WO2025257933A1 - 端末、端末の制御方法及び記憶媒体 - Google Patents
端末、端末の制御方法及び記憶媒体Info
- Publication number
- WO2025257933A1 WO2025257933A1 PCT/JP2024/021188 JP2024021188W WO2025257933A1 WO 2025257933 A1 WO2025257933 A1 WO 2025257933A1 JP 2024021188 W JP2024021188 W JP 2024021188W WO 2025257933 A1 WO2025257933 A1 WO 2025257933A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- business card
- digital business
- user
- terminal
- digital
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
Definitions
- the present invention relates to a terminal, a terminal control method, and a storage medium.
- Patent Document 1 describes controlling the disclosure of personal information indicating that an owner has a specific attribute.
- the attribute management information in Patent Document 1 includes multiple pieces of attribute information, and has a hierarchical structure in which the range of attributes indicated by one piece of attribute information is included in the range of attributes indicated by attribute information higher than that piece of attribute information.
- a computer accepts a disclosure request requesting disclosure of personal information indicating that a personal information owner has a specific attribute.
- the computer performs a determination process to determine whether, in the attribute management information, a first attribute indicated by first attribute information and a second attribute indicated by second attribute information higher than the first attribute information correspond to the specific attribute.
- the first attribute information corresponds to one or more pieces of personal information held by the personal information owner. Based on the result of the determination process, the computer selects one or more pieces of personal information as the personal information to be disclosed.
- the primary objective of the present invention is to provide a terminal, a method for controlling the terminal, and a storage medium that enable the recipient of a business card to verify the card.
- a terminal in accordance with a first aspect of the present invention, includes a first acquisition means for acquiring a digital business card, the contents of which can be verified online, as a certificate proving that a first user belongs to a specified organization, and a provision means for providing the acquired digital business card to an external party.
- a terminal control method comprising: a first acquisition step of acquiring a digital business card that is a certificate proving that a first user belongs to a specified organization and whose contents can be verified online; and a provision step of providing the acquired digital business card to an external party.
- a computer-readable storage medium stores a program for causing a computer installed in a terminal to execute a first acquisition process for acquiring a digital business card, the content of which can be verified online, as a certificate proving that a first user belongs to a specified organization, and a provision process for providing the acquired digital business card to an external party.
- a terminal In accordance with each aspect of the present invention, a terminal, a method for controlling the terminal, and a storage medium are provided that contribute to enabling the recipient of a business card to verify the received business card.
- the effects of the present invention are not limited to those described above. The present invention may achieve other effects instead of or in addition to these effects.
- FIG. 1 is a diagram for explaining an overview of an embodiment.
- FIG. 2 is a flowchart illustrating the operation of one embodiment.
- FIG. 3 is a diagram illustrating an example of a schematic configuration of an information processing system according to an embodiment of the present disclosure.
- FIG. 4 is a diagram illustrating an example of a display of a terminal according to an embodiment of the present disclosure.
- FIG. 5 is a diagram for explaining the operation of the information processing system according to an embodiment of the present disclosure.
- FIG. 6 is a diagram for explaining the operation of the information processing system according to an embodiment of the present disclosure.
- FIG. 7 is a diagram illustrating an example of a display on a terminal according to an embodiment of the present disclosure.
- FIG. 8 is a diagram illustrating an example of a processing configuration of a terminal according to an embodiment of the present disclosure.
- FIG. 9 is a flowchart illustrating an example of the operation of the identity verification unit according to an embodiment of the present disclosure.
- FIG. 10 is a flowchart illustrating an example of the operation of the acquisition control unit according to an embodiment of the present disclosure.
- FIG. 11 is a diagram illustrating an example of a processing configuration of a server device according to an embodiment of the present disclosure.
- FIG. 12 is a diagram illustrating an example of an employee management database according to an embodiment of the present disclosure.
- FIG. 13 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure.
- FIG. 13 is a sequence diagram illustrating an example of the operation of the information processing system according to an embodiment of the present disclosure.
- FIG. 14 is a diagram illustrating an example of a display on a terminal according to a modified example of the embodiment of the present disclosure.
- FIG. 15 is a diagram illustrating the operation of an information processing system according to a modified example of an embodiment of the present disclosure.
- FIG. 16 is a diagram illustrating an example of a hardware configuration of a terminal according to the present disclosure.
- the terminal 100 comprises a first acquisition means 101 and a provision means 102 (see Figure 1).
- the first acquisition means 101 acquires a digital business card, which is a certificate that proves that the first user belongs to a specific organization and whose contents can be verified online (step S1 in Figure 2).
- the provision means 102 provides the acquired digital business card to an external party (step S2).
- Terminal 100 acquires a digital business card whose name is that of the owner (first user) and whose contents can be verified online.
- Terminal 100 provides the acquired digital business card to another person (for example, the first user's business partner). More specifically, terminal 100 provides the digital business card to a device such as a smartphone owned by the other person. The other person's device verifies the acquired digital business card and notifies the user (the first user's business partner) of the results. In this way, terminal 100 is able to verify a business card received by a user other than the owner of terminal 100.
- the information processing system includes at least one or more groups or organizations.
- the organizations included in the information processing system include, for example, companies, local governments, non-profit organizations, educational institutions, etc. These groups or organizations issue business cards that certify the identity of members belonging to the organizations, etc.
- a description will be given taking a company as an example of a group or organization that issues business cards.
- the information processing system includes a server device 10 managed and operated by each company that issues business cards.
- the server device 10 controls and manages the company's employees.
- the server device 10 issues electronic business cards (digital business cards) to employees.
- the server device 10 may be installed within the company's premises, or on a network (cloud).
- users carry terminals 20.
- the users operate terminals 20 to access server device 10.
- the users input various information to server device 10 and obtain various information from server device 10 via terminal 20.
- Each device shown in FIG. 3 is connected to a network.
- the server device 10 and the terminal 20 are connected to the network via wired or wireless communication means.
- the configuration of the information processing system shown in FIG. 3 is an example and is not intended to be limiting.
- the information processing system may include multiple server devices 10. Load balancing and redundancy may be achieved by using multiple server devices 10.
- a digital wallet is an electronic information storage service that guarantees information security such as data integrity, reliability, and availability.
- a user installs an application to create a digital wallet on their terminal 20.
- an application to create a digital wallet on their terminal 20.
- the user can store digital content on terminal 20, such as digital business cards, digital employee ID cards, electronic money, identification documents such as passports and driver's licenses, and various tickets such as airline tickets.
- the user's terminal 20 stores digital content such as that shown in Figure 4.
- the digital content stored on the terminal 20 includes official identification documents such as passports and driver's licenses, as well as digital business cards and digital employee ID cards issued by companies.
- terminal 20 When the digital wallet application is launched for the first time, terminal 20 performs identity verification using an identification card issued by a public institution such as a government agency. Terminal 20 also performs identity verification of the user when opening a digital wallet.
- terminal 20 verifies the identity of the person using an identification document that contains the biometric information of the person in question, such as a My Number card or passport.
- Terminal 20 uses the My Number card or passport as a root of trust.
- biometric information examples include data (features) calculated from physical characteristics unique to an individual, such as the face, fingerprint, voiceprint, veins, retina, and iris pattern.
- biometric information may be image data such as a face image or fingerprint image.
- Biometric information may be any information that includes the user's physical characteristics. In this disclosure, we will explain the use of biometric information related to a person's "face” (a face image or features generated from a face image).
- Terminal 20 obtains information about the holder (issuer) of the identification card from the user's identification card. For example, terminal 20 obtains information about the holder of the My Number card from the card's integrated circuit (IC).
- IC integrated circuit
- terminal 20 acquires biometric information (facial image) of the My Number card holder. Terminal 20 internally stores the biometric information read from the My Number card.
- terminal 20 acquires biometric information of the user (the person who opened the digital wallet). For example, terminal 20 acquires and stores a facial image by photographing the user.
- Terminal 20 performs a matching process (authentication process) using the biometric information acquired from the identification card and the user's biometric information. If the authentication process (one-to-one authentication) is successful, terminal 20 opens a digital wallet. Terminal 20 confirms through a matching process (authentication process) using biometric information that the person in whose name the identification card was issued and the user using terminal 20's digital wallet are the same person.
- authentication process authentication process
- biometric information acquired from the identification card and the user's biometric information If the authentication process (one-to-one authentication) is successful, terminal 20 opens a digital wallet. Terminal 20 confirms through a matching process (authentication process) using biometric information that the person in whose name the identification card was issued and the user using terminal 20's digital wallet are the same person.
- the server device 10 acquires information such as name, gender, date of birth, address, biometric information (facial image), employee number, department, and contact information (telephone number, email address, etc.) from a web page for employee registration. Alternatively, a human resources department employee may input the employee's name, gender, etc. into the server device 10.
- the server device 10 When the server device 10 acquires the employee's name, biometric information, etc., it generates an employee ID to identify the employee. The server device 10 associates the generated employee ID with the acquired information and stores them in the employee management database. Details of the employee management database will be described later.
- employee IDs, names, etc. are stored in the employee management database, creating an employee account (employee account).
- a user obtains a digital business card from their company to be stored in their digital wallet.
- the digital wallet application requests the company to issue a digital business card.
- the issuer (company) of the digital business card issues Verifiable Credentials (VCs), the contents of which can be verified online, as the digital business card.
- VCs Verifiable Credentials
- VCs will be referred to as “credential certificates,” and digital business cards issued as VCs will be referred to as “digital business card VCs.”
- the user's terminal 20 Prior to requesting the issuance of a digital business card VCs, the user's terminal 20 generates a pair of public and private keys. The terminal 20 also generates a decentralized identifier (DID). The terminal 20 registers the generated DID (user ID; holder ID) and public key in the blockchain (step S01 in Figure 5).
- DID decentralized identifier
- the user's terminal 20 presents the user ID and requests the issuer of the digital business card VCs (server device 10) to issue the digital business card VCs. Specifically, the terminal 20 sends a "digital business card issuance request" to the server device 10, which includes information identifying the user (e.g., employee number) and the user ID, etc. (step S02).
- terminal 20 transmits the user's personal information (e.g., employee number) to server device 10 of the company that issued the digital business card VCs.
- Terminal 20 may provide the personal information to server device 10 by registering the personal information in a blockchain, or may provide the personal information to server device 10 without using a blockchain. In other words, registering personal information in a blockchain is optional.
- the server device 10 generates and stores the issuer's DID (issuer ID), private key, and public key in advance.
- the server device 10 determines whether the user requesting the issuance of a digital business card VC is eligible to receive the digital business card VC. Specifically, the server device 10 determines whether the user requesting the issuance of a digital business card VC is an employee of the company.
- the server device 10 If the user is eligible to receive a digital business card VC, the server device 10 generates a digital business card VC that includes the issuer ID and the user ID.
- the server device 10 generates digital business card VCs that include metadata such as the type of credential certificate (digital business card), the issuing organization name, and the date and time of issue, as well as the credential information itself, and the issuer's public key information and electronic signature.
- the credential information itself contains specific information certified by the issuer (for example, company name, employee name, facial image, department, contact information, etc.).
- the server device 10 sends the generated digital business card VCs to the terminal 20 of the user (the user who will become the owner of the digital business card VCs; the person requesting the issuance of the digital business card VCs) (digital business card issuance; step S03).
- the server device 10 registers the issuer ID and the generated public key in the blockchain (step S04).
- the terminal 20 stores the received digital business card VCs in its digital wallet.
- VCs Exchange digital business cards
- the user installs a business card management application on the terminal 20.
- the business card management application provides services using digital business card VCs stored in the digital wallet.
- a user can exchange digital business card VCs stored in a digital wallet with another person (e.g., a business partner).
- terminal 20 business card management application
- detects a predetermined operation by the user e.g., pressing the business card exchange button
- terminal 20 signs the digital business card VCs using a private key corresponding to the user's DID (user ID). Terminal 20 then converts the signed digital business card VCs into a two-dimensional barcode.
- the terminal 20 displays the generated two-dimensional barcode.
- the other person's terminal 20 obtains the digital business card VCs by reading the displayed two-dimensional barcode.
- the terminals 20 owned by user A and user B each display a two-dimensional barcode and read the two-dimensional barcode displayed on the other person's terminal 20.
- the terminal 20 decodes the two-dimensional barcode and obtains the digital business card VCs.
- Terminal 20 obtains the issuer ID and user ID from the acquired digital business card VCs of the other party. Furthermore, terminal 20 obtains the public key corresponding to the acquired issuer ID and the public key corresponding to the acquired user ID from the blockchain.
- the terminal 20 verifies the digital business card VCs it receives from the other party. Specifically, the terminal 20 verifies the signature of the owner and the signature of the issuer attached to the digital business card VCs. By verifying these signatures, the terminal 20 confirms that the digital business card VCs it receives from the user (the owner of the digital business card VCs; for example, the business partner) have not been tampered with and that the certificate was issued by a trusted issuer.
- the terminal 20 If the terminal 20 successfully verifies the acquired digital business card VCs, it displays the contents of the acquired digital business card VCs and stores them internally. At that time, the terminal 20 may store the digital business card VCs in association with the date, time, and location at which the digital business card VCs were acquired.
- the terminal 20 may store information relating to the circumstances when the digital business card VCs were acquired, in association with the acquired digital business card VCs. For example, the terminal 20 may store the digital business card VCs in association with the name of the event when the digital business card VCs were exchanged (e.g., the name of a conference or exhibition attended by the user). Specifically, when the terminal 20 acquires a digital business card VC, it references the user's schedule information. If an event is set for the date and time the digital business card was acquired, the terminal 20 acquires the name of the event (e.g., the name of the conference or exhibition) and stores it in association with the acquired digital business card VC.
- the terminal 20 acquires the name of the event (e.g., the name of the conference or exhibition) and stores it in association with the acquired digital business card VC.
- the terminal 20 displays the event name (e.g., the name of the conference or exhibition) along with the digital business card VCs.
- the event name e.g., the name of the conference or exhibition
- the terminal 20 (business card management application) allows the user to view the digital business cards VCs of other people stored therein in response to a predetermined operation by the user (for example, pressing the business card display button). For example, the terminal 20 displays a screen such as that shown in FIG.
- the terminal 20 may utilize the acquired digital business card VCs in various applications.
- the terminal 20 may utilize the acquired digital business card VCs in an application that manages other people's contact information in an address book.
- information obtained from the digital business card VCs e.g., name, company, department, telephone number, email address
- users can treat contacts automatically registered from Digital Business Card VCs in the same way as manually registered contacts. In other words, users can select from their address book the people they want to send emails to, schedule meetings with, or chat with.
- the email application or the like may distinguish between employees who have exchanged digital business cards and those who have not in an address book that manages the contact information of other employees within the company.
- Examples of the terminal 20 include a mobile terminal device such as a smartphone, a mobile phone, a game console, or a tablet, a computer (personal computer, laptop computer), etc.
- the terminal 20 can be any equipment or device that can accept user operations and communicate with the server device 10, etc.
- FIG. 8 is a diagram showing an example of the processing configuration (processing module) of a terminal 20 according to an embodiment of the present disclosure.
- the terminal 20 includes a communication control unit 201, an identity verification unit 202, an acquisition control unit 203, a usage control unit 204, and a storage unit 205.
- the communication control unit 201 is a means for controlling communications with other devices. For example, the communication control unit 201 receives data (packets) from the server device 10. The communication control unit 201 also transmits data to the server device 10. The communication control unit 201 passes data received from other devices to other processing modules. The communication control unit 201 transmits data obtained from other processing modules to other devices. In this way, other processing modules send and receive data to other devices via the communication control unit 201. The communication control unit 201 functions as a receiver that receives data from other devices and as a transmitter that transmits data to other devices.
