Credential processing method, credential processing system, terminal device, server device, and program
Patent Information
- Application Number
- PCT/JP2026/005285
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-19
- Filing Date
- 2026-02-13
- Publication Date
- 2026-08-27
Smart Images

Figure JP2026005285_27082026_PF_FP_ABST
Abstract
Description
Qualification Certificate Processing Method, Qualification Certificate Processing System, Terminal Device, Server Device, and Program
[0001] The present disclosure relates to a qualification certificate processing method, a qualification certificate processing system, a terminal device, a server device, and a program.
[0002] Conventionally, a system for processing a digital student ID in which a student ID is represented by digital data has been known. This system includes a first server that controls the digital student ID, a first ID that is an ID associated with an electronic certificate stored in an identity certificate and that is linked to the validity of the identity certificate, and a second ID for an educational institution to manage students. The second server stores the first ID and the second ID in association with each other, and a terminal possessed by a student. When the first server acquires from the terminal that the student wishes to use the digital student ID, the first server notifies the second server of the second ID of the student. When the first ID corresponding to the notified second ID is valid, the second server generates a digital student ID for the student who wishes to use the digital student ID and transmits the generated digital student ID to the first server (see Patent Document 1).
[0003] Japanese Patent No. 7218840
[0004] In the system of Patent Document 1, the usage scenario of the digital student ID is limited to online, and it is difficult to simply perform identity verification when using the service, and there is room for improvement.
[0005] The present disclosure provides a qualification certificate processing method, a qualification certificate processing system, a terminal device, a server device, and a program that can use a digital qualification certificate both online and offline and can easily perform identity verification when using the service.
[0006] One aspect of this disclosure is a certificate processing method for processing a digital certificate certified by a designated certification business operator, comprising: obtaining personal information of a user by reading it from the user's digital identification card pre-stored in a terminal device; obtaining qualification information relating to a qualification entered by the user, or qualification information transmitted by the certification business operator server to the terminal device in response to the user's request; obtaining the certification business operator's electronic certificate; generating a digital certificate based on the obtained personal information, qualification information, and electronic certificate; and storing the digital certificate in the memory of the terminal device.
[0007] One aspect of the present disclosure is a certificate processing system for processing digital certificates certified by a designated certification authority, comprising a terminal device and a certification authority server, wherein the terminal device obtains the user's personal information by reading it from the user's digital identification card pre-stored in the terminal device's memory, obtains qualification information relating to the qualification entered by the user, or qualification information transmitted to the terminal device by the certification authority server at the user's request, obtains the certification authority's electronic certificate from the certification authority server, generates a digital certificate based on the obtained personal information, qualification information and electronic certificate, and stores the digital certificate in the memory.
[0008] One aspect of the present disclosure is a terminal device for processing a digital certificate certified by a designated certification business operator, comprising a processor and a memory, wherein the processor obtains the user's personal information by reading it from the user's digital identification card pre-stored in the memory, obtains qualification information relating to the qualification entered by the user, or qualification information transmitted to the terminal device by the certification business operator server at the user's request, obtains the certification business operator's electronic certificate, generates a digital certificate based on the obtained personal information, qualification information and electronic certificate, and stores the digital certificate in the memory.
[0009] One aspect of the present disclosure is a server device for processing digital credentials certified by a designated certification business operator, comprising a processor and memory, wherein the processor acquires a digital credentials from a terminal device and stores the digital credentials in the memory, the terminal device acquires the user's personal information read from the user's digital identification card stored in the terminal device, acquires credential information relating to the credentials entered by the user, or credential information transmitted to the terminal device by the certification business operator server at the user's request, acquires the certification business operator's electronic certificate, generates the digital credentials based on the acquired personal information, the credential information and the electronic certificate, stores the digital credentials in the terminal device, and transmits the digital credentials to the server device.
[0010] One aspect of this disclosure is a program that causes a computer to execute the above-described certificate processing method.
[0011] According to this disclosure, digital credentials can be used both online and offline, and identity verification can be easily performed when using the service.
[0012] Figures illustrating the configuration of the data processing system in the first embodiment of this disclosure; Sequence diagrams illustrating the operation of the data processing system when a My Number Card is digitized and registered in the OS wallet of a terminal device; Sequence diagram (1) illustrating the operation of the data processing system when issuing a digital student ID; Sequence diagram (2) illustrating the operation of the data processing system when issuing a digital student ID; Sequence diagram (1) illustrating the operation of the data processing system when purchasing a digital commuter pass; Sequence diagram (2) illustrating the operation of the data processing system when purchasing a digital commuter pass; Figures illustrating an example of the data structure of a digital My Number Card; Figures illustrating an example of a bound digital student ID; Figures illustrating an example of a physical student ID card that also serves as a commuter pass purchase certificate; Figures illustrating an example of a physical student ID card that also serves as a commuter pass purchase certificate.
[0013] The embodiments will be described in detail below, with reference to the drawings as appropriate. However, unnecessary details may be omitted. For example, detailed explanations of already well-known matters or redundant explanations of substantially identical configurations may be omitted. This is to avoid the following explanation becoming unnecessarily verbose and to facilitate understanding by those skilled in the art. The accompanying drawings and the following explanation are provided to enable those skilled in the art to fully understand this disclosure and are not intended to limit the subject matter described in the claims.
[0014] (Background to obtaining the embodiments of this disclosure) In the system of Patent Document 1, when purchasing a commuter pass with a student discount, the student presents a digital student ID to the railway company. The railway company visually verifies the digital student ID, which is verified as the student's identity using a My Number Card, and sells the commuter pass.
