Acquisition device, acquisition system, acquisition method, and program

The acquisition device and system use a tamper-resistant storage circuit to securely authenticate and issue verifiable credentials, addressing data tampering issues in cloud-based digital identity wallets by preventing unauthorized access and ensuring credential integrity.

WO2026099969A1PCT designated stage Publication Date: 2026-05-15NT T INC
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NT T INC
Filing Date
2024-11-06
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

There is a need for a mechanism to acquire verifiable credentials while preventing attacks such as data tampering in cloud-based digital identity wallets.

Method used

An acquisition device and system that utilizes a tamper-resistant storage arithmetic processing circuit to store user certification authority certificates and private keys, enabling secure signature requests and responses to authenticate the user and prevent tampering, with a control unit managing the issuance of verifiable credentials through a management device.

Benefits of technology

The solution ensures secure acquisition of verifiable credentials by preventing malware infection, redirection to unauthorized cloud wallets, and endpoint name matching attacks, thereby ensuring the integrity of the credential issuance process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024039514_15052026_PF_FP_ABST
    Figure JP2024039514_15052026_PF_FP_ABST
Patent Text Reader

Abstract

An acquisition device (100) according to the present disclosure comprises a control unit (103) and a SIM card (104). The SIM card (104) stores a user certificate authority certificate, a user's public key, and a user's secret key paired with the public key, which have been issued by a certificate authority. When requesting issuance of VC, the control unit (103) outputs a signature request to the SIM card (104). In response to the signature request, the SIM card (104) outputs, to the control unit (130), a signature response to which a signature created using the secret key is put and which includes the user certificate authority certificate to which the signature of the certificate authority is put and which includes the public key. The control unit (103) transmits, to an issuance device (200), an endpoint notification including the signature response.
Need to check novelty before this filing date? Find Prior Art

Description

Acquisition Device, Acquisition System, Acquisition Method, and Program

[0001] The present disclosure relates to an acquisition device, an acquisition system, an acquisition method, and a program.

[0002] In recent years, self-sovereign identity (SSI) technology has been studied in which users manage their own identifiers and identities and control presentation destinations without relying on a centralized identity provider (IdP) or the like (see Non-Patent Documents 1 and 2).

[0003] In digital identity, there are three parties: Holder, Issuer, and Verifier. Holder is a user or the like who manages and holds their own digital identity. The Issuer issues verifiable credentials (VCs) that prove the user's attributes and / or qualifications to the Holder, after verifying attribute information (name, age, address, etc.) and qualification information (being an employee of a certain company, being a member of a certain service, etc.). The Verifier requests and receives the VCs necessary for service provision from the Holder, verifies the Holder's attributes, qualifications, etc., and makes decisions regarding service provision.

[0004] A digital identity wallet (DIW) has been proposed for managing user (Holder) ID data and using it for identity verification and attribute proof (see Non-Patent Document 3). As embodiments of the DIW, there are two forms: a form in which ID data is managed within a user device (local wallet) and a form in which ID data is managed on a platform hosted by a cloud provider or the like (cloud wallet).

[0005] “W3C Decentralized Identifiers (DID)” [online], [Accessed October 29, 2024], Internet<URL: https: / / www.w3.org / TR / did-core / > “W3C Verifiable Credentials” [online], [Accessed October 29, 2024], Internet<URL: https: / / www.w3.org / TR / vc-data-model / > “European digital identity wallet” [online], [searched October 29, 2024], Internet <URL: https: / / digital-strategy.ec.europa.eu / en / library / european-digital-identity-wallet-architecture-and-reference-framework>

[0006] By using a cloud-based DIW (Data Identity Warehouse), users can reduce the effort required to properly manage user devices equipped with ID data and ID data processing functions. Furthermore, using a cloud-based DIW reduces the risk of external access to ID data due to factors such as loss of user devices or inadequate security settings.

[0007] In cloud-based DIW (Data Intervention Work), there is a need for a mechanism that can retrieve VCs (Virtual Certificates) from issuing devices while preventing attacks such as data tampering.

[0008] In light of the problems described above, the purpose of this disclosure is to provide an acquisition device, acquisition system, acquisition method, and program that can acquire verifiable credentials while preventing attacks such as information tampering.

[0009] An acquisition device according to one embodiment is an acquisition device for acquiring verifiable credentials of a user, comprising: a control unit; and a tamper-resistant storage arithmetic processing circuit, wherein the storage arithmetic processing circuit stores a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user; the control unit outputs a signature request to the storage arithmetic processing circuit when it requests the issuance of the verifiable credentials; the storage arithmetic processing circuit outputs to the control unit a signature response that is signed using the private key, includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority; and the control unit transmits an endpoint notification, including the signature response, to an issuing device that issues the verifiable credentials, notifying a management device that manages the verifiable credentials.

