Terminal, system, terminal control method, and storage medium

The terminal provides a selection, acquisition, and storage solution for credential certificates, addressing the challenge of managing multiple digital wallets by allowing users to choose the storage location, thereby simplifying the process and reducing user burden.

WO2026062754A1PCT designated stage Publication Date: 2026-03-26NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Users face difficulty in selecting the appropriate digital wallet from multiple wallets to store a requested credential certificate, leading to increased burden in managing certificates.

Method used

A terminal equipped with a selection means, acquisition means, and storage means that allows users to choose the digital wallet for storing credential certificates, thereby reducing the burden of managing multiple digital wallets.

Benefits of technology

Enables users to easily select and store credential certificates in their preferred digital wallet, simplifying the management of multiple digital wallets and reducing user burden.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024033189_26032026_PF_FP_ABST
    Figure JP2024033189_26032026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a terminal that contributes to reducing the burden on a user of the terminal for managing certificates by using a plurality of digital wallets. The terminal comprises a selection means, an acquisition means, and a storage means. When receiving, from a first service provider, a notification that a credential certificate has been issued, the selection means enables the user to select a digital wallet storing the issued credential certificate from among the plurality of digital wallets. The acquisition means acquires the issued credential certificate. The storage means stores the acquired credential certificate in the digital wallet selected by the user.
Need to check novelty before this filing date? Find Prior Art

Description

Terminal, System, Method for Controlling Terminal, and Storage Medium

[0001] The present invention relates to a terminal, a system, a method for controlling a terminal, and a storage medium.

[0002] There is a technology related to the authenticity determination of digital certificates.

[0003] For example, Patent Document 1 discloses a guarantee badge display system that generates a digital certificate file that guarantees the authenticity of predetermined matters regarding a user and guarantees that the digital certificate file is authentic and has not been tampered with.

[0004] Japanese Patent No. 7443036

[0005] Multiple digital wallets may be generated on a user's terminal. In such a case, a user who is requested by a service provider to submit a certificate (digital certificate; for example, a credential certificate) needs to select a digital wallet in which the requested certificate is stored from among the multiple digital wallets. However, if a certificate acquired by a terminal such as a smartphone is automatically stored in any digital wallet, it is difficult for the user to select the digital wallet in which the requested certificate is stored from among the multiple digital wallets.

[0006] A main object of the present invention is to provide a terminal, a system, a method for controlling a terminal, and a storage medium that contribute to reducing the burden on a user of a terminal that manages certificates using multiple digital wallets.

[0007] According to a first aspect of the present invention, when receiving a notification that a credential certificate has been issued from a first service provider, there is provided a selection means that enables a user to select a digital wallet in which the issued credential certificate is to be stored from among multiple digital wallets, an acquisition means that acquires the issued credential certificate, and a storage means that stores the acquired credential certificate in the digital wallet selected by the user.

[0008] A second aspect of the present invention provides a system comprising a first service provider's certificate issuing device and a terminal, wherein the terminal, upon receiving notification from the certificate issuing device that a credential certificate has been issued, includes a selection means that enables the user to select a digital wallet from among a plurality of digital wallets to store the issued credential certificate, an acquisition means for acquiring the issued credential certificate, and a storage means for storing the acquired credential certificate in the digital wallet selected by the user.

[0009] A third aspect of the present invention provides a terminal control method comprising: a selection step, which enables the user to select a digital wallet to store the issued credential certificate from among a plurality of digital wallets upon receiving notification from a first service provider that a credential certificate has been issued; an acquisition step, which acquires the issued credential certificate; and a storage step, which stores the acquired credential certificate in the digital wallet selected by the user.

[0010] A fourth aspect of the present invention is provided, a computer-readable storage medium is provided that stores a program for causing a computer installed in a terminal to execute the following: a selection process, which enables the user to select a digital wallet from among a plurality of digital wallets to store the issued credential certificate when it receives notification from a first service provider that a credential certificate has been issued; an acquisition process, which acquires the issued credential certificate; and a storage process, which stores the acquired credential certificate in the digital wallet selected by the user.

[0011] According to each aspect of the present invention, a terminal, a system, a method for controlling the terminal, and a storage medium are provided that contribute to reducing the burden on users of a terminal that manages certificates using multiple digital wallets. However, the effects of the present invention are not limited to those described above. The present invention may provide other effects in lieu of or in conjunction with the effects described above.

[0012] Figure 1 is a diagram illustrating the outline of one embodiment. Figure 2 is a flowchart of the operation of one embodiment. Figure 3 is a diagram showing an example of the schematic configuration of an information processing system according to an embodiment of this disclosure. Figure 4 is a diagram showing an example of the display of a terminal according to an embodiment of this disclosure. Figure 5 is a diagram illustrating the operation of an information processing system according to an embodiment of this disclosure. Figure 6 is a diagram illustrating the operation of an information processing system according to an embodiment of this disclosure. Figure 7 is a diagram illustrating the operation of an information processing system according to an embodiment of this disclosure. Figure 8 is a diagram illustrating the operation of an information processing system according to an embodiment of this disclosure. Figure 9 is a diagram showing an example of the processing configuration of a terminal according to an embodiment of this disclosure. Figure 10 is a flowchart illustrating an example of the operation of an acquisition control unit according to an embodiment of this disclosure. Figure 11 is a diagram showing an example of the processing configuration of a server device according to an embodiment of this disclosure. Figure 12 is a diagram showing an example of the processing configuration of a business terminal according to an embodiment of this disclosure. Figure 13 is a flowchart illustrating an example of the operation of a service provision control unit according to an embodiment of this disclosure. Figure 14 is a sequence diagram showing an example of the operation of an information processing system according to an embodiment of this disclosure. Figure 15 is a sequence diagram showing an example of the operation of an information processing system according to an embodiment of this disclosure. Figure 16 is a diagram showing an example of the display of a terminal according to an embodiment of this disclosure. Figure 17 is a diagram showing an example of the display of a terminal according to the embodiment of this disclosure. Figure 18 is a diagram showing an example of the display of a terminal according to the embodiment of this disclosure. Figure 19 is a diagram showing an example of the hardware configuration of a business terminal according to this disclosure. Figure 20 is a diagram showing an example of the hardware configuration of a terminal according to this disclosure.

[0013] First, an overview of one embodiment will be described. The reference numerals in the drawings attached to this overview are provided for convenience as examples to aid understanding, and this overview is not intended to be limiting in any way. Furthermore, unless otherwise specified, the blocks shown in each drawing represent functional units, not hardware units. The connecting lines between blocks in each drawing include both bidirectional and unidirectional lines. Unidirectional arrows schematically indicate the flow of the main signal (data) and do not exclude bidirectional flow. In this specification and in the drawings, elements that can be similarly described are given the same reference numerals to avoid redundant explanation.

[0014] A terminal 100 according to one embodiment includes a selection means 101, an acquisition means 102, and a storage means 103 (see Figure 1). When the selection means 101 receives notification from a first service provider that a credential certificate has been issued, it enables the user to select a digital wallet from among multiple digital wallets to store the issued credential certificate (step S1 in Figure 2). The acquisition means 102 acquires the issued credential certificate (step S2). The storage means 103 stores the acquired credential certificate in the digital wallet selected by the user (step S3).

[0015] When terminal 100 receives notification that a credential certificate has been issued, it controls the terminal so that the user can select the storage location for the issued credential certificate from among the multiple digital wallets installed on the terminal. Terminal 100 stores the credential certificate in the digital wallet selected by the user. In this way, users of terminal 100 can choose the storage location for the credential certificate issued by the first service provider. Because users can choose the digital wallet to store the credential certificate themselves, they can easily select the digital wallet that stores the credential certificate requested by the service provider. As a result, the burden on terminal users who manage certificates using multiple digital wallets is reduced.

[0016] Specific embodiments will be described in more detail below with reference to the drawings.

[0017] [First Embodiment] The first embodiment will be described in more detail with reference to the drawings.

[0018] [System Configuration] As shown in Figure 3, the information processing system according to the first embodiment includes at least one certificate issuer and at least one service provider.

[0019] A certificate issuer is the entity that issues certificates to users. For example, a certificate issuer issues certificates that prove the user's "identity" or "attributes." For example, a certificate issuer issues an identification card that proves the user's name, gender, date of birth, address, etc. Alternatively, a certificate issuer issues certificates that prove the user's "rights" or "qualifications."

[0020] For example, public institutions that issue identification documents such as driver's licenses, passports, and My Number cards are considered certificate issuers. Alternatively, businesses that provide services to users (customers) are also considered certificate issuers. For example, businesses that sell airline tickets, train tickets, concert tickets, etc. are considered certificate issuers.

[0021] Each certificate issuer is provided with a server device 10. The server device 10 is a server that performs the processing and operations necessary to carry out the certificate issuer's business. The server device 10 may be managed and operated by the certificate issuer, or its management and operation may be entrusted to another business operator, etc. The server device 10 may be installed in the certificate issuer's building, or it may be installed on a network (on the cloud).

[0022] A service provider is a business that provides services to users. For example, a business that sells tickets is a service provider. Or a credit card company that provides credit services is a service provider. Or a business that operates a theme park or holds concerts is a service provider. Or a business that operates transportation such as railways, buses, and airplanes is a service provider. Or a business such as a retail store or restaurant is a service provider. Service providers are not limited to private companies; public institutions such as city halls are also included as service providers in the disclosure of this application.

[0023] Depending on the industry and business type of the service provider, the same company may act as both a certificate issuer and a service provider.

[0024] For example, a credit card company issues a credit card that proves that the user is eligible to enjoy credit services. A credit card company is both the issuer of the certificate that issues the credit card and the service provider that provides the credit service.

[0025] Each service provider is equipped with a service server 20 and a service terminal 21 for providing services to users. For example, the service server 20 provides services to users via a website. For example, the service server 20 provides online services to users without requiring instructions or operations from the service provider's employees (the service server 20 provides services automatically and autonomously).

[0026] Alternatively, employees of the service provider may operate the service provider terminal 21 to provide services to users. The service provider terminal 21 may be a personal computer, a tablet, a POS (Point of Sale) terminal, or a digital signage terminal.

