Method and system for replacing verifiable credential

WO2026160815A1PCT designated stage Publication Date: 2026-07-30HOPAE INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HOPAE INC
Filing Date
2026-01-20
Publication Date
2026-07-30

Smart Images

  • Figure KR2026001170_30072026_PF_FP_ABST
    Figure KR2026001170_30072026_PF_FP_ABST
Patent Text Reader

Abstract

According to one aspect of the present invention, provided is a method for replacing a verifiable credential (VC), the method comprising the steps of: specifying at least one VC as a VC to be replaced; and in response to the VC to be replaced being verified by an issuer node, having a new VC issued corresponding to the VC to be replaced so as to replace the VC to be replaced with the new VC.
Need to check novelty before this filing date? Find Prior Art

Description

Method and system for replacing VC

[0001] The present invention relates to a method and system for replacing VC.

[0002] Recently, as interest in Self-Sovereign Identity (SSI) has increased, there has been active discussion regarding methods to prove the qualifications required to receive desired services using Verifiable Credentials (VC; hereinafter abbreviated as "Credentials"). Basically, this method is carried out by an issuer issuing a credential that digitally expresses that a specific entity, such as an individual or organization, possesses a specific qualification, thereby enabling that specific entity to possess the credential; the holder of the credential then presents it to a verifier in the form of a Verifiable Presentation (VP; hereinafter abbreviated as "Presentation"), and the verifier verifies it.

[0003] As an example of prior art regarding this, the technology disclosed in Korean Patent Publication No. 10-2023-0143410 may be cited. According to this, the method is characterized by comprising: a step of analyzing the ID issuance history recorded in a distributed ID management contract in response to a request for the issuance of a 'distributed ID' from a user to inquire whether there is a distributed ID already issued to the user; a step of issuing a new distributed ID to the user if there is no distributed ID already issued as a result of the inquiry; and a step of updating the ID issuance history by recording the details of the distributed ID issuance in the ID issuance history while registering the issued distributed ID in a distributed ID storage as the new distributed ID delivered to the user is recorded in the user's electronic wallet.

[0004] However, according to the conventional technology described above and other technologies introduced so far, there was no way to replace the VC in a user-friendly manner when a situation arose where the VC needed to be replaced (e.g., upgrade, migration, etc.) due to the development of new technology after the VC was issued.

[0005] For example, most VCs use conventional encryption methods such as RSA (Revest, Shamir, Adleman) or Elliptic Curve Cryptography (ECC), making them vulnerable to security threats arising from the advancement of quantum computers. To address this, users had to manually perform the replacement process to replace existing VCs with VCs that utilize quantum-resistant encryption technology. However, this method was not only time-consuming but also had the problem of potentially hindering the user experience.

[0006] Accordingly, the inventor(s) propose a technology for replacing a VC with a new VC by identifying at least one VC as a VC to be replaced and, in response to the VC to be replaced being verified by an issuer node, issuing a new VC corresponding to the VC to be replaced.

[0007] <Prior Art Literature>

[0008] <Patent Literature>

[0009] (Patent Document 0001) Korean Published Patent Application No. 10-2023-0143410 (October 12, 2023)

[0010] The present invention aims to solve all the problems of the aforementioned prior art.

[0011] In addition, the present invention has another objective of replacing the VC to be replaced with a new VC by identifying at least one VC as the VC to be replaced and, in response to the VC to be replaced being verified by an issuer node, issuing a new VC corresponding to the VC to be replaced.

[0012] In addition, the present invention has another objective of completely eliminating vulnerabilities in existing VCs by replacing the entire VC.

[0013] In addition, another objective of the present invention is to enhance user convenience by allowing the VC to be replaced without user intervention.

[0014] In addition, the present invention has another objective of distributing the system load when replacing the VC.

[0015] In addition, the present invention has another objective of efficiently protecting user information by ensuring that the VC is replaced while varying the replacement strategy according to the replacement priority.

[0016] In addition, another objective of the present invention is to enable the smooth replacement of existing VCs while maintaining compatibility with existing systems.

[0017] A representative configuration of the present invention for achieving the above objective is as follows.

