Presentation device, management device, verification device, verification method, and program
The solution allows offline presentation of verifiable credentials through a device with storage and control units, addressing the issue of offline credential presentation in digital identity management systems by using stored credentials and certificates.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-02
AI Technical Summary
Existing digital identity management systems fail to allow users to present verifiable credentials when their devices are offline, as they rely on network connectivity to retrieve credentials from cloud-based management systems.
A presentation device equipped with a storage unit and control unit to store and transmit verifiable credentials and an Offline ID certificate, enabling offline communication with verification devices, and a management device to notify credentials and certificates to the presentation device when online, ensuring offline verification.
Enables the presentation of verifiable credentials even when the presentation device is offline by using stored credentials and certificates, ensuring seamless identity verification without network connectivity.
Smart Images

Figure JP2024033966_02042026_PF_FP_ABST
Abstract
Description
Presentation device, management device, verification device, verification method, and program
[0001] The present disclosure relates to a presentation device, a management device, a verification device, a verification method, and a program.
[0002] In recent years, self-sovereign identity (SSI) technology has been studied in which users manage their own identifiers and identities and control presentation destinations without depending on a centralized identity provider (IdP) or the like (see Non-Patent Documents 1 and 2).
[0003] In digital identity, there are three parties: Holder, Issuer, and Verifier. The Holder is a user or the like who manages and holds his / her digital identity. The Issuer issues verifiable credential information (VC: Verifiable Credentials) that proves the user's attributes and / or qualifications to the Holder after verifying attribute information (name, age, address, etc.), qualification information (being an employee of a certain company, being a member of a certain service, etc.). The Verifier requests and receives the VCs necessary for service provision from the Holder, verifies the Holder's attributes, qualifications, etc., and makes decisions such as service provision.
[0004] A digital identity wallet (DIW: Digital Identity Wallet) has been proposed that manages the ID data of a user (Holder) and is used for identity verification and attribute proof (see Non-Patent Document 3). As embodiments of the DIW, there are two forms: a form in which ID data is managed within a user device (local wallet) and a form in which ID data is managed on a platform hosted by a cloud provider or the like (cloud wallet).
[0005] “W3C Decentralized Identifiers (DID)” [online], [Accessed September 9, 2024], Internet<URL: https: / / www.w3.org / TR / did-core / > “W3C Verifiable Credentials” [online], [Accessed September 9, 2024], Internet<URL: https: / / www.w3.org / TR / vc-data-model / > “European digital identity wallet” [online], [searched September 9, 2024], Internet <URL: https: / / digital-strategy.ec.europa.eu / en / library / european-digital-identity-wallet-architecture-and-reference-framework>
[0006] By using a cloud-based DIW (Data Identity Warehouse), users can reduce the effort required to properly manage user devices equipped with ID data and ID data processing functions. Furthermore, using a cloud-based DIW reduces the risk of external access to ID data due to factors such as loss of user devices or inadequate security settings.
[0007] In a scenario where a user's digital identity is managed in a cloud wallet, when the Holder device (presenting device) is online and can communicate with the cloud wallet (management device) via the network, the presenting device can communicate with the management device, obtain the VC managed by the management device, and present it to the Verifier (verification device). However, when the presenting device is offline and cannot communicate with the management device via the network, it cannot obtain the VC and therefore cannot present it to the verification device. Consequently, a mechanism is needed that allows the presenting device to present the VC to the verification device even when it is offline.
[0008] In light of the problems described above, the purpose of this disclosure is to provide a presentation device, a management device, a verification device, a verification method, and a program that can present verifiable credentials to a verification device even when the presentation device is offline.
[0009] A presentation device according to one embodiment is a presentation device for presenting verifiable credentials of a user, the presentation device is capable of communicating via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and is capable of communicating with the verification device without the network, and comprises a storage unit that stores verifiable credentials of the user managed by the management device, which are notified by the management device when the presentation device is online and can communicate with the management device via the network, and an Offline ID certificate that proves that the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network, and a control unit that, when presenting the stored verifiable credentials to the verification device in the offline state, transmits the stored verifiable credentials and the Offline ID certificate to the verification device.
