Terminal device, information processing method, and information processing program

WO2026168255A1PCT designated stage Publication Date: 2026-08-13FELICA NETWORKS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-01-28
Publication Date
2026-08-13

Smart Images

  • Figure JP2026002846_13082026_PF_FP_ABST
    Figure JP2026002846_13082026_PF_FP_ABST
Patent Text Reader

Abstract

A terminal device according to the present disclosure comprises: an accepting unit that accepts at least one of a selection of a setting of a disclosure rule associated with attribute information included in certification information certifying a qualification of a user and a selection of a setting of a disclosure rule associated with identification information of a business operator; a verifying unit that verifies the identification information of the business operator when the business operator requests the disclosure of the certification information; and a transmitting unit that transmits the attribute information to the business operator on the basis of the verified identification information and at least one of the disclosure rule associated with the attribute information and the disclosure rule associated with the identification information.
Need to check novelty before this filing date? Find Prior Art

Description

Terminal device, information processing method, and information processing program

[0001] The present disclosure relates to a terminal device, an information processing method, and an information processing program.

[0002] Conventionally, a technique for selectively disclosing customer (user) information to a financial service provider (business operator) has been known. For example, in the prior art, the technique of selective disclosure is used to minimize the user information disclosed to the business operator.

[0003] Japanese Patent Application Laid-Open No. 2024-507376

[0004] However, in the above prior art, no specific method has been studied regarding which information of the user is selectively disclosed. For this reason, in the prior art, the user's information is not appropriately disclosed, and the user's information cannot be efficiently presented.

[0005] Therefore, the present disclosure proposes a terminal device, an information processing method, and an information processing program capable of efficiently presenting user information.

[0006] In order to solve the above problems, a terminal device according to one aspect of the present disclosure includes a reception unit that receives at least one of a selection of a setting of a disclosure rule associated with attribute information included in proof information for proving a user's qualification and a selection of a setting of a disclosure rule associated with identification information of a business operator, a verification unit that verifies the identification information of the business operator when the business operator requests disclosure of the proof information, and a transmission unit that transmits attribute information to the business operator based on at least one of the disclosure rule associated with the attribute information and the disclosure rule associated with the identification information, and the verified identification information.

[0007] Figure 1 is a diagram showing an example configuration of an information processing system according to an embodiment. Figure 2 is a diagram showing an overview of the information processing system according to an embodiment. Figure 3 is a diagram showing an example configuration of a business operator terminal and a terminal device according to an embodiment. Figure 4 is a diagram showing an example of a reception screen related to setting disclosure rules. Figure 5 is a diagram showing an example of setting disclosure rules. Figure 6 is a diagram showing an example of setting up the update of certification information. Figure 7 is a diagram showing an example of a use case at a convenience store. Figure 8 is a diagram showing an example of a use case at a convenience store when disclosure rules have not been set. Figure 9 is a diagram showing an example of a use case for entering and leaving a university. Figure 10 is a diagram showing an example of a use case for entering and leaving a university when the business operator terminal has been replaced. Figure 11 is a diagram showing the functions of the wallet on the terminal device and the Verifyer on the business operator terminal. Figure 12 is a flowchart showing an example of a processing procedure when the disclosure rule is linked to identification information. Figure 13 is a flowchart showing an example of a processing procedure when the disclosure rule is linked to attribute information. Figure 14 is a diagram illustrating an overview of a modified example of information processing according to an embodiment. Figure 15 shows a modified example of the functions of a wallet on a terminal device and a verifier on a carrier terminal. Figure 16 is a hardware configuration diagram showing an example of a computer that implements the functions of a terminal device.

[0008] Embodiments of this disclosure will be described in detail below with reference to the drawings. In each of the following embodiments, the same parts will be denoted by the same reference numerals to avoid redundant descriptions.

[0009] This disclosure will be described in the following order of items: 1. Prior Art 2. Embodiments 2-1. Overview of the Information Processing System According to the Embodiment 2-2. Configuration of the Business Operator Terminal and Terminal Device According to the Embodiment 2-3. Information Processing Procedure According to the Embodiment 2-4. Modifications According to the Embodiment 3. Other Embodiments 4. Effects of the Terminal Device According to the Disclosure 5. Hardware Configuration

[0010] (1. Conventional Technology) In recent years, Verifiable Credential (VC) technology, which is becoming increasingly widespread, has been used for identification documents such as national IDs and driver's licenses, as well as certificates of qualifications including academic degrees. VCs are digital certificates that can be managed or owned by each individual using an application called a wallet on their smartphone or in the cloud, and their authenticity can be verified based on information from a trusted third-party organization called a Verifiable Data Register.

[0011] Some Certificate Value Controllers (VCs), such as mDL (mdoc) standardized under ISO / IEC 18013-5 and SD-JWT being standardized by the IETF, have a selective disclosure function for attribute information. This selective disclosure function allows, with the user's consent and selective disclosure instructions, not only to disclose all attribute information contained in a certificate issued by the issuer, but also to partially conceal attribute information contained in the certificate and disclose only a portion of it, depending on the purpose. In addition, verifiers can trust that the certificate was issued by the issuer by looking only at the partially disclosed attribute information.

[0012] On the other hand, selective disclosure features may present challenges in terms of user experience and privacy protection in everyday use cases for verifying personal information. Specifically, when using selective disclosure features for age verification at convenience stores, for example, the user must select and consent to the personal information items to be presented to the cashier each time they are asked to verify their age, making the process cumbersome. Therefore, traditional selective disclosure features may cause problems such as congestion at the cashier. Furthermore, if users become accustomed to the process of selecting, consenting, and presenting information repeatedly, their consent may become meaningless, and they may unintentionally disclose information they did not intend to disclose. In this case, the complexity of the consent process could actually expose users to the risk of personal information leakage, potentially raising privacy concerns.

[0013] Therefore, this disclosure proposes a terminal device that can prevent errors in disclosing attribute information and reduce user operations required to verify personal information by setting the recipient of the attribute information request and the attribute information to be disclosed either in advance or after it has been presented.

[0014] (2. Embodiments) (2-1. Overview of the Information Processing System According to the Embodiment) First, an example of the configuration of the information processing system according to the embodiment will be described using Figure 1. Figure 1 is a diagram showing an example of the configuration of the information processing system according to the embodiment.

[0015] In Figure 1, the information processing system includes a Verifyer CA (Certification Authority) 10 (hereinafter also referred to as VCA 10), a business terminal 50, and a terminal device 100.

[0016] VCA10 is a Certificate Authority that issues authentication information to the Verifier, and may be the issuer of a VC or the provider of a wallet application. For example, VCA10 may be an organization that issues VCs containing personal information such as personal qualification information, such as a public safety commission, the national government, local governments, or educational institutions, or an agency acting on their behalf, or a provider of a wallet application (hereinafter simply referred to as a wallet) that can receive the issued VC. A VC is proof of a user's qualifications or identity, such as a driver's license, student ID, or employee ID. A VC contains multiple pieces of attribute information. Attribute information includes personal information such as name, address, telephone number, photograph, and age, as well as certificate-specific information such as the certificate number and affiliated organization, and indirect personal information such as whether the person is 18 years of age or older.

[0017] The business terminal 50 is a terminal device used by businesses that request the presentation of a VC (Virtual Computer). For example, the business terminal 50 can be any form of information processing device (computer). The business terminal 50 is installed, for example, in convenience stores, supermarkets, and doors for entry and exit. The business terminal 50 may also be a device that connects to the terminal device 100 by communication, etc., and may be a device that is actually or virtually installed as a backend server for a website such as an EC (Electronic Commerce) site or an application on a smartphone, and connected via the internet.

[0018] The business terminal 50 has a Verifyer 51. The Verifyer 51 is a store terminal, smartphone, website, or cloud application. The Verifyer 51 holds a Verifyer digital certificate (hereinafter also simply referred to as a digital certificate) and a Verifyer private key. The digital certificate is information that proves the business that requests the presentation of the VC. The Verifyer private key corresponds to the digital certificate and is used for generating signatures, etc. The digital certificate and Verifyer private key may be fixed ones that are held in advance, or they may be dynamically generated when the presentation of the VC is requested, but the digital certificate used must be signed by the VCA 10 described later.