[0018] According to one aspect of the present invention, a method is provided comprising the steps of: identifying at least one VC as a replacement target VC; and replacing the replacement target VC with the new VC by issuing a new VC corresponding to the replacement target VC in response to the replacement target VC being verified by an issuer node.

[0019] According to another aspect of the present invention, a system is provided comprising: a replacement target management unit that specifies at least one VC as a replacement target VC; and a VC replacement unit that replaces the replacement target VC with the new VC by issuing a new VC corresponding to the replacement target VC in response to the replacement target VC being verified by an issuer node.

[0020] In addition to this, other methods for implementing the present invention, other systems, and non-transient computer-readable recording media for recording a computer program for executing said methods are further provided.

[0021] According to the present invention, at least one VC is designated as a VC to be replaced, and in response to the VC to be replaced being verified by an issuer node, a new VC corresponding to the VC to be replaced is issued, thereby enabling the VC to be replaced to be replaced with a new VC.

[0022] In addition, according to the present invention, vulnerabilities of the existing VC can be completely eliminated by replacing the entire VC.

[0023] In addition, according to the present invention, user convenience can be enhanced by allowing the VC to be replaced without user intervention.

[0024] In addition, according to the present invention, the system load can be distributed when replacing the VC.

[0025] In addition, according to the present invention, user information can be efficiently protected by replacing the VC while varying the replacement strategy according to the replacement priority.

[0026] In addition, according to the present invention, it is possible to smoothly replace the existing VC while maintaining compatibility with the existing system.

[0027] FIG. 1 is a diagram showing the schematic configuration of an entire system for replacing a VC according to one embodiment of the present invention.

[0028] FIG. 2 is a drawing illustrating in detail the internal configuration of a holder-side system according to one embodiment of the present invention.

[0029] <Explanation of Symbols>

[0030] 100: Communication network

[0031] 200: Validator-side system

[0032] 300: Holder-side system

[0033] 400: Issuer-side system

[0034] 310: Management Department to be Replaced

[0035] 320: VC Replacement

[0036] 330: Communications Department

[0037] 340: Control unit

[0038] 500: Device

[0039] The following detailed description of the invention refers to the accompanying drawings, which illustrate specific embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention. It should be understood that various embodiments of the invention are different but need not be mutually exclusive. For example, specific shapes, structures, and characteristics described herein may be modified from one embodiment to another without departing from the spirit and scope of the invention. It should also be understood that the location or arrangement of individual components within each embodiment may be modified without departing from the spirit and scope of the invention. Accordingly, the following detailed description is not meant to be limiting, and the scope of the invention should be understood to encompass the scope claimed by the claims and all equivalents thereof. Similar reference numerals in the drawings indicate identical or similar components across various aspects.

[0040] Hereinafter, in order to enable a person skilled in the art to easily practice the present invention, various preferred embodiments of the present invention will be described in detail with reference to the attached drawings.

[0041] Configuration of the entire system

[0042] FIG. 1 is a diagram showing the schematic configuration of an entire system for replacing a VC according to one embodiment of the present invention.

[0043] As illustrated in FIG. 1, the entire system according to one embodiment of the present invention may include a communication network (100), a verifier-side system (200), a holder-side system (300), an issuer-side system (400), and a device (500).

[0044] First, a communication network (100) according to one embodiment of the present invention can be configured regardless of the mode of communication, such as wired communication or wireless communication, and can be configured as various communication networks such as a Local Area Network (LAN), a Metropolitan Area Network (MAN), or a Wide Area Network (WAN). Preferably, the communication network (100) referred to in this specification may be the known Internet or the World Wide Web (WWW). However, the communication network (100) may include at least a known wired / wireless data communication network, a known telephone network, or a known wired / wireless television communication network, without being limited thereto.

[0045] For example, the communication network (100) may be a wireless data communication network and may implement conventional communication methods such as WiFi communication, WiFi-Direct communication, Long Term Evolution (LTE) communication, 5G communication, Bluetooth communication (including Bluetooth Low Energy (BLE) communication), infrared communication, ultrasonic communication, etc., in at least a part thereof. As another example, the communication network (100) may be an optical communication network and may implement conventional communication methods such as Light Fidelity (LiFi), etc., in at least a part thereof.

