Digital wallet management system and information processing system
The digital wallet management system addresses the vulnerability of single wallet pass systems by enabling multiple wallet passes for authentication, ensuring secure and reliable data output through dual verification processes.
Patent Information
- Application Number
- PCT/JP2025/023338
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-28
- Filing Date
- 2025-06-27
- Publication Date
- 2026-01-02
AI Technical Summary
Existing digital wallet systems allow only one wallet pass for authentication, making them vulnerable to misuse by malicious third parties impersonating legitimate users.
A digital wallet management system that allows multiple wallet passes, including a first and second wallet pass, to ensure reliable data output by acquiring and outputting information from both passes, with identity verification and authentication processes.
Ensures reliable data output by utilizing multiple wallet passes, enhancing security and reducing the risk of misuse by allowing simultaneous authentication and verification of multiple forms of identification.
Smart Images

Figure JP2025023338_02012026_PF_FP_ABST
Abstract
Description
Digital wallet management system and information processing system
[0001] The present disclosure relates to a digital wallet management system and an information processing system.
[0002] Patent Literature 1 discloses an authentication terminal that provides an authentication terminal that contributes to improving user convenience, and includes a first acquisition unit, a second acquisition unit, a control unit, and an authentication processing unit. The first acquisition unit acquires first biometric information of the user from another device when the distance between the device and the user reaches a first distance. The second acquisition unit acquires second biometric information of the user when the distance between the device and the user reaches a second distance. The control unit controls acquisition of authentication data required to determine whether to provide a service to the user from a terminal carried by the user. The authentication processing unit determines that the authentication process of the user has been successful when the result of a matching process using the first biometric information and the second biometric information is successful and the authentication data acquired from the terminal is valid.
[0003] International Publication No. 2023 / 053360
[0004] Patent Literature 1 describes the use of one digital wallet on a user's device in authentication processing. However, if only one digital wallet can be used in authentication processing, there is a concern that a malicious third party may misuse the digital wallet by impersonating the legitimate user. Therefore, there is room for improvement in terms of what kind of digital wallet should be allowed to be used in authentication processing for identity verification when receiving services.
[0005] The present disclosure has been devised in consideration of the above-mentioned conventional circumstances, and aims to provide a digital wallet management system and information processing system that can output information on multiple wallet passes, not just one wallet pass, to ensure the reliability of the data.
[0006] The present disclosure provides a digital wallet management system comprising: an input item acquisition unit that acquires input request items required by a service; an information acquisition unit that acquires item information based on the input request items; and an output unit that outputs the acquired item information, wherein when the input request items request first item information including a first wallet pass and second item information including a second wallet pass different from the first wallet pass, the information acquisition unit acquires the first item information from the first wallet pass and acquires the second item information from the second wallet pass, and the output unit outputs the first item information and the second item information.
[0007] The present disclosure also provides an information processing system that acquires information about a wallet pass stored in a user terminal, wherein the information processing system requests first item information including a first wallet pass and second item information including a second wallet pass different from the first wallet pass from the user terminal, and acquires information including at least the first item information and the second item information from the user terminal, and the information acquired from the user terminal is acquired by the user terminal acquiring the first item information from the first wallet pass and the second item information from the second wallet pass in response to a request from the information processing system, and outputting the first item information and the second item information to the information processing system.
[0008] According to the present disclosure, it is possible to output information on multiple wallet passes, rather than just one wallet pass, to ensure the reliability of the data.
[0009] 1. A block diagram showing an example of the configuration of a user terminal and a service server according to this embodiment. 2. A diagram showing an example of a sequence up to the input of item information executed between a user terminal and a service server according to this embodiment. 3. A diagram showing an example of a sequence up to the input of item information executed between a user terminal and a service server according to this embodiment. 4. A diagram showing an example of a sequence up to the input of item information executed between a user terminal and a service server according to this embodiment. 5. A diagram showing an example of input items displayed on the display unit of a user terminal according to this embodiment. 6. A diagram showing an example of item information linked to each wallet pass displayed on the display unit of a user terminal according to this embodiment. 7. A diagram showing an example of the display unit of a user terminal when performing identity verification according to this embodiment. 1 is a diagram showing an example of input items that have already been input; FIG. 2 is a diagram showing an example of the display unit of a user terminal when performing payment and date of birth authentication simultaneously according to this embodiment; FIG. 3 is a block diagram showing an example of the hardware configuration of a service server according to this embodiment; FIG. 4 is a block diagram showing another example of the configuration of a user terminal and a service server according to this embodiment; FIG. 5 is a block diagram showing another example of the configuration of a user terminal and a service server according to this embodiment;
[0010] Hereinafter, with reference to the drawings as appropriate, embodiments specifically disclosing the configuration and operation of a digital wallet management system and an information processing system according to the present disclosure will be described in detail. However, unnecessary detailed descriptions may be omitted. For example, detailed descriptions of well-known matters or redundant descriptions of substantially identical configurations may be omitted. This is to avoid unnecessary redundancy in the following description and to facilitate understanding by those skilled in the art. Note that the accompanying drawings and the following description are provided to enable those skilled in the art to fully understand the present disclosure and are not intended to limit the subject matter recited in the claims. Furthermore, unless otherwise specified, the order of the steps in the flow may be reversed.