- the identity verification unit 202 and acquisition control unit 203 implement a digital wallet application.
- the usage control unit 204 implements a business card management application. Detailed explanations of the installation of the digital wallet application and business card management application will be omitted, as application installation is clear to those skilled in the art.
- the identity verification unit 202 is a means for verifying the identity of the creator of a digital wallet.
- the identity verification unit 202 verifies the identity of the creator of the digital wallet using biometric information obtained from the identification card and the biometric information of the creator who opens the digital wallet. More specifically, the identity verification unit 202 verifies that the creator of the digital wallet and the person in whose name the identification card issued by a public institution (the person to whom it is issued) are the same.
- Figure 9 is a flowchart showing an example of the operation of the identity verification unit 202. The operation of the identity verification unit 202 will be explained with reference to Figure 9.
- the identity verification unit 202 obtains information about the identity card holder from the identity card held by the user. For example, the identity verification unit 202 obtains biometric information about the identity card holder from an IC (Integrated Circuit) chip mounted on a My Number card or passport (step S101).
- IC Integrated Circuit
- the identity verification unit 202 obtains the PIN number for the user authentication electronic certificate using a GUI (Graphical User Interface) or the like.
- GUI Graphic User Interface
- the identity verification unit 202 obtains the information written in the MRZ (Machine Readable Zone) printed on the face of the passport using OCR (Optical Character Recognition) technology.
- the identity verification unit 202 reads information from the IC chip using the acquired PIN (four-digit number) and the information written in the MRZ as a password.
- the identity verification unit 202 stores the biometric information (face information, face image) of the holder of the identity card (My Number card, passport, etc.) read from the identity card in the memory unit 205 (step S102).
- the identity verification unit 202 acquires biometric information of the user (user of terminal 20; creator of the digital wallet) (step S103). For example, the identity verification unit 202 prompts the user to take a photo of their own face using a GUI or the like (acquiring a facial image by taking a selfie, so to speak).
- the identity verification unit 202 acquires biometric information from the identification card and, upon acquiring the biometric information of the user operating the device, performs a matching process using the biometric information acquired from the identification card and the user's biometric information (step S104). The identity verification unit 202 determines whether the two pieces of biometric information substantially match.
- the identity verification unit 202 generates feature quantities from each of the two pieces of biometric information (e.g., facial images).
- the identity verification unit 202 extracts the eyes, nose, mouth, etc. from the facial image as feature points. The identity verification unit 202 then calculates the position of each feature point and the distance between each feature point as feature amounts (generating a feature vector consisting of multiple feature amounts).
- the identity verification unit 202 performs a matching process (authentication process) using the two generated feature amounts. Specifically, the identity verification unit 202 calculates the similarity between corresponding face images using the two feature amounts. Based on the result of threshold processing on the calculated similarity, the identity verification unit 202 determines whether the two images are face images of the same person. Note that the similarity can be calculated using a chi-squared distance, Euclidean distance, or the like. The greater the distance, the lower the similarity, and the closer the distance, the higher the similarity.
- the identity verification unit 202 determines that the matching process was successful. If the similarity is equal to or less than the predetermined value, the identity verification unit 202 determines that the matching process failed.
- step S105 If the matching process is successful (step S105, Yes branch), the identity verification unit 202 permits the user to use the digital wallet (permission to use; step S106). In other words, if the authentication process (one-to-one authentication) is successful, the identity verification unit 202 opens the digital wallet.
- the identity verification unit 202 treats the person who was issued the identification card and the user of the terminal 20 as the same person.
- the digital wallet is launched for the first time, it is determined whether the person in the name of the identification card and the user of the terminal 20 are the same person. If the person in the name of the identification card and the person who opened the digital wallet are the same person, the terminal 20 makes the digital wallet application available.
- step S105 If the matching process fails (step S105, No branch), the identity verification unit 202 does not permit the user to use the digital wallet (use denial; step S107). In other words, if the authentication process (one-to-one authentication) fails, the user cannot use the digital wallet (cannot open a digital wallet).
- the identity verification unit 202 determines that identity verification has been successful when the authentication process using the biometric information obtained from the identification card and the biometric information of the creator who opens the digital wallet is successful. If identity verification is successful, the digital wallet is opened.
- the acquisition control unit 203 is a means for controlling the acquisition of credential certificates, including digital business card VCs. For example, the acquisition control unit 203 requests the server device 10 to issue digital business card VCs. The acquisition control unit 203 stores the digital business card VCs acquired from the server device 10 (the user's company) in a digital wallet.
- FIG. 10 is a flowchart showing an example of the operation of the acquisition control unit 203. The operation of the acquisition control unit 203 according to an embodiment of the present disclosure will be described with reference to FIG. 10.
- the acquisition control unit 203 controls the acquisition of digital business card VCs.
- the acquisition control unit 203 generates a public key/private key pair and a user ID (user's DID), which is a distributed identifier.
- the acquisition control unit 203 registers the generated user ID and public key in the blockchain (registering the public key, etc.; step S201).
- the acquisition control unit 203 uses a GUI or the like to acquire the information necessary to request the issuance of a digital business card VC (acquisition of necessary information; step S202).
- the acquisition control unit 203 acquires information (e.g., company name) about the company that has the authority to issue digital business cards VCs.
- the acquisition control unit 203 acquires information (e.g., employee number) that the server device 10 uses to identify the user.
- the acquisition control unit 203 notifies the certificate issuer of the acquired necessary information and user ID. Specifically, the acquisition control unit 203 notifies the server device 10 of information for identifying the person to whom the digital business card VCs will be issued (for example, an employee number) and the user ID. The acquisition control unit 203 sends a "digital business card issuance request" to the server device 10, including the information for identifying the person to whom the digital business card VCs will be issued, the user ID, etc. (step S203).
- the acquisition control unit 203 can refer to table information that associates and stores company names with server device 10 addresses, and identify the address of the server device 10 to which the digital business card issuance request will be sent.
- the acquisition control unit 203 may also sign the information included in the digital business card issuance request using a private key corresponding to the public key registered in the blockchain.
- the acquisition control unit 203 receives a response (positive or negative response) to the digital business card issuance request from the server device 10 (step S204).
- step S205 If a negative response is received indicating that the issuance of the digital business card VCs has failed (step S205, No branch), the acquisition control unit 203 notifies the user that the digital business card VCs has not been issued (notification of non-issuance; step S206).
- the acquisition control unit 203 stores the digital business card VCs included in the affirmative response in the digital wallet (step S207). At that time, the acquisition control unit 203 may notify the user that the digital business card VCs have been issued.
- the acquisition control unit 203 may verify the signature attached to the digital business card VCs acquired from the server device 10. In this case, the acquisition control unit 203 acquires from the blockchain a public key corresponding to the issuer ID written on the digital business card VCs. The acquisition control unit 203 may use the acquired public key to verify the signature attached to the digital business card VCs, and if the verification is successful, store the digital business card VCs in the digital wallet.
- the acquisition control unit 203 operates as a first acquisition means for acquiring digital business card VCs, which are certificates that prove that the first user belongs to a specified organization and whose contents can be verified online.
- the acquisition control unit 203 also stores the digital business card VCs acquired from the user's company in a digital wallet. At that time, if the acquisition control unit 203 successfully verifies the signature of the acquired digital business card VCs, it may store the acquired digital business card VCs in the digital wallet.
- the usage control unit 204 is a means for controlling the use of digital content (credential certificates) stored in the digital wallet. In particular, the usage control unit 204 controls the use of digital business card VCs.
- the usage control unit 204 functions as a providing means and a second acquiring means.
- the usage control unit 204 provides the digital business card VCs of the first user stored internally to the outside.
- the usage control unit 204 acquires the digital business card VCs of the second user and verifies the acquired digital business card of the second user. If the verification of the second user's digital business card is successful, the usage control unit 204 stores the acquired digital business card of the second user.
- the usage control unit 204 controls the exchange of digital business card VCs. Specifically, the usage control unit 204 controls the provision of digital business card VCs stored in the digital wallet to the other party, and the acceptance of digital business card VCs provided by the other party.
- a predetermined operation e.g., pressing the business card exchange button
- the usage control unit 204 When a predetermined operation by the user is detected, the usage control unit 204 generates a two-dimensional barcode based on the digital business card VCs stored in the digital wallet. More specifically, the usage control unit 204 signs the digital business card VCs using a private key corresponding to the user's DID (user ID). The usage control unit 204 converts the signed digital business card VCs into a two-dimensional barcode. The usage control unit 204 displays the two-dimensional barcode generated based on the digital business card VCs.
- DID user ID
- the usage control unit 204 signs the digital business card VCs provided to the other party using the private key (private key corresponding to the user ID) generated when the issuance of the digital business card VCs is requested.
- the usage control unit 204 controls the camera installed on the terminal 20 to read the two-dimensional barcode displayed on the other party's terminal 20.
- the usage control unit 204 decodes the read two-dimensional barcode and obtains the digital business card VCs.
- the usage control unit 204 verifies the acquired digital business card VCs. Specifically, the usage control unit 204 reads the issuer ID and user ID from the digital business card VCs. The usage control unit 204 obtains the public key corresponding to the read issuer ID from the blockchain. Similarly, the usage control unit 204 obtains the public key corresponding to the read user ID from the blockchain.
- the usage control unit 204 verifies the signature of the holder (the party exchanging the digital business card VCs) and the signature of the issuer attached to the digital business card VCs.
- the usage control unit 204 If verification of the other party's digital business card VC fails, the usage control unit 204 notifies the user of this. At that time, the usage control unit 204 may also notify the user that the acquired digital business card VC may be a counterfeit business card.
- the usage control unit 204 displays the acquired digital business card VCs. Furthermore, the usage control unit 204 stores the acquired digital business card VCs in the storage unit 205.
- the usage control unit 204 may store the acquired digital business card VCs (digital business card VCs of the other party with whom the business card was exchanged) in association with the acquisition date, time, and location of the digital business card VCs.
- the usage control unit 204 receives GPS signals from GPS (Global Positioning System) satellites to perform positioning and calculates location information including the latitude, longitude, and altitude of the terminal 20.
- GPS Global Positioning System
- the usage control unit 204 identifies the acquisition location where the business card exchange took place from the location information (X, Y, Z coordinates). For example, the usage control unit 204 identifies the acquisition location by referring to table information that associates and stores location information with the name of the acquisition location.
- the usage control unit 204 may only perform either control to provide digital business card VCs to the other party or control to accept digital business card VCs provided by the other party.
- the usage control unit 204 provides the first user's digital business card VCs to others by displaying a two-dimensional barcode generated based on the digital business card stored in the digital wallet. Furthermore, the usage control unit 204 stores digital business card VCs obtained from the other party that have been successfully verified, in association with the acquisition date, time, and location of the successfully verified digital business card VCs.
- the usage control unit 204 may control not only the exchange of digital business card VCs, but also other uses of the digital business card VCs. For example, in response to a predetermined operation by the user (for example, pressing the business card display button), the usage control unit 204 allows the user to view the digital business card VCs stored in the storage unit 205. For example, the usage control unit 204 displays a screen such as that shown in FIG. 7.
- the usage control unit 204 may call that contact.
- the usage control unit 204 may set that email address as the email destination and launch an email application.
- the usage control unit 204 may perform a search for digital business card VCs. For example, the usage control unit 204 may extract digital business card VCs that match the acquisition date and time and acquisition location specified by the user, and display the extracted digital business card VCs.
- the usage control unit 204 may control digital business card VCs that have been accepted due to successful verification so that they can be used by applications that use address books. In other words, the usage control unit 204 may allow acquired digital business card VCs to be used by applications other than the business card management application.
- digital business card VCs may be handed over to an email application, a meeting scheduling application, a communication application, etc. using a data sharing method within a smartphone called DeepLink.
- the email application, etc. may obtain the name, company name, contact information, etc. of the business card holder from the obtained digital business card VCs, and add the obtained name, etc. to an address book.
- the email application or the like may perform grouping based on the holders of the digital business card VCs.
- the email application or the like may create multiple groups, such as a group of employees working at the same company and a group of employees working at other companies, and use these groups to manage the digital business card VCs.
- the storage unit 205 is a means for storing information necessary for the operation of the terminal 20.
- the storage unit 205 stores the user's biometric information acquired when the digital wallet is opened, and also stores digital business card VCs, etc., in the digital wallet.
- [Server device] 11 is a diagram illustrating an example of a processing configuration (processing module) of the server device 10 according to the embodiment of the present disclosure.
- the server device 10 includes a communication control unit 301, an employee management unit 302, a digital business card control unit 303, and a storage unit 304.
- the communication control unit 301 is a means for controlling communication with other devices. For example, the communication control unit 301 receives data (packets) from the terminal 20. The communication control unit 301 also transmits data to the terminal 20. The communication control unit 301 passes data received from other devices to other processing modules. The communication control unit 301 transmits data obtained from other processing modules to other devices. In this way, other processing modules send and receive data to other devices via the communication control unit 301. The communication control unit 301 functions as a receiver that receives data from other devices and as a transmitter that transmits data to other devices.
- the employee management unit 302 is a means for managing employees belonging to one company (enterprise).
- the employee management unit 302 acquires the employee's name, gender, date of birth, address, biometric information (facial image), employee number, department, contact information (telephone number, email address, etc.) from a web page for employee registration, etc.
- the employee management unit 302 generates an employee ID for identifying the employee.
- the employee ID may be any information that can uniquely identify the employee.
- the employee management unit 302 may assign a unique value each time an employee is registered and use this as the employee ID.
- the employee management unit 302 stores the generated employee ID, the acquired employee name, biometric information (facial image), etc. in the employee management database (see Figure 12). Note that the employee management database shown in Figure 12 is an example and is not intended to limit the items to be stored.
- the employee management unit 302 deletes the account (entry in the employee management database) of the resigned employee. Furthermore, the employee management unit 302 executes processing to invalidate the digital business card VCs issued to the resigned employee. Specifically, the employee management unit 302 controls the registration of the electronic certificate for verifying the signature issued to the resigned employee in a revocation list.
- the digital business card control unit 303 is a means for executing control related to digital business card VCs. For example, the digital business card control unit 303 issues digital business card VCs to employees. The digital business card control unit 303 processes a "digital business card issuance request" received from the terminal 20.
- the digital business card control unit 303 searches the employee management database using information included in the digital business card issuance request to identify the recipient (e.g., employee number) as a key.
- the digital business card control unit 303 sends a negative response to the terminal 20 indicating that the issuance of the digital business card VCs has failed.
- the digital business card control unit 303 If the search is successful, the digital business card control unit 303 generates a digital business card VC using the information stored in the employee management database.
- the digital business card control unit 303 generates a digital business card VC that includes the issuer ID and user ID (the DID of the person to whom the certificate is issued; the user ID included in the digital business card issuance request).
- the digital business card control unit 303 generates digital business card VCs as credential certificates (VCs) that contain metadata including the type of credential certificate, the name of the issuing organization, the date and time of issue, etc., the credential information itself, and the issuer's public key information and electronic signature.
- the credential information itself includes the company name, the name, facial image, department, contact information, etc. of the person to whom the digital business card VC is issued.
- the electronic signature attached to the digital business card VC is issued using a private key corresponding to the issuer ID generated in advance.
- the digital business card control unit 303 sends the generated digital business card VCs to the terminal 20. Specifically, the digital business card control unit 303 sends an acknowledgement including the digital business card VCs to the terminal 20. Furthermore, the digital business card control unit 303 registers the issuer ID, public key, etc., generated in advance, in the blockchain.
