Presentation device, management device, verification device, verification method, and program

The system addresses the offline verification challenge in self-sovereign identity systems by enabling offline presentation of verifiable credentials through proximity communication and legitimacy confirmation, ensuring seamless credential verification.

WO2026069430A1PCT designated stage Publication Date: 2026-04-02NT T INC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-24
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

In self-sovereign identity systems, when a user's device is offline, it cannot obtain or present verifiable credentials managed by a cloud-based management device, leading to a lack of verification capability.

Method used

A presentation device, management device, and verification device system that enables offline verification by using proximity communication and a management device to confirm the legitimacy of the verification device, allowing the presentation of verifiable credentials.

Benefits of technology

Enables the presentation of verifiable credentials even when the presentation device is offline by confirming the legitimacy of the verification device through network-independent communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024033965_02042026_PF_FP_ABST
    Figure JP2024033965_02042026_PF_FP_ABST
Patent Text Reader

Abstract

A verification method according to the present disclosure involves: a presentation device (100) sending, when presenting a verifiable credential (VC) that can be verified in an offline state to a verification device (200), an indication of a management device (300) managing the VC to the verification device (200); the verification device (200) transmitting a VC presentation request to the indicated management device (300); the management device (300) transmitting, upon receiving the presentation request, an attestation request requesting proof of validity of the verification device (200) to the verification device (200); the verification device (200) transmitting, upon receiving the attestation request, an attestation response including information relating to validity of the verification device (200) to the management device (300); and the management device (300) presenting the requested VC to the verification device (200) upon determining that the verification device (200) is valid on the basis of the information relating to validity of the verification device (200).
Need to check novelty before this filing date? Find Prior Art

Description

Presentation device, management device, verification device, verification method, and program

[0001] The present disclosure relates to a presentation device, a management device, a verification device, a verification method, and a program.

[0002] In recent years, self-sovereign identity (SSI) technology has been studied in which a user manages their own identifier and identity and controls the presentation destination without relying on a centralized identity provider (IdP) or the like (see Non-Patent Documents 1 and 2).

[0003] In digital identity, there are three parties: Holder, Issuer, and Verifier. Holder is a user who manages and holds their own digital identity. The Issuer issues verifiable credential information (VC: Verifiable Credentials) that proves the user's attributes and / or qualifications, such as attribute information (name, age, address, etc.) and qualification information (being an employee of a certain company, being a member of a certain service, etc.) to the user after verification. The Verifier requests and receives the VC necessary for service provision from the Holder, verifies the Holder's attributes and qualifications, and makes decisions regarding service provision.

[0004] A digital identity wallet (DIW: Digital Identity Wallet) has been proposed that manages the ID data of a user (Holder) and is used for identity verification and attribute proof (see Non-Patent Document 3). As embodiments of the DIW, there are two forms: a form in which ID data is managed within a user device (local wallet) and a form in which ID data is managed on a platform hosted by a cloud provider or the like (cloud wallet).

[0005] “W3C Decentralized Identifiers (DID)” [online], [Accessed September 9, 2024], Internet<URL: https: / / www.w3.org / TR / did-core / > “W3C Verifiable Credentials” [online], [Accessed September 9, 2024], Internet<URL: https: / / www.w3.org / TR / vc-data-model / > “European digital identity wallet” [online], [searched September 9, 2024], Internet <URL: https: / / digital-strategy.ec.europa.eu / en / library / european-digital-identity-wallet-architecture-and-reference-framework>

[0006] By using a cloud-based DIW (Data Intrusion Prevention System), users can reduce the effort required to properly manage user devices equipped with ID data and ID data processing functions. Furthermore, using a cloud-based DIW reduces the risk of external access to ID data due to factors such as loss of user devices or inadequate security settings.