[0046] Next, a node (not shown) according to one embodiment of the present invention, for example, an issuer node, a holder node, a verifier node, etc., is a contact point or connection point capable of communicating with other nodes through a communication network (100), and may be a concept including a physical node of a server, computer, laptop, smartphone, tablet PC, etc. (i.e., a digital device equipped with memory means and equipped with a microprocessor to have computational capabilities) or a logical node of an application, program module, virtual machine, etc. (i.e., a virtual node).

[0047] Specifically, according to one embodiment of the present invention, a node may be a digital wallet itself or a concept that includes a digital wallet. A digital wallet refers to a software or hardware device that allows a user to securely store and manage digital assets, authentication information, identity information, etc., and means of storing various data and enabling the use of the stored data as needed. For example, an issuer node, a holder node, and a validator node may each refer to a digital wallet owned by the issuer, holder, and validator, or a digital wallet running on the devices of the issuer, holder, and validator.

[0048] According to one embodiment of the present invention, these nodes may refer to each node that is associated with one another to form a distributed ledger network. According to one embodiment of the present invention, in order to support the use of credentials based on Distributed Ledger Technology (DLT), these nodes may include a validator-side system (200), a holder-side system (300), and / or an issuer-side system (400), which will be described later, in the form of program modules such as applications or widgets. Additionally, such program modules may be downloaded from an external application distribution server (not shown) or an external system (not shown), etc.

[0049] Here, according to one embodiment of the present invention, a distributed ledger may refer to a method of storing and managing data in a distributed manner across multiple nodes without centralized authority while maintaining data integrity and security. Specifically, the distributed ledger described above includes, but is not limited to, a blockchain, a tangle, a hashgraph, a directed acyclic graph (DAG), etc.

[0050] Specifically, a distributed ledger according to one embodiment of the present invention may be a blockchain (or a blockchain network). The aforementioned blockchain network may be a network capable of ensuring the integrity and reliability of the recorded information without relying on an authorized third party by jointly verifying information to be stored on the network by a plurality of nodes participating in the network, and recording and sharing the verified information on the network. For example, according to one embodiment of the present invention, such a blockchain network may be a network that is similar in at least some of its characteristics to those of conventional blockchain networks such as Bitcoin, Ethereum, and Quantum. Furthermore, according to one embodiment of the present invention, such a blockchain network may be a concept that includes various types of blockchain networks, such as a private blockchain network, a public blockchain network, or a hybrid network of a private blockchain and a public blockchain.

[0051] Meanwhile, according to one embodiment of the present invention, the fact that each node may be associated with the aforementioned nodes to form a distributed ledger network is merely an example and is not limited thereto. That is, a node according to one embodiment of the present invention may refer to any kind of reliable storage means that acts as a participant in verifying and storing data and exchanging information with other nodes to maintain the integrity and consistency of the entire system.

[0052] Next, a verifier-side system (200) according to one embodiment of the present invention can perform a function of verifying the credentials based on information regarding credentials provided by a holder node.

[0053] According to one embodiment of the present invention, the validator-side system (200) may mean a system that includes a validator node or is included in a validator node, and may mean the validator node itself.

[0054] Next, a holder-side system (300) according to one embodiment of the present invention can perform the function of proving its own qualifications by receiving credentials from an issuer node (400) and presenting information regarding them to a verifier node.

[0055] According to one embodiment of the present invention, the holder-side system (300) may refer to a system that includes a holder node or is included in a holder node, or it may refer to the holder node itself. In particular, the holder-side system (300) according to one embodiment of the present invention may be a system that includes a digital wallet or includes a digital wallet, or it may be a separate system capable of linking with the digital wallet of a holder node. According to one embodiment of the present invention, such a holder-side system (300) may be a system managed by the operator of the digital wallet or a system managed by a third party different from the operator of the digital wallet.

[0056] In addition, a holder-side system (300) according to one embodiment of the present invention may perform the function of replacing a VC with a new VC by identifying at least one VC as a VC to be replaced and, in response to the VC to be replaced being verified by an issuer node, issuing a new VC corresponding to the VC to be replaced.

[0057] The configuration and function of the holder-side system (300) according to the present invention will be examined in detail through the following detailed description.