[0010] A management device according to one embodiment is a management device for managing user verifiable credentials, wherein the management device is capable of communicating via a network with a presentation device that presents the verifiable credentials and a verification device that verifies the verifiable credentials, and includes a control unit that, when the presentation device is online and able to communicate with the management device via the network, notifies the presentation device of the verifiable credentials of the user to be managed and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and unable to communicate with the management device via the network.
[0011] A verification device according to one embodiment is a verification device for verifying a user's verifiable credentials, wherein the verification device is able to communicate via a network with a management device that manages the verifiable credentials and a presentation device that presents the verifiable credentials, and is also able to communicate with the presentation device without using the network, and includes a control unit that receives the user's verifiable credentials transmitted from the presentation device, the verifiable credentials of the managed user, and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network, and verifies the verifiable credentials when it determines, based on the Offline ID certificate, that the verifiable credentials were issued to the user.
[0012] A verification method according to one embodiment is a verification method in a verification system comprising: a presentation device that presents verifiable credentials of a user; a management device that manages the verifiable credentials; and a verification device that verifies the verifiable credentials, wherein the presentation device, the management device, and the verification device can communicate with each other via a network, and the presentation device and the verification device can communicate with each other without the network; the management device notifies the presentation device of the verifiable credentials it manages and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network; the presentation device stores the verifiable credentials and the Offline ID certificate notified by the management device; and when the presentation device presents the stored verifiable credentials to the verification device, it transmits the stored verifiable credentials and the Offline ID certificate to the verification device. The verification device receives the verifiable credentials and the Offline ID certificate transmitted from the presentation device, verifies that the verifiable credentials were issued to the user based on the Offline ID certificate, and if it determines that the verifiable credentials were issued to the user based on the Offline ID certificate, it verifies the verifiable credentials.
[0013] A program according to one embodiment causes a computer to operate as the presentation device, the management device, or the verification device.
[0014] According to this disclosure, verifiable credentials can be presented to the verification device even when the presentation device is offline.
[0015] This figure shows an example configuration of a verification system according to one embodiment of this disclosure. This figure schematically shows the operation of the verification system shown in Figure 1. This is a sequence diagram showing an example of the operation of the verification system shown in Figure 1.
[0016] Embodiments of this disclosure will be described below with reference to the drawings.
[0017] Figure 1 is a diagram showing an example configuration of a verification system 10 according to one embodiment of the present disclosure.
[0018] As shown in Figure 1, the verification system 10 according to this embodiment comprises a presentation device 100, a verification device 200, and a management device 300. The presentation device 100, the verification device 200, and the management device 300 can communicate with each other via a network 11 such as the Internet. The presentation device 100 and the verification device 200 can also communicate without using the network 11. For example, the presentation device 100 and the verification device 200 can communicate using proximity communication. Therefore, even when the presentation device 100 is offline and cannot communicate via the network 11, the presentation device 100 and the verification device 200 can communicate using proximity communication, for example.
[0019] The presentation device 100 is a device used by the user (Holder), such as a smartphone or personal computer. The presentation device 100 presents the user's verifiable credentials (VC). As mentioned above, a VC is a certificate that proves the user's attributes and / or qualifications. The VC is issued by an Issuer that verifies the user's attributes and qualifications and issues a signed certificate. In a cloud wallet, the VC is managed by the management device 300. When online, the presentation device 100 retrieves the VC managed by the management device 300 and presents it to the verification device 200. On the other hand, when offline, the presentation device 100 cannot retrieve the VC from the management device 300 and cannot present the VC to the verification device 200.
[0020] As shown in Figure 1, the presentation device 100 according to this embodiment comprises a storage unit 101, a communication unit 102, and a control unit 103.
