Issuing device, communication method, program, and verification device
The system uses verifiable credentials to manage and verify call rights, ensuring users' telephone numbers remain private and limiting unwanted contact, addressing privacy and security risks in communication systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NT T INC
- Filing Date
- 2024-11-05
- Publication Date
- 2026-05-15
AI Technical Summary
Existing communication systems risk exposing users' telephone numbers to unauthorized parties, and there is a possibility of unwanted contact after a desired period, compromising privacy and security.
A system utilizing verifiable credentials (VCs) to prove ownership of a telephone number and call rights, managed by a management device, where a verification device confirms the validity of these credentials before allowing communication, ensuring that the user's number is not disclosed and limiting contact after a specified period.
Users can restrict communication partners without revealing their telephone number, preventing unauthorized access and unwanted contact beyond a desired timeframe, thus enhancing privacy and security.
Smart Images

Figure JP2024039317_15052026_PF_FP_ABST
Abstract
Description
Issuing device, communication method, program, and verification device
[0001] The present disclosure relates to an issuing device, a communication method, a program, and a verification device.
[0002] In Non-Patent Document 1, SIP that provides a call control mechanism is defined. "SIP" is an abbreviation for Session Initiation Protocol.
[0003] J. Rosenberg, et al., “SIP: Session Initiation Protocol”, RFC 3261 (Proposed Standard), Internet Engineering Task Force, June 2002
[0004] In a general telephone system, a call is made by specifying a destination using a telephone number. Therefore, the user needs to pre-inform the other party of the telephone number as a contact. This is the same for any type of telephone, such as a landline or a mobile phone. In SIP as well, since a telephone number must be specified when making a call, the user needs to notify the other party of the telephone number when wanting to make contact. However, in such a telephone mechanism, if a malicious operator knows the telephone number, there is a risk that the telephone number will be leaked to other operators without permission. Therefore, by using a VC that proves the right to call the destination, it is conceivable to realize a mechanism that can limit the call partner without notifying the other party of the telephone number. However, there is a possibility that contact may come from the party to whom the VC has been passed even after the elapse of a desired period.
[0005] In view of such circumstances, an object of the present disclosure is to enable a user to limit the other party without notifying the other party of a contact such as a telephone number, and to prevent contact from coming after the elapse of a desired period.
[0006] An issuing device according to one embodiment includes a communication unit that communicates with a verification device and a management device, a control unit that receives from the verification device via the communication unit right information that indicates the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device, which has been issued from the first terminal device to the second terminal device and presented from the second terminal device to the verification device, a control unit that receives from the management device via the communication unit status information indicating whether or not the right information is valid, which has been registered with the management device by the first terminal device, a control unit that verifies the received right information to confirm the first user, and after confirming that the right information is valid by referring to the received status information, transmits a response to the verification device via the communication unit indicating permission to communicate to the first terminal device.
[0007] A communication method according to one embodiment includes: a first terminal device issuing rights information to the second terminal device that indicates the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device; the first terminal device registering status information in a management device indicating whether or not the rights information is valid; the issued rights information being presented from the second terminal device to a verification device, transferred from the verification device to an issuing device, verified by the issuing device to confirm the first user, the registered status information being transmitted from the management device to the issuing device, referenced by the issuing device to confirm that the rights information is valid, a response authorizing communication to the first terminal device being transmitted from the issuing device to the verification device, and the first terminal device receiving the communication from the second terminal device when the verification device requests the communication.
[0008] A verification device according to one embodiment includes a communication unit that communicates with an issuing device, a second terminal device, and a management device; a control unit that receives, via the communication unit, rights information issued from the first terminal device to the second terminal device and presented by the second terminal device, indicating the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device; status information registered by the first terminal device to the management device, indicating whether the rights information is valid or not, received from the management device via the communication unit; confirms that the rights information is valid by referring to the received status information, and then transfers the received rights information to the issuing device via the communication unit; and when the transferred rights information is verified by the issuing device and the first user is confirmed, the control unit receives a response from the issuing device via the communication unit indicating permission for communication to the first terminal device, and then requests the communication from the second terminal device via the communication unit.
[0009] According to this disclosure, users can limit who can contact them without disclosing their phone number or other contact information, and can also prevent further contact after a desired period of time has elapsed.
[0010] This is a block diagram showing the configuration of a communication system according to one embodiment. This is a block diagram showing the configuration of an issuing device included in the communication system. This is a block diagram showing the configuration of a first terminal device included in the communication system. This is a block diagram showing the configuration of a second terminal device included in the communication system. This is a block diagram showing the configuration of a verification device included in the communication system. This is a sequence diagram showing the operation of the communication system. This is a block diagram showing a modified configuration of the communication system. This is a sequence diagram showing a modified operation of the communication system.
[0011] One embodiment will be described below with reference to the figures.
[0012] In each figure, identical or corresponding parts are denoted by the same reference numerals. In the description of this embodiment, the description of identical or corresponding parts will be omitted or simplified as appropriate.
[0013] Referring to Figure 1, the configuration and operation of the communication system 10 according to this embodiment will be described.
[0014] The communication system 10 includes an issuing device 20, a first terminal device 30, a second terminal device 40, a verification device 50, and a management device 60.
[0015] The issuing device 20 and the verification device 50 are each a server computer or a dedicated computer. The issuing device 20 and the verification device 50 can communicate with each other via the carrier network 11 and also via the internet 12. The issuing device 20 can also communicate with the first terminal device 30 via the internet 12. The issuing device 20 may also communicate with the first terminal device 30 via the carrier network 11. The verification device 50 can also communicate with the second terminal device 40 via the internet 12. The verification device 50 may also communicate with the second terminal device 40 via the carrier network 11.
[0016] In this embodiment, communication carrier A operates the issuing device 20, but a business operator other than a communication carrier may also operate the issuing device 20. In this embodiment, communication carrier B operates the verification device 50, but a business operator other than a communication carrier may also operate the verification device 50.
[0017] The first terminal device 30 and the second terminal device 40 are, respectively, mobile terminals such as smartphones or tablets, general-purpose terminals such as PCs, or dedicated terminals such as landline telephones. "PC" is an abbreviation for personal computer. The first terminal device 30 and the second terminal device 40 can call each other via the carrier network 11 and can communicate with each other via the internet 12.
[0018] In this embodiment, a general user X who has a telephone contract with telecommunications carrier A uses the first terminal device 30, but a business operator who has a telephone contract with telecommunications carrier A may also use the first terminal device 30. In this embodiment, a service provider Y who has a telephone contract with telecommunications carrier B uses the second terminal device 40, but a general user who has a telephone contract with telecommunications carrier B may also use the second terminal device 40.
