 2 when the user receives a service and biometric information of the user receiving the service (step S601). The issuing unit 51 of the issuing system 1 (information processing device 50) issues a certificate held by the user using the first cancelable key issued by the terminal 2 when the user receives the service and the biometric information of the user receiving the service (step S602). The issuing unit 51 of the issuing system 1 (information processing device 50) acquires a second cancelable key issued by the terminal 2 when the certificate is reissued and the user's biometric information (step S603). The issuing unit 51 of the issuing system 1 (information processing device 50) reissues a certificate held by the user using the second cancelable key issued by the terminal 2 when the certificate is reissued and the user's biometric information (step S604).
[0061] 15 is a third diagram showing the processing flow of an information processing device according to the present disclosure. Alternatively, when a user receives a service, the issuing means 51 of the issuing system 1 (information processing device 50) issues a certificate held by the user using a first cancelable key issued by the issuing system 1 and biometric information of the user receiving the service (step S701). When the certificate is reissued, the issuing means 51 of the issuing system 1 reissues the certificate held by the user using a second cancelable key issued by the issuing system 1 and biometric information of the user (step S702).
[0062] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0063] Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0064] (Supplementary Note 1) An information processing system comprising an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and biometric information of the user, wherein the issuing means reissues the certificate held by the user using a second cancelable key issued by the specified issuing device and the biometric information of the user when reissuing the certificate.
[0065] (Supplementary Note 2) An information processing system comprising: an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and biometric information of the user when the service is received; and the issuing means for reissuing the certificate held by the user using a second cancelable key issued by the terminal of the user and biometric information of the user when the certificate is reissued.
[0066] (Supplementary Note 3) The information processing system according to Supplementary Note 1 or Supplementary Note 2, wherein the issuing means issues the certificate to which an electronic certificate signed using a private key of an issuer of the certificate is attached, and issues a public key corresponding to the private key; and a verifying means uses the public key to verify whether the certificate has been tampered with.
[0067] (Supplementary Note 4) The information processing system according to Supplementary Note 1, wherein the first cancelable key is different for each of a plurality of service providers.
[0068] (Supplementary Note 5) An information processing system according to any one of Supplementary Note 1 to Supplementary Note 4, comprising: an authentication means for performing authentication using a certificate generated at the time of authentication using biometric information acquired from the user and the first cancelable key, and a certificate held by the user.
[0069] (Supplementary Note 6) The information processing system according to any one of Supplementary Note 1 to Supplementary Note 5, further comprising: a reissue request means for generating the second cancelable key based on the state of the first cancelable key and requesting a reissue of the certificate held by the user.
[0070] (Supplementary Note 7) The information processing system according to any one of Supplementary Notes 1 to 6, wherein the issuing means performs authentication using biometric information of the user when issuing a certificate, and issues a certificate held by the user using the biometric information.
[0071] (Supplementary Note 8) An information processing device comprising: an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and biometric information of the user; and the issuing means for reissuing the certificate held by the user using a second cancelable key issued by the specified issuing device and the biometric information of the user when reissuing the certificate.
[0072] (Supplementary Note 9) An information processing device comprising: an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and biometric information of the user when receiving the service; and the issuing means for reissuing the certificate held by the user using a second cancelable key issued by the terminal of the user and biometric information of the user when reissuing the certificate.
[0073] (Supplementary Note 10) The information processing device according to Supplementary Note 8, wherein the first cancelable key is different for each of a plurality of service providers.
[0074] (Supplementary Note 11) The information processing device according to any one of Supplementary Note 8 to Supplementary Note 10, further comprising: a reissue request means for generating the second cancelable key based on the state of the first cancelable key and requesting reissue of the certificate held by the user.
[0075] (Supplementary Note 12) The information processing device according to any one of Supplementary Note 8 to Supplementary Note 11, wherein the issuing means performs authentication using biometric information of the user when issuing a certificate, and issues a certificate held by the user using the biometric information.
[0076] (Supplementary Note 13) A processing method for issuing a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and biometric information of the user, and reissuing the certificate held by the user using a second cancelable key issued by the specified issuing device and the biometric information of the user when reissuing the certificate.
[0077] (Supplementary Note 14) A processing method for issuing a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and biometric information of the user when receiving the service, and for reissuing the certificate held by the user using a second cancelable key issued by the terminal of the user and biometric information of the user when reissuing the certificate.
[0078] (Supplementary Note 15) A processing method according to Supplementary Note 13 or Supplementary Note 14, which includes issuing a certificate to which an electronic certificate signed using a private key of the issuer of the certificate is attached, issuing a public key corresponding to the private key, and verifying whether the certificate has been tampered with using the public key.
[0079] (Supplementary Note 16) The processing method according to Supplementary Note 13, wherein the first cancelable key is different for each of a plurality of service providers.
[0080] (Supplementary Note 17) The processing method described in any one of Supplementary Note 13 to Supplementary Note 16, wherein authentication is performed using an authentication certificate generated using biometric information acquired from the user and the first cancelable key, and a certificate held by the user.
[0081] (Supplementary Note 18) The processing method according to any one of Supplementary Note 13 to Supplementary Note 17, wherein the second cancelable key is generated based on the state of the first cancelable key, and a reissue of the certificate held by the user is requested.
