IP Library › Granted Patent US 12,524,568
Granted Patent B2
US 12,524,568 · App. 18/267,672 · Granted Jan 13, 2026

User information management system, user information management method, user agent and program

Inventors: Yoshihiko Omori (Musashino, JP); Takao Yamashita (Musashino, JP); Yurika Suga (Musashino, JP); Yasuhiko Yoshimura (Musashino, JP)
Assignee: NTT, Inc.
G06F21/6245G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,568
App. No.
18/267,672
Granted
Jan 13, 2026
Kind
B2
Abstract

A user agent stores user information of a user and user information provided to a service provider server. When a user terminal registers the user in the service provider server, the user agent sends the user information already provided to the service provider server to the user terminal. When the user agent receives a provision permission of the user information from the user terminal, the user agent generates pseudo user identification information, a public key, and a private key, signs a service document of the service provider server, and sends the service document to the service provider server via the user terminal. When the signed service document is received, the user agent verifies the signature and sends user information to the service provider server.

Claims (64)

1 . A user information management system comprising:

a user terminal used by a user;

a user agent; and

a service provider server, wherein:

the user agent includes:

a storage configured to store:

a registered user database in which user identification information of the user and user information of the user are stored in association with each other; and

a provided user information database in which the service provider server and provided user information that was provided to the service provider server are stored in association with each other;

a user information providing destination search unit, implemented using one or more computing devices, configured to:

receive a request from the user terminal with a service provider service document including identification information of the service provider server and a user information type requested by the service provider server; and

transmit (i) a first set of user information of the user of the user terminal already provided to the service provider server and (ii) a second set of user information of the user corresponding to the user information type to the user terminal; and

a user information access right approval unit, implemented using one or more computing devices, configured to:

receive service provider server permission indicating a portion of the user information to be provided to the service provider server from the user terminal;

generate (i) pseudo user identification information that identifies the user in the service provider server and (ii) a pair of a private key and a public key associated with the pseudo user identification information;

generate a signed service provider service document obtained by adding a signature to the service provider service document using the private key; and

transmit the pseudo user identification information and the signed service provider service document to the user terminal;

the user terminal includes:

a user information provision request unit, implemented using one or more computing devices, configured to transmit the service provider server permission to the user agent; and

a service document transfer unit, implemented using one or more computing devices, configured to transmit the pseudo user identification information and the signed service provider service document to the service provider server;

the service provider server includes:

a user information request unit, implemented using one or more computing devices, configured to transmit the pseudo user identification information and the signed service provider service document to the user agent; and

the user agent further includes:

a providing unit, implemented using one or more computing devices, configured to verify the signature of the signed service provider service document using the public key associated with the pseudo user identification information, and return the service provider server permission to the service provider server in a case where the verification is successful.

2 . The user information management system according to claim 1 , further comprising:

a related service provider server configured to provide a service in cooperation with the service provider server, in which the related service provider server includes a related user information request unit, wherein:

the service provider server further includes a related service document transfer unit;

in the service provider service document, the identification information of the related service provider server is further included;

in the provided user information database, the related service provider server and the user information provided to the related service provider server are stored in association with each other;

the user information providing destination search unit of the user agent is configured to receive a request from the user terminal with a related service provider service document including related identification information of the related service provider server and a type of information requested by the related service provider server and transmits a third set of user information of the user of the user terminal already provided to the related service provider server to the user terminal;

the user information provision request unit of the user terminal is configured to transmit related service provider server permission indicating additional user information to be provided to the related service provider server to the user agent;

the user information access right approval unit of the user agent is configured to generate a signed related service provider service document obtained by adding a corresponding signature to the related service provider service document using the private key, and transmit the pseudo user identification information and the signed service provider service document to the user terminal;

the service document transfer unit included in the user terminal is configured to transmit the signed related service provider service document to the service provider server;

the related service document transfer unit of the service provider server is configured to transmit the pseudo user identification information, the signed service provider service document, and the signed related service provider service document to the related service provider server;

the related user information request unit of the related service provider server is configured to transmit the pseudo user identification information, the signed service provider service document, and the signed related service provider service document to the user agent; and

the providing unit of the user agent is configured to:

verify the signature of the signed service provider service document using the public key associated with the pseudo user identification information;

in a case where the verification is successful, verify that identification information of the related service provider server is included in the signed service provider service document;

in a case where the verification is successful, verify the signature of the signed related service provider service document using the public key associated with the pseudo user identification information; and

in a case where the verification is successful, return the related service provider server permission to the related service provider server.

3 . The user information management system according to claim 1 , wherein the providing unit of the user agent is configured to acquire the service provider server permission from the registered user database, extract the service provider server permission into extracted user information corresponding to a user information type included in the signed service provider service document, and return the extracted user information to the service provider server.