[0019] Regarding the root certificate of the electronic certificate, for simplicity, it is referred to as VCA10, but if the terminal device 100 and the business terminal 50 are equipped with a mechanism to allow other root certificates, it is not a problem even if it is issued by another VCA, such as a second VCA or a third VCA.

[0020] Terminal device 100 is a terminal operated by the user who is the rights holder of the VC. Any form of information processing device (computer) can be used for terminal device 100. For example, terminal device 100 may be a mobile terminal such as a mobile phone, smart device (smartphone, wearable device, or tablet), PDA (Personal Digital Assistant), notebook PC (Personal Computer), or portable game console.

[0021] The terminal device 100 has a wallet 101. The wallet 101 is an application. For example, the application operates within the terminal device 100, the Web, cloud services, and NFC (Near Field Communication) chips. For example, the wallet 101 holds one or more VCs. The wallet 101 also has at least one disclosure rule linked to attribute information contained in the VC, and at least one disclosure rule linked to the identification information of the business operator requesting the presentation of the VC. The identification information is information that can identify the business operator, for example, an electronic certificate. An overview of the disclosure rules will be described later.

[0022] VCA10 distributes its public key certificate to terminal device 100 (step S1). VCA10 also uses its private key to sign and issue a public key certificate and distribute the public key certificate to the public key corresponding to the Verified private key held by the business terminal 50 (step S2). VCA10 may have already completed the process in step S2 before the business requests a VC, or it may perform the process in step S2 when a VC request is made.

[0023] The operator terminal 50 and the terminal device 100 are connected via a network such as the Internet, or via short-range wireless communication such as NFC, BLE (Bluetooth® Low Energy), Wi-Fi® Aware, or UWB (Ultra Wide Band) (Step S3).

[0024] Next, an overview of the information processing system according to the embodiment will be explained using Figure 2. Figure 2 is a diagram showing an overview of the information processing system according to the embodiment.

[0025] As shown in Figure 2, wallet 101 possesses a VCA certificate as a condition 21 that omits the process of confirming with the user whether or not to disclose attribute information to the business operator. Wallet 101 possesses a VCA certificate issued by VCA 10. For example, the VCA certificate includes VC. Note that wallet 101 may possess multiple VCA certificates issued by different VCAs.

[0026] Furthermore, wallet 101 has disclosure rules as a condition 21 that omits the need to confirm with the user whether or not to disclose attribute information to the business operator. For example, wallet 101 has disclosure rules regarding the VC and the attribute information of the VC for the Verifier's digital certificate.

[0027] For example, as a setting for disclosure rules, wallet 101 may accept settings for each VC's attribute information, allowing the user to select the business operator or service of the business operator to disclose information to, and then choose to "allow disclosure," "deny disclosure," or "confirm whether disclosure is permissible each time."

[0028] For example, Wallet 101 may accept the setting of disclosure rules for businesses that have requested disclosure of VCs. As part of the disclosure rule setting, Wallet 101 may accept settings such as "allow disclosure," "deny disclosure," or "confirm whether disclosure is permissible each time," by selecting the attribute information to be disclosed for each business. Furthermore, Wallet 101 may accept the setting of similar disclosure rules for businesses that have previously provided VCs.

[0029] As a condition 22 for omitting the confirmation from the user regarding the disclosure of attribute information to the business operator, Verifyer 51 possesses a Verifyer digital certificate and a Verifyer private key. Verifyer 51 possesses a Verifyer digital certificate issued by VCA 10. Furthermore, Verifyer 51 possesses a Verifyer private key corresponding to the Verifyer digital certificate.

[0030] Next, the following explanation describes an example in which a business operator requests attribute information from a user, such as whether the user is 20 years of age or older. First, the verifier 51 and the wallet 101 establish communication via a network or short-range wireless communication (step S11).

[0031] Verifier 51 initiates a credential request (step S12). For example, a credential request is a request for disclosure of attribute information included in the VC. Verifier 51 generates a credential request that includes a request for attribute information (step S13). For example, Verifier 51 generates a credential request that includes "whether the person is 20 years of age or older" as attribute information.

[0032] Verifier 51 generates a signature in response to the credential request using the Verifier private key corresponding to the Verifier digital certificate (step S14). When generating a signature with the Verifier private key, Verifier 51 may bind the signature information to a specific communication, including values ​​agreed upon with the wallet, such as the connection information used in step S11, in order to prevent the individually generated signature information from being reused by a third party. Verifier 51 sends the Verifier digital certificate, the generated credential request, and the generated signature to the wallet 101 (step S15).

[0033] Wallet 101 verifies the Verifier digital certificate of the business operator (Verifier 51). For example, Wallet 101 verifies the Verifier digital certificate using the Verifier CA certificate (step S16). Wallet 101 verifies the signature using the public key contained in the Verifier digital certificate (step S17).

[0034] Wallet 101 selects the VCs and their attribute information to disclose based on the disclosure rules, from the attribute information requests included in the credential request (step S18). For example, Wallet 101 selects the VCs and their attribute information that include the attribute information "whether the person is 20 years of age or older".

[0035] If the disclosure of attribute information included in the credential request is permitted by the disclosure rules, the wallet 101 generates a VC containing the requested attribute information and a credential response containing that attribute information (step S19).

[0036] Specifically, if the disclosure rules allow disclosure of the attribute information "age 20 or older" and the VC containing that attribute information, wallet 101 generates a credential response that includes the VC containing the requested attribute information.

[0037] On the other hand, if the attribute information "age 20 or older" or the disclosure of a VC containing that attribute information is set to "disclosure not permitted" by the disclosure rules, wallet 101 will not provide the attribute information requested by the business operator (Verifier 51) and therefore will not generate a credential response.

[0038] If the attribute information "age 20 or older" or the VC containing that attribute information and the disclosure of that attribute information are required by the disclosure rules to "confirm on a case-by-case basis," the wallet 101 displays it on the terminal device 100 and confirms with the user whether or not to present the relevant attribute information. If, as a result of the user's confirmation, the wallet 101 is permitted to present it to the business operator (Verifier), it generates a credential response that includes the attribute information "age 20 or older."

[0039] The wallet 101 sends the generated credential response to the verifier 51 (step S20). The verifier 51 obtains attribute information by verifying the sent credential response (step S21).

[0040] Thus, in this disclosure, by setting disclosure rules that define which attribute information is permitted to be disclosed and which businesses are permitted to disclose it, it is possible to suppress the disclosure of personal information against the user's will while reducing the user's actions involved in the disclosure of attribute information. Therefore, the terminal device 100 in this disclosure can efficiently present user information.

[0041] (2-2. Configuration of the Operator Terminal and the Terminal Device According to the Embodiment) Next, the configurations of the operator terminal 50 and the terminal device 100 according to the embodiment will be described with reference to FIG. 3. FIG. 3 is a diagram showing a configuration example of the operator terminal 50 and the terminal device 100 according to the embodiment.

[0042] As shown in FIG. 3, the operator terminal 50 includes a communication unit 60, a storage unit 70, and a control unit 80.

[0043] The communication unit 60 is realized, for example, by a NIC (Network Interface Card) or the like. The communication unit 110 is connected to a network (Internet, NFC, Bluetooth, etc.) either wired or wirelessly, and transmits and receives information to and from the terminal device 100 via the network.

[0044] The storage unit 70 is realized, for example, by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. When storing the Verifier private key, it is securely realized by using tamper-resistant hardware such as an HSM (Hardware Security Module) or an SE (Secure Element), or a software security-protected area such as a TEE (Trusted Execution Environment).

[0045] The control unit 80 is realized, for example, when a program stored inside the operator terminal 50 is executed using a RAM or the like as a work area by a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or the like. Also, the control unit 80 is a controller, and may be realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0046] The control unit 80 includes a receiving unit 81, a generating unit 82, a display control unit 83, and a transmitting unit 84, and realizes or executes the information processing functions and operations described below. The generating unit 82 includes a verification unit 85. The internal configuration of the control unit 80 is not limited to the configuration shown in FIG. 3, and may be any other configuration as long as it can perform the information processing described later.

[0047] The receiving unit 81 receives the attribute information included in the VC from the terminal device 100. For example, the receiving unit 81 receives a credential response.

[0048] The generating unit 82 generates a credential request to request the attribute information included in the VC. For example, the generating unit 82 generates the user's attribute information required by the operator as a credential request. The generating unit 82 generates a signature for the credential request using the Verifier private key corresponding to the Verifier electronic certificate. Note that existing techniques may be used for signature generation. The signature generation may be executed within a security module such as a TEE, SE, HSM, or SIM (Subscriber Identity Module) card that manages the Verifier private key.