[0058] Next, the issuer-side system (400) according to one embodiment of the present invention can perform the function of generating credentials and issuing them to a holder node. Generally, the issuer is a trusted institution or organization that has the authority to verify information about an individual or organization and issue credentials that prove it. For example, various institutions such as universities, government agencies, financial institutions, and employers may be such issuers, but are not limited thereto.

[0059] According to one embodiment of the present invention, the issuer-side system (400) may mean a system that includes an issuer node or is included in an issuer node, and may mean the issuer node itself.

[0060] Next, the device (500) according to one embodiment of the present invention is a digital device that includes a function to communicate after connecting to a verifier-side system (200), a holder-side system (300) and / or an issuer-side system (400). Any digital device equipped with memory means and equipped with a microprocessor to have computational capabilities, such as a smartphone, tablet, smart watch, smart band, smart glasses, desktop computer, laptop computer, workstation, PDA, web pad, mobile phone, etc., can be adopted as the device (500) according to the present invention.

[0061] In particular, the device (500) may include an application (not shown) that enables a user to receive services according to the present invention from the validator-side system (200), the holder-side system (300), and / or the issuer-side system (400). Such an application may be downloaded from the validator-side system (200), the holder-side system (300), the issuer-side system (400), and / or an external application distribution server (not shown). Meanwhile, the nature of such an application may generally be similar to the replacement target management unit (310), VC replacement unit (320), communication unit (330), and control unit (340) of the holder-side system (300) as described below. Here, at least a part of the application may be replaced with a hardware device or firmware device capable of performing substantially the same or equivalent functions as needed.

[0062] According to one embodiment of the present invention, such a device (500) may mean one of a plurality of nodes (e.g., issuer node, holder node, validator node, etc.) that are associated with each other to form a distributed ledger network.

[0063] Configuration of the holder-side system

[0064] Below, we will examine the internal configuration of the holder-side system (300) that performs important functions for the implementation of the present invention and the functions of each component.

[0065] FIG. 2 is a drawing illustrating in detail the internal configuration of a holder-side system (300) according to one embodiment of the present invention.

[0066] As illustrated in FIG. 2, a holder-side system (300) according to one embodiment of the present invention may be configured to include a replacement target management unit (310), a VC replacement unit (320), a communication unit (330), and a control unit (340). According to one embodiment of the present invention, the replacement target management unit (310), the VC replacement unit (320), the communication unit (330), and the control unit (340) may be program modules, at least some of which communicate with an external system (not shown). Such program modules may be included in the holder-side system (300) in the form of an operating system, an application program module, or other program modules, and may be physically stored in various known storage devices. Additionally, such program modules may be stored in a remote storage device capable of communicating with the holder-side system (300). Meanwhile, such program modules encompass, but are not limited to, routines, subroutines, programs, objects, components, data structures, etc., that perform specific tasks or execute specific abstract data types as described below according to the present invention.

[0067] Meanwhile, although the holder-side system (300) has been described as above, this description is exemplary, and it is obvious to those skilled in the art that at least some of the components or functions of the holder-side system (300) may be realized within a device (500) or server (not shown) or included within an external system (not shown) as needed.

[0068] First, a replacement target management unit (310) according to one embodiment of the present invention can perform the function of specifying at least one VC as a replacement target VC.

[0069] Specifically, according to one embodiment of the present invention, a holder node may hold at least one VC in a digital wallet, etc., and a replacement target management unit (310) may identify at least one VC among them that requires replacement (e.g., upgrade, migration, etc.) for reasons such as security enhancement as a replacement target VC. To this end, the replacement target management unit (310) according to one embodiment of the present invention may investigate and obtain information regarding the VC held by the holder node, for example, the expiration date of the VC, the issuing entity (issuer node), the policy of the issuing entity, and whether the issuing entity supports the replacement process.