[0011] (Embodiment) First, a user terminal 10 according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing an example of the configuration of a user terminal and a service server according to this embodiment. It goes without saying that the user terminal 10 and the relationship between the user terminal 10 and the service server 20 shown in Fig. 1 are merely examples and are not limited to these.
[0012] The user terminal 10 is an electronic terminal such as a smartphone or tablet terminal that can be carried by a user. The user terminal 10 includes a control unit 11, a storage unit 12, a communication unit 13, an authentication unit 14, and a display unit 15.
[0013] The control unit 11 is configured using, for example, a Central Processing Unit (CPU) or a Field Programmable Gate Array (FPGA), and performs various processes and controls in cooperation with the storage unit 12. Specifically, the control unit 11 references programs and data stored in the storage unit 12 and executes the programs to realize the functions of the user terminal 10. The control unit 11 controls the functions of the service app 111 and the digital ID wallet 112. Data within the service app 111 and the digital ID wallet 112 is stored in the storage unit 12 either encrypted or unencrypted.
[0014] The service application 111 is configured as a standalone application program and functionally includes an input item acquisition unit 1111, an information acquisition unit 1112, and an output unit 1113. The input item acquisition unit 1111 acquires input items required by the service (specifically, the service server 20). The input items referred to here are, for example, items that a user must enter when purchasing an item at an online shop, and may include name, address, telephone number, credit card number, etc. The information acquisition unit 1112 acquires item information based on the input items. The item information referred to here is actual data or information corresponding to each of the input items described above. The output unit 1113 outputs the item information acquired by the information acquisition unit 1112 to the user or the service server. The term "output" includes, for example, displaying the information on a display device such as a screen, transmitting the information to an external device at the communication destination, or storing the information in the external device at the communication destination.
[0015] The digital ID wallet 112 is configured as a single application program or application data referenced and used by the service application 111, and includes a wallet 112a and a wallet 112b.
[0016] Wallet 112a includes one or more wallet passes, such as a wallet pass for a student ID card (i.e., valid student ID data) that authentically proves that the user is a student if the user is a student, and a wallet pass for a license (i.e., valid license data) that authenticates a driver's license if the user holds such a license. Here, "valid" means that, for example, in the case of a student ID card, it is officially certified with a certification stamp or certificate officially issued by a business such as a school stamp, and that this state can be verified.
[0017] Wallet 112b also includes one or more wallet passes, such as a ticket wallet pass that certifies that a ticket has been legitimately purchased electronically through online shopping, etc., and an electronic payment wallet pass that certifies that payment has been legitimately made for the purchase of goods or services through online shopping or at a physical store, etc. Information linked to each wallet pass includes, for example, the license number, driving conditions, address, etc. for a driver's license, the company name, workplace contact number, etc. for an employee ID card, and personal identification data for a passport.
[0018] When the information acquisition unit 1112 determines that the requested input items request, for example, first item information including a wallet pass (student ID card in FIG. 1 ) and second item information including another wallet pass (driver's license in FIG. 1 ) different from the first wallet pass, the information acquisition unit 1112 acquires the first item information from the first wallet pass (student ID card) and the second item information from the second wallet pass (driver's license). The two different wallet passes may be in the same wallet or in different wallets.
[0019] The output unit 1113 outputs the first item information and the second item information by, for example, displaying them to the user or transmitting them to the service server 20. The first item information and the second item information may be output simultaneously.
[0020] The service application 111 may be an application integrated with the digital ID wallet 112 .
[0021] The memory unit 12 has, for example, a random access memory (hereinafter referred to as "RAM") as a work memory used when executing each process of the control unit 11, and a storage for storing programs and data that define the operation of the control unit 11. The RAM temporarily stores data or information generated or acquired by the control unit 11. The memory unit 12 may store encrypted data linked to the wallet pass.
[0022] The communication unit 13 communicates with the service server 20 wirelessly or wired. As shown in FIG. 1 , communication with the service server 20 may be via a network, or may be both. Wired communication corresponds to at least one of a wired local area network (hereinafter referred to as "LAN"), a wired wide area network (hereinafter referred to as "WAN"), and power line communication (PLC), and other network configurations capable of wired communication may also be used. On the other hand, wireless communication corresponds to at least one of a wireless LAN such as Wi-Fi (registered trademark), a wireless WAN, short-range communication such as NFC, and a mobile communication network such as 4G or 5G, and other network configurations capable of wireless communication may also be used.
[0023] The authentication unit 14 is, for example, a camera device that is pre-installed in the user terminal 10. The authentication unit 14 generates image information including the face of the user captured by the camera device.
[0024] The display unit 15 is a touch panel that detects input operations by the user and has a display function such as a screen, or a display that simply has a display function such as a screen.
[0025] The service server 20 is a computer device configured, for example, by a general-purpose personal computer or server computer. While the detailed configuration of the service server 20 is not illustrated, as it is a general-purpose computer device, it includes a processor, memory, and a communication unit connectable to a network. The service server 20 is a server for providing various services (e.g., car sharing membership registration, credit card application, real estate application, insurance application, online shop purchase, etc.). The service server 20 transmits input items required for the various applications described above to the user terminal 10 via a network. The service server 20 may be a general web server, a store payment terminal (manned or unmanned cash register), a reception terminal at a hospital or government office, etc.