[0027] Alternatively, the service server 20 and the service provider terminal 21 may be connected, and the service provider's employees may provide services to users while referring to information stored on the service server 20 via the service provider terminal 21.

[0028] Furthermore, the service provider's equipment (business terminal 21, service server 20) related to this disclosure generates at least the verification result certificate described later and issues the generated verification result certificate to the user. Therefore, the business terminal 21 and service server 20 are equipped with the function of certificate issuing devices.

[0029] The user possesses terminal 30. For example, the user operates terminal 30 to request (demand) the issuance of a certificate from a certificate issuer. The user also uses terminal 30 to provide the service provider with information requested by the service provider.

[0030] Each device shown in Figure 3 is connected to a network. Specifically, the server device 10, service server 20, carrier terminal 21, and terminal 30 are connected to the network by wired or wireless communication means.

[0031] The configuration of the information processing system shown in Figure 3 is illustrative and not intended to limit its configuration. For example, the server devices 10 of each certificate issuer and the devices of the service provider (service server 20, business terminal 21) may belong to different networks. Alternatively, each certificate issuer may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10. Similarly, each service provider may include multiple service servers 20 and multiple business terminals 21.

[0032] [Outline of Operation] Next, the outline of the operation of the information processing system according to the first embodiment will be described.

[0033] <Preparing the Digital Wallet> The user's terminal 30 is equipped with a digital wallet function. A digital wallet is an electronic information storage service that guarantees information security, including data integrity, reliability, and availability.

[0034] The user installs an application on their device 30 to implement a digital wallet. By opening a digital wallet on device 30, the user can store various digital content on device 30, such as identification documents like My Number cards, employee IDs, and student IDs, tickets like airline tickets and concert tickets, electronic money, and credit cards.

[0035] <Acquisition of Digital Content> Users who have opened a digital wallet will acquire the digital content to be stored in that digital wallet.

[0036] The user operates terminal 30 to request the issuance of a certificate from the certificate issuer. Specifically, the digital wallet application requests the issuance of a certificate from the certificate issuer. The certificate issuer issues VCs (Verifiable Credentials) as certificates, which can be verified online. In the following explanation, VCs will be referred to as "credential certificates".

[0037] Furthermore, specific certificates issued as credential documents will be indicated by adding "VCs" after the name of the certificate. For example, a My Number Card issued as a credential document will be written as "My Number Card VCs".

[0038] By obtaining credential certificates from each certificate issuer, the user's terminal 30 stores digital content, such as that shown in Figure 4. In the following explanation, unless otherwise specified, the content stored in the digital wallet is the credential certificate.

[0039] <Procedure for obtaining a credential certificate> First, we will explain how to obtain a credential certificate.

[0040] Prior to the request for issuing a credential certificate, the user's terminal 30 generates a pair of public and private keys. Further, the terminal 30 generates a decentralized identifier (DID). The terminal 30 registers the generated DID (user ID; holder ID) and the public key in the blockchain (step S01 in FIG. 5).

[0041] Furthermore, while presenting the user ID, the user's terminal 30 requests the credential certificate issuer (server device 10) to issue a credential certificate. Specifically, the terminal 30 transmits a "certificate issuance request" including information about the certificate to be issued (e.g., the type of the credential certificate), information identifying the object to be proved by the credential certificate, the user ID, etc. to the server device 10 (step S02).

[0042] Note that the server device 10 generates, in advance, the DID (issuer ID), private key, and public key of the issuer and stores them.

[0043] Upon receiving the certificate issuance request, the certificate issuer determines whether it is possible to issue the credential certificate desired by the user.

[0044] If it is possible to issue the credential certificate desired by the user, the server device 10 generates a credential certificate including the issuer ID and the user ID.

[0045] Specifically, the server device 10 generates a credential certificate including metadata such as the type of the credential certificate, the name of the issuing organization, the issue date and time, the expiration period, etc., the claim content (qualification information, claim), and proofs such as the public key information and digital signature of the issuer. Note that the specific information to be proved by the issuer is described in the claim content.

[0046] The server device 10 provides the generated credential certificate to the user's terminal 30 (the user who becomes the holder of the certificate; the requester of the certificate issuance) (step S03).

[0047] Specifically, the server device 10 stores the generated credential certificate in the online storage. The server device 10 generates a certificate acquisition URL from the URL (Uniform Resource Locator) of the storage destination of the credential certificate. The server device 10 transmits an affirmative response (response to the certificate issuance request) including the generated certificate acquisition URL to the terminal 30.

[0048] Further, the server device 10 registers the issuer ID and the generated public key, etc. in the blockchain (step S04).

[0049] The terminal 30 accesses the certificate acquisition URL included in the affirmative response to acquire the credential certificate. The terminal 30 stores the acquired credential certificate in the digital wallet.

[0050] <Service enjoyment> When the credential certificate is stored in the digital wallet, the user can receive the service provided by the service provider using the stored credential certificate. At that time, the user provides the service provider with the credential certificate required by the service provider (the credential certificate necessary for the service provider to provide the service).

[0051] Specifically, the device of the service provider (the business operator terminal 21 or the service server 20) transmits a "certificate providing request" to the terminal 30 possessed by the user (step S11 in FIG. 6). The certificate providing request describes information regarding at least one or more credential certificates necessary for the service provider to provide the service.

[0052] For example, the certificate providing request describes information for specifying the credential certificate required by the service provider. For example, when the service provider requests the provision of an identity certificate VCs, information such as the types of identity certificates such as "My Number Card" and "Driver's License" is included in the certificate providing request.

[0053] Upon receiving a request for a certificate, terminal 30 transmits the credential certificate stored in the digital wallet to the business terminal 21, etc. Specifically, terminal 30 selects the designated credential certificate from among multiple credential certificates stored in the digital wallet.

[0054] Subsequently, terminal 30 signs the selected credential certificate using the private key corresponding to the user's DID (User ID). Terminal 30 transmits the signed credential certificate and the user's DID (User ID) to the service provider terminal 21 (step S12). The signed credential certificate is sometimes referred to as a VP (Verifiable Presentation).

[0055] The operator terminal 21, etc., verifies the acquired credential certificate. At that time, the operator terminal 21, etc., obtains the public key from the blockchain (step S13). Further details regarding the verification of the credential certificate will be described later.

[0056] After verifying the acquired credential certificate, the service provider provides the service to the user. At that time, the service provider terminal 21 notifies employees, etc., of the information obtained from the acquired credential certificate, and the service server 20 uses the information obtained from the credential certificate to determine whether or not to provide the service.

[0057] <Issuance of Verification Result Certificates (VCs)> Here, when the service provider verifies the credential certificate obtained from the user, it issues a certificate regarding the verification result (verification record) of the obtained credential certificate. More specifically, the service provider's certificate issuing device (business terminal 21, service server 20) issues a verification result certificate in the form of a credential certificate, which certifies the verification result of the obtained credential certificate. That is, the service provider's certificate issuing device issues a credential certificate which certifies the verification result of the credential certificate obtained from the user.

[0058] In the following explanation, the credential certificates obtained by a service provider from a user in order to provide a service will be referred to as "Credential Certificates VCs." Furthermore, the credential certificates that the service provider uses to certify (guarantee) the verification results of the obtained credential certificates will be referred to as "Verification Result Certificates VCs." The recipient (holder) of the Verification Result Certificates VCs is the user who provided the Credential Certificates VCs.

[0059] Specifically, the service provider's devices (business terminal 21, service server 20) verify the acquired certificate VCs and generate verification result certificate VCs that prove the result. The business terminal 21, etc., stores the generated verification result certificate VCs in online storage and generates a URL for obtaining the certificate.

[0060] The service provider terminal 21, etc., transmits a "certificate issuance notification" to terminal 30, which includes information on acquired certificates (VCs) and the generated URL for obtaining the certificate (step S14 in Figure 6). The information on acquired certificates (VCs) includes the type of credential certificate verified by the service provider.

[0061] Terminal 30 accesses the URL for obtaining the certificate included in the certificate issuance notification and obtains the verification result certificates (VCs). Terminal 30 stores the obtained verification result certificates (VCs) in its digital wallet. At the same time, Terminal 30 stores the information of the credential certificate that the obtained verification result certificates (VCs) are verifying (such as the type of credential certificate verified by the service provider) in association with the obtained verification result certificates (VCs).

[0062] Furthermore, Verification Result Certificates (VCs) may not only certify the verification results of Acquisition Certificates (VCs), but may also be certificates that certify qualifications related to the service provider's services.

[0063] Users can receive services from other service providers by providing them with verification result certificates (VCs) obtained from the service provider.

[0064] <Specific Example 1> This section explains a specific example of a credential certificate (verification result certificate VCs) that proves the verification results of acquisition certificates VCs.

[0065] For example, at time A shown in Figure 7, the user obtains a My Number Card VCs from local government A. Subsequently, at time B, the user visits a retail store to purchase alcohol or tobacco. When selling products such as alcohol or tobacco that have age restrictions, the retail store requests the user to provide their My Number Card VCs for age verification.

[0066] Specifically, the business terminal 21 installed at retail store B sends a "certificate provision request" to the user's terminal 30, requesting the provision of My Number Card VCs.

[0067] Terminal 30 transmits the My Number Card VCs stored in the digital wallet to the business terminal 21 in response to the receipt of the certificate provision request.

[0068] The business terminal 21 verifies the acquired My Number Card VCs. The business terminal 21 notifies the staff of retail store B of the verification results and information obtained from the My Number Card VCs (for example, the user's age). The staff of retail store B decide whether or not to provide the service (whether or not to sell alcohol and tobacco) based on the information they are notified of.

[0069] Furthermore, if retailer B verifies the My Number Card VCs, it will issue a verification result certificate VCs regardless of whether the service is provided or not (time C in Figure 7). Note that the time between time B and time C is extremely short.

[0070] The service provider's service server 20 issues verification result certificates (VCs) whose claimed content (credential information body) includes the following items: • Issuer information of the acquisition certificate VCs • Claims made by the acquisition certificate VCs • Verification date and time of the acquisition certificate VCs • Verification result at the verification date and time of the acquisition certificate VCs • Issuance date of the acquisition certificate VCs • Expiration date of the acquisition certificate VCs • Verifier information at the verification date and time of the acquisition certificate VCs

[0071] Furthermore, verification certificates (VCs), like regular credential certificates, include metadata such as the issuance date and time and validity period of the verification certificate VC, as well as proof such as the issuer's public key information and digital signature.