[0070] For example, a replacement target management unit (310) according to one embodiment of the present invention may identify a replacement target VC based on the expiration date of at least one VC. Specifically, for example, the replacement target management unit (310) may identify a VC with a predetermined period remaining until expiration (e.g., a VC with 30 days remaining until expiration, a VC with 1 week remaining, etc.) or a VC whose expiration date has arrived as a replacement target VC. If the issuer node does not support the replacement process (e.g., does not support quantum tolerance), the replacement target management unit (310) may, if necessary, temporarily wrap the existing VC (e.g., quantum tolerance wrapping) until the issuer node supports the replacement process. This method of using the expiration date of the VC has the advantage of allowing the replacement process to proceed in the background while using the existing VC update UI as is.

[0071] As another example, a replacement target management unit (310) according to one embodiment of the present invention may identify the VC requested for presentation by the validator node as a replacement target VC in response to the determination that the VC requested for presentation by the validator node needs to be replaced.

[0072] Specifically, for example, the replacement target management unit (310) according to one embodiment of the present invention can determine whether a VC requested to be presented by a validator node needs to be replaced. For example, if the importance of a transaction is determined to be high, such as when a validator node requests a holder node to present a financial transaction (or high-value transaction) VC, a medical record VC, or a government-issued identification card VC in order to proceed with a transaction, and if replacement (upgrade, migration, etc.) of the VC required to proceed with the transaction (i.e., the VC requested to be presented by the validator node) is possible, the replacement target management unit (310) can determine that the VC needs to be replaced and specify the VC as a replacement target VC. This method of determining whether the VC needs to be replaced immediately before use can be useful when replacing a VC that needs to be used immediately.

[0073] As another example, a replacement target management unit (310) according to one embodiment of the present invention may specify the at least one VC as a replacement target VC in response to a change in the policy of the issuer node for at least one VC.

[0074] Specifically, for example, a replacement target management unit (310) according to one embodiment of the present invention can automatically identify the cryptographic algorithm used in the VC at the time when the holder node receives the VC or thereafter, and manage it as metadata. For example, the replacement target management unit (310) can detect a signature algorithm (RSA, ECDSA, EdDSA, etc.) upon receiving the VC, and verify a hash function (SHA-256, SHA-512, etc.) and a key length (2048, 4096 bits, etc.). Furthermore, based on this information, the replacement target management unit (310) can classify the security level of the VC and tag it in the metadata for storage. The metadata recorded for each VC may have the following format:

[0075] {

[0076] vc_id: "credential_123",

[0077] current_algorithm: "RSA-2048",

[0078] security_level: "medium",

[0079] issuer_supported: ["RSA-2048", "ECDSA-P256", "Dilithium3"],

[0080] recommended: "ECDSA-P256",

[0081] last_check: "2024-11-29",

[0082] replacement_needed: true,

[0083] priority: "high"

[0084] }

[0085] Continuing, the replacement target management unit (310) can periodically query the .well-known endpoint of the issuer node to check the list of cryptographic algorithms supported by the issuer node. Then, the replacement target management unit (310) can identify the VC issued by the issuer node as the replacement target VC when it detects that the security policy has been updated, such as when the recommended cryptographic algorithm is changed, when a deprecation notice for an existing cryptographic algorithm is issued, when there is a CVE (Common Vulnerabilities & Exposures) alert, or when regulatory requirements are changed.

[0086] By doing this, the state of each VC (e.g., encryption state) can be continuously tracked, and the VC can be dynamically replaced in accordance with changes in the issuer node's policy.

[0087] Next, the VC replacement unit (320) according to one embodiment of the present invention can perform the function of replacing the VC to be replaced with a new VC by receiving a new VC corresponding to the VC to be replaced in response to the VC to be replaced being verified by the issuer node.

[0088] Specifically, a VC replacement unit (320) according to one embodiment of the present invention may request the issuance of a new VC corresponding to the VC to be replaced from an issuer node. Then, the issuer node may respond to this request and verify whether the VC to be replaced of the holder node is valid, etc. Then, if the VC to be replaced is verified by the issuer node, the VC replacement unit (320) may receive a new VC corresponding to the VC to be replaced from the issuer node.

[0089] When the VC to be replaced is replaced with the new VC by receiving a new VC corresponding to the VC to be replaced from the issuer node, the VC replacement unit (320) according to one embodiment of the present invention may, if necessary, notify the user (holder node) that the VC has been replaced in a way that optimizes the user experience. For example, the VC replacement unit (320) may notify the user of the fact that the VC is being replaced (or has been replaced) by using expressions such as "identity is being verified," or by using expressions such as "security upgrade completed."