[0015] Furthermore, in the system described in Patent Document 1, digital student IDs are sent and received between a first server and a second server, but the terminal device held by the student does not store the digital student ID. Therefore, if a student wants to use the digital student ID on the terminal device, it needs to be obtained from either the first or second server. In other words, Patent Document 1 assumes that the digital student ID will be used online. Also, when a student tries to use a service using a digital student ID, the authenticity of the electronic certificate of the digital student ID (i.e., the student's identity) cannot be guaranteed between the terminal and the service server providing the service. Therefore, the system used for identity verification becomes complex.
[0016] The following embodiments describe a certificate processing method, a certificate processing system, a terminal device, a server device, and a program that enable the use of digital certificates both online and offline, and facilitate identity verification when using the service.
[0017] (First Embodiment) Figure 1 is a diagram showing an example configuration of a data processing system 5 in the first embodiment of the present disclosure. The data processing system 5 includes a terminal device 10 and a plurality of servers. The plurality of servers include a DIW (Digital Identity Wallet) server 20, a first authentication server 30, a second authentication server 40, a third authentication server 50, a service server 60, and a code reader 70. The terminal device 10 and the plurality of servers may be connected to each other via a network NT. The code reader 70 may be omitted.
[0018] Each of the multiple servers may be configured as an on-premises server device or as a cloud-based server on a network. Each of the multiple servers may be configured as a single computer or as a distributed configuration across multiple computers. Furthermore, at least one computer may combine at least some of the functions of the multiple servers; for example, one or two computers may have the functions of the first authentication server 30, the second authentication server 40, and the third authentication server 50, or four or more computers may have them.
[0019] Terminal device 10 is a user terminal owned by a user who enjoys various services. Terminal device 10 is capable of storing data for various digital certificates. Digital certificates include, for example, digital qualification certificates certified by a designated certification body. Digital qualification certificates include, for example, digital student ID cards certified by a school (e.g., university, high school). Note that the certification body is not limited to schools, but may be a company or other organization.
[0020] The DIW server 20 performs processing related to the Digital ID Wallet (DIW). The first authentication server 30 is a server for the school authentication infrastructure. The second authentication server 40 is a server for the Digital Agency's common authentication infrastructure. The third authentication server 50 is a server for the Japanese Public Key Infrastructure (JPKI) of the Japan Agency for Local Authority Information Systems (J-LIS). The service server 60 performs processing related to the services provided by the data processing system 5. Each server has at least a processor, memory, and a communication device.
[0021] The terminal device 10 comprises a processor 11, memory 12, a communication device 13, an input device 14, and a display device 15. The terminal device 10 is possessed, for example, by a user using a digital student ID.
[0022] The processor 11 may be configured using, for example, a Central Processing Unit (CPU), a Digital Signal Processor (DSP), or a Graphical Processing Unit (GPU). The processor 11 may also be configured using various integrated circuits (for example, a Large Scale Integration (LSI) or a Field Programmable Gate Array (FPGA)). The processor 11 implements various functions by executing programs held in the memory 12. These functions include, for example, an OS wallet that holds and manages information related to the digital ID wallet, a DIW application (also called a DIW app) that performs processing related to the digital ID wallet, and a service application (also called a service app) that performs processing related to various services. The processor 11 comprehensively controls each part of the terminal device 10 and performs various processes.
[0023] Memory 12 includes, for example, Random Access Memory (RAM) or Read Only Memory (ROM). Memory 12 may include volatile memory or non-volatile memory. Memory 12 may include, for example, a Hard Disk Drive (HDD), Solid State Drive (SSD), optical disc, SD card, etc. Memory 12 may also be an external storage medium and may be detachable from the terminal device 10. Memory 12 stores various data, information, or programs.
[0024] Memory 12 holds, for example, information related to a digital ID wallet. The digital ID wallet holds various digital certificates. Digital certificates are electronic data of various certificates that prove identity. Digital certificates include, for example, digital certificates corresponding to official certificates issued by public institutions and digital certificates corresponding to private certificates issued by private institutions. Official certificates include, for example, driver's licenses (e.g., driver's licenses), My Number cards, international driver's licenses, passports, etc. Private certificates include, for example, employee IDs, qualification certificates, student IDs, etc. Some certificates have expiration dates. In this embodiment, digital certificates broadly include those that can prove the identity of the user, and may also include, for example, electronic tickets. The digital ID wallet may also have credit card functionality, electronic money functionality, and point functionality that can be used for electronic payments.
[0025] Therefore, a digital ID wallet can store digital certificates such as digital identification cards (e.g., digital My Number cards), digital qualification certificates (e.g., digital student IDs, digital employee IDs), and digital certificates related to commuting to school or work (e.g., digital school attendance certificates, digital commuter certificates). In addition, various digital certificates may also hold the user's facial image data. Furthermore, at least a portion of at least one digital certificate may be combined to generate a new digital certificate. For example, a digital student ID may contain data from a digital school attendance certificate.
[0026] Furthermore, memory 12 may store information such as public keys and digital certificates obtained from each server.
[0027] Furthermore, as shown in Figure 1, the terminal device 10 has a secure element 12A. The secure element 12A is a tamper-resistant memory. The secure element 12A holds various types of data and information. For example, the secure element 12A holds information about a secret key obtained from a server.
[0028] The communication device 13 communicates various data or information according to a wired or wireless communication method. The communication method used by the communication device 13 may include, for example, a Local Area Network (LAN), a Wide Area Network (WAN), a mobile phone network, or a power line communication method.
[0029] The communication device 13 communicates with, for example, external communication devices (e.g., various servers) or the network NT.
[0030] The input device 14 may include various buttons, keys, a mouse, a keyboard, a touch panel, a microphone, or other input devices. The input device 14 accepts input of various data or information. The input device 14 may be operated by the user of the terminal device 10. The user here is, for example, a user of a digital wallet, the user who possesses a digital certificate and uses various services.
[0031] The input device 14 accepts, for example, general operations of the terminal device 10 and operations related to the execution of applications.
