Terminal, information processing method, and program product

By exchanging electronic information between terminals and verifying the validity of signatures and certificates, the problem of inaccurate tracking of mobile objects in the prior art is solved, and safe utilization relationship tracking is achieved, which is suitable for the utilization scenarios of diverse mobile objects such as vehicles, aircraft, and ships.

CN120455028APending Publication Date: 2025-08-08TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411270483.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-09-22
Filing Date
2024-09-11
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The prior art is difficult to effectively track users' utilization of mobile bodies while ensuring safety. Especially in the context of MaaS diversification and settlement efficiency, the problem of mismatching utilization information with actual users has affected the utilization tracking of mobile bodies such as vehicles, aircraft, ships, etc.

Method used

By exchanging electronic information between terminals, generating and verifying electronic signatures and electronic certificates, using the public key of the certification authority to verify the validity of the signatures and certificates, establishing an identifier correspondence between the first object and the second object, and entrusting the management server to record the correspondence.

Benefits of technology

It realizes that under the premise of ensuring security, tracking the utilization relationship between the first object and the second object, ensuring the authenticity and matching of electronic information, and supporting diversified mobile object utilization scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455028A_ABST
    Figure CN120455028A_ABST
Patent Text Reader

Abstract

The invention relates to a terminal, an information processing method, and a program product, and provides a technology effective in tracking the use of a moving body by a user while ensuring security. In a terminal associated with a first object that is one of a moving object and a user, a control unit provides electronic information to another terminal associated with a second object that is the other of the moving object and the user. The control unit acquires the electronic signature of the second object, the electronic certificate of the second object, and the identifier of the second object from the other terminal. The control unit executes the following processes: verifying the validity of the electronic certificate of the second object using the public key of the authentication authority; and verifying the validity of the electronic signature of the second object using the public key of the second object included in the electronic certificate of the second object. The control unit delegates the setting of the correspondence relationship between the identifier of the first object and the identifier of the second object to the management server in response to the success of verification of the validity of the electronic certificate and the electronic signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a terminal, an information processing method, and a program product. Background Art

[0002] Patent Document 1 proposes a fee collection system for collecting service fees from vehicle users using a medium such as a card. Specifically, the fee collection system proposed in Patent Document 1 is configured to allocate a request for highway usage fees for a rental vehicle to a target user based on the corresponding relationship (charging information, registration information, settlement information, and usage information) between the ETC (Electronic Toll Collection System) card ID, the rental vehicle company, the rental vehicle usage date and time, and the rental vehicle user.

[0003] Patent Document 1: Japanese Patent Application Laid-Open No. 2022-140747 Summary of the Invention

[0004] An object of the present disclosure is to provide a technology that is effective in tracking a user's use of a mobile object while ensuring safety.

[0005] A first terminal according to the present disclosure is a terminal associated with a first target that is one of a mobile object and a user, and includes a control unit configured to execute the following processing:

[0006] providing electronic information to another terminal associated with a second object that is the other of the mobile object and the user;

[0007] acquiring, from the other terminal, an electronic signature of the second subject generated using the electronic information, an electronic certificate of the second subject issued by a certification authority, and an identifier of the second subject;

[0008] Use the public key of the above-mentioned certification authority to verify the validity of the above-mentioned electronic certificate obtained;

[0009] Verifying the validity of the obtained electronic signature using the public key of the second object included in the electronic certificate; and

[0010] Upon successful verification of the validity of the electronic certificate and the electronic signature, a request for setting the correspondence relationship between the identifier of the first object and the identifier of the second object is transmitted to a management server.

[0011] The information processing method according to the second aspect of the present disclosure is a method in which a terminal associated with a first object, which is one of a mobile object and a user, performs the following processing:

[0012] providing electronic information to another terminal associated with a second object that is the other of the mobile object and the user;

[0013] acquiring, from the other terminal, an electronic signature of the second subject generated using the electronic information, an electronic certificate of the second subject issued by a certification authority, and an identifier of the second subject;

[0014] Use the public key of the above-mentioned certification authority to verify the validity of the above-mentioned electronic certificate obtained;

[0015] Verifying the validity of the obtained electronic signature using the public key of the second object included in the electronic certificate; and

[0016] Upon successful verification of the validity of the electronic certificate and the electronic signature, a request for setting the correspondence relationship between the identifier of the first object and the identifier of the second object is transmitted to a management server.