[0010] An acquisition system according to one embodiment comprises an acquisition device for acquiring verifiable credentials of a user, a management device for managing the verifiable credentials, and an issuing device for issuing the verifiable credentials, wherein the acquisition device includes a tamper-resistant storage arithmetic processing circuit, the acquisition device stores in the storage arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the user's legitimacy, the acquisition device outputs a signature request to the storage arithmetic processing circuit when it requests the issuance of the verifiable credentials, the acquisition device outputs a signature response in the storage arithmetic processing circuit in response to the signature request, which is a signed signature response created using the private key, which includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority, and the acquisition device transmits an endpoint notification to the issuing device, which includes the signature response, notifying the management device that manages the verifiable credentials. If the issuing device verifies the signature of the Certificate Authority attached to the user Certificate Authority certificate included in the endpoint notification using the public key of the Certificate Authority, and determines that the signature of the Certificate Authority is valid, it verifies the signature attached to the signature response using the public key included in the user Certificate Authority certificate, and determines that the signature attached to the signature response is valid, it sends an acceptance request to the management device notified by the endpoint notification, requesting the acceptance of the verifiable credentials; the management device, in response to the acceptance request, sends an issue request to the issuing device, requesting the issuance of the verifiable credentials, which includes the identifier of the management device; and the issuing device, in response to the issue request, issues verifiable credentials associated with the identifier of the management device included in the issue request to the management device.

[0011] An acquisition method according to one embodiment is an acquisition method in an acquisition system comprising an acquisition device for acquiring verifiable credentials of a user, a management device for managing the verifiable credentials, and an issuing device for issuing the verifiable credentials, wherein the acquisition device comprises a tamper-resistant storage arithmetic processing circuit, the acquisition device stores in the storage arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user, the acquisition device outputs a signature request to the storage arithmetic processing circuit in response to the signature request, the acquisition device outputs a signature response in the storage arithmetic processing circuit, which is a signed signature response created using the private key, which includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority, and the acquisition device transmits an endpoint notification to the issuing device, which notifies the management device that manages the verifiable credentials, including the signature response. If the issuing device verifies the signature of the Certificate Authority attached to the user Certificate Authority certificate included in the endpoint notification using the public key of the Certificate Authority, and determines that the signature of the Certificate Authority is valid, it verifies the signature attached to the signature response using the public key included in the user Certificate Authority certificate, and determines that the signature attached to the signature response is valid, it sends an acceptance request to the management device notified by the endpoint notification, requesting the acceptance of the verifiable credentials; the management device, in response to the acceptance request, sends an issue request to the issuing device, requesting the issuance of the verifiable credentials, which includes the identifier of the management device; and the issuing device, in response to the issue request, issues verifiable credentials associated with the identifier of the management device included in the issue request to the management device.

[0012] A program according to one embodiment causes a computer to operate as the acquisition device described above.

[0013] According to this disclosure, it is possible to obtain verifiable credentials while preventing attacks such as information tampering.

[0014] This figure shows an example configuration of an acquisition system according to one embodiment of the present disclosure. This is a sequence diagram showing an example of the operation of the acquisition system shown in Figure 1. This is a sequence diagram showing another example of the operation of the acquisition system shown in Figure 1. This is a sequence diagram showing yet another example of the operation of the acquisition system shown in Figure 1. This is a sequence diagram showing yet another example of the operation of the acquisition system shown in Figure 1.

[0015] Embodiments of this disclosure will be described below with reference to the drawings.

[0016] Figure 1 is a diagram showing an example configuration of an acquisition system 10 according to one embodiment of the present disclosure.

[0017] As shown in Figure 1, the acquisition system 10 according to this embodiment comprises an acquisition device 100, an issuing device 200, and a management device 300. The acquisition device 100, the issuing device 200, and the management device 300 can communicate with each other via a network 11 such as the Internet.

[0018] The acquisition device 100 is a device used by the user (Holder), such as a smartphone or personal computer. The acquisition device 100 acquires the user's verifiable credentials (VC). As described above, a VC is a certificate that proves the user's attributes and / or qualifications. The VC is issued by the Issuer's issuing device 200, which issues a signed certificate after verifying the user's attributes and qualifications. In the cloud wallet, the VC is managed by the management device 300. In this embodiment, the VC is issued by the issuing device 200 in response to a request from the acquisition device 100 and acquired and managed by the management device 300.

[0019] As shown in Figure 1, the acquisition device 100 according to this embodiment includes a storage unit 101, a communication unit 102, a control unit 103, and a SIM (Subscriber Identity Module) card 104.

[0020] The storage unit 101 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The semiconductor memory is, for example, RAM (Random Access Memory), ROM (Read Only Memory), or flash memory. The RAM is, for example, SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory). The ROM is, for example, EEPROM (Electrically Erasable Programmable Read Only Memory). The flash memory is, for example, SSD (Solid-State Drive). The magnetic memory is, for example, HDD (Hard Disk Drive). The storage unit 101 functions, for example, as main memory, auxiliary memory, or cache memory. The storage unit 101 stores information used in the operation of the acquisition device 100 and information obtained by the operation of the acquisition device 100.

[0021] The communication unit 102 includes at least one communication module. The communication module is, for example, a module compatible with a LAN communication standard such as Ethernet®. The communication unit 102 communicates with the issuing device 200 and the management device 300 via the network 11. The communication unit 102 receives information used for the operation of the acquisition device 100 and transmits information obtained through the operation of the acquisition device 100.

[0022] The control unit 103 includes at least one processor, at least one programmable circuit, at least one dedicated circuit, or any combination thereof. The processor is a general-purpose processor such as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit), or a dedicated processor specialized for a specific process. The programmable circuit is, for example, an FPGA (Field-Programmable Gate Array). The dedicated circuit is, for example, an ASIC (Application Specific Integrated Circuit).

[0023] The control unit 103 controls each part of the acquisition device 100 and executes processes related to the operation of the acquisition device 100. For example, when the control unit 103 requests the issuance of a VC, it outputs a signature request to the SIM card 104. The control unit 103 also sends an endpoint notification to the issuing device 200, notifying the management device 300 that manages the VC, including the signature response output from the SIM card 104 in response to the signature request.