[0072] In the example of the sale of alcoholic beverages and tobacco at the above-mentioned retail store B, the business terminal 21 of retail store B issues a Verification Result Certificate (VCs) with the following claim details: • Issuer information of the My Number Card VCs: Local government A • Claim details of the My Number Card VCs: Name, gender, date of birth, address, facial image • Verification date and time of the My Number Card VCs: August 6, 2024, 10:10 AM • Verification result at the time of the My Number Card VCs verification: Verification successful • Issuance date of the My Number Card VCs: January 10, 2024 • Expiration date of the My Number Card VCs: January 10, 2034 • Verifier information at the time of the My Number Card VCs verification: Retail store B

[0073] The user's terminal 30 stores the issued verification result certificates VCs in its digital wallet. More specifically, the terminal 30 remembers that the acquired verification result certificates VCs are verification result certificates VCs related to the verification results of My Number Card VCs.

[0074] <Specific Example 2> Next, we will explain the case where the Verification Result Certificate (VCs) not only proves the verification result of the Acquisition Certificate (VCs), but also serves as proof of qualifications related to the services provided by the service provider.

[0075] Here, we will explain using the example of a credit card company issuing credit card VCs. Similar to the first example, the user obtains a My Number Card VC from local government A (time A in Figure 8).

[0076] The user accesses the service server 20 of credit card company C to obtain a credit card. The service server 20 of credit card company C obtains the user's My Number Card VCs to verify the user's identity (time B).

[0077] The service server 20 of credit card company C verifies the My Number Card VCs and determines whether or not to provide the service (issue the credit card) based on the results.

[0078] If it is determined that the service can be provided, the service server 20 of credit card company C issues credit card VCs (time C in Figure 8). The credit card VCs issued by the credit card company also function as verification result certificate VCs, which are used by credit card company C to certify the verification results of the My Number Card VCs.

[0079] The credit card company's service server 20 issues credit card VCs that include credit card information (cardholder information, expiration date, card type, etc.) and the claims of the verification result certificates VCs shown in Specific Example 1.

[0080] For example, a credit card company's service server 20 issues a Verification Result Certificate (VC) with claims including the following items: • Credit card information: Taro Yamada, August 10, 2029, Gold Card • Issuer information for My Number Card VCs: Local Government A • Claims on My Number Card VCs: Name, gender, date of birth, address, facial image • Verification date and time of My Number Card VCs: August 10, 2024, 9:00 AM • Verification result at the time of My Number Card VCs verification: Verification successful • Issuance date of My Number Card VCs: January 10, 2024 • Expiration date of My Number Card VCs: January 10, 2034 • Verifier information at the time of My Number Card VCs verification: Credit card company C

[0081] The user's terminal 30 stores the issued credit card VCs in its digital wallet. More specifically, the terminal 30 remembers that the acquired credit card VCs are also verification result certificates VCs related to the verification results of the My Number Card VCs.

[0082] Furthermore, if a service provider does not provide a service to a user, the service provider will issue a Verification Result Certificate (VC) that does not have the function of certifying the service provided by the service provider. For example, if credit card company C successfully verifies the My Number Card VC but there is a problem with the user's creditworthiness, the service provider will not provide the service (will not issue a credit card). In this case, instead of issuing a credit card VC, credit card company C will issue a Verification Result Certificate (VC) that does not contain credit card information.

[0083] <Use of Verification Result Certificates (VCs)> Verification Result Certificates (VCs) are used in the same way as other credential certificates.

[0084] For example, a service provider that only needs to confirm that a valid My Number Card has been issued when providing a service may request users to provide a Verification Result Certificate (VC) that proves the verification result of the My Number Card VCs. For example, service provider D, which holds an event for My Number Card holders, may request users to provide a Verification Result Certificate (VC) that proves the verification result of the My Number Card VCs.

[0085] The user's terminal 30 provides the service provider D with verification result certificates VCs in response to a request from the service provider D (time D in Figures 7 and 8). In specific example 2, credit card VCs that function as verification result certificates VCs are provided to the service provider D.

[0086] Service provider D determines that a user possesses a valid My Number Card VCs based on the fact that a third party (in the above example, a retail store or credit card company) has successfully verified the My Number Card VCs. In other words, service provider D can omit obtaining the My Number Card VCs themselves from the user, or omit the verification of the My Number Card VCs. Furthermore, depending on service provider D's policy, it may not even be necessary to verify the verification result certificate VCs.

[0087] For example, consider the case in Figure 8 where a user wishes to purchase goods such as alcohol or tobacco using credit card VCs. In this case, the service provider D's terminal 21 requests the user (terminal 30) to provide credit card VCs accompanied by the verification results of the identity document VCs, in response to an operation by a store employee or other person.

[0088] Terminal 30 provides service provider D with credit card VCs (credit card VCs acquired at time C) which also function as verification result certificate VCs for My Number Card VCs.

[0089] Service provider D's terminal 21 verifies the acquired credit card VCs. If the verification is successful, the terminal 21 uses the information on the My Number Card VCs, which the credit card VCs use to prove the verification result, to determine whether or not it is possible to sell the goods to the user. Specifically, the terminal 21 uses the verification result of the My Number Card VCs and the claimed information (for example, the user's date of birth) to determine whether or not it is possible to sell the goods to the user.

[0090] If the product is available for sale (i.e., the user is 20 years of age or older), service provider D (business terminal 21) will settle the payment for the product using credit cards VCs.

[0091] Thus, service provider D can determine whether or not to provide the service using the results of credit card company C's verification of My Number Card VCs and the information presented on the My Number Card VCs (e.g., date of birth). In other words, service provider D can assume that My Number Card VCs have been presented upon presentation of a credit card VC, and therefore does not need to acquire or verify My Number Card VCs.

[0092] Next, we will describe the details of each device included in the information processing system according to the first embodiment.

[0093] [Terminal] Figure 9 is a diagram showing an example of the processing configuration (processing module) of a terminal 30 according to the embodiment disclosed herein. Referring to Figure 9, the terminal 30 comprises a communication control unit 201, an acquisition control unit 202, a utilization control unit 203, and a storage unit 204.

[0094] The communication control unit 201 is a means for controlling communication with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes the data received from other devices to other processing modules. The communication control unit 201 transmits the data acquired from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 201. The communication control unit 201 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.

[0095] Furthermore, the communication control unit 201 also supports short-range wireless communication such as Bluetooth® and NFC (Near Field Communication). The communication control unit 201 communicates with the carrier terminal 21 using short-range wireless communication.

[0096] The digital wallet application is implemented by the acquisition control module 202 and the utilization control module 203. A detailed explanation of the installation of the digital wallet application is omitted, as its installation is obvious to those skilled in the art.

[0097] The acquisition control unit 202 is a means for controlling the acquisition of credential certificates. The acquisition control unit 202 requests the certificate issuer to issue the certificate selected by the user and stores the certificate obtained from the certificate issuer in the digital wallet.

[0098] Figure 10 is a flowchart showing an example of the operation of the acquisition control unit 202. The operation of the acquisition control unit 202 according to the embodiment disclosed herein will be explained with reference to Figure 10.

[0099] When a user who has opened a digital wallet launches the digital wallet application and performs a predetermined action (for example, pressing the certificate issuance button), the acquisition control unit 202 performs control related to the acquisition of the credential certificate desired by the user.

[0100] First, the acquisition control unit 202 generates a public key and a private key pair, and a distributed identifier, which is a user ID (user's DID). The acquisition control unit 202 registers the generated user ID and public key on the blockchain (registering the public key, etc.; step S101).

[0101] Next, the acquisition control unit 202 uses a GUI or the like to acquire the information necessary for requesting the issuance of a credential certificate (acquisition of necessary information; step S102).

[0102] Specifically, the acquisition control unit 202 acquires information about the certificate issuer who has the authority to issue the credential certificate that the user wishes to have issued (e.g., name of the local government, company name, university name, ticket vendor name), the type of certificate desired, etc. Furthermore, the acquisition control unit 202 acquires information that the certificate issuer uses to identify the person to be certified (e.g., employee number, student ID number, or name or combination of name and date of birth, etc.).

[0103] The acquisition control unit 202 notifies the certificate issuer of the necessary information and user ID that it has acquired. Specifically, the acquisition control unit 202 notifies the certificate issuer of the type of credential certificate, information to identify the subject of certification, and the user ID.

[0104] The acquisition control unit 202 sends a "certificate issuance request" including the type of credential certificate, information identifying the subject of certification, and user ID to the server device 10 of the certificate issuer selected by the user (step S103).

[0105] The acquisition control unit 202 receives a response (affirmative response, negative response) to the certificate issuance request from the server device 10 (step S104).

[0106] If a negative response is received indicating that the issuance of the certificate failed (step S105, No branch), the acquisition control unit 202 notifies the user that the credential certificate was not issued (notification of non-issuance; step S106).

[0107] If an affirmative response indicating that the certificate has been successfully issued is received (step S105, Yes branch), the acquisition control unit 202 accesses the certificate acquisition URL included in the affirmative response and acquires the credential certificate issued by the certificate issuer (step S107).

[0108] The acquisition control unit 202 stores the acquired credential certificate in the digital wallet (step S108).

[0109] The acquisition control unit 202 processes the certificate issuance notification received from the service provider's certificate issuing device (business terminal 21, service server 20). Specifically, the acquisition control unit 202 accesses the certificate acquisition URL included in the notification to obtain verification result certificates VCs, etc. The acquisition control unit 202 stores the obtained verification result certificates VCs, etc. in the digital wallet.

[0110] At that time, the acquisition control unit 202 also stores information about the credential certificate that the verification result certificate VCs are certifying (for example, the type of credential certificate). For example, the acquisition control unit 202 stores correspondences such as "Verification Result Certificate VCs (1): My Number Card VCs" and "Credit Card VCs: My Number Card VCs".

[0111] The usage control unit 203 is a means for controlling the use of digital content (credential certificates) stored in the digital wallet.