[0032] The display device 15 is, for example, a liquid crystal display or an organic EL display. The display device 15 displays various data or information. The display by the display device 15 may be confirmed by, for example, a user.
[0033] The display device 15 displays, for example, screens used in the OS wallet, DIW app, service app, digital certificates, facial image data, etc.
[0034] The code reader 70 reads various types of codes. For example, the code reader 70 optically reads codes displayed on a display device (e.g., one-dimensional codes (e.g., barcodes), two-dimensional codes (e.g., QR codes (registered trademarks))). The code reader 70 is installed, for example, at a service provider's service location (e.g., a railway company's ticket counter). The code reader 70 comprises, for example, a processor, memory, a communication device, and a code reading device. The code reader 70 transmits the code reading information read from the code to a terminal device 10 or the like. The code reader 70 is one of the terminal devices.
[0035] <Operation of the Data Processing System> Next, the operation of the data processing system 5 will be explained.
[0036] First, we will explain how to digitize the My Number Card (also known as "MNC (My Number Card)") and register (store) it in the OS wallet of the terminal device 10.
[0037] Figure 2 is a sequence diagram showing an example of the operation of the data processing system 5 when the My Number Card is digitized and registered (stored) in the OS wallet of the terminal device 10. In sequence diagrams such as Figure 2, "UI (User Interface)" refers to at least one of the input device 14 and the display device 15.
[0038] The terminal device 10 includes a service application 111, an OS wallet 112, and an MNC application 113.
[0039] First, the MNC application 113 presents a request for the user to enter their PIN and a request for authentication of their My Number Card (physical card) (step S101). This presentation is, for example, displayed on the display device 15, but other presentations (for example, voice output) may also be used. The user confirms this request displayed on the display device 15. The input device 14 receives the PIN from the user and sends the PIN input information to the MNC application 113 (step S102).
[0040] The MNC application 113 retrieves four pieces of information and facial image data from the IC chip of the My Number Card (step S103). The four pieces of information are address, name, date of birth, and gender. The MNC application 113 also retrieves the electronic certificate of the My Number Card (also called the MNC electronic certificate) from the IC chip of the My Number Card (step S104). The MNC electronic certificate includes, for example, the public key of the My Number Card issuer (third authentication server). In this case, the MNC application 113 may also retrieve the same information stored in the IC chip of the My Number Card along with the four pieces of information and facial image data.
[0041] The MNC application 113 makes a validity determination request to the third authentication server 50 to determine the validity of the acquired MNC digital certificate (step S105). In this case, the MNC application 113 sends a validity determination request to the third authentication server 50 that includes information on the NMC digital certificate encrypted with a private key.
[0042] The third authentication server 50 receives a validity determination request for the MNC digital certificate. The third authentication server 50 determines the validity of the MNC digital certificate according to the validity determination request (step S106) and determines whether the MNC digital certificate is valid or not (step S107). For example, the third authentication server 50 can confirm that the terminal device 10, which is the other device, possesses the private key by successfully decrypting the MNC digital certificate, which is encrypted with the private key included in the validity determination request, using one of the public keys held by the third authentication server 50. In this case, the third authentication server 50 determines that the MNC digital certificate is valid, that is, that the My Number Card of the user of the terminal device 10 is valid.
[0043] If the MNC digital certificate is invalid (No. in step S107), the third authentication server 50 sends the result of the validity determination (i.e., information that it is invalid) to the MNC application 113 (step S108). In this case, the MNC application 113 may display the information of the validity determination result via the display device 15. Then, the MNC application 113 proceeds to step S101.
[0044] On the other hand, when the MNC electronic certificate is valid (Yes in step S108), the third authentication server 50 transmits the result of the validity determination (i.e., information indicating validity) to the MNC app 113 (step S109). In this case, the MNC app 113 may display the information of the result of the validity determination via the display device 15. Then, the MNC app 113 proceeds to step S110.
[0045] The MNC app 113 generates a digital my number card (also referred to as "MNVC (My Number Virtual Card)") (step S110). The MNC app 113 sends a storage request for the digital my number card to the OS wallet 112 (S111). The OS wallet 112 causes the memory 12 to hold the generated digital my number card (S112).
[0046] According to such an operation example in FIG. 2, the data processing system 5 can verify the my number card and hold the digital my number card corresponding to the verified my number card in the local memory 12. Therefore, when using the digital my number card, the data processing system 5 can obtain the storage information of the electronic my number card without cooperating with other servers. For example, the authenticity of the storage information of the digital my number card can be ensured between the service server 60, which is the server of the operator providing the service, and the terminal device 10, that is, between the two.
[0047] Next, the issuance of a digital student ID as an example of a digital certificate and a digital qualification certificate will be described.
[0048] FIGS. 3A and 3B are sequence diagrams showing operation examples at the time of issuing a digital student ID by the data processing system 5.
[0049] In Figures 3A and 3B, the data processing system 5 digitizes the physical student ID card, links it to the digital My Number Card (also called holder binding, or simply "binding"), and then registers (stores) it in the digital ID wallet. The binding (association) between the digital student ID card and the digital My Number Card serves as proof of the person's identity and that they are a student of the school that issued the digital student ID card.
[0050] The DIW application 114 receives user instructions via the input device 14, installs the DIW application 114 from a designated store, and performs various initial settings for the DIW application 114 (step S201).
[0051] The service application 111 receives user instructions via the input device 14, installs the service application 111 from a predetermined store, and performs various initial settings for the service application 111 (step S202). The services processed by the service application 111 are, for example, the services of a railway company.
[0052] The service application 111 makes an application call to the DIW application 114 (step S203).
[0053] The DIW application 114 displays the certificate issuance selection screen via the display device 15 (step S204). The certificate issuance selection screen is for the user to select the digital certificate they wish to issue. For example, a digital student ID card or a digital student discount certificate can be selected.