[0024] The SIM card 104 is an example of a memory arithmetic processing circuit that has tamper resistance (resistance to unauthorized reading or alteration of internal information). The memory arithmetic processing circuit is composed of, for example, a CPU and memory. The SIM card 104 stores information used for the operation of the acquisition device 100 and information obtained by the operation of the acquisition device 100. The SIM card 104 also executes processing related to the operation of the acquisition device 100. For example, the SIM card 104 stores a user CA certificate, a public key (user CA Pk), and a private key (user CA Pk) that is paired with the public key, which are issued to the user by a Certificate Authorities (CA) that proves the legitimacy of the user (Holder), and are not shown in Figure 1. Furthermore, when a signature request is output from the control unit 103, the SIM card 104 outputs a signature response to the signature request to the control unit 103.

[0025] The issuing device 200 is a device used by the Issuer. The issuing device 200 issues verifiable credentials (VCs) to the user.

[0026] As shown in Figure 1, the issuing device 200 according to this embodiment includes a storage unit 201, a communication unit 202, and a control unit 203.

[0027] The storage unit 201, like the storage unit 101, includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 201 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 201 stores information used for the operation of the issuing device 200 and information obtained by the operation of the issuing device 200.

[0028] The communication unit 202, like the communication unit 102, includes at least one communication module. The communication unit 202 communicates with the acquisition device 100 and the management device 300 via the network 11. The communication unit 202 receives information used for the operation of the issuing device 200 and transmits information obtained through the operation of the issuing device 200.

[0029] The control unit 203 controls each part of the issuing device 200 and executes processes related to the operation of the issuing device 200. For example, when the control unit 203 receives an endpoint notification from the acquisition device 100, it sends an acceptance request to the management device 300, which was notified by the endpoint notification, requesting the acceptance of the VC. Also, when the control unit 203 receives a VC issuance request from the management device 300, for example, it issues the VC to the management device 300.

[0030] The management device 300 is a device such as a server connected to the network 11. The management device 300 manages user verifiable credentials (VCs) issued to the Holder by the Issuer.

[0031] As shown in Figure 1, the management device 300 according to this embodiment includes a storage unit 301, a communication unit 302, and a control unit 303.

[0032] Like the storage unit 101, the storage unit 301 includes at least one semiconductor memory, at least one magnetic memory, at least one optical memory, or any combination thereof. The storage unit 301 functions, for example, as a main memory, an auxiliary memory, or a cache memory. The storage unit 301 stores information used for the operation of the management device 300 and information obtained by the operation of the management device 300.

[0033] The communication unit 302, like the communication unit 102, includes at least one communication module. The communication unit 302 communicates with the acquisition device 100 and the issuing device 200 via the network 11. The communication unit 302 receives information used for the operation of the management device 300 and transmits information obtained through the operation of the management device 300.

[0034] The control unit 303 controls each part of the management device 300 and executes processes related to the operation of the management device 300. For example, when the control unit 303 receives a receipt request from the issuing device 200 requesting the receipt of a VC, it sends a VC issuance request to the issuing device 200. The control unit 303 also manages the VCs issued by the issuing device 200 in response to the VC issuance request.

[0035] The functions of the acquisition device 100, the issuing device 200, and the management device 300 are realized by executing the program according to this embodiment on processors acting as control units 103, 203, and 303. In other words, the functions of the acquisition device 100, the issuing device 200, and the management device 300 are realized by software. The program causes the computer to perform the operations of the acquisition device 100, the issuing device 200, and the management device 300, thereby causing the computer to function as the acquisition device 100, the issuing device 200, and the management device 300. That is, the computer functions as the acquisition device 100, the issuing device 200, and the management device 300 by performing the operations of the acquisition device 100, the issuing device 200, and the management device 300 according to the program.

[0036] The program can be stored on a non-temporary computer-readable medium. Examples of non-temporary computer-readable mediums include flash memory, magnetic recording devices, optical discs, magneto-optical recording media, or ROM. The program can be distributed, for example, by selling, transferring, or leasing portable media such as SD (Secure Digital) cards, DVDs (Digital Versatile Discs), or CD-ROMs (Compact Disc Read Only Memory) on which the program is stored. The program may also be distributed by storing it in server storage and transferring it from the server to other computers. The program may also be provided as a program product.

[0037] A computer, for example, stores a program stored on a portable medium or a program transferred from a server in its main memory. Then, the computer reads the program stored in the main memory with its processor and executes the processing according to the read program. The computer may also read the program directly from the portable medium and execute the processing according to the program. The computer may also execute the processing according to the received program sequentially each time a program is transferred to it from a server. Processing may also be performed by a so-called ASP (Application Service Provider) type service, which does not transfer programs from the server to the computer, but realizes its function only through execution instructions and result retrieval. A program includes information used for processing by an electronic computer that is equivalent to a program. For example, data that is not a direct instruction to the computer but has the nature of defining the computer's processing falls under "equivalent to a program".

[0038] Some or all of the functions of the acquisition device 100, the issuing device 200, and the management device 300 may be implemented by programmable circuits or dedicated circuits as control units 103, 203, and 303. In other words, some or all of the functions of the acquisition device 100, the issuing device 200, and the management device 300 may be implemented by hardware.