[0019] The management device 60 is a server computer or a dedicated computer. The management device 60 is publicly accessible to anyone via the Internet 12.
[0020] In this embodiment, the VC status management registry functions as the management device 60. "VC" is an abbreviation for verifiable credential. For example, the VC status management registry may be a public blockchain.
[0021] The issuing device 20 has a database 24, a VC issuing function 25, a VP verification function 26, and a connection management function 27. "VP" is an abbreviation for verifiable presentation. The first terminal device 30 has a wallet 36, a VC issuing function 37, and a telephone function 38. The second terminal device 40 has a wallet 46 and a telephone function 47. The verification device 50 has a database 54, a VP verification function 55, and a connection management function 56.
[0022] The issuing device 20 manages terminal information related to the first terminal device 30 using the database 24. This terminal information includes the telephone number of user X. This telephone number was obtained by user X through a telephone contract with telecommunications carrier A. Similarly, the verification device 50 manages terminal information related to the second terminal device 40 using the database 54. This terminal information includes the telephone number of service provider Y. This telephone number was obtained by service provider Y through a telephone contract with telecommunications carrier B.
[0023] The first terminal device 30 uses a wallet 36 to manage the VC that proves the credentials of user X, as well as user X's user ID and private key, and converts the VC to a VP as needed and presents it. "ID" is an abbreviation for identifier. Similarly, the second terminal device 40 uses a wallet 46 to manage the VC that proves the credentials of service provider Y, as well as service provider Y's user ID and private key, and converts the VC to a VP as needed and presents it.
[0024] In S101, the issuing device 20 uses the VC issuing function 25 to refer to the database 24 and confirm that user X possesses a telephone number managed by telecommunications carrier A, and then issues a telephone number VC to the first terminal device 30. The telephone number VC is a VC that proves that user X possesses a telephone number managed by telecommunications carrier A. The telephone number VC does not include user X's telephone number itself. The first terminal device 30 manages the telephone number VC using the wallet 36.
[0025] In S102, the first terminal device 30 issues a call right VC using the VC issuance function 37 in response to a user operation specifying service provider Y as the recipient of the call. The call right VC is a VC that proves that service provider Y has been granted the right to make a call to user X. The second terminal device 40 manages the call right VC using the wallet 46.
[0026] In S102A, the first terminal device 30 registers the valid status of the calling rights VC with the management device 60. At that time, the first terminal device 30 does not register the calling rights VC itself, but registers the ID of the calling rights VC linked to the valid status of the calling rights VC.
[0027] In S103, the first terminal device 30 uses the wallet 36 to convert the telephone number VC to a telephone number VP and presents it to the second terminal device 40. The second terminal device 40 manages the telephone number VP using, for example, the wallet 46, but may manage the telephone number VP by other means.
[0028] In S104, the second terminal device 40, in response to a user operation specifying user X as the recipient of the call, uses the wallet 46 to convert the calling right VC into calling right VP and presents it to the verification device 50.
[0029] In S105, the second terminal device 40 transfers the telephone number VP to the verification device 50 using, for example, the wallet 46, but the telephone number VP may be transferred to the verification device 50 by other means.
[0030] In S106, the verification device 50 uses the VP verification function 55 to verify the telephone number VP and confirms that user X has a telephone number managed by telecommunications carrier A. That is, the verification device 50 confirms that telecommunications carrier A is the issuer of the telephone number VC. The verification device 50 may further verify the outgoing call right VP using the VP verification function 55 and confirm that service provider Y has been granted the right to make a call to user X, and may also refer to the database 54 to confirm that service provider Y has a telephone number managed by telecommunications carrier B. That is, the verification device 50 may confirm that the issuer of the outgoing call right VP is service provider Y, which has a telephone contract with telecommunications carrier B.
[0031] In S106A, the verification device 50 confirms the status of the calling rights VC with the management device 60. If the calling rights VC has expired, the verification device 50 notifies the second terminal device 40 of the invalid status of the calling rights VC and terminates. Step S106A is optional.
[0032] In S107, the verification device 50 uses the VP verification function 55 to transfer the calling rights VP to the issuing device 20. The verification device 50 may further transfer the telephone number VP to the issuing device 20 using the VP verification function 55.
[0033] In S108, the issuing device 20 uses the VP verification function 26 to verify the calling right VP and confirms that service provider Y has been granted the right to make a call to user X, and also refers to the database 24 to confirm that user X has a telephone number managed by telecommunications carrier A. That is, the issuing device 20 confirms that the issuer of the calling right VC is user X, who has a telephone contract with telecommunications carrier A. The issuing device 20 may further verify the telephone number VP using the VP verification function 26 and confirm that user X has a telephone number managed by telecommunications carrier A. That is, the issuing device 20 may confirm that the issuer of the telephone number VC is telecommunications carrier A.
[0034] In S108A, the issuing device 20 checks the status of the calling right VC with the management device 60. If the calling right VC has expired, the issuing device 20 notifies the verification device 50 of the invalid status of the calling right VC and terminates. If the step in S106A is performed, the step in S108A may be omitted.
[0035] In S109, the issuing device 20 uses the connection management function 27 to transmit a call permission response to the verification device 50. The call permission response is a response granting permission for a call to be made from the second terminal device 40 to the first terminal device 30.
[0036] In S110, the verification device 50 uses the connection management function 56 to send a connection request to the second terminal device 40. The connection request is a request for an outgoing call from the second terminal device 40 to the first terminal device 30.
[0037] The second terminal device 40, in response to a connection request, uses its telephone function 47 to make a call to the first terminal device 30. The verification device 50 uses its connection management function 56 to relay the call from the second terminal device 40 to the first terminal device 30. The issuing device 20 uses its connection management function 27 to relay the call from the second terminal device 40 to the first terminal device 30. The first terminal device 30 uses its telephone function 38 to accept the call from the second terminal device 40. As a result, the first terminal device 30 and the second terminal device 40 establish a call connection with each other. The procedure from making a call to establishing a call connection can be based on a known protocol such as SIP.
[0038] Referring to Figure 2, the configuration of the issuing device 20 according to this embodiment will be described.
[0039] The issuing device 20 comprises a control unit 21, a storage unit 22, and a communication unit 23.
[0040] The control unit 21 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU or GPU, or a dedicated processor specialized for a specific process. "CPU" is an abbreviation for central processing unit. "GPU" is an abbreviation for graphics processing unit. The programmable circuit is, for example, an FPGA. "FPGA" is an abbreviation for field-programmable gate array. The dedicated circuit is, for example, an ASIC. "ASIC" is an abbreviation for application specific integrated circuit. The control unit 21 controls each part of the issuing device 20 and executes processes related to the operation of the issuing device 20.