[0021] The storage unit 101 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM (Random Access Memory), ROM (Read Only Memory), or flash memory. The RAM is, for example, SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory). The ROM is, for example, EEPROM (Electrically Erasable Programmable Read Only Memory). The flash memory is, for example, SSD (Solid-State Drive). The magnetic memory is, for example, HDD (Hard Disk Drive). The storage unit 101 functions, for example, as main memory, auxiliary memory, or cache memory. The storage unit 101 stores information used for the operation of the presentation device 100 and information obtained by the operation of the presentation device 100. The storage unit 101 stores, for example, a VC managed by the management device 300, which is notified by the management device 300 (described later), and an Offline ID certificate that proves that the VC was issued to the VC user even when offline.
[0022] The communication unit 102 includes at least one communication module. The communication module is, for example, a module compatible with a LAN communication standard such as Ethernet (registered trademark). The communication unit 102 communicates with the verification device 200 and the management device 300 via the network 11. The communication unit 102 also communicates with the verification device 200 without using the network 11. The communication unit 102 also communicates with the verification device 200 via proximity communication, for example. The communication unit 102 receives information used for the operation of the presentation device 100 and transmits information obtained through the operation of the presentation device 100.
[0023] The control unit 103 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit), or a dedicated processor specialized for a specific process. The programmable circuit is, for example, an FPGA (Field-Programmable Gate Array). The dedicated circuit is, for example, an ASIC (Application Specific Integrated Circuit).
[0024] The control unit 103 controls each part of the presentation device 100 and executes processes related to the operation of the presentation device 100. For example, when the presentation device 100 is in an offline state where it cannot communicate with the management device 300 via the network 11, and the control unit 103 presents the stored VC to the verification device 200, it transmits the stored VC and the Offline ID certificate to the verification device 200.
[0025] Verification device 200 is a device used by Verifier. Verification device 200 verifies the user's verifiable credentials (VC) (verifies the user's (Holder's) attributes and credentials, etc.).
[0026] As shown in Figure 1, the verification device 200 according to this embodiment includes a storage unit 201, a communication unit 202, and a control unit 203.
[0027] The storage unit 201, like the storage unit 101, includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 201 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 201 stores information used for the operation of the verification device 200 and information obtained by the operation of the verification device 200.
[0028] The communication unit 202, like the communication unit 102, includes at least one communication module. The communication unit 202 communicates with the display device 100 and the management device 300 via the network 11. The communication unit 202 also communicates with the display device 100 without using the network 11. For example, the communication unit 202 communicates with the display device 100 via proximity communication. The communication unit 202 receives information used for the operation of the verification device 200 and transmits information obtained through the operation of the verification device 200.
[0029] The control unit 203 controls each part of the verification device 200 and executes processes related to the operation of the verification device 200. For example, the control unit 203 receives the VC and Offline ID certificate transmitted from the presentation device 100. If the control unit 203 determines that the VC was issued to the user based on the Offline ID certificate, it verifies the VC.
[0030] The management device 300 is a device such as a server connected to the network 11. The management device 300 manages user verifiable credentials (VCs) issued to the Holder by the Issuer.
[0031] As shown in Figure 1, the management device 300 according to this embodiment includes a storage unit 301, a communication unit 302, and a control unit 303.
[0032] Like the storage unit 101, the storage unit 301 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 301 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 301 stores information used for the operation of the management device 300 and information obtained by the operation of the management device 300.
[0033] The communication unit 302, like the communication unit 102, includes at least one communication module. The communication unit 302 communicates with the presentation device 100 and the verification device 200 via the network 11. The communication unit 302 receives information used for the operation of the management device 300 and transmits information obtained through the operation of the management device 300.
[0034] The control unit 303 controls each part of the management device 300 and executes processes related to the operation of the management device 300. For example, when the presentation device 100 is online and can communicate with the management device 300 via the network 11, the control unit 303 notifies the presentation device 100 of the VC of the user to be managed and an Offline ID certificate that proves that the VC was issued to the user even when offline. The Offline ID certificate indicates an ID that identifies the user (Holder) to whom the VC was issued.