[0026] An example of the hardware configuration of the service server 20 will now be described with reference to Fig. 10. Fig. 10 is a block diagram showing an example of the hardware configuration of the service server 20 according to the present embodiment. The service server 20 includes at least a control unit 21, a storage unit 22, a communication unit 23, a verification unit 24, and a display unit 25.
[0027] The control unit 21 is configured using, for example, a CPU or FPGA, and performs various processes and controls in cooperation with the storage unit 22. Specifically, the control unit 21 references programs and data stored in the storage unit 22 and executes the programs to realize each function of the service server 20. The control unit 21 controls the verification unit 24 to verify the authenticity of a wallet pass (e.g., a third wallet pass described later) sent from the user terminal 10, and obtains the verification result by the verification unit 24 and stores it in the storage unit 22.
[0028] The memory unit 22 includes, for example, a RAM as a work memory used when executing the processes of the control unit 21 and the verification unit 24, and a storage for storing programs and data that define the operation of the control unit 21. The RAM temporarily stores data or information generated or acquired by the control unit 21. The memory unit 22 may store, for example, the verification results by the verification unit 24.
[0029] The communication unit 23 communicates with the user terminal 10 wirelessly or wired. As shown in FIG. 1 , communication with the user terminal 10 may be via a network, or may be both. Wired communication may be, for example, at least one of a wired LAN, a wired WAN, and power line communication (PLC), or may be other network configurations capable of wired communication. On the other hand, wireless communication may be at least one of a wireless LAN such as Wi-Fi (registered trademark), a wireless WAN, short-range communication such as NFC, or a mobile communication network such as 4G or 5G, or may be other network configurations capable of wireless communication.
[0030] The verification unit 24 verifies the authenticity of a wallet pass (see below) sent from the user terminal 10 based on instructions from the control unit 21, and sends the verification result to the control unit 21 or stores it in the memory unit 22. The method of verifying authenticity itself may be performed using a well-known method (for example, public key cryptography or common key cryptography) for verifying that the wallet pass has not been tampered with, so a description of the verification method itself will be omitted here.
[0031] The display unit 25 is a touch panel that detects input operations by the user and has a display function such as a screen, or a display that simply has a display function such as a screen.
[0032] Next, other configuration examples of the user terminal 10 according to this embodiment will be described with reference to Figures 11 to 13. Figures 11 and 12 are block diagrams showing other examples of the configuration of the user terminal 10 and service server 20 according to this embodiment. Figure 13 is a block diagram showing the configuration example of Figure 1 in terms of a software layer structure. In the explanation of Figures 11 and 12, components that overlap with corresponding components in Figure 1 are given the same reference numerals, and explanations thereof are simplified or omitted, and differences will be explained.
[0033] The configuration example of Fig. 11 differs from the configuration example of Fig. 1 in that the digital ID wallet 112 directly holds and manages two wallet passes, which are the user's personal information: one with item information "ticket" and the other with item information "electronic payment." In other words, in Fig. 11, the digital ID wallet 112 holds and manages two wallet passes: one with item information "ticket" and the other with item information "electronic payment." Furthermore, in response to a request from the service app 111, the digital ID wallet 112 performs authentication such as user identity verification, verification of the authenticity of the wallet pass, and user selection permission, and then extracts and provides the item information of the selected wallet pass to the service app 111. Meanwhile, in the configuration example of Fig. 1, these wallet passes were held and managed by wallet 112b based on instructions from the digital ID wallet 112 (see Fig. 13).
[0034] Similarly, the configuration example of FIG. 12 differs from the configuration example of FIG. 1 in that the digital ID wallet 112 directly holds and manages four wallet passes, each of which is the user's personal information: a wallet pass with item information "student ID," a wallet pass with item information "driver's license," a wallet pass with item information "ticket," and a wallet pass with item information "electronic payment." In other words, in FIG. 12, the digital ID wallet 112 holds and manages a wallet pass with item information "student ID," a wallet pass with item information "driver's license," a wallet pass with item information "ticket," and a wallet pass with item information "electronic payment." Furthermore, in response to a request from the service app 111, the digital ID wallet 112 performs processes such as authentication of the user's identity, verification of the authenticity of the wallet pass, and permission for the user's selection, and then extracts and provides the item information of the selected wallet pass to the service app 111. In contrast, in the configuration example of FIG. 1, these wallet passes were held and managed by wallets 112a and 112b, respectively, based on instructions from the digital ID wallet 112 (see FIG. 13).
[0035] FIG. 13 illustrates the software layer structure of the exemplary configuration illustrated in FIG. 1 . That is, in the user terminal 10, the communication unit 13 that communicates data with the service server 20 is illustrated as the top layer, followed by a service application 111 or a browser 111a, such as a web application, that inputs and outputs data to and from the communication unit 13, as the next layer. Note that the browser 111a may be provided as an example of the service application 111. Next, the digital ID wallet 112 that inputs and outputs data to and from the service application 111 or the browser 111a is illustrated as the next layer. Finally, wallets 112a and 112b that input and output data to and from the digital ID wallet 112 are illustrated as the lowest layer. Note that the wallet 112a is not necessarily under the control of the digital ID wallet 112. The digital ID wallet 112 and the wallet 112a are independent applications and may be linked via a known interface. A wallet pass may be added to the wallet 112a without going through the digital ID wallet 112. Furthermore, the wallet 112a may be capable of presenting and using a wallet pass managed by the wallet 112a without going through the digital ID wallet 112.