[0041] The storage unit 22 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM, ROM, or flash memory. "RAM" is an abbreviation for random access memory. "ROM" is an abbreviation for read-only memory. The RAM is, for example, SRAM or DRAM. "SRAM" is an abbreviation for static random access memory. "DRAM" is an abbreviation for dynamic random access memory. The ROM is, for example, EEPROM. "EEPROM" is an abbreviation for electrically erasable programmable read-only memory. The flash memory is, for example, SSD. "SSD" is an abbreviation for solid-state drive. The magnetic memory is, for example, HDD. "HDD" is an abbreviation for hard disk drive. The storage unit 22 functions, for example, as main memory, auxiliary memory, or cache memory. The storage unit 22 stores information used for the operation of the issuing device 20 and information obtained through the operation of the issuing device 20. For example, the database 24 shown in Figure 1 is constructed in the storage unit 22.
[0042] The communication unit 23 includes at least one communication module. The communication module is a module corresponding to a wired LAN communication standard such as Ethernet (registered trademark) or a wireless LAN communication standard such as IEEE 802.11. "LAN" is an abbreviation for local area network. "IEEE" is an abbreviation for Institute of Electrical and Electronics Engineers. The communication unit 23 communicates with the first terminal device 30, the verification device 50, and the management device 60. The communication unit 23 receives information used in the operation of the issuing device 20 and transmits information obtained by the operation of the issuing device 20. For example, the database 24 shown in FIG. 1 may be constructed in an external storage to which the communication unit 23 can be connected.
[0043] Functions such as the VC issuing function 25, the VP verification function 26, and the connection management function 27 of the issuing device 20 are realized by executing the issuing program according to the present embodiment with a processor as the control unit 21. That is, the functions of the issuing device 20 are realized by software. The issuing program causes a computer to execute the operation of the issuing device 20, thereby making the computer function as the issuing device 20. That is, the computer functions as the issuing device 20 by executing the operation of the issuing device 20 according to the issuing program.
[0044] Some or all of the functions of the issuing device 20 may be realized by a programmable circuit or a dedicated circuit as the control unit 21. That is, some or all of the functions of the issuing device 20 may be realized by hardware.
[0045] Referring to FIG. 3, the configuration of the first terminal device 30 according to the present embodiment will be described.
[0046] The first terminal device 30 includes a control unit 31, a storage unit 32, a communication unit 33, an input unit 34, and an output unit 35.
[0047] The control unit 31 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU or GPU, or a dedicated processor specialized for specific processing. The programmable circuit is, for example, an FPGA. The dedicated circuit is, for example, an ASIC. The control unit 31 executes processes related to the operation of the first terminal device 30 while controlling each part of the first terminal device 30.
[0048] The storage unit 32 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, a RAM, ROM, or flash memory. The RAM is, for example, a SRAM or DRAM. The ROM is, for example, an EEPROM. The flash memory is, for example, a SSD. The magnetic memory is, for example, an HDD. The storage unit 32 functions as, for example, a main memory device, an auxiliary storage device, or a cache memory. Information used for the operation of the first terminal device 30 and information obtained by the operation of the first terminal device 30 are stored in the storage unit 32. For example, the wallet 36 shown in FIG. 1 is constructed in the storage unit 32.
[0049] The communication unit 33 includes at least one communication module. The communication module is a module corresponding to a wired LAN communication standard such as Ethernet (registered trademark), a wireless LAN communication standard such as IEEE802.11, or a mobile communication standard such as LTE, 4G standard, or 5G standard. "LTE" is an abbreviation for Long Term Evolution. "4G" is an abbreviation for 4th generation. "5G" is an abbreviation for 5th generation. The communication unit 33 communicates with the issuing device 20, the second terminal device 40, and the management device 60. The communication unit 33 receives information used for the operation of the first terminal device 30 and transmits information obtained by the operation of the first terminal device 30.
[0050] The input unit 34 includes at least one input device. The input device is, for example, a physical key, a capacitive key, a pointing device, a touchscreen integrated with a display, a visible light camera, a depth camera, LiDAR, or a microphone. "LiDAR" is an abbreviation for light detection and ranging. The input unit 34 accepts operations to input information used for the operation of the first terminal device 30. The input unit 34 may be connected to the first terminal device 30 as an external input device instead of being provided in the first terminal device 30. As a connection interface, an interface compatible with standards such as USB, HDMI®, or Bluetooth® can be used. "USB" is an abbreviation for Universal Serial Bus. "HDMI®" is an abbreviation for High-Definition Multimedia Interface.
[0051] The output unit 35 includes at least one output device. The output device is, for example, a display or a speaker. The display is, for example, an LCD or an organic EL display. "LCD" is an abbreviation for liquid crystal display. "EL" is an abbreviation for electroluminescent. The output unit 35 outputs information obtained by the operation of the first terminal device 30. Instead of being provided in the first terminal device 30, the output unit 35 may be connected to the first terminal device 30 as an external output device. As the connection interface, an interface compatible with standards such as USB, HDMI (registered trademark), or Bluetooth (registered trademark) can be used.
[0052] The functions of the first terminal device 30, such as the VC issuance function 37 and the telephone function 38, are realized by executing the first terminal program according to this embodiment on the processor acting as the control unit 31. In other words, the functions of the first terminal device 30 are realized by software. The first terminal program causes the computer to perform the operations of the first terminal device 30, thereby causing the computer to function as the first terminal device 30. That is, the computer functions as the first terminal device 30 by performing the operations of the first terminal device 30 according to the first terminal program.
[0053] Some or all of the functions of the first terminal device 30 may be implemented by a programmable circuit or a dedicated circuit as the control unit 31. In other words, some or all of the functions of the first terminal device 30 may be implemented by hardware.
[0054] Referring to Figure 4, the configuration of the second terminal device 40 according to this embodiment will be described.
[0055] The second terminal device 40 includes a control unit 41, a storage unit 42, a communication unit 43, an input unit 44, and an output unit 45.
[0056] The control unit 41 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU or GPU, or a dedicated processor specialized for a specific process. The programmable circuit is, for example, an FPGA. The dedicated circuit is, for example, an ASIC. The control unit 41 controls each part of the second terminal device 40 and executes processes related to the operation of the second terminal device 40.
[0057] The storage unit 42 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM, ROM, or flash memory. The RAM is, for example, SRAM or DRAM. The ROM is, for example, EEPROM. The flash memory is, for example, SSD. The magnetic memory is, for example, HDD. The storage unit 42 functions, for example, as a main memory, auxiliary memory, or cache memory. The storage unit 42 stores information used for the operation of the second terminal device 40 and information obtained by the operation of the second terminal device 40. For example, the wallet 46 shown in Figure 1 is built in the storage unit 42.