[0007] In a situation where a user's digital identity is managed in a cloud wallet, when the Holder device (presenting device) is online and can communicate with the cloud wallet (management device) via the network, the presenting device can communicate with the management device, obtain the VC managed by the management device, and present it to the Verifier (verification device). However, when the presenting device is offline and cannot communicate with the management device via the network, it cannot obtain the VC and therefore cannot present it to the verification device. Furthermore, in the offline state, the presenting device cannot perform VC expiration verification or DID (Decentralized Identifier) ​​verification, which proves the attributes of the verification device, via the network. Therefore, a mechanism is needed that allows the presenting device to verify the legitimacy of the verification device and present the VC to the verification device even when the presenting device is offline.

[0008] In light of the problems described above, the purpose of this disclosure is to provide a presentation device, a management device, a verification device, a verification method, and a program that can present verifiable credentials to the verification device after confirming the legitimacy of the verification device, even when the presentation device is offline.

[0009] A presentation device according to one embodiment is a presentation device that presents verifiable credentials of a user, wherein the presentation device is capable of communicating via a network with a management device that manages the verifiable credentials and a verification device that verifies the verifiable credentials, and is capable of communicating with the verification device without the network, and includes a control unit that notifies the verification device of the management device that manages the verifiable credentials when presenting the verifiable credentials to the verification device in an offline state where communication with the management device via the network is not possible.

[0010] A management device according to one embodiment is a management device for managing verifiable user credentials, the management device being able to communicate via a network with a presentation device that presents the verifiable credentials and a verification device that verifies the verifiable credentials, and a control unit that, upon receiving a presentation request from the verification device requesting the presentation of the verifiable credentials, transmits a certification request to the verification device requesting proof of the legitimacy of the verification device, and, based on the information regarding the legitimacy of the verification device transmitted from the verification device in response to the certification request, determines that the verification device is legitimate, and then presents the verifiable credentials requested by the presentation request to the verification device.

[0011] A verification device according to one embodiment is a verification device for verifying a user's verifiable credentials, wherein the verification device is able to communicate via a network with a management device that manages the verifiable credentials and a presentation device that presents the verifiable credentials, and is also able to communicate with the presentation device without using the network, and when the presentation device notifies the management device that manages the verifiable credentials, the verification device sends a presentation request to the notified management device requesting the presentation of the verifiable credentials, and when the verification device receives a certification request from the management device in response to the presentation request requesting information regarding the legitimacy of the verification device, it sends a certification response including information regarding the legitimacy of the verification device to the management device.

[0012] A verification method according to one embodiment is a verification method in a verification system comprising: a presentation device that presents verifiable credentials of a user; a management device that manages the verifiable credentials; and a verification device that verifies the verifiable credentials, wherein the presentation device, the management device, and the verification device can communicate with each other via a network, and the presentation device and the verification device can communicate without the network; the presentation device notifies the management device of the association between the verifiable credentials and the verification device that presents the verifiable credentials; the management device stores the association between the verifiable credentials and the verification device that presents the verifiable credentials notified by the presentation device; when the presentation device presents the verifiable credentials to the verification device in an offline state where it cannot communicate with the management device via the network, it notifies the verification device of the management device that manages the verifiable credentials; and the verification device transmits a presentation request to the management device notified by the presentation device, requesting the presentation of the verifiable credentials. The process includes the steps of: the management device presenting verifiable credentials stored in association with the verification device that sent the presentation request to the verification device; and the verification device verifying the verifiable credentials sent from the management device.

[0013] A program according to one embodiment causes a computer to operate as the presentation device, the management device, or the verification device.

[0014] According to this disclosure, even if the presentation device is offline, the validity of the verification device can be confirmed, and verifiable credentials can be presented to the verification device.

[0015] This figure shows an example configuration of a verification system according to one embodiment of this disclosure. This is a sequence diagram showing an example of the operation of the verification system shown in Figure 1.

[0016] Embodiments of this disclosure will be described below with reference to the drawings.

[0017] Figure 1 is a diagram showing an example configuration of a verification system 10 according to one embodiment of the present disclosure.

[0018] As shown in Figure 1, the verification system 10 according to this embodiment comprises a presentation device 100, a verification device 200, and a management device 300. The presentation device 100, the verification device 200, and the management device 300 can communicate with each other via a network 11 such as the Internet. The presentation device 100 and the verification device 200 can also communicate without using the network 11. For example, the presentation device 100 and the verification device 200 can communicate using proximity communication. Therefore, even when the presentation device 100 is offline and cannot communicate via the network 11, the presentation device 100 and the verification device 200 can communicate using proximity communication, for example.