[0035] The functions of the presentation device 100, the verification device 200, and the management device 300 are realized by executing the program according to this embodiment on processors acting as control units 103, 203, and 303. In other words, the functions of the presentation device 100, the verification device 200, and the management device 300 are realized by software. The program causes the computer to execute the operations of the presentation device 100, the verification device 200, and the management device 300, thereby causing the computer to function as the presentation device 100, the verification device 200, and the management device 300. That is, the computer functions as the presentation device 100, the verification device 200, and the management device 300 by executing the operations of the presentation device 100, the verification device 200, and the management device 300 according to the program.
[0036] The program can be stored on a non-temporary computer-readable medium. Examples of non-temporary computer-readable mediums include flash memory, magnetic recording devices, optical discs, magneto-optical recording media, or ROM. The program can be distributed, for example, by selling, transferring, or leasing portable media such as SD (Secure Digital) cards, DVDs (Digital Versatile Discs), or CD-ROMs (Compact Disc Read Only Memory) on which the program is stored. The program may also be distributed by storing it in server storage and transferring it from the server to other computers. The program may also be provided as a program product.
[0037] A computer, for example, stores a program stored on a portable medium or a program transferred from a server in its main memory. Then, the computer reads the program stored in the main memory with its processor and executes the processing according to the read program. The computer may also read the program directly from the portable medium and execute the processing according to the program. The computer may also execute the processing according to the received program sequentially each time a program is transferred to it from a server. Processing may also be performed by a so-called ASP (Application Service Provider) type service, which does not transfer programs from the server to the computer, but realizes its function only through execution instructions and result retrieval. A program includes information used for processing by an electronic computer that is equivalent to a program. For example, data that is not a direct instruction to the computer but has the nature of defining the computer's processing falls under "equivalent to a program".
[0038] Some or all of the functions of the presentation device 100, the verification device 200, and the management device 300 may be implemented by programmable circuits or dedicated circuits as control units 103, 203, and 303. In other words, some or all of the functions of the presentation device 100, the verification device 200, and the management device 300 may be implemented by hardware.
[0039] Next, the operation of each device in the verification system 10 according to this embodiment will be described. Figure 2 is a schematic diagram showing the operation of each device in the verification system 10 according to this embodiment, and is a diagram for explaining the presentation of VC from the presentation device 100 to the verification device 200 when the presentation device 100 is in an offline state.
[0040] The Issuer's issuing device 400 registers a public key created from the private key (Issuer private key) associated with the Issuer's identifier (Decentralized Identifier: DID) with the blockchain 500. The management device 300 also registers a public key created from the private key (Holder private key) associated with the Management Device 300's identifier (DID) with the blockchain 500.
[0041] The issuing device 400 issues a VC (Online VC) to the user (Holder) to the management device 300. The management device 300 manages the VC issued by the issuing device 400 by storing it in the storage unit 301, etc. The VC managed by the management device 300 includes the Holder's DID, the Holder's attributes, the issuing device 400's (Issuer) DID, and the issuing device 400's (Issuer) signature. The management device 300 uses the issuing device 400's public key registered in the blockchain 500 to verify whether the signature of the issuing device 400 included in the VC is legitimate (whether the VC was legitimately issued by the issuing device 400).
[0042] When the issuing device 400 determines that the VC issued is legitimate, the management device 300, while online and able to communicate with the presentation device 100 via the network 11, transmits the managed VC and an Offline ID certificate to the presentation device 100, which proves that the VC was issued to the user even when offline. The Offline ID certificate indicates the ID (Offline ID) that identifies the user (Holder) to whom the VC was issued.
[0043] A Holder has various VCs depending on their attributes (name, age, address, etc.) and qualifications (whether they are an employee of a certain company, a member of a certain service, etc.). The management device 300 manages the various VCs of the Holder and transmits some of these VCs to the display device 100 when online. For example, the management device 300 transmits to the display device 100 when online the VCs that have been pre-specified by the user (Holder).
[0044] When the presentation device 100 presents the VC to the verification device 200 in the online state, the presentation device 100 requests the VC to be presented to the management device 300. The management device 300 transmits the VC to the presentation device 100 in response to the request from the presentation device 100. In the present embodiment, the management device 300 further transmits the VC to the presentation device 100 without a request from the presentation device 100 in the online state.
