Presentation device, verification system, verification method, and program

The presentation device, using a tamper-resistant circuit and cryptographic authentication, enables secure offline presentation of verifiable credentials by generating a signed signature response, addressing the vulnerability of offline credential presentation in digital identity management systems.

WO2026088356A1PCT designated stage Publication Date: 2026-04-30NT T INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-23
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

Existing digital identity management systems fail to securely present verifiable credentials when the presenting device is offline, making them vulnerable to information tampering.

Method used

A presentation device equipped with a tamper-resistant storage arithmetic processing circuit and a control unit that uses a user authentication authority certificate and private key to generate a signed signature response, allowing secure credential presentation even offline, verified by a verification device through a management device.

Benefits of technology

Ensures secure and tamper-proof presentation of verifiable credentials offline by leveraging a tamper-resistant memory arithmetic processing circuit and cryptographic authentication, preventing information tampering and ensuring legitimacy verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024037817_30042026_PF_FP_ABST
    Figure JP2024037817_30042026_PF_FP_ABST
Patent Text Reader

Abstract

A presentation device (100) according to the present disclosure comprises a control unit (103) and a SIM card (104). The SIM card (104) stores a user certification authority certificate, a user public key, and a user private key paired with the public key, all of which are issued by a certification authority (600). When presenting VCs to a verification device (200), the control unit (103) outputs, to the SIM card (104), a signature request including information relating to verifiable credentials. In response to the signature request, the SIM card (104) outputs, to the control unit (103), a signature response to which a signature created using the private key is attached, the signature response including the user certification authority certificate and information relating to the VCs included in the signature request, the user certification authority certificate including the public key and having the signature of the certification authority (600) attached thereto. The control unit (103) transmits an endpoint notification including the signature response to the verification device (200).
Need to check novelty before this filing date? Find Prior Art

Description

Presentation device, verification system, verification method, and program

[0001] The present disclosure relates to a presentation device, a verification system, a verification method, and a program.

[0002] In recent years, self-sovereign identity (SSI) technology has been studied in which users manage their own identifiers and identities and control the presentation destination without relying on a centralized identity provider (IdP) or the like (see Non-Patent Documents 1 and 2).

[0003] In digital identity, there are three parties: Holder, Issuer, and Verifier. The Holder is a user or the like who manages and holds their own digital identity. The Issuer issues verifiable credentials (VCs) that prove the user's attributes and / or qualifications, such as attribute information (name, age, address, etc.) and qualification information (being an employee of a certain company, being a member of a certain service, etc.), after verifying them to the Holder. The Verifier requests and receives the necessary VCs for service provision from the Holder, verifies the Holder's attributes, qualifications, etc., and makes decisions regarding service provision.

[0004] A digital identity wallet (DIW) has been proposed that manages the ID data of a user (Holder) and is used for identity verification and attribute proof (see Non-Patent Document 3). As embodiments of the DIW, there are two forms: a form in which ID data is managed within a user device (local wallet) and a form in which ID data is managed on a platform hosted by a cloud provider or the like (cloud wallet).

[0005] “W3C Decentralized Identifiers (DID)” [online], [Accessed September 9, 2024], Internet<URL: https: / / www.w3.org / TR / did-core / > “W3C Verifiable Credentials” [online], [Accessed September 9, 2024], Internet<URL: https: / / www.w3.org / TR / vc-data-model / > “European digital identity wallet” [online], [searched September 9, 2024], Internet <URL: https: / / digital-strategy.ec.europa.eu / en / library / european-digital-identity-wallet-architecture-and-reference-framework>

[0006] By using a cloud-based DIW (Data Identity Warehouse), users can reduce the effort required to properly manage user devices equipped with ID data and ID data processing functions. Furthermore, using a cloud-based DIW reduces the risk of external access to ID data due to factors such as loss of user devices or inadequate security settings.

[0007] In a scenario where a user's digital identity is managed in a cloud wallet, when the Holder device (presenting device) is online and can communicate with the cloud wallet (management device) via the network, the presenting device can communicate with the management device, obtain the VC managed by the management device, and present it to the Verifier (verification device). However, when the presenting device is offline and cannot communicate with the management device via the network, it cannot obtain the VC and therefore cannot present it to the verification device. Consequently, a mechanism is needed that allows the presenting device to present the VC to the verification device while preventing attacks such as information tampering, even when the presenting device is offline.

[0008] In light of the problems described above, the purpose of this disclosure is to provide a presentation device, a verification system, a verification method, and a program that can present verifiable credentials to a verification device while preventing attacks such as information tampering, even when the presentation device is offline.

[0009] A presentation device according to one embodiment is a presentation device for presenting verifiable credentials of a user, wherein the presentation device is able to communicate via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and is also able to communicate with the verification device without the network, and comprises a storage unit, a control unit, and a tamper-resistant storage arithmetic processing circuit, wherein the storage unit stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network, the storage arithmetic processing circuit stores a user authentication authority certificate, a public key, and a private key paired with the public key, which are issued to the user by an authentication authority that certifies the legitimacy of the user, and when the control unit presents the verifiable credentials to the verification device, it outputs a signature request to the storage arithmetic processing circuit, which includes information regarding the verifiable credentials stored in the storage unit. The memory arithmetic processing circuit outputs to the control unit a signed signature response, which, in response to the signature request, is signed using the private key and includes information about the verifiable credentials included in the signature request and the user certification authority certificate, the user certification authority certificate includes the public key and is signed by the certification authority. The control unit then sends an endpoint notification to the verification device, which includes the signed signature response and notifies the verification device of an endpoint to verify the legitimacy of the verification device.