[0058] The communication unit 43 includes at least one communication module. The communication module is, for example, a module compatible with a wired LAN communication standard such as Ethernet®, a wireless LAN communication standard such as IEEE 802.11, or a mobile communication standard such as LTE, 4G, or 5G. The communication unit 43 communicates with the first terminal device 30 and the verification device 50. The communication unit 43 may also communicate with the management device 60. The communication unit 43 receives information used for the operation of the second terminal device 40 and transmits information obtained by the operation of the second terminal device 40.
[0059] The input unit 44 includes at least one input device. The input device may be, for example, a physical key, a capacitive key, a pointing device, a touchscreen integrated with a display, a visible light camera, a depth camera, LiDAR, or a microphone. The input unit 44 accepts operations to input information used for the operation of the second terminal device 40. The input unit 44 may be connected to the second terminal device 40 as an external input device instead of being provided in the second terminal device 40. As the connection interface, an interface compatible with standards such as USB, HDMI®, or Bluetooth® can be used.
[0060] The output unit 45 includes at least one output device. The output device is, for example, a display or a speaker. The display is, for example, an LCD or an organic EL display. The output unit 45 outputs information obtained by the operation of the second terminal device 40. Instead of being provided in the second terminal device 40, the output unit 45 may be connected to the second terminal device 40 as an external output device. As the connection interface, an interface compatible with standards such as USB, HDMI®, or Bluetooth® can be used.
[0061] The functions of the second terminal device 40, such as the telephone function 47, are realized by executing the second terminal program according to this embodiment on the processor acting as the control unit 41. In other words, the functions of the second terminal device 40 are realized by software. The second terminal program causes the computer to perform the operations of the second terminal device 40, thereby causing the computer to function as the second terminal device 40. That is, the computer functions as the second terminal device 40 by performing the operations of the second terminal device 40 according to the second terminal program.
[0062] Some or all of the functions of the second terminal device 40 may be implemented by a programmable circuit or a dedicated circuit as the control unit 41. In other words, some or all of the functions of the second terminal device 40 may be implemented by hardware.
[0063] Referring to Figure 5, the configuration of the verification device 50 according to this embodiment will be described.
[0064] The verification device 50 comprises a control unit 51, a storage unit 52, and a communication unit 53.
[0065] The control unit 51 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU or GPU, or a dedicated processor specialized for a specific process. The programmable circuit is, for example, an FPGA. The dedicated circuit is, for example, an ASIC. The control unit 51 controls each part of the verification device 50 and executes processes related to the operation of the verification device 50.
[0066] The storage unit 52 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM, ROM, or flash memory. The RAM is, for example, SRAM or DRAM. The ROM is, for example, EEPROM. The flash memory is, for example, SSD. The magnetic memory is, for example, HDD. The storage unit 52 functions, for example, as main memory, auxiliary memory, or cache memory. The storage unit 52 stores information used for the operation of the verification device 50 and information obtained by the operation of the verification device 50. For example, the database 54 shown in Figure 1 is built in the storage unit 52.
[0067] The communication unit 53 includes at least one communication module. The communication module is, for example, a module compatible with a wired LAN communication standard such as Ethernet® or a wireless LAN communication standard such as IEEE 802.11. The communication unit 53 communicates with the issuing device 20, the second terminal device 40, and the management device 60. The communication unit 53 receives information used for the operation of the verification device 50 and transmits information obtained by the operation of the verification device 50. For example, the database 54 shown in Figure 1 may be built on external storage that the communication unit 53 can connect to.
[0068] The functions of the verification device 50, such as the VP verification function 55 and the connection management function 56, are realized by executing the verification program according to this embodiment on the processor acting as the control unit 51. In other words, the functions of the verification device 50 are realized by software. The verification program causes the computer to perform the operations of the verification device 50, thereby causing the computer to function as the verification device 50. That is, the computer functions as the verification device 50 by performing the operations of the verification device 50 according to the verification program.
[0069] Some or all of the functions of the verification device 50 may be implemented by a programmable circuit or a dedicated circuit as the control unit 51. In other words, some or all of the functions of the verification device 50 may be implemented by hardware.
[0070] Programs such as publishing programs, first terminal programs, second terminal programs, or verification programs can be stored on a non-temporary computer-readable medium. Examples of non-temporary computer-readable media include flash memory, magnetic recording devices, optical discs, magneto-optical recording media, or ROM. Program distribution is carried out, for example, by selling, transferring, or lending portable media such as SD cards, DVDs, or CD-ROMs containing the programs. "SD" is an abbreviation for Secure Digital. "DVD" is an abbreviation for digital versatile disc. "CD-ROM" is an abbreviation for compact disc read only memory. Programs may also be distributed by storing them in server storage and transferring them from the server to other computers. Programs may also be provided as program products.
[0071] A computer, for example, stores a program stored on a portable medium or a program transferred from a server in its main memory. Then, the computer reads the program stored in the main memory with its processor and executes the processing according to the read program. The computer may also read a program directly from the portable medium and execute the processing according to the program. The computer may also execute the processing according to the received program sequentially each time a program is transferred to it from a server. Processing may also be performed by a so-called ASP type service, which does not transfer programs from the server to the computer, but realizes its function only through execution instructions and result retrieval. "ASP" is an abbreviation for application service provider. A program includes information used for processing by an electronic computer that is equivalent to a program. For example, data that is not a direct instruction to the computer but has the nature of defining the computer's processing falls under "equivalent to a program".
[0072] The operation of the communication system 10 according to this embodiment will be described in detail with reference to Figures 6 and 7. The operation described below corresponds to the communication method according to this embodiment.
[0073] In S101, the control unit 21 of the issuing device 20 issues qualification information to the first terminal device 30 via the communication unit 23, indicating the qualification of the first user associated with the first terminal device 30, with the issuer's signature. The control unit 31 of the first terminal device 30 receives the qualification information issued from the issuing device 20 via the communication unit 33. In this embodiment, user X corresponds to the first user, communication carrier A to the issuer, and telephone number VC to the qualification information issued from the issuing device 20 to the first terminal device 30.
[0074] In S102, the control unit 31 of the first terminal device 30 receives a user operation via the input unit 34 to specify a second user associated with the second terminal device 40. In response to this user operation, the control unit 31 of the first terminal device 30 issues rights information indicating the rights of the second user with the signature of the first user to the second terminal device 40 via the communication unit 33. The control unit 41 of the second terminal device 40 receives the rights information issued from the first terminal device 30 via the communication unit 43. In this embodiment, the service provider Y corresponds to the second user, and the calling right VC corresponds to the rights information issued from the first terminal device 30 to the second terminal device 40.
[0075] In S102A, the control unit 31 of the first terminal device 30 registers information indicating that the rights information issued in S102 is valid with the management device 60 via the communication unit 33 as status information indicating whether or not the rights information is valid. In this embodiment, the valid status of the calling rights VC corresponds to the status information.