[0019] The presentation device 100 is a device used by the user (Holder), such as a smartphone or personal computer. The presentation device 100 presents the user's verifiable credentials (VC). As mentioned above, a VC is a certificate that proves the user's attributes and / or qualifications. The VC is issued by an Issuer that verifies the user's attributes and qualifications and issues a signed certificate. In a cloud wallet, the VC is managed by the management device 300. When online, the presentation device 100 retrieves the VC managed by the management device 300 and presents it to the verification device 200. On the other hand, when offline, the presentation device 100 cannot retrieve the VC from the management device 300 and cannot present the VC to the verification device 200.

[0020] As shown in Figure 1, the presentation device 100 according to this embodiment comprises a storage unit 101, a communication unit 102, and a control unit 103.

[0021] The storage unit 101 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM (Random Access Memory), ROM (Read Only Memory), or flash memory. The RAM is, for example, SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory). The ROM is, for example, EEPROM (Electrically Erasable Programmable Read Only Memory). The flash memory is, for example, SSD (Solid-State Drive). The magnetic memory is, for example, HDD (Hard Disk Drive). The storage unit 101 functions, for example, as main memory, auxiliary memory, or cache memory. The storage unit 101 stores information used for the operation of the presentation device 100 and information obtained by the operation of the presentation device 100.

[0022] The communication unit 102 includes at least one communication module. The communication module is, for example, a module compatible with a LAN communication standard such as Ethernet (registered trademark). The communication unit 102 communicates with the verification device 200 and the management device 300 via the network 11. The communication unit 102 also communicates with the verification device 200 without using the network 11. The communication unit 102 also communicates with the verification device 200 via proximity communication, for example. The communication unit 102 receives information used for the operation of the presentation device 100 and transmits information obtained through the operation of the presentation device 100.

[0023] The control unit 103 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit), or a dedicated processor specialized for a specific process. The programmable circuit is, for example, an FPGA (Field-Programmable Gate Array). The dedicated circuit is, for example, an ASIC (Application Specific Integrated Circuit).

[0024] The control unit 103 controls each part of the presentation device 100 and executes processes related to the operation of the presentation device 100. For example, the control unit 103 associates a VC (verifiable credentials) with a verification device 200 that presents the VC and notifies the management device 300. Typically, there are various VCs for a Holder, depending on the Holder's attributes (name, age, address, etc.) and qualifications (whether they are an employee of a certain company, a member of a certain service, etc.). For example, even when the presentation device 100 is offline, the control unit 103 associates a VC that the user wishes to be presented with the verification device 200 that presents the VC and notifies the management device 300.

[0025] Verification device 200 is a device used by the Verifier. Verification device 200 verifies the user's VC (Verify the user's (Holder's) attributes and qualifications, etc.). When online, verification device 200 verifies the VC presented by presentation device 100. When presentation device 100 is offline, verification device 200 verifies the VC presented by management device 300, as will be described in detail later.

[0026] As shown in Figure 1, the verification device 200 according to this embodiment includes a storage unit 201, a communication unit 202, and a control unit 203.

[0027] The storage unit 201, like the storage unit 101, includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 201 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 201 stores information used for the operation of the verification device 200 and information obtained by the operation of the verification device 200.

[0028] The communication unit 202, like the communication unit 102, includes at least one communication module. The communication unit 202 communicates with the display device 100 and the management device 300 via the network 11. The communication unit 202 also communicates with the display device 100 without using the network 11. For example, the communication unit 202 communicates with the display device 100 via proximity communication. The communication unit 202 receives information used for the operation of the verification device 200 and transmits information obtained through the operation of the verification device 200.