[0039] Next, the operation of each device in the acquisition system 10 according to this embodiment will be described. Figure 2 is a sequence diagram showing an example of the operation of the acquisition system 10 according to this embodiment, and is a diagram for explaining the acquisition method in the acquisition system 10 according to this embodiment.

[0040] In the example shown in Figure 2, the SIM card 104 pre-stores a user CA certificate, a public key (user CA Pk), and a private key (user CA Sk) issued to the user (Holder) by a certification authority, which prove the user's legitimacy. The SIM card 104 also pre-stores a wallet address (e.g., a URL (Uniform Resource Locator)), which is the address of the management device 300 that manages the user's VC. Alternatively, instead of a wallet address, an identifier such as a SUPI (Subscriber Permanent Identifier) ​​or SUCI (Subscriber Concealed Identifier) ​​indicating the telephone carrier subscriber ID may be stored in the SIM card 104. The SUPI and SUCI contain information that identifies the country or carrier, and in the case of SUCI, it is anonymized, making it possible to conceal the user (Holder) from the issuing device 200.

[0041] Furthermore, the storage unit 301 of the management device 300 has the identifier (C-DID) of the management device 300 (cloud wallet) stored in advance.

[0042] When issuing a VC to the acquisition device 100, the issuing device 200 notifies the acquisition device 100 of the number used only once (Nonce) (step S11).

[0043] When the acquisition device 100 (control unit 103) requests the issuance of a VC for a user (Holder), it outputs a signature request to the SIM card 104 (step S12). The control unit 103 includes the Nonce notified from the issuance device 200 in the signature request. Also, the acquisition device 100 may include the identifier (C-DID) of the management device 300 in the signature request. The management device 300 may use a plurality of C-DIDs. In this case, by including the C-DID in the signature request, the VC to be issued later can be associated with the C-DID. Note that when the C-DID is not included in the signature request, the C-DID associated with the VC may be selected by the management device 300.

[0044] When the SIM card 104 receives a signature request from the control unit 103, it outputs a signature response to the control unit 103 (step S13). The SIM card 104 includes the Nonce included in the signature request in the signature response. Also, the SIM card 104 includes a Seq, which is a number representing a sequence independent of the Nonce, in the signature response. Also, the SIM card 104 includes the wallet address included in the signature request in the signature response. Also, when the C-DID is included in the signature request, the SIM card 104 may include the C-DID in the signature response.

[0045] Also, the SIM card 104 includes the stored user CA certificate in the signature response. Here, the SIM card 104 includes the public key (user CA Pk) issued to the user by the certification authority in the user CA certificate, and attaches a signature (RootCA signature) generated by the public key of the certification authority (RootCA public key) to the user CA certificate. Also, the SIM card 104 attaches a signature (user CA signature) generated by the private key (user CA Sk) issued to the user by the certification authority to the entire signature response. Thus, the SIM card 104 outputs a signature response to the control unit 103 that includes the user CA certificate, has a signature (user CA signature) created using the private key (user CA Sk) attached in response to the signature request, the user CA certificate includes the public key (user CA Pk), and has the signature of the certification authority (RootCA signature) attached.

[0046] When the acquisition device 100 (control unit 103) outputs a signature response from the SIM card 104, it transmits an endpoint notification (EP notification) including the signature response to the issuing device 200 to notify the management device 300 that manages the VC (step S14).

[0047] The issuing device 200 verifies the Root CA signature attached to the user CA certificate included in the EP notification using the public key of the certification authority (Root CA public key). Thereby, the issuing device 200 can confirm that the acquisition device 100 that has transmitted the EP notification has been authenticated by the certification authority (the integrity of the acquisition device 100). The issuing device 200 may have previously acquired the Root CA public key, or may acquire the Root CA public key from the certification authority in response to the reception of the EP notification.

[0048] When the issuing device 200 confirms the integrity of the acquisition device 100, it verifies the user CA signature attached to the signature response using the user CA Pk included in the user CA certificate. As described above, since the user CA Pk and the user CA Sk are stored in the tamper-resistant SIM card 104, it is difficult to forge them. Therefore, the issuing device 200 can confirm that the EP notification is a legitimate notification from the acquisition device 100 by verifying the user CA signature.

[0049] As described above, the EP notification includes the Nonce notified to the acquisition device 100 for the issuing device 200 to issue the VC. Thereby, the issuing device 200 can confirm that the EP notification is in response to the request from the issuing device 200.

[0050] When the issuing device 200 confirms that the acquiring device 100 that sent the EP notification is authenticated by the certification authority, and that the EP notification is a legitimate notification from the acquiring device 100, it sends an acceptance request to the management device 300 requesting the acceptance of the VC issued by the issuing device 200 (step S15). Specifically, the issuing device 200 sends an acceptance request to the management device 300, which includes the EP notification received from the acquiring device 100. The issuing device 200 may also send a VC proving the identity of the issuing device 200 to the management device 300 along with the acceptance request.

[0051] When the management device 300 receives an acceptance request transmitted from the issuing device 200, it stores the Seq included in the acceptance request in the storage unit 301. In this way, the management device 300 can ensure that acceptance requests for already issued VCs are not repeated, that is, that the information included in the EP notification is not reused. When the management device 300 receives an acceptance request, it sends an attendance request (certification request) to the issuing device 200 requesting information regarding the legitimacy of the issuing device 200 (step S16).

[0052] When the issuing device 200 receives an attendance request sent from the management device 300, it sends an attendance response (certification response) to the management device 300 that contains information regarding the legitimacy of the issuing device 200 (step S17). The information regarding the legitimacy of the issuing device 200 may be, for example, an attendance report issued by the hardware of the issuing device 200 or a VC that certifies the attributes of the issuing device 200.