[0017] A program product according to a third aspect of the present disclosure is configured to cause a terminal associated with a first object, which is one of a mobile object and a user, to execute the following processing:

[0018] providing electronic information to another terminal associated with a second object that is the other of the mobile object and the user;

[0019] acquiring, from the other terminal, an electronic signature of the second subject generated using the electronic information, an electronic certificate of the second subject issued by a certification authority, and an identifier of the second subject;

[0020] Use the public key of the above-mentioned certification authority to verify the validity of the above-mentioned electronic certificate obtained;

[0021] Verifying the validity of the obtained electronic signature using the public key of the second object included in the electronic certificate; and

[0022] Upon successful verification of the validity of the electronic certificate and the electronic signature, a request for setting the correspondence relationship between the identifier of the first object and the identifier of the second object is transmitted to a management server.

[0023] In addition, another embodiment of the present disclosure may be a non-transitory storage medium storing the program product.

[0024] According to the present disclosure, it is possible to provide a technology that is effective in tracking a user's use of a mobile object while ensuring safety. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is a diagram schematically showing an example of a scenario in which the present disclosure is applied.

[0026] Figure 2 It is a diagram schematically showing an embodiment of a scenario in which the present disclosure is applied.

[0027] Figure 3 This is a diagram schematically showing an example of the hardware configuration of the management server in the embodiment.

[0028] Figure 4 This is a diagram schematically showing an example of the hardware configuration of the first server in the embodiment.

[0029] Figure 5 This is a diagram schematically showing an example of the hardware configuration of the second server in the embodiment.

[0030] Figure 6 This is a diagram schematically showing an example of the hardware configuration of the first terminal in the embodiment.

[0031] Figure 7 This is a diagram schematically showing an example of the hardware configuration of the second terminal in the embodiment.

[0032] Figure 8 This is a diagram schematically showing an example of the software configuration of each device according to the embodiment.

[0033] Figure 9 This is a diagram schematically showing an example of association information in the embodiment.

[0034] Figure 10 This is a diagram schematically showing an example of first object information in the embodiment.

[0035] Figure 11 This is a diagram schematically showing an example of the second object information in the embodiment.

[0036] Figure 12 This is a sequence diagram showing an example of a process procedure for association setting according to the embodiment.

[0037] Figure 13 It is a diagram schematically showing a first modification example of a scenario in which the present disclosure is applied.

[0038] Figure 14 This is a diagram schematically showing an example of the hardware configuration of the third terminal in a modified example.

[0039] Figure 15 This is a diagram schematically showing an example of the software configuration of each device according to a modification.

[0040] Figure 16This is a diagram schematically showing an example of the second object information in a modified example.

[0041] Figure 17 This is a diagram schematically showing an example of association information in a modified example.

[0042] Figure 18 It is a diagram schematically showing a second modified example of a scenario in which the present disclosure is applied. DETAILED DESCRIPTION

[0043] According to the conventional system proposed in Patent Document 1, users can pay highway tolls using ETC even if they do not have their own ETC cards. However, the inventors of the present application have discovered the following problems with the conventional system.

[0044] Specifically, it is believed that with the diversification of MaaS (Mobility as a Service), there is a growing demand for tracking user usage of mobile vehicles while ensuring safety, for reasons of convenience, such as improved billing efficiency. In contrast, existing systems can maintain usage information, corresponding to the date and time of use and the user, based on rental car contracts or reservations. However, because this usage date and time depends on the contract or reservation, this usage information does not necessarily correspond to the user's actual use of the rental vehicle. Furthermore, the generation of usage information for vehicles used without contracts or reservations (e.g., private cars, company cars, etc.) is not inherently designed. Therefore, existing systems make it difficult to track user usage of mobile vehicles while ensuring safety. Furthermore, this problem is not limited to vehicle usage scenarios. Similar issues can also arise in scenarios involving the use of mobile vehicles other than vehicles (e.g., aircraft, ships, etc.), as well as in scenarios involving the use of multiple types of mobile vehicles. Furthermore, the same problem can arise in all usage scenarios other than mobile vehicles.