- the memory unit 304 is a means for storing information necessary for the operation of the server device 10.
- FIG. 13 is a sequence diagram showing an example of the operation of an information processing system according to an embodiment of the present disclosure. The operation of the information processing system according to the first embodiment for issuing digital business cards (VCs) will be described with reference to FIG. 13.
- VCs digital business cards
- Terminal 20 generates a public key, a private key, and a user ID, and registers the user ID and public key in the blockchain (step S21).
- the terminal 20 sends a digital business card issuance request including the above user ID to the server device 10 (step S22).
- the server device 10 generates qualification information for the user (the person to whom the digital business card VCs are issued) and generates a digital business card VC that includes the generated qualification information (step S23).
- the server device 10 generates a digital business card VC that includes the user ID and issuer ID and is digitally signed.
- the server device 10 transmits the generated digital business card VCs to the terminal 20 (step S24).
- the terminal 20 stores the digital business card VCs in the digital wallet (step S25).
- a VP Very Presentation
- a portion of the digital business card VC issued by the user's company may be provided by the user (holder) to the counterparty (e.g., a business partner) as a verifiable presentation.
- a user may decide which items to include in a digital business card VP depending on the person with whom they are exchanging business cards. For example, if the person is an important business partner, the user may provide the other party with a digital business card VP that includes all of the information included in the digital business card VCs. On the other hand, if there are doubts about the other party's identity, the user may provide the other party with a digital business card VP that includes the company name, name, and email address, but does not include a facial image. In other words, the terminal 20 may achieve "selective minimal disclosure" using VP (verifiable presentation).
- the issuer of the digital business card VCs (the employee's company) separates the data to be subject to selective minimal disclosure from the data set and calculates the hash value of the separated data.
- the server device 10 embeds the hash value of the separated data in the above-mentioned data set.
- the server device 10 signs the entire data set, including the hash value of the separated data, and generates the digital business card VCs.
- the usage control unit 204 of the terminal 20 displays a GUI that allows the user to select the items to provide to the party from among the multiple items listed in the digital business card VCs. For example, the usage control unit 204 uses a GUI such as that shown in FIG. 14 to obtain the items in the digital business card VCs that the user is permitted to provide to the party.
- the terminal 20 converts the digital business card VP, which includes the selected items and is signed with the user's private key, into a two-dimensional barcode and displays the converted two-dimensional barcode.
- the usage control unit 204 of the terminal 20 that decodes the two-dimensional barcode and obtains the digital business card VP verifies the signature of the digital business card VP in the same way as with digital business card VCs, and if the verification is successful, accepts the digital business card VP.
- the usage control unit 204 of the terminal 20 generates a verifiable presentation (digital business card VP) that includes items selected by the first user from among multiple items included in the first user's digital business card VCs.
- the usage control unit 204 provides the generated verifiable presentation to the outside.
- the terminal 20 may create a new digital business card VP from some of the information contained in the digital business card VCs and provide the created digital business card VP to the other party.
- the terminal 20 may allow the user to select the information (items) to provide to the other party from the information contained in the digital business card VCs. The user can decide the items to include in the digital business card VP depending on the other party and the situation.
- the server device 10 issues digital business card VCs containing common items to each employee.
- the digital business card control unit 303 of the server device 10 may issue digital business card VCs containing information specific to the person to whom the card is issued (the employee).
- the digital business card control unit 303 may generate digital business card VCs containing information about the employee's qualifications, information about training courses taken both inside and outside the company, and information about awards received both inside and outside the company.
- the digital business card control unit 303 generates a digital business card VC that includes the qualification information, etc.
- the terminal 20 acquires digital business card VCs and stores them in the digital wallet.
- the terminal 20 may acquire other credentials and store them in the digital wallet.
- the information processing system may include a certificate issuer that issues credential certificates different from digital business cards VCs.
- a certificate issuer is an entity that issues certificates to users. More specifically, a certificate issuer is an organization or the like that has the authority to issue certificates that certify a user's "qualifications.” For example, a certificate issuer issues certificates that certify a user's identity, certificates that certify a user's affiliation (or past affiliation), certificates that certify a user's abilities (qualifications), etc.
- certificate issuer For example, a public institution that issues identification documents such as driver's licenses, passports, and My Number cards would be considered a certificate issuer. Alternatively, an institution or association that issues certificates certifying qualifications or language proficiency required for a specific job would be considered a certificate issuer.
- Each certificate issuer has a server with functions equivalent to the company's server device 10.
- the certificate issuer's server issues a credential certificate that certifies the qualifications held by the user.
- the terminal 20 stores the credential certificate obtained from the certificate issuer's server in its digital wallet.
- the terminal 20 may also provide the other party with the credential certificate corresponding to the qualification information.
- the usage control unit 204 obtains a credential certificate that certifies the language ability from the digital wallet.
- the usage control unit 204 generates a two-dimensional barcode to be presented to the other party using the digital business card VCs and the credential certificate corresponding to the qualification information included in the digital business card VCs.
- the usage control unit 204 provides the generated two-dimensional barcode to the other party.
- the usage control unit 204 may provide a credential certificate corresponding to the information regarding the qualifications to an external party along with the first user's digital business card VCs.
- the terminal 20 may provide the other party with a credential certificate that guarantees the authenticity of some of the information contained in the digital business card VCs.
- the other party's terminal 20 may then verify the acquired credential certificate (the credential certificate corresponding to the qualification information) and determine whether or not to accept the digital business card VCs based on the results.
- a user may use the digital business card VC stored in the digital wallet as a certificate of entry to an area where entry is restricted. For example, when a user enters a VIP (Very Important Person) room or a security room, the digital business card VC may be presented to a device that controls entry to the VIP room or the like.
- VIP Very Important Person
- the door to the restricted entry area is connected to the authentication terminal 30.
- a user attempting to enter the restricted entry area operates the terminal 20 to display their digital business card VC (displaying a two-dimensional barcode generated based on the digital business card VC).
- the user presents the two-dimensional barcode displayed on the terminal 20 to the authentication terminal 30.
- the authentication terminal 30 acquires the digital business card VC from the presented two-dimensional barcode. The authentication terminal 30 verifies the acquired digital business card VC. If the digital business card VC is successfully verified, the authentication terminal 30 determines whether the user presenting the digital business card VC has the authority to enter the restricted entry area.
- the authentication terminal 30 determines whether the user has the authority to enter the restricted entry area based on the business card holder's job title, department, qualification information, etc. obtained from the digital business card VCs.
- the authentication terminal 30 opens the door. If the user does not have authority to enter the restricted entry area, the authentication terminal 30 does not open the door.
- the terminal 20 may present the digital business card VCs along with a credential certificate corresponding to the credential information to the authentication terminal 30.
- the authentication terminal 30 may open the door if the digital business card VCs and credential certificate are each successfully verified and the user has the authority to enter the restricted entry area.
- Digital business card VCs acquired by a user from others may be shared within the company.
- the usage control unit 204 of the terminal 20 successfully verifies the digital business card VC acquired from others, it transmits information identifying the user (e.g., employee number) and the acquired digital business card VC to the server device 10.
- the digital business card control unit 303 of the server device 10 identifies the sender of the digital business card VCs based on information identifying the user (employee number).
- the digital business card control unit 303 may also send the acquired digital business card VCs to employees other than the sender (email addresses of each employee registered in the employee management database).
- the digital business card control unit 303 may determine the destination of digital business card VCs in accordance with a predetermined policy.
- the policy may be set to "send digital business cards to employees in the same department" or "when a digital business card obtained by a department manager is acquired, the digital name is sent to employees at the department manager level or above.”
- the server device 10 may set the disclosure scope of the digital business card VCs when generating the digital business card VCs.
- the digital business card control unit 303 sets disclosure scopes such as "sharing prohibited,” “sharing permitted only within the same department,” and “no sharing restrictions” for the digital business card VCs (describe this in the main body of the qualification information).
- the user may set the disclosure scope for their own digital business card VCs.
- the usage control unit 204 may obtain the user's desired disclosure scope using a GUI.
- the server device 10 When the server device 10 receives digital business card VCs from users, it may distribute the received digital business card VCs (share them within the company) according to the disclosure scope set for the digital business card VCs. In the above example, digital business card VCs set as "no sharing" will not be sent to anyone. In contrast, digital business card VCs set as "no sharing restrictions" will be sent to each employee.
- the usage control unit 204 of the terminal 20 may transmit successfully verified digital business card VCs to a server device 10 operated by a specified organization, thereby making it possible for the second user's digital business card VCs to be shared within the specified organization.
- digital business card VCs acquired by a user may be shared with others.
- the digital business card VCs may be shared in accordance with a predetermined policy.
- a disclosure range may be set for the digital business card VCs.
- the disclosure range of the digital business card VCs may be managed by the issuer (server device 10) or owner (terminal 20) of the digital business card VCs.
- the digital business card VCs are exchanged using two-dimensional barcodes.
- the digital business card VCs may be exchanged by other means.
- the terminal 20 may exchange the digital business card VCs using a short-range wireless communication means such as Bluetooth (registered trademark) or NFC (Near Field Communication).
- the terminal 20 may perform identity verification of the counterparty.
- the counterparty's terminal 20 converts the digital business card VC and the user's biometric information acquired when the digital wallet was opened to generate a two-dimensional barcode.
- the terminal 20 acquires the digital business card VCs and the other party's biometric information from the two-dimensional barcode.
- the usage control unit 204 of the terminal 20 photographs the other party (the person exchanging business cards in front of the other party) before or after verifying the digital business card VCs, and acquires the other party's biometric information.
- the usage control unit 204 may make successful identity verification using the biometric information acquired by photographing and the biometric information acquired along with the digital business card VCs a requirement for accepting the digital business card VCs.
- the terminal 20 stores digital business card VCs issued as credential certificates in a digital wallet.
- the terminal 20 provides the digital business card VCs stored in the digital wallet to the other party.
- the other party's terminal 20 verifies the acquired digital business card VCs, and if the verification is successful, accepts the acquired digital business card VCs.
- the terminal 20 provides the other party with the digital business card VCs it has acquired from the user's company.
- the other party's terminal 20 can confirm that the digital business card VCs has not been tampered with and that they have been issued by a legitimate certificate issuer (the user's company).
- the user can trust the other party and the contents of the acquired digital business card VCs.
- Figure 16 is a diagram showing an example of the hardware configuration of terminal 20.
- the terminal 20 can be configured as an information processing device (a so-called computer) and has the configuration shown in FIG. 16.
- the terminal 20 has a processor 311, memory 312, an input/output interface 313, and a communication interface 314.
- the components such as the processor 311 are connected by an internal bus or the like and are configured to be able to communicate with each other.
- the terminal 20 may include hardware not shown, and may not have an input/output interface 313 as necessary.
- the number of processors 311, etc. included in the terminal 20 is not intended to be limited to the example shown in FIG. 16; for example, the terminal 20 may include multiple processors 311.
- Processor 311 is, for example, a programmable device such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or DSP (Digital Signal Processor). Alternatively, processor 311 may be a device such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit). Processor 311 executes various programs including an operating system (OS).
- OS operating system
- Memory 312 may be RAM (Random Access Memory), ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc. Memory 312 stores the OS program, application programs, and various data.
- RAM Random Access Memory
- ROM Read Only Memory
- HDD Hard Disk Drive
- SSD Solid State Drive
- the input/output interface 313 is an interface for a display device and an input device (not shown).
- the display device is, for example, an LCD display.
- the input device is, for example, a device that accepts user operations, such as a keyboard or mouse.
- the communication interface 314 is a circuit, module, etc. that communicates with other devices.
- the communication interface 314 includes a NIC (Network Interface Card), etc.
- the functions of terminal 20 are realized by various processing modules.
- the processing modules are realized by processor 311 executing programs stored in memory 312.
- the programs can be recorded on a computer-readable storage medium.
- the storage medium can be a non-transitory medium such as a semiconductor memory, hard disk, magnetic recording medium, or optical recording medium.
- the present invention can also be embodied as a computer program product.
- the programs can be downloaded via a network or updated using a storage medium that stores the programs.
- the processing modules can be realized by semiconductor chips.
- server device 10 can also be configured using an information processing device, just like the terminal 20, and its basic hardware configuration is no different from that of the terminal 20, so a description thereof will be omitted.
- Terminal 20 which is an information processing device, is equipped with a computer, and the functions of terminal 20 can be realized by having the computer execute a program. Furthermore, terminal 20 executes a control method for terminal 20 using the program.
- server device 10 is equipped with a computer, and the functions of server device 10 can be realized by having the computer execute a program. Furthermore, server device 10 executes a control method for server device 10 using the program.
- the terminal 20 provides digital business card VCs to others in response to user operation.
- the terminal 20 may also provide digital business card VCs stored in the digital wallet in response to a request from the other party.
- the terminal 20 may send a signed digital business card VC to the other party's terminal 20.
- the terminal 20 may discard the digital business card VCs, or it may store them separately from other digital business card VCs that have been successfully verified.
- the terminal 20 may store a history of the verification results of digital business card VCs.
- the terminal 20 may store digital business card VCs that were successfully verified and digital business card VCs that were unsuccessfully verified, allowing for subsequent verification of digital business card VCs.
- the terminal 20 when a request for issuance of a digital business card is made, transmits an employee number to the server device 10 as information for identifying the user.
- the terminal 20 may also transmit the user's biometric information (facial image) to the server device 10 as information for identifying the user.
- the server device 10 may identify the user who wishes to be issued a digital business card VCs by performing a matching process (authentication process) using the biometric information.
- the certificate issuer's server device 10 issues a credential certificate that does not require a certification authority for certificate verification.
- the server device 10 may also issue a certificate that requires a certification authority (a certificate based on a public key infrastructure).
- identity verification confirming that the identity card holder and the digital wallet creator match
- identity verification can also be performed using an electronic certificate stored in the identification card.
- the terminal 20 obtains an electronic certificate (electronic signature certificate, electronic user certificate) from the My Number card held by the user.
- the terminal 20 then sends the obtained electronic signature to a certification authority (J-LIS; Japan Agency for Local Authority Information Systems) and requests the certification authority to verify the validity of the electronic certificate. If the electronic certificate is valid, the terminal 20 determines that identity verification has been successful.
- J-LIS Japan Agency for Local Authority Information Systems
- terminal 20 may be implemented in another device, apparatus, etc. More specifically, the above-described “identity verification unit (identity verification means)” and “acquisition control unit (acquisition control means)” may be implemented in any of the devices included in the system.
- data transmitted between each device may be encrypted. Users' personal information and other information is transmitted between these devices, and in order to properly protect this information, it is desirable that encrypted data be transmitted and received.
- each embodiment may be used alone or in combination. For example, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of one embodiment with other configurations.
- a terminal comprising:
- Appendix 2 The terminal described in Appendix 1, wherein the providing means provides the digital business card of the first user to another person by displaying a two-dimensional barcode generated based on the acquired digital business card.
- Appendix 3 The terminal described in Appendix 2, wherein the providing means, when information regarding the qualifications held by the first user is included in the first user's digital business card, provides a credential certificate corresponding to the information regarding the qualifications to an external party together with the first user's digital business card.
- Appendix 4 A terminal described in any one of Appendixes 1 to 3, wherein the providing means generates a verifiable presentation including items selected by the first user from a plurality of items included in the first user's digital business card, and provides the generated verifiable presentation to an external party.
- the terminal described in Appendix 1 further comprises a second acquisition means for acquiring the digital business card of a second user, verifying the acquired digital business card of the second user, and storing the acquired digital business card of the second user if the verification of the digital business card of the second user is successful.