[0053] When the management device 300 receives an attention response from the issuing device 200, it verifies the legitimacy of the issuing device 200 based on the attention report included in the attention response or the VC which proves the attributes of the issuing device 200. Once the management device 300 has confirmed the legitimacy of the issuing device 200, it sends an issuance request to the issuing device 200 requesting the issuance of a VC. The management device 300 includes its identifier (C-DID) in the issuance request. The management device 300 also sends an attention verification result indicating the verification result of the legitimacy of the issuing device 200 to the issuing device 200 (step S18).

[0054] When the issuing device 200 receives an issuance request and attendance verification result from the management device 300, it issues a VC associated with the identifier (C-DID) of the management device 300 included in the issuance request to the management device 300 (step S19). The issued VC is stored and managed by the management device 300.

[0055] When the management device 300 receives a VC issued by the issuing device 200, it transmits an issuance result indicating that a VC has been issued to the issuing device 200 (step S20). The issuing device 200 transmits the issuance result and the attendance verification result received from the management device 300 to the acquisition device 100.

[0056] As shown in Figure 2, in the example, the tamper-resistant SIM card 104 stores the user CA certificate, user CA Pk, user CA Sk, and wallet address, and sends an EP notification containing a signature response generated using these to the issuing device 200. The issuing device 200 also verifies, based on the user CA certificate and other information included in the EP notification, that the acquiring device 100 that sent the EP notification is authenticated by a certification authority, and that the EP notification is a legitimate notification from the acquiring device 100. This prevents malware infection of the acquiring device 100, redirection to a cloud wallet owned by someone other than the owner of the acquiring device 100, and attacks such as name matching using endpoint information.

[0057] Furthermore, by having the management device 300 store the Seq included in the VC request (EP notification), it is possible to prevent the EP notification from being reused repeatedly and to prevent the Verifier from performing endpoint name matching.

[0058] Figure 3 is a sequence diagram showing another example of the operation of the acquisition system 10 according to this embodiment. In Figure 3, the same reference numerals are used for processes similar to those in Figure 2, and their explanations are omitted.

[0059] In Figure 3, the management device 300 is equipped with a Trusted Execution Environment (TEE). A Trusted Execution Environment is a secure area of ​​the device's hardware and software that can protect specific data and processes from external tampering and interference. The construction of a TEE itself is well known to those skilled in the art, so a detailed explanation is omitted. The Trusted Execution Environment of the management device 300 stores the public key (TEE Pk) of the management device 300 and its corresponding private key (TEE Sk), which are issued by a certification authority.

[0060] The SIM card 104 stores the user CA certificate, public key (user CA Pk), and private key (user CA Sk) issued to the user by the Certificate Authority. The SIM card 104 also stores the signature of the management device 300 (cloud wallet Tee Sk signature) generated using the Tee Sk. In other words, the SIM card 104 stores the signature (cloud wallet Tee Sk signature) created using the management device 300's private key (user CA Sk), which is managed in the management device 300's trusted execution environment (TEE). The cloud wallet Tee Sk signature is pre-stored on the SIM card 104. Furthermore, in the example shown in Figure 3, the wallet address may be stored in the storage unit 101 of the acquisition device 100, rather than on the SIM card 104.

[0061] When a signature request is input from the control unit 103 (step S12), the SIM card 104 outputs a signature response to the control unit 103 (step S31). Specifically, the SIM card 104 includes the Nonce, Seq, and user CA certificate in the signature response, which is signed by the user CA, similar to the example shown in Figure 2. Furthermore, in the example shown in Figure 3, the SIM card 104 includes the cloud wallet Tee Sk signature in the signature response. That is, in response to the signature request, the SIM card 104 outputs a signature response to the control unit 103 that further includes a signature (cloud wallet Tee Sk signature) created using the private key (Tee Sk) of the management device 300.

[0062] The control unit 103 sends an EP notification including a signature response to the issuing device 200 (step S32). Here, the control unit 103 includes the wallet address stored in the storage unit 101 in the EP notification.

[0063] When the issuing device 200 receives an EP notification, it obtains a Tee Pk from the management device 300. The issuing device 200 then uses the obtained Tee Pk to verify the cloud wallet Tee Sk signature included in the EP notification. As described above, the Tee Pk and Tee Sk are issued by a Certificate Authority and bear the Certificate Authority's signature. Therefore, by verifying the cloud wallet Tee Sk signature using the Tee Pk, the issuing device 200 can confirm that the EP notification is not forged.

[0064] In the example described above, the issuing device 200 obtains the Tee Pk from the management device 300 in response to the receipt of the EP notification and verifies the cloud wallet Tee Sk signature, but this is not the only example.

[0065] If a VC stored in the management device 300 is Keybound (meaning that when a VC is issued, the VC is associated with a TEE Pk stored in the management device 300), the management device 300 may include the Tee Pk associated with the VC in the issuance request (step S33). The issuing device 200 uses the Tee Pk included in the issuance request to verify the cloud wallet Tee Sk signature included in the EP notification. In this way, the issuing device 200 can verify the identity of the management device 300.

[0066] When the issuing device 200 receives an issuance request including the C-DID and Tee Pk, it issues a VC associated with the C-DID and Tee Pk to the management device 300 (step S34).