4 . The user information management system according to claim 1 , wherein the user information provision request unit of the user terminal is configured to display a provision user information confirmation screen including at least one of previously provided user information already provided to the service provider server, new user information to be provided to the service provider server, related user information already provided to the related service provider server, and related user information to be provided to the related service provider server, and acquire the service provider server permission.

5 . A user agent of an information management system including a user terminal used by a user, the user agent, and a service provider server, the user agent comprising:

a storage configured to store a registered user database in which user identification information of the user and user information of the user are stored in association with each other, and a provided user information database in which the service provider server and provided user information that was provided to the service provider server are stored in association with each other;

a user information providing destination search unit, implemented using one or more computing devices, configured to:

receive a request from the user terminal with a service provider service document including identification information of the service provider server and a user information type requested by the service provider server; and

transmit a first set of user information of the user of the user terminal already provided to the service provider server and a second set of user information of the user corresponding to the user information type to the user terminal;

a user information access right approval unit, implemented using one or more computing devices, configured to:

receive service provider server permission indicating a portion of the user information to be provided to the service provider server;

generate pseudo user identification information that identifies the user in the service provider server and a pair of a private key and a public key associated with the pseudo user identification information;

generate a signed service provider service document obtained by adding a signature to the service provider service document using the private key; and

transmit the pseudo user identification information and the signed service provider service document to the user terminal; and

a user information providing unit, implemented using one or more computing devices, configured to:

verify a signature of the signed service provider service document obtained from the user terminal and transmitted by the service provider server using a public key associated with the pseudo user identification information; and

return the service provider server provision permission user information to the service provider server in a case where the verification is successful.

6 . A non-transitory computer recording medium storing a program, wherein execution of the program causes one or more computers to perform operations comprising:

storing, in a storage, a registered user database in which user identification information of a user and user information of the user are stored in association with each other, and a provided user information database in which a service provider server and provided user information that was provided to the service provider server are stored in association with each other, and

receiving a request from a user terminal with a service provider service document including identification information of the service provider server and a user information type requested by the service provider server;

transmitting a first set of user information of the user of the user terminal already provided to the service provider server and a second set of user information of the user corresponding to the user information type to the user terminal;

receiving service provider server permission indicating a portion of the user information to be provided to the service provider server;

generating pseudo user identification information that identifies the user in the service provider server and a pair of a private key and a public key associated with the pseudo user identification information;

generating a signed service provider service document obtained by adding a signature to the service provider service document using the private key;

transmitting the pseudo user identification information and the signed service provider service document to the user terminal;

verifying the signature of the signed service provider service document obtained from the user terminal and transmitted by the service provider server using the public key associated with the pseudo user identification information; and

returning the service provider server permission to the service provider server in a case where the verification is successful.

Assignments (2)
CHANGE OF NAME Recorded Aug 14, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072412/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: OMORI, YOSHIHIKO; YAMASHITA, TAKAO; SUGA, YURIKA; YOSHIMURA, YASUHIKO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 063964/0770 →
Continuity (1)
Related Publication 20240104241A1 · Mar 28, 2024
References Cited (20)
US 10461942B1 · Vo · 2019 [cited by examiner]
US 20010010044A1 · Aieta · 2001 [cited by examiner]
US 20010042050A1 · Fletcher · 2001 [cited by examiner]
US 20050192008A1 · Desai · 2005 [cited by examiner]
US 20100063929A1 · Torigai · 2010 [cited by examiner]
US 20160203268A1 · Lacey · 2016 [cited by examiner]
US 20170155512A1 · Ogura · 2017 [cited by examiner]
US 20170302445A1 · Kobayashi · 2017 [cited by examiner]
US 20180113734A1 · Yamato · 2018 [cited by examiner]
US 20190007525A1 · Smith · 2019 [cited by examiner]
US 20190258820A1 · Gaspar · 2019 [cited by examiner]
US 20190333058A1 · Hong · 2019 [cited by examiner]
US 20210067334A1 · Angel · 2021 [cited by examiner]
US 20230086806A1 · Kamal · 2023 [cited by examiner]
US 20240129130A1 · Semenovskiy · 2024 [cited by examiner]
US 20240370585A1 · Madhavapeddi · 2024 [cited by examiner]
NPL Search Terms (Year: 2025). [cited by examiner]
Camenisch et al., “An Efficient System for Non-transferable Anonymous Credentials with Optional Anonymity Revocation,” Presented at Advances in Cryptology—Eurocrypt 2001, International Conference on the Theory and Appli… [cited by applicant]
Omori et al., “A Study on Sharing Method of User Credentials for Self-Sovereign Identity,” The Institute of Electronics, Information and Communication Engineers 2020 General Conference, Mar. 2020, 3 pages (with machine … [cited by applicant]
Reed et al., “Decentralized Identifiers (DIDs) v1.0 Core architecture, data model, and representations,” W3C Working Draft, Oct. 2020, 92 pages. [cited by applicant]