[0036] 11 is assumed instead of Fig. 1, wallet 112b in Fig. 13 is not provided, and a total of two wallet passes, one with item information "ticket" and the other with item information "electronic payment", are held and managed in digital ID wallet 112. Similarly, when the configuration example in Fig. 12 is assumed instead of Fig. 1, neither of wallets 112a nor 112b in Fig. 13 is provided, and a total of four wallet passes, one with item information "student ID card", one with item information "license", one with item information "ticket", and one with item information "electronic payment", are held and managed in digital ID wallet 112.
[0037] Next, a sequence up to the input of item information executed between a user terminal and a service server will be described with reference to Figures 2 to 4. Figure 2 is a diagram showing an example of a sequence up to the input of item information executed between a user terminal and a service server according to this embodiment. Figure 3 is a diagram showing an example of a sequence up to the input of item information executed between a user terminal and a service server according to this embodiment. Figure 4 is a diagram showing an example of a sequence up to the input of item information executed between a user terminal and a service server according to this embodiment.
[0038] First, a case where the service application 111 of the user terminal 10 determines the wallet pass to be referenced will be described. As shown in Fig. 2, the user first accesses the service server 20 using the user terminal 10 (step ST1). Then, based on the access in step ST1, the service server 20 requests the service application 111 of the user terminal 10 to input items corresponding to the access from the user terminal 10 (step ST2). The service application 111 requests item information from one or more digital ID wallets 112 corresponding to the input items requested in step ST2 (step ST3).
[0039] In order to respond to the request from the service application 111, the digital ID wallet 112 requests the user's approval for the service application 111 to access the digital ID wallet 112 (step ST4). This request can be realized, for example, by the digital ID wallet 112 generating a notification screen for requesting the user's approval for access and displaying the notification screen on the display unit 15. When the user approves the access to the digital ID wallet 112 (step ST5), the service application 111 acquires information associated with the digital ID wallet 112 and stored in the storage unit 12 (step ST6). Note that although it has been described here that the actual data corresponding to the digital ID wallet 112 is stored in the storage unit 12, the digital ID wallet 112 itself may store the actual data.
[0040] The service application 111 inquires of the user about whether or not to send information to the service server 20 (step ST7), and the user performs an input process to confirm (step ST8). After this, the service application 111 transmits information for input items based on the information acquired from the digital ID wallet 112 to the service server 20 based on the input process of step ST8 (step ST9). At this time, the input items may be automatically input into an input form on the website of the service server 20, or may be transmitted directly to the service server 20. Note that it is not necessary to input all of the input items requested by the service server 20 using information from the digital ID wallet 112; the user may input any missing items. The same applies to FIGS. 3 and 4.
[0041] In this way, the information acquisition unit 1112 identifies the item information to be acquired based on the acquired input request items, and if there are two or more wallet paths from which the identified item information is to be acquired, it may acquire the item information from each of the multiple wallet paths, or, as described below, it may acquire a new wallet path P1 (see Figure 14) generated by the digital ID wallet 112 by integrating the respective item information.
[0042] Next, a case where a user determines a wallet pass to reference will be described. Also, in FIG. 3 , user identity verification is also performed. As shown in FIG. 3 , the user first accesses the service server 20 using the user terminal 10 (step ST11). Based on the access in step ST1, the service server 20 requests the service application 111 of the user terminal 10 to input items corresponding to the access from the user terminal 10 (step ST12). Based on the request in step ST12, the service application 111 generates a screen (not shown) for inquiring about the wallet pass to reference from the user and displays it on the display unit 15 (step ST13). The user looks at the screen (not shown) displayed on the display unit 15 and performs an input operation to specify the wallet pass to reference (step ST14). At this time, the user may specify multiple wallet passes. The service application 111 requests information from the digital ID wallet 112 specified by the user based on the input operation in step ST14 (step ST15).
[0043] In order to respond to the request from the service application 111, the digital ID wallet 112 requests the user to verify his / her identity (step ST16). When the user authenticates the digital ID wallet 112 (step ST17), the service application 111 acquires information associated with the digital ID wallet 112 and stored in the storage unit 12 (step ST18). The service application 111 inquires of the user about whether or not to transmit information to the service server 20 (step ST19). When the user confirms (step ST20), the service application 111 transmits to the service server 20 input items based on the information acquired from the digital ID wallet 112 (step ST21).
[0044] In this way, the information acquisition unit 1112 may perform identity verification on the user, and when the identity verification is approved, acquire item information from each of the multiple wallet passes.
[0045] Next, a case where the service server 20 determines the wallet pass to be referenced will be described. Also, in FIG. 4, user identity verification is also performed. As shown in FIG. 4, the user first accesses the service server 20 using the user terminal 10 (step ST21). Then, based on the access in step ST31, the service server 20 notifies the service application 111 of the user terminal 10 of a list of multiple wallet passes to be referenced and input items (step ST22). The service application 111 inquires of the user about the wallet pass to be referenced (step ST23), and the user specifies the wallet pass to be referenced (step ST24). The service application 111 requests information from the digital ID wallet 112 specified by the user (step ST25).