[0067] In the example shown in Figure 3, similar to the example shown in Figure 2, it is possible to prevent attacks such as malware infection of the acquisition device 100, redirection to a cloud wallet owned by someone other than the owner of the acquisition device 100, and name matching using endpoint information.

[0068] Furthermore, by having the management device 300 store the Seq included in the VC request (EP notification), it is possible to prevent the EP notification from being reused repeatedly and to prevent the Verifier from performing endpoint name matching.

[0069] Figure 4 is a sequence diagram showing yet another example of the operation of the acquisition system 10 according to this embodiment. In Figure 4, the same reference numerals are used for processes as in Figure 2, and their explanations are omitted.

[0070] In the example shown in Figure 4, the acquisition device 100 further includes an authenticator 105 that performs biometric authentication of the user. The authenticator 105 has a private key (FIDO Sk).

[0071] As in the example shown in Figure 2, the SIM card 104 stores the user CA certificate, public key (user CA Pk), and user private key (user CA Sk). The wallet address is also pre-stored on the SIM card 104. Furthermore, in the example shown in Figure 4, the public key (FIDO Pk) of the authenticator 105 is also stored on the SIM card 104.

[0072] When the acquisition device 100 (control unit 103) requests the issuance of a VC, it outputs a signature request and a biometric authentication request (FIDO authentication request) requesting the user's biometric authentication to the SIM card 104 (step S41).

[0073] The authenticator 105 performs biometric authentication of the user and outputs the biometric authentication result to the SIM card 104.

[0074] The SIM card 104 performs biometric authentication (Passkey authentication) using the FIDO Sk of the authenticator 105 and the stored FIDO Pk. If authentication is successful, the SIM card 104 includes a VC indicating that FIDO authentication was performed in the signature response. That is, when the user is biometrically authenticated by the authenticator 105, the SIM card 104 outputs a signature response to the control unit 103 that further includes a VC indicating that the user has been biometrically authenticated (step S42).

[0075] When the issuing device 200 receives the EP notification, it confirms that the user has been biometrically authenticated based on the VC indicating that FIDO authentication has been performed.

[0076] In the example shown in Figure 4, the public key (FIDO Pk) of the authenticator 105 is stored in the SIM card 104, and the result of biometric authentication by the authenticator 105 is authenticated using FIDO Pk and FIDO Sk, thereby preventing impersonation by handing over the SIM card 104 to someone else.

[0077] Figure 5 is a sequence diagram showing yet another example of the operation of the acquisition system 10 according to this embodiment. In Figure 5, the same reference numerals are used for processes similar to those in Figure 2, and their explanations are omitted.

[0078] In the example shown in Figure 5, the SIM card 104 pre-stores the user CA certificate, public key (user CA Pk), and private key (user CA Sk) issued to the user by a certification authority. The SIM card 104 also pre-stores a cloud wallet VC that certifies the attributes / qualifications of the management device 300 that manages the user's VC. The cloud wallet VC is issued by a certification authority such as a carrier and bears the certification authority's signature. The cloud wallet VC includes the identifier (C-DID) of the management device 300 (cloud wallet), the public key (C-Pk) of the management device 300, and the cloud wallet address.

[0079] Furthermore, the storage unit 301 of the management device 300 has the identifier (C-DID), the public key (C-Pk), and the private key (C-Sk) of the management device 300 pre-stored in it.

[0080] When a signature request is input from the control unit 103 (step S12), the SIM card 104 outputs a signature response to the control unit 103 (step S51). Specifically, the SIM card 104 includes the Nonce, Seq, and user CA certificate in the signature response, which is signed by the user CA, similar to the example shown in Figure 2. Furthermore, in the example shown in Figure 5, the SIM card 104 includes the cloud wallet VC in the signature response. That is, in response to the signature request, the SIM card 104 outputs a signature response to the control unit 103 that includes the identifier (C-DID) of the management device 300, the public key (C-Pk) of the management device, and the cloud wallet address, and further includes the cloud wallet VC, which is signed by the Certificate Authority.

[0081] When the issuing device 200 receives an EP notification, it verifies the RootCA signature attached to the user CA certificate included in the EP notification using the RootCA public key, similar to the example shown in Figure 2. This allows the issuing device 200 to confirm that the acquiring device 100 that sent the EP notification is authenticated by a certification authority (the integrity of the acquiring device 100). The issuing device 200 also verifies the signature of the cloud wallet VC included in the EP notification. This allows the issuing device 200 to confirm that the cloud wallet VC is authenticated by a certification authority.

[0082] Furthermore, when the issuing device 200 receives the issuance request and attendance verification result from the management device 300 (step S18), it may verify, by means of DID-AUTH or other means, whether the C-DID and C-Pk stored in the management device 300 match the C-DID and C-Pk included in the cloud wallet VC.

[0083] As described above, the acquisition device 100 according to this embodiment comprises a control unit 103 and a SIM card 104 as a tamper-resistant memory arithmetic processing circuit. The SIM card 104 stores a user certification authority certificate (user CA certificate), a public key (user CA Pk), and a private key (user CA Sk) paired with the public key, which are issued to the user by the certification authority. When the control unit 103 requests the issuance of a VC, it outputs a signature request to the SIM card 104. In response to the signature request, the SIM card 104 outputs a signature response to the control unit 103, which includes a signature (user CA signature) created using the user's private key (user CA Sk), the user CA certificate, the user CA certificate includes the user's public key (user CA Pk), and is signed by the certification authority 600 (RootCA signature). The control unit 103 transmits an EP notification including the signature response to the issuing device 200.