[0049] The verification unit 85 verifies the credential response transmitted from the terminal device 100. The display control unit 135 displays the information output by the operator terminal 50. The transmitting unit 84 transmits a credential request to the terminal device 100 to request the attribute information included in the VC.

[0050] Next, the configuration of the terminal device 100 according to the embodiment will be described. As shown in FIG. 3, the terminal device 100 includes a communication unit 110, a storage unit 120, and a control unit 130.

[0051] The communication unit 110 is realized by, for example, a NIC or the like. The communication unit 110 is connected to a network (Internet, NFC, Bluetooth, etc.) by wire or wirelessly, and transmits and receives information to and from the operator terminal 50 via the network.

[0052] The storage unit 120 is implemented by, for example, a semiconductor memory element such as RAM or flash memory, or a storage device such as a hard disk or optical disc. As shown in Figure 3, the storage unit 120 has a VC storage unit 121 and a disclosure rule storage unit 122. For example, the storage unit 120 stores at least one of the following: a disclosure rule setting linked to attribute information, and a disclosure rule setting linked to the identification information of a business operator.

[0053] The VC storage unit 121 stores information related to the VC. Specifically, the VC storage unit 121 stores attribute information, including personal information such as name, address, telephone number, facial photograph, and age. The VC storage unit 121 also stores attribute information, including certificate number, information about the organization to which the person belongs, and indirect personal information.

[0054] The disclosure rule storage unit 122 stores the configured disclosure rules. For example, the disclosure rule storage unit 122 stores at least one of the following: a disclosure rule linked to attribute information, and a disclosure rule linked to the identification information of the business operator.

[0055] The control unit 130 is implemented, for example, by a CPU or MPU, which executes a program (for example, the information processing program according to this disclosure) stored inside the terminal device 100 using RAM or the like as a working area. The control unit 130 is also a controller and may be implemented, for example, by an integrated circuit such as an ASIC or FPGA.

[0056] The control unit 130 includes a receiving unit 131, a receiving unit 132, a generation unit 133, a transmission unit 134, and a display control unit 135, and realizes or executes the information processing functions and operations described below. The generation unit 133 also includes a verification unit 136. Note that the internal configuration of the control unit 130 is not limited to the configuration shown in Figure 3, and other configurations are also acceptable as long as they perform the information processing described later.

[0057] The reception unit 131 accepts at least one of the following: the selection of a disclosure rule to be linked to attribute information included in the certification information that proves the user's qualifications, and the selection of a disclosure rule to be linked to the identification information of the business operator. The certification information that proves the user's qualifications is, for example, a VC. The storage unit 120 stores at least one of the selected disclosure rule settings linked to the attribute information and the selected disclosure rule settings linked to the identification information of the business operator.

[0058] The reception unit 131 may accept requests from parties other than the user to set disclosure rules for user VCs. For example, the reception unit 131 may accept requests from the issuer of the VC or the user's guardian to set disclosure rules for user VCs. Identification information is information that can identify a business operator. For example, identification information is an electronic certificate, MAC authentication attached to a credential request command, or a VC issued to a verifier. Identification information may include the business operator's name, service information, and information about the issuer of the identification information. In addition, electronic certificates and VCs may contain different information for each business operator and service.

[0059] The reception unit 131 may accept the setting of disclosure rules at any time. For example, the reception unit 131 may accept the setting of disclosure rules when it first presents attribute information included in the certification information to a business operator. The reception unit 131 may also accept the setting of disclosure rules for business operators to whom attribute information has been presented in the past, based on the history of past attribute information presentations. The reception unit 131 may also accept the setting of disclosure rules for services that are frequently presented, based on the history of past attribute information presentations. The reception unit 131 may also accept the setting of disclosure rules for business operators that are pre-configured in the wallet.

[0060] For example, the reception unit 131 accepts settings for disclosure rules linked to attribute information, such as which businesses are permitted to disclose information, which businesses are refused disclosure, and which businesses will verify the disclosure, for each piece of attribute information. Specifically, the reception unit 131 accepts settings for which businesses are permitted to disclose names, which businesses are refused disclosure, and which businesses will verify the disclosure of names. Similarly, the reception unit 131 may accept settings for disclosure rules for multiple pieces of attribute information, such as facial photographs and addresses. Note that verification of disclosure means, for example, obtaining the user's consent to disclosure before disclosing the information to a business.

[0061] For example, the reception unit 131 accepts settings for disclosure rules linked to attribute information, such as which services of businesses are permitted to disclose information, which services of businesses are denied disclosure, and which services of businesses will verify the disclosure, for each piece of attribute information. A business's services refer to the businesses that a business operates, such as financial services or e-commerce services. Specifically, the reception unit 131 accepts settings for which services of businesses are permitted to disclose names, which services of businesses are denied disclosure, and which services of businesses will verify the disclosure of names. For example, the reception unit 131 accepts a request to permit the disclosure of names for Company A's financial services, but to deny the disclosure of names for Company A's e-commerce services. Similarly, the reception unit 131 may accept settings for disclosure rules for multiple pieces of attribute information, such as facial photographs and addresses.

[0062] For example, the reception unit 131 accepts the setting of attribute information to be permitted for disclosure, attribute information to be refused for disclosure, and attribute information to be confirmed for disclosure, as disclosure rules linked to the identification information, for each business operator's identification information. For example, the reception unit 131 accepts the setting of disclosure rules for attribute information that includes at least one of the following: the user's name, address, telephone number, facial photograph, age, and information from a certificate. The reception unit 131 may also accept the setting of disclosure rules for attribute information in an indirect form, such as "the user is 18 years of age or older." In addition, the reception unit 131 accepts the setting of disclosure rules for certificate information such as the certificate number and affiliated organization, as unique information of certificates such as a driver's license that proves the user's qualifications or identity. Specifically, the reception unit 131 accepts the setting of whether or not to disclose attribute information for each business operator indicated by the identification information. For example, the reception unit 131 accepts the setting to disclose the name, address, and facial photograph to company A. The reception unit 131 also accepts the setting not to disclose the name to company B.

[0063] Figure 4 shows an example of a reception screen for setting disclosure rules. As shown in Figure 4, the reception unit 131 accepts the setting of disclosure rules for the business operator "A-mart" from the disclosure rule setting screen 401. The setting screen consists of items 402 for which disclosure is permitted for "A-mart", an expiration date 403 for the disclosure rules, and a limit on the number of disclosures 404.

[0064] Reception Department 131 receives the items 402 that "A-mart" is permitted to disclose from the attribute information included in the VC. Reception Department 131 accepts whether or not to permit disclosure of attribute information such as name, address, telephone number, and whether the person is 20 years of age or older. Reception Department 131 accepts requests not to disclose the name and telephone number. Reception Department 131 accepts requests to confirm disclosure of the address. Reception Department 131 accepts requests to permit disclosure regarding whether the person is 20 years of age or older.

[0065] Furthermore, the reception unit 131 accepts April 30, 2024, as the expiration date 403 for the disclosure rules. The reception unit 131 accepts an unlimited number of disclosure requests as the limit 404.

[0066] Figure 5 shows an example of setting disclosure rules. As shown in Figure 5, the reception unit 131 accepts the setting of disclosure rules for business operators α and β regarding the VC and the attribute information 501 of the VC, name, address, and facial photograph of the driver's license. The disclosure rule storage unit 122 stores the disclosure rule settings as shown in Figure 5.

[0067] Specifically, the reception unit 131 accepts the setting of disclosure rules for multiple electronic certificates included in each of business operator α's financial services, e-commerce services, and access control services, as identification information 502 of business operator α. The reception unit 131 also accepts the setting of disclosure rules for multiple electronic certificates included in each of business operator β's financial services, e-commerce services, and access control services, as identification information 503 of business operator β.

[0068] As shown in Figure 5, for example, the reception unit 131 accepts the name as available for presentation (disclosure) to business operator α. The reception unit 131 also accepts the facial photograph as available for presentation (disclosure) to business operator β's electronic certificate 25.

[0069] For example, the reception unit 131 accepts the setting of the period during which attribute information can be disclosed as a disclosure rule. Specifically, the reception unit 131 may accept any period from the user as the setting of the period during which disclosure is possible, or it may accept any period as a default setting, etc.