[0054] The DIW application 114 receives user input via the input device 14 and enters the required items for the desired digital certificate (step S205). The required items include, for example, the user's student ID number, password, school identification information (e.g., school name), and other information. The student ID number is one of the credentials that indicates eligibility (e.g., being a student).
[0055] The DIW application 114 sends an attendance verification request to the first authentication server 30 via the communication device 13 (step S206). The attendance verification request includes the student ID number and password.
[0056] The first authentication server 30 authenticates the user by comparing the student ID number and password included in the enrollment verification request obtained from the DIW application 114 with the student ID number and password held by the first authentication server 30 (step S207). This authentication is an enrollment authentication that determines whether or not the user is enrolled in the school. Although authentication using a student ID number and password is used as an example here, the system is not limited to this, and other authentication methods required by the school may also be used.
[0057] The first authentication server 30 determines whether the authentication in step S207 was successful (S208). For example, if both the student ID number and the password match, it is determined that the authentication was successful, and if at least one of the student ID number and the password does not match, it is determined that the authentication failed.
[0058] If the authentication in step S207 fails (No. in step S208), the first authentication server 30 sends authentication result information (i.e., authentication failure information) to the DIW application 114 (step S209). In this case, the DIW application 114 may display the authentication result information via the display device 15. Then, the MNC application 113 proceeds to step S204.
[0059] If the authentication in step S207 is successful (Yes in step S208), the first authentication server 30 sends authentication result information (i.e., authentication success information) to the DIW application 114 (step S210). The authentication result information includes the school's digital certificate and the school's (e.g., university's) private key and public key pair. Specifically, the first authentication server 30 sends the digital certificate issued by the school (also called the school digital certificate) and the private key and public key pair. This is to prevent data tampering. The school digital certificate includes, for example, the public key of the issuer (school, first authentication server). The DIW application 114 may display the authentication result information via the display device 15. Then, the DIW application 114 proceeds to step S211.
[0060] The DIW application 114 sends a request to the OS wallet 112 to obtain the digital My Number (step S211).
[0061] The OS wallet 112 reads the information from the digital My Number Card (step S212). The digital My Number Card holds the same information as the physical My Number Card.
[0062] The OS wallet 112 sends the retrieved information, including name, date of birth, address, and MNC digital certificate, to the DIW application 114. The OS wallet 112 may also acquire and send facial image data to the DIW application 114 (step S213).
[0063] The DIW application 114 receives user input via the input device 14 and inputs (acquires) information about the school commute route (step S214).
[0064] The DIW application 114 generates a digital student ID card based on the acquired information (for example, name, date of birth, address, MNC digital certificate, and school digital certificate) and the information on the student's commute route, and stores the digital student ID card in the DIW application 114 as one of the digital ID wallets (step S215). In this case, the DIW application 114 may bind (combine) each of the acquired pieces of information to generate a digital student ID card that includes each of the pieces of information. Alternatively, it may generate a digital student ID card that does not include some of the acquired pieces of information.
[0065] The digital student ID includes, for example, the information shown in Figure 6, which will be described later. The DIW application 114 may acquire each piece of information contained in the digital student ID shown in Figure 6 and generate a digital student ID based on this information.
[0066] The DIW application 114 sends the digital student ID and a registration request for the digital student ID to the DIW server 20 via the communication device 13 (step S216).
[0067] The DIW server 20 receives the digital student ID and the registration request for the digital student ID, and stores (registers) the digital student ID in the memory of the DIW server 20 according to the registration request (step S217). In this way, the DIW server 20 may also back up the digital student ID by holding it in the same way as the terminal device 10. For example, if a student loses their digital student ID, the terminal device 10 will download the digital student ID from the DIW server 20 to the DIW application 114. At that time, the DIW application 114 will perform facial recognition of the student, and only if facial recognition is successful can it download the backed-up digital student ID and store it again in the DIW application 114.
[0068] The DIW server 20 notifies the DIW application 114 of the digital student ID registration result via the communication device 13 (step S218). The DIW server 20 also notifies the service application 111 of the digital student ID registration result via the communication device 13 (step S219). The registration result here includes registration success or registration failure.
[0069] Furthermore, when issuing (generating) a digital student ID, it is not necessary to query the third authentication server 50. Instead, the DIW server 20 (for example, DIW Cloud) may query and confirm whether the My Number Card of the person for whom the digital student ID is to be issued is valid or invalid. The DIW server 20 may, as appropriate, retrieve the invalid MNC list information, which is made open to the public server from the third authentication server 50, to query and confirm whether the My Number Card MNC is valid or invalid. The invalid MNC list information includes information about invalid My Number Cards.
[0070] Furthermore, when the DIW application 114 stores the digital student ID, it may reconstruct the digital student ID using the information contained in the digital student ID. For example, if at least a portion of the information held by the digital My Number Card is extracted and used as information included in the digital student ID, it may be recognized that the contents of the digital My Number Card have been tampered with, and the MNC electronic certificate may not be usable. In contrast, the DIW application 114 can reconstruct the digital student ID, including some of the data from the digital My Number Card, to enable the legitimate use of the MNC electronic certificate. Such reconstruction of the digital student ID may also be performed when the DIW server 20 stores the digital student ID in memory as a backup. In other words, the DIW server 20 may reconstruct the digital student ID using the information contained in the digital student ID and store it in memory.
[0071] According to the operation examples shown in Figures 3A and 3B, the data processing system 5 can easily create a digital student ID card using the stored information of the digital My Number Card. In this case, since the digital My Number Card is stored in the OS wallet 112 of the memory 12 of the terminal device 10, it is not necessary to cooperate with other servers to ensure the authenticity of the My Number Card when generating the digital student ID card.