[0084] By sending an EP notification containing a signature response generated using the user CA certificate, user CA Pk, and user CA Sk stored in the tamper-resistant SIM card 104 to the issuing device 200, it is possible to prevent malware infection of the acquisition device 100, redirection to a cloud wallet owned by someone other than the owner of the acquisition device 100, and attacks such as name matching using endpoint information. Therefore, according to this disclosure, verifiable credentials can be obtained while preventing attacks such as information tampering.

[0085] The following additional information is disclosed regarding the embodiments described above.

[0086] [Addendum 1] An acquisition device for acquiring verifiable credentials of a user, comprising: a control unit; and a tamper-resistant storage arithmetic processing circuit, wherein the storage arithmetic processing circuit is configured to store a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user; the control unit is configured to output a signature request to the storage arithmetic processing circuit when it requests the issuance of the verifiable credentials; the storage arithmetic processing circuit outputs to the control unit a signature response that is signed using the private key, which includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority; and the control unit transmits an endpoint notification, which includes the signature response, to an issuing device that issues the verifiable credentials, notifying a management device that manages the verifiable credentials.

[0087] [Addendum 2] An acquisition device as described in Addendum 1, wherein the memory processing circuit further stores the address of the management device and further includes the address of the management device in the signature response.

[0088] [Appendix 3] The acquisition device described in Appendix 1, further comprising a storage unit for storing the address of the management device, wherein the storage arithmetic processing circuit further stores a signature generated using the private key of the management device, which is managed in a trusted execution environment of the management device, and outputs the signature response to the control unit in response to the signature request, which further includes the signature created using the private key of the management device, and the control unit transmits the endpoint notification, which includes the signature response and the address of the management device, to the issuing device.

[0089] [Appendix 4] An acquisition device according to any one of the appendix items 1 to 3, further comprising an authenticator for performing biometric authentication of the user, wherein the control unit, when requesting the issuance of verifiable credentials, outputs the signature request and a biometric authentication request requesting biometric authentication of the user to the storage arithmetic processing circuit, and when the user is biometrically authenticated by the authenticator, the storage arithmetic processing circuit outputs the signature response to the control unit, further including verifiable credentials indicating that the user has been biometrically authenticated.

[0090] [Appendix 5] An acquisition device as described in Appendix 1, wherein the memory arithmetic processing circuit further stores verifiable credentials of the management device, which include the identifier of the management device and the public key of the management device and are signed by the certification authority, and outputs the signature response, which further includes the verifiable credentials of the management device, to the control unit in response to the signature request.

[0091] [Addendum 6] An acquisition system comprising an acquisition device for acquiring verifiable credentials of a user, a management device for managing the verifiable credentials, and an issuing device for issuing the verifiable credentials, wherein the acquisition device comprises a tamper-resistant memory arithmetic processing circuit, the acquisition device stores in the memory arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user, the acquisition device outputs a signature request to the memory arithmetic processing circuit when it requests the issuance of the verifiable credentials, the acquisition device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority, and the acquisition device transmits an endpoint notification to the issuing device, which includes the signature response, notifying the management device that manages the verifiable credentials. An acquisition system in which the issuing device verifies the signature of the Certificate Authority attached to the user Certificate Authority certificate included in the endpoint notification using the public key of the Certificate Authority, and if it determines that the signature of the Certificate Authority is valid, it verifies the signature attached to the signature response using the public key included in the user Certificate Authority certificate, and if it determines that the signature attached to the signature response is valid, it sends an acceptance request to the management device notified by the endpoint notification requesting to receive the verifiable credentials; the management device, in response to the acceptance request, sends an issue request to the issuing device requesting to issue the verifiable credentials, which include the identifier of the management device; and the issuing device, in response to the issue request, issues verifiable credentials associated with the identifier of the management device included in the issue request to the management device.

[0092] [Addendum 7] A verification method in an acquisition system comprising an acquisition device for acquiring verifiable credentials of a user, a management device for managing the verifiable credentials, and an issuing device for issuing the verifiable credentials, wherein the acquisition device comprises a tamper-resistant memory arithmetic processing circuit, the acquisition device stores in the memory arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user, the acquisition device outputs a signature request to the memory arithmetic processing circuit when it requests the issuance of the verifiable credentials, the acquisition device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature created using the private key and includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority, and the acquisition device transmits an endpoint notification to the issuing device, which includes the signature response, notifying the management device that manages the verifiable credentials. Acquisition method comprising: the issuing device verifies the signature of the Certificate Authority attached to the user Certificate Authority certificate included in the endpoint notification using the public key of the Certificate Authority, and if it determines that the signature of the Certificate Authority is valid, it verifies the signature attached to the signature response using the public key included in the user Certificate Authority certificate, and if it determines that the signature attached to the signature response is valid, it sends an acceptance request to the management device notified by the endpoint notification requesting the acceptance of the verifiable credentials; the management device, in response to the acceptance request, sends an issuance request to the issuing device requesting the issuance of the verifiable credentials, which includes the identifier of the management device; and the issuing device, in response to the issuance request, issues verifiable credentials associated with the identifier of the management device included in the issuance request to the management device.

[0093] [Appendix 8] A non-temporary storage medium storing a program executable by a computer, the non-temporary storage medium storing a program that causes the computer to function as an acquisition device described in any one of the appendix items 1 to 5.