[0070] For example, the reception unit 131 accepts the setting of the number of times attribute information can be disclosed as a disclosure rule. Specifically, the reception unit 131 may accept settings of unlimited or any number of times as the number of times disclosure is permitted.

[0071] For example, the reception unit 131 accepts settings for updating certification information. Specifically, the reception unit 131 accepts settings for automatically updating the expiration date of the certification information.

[0072] The receiving unit 132 receives a credential request from the carrier terminal 50. For example, the receiving unit 132 receives the type of attribute information requested by the carrier from the carrier terminal 50 as a credential request. Specifically, the receiving unit 132 receives a request for the user's address as a credential request.

[0073] The receiving unit 132 receives VCs from the issuer of the VC. The receiving unit 132 may receive multiple VCs.

[0074] The generation unit 133 generates a credential response. For example, the generation unit 133 generates user attribute information requested by the business operator as a credential request as a credential response.

[0075] Specifically, if the attribute information requested by the business operator is a disclosure rule set by the reception unit 131 and is attribute information that permits disclosure, the generation unit 133 generates attribute information of the user who permits disclosure as a credential response. Note that if the generation unit 133 stores multiple VCs and the attribute information contained in those VCs, and multiple VCs permit the disclosure of the attribute information requested by the business operator, the generation unit 133 may disclose the attribute information contained in any of the VCs.

[0076] The verification unit 136 verifies the identification information of a business operator when the business operator requests disclosure of certification information. For example, the verification unit 136 verifies the identification information including the business operator's name and the business operator's services. For example, the verification unit 136 verifies the electronic certificate that identifies the business operator using a VCA certificate. Specifically, when the verifier 51 requests a VC from the wallet 101, the verification unit 136 verifies the authentication information of the business operator by using a function that notifies the wallet 101 of the authentication information, which is the business operator's identification information. The verification unit 136 first verifies the notified electronic certificate using a VCA certificate, and then verifies the signature using the public key contained in the electronic certificate. The verification unit 136 verifies the legitimacy of the business operator by having the wallet 101 verify the signature using a function called "Reader Authentication" of mdoc as standardized in ISO / IEC 18013-5.

[0077] For example, the verification unit 136 verifies whether the user is indeed the user in question. Specifically, the verification unit 136 verifies whether the user is the user in question as a confirmation before disclosing attribute information to the business operator. For example, the verification unit 136 verifies whether the user is the user in question using password authentication or pattern authentication based on knowledge authentication, or fingerprint authentication based on biometric authentication.

[0078] The transmitting unit 134 transmits attribute information to the business operator based on at least one of the disclosure rules associated with attribute information and the identification information, and the verified identification information. For example, if the attribute information that the transmitting unit 134 permits the business operator to disclose includes attribute information that the business operator requests to be disclosed, the transmitting unit 134 transmits the attribute information that permits disclosure to the business operator if the attribute information that the business operator requests to be disclosed is included in the attribute information that permits disclosure under the disclosure rules that the receiving unit 131 has accepted. For example, the transmitting unit 134 transmits the attribute information to the business operator terminal 50 as a credential response.

[0079] The transmitting unit 134 transmits to the issuer that it has received a request to update the certification information and that it possesses the certification information, based on a request from the issuer that issues certification information such as a VC. For example, in order to extend the validity period of the certification information, the transmitting unit 134 transmits to the issuer that it has received a request to update the certification information and that it possesses the certification information.

[0080] Figure 6 shows an example of the settings for updating certification information. As shown in Figure 6, the reception unit 131 accepts the prior settings for updating certification information. The reception unit 131 accepts the VC to be updated and the user's identity from a screen 601 that displays the VC to be updated for automatic renewal and a screen 602 that confirms the user's identity. The attribute information included in the VC to be automatically updated is sent to the issuer of the VC to be automatically updated.

[0081] The receiving unit 132 (terminal device 100 in the figure) receives a request to present the VC from the VC issuer 603 when the expiration date of the VC to be renewed is approaching. For example, if the expiration date of the VC is April 30, 2024, the receiving unit 132 will receive the request on April 29, 2024. The transmitting unit 134 (terminal device 100 in the figure), if the above-mentioned prior settings for updating the certification information have been made, transmits the VC to the VC issuer 603 to prove that it possesses the VC.

[0082] The display control unit 135, described later, displays the VC 604 that has been reissued by the VC issuer 603. Specifically, the display control unit 135 displays the VC with an updated expiration date.

[0083] If the display control unit 135 cannot verify the identification information of the business operator, it displays that the identification information could not be verified. For example, if the display control unit 135 cannot verify the identification information of the business operator, it displays that the business operator is unknown.

[0084] The display control unit 135 displays information output by the terminal device 100. For example, the display control unit 135 displays a screen that accepts the user's selection of disclosure rule settings. It also displays a screen for authenticating the user's identity.

[0085] Next, we will explain the use cases in this disclosure using Figures 7 to 10. Figure 7 is a diagram showing an example of a use case at a convenience store. As shown in Figure 7, the reception unit 131 receives the setting of disclosure rules from the disclosure rule setting screen 801 of the convenience store operator "A-mart". The reception unit 131 receives the request to disclose to "A-mart" the attribute information of VC (VC_1 in the diagram), which is "20 years of age or older".

[0086] Next, the receiving unit 132 receives a request from the "A-mart" operator terminal 50A to verify the user's age, specifically whether they are "20 years of age or older." The operator terminal 50A and the terminal device 100 are connected via a network, enabling communication between them.

[0087] The generation unit 133 generates information including the fact that the user is "20 years of age or older," which is attribute information that is permitted to be disclosed to "A-mart," for transmission to the "A-mart" business terminal 50A. Subsequently, the reception unit 131 accepts user authentication from the user authentication screen 802 to confirm that the user is the actual user. If user authentication is successful, the transmission unit 134 transmits information including that the user is "20 years of age or older" to A-mart. Upon receiving the information including that the user is "20 years of age or older," the A-mart business terminal 50A, for example, authorizes the purchase of alcoholic beverages.

[0088] Figure 8 shows an example of a use case at a convenience store when no disclosure rules have been set. As shown in Figure 8, the receiving unit 132 receives an age verification request from the A-mart operator terminal 50A to confirm whether the user is "20 years of age or older". The operator terminal 50A and the terminal device 100 are connected via a network so that they can communicate with each other.

[0089] The reception unit 131 accepts the setting of disclosure rules from the disclosure rule setting screen 901 of the convenience store "A-mart". The reception unit 131 accepts attribute information that permits disclosure from the attribute information of VC (VC_1 in the diagram).

[0090] The generation unit 133 generates information including that the user is "20 years of age or older" if the user has given permission to "A-mart" to disclose that the user is "20 years of age or older". Subsequently, the reception unit 131 accepts user authentication from the user authentication screen 902 to confirm that the user is the user. If user authentication is successful, the transmission unit 134 transmits information including that the user is "20 years of age or older" to A-mart. Upon receiving the information including that the user is "20 years of age or older", A-mart's business terminal 50A authorizes, for example, the purchase of alcoholic beverages.

[0091] Furthermore, the UI (User Interface) for setting disclosure rules may include, for example, the ability to copy rules set in "A-mart" and use them as disclosure rules in other convenience stores such as "B-mart". The UI for setting disclosure rules may also include a function to select and delete multiple set rules simultaneously.

[0092] Figure 9 shows an example of a use case for entry and exit at a university. As shown in Figure 9, the reception unit 131 receives the setting of disclosure rules from the disclosure rule setting screen 1001 of the university "A-Univ.", which is the service provider. The reception unit 131 receives the request to disclose the attribute information of VC (VC_1 in the figure), namely "Department," to "A-Univ.".

[0093] Next, the receiving unit 132 receives a request for "subject" information from the operator terminal 50B installed on the door 1011 of "A-Univ.". The operator terminal 50B and the terminal device 100 are connected via a network so that they can communicate with each other.

[0094] The generation unit 133 generates information including "department" information, which is attribute information that is permitted to be disclosed to "A-Univ.", for transmission to the business terminal 50B of "A-Univ.". Subsequently, the transmission unit 134 transmits the information including "department" information to the business terminal 50B of "A-Univ.". Upon receiving the information including "department" information, the business terminal 50B of "A-Univ." opens the door 1011. The display control unit 135 also displays a screen 1002 to the user indicating that the attribute information has been transmitted.