[0029] The control unit 203 controls each part of the verification device 200 and executes processes related to the operation of the verification device 200. For example, when the control unit 203 receives notification from the presentation device 100 to the management device 300 which manages the VC to be presented, and the identification information of the VC, it sends a presentation request to the notified management device 300 requesting the presentation of the VC indicated by the identification information. Also, in response to the presentation request, when the control unit 203 receives a certification request from the management device 300 requesting information regarding the legitimacy of the verification device 200, it sends a certification response containing information regarding the legitimacy of the verification device 200 to the management device 300. Furthermore, the control unit 203 verifies the VC sent from the management device 300 in response to the certification response.

[0030] The management device 300 is a device such as a server connected to the network 11. The management device 300 manages user verifiable credentials (VCs) issued to the Holder.

[0031] As shown in Figure 1, the management device 300 according to this embodiment includes a storage unit 301, a communication unit 302, and a control unit 303.

[0032] Like the storage unit 101, the storage unit 301 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 301 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 301 stores information used in the operation of the management device 300 and information obtained through the operation of the management device 300. For example, the storage unit 301 stores the association between a VC and a verification device 200 that presents the VC, as notified by the presentation device 100.

[0033] The communication unit 302, like the communication unit 102, includes at least one communication module. The communication unit 302 communicates with the presentation device 100 and the verification device 200 via the network 11. The communication unit 302 receives information used for the operation of the management device 300 and transmits information obtained through the operation of the management device 300.

[0034] The control unit 303 controls each part of the management device 300 and executes processes related to the operation of the management device 300. For example, when the control unit 303 receives a request from the verification device 200 to present a VC, it presents the VC stored in association with the verification device 200 to the verification device 200.

[0035] The functions of the presentation device 100, the verification device 200, and the management device 300 are realized by executing the program according to this embodiment on processors acting as control units 103, 203, and 303. In other words, the functions of the presentation device 100, the verification device 200, and the management device 300 are realized by software. The program causes the computer to execute the operations of the presentation device 100, the verification device 200, and the management device 300, thereby causing the computer to function as the presentation device 100, the verification device 200, and the management device 300. That is, the computer functions as the presentation device 100, the verification device 200, and the management device 300 by executing the operations of the presentation device 100, the verification device 200, and the management device 300 according to the program.

[0036] The program can be stored on a non-temporary computer-readable medium. Examples of non-temporary computer-readable mediums include flash memory, magnetic recording devices, optical discs, magneto-optical recording media, or ROM. The program can be distributed, for example, by selling, transferring, or leasing portable media such as SD (Secure Digital) cards, DVDs (Digital Versatile Discs), or CD-ROMs (Compact Disc Read Only Memory) on which the program is stored. The program may also be distributed by storing it in server storage and transferring it from the server to other computers. The program may also be provided as a program product.

[0037] A computer, for example, stores a program stored on a portable medium or a program transferred from a server in its main memory. Then, the computer reads the program stored in the main memory with its processor and executes the processing according to the read program. The computer may also read the program directly from the portable medium and execute the processing according to the program. The computer may also execute the processing according to the received program sequentially each time a program is transferred to it from a server. Processing may also be performed by a so-called ASP (Application Service Provider) type service, which does not transfer programs from the server to the computer, but realizes its function only through execution instructions and result retrieval. A program includes information used for processing by an electronic computer that is equivalent to a program. For example, data that is not a direct instruction to the computer but has the nature of defining the computer's processing falls under "equivalent to a program".

[0038] Some or all of the functions of the presentation device 100, the verification device 200, and the management device 300 may be implemented by programmable circuits or dedicated circuits as control units 103, 203, and 303. In other words, some or all of the functions of the presentation device 100, the verification device 200, and the management device 300 may be implemented by hardware.

[0039] Next, the operation of each device in the verification system 10 according to this embodiment will be described. Figure 2 is a sequence diagram showing an example of the operation of the verification system 10 according to this embodiment, and is a diagram for explaining the verification method in the verification system 10 according to this embodiment.

[0040] The presentation device 100 and the management device 300 exchange their public keys (step S11). It is assumed that the presentation device 100 is online and able to communicate via the network 11.