[0076] In S103, the control unit 31 of the first terminal device 30 presents the credentials received in S101 to the second terminal device 40 via the communication unit 33. The control unit 41 of the second terminal device 40 receives the credentials presented from the first terminal device 30 via the communication unit 43. In this embodiment, the telephone number VP corresponds to the credentials presented from the first terminal device 30 to the second terminal device 40.
[0077] In S104, the control unit 41 of the second terminal device 40 receives a user operation to specify the first user via the input unit 44. In response to this user operation, the control unit 41 of the second terminal device 40 presents the rights information received in S102 to the verification device 50 via the communication unit 43. The control unit 51 of the verification device 50 receives the rights information presented from the second terminal device 40 via the communication unit 53. In this embodiment, the calling right VP corresponds to the rights information presented from the second terminal device 40 to the verification device 50.
[0078] In S105, the control unit 41 of the second terminal device 40 transfers the credential information received in S103 to the verification device 50 via the communication unit 43. The control unit 51 of the verification device 50 receives the credential information transferred from the second terminal device 40, that is, the credential information presented from the first terminal device 30 via the second terminal device 40, via the communication unit 53. In this embodiment, the telephone number VP corresponds to the credential information transferred from the second terminal device 40 to the verification device 50.
[0079] In S106, the control unit 51 of the verification device 50 verifies the credential information received in S105 to confirm the issuer. In this embodiment, the control unit 51 of the verification device 50 verifies the telephone number VP and confirms that the issuer of the telephone number VC is the telecommunications carrier A.
[0080] In S106A, the control unit 51 of the verification device 50 accesses the management device 60 and receives the status information registered in the management device 60 by the first terminal device 30 in S102A from the management device 60 via the communication unit 53. The control unit 51 of the verification device 50 refers to the received status information and confirms that the rights information received in S104 is valid. In this embodiment, the control unit 51 of the verification device 50 confirms that the valid status of the calling rights VC is registered in the management device 60.
[0081] In S107, the control unit 51 of the verification device 50 transfers the rights information received in S104 to the issuing device 20 via the communication unit 53. The control unit 21 of the issuing device 20 receives the rights information transferred from the verification device 50, that is, the rights information presented from the second terminal device 40 via the verification device 50, via the communication unit 23. In this embodiment, the calling right VP corresponds to the rights information transferred from the verification device 50 to the issuing device 20.
[0082] In S108, the control unit 21 of the issuing device 20 verifies the rights information received in S107 to confirm the first user. In this embodiment, the control unit 21 of the issuing device 20 verifies the calling right VP and confirms that the issuer of the calling right VC is user X who has a telephone contract with telecommunications carrier A.
[0083] In S108A, the control unit 21 of the issuing device 20 accesses the management device 60 and receives the status information registered in the management device 60 by the first terminal device 30 in S102A from the management device 60 via the communication unit 23. The control unit 21 of the issuing device 20 refers to the received status information and confirms that the rights information received in S107 is valid. In this embodiment, the control unit 21 of the issuing device 20 confirms that the valid status of the calling rights VC is registered in the management device 60.
[0084] In S109, the control unit 21 of the issuing device 20 transmits a response to the verification device 50 via the communication unit 23 granting permission for communication to the first terminal device 30. The control unit 51 of the verification device 50 receives the response transmitted from the issuing device 20 via the communication unit 53. In this embodiment, the call permission response corresponds to the response transmitted from the issuing device 20 to the verification device 50.
[0085] In S110, the control unit 51 of the verification device 50 requests the second terminal device 40 to make a communication to the first terminal device 30 via the communication unit 53. The control unit 41 of the second terminal device 40 receives the request for communication to the first terminal device 30 from the verification device 50 via the communication unit 43. The control unit 41 of the second terminal device 40 executes the communication to the first terminal device 30 via the communication unit 43 in response to the received request. The control unit 31 of the first terminal device 30 receives the communication from the second terminal device 40 to the first terminal device 30 via the communication unit 33. In this embodiment, the connection request corresponds to the request from the verification device 50. The control unit 41 of the second terminal device 40 makes a call to the first terminal device 30 in response to the connection request. The control unit 31 of the first terminal device 30 receives the call from the second terminal device 40.
[0086] In S111, the control unit 31 of the first terminal device 30 receives a user operation via the input unit 34 to invalidate the rights information issued in S102. In response to this user operation, the control unit 31 of the first terminal device 30 instructs the management device 60 via the communication unit 33 to update the status information registered in S102A to information indicating that the rights information is invalid. In this embodiment, if user X does not want to receive contact from the party to whom the calling rights VC was given, i.e., service provider Y, the user can register the invalidation of the calling rights VC. The control unit 31 of the first terminal device 30 associates the ID of the calling rights VC with the invalid status of the calling rights VC instead of the valid status of the calling rights VC.
[0087] The rights information may include information indicating the expiration date set by the first terminal device 30. In such a modified example, the control unit 21 of the issuing device 20 further confirms that the expiration date has not passed when verifying the rights information. Therefore, in S108, the control unit 21 of the issuing device 20 verifies the rights information to confirm the first user and confirms that the expiration date has not passed, and then in S109, transmits a response to the verification device 50 granting permission for communication to the first terminal device 30.
[0088] In addition to steps S106A and S108A, or in place of either or both of steps S106A and S108A, the control unit 41 of the second terminal device 40 may perform a step of accessing the management device 60. In such a modification, the control unit 41 of the second terminal device 40 receives the status information registered with the management device 60 by the first terminal device 30 in S102A from the management device 60 via the communication unit 33. The control unit 41 of the second terminal device 40 refers to the received status information and confirms that the rights information received in S102 is valid.
[0089] In this embodiment, the credentials do not include the first user's phone number, and the communication destined for the first terminal device 30 includes a phone call destined for the first terminal device 30. Therefore, the first user can prove that they possess a phone number without notifying the recipient of their phone number, and then restrict the recipient. Thus, the phone number cannot be known to malicious operators, and the risk of the phone number being leaked to other operators without permission can be eliminated. In other words, the leakage of phone numbers can be prevented, and the situation in which phone numbers are disseminated to third parties can be avoided.