[0095] Figure 10 shows an example of a use case for entry and exit at a university in the event that the operator's terminal has been swapped. Similar to Figure 9, the reception unit 131 accepts the setting of disclosure rules from the disclosure rule setting screen 1101 of the operator, the university "A-Univ.". The reception unit 131 accepts the disclosure of the attribute information of the VC (VC_1 in the figure), namely "Department," to "A-Univ.".

[0096] Next, the receiving unit 132 receives a request for "subject" information from the operator terminal 50C installed in the door 1111 of "A-Univ.". The operator terminal 50C and the terminal device 100 are connected via a network so that they can communicate with each other.

[0097] The verification unit 136 verifies that the request originates from a carrier terminal that does not have authentication information, because the carrier terminal has been replaced. The carrier terminal may be, for example, an IC card reader that can communicate with terminal device 100. The display control unit 135 displays to the user on screen 1102 that the carrier's authentication failed, saying, "Authentication failed. Do you want to disclose your information?" The display control unit 135 may also use a combination of on-screen animations such as pop-ups and warning sounds to attract the user's attention.

[0098] Next, the following explanation will describe the case where the functions performed by the terminal device 100 and the business terminal 50 described above are performed by the application wallet 101 and the application Verifyer 51. Note that the internal configuration of wallet 101 and Verifyer 51 is not limited to the configuration shown in Figure 11.

[0099] Figure 11 shows the functions of the wallet 101 of the terminal device 100 and the Verifyer 51 of the carrier terminal 50. For example, the wallet 101 and Verifyer 51 are applications. As shown in Figure 11, the wallet 101 has a communication unit 110A, a VC storage unit 120A, a screen display unit 130A, and a presented VC generation unit 130B. For example, the VC storage unit 120A stores a VC that includes attribute information. Note that the internal configuration of the wallet 101 and Verifyer 51 is not limited to the configuration shown in Figure 11.

[0100] The presentation VC generation unit 130B has a selective disclosure function, a disclosure rule storage function, a verifier authentication function, and a user authentication function. For example, the selective disclosure function refers to a function related to the disclosure of attribute information and the setting of disclosure rules. The disclosure rule storage function refers to a function that stores the settings of disclosure rules. The verifier authentication function refers to a function related to authentication to a business operator performed by the terminal device 100. The user authentication function refers to a function related to authentication of whether the user is the real person.

[0101] For example, the functions performed by the wallet 101 are realized by the various configurations of the terminal device 100 shown in Figure 3. For example, the functions performed by the screen display unit 130A are realized by the display control unit 135 of the terminal device 100 shown in Figure 3. Also, the functions performed by the communication unit 110A are realized by the communication unit 110 of the terminal device 100 shown in Figure 3. The functions performed by the VC storage unit 120A are realized by the VC storage unit 121 of the terminal device 100 shown in Figure 3.

[0102] For example, the selective disclosure function, the verifier authentication function, and the user authentication function performed by the presentation VC generation unit 130B are implemented by the reception unit 131, the receiving unit 132, the generation unit 133, the transmission unit 134, and the verification unit 136 of the terminal device 100 shown in Figure 3. The disclosure rule storage function performed by the presentation VC generation unit 130B is implemented by the disclosure rule storage unit 122 of the terminal device 100 shown in Figure 3.

[0103] The Verified 51 includes a communication unit 60A, an image display unit 80A, a VC request generation unit 80B, and a VC verification unit 80C. The VC request generation unit 80B has a VC request function and a Verified authentication generation function.

[0104] For example, the VC request function refers to the function related to credential requests. The Verifyer authentication function refers to the function related to the generation of signatures, etc.

[0105] For example, the functions performed by the Verifyer 51 are realized by the various configurations of the carrier terminal 50 shown in Figure 3. For example, the functions performed by the communication unit 60A are realized by the communication unit 60 of the carrier terminal 50 shown in Figure 3. The image display unit 80A, the VC request generation unit 80B, and the VC verification unit 80C are realized by the receiving unit 81, generation unit 82, display control unit 83, transmission unit 84, and verification unit 85 of the carrier terminal 50 shown in Figure 3.

[0106] (2-3. Information Processing Procedure According to an Embodiment) Next, the processing flow of the terminal device 100 will be explained using Figures 12 and 13. Figure 12 is a flowchart showing an example of a processing procedure when the disclosure rule is linked to identification information.

[0107] As shown in Figure 12, the receiving unit 132 of the terminal device 100 determines whether it has received the credential request, signature, and digital certificate (step S101). The receiving unit 132 repeats the process in step S101 until it has received the credential request, signature, and digital certificate (step S101: No).

[0108] If the verification unit 136 receives a credential request, signature, and digital certificate (step S101: Yes), it determines whether it was able to verify the digital certificate using the VCA certificate (step S102). If the display control unit 135 cannot verify the digital certificate (step S102: No), it executes the process from step S107.

[0109] If the verification unit 136 can verify the digital certificate (step S102: Yes), it determines whether the signature can be verified using the public key included in the digital certificate (step S103). If the display control unit 135 cannot verify the signature (step S103: No), it executes the process from step S107.

[0110] If the signature can be verified (step S103: Yes), the generation unit 133 determines whether there is a disclosure rule corresponding to the thumbprint of the digital certificate (step S104). The thumbprint is the encrypted information of the digital certificate and is a unique value for each digital certificate used to determine whether the digital certificate is a previously accepted certificate, etc.

[0111] If there is no disclosure rule corresponding to the thumbprint (step S104: No), the display control unit 135 executes the processing from step S107. If there is a disclosure rule corresponding to the thumbprint (step S104: Yes), the generation unit 133 selects one of the requested credential attribute information to generate attribute information to send to the business terminal 50 (step S105).

[0112] Next, the generation unit 133 determines whether the selected attribute information is set to "Confirm whether disclosure is permitted" or whether there is no setting for the selected attribute information (step S106). If the selected attribute information is set to "Confirm whether disclosure is permitted" or if there is no setting for the selected attribute information (step S106: No), the generation unit 133 determines whether the selected attribute information is set to "Not disclosable" (step S111).

[0113] If the selected information is set to "Not Disclosable" (Step S111: Yes), the generation unit 133 sets the selected attribute information to "Not Disclosable" (Step S112) in order to generate attribute information to be transmitted to the business terminal 50.

[0114] On the other hand, if the selected attribute information is not set to "not disclosable" (step S111: No), the generation unit 133 sets the selected attribute information to "disclosable" in order to generate attribute information to be transmitted to the business terminal 50 (step S113).

[0115] After the processing in step S112 or step S113 is executed, the processing from step S109 onwards is executed.

[0116] The display control unit 135 executes the process from step S107 if the selected attribute information is set to "Confirm whether disclosure is permitted" or if it is set for the selected attribute information (step S106: Yes).

[0117] The display control unit 135 displays all attribute information of the requested credentials to the user (step S107). Subsequently, the reception unit 131 determines whether it has received a request to disclose all attribute information of the requested credentials (step S108).

[0118] If the generation unit 133 has not received confirmation that all attribute information of the requested credentials can be disclosed (step S108: No), it repeats the process from step S105.

[0119] If the generation unit 133 receives a response regarding whether all attribute information of the requested credentials can be disclosed (step S108: Yes), it determines whether the requested credentials are "disclosable" (step S109).

[0120] If the requested credentials are not "disclosable" (step S109: No), the transmitting unit 134 terminates processing without sending a credential response to the carrier terminal 50. In other words, if the requested credentials are "not disclosable", the transmitting unit 134 terminates processing without sending a credential response to the carrier terminal 50.

[0121] If the requested credentials are "disclosable" (step S109: Yes), the transmission unit 134 transmits a credential response containing the disclosable attribute information to the carrier terminal 50 (step S110).

[0122] Furthermore, the display control unit 135 may display a screen to accept the setting of disclosure rules for the next time after sending the credential response to the business terminal (after step S110). In this way, the display control unit 135 can display the dialog for setting disclosure rules at a clear, convenient, and memorable time, as it is linked to the previous presentation action to determine which verifier to set disclosure rules for.

[0123] Here, we will explain in detail how to set up disclosure rules for future transactions. For future transactions, if a user indicates their intention to skip consent through a specific action, they may be automatically registered for the disclosure rules from then on.