[0046] In order to respond to the request from the service application 111, the digital ID wallet 112 requests the user to verify his / her identity (step ST26). When the user authenticates the digital ID wallet 112 (step ST27), the service application 111 acquires information associated with the digital ID wallet 112 and stored in the storage unit 12 (step ST28). The service application 111 inquires of the user about whether or not to transmit information to the service server 20 (step ST29). When the user confirms (step ST30), the service application 111 transmits to the service server 20 input items based on the information acquired from the digital ID wallet 112 (step ST31).
[0047] From the perspective of the service server 30, the service server 30 is an information processing system that acquires information about wallet passes stored in the user terminal 10, and the information processing system (service server 20) requests the user terminal 10 for first item information contained in a first wallet pass and second item information contained in a second wallet pass different from the first wallet pass, and acquires information including at least the first item information and the second item information from the user terminal.The information acquired from the user terminal 10 may be acquired by the user terminal acquiring the first item information from the first wallet pass and the second item information from the second wallet pass in response to a request from the information processing system, and outputting the first item information and the second item information to the information processing system (service server 20).
[0048] Next, the display flow of the display unit 15 of the user terminal 10 will be described with reference to Figs. 5 to 9. Fig. 5 is a diagram showing an example of input items displayed on the display unit of the user terminal according to this embodiment. Fig. 6 is a diagram showing an example of item information linked to each wallet pass displayed on the display unit of the user terminal according to this embodiment. Fig. 7 is a diagram showing an example of the display unit of the user terminal when performing identity verification according to this embodiment. Fig. 8 is a diagram showing an example of input items displayed on the display unit of the user terminal according to this embodiment. Fig. 9 is a diagram showing an example of the display unit of the user terminal when performing payment and date of birth authentication simultaneously according to this embodiment.
[0049] The user opens a website linked to the service server 20 as shown in FIG. 5 and selects identity verification. The service server 20 requests input using identity verification from the user terminal 10. Input using identity verification means inputting information into input fields after verifying the user's identity as shown in FIGS. 2 and 3. When the service application 111 accepts the request, FIG. 6 is displayed, prompting the user to select a digital wallet. In FIG. 6, the service application 111 asks the user whether or not it is OK to obtain information to be entered into input fields from the digital ID wallet 112. The user selects a wallet pass, etc., from which data may be obtained and presses the "Agree and Share" button. The data to be shared is data linked to a health insurance card or employee ID. In this way, data can be obtained from multiple wallet passes and entered into input fields.
[0050] Then, identity verification can be performed as shown in Fig. 7. That is, identity verification can be performed by, for example, generating an image of the user using the authentication unit 14, which is a camera of the user terminal 10, and comparing the image with a face image of the user that is pre-linked to the wallet pass from which information is to be obtained and stored. That is, identity verification can be performed based on biometric information linked to the wallet pass from which information is to be obtained and biometric information obtained from the user. Furthermore, the biometric information linked to the wallet pass from which data is to be obtained may be face information, and the biometric information obtained from the user may be image information including an image of the user's face.
[0051] Once identity verification is complete, the data acquired from the wallet pass is entered into the input items and displayed as shown in Fig. 8. If the data acquired from the wallet pass alone is not enough to enter all the information, the user may enter the information manually. When the input item acquisition unit 1111 acquires an input form, the information acquisition unit 1112 may input item information corresponding to the input form based on the data acquired from multiple wallet passes.
[0052] Furthermore, once identity verification is complete, as shown in Figure 9, when making payments at stores, medical institutions, etc., the cashless payment app registered in the wallet and the user's driver's license can be used to verify the user's date of birth at the same time.
[0053] Next, with reference to FIG. 14 , the item information of the wallet pass transmitted from the user terminal 10 to the service server 20 will be described. FIG. 14 is a diagram showing an example of a wallet pass transmitted from the user terminal 10 to the verification terminal 200. In FIG. 14 , the verification terminal 200 may be the service server 20 shown in FIG. 1 , FIG. 11 , or FIG. 12 , or may be a store server operated by the store used by the user. In either case, the verification terminal 200 is a terminal used by the user to make a payment when the user uses the user terminal 10 to pay for a provided service. As shown in FIG. 14 , item information of the wallet pass, which is personal information unique to the user, is transmitted from the user terminal 10 to the verification terminal 200 at the time of payment.
[0054] When the user terminal 10 transmits item information of a wallet pass, which is personal information unique to the user, to the service server 20, the digital ID wallet 112 generates a wallet pass P1 by integrating the wallet pass of the wallet 112 whose item information is "student ID" and the wallet pass whose item information is "ticket." Furthermore, the digital ID wallet 112 sends a request to the service app 111 to transmit the wallet pass P1 generated by the integration to the service server 20. In response to this request, the service app 111 transmits the wallet pass P1 to the service server 20 via the communication unit 13. This allows the service server 20 to collectively verify the authenticity of the wallet pass P1 integrated in the user terminal 10. In other words, the service server 20 does not need to verify the wallet pass for "student ID" and the wallet pass for "ticket" separately, thereby simplifying the verification process.