[0045] The presentation device 100 stores the VC (Online VC) transmitted from the management device 300 and the Offline ID proof in the storage unit 101.
[0046] When the presentation device 100 presents the stored VC to the verification device 200 in the offline state, the presentation device 100 transmits the VC and the Offline ID proof to the verification device 200 together with the signature by the private key (Holder private key) of the presentation device 100 associated with the Offline ID of the user (Holder) indicated in the Offline ID proof.
[0047] The verification device 200 receives the VC and the Offline ID proof transmitted from the presentation device 100. The verification device 200 determines whether the VC was issued to the user (Holder) based on the Offline ID proof. When the verification device 200 determines that the VC was issued to the user (Holder), the verification device 200 determines whether the VC was properly issued by the issuing device 400 to the user by the public key of the management device 300 stored in the blockchain 500. When the verification device 200 determines that the VC was properly issued to the Holder, the verification device 200 verifies the received VC.
[0048] FIG. 3 is a sequence diagram showing an example of the operation of the verification system 10 according to the present embodiment, and is a diagram for explaining the verification method in the verification system 10 according to the present embodiment.
[0049] The presentation device 100 and the management device 300 exchange their public keys (step S11). It is assumed that the presentation device 100 is in an online state where it can communicate via the network 11.
[0050] After the public key exchange, the management device 300 transfers the VCs it manages to the presentation device 100 when the presentation device 100 is online and can communicate with the management device 300 via the network 11 (step S12). Specifically, the management device 300 sends the VCs and an Offline ID certificate to the presentation device 100, which proves that the VCs were issued to the user (Holder) even when offline. As described above, the management device 300 sends, for example, some of the VCs it manages (for example, VCs specified by the user) to the presentation device 100. The management device 300 transfers the VCs to the presentation device 100 at predetermined time intervals. In this way, even if a VC is updated, the latest VC can be transferred to the presentation device 100.
[0051] The presentation device 100 stores the VC and Offline ID certificate notified by the management device 300 in the storage unit 101 (step S13).
[0052] Assume that after the transfer of the VC, the presentation device 100 goes offline and is unable to communicate with the management device 300 via the network 11. When the presentation device 100 presents a stored VC to the verification device 200 while offline, it notifies the verification device 200 of an endpoint (step S14). The endpoint is the URL (Uniform Resource Locator) of the management device 300 that manages the VC to be presented. The endpoint may also be the URL of another device capable of verifying the legitimacy of the verification device 200, as described later. The notification of the endpoint by the presentation device 100 includes information that allows the presentation device 100 to be authenticated by signing with the presentation device 100's private key or by a similar method. Thus, when the presentation device 100 presents a stored VC to the verification device 200 while offline, it notifies the verification device 200 of the endpoint that manages the VC (for example, information that identifies the management device 300, such as the URL of the management device 300).
[0053] When the verification device 200 receives notification from the presentation device 100 of an endpoint (a management device 300 that manages the VC), it sends an attendance start request to the notified management device 300 requesting the verification of the validity of the verification device 200 to begin (step S15).
[0054] When the management device 300 receives an attendance start request from the verification device 200, it sends an attendance request (certification request) to the verification device 200 requesting information regarding the legitimacy of the verification device 200 (step S16).
[0055] When the verification device 200 receives an attestation request sent from the management device 300 in response to an attestation start request, it sends an attestation response (certification response) containing information regarding the legitimacy of the verification device 200 to the management device 300 (step S17). The information regarding the legitimacy of the verification device 200 may be, for example, an attestation report issued by the hardware of the verification device 200 or a VC that certifies the attributes of the verification device 200.
[0056] When the management device 300 receives an attention response from the verification device 200, it verifies the legitimacy of the verification device 200 based on the attention report included in the attention response or a VC that proves the attributes of the verification device 200. The management device 300 sends the attention verification result, which has been signed by the management device 300, to the verification device 200 (step S18). The management device 300 may encrypt the attention verification result with the public key of the presentation device 100.
[0057] The verification device 200 transmits the attestation verification result received from the management device 300 to the presentation device 100 (step S19).