[0124] For example, the reception unit 131 may prepare a message that says, "Next time, skip 'user consent' for the recipient of this presentation," so that it will be automatically registered as a disclosure rule from the next time onward, and accept input via the checkbox. Alternatively, the reception unit 131 may accept the setting of the disclosure rule for the next time onward by having the user read the QR code (registered trademark) displayed by the business operator terminal 50 while clicking a physical button such as the volume button on the terminal device 100, or by holding the device over the NFC reader of the business operator terminal 50.

[0125] Furthermore, the setting of disclosure rules for subsequent visits may be represented by software rather than a physical button. For example, the reception unit 131 may display an image such as a "fingerprint" on the mobile phone screen, and the user can indicate that they have permitted to skip consent from the next visit by placing their actual finger over the fingerprint image. Also, in the above example, the disclosure rules may be automatically set retrospectively based solely on the user's actions, without the need for a dialog box.

[0126] Next, we will explain an example of a case where disclosure rules are linked to attribute information. Figure 13 is a flowchart showing an example of a processing procedure when disclosure rules are linked to attribute information.

[0127] The processes from steps S101 to S103 in Figure 13 are the same as those in Figure 12, so their explanation will be omitted. If the generation unit 133 can verify the signature with the public key included in the electronic certificate (step S103: Yes), it selects one of the requested credential attribute information to generate attribute information to send to the business terminal 50 (step S204).

[0128] Next, the generation unit 133 determines whether there is a disclosure rule corresponding to the selected attribute information (step S205). If there is no disclosure rule corresponding to the selected attribute information (step S205: No), the display control unit 135 executes the processing from step S107.

[0129] If the generation unit 133 has a disclosure rule corresponding to the selected attribute information (step S205: Yes), it determines whether the electronic certificate is set to "confirm whether disclosure is permitted" or whether there is no setting for the selected electronic certificate (step S206).

[0130] The generation unit 133 determines whether the electronic certificate is set to "confirm whether disclosure is permitted" or, if there is no setting for the selected electronic certificate (step S206: No), whether the electronic certificate is set to "disclosure not permitted" (step S211).

[0131] If the electronic certificate is set to "Not Disclosable" (step S211: Yes), the generation unit 133 sets the selected attribute information to "Not Disclosable" (step S112), similar to step S112 in Figure 12. Note that the processing from step S112 onwards is the same as the processing from step S112 onwards in Figure 12, so the explanation is omitted.

[0132] If the electronic certificate is not set to "not disclosable" (step S211: No), the generation unit 133 sets the selected attribute information to "disclosable" (step S113), similar to step S113 in Figure 12. Note that the processing from step S113 onwards is the same as the processing from step S112 onwards in Figure 12, so the explanation is omitted.

[0133] On the other hand, if the display control unit 135 is set to "confirm whether disclosure is permitted" or if there is no setting for the selected electronic certificate (step S206: Yes), it performs the same processing as in step S107 in Figure 12. Note that the processing from step S107 onwards is the same as the processing from step S107 onwards in Figure 12, so the explanation is omitted.

[0134] (2-4. Modifications of the Embodiment) The information processing according to the embodiment described above may be modified in various ways. Modifications of the embodiment will be described below.

[0135] Figure 14 is a diagram illustrating an overview of a modified example of the information processing according to the embodiment. In the following description, explanations that overlap with those in Figure 1 will be omitted. As shown in Figure 14, the processing that was performed in the wallet 101 of the terminal device 100 may also be performed in the wallet manager 103 and the wallet 105. Furthermore, the wallet 105 may be performed in the NFC chip 104.

[0136] The NFC chip 104 has a communication unit, a storage unit, and a control unit. The communication unit is implemented by, for example, a NIC. The communication unit is wirelessly connected to the network and transmits and receives information to and from the operator terminal 50 via the network. The storage unit is implemented by, for example, a semiconductor memory element such as RAM or flash memory, or a storage device such as a hard disk or optical disc. The control unit is implemented by, for example, a CPU or MPU, which executes a program stored inside the terminal device 100 using RAM or the like as a working area. The control unit is also a controller and may be implemented by, for example, an integrated circuit such as an ASIC or FPGA.

[0137] For example, terminal device 100 has a wallet manager 103 for disclosing settings to the NFC chip 104. The wallet manager 103 is, for example, an application. For example, the wallet manager 103 is an application for terminal device 100 equipped with an NFC chip 104 on which the wallet 105 operates.

[0138] The wallet manager 103 may be located in a terminal device other than the terminal device equipped with the NFC chip on which the wallet operates. For example, the wallet manager may be configured to be located in a terminal device such as a smartphone. Also, the NFC chip 104 may be configured to be located in a physical card.

[0139] The wallet manager 103 includes a UI function that displays information necessary for information processing. Furthermore, the wallet manager 103 can perform user authentication and other processes to verify that the user is indeed a user.

[0140] Figure 15 shows a modified example of the functions of the wallet 101 on the terminal device 100 and the Verified 51 on the carrier terminal 50. Explanations of content common to Figure 11 are omitted.

[0141] As shown in Figure 15, in a configuration that includes a wallet manager 106, the wallet 105 does not need to include functions as a UI that displays information necessary for information processing, or functions such as user authentication that authenticates the user's identity.

[0142] The wallet manager 106 of the terminal device 100 has a screen display unit 130A that includes a UI function for displaying information necessary for information processing. The wallet manager 106 also has a presentation VC setting unit 130C that performs processes such as user authentication to authenticate that the user is a user and processing for setting disclosure rules.

[0143] The NFC chip's wallet 105 has a disclosure rule storage function that stores disclosure rules and a presentation VC generation unit 130D that includes a Verifyer authentication function. The wallet 105 also has a VC storage unit 120A and a communication unit 110B.

[0144] To illustrate with the configuration shown in Figure 3, for example, the terminal device 100 includes an NFC chip, and the NFC chip comprises a verification unit 136 and a transmission unit 134. Specifically, the terminal device 100, such as a smartphone, may be configured to include a receiving unit 131 and a display control unit 135, while the NFC chip included in the smartphone may comprise a receiving unit 132, a generation unit 133 including a verification unit 136, and a transmission unit 134.

[0145] As an alternative example, we will describe an example in which a wallet 105 contained in an NFC chip is installed in a watch-type wearable device. Information is presented to the verifier, for example, by the user holding the NFC chip over an IC card reader. Therefore, it is preferable to use a watch-type wearable device equipped with an NFC chip that is easy for the user to hold over an IC card reader, for the wallet 105 contained in the NFC chip. If the watch-type wearable device is the wallet 105, the terminal device 100 may run the wallet manager 106 as a companion application on the terminal device 100. For example, the watch-type wearable device and the terminal device 100 are connected in a way that allows communication via BLE.

[0146] In other embodiments, the wallet 105 or wallet manager 106 can back up disclosure rules associated with an account such as a platform provider. For example, if a user changes their mobile phone due to a model change or if they are concerned about losing their device, the wallet 105 or wallet manager 106 can store the disclosure rules on an external server through user operation. By storing the disclosure rules on an external server, the wallet 105 or wallet manager 106 can restore the disclosure rules without having to reconfigure them. Therefore, the wallet 105 or wallet manager 106 can improve user convenience by storing the disclosure rules on an external server.

[0147] Disclosure rules can be deployed in CSV files, tab-delimited text files, or spreadsheet software file formats. In addition to users entering the disclosure rules using the UI, they can also be set by importing files from external sources. The configured disclosure rules can be exported as a file. Therefore, when managing wallet 105 or wallet manager 106, for example, at a university or company, it becomes possible to set disclosure rules in bulk from an external source. Wallet 105 or wallet manager 106 also reduces the burden of input and makes it easy to deploy disclosure rules even when users are using BYOD (Bring Your Own Device) and bringing their own mobile phones to universities or companies.

[0148] The wallet 105 or wallet manager 106 can also suggest setting up disclosure rules that do not require authentication as a recommendation to the user, based on the user's usage history. For example, when suggesting setting up disclosure rules that do not require authentication, the wallet 105 or wallet manager 106 stores the suggestion history to understand the user's multiple visits to the same door or store. The wallet 105 or wallet manager 106 also infers and determines from the status of other rule settings that a similar approach is in line with the user's preferences and displays the recommendation to the user in a pop-up. The wallet 105 or wallet manager 106 has a UI that allows the user to choose whether to accept the recommendation, edit the recommended content and then accept it, or cancel (reject) the recommendation.