[0112] The usage control unit 203 provides the service provider with a certificate stored in the digital wallet that is specified by the service provider, in response to a request from the service provider.

[0113] Specifically, the user control unit 203 processes certificate provision requests received from the service provider's equipment (service terminal 21, service server 20).

[0114] Upon receiving a request for a certificate, the user control unit 203 selects the credential certificate specified by the service provider from among the multiple credential certificates stored in the digital wallet. Subsequently, the user control unit 203 signs the selected credential certificate using the private key corresponding to the user's DID (User ID).

[0115] Furthermore, the user control unit 203 signs the credential certificate using the private key (the private key corresponding to the user ID) generated when issuing the credential certificate requested by the service provider. For example, when a My Number Card VCs is submitted, the user control unit 203 signs the My Number Card VCs using the private key corresponding to the user ID transmitted to the local government's server device 10.

[0116] If the credential certificate specified by the service provider can be provided, the user control unit 203 sends an affirmative response to the service provider terminal 21, etc., including the signed credential certificate and the user ID. If the credential certificate specified by the service provider cannot be provided, the user control unit 203 sends a negative response to the service provider terminal 21, etc., indicating that the credential certificate cannot be provided.

[0117] The user control unit 203 may create a user ID, public key, and private key pair each time it receives a certificate provision request, and register the user ID and public key on the blockchain. The user control unit 203 may also transmit the generated user ID to the business terminal 21 or the like.

[0118] The memory unit 204 is a means for storing information necessary for the operation of the terminal 30.

[0119] [Server Device] Figure 11 is a diagram showing an example of the processing configuration (processing module) of the server device 10 according to the embodiment disclosed herein. Referring to Figure 11, the server device 10 comprises a communication control unit 301, a certificate issuing unit 302, and a storage unit 303.

[0120] The communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 30. The communication control unit 301 also transmits data to the terminal 30. The communication control unit 301 passes the data received from other devices to other processing modules. The communication control unit 301 transmits the data acquired from other processing modules to other devices. In this way, other processing modules send and receive data with other devices via the communication control unit 301. The communication control unit 301 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.

[0121] The certificate issuing unit 302 is a means of issuing credential certificates to users. The certificate issuing unit 302 processes the "certificate issuance request" received from the terminal 30.

[0122] Upon receiving a certificate issuance request, the certificate issuance unit 302 searches a database (not shown in Figure 11, etc.) that stores user information, using information to identify the item to be certified included in the certificate issuance request (for example, employee number, etc.) as a key.

[0123] If the above search fails, the certificate issuing unit 302 sends a negative response to the terminal 30 indicating that the certificate has not been issued.

[0124] If the above search is successful, the certificate issuing unit 302 will, if necessary, determine whether or not it is possible to issue the credential certificate that the user wishes to have issued.

[0125] For example, if a user requests the issuance of a My Number Card VCs, the certificate issuance unit 302 determines whether or not the user meets the requirements for receiving a My Number Card VCs.

[0126] Detailed explanations regarding the determination of whether or not to issue a credential certificate are omitted, as the requirements for issuing individual credential certificates differ from the intent of this disclosure.

[0127] If it is not possible to issue a credential certificate to the user, the certificate issuing unit 302 sends a negative response to the terminal 30 indicating that the certificate issuance failed (certificate cannot be issued).

[0128] If it is possible to issue a credential certificate to the user, the certificate issuing unit 302 generates a credential certificate to be issued to the user. The certificate issuing unit 302 generates a credential certificate that includes the issuer ID and the user ID (DID of the recipient of the certificate; the user ID included in the certificate issuance request).

[0129] Specifically, the certificate issuing unit 302 generates a credential certificate that includes metadata such as the type of credential certificate, the name of the issuing organization, the date and time of issuance, and the validity period, as well as the claims and a proof consisting of the issuer's public key information and digital signature. The digital signature affixed to the credential certificate is performed using a private key corresponding to the issuer ID that was generated in advance.

[0130] The certificate issuing unit 302 stores the generated credential certificate in online storage (cloud storage), etc. The certificate issuing unit 302 generates a certificate retrieval URL from the URL where the credential certificate is stored. The certificate issuing unit 302 sends an acknowledgment containing the generated certificate retrieval URL to the terminal 30. Furthermore, the certificate issuing unit 302 registers the previously generated issuer ID and public key, etc., on the blockchain.

[0131] The memory unit 303 is a means for storing information necessary for the operation of the server device 10.

[0132] [Carrier Terminal] Figure 12 is a diagram showing an example of the processing configuration (processing module) of a carrier terminal 21 according to the embodiment disclosed herein. Referring to Figure 12, the carrier terminal 21 comprises a communication control unit 401, a service provision control unit 402, and a storage unit 403.

[0133] The communication control unit 401 is a means for controlling communication with other devices. For example, the communication control unit 401 receives data (packets) from the terminal 30. The communication control unit 401 also transmits data to the terminal 30. The communication control unit 401 passes the data received from other devices to other processing modules. The communication control unit 401 transmits the data acquired from other processing modules to other devices. In this way, other processing modules transmit and receive data with other devices via the communication control unit 401. The communication control unit 401 has the function of a receiving unit that receives data from other devices and the function of a transmitting unit that transmits data to other devices.

[0134] The service provision control unit 402 is a means for performing control related to the services provided to the user.

[0135] The service provision control unit 402 has the functions of an acquisition means, a generation means, and an issuing means. The acquisition means acquires a first credential certificate from the user. The generation means verifies the first credential certificate and generates a verification result certificate that proves the verification result of the first credential certificate. The issuing means issues the generated verification result certificate to the user. More specifically, the generation means generates a second credential certificate as a verification result certificate that proves the verification result of the first credential certificate.

[0136] When a user requests the provision of a service, the service provision control unit 402 obtains the credential certificate necessary for providing the service.

[0137] Figure 13 is a flowchart showing an example of the operation of the service provision control unit 402 according to the embodiment disclosed herein. The operation of the service provision control unit 402 will be explained with reference to Figure 13.

[0138] The service provision control unit 402 sends a "certificate provision request" to the terminal 30 (step S201). The service provision control unit 402 sends a certificate provision request to the terminal 30 that includes information identifying the required credential certificate (for example, the type of credential certificate).

[0139] If a negative response (inability to provide the certificate) is received from terminal 30 (step S202, No branch), the service provision control unit 402 notifies the user, etc., that the service cannot be provided because the necessary information cannot be obtained (step S203).

[0140] If the terminal 30 receives an acknowledgment (a response including a credential certificate) (step S202, Yes branch), the service provision control unit 402 verifies the credential certificate included in the acknowledgment (step S204).

[0141] The service provision control unit 402 verifies at least one of the three items related to the validity of the credential certificate.

[0142] The first item is the verification of the electronic signature attached to the credential certificate.

[0143] In this case, the service provision control unit 402 obtains the issuer ID and user ID listed on the credential certificate. The service provision control unit 402 obtains the public key corresponding to the obtained issuer ID from the blockchain. Similarly, the service provision control unit 402 obtains the public key corresponding to the obtained user ID from the blockchain.

[0144] The service provision control unit 402 verifies the signature of the holder (the user requesting the service) and the signature of the issuer attached to the credential certificate. By verifying these signatures, the service provision control unit 402 confirms that the credential certificate obtained from the user (the holder of the credential certificate) has not been tampered with and that it was issued by a trustworthy issuer.

[0145] The service provision control unit 402 determines that the verification of the credential certificate has been successful if it successfully verifies the signatures of both the holder and the issuer of the credential certificate. The service provision control unit 402 determines that the verification of the credential certificate has failed if it fails to verify the signature of at least one of the holder or issuer of the credential certificate.

[0146] The second item is to verify that the credential certificate has not been set to invalid.

[0147] In this case, the service provision control unit 402 accesses the blockchain and verifies that the received credential certificate is not listed in the certificate issuer's revocation list. The service provision control unit 402 also verifies that the credential certificate obtained from the user has not been invalidated by the issuer before its expiration date.

[0148] The service provision control unit 402 determines that the verification of the acquired credential certificate was successful if the credential certificate is not listed in the revocation list. The service provision control unit 402 determines that the verification of the acquired credential certificate failed if the credential certificate is listed in the revocation list.

[0149] The third item is verification that the validity period (expiration date) of the credential certificate has not expired.

[0150] The service provision control unit 402 checks the validity period set on the credential certificate. If the validity period set on the credential certificate has not expired, the service provision control unit 402 determines that the verification of the acquired credential certificate was successful. If the validity period set on the credential certificate has expired, the service provision control unit 402 determines that the verification of the acquired credential certificate failed.

[0151] The service provision control unit 402 determines that the verification of the credential certificate obtained from the user has been successful if it determines that "verification was successful" in one of the predetermined items from the first to third items.

[0152] The service provision control unit 402 determines that the verification of the credential certificate obtained from the user has failed if it determines that "verification failed" in one of the predetermined items from the first to third items.

[0153] Once the verification of the credential certificate is complete, the service provision control unit 402 performs control related to the provision of the service (step S205).

[0154] For example, if the verification of the credential certificate fails, the service provision control unit 402 will notify the service provider's employees or other relevant personnel accordingly.

[0155] Alternatively, if the credential certificate is successfully verified, the service provision control unit 402 will notify the employee of all or part of the claims obtained from the credential certificate. For example, if a My Number Card VCs is obtained, the service provision control unit 402 may notify the employee of the user's age (date of birth) obtained from the My Number Card VCs.

[0156] Alternatively, the service provision control unit 402 may automatically determine whether or not to provide the service based on the claims obtained from the credential certificate.

[0157] Detailed explanations regarding the determination of whether or not to provide individual services are omitted, as such determinations are outside the scope of this disclosure.

[0158] Furthermore, even if a Verification Result Certificate (VCs) is obtained, the Service Provision Control Unit 402 processes it in the same way as a regular credential certificate. The Service Provision Control Unit 402 may also determine whether or not to provide the service based on the claims made in the Verification Result Certificate (VCs).

[0159] Once the verification of the credential certificate is complete, the service provision control unit 402 generates verification result certificates VCs that prove the verification result of the credential certificate (acquisition certificate VCs) (step S206). The service provision control unit 402 generates a second credential certificate (verification result certificate VCs) regardless of whether the verification of the first credential certificate (acquisition certificate VCs) was successful or not.