[0090] Additionally, when the VC to be replaced is replaced with a new VC, the VC replacement unit (320) according to one embodiment of the present invention may, if necessary, present the newly issued new VC to the validator node.

[0091] Meanwhile, the VC replacement unit (320) according to one embodiment of the present invention can replace the VC to be replaced at a time when the process of replacing the VC to be replaced can be processed in the background of the user device (500).

[0092] Specifically, the VC replacement unit (320) according to one embodiment of the present invention can determine the timing at which the VC to be replaced is replaced so that the replacement of the VC can be performed without the user being aware of it. For example, the process of replacing the VC to be replaced can be processed in the background of the user device (500) by satisfying conditions such as when the user device (500) is charging and connected to WiFi, when the user device (500) is statistically inactive during sleep time, when there is sufficient spare CPU / memory resources of the user device (500), or when the battery level of the user device (500) is 50% or higher. This method of performing the replacement in the background of the user device (500) can be useful when replacing a VC that has relatively spare capacity.

[0093] At this time, the VC replacement unit (320) according to one embodiment of the present invention may replace (batch process) the VCs to be replaced at the above time in units of a predetermined number, for example, in units of 5 to 10, in order to efficiently use computing resources.

[0094] In addition, when the process of replacing a VC to be replaced is processed in the background of a user device (500), a replacement target management unit (310) according to one embodiment of the present invention can identify a VC to be replaced based on the replacement priority of at least one VC.

[0095] Specifically, a replacement target management unit (310) according to one embodiment of the present invention can identify VCs to be replaced in order of the highest replacement priority of the VCs. According to one embodiment of the present invention, such priority can be determined based on the time remaining until the expiration of each VC, frequency of use, importance score, etc. For example, the replacement target management unit (310) can determine that VCs that are frequently used and have a high importance score are ranked 1st, VCs that are scheduled to expire soon are ranked 2nd, and VCs that are rarely used are ranked 3rd, and create a replacement queue so that VC replacements are replaced according to the determined rankings.

[0096] Meanwhile, the VC replacement unit (320) according to one embodiment of the present invention may issue a subsequent new VC after a predetermined waiting time has elapsed from the time a new VC is issued. For example, the VC replacement unit (320) may distribute the load of the server by issuing a second new VC (i.e., a subsequent new VC) 5 minutes after the time a first new VC is issued.

[0097] On the other hand, according to one embodiment of the present invention, the VC to be replaced can be treated as valid for a predetermined period of time together with the new VC after the new VC is issued. That is, according to one embodiment of the present invention, in order to facilitate a smooth transition from the VC to be replaced to the new VC, even if the new VC is issued, the VC to be replaced is not immediately invalidated, but can be treated as a valid VC together with the new VC for a predetermined period of time.

[0098] On the other hand, the VC replacement unit (320) according to one embodiment of the present invention may issue a new VC in response to the determination that the VC to be replaced is not in a state where replacement is in progress.

[0099] For example, the VC replacement unit (320) can prevent the replacement process from proceeding redundantly by indicating that the VC is being replaced, such as by setting a flag, when the replacement process for the VC to be replaced is in progress. Specifically, for example, the VC replacement unit (320) can prevent the replacement process for the VC from proceeding again by determining that the replacement process can be processed in the background while the replacement for the VC with an imminent expiration date is in progress.

[0100] Next, the communication unit (330) according to one embodiment of the present invention can perform the function of enabling data transmission and reception from / to the replacement target management unit (310) and the VC replacement unit (320).

[0101] Finally, the control unit (340) according to one embodiment of the present invention can perform the function of controlling the flow of data between the replacement target management unit (310), the VC replacement unit (320), and the communication unit (330). That is, the control unit (340) according to one embodiment of the present invention can control the replacement target management unit (310), the VC replacement unit (320), and the communication unit (330) to perform their respective unique functions by controlling the flow of data from / to / from the outside of the holder-side system (300) or the flow of data between each component of the holder-side system (300).