[0058] If the attendance verification result transmitted from the verification device 200 indicates that the validity of the verification device 200 has been verified by the management device 300, the presentation device 100 transmits the VC to be presented to the verification device 200 (step S20). The presentation device 100 transmits the Offline ID certificate along with the VC to the verification device 200. In this way, when the presentation device 100 is notified by the verification device 200 that the validity of the verification device 200 has been verified by the management device 300, it transmits the stored VC and Offline ID certificate to the verification device 200 (step S20).
[0059] The verification device 200 verifies the VC transmitted from the presentation device 100.
[0060] As described above, the management device 300 according to this embodiment includes a control unit 303. When the presentation device 100 is online and can communicate with the management device 300 via the network 11, the control unit 303 notifies the presentation device 100 of the verifiable credentials (VC) to be managed, and an Offline ID certificate that proves that the verifiable credentials have been issued to the user, even when offline.
[0061] Furthermore, the presentation device 100 according to this embodiment includes a storage unit 101 and a control unit 103. The storage unit 101 stores verifiable credentials managed by the management device 300, which are notified by the management device 300, and an Offline ID certificate that proves that the verifiable credentials were issued to the user even in an offline state. When the control unit 103 presents the stored verifiable credentials to the verification device 200 in an offline state where it cannot communicate with the management device 300 via the network 11, it transmits the stored verifiable credentials and the Offline ID certificate to the verification device 200.
[0062] Furthermore, the verification device 200 according to this embodiment includes a control unit 203. The control unit 203 receives verifiable credentials transmitted from the presentation device 100 and an Offline ID certificate that proves that the verifiable credentials were issued to the user even in an offline state. When the control unit 203 determines that the verifiable credentials were issued to the user based on the Offline ID certificate, it verifies the verifiable credentials.
[0063] Verifiable credentials and Offline ID certificates are pre-stored in the presentation device 100 while online. When offline, the stored verifiable credentials and Offline ID certificates are transmitted to the verification device 200. This allows the verification device 200 to confirm that the verifiable credentials were issued to the user, and then present the verifiable credentials to the verification device 200. Therefore, according to this disclosure, verifiable credentials can be presented to the verification device 200 even when the presentation device 100 is offline.
[0064] Furthermore, in this embodiment, when the presentation device 100 presents verifiable credentials stored to the verification device 200, it notifies the verification device 200 of an endpoint capable of verifying the legitimacy of the verification device 200. When the presentation device 100 receives notification from the verification device 200 that the legitimacy of the verification device 200 has been verified by the endpoint, it transmits the stored verifiable credentials and the ID certificate to the verification device 200.
[0065] In this embodiment, when the verification device 200 receives notification from the presentation device 100 of an endpoint capable of verifying the legitimacy of the verification device 200, it sends a start request to the notified endpoint requesting the start of proof of the legitimacy of the verification device 200. Upon receiving a proof request in response to the start request, the verification device 200 sends a proof response containing information regarding the legitimacy of the verification device 200 to the management device. Then, upon receiving a verification result in response to the proof response that proves the legitimacy of the verification device 200, the verification device 200 sends the verification result to the presentation device 100 and verifies the verifiable credentials sent from the presentation device 100 according to the verification result.
[0066] In this embodiment, when the management device 300 receives a start request from the verification device 200 requesting the start of the verification of the verification device 200's legitimacy, it sends a proof request to the verification device requesting information regarding the legitimacy of the verification device 200. The management device 300 then verifies whether the verification device 200 is legitimate based on the information regarding the legitimacy of the verification device 200 sent from the verification device 200 in response to the proof request, and sends the verification result to the verification device 200.
[0067] By doing this, even if the presentation device 100 is offline, the validity of the verification device 200 can be confirmed, and verifiable qualification information can be presented to the verification device 200.
[0068] The following additional information is disclosed regarding the embodiments described above.