- Appendix 8 The terminal described in Appendix 7, wherein the second acquisition means transmits the successfully verified digital business card to a server device operated by the specified organization, thereby enabling the second user's digital business card to be shared within the specified organization.
- Appendix 9 a first acquisition step of acquiring a digital business card that is a certificate that proves that the first user belongs to a predetermined organization and whose contents can be verified online; a providing step of providing the acquired digital business card to an external party;
- a method for controlling a terminal comprising:
- Appendix 11 A terminal control method as described in Appendix 10, wherein the providing step provides, if information regarding the qualifications held by the first user is included in the first user's digital business card, a credential certificate corresponding to the information regarding the qualifications to an external party together with the first user's digital business card.
- Appendix 12 A method for controlling a terminal described in any one of Appendices 9 to 11, wherein the providing step generates a verifiable presentation including items selected by the first user from a plurality of items included in the first user's digital business card, and provides the generated verifiable presentation to an external party.
- the terminal control method described in Appendix 9 further includes a second acquisition step of acquiring the digital business card of a second user, verifying the acquired digital business card of the second user, and storing the acquired digital business card of the second user if the verification of the digital business card of the second user is successful.
- Appendix 16 The terminal control method described in Appendix 15, wherein the second acquisition process transmits the successfully verified digital business card to a server device operated by the specified organization, thereby enabling the second user's digital business card to be shared within the specified organization.
- the computer installed in the device a first acquisition process for acquiring a digital business card that is a certificate that proves that the first user belongs to a predetermined organization and whose contents can be verified online; a providing process for providing the acquired digital business card to an external party; A computer-readable storage medium that stores a program for executing the above.
- Appendix 18 A storage medium as described in Appendix 17, wherein the providing process provides the digital business card of the first user to another person by displaying a two-dimensional barcode generated based on the acquired digital business card.
- Appendix 19 The storage medium described in Appendix 18, wherein the provision process provides, if information regarding the qualifications held by the first user is included in the first user's digital business card, a credential certificate corresponding to the information regarding the qualifications to an external party together with the first user's digital business card.
- Appendix 20 A storage medium described in any one of Appendices 17 to 19, wherein the providing process generates a verifiable presentation including items selected by the first user from a plurality of items included in the first user's digital business card, and provides the generated verifiable presentation to an external party.
- Appendix 21 The storage medium described in Appendix 17 further executes a second acquisition process, which acquires the digital business card of a second user, verifies the acquired digital business card of the second user, and stores the acquired digital business card of the second user if the verification of the digital business card of the second user is successful.
- Appendix 24 The storage medium described in Appendix 23, wherein the second acquisition process transmits the successfully verified digital business card to a server device operated by the specified organization, thereby enabling the second user's digital business card to be shared within the specified organization.
- Server device 20
- Terminal 30
- Authentication terminal 100
- First acquisition means 102
- Provision means 201
- Communication control unit 202
- Personal identification unit 203
- Acquisition control unit 204
- Usage control unit 205
- Storage unit 301
- Communication control unit 302
- Employee management unit 303
- Digital business card control unit 304
- Storage unit 311 Processor 312 Memory 313 Input/output interface 314 Communication interface
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
名刺を受領した相手方が当該受領した名刺を検証可能とする端末を提供する。端末は、第1の取得手段と、提供手段と、を備える。第1の取得手段は、第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する。提供手段は、取得されたデジタル名刺を外部に提供する。
Description
本発明は、端末、端末の制御方法及び記憶媒体に関する。
個人情報の開示に関する技術が存在する。
例えば、特許文献1には、所有者が特定の属性を有することを示す個人情報の開示を制御する、と記載されている。特許文献1の属性管理情報は、複数の属性情報を含み、且つ、複数の属性情報のうち1つの属性情報が示す属性の範囲が、その属性情報よりも上位の属性情報が示す属性の範囲に含まれる階層構造を有する。コンピュータは、個人情報所有者が特定の属性を有することを示す個人情報の開示を要求する開示要求を受け付ける。コンピュータは、属性管理情報において、第1属性情報が示す第1属性と、第1属性情報よりも上位の第2属性情報が示す第2属性とが、特定の属性に対応するか否かを判定する判定処理を行う。第1属性情報は、個人情報所有者が保有する1つ又は複数の個人情報それぞれに対応する。コンピュータは、判定処理の結果に基づいて、1つ又は複数の個人情報の何れかを開示対象の個人情報として選択する。
ビジネスの場において、当事者同士による名刺交換が行われる。ここで、紙媒体の名刺は偽造が容易であり、名刺の受領者が相手方から取得した名刺の信憑性を検証することは困難である。とりわけ、名刺を交換した直後に、受領者が受領した名刺の信憑性を検証することは難しい。
本発明は、名刺を受領した相手方が当該受領した名刺を検証可能とすることに寄与する、端末、端末の制御方法及び記憶媒体を提供することを主たる目的とする。
本発明の第1の視点によれば、第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得手段と、前記取得されたデジタル名刺を外部に提供する、提供手段と、を備える、端末が提供される。
本発明の第2の視点によれば、第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得工程と、前記取得されたデジタル名刺を外部に提供する、提供工程と、を備える、端末の制御方法が提供される。
本発明の第3の視点によれば、端末に搭載されたコンピュータに、第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得処理と、前記取得されたデジタル名刺を外部に提供する、提供処理と、を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体が提供される。
本発明の各視点によれば、名刺を受領した相手方が当該受領した名刺を検証可能とすることに寄与する、端末、端末の制御方法及び記憶媒体が提供される。なお、本発明の効果は上記に限定されない。本発明により、当該効果の代わりに、又は当該効果と共に、他の効果が奏されてもよい。
はじめに、一実施形態の概要について説明する。なお、この概要に付記した図面参照符号は、理解を助けるための一例として各要素に便宜上付記したものであり、この概要の記載はなんらの限定を意図するものではない。また、特段の釈明がない場合には、各図面に記載されたブロックはハードウェア単位の構成ではなく、機能単位の構成を表す。各図におけるブロック間の接続線は、双方向及び単方向の双方を含む。一方向矢印については、主たる信号(データ)の流れを模式的に示すものであり、双方向性を排除するものではない。なお、本明細書及び図面において、同様に説明されることが可能な要素については、同一の符号を付することにより重複説明が省略され得る。
一実施形態に係る端末100は、第1の取得手段101と、提供手段102と、を備える(図1参照)。第1の取得手段101は、第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する(図2のステップS1)。提供手段102は、取得されたデジタル名刺を外部に提供する(ステップS2)。
端末100は、所有者(第1の利用者)を名義人とする名刺であって、内容の検証がオンラインで可能なデジタル名刺を取得する。端末100は、取得したデジタル名刺を他者(例えば、第1の利用者の商談相手)に提供する。より具体的には、端末100は、他者が所持するスマートフォン等の端末にデジタル名刺を提供する。他者の端末は、取得したデジタル名刺を検証し、その結果を利用者(第1の利用者の商談相手)に通知する。このように、端末100は、端末100の所持者とは異なる利用者が受領した名刺を検証することを実現する。
以下に具体的な実施形態について、図面を参照してさらに詳しく説明する。
[第1の実施形態]
第1の実施形態について、図面を用いてより詳細に説明する。
第1の実施形態について、図面を用いてより詳細に説明する。
[システムの構成]
第1の実施形態に係る情報処理システムには、少なくとも1以上の団体、組織が含まれる。情報処理システムに含まれる組織には、例えば、企業、自治体、非営利団体、教育機関等が含まれる。これらの団体、組織は、組織等に所属する構成員の身分を証明する名刺を発行する。第1の実施形態では、名刺を発行する団体、組織として企業を例にとり説明を行う。
第1の実施形態に係る情報処理システムには、少なくとも1以上の団体、組織が含まれる。情報処理システムに含まれる組織には、例えば、企業、自治体、非営利団体、教育機関等が含まれる。これらの団体、組織は、組織等に所属する構成員の身分を証明する名刺を発行する。第1の実施形態では、名刺を発行する団体、組織として企業を例にとり説明を行う。
図3に示すように、情報処理システムには、名刺を発行する各企業によって管理、運営されるサーバ装置10が含まれる。サーバ装置10は、自社の社員に関する制御や管理等を行う。とりわけ、サーバ装置10は、社員に対して電子的な名刺(デジタル名刺)を発行する。サーバ装置10は、企業の建物内に設置されていてもよいし、ネットワーク上(クラウド上)に設置されていてもよい。
また、利用者(社員)は、端末20を所持する。利用者は、端末20を操作してサーバ装置10にアクセスする。利用者は、端末20を介してサーバ装置10に種々の情報を入力したり、サーバ装置10から種々の情報を取得したりする。
図3に示す各装置は、ネットワークに接続されている。具体的には、サーバ装置10及び端末20は、有線又は無線の通信手段によりネットワークに接続されている。
図3に示す情報処理システムの構成は例示であって、その構成を限定する趣旨ではない。例えば、情報処理システムには複数のサーバ装置10が含まれていてもよい。複数のサーバ装置10により負荷分散や冗長化が実現されてもよい。
[概略動作]
続いて、第1の実施形態に係る情報処理システムの概略動作について説明する。
続いて、第1の実施形態に係る情報処理システムの概略動作について説明する。
<デジタルウォレットの準備>
利用者の端末20は、デジタルウォレット機能を備える。デジタルウォレットは、データの完全性、信頼性、可用性などの情報セキュリティ性が担保された、電子情報保存サービスである。
利用者の端末20は、デジタルウォレット機能を備える。デジタルウォレットは、データの完全性、信頼性、可用性などの情報セキュリティ性が担保された、電子情報保存サービスである。
利用者は、所持する端末20にデジタルウォレットを実現するためのアプリケーションをインストールする。利用者は、デジタルウォレットを端末20に開設することで、デジタル名刺、デジタル社員証、電子マネー、パスポートや運転免許証等の身分証明書、航空券等の各種チケット等のデジタルコンテンツを端末20に保管できる。
例えば、利用者の端末20は、図4に示すようなデジタルコンテンツを保管する。端末20に格納されるデジタルコンテンツのなかには、パスポート、運転免許証等の公的な身分証明書や企業が発行したデジタル名刺、デジタル社員証等が含まれる。
端末20は、デジタルウォレットアプリケーションの初回起動時に、行政機関等の公的機関から発行された身分証明書を使った本人確認を行う。端末20は、デジタルウォレットの開設時に利用者の本人確認を行う。
例えば、端末20は、マイナンバーカード、パスポートといった名義人の生体情報が記載された身分証明書を使って本人確認を行う。端末20は、マイナンバーカードやパスポートを信頼の基点(Root of Trust)として用いる。
なお、生体情報には、例えば、顔、指紋、声紋、静脈、網膜、瞳の虹彩の模様(パターン)といった個人に固有の身体的特徴から計算されるデータ(特徴量)が例示される。あるいは、生体情報は、顔画像、指紋画像等の画像データであってもよい。生体情報は、利用者の身体的特徴を情報として含むものであればよい。本願開示では、人の「顔」に関する生体情報(顔画像又は顔画像から生成された特徴量)を用いる場合について説明する。