[0041] After the public key exchange, the presentation device 100 performs a pre-configuration for the management device 300. Specifically, the presentation device 100 notifies the management device 300 of the association between the VC and the verification device 200 that presents the VC (step S12). The management device 300 stores the association between the VC and the verification device 200 that presents the VC, as notified by the presentation device 100, in the storage unit 201 (step S13). The association between the VC and the verification device 200 that presents the VC does not have to be one-to-one.

[0042] After the completion of the pre - setting, assume that the presentation device 100 enters an offline state where it cannot communicate with the management device 300 via the network 11. When the presentation device 100 presents the VC to the verification device 200 in the offline state, it notifies the verification device 200 of the endpoint. The endpoint is, for example, the URL (Uniform Resource Locator) of the management device 300 that manages the VC to be presented. The endpoint may also be the URL of another device that can verify the legitimacy of the verification device 200, which will be described later. The notification of the endpoint by the presentation device 100 includes information that can authenticate the presentation device 100, such as a signature with the private key of the presentation device 100 or a similar method. Also, the presentation device 100 notifies the verification device 200 of the ID and attributes of the VC to be presented (step S14). These pieces of information may be notified after being encrypted with the public key of the presentation device 100.

[0043] In this way, when the presentation device 100 presents the VC to the verification device 200 in an offline state where it cannot communicate with the management device 300 via the network 11, it notifies the verification device 200 of the management device 300 that manages the VC and the identification information (such as ID and attributes) of the VC.

[0044] When the verification device 200 is notified of the endpoint (the management device 300 that manages the VC) from the presentation device 100, it sends a presentation request (VC request) to the notified management device 300 to request the presentation of the VC identified by the identification information (step S15). The verification device 200 includes in the VC request the ID and attributes of the VC that the presentation device 100 is about to present, which are notified from the presentation device 100. In this way, the verification device 200 sends a request for presenting the VC to the management device 300 notified from the presentation device 100.

[0045] When the management device 300 receives the VC request from the verification device 200, it sends an attestation request (proof request) to the verification device 200 to request information regarding the legitimacy of the verification device 200 (step S16).

[0046] When the verification device 200 receives an attestation request sent from the management device 300, it transmits an attestation response (certification response) including information regarding the legitimacy of the verification device 200 to the management device 300 (step S17). Information regarding the legitimacy of the verification device 200 is, for example, an attestation report issued by the hardware of the verification device 200 or a VC that proves the attributes of the verification device 200.

[0047] When the management device 300 receives an attestation response from the verification device 200, it verifies the legitimacy of the verification device 200 based on an attestation report included in the attestation response or a VC that proves the attributes of the verification device 200. The management device 300 transmits an attestation verification result with the signature of the management device 300 attached to the verification result to the verification device 200 (step S18).

[0048] As described above, when the management device 300 receives a VC presentation request (VC request) from the verification device 200, it transmits an attestation request, which is a proof request for information regarding the legitimacy of the verification device 200, to the verification device 200. Then, the management device 300 verifies whether the verification device 200 is legitimate based on the information regarding the legitimacy of the verification device 200 (such as an attestation report included in the attestation response or a VC that proves the attributes of the verification device 200) transmitted from the verification device 200 in response to the proof request. When the management device 300 determines that the verification device 200 is legitimate, if a VC identified by the identification information included in the VC request is stored in association with the verification device 200, the management device 300 presents the VC to the verification device 200.

[0049] Since the presentation device 100 is in an offline state, it is impossible to verify the legitimacy of the verification device 200 based on an attestation report of the verification device 200 or a VC that proves the attributes of the verification device 200. In the present embodiment, the legitimacy of the verification device 200 can be verified through the interaction between the verification device 200 and the management device 300 from step S15 to step S18.

[0050] The verification device 200 verifies the VC transmitted from the management device 300. The verification device 200 transmits the VC verification result and the attention verification result to the presentation device 100 as needed (step S19).

[0051] As described above, the presentation device 100 according to this embodiment includes a control unit 103. When the control unit 103 presents verifiable credentials to the verification device 200 in an offline state where it cannot communicate with the management device 300 via the network 11, it notifies the verification device 200 of the management device 300 which manages the verifiable credentials.