[0069] [Addendum 1] A presentation device for presenting user verifiable credentials, wherein the presentation device is able to communicate via a network with a management device that manages the verifiable credentials, and is able to communicate without the network with a verification device that verifies the verifiable credentials, and comprises a storage unit and a control unit, wherein the storage unit is configured to store verifiable credentials of the user managed by the management device, which are notified by the management device when the presentation device is online and able to communicate with the management device via the network, and an Offline ID certificate which proves that the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network, and the control unit is configured to transmit the stored verifiable credentials and the Offline ID certificate to the verification device when presenting the stored verifiable credentials to the verification device in the offline state.
[0070] [Addendum 2] In the presentation device described in Addendum 1, the control unit notifies the verification device of a management device that manages the verifiable credentials when presenting the stored verifiable credentials to the verification device, and when the verification device notifies the control unit that the management device has verified the legitimacy of the verification device, the control unit transmits the stored verifiable credentials and the Offline ID certificate to the verification device.
[0071] [Appendix 3] A management device for managing verifiable user credentials, wherein the management device is capable of communicating via a network with a presentation device that presents the verifiable credentials and a verification device that verifies the verifiable credentials, and comprises a control unit, wherein the control unit is configured to notify the presentation device of the verifiable credentials of the user to be managed, and an Offline ID certificate that proves the verifiable credentials were issued to the user, even when the presentation device is in an online state where it can communicate with the management device via the network.
[0072] [Addendum 4] A management device as described in Addendum 3, wherein the control unit, upon receiving a start request from the verification device requesting the start of proof of the validity of the verification device, transmits a proof request to the verification device requesting information regarding the validity of the verification device, verifies whether the verification device is valid or not based on the information regarding the validity of the verification device transmitted from the verification device in response to the proof request, and transmits the verification result to the verification device.
[0073] [Appendix 5] Verification device for verifying user verifiable credentials, wherein the verification device is capable of communicating via a network with a management device that manages the verifiable credentials, and is capable of communicating without the network with a presentation device that presents the verifiable credentials, and comprises a control unit, wherein the control unit receives the user's verifiable credentials transmitted from the presentation device, the user's verifiable credentials to be managed, and an Offline ID certificate that proves the verifiable credentials were issued to the user even in an offline state where the presentation device cannot communicate with the management device via the network, and when it determines that the verifiable credentials were issued to the user based on the Offline ID certificate, it verifies the verifiable credentials.
[0074] [Addendum 6] A verification device as described in Addendum 5, wherein the control unit, upon being notified by the presentation device of a management device that manages the verifiable credentials, transmits a start request to the notified management device requesting the start of proof of the validity of the verification device; upon receiving a proof request in response to the start request requesting information regarding the validity of the verification device, transmits a proof response containing information regarding the validity of the verification device to the management device; and upon receiving a verification result in response to the proof response that proves the validity of the verification device, transmits the verification result to the presentation device.
[0075] [Addendum 7] A verification method in a verification system comprising: a presentation device that presents verifiable credentials of a user; a management device that manages the verifiable credentials and is able to communicate with the presentation device via a network; and a verification device that verifies the verifiable credentials and is able to communicate with the presentation device without the network, wherein the management device notifies the presentation device of the verifiable credentials it manages and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network; the presentation device stores the verifiable credentials and the Offline ID certificate notified by the management device; and when the presentation device presents the stored verifiable credentials to the verification device, it transmits the stored verifiable credentials and the Offline ID certificate to the verification device. Verification method comprising: the verification device receiving the verifiable credentials and the Offline ID certificate transmitted from the presentation device; verifying that the verifiable credentials were issued to the user based on the Offline ID certificate; and, if it determines that the verifiable credentials were issued to the user based on the Offline ID certificate, verifying the verifiable credentials.
[0076] [Appendix 8] A non-temporary storage medium storing a program executable by a computer, the non-temporary storage medium storing a program that causes the computer to function as the presentation device described in Appendix 1, the management device described in Appendix 3, or the verification device described in Appendix 5.
[0077] Although the embodiments described above are representative examples, it will be apparent to those skilled in the art that many modifications and substitutions are possible within the spirit and scope of this disclosure. Therefore, the present invention should not be construed as being limited by the embodiments described above, and various modifications or changes are possible without departing from the claims. For example, it is possible to combine multiple component blocks shown in the configuration diagram of the embodiments into one, or to divide one component block.