端末20は、利用者の身分証明書から当該身分証明書の名義人(被発行者)に関する情報を取得する。例えば、端末20は、マイナンバーカードのIC(Integrated Circuit)から当該マイナンバーカードの名義人に関する情報を取得する。
具体的には、端末20は、マイナンバーカードの名義人の生体情報(顔画像)を取得する。端末20は、マイナンバーカードから読み出した生体情報を内部に記憶する。
さらに、端末20は、利用者(デジタルウォレットの開設者)の生体情報を取得する。例えば、端末20は、利用者を撮影することで顔画像を取得し、記憶する。
端末20は、身分証明書から取得した生体情報と利用者の生体情報を使った照合処理(認証処理)を実行する。端末20は、認証処理(1対1認証)に成功すると、デジタルウォレットを開設する。端末20は、身分証明書の発行を受けた名義人と端末20のデジタルウォレットを利用する利用者が同一人物であることを、生体情報を使った照合処理(認証処理)により確認する。
<アカウントの生成>
企業に入社すると、社員は、社員登録を行う。社員は、端末20を操作してサーバ装置10にアクセスする。
企業に入社すると、社員は、社員登録を行う。社員は、端末20を操作してサーバ装置10にアクセスする。
サーバ装置10は、社員登録のためのウェブページ等において、氏名、性別、生年月日、住所、生体情報(顔画像)、社員番号、所属部署、連絡先(電話番号、メールアドレス等)等を取得する。あるいは、人事部の担当者等が社員の氏名、性別等をサーバ装置10に入力してもよい。
サーバ装置10は、社員の氏名、生体情報等を取得すると、当該社員を識別するための社員IDを生成する。サーバ装置10は、生成した社員IDと取得した情報を対応付けて社員管理データベースに記憶する。社員管理データベースの詳細は後述する。
社員IDや氏名等が社員管理データベースに記憶されることで、社員のアカウント(社員アカウント)が生成される。
<デジタル名刺の取得>
利用者(社員)は、デジタルウォレットに格納するデジタル名刺を所属企業から取得する。具体的には、デジタルウォレットアプリケーションは、社員が所属する企業に対してデジタル名刺の発行要求を行う。デジタル名刺の発行者(企業)は、内容の検証がオンラインで可能なVCs(Verifiable Credentials)をデジタル名刺として発行する。
利用者(社員)は、デジタルウォレットに格納するデジタル名刺を所属企業から取得する。具体的には、デジタルウォレットアプリケーションは、社員が所属する企業に対してデジタル名刺の発行要求を行う。デジタル名刺の発行者(企業)は、内容の検証がオンラインで可能なVCs(Verifiable Credentials)をデジタル名刺として発行する。
以降の説明において、VCsを「クレデンシャル証明書」と表記し、VCsとして発行されたデジタル名刺を「デジタル名刺VCs」と表記する。
デジタル名刺VCsの発行要求に先立ち、利用者の端末20は、公開鍵と秘密鍵のペアを生成する。また、端末20は、分散型識別子(DID;Decentralized Identifier)を生成する。端末20は、生成したDID(利用者ID;保有者ID)と公開鍵をブロックチェーンに登録する(図5のステップS01)。
さらに、利用者の端末20は、利用者IDを提示しつつ、デジタル名刺VCsの発行者(サーバ装置10)に対してデジタル名刺VCsの発行を要求する。具体的には、端末20は、利用者を特定する情報(例えば、社員番号)と利用者ID等を含む「デジタル名刺発行要求」をサーバ装置10に送信する(ステップS02)。
このように、端末20は、ステップS02において、利用者の個人情報(例えば、社員番号)をデジタル名刺VCsの発行者である企業のサーバ装置10に送信する。端末20は、個人情報をブロックチェーンに登録することで個人情報をサーバ装置10に提供してもよいし、ブロックチェーンを用いずに個人情報をサーバ装置10に提供してもよい。即ち、個人情報のブロックチェーンへの登録は任意である。
なお、サーバ装置10は、事前に発行者のDID(発行者ID)、秘密鍵及び公開鍵を生成し、記憶する。
デジタル名刺発行要求を受信すると、サーバ装置10は、デジタル名刺VCsの発行を要求する利用者が当該デジタル名刺VCsの発行を受ける資格を備えているか否か判定する。具体的には、サーバ装置10は、デジタル名刺VCsの発行を希望する利用者が自社に在籍している社員か否か判定する。
利用者がデジタル名刺VCsの発行を受ける資格を備えていれば、サーバ装置10は、発行者IDと利用者IDを含むデジタル名刺VCsを生成する。
具体的には、サーバ装置10は、クレデンシャル証明書の種別(デジタル名刺)、発行組織名、発行日時等を含むメタデータと、資格情報本体と、発行者の公開鍵情報や電子署名等を含むデジタル名刺VCsを生成する。なお、資格情報本体に、発行者が証明する具体的な情報(例えば、社名、社員の氏名、顔画像、所属部署、連絡先等)が記載される。
サーバ装置10は、生成したデジタル名刺VCsを利用者(デジタル名刺VCsの保有者となる利用者;デジタル名刺VCsの発行依頼者)の端末20に送信する(デジタル名刺発行;ステップS03)。
さらに、サーバ装置10は、発行者IDと上記生成した公開鍵をブロックチェーンに登録する(ステップS04)。
端末20は、受信したデジタル名刺VCsをデジタルウォレットに格納する。
<デジタル名刺VCsの交換>
利用者は、端末20に名刺管理アプリケーションをインストールする。名刺管理アプリケーションは、デジタルウォレットに格納されたデジタル名刺VCsを用いたサービスを提供する。
利用者は、端末20に名刺管理アプリケーションをインストールする。名刺管理アプリケーションは、デジタルウォレットに格納されたデジタル名刺VCsを用いたサービスを提供する。
例えば、利用者(社員)は、デジタルウォレットに格納されたデジタル名刺VCsを他者(例えば、商談相手)と交換することができる。例えば、端末20(名刺管理アプリケーション)は、利用者による所定の操作(例えば、名刺交換ボタンの押下)を検出すると、デジタルウォレットに格納されたデジタル名刺VCsを用いて2次元バーコードを生成する。
より具体的には、端末20は、利用者のDID(利用者ID)に対応する秘密鍵を用いてデジタル名刺VCsに署名する。端末20は、署名が付されたデジタル名刺VCsを2次元バーコードに変換する。
端末20は、生成した2次元バーコードを表示する。他者の端末20は、表示された2次元バーコードを読み取ることでデジタル名刺VCsを取得する。例えば、図6に示すように、利用者A及び利用者Bそれぞれが所持する端末20は、2次元バーコードを表示して、相手方の端末20に表示された2次元バーコードを読み取る。端末20は、2次元バーコードをデコードしてデジタル名刺VCsを取得する。
端末20は、取得した相手方のデジタル名刺VCsから発行者IDと利用者IDを取得する。さらに、端末20は、取得した発行者IDに対応する公開鍵と取得した利用者IDに対応する公開鍵をブロックチェーンから取得する。
端末20は、相手方から取得したデジタル名刺VCsを検証する。具体的には、端末20は、デジタル名刺VCsに付与された保有者の署名と発行者の署名を検証する。これらの署名の検証によって、端末20は、利用者(デジタル名刺VCsの保有者;例えば、商談相手)から取得したデジタル名刺VCsが改ざんされていないことや信頼できる発行者から発行された証明書であることを確認する。
端末20は、取得したデジタル名刺VCsの検証に成功すると、当該取得したデジタル名刺VCsの内容を表示すると共に内部に記憶する。その際、端末20は、デジタル名刺VCsを、当該デジタル名刺VCsを取得した日時及び場所と対応付けて記憶してもよい。
端末20は、デジタル名刺VCsの取得時の状況等に関する情報を当該取得したデジタル名刺VCsと対応付けて記憶してもよい。例えば、端末20は、デジタル名刺VCsの交換が行われた際のイベント名(例えば、利用者が参加した会議名、展示会名)とデジタル名刺VCsを対応付けて記憶してもよい。具体的には、端末20は、デジタル名刺VCsを取得すると、利用者のスケジュール情報を参照する。端末20は、デジタル名刺を取得した日時にイベントが設定されていれば、当該イベントの名称(会議名、展示会名)を取得し、取得したデジタル名刺VCsと対応付けて記憶する。端末20は、利用者がデジタル名刺VCsを閲覧(検索)する際、デジタル名刺VCsと共にイベント名(例えば、会議名、展示会名)を表示する。当該表示に接した利用者は、デジタル名刺VCsを取得した際の状況等を思い出しやすくなる。
<デジタル名刺VCsの他の活用>
端末20(名刺管理アプリケーション)は、利用者による所定の操作(例えば、名刺表示ボタンの押下)に応じて内部に記憶した他者のデジタル名刺VCsの閲覧を可能にする。例えば、端末20は、図7に示すような画面を表示する。
端末20(名刺管理アプリケーション)は、利用者による所定の操作(例えば、名刺表示ボタンの押下)に応じて内部に記憶した他者のデジタル名刺VCsの閲覧を可能にする。例えば、端末20は、図7に示すような画面を表示する。
あるいは、端末20は、取得したデジタル名刺VCsを種々のアプリケーションにおいて活用してもよい。例えば、端末20は、他者の連絡先等をアドレス帳で管理するアプリケーションにおいて上記取得したデジタル名刺VCsを利用してもよい。例えば、メールアプリケーション、会議設定アプリケーション、コミュニケーションアプリケーション等のアドレス帳にデジタル名刺VCsから得られる情報(例えば、氏名、所属企業、所属部署、電話番号、メールアドレス)が登録されてもよい。
利用者は、メールアプリケーション等において、デジタル名刺VCsから自動登録された連絡先を手動で登録された連絡先と同様に扱うことができる。即ち、利用者は、電子メールを送信したい相手、会議のスケジュールを調整したい相手、チャットを行いたい相手をアドレス帳から選択できる。
また、メールアプリケーション等は、利用者が属する企業の社員とデジタル名刺の交換を行った場合、社内の他の社員の連絡先を管理するアドレス帳において、デジタル名刺交換を行った社員と行っていない社員を区別可能に表示してもよい。
続いて、第1の実施形態に係る情報処理システムに含まれる各装置の詳細について説明する。
[端末]
端末20には、スマートフォン、携帯電話機、ゲーム機、タブレット等の携帯端末装置やコンピュータ(パーソナルコンピュータ、ノートパソコン)等が例示される。端末20は、利用者の操作を受け付け、サーバ装置10等と通信可能であれば任意の機器、デバイスとすることができる。
端末20には、スマートフォン、携帯電話機、ゲーム機、タブレット等の携帯端末装置やコンピュータ(パーソナルコンピュータ、ノートパソコン)等が例示される。端末20は、利用者の操作を受け付け、サーバ装置10等と通信可能であれば任意の機器、デバイスとすることができる。
図8は、本願開示の実施形態に係る端末20の処理構成(処理モジュール)の一例を示す図である。図8を参照すると、端末20は、通信制御部201と、本人確認部202と、取得制御部203と、利用制御部204と、記憶部205と、を備える。
通信制御部201は、他の装置との間の通信を制御する手段である。例えば、通信制御部201は、サーバ装置10からデータ(パケット)を受信する。また、通信制御部201は、サーバ装置10に向けてデータを送信する。通信制御部201は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部201は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部201を介して他の装置とデータの送受信を行う。通信制御部201は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。
本人確認部202及び取得制御部203によってデジタルウォレットアプリケーションが実現される。また、利用制御部204によって名刺管理アプリケーションが実現される。なお、デジタルウォレットアプリケーションや名刺管理アプリケーションのインストールに関する詳細な説明は省略する。アプリケーションのインストールは、当業者にとって明らかなためである。
本人確認部202は、デジタルウォレットの開設者の本人確認を行う手段である。本人確認部202は、身分証明書から得られる生体情報と、デジタルウォレットを開設する開設者の生体情報と、を用いてデジタルウォレットを開設する開設者の本人確認を行う。より具体的には、本人確認部202は、デジタルウォレットの開設者と公的機関から発行された身分証明書の名義人(被発行者)が同一であることを確認する。
図9は、本人確認部202の動作の一例を示すフローチャートである。図9を参照しつつ、本人確認部202の動作を説明する。
本人確認部202は、デジタルウォレットの開設時(初回起動時)に、利用者が所持する身分証明書から当該身分証明書の名義人に関する情報を取得する。例えば、本人確認部202は、マイナンバーカードやパスポートに搭載されたIC(Integrated Circuit)チップから身分証明書の名義人の生体情報を取得する(ステップS101)。
例えば、マイナンバーカードが身分証明書として用いられる場合には、本人確認部202は、利用者証明用電子証明書用の暗証番号をGUI(Graphical User Interface)等を用いて取得する。あるいは、パスポートが身分証明書として用いられる場合には、本人確認部202は、パスポートの券面に記載されたMRZ(Machine Readable Zone)に記載された情報をOCR(Optical Character Recognition)技術を用いて取得する。
本人確認部202は、取得した暗証番号(4桁の数字)やMRZに記載された情報をパスワードとして用いてICチップから情報を読み出す。本人確認部202は、身分証明書(マイナンバーカード、パスポート等)から読み出した当該身分証明書の名義人に関する生体情報(顔情報、顔画像)を記憶部205に記憶する(ステップS102)。
さらに、本人確認部202は、利用者(端末20の利用者;デジタルウォレットの開設者)の生体情報を取得する(ステップS103)。例えば、本人確認部202は、GUI等を用いて自身の顔を撮影するように利用者に促す(所謂、自撮りにより顔画像を取得する)。
本人確認部202は、身分証明書から生体情報を取得し、自装置を操作する利用者の生体情報を取得すると、当該身分証明書から得られた生体情報と利用者の生体情報を用いた照合処理を実行する(ステップS104)。本人確認部202は、2つの生体情報が実質的に一致するか否かを判定する。
具体的には、本人確認部202は、2つの生体情報(例えば、顔画像)それぞれから特徴量を生成する。
なお、特徴量の生成処理に関しては既存の技術を用いることができるので、その詳細な説明を省略する。例えば、本人確認部202は、顔画像から目、鼻、口等を特徴点として抽出する。その後、本人確認部202は、特徴点それぞれの位置や各特徴点間の距離を特徴量として計算する(複数の特徴量からなる特徴ベクトルを生成する)。
次に、本人確認部202は、当該生成された2つの特徴量を用いた照合処理(認証処理)を実行する。具体的には、本人確認部202は、2つの特徴量を用いて対応する顔画像間の類似度を算出する。本人確認部202は、当該算出した類似度に対する閾値処理の結果に基づき、2つの画像が同一人物の顔画像か否かを判定する。なお、当該類似度には、カイ二乗距離やユークリッド距離等を用いることができる。距離が離れているほど類似度は低く、距離が近いほど類似度が高い。
類似度が所定の値よりも大きければ(距離が所定の値よりも短ければ)、本人確認部202は、照合処理に成功したと判定する。類似度が所定の値以下であれば、本人確認部202は、照合処理に失敗したと判定する。
照合処理に成功すると(ステップS105、Yes分岐)、本人確認部202は、利用者にデジタルウォレットの利用を許可する(利用許可;ステップS106)。即ち、本人確認部202は、認証処理(1対1認証)に成功すると、デジタルウォレットを開設する。
本人確認部202は、生体情報を使った照合処理(認証処理)に成功すると、身分証明書の発行を受けた名義人と端末20の利用者が同一人物であると扱う。デジタルウォレットの初回起動時に、身分証明書の名義人と端末20の利用者が同一人物か否か判定される。身分証明書の名義人とデジタルウォレットの開設者が同一人物であれば、端末20は、デジタルウォレットアプリケーションを利用可能にする。
照合処理に失敗すると(ステップS105、No分岐)、本人確認部202は、利用者にデジタルウォレットの利用を許可しない(利用拒否;ステップS107)。即ち、認証処理(1対1認証)が失敗すると、利用者は、デジタルウォレットを利用できない(デジタルウォレットを開設できない)。
このように、本人確認部202は、身分証明書から得られる生体情報とデジタルウォレットを開設する開設者の生体情報を用いた認証処理に成功した場合に、本人確認に成功したと判定する。本人確認に成功すると、デジタルウォレットが開設される。
取得制御部203は、デジタル名刺VCsをはじめとしたクレデンシャル証明書の取得に関する制御を行う手段である。例えば、取得制御部203は、サーバ装置10に対し、デジタル名刺VCsの発行を要求する。取得制御部203は、サーバ装置10(利用者の所属企業)から取得したデジタル名刺VCsをデジタルウォレットに格納する。
図10は、取得制御部203の動作の一例を示すフローチャートである。図10を参照しつつ、本願開示の実施形態に係る取得制御部203の動作を説明する。
利用者がデジタルウォレットアプリケーションを起動し、所定の動作(例えば、デジタル名刺発行ボタンの押下)を行うと、取得制御部203は、デジタル名刺VCsの取得に関する制御を行う。
はじめに、取得制御部203は、公開鍵と秘密鍵のペアと、分散型識別子である利用者ID(利用者のDID)を生成する。取得制御部203は、生成した利用者IDと公開鍵をブロックチェーンに登録する(公開鍵等を登録;ステップS201)。
続いて、取得制御部203は、GUI等を用いて、デジタル名刺VCsの発行要求に必要な情報を取得する(必要情報の取得;ステップS202)。
例えば、取得制御部203は、デジタル名刺VCsの発行権限を持つ企業の情報(例えば、社名)を取得する。あるいは、取得制御部203は、サーバ装置10が利用者を特定するための情報(例えば、社員番号)を取得する。
取得制御部203は、取得した必要情報や利用者IDを証明書発行者に通知する。具体的には、取得制御部203は、デジタル名刺VCsの被発行者を特定するための情報(例えば、社員番号)、利用者IDをサーバ装置10に通知する。取得制御部203は、被発行者を特定する情報、利用者ID等を含む「デジタル名刺発行要求」をサーバ装置10に送信する(ステップS203)。
その際、取得制御部203は、社名とサーバ装置10のアドレスを対応付けて記憶するテーブル情報等を参照して、デジタル名刺発行要求の送信先となるサーバ装置10のアドレスを特定すればよい。
なお、取得制御部203は、ブロックチェーンに登録した公開鍵に対応する秘密鍵を用いてデジタル名刺発行要求に含まれる情報に署名を付与してもよい。
取得制御部203は、デジタル名刺発行要求に対する応答(肯定応答、否定応答)をサーバ装置10から受信する(ステップS204)。
デジタル名刺VCsの発行に失敗した旨を示す否定応答を受信した場合(ステップS205、No分岐)、取得制御部203は、デジタル名刺VCsが発行されなかった事実を利用者に通知する(非発行を通知;ステップS206)。