[0055] Next, a sequence up to transmission and reception of wallet pass item information executed between the user terminal 10 and the service server 20 will be described with reference to Figures 15 and 16. Figures 15 and 16 are diagrams showing another example of a sequence up to input of item information executed between the user terminal 10 and the service server 20 according to this embodiment. In the description of Figures 15 and 16, the same processes as the corresponding processes in Figure 2 are assigned the same step numbers, and the description is simplified or omitted, and different contents will be described.
[0056] 15, first, a user accesses the service server 20 using the user terminal 10 (step ST1). Based on the access in step ST1, the service server 20 requests the service application 111 of the user terminal 10 to input items corresponding to the access from the user terminal 10 (step ST2). The service application 111 instructs the digital ID wallet 112 to acquire item information of the wallet pass corresponding to the input items requested in step ST2.
[0057] In response to an instruction from the service application 111, the digital ID wallet 112 requests the user's approval for the service application 111 to access the digital ID wallet 112 (step ST4). This request can be realized, for example, by the digital ID wallet 112 generating a notification screen for requesting the user's approval for access and displaying it on the display unit 15. If the user approves access to the digital ID wallet 112 (step ST5), the digital ID wallet 112 requests information about the item information of the wallet pass corresponding to the input items from each managed wallet (e.g., wallet 112a) (step ST11). The digital ID wallet 112 acquires information about the item information of the wallet pass corresponding to the input items based on the request in step ST11 (step ST12). If information related to multiple wallet passes is requested, information may be acquired from the multiple wallet passes in steps ST11 and ST12, and the multiple wallet passes may be managed by different wallets 112a, 112b, or digital ID wallet 112.
[0058] In step ST5, the authorization for the user to access the digital ID wallet 112 may include an authentication process to confirm whether the user has legitimate authority. For example, facial recognition, fingerprint recognition, passcode recognition, or a combination thereof may be used to determine whether the user has legitimate authority. This makes it difficult to fraudulently use the wallet pass stored in the user terminal 10.
[0059] Note that a person with legitimate authority is not limited to the owner of the user terminal 10. Whether or not a person has legitimate authority may be determined based on authentication information (e.g., facial information or other authentication information) stored in the wallet pass.
[0060] Furthermore, the authority may be determined based on a person other than the person associated with the wallet pass. For example, a wallet pass (such as a student ID card) associated with a minor may be stored in the parent's user terminal 10. In this case, the parent's biometric authentication may also be used to determine whether the person has legitimate authority.
[0061] It should be noted that there may be cases where the data is provided without determining whether it has legitimate authority, such as when there is no need to verify authenticity. Also, by setting this in advance in the user terminal 10 or the digital ID wallet 112 or wallet 112a, the data may be provided without determining whether it has legitimate authority.
[0062] The digital ID wallet 112 inquires whether or not it is OK to send the information acquired in step ST12 to the service server 20 (step ST7), and the user performs an input process to confirm (step ST8). After this, the digital ID wallet 112 instructs the service application 111 to send information for input items that are based on the information acquired from the digital ID wallet 112 and that are judged to be OK to send based on the input process of step ST8. The service application 111 transmits the information for input items that are based on the information acquired from the digital ID wallet 112 and that are judged to be OK to send based on the input process of step ST8 to the service server 20 via the communication unit 13 (step ST9).
[0063] In step ST7, information acquired from multiple wallet passes may be displayed on a single interface for selection. Items that must be sent may be displayed in a manner that distinguishes between items that are optional and items that must be sent.
[0064] In addition, by setting the user terminal 10 or the digital ID wallet 112 or wallet 112a in advance, the provision of information may always be permitted or rejected without requiring the user to make a selection, or the user may be asked to confirm whether to permit or reject the provision of information on a conditional basis.
[0065] When the service server 20 receives the information for the input items transmitted in step ST9, it provides the corresponding service (e.g., payment, service usage) based on the information. The service server 20 may verify the authenticity based on the received information and determine whether to provide the service based on the result. At this time, the digital ID wallet 112 may include information for verifying the authenticity in the information it transmits. For example, the information it transmits may include an encrypted token or one-time password corresponding to the corresponding service. In verifying the authenticity, the service server 20 may verify the authenticity by inquiring of the issuer of the credential information associated with the received information.
[0066] The description of FIG. 16 will focus on the differences from the description of FIG.
[0067] 16, after step ST12, the digital ID wallet 112 verifies the authenticity of each of the item information (see FIG. 11 or 12) of the wallet acquired in step ST12 or the wallet pass stored in the digital ID wallet 112 (ST13). The authenticity verification by the digital ID wallet 112 may be the same as or different from the authenticity verification performed by the service server 20, and in either case, any known method may be used as appropriate. If the digital ID wallet 112 determines in step ST13 that the authenticity verification of the item information of each wallet pass has been successful, it executes the processing of step ST7.