[0072] In addition, while Figures 3A and 3B illustrate the generation of a digital student ID card with the functionality of a digital school attendance certificate, a digital student ID card without this functionality may also be generated. In this case, the processing related to commuting (for example, obtaining information on the commuting route) may be omitted.
[0073] In Figures 3A and 3B, the DIW application 114 is shown as an example of acquiring information on necessary items such as student ID numbers through user input via the input device 14, but it is not limited to this. At least a portion of the information on the necessary items transmitted from the first authentication server 30 to the terminal device 10 may also be acquired.
[0074] Next, as an example of using a digital qualification card for services, we will explain how to purchase a student discount commuter pass using a digital student ID card.
[0075] Figures 4A and 4B are sequence diagrams showing an example of the operation when purchasing a digital commuter pass (i.e., a student discount pass) using the data processing system 5. In Figures 4A and 4B, a digital commuter pass is purchased using a digital student ID card that also functions as a digital student certificate. The digital commuter pass is data that digitizes a regular commuter pass.
[0076] The data processing system 5, with its processor 11 receiving user input via the input device 14, calls the service application 111 (step S301). The service application 111 calls the DIW application 114 and requests the DIW application 114 to retrieve personal information contained in the digital student ID card via the API (Application Programming Interface) (step S302).
[0077] The DIW application 114 sends a request to the DIW server 20 to retrieve a digital student ID via the communication device 13 (step S303). The DIW server 20 retrieves the digital student ID held in the memory of the DIW server 20 (step S304). The digital student ID contains information such as name, commuting route, user address, school address, and date of birth. The user address is the address of the student (user) holding the digital student ID. The DIW server 20 loads the digital student ID and sends it to the DIW application 114 (step S305).
[0078] Furthermore, if the digital student ID is stored in the local memory 12, the DIW application 114 does not need to request the DIW server 20 to retrieve the digital student ID or digital commuter certificate each time it is needed. Therefore, steps S303 to S305 can basically be omitted.
[0079] The DIW app 114 presents (for example, displays) the personal information of the digital ID wallet to be provided to the service provider via the display device 15 (step S306). The user confirms the presented personal information to be provided. If there is no excess or deficiency in the personal information to be provided, the DIW app 114 receives a consent button press via the input device 14 (step S307). If there is excess or deficiency in the personal information to be provided, the DIW app 114 receives user input via the input device 14, deletes or adds at least some of the personal information to be provided, and then receives a consent button press. This allows the terminal device 10 to prevent unintended information from being provided without the user's knowledge while messages are being exchanged between the DIW app 114 and the service app 111.
[0080] The DIW app 114 determines whether to issue the digital commuter pass offline in person by a store clerk (also referred to as in-person issuance) (step S308). Here, the options are to issue it in person or online (also referred to as online issuance). For example, if the user specifies in-person issuance via input device 14, the DIW app 114 determines to issue it in person. For example, if the user specifies online issuance via input device 14, the DIW app 114 determines to issue it online.
[0081] If the student ID is issued in person (Yes in step S308), the DIW app 114 generates a code (also called a qualification code) that encodes the digital student ID (step S309). The qualification code is a code that can be verified by the service provider. The DIW app 114 then displays the generated qualification code via the display device 15 (step S310).
[0082] The code reader 70 reads the displayed qualification certificate code, for example, optically (S311). The code reader 70 transmits the code reading information read from the qualification certificate code to the DIW application 114. The code reading information is, for example, the same information as the information stored in the digital student ID card (student ID card stored data). Then, the data processing system 5 proceeds to step S312.
[0083] On the other hand, when issuing online (No. in step S308), the data processing system 5 proceeds to step S312 without performing the processing in steps S309 to S311.
[0084] Furthermore, even if an attempt is made to issue the card in person (Yes in step S308), if the above coding cannot be performed, the service server 60 may access the DIW server 20 and obtain the necessary data (i.e., information contained in the digital student ID card, including the digital school attendance certificate) from the DIW server 20.
[0085] The DIW application 114 requests the service application 111 to link the digital student ID with the services provided by the service server 60 (step S312). In this case, the DIW application 114 sends the information held by the acquired digital student ID to the service application 111.
[0086] The service application 111 retrieves the information held by the digital student ID (also referred to as student ID storage data) from the DIW application 114. The service application 111 verifies the signature contained in the digital student ID using the public key held by the service application 111 (step S313).
[0087] Signature verification here can be implemented using a common mechanism such as PKI (Public Key Infrastructure). As an example, the following process is performed. Specifically, the DIW application 114 generates a hash value (first hash value) of the student ID data, encrypts the hash value using the school's private key to generate a signature, and sends the signed student ID data to the service application 111. The DIW application 114 also sends the school's public key to the service application 111. The service application 111 obtains the signed student ID data and the school's public key. The service application 111 determines whether the hash value (second hash value) of the signed student ID data and the hash value (third hash value) obtained by decrypting the signed student ID data with the public key are the same. The service application 111 determines that the signature is valid if the second hash value and the third hash value are the same, and that the signature is invalid if these hash values are not the same.
[0088] The service application 111 can verify, through signature verification, whether or not the user has been impersonated and whether or not the information on the digital student ID has been tampered with.
[0089] The service application 111 notifies the service server 60 of the signature verification result via the communication device 13 (step S314). The signature verification result includes, for example, information indicating that the signature is valid, information indicating that the signature is invalid, etc. Note that the signature verification result information may be notified only if the signature is valid.
[0090] The service server 60 receives signature verification result information from the service application 111. If the signature verification result includes information that the signature is valid, the service server 60 issues (generates) a digital commuter pass based on the information stored in the digital student ID card, including the digital student ID card (student ID card stored data) (step S315). The digital commuter pass is an example of a digital service usage ticket that allows a user to use services according to the user's status. The service server 60 sends a request to store the digital commuter pass to the service application 111 (step S316).