デジタル名刺VCsの発行に成功した旨を示す肯定応答を受信した場合(ステップS205、Yes分岐)、取得制御部203は、当該肯定応答に含まれるデジタル名刺VCsをデジタルウォレットに格納する(ステップS207)。その際、取得制御部203は、デジタル名刺VCsが発行された事実を利用者に通知してもよい。
取得制御部203は、サーバ装置10から取得したデジタル名刺VCsに付された署名を検証してもよい。この場合、取得制御部203は、デジタル名刺VCsに記載された発行者IDに対応する公開鍵をブロックチェーンから取得する。取得制御部203は、取得した公開鍵を用いてデジタル名刺VCsに付された署名を検証し、検証に成功すると、デジタル名刺VCsをデジタルウォレットに格納してもよい。
このように、取得制御部203は、第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺VCsを取得する、第1の取得手段として動作する。また、取得制御部203は、利用者の所属企業から取得したデジタル名刺VCsをデジタルウォレットに格納する。その際、取得制御部203は、取得したデジタル名刺VCsの署名の検証に成功すると、当該取得したデジタル名刺VCsをデジタルウォレットに格納してもよい。
利用制御部204は、デジタルウォレットに格納されたデジタルコンテンツ(クレデンシャル証明書)の利用に関する制御を行う手段である。とりわけ、利用制御部204は、デジタル名刺VCsの利用に関する制御を行う。
利用制御部204は、提供手段としての機能と、第2の取得手段としての機能と、を備える。提供手段としての利用制御部204は、内部に記憶された第1の利用者のデジタル名刺VCsを外部に提供する。第2の取得手段としての利用制御部204は、第2の利用者のデジタル名刺VCsを取得し、当該取得した第2の利用者のデジタル名刺を検証する。利用制御部204は、第2の利用者のデジタル名刺の検証に成功すると取得した第2の利用者のデジタル名刺を記憶する。
例えば、名刺管理アプリケーションを起動した利用者が、所定の操作(例えば、名刺交換ボタンの押下)を行うと、利用制御部204は、デジタル名刺VCsの交換に関する制御を行う。具体的には、利用制御部204は、デジタルウォレットに格納されたデジタル名刺VCsを相手方に提供する制御と、相手方から提供されたデジタル名刺VCsを受け入れる制御と、を行う。
利用者による所定の操作を検出すると、利用制御部204は、デジタルウォレットに格納されたデジタル名刺VCsに基づいて2次元バーコードを生成する。より具体的には、利用制御部204は、利用者のDID(利用者ID)に対応する秘密鍵を用いてデジタル名刺VCsに署名する。利用制御部204は、署名が付されたデジタル名刺VCsを2次元バーコードに変換する。利用制御部204は、デジタル名刺VCsに基づき生成された2次元バーコードを表示する。
なお、利用制御部204は、デジタル名刺VCsの発行要求時に生成した秘密鍵(利用者IDに対応する秘密鍵)を用いて相手方に提供するデジタル名刺VCsに署名する。
利用制御部204は、端末20に搭載されたカメラを制御し、相手方の端末20に表示された2次元バーコードを読み取る。利用制御部204は、読み取った2次元バーコードをデコードしてデジタル名刺VCsを取得する。
利用制御部204は、取得したデジタル名刺VCsを検証する。具体的には、利用制御部204は、デジタル名刺VCsから発行者IDと利用者IDを読み出す。利用制御部204が、読み出した発行者IDに対応する公開鍵をブロックチェーンから取得する。同様に、利用制御部204は、読み出した利用者IDに対応する公開鍵をブロックチェーンから取得する。
利用制御部204は、デジタル名刺VCsに付与された保有者(デジタル名刺VCsを交換する相手方)の署名と発行者の署名をそれぞれ検証する。
相手方のデジタル名刺VCsの検証に失敗した場合、利用制御部204は、その旨を利用者に通知する。その際、利用制御部204は、取得したデジタル名刺VCsは偽造された名刺である可能性を利用者に通知してもよい。
相手方のデジタル名刺VCsの検証に成功した場合、利用制御部204は、取得したデジタル名刺VCsを表示する。さらに、利用制御部204は、取得したデジタル名刺VCsを記憶部205に記憶する。
その際、利用制御部204は、取得したデジタル名刺VCs(名刺交換した相手方のデジタル名刺VCs)を、当該デジタル名刺VCsの取得日時及び取得場所と対応付けて記憶してもよい。
なお、利用制御部204は、GPS(Global Positioning System)衛星からのGPS信号を受信して測位を実行し、端末20の緯度、経度及び高度を含む位置情報を算出する。利用制御部204は、位置情報(X、Y、Z座標)から名刺交換が行われた取得場所を特定する。例えば、利用制御部204は、位置情報と取得場所の名称を対応付け記憶するテーブル情報を参照して取得場所を特定する。
なお、利用制御部204は、デジタル名刺VCsを相手方に提供する制御、相手方から提供されたデジタル名刺VCsを受け入れるための制御のいずれか一方に限り行ってもよいことは勿論である。
このように、利用制御部204は、デジタルウォレットに記憶されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、第1の利用者のデジタル名刺VCsを他者に提供する。さらに、利用制御部204は、相手方から取得したデジタル名刺VCsであって、検証に成功したデジタル名刺VCsを、当該検証に成功したデジタル名刺VCsの取得日時及び取得場所と対応付けて記憶する。
ここで、利用制御部204は、デジタル名刺VCsの交換だけでなく、デジタル名刺VCsの他の利用に関する制御を行ってもよい。例えば、利用者による所定の操作(例えば、名刺表示ボタンの押下)に応じて、利用制御部204は、記憶部205に記憶されたデジタル名刺VCsを利用者が閲覧可能にする。例えば、利用制御部204は、図7に示すような画面を表示する。
その際、利用制御部204は、表示されたデジタル名刺VCsの電話番号に相当する領域に利用者が触れた場合、当該連絡先に電話をかけてもよい。あるいは、利用制御部204は、電子メールアドレスに相当する領域に利用者が触れた場合、当該電子メールアドレスを電子メールの送信先に設定しメールアプリケーションを起動してもよい。
あるいは、利用制御部204は、デジタル名刺VCsの検索を実現してもよい。例えば、利用制御部204は、利用者が指定する取得日時や取得場所に合致するデジタル名刺VCsを抽出し、当該抽出されたデジタル名刺VCsを表示してもよい。
あるいは、利用制御部204は、検証に成功したことで受け入れたデジタル名刺VCsを、アドレス帳を用いるアプリケーションが利用可能に制御してもよい。即ち、利用制御部204は、取得したデジタル名刺VCsを名刺管理アプリケーション以外のアプリケーションが利用可能としてもよい。
例えば、DeepLinkと称されるスマートフォン内のデータ共有手段を用いてデジタル名刺VCsがメールアプリケーション、会議設定アプリケーション、コミュニケーションアプリケーション等に引き渡されてもよい。メールアプリケーション等は、取得したデジタル名刺VCsから名刺名義人の氏名、社名、連絡先等を取得し、当該取得した氏名等をアドレス帳に追加してもよい。
その際、メールアプリケーション等は、デジタル名刺VCsの名義人に基づくグループ分けを行ってもよい。例えば、メールアプリケーション等は、同じ企業に勤務する社員のグループ、他社の社員のグループといった複数のグループを生成し、当該グループを用いてデジタル名刺VCsを管理してもよい。
記憶部205は、端末20の動作に必要な情報を記憶する手段である。記憶部205は、デジタルウォレットの開設時に取得された利用者の生体情報を記憶すると共に、デジタル名刺VCs等をデジタルウォレットにより記憶する。
[サーバ装置]
図11は、本願開示の実施形態に係るサーバ装置10の処理構成(処理モジュール)の一例を示す図である。図11を参照すると、サーバ装置10は、通信制御部301と、社員管理部302と、デジタル名刺制御部303と、記憶部304と、を備える。
図11は、本願開示の実施形態に係るサーバ装置10の処理構成(処理モジュール)の一例を示す図である。図11を参照すると、サーバ装置10は、通信制御部301と、社員管理部302と、デジタル名刺制御部303と、記憶部304と、を備える。
通信制御部301は、他の装置との間の通信を制御する手段である。例えば、通信制御部301は、端末20からデータ(パケット)を受信する。また、通信制御部301は、端末20に向けてデータを送信する。通信制御部301は、他の装置から受信したデータを他の処理モジュールに引き渡す。通信制御部301は、他の処理モジュールから取得したデータを他の装置に向けて送信する。このように、他の処理モジュールは、通信制御部301を介して他の装置とデータの送受信を行う。通信制御部301は、他の装置からデータを受信する受信部としての機能と、他の装置に向けてデータを送信する送信部としての機能と、を備える。
社員管理部302は、自社(企業)に属する社員の管理等を行う手段である。
社員管理部302は、社員登録のためのウェブページ等において、社員の氏名、性別、生年月日、住所、生体情報(顔画像)、社員番号、所属部署、連絡先(電話番号、メールアドレス等)等を取得する。
さらに、社員管理部302は、社員を識別するための社員IDを生成する。社員IDは、社員を一意に識別できる情報であればどのような情報であってもよい。例えば、社員管理部302は、社員登録のたびに一意な値を採番し社員IDとしてもよい。
社員管理部302は、生成した社員ID、取得した社員の氏名、生体情報(顔画像)等を社員管理データベースに記憶する(図12参照)。なお、図12に示す社員管理データベースは例示であって、記憶する項目等を限定する趣旨ではない。
なお、社員が退職すると、人事部の担当者等はその旨をサーバ装置10に入力する。社員管理部302は、当該退職した社員のアカウント(社員管理データベースのエントリ)を削除する。さらに、社員管理部302は、当該退職した社員に発行されたデジタル名刺VCsを無効にする処理を実行する。具体的には、社員管理部302は、退職した社員に発行された署名を検証するための電子証明書を失効リストに登録する制御を行う。
デジタル名刺制御部303は、デジタル名刺VCsに関する制御を実行する手段である。例えば、デジタル名刺制御部303は、社員に対してデジタル名刺VCsを発行する。デジタル名刺制御部303は、端末20から受信した「デジタル名刺発行要求」を処理する。
デジタル名刺発行要求を受信すると、デジタル名刺制御部303は、当該デジタル名刺発行要求に含まれる被発行者を特定するための情報(例えば、社員番号)をキーとして社員管理データベースを検索する。
デジタル名刺制御部303は、上記検索に失敗すると(対応する利用者が社員管理データベースに登録されていないと)、デジタル名刺VCsの発行失敗を示す否定応答を端末20に送信する。
デジタル名刺制御部303は、上記検索に成功すると、社員管理データベースに記憶された情報を用いてデジタル名刺VCsを生成する。デジタル名刺制御部303は、発行者IDと利用者ID(証明書の被発行者のDID;デジタル名刺発行要求に含まれる利用者ID)を含むデジタル名刺VCsを生成する。
具体的には、デジタル名刺制御部303は、クレデンシャル証明書の種別、発行組織名、発行日時等を含むメタデータと、資格情報本体と、発行者の公開鍵情報や電子署名等を含むクレデンシャル証明書(VCs)をデジタル名刺VCsとして生成する。なお、資格情報本体には、社名、デジタル名刺VCsの被発行者の氏名、顔画像、所属部署、連絡先等が含まれる。また、デジタル名刺VCsに付される電子署名は、事前に生成された発行者IDに対応する秘密鍵によって行われる。
デジタル名刺制御部303は、生成したデジタル名刺VCsを端末20に送信する。具体的には、デジタル名刺制御部303は、デジタル名刺VCsを含む肯定応答を端末20に送信する。さらに、デジタル名刺制御部303は、事前に生成された、発行者IDと公開鍵等をブロックチェーンに登録する。
記憶部304は、サーバ装置10の動作に必要な情報を記憶する手段である。
[システムの動作]
続いて、第1の実施形態に係る情報処理システムの動作について説明する。
続いて、第1の実施形態に係る情報処理システムの動作について説明する。
図13は、本願開示の実施形態に係る情報処理システムの動作の一例を示すシーケンス図である。図13を参照し、第1の実施形態に係る情報処理システムのデジタル名刺VCs発行に関する動作について説明する。
端末20は、公開鍵、秘密鍵、利用者IDを生成し、利用者ID及び公開鍵をブロックチェーンに登録する(ステップS21)。
端末20は、上記利用者IDを含むデジタル名刺発行要求をサーバ装置10に送信する(ステップS22)。
サーバ装置10は、利用者(デジタル名刺VCsの被発行者)の資格情報を生成し、当該生成した資格情報を含むデジタル名刺VCsを生成する(ステップS23)。サーバ装置10は、利用者IDと発行者IDを含み、電子署名が付されたデジタル名刺VCsを生成する。
サーバ装置10は、生成したデジタル名刺VCsを端末20に送信する(ステップS24)。
端末20は、デジタル名刺VCsをデジタルウォレットに格納する(ステップS25)。
続いて、第1の実施形態に係る変形例について説明する。
<変形例1>
相手方にデジタル名刺VCsを提供する際に、クレデンシャル証明書であるデジタル名刺VCsに代えて、VP(Verifiable Presentation)が相手方に提供されてもよい。即ち、利用者の所属企業が発行したデジタル名刺VCsの一部が検証可能なプレゼンテーションとして利用者(保有者)から相手方(例えば、商談相手)に提供されてもよい。
相手方にデジタル名刺VCsを提供する際に、クレデンシャル証明書であるデジタル名刺VCsに代えて、VP(Verifiable Presentation)が相手方に提供されてもよい。即ち、利用者の所属企業が発行したデジタル名刺VCsの一部が検証可能なプレゼンテーションとして利用者(保有者)から相手方(例えば、商談相手)に提供されてもよい。
なお、以降の説明において、VP(検証可能なプレゼンテーション)として提供されるデジタル名刺を「デジタル名刺VP」と表記する。
例えば、利用者は、名刺を交換する相手方に応じてデジタル名刺VPに含まれる項目を決定する。例えば、相手方が重要な商談相手であれば、利用者は、デジタル名刺VCsに含まれる全ての情報を含むデジタル名刺VPを相手方に提供する。対して、相手方の身元に疑念がある場合には、利用者は、社名、氏名、メールアドレスを含み、顔画像を含まないデジタル名刺VPを相手方に提供する。即ち、端末20は、VP(検証可能なプレゼンテーション)を用いた「選択的最小開示」を実現してもよい。
なお、上記選択的最小開示を実現するため、デジタル名刺VCsの発行者(社員の所属企業)は、選択的最小開示の対象としたいデータをデータ集合から切り離し、当該切り離したデータのハッシュ値を計算する。サーバ装置10は、切り離したデータのハッシュ値を上記データ集合に埋め込む。サーバ装置10は、切り離されたデータのハッシュ値を含むデータ集合全体に対して署名を行い、デジタル名刺VCsを生成する。
相手方にデジタル名刺を提供する際、端末20の利用制御部204は、デジタル名刺VCsに記載された複数の項目のなかから相手方に提供する項目を選択可能とするようなGUIを表示する。例えば、利用制御部204は、図14に示すようなGUIを使って、利用者が相手方に提供を許可するデジタル名刺VCs内の項目を取得する。
端末20は、選択された項目を含みつつ、利用者の秘密鍵によって署名されたデジタル名刺VPを2次元バーコードに変換し、当該変換された2次元バーコードを表示する。
2次元バーコードをデコードしてデジタル名刺VPを取得した端末20の利用制御部204は、デジタル名刺VCsの場合と同様にデジタル名刺VPの署名を検証し、検証に成功すると当該デジタル名刺VPを受け入れる。
このように、端末20の利用制御部204は、第1の利用者のデジタル名刺VCsに含まれる複数の項目のなかから当該第1の利用者が選択した項目を含む、検証可能なプレゼンテーション(デジタル名刺VP)を生成する。利用制御部204は、生成された検証可能なプレゼンテーションを外部に提供する。
即ち、端末20は、デジタル名刺VCsに含まれる一部の情報から新たなデジタル名刺VPを作成し、当該作成したデジタル名刺VPを相手方に提供してもよい。その際、端末20は、デジタル名刺VCsに含まれる情報のなかから相手方に提供する情報(項目)を利用者が選択可能としてもよい。利用者は、相手方や状況に応じて、デジタル名刺VPに含める項目を決定することができる。
<変形例2>
上記実施形態では、サーバ装置10は、各社員に対し、共通の項目を含むデジタル名刺VCsを発行する場合について説明した。しかし、サーバ装置10のデジタル名刺制御部303は、被発行者(社員)に特有な情報を含むデジタル名刺VCsを発行してもよい。例えば、デジタル名刺制御部303は、社員が持つ資格情報、社内外で履修した研修に関する情報、社内外で表彰された事柄の情報等を含むデジタル名刺VCsを生成してもよい。
上記実施形態では、サーバ装置10は、各社員に対し、共通の項目を含むデジタル名刺VCsを発行する場合について説明した。しかし、サーバ装置10のデジタル名刺制御部303は、被発行者(社員)に特有な情報を含むデジタル名刺VCsを発行してもよい。例えば、デジタル名刺制御部303は、社員が持つ資格情報、社内外で履修した研修に関する情報、社内外で表彰された事柄の情報等を含むデジタル名刺VCsを生成してもよい。
社員や人事部の担当者は、社員のアカウントに上記資格情報、研修情報、表彰情報を登録する。デジタル名刺制御部303は、被発行者のアカウントに上記資格情報等が登録されていれば、当該資格情報等を含むデジタル名刺VCsを生成する。
<変形例3>
上記実施形態では、端末20は、デジタル名刺VCsを取得してデジタルウォレットに格納する場合について説明した。しかし、端末20は、他のクレデンシャル証明書を取得してデジタルウォレットに格納してもよい。
上記実施形態では、端末20は、デジタル名刺VCsを取得してデジタルウォレットに格納する場合について説明した。しかし、端末20は、他のクレデンシャル証明書を取得してデジタルウォレットに格納してもよい。
即ち、情報処理システムには、デジタル名刺VCsとは異なるクレデンシャル証明書を発行する証明書発行者が含まれていてもよい。具体的には、証明書発行者は、利用者に証明書を発行する主体である。より具体的には、証明書発行者は、利用者の「資格」を証明する証明書の発行権限を持つ団体等である。例えば、証明書発行者は、利用者の身分を証明する証明書、利用者の所属(又は所属していたこと)を証明する証明書、利用者が有する能力(資格)を証明する証明書等を発行する。
例えば、運転免許証、パスポート、マイナンバーカード等の身分証明書を発行する公的機関が証明書発行者に該当する。あるいは、所定業務に求められる資格や語学力等を証明する証明書を発行する機関、協会等が証明書発行者に該当する。
各証明書発行者は、企業のサーバ装置10と同等の機能を備えるサーバを備える。証明書発行者のサーバは、利用者からの要求に応じて、当該利用者が所有する資格等を証明するクレデンシャル証明書を発行する。端末20は、証明書発行者のサーバから取得したクレデンシャル証明書をデジタルウォレットに格納する。
<変形例4>
端末20は、相手方に提供するデジタル名刺のなかに資格情報等が含まれ、当該資格情報に対応するクレデンシャル証明書がデジタルウォレットに格納されている場合には、当該資格情報に対応するクレデンシャル証明書も相手方に提供してもよい。