[0068] Here, the authenticity may be verified by verifying the authenticity of the wallet pass from which the information was obtained. By verifying the authenticity of only the information confirmed by the user to be provided, the resources required for verification can be reduced. If the wallet pass includes a facial image associated with the wallet pass, features corresponding to the facial image, or other information indicating biometric information, this information may be used to determine whether the user has legitimate authority. The digital ID wallet 112 may verify the authenticity of the wallet pass based on the information obtained in step ST12. For example, the authenticity of the wallet pass may be verified using the wallet pass issuer, a certification authority, or a blockchain.
[0069] After step ST8, the digital ID wallet 112 instructs the service application 111 to transmit information for input items based on the information acquired from the digital ID wallet 112 that was determined to be transmittable based on the input processing in step ST8. At this time, if there is a plurality of pieces of information (item information) acquired from the digital ID wallet 112 that was determined to be transmittable, the digital ID wallet 112 stores and forms a wallet pass that integrates each piece of information (item information) (step ST14). Thereafter, the digital ID wallet 112 instructs the service application 111 to transmit information for input items based on the item information of the wallet pass formed in step ST14. The service application 111 transmits the item information of the wallet pass formed in step ST14 to the service server 20 via the communication unit 13 (step ST9).
[0070] When the service server 20 receives the information of the input items sent in step ST9, it comprehensively verifies the authenticity of that information (i.e., the wallet pass that integrates multiple information items), and if the verification result is successful, it provides the corresponding service (e.g., payment, service use).
[0071] (Additional Notes) The above description of the embodiments discloses the following techniques.
[0072] (Item 1) A digital wallet management system (service app 111) comprising: an input item acquisition unit (1111) that acquires input items required by a service; an information acquisition unit (1112) that acquires item information based on the input items; and an output unit (1113) that outputs the acquired item information to a user or a service server (20), wherein when the input items request first item information including a first wallet pass and second item information including a second wallet pass different from the first wallet pass, the information acquisition unit acquires the first item information from the first wallet pass and acquires the second item information from the second wallet pass, and the output unit 1113 outputs the first item information and the second item information to the user or the service server. With this configuration, the digital wallet management system can output information on multiple wallet passes, not just one wallet pass.
[0073] (Item 2) The digital wallet management system according to Item 1, wherein the output unit 1113 simultaneously outputs the first item information and the second item information to the user or the service server 20. With this configuration, the digital wallet management system can simultaneously output information on multiple wallet passes, rather than just one wallet pass.
[0074] (Item 3) The digital wallet management system according to Item 1 or 2, wherein the information acquisition unit performs identity verification on the user, and when the identity verification is approved, acquires the first item of information from the first wallet pass, and acquires the second item of information from the second wallet pass. With this configuration, the digital wallet management system can safely output information on multiple wallet passes, not just one wallet pass.
[0075] (Item 4) The digital wallet management system according to Item 1 or 2, wherein the information acquisition unit identifies item information to be acquired based on the acquired input request items, and when there are two or more wallet passes from which the identified item information is to be acquired, acquires the first item information from the first wallet pass and acquires the second item information from the second wallet pass. With this configuration, the digital wallet management system can output information on multiple wallet passes more accurately, rather than just information on one wallet pass.
[0076] (Item 5) The digital wallet management system according to any one of Items 2 to 4, wherein when the input acquisition unit acquires an input form, the information acquisition unit inputs item information corresponding to the input form based on the first item information and the second item information. With this configuration, the digital wallet management system can easily output information about not only one wallet pass but also multiple wallet passes.
[0077] (Item 6) The digital wallet management system according to Item 3, wherein the information acquisition unit 1112 performs the identity verification based on biometric information linked to the first wallet pass and biometric information acquired from the user. With this configuration, the digital wallet management system can output information on multiple wallet passes more safely, rather than just information on one wallet pass.
[0078] (Item 7) The digital wallet management system according to Item 6, wherein the biometric information linked to the first wallet pass is face information, and the biometric information acquired from the user is image information including an image of the user's face. With this configuration, the digital wallet management system can output highly confidential information of multiple wallet passes more safely, rather than just information of a single wallet pass.
[0079] (Item 8) The digital wallet management system according to any one of Items 1 to 7, wherein the output unit generates a third wallet pass by integrating the first item information acquired from the first wallet pass and the second item information acquired from the second wallet pass, and sends the third wallet pass to an information processing system that provides the service. With this configuration, the digital wallet management system can send the item information of the third wallet pass, which is the integration of the first item information and the second item information, to the information processing system, and can perform authenticity verification processing on the information processing system side using the item information of the third wallet pass, thereby simplifying the verification processing.
[0080] (Item 9) The digital wallet management system according to Item 8, further comprising a wallet pass management unit (e.g., digital ID wallet 112) that manages the first wallet pass and the second wallet pass, wherein the wallet pass management unit verifies the authenticity of the first wallet pass and the second wallet pass in response to the request from the information acquisition unit, and if the verification is successful, integrates the first item information acquired from the first wallet pass and the second item information acquired from the second wallet pass to generate the third wallet pass. With this configuration, the digital wallet management system can verify the authenticity of each of the item information of the first wallet pass and the item information of the second wallet pass on the wallet pass management unit side, and can integrate the item information into the third wallet pass if the verification of authenticity is successful.
[0081] (Item 10) The digital wallet management system according to Item 9, wherein the wallet pass management unit stores item information that is permitted to be transmitted to the information processing system by a user operation from among the first item information and the second item information integrated into the third wallet pass. With this configuration, the digital wallet management system can transmit to the information processing system only the first item information and second item information that have been successfully verified by the wallet pass management unit and that have been permitted by the user.