[0052] Furthermore, the management device 300 according to this embodiment includes a control unit 303. When the control unit 303 receives a request from the verification device 200 to present verifiable credentials, it sends a proof request to the verification device 200 requesting proof of the legitimacy of the verification device 200. Based on the information regarding the legitimacy of the verification device sent from the verification device 200 in response to the proof request, the control unit 303 determines that the verification device 200 is legitimate and presents the verifiable credentials requested by the presentation request to the verification device 200.

[0053] By doing this, even if the presentation device 100 is offline, the validity of the verification device 200 can be confirmed, and verifiable qualification information can be presented to the verification device 200.

[0054] The following additional information is disclosed regarding the embodiments described above.

[0055] [Addendum 1] A presentation device for presenting verifiable credentials of a user, wherein the presentation device is capable of communicating via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and is also capable of communicating with the verification device without the network, and comprises a control unit, wherein the control unit is configured to notify the verification device of the management device for managing the verifiable credentials when presenting the verifiable credentials to the verification device in an offline state where communication with the management device via the network is not possible.

[0056] [Addendum 2] In the presentation device described in Addendum 1, the control unit notifies the management device of the association between the verifiable credentials and the verification device that presents the verifiable credentials.

[0057] [Appendix 3] A management device for managing verifiable user credentials, wherein the management device is capable of communicating via a network with a presentation device that presents the verifiable credentials and a verification device that verifies the verifiable credentials, and comprises a control unit, wherein when the control unit receives a presentation request from the verification device requesting the presentation of the verifiable credentials, it transmits a certification request to the verification device requesting proof of the legitimacy of the verification device, and when the verification device determines that it is legitimate based on the information regarding the legitimacy of the verification device transmitted from the verification device in response to the certification request, it presents the verifiable credentials requested by the presentation request to the verification device.

[0058] [Appendix 4] The management device described in Appendix 3, further comprising a storage unit, wherein the storage unit is configured to store the association between the verifiable credentials notified by the presentation device and the verification device that presents the verifiable credentials, and the control unit, upon receiving the presentation request from the verification device, presents the verifiable credentials stored in association with the verification device to the verification device.

[0059] [Appendix 5] Verification device for verifying user verifiable credentials, wherein the verification device is capable of communicating via a network with a management device that manages the verifiable credentials and a presentation device that presents the verifiable credentials, and is also capable of communicating with the presentation device without the network, and comprises a control unit, wherein when the control unit is notified by the presentation device of the management device that manages the verifiable credentials, it transmits a presentation request to the notified management device requesting the presentation of the verifiable credentials, and when the control unit receives a certification request from the management device requesting information regarding the legitimacy of the verification device in response to the presentation request, it transmits a certification response containing information regarding the legitimacy of the verification device to the management device.

[0060] [Addendum 6] Verification device as described in Addendum 5, wherein the control unit, upon being notified by the presentation device of a management device that manages the verifiable credentials, transmits a presentation request to the notified management device requesting the presentation of the verifiable credentials, and verifies the verifiable credentials transmitted from the management device in response to the presentation request.

[0061] [Addendum 7] A verification method in a verification system comprising a presentation device for presenting verifiable user credentials, a management device for managing the verifiable credentials, and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network, the presentation device notifies the management device of the association between the verifiable credentials and the verification device presenting the verifiable credentials, the management device stores the association between the verifiable credentials and the verification device presenting the verifiable credentials notified by the presentation device, and when the presentation device presents the verifiable credentials to the verification device in an offline state where it cannot communicate with the management device via the network, it notifies the verification device of the management device that manages the verifiable credentials, and the verification device transmits a presentation request to the management device notified by the presentation device requesting the presentation of the verifiable credentials. A verification method comprising: the management device presents verifiable credentials stored in association with the verification device that sent the presentation request to the verification device; and the verification device verifies the verifiable credentials sent from the management device.

[0062] [Appendix 8] A non-temporary storage medium storing a program executable by a computer, the non-temporary storage medium storing a program that causes the computer to function as the presentation device described in Appendix 1 or 2, the management device described in Appendix 3 or 4, or the verification device described in Appendix 5 or 6.