[0010] A verification system according to one embodiment comprises a presentation device that presents verifiable credentials of a user, a management device that manages the verifiable credentials, and a verification device that verifies the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network, the presentation device includes a tamper-resistant memory arithmetic processing circuit, the presentation device stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network, the presentation device stores in its memory arithmetic processing circuit a user authentication authority certificate, a public key, and a private key paired with the public key that proves the legitimacy of the user, which are issued to the user by an authentication authority that proves the legitimacy of the user, and when the presentation device presents the verifiable credentials to the verification device, it outputs a signature request to the memory arithmetic processing circuit that includes the stored information regarding the verifiable credentials. The presenting device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature response created using the private key and includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority. The presenting device sends an endpoint notification to the verification device that notifies an endpoint to verify the legitimacy of the verification device, which includes the signature response. The verification device verifies the signature of the certification authority attached to the user certification authority certificate included in the endpoint notification using the certification authority's public key, and if it determines that the certification authority's signature is legitimate, it verifies the signature attached to the signature response using the public key included in the user certification authority certificate, and if it determines that the signature attached to the signature response is legitimate, it sends a presentation request to the management device requesting the presentation of the verifiable credentials included in the endpoint notification. The management device sends the verifiable credentials requested to be presented in response to the presentation request to the verification device.The verification device verifies the verifiable credentials presented by the management device.

[0011] A verification method according to one embodiment is a verification method in a verification system comprising: a presentation device that presents verifiable credentials of a user; a management device that manages the verifiable credentials; and a verification device that verifies the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network; the presentation device comprises a tamper-resistant memory arithmetic processing circuit; the presentation device stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network; the presentation device stores, in its memory arithmetic processing circuit, a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the user's legitimacy; and when the presentation device presents the verifiable credentials to the verification device, it outputs a signature request to the memory arithmetic processing circuit, which includes the stored information regarding the verifiable credentials. The presenting device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature response created using the private key, which includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority. The presenting device sends an endpoint notification to the verification device that notifies an endpoint to verify the legitimacy of the verification device, which includes the signature response. The verification device verifies the signature of the certification authority attached to the user certification authority certificate included in the endpoint notification using the certification authority's public key, and if it determines that the certification authority's signature is legitimate, it verifies the signature attached to the signature response using the public key included in the user certification authority certificate, and if it determines that the signature attached to the signature response is legitimate, it sends a presentation request to the management device requesting the presentation of the verifiable credentials included in the endpoint notification.The management device transmits the verifiable credentials requested to be presented in response to the presentation request to the verification device, and the verification device verifies the verifiable credentials presented by the management device.

[0012] A program according to one embodiment causes a computer to operate as the above-mentioned display device.

[0013] According to this disclosure, even when the presentation device is offline, verifiable credentials can be presented to the verification device while preventing attacks such as information tampering.

[0014] This figure shows an example configuration of a verification system according to one embodiment of the present disclosure. This figure schematically shows the operation of the verification system shown in Figure 1. This is a sequence diagram showing an example of the operation of the verification system shown in Figure 1. This is a sequence diagram showing another example of the operation of the verification system shown in Figure 1. This is a sequence diagram showing yet another example of the operation of the verification system shown in Figure 1. This is a sequence diagram showing yet another example of the operation of the verification system shown in Figure 1.

[0015] Embodiments of this disclosure will be described below with reference to the drawings.

[0016] Figure 1 is a diagram showing an example configuration of a verification system 10 according to one embodiment of the present disclosure.

[0017] As shown in Figure 1, the verification system 10 according to this embodiment comprises a presentation device 100, a verification device 200, and a management device 300. The presentation device 100, the verification device 200, and the management device 300 can communicate with each other via a network 11 such as the Internet. The presentation device 100 and the verification device 200 can also communicate without using the network 11. For example, the presentation device 100 and the verification device 200 can communicate using proximity communication. Therefore, even when the presentation device 100 is offline and cannot communicate via the network 11, the presentation device 100 and the verification device 200 can communicate using proximity communication, for example.

[0018] The presentation device 100 is a device used by the user (Holder), such as a smartphone or personal computer. The presentation device 100 presents the user's verifiable credentials (VC). As mentioned above, a VC is a certificate that proves the user's attributes and / or qualifications. A VC is issued by an Issuer that verifies the user's attributes and qualifications and issues a signed certificate. In a cloud wallet, VCs are managed by the management device 300. When online, the presentation device 100 can obtain the VCs managed by the management device 300 and present them to the verification device 200. On the other hand, when offline, the presentation device 100 cannot obtain VCs from the management device 300 and cannot present the VCs to the verification device 200.

[0019] As shown in Figure 1, the presentation device 100 according to this embodiment includes a storage unit 101, a communication unit 102, a control unit 103, and a SIM (Subscriber Identity Module) card 104.

[0020] The storage unit 101 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM (Random Access Memory), ROM (Read Only Memory), or flash memory. The RAM is, for example, SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory). The ROM is, for example, EEPROM (Electrically Erasable Programmable Read Only Memory). The flash memory is, for example, SSD (Solid-State Drive). The magnetic memory is, for example, HDD (Hard Disk Drive). The storage unit 101 functions, for example, as main memory, auxiliary memory, or cache memory. The storage unit 101 stores information used for the operation of the presentation device 100 and information obtained by the operation of the presentation device 100. The memory unit 101 stores, for example, information about VCs managed by the management device 300, which is notified by the management device 300 (described later). The information about VCs is, for example, information that can identify a VC, such as the VC's ID and attributes.

[0021] The communication unit 102 includes at least one communication module. The communication module is, for example, a module compatible with a LAN communication standard such as Ethernet (registered trademark). The communication unit 102 communicates with the verification device 200 and the management device 300 via the network 11. The communication unit 102 also communicates with the verification device 200 without using the network 11. The communication unit 102 also communicates with the verification device 200 via proximity communication, for example. The communication unit 102 receives information used for the operation of the presentation device 100 and transmits information obtained through the operation of the presentation device 100.

[0022] The control unit 103 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit), or a dedicated processor specialized for a specific process. The programmable circuit is, for example, an FPGA (Field-Programmable Gate Array). The dedicated circuit is, for example, an ASIC (Application Specific Integrated Circuit).