[0160] Specifically, the service provision control unit 402 issues verification result certificates VCs whose claims include the following items. The service provision control unit 402 generates a credential certificate that includes at least one of the following items as its claims: • Issuer information of the acquisition certificate VCs • Claims of the acquisition certificate VCs • Verification date and time of the acquisition certificate VCs • Verification result at the verification date and time of the acquisition certificate VCs • Issuance date of the acquisition certificate VCs • Expiration date of the acquisition certificate VCs • Verifier information at the verification date and time of the acquisition certificate VCs

[0161] Furthermore, if the service provider's service involves the issuance of a credential certificate, the service provision control unit 402 sets the above information in the claims of the issued credential certificate. That is, the service provision control unit 402 may generate (issue) a third credential certificate that is related to the service provided to the user and certifies the verification result of the first credential certificate.

[0162] When verification result certificates VCs are generated, the service provision control unit 402 issues the verification result certificates VCs (step S207). Specifically, the service provision control unit 402 stores the generated verification result certificates VCs in online storage and generates a certificate acquisition URL. The service provision control unit 402 sends a certificate issuance notification to the user's terminal 30, which includes information about the acquired certificates VCs and the generated certificate acquisition URL.

[0163] The memory unit 403 is a means for storing information necessary for the operation of the business terminal 21.

[0164] [Service Server] A detailed explanation of the configuration and operation of the service server 20 is omitted. The basic configuration and operation of the service server 20 can be the same as that of the carrier terminal 21. The carrier terminal 21 communicates with terminal 30 via short-range wireless communication such as Bluetooth® to obtain credential certificates. In contrast, the service server 20 communicates with terminal 30 via a communication network such as the Internet to obtain credential certificates. When the service server 20 verifies the credential certificates necessary for providing the service, it issues verification result certificates VCs to the user, which certify the verification result of the credential certificates.

[0165] The operator terminal 21 and the service server 20 operate as certificate issuing devices that issue verification result certificates VCs.

[0166] [System Operation] Next, the operation of the information processing system according to the first embodiment will be described.

[0167] Figure 14 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment disclosed herein. Referring to Figure 14, the operation relating to the issuance of a credential certificate of the information processing system according to the first embodiment will be described.

[0168] Terminal 30 generates a public key, a private key, and a user ID, and registers the user ID and public key on the blockchain (step S21).

[0169] Terminal 30 sends a certificate issuance request including the above-mentioned user ID to the certificate issuer's server device 10 (step S22).

[0170] The server device 10 generates the user's (the recipient of the credential certificate) claims (claims, qualification information) and generates a credential certificate containing the generated claims (step S23). The server device 10 generates a credential certificate that includes the user ID and issuer ID and is electronically signed.

[0171] The server device 10 provides the generated credential certificate to the terminal 30 by storing it in online storage or the like (step S24).

[0172] Terminal 30 obtains a credential certificate according to the URL for obtaining the certificate and stores the obtained credential certificate in the digital wallet (step S25).

[0173] Figure 15 is a sequence diagram showing an example of the operation of the information processing system according to the embodiment disclosed herein. Referring to Figure 15, the operation relating to the issuance of verification result certificates VCs of the information processing system according to the first embodiment will be described.

[0174] The service provider's device (in the example in Figure 15, the service provider terminal 21) sends a certificate request to terminal 30 specifying the required credential certificate (step S31).

[0175] Terminal 30 reads the credential certificate specified by the service provider from the digital wallet and transmits the signed credential certificate to the service provider terminal 21 (step S32).

[0176] The operator terminal 21 verifies the acquired credential certificates (acquired certificates VCs) (step S33).

[0177] Regardless of the verification result, the operator terminal 21 generates verification result certificates VCs (step S34).

[0178] The operator terminal 21 provides the generated verification result certificates VCs to terminal 30 by storing them in online storage or the like. Specifically, the operator terminal 21 sends a certificate issuance notification, including a URL for obtaining the certificate, to terminal 30 (step S35).

[0179] Terminal 30 obtains verification result certificates VCs according to the certificate acquisition URL and stores the obtained verification result certificates VCs in the digital wallet (step S36).

[0180] Next, a modified example of the first embodiment will be described.

[0181] <Modification 1> A service provider who has obtained Verification Result Certificates VCs and verified the obtained Verification Result Certificates VCs may issue new Verification Result Certificates VCs. For example, in the examples of Figures 7 and 8, service provider D may issue the Verification Result Certificates VCs.

[0182] For example, in Figure 8, the service provider D's terminal 21 obtains credit card VCs that prove the verification results of My Number Card VCs. The service provider terminal 21 verifies the credit card VCs. The service provider terminal 21 issues new verification result certificates VCs that prove the verification results of the credit card VCs that prove the verification results of My Number Card VCs.

[0183] Furthermore, new Verification Result Certificates (VCs) may include the claims of the acquired Verification Result Certificates (VCs) and the claims of the Acquisition Certificates (VCs) that prove the verification results of the acquired Verification Result Certificates (VCs). In the example above, the new Verification Result Certificates (VCs) may include the verification results and claims of the credit card VCs and the verification results and claims of the My Number Card VCs.

[0184] The user's terminal 30 stores the new verification result certificates VCs issued by the service provider in its digital wallet. At that time, the terminal 30 stores the correspondence between "verification result certificates VCs (2): credit card VCs, My Number card VCs".

[0185] A service provider that provides services to users who possess valid credit card VCs and valid My Number card VCs may request the user to provide the above-mentioned verification result certificate VCs (2).

[0186] <Modification 2> In the above embodiment, the following items are included as information regarding the Acquisition Certificate VCs contained in the Verification Result Certificate VCs: • Issuer information of the Acquisition Certificate VCs • Claims made by the Acquisition Certificate VCs • Verification date and time of the Acquisition Certificate VCs • Verification results at the verification date and time of the Acquisition Certificate VCs • Issuance date of the Acquisition Certificate VCs • Expiration date of the Acquisition Certificate VCs • Verifier information at the verification date and time of the Acquisition Certificate VCs

[0187] However, verification certificates (VCs) that include some of the above items may be issued.

[0188] For example, instead of the above items, the ID information (Credential ID) of the Acquisition Certificate VCs (My Number Card VCs in the example shown in Figure 8, etc.) may be included in the Verification Result Certificate VCs. A service provider that has acquired the Verification Result Certificate VCs may send the above ID information to the certificate issuer and inquire about the validity of the corresponding credential certificate, etc.

[0189] Thus, the service provision control unit 402 of the certificate issuing device (business terminal 21, etc.) may generate the second credential certificate (verification result certificate VCs) which includes the ID information of the first credential certificate (acquisition certificate VCs) as the asserted content.

[0190] Alternatively, the Verification Result Certificate VCs may include information to access the location where information about the credential certificates (Acquisition Certificate VCs) that prove the verification result are stored.

[0191] In this case, the certificate issuer stores the date and time of issuance, status (valid, invalid), and claims of the credential certificate in online storage. For example, the server device 10 of a local government that issues My Number Card VCs stores the date and time of issuance, status, and specific claims (name, gender, date of birth, address, facial image, etc.) of the My Number Card VCs in online storage.

[0192] The certificate issuer generates pointer information to access the online storage where the above information is stored. Specifically, the certificate issuer's server device 10 generates a URL, etc., to access the online storage where the above information is stored as a "reference pointer" and includes it in the credential certificate. This reference pointer is also included in the verification result certificates VCs that prove the verification result.

[0193] A service provider that has obtained Verification Result Certificates (VCs) may use the reference pointer obtained from those Verification Result Certificates (VCs) to retrieve the latest status and claims of the Acquired Certificates (VCs). The service provider may use the retrieved latest information to determine the validity of the Acquired Certificates (VCs) and whether or not to provide the service.

[0194] For example, a service provider that limits its services to residents residing in a specific area uses the above-mentioned reference pointer to obtain the user's address as recorded on their My Number Card. The service provider then uses the obtained address to determine whether or not they can provide the service.

[0195] As a result, even if the information certified by the Acquisition Certificate VCs changes after the Verification Result Certificate VCs are issued, the service provider can obtain the latest information. That is, even if the content of the Acquisition Certificate VCs (in the above example, the My Number Card VCs) changes from its original content, the service provider can obtain the latest information certified by the Acquisition Certificate VCs from the Verification Result Certificate VCs (for example, the Credit Card VCs). For example, in the example in Figure 8, service provider D can refer to the latest information certified by the My Number Card VCs at point D.

[0196] Thus, the service provision control unit 402 may generate a second credential certificate (verification result certificate VCs) which includes a reference pointer as its assertion content for accessing information about the first online credential certificate (acquisition certificate VCs).

[0197] <Variation 3> The service provider's equipment (operator terminal 21, service server 20) may determine the information regarding the acquisition certificate VCs to be described in the verification result certificate VCs according to various conditions.

[0198] For example, if a credit card company successfully verifies the identity of a My Number Card VC, it may issue a credit card VC that does not include the information claimed on the My Number Card VC (e.g., name, gender, date of birth, address, facial image, etc.).

[0199] Alternatively, a credit card company may issue a credit card VC that includes all or part of the information claimed on the My Number Card VCs (e.g., name, gender, date of birth, address, facial image, etc.).

[0200] Alternatively, credit card companies may issue credit card VCs based on conditional branching according to the information obtained from My Number Card VCs. For example, a credit card company may issue credit card VCs according to the age of the recipient of the credit card VCs.

[0201] <Variation 4> The service provider may provide the verification results of the credential certificate to others in a format other than the credential certificate. Specifically, the certificate issuing device (business terminal 21, service server 20) may issue a verification result certificate to the user in a format other than the credential certificate.

[0202] For example, a service provider's certificate issuing device (business terminal 21, service server 20) may allow a third party to access the verification result certificate of the credential certificate using a two-dimensional barcode (two-dimensional code) or a URL. Two-dimensional barcodes include QR (Quick Response) code (registered trademark).