[0090] In this embodiment, a calling rights certificate (VC) is issued from user X to service provider Y, and a telephone number certificate (VC) issued to user X by telecommunications carrier A, with which user X has a contract, is presented. The telephone number certificate (VC) is a certificate issued by telecommunications carrier A proving that user X owns a telephone number. The telephone number cannot be known from either the telephone number certificate (VC) or the telephone number VP (VC). Telecommunications carrier A can access user X from the identifier of the VC. The telephone number certificate (VC) may be one-time. The calling rights certificate (VC) is a certificate that authorizes user X to call service provider Y. If service provider Y wants to call user X, it presents the calling rights certificate (VC) to telecommunications carrier B, with which service provider Y has a contract. Telecommunications carrier B, with which service provider Y has a contract, requests a call from telecommunications carrier A based on the telephone number certificate (VC) and simultaneously presents the calling rights certificate (VC). Telecommunications carrier A verifies the calling rights certificate (VC), and once it confirms that it is a valid certificate, it activates the telephone line in response to a request from telecommunications carrier B.
[0091] As described above, in this embodiment, by combining a VC that proves ownership of a telephone number with a VC that proves the right to make a call to the recipient, it becomes possible to prove ownership of a telephone number and limit the recipient of a call without notifying the other party of the telephone number. For example, user X can make a call to service provider Y without disclosing their telephone number.
[0092] Once a voice call (VC) is given, the recipient may continue to contact the user until the VC automatically expires. However, in this embodiment, the terminal performs the registration and expiration procedures for the VC, which proves the right to make a call to the recipient, and the communication carrier confirms the validity of the VC. Therefore, according to this embodiment, even if a VC is given, it is possible to prevent further contact before the VC automatically expires.
[0093] A modified example of the configuration and operation of the communication system 10 will be described with reference to Figure 8.
[0094] In this modified version, the first terminal device 30 has an email function 39 instead of a telephone function 38. The second terminal device 40 has an email function 48 instead of a telephone function 47.
[0095] The issuing device 20 manages terminal information related to the first terminal device 30 using the database 24. This terminal information includes the email address of user X. This email address was obtained by user X through a provider contract with email service provider A. Similarly, the verification device 50 manages terminal information related to the second terminal device 40 using the database 54. This terminal information includes the email address of service provider Y. This email address was obtained by service provider Y through a provider contract with email service provider B.
[0096] In S201, the issuing device 20 uses the VC issuing function 25 to refer to the database 24 and confirm that user X possesses an email address managed by mail service provider A, and then issues an email address VC to the first terminal device 30. The email address VC is a VC that proves that user X possesses an email address managed by mail service provider A. The email address VC does not include user X's email address itself. The first terminal device 30 manages the email address VC using the wallet 36.
[0097] In S202, the first terminal device 30 issues a sending right VC using the VC issuance function 37 in response to a user operation specifying service provider Y as the recipient of the email. The sending right VC is a VC that proves that service provider Y has been granted the right to send an email to user X. The second terminal device 40 manages the sending right VC using the wallet 46.
[0098] In S202A, the first terminal device 30 registers the valid status of the transmission right VC with the management device 60. At that time, the first terminal device 30 does not register the transmission right VC itself, but registers the ID of the transmission right VC.
[0099] In S203, the first terminal device 30 uses the wallet 36 to convert the email address VC to an email address VP and presents it to the second terminal device 40. The second terminal device 40 manages the email address VP using, for example, the wallet 46, but may manage the email address VP by other means.
[0100] In S204, the second terminal device 40, in response to a user operation specifying user X as the recipient of the email, uses the wallet 46 to convert the sending right VC to a sending right VP and presents it to the verification device 50.
[0101] In S205, the second terminal device 40 transfers the email address VP to the verification device 50 using, for example, the wallet 46, but the email address VP may be transferred to the verification device 50 by other means.
[0102] In S206, the verification device 50 uses the VP verification function 55 to verify the email address VP and confirms that user X has an email address managed by email service provider A. That is, the verification device 50 confirms that the issuer of the email address VC is email service provider A. The verification device 50 may also use the VP verification function 55 to further verify the sending rights VP and confirm that service provider Y has been granted the right to send email to user X, and may also refer to the database 54 to confirm that service provider Y has an email address managed by email service provider B. That is, the verification device 50 may confirm that the issuer of the sending rights VP is service provider Y, which has a provider contract with email service provider B.
[0103] In S206A, the verification device 50 checks the status of the transmission right VC with the management device 60. If the transmission right VC has expired, the verification device 50 notifies the second terminal device 40 of the invalid status of the transmission right VC and terminates. Step S206A is optional.
[0104] In S207, the verification device 50 uses the VP verification function 55 to transfer the transmission rights VP to the issuing device 20. The verification device 50 may further transfer the email address VP to the issuing device 20 using the VP verification function 55.
[0105] In S208, the issuing device 20 uses the VP verification function 26 to verify the sending rights VP and confirms that service provider Y has been granted the right to send email to user X. It also refers to the database 24 and confirms that user X has an email address managed by email service provider A. In other words, the issuing device 20 confirms that the issuer of the sending rights VC is user X, who has a provider contract with email service provider A. The issuing device 20 may further verify the email address VP using the VP verification function 26 and confirm that user X has an email address managed by email service provider A. In other words, the issuing device 20 may confirm that the issuer of the email address VC is email service provider A.
[0106] In S208A, the issuing device 20 checks the status of the transmission right VC with the management device 60. If the transmission right VC has expired, the issuing device 20 notifies the verification device 50 of the invalid status of the transmission right VC and terminates. If the step in S206A is executed, the step in S208A may be omitted.
[0107] In S209, the issuing device 20 uses the connection management function 27 to send a transmission permission response to the verification device 50. The transmission permission response is a response granting permission for email transmission from the second terminal device 40 to the first terminal device 30.
[0108] In S210, the verification device 50 uses the connection management function 56 to send a transmission request to the second terminal device 40. The transmission request is a request for email transmission from the second terminal device 40 to the first terminal device 30.
[0109] The second terminal device 40 sends an email to the first terminal device 30 using its email function 48 in response to a transmission request. The verification device 50 forwards the email from the second terminal device 40 to the first terminal device 30 using its connection management function 56. The issuing device 20 forwards the email from the second terminal device 40 to the first terminal device 30 using its connection management function 27. The first terminal device 30 receives the email from the second terminal device 40 using its email function 39. The procedure from sending to receiving an email can be a procedure conforming to a known protocol such as SMTP. "SMTP" is an abbreviation for Simple Mail Transfer Protocol.
[0110] Refer to Figure 9 to explain in detail a modified example of the operation of the communication system 10.
[0111] In S201, the control unit 21 of the issuing device 20 issues to the first terminal device 30, via the communication unit 23, credentials indicating the credentials of the first user associated with the first terminal device 30, with the issuer's signature. The control unit 31 of the first terminal device 30 receives the credentials issued from the issuing device 20 via the communication unit 33. In this modified example, user X corresponds to the first user, email service provider A to the issuer, and email address VC to the credentials issued from the issuing device 20 to the first terminal device 30.