[0023] The control unit 103 controls each part of the presentation device 100 and executes processes related to the operation of the presentation device 100. For example, when the control unit 103 presents a VC to the verification device 200, it outputs a signature request to the SIM card 104, which includes information about the VC stored in the storage unit 101. The control unit 103 also transmits the signature response output from the SIM card 104 in response to the signature request to the verification device 200 as an endpoint notification that notifies the endpoint to verify the legitimacy of the verification device 200. As described above, the presentation device 100 can communicate with the verification device 200 via proximity communication or the like without going through the network 11. Therefore, the presentation device 100 can send an endpoint notification to the verification device 200 even when it is offline.

[0024] The SIM card 104 is an example of a memory arithmetic processing circuit that has tamper resistance (resistance to unauthorized reading or alteration of internal information). The memory arithmetic processing circuit is composed of, for example, a CPU and memory. The SIM card 104 stores information used for the operation of the presentation device 100 and information obtained through the operation of the presentation device 100. The SIM card 104 also executes processing related to the operation of the presentation device 100. For example, the SIM card 104 stores a user CA certificate, a public key (user CA Pk), and a private key (user CA Pk) that is paired with the public key, which are issued to the user by a Certificate Authorities (CA) that proves the legitimacy of the user (Holder), and are not shown in Figure 1. Furthermore, when a signature request is output from the control unit 103, the SIM card 104 outputs a signature response to the signature request to the control unit 103.

[0025] Verification device 200 is a device used by Verifier. Verification device 200 verifies the user's verifiable credentials (VC) (verifies the user's (Holder's) attributes and credentials, etc.).

[0026] As shown in Figure 1, the verification device 200 according to this embodiment includes a storage unit 201, a communication unit 202, and a control unit 203.

[0027] The storage unit 201, like the storage unit 101, includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 201 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 201 stores information used for the operation of the verification device 200 and information obtained by the operation of the verification device 200.

[0028] The communication unit 202, like the communication unit 102, includes at least one communication module. The communication unit 202 communicates with the display device 100 and the management device 300 via the network 11. The communication unit 202 also communicates with the display device 100 without using the network 11. For example, the communication unit 202 communicates with the display device 100 via proximity communication. The communication unit 202 receives information used for the operation of the verification device 200 and transmits information obtained through the operation of the verification device 200.

[0029] The control unit 203 controls each part of the verification device 200 and executes processes related to the operation of the verification device 200. For example, the control unit 203 verifies the VC presented by the management device 300, which will be described later.

[0030] The management device 300 is a device such as a server connected to the network 11. The management device 300 manages user verifiable credentials (VCs) issued to the Holder by the Issuer.

[0031] As shown in Figure 1, the management device 300 according to this embodiment includes a storage unit 301, a communication unit 302, and a control unit 303.

[0032] Like the storage unit 101, the storage unit 301 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 301 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 301 stores information used for the operation of the management device 300 and information obtained by the operation of the management device 300.

[0033] The communication unit 302, like the communication unit 102, includes at least one communication module. The communication unit 302 communicates with the presentation device 100 and the verification device 200 via the network 11. The communication unit 302 receives information used for the operation of the management device 300 and transmits information obtained through the operation of the management device 300.

[0034] The control unit 303 controls each part of the management device 300 and executes processes related to the operation of the management device 300. For example, when the presentation device 100 is online and can communicate with the management device 300 via the network 11, the control unit 303 notifies the presentation device 100 of information regarding the VC of the user to be managed. Also, when the control unit 303 receives a presentation request from the verification device 200 that requests the presentation of a VC, it verifies the validity of the verification device 200 and presents the requested VC to the verification device 200.

[0035] The functions of the presentation device 100, the verification device 200, and the management device 300 are realized by executing the program according to this embodiment on processors acting as control units 103, 203, and 303. In other words, the functions of the presentation device 100, the verification device 200, and the management device 300 are realized by software. The program causes the computer to execute the operations of the presentation device 100, the verification device 200, and the management device 300, thereby causing the computer to function as the presentation device 100, the verification device 200, and the management device 300. That is, the computer functions as the presentation device 100, the verification device 200, and the management device 300 by executing the operations of the presentation device 100, the verification device 200, and the management device 300 according to the program.

[0036] The program can be stored on a non-temporary computer-readable medium. Examples of non-temporary computer-readable mediums include flash memory, magnetic recording devices, optical discs, magneto-optical recording media, or ROM. The program can be distributed, for example, by selling, transferring, or leasing portable media such as SD (Secure Digital) cards, DVDs (Digital Versatile Discs), or CD-ROMs (Compact Disc Read Only Memory) on which the program is stored. The program may also be distributed by storing it in server storage and transferring it from the server to other computers. The program may also be provided as a program product.

[0037] A computer, for example, stores a program stored on a portable medium or a program transferred from a server in its main memory. Then, the computer reads the program stored in the main memory with its processor and executes the processing according to the read program. The computer may also read the program directly from the portable medium and execute the processing according to the program. The computer may also execute the processing according to the received program sequentially each time a program is transferred to it from a server. Processing may also be performed by a so-called ASP (Application Service Provider) type service, which does not transfer programs from the server to the computer, but realizes its function only through execution instructions and result retrieval. A program includes information used for processing by an electronic computer that is equivalent to a program. For example, data that is not a direct instruction to the computer but has the nature of defining the computer's processing falls under "equivalent to a program".

[0038] Some or all of the functions of the presentation device 100, the verification device 200, and the management device 300 may be implemented by programmable circuits or dedicated circuits as control units 103, 203, and 303. In other words, some or all of the functions of the presentation device 100, the verification device 200, and the management device 300 may be implemented by hardware.

[0039] Next, the operation of each device in the verification system 10 according to this embodiment will be described. Figure 2 is a schematic diagram showing the operation of each device in the verification system 10 according to this embodiment.

[0040] The Issuer's issuing device 400 registers a public key created from the private key (Issuer private key) associated with the Issuer's identifier (Decentralized Identifier: DID) with the blockchain 500. The management device 300 also registers a public key created from the private key (Holder private key) associated with the Management Device 300's identifier (DID) with the blockchain 500.