[0091] The service application 111 receives a request to store the digital commuter pass via the communication device 13. In response to the request, the service application 111 stores and holds the digital commuter pass in the digital ID wallet (step S317). The service application 111 sends a notification to the DIW application 114 that the digital commuter pass has been issued (step S318). The DIW application 114 may also send the digital commuter pass to the DIW server 20 as a backup of the digital commuter pass, and the DIW server 20 may store the digital commuter pass there. This allows the terminal device 10 to download the digital commuter pass backed up on the DIW server 20 as needed when the terminal device 10 is lost or malfunctions, when the terminal device 10 is reset, or when the terminal device 10 is changed to a different model.
[0092] When the DIW app 114 receives notification that the digital commuter pass has been issued, it sends the provided information, including the personal information and the date and time of provision that the DIW app 114 provided to the service app 111, and a request for registration of the provided information to the DIW server 20 via the communication device 13 (step S319).
[0093] The DIW server 20 receives the provided information and registration request from the DIW application 114, and registers (stores) the provided information in memory in response to the registration request (step S320). This allows the user to check the history of what information stored in the digital ID wallet has been provided to which service by checking the provided information stored in the memory of the DIW server 20.
[0094] According to the operational examples shown in Figures 4A and 4B, the data processing system 5 can verify the information on the digital student ID card both in person and online, as the terminal device 10 locally stores the digital student ID card. Furthermore, since the data processing system 5 can guarantee that the digital student ID card is backed by a verified digital My Number Card, the authenticity of the MNC electronic certificate and the school electronic certificate can be confirmed between the terminal device 10 and the service server 60, enabling the secure sale of digital commuter passes.
[0095] Figure 5 shows an example of the data structure of a digital My Number Card.
[0096] The digital My Number Card (MNVC) includes information such as name, address, date of birth, gender, facial image information, expiration date, and MNC electronic certificate. The digital My Number Card may include the same information as the physical My Number Card (MNC).
[0097] Figure 6 shows an example of bound data (also referred to as a bound digital student ID) stored in a digital student ID.
[0098] The bound digital student ID includes information such as name, address, date of birth, gender, facial image data, expiration date, school name, student ID number, grade level, school address, commuting route, validity period of commuter pass, planned start date of commuter pass use, validity period of student ID certificate, MNC digital certificate, and school digital certificate. The MNC digital certificate is encrypted and digitally signed with a private key issued by the My Number Card issuer (second authentication server 40 or third authentication server 50), and is associated with a public key issued by the My Number Card issuer. The school digital certificate is encrypted and digitally signed with a private key issued by the school (first authentication server 30), and is associated with a public key issued by the school.
[0099] The school digital certificate may be the digital certificate issued by the school itself, or it may be generated by the DIW application 114 based on the private key and public key issued by the school. In other words, from the initial acquisition from the first authentication server 30, a school digital certificate may be obtained in which predetermined data is hashed, digitally signed with the school's private key, and further accompanied by the school's public key issued by the school. Alternatively, the DIW application 114 may generate a school digital certificate by hashing predetermined data (for example, the data contained between "Name" and "MNC Digital Certificate" in Figure 6), digitally signing it with the school's private key, and further adding the school's public key.
[0100] Information such as the commuting route, the validity period of the commuter pass, the planned start date of use of the commuter pass, and the validity period of the student ID card is included in the data of the digital student ID card. Furthermore, this information is an example of service usage information used to access certain services (e.g., train rides) according to the user's status (e.g., student).
[0101] Furthermore, a user (student) will only need to present their student ID card once between the start date of their commuter pass and the expiration date of their student ID card. Also, the user (student) must carry their digital student ID card with them at all times during the period they are using it, as they may be asked to show it. By digitizing the student ID card and storing it as a digital student ID card in the terminal device 10, the digital student ID card can be presented immediately. Additionally, if the user's address or campus (school location) changes, the student ID card needs to be updated. Information regarding changes in the user's address can be obtained from the update information on the My Number Card. The digital student ID card and the digital student ID card may be integrated or separate.
[0102] As mentioned above, a digital student ID does not necessarily have to include a digital attendance certificate.
[0103] Figure 7 shows an example of a physical student attendance certificate.
[0104] The digital student ID card may contain the same information as the physical student ID card C1 shown in Figure 7, and may contain information that is not present in the physical student ID card C1, or may not contain information that is present in the physical student ID card C1.
[0105] Figure 8 shows an example of a physical student ID card that also serves as a certificate for purchasing commuter passes.
[0106] A bound digital student ID (including a digital commuter pass) contains the same information as the student ID-integrated commuter pass purchase certificate C2 shown in Figure 8. The bound digital student ID may contain information not present in the physical student ID-integrated commuter pass purchase certificate C2, or it may not contain information present in the physical student ID-integrated commuter pass purchase certificate C2. Note that area A2 represents the student ID portion.
[0107] Even if the student ID portion in area A2 shown in Figure 8 is digitized to generate a digital student ID, the data portion in area A1 shown in Figure 7 is insufficient to generate a bound digital student ID. Therefore, when the DIW application 114 generates a bound digital student ID, it obtains the data in area A1 (for example, data on the commuting route, the validity period of the commuter pass, the planned start date of use of the commuter pass, and the validity period of the student certificate) by receiving user input via the input device 14, or by obtaining it from another server via the communication device 13. If there is other information necessary for generating a digital student ID or a bound digital student ID, it may be obtained via the input device 14 as needed.
[0108] As described above, the data processing system 5 of this embodiment can store a digital student ID card in the terminal device 10 held by a user such as a student. Therefore, when the terminal device 10 tries to use the digital student ID card, it does not need to retrieve the digital student ID card from another server, so the digital student ID card can be used to enjoy services both online and offline. Furthermore, when a user tries to use a service using the digital student ID card, the data processing system 5 can guarantee the authenticity of the verification of the digital certificate (i.e., the user's identity) of the digital student ID card between the terminal device 10 and the service server 60. Thus, the data processing system 5 can suppress the complexity of the system configuration required for identity verification. As a result, the data processing system 5 can use the digital certificate both online and offline, and identity verification can be easily performed when using the service.