[0045] In view of this, the terminal involved in the first method of the present disclosure is a terminal associated with a first object as one party of a mobile body and a user, and has a control unit configured to perform the following processing: providing electronic information to other terminals associated with a second object as the other party of the above-mentioned mobile body and the above-mentioned user; obtaining an electronic signature generated using the above-mentioned electronic information, an electronic certificate of the above-mentioned second object issued by a certification authority, and an identifier of the above-mentioned second object from the above-mentioned other terminals; using the public key of the above-mentioned certification authority to verify the validity of the above-mentioned electronic certificate obtained; using the public key of the above-mentioned second object included in the above-mentioned electronic certificate to verify the validity of the above-mentioned electronic signature obtained; and sending a setting delegation of the correspondence (association establishment) between the identifier of the above-mentioned first object and the above-mentioned identifier of the above-mentioned second object to the management server based on the successful verification of the validity of the above-mentioned electronic certificate and the above-mentioned electronic signature.

[0046] In one example, the provision of electronic information from a terminal associated with a first object (hereinafter also referred to as the "first terminal") to another terminal associated with a second object (hereinafter also referred to as the "second terminal") can be performed based on the establishment of a utilization relationship between a moving object and a user. The establishment of a utilization relationship between a moving object and a user refers to the user starting to utilize the moving object. The user starting to utilize the moving object can include, for example, the user boarding the moving object, the user starting to rent the moving object, and the user passing through the ticket gate of the moving object. The electronic information can be a random number generated by the control unit of the first terminal, or a timestamp, etc.

[0047] The second terminal, having received the electronic information provided by the first terminal, uses the electronic information to generate an electronic signature corresponding to the second object. For example, the electronic signature of the second object can be generated by encrypting predetermined information including the electronic information and the identifier of the second object using a key corresponding to the public key of the second object. The electronic signature of the second object generated by the second terminal is provided to the first terminal along with the electronic certificate of the second object issued by a certification authority and the identifier of the second object.

[0048] Furthermore, data exchange between the first terminal and the second terminal may be performed through wireless or wired data communication, or may be performed through methods other than data communication, such as reading a two-dimensional code.

[0049] In the first terminal that receives the electronic signature of the second object, the electronic certificate of the second object, and the identifier of the second object, the control unit verifies the validity of the electronic certificate of the second object using the public key of the certification authority. In one example, verifying the validity of the electronic certificate of the second object may include: using the public key of the certification authority to decode the electronic signature of the certification authority included in the electronic certificate; using the owner identification information of the second object included in the electronic certificate and the public key of the second object to verify the validity of the information from which the electronic signature of the certification authority is decoded; and determining whether the electronic certificate has not expired. In addition, the verification of the validity of the electronic certificate of the second object may also be performed by an external server that maintains the public key of the certification authority. In addition, in one example, the certification authority is a third-party organization that performs certification-related services such as issuing an electronic certificate for the second object.

[0050] Furthermore, the control unit of the first terminal verifies the validity of the second subject's electronic signature using the second subject's public key included in the second subject's electronic certificate. In one example, verifying the validity of the second subject's electronic signature may include: decrypting the second subject's electronic signature using the second subject's public key included in the second subject's electronic certificate; and comparing the decoded second subject's electronic signature information with the aforementioned specified information. If the comparison between the decoded second subject's electronic signature information and the aforementioned specified information is successful, it is proven that the second subject's electronic signature was generated using the second subject's key (the key corresponding to the second subject's public key included in the second subject's electronic certificate) and the electronic information provided by the first terminal. This ensures that the source of the second subject's electronic signature possesses the second subject's key and that the destination of the electronic information matches the source of the second subject's electronic signature. In other words, the matching of the source of the second subject's electronic signature with the second subject, whose identity has been verified by the certification authority, is guaranteed. Therefore, if the comparison between the decoded second subject's electronic signature information and the aforementioned specified information is successful, the control unit of the first terminal determines that the second subject's electronic signature is valid.

[0051] Furthermore, the order in which the validity of the second subject's electronic certificate and the second subject's electronic signature are verified can be arbitrary. In one example, the validity of the second subject's electronic signature can be verified after the validity of the second subject's electronic certificate is verified. In another example, the validity of the second subject's electronic certificate can be verified after the validity of the second subject's electronic signature is verified. In yet another example, the validity of the second subject's electronic certificate and the second subject's electronic signature can be verified at least partially in parallel.