[0082] (Item 11) An information processing system (service server 20) that acquires wallet pass information stored in a user terminal (10), wherein the information processing system requests first item information including a first wallet pass and second item information including a second wallet pass different from the first wallet pass from the user terminal, acquires information including at least the first item information and the second item information from the user terminal, and the information acquired from the user terminal is acquired by the user terminal acquiring the first item information from the first wallet pass and acquiring the second item information from the second wallet pass in response to a request from the information processing system, and outputting the first item information and the second item information to the information processing system. With this configuration, the information processing system can output information on multiple wallet passes, not just one wallet pass.
[0083] Although various embodiments have been described above with reference to the accompanying drawings, the present disclosure is not limited to such examples. It is clear that those skilled in the art can conceive of various modifications, alterations, substitutions, additions, deletions, and equivalents within the scope of the claims, and it is understood that these also fall within the technical scope of the present disclosure. Furthermore, the components of the various embodiments described above may be combined in any manner without departing from the spirit of the invention.
[0084] This application is based on a Japanese patent application (Patent Application No. 2024-105199) filed on June 28, 2024, the contents of which are incorporated herein by reference.
[0085] The present disclosure is useful as a digital wallet management system and information processing system that can output information on multiple wallet passes, not just one wallet pass, to ensure the reliability of the data.
[0086] REFERENCE SIGNS LIST 10 User terminal 11 Control unit 111 Service application 1111 Input item acquisition unit 1112 Information acquisition unit 1113 Output unit 112 Digital ID wallet 112a Wallet 112b Wallet 12 Storage unit 13 Communication unit 14 Authentication unit 15 Display unit 20 Service server 21 Control unit 22 Storage unit 23 Communication unit 24 Verification unit 25 Display unit
Claims
1. A digital wallet management system comprising: an input item acquisition unit that acquires input required items for requesting a service; an information acquisition unit that acquires item information based on the input required items; and an output unit that outputs the acquired item information, wherein when the input required items request first item information including a first wallet pass and second item information including a second wallet pass different from the first wallet pass, the information acquisition unit acquires the first item information from the first wallet pass and acquires the second item information from the second wallet pass, and the output unit outputs the first item information and the second item information.
2. The digital wallet management system according to claim 1, wherein the output unit simultaneously outputs the first item information and the second item information to the user or a service server that provides the service.
3. The digital wallet management system of claim 1 or 2, wherein the information acquisition unit performs identity verification on the user, and when the identity verification is approved, acquires the first item of information from the first wallet pass and acquires the second item of information from the second wallet pass.
4. The digital wallet management system of claim 1 or 2, wherein the information acquisition unit identifies item information to be acquired based on the acquired input request items, and if there are two or more wallet paths from which the identified item information is to be acquired, acquires the first item information from a first wallet path among the two or more destination wallet paths, and acquires the second item information from a second wallet path among the two or more destination wallet paths.
5. A digital wallet management system as described in claim 1 or 2, wherein when the input item acquisition unit acquires an input form requesting input from a user, the information acquisition unit inputs item information corresponding to the input form based on the first item information and the second item information.
6. The digital wallet management system according to claim 3, wherein the information acquisition unit performs the identity verification based on biometric information linked to the first wallet pass and biometric information acquired from the user.
7. The digital wallet management system described in claim 6, wherein the biometric information linked to the first wallet pass is facial information, and the biometric information obtained from the user is image information including a captured image of the user's face.
8. The digital wallet management system of claim 1, wherein the output unit generates a third wallet pass by integrating the first item information acquired from the first wallet pass and the second item information acquired from the second wallet pass, and sends the third wallet pass to an information processing system that provides the service.
9. The digital wallet management system according to claim 8, further comprising a wallet pass management unit that manages the first wallet pass and the second wallet pass, wherein the wallet pass management unit verifies the authenticity of the first wallet pass and the second wallet pass in response to the request from the information acquisition unit, and if the verification is successful, generates the third wallet pass by integrating the first item information acquired from the first wallet pass and the second item information acquired from the second wallet pass.
10. The digital wallet management system described in claim 9, wherein the wallet pass management unit stores item information from the first item information and the second item information integrated into the third wallet pass that is permitted to be sent to the information processing system by user operation.
11. An information processing system that acquires information about a wallet pass stored in a user terminal, wherein the information processing system requests first item information including a first wallet pass and second item information including a second wallet pass different from the first wallet pass from the user terminal, and acquires information including at least the first item information and the second item information from the user terminal in response to a request from the information processing system, by the user terminal acquiring the first item information from the first wallet pass and acquiring the second item information from the second wallet pass, and outputting the first item information and the second item information to the information processing system.
Citation Information
Patent Citations
Receiving fingerprints through touch screen of ce device
JP2016071878A
Biometric information authentication system and method using financial card information stored in a mobile communication terminal
JP2019504384A
Authentication terminal, system, method and program
JP2023051799A
Generating and utilizing a digital pass with user verification and autofill formatted data
US20210064725A1
System and method for generating notifications based on digital wallet pass data
US20220284418A1