IP Library › Granted Patent US 12,574,391
Granted Patent B2
US 12,574,391 · App. 18/334,762 · Granted Mar 10, 2026

Computer-readable recording medium storing information management program, information management method, information processing device, and information sharing system

Inventor: Mebae Yamaoka (Kawasaki, JP)
Assignee: Fujitsu Limited
H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,391
App. No.
18/334,762
Granted
Mar 10, 2026
Kind
B2
Abstract

A non-transitory computer-readable recording medium storing an information management program for causing a computer to execute processing including: receiving distribution information obtained by attaching, to distribution content to be distributed by a user, attribute information on the user that includes signature information that is signed by an issuing authority that issues information regarding an attribute of the user and that proves that the issuing authority has issued the attribute information; verifying whether the attribute information on the user included in the distribution information is the attribute information issued by the issuing authority, by using the signature information; and outputting the distribution content, based on a verification result.

Claims (87)

1 . A non-transitory computer-readable recording medium storing an information management program for causing a computer operating as a service provider device in an information sharing system to execute processing comprising:

receiving, from a posting device in the information sharing system, distribution information obtained by attaching, to distribution content to be distributed by a user, attribute information on the user that includes first signature information that is signed by an issuing authority that issues information regarding an attribute of the user and that proves that the issuing authority has issued the attribute information;

verifying whether the attribute information on the user included in the distribution information is the attribute information issued by the issuing authority, by using the first signature information; and

outputting the distribution content, based on a verification result, wherein

the issuing authority, the posting device, and the computer operating as the service provider device are devices that constitute the information sharing system with a decentralized identity infrastructure as a platform and specify each other by using a respective decentralized identifier,

the receiving includes

receiving, as the distribution information, a first Verifiable Credential from the posting device, the first Verifiable Credential being issued by the posting device operating as an Issuer and including: the distribution content, a first Verifiable Presentation of the user, a first decentralized identifier of the posting device of the user, and second signature information signed by the posting device of the user, the first Verifiable Presentation including the attribute information of the user issued by the issuing authority and a second decentralized identifier of the issuing authority,

the verifying includes:

acquiring, from a data registry of the decentralized identity infrastructure, first public key information of the posting device of the user associated with the first decentralized identifier included in the first Verifiable Credential; and

verifying whether the first Verifiable Credential has been issued by the posting device of the user, by using the first public key information and the second signature information, and

the outputting includes:

when a result of the verifying indicates that the first Verifiable Credential has been issued by the posting device of the user,

outputting, in a response to a request from a user terminal of another user in the information sharing system, a second Verifiable Presentation to the user terminal, the second Verifiable Presentation including: the first Verifiable Credential, a third decentralized identifier of the computer operating as the service provider device, and third signature information which is signed by the computer operating as the service provider device, thereby the user terminal performs processing including:

receiving the second Verifiable Presentation from the computer operating as the service provider device;

acquiring, from the data registry of the decentralized identity infrastructure, second public key information of the computer operating as the service provider device associated with the third decentralized identifier included in the second Verifiable Presentation;

verifying whether the second Verifiable Presentation is information transmitted from the computer, by using the second public key information and the third signature information in the second Verifiable Presentation;

acquiring, from the data registry of the decentralized identity infrastructure, third public key information of the issuing authority associated with the second decentralized identifier included in the first Verifiable Presentation;

verifying whether the attribute information in the first Verifiable Presentation embedded in the second Verifiable Presentation is information issued by the issuing authority, based on the third public key information and the first signature information included in the first Verifiable Presentation embedded in the second Verifiable Presentation.

2 . The non-transitory computer-readable recording medium according to claim 1 , wherein

the distribution content is evaluation content of the user for a product purchased via a website provided by the service provider device, and

the attribute information on the user is credential information regarding a credential owned by the user,

the issuing authority is a certification authority that certifies the credential,

the distribution information is posted information configured to post the evaluation content for the purchased product to the website,

the receiving of the distribution information includes

receiving the posted information obtained by attaching the credential information on the user that includes the first signature information of the issuing authority, to the evaluation content for the purchased product, and

the verifying of the computer includes

verifying whether the posted information is a post from the user having the credential information issued by a valid authority, by using the first signature information.