[0094] Although the embodiments described above are representative examples, it will be apparent to those skilled in the art that many modifications and substitutions are possible within the spirit and scope of this disclosure. Therefore, the present invention should not be construed as being limited by the embodiments described above, and various modifications or changes are possible without departing from the claims. For example, it is possible to combine multiple component blocks shown in the configuration diagram of the embodiments into one, or to divide one component block.

[0095] 10 Acquisition system 11 Network 100 Acquisition device 200 Issuing device 300 Management device 101, 201, 301 Storage unit 102, 202, 302 Communication unit 103, 203, 303 Control unit 104 SIM card (storage information processing circuit) 105 Authenticator

Claims

1. An acquisition device for acquiring verifiable credentials of a user, comprising: a control unit; and a tamper-resistant storage arithmetic processing circuit, wherein the storage arithmetic processing circuit stores a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the legitimacy of the user; the control unit outputs a signature request to the storage arithmetic processing circuit when it requests the issuance of the verifiable credentials; the storage arithmetic processing circuit outputs to the control unit a signature response, which is signed using the private key, includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority; and the control unit transmits an endpoint notification, which includes the signature response, to an issuing device that issues the verifiable credentials, notifying a management device that manages the verifiable credentials.

2. An acquisition device according to claim 1, wherein the memory arithmetic processing circuit further stores the address of the management device and further includes the address of the management device in the signature response.

3. An acquisition device according to claim 1, further comprising a storage unit for storing the address of the management device, wherein the storage arithmetic processing circuit further stores a signature generated using the private key of the management device, which is managed in a trusted execution environment of the management device, and outputs the signature response to the control unit in response to the signature request, which further includes the signature created using the private key of the management device, and the control unit transmits the endpoint notification, which includes the signature response and the address of the management device, to the issuing device.

4. An acquisition device according to claim 1, further comprising an authenticator for performing biometric authentication of the user, wherein the control unit outputs the signature request and the biometric authentication request for the user to the storage arithmetic processing circuit when it requests the issuance of verifiable credentials, and the storage arithmetic processing circuit outputs the signature response to the control unit, further including verifiable credentials indicating that the user has been biometrically authenticated, when the user has been biometrically authenticated by the authenticator.

5. An acquisition device according to claim 1, wherein the storage arithmetic processing circuit further stores verifiable credentials of the management device, which include an identifier of the management device and the public key of the management device, and which are signed by the certification authority, and outputs the signature response, which further includes the verifiable credentials of the management device, to the control unit in response to the signature request.

6. An acquisition system comprising an acquisition device for acquiring user verifiable credentials, a management device for managing the verifiable credentials, and an issuing device for issuing the verifiable credentials, wherein the acquisition device comprises a tamper-resistant memory arithmetic processing circuit, the acquisition device stores in the memory arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that verifies the user's legitimacy, the acquisition device outputs a signature request to the memory arithmetic processing circuit when it requests the issuance of the verifiable credentials, the acquisition device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signed signature response created using the private key, which includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority, and the acquisition device transmits an endpoint notification to the issuing device, which notifies the management device that manages the verifiable credentials, including the signature response. An acquisition system in which the issuing device verifies the signature of the Certificate Authority attached to the user Certificate Authority certificate included in the endpoint notification using the public key of the Certificate Authority, and if it determines that the signature of the Certificate Authority is valid, it verifies the signature attached to the signature response using the public key included in the user Certificate Authority certificate, and if it determines that the signature attached to the signature response is valid, it sends an acceptance request to the management device notified by the endpoint notification requesting to receive the verifiable credentials; the management device, in response to the acceptance request, sends an issue request to the issuing device requesting to issue the verifiable credentials, which include the identifier of the management device; and the issuing device, in response to the issue request, issues verifiable credentials associated with the identifier of the management device included in the issue request to the management device.

7. An acquisition method in an acquisition system comprising an acquisition device for acquiring verifiable credentials of a user, a management device for managing the verifiable credentials, and an issuing device for issuing the verifiable credentials, wherein the acquisition device comprises a tamper-resistant memory arithmetic processing circuit, the acquisition device stores in the memory arithmetic processing circuit a user certification authority certificate, a public key, and a private key paired with the public key, which are issued to the user by a certification authority that certifies the user's legitimacy, the acquisition device outputs a signature request to the memory arithmetic processing circuit when it requests the issuance of the verifiable credentials, the acquisition device outputs a signature response in the memory arithmetic processing circuit in response to the signature request, which is a signature created using the private key and includes the user certification authority certificate, the user certification authority certificate includes the public key, and is signed by the certification authority, and the acquisition device transmits an endpoint notification to the issuing device, which includes the signature response, notifying the management device that manages the verifiable credentials. Acquisition method comprising: the issuing device verifies the signature of the Certificate Authority attached to the user Certificate Authority certificate included in the endpoint notification using the public key of the Certificate Authority, and if it determines that the signature of the Certificate Authority is valid, it verifies the signature attached to the signature response using the public key included in the user Certificate Authority certificate, and if it determines that the signature attached to the signature response is valid, it sends an acceptance request to the management device notified by the endpoint notification requesting the acceptance of the verifiable credentials; the management device, in response to the acceptance request, sends an issuance request to the issuing device requesting the issuance of the verifiable credentials, which includes the identifier of the management device; and the issuing device, in response to the issuance request, issues verifiable credentials associated with the identifier of the management device included in the issuance request to the management device.

8. A program that causes a computer to operate as an acquisition device according to any one of claims 1 to 5.