[0109] While this embodiment primarily illustrates the example of students commuting to school, it is not limited to this. It may also be applied to employees commuting to work. In this case, "commuting to school" should be read as "commuting," student ID numbers as employee ID numbers, and other information as necessary.
[0110] Alternatively, instead of obtaining credentials (e.g., student ID number) through user input, the system may obtain credentials that the authentication provider (e.g., university) transmits to the terminal device 10 in response to the user's request.
[0111] In this embodiment, the use case exemplified is the purchase of a digital commuter pass using a digital student ID with a digital student ID card, but it is not limited to this. Other use cases may include correctly settling transportation expenses for part-time jobs using a digital student ID card. Furthermore, other use cases may include applying student discounts for various services (such as karaoke, museums, art galleries, parks, movie theaters, sports facilities, temple visits, and admissions) using a digital student ID card.
[0112] (Summary of Embodiments) Based on the above, this disclosure contains at least the following information. The components etc. in parentheses are examples of those corresponding to the embodiments described above, but are not limited thereto.
[0113] (Item 1) A certificate processing method for processing a digital certificate (e.g., digital student ID) certified by a designated business operator (e.g., a university), comprising: obtaining the user's personal information by reading it from the user's digital identification card (digital My Number card) pre-stored in a terminal device (e.g., terminal device 10); obtaining qualification information (e.g., student ID number) related to the qualification entered by the user, or qualification information (e.g., student ID number) transmitted to the terminal device by a business operator authentication server (e.g., first authentication server) in response to the user's request; obtaining the business operator's electronic certificate (e.g., school electronic certificate); generating a digital certificate based on the obtained personal information, qualification information and electronic certificate; and storing the digital certificate in the memory (e.g., memory 12) of the terminal device.
[0114] This allows the certificate processing method to store digital certificates within the user's terminal device. Therefore, when the terminal device attempts to use a digital student ID, the certificate processing method eliminates the need to retrieve the digital certificate from another server, allowing the digital certificate to be used for service access both online and offline. Furthermore, when attempting to use a service with a digital student ID, the certificate processing method can guarantee the authenticity of the digital certificate's electronic certificate (i.e., the user's identity) between the terminal device and the service server providing the service. Thus, the certificate processing method can avoid the complexity of the system configuration required for identity verification. Consequently, the certificate processing method allows digital certificates to be used both online and offline, and facilitates easy identity verification when using services.
[0115] (Item 2) The qualification processing method described in Item 1, wherein generating the digital qualification certificate includes obtaining service usage information (e.g., commuting information) for using a predetermined service (e.g., riding a train) according to the user's identity, and generating the digital qualification certificate based on the obtained personal information, qualification information, service usage information, and electronic certificate.
[0116] This allows the certificate processing method to generate a digital certificate that combines a certificate for using the service (e.g., a school attendance certificate) and a certificate of qualification (e.g., a student ID), and store it within the terminal device. Therefore, the certificate processing method allows the terminal device to be used to access the service both online and offline.
[0117] (Item 3) The certificate processing method according to Item 2, further comprising: the terminal device acquiring the digital certificate held in the memory; the terminal device transmitting the certificate storage data, which is data stored in the digital certificate, to a service server (e.g., service server 60) that provides the service; the service server generating a digital service usage ticket (e.g., a digital commuter pass) for the user to use the service according to the user's status based on the certificate storage data; the service server transmitting the digital service usage ticket to the terminal device; and the terminal device storing the digital service usage ticket in the memory.
[0118] As a result, the qualification certificate processing method allows the terminal device to easily obtain the digital qualification certificate issued by the service server without having to perform any processing to acquire the digital qualification certificate from other servers, etc., because the terminal device holds the digital qualification certificate in its memory when the digital service usage ticket is issued.
[0119] (Item 4) The terminal device comprises a user terminal (terminal device 10) used by the user and a code reader (code reader 70) for reading codes, and the method for processing qualifications according to Item 3, wherein transmitting the qualification storage data to the service server includes the user terminal generating a qualification code by encoding the qualification storage data, and the code reader reading the qualification code and transmitting the code reading information obtained as the qualification storage data to the service server.
[0120] This allows the certificate processing method to be adapted so that, for example, a service provider can provide certificate data to the service server using a certificate code, even in person (offline), and easily issue digital service vouchers.
[0121] (Item 5) The digital service voucher includes digital student commuter passes or digital commuter passes, and the qualification certificate processing method described in Item 3.
[0122] This allows terminal devices to easily obtain digital student and commuter passes as part of the qualification certificate processing method.
[0123] (Item 6) A qualification processing system for processing digital qualification certificates certified by a designated business operator, comprising a terminal device and a business operator authentication server, wherein the terminal device obtains the user's personal information by reading it from the user's digital identification card pre-stored in the memory of the terminal device, obtains qualification information relating to qualifications entered by the user, or qualification information transmitted to the terminal device by the business operator authentication server in response to the user's request, obtains the business operator's electronic certificate from the business operator authentication server, generates a digital qualification certificate based on the obtained personal information, qualification information and electronic certificate, and stores the digital qualification certificate in the memory.
[0124] As a result, the qualification certificate processing system achieves the same effect as item 1.
[0125] (Item 7) A terminal device for processing digital qualification certificates certified by a designated business operator, comprising a processor and a memory, wherein the processor obtains the user's personal information by reading it from the user's digital identification card pre-stored in the memory, obtains qualification information relating to the qualification entered by the user, or qualification information transmitted to the terminal device by the business operator authentication server in response to the user's request, obtains the business operator's electronic certificate, generates a digital qualification certificate based on the obtained personal information, qualification information and electronic certificate, and stores the digital qualification certificate in the memory.