[0052] If the validity of the electronic certificate and the electronic signature of the second object are successfully verified, the authenticity of the second object can be determined to be guaranteed. Therefore, if the validity of the electronic certificate and the electronic signature of the second object are successfully verified, the control unit of the first terminal sends a request to the management server to set a correspondence (establish an association) between the identifier of the first object and the identifier of the second object. As a result, the correspondence (establish an association) between the identifier of the first object and the identifier of the second object is set in the management server. By recording this setting, the utilization relationship between the first object and the second object can be tracked.

[0053] Therefore, according to the first aspect of the present disclosure, the correspondence (association) between the identifier of the first object and the identifier of the second object can be established under the condition that the authenticity of the second object is guaranteed. As a result, the utilization relationship between the first object and the second object can be tracked while ensuring security.

[0054] Other aspects of the present disclosure may be an information processing method in which a computer executes the processing of the first terminal, a program for causing a computer to execute the processing of the first terminal, or a non-transitory storage medium storing the program. The non-transitory storage medium referred to here is a storage medium that is readable by a machine such as a computer, and is a medium that stores information such as a program through electrical, magnetic, optical, mechanical or chemical effects. In addition, one aspect of the present disclosure may be any one of the second terminal and the management server related to the first terminal involved in the above-mentioned aspect. Furthermore, one aspect of the present disclosure may be an information processing method related to any one of the second terminal and the management server, a program, or a non-transitory storage medium storing the program.

[0055] Hereinafter, an embodiment of the present disclosure will be described based on the accompanying drawings. The configuration of the following embodiment is illustrative, wherein the embodiment described below is merely an illustrative embodiment of the present disclosure in all respects. Various improvements or modifications may be made without departing from the scope of the present disclosure. When implementing the present disclosure, a specific configuration corresponding to the embodiment may be appropriately adopted. Among them, the data appearing in the present embodiment is described by natural language, and more specifically, is specified by computer-recognizable pseudo-language, instructions, parameters, machine language, etc.

[0056] <Implementation Method>

[0057] Figure 1An example of a scenario in which the present disclosure is applied is schematically shown. The management system 100 involved in this embodiment includes a management server 1, a first server 2, a second server 3, a first terminal 4 and a second terminal 5. The management server 1 is one or more computers configured to record the correspondence (association establishment) between the first object and the second object. The first server 2 is one or more computers configured to perform authentication of the first object. The second server 3 is one or more computers configured to perform authentication of the second object. The first server 2 and the second server 3 can be respectively referred to as authentication servers, ID (identification) servers, etc. At least one of the first server 2 and the second server 3 can be equipped by a third-party organization such as a certification body, a public organization, a neutral organization, or an enterprise (manufacturer or service operation company, etc.). The first terminal 4 is a computer corresponding to the first object, which is equivalent to the "terminal" involved in the present disclosure. The second terminal 5 is a computer corresponding to the second object, which is equivalent to the "other terminal" involved in the present disclosure.

[0058] In this embodiment, when a utilization relationship is established between the first object and the second object, data exchange is performed between the first terminal 4 of the first object and the second terminal 5 of the second object (steps SA101-SA102). Figure 1 In the application example shown, first, the first terminal 4 provides electronic information to the second terminal 5 (step SA101). Upon receiving the electronic information provided by the first terminal 4, the second terminal 5 uses predetermined information including the electronic information and the identifier of the second object (hereinafter also referred to as the "second identifier") and the key of the second object to generate an electronic signature for the second object. The second terminal 5 then provides the generated electronic signature of the second object, the second identifier of the second object, and the electronic certificate of the second object to the first terminal 4 (step SA102).

[0059] Upon receiving the electronic signature, second identifier, and electronic certificate of the second subject provided by the second terminal 5, the first terminal 4 sends the second identifier and electronic certificate of the second subject to the second server 3, thereby delegating the verification of the validity of the second identifier and electronic certificate of the second subject to the second server 3 (step SA103). Upon receiving this delegation, the second server 3 verifies the validity of the electronic certificate and second identifier of the second subject and transmits the verification result to the first terminal 4 (step SA104).