端末20は、相手方に提供するデジタル名刺のなかに資格情報等が含まれ、当該資格情報に対応するクレデンシャル証明書がデジタルウォレットに格納されている場合には、当該資格情報に対応するクレデンシャル証明書も相手方に提供してもよい。
例えば、デジタル名刺VCsに語学の能力を示す項目が含まれている場合、利用制御部204は、当該語学の能力を証明するクレデンシャル証明書をデジタルウォレットから取得する。利用制御部204は、デジタル名刺VCsと当該デジタル名刺VCsに含まれる資格情報に対応するクレデンシャル証明書を用いて相手方に提示する2次元バーコードを生成する。利用制御部204は、生成した2次元バーコードを相手方に提供する。
このように、利用制御部204は、第1の利用者が有する資格に関する情報が当該第1の利用者のデジタル名刺VCsに含まれる場合、当該資格に関する情報に対応するクレデンシャル証明書を第1の利用者のデジタル名刺VCsと共に外部に提供してもよい。
即ち、端末20は、デジタル名刺VCsに記載された一部の情報の信憑性を担保するクレデンシャル証明書を相手方に提供してもよい。相手方の端末20は、取得したクレデンシャル証明書(資格情報に対応するクレデンシャル証明書)を検証し、その結果に応じてデジタル名刺VCsの受け入れ可否を判定してもよい。
<変形例5>
利用者は、デジタルウォレットに格納されたデジタル名刺VCsを、入場が制限されているエリアへの入場証明書として活用してもよい。例えば、利用者がVIP(Very Important Person)ルームやセキュリティルームに入場する際、VIPルーム等への入場を制御する装置にデジタル名刺VCsが提示されてもよい。
利用者は、デジタルウォレットに格納されたデジタル名刺VCsを、入場が制限されているエリアへの入場証明書として活用してもよい。例えば、利用者がVIP(Very Important Person)ルームやセキュリティルームに入場する際、VIPルーム等への入場を制御する装置にデジタル名刺VCsが提示されてもよい。
例えば、図15に示すように、入場制限エリアのドアと認証端末30が接続されている。入場制限エリアに入場しようとする利用者は、端末20を操作して、デジタル名刺VCsを表示する(デジタル名刺VCsに基づき生成された2次元バーコードを表示する)。利用者は、端末20に表示された2次元バーコードを認証端末30に提示する。
認証端末30は、提示された2次元バーコードからデジタル名刺VCsを取得する。認証端末30は、取得したデジタル名刺VCsの検証を行う。デジタル名刺VCsの検証に成功すると、認証端末30は、デジタル名刺VCsを提示する利用者が入場制限エリアに入場する権限を備えているか否か判定する。
例えば、認証端末30は、デジタル名刺VCsから得られる名刺名義人の役職、所属部署、資格情報等に基づいて利用者が入場制限エリアに入場する権限を備えているか否か判定する。
利用者が入場制限エリアに入場する権限を備えていれば、認証端末30は、ドアを開く。利用者が入場制限エリアに入場する権限を備えていなければ、認証端末30は、ドアを開かない。
あるいは、デジタル名刺VCsに資格情報が含まれている場合には、端末20は、当該デジタル名刺VCsと共に資格情報に対応するクレデンシャル証明書を認証端末30に提示してもよい。認証端末30は、デジタル名刺VCsとクレデンシャル証明書のそれぞれについて検証に成功し、且つ、利用者が入場制限エリアに入場する権限を備えている場合に、ドアを開いてもよい。
<変形例6>
利用者が他者から取得したデジタル名刺VCsは、社内で共有されてもよい。この場合、端末20の利用制御部204は、他者から取得したデジタル名刺VCsの検証に成功すると、利用者を特定する情報(例えば、社員番号)と上記取得したデジタル名刺VCsをサーバ装置10に送信する。
利用者が他者から取得したデジタル名刺VCsは、社内で共有されてもよい。この場合、端末20の利用制御部204は、他者から取得したデジタル名刺VCsの検証に成功すると、利用者を特定する情報(例えば、社員番号)と上記取得したデジタル名刺VCsをサーバ装置10に送信する。
サーバ装置10のデジタル名刺制御部303は、利用者を特定する情報(社員番号)に基づいてデジタル名刺VCsの送信元を特定する。デジタル名刺制御部303は、取得したデジタル名刺VCsを当該送信元以外の社員(社員管理データベースに登録された各社員のメールアドレス)に送信してもよい。
あるいは、デジタル名刺制御部303は、予め定められたポリシに従ってデジタル名刺VCsの送信先を決定してもよい。例えば、ポリシには「同じ部署に所属する社員にデジタル名刺を送信する」や「部長職が取得したデジタル名刺は、部長職以上の社員にデジタル名を送信する」といった内容が設定される。
あるいは、サーバ装置10は、デジタル名刺VCsの生成時に、当該デジタル名刺VCsの開示範囲を設定してもよい。例えば、デジタル名刺制御部303は、「共有禁止」、「同じ部署に限り共有許可」、「共有制限無し」といった開示範囲をデジタル名刺VCsに設定する(資格情報本体に記載する)。
あるいは、利用者(端末20)が、自身のデジタル名刺VCsに開示範囲を設定してもよい。この場合、利用制御部204は、GUIを用いて利用者が希望する開示範囲を取得すればよい。
利用者からデジタル名刺VCsを受信したサーバ装置10は、デジタル名刺VCsに設定された開示範囲に応じて、受信したデジタル名刺VCsを配布(社内で共有)してもよい。上記の例では、「共有禁止」と設定されたデジタル名刺VCsは誰にも送信されない。対して、「共有制限無し」と設定されたデジタル名刺VCsは各社員に送信される。
このように、端末20の利用制御部204は、検証に成功したデジタル名刺VCsを所定の組織によって運営されるサーバ装置10に送信することで、第2の利用者のデジタル名刺VCsを当該所定の組織内で共有可能としてもよい。即ち、利用者が取得したデジタル名刺VCsは、他者と共有されてもよい。その際、予め定められたポリシに従ってデジタル名刺VCsが共有されてもよい。あるいは、デジタル名刺VCsに開示範囲が設定されていてもよい。即ち、デジタル名刺VCsの開示範囲が、デジタル名刺VCsの発行者(サーバ装置10)や所有者(端末20)により管理されてもよい。
<変形例7>
上記実施形態では、2次元バーコードを用いてデジタル名刺VCsが交換される場合について説明した。しかし、デジタル名刺VCsは他の手段により交換されてもよい。例えば、端末20は、Bluetooth(登録商標)やNFC(Near Field Communication)等の近距離無線通信手段を使ってデジタル名刺VCsを交換してもよい。
上記実施形態では、2次元バーコードを用いてデジタル名刺VCsが交換される場合について説明した。しかし、デジタル名刺VCsは他の手段により交換されてもよい。例えば、端末20は、Bluetooth(登録商標)やNFC(Near Field Communication)等の近距離無線通信手段を使ってデジタル名刺VCsを交換してもよい。
<変形例8>
相手方からデジタル名刺VCsを取得する際、端末20は、当該相手方の本人確認を実行してもよい。例えば、相手方の端末20は、デジタル名刺VCsとデジタルウォレットの開設時に取得した利用者の生体情報を変換して2次元バーコードを生成する。
相手方からデジタル名刺VCsを取得する際、端末20は、当該相手方の本人確認を実行してもよい。例えば、相手方の端末20は、デジタル名刺VCsとデジタルウォレットの開設時に取得した利用者の生体情報を変換して2次元バーコードを生成する。
端末20は、2次元バーコードからデジタル名刺VCsと相手方の生体情報を取得する。端末20の利用制御部204は、デジタル名刺VCsの検証に前後して、相手方(面前の名刺交換相手)を撮影し、当該相手方の生体情報を取得する。利用制御部204は、撮影により得られた生体情報とデジタル名刺VCsと共に取得した生体情報を用いた本人確認の成功を、デジタル名刺VCsの受け入れ要件としてもよい。
以上のように、第1の実施形態に係る端末20は、クレデンシャル証明書として発行されたデジタル名刺VCsをデジタルウォレットに記憶する。端末20は、利用者同士の名刺交換の際、デジタルウォレットに記憶されたデジタル名刺VCsを相手方に提供する。相手方の端末20は、取得したデジタル名刺VCsを検証し、検証に成功すると当該取得したデジタル名刺VCsを受け入れる。
このように、端末20は、利用者の所属企業から取得したデジタル名刺VCsを相手方に提供する。相手方の端末20は、取得したデジタル名刺VCsの署名を検証することで、当該デジタル名刺VCsが改ざんされていないことやデジタル名刺VCsが正当な証明書発行者(利用者の所属企業)から発行されたことを確認できる。その結果、利用者は、相手方及び取得したデジタル名刺VCsに記載された内容を信用することができる。
続いて、情報処理システムを構成する各装置のハードウェアについて説明する。図16は、端末20のハードウェア構成の一例を示す図である。
端末20は、情報処理装置(所謂、コンピュータ)により構成可能であり、図16に例示する構成を備える。例えば、端末20は、プロセッサ311、メモリ312、入出力インターフェイス313及び通信インターフェイス314等を備える。上記プロセッサ311等の構成要素は内部バス等により接続され、相互に通信可能に構成されている。
但し、図16に示す構成は、端末20のハードウェア構成を限定する趣旨ではない。端末20は、図示しないハードウェアを含んでもよいし、必要に応じて入出力インターフェイス313を備えていなくともよい。また、端末20に含まれるプロセッサ311等の数も図16の例示に限定する趣旨ではなく、例えば、複数のプロセッサ311が端末20に含まれていてもよい。
プロセッサ311は、例えば、CPU(Central Processing Unit)、MPU(Micro Processing Unit)、DSP(Digital Signal Processor)等のプログラマブルなデバイスである。あるいは、プロセッサ311は、FPGA(Field Programmable Gate Array)、ASIC(Application Specific Integrated Circuit)等のデバイスであってもよい。プロセッサ311は、オペレーティングシステム(OS;Operating System)を含む各種プログラムを実行する。
メモリ312は、RAM(Random Access Memory)、ROM(Read Only Memory)、HDD(Hard Disk Drive)、SSD(Solid State Drive)等である。メモリ312は、OSプログラム、アプリケーションプログラム、各種データを格納する。
入出力インターフェイス313は、図示しない表示装置や入力装置のインターフェイスである。表示装置は、例えば、液晶ディスプレイ等である。入力装置は、例えば、キーボードやマウス等のユーザ操作を受け付ける装置である。
通信インターフェイス314は、他の装置と通信を行う回路、モジュール等である。例えば、通信インターフェイス314は、NIC(Network Interface Card)等を備える。
端末20の機能は、各種処理モジュールにより実現される。当該処理モジュールは、例えば、メモリ312に格納されたプログラムをプロセッサ311が実行することで実現される。また、当該プログラムは、コンピュータが読み取り可能な記憶媒体に記録することができる。記憶媒体は、半導体メモリ、ハードディスク、磁気記録媒体、光記録媒体等の非トランジェント(non-transitory)なものとすることができる。即ち、本発明は、コンピュータプログラム製品として具現することも可能である。また、上記プログラムは、ネットワークを介してダウンロードするか、あるいは、プログラムを記憶した記憶媒体を用いて、更新することができる。さらに、上記処理モジュールは、半導体チップにより実現されてもよい。
なお、サーバ装置10等も端末20と同様に情報処理装置により構成可能であり、その基本的なハードウェア構成は端末20と相違する点はないので説明を省略する。
情報処理装置である端末20は、コンピュータを搭載し、当該コンピュータにプログラムを実行させることで端末20の機能が実現できる。また、端末20は、当該プログラムにより端末20の制御方法を実行する。同様に、サーバ装置10は、コンピュータを搭載し、当該コンピュータにプログラムを実行させることでサーバ装置10の機能が実現できる。また、サーバ装置10は、当該プログラムによりサーバ装置10の制御方法を実行する。
[変形例]
なお、上記実施形態にて説明した情報処理システムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
なお、上記実施形態にて説明した情報処理システムの構成、動作等は例示であって、システムの構成等を限定する趣旨ではない。
上記実施形態では、端末20は、利用者の操作に応じてデジタル名刺VCsを他者に提供する場合について説明した。しかし、端末20は、当該他者からの要求に応じて、デジタルウォレットに記憶されたデジタル名刺VCsを提供してもよい。例えば、端末20は、Bluetooth(登録商標)等の通信手段により「デジタル名刺提供要求」を相手方の端末20から受信すると、署名付きのデジタル名刺VCsを当該相手方の端末20に送信してもよい。
端末20は、相手方から取得したデジタル名刺VCsの検証に失敗した場合、当該デジタル名刺VCsを破棄してもよいし、検証に成功した他のデジタル名刺VCsと区別して記憶してもよい。
端末20は、デジタル名刺VCsの検証結果の履歴を記憶してもよい。端末20は、検証に成功したデジタル名刺VCs、検証に失敗したデジタル名刺VCsをそれぞれ記憶し、デジタル名刺VCsに関する事後的な検証を可能としてもよい。
上記実施形態では、デジタル名刺の発行要求を行う際、端末20は、利用者を特定するための情報として社員番号をサーバ装置10に送信する場合について説明した。しかし、端末20は、利用者を特定するための情報として当該利用者の生体情報(顔画像)をサーバ装置10に送信してもよい。サーバ装置10は、生体情報を用いた照合処理(認証処理)を実行することで、デジタル名刺VCsの発行を希望する利用者を特定してもよい。
上記実施形態では、証明書発行者のサーバ装置10は、証明書の検証に認証局を必要としないクレデンシャル証明書を発行する場合について説明した。しかし、サーバ装置10は、認証局を必要とする証明書(公開鍵基盤に基づく証明書)を発行してもよい。
上記実施形態では、身分証明書から得られる生体情報を用いて本人確認(身分証明書の名義人とデジタルウォレット開設者の一致を確認)が行われる場合について説明した。しかし、当該本人確認は、身分証明書に格納された電子証明書を用いて行われてもよい。具体的には、端末20は、利用者が所持するマイナンバーカードから電子証明書(署名用電子証明書、利用者証明用電子証明書)を取得する。端末20は、取得した電子署名書を認証機関(J-LIS;Japan Agency for Local Authority Information Systems)に送信し、電子証明書の有効性検証を当該認証機関に依頼する。端末20は、電子証明書が有効であれば、本人確認に成功したと判定する。
端末20の一部の機能は別の装置、デバイス等に実装されていてもよい。より具体的には、上記説明した「本人確認部(本人確認手段)」、「取得制御部(取得制御手段)」等がシステムに含まれるいずれかの装置に実装されていればよい。
各装置(例えば、サーバ装置10、端末20)間のデータ送受信の形態は特に限定されないが、これら装置間で送受信されるデータは暗号化されていてもよい。これらの装置間では、利用者の個人情報等が送受信され、これらの情報を適切に保護するためには、暗号化されたデータが送受信されることが望ましい。
上記説明で用いた流れ図(フローチャート、シーケンス図)では、複数の工程(処理)が順番に記載されているが、実施形態で実行される工程の実行順序は、その記載の順番に制限されない。実施形態では、例えば各処理を並行して実行する等、図示される工程の順番を内容的に支障のない範囲で変更することができる。
上記の実施形態は本願開示の理解を容易にするために詳細に説明したものであり、上記説明したすべての構成が必要であることを意図したものではない。また、複数の実施形態について説明した場合には、各実施形態は単独で用いてもよいし、組み合わせて用いてもよい。例えば、実施形態の構成の一部を他の実施形態の構成に置き換えることや、実施形態の構成に他の実施形態の構成を加えることも可能である。さらに、実施形態の構成の一部について他の構成の追加、削除、置換が可能である。
上記の説明により、本発明の産業上の利用可能性は明らかであるが、本発明は、デジタルウォレットに格納されたデジタル名刺を活用する情報処理システムなどに好適に適用可能である。
上記の実施形態の一部又は全部は、以下の付記のようにも記載され得るが、以下には限られない。
[付記1]
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得手段と、
前記取得されたデジタル名刺を外部に提供する、提供手段と、
を備える、端末。
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得手段と、
前記取得されたデジタル名刺を外部に提供する、提供手段と、
を備える、端末。
[付記2]
前記提供手段は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、付記1に記載の端末。
前記提供手段は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、付記1に記載の端末。
[付記3]
前記提供手段は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、付記2に記載の端末。
前記提供手段は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、付記2に記載の端末。
[付記4]
前記提供手段は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、付記1乃至3のいずれか一項に記載の端末。
前記提供手段は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、付記1乃至3のいずれか一項に記載の端末。
[付記5]
第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得手段をさらに備える、付記1に記載の端末。
第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得手段をさらに備える、付記1に記載の端末。
[付記6]
前記第2の取得手段は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、付記5に記載の端末。
前記第2の取得手段は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、付記5に記載の端末。
[付記7]
前記第2の取得手段は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、付記6に記載の端末。
前記第2の取得手段は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、付記6に記載の端末。
[付記8]