[0126] As a result, the terminal device will achieve the same effect as item 1.
[0127] (Item 8) A server device (DIW server 20) that processes digital qualification certificates certified by a designated business operator, comprising a processor and memory, wherein the processor acquires a digital qualification certificate from a terminal device and stores the digital qualification certificate in the memory, the terminal device acquires the user's personal information read from the user's digital identification card stored in the terminal device, acquires qualification information relating to the qualification entered by the user, or qualification information transmitted to the terminal device by the business operator authentication server at the user's request, acquires the business operator's electronic certificate, generates the digital qualification certificate based on the acquired personal information, the qualification information and the electronic certificate, stores the digital qualification certificate in the terminal device, and transmits the digital qualification certificate to the server device.
[0128] As a result, the server device achieves the same effect as item 1, and can also retain digital certificates as a backup. Therefore, the server device can provide digital certificates even if, for example, the terminal device becomes unable to provide them for any reason.
[0129] (Item 9) A program that causes a computer to execute the qualification certificate processing method described in Item 1.
[0130] This allows the program to achieve the same effect as item 1.
[0131] Although various embodiments have been described above with reference to the drawings, it goes without saying that this disclosure is not limited to such examples. It is clear to those skilled in the art that various modifications or alterations can be conceived within the scope of the claims, and these will naturally also fall within the technical scope of this disclosure. Furthermore, the components of the above embodiments may be combined in any way without departing from the spirit of the invention.
[0132] Furthermore, the above embodiment may also apply to a program that implements the functions of the certificate processing method, which is supplied to a computer (e.g., terminal device 10) via a network or various storage media, and which is read and executed by the computer's processor, as well as a recording medium on which this program is stored.
[0133] This disclosure is based on Japanese Patent Application No. 2025-024991 filed on February 19, 2025, the contents of which are incorporated herein by reference.
[0134] This disclosure is useful for certificate processing methods, certificate processing systems, terminal devices, server devices, and programs that enable the use of digital certificates both online and offline, and facilitate identity verification when using services.
[0135] 5 Data Processing System 10 Terminal Device 11 Processor 12 Memory 13 Communication Device 14 Input Device 15 Display Device 20 DIW Server 30 First Authentication Server 40 Second Authentication Server 50 Third Authentication Server 60 Service Server 70 Code Reader
Claims
1. A certificate processing method for processing a digital certificate certified by a designated certification business operator, comprising: obtaining the user's personal information by reading it from the user's digital identification card pre-stored in a terminal device; obtaining qualification information relating to the qualification entered by the user, or qualification information transmitted by the certification business operator server to the terminal device in response to the user's request; obtaining the certification business operator's electronic certificate; generating a digital certificate based on the obtained personal information, qualification information, and electronic certificate; and storing the digital certificate in the memory of the terminal device.
2. The certificate processing method according to claim 1, wherein generating the digital certificate includes obtaining service usage information for using a predetermined service according to the user's identity, and generating the digital certificate based on the obtained personal information, the qualification information, the service usage information, and the electronic certificate.
3. The certificate processing method according to claim 2, further comprising: the terminal device acquiring the digital certificate held in the memory; the terminal device transmitting the certificate storage data, which is data stored in the digital certificate, to a service server providing the service; the service server issuing a digital service usage ticket for the user to use the service according to the user's status based on the certificate storage data; the service server transmitting the digital service usage ticket to the terminal device; and the terminal device storing the digital service usage ticket in the memory.
4. The terminal device comprises a user terminal used by the user and a code reader for reading codes, and the method for processing a certificate of credentials according to claim 3, wherein transmitting the certificate of credentials stored data to the service server includes the user terminal generating a certificate of credentials code by encoding the certificate of credentials stored data, and the code reader reading the certificate of credentials code and transmitting the code reading information obtained as the certificate of credentials stored data to the service server.
5. The qualification certificate processing method according to claim 3, wherein the digital service usage voucher includes a digital student commuter pass or a digital commuter pass.
6. A certificate processing system for processing digital certificates certified by a designated certification business operator, comprising a terminal device and a certification business operator server, wherein the terminal device obtains the user's personal information by reading it from the user's digital identification card pre-stored in the memory of the terminal device, obtains qualification information relating to the qualification entered by the user, or qualification information transmitted to the terminal device by the certification business operator server in response to the user's request, obtains the certification business operator's electronic certificate from the certification business operator server, generates a digital certificate based on the obtained personal information, qualification information and electronic certificate, and stores the digital certificate in the memory.
7. A terminal device for processing digital certificates certified by a designated certification business operator, comprising a processor and a memory, wherein the processor obtains the user's personal information by reading it from the user's digital identification card pre-stored in the memory, obtains qualification information relating to the qualification entered by the user, or qualification information transmitted to the terminal device by the certification business operator server in response to the user's request, obtains the certification business operator's electronic certificate, generates a digital certificate based on the obtained personal information, qualification information and electronic certificate, and stores the digital certificate in the memory.
8. A server device for processing digital certificates certified by a designated certification business operator, comprising a processor and memory, wherein the processor acquires a digital certificate from a terminal device and stores the digital certificate in the memory; the terminal device acquires the user's personal information read from the user's digital identification card stored in the terminal device, acquires qualification information related to the qualification entered by the user, or qualification information transmitted by the certification business operator server to the terminal device at the user's request, acquires the certification business operator's electronic certificate, generates the digital certificate based on the acquired personal information, qualification information and electronic certificate, stores the digital certificate in the terminal device, and transmits the digital certificate to the server device.
9. A program that causes a computer to execute the qualification certificate processing method described in claim 1.