[0112] In S202, the control unit 31 of the first terminal device 30 receives a user operation via the input unit 34 to specify a second user associated with the second terminal device 40. In response to this user operation, the control unit 31 of the first terminal device 30 issues rights information indicating the rights of the second user with the signature of the first user to the second terminal device 40 via the communication unit 33. The control unit 41 of the second terminal device 40 receives the rights information issued from the first terminal device 30 via the communication unit 43. In this modified example, the service provider Y corresponds to the second user, and the transmission right VC corresponds to the rights information issued from the first terminal device 30 to the second terminal device 40.
[0113] In S202A, the control unit 31 of the first terminal device 30 registers information indicating that the rights information issued in S202 is valid with the management device 60 via the communication unit 33 as status information indicating whether or not the rights information is valid. In this embodiment, the valid status of the transmission rights VC corresponds to the status information.
[0114] In S203, the control unit 31 of the first terminal device 30 presents the credentials received in S201 to the second terminal device 40 via the communication unit 33. The control unit 41 of the second terminal device 40 receives the credentials presented from the first terminal device 30 via the communication unit 43. In this modified example, the email address VP corresponds to the credentials presented from the first terminal device 30 to the second terminal device 40.
[0115] In S204, the control unit 41 of the second terminal device 40 receives a user operation to specify the first user via the input unit 44. In response to this user operation, the control unit 41 of the second terminal device 40 presents the rights information received in S202 to the verification device 50 via the communication unit 43. The control unit 51 of the verification device 50 receives the rights information presented from the second terminal device 40 via the communication unit 53. In this modified example, the transmission right VP corresponds to the rights information presented from the second terminal device 40 to the verification device 50.
[0116] In S205, the control unit 41 of the second terminal device 40 transfers the credentials received in S203 to the verification device 50 via the communication unit 43. The control unit 51 of the verification device 50 receives the credentials transferred from the second terminal device 40, that is, the credentials presented from the first terminal device 30 via the second terminal device 40, via the communication unit 53. In this modified example, the email address VP corresponds to the credentials transferred from the second terminal device 40 to the verification device 50.
[0117] In S206, the control unit 51 of the verification device 50 verifies the credentials received in S205 to confirm the issuer. In this modified example, the control unit 51 of the verification device 50 verifies the email address VP and confirms that the issuer of email address VC is email service provider A.
[0118] In S206A, the control unit 51 of the verification device 50 accesses the management device 60 and receives the status information registered in the management device 60 by the first terminal device 30 in S202A from the management device 60 via the communication unit 53. The control unit 51 of the verification device 50 refers to the received status information and confirms in S204 that the received rights information is valid. In this embodiment, the control unit 51 of the verification device 50 confirms that the valid status of the transmission rights VC is registered in the management device 60.
[0119] In S207, the control unit 51 of the verification device 50 transfers the rights information received in S204 to the issuing device 20 via the communication unit 53. The control unit 21 of the issuing device 20 receives the rights information transferred from the verification device 50, that is, the rights information presented from the second terminal device 40 via the verification device 50, via the communication unit 23. In this modified example, the transmission rights VP corresponds to the rights information transferred from the verification device 50 to the issuing device 20.
[0120] In S208, the control unit 21 of the issuing device 20 verifies the rights information received in S207 to confirm the first user. In this modified example, the control unit 21 of the issuing device 20 verifies the transmission rights VP and confirms that the issuer of the transmission rights VC is user X, who has a provider contract with mail service provider A.
[0121] In S208A, the control unit 21 of the issuing device 20 accesses the management device 60 and receives the status information registered in the management device 60 by the first terminal device 30 in S202A from the management device 60 via the communication unit 23. The control unit 21 of the issuing device 20 refers to the received status information and confirms in S207 that the received rights information is valid. In this embodiment, the control unit 21 of the issuing device 20 confirms that the valid status of the transmission rights VC is registered in the management device 60.
[0122] In S209, the control unit 21 of the issuing device 20 transmits a response to the verification device 50 via the communication unit 23 granting permission for communication to the first terminal device 30. The control unit 51 of the verification device 50 receives the response transmitted from the issuing device 20 via the communication unit 53. In this modified example, the transmission permission response corresponds to the response transmitted from the issuing device 20 to the verification device 50.
[0123] In S210, the control unit 51 of the verification device 50 requests the second terminal device 40 to send a communication to the first terminal device 30 via the communication unit 53. The control unit 41 of the second terminal device 40 receives the request for communication from the verification device 50 to the first terminal device 30 via the communication unit 43. The control unit 41 of the second terminal device 40 executes the communication to the first terminal device 30 via the communication unit 43 in response to the received request. The control unit 31 of the first terminal device 30 receives the communication from the second terminal device 40 to the first terminal device 30 via the communication unit 33. In this modified example, the transmission request corresponds to the request from the verification device 50. The control unit 41 of the second terminal device 40 sends an email to the first terminal device 30 in response to the transmission request. The control unit 31 of the first terminal device 30 receives the email from the second terminal device 40.
[0124] The operation of the control unit 31 of the first terminal device 30 when it receives a user operation to invalidate the rights information issued in S202 is the same as the step in S111 shown in Figure 7, so the explanation is omitted. In this modified example, if user X does not want to receive contact from the party to whom the transmission rights VC was given, i.e., service provider Y, it can register the invalidation of the transmission rights VC. The control unit 31 of the first terminal device 30 associates the ID of the transmission rights VC with the invalid status of the transmission rights VC instead of the valid status of the transmission rights VC.
[0125] In this modified version, the credentials do not include the email address of the first user, and communication to the first terminal device 30 includes sending an email to the first terminal device 30. Therefore, the first user can prove that they possess the email address without notifying the recipient of the email address, and then restrict the recipient. Thus, the email address will not be known to malicious businesses, and the risk of the email address being leaked to other businesses without permission will be eliminated. In other words, it is possible to prevent the leakage of email addresses and avoid situations in which email addresses are spread to third parties.
[0126] In this modified example, a sending rights certificate (VC) is issued from user X to service provider Y, and an email address certificate (VC) issued to user X by email service provider A, with whom user X has a contract, is presented. The email address certificate (VC) is a certificate issued by email service provider A proving that user X owns an email address. The email address cannot be known from either the email address certificate (VC) or the email address VP (VP). Email service provider A can access user X from the identifier of the certificate (VC). The email address certificate (VC) may be one-time certificate. The sending rights certificate (VC) is a certificate that authorizes service provider Y to send emails to user X. If service provider Y wants to send an email to user X, it presents the sending rights certificate (VC) to email service provider B, with whom service provider Y has a contract. Email service provider B, with whom service provider Y has a contract, requests email service provider A to send an email based on the email address certificate (VC), and simultaneously presents the sending rights certificate (VC). Email service provider A verifies the sending rights certificate (VC), and once it confirms that it is a valid certificate, it requests email service provider B to send the email.