[0203] When a two-dimensional barcode is used, the business terminal 21 converts information about the acquisition certificate VCs (issuer of the acquisition certificate VCs, claims, verification results, issuance date, etc.) into a two-dimensional barcode. The business terminal 21 then transmits the obtained two-dimensional barcode to the user's terminal 30.

[0204] Terminal 30 stores a two-dimensional barcode obtained using a digital wallet or other means.

[0205] When the service provider requests the user to present a verification certificate proving the verification of the credentials, the user operates terminal 30 to display the corresponding 2D barcode. The user then presents terminal 30 displaying the 2D barcode to the service provider.

[0206] The service provider's equipment (operator terminal 21, service server 20) decrypts the presented 2D barcode and refers to the verification results of the credential certificate by other service providers.

[0207] If a URL is used, the business terminal 21 stores information regarding the Certificate of Acquisition VCs (issuer of the Certificate of Acquisition VCs, claims, verification results, issuance date, etc.) in online storage or the like. The business terminal 21 notifies terminal 30 of the URL for accessing the information storage location.

[0208] Terminal 30 stores the notified URL and, when requested by the service provider to present a certificate of the verification result of the credential certificate, provides the corresponding URL. The service provider then refers to the credential certificate verification results from other service providers according to the provided URL.

[0209] Thus, the verification results of a credential certificate by a service provider (verification result certificate) may be provided to other service providers using means such as a two-dimensional barcode or URL. In this case, other service providers cannot verify the legitimacy of the two-dimensional barcode or URL. However, if the time between the verification of the credential certificate and the provision of the verification results to a third party is short, the provision of services is often not hindered even if the verification of the two-dimensional barcode, etc., is not performed.

[0210] <Modification 5> In the above embodiment, a case was described in which a service provider issues one verification result certificate VCs when verifying one credential certificate.

[0211] However, a service provider may issue multiple verification result certificates (VCs) in response to verifying one set of credentials. For example, consider a case where a ticket vendor verifies My Number Card VCs and issues multiple ticket VCs. In this case, each of the multiple ticket VCs may function as a verification result certificate VC that proves the verification result of the My Number Card VCs.

[0212] Alternatively, a service provider may issue a single Verification Result Certificate (VC) that certifies the verification results of multiple credential documents. For example, a service provider that has verified My Number Card VCs and passport VCs may issue a single Verification Result Certificate (VC) that certifies the verification results of these identity document VCs.

[0213] Alternatively, if the service provider verifies the credential certificate at multiple times, it may issue a verification result certificate VCs that compiles the verification results of the credential certificate at those multiple times. For example, if the My Number Card VCs are verified at time points B1, B2, and B3, the service provider may issue a verification result certificate VCs containing the verification results at each time point after time point B3.

[0214] Alternatively, if the service provider has verified multiple credential certificates at different points in time, it may issue verification result certificates (VCs) for each of the verification results of the multiple credential certificates at each point in time.

[0215] <Modification 6> In the above embodiment, the case where the issuer of the acquisition certificate VCs and the issuer of the verification result certificate VCs are different was described. However, these issuers may be the same company, organization, etc. For example, if a local government that issues My Number Card VCs provides administrative services using the My Number Card VCs issued to a user, it may issue a verification result certificate VC that proves the verification result of the My Number Card VCs.

[0216] <Modification 7> In the above embodiment, the credential certificate was described as being provided by the user to the service provider via a communication means such as the Internet or Bluetooth®. However, the credential certificate may also be provided by the user to the service provider (business terminal 21) by displaying it on the screen of the terminal 30.

[0217] For example, when providing a service to a user, an employee of the service provider informs the user (verbally) of the information regarding the credential documents required to receive the service. The user operates terminal 30 to select the provided credential documents. Terminal 30 signs the selected credential documents and converts the signed credential documents into a two-dimensional barcode. Terminal 30 displays the two-dimensional barcode.

[0218] Employees of the service provider operate the service provider terminal 21 to read the two-dimensional barcode and decrypt the two-dimensional barcode to obtain a credential certificate.

[0219] <Modification 8> The user's terminal 30 may perform identity verification of the user when opening a digital wallet. For example, the terminal 30 may perform identity verification using a My Number Card or the like.

[0220] <Modification 9> In the above embodiment, the configuration and operation of the information processing system were explained using the example of a case where the credential certificate is stored in the digital wallet of the terminal 30 held by the user. However, the credential certificate may also be stored in an online wallet (web wallet).

[0221] In this case, the user operates terminal 30 to access the wallet provider's server. The user creates an account on the wallet provider's server.

[0222] Terminal 30 stores credentials in an online wallet or retrieves credentials from an online wallet via a web browser. Terminal 30 may also access the online wallet via a dedicated application installed on its own device.

[0223] Thus, the wallet for storing the credential certificate does not have to exist on terminal 30, but may exist on the network. In other words, the credential certificate is not stored on terminal 30, but may be stored in a wallet on the network.

[0224] As described above, the certificate issuing device (business terminal 21 or service server 20) according to the first embodiment verifies the credential certificate obtained from the user and issues a verification result certificate VCs to the user that certifies the verification result. The terminal 30 held by the user stores the issued verification result certificate VCs in a digital wallet. The terminal 30 can provide the verification result certificate VCs to other service providers other than the service provider that issued the verification result certificate VCs (the service provider that manages the certificate issuing device). The other service provider obtains the result of the service provider that issued the verification result certificate VCs verifying the credential certificate from the verification result certificate VCs. The other service provider trusts the result of the verification of the credential certificate by the issuer of the verification result certificate VCs and can use the verification result to determine whether or not to provide its own services. In other words, other service providers do not need to obtain or verify credential certificates whose verification results have been certified (guaranteed) by other service providers. As a result, the burden on service providers that provide services using credential certificates (digital certificates) is reduced.

[0225] [Second Embodiment] Next, a second embodiment will be described in detail with reference to the drawings.

[0226] In the first embodiment, the configuration and operation of the information processing system were described on the premise that one digital wallet is opened on the user's terminal 30. However, multiple digital wallets may be opened on the terminal 30 at the request of a certificate issuer that issues credential certificates.

[0227] As described above, users may select a credential certificate designated by the service provider from within their digital wallet and provide that selected credential certificate to the service provider. For example, a user who has been verbally informed of the required credential certificate needs to operate terminal 30 to select the credential certificate designated by the service provider.

[0228] In this case, if terminal 30 automatically stores the acquired credential certificate in one of several digital wallets, it becomes impossible to know where the issued credential certificate is stored. In this situation, it is difficult for the user to select the digital wallet that stores the credential certificate requested by the service provider.

[0229] In the second embodiment, the solution to the above-mentioned problem that occurs when multiple digital wallets are installed on the terminal 30 will be described.

[0230] Note that the configuration of the authentication system according to the second embodiment can be the same as that of the first embodiment, so the explanation corresponding to Figure 3 is omitted. Also, the processing configuration of the server device 10, business terminal 21, service server 20, and terminal 30 according to the second embodiment can be the same as that of the first embodiment, so the explanation is omitted.

[0231] The following will focus on explaining the differences between the first and second embodiments.

[0232] In the second embodiment, the service provider's certificate issuing device (business terminal 21, service server 20) issues individual verification result certificates VCs regardless of whether or not it issues credential certificates corresponding to the services provided.

[0233] For example, when a credit card company uses My Number Card VCs for identity verification, it issues not only credit card VCs but also verification result certificate VCs that prove the verification result of the My Number Card VCs. In this case, the business terminal 21 and service server 20 send certificate issuance notifications corresponding to the credit card VCs and certificate issuance notifications corresponding to the verification result certificate VCs for the My Number Card VCs to terminal 30.

[0234] Credit card VCs may or may not function as verification result certificate VCs.

[0235] In the second embodiment, when terminal 30 receives a certificate issuance notification while multiple digital wallets are installed, it asks the user for the location where the credential certificates (e.g., verification result certificates VCs) included in the notification are stored.

[0236] For example, the acquisition control unit 202 of terminal 30 uses a GUI (Graphical User Interface) as shown in Figure 16 to acquire the digital wallet that will be the storage location for the credential certificates (verification result certificates VCs) desired by the user. If the "Select All" button is pressed in Figure 16, the acquisition control unit 202 treats all digital wallets as having been selected.

[0237] Once the digital wallet to which the credential certificates will be stored is determined, the acquisition control unit 202 acquires the credential certificates (e.g., verification result certificates VCs) according to the certificate acquisition URL.

[0238] When a credential certificate is obtained, the acquisition control unit 202 stores the obtained credential certificate in the digital wallet selected by the user.

[0239] Thus, the acquisition control unit 202 includes the functions of a selection means, an acquisition means, and a storage means. When the selection means receives notification from the first service provider that a credential certificate has been issued, it enables the user to select a digital wallet from among multiple digital wallets to store the issued credential certificate. The acquisition means acquires the issued credential certificate. The storage means stores the acquired credential certificate in the digital wallet selected by the user. The storage unit 204 stores multiple digital wallets.

[0240] Here, if the acquired verification result certificates VCs satisfy predetermined conditions, the acquisition control unit 202 can treat the verification result certificates VCs that satisfy the predetermined conditions as copies of the credential certificates that prove the verification results.

[0241] For example, if the verification result certificate VCs that prove the verification result of My Number Card VCs meet predetermined conditions, the acquisition control unit 202 may treat the acquired verification result certificate VCs as copies of My Number Card VCs. In other words, verification result certificate VCs that meet predetermined conditions are stored in the digital wallet selected by the user as copies of My Number Card VCs.

[0242] For example, the specified conditions are all or part of the following items: • The verification of the Verification Result Certificate (VCs) is determined to be successful. • The verification result of the Acquisition Certificate (VCs) is successful. • The claims made by the Verification Result Certificate (VCs) regarding the Acquisition Certificate (VCs) are substantially the same as the claims made by the Acquisition Certificate (VCs).

[0243] For example, the memory unit 204 stores the items to be included in the claims for various types of identification documents (such as My Number Cards and driver's license VCs), including information to be included in the identification documents themselves (such as name and address). The acquisition control unit 202 determines that the two sets of claims are substantially identical if the information to be included in the claims of the previously stored identification documents matches the information to be included in the claims of the verification result certificates.