[0041] The issuing device 400 issues a VC (Online VC) for a user (Holder) to the management device 300. The management device 300 manages the VC issued from the issuing device 400 by storing it in the storage unit 301. The VC managed by the management device 300 includes the DID of the Holder, the attributes of the Holder, the DID of the issuing device 400 (Issuer), and the signature of the issuing device 400 (Issuer). The management device 300 uses the public key of the issuing device 400 registered in the blockchain 500 to verify whether the signature of the issuing device 400 included in the VC is legitimate (whether the VC is legitimately issued by the issuing device 400).

[0042] When it is determined that the VC issued by the issuing device 400 is legitimate, the management device 300 notifies the presentation device 100 of information regarding the managed VC in an online state where communication with the presentation device 100 is possible via the network 11. The management device 300 notifies the presentation device 100 of information that can identify the VC, such as the ID and attributes of the VC, as information regarding the VC.

[0043] As for the VCs of the Holder, there are various VCs according to the attributes of the Holder (name, age, address, etc.) and qualifications (such as being an employee of a certain company or a member of a certain service). The management device 300 manages various VCs of the Holder and notifies the presentation device 100 of the ID, attributes, etc. of all or part of the managed VCs.

[0044] The presentation device 100 stores the ID and attributes of the VC transmitted from the management device 300 in the storage unit 101. Further, the presentation device 100 stores a certificate for proving the legitimacy of the user (user CA certificate), a public key (user CA public key (Pk)), and a secret key (user CA secret key (Sk)) that is paired with the public key, which are issued to the user by the certification authority 600 that proves the legitimacy of the user.

[0045] When the presentation device 100 presents a VC to the verification device 200, it sends an endpoint notification (EP notification) to the verification device 200 that notifies the endpoint for verifying the legitimacy of the verification device 200. As will be described in detail later, the EP notification includes a user CA certificate signed by the certification authority 600. In this embodiment, an example in which the endpoint is the management device 300 will be used for explanation. However, the endpoint may be another device that has the function of verifying the legitimacy of the verification device 200.

[0046] The verification device 200 receives the EP notification transmitted from the presentation device 100. The verification device 200 uses the public key of the certification authority 600 (Root CA public key) to verify the signature of the certification authority 600 attached to the user CA certificate included in the EP notification. In this way, the verification device 200 can confirm whether or not the user CA certificate has been authenticated by the certification authority 600. Once the verification device 200 has confirmed that the user CA certificate has been authenticated by the certification authority 600, it sends a VC presentation request to the management device 300.

[0047] Figure 3 is a sequence diagram showing an example of the operation of the verification system 10 according to this embodiment, and is a diagram for explaining the verification method in the verification system 10 according to this embodiment.

[0048] In the example shown in FIG. 3, the SIM card 104 stores in advance a user CA certificate, a public key (user CA Pk), and a private key (user CA Sk) issued by the certification authority 600 to the user (Holder). Further, the SIM card 104 stores in advance a wallet address (e.g., URL), which is the address of the management device 300 that manages the user's VC. Instead of the wallet address, an identifier such as a SUPI (Subscriber Permanent Identifier) or a SUCI (Subscriber Concealed Identifier) indicating the telephone carrier subscriber ID may be stored in the SIM card 104. The SUP and SUCI include information for identifying a country or a carrier, and since the SUCI is anonymized, it is possible to conceal the user (Holder) from the verification device 200.

[0049] Also, the storage unit 301 of the management device 300 stores in advance the user CA Pk and the user CA Sk.

[0050] When the presentation device 100 is in an online state, the management device 300 notifies information related to the VC, such as a list of the IDs of the VCs managed by the management device 300 or the attributes (age, gender, address, etc.) described in the VC (step S10).

[0051] When the verification device 200 requests the presentation device 100 to present a VC, the verification device 200 notifies the presentation device 100 of a Nonce (number used once), which is a number used only once (step S11).

[0052] When the presentation device 100 (control unit 103) presents the user's (Holder's) VC to the verification device 200, the presentation device 100 outputs a signature request to the SIM card 104 (step S12). The control unit 103 includes the ID / attribute of the VC to be presented and the Nonce notified from the verification device 200 in the presentation request.

[0053] When the SIM card 104 receives a signature request from the control unit 103, it outputs a signature response to the control unit 103 (step S13). The SIM card 104 includes the Nonce included in the signature request in the signature response. The SIM card 104 also includes Seq, a number representing a sequence independent of Nonce, in the signature response. Furthermore, the SIM card 104 includes the wallet address and the ID / attributes of the VC included in the signature request in the signature response. Specifically, the SIM card 104 includes a URL in the signature response that combines the wallet address and the ID / attributes of the VC.

[0054] Furthermore, the SIM card 104 includes the stored user CA certificate in the signature response. Here, the SIM card 104 includes the public key (user CA Pk) issued to the user by the certification authority 600 in the user CA certificate, and affixes a signature (RootCA signature) generated by the certification authority 600's public key (RootCA public key) to the user CA certificate. In addition, the SIM card 104 affixes a signature (user CA signature) generated by the private key (user CA Sk) issued to the user by the certification authority 600 to the entire signature response. In this way, the SIM card 104 outputs to the control unit 103 a signature response in response to a signature request, which is a signature (user CA signature) created using a private key (user CA Sk), includes information about the VC included in the signature request, and a user CA certificate, the user CA certificate includes a public key (user CA Pk), and is signed by the certification authority 600 (RootCA signature).

[0055] When the presentation device 100 (control unit 103) receives a signature response from the SIM card 104, it sends an endpoint notification (EP notification) to the verification device 200 that notifies the verification device 200 of the endpoint to verify the legitimacy of the verification device 200, including the signature response (step S14). In this embodiment, the endpoint is the management device 300.

[0056] The verification device 200 uses the RootCA public key to verify the RootCA signature attached to the user CA certificate included in the EP notification. This allows the verification device 200 to confirm that the presenting device 100 that sent the EP notification has been authenticated by the certification authority 600 (the integrity of the presenting device 100). The verification device 200 may have obtained the RootCA public key in advance, or it may have obtained the RootCA public key from the certification authority 600 upon receiving the EP notification.