[0149] In this way, the wallet 105 or wallet manager 106 can provide a highly convenient application by automatically generating rules from other rules and usage history, saving users the trouble of setting disclosure rules from scratch. Furthermore, the wallet 105 or wallet manager 106 can provide an application that helps save users time by adding a function that allows them to edit the automatically generated rules and set them as their own rules.

[0150] Furthermore, while disclosure rules improve user convenience, universities and companies also want to enhance security during non-standard times. For example, Wallet 105 or Wallet Manager 106 can disable user-defined disclosure rules during times when there are relatively few users, such as at night or on weekends, even if such rules are set. The setting that prevents skipping authentication is a feature that can be set when the issuer prioritizes security over user convenience, and it prevents malicious users who might be using a found mobile phone or other device without permission from abusing disclosure rules.

[0151] (3. Other Embodiments) The processes according to each of the embodiments described above may be carried out in various other forms besides those described above.

[0152] Furthermore, among the processes described in each of the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by known methods. In addition, the processing procedures, specific names, and information including various data and parameters shown in the above document and drawings can be changed at will unless otherwise specified. For example, the various information shown in each figure is not limited to the information shown.

[0153] Furthermore, the components of each illustrated device are functionally conceptual and do not necessarily need to be physically configured as shown. In other words, the specific forms of distribution and integration of each device are not limited to those shown, and all or part of them can be functionally or physically distributed and integrated in any unit according to various loads and usage conditions.

[0154] Furthermore, the embodiments and modifications described above can be combined as appropriate, provided that the processing content is not inconsistent.

[0155] Furthermore, the effects described herein are merely illustrative and not limiting; other effects may also occur.

[0156] (4. Effects of the terminal device relating to this disclosure) As described above, the terminal device relating to this disclosure (terminal device 100 in the embodiment) comprises a receiving unit (receiving unit 131 in the embodiment), a receiving unit (receiving unit 132 in the embodiment), a generation unit (generation unit 133 in the embodiment), a transmission unit (transmission unit 134 in the embodiment), a display control unit (display control unit 135 in the embodiment), and a verification unit (verification unit 136 in the embodiment). The receiving unit accepts at least one of the following: the selection of setting a disclosure rule linked to attribute information included in the certification information that proves the user's qualifications, and the selection of setting a disclosure rule linked to the identification information of the business operator. The verification unit also verifies the identification information of the business operator when the business operator requests disclosure of the certification information. The transmission unit transmits the attribute information to the business operator based on at least one of the disclosure rules linked to the attribute information and the disclosure rules linked to the identification information, and the verified identification information.

[0157] Thus, by setting disclosure rules in advance, the terminal device related to this disclosure can automatically disclose attribute information to the business operator. Therefore, by automating the disclosure process, the number of times the user operates the terminal device is reduced, and the risk of unintended information transmission is mitigated.

[0158] Furthermore, the terminal device can verify the business operator using the operator's identification information, thereby reducing the risk of sending information to unintended recipients. Therefore, the terminal device can efficiently present user information.

[0159] Furthermore, the reception department accepts requests for disclosure rules linked to attribute information, specifying which businesses will permit disclosure, which businesses will refuse disclosure, and which businesses will verify the disclosure, for each piece of attribute information.

[0160] In this way, the terminal device related to this disclosure can suppress the risk of unintended information transmission for each attribute of information by allowing the business operator to set whether or not to disclose each attribute of information.

[0161] Furthermore, the reception department accepts the setting of attribute information that is permitted to be disclosed, attribute information that is denied disclosure, and attribute information that requires confirmation of disclosure, as disclosure rules linked to the identification information, for each business operator's identification information.

[0162] Thus, the terminal device related to this disclosure can mitigate the risk of unintended information transmission for each business operator by allowing them to configure whether or not to disclose attribute information. Furthermore, the terminal device can flexibly accept settings such as increasing or decreasing the number of recipients to whom information is disclosed.

[0163] Furthermore, the reception department accepts requests for disclosure rules linked to attribute information, specifying which services the business operator will permit disclosure to, which services the business operator will refuse disclosure to, and which services the business operator will verify the disclosure to, for each piece of attribute information.

[0164] In this way, the terminal device related to this disclosure accepts settings for whether or not to disclose attribute information for each service of the service provider, allowing the user to decide who to disclose their attribute information to in detail.

[0165] The reception desk also accepts requests to set disclosure rules for attribute information, including the user's name, address, phone number, facial photograph, age, and at least one piece of information from identification documents.

[0166] In this way, the terminal device related to this disclosure can mitigate the risk of unintended information transmission by accepting the setting of disclosure rules for attribute information, including personal information.

[0167] Furthermore, the reception desk accepts requests to set a period during which attribute information can be disclosed, as part of the disclosure rules. In this way, the terminal device related to this disclosure can prevent the disclosure of information that the user did not intend by setting a period.

[0168] Furthermore, the reception desk accepts requests for setting the number of times attribute information can be disclosed as part of the disclosure rules. In this way, the terminal device related to this disclosure can prevent businesses from unnecessarily repeating disclosures by allowing them to set the number of times disclosure is permitted.

[0169] Furthermore, the verification unit verifies the business name of the service provider and identification information including the service provider's services.

[0170] Thus, the terminal device related to this disclosure can suppress the disclosure of attribute information to unintended businesses or their services by verifying identification information, including the business name and the business's services.

[0171] If the display control unit cannot verify the identification information of the business operator, it will display a message indicating that the identification information could not be verified.

[0172] Thus, the terminal device related to this disclosure can prevent the unintended leakage of user attribute information by displaying to the user that it cannot verify the identification information of the business operator.

[0173] Furthermore, the reception unit accepts requests for updating certification information. The transmission unit, based on a request from the issuer of the certification information, transmits to the issuer that it has received the request for updating the certification information and that it possesses the certification information.

[0174] Thus, the terminal device related to this disclosure can automatically renew the validity period of the certification information, thereby improving usability.

[0175] Furthermore, if the attribute information that the business operator is permitted to disclose includes attribute information that the business operator requests to be disclosed, the transmitting unit will transmit the attribute information to the business operator.

[0176] Thus, the terminal device involved in this disclosure transmits attribute information authorized for disclosure by the user, their guardian, the issuer of the VC, etc., to the business operator, thereby preventing the leakage of attribute information unintentionally intended by the user. In addition, the terminal device improves usability by disclosing attribute information without obtaining confirmation from the user.

[0177] Furthermore, the terminal device includes an NFC chip, which comprises a verification unit and a transmission unit. In this way, the terminal device relating to this disclosure eliminates the need for screen operation by pre-setting disclosure rules, and allows for the disclosure of attribute information using an NFC chip that does not have a screen display function.

[0178] (5. Hardware Configuration) The information devices such as the terminal device 100 according to each embodiment described above are realized by a computer 1000 having a configuration such as that shown in Figure 16. Hereinafter, the terminal device 100 according to the embodiment will be described as an example. Figure 16 is a hardware configuration diagram showing an example of a computer 1000 that realizes the functions of the terminal device 100. The computer 1000 has a CPU 1100, RAM 1200, ROM (Read Only Memory) 1300, HDD (Hard Disk Drive) 1400, communication interface 1500, and input / output interface 1600. The parts of the computer 1000 are connected by a bus 1050.

[0179] The CPU 1100 operates based on programs stored in the ROM 1300 or HDD 1400 and controls each part. For example, the CPU 1100 loads the programs stored in the ROM 1300 or HDD 1400 into the RAM 1200 and executes processing corresponding to various programs.

[0180] ROM 1300 stores boot programs such as the BIOS (Basic Input Output System) that are executed by the CPU 1100 when the computer 1000 starts up, as well as programs that depend on the computer 1000's hardware.

[0181] The HDD 1400 is a computer-readable recording medium that non-temporarily stores programs executed by the CPU 1100 and data used by such programs. Specifically, the HDD 1400 is a recording medium that stores a conversion program according to this disclosure, which is an example of program data 1450.

[0182] The communication interface 1500 is an interface for the computer 1000 to connect to an external network 1550 (e.g., the Internet). For example, the CPU 1100 can receive data from other devices or transmit data it has generated to other devices via the communication interface 1500.