[0063] Although the embodiments described above are representative examples, it will be apparent to those skilled in the art that many modifications and substitutions are possible within the spirit and scope of this disclosure. Therefore, the present invention should not be construed as being limited by the embodiments described above, and various modifications or changes are possible without departing from the claims. For example, it is possible to combine multiple component blocks shown in the configuration diagram of the embodiments into one, or to divide one component block.

[0064] 10 Verification system 11 Network 100 Presentation device 200 Verification device 300 Management device 101, 201, 301 Storage unit 102, 202, 302 Communication unit 103, 203, 303 Control unit

Claims

1. A presentation device for presenting user verifiable credentials, wherein the presentation device is capable of communicating via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and is capable of communicating with the verification device without the network, and includes a control unit that notifies the verification device of the management device for managing the verifiable credentials when presenting the verifiable credentials to the verification device in an offline state where communication with the management device via the network is not possible.

2. A presentation device according to claim 1, wherein the control unit notifies the management device of the association between the verifiable credentials and a verification device that presents the verifiable credentials.

3. A management device for managing user verifiable credentials, the management device being able to communicate via a network with a presentation device that presents the verifiable credentials and a verification device that verifies the verifiable credentials, and a control unit that, upon receiving a presentation request from the verification device requesting the presentation of the verifiable credentials, transmits a certification request to the verification device requesting proof of the legitimacy of the verification device, and, based on the information regarding the legitimacy of the verification device transmitted from the verification device in response to the certification request, determines that the verification device is legitimate, and presents the verifiable credentials requested by the presentation request to the verification device.

4. A management device according to claim 3, further comprising a storage unit that stores the association between the verifiable credentials notified by the presentation device and a verification device that presents the verifiable credentials, wherein the control unit, upon receiving the presentation request from the verification device, presents the verifiable credentials stored in association with the verification device to the verification device.

5. A verification device for verifying user verifiable credentials, wherein the verification device is capable of communicating via a network with a management device for managing the verifiable credentials and a presentation device for presenting the verifiable credentials, and is also capable of communicating with the presentation device without the network, and includes a control unit that, upon being notified by the presentation device of the management device for managing the verifiable credentials, transmits a presentation request to the notified management device requesting the presentation of the verifiable credentials, and upon receiving a certification request from the management device in response to the presentation request requesting information regarding the legitimacy of the verification device, transmits a certification response including information regarding the legitimacy of the verification device to the management device.

6. Verification device according to claim 5, wherein the control unit, upon being notified by the presentation device of a management device that manages the verifiable credentials, transmits a presentation request to the notified management device requesting the presentation of the verifiable credentials, and verifies the verifiable credentials transmitted from the management device in response to the presentation request.

7. A verification method in a verification system comprising: a presentation device for presenting user verifiable credentials; a management device for managing the verifiable credentials; and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network; the presentation device notifies the management device of the association between the verifiable credentials and the verification device presenting the verifiable credentials; the management device stores the association between the verifiable credentials and the verification device presenting the verifiable credentials notified by the presentation device; when the presentation device presents the verifiable credentials to the verification device in an offline state where it cannot communicate with the management device via the network, it notifies the verification device of the management device that manages the verifiable credentials; and the verification device transmits a presentation request to the management device notified by the presentation device, requesting the presentation of the verifiable credentials. A verification method comprising the steps of: the management device presenting verifiable credentials stored in association with the verification device that sent the presentation request to the verification device; and the verification device verifying the verifiable credentials sent from the management device.

8. A program that causes a computer to operate as the presentation device described in claim 1 or 2, the management device described in claim 3 or 4, or the verification device described in claim 5 or 6.

Citation Information

Patent Citations

  • Decentralized identity label protection method and system based on pseudonyms

    CN117786744A

  • Integrated authentication system for decentralized identity platforms

    JP2022544411A

  • TERMINAL, SYSTEM, TERMINAL CONTROL METHOD AND PROGRAM

    JP7485187B1

  • Certificate authenticating method, certificate issuing device, and authentication device

    WO2008096825A1