3 . An information management method implemented by a computer operating as a service provider device in an information sharing system, the information management method comprising:

receiving, from a posting device in the information sharing system, distribution information obtained by attaching, to distribution content to be distributed by a user, attribute information on the user that includes first signature information that is signed by an issuing authority that issues information regarding an attribute of the user and that proves that the issuing authority has issued the attribute information;

verifying whether the attribute information on the user included in the distribution information is the attribute information issued by the issuing authority, by using the first signature information; and

outputting the distribution content, based on a verification result, wherein

the issuing authority, the posting device, and the computer operating as the service provider device are devices that constitute the information sharing system with a decentralized identity infrastructure as a platform and specify each other by using a respective decentralized identifier,

the receiving includes

receiving, as the distribution information, a first Verifiable Credential from the posting device, the first Verifiable Credential being issued by the posting device operating as an Issuer and including: the distribution content, a first Verifiable Presentation of the user, a first decentralized identifier of the posting device of the user, and second signature information signed by the posting device of the user, the first Verifiable Presentation including the attribute information of the user issued by the issuing authority and a second decentralized identifier of the issuing authority,

the verifying includes:

acquiring, from a data registry of the decentralized identity infrastructure, first public key information of the posting device of the user associated with the first decentralized identifier included in the first Verifiable Credential; and

verifying whether the first Verifiable Credential has been issued by the posting device of the user, by using the first public key information and the second signature information, and

the outputting includes: when a result of the verifying indicates that the first Verifiable Credential has been issued by the posting device of the user,

outputting, in a response to a request from a user terminal of another user in the information sharing system, a second Verifiable Presentation to the user terminal, the second Verifiable Presentation including: the first Verifiable Credential, a third decentralized identifier of the computer operating as the service provider device, and third signature information which is signed by the computer operating as the service provider device, thereby the user terminal performs processing including:

receiving the second Verifiable Presentation from the computer operating as the service provider device;

acquiring, from the data registry of the decentralized identity infrastructure, second public key information of the computer operating as the service provider device associated with the third decentralized identifier included in the second Verifiable Presentation;

verifying whether the second Verifiable Presentation is information transmitted from the computer, by using the second public key information and the third signature information in the second Verifiable Presentation;

acquiring, from the data registry of the decentralized identity infrastructure, third public key information of the issuing authority associated with the second decentralized identifier included in the first Verifiable Presentation;

verifying whether the attribute information in the first Verifiable Presentation embedded in the second Verifiable Presentation is information issued by the issuing authority, based on the third public key information and the first signature information included in the first Verifiable Presentation embedded in the second Verifiable Presentation.

4 . An information management apparatus being a computer operating as a service provider device in an information sharing system, the information management apparatus comprising:

a memory; and

a processor coupled to the memory, the processor being configured to perform processing including:

receiving, from a posting device in the information sharing system, distribution information obtained by attaching, to distribution content to be distributed by a user, attribute information on the user that includes first signature information that is signed by an issuing authority that issues information regarding an attribute of the user and that proves that the issuing authority has issued the attribute information;

verifying whether the attribute information on the user included in the distribution information is the attribute information issued by the issuing authority, by using the first signature information; and

outputting the distribution content, based on a verification result, wherein

the issuing authority, the posting device, and the computer operating as the service provider device are devices that constitute the information sharing system with a decentralized identity infrastructure as a platform and specify each other by using a respective decentralized identifier,

the receiving includes

receiving, as the distribution information, a first Verifiable Credential from the posting device, the first Verifiable Credential being issued by the posting device operating as an Issuer and including: the distribution content, a first Verifiable Presentation of the user, a first decentralized identifier of the posting device of the user, and second signature information signed by the posting device of the user, the first Verifiable Presentation including the attribute information of the user issued by the issuing authority and a second decentralized identifier of the issuing authority,

the verifying includes:

acquiring, from a data registry of the decentralized identity infrastructure, first public key information of the posting device of the user associated with the first decentralized identifier included in the first Verifiable Credential; and

verifying whether the first Verifiable Credential has been issued by the posting device of the user, by using the first public key information and the second signature information, and

the outputting includes: when a result of the verifying indicates that the first Verifiable Credential has been issued by the posting device of the user,

outputting, in a response to a request from a user terminal of another user in the information sharing system, a second Verifiable Presentation to the user terminal, the second Verifiable Presentation including: the first Verifiable Credential, a third decentralized identifier of the computer operating as the service provider device, and third signature information which is signed by the computer operating as the service provider device, thereby the user terminal performs processing including:

receiving the second Verifiable Presentation from the computer operating as the service provider device;

acquiring, from the data registry of the decentralized identity infrastructure, second public key information of the computer operating as the service provider device associated with the third decentralized identifier included in the second Verifiable Presentation;

verifying whether the second Verifiable Presentation is information transmitted from the computer, by using the second public key information and the third signature information in the second Verifiable Presentation;

acquiring, from the data registry of the decentralized identity infrastructure, third public key information of the issuing authority associated with the second decentralized identifier included in the first Verifiable Presentation;

verifying whether the attribute information in the first Verifiable Presentation embedded in the second Verifiable Presentation is information issued by the issuing authority, based on the third public key information and the first signature information included in the first Verifiable Presentation embedded in the second Verifiable Presentation.