[0127] As described above, in this modified version, by combining a VC that proves ownership of an email address with a VC that proves the right to send emails to the sender, it becomes possible to prove ownership of an email address without notifying the recipient of the email address, and to limit the communication recipients. For example, user X can receive emails from service provider Y without disclosing their email address.
[0128] Once a VC (Virtual Code) is given, the recipient may continue to contact you until the VC automatically expires. However, in this modified version, the terminal performs the registration and revocation procedures for the VC, which proves the right to send emails to the recipient, and the email service provider verifies the validity of that VC. Therefore, according to this modified version, even if a VC has been given, it is possible to prevent further contact before the VC automatically expires.
[0129] The following additional information is disclosed regarding the embodiments described above.
[0130] (Note 1) An issuing device comprising: a communication unit that communicates with a verification device and a management device; a control unit that receives from the verification device via the communication unit right information, which is issued from the first terminal device to the second terminal device and presented from the second terminal device to the verification device, indicating the rights of the second user associated with the second terminal device with the signature of the first user associated with the first terminal device; a control unit that receives from the management device via the communication unit status information, which is registered with the management device by the first terminal device, indicating whether or not the right information is valid; a control unit that verifies the received right information to confirm the first user, and after confirming that the right information is valid by referring to the received status information, transmits a response to the verification device via the communication unit indicating permission to communicate to the first terminal device. (Note 2) The issuing device according to Note 1, wherein the right information includes information indicating an expiration date set by the first terminal device, and the control unit further confirms that the expiration date has not expired when verifying the right information. (Note 3) A communication method comprising: a first terminal device issuing rights information to the second terminal device that indicates the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device; the first terminal device registering status information in a management device indicating whether or not the rights information is valid; the issued rights information being presented from the second terminal device to a verification device, transferred from the verification device to an issuing device, verified by the issuing device to confirm the first user, the registered status information being transmitted from the management device to the issuing device, referenced by the issuing device to confirm that the rights information is valid, a response authorizing communication to the first terminal device being transmitted from the issuing device to the verification device, and the first terminal device receiving the communication from the second terminal device when the verification device requests the communication. (Appendix 4) The communication method according to Appendix 3, further comprising the first terminal device updating the registered status information to information indicating that the rights information is invalid in response to a user operation that invalidates the rights information.(Note 5) The communication method described in Note 3 or Note 4, wherein the communication includes a telephone call to the first terminal device. (Note 6) The communication method described in Note 3 or Note 4, wherein the communication includes sending an email to the first terminal device. (Note 7) A program that causes a computer to perform an operation equivalent to the communication method described in any one of Note 3 to Note 6. (Appendix 8) Verification device comprising: a communication unit that communicates with an issuing device, a second terminal device, and a management device; a control unit that receives, via the communication unit, rights information issued from the first terminal device to the second terminal device and presented by the second terminal device, indicating the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device; status information registered by the first terminal device to the management device, indicating whether or not the rights information is valid, received from the management device via the communication unit; confirming that the rights information is valid by referring to the received status information, and then forwarding the received rights information to the issuing device via the communication unit; and when the forwarded rights information is verified by the issuing device and the first user is confirmed, the control unit that receives a response from the issuing device via the communication unit granting permission for communication to the first terminal device, and then requests the communication from the second terminal device via the communication unit.
[0131] This disclosure is not limited to the embodiments described above. For example, two or more blocks shown in the block diagram may be combined, or one block may be divided. Instead of executing two or more steps shown in the flowchart in chronological order as described, they may be executed in parallel or in a different order, depending on the processing capacity of the device performing each step, or as necessary. Other modifications are possible without departing from the spirit of this disclosure.
[0132] 10 Communication system 11 Carrier network 12 Internet 20 Issuing device 21, 31, 41, 51 Control unit 22, 32, 42, 52 Storage unit 23, 33, 43, 53 Communication unit 24, 54 Database 25, 37 VC issuance function 26, 55 VP verification function 27, 56 Connection management function 34, 44 Input unit 35, 45 Output unit 36, 46 Wallet 38, 47 Telephone function 39, 48 Email function 30 First terminal device 40 Second terminal device 50 Verification device 60 Management device
Claims
1. An issuing device comprising: a communication unit that communicates with a verification device and a management device; a control unit that receives from the verification device via the communication unit right information, which is issued from the first terminal device to the second terminal device and presented from the second terminal device to the verification device, indicating the rights of the second user associated with the second terminal device with the signature of the first user associated with the first terminal device; a control unit that receives from the management device via the communication unit status information, which is registered with the management device by the first terminal device, indicating whether or not the right information is valid; a control unit that verifies the received right information to confirm the first user, and after confirming that the right information is valid by referring to the received status information, transmits a response to the verification device via the communication unit granting permission for communication to the first terminal device.
2. The issuing device according to claim 1, wherein the rights information includes information indicating an expiration date set by the first terminal device, and the control unit further confirms that the expiration date has not expired when verifying the rights information.
3. A communication method comprising: a first terminal device issuing rights information to the second terminal device that indicates the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device; the first terminal device registering status information in a management device indicating whether or not the rights information is valid; the issued rights information being presented from the second terminal device to a verification device, transferred from the verification device to an issuing device, verified by the issuing device to confirm the first user, the registered status information being transmitted from the management device to the issuing device, referenced by the issuing device to confirm that the rights information is valid, a response authorizing communication to the first terminal device being transmitted from the issuing device to the verification device, and the first terminal device receiving the communication from the second terminal device when the verification device requests the communication.
4. The communication method according to claim 3, further comprising the first terminal device updating the registered status information to information indicating that the rights information is invalid in response to a user operation that invalidates the rights information.
5. The communication method according to claim 3, wherein the communication includes a telephone call addressed to the first terminal device.
6. The communication method according to claim 3, wherein the communication includes sending an email to the first terminal device.
7. A program that causes a computer to perform an operation equivalent to the communication method described in any one of claims 3 to 6.
8. Verification device comprising: a communication unit that communicates with an issuing device, a second terminal device, and a management device; a control unit that receives, via the communication unit, rights information issued from the first terminal device to the second terminal device and presented by the second terminal device, indicating the rights of a second user associated with the second terminal device, with the signature of the first user associated with the first terminal device; status information registered by the first terminal device to the management device, indicating whether the rights information is valid or not, received from the management device via the communication unit; confirming that the rights information is valid by referring to the received status information, and then forwarding the received rights information to the issuing device via the communication unit; and when the forwarded rights information is verified by the issuing device and the first user is confirmed, the control unit that receives a response from the issuing device via the communication unit granting permission for communication to the first terminal device, and then requests the communication from the second terminal device via the communication unit.