[0078] 10 Verification system 11 Network 100 Presentation device 200 Verification device 300 Management device 400 Issuing device 500 Blockchain 101, 201, 301 Storage unit 102, 202, 302 Communication unit 103, 203, 303 Control unit
Claims
1. A presentation device for presenting user verifiable credentials, the presentation device being able to communicate via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and also being able to communicate with the verification device without the network, and comprising: a storage unit that stores verifiable credentials of the user managed by the management device, which are notified by the management device when the presentation device is online and able to communicate with the management device via the network, and an Offline ID certificate that proves that the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network; and a control unit that, when presenting the stored verifiable credentials to the verification device in the offline state, transmits the stored verifiable credentials and the Offline ID certificate to the verification device.
2. The presentation device according to claim 1, wherein the control unit, when presenting the stored verifiable credentials to the verification device, notifies the verification device of an endpoint capable of verifying the legitimacy of the verification device, and when notified by the verification device that the legitimacy of the verification device has been proven by the endpoint, transmits the stored verifiable credentials and the Offline ID certificate to the verification device.
3. A management device for managing user verifiable credentials, wherein the management device is capable of communicating via a network with a presentation device that presents the verifiable credentials and a verification device that verifies the verifiable credentials, and comprises a control unit that, when the presentation device is online and able to communicate with the management device via the network, notifies the presentation device of the verifiable credentials of the user to be managed and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and unable to communicate with the management device via the network.
4. A management device according to claim 3, wherein the control unit, upon receiving a start request from the verification device requesting the start of proof of the validity of the verification device, transmits a proof request to the verification device requesting information regarding the validity of the verification device, verifies whether the verification device is valid or not based on the information regarding the validity of the verification device transmitted from the verification device in response to the proof request, and transmits the verification result to the verification device.
5. A verification device for verifying user verifiable credentials, wherein the verification device is capable of communicating via a network with a management device for managing the verifiable credentials and a presentation device for presenting the verifiable credentials, and is also capable of communicating with the presentation device without the network, and receives the user's verifiable credentials transmitted from the presentation device, the verifiable credentials of the managed user, and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network, and if it determines based on the Offline ID certificate that the verifiable credentials were issued to the user, it includes a control unit that verifies the verifiable credentials.
6. Verification device according to claim 5, wherein the control unit, upon being notified by the presentation device of an endpoint capable of verifying the validity of the verification device, transmits a start request to the notified endpoint requesting the start of proof of the validity of the verification device; upon receiving a proof request in response to the start request requesting information regarding the validity of the verification device, transmits a proof response containing information regarding the validity of the verification device to the management device; and upon receiving a verification result in response to the proof response that proves the validity of the verification device, transmits the verification result to the presentation device.
7. A verification method in a verification system comprising a presentation device for presenting user verifiable credentials, a management device for managing the verifiable credentials, and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate with each other without the network; the management device notifies the presentation device of the verifiable credentials it manages and an Offline ID certificate that proves the verifiable credentials were issued to the user even when the presentation device is offline and cannot communicate with the management device via the network; the presentation device stores the verifiable credentials and the Offline ID certificate notified by the management device; and when the presentation device presents the stored verifiable credentials to the verification device, it transmits the stored verifiable credentials and the Offline ID certificate to the verification device. Verification method comprising: the verification device receiving the verifiable credentials and the Offline ID certificate transmitted from the presentation device; verifying that the verifiable credentials were issued to the user based on the Offline ID certificate; and, if it determines that the verifiable credentials were issued to the user based on the Offline ID certificate, verifying the verifiable credentials.
8. A program that causes a computer to operate as the presentation device described in claim 1 or 2, the management device described in claim 3 or 4, or the verification device described in claim 5 or 6.
Citation Information
Patent Citations
TERMINAL, SYSTEM, TERMINAL CONTROL METHOD AND PROGRAM
JP7485187B1
Certificate authenticating method, certificate issuing device, and authentication device
WO2008096825A1