[0244] Alternatively, the acquisition control unit 202 may use a large language model (LLM) obtained by machine learning to determine whether the claims made by the verification result certificates VCs regarding the acquisition certificates VCs are substantially the same as the claims made by the acquisition certificates VCs.

[0245] For example, if the verification of the Verification Result Certificate VCs is successful, and the verification result of the My Number Card VCs is also successful, and the claims made by the Verification Result Certificate VCs include the claims made by the My Number Card VCs, then the Verification Result Certificate VCs are determined to meet the predetermined conditions. In this case, the acquisition control unit 202 treats the Verification Result Certificate VCs as a copy of the My Number Card VCs and stores it in the digital wallet.

[0246] For example, the acquisition control unit 202 makes an association such as "Verification Result Certificate VCs (3); My Number Card VCs (copy)" and stores it in the digital wallet.

[0247] Thus, the acquisition control unit 202 receives notification from the first service provider that a second credential certificate has been issued by the first service provider, certifying the verification result of the first credential certificate. If the second credential certificate satisfies predetermined conditions, the acquisition control unit 202 stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user.

[0248] More specifically, the acquisition control unit 202 stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user if it successfully verifies the second credential certificate. The acquisition control unit 202 also stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user if the second credential certificate proves that the verification of the first credential certificate was successful. The acquisition control unit 202 also stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user if the claims of the first credential certificate are included in the claims of the second credential certificate.

[0249] The user operates terminal 30 to select the credential certificate requested by the service provider. If multiple digital wallets are installed on terminal 30, the user control unit 203 prompts the user to select the digital wallet containing the requested credential certificate.

[0250] For example, the user control unit 203 displays a GUI as shown in Figure 17 to accept the user's selection of a digital wallet.

[0251] When a user selects a digital wallet, the user control unit 203 displays a list of credential certificates stored in the selected digital wallet. With respect to the verification result certificates VCs, the user control unit 203 explicitly states that the verification result certificates VCs are copies of other credential certificates (see Figure 18).

[0252] The user control unit 203 provides the service provider with the credential certificate selected by the user. For example, the user control unit 203 converts the credential certificate selected by the user into a two-dimensional barcode and displays the two-dimensional barcode.

[0253] In this way, the user control unit 203 enables the user to select a digital wallet from among multiple digital wallets that stores the credential certificate that the user will provide to the second service provider. Furthermore, if the selected digital wallet contains a second credential certificate stored as a copy of the first credential certificate, the user control unit 203 explicitly indicates that the second credential certificate is a copy of the first credential certificate. While explicitly indicating that the second credential certificate is a copy of the first credential certificate, the user control unit 203 enables the user to select the credential certificate that they will provide to the second service provider.

[0254] Furthermore, when the service provider's equipment (operator terminal 21, service server 20) requests the terminal 30 to provide a credential certificate, if a copy of the required credential certificate is sufficient, it will notify the terminal 30 accordingly. In other words, if the original credential certificate is required, the service provider's equipment may notify the terminal 30 accordingly.

[0255] As described above, when a credential certificate is issued, the terminal 30 according to the second embodiment controls the terminal 30 so that the user can select the storage location of the issued credential certificate from among the multiple digital wallets installed on the terminal 30. The terminal 30 stores the issued credential certificate in the digital wallet selected by the user. In other words, the user can select the digital wallet to which the credential certificate issued by the first service provider will be stored. Because the user can select the digital wallet to which the credential certificate will be stored, the user can easily select the digital wallet that stores the credential certificate requested by the service provider. As a result, the burden on the user of a terminal that manages certificates using multiple digital wallets is reduced.

[0256] Furthermore, users can store acquired credential certificates in each of their multiple digital wallets. If the issued credential certificates are stored in each digital wallet, the user does not need to select the storage location (digital wallet) for the requested credential certificates. As a result, the burden on users of terminal 30 equipped with multiple digital wallets is further reduced.

[0257] Furthermore, if the verification result certificates VCs issued by the service provider meet certain conditions, terminal 30 treats them as copies of the credential certificates verified by the service provider. Through this operation of terminal 30, essentially the same credential certificate can be stored in multiple digital wallets without the user having to request the issuance of a credential certificate from the certificate issuer. For example, if a user wishes to store their My Number Card VCs in multiple digital wallets, the user does not need to request the reissuance of the My Number Card VCs from the local government or other relevant parties. When using the My Number Card VCs, the user only needs to select the storage location for the verification result certificates VCs that will be treated as copies of the My Number Card VCs.

[0258] Next, we will describe the hardware of each device that makes up the information processing system. Figure 19 shows an example of the hardware configuration of the business terminal 21.

[0259] The operator terminal 21 can be configured using an information processing device (a so-called computer), and has the configuration illustrated in Figure 19. For example, the operator terminal 21 includes a processor 311, memory 312, input / output interface 313, and communication interface 314, etc. The components of the processor 311, etc. are connected by an internal bus or the like and are configured to communicate with each other.

[0260] However, the configuration shown in Figure 19 is not intended to limit the hardware configuration of the carrier terminal 21. The carrier terminal 21 may include hardware not shown, and may not have an input / output interface 313 if necessary. Furthermore, the number of processors 311 etc. included in the carrier terminal 21 is not limited to the example in Figure 19; for example, multiple processors 311 may be included in the carrier terminal 21.

[0261] The processor 311 is a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). Alternatively, the processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit). The processor 311 executes various programs, including an operating system (OS).

[0262] Memory 312 can be RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc. Memory 312 stores the OS program, application programs, and various data.

[0263] The input / output interface 313 is an interface for a display device or input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a device that accepts user input such as a keyboard or mouse.

[0264] The communication interface 314 is a circuit, module, etc., that communicates with other devices. For example, the communication interface 314 may include a NIC (Network Interface Card).

[0265] The functions of the operator terminal 21 are realized by various processing modules. These processing modules are realized, for example, by the processor 311 executing a program stored in memory 312. The program can also be recorded on a computer-readable storage medium. The storage medium can be a non-transitory material such as semiconductor memory, hard disk, magnetic recording medium, or optical recording medium. In other words, the present invention can also be embodied as a computer program product. Furthermore, the program can be downloaded via a network or updated using the storage medium on which the program is stored. Moreover, the processing module may be realized by a semiconductor chip.

[0266] Note that the server device 10, service server 20, and terminal 30 can also be configured using information processing equipment, similar to the carrier terminal 21, and their basic hardware configurations are no different from those of the carrier terminal 21, so a detailed explanation is omitted. For example, as shown in Figure 20, terminal 30 includes a processor 411, memory 412, input / output interface 413, and communication interface 414.

[0267] The information processing device, the business terminal 21, is equipped with a computer, and its functions can be realized by having the computer execute a program. Furthermore, the business terminal 21 executes a control method for the business terminal 21 using this program. Similarly, the terminal 30 is equipped with a computer, and its functions can be realized by having the computer execute a program. Furthermore, the terminal 30 executes a control method for the terminal 30 using this program.

[0268] [Modification] Note that the configuration and operation of the information processing system described in the above embodiment are illustrative examples and are not intended to limit the system configuration.

[0269] In the above embodiment, the case was described in which the certificate issuer's server device 10 issues a credential certificate that does not require a Certificate Authority for verification. However, the server device 10 may also issue a certificate that requires a Certificate Authority (a public key infrastructure-based certificate).

[0270] Terminal 30 may obtain the user's consent to provide the credential certificate before providing it to the service provider. In this case, terminal 30 may obtain consent to submit the credential certificate while clearly indicating the credential certificate that has been requested.

[0271] The acquisition control unit 202 of terminal 30 may notify the user of the fact that a credential certificate has been issued when it has acquired one from the server device 10. The acquisition control unit 202 may also verify the signature attached to the credential certificate acquired from the certificate issuer. In this case, the acquisition control unit 202 acquires the public key corresponding to the issuer ID written on the credential certificate from the blockchain. The acquisition control unit 202 uses the acquired public key to verify the signature attached to the credential certificate. The acquisition control unit 202 may use successful signature verification as a condition for storing the credential certificate in the digital wallet.

[0272] In the above embodiment, the case was described in which the operator terminal 21 and the service server 20 issue a second credential certificate (verification result certificate VCs) regardless of the verification result of the first credential certificate. However, the operator terminal 21, etc., may issue a second credential certificate if the verification of the first credential certificate is successful, or may issue a second credential certificate if the verification of the first credential certificate fails.

[0273] In the above embodiment, the terminal 30, upon receiving a certificate issuance notification from the business terminal 21 or the like, inquired with the user about the storage location of the credential certificate. However, the terminal 30 may determine the storage location of the credential certificate by other means. For example, upon receiving a certificate issuance notification, the terminal 30 notifies the user of this fact. The user selects one digital wallet (an application that controls a digital wallet) from among several digital wallets and launches it. The launched digital wallet accesses the certificate acquisition URL included in the certificate issuance notification and acquires (downloads) the credential certificate stored in online storage. The digital wallet stores the acquired credential certificate.

[0274] Some functions of the operator terminal 21 and terminal 30 may be implemented in other devices or equipment. More specifically, it is sufficient if the "acquisition control unit (acquisition control means)", "utilization control unit (utilization control means)", "service provision control unit (service provision control means)", etc. described above are implemented in any of the devices included in the system.

[0275] The form of data transmission and reception between each device (for example, server device 10, terminal 30) is not particularly limited, but the data transmitted and received between these devices may be encrypted. Personal information of users is transmitted and received between these devices, and it is desirable that encrypted data be transmitted and received in order to properly protect this information.

[0276] In the flowcharts (sequence diagrams) used in the above description, multiple processes are shown in order, but the execution order of the processes performed in the embodiment is not limited to the order in which they are shown. In the embodiment, the order of the illustrated processes can be changed to the extent that it does not impede the content, for example, by executing each process in parallel.

[0277] The embodiments described above are explained in detail to facilitate understanding of the disclosure, and it is not intended that all the configurations described above are necessary. Furthermore, when multiple embodiments are described, each embodiment may be used individually or in combination. For example, it is possible to replace parts of the configuration of one embodiment with those of another embodiment, or to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of one embodiment with those of another.

[0278] As described above, the industrial applicability of the present invention is clear, and it is particularly applicable to information processing systems, etc., that include service providers who provide services to users using certificates stored in a digital wallet.