[0082] (Supplementary Note 19) The processing method according to any one of Supplementary Note 13 to Supplementary Note 18, wherein authentication is performed using biometric information of the user when issuing a certificate, and a certificate held by the user is issued using the biometric information.
[0083] (Supplementary Note 20) A storage medium storing a program that causes a computer to function as an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and biometric information of the user, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the specified issuing device and the biometric information of the user when the certificate is reissued.
[0084] (Supplementary Note 21) A storage medium storing a program that causes a computer to function as an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and biometric information of the user when the service is received, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the terminal of the user and biometric information of the user when the certificate is reissued.
[0085] (Supplementary Note 22) A storage medium storing the program according to Supplementary Note 20, wherein the first cancelable key is different for each of a plurality of service providers.
[0086] (Supplementary Note 23) A storage medium storing a program according to any one of Supplementary Note 20 to Supplementary Note 22, which functions as a reissue request means for generating the second cancelable key based on the state of the first cancelable key and requesting reissue of the certificate held by the user.
[0087] (Supplementary Note 24) A storage medium storing a program according to any one of Supplementary Note 20 to Supplementary Note 23, wherein the issuing means performs authentication using biometric information of the user when issuing a certificate, and issues a certificate held by the user using the biometric information.
[0088] DESCRIPTION OF SYMBOLS 1... Issuing system 2... Terminal 3... Management device 4... Service providing system 11, 21, 41... Control unit 12, 22, 42... Transmitting / receiving unit 13... Certificate issuing unit 14... Registration unit 15... Reissue detection unit 23... Certificate management unit 24, 43... Key generation unit 44... Verification unit 45... Authentication unit 46... Service providing unit 50... Information processing device 51... Issuing means 100... Information processing system
Claims
1. An information processing system comprising an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and biometric information of the user, wherein the issuing means reissues the certificate held by the user using a second cancelable key issued by the specified issuing device and the biometric information of the user when the certificate is reissued.
2. An information processing system comprising an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and the user's biometric information when the service is received, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the terminal of the user and the user's biometric information when the certificate is reissued.
3. An information processing system according to claim 1 or claim 2, wherein the issuing means issues the certificate with an electronic certificate signed using the private key of the issuer of the certificate, issues a public key corresponding to the private key, and comprises a verifying means for verifying whether the certificate has been tampered with using the public key.
4. The information processing system according to claim 1, wherein the first cancelable key is different for each of a plurality of service providers.
5. An information processing system as described in claim 4, further comprising an authentication means for performing authentication using a certificate generated at the time of authentication using biometric information acquired from the user and the first cancelable key, and a certificate held by the user.
6. The information processing system according to claim 5, further comprising: a reissue request means for generating the second cancelable key based on the state of the first cancelable key and requesting the reissue of the certificate held by the user.
7. The information processing system according to claim 6, wherein the issuing means performs authentication using biometric information of the user when issuing a certificate, and issues a certificate held by the user using the biometric information.
8. An information processing device comprising an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and biometric information of the user, wherein the issuing means reissues the certificate held by the user using a second cancelable key issued by the specified issuing device and the biometric information of the user when reissuing the certificate.
9. An information processing device comprising an issuing means for issuing a certificate held by a user receiving a service using a first cancelable key issued by the terminal of the user receiving the service and the user's biometric information when the service is received, wherein the issuing means reissues the certificate held by the user using a second cancelable key issued by the terminal of the user and the user's biometric information when the certificate is reissued.
10. The information processing device according to claim 8, wherein the first cancelable key is different for each of a plurality of service providers.
11. The information processing device according to claim 10, further comprising: a reissue request means for generating the second cancelable key based on the state of the first cancelable key and requesting the reissue of the certificate held by the user.
12. The information processing device according to claim 11, wherein the issuing means performs authentication using biometric information of the user when issuing a certificate, and issues a certificate held by the user using the biometric information.
13. A processing method for issuing a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and the user's biometric information, and reissuing the certificate held by the user using a second cancelable key issued by the specified issuing device and the user's biometric information when reissuing the certificate.
14. A processing method for issuing a certificate held by a user receiving a service using a first cancelable key issued by the user's terminal and the user's biometric information when receiving the service, and for reissuing the certificate held by the user using a second cancelable key issued by the user's terminal and the user's biometric information when reissuing the certificate.
15. A storage medium storing a program that causes a computer to function as an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by a specified issuing device and the user's biometric information, and that causes the issuing means to reissue the certificate held by the user using a second cancelable key issued by the specified issuing device and the user's biometric information when reissuing the certificate.
16. A storage medium storing a program that causes a computer to function as an issuing means that issues a certificate held by a user receiving a service using a first cancelable key issued by the user's terminal and the user's biometric information when receiving the service, and the issuing means reissues the certificate held by the user using a second cancelable key issued by the user's terminal and the user's biometric information when reissuing the certificate.
Citation Information
Patent Citations
Certificate for authentication and terminal equipment
JP2004272551A
Information security authentication method and system
JP2008526173A
Method for registering biometric information in biometric authentication system, method for use application of template, and authentication method
JP2012003648A