5 . An information sharing system comprising:

a first computer operating as a posting device in the information sharing system;

a second computer operating as a service provider device in the information sharing system; and

a third computer operating as a user terminal, wherein

the first computer includes a first hardware processor configured to perform processing including

transmitting, to the second computer operating as the service provider device, distribution information obtained by attaching, to distribution content to be distributed by a user of the posting device, attribute information on the user that includes first signature information that is signed by an issuing authority that issues information regarding an attribute of the user and that proves that the issuing authority has issued the attribute information,

the second computer includes a second hardware processor configured to perform processing including:

receiving the distribution information from the first computer operating as the posting device;

verifying whether the attribute information on the user included in the distribution information is the attribute information issued by the issuing authority, by using the first signature information; and

outputting the distribution content, based on a verification result, wherein

the issuing authority, the posting device, and the second computer operating as the service provider device are devices that constitute the information sharing system with a decentralized identity infrastructure as a platform and specify each other by using a respective decentralized identifier,

the receiving includes

receiving, as the distribution information, a first Verifiable Credential from the first computer operating as the posting device, the first Verifiable Credential being issued by the posting device operating as an Issuer and including: the distribution content, a first Verifiable Presentation of the user, a first decentralized identifier of the posting device of the user, and second signature information signed by the first computer operating as the posting device of the user, the first Verifiable Presentation including the attribute information of the user issued by the issuing authority and a second decentralized identifier of the issuing authority,

the verifying includes:

acquiring, from a data registry of the decentralized identity infrastructure, first public key information of the posting device of the user associated with the first decentralized identifier included in the first Verifiable Credential; and

verifying whether the first Verifiable Credential has been issued by the posting device of the user, by using the first public key information and the second signature information,

the outputting includes:

when a result of the verifying indicates that the first Verifiable Credential has been issued by the posting device of the user, outputting, in a response to a request from a user terminal of another user in the information sharing system, a second Verifiable Presentation to the user terminal, the second Verifiable Presentation including: the first Verifiable Credential, a third decentralized identifier of the second computer operating as the service provider device, and third signature information which is signed by the second computer operating as the service provider device, and

the third computer includes a third hardware processor configured to perform processing including:

receiving the second Verifiable Presentation from the second computer operating as the service provider device;

acquiring, from the data registry of the decentralized identity infrastructure, second public key information of the second computer operating as the service provider device associated with the third decentralized identifier included in the second Verifiable Presentation;

verifying whether the second Verifiable Presentation is information transmitted from the second computer, by using the second public key information and the third signature information in the second Verifiable Presentation;

acquiring, from the data registry of the decentralized identity infrastructure, third public key information of the issuing authority associated with the second decentralized identifier included in the first Verifiable Presentation;

verifying whether the attribute information in the first Verifiable Presentation embedded in the second Verifiable Presentation is information issued by the issuing authority, based on the third public key information and the first signature information included in the first Verifiable Presentation embedded in the second Verifiable Presentation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: YAMAOKA, MEBAE
To: FUJITSU LIMITED
Reel/Frame 063966/0845 →
Priority Claims (1)
JP 2022-153900 · Sep 27, 2022 · national
Continuity (1)
Related Publication 20240106834A1 · Mar 28, 2024
References Cited (23)
US 9660978B1 · Truskovsky · 2017 [cited by examiner]
US 11012233B1 · Uhr et al. · 2021 [cited by applicant]
US 20120221479A1 · Schneck, III · 2012 [cited by examiner]
US 20120311663A1 · Seidl · 2012 [cited by examiner]
US 20130219184A1 · Amaya Calvo · 2013 [cited by examiner]
US 20140173287A1 · Mizunuma · 2014 [cited by applicant]
US 20140351907A1 · Noble · 2014 [cited by applicant]
US 20160119147A1 · Saidalavi · 2016 [cited by examiner]
US 20170103472A1 · Shah · 2017 [cited by examiner]
US 20180182001A1 · Ghoshal · 2018 [cited by examiner]
US 20180232515A1 · Guo · 2018 [cited by examiner]
US 20210209070A1 · Latorre · 2021 [cited by examiner]
US 20210218574A1 · Mao · 2021 [cited by examiner]
US 20210256505A1 · Peng · 2021 [cited by examiner]
US 20220272085A1 · Novotny · 2022 [cited by examiner]
US 20230230144A1 · Lavasanijou · 2023 [cited by examiner]
US 20230410159A1 · Zavesky · 2023 [cited by examiner]
US 20240022908A1 · Baskaran · 2024 [cited by examiner]
WO 2013008778A1 · 2013 [cited by applicant]
WO 2022030570A1 · 2022 [cited by applicant]
EESR—Extended European Search Report dated Dec. 4, 2023 for corresponding European Patent Application No. 23178636.9 [8 pages]. [cited by applicant]
EPOA—European Office Action dated Sep. 30, 2025 for corresponding European Patent Application No. 23178636.9 [12 pages]. [cited by applicant]
JPOA—Japanese Office Action mailed Dec. 23, 2025 for corresponding Japanese Patent Application No. 2022-153900 with machine translation. ** Remaining U.S. References cited in the JPOA were previously submitted in the ID… [cited by applicant]