[0057] Once the verification device 200 confirms the integrity of the presentation device 100, it uses the User CA Pk contained in the User CA certificate to verify the User CA signature attached to the signature response. As described above, since the User CA Pk and User CA Sk are stored in the tamper-resistant SIM card 104, tampering is difficult. Therefore, by verifying the User CA signature, the verification device 200 can confirm that the EP notification is a legitimate notification from the presentation device 100.

[0058] As described above, the EP notification includes a Nonce that the verification device 200 notified the presentation device 100 to request the presentation of the VC. This allows the verification device 200 to confirm that the EP notification is in response to a request from the verification device 200.

[0059] When the verification device 200 confirms that the presenting device 100 that sent the EP notification has been authenticated by the certification authority 600, and that the EP notification is a legitimate notification from the presenting device 100, it sends a VC request to the management device 300 requesting the presentation of a VC that includes the ID / attributes in the EP notification (step S15). Specifically, the verification device 200 sends a VC request to the management device 300 that includes the EP notification received from the presenting device 100 and a VC that proves the identity of the verification device 200.

[0060] When the management device 300 receives a VC request transmitted from the verification device 200, it stores the Seq included in the VC request in the storage unit 301. In this way, the management device 300 can ensure that a VC request for a VC that has already been presented is not repeated. When the management device 300 receives a VC request, it sends an attendance request (certification request) to the verification device 200 requesting information regarding the legitimacy of the verification device 200 (step S16).

[0061] When the verification device 200 receives an attendance request sent from the management device 300, it sends an attendance response (certification response) to the management device 300 containing information regarding the legitimacy of the verification device 200 (step S17). The information regarding the legitimacy of the verification device 200 may be, for example, an attestation report issued by the hardware of the verification device 200 or a VC that certifies the attributes of the verification device 200.

[0062] When the management device 300 receives an attendance response from the verification device 200, it verifies the legitimacy of the verification device 200 based on the attendance report or VC that proves the attributes of the verification device 200 included in the attendance response. After confirming the legitimacy of the verification device 200, the management device 300 uses the stored user CA Pk to verify the user CA signature included in the VC request and checks whether the user CA Pk included in the user CA certificate has been forged. After confirming that the user CA Pk included in the user CA certificate has not been forged, the management device 300 sends the VC response, which includes the VC requested to be presented in the VC request, and the attendance verification result indicating the verification result of the legitimacy of the verification device 200 to the verification device 200 (step S18).

[0063] When the verification device 200 receives a VC response from the management device 300, it verifies the VC included in the VC response. The verification device 200 then transmits the VC verification result, which shows the verification result of the VC, and the attention verification result received from the management device 300 to the presentation device 100 (step S19).

[0064] As shown in Figure 3, in the example, the tamper-resistant SIM card 104 stores the user CA certificate, user CA Pk, user CA Sk, and wallet address, and sends an EP notification containing a signature response generated using these to the verification device 200. The verification device 200 also verifies, based on the user CA certificate and other information included in the EP notification, that the presenting device 100 that sent the EP notification has been authenticated by the certification authority 600, and that the EP notification is a legitimate notification from the presenting device 100. This prevents malware infection of the presenting device 100, redirection to a cloud wallet owned by someone other than the owner of the presenting device 100, and attacks such as name matching using endpoint information.

[0065] Furthermore, by having the management device 300 store the Seq included in the VC request (EP notification), it is possible to prevent the EP notification from being reused repeatedly and to prevent the Verifier from performing endpoint name matching.

[0066] Figure 4 is a sequence diagram showing another example of the operation of the verification system 10 according to this embodiment. In Figure 4, the same reference numerals are used for processes similar to those in Figure 3, and their explanations are omitted.

[0067] In Figure 4, the management device 300 is equipped with a Trusted Execution Environment (TEE). A Trusted Execution Environment is a secure area of ​​the device's hardware and software that can protect specific data and processes from external tampering and interference. The construction of a TEE itself is well known to those skilled in the art, so a detailed explanation is omitted. The Trusted Execution Environment of the management device 300 stores the public key (TEE Pk) of the management device 300 and its corresponding private key (TEE Sk), which are issued by the certification authority 600.

[0068] The SIM card 104 stores the user CA certificate and private key (user CA Sk) issued to the user by the certification authority 600. The SIM card 104 also stores the signature of the management device 300 (cloud wallet Tee Sk signature) generated using the Tee Sk. In other words, the SIM card 104 stores the signature (cloud wallet Tee Sk signature) created using the management device 300's private key (user CA Sk), which is managed in the management device 300's trusted execution environment (Tee). The cloud wallet Tee Sk signature is pre-stored on the SIM card 104. Furthermore, in the example shown in Figure 4, the wallet address may be stored in the storage unit 101 of the presentation device 100, rather than on the SIM card 104.

[0069] When a signature request is input from the control unit 103 (step S12), the SIM card 104 outputs a signature response to the control unit 103 (step S20). Specifically, the SIM card 104 includes the Nonce, Seq, and user CA certificate in the signature response, which is signed by the user CA, similar to the example shown in Figure 3. Furthermore, in the example shown in Figure 4, the SIM card 104 also includes the cloud wallet Tee Sk signature in the signature response. That is, in response to the signature request, the SIM card 104 outputs a signature response to the control unit 103 which further includes a signature (cloud wallet Tee Sk signature) created using the private key (Tee Sk) of the management device 300.

[0070] The control unit 103 transmits the EP notification, which includes the signature response, to the verification device 200. Here, the control unit 103 includes the wallet address stored in the storage unit 101 in the EP notification.

[0071] When the verification device 200 receives an EP notification, it obtains a Tee Pk from the management device 300. The verification device 200 then uses the obtained Tee Pk to verify the cloud wallet Tee Sk signature included in the EP notification. As described above, the Tee Pk and Tee Sk are issued by the Certificate Authority 600 and bear the signature of the Certificate Authority 600. Therefore, by verifying the cloud wallet Tee Sk signature using the Tee Pk, the verification device 200 can verify that the EP notification is not forged.