[0279] Some or all of the above embodiments may also be described as follows, but are not limited to the following:

[0280] [Note 1] A terminal comprising: a selection means that, upon receiving notification from a first service provider that a credential certificate has been issued, allows the user to select a digital wallet from among several digital wallets to store the issued credential certificate; an acquisition means for acquiring the issued credential certificate; and a storage means for storing the acquired credential certificate in the digital wallet selected by the user.

[0281] [Note 2] The terminal as described in Note 1, wherein the selection means receives notification from the first service provider that a second credential certificate has been issued that certifies the verification result of the first credential certificate by the first service provider, and the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user if the second credential certificate satisfies predetermined conditions.

[0282] [Note 3] The terminal as described in Note 2, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user when the verification of the second credential certificate is successful.

[0283] [Note 4] The terminal as described in Note 2, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user when the second credential certificate proves that the verification result of the first credential certificate was successful.

[0284] [Note 5] The terminal as described in Note 2, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user when the claims of the first credential certificate are included in the claims of the second credential certificate.

[0285] [Note 6] The terminal as described in Note 2, further comprising usage control means that enables the user to select from among the plurality of digital wallets a digital wallet containing the credential certificate to be provided to the second service provider.

[0286] [Note 7] The terminal as described in Note 6, wherein the usage control means, when the selected digital wallet contains the second credential certificate stored as a copy of the first credential certificate, allows the user to select a credential certificate to provide to the second service provider, while clearly indicating that the second credential certificate is a copy of the first credential certificate.

[0287] [Appendix 8] A system comprising: a certificate issuing device of a first service provider; a terminal; the terminal comprising: a selection means that, upon receiving notification from the certificate issuing device that a credential certificate has been issued, enables the user to select a digital wallet from among a plurality of digital wallets to store the issued credential certificate; an acquisition means for acquiring the issued credential certificate; and a storage means for storing the acquired credential certificate in the digital wallet selected by the user.

[0288] [Note 9] The system as described in Note 8, wherein the selection means receives notification from the first service provider that a second credential certificate has been issued that certifies the verification result of the first credential certificate by the first service provider, and the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user if the second credential certificate satisfies predetermined conditions.

[0289] [Note 10] The system as described in Note 9, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user when the verification of the second credential certificate is successful.

[0290] [Note 11] The system as described in Note 9, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user when the second credential certificate proves that the verification result of the first credential certificate was successful.

[0291] [Note 12] The system according to Note 9, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user when the claims of the first credential certificate are included in the claims of the second credential certificate.

[0292] [Note 13] The system according to Note 9, further comprising usage control means that enables the user to select from among the plurality of digital wallets a digital wallet in which a credential certificate to be provided to the second service provider is stored.

[0293] [Note 14] The system according to Note 13, wherein the usage control means, when the selected digital wallet contains the second credential certificate stored as a copy of the first credential certificate, allows the user to select a credential certificate to provide to the second service provider, while clearly indicating that the second credential certificate is a copy of the first credential certificate.

[0294] [Note 15] A terminal control method comprising: a selection step, which enables the user to select a digital wallet to store the issued credential certificate from among several digital wallets when the terminal receives notification from a first service provider that a credential certificate has been issued; an acquisition step, which acquires the issued credential certificate; and a storage step, which stores the acquired credential certificate in the digital wallet selected by the user.

[0295] [Note 16] The terminal control method according to Note 15, wherein the selection step receives notification from the first service provider that a second credential certificate has been issued that certifies the verification result of the first credential certificate by the first service provider, and the storage step stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user if the second credential certificate satisfies predetermined conditions.

[0296] [Note 17] The terminal control method according to Note 16, wherein the storage step, if the verification of the second credential certificate is successful, stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user.

[0297] [Note 18] The terminal control method according to Note 16, wherein the storage step involves storing the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user, when the second credential certificate proves that the verification result of the first credential certificate is successful.

[0298] [Note 19] The terminal control method according to Note 16, wherein the storage step involves storing the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user, if the claims of the first credential certificate are included in the claims of the second credential certificate.

[0299] [Note 20] The terminal control method according to Note 16, further comprising a usage control step that enables the user to select from among the plurality of digital wallets a digital wallet containing a credential certificate to be provided to the second service provider.

[0300] [Note 21] The terminal control method described in Note 20, wherein the usage control step allows the user to select a credential certificate to provide to the second service provider, while clearly indicating that the second credential certificate is a copy of the first credential certificate, when the selected digital wallet contains the second credential certificate stored as a copy of the first credential certificate.

[0301] [Note 22] A computer-readable storage medium that stores a program for causing a computer installed in a terminal to execute the following: a selection process that enables the user to select a digital wallet to store the issued credential certificate from among several digital wallets when it receives notification from a first service provider that a credential certificate has been issued; an acquisition process that acquires the issued credential certificate; and a storage process that stores the acquired credential certificate in the digital wallet selected by the user.

[0302] [Note 23] The storage medium described in Note 22, wherein the selection process receives notification from the first service provider that a second credential certificate has been issued that certifies the verification result of the first credential certificate by the first service provider, and the storage process stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user if the second credential certificate satisfies predetermined conditions.

[0303] [Note 24] The storage medium described in Note 23, wherein, if the verification of the second credential certificate is successful, the second credential certificate is stored as a copy of the first credential certificate in the digital wallet selected by the user.

[0304] [Note 25] The storage medium described in Note 23, wherein the storage process involves storing the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user, when the second credential certificate proves that the verification result of the first credential certificate is successful.

[0305] [Note 26] The storage medium described in Note 23, wherein the storage process stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user when the claims of the first credential certificate are included in the claims of the second credential certificate.

[0306] [Note 27] The storage medium described in Note 23, which further executes usage control processing that enables the user to select from among the plurality of digital wallets a digital wallet containing the credential certificate to be provided to the second service provider.

[0307] [Note 28] The storage medium described in Note 27, wherein the usage control process allows the user to select a credential certificate to provide to the second service provider, while explicitly stating that the second credential certificate is a copy of the first credential certificate, if the selected digital wallet contains the second credential certificate stored as a copy of the first credential certificate.

[0308] Furthermore, some or all of the configurations described in Appendices 2 to 7, which are subordinate to Appendice 1 above, may also be subordinate to Appendices 8, 15, and 22 in the same way as those described in Appendices 2 to 7. Moreover, not limited to Appendices 1, 8, 15, and 22, some or all of the configurations described as appendices may also be subordinate to various hardware, software, various recording means for recording software, or systems, without departing from the embodiments described above.

[0309] Furthermore, each disclosure of the above-mentioned prior art documents cited herein is incorporated herein by reference. Although embodiments of the present invention have been described above, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that these embodiments are merely illustrative and that various modifications are possible without departing from the scope and spirit of the present invention. That is, the present invention naturally includes the entire disclosure, including the claims, and various modifications and alterations that can be made by those skilled in the art in accordance with the technical idea.

[0310] 10 Server device 20 Service server 21 Operator terminal 30 Terminal 100 Terminal 101 Selection means 102 Acquisition means 103 Storage means 201 Communication control unit 202 Acquisition control unit 203 Utilization control unit 204 Storage unit 301 Communication control unit 302 Certificate issuance unit 303 Storage unit 311 Processor 312 Memory 313 Input / output interface 314 Communication interface 401 Communication control unit 402 Service provision control unit 403 Storage unit 411 Processor 412 Memory 413 Input / output interface 414 Communication interface

Claims

1. A terminal comprising: a selection means that, upon receiving notification from a first service provider that a credential certificate has been issued, allows the user to select a digital wallet from among several digital wallets to store the issued credential certificate; an acquisition means for acquiring the issued credential certificate; and a storage means for storing the acquired credential certificate in the digital wallet selected by the user.

2. The terminal according to claim 1, wherein the selection means receives notification from the first service provider that a second credential certificate has been issued that certifies the verification result of the first credential certificate by the first service provider, and the storage means stores the second credential certificate as a copy of the first credential certificate in the digital wallet selected by the user if the second credential certificate satisfies predetermined conditions.

3. The terminal according to claim 2, wherein, upon successful verification of the second credential certificate, the storage means stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user.

4. The terminal according to claim 2, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user when the second credential certificate proves that the verification result of the first credential certificate is successful.

5. The terminal according to claim 2, wherein the storage means stores the second credential certificate as a copy of the first credential certificate in a digital wallet selected by the user when the claims of the first credential certificate are included in the claims of the second credential certificate.

6. The terminal according to claim 2, further comprising usage control means that enables the user to select from among the plurality of digital wallets a digital wallet in which a credential certificate to be provided to the second service provider is stored.

7. The terminal according to claim 6, wherein the usage control means, when the selected digital wallet contains the second credential certificate stored as a copy of the first credential certificate, allows the user to select a credential certificate to provide to the second service provider, while clearly indicating that the second credential certificate is a copy of the first credential certificate.

8. A system comprising: a certificate issuing device of a first service provider; a terminal; the terminal comprising: a selection means that, upon receiving notification from the certificate issuing device that a credential certificate has been issued, enables the user to select a digital wallet from among a plurality of digital wallets to store the issued credential certificate; an acquisition means for acquiring the issued credential certificate; and a storage means for storing the acquired credential certificate in the digital wallet selected by the user.

9. A terminal control method comprising: a selection step, which enables the user to select a digital wallet to store the issued credential certificate from among several digital wallets upon receiving notification from a first service provider that a credential certificate has been issued; an acquisition step, which acquires the issued credential certificate; and a storage step, which stores the acquired credential certificate in the digital wallet selected by the user.

10. A computer-readable storage medium that stores a program for causing a computer installed in a terminal to execute the following: a selection process that enables the user to select a digital wallet from among several digital wallets to store the issued credential certificate when it receives notification from a first service provider that a credential certificate has been issued; an acquisition process that acquires the issued credential certificate; and a storage process that stores the acquired credential certificate in the digital wallet selected by the user.

Citation Information

Patent Citations

  • Information processing device, information processing method, and information processing program

    JP2024060266A

  • Terminal, system, terminal control method and program

    JP7371818B1

  • Processing apparatus

    KR1020240064527A

  • Online banking digital wallet management

    US20150254638A1