[0183] The input / output interface 1600 is an interface for connecting the input / output device 1650 and the computer 1000. For example, the CPU 1100 receives data from input devices such as a keyboard or mouse via the input / output interface 1600. The CPU 1100 also transmits data to output devices such as a display, speaker, or printer via the input / output interface 1600. The input / output interface 1600 may also function as a media interface for reading programs recorded on a predetermined recording medium (media). Examples of media include optical recording media such as DVDs (Digital Versatile Discs) and PDs (Phase Change Rewritable Disks), magneto-optical recording media such as MOs (Magneto-Optical Disks), tape media, magnetic recording media, or semiconductor memory.

[0184] For example, when the computer 1000 functions as a terminal device 100 according to the embodiment, the CPU 1100 of the computer 1000 realizes functions such as the control unit 130 by executing an information processing program loaded on the RAM 1200. The HDD 1400 stores the information processing program according to this disclosure and data in the storage unit 120. The CPU 1100 reads and executes the program data 1450 from the HDD 1400, but as another example, these programs may be obtained from other devices via an external network 1550.

[0185] Furthermore, this technology can also be configured as follows: (1) A terminal device comprising: a receiving unit that accepts at least one of the following: the selection of setting disclosure rules linked to attribute information included in certification information that proves the user's qualifications, and the selection of setting disclosure rules linked to the identification information of a business operator; a verification unit that verifies the identification information of the business operator when the business operator requests disclosure of the certification information; and a transmitting unit that transmits attribute information to the business operator based on at least one of the disclosure rules linked to the attribute information and the identification information, and the verified identification information. (2) The terminal device according to (1), wherein the receiving unit accepts the setting of business operators that permit disclosure, business operators that refuse disclosure, and business operators that confirm disclosure as disclosure rules linked to the attribute information for each piece of attribute information. (3) The terminal device according to (1) or (2), wherein the receiving unit accepts the setting of attribute information that permits disclosure, attribute information that refuses disclosure, and attribute information that confirms disclosure as disclosure rules linked to the identification information for each piece of business operator's identification information. (4) The receiving unit is a terminal device according to any one of (1) to (3) above, which accepts the setting of disclosure rules for each piece of attribute information, including the services of businesses that permit disclosure, the services of businesses that refuse disclosure, and the services of businesses that verify disclosure. (5) The receiving unit is a terminal device according to any one of (1) to (4) above, which accepts the setting of disclosure rules for attribute information, which includes at least one of the user's name, address, telephone number, facial photograph, age, and certificate information. (6) The receiving unit is a terminal device according to any one of (1) to (5) above, which accepts the setting of a disclosure rule, which specifies the period during which the attribute information can be disclosed. (7) The receiving unit is a terminal device according to any one of (1) to (6) above, which accepts the setting of a disclosure rule, which specifies the number of times the attribute information can be disclosed. (8) The verification unit is a terminal device according to any one of (1) to (7) above, which verifies the identification information, which includes the business name of the business and the services of the business.(9) A terminal device according to any one of (1) to (8), further comprising a display control unit that indicates that the identification information of the business operator could not be verified if the identification information of the business operator could not be verified. (10) A terminal device according to any one of (1) to (9), wherein the receiving unit receives a setting for updating the certification information, and the transmitting unit transmits to the issuer that it has received the setting for updating the certification information and that it possesses the certification information, based on a presentation request from the issuer that issues the certification information. (11) A terminal device according to any one of (1) to (10), wherein the transmitting unit transmits attribute information to the business operator if the attribute information that the business operator requests to be disclosed is included in the attribute information that the business operator requests to be disclosed. (12) A terminal device according to any one of (1) to (11), wherein the terminal device includes an NFC chip, and the NFC chip comprises the verification unit and the transmitting unit. (13) An information processing method comprising: a computer receiving at least one of the following: a selection of setting disclosure rules associated with attribute information contained in certification information that proves the user's credentials, and a selection of setting disclosure rules associated with the identification information of a business operator; verifying the identification information of the business operator when the business operator requests disclosure of the certification information; and transmitting the attribute information to the business operator based on at least one of the disclosure rules associated with the attribute information and the disclosure rules associated with the identification information, and the verified identification information. (14) An information processing program for causing a computer to function as an information processing device comprising: a receiving unit that receives at least one of the following: a selection of setting disclosure rules associated with attribute information contained in certification information that proves the user's credentials, and a selection of setting disclosure rules associated with the identification information of a business operator; a verification unit that verifies the identification information of the business operator when the business operator requests disclosure of the certification information; and a transmitting unit that transmits the attribute information to the business operator based on at least one of the disclosure rules associated with the attribute information and the disclosure rules associated with the identification information, and the verified identification information.

[0186] 10 VCA 50 Operator terminal 100 Terminal device 110 Communication unit 120 Storage unit 130 Control unit 131 Reception unit 132 Receiver unit 133 Generation unit 134 Transmission unit 135 Display control unit 136 Verification unit

Claims

1. A terminal device comprising: a receiving unit that accepts at least one of the following: the selection of setting disclosure rules linked to attribute information contained in certification information that proves the user's qualifications, and the selection of setting disclosure rules linked to the identification information of a business operator; a verification unit that verifies the identification information of the business operator when the business operator requests disclosure of the certification information; and a transmitting unit that transmits attribute information to the business operator based on at least one of the disclosure rules linked to the attribute information and the disclosure rules linked to the identification information, and the verified identification information.

2. The terminal device according to claim 1, wherein the receiving unit receives, for each piece of attribute information, the settings of a business operator that permits disclosure, a business operator that refuses disclosure, and a business operator that verifies disclosure, as disclosure rules associated with the attribute information.

3. The terminal device according to claim 1, wherein the receiving unit accepts, for each piece of identification information of the business operator, the setting of attribute information to permit disclosure, attribute information to refuse disclosure, and attribute information to confirm disclosure, as disclosure rules associated with the identification information.

4. The terminal device according to claim 1, wherein the receiving unit receives, for each piece of attribute information, the settings of the services of the business operator that permits disclosure, the services of the business operator that refuses disclosure, and the services of the business operator that confirms disclosure, as disclosure rules associated with the attribute information.

5. The terminal device according to claim 1, wherein the reception unit accepts the setting of disclosure rules for attribute information, which include at least one of the user's name, address, telephone number, facial photograph, age, and information from a certificate.

6. The terminal device according to claim 1, wherein the reception unit accepts the setting of a period during which the attribute information can be disclosed as a disclosure rule.

7. The terminal device according to claim 1, wherein the reception unit accepts the setting of the number of times the attribute information can be disclosed as a disclosure rule.

8. The terminal device according to claim 1, wherein the verification unit verifies the business name of the business operator and identification information including the services of the business operator.

9. The terminal device according to claim 1, further comprising a display control unit that indicates that the identification information of the business operator could not be verified if the identification information of the business operator could not be verified.

10. The terminal device according to claim 1, wherein the receiving unit receives a setting for updating the certification information, and the transmitting unit transmits to the issuer that it has received the setting for updating the certification information and that it possesses the certification information, based on a presentation request from the issuer that issues the certification information.

11. The terminal device according to claim 1, wherein the transmitting unit transmits attribute information to the business operator if the attribute information that the business operator is permitted to disclose includes attribute information that the business operator requests to be disclosed.

12. The terminal device according to claim 1, wherein the terminal device includes an NFC chip, and the NFC chip comprises the verification unit and the transmission unit.

13. An information processing method comprising: a computer receiving at least one of the following: the selection of setting disclosure rules associated with attribute information contained in certification information that proves a user's credentials, and the selection of setting disclosure rules associated with the identification information of a business operator; the computer verifying the identification information of the business operator when the business operator requests disclosure of the certification information; and transmitting the attribute information to the business operator based on at least one of the disclosure rules associated with the attribute information and the disclosure rules associated with the identification information, and the verified identification information.

14. An information processing program for causing a computer to function as an information processing device comprising: a receiving unit that receives at least one of the following: the selection of setting disclosure rules linked to attribute information contained in certification information that proves the user's credentials, and the selection of setting disclosure rules linked to the identification information of a business operator; a verification unit that verifies the identification information of the business operator when the business operator requests disclosure of the certification information; and a transmitting unit that transmits attribute information to the business operator based on at least one of the disclosure rules linked to the attribute information and the disclosure rules linked to the identification information, and the verified identification information.