[0072] In the example described above, the verification device 200 obtains the Tee Pk from the management device 300 in response to the receipt of the EP notification and verifies the cloud wallet Tee Sk signature. However, the example is not limited to this.

[0073] If the VC stored in the management device 300 is Keybound (i.e., when the VC is issued, the VC and the Tee Pk stored in the management device 300 are linked), the management device 300 may include the Tee Pk linked to the VC in the VC response that presents the VC to the verification device 200 (step S22). The verification device 200 uses the Tee Pk included in the VC response to verify the cloud wallet Tee Sk signature included in the EP notification. In this way, the verification device 200 can verify the identity of the management device 300.

[0074] In the example shown in Figure 4, similar to the example shown in Figure 3, it is possible to prevent attacks such as malware infection of the presentation device 100, redirection to a cloud wallet owned by someone other than the owner of the presentation device 100, and name matching using endpoint information.

[0075] Furthermore, by having the management device 300 store the Seq included in the VC request (EP notification), it is possible to prevent the EP notification from being reused repeatedly and to prevent the Verifier from performing endpoint name matching.

[0076] Figure 5 is a sequence diagram showing yet another example of the operation of the verification system 10 according to this embodiment. In Figure 5, the same reference numerals are used for processes as in Figure 3, and their explanations are omitted.

[0077] In the example shown in Figure 5, the presentation device 100 further includes an authenticator 105 that performs biometric authentication of the user. The authenticator 105 has a private key (FIDO Sk).

[0078] The SIM card 104 stores the user CA certificate and the user's private key (User CA Sk), similar to the example shown in Figure 3. The wallet address is also pre-stored on the SIM card 104. Furthermore, in the example shown in Figure 5, the public key (FIDO Pk) of the authenticator 105 is also stored on the SIM card 104.

[0079] When the presentation device 100 (control unit 103) presents the user's (Holder's) VC to the verification device 200, it outputs a signature request and a biometric authentication request (FIDO request) requesting the user's biometric authentication to the SIM card 104 (step S30).

[0080] The authenticator 105 performs biometric authentication of the user and outputs the biometric authentication result to the SIM card 104.

[0081] The SIM card 104 performs biometric authentication (Passkey authentication) using the FIDO Sk of the authenticator 105 and the stored FIDO Pk. If authentication is successful, the SIM card 104 includes a VC indicating that FIDO authentication was performed in the signature response. That is, when the user is biometrically authenticated by the authenticator 105, the SIM card 104 outputs a signature response to the control unit 103 that further includes a VC indicating that the user has been biometrically authenticated.

[0082] When the verification device 200 receives an EP notification, it confirms that the user has been biometrically authenticated based on the VC indicating that FIDO authentication has been performed.

[0083] In the example shown in Figure 5, the public key (FIDO Pk) of the authenticator 105 is stored in the SIM card 104, and the result of biometric authentication by the authenticator 105 is authenticated using FIDO Pk and FIDO Sk, thereby preventing impersonation by handing over the SIM card 104 to someone else.

[0084] Figure 6 is a sequence diagram showing yet another example of the operation of the verification system 10 according to this embodiment. In Figure 6, the same reference numerals are used for processes as in Figure 3, and their explanations are omitted.

[0085] In the example shown in Figure 6, the SIM card 104 pre-stores the user CA certificate, public key (user CA Pk), and private key (user CA Sk) issued to the user by the certification authority 600. The SIM card 104 also pre-stores a cloud wallet VC, which certifies the attributes / qualifications of the management device 300 that manages the user's VC. The cloud wallet VC is issued by the certification authority 600, such as a carrier, and bears the certification authority 600's signature. The cloud wallet VC includes the identifier (C-DID) of the management device 300 (cloud wallet), the public key (C-Pk) of the management device 300, and the cloud wallet address.

[0086] Furthermore, the storage unit 301 of the management device 300 has the identifier (C-DID), the public key (C-Pk), and the private key (C-Sk) of the management device 300 pre-stored in it.

[0087] When a signature request is input from the control unit 103 (step S12), the SIM card 104 outputs a signature response to the control unit 103 (step S40). Specifically, the SIM card 104 includes the Nonce, Seq, and user CA certificate in the signature response, which is signed by the user CA, similar to the example shown in Figure 3. Furthermore, in the example shown in Figure 6, the SIM card 104 also includes the cloud wallet VC in the signature response. That is, in response to the signature request, the SIM card 104 outputs a signature response to the control unit 103 that includes the identifier (C-DID) of the management device 300, the public key (C-Pk) of the management device, and the cloud wallet address, and further includes the cloud wallet VC signed by the certification authority 600.

[0088] When the verification device 200 receives an EP notification, it uses the RootCA public key to verify the RootCA signature attached to the user CA certificate included in the EP notification, similar to the example shown in Figure 3. This allows the verification device 200 to confirm that the presenting device 100 that sent the EP notification has been authenticated by the certification authority 600 (the integrity of the presenting device 100). The verification device 200 also verifies the signature of the cloud wallet VC included in the EP notification. This allows the verification device 200 to confirm that the cloud wallet VC has been authenticated by the certification authority 600.

[0089] Furthermore, when the verification device 200 receives the VC response and the attention verification result from the management device 300 (step S18), it may verify, by means of DID-AUTH or other means, whether the C-DID and C-Pk stored in the management device 300 match the C-DID and C-Pk included in the cloud wallet VC.