[0102] The embodiments according to the present invention described above may be implemented in the form of program instructions that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, etc., either individually or in combination. The program instructions recorded on the computer-readable recording medium may be those specifically designed and configured for the present invention or those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc. Hardware devices may be modified into one or more software modules to perform processing according to the present invention, and vice versa.

[0103] Although the present invention has been described above with reference to specific details such as specific components, limited embodiments, and drawings, this is provided only to aid in a more comprehensive understanding of the invention, and the invention is not limited to the above embodiments, and a person skilled in the art to which the invention belongs can make various modifications and changes from this description.

[0104] Accordingly, the scope of the present invention should not be limited to the embodiments described above, and all scopes equivalent to or equivalently modified from the claims set forth below, as well as the claims set forth below, shall be considered to fall within the scope of the concept of the present invention.

Claims

1. As a method for replacing a VC (Verifiable Credential), A step of specifying at least one VC as a replacement target VC, and The step of replacing the VC to be replaced with the new VC by issuing a new VC corresponding to the VC to be replaced in response to the verification of the VC to be replaced by the issuer node. method.

2. In Paragraph 1, In the specific step above, identifying the VC to be replaced based on the expiration date of at least one VC. method.

3. In Paragraph 1, In the specific step above, in response to the determination that the VC requested to be presented by the validator node requires replacement, the VC requested to be presented by the validator node is identified as the VC to be replaced. method.

4. In Paragraph 1, In the specific step above, in response to a change in the policy of the issuer node for the at least one VC, the at least one VC is identified as the replacement target VC. method.

5. In Paragraph 1, In the above replacement step, the replacement target VC is replaced at a time when the process regarding the replacement can be processed in the background of the user device. method.

6. In Paragraph 5, At the above point in time, the above replacement target VC is replaced in units of a predetermined number. method.

7. In Paragraph 5, In the specific step above, identifying the VC to be replaced based on the replacement priority of the at least one VC. method.

8. In Paragraph 1, In the above replacement step, a subsequent new VC of the said new VC is issued after a predetermined waiting time has elapsed from the time the said new VC is issued. method.

9. In Paragraph 1, The above-mentioned replacement VC is treated as valid for a predetermined period of time together with the above-mentioned new VC after the issuance of the above-mentioned new VC method.

10. In Paragraph 1, In the above replacement step, in response to the determination that the VC to be replaced is not in a state where replacement is in progress, the new VC is issued. method.

11. A non-transient computer-readable recording medium for recording a computer program for executing the method according to paragraph 1.

12. As a system for replacing a VC (Verifiable Credential), A replacement target management unit that specifies at least one VC as a replacement target VC, and A VC replacement unit comprising, in response to the verification of the VC to be replaced by an issuer node, replacing the VC to be replaced with the new VC by issuing a new VC corresponding to the VC to be replaced. System.

13. In Paragraph 12, The above replacement target management unit identifies the replacement target VC based on the expiration date of the at least one VC. System.

14. In Paragraph 12, The above replacement target management unit, in response to the determination that a VC requested for presentation by a validator node requires replacement, identifies the VC requested for presentation by the validator node as the replacement target VC. System.

15. In Paragraph 12, The above replacement target management unit identifies the at least one VC as the replacement target VC in response to a change in the policy of the issuer node for the at least one VC. System.

16. In Paragraph 12, The above VC replacement unit ensures that the VC to be replaced is replaced at a time when the process regarding the replacement can be processed in the background of the user device. System.

17. In Paragraph 16, The above VC replacement unit ensures that the above-mentioned VC to be replaced is replaced in units of a predetermined number at the above time. method.

18. In Paragraph 16, The above replacement target management unit identifies the replacement target VC based on the replacement priority of the at least one VC. System.

19. In Paragraph 12, The above VC replacement unit is configured to issue a subsequent new VC of the said new VC after a predetermined waiting time has elapsed from the time the said new VC is issued. System.

20. In Paragraph 12, The above-mentioned replacement VC is treated as valid for a predetermined period of time together with the above-mentioned new VC after the issuance of the above-mentioned new VC System.

21. In Paragraph 12, The above VC replacement unit, in response to the determination that the above-mentioned VC to be replaced is not in a state where replacement is in progress, causes the above-mentioned new VC to be issued. System.