[0060] Furthermore, the first terminal 4 verifies the validity of the electronic signature of the second subject received from the second terminal 5 (step SA105). The validity of the electronic signature of the second subject is verified using the public key of the second subject included in the electronic certificate of the second subject, the identifier of the second subject provided by the second subject, and the electronic information provided from the first terminal 4 to the second terminal 5 in step SA101.

[0061] In addition, Figure 1 In the example shown, the validity of the electronic signature of the second object is verified after the validity of the electronic certificate of the second object is verified. However, the order of verifying the validity of the electronic certificate of the second object and the validity of the electronic signature of the second object may be arbitrary.

[0062] If the verification of the validity of the electronic certificate, second identifier and electronic signature of the second object is successful, the first terminal 4 entrusts the setting of the correspondence (association establishment) between the first identifier and the second identifier to the management server 1 by sending the identifier of the first object (hereinafter also referred to as the "first identifier") and the second identifier to the management server 1 (step SA106).

[0063] The management server 1 that receives the setting request for the correspondence between the first identifier and the second identifier sets the correspondence between the first identifier and the second identifier (step SA107). In one example, the management server 1 generates association establishment information indicating the setting of the correspondence between the first identifier and the second identifier, and records the generated association establishment information. The management server 1 can return the result of the association establishment process to at least one of the first terminal 4 and the second terminal 5. In addition, a series of processes from the data exchange between the first terminal 4 and the second terminal to the association establishment setting can be performed in real time according to the generation of the utilization relationship. The set association establishment (correspondence) can be appropriately terminated according to the disappearance of the utilization relationship between the first object and the second object. Setting the correspondence between the first identifier and the second identifier can be processed as setting the correspondence between the first object and the second object.

[0064] Furthermore, upon receiving the request to set the correspondence between the first and second identifiers, the management server 1 may authenticate the first target through the first server 2 and set the correspondence between the first and second identifiers upon successful authentication.

[0065] As described above, in this embodiment, the authenticity of the second object is verified based on the generation of a utilization relationship between the first object and the second object (steps SA101 to SA105). As a result, security can be expected to be ensured. In addition, when the authenticity of the second object is successfully verified, the correspondence between the first identifier and the second identifier is set (association establishment) (steps SA106 to SA107). Through the record of the association establishment setting, the utilization relationship between the first object and the second object can be tracked. Therefore, according to this embodiment, the utilization relationship between the first object and the second object can be tracked while ensuring security.

[0066] (Target)

[0067] As long as the utilization relationship between the first object and the second object can be established, there is no special limitation and they can be appropriately selected according to the implementation method. The first object and the second object can be any object, a person, other living things, etc. Any thing can include a virtual thing. The utilization relationship can be established, for example, by one party using the other party, one party holding the other party, one party combining with the other party, one party connecting with the other party, etc., to generate a real or virtual relationship between at least two things. The management system 100 of the present disclosure can be used in any scenario of tracking the corresponding relationship between two or more things.

[0068] (terminal)

[0069] The first terminal 4 and the second terminal are associated with the first object and the second object, respectively. The relationship between the first terminal 4 and the first object, and the relationship between the second terminal and the second object may not be particularly limited and may be appropriately determined according to the implementation method. In one example, either the first terminal 4 or the second terminal 5 may be held by the corresponding object. In another example, either the first terminal 4 or the second terminal 5 may be loaded on the corresponding object. Loading includes not only always being placed on the object, but also being at least temporarily placed on the object when the object is in use. Loading may include being held by the user of the object. In addition, either the first terminal 4 or the second terminal 5 may also be the object itself.

[0070] (Identifier)

[0071] The first and second identifiers are data used to identify each object. As long as they can identify each object, the data format and structure of the first and second identifiers are not particularly limited and can be appropriately selected based on the implementation. In one example, each of the first and second identifiers can be composed of a sequence of symbols including numbers and letters.

[0072] The first identifier and the second identifier can be obtained as appropriate. In one example, at least one of the first identifier and the second identifier can be pre-stored in the corresponding terminal. In another example, at least one of the first identifier and the second identifier can be obtained by any device such as an input device or a sensor. For example, at least one of the first identifier and