[0090] As described above, the presentation device 100 according to this embodiment comprises a storage unit 101, a control unit 103, and a SIM card 104 as a tamper-resistant storage arithmetic processing circuit. The storage unit 101 stores information about the VC managed by the management device 300, which is notified from the management device 300 when the device is online. The SIM card 104 stores the user certification authority certificate (user CA certificate), the public key (user CA Pk), and the private key (user CA Sk) that is paired with the public key, which are issued to the user by the certification authority 600. When the control unit 103 presents the VC to the verification device 200, it outputs a signature request to the SIM card 104, which includes the information about the VC stored in the storage unit 101. In response to the signature request, the SIM card 104 outputs a signature response to the control unit 103, which is a signature (User CA signature) created using the user's private key (User CA Sk), includes information about the VC included in the signature request, and a User CA certificate, the User CA certificate includes the user's public key (User CA Pk), and is signed by the Certificate Authority 600 (RootCA signature). The control unit 103 then transmits an EP notification containing the signature response to the verification device 200.

[0091] By sending an EP notification containing a signature response generated using the user CA certificate, user CA Pk, and user CA Sk stored in the tamper-resistant SIM card 104 to the verification device 200, it is possible to prevent malware infection of the presenting device 100, redirection to a cloud wallet owned by someone other than the owner of the presenting device 100, and attacks such as name matching using endpoint information. Therefore, according to this disclosure, even when the presenting device is offline, it is possible to present verifiable credentials to the verification device while preventing attacks such as information tampering.

[0092] The following additional information is disclosed regarding the embodiments described above.

[0093] [Addendum 1] A presentation device for presenting user verifiable credentials, wherein the presentation device is capable of communicating via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and is capable of communicating with the verification device without the network, and comprises a storage unit, a control unit, and a tamper-resistant storage arithmetic processing circuit, wherein the storage unit is configured to store information relating to the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and capable of communicating with the management device via the network, and the storage arithmetic processing circuit is configured to store a user authentication authority certificate, a public key, and a private key paired with the public key, which are issued to the user by an authentication authority that certifies the legitimacy of the user. The presenting device is configured such that when the control unit presents the verifiable credentials to the verification device, it outputs a signature request to the storage arithmetic processing circuit, which includes information about the verifiable credentials stored in the storage unit; the storage arithmetic processing circuit outputs to the control unit a signature response, which is signed using the private key, and which includes information about the verifiable credentials included in the signature request, and the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority; and the control unit transmits an endpoint notification to the verification device, which includes the signature response and notifies the verification device of an endpoint for verifying the legitimacy of the verification device.

[0094] [Addendum 2] A presentation device as described in Addendum 1, wherein the memory arithmetic processing circuit further stores the address of the management device and further includes the address of the management device in the signature response.

[0095] [Appendix 3] The presentation device according to Appendix 1, wherein the storage unit further stores the address of the management device, the storage arithmetic processing circuit further stores a signature generated using the private key of the management device, which is managed in a trusted execution environment of the management device, the signature response further including the signature created using the private key of the management device in response to the signature request, and the control unit transmits the endpoint notification including the signature response and the address of the management device to the verification device.

[0096] [Appendix 4] A presentation device according to any one of the appendix items 1 to 3, further comprising an authenticator for biometric authentication of the user, wherein the control unit outputs the signature request and the biometric authentication request for biometric authentication of the user to the storage arithmetic processing circuit when presenting the verifiable credentials to the verification device, and the storage arithmetic processing circuit outputs the signature response to the control unit, further including verifiable credentials indicating that the user has been biometrically authenticated, when the user is biometrically authenticated by the authenticator.

[0097] [Appendix 5] The presentation device described in Appendix 1, wherein the memory arithmetic processing circuit further stores verifiable credentials of the management device, which include an identifier of the management device and the public key of the management device, and which are signed by the certification authority, and outputs the signature response, which further includes verifiable credentials of the management device, to the control unit in response to the signature request.

[0098] [Appendix 6] A verification system comprising: a presentation device for presenting user verifiable credentials; a management device for managing the verifiable credentials; and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network; the presentation device comprises a tamper-resistant memory arithmetic processing circuit; the presentation device stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network; the presentation device stores, in its memory arithmetic processing circuit, a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the user's legitimacy; and when the presentation device presents the verifiable credentials to the verification device, it outputs a signature request to the memory arithmetic processing circuit, which includes the stored information regarding the verifiable credentials. The presenting device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature response created using the private key and includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority. The presenting device sends an endpoint notification to the verification device that notifies an endpoint to verify the legitimacy of the verification device, which includes the signature response. The verification device verifies the signature of the certification authority attached to the user certification authority certificate included in the endpoint notification using the certification authority's public key, and if it determines that the certification authority's signature is legitimate, it verifies the signature attached to the signature response using the public key included in the user certification authority certificate, and if it determines that the signature attached to the signature response is legitimate, it sends a presentation request to the management device requesting the presentation of the verifiable credentials included in the endpoint notification. The management device sends the verifiable credentials requested to be presented in response to the presentation request to the verification device.A verification system in which the verification device verifies verifiable credentials presented by the management device.

[0099] [Appendix 7] A verification method in a verification system comprising: a presentation device for presenting verifiable credentials of a user; a management device for managing the verifiable credentials; and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network; the presentation device comprises a tamper-resistant memory arithmetic processing circuit; the presentation device stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network; the presentation device stores in its memory arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user; and when the presentation device presents the verifiable credentials to the verification device, it outputs a signature request to the memory arithmetic processing circuit, which includes the stored information regarding the verifiable credentials. The presenting device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature response created using the private key and includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority. The presenting device sends an endpoint notification to the verification device that notifies an endpoint to verify the legitimacy of the verification device, which includes the signature response. The verification device verifies the signature of the certification authority attached to the user certification authority certificate included in the endpoint notification using the certification authority's public key, and if it determines that the certification authority's signature is legitimate, it verifies the signature attached to the signature response using the public key included in the user certification authority certificate, and if it determines that the signature attached to the signature response is legitimate, it sends a presentation request to the management device requesting the presentation of the verifiable credentials included in the endpoint notification. The management device sends the verifiable credentials requested to be presented in response to the presentation request to the verification device.A verification method comprising the verification device verifying verifiable credentials presented by the management device.