前記第2の取得手段は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、付記7に記載の端末。
前記第2の取得手段は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、付記7に記載の端末。
[付記9]
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得工程と、
前記取得されたデジタル名刺を外部に提供する、提供工程と、
を備える、端末の制御方法。
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得工程と、
前記取得されたデジタル名刺を外部に提供する、提供工程と、
を備える、端末の制御方法。
[付記10]
前記提供工程は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、付記9に記載の端末の制御方法。
前記提供工程は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、付記9に記載の端末の制御方法。
[付記11]
前記提供工程は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、付記10に記載の端末の制御方法。
前記提供工程は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、付記10に記載の端末の制御方法。
[付記12]
前記提供工程は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、付記9乃至11のいずれか一項に記載の端末の制御方法。
前記提供工程は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、付記9乃至11のいずれか一項に記載の端末の制御方法。
[付記13]
第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得工程をさらに備える、付記9に記載の端末の制御方法。
第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得工程をさらに備える、付記9に記載の端末の制御方法。
[付記14]
前記第2の取得工程は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、付記13に記載の端末の制御方法。
前記第2の取得工程は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、付記13に記載の端末の制御方法。
[付記15]
前記第2の取得工程は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、付記14に記載の端末の制御方法。
前記第2の取得工程は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、付記14に記載の端末の制御方法。
[付記16]
前記第2の取得工程は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、付記15に記載の端末の制御方法。
前記第2の取得工程は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、付記15に記載の端末の制御方法。
[付記17]
端末に搭載されたコンピュータに、
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得処理と、
前記取得されたデジタル名刺を外部に提供する、提供処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
端末に搭載されたコンピュータに、
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得処理と、
前記取得されたデジタル名刺を外部に提供する、提供処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
[付記18]
前記提供処理は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、付記17に記載の記憶媒体。
前記提供処理は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、付記17に記載の記憶媒体。
[付記19]
前記提供処理は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、付記18に記載の記憶媒体。
前記提供処理は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、付記18に記載の記憶媒体。
[付記20]
前記提供処理は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、付記17乃至19のいずれか一項に記載の記憶媒体。
前記提供処理は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、付記17乃至19のいずれか一項に記載の記憶媒体。
[付記21]
第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得処理をさらに実行させる、付記17に記載の記憶媒体。
第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得処理をさらに実行させる、付記17に記載の記憶媒体。
[付記22]
前記第2の取得処理は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、付記21に記載の記憶媒体。
前記第2の取得処理は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、付記21に記載の記憶媒体。
[付記23]
前記第2の取得処理は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、付記22に記載の記憶媒体。
前記第2の取得処理は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、付記22に記載の記憶媒体。
[付記24]
前記第2の取得処理は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、付記23に記載の記憶媒体。
前記第2の取得処理は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、付記23に記載の記憶媒体。
また、上述した付記1に従属する付記2~付記8に記載した構成の一部または全ては、付記9及び付記17に対しても付記2~付記8と同様の従属関係により従属し得る。さらには、付記1、付記9及び付記17に限らず、上述した各実施の形態から逸脱しない範囲において、様々なハードウェア、ソフトウェア、ソフトウェアを記録するための種々の記録手段、またはシステムに対しても同様に、付記として記載した構成の一部または全てを従属させ得る。
なお、引用した上記の先行技術文献の各開示は、本書に引用をもって繰り込むものとする。以上、本発明の実施形態を説明したが、本発明はこれらの実施形態に限定されるものではない。これらの実施形態は例示にすぎないということ、及び、本発明のスコープ及び精神から逸脱することなく様々な変形が可能であるということは、当業者に理解されるであろう。即ち、本発明は、請求の範囲を含む全開示、技術的思想にしたがって当業者であればなし得る各種変形、修正を含むことは勿論である。
10 サーバ装置
20 端末
30 認証端末
100 端末
101 第1の取得手段
102 提供手段
201 通信制御部
202 本人確認部
203 取得制御部
204 利用制御部
205 記憶部
301 通信制御部
302 社員管理部
303 デジタル名刺制御部
304 記憶部
311 プロセッサ
312 メモリ
313 入出力インターフェイス
314 通信インターフェイス
20 端末
30 認証端末
100 端末
101 第1の取得手段
102 提供手段
201 通信制御部
202 本人確認部
203 取得制御部
204 利用制御部
205 記憶部
301 通信制御部
302 社員管理部
303 デジタル名刺制御部
304 記憶部
311 プロセッサ
312 メモリ
313 入出力インターフェイス
314 通信インターフェイス
Claims (10)
- 第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得手段と、
前記取得されたデジタル名刺を外部に提供する、提供手段と、
を備える、端末。 - 前記提供手段は、前記取得されたデジタル名刺に基づいて生成された2次元バーコードを表示することで、前記第1の利用者の前記デジタル名刺を他者に提供する、請求項1に記載の端末。
- 前記提供手段は、前記第1の利用者が有する資格に関する情報が前記第1の利用者のデジタル名刺に含まれる場合、前記資格に関する情報に対応するクレデンシャル証明書を前記第1の利用者のデジタル名刺と共に外部に提供する、請求項2に記載の端末。
- 前記提供手段は、前記第1の利用者のデジタル名刺に含まれる複数の項目のなかから前記第1の利用者が選択した項目を含む、検証可能なプレゼンテーションを生成し、前記生成された検証可能なプレゼンテーションを外部に提供する、請求項1乃至3のいずれか一項に記載の端末。
- 第2の利用者の前記デジタル名刺を取得し、前記取得した第2の利用者のデジタル名刺を検証し、前記第2の利用者のデジタル名刺の検証に成功すると前記取得した第2の利用者のデジタル名刺を記憶する、第2の取得手段をさらに備える、請求項1に記載の端末。
- 前記第2の取得手段は、前記検証に成功したデジタル名刺を、前記検証に成功したデジタル名刺の取得日時及び取得場所と対応付けて記憶する、請求項5に記載の端末。
- 前記第2の取得手段は、前記検証に成功したデジタル名刺を、アドレス帳を用いるアプリケーションが利用可能に制御する、請求項6に記載の端末。
- 前記第2の取得手段は、前記検証に成功したデジタル名刺を前記所定の組織によって運営されるサーバ装置に送信することで、前記第2の利用者のデジタル名刺を前記所定の組織内で共有可能とする、請求項7に記載の端末。
- 第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得工程と、
前記取得されたデジタル名刺を外部に提供する、提供工程と、
を備える、端末の制御方法。 - 端末に搭載されたコンピュータに、
第1の利用者が所定の組織に属していることを証明する証明書であって、内容の検証がオンラインで可能なデジタル名刺を取得する、第1の取得処理と、
前記取得されたデジタル名刺を外部に提供する、提供処理と、
を実行させるためのプログラムを記憶する、コンピュータ読取可能な記憶媒体。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2024/021188 WO2025257933A1 (ja) | 2024-06-11 | 2024-06-11 | 端末、端末の制御方法及び記憶媒体 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2024/021188 WO2025257933A1 (ja) | 2024-06-11 | 2024-06-11 | 端末、端末の制御方法及び記憶媒体 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025257933A1 true WO2025257933A1 (ja) | 2025-12-18 |
Family
ID=98050714
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2024/021188 Pending WO2025257933A1 (ja) | 2024-06-11 | 2024-06-11 | 端末、端末の制御方法及び記憶媒体 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2025257933A1 (ja) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2002297795A (ja) * | 2001-03-29 | 2002-10-11 | Seiko Epson Corp | 電子名刺装置 |
| US20180139210A1 (en) * | 2016-11-14 | 2018-05-17 | Instrinsic Value, LLC | Systems, devices, and methods for access control and identification of user devices |
| JP2022502748A (ja) * | 2018-09-21 | 2022-01-11 | ディントーク ホールディング(ケイマン) リミテッド | 電子名刺管理方法および装置 |
| JP2022090150A (ja) * | 2020-12-07 | 2022-06-17 | 三菱電機Itソリューションズ株式会社 | データ受信装置、データ受信方法及びデータ受信プログラム |
| US11432149B1 (en) * | 2019-10-10 | 2022-08-30 | Wells Fargo Bank, N.A. | Self-sovereign identification via digital credentials for selected identity attributes |
-
2024
- 2024-06-11 WO PCT/JP2024/021188 patent/WO2025257933A1/ja active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2002297795A (ja) * | 2001-03-29 | 2002-10-11 | Seiko Epson Corp | 電子名刺装置 |
| US20180139210A1 (en) * | 2016-11-14 | 2018-05-17 | Instrinsic Value, LLC | Systems, devices, and methods for access control and identification of user devices |
| JP2022502748A (ja) * | 2018-09-21 | 2022-01-11 | ディントーク ホールディング(ケイマン) リミテッド | 電子名刺管理方法および装置 |
| US11432149B1 (en) * | 2019-10-10 | 2022-08-30 | Wells Fargo Bank, N.A. | Self-sovereign identification via digital credentials for selected identity attributes |
| JP2022090150A (ja) * | 2020-12-07 | 2022-06-17 | 三菱電機Itソリューションズ株式会社 | データ受信装置、データ受信方法及びデータ受信プログラム |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| SG11202109105WA (en) | Credential verification and issuance through credential service providers | |
| JP7758365B2 (ja) | 端末、端末の制御方法及びプログラム | |
| JP6504639B1 (ja) | サービス提供システムおよびサービス提供方法 | |
| Chowdhary et al. | Blockchain based framework for student identity and educational certificate verification | |
| JP7124988B2 (ja) | 認証サーバ、認証システム、認証サーバの制御方法及びプログラム | |
| JP7794257B2 (ja) | 端末、システム、端末の制御方法及びプログラム | |
| WO2022024281A1 (ja) | 認証サーバ、認証システム、認証要求処理方法及び記憶媒体 | |
| JP2025088095A (ja) | 端末、システム、端末の制御方法及びプログラム | |
| JP7848704B2 (ja) | サーバ、サーバの制御方法、プログラム及びシステム | |
| WO2025057526A1 (ja) | 端末、システム、端末の制御方法及び記憶媒体 | |
| CN115867908A (zh) | 基于生物特征信息的电子认证书管理方法 | |
| WO2024161526A1 (ja) | サーバ装置、システム、サーバ装置の制御方法及び記憶媒体 | |
| JP7758263B1 (ja) | 端末、端末の制御方法及びプログラム | |
| JP2025110643A (ja) | サーバ装置、サーバ装置の制御方法及びプログラム | |
| JP7764984B1 (ja) | 認証端末、システム、認証端末の制御方法及びプログラム | |
| JP7740609B1 (ja) | サーバ装置、端末、サーバ装置の制御方法及びプログラム | |
| JP2026010527A (ja) | サーバ装置、サーバ装置の制御方法及びプログラム | |
| JP7589829B2 (ja) | システム、認証端末、認証端末の制御方法及びプログラム | |
| TWI874066B (zh) | 電子認證系統及電子認證方法 | |
| US20260111594A1 (en) | Decentralized identity management apparatus, decentralized identity management system, decentralized identity management method, and decentralized identity management storage medium | |
| JP2025159477A (ja) | サーバ装置、システム、サーバ装置の制御方法及びプログラム | |
| JP2026010653A (ja) | システム、情報処理装置、情報処理装置の制御方法及びプログラム | |
| Sasso et al. | A proposal for a unified identity card for use in an academic federation environment | |
| KR102960629B1 (ko) | 자격증명 서비스 제공자를 통한 자격증명 검증 및 발행 | |
| WO2025115463A1 (ja) | 端末、システム、端末の制御方法及び記憶媒体 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24943297 Country of ref document: EP Kind code of ref document: A1 |