[0100] [Appendix 8] A non-temporary storage medium storing a program executable by a computer, the non-temporary storage medium storing a program that causes the computer to function as a presentation device as described in any one of the appendix items 1 to 5.

[0101] Although the embodiments described above are representative examples, it will be apparent to those skilled in the art that many modifications and substitutions are possible within the spirit and scope of this disclosure. Therefore, the present invention should not be construed as being limited by the embodiments described above, and various modifications or changes are possible without departing from the claims. For example, it is possible to combine multiple component blocks shown in the configuration diagram of the embodiments into one, or to divide one component block.

[0102] 10 Verification system 11 Network 100 Presentation device 200 Verification device 300 Management device 400 Issuing device 500 Blockchain 600 Certification authority 101, 201, 301 Storage unit 102, 202, 302 Communication unit 103, 203, 303 Control unit 104 SIM card (storage information processing circuit) 105 Authenticator

Claims

1. A presentation device for presenting user verifiable credentials, wherein the presentation device is capable of communicating via a network with a management device for managing the verifiable credentials and a verification device for verifying the verifiable credentials, and is capable of communicating with the verification device without the network, and comprises: a storage unit, a control unit, and a tamper-resistant storage arithmetic processing circuit, wherein the storage unit stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and capable of communicating with the management device via the network, the storage arithmetic processing circuit stores a user authentication authority certificate, a public key, and a private key paired with the public key, which are issued to the user by an authentication authority that certifies the user's legitimacy, and when the control unit presents the verifiable credentials to the verification device, it outputs a signature request to the storage arithmetic processing circuit, which includes information regarding the verifiable credentials stored in the storage unit. Presentation device, wherein the memory arithmetic processing circuit outputs to the control unit the signature response, which is a signed signature response created using the private key in response to the signature request, and which includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority; and the control unit transmits to the verification device an endpoint notification that notifies the verification device of an endpoint to verify the legitimacy of the verification device, which includes the signature response.

2. The presentation device according to claim 1, wherein the memory arithmetic processing circuit further stores the address of the management device and further includes the address of the management device in the signature response.

3. Presentation device according to claim 1, wherein the storage unit further stores the address of the management device, the storage arithmetic processing circuit further stores a signature generated using the private key of the management device, which is managed in a trusted execution environment of the management device, in response to the signature request, outputs the signature response to the control unit, which further includes the signature created using the private key of the management device, and the control unit transmits the endpoint notification, which includes the signature response and the address of the management device, to the verification device.

4. A presentation device according to claim 1, further comprising an authenticator for biometric authentication of the user, wherein the control unit outputs the signature request and the biometric authentication request for biometric authentication of the user to the storage arithmetic processing circuit when presenting the verifiable credentials to the verification device, and the storage arithmetic processing circuit outputs the signature response to the control unit, further including verifiable credentials indicating that the user has been biometrically authenticated, when the user is biometrically authenticated by the authenticator.

5. A presentation device according to claim 1, wherein the memory arithmetic processing circuit further stores verifiable credentials of the management device, which include an identifier of the management device and the public key of the management device, and which are signed by the certification authority, and outputs the signature response, which further includes the verifiable credentials of the management device, to the control unit in response to the signature request.

6. A verification system comprising: a presentation device for presenting user verifiable credentials; a management device for managing the verifiable credentials; and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network; the presentation device comprises a tamper-resistant memory arithmetic processing circuit; the presentation device stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network; the presentation device stores, in its memory arithmetic processing circuit, a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the user's legitimacy; and when the presentation device presents the verifiable credentials to the verification device, it outputs a signature request to the memory arithmetic processing circuit, which includes the stored information regarding the verifiable credentials. The presenting device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature response created using the private key and includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority. The presenting device sends an endpoint notification to the verification device that notifies an endpoint to verify the legitimacy of the verification device, which includes the signature response. The verification device verifies the signature of the certification authority attached to the user certification authority certificate included in the endpoint notification using the certification authority's public key, and if it determines that the certification authority's signature is legitimate, it verifies the signature attached to the signature response using the public key included in the user certification authority certificate, and if it determines that the signature attached to the signature response is legitimate, it sends a presentation request to the management device requesting the presentation of the verifiable credentials included in the endpoint notification. The management device sends the verifiable credentials requested to be presented in response to the presentation request to the verification device.A verification system in which the verification device verifies verifiable credentials presented by the management device.

7. A verification method in a verification system comprising: a presentation device for presenting user verifiable credentials; a management device for managing the verifiable credentials; and a verification device for verifying the verifiable credentials, wherein the presentation device, the management device, and the verification device are able to communicate with each other via a network, and the presentation device and the verification device are able to communicate without the network; the presentation device comprises a tamper-resistant memory arithmetic processing circuit; the presentation device stores information regarding the verifiable credentials managed by the management device, which is notified by the management device when the presentation device is online and able to communicate with the management device via the network; the presentation device stores, in its memory arithmetic processing circuit, a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the user's legitimacy; and when the presentation device presents the verifiable credentials to the verification device, it outputs a signature request to the memory arithmetic processing circuit, which includes the stored information regarding the verifiable credentials. The presenting device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature response created using the private key and includes information about the verifiable credentials included in the signature request and the user certification authority certificate, wherein the user certification authority certificate includes the public key and is signed by the certification authority. The presenting device sends an endpoint notification to the verification device that notifies an endpoint to verify the legitimacy of the verification device, which includes the signature response. The verification device verifies the signature of the certification authority attached to the user certification authority certificate included in the endpoint notification using the certification authority's public key, and if it determines that the certification authority's signature is legitimate, it verifies the signature attached to the signature response using the public key included in the user certification authority certificate, and if it determines that the signature attached to the signature response is legitimate, it sends a presentation request to the management device requesting the presentation of the verifiable credentials included in the endpoint notification. The management device sends the verifiable credentials requested to be presented in response to the presentation request to the verification device.A verification method comprising the verification device verifying verifiable credentials presented by the management device.

8. A program that causes a computer to operate as a presentation device according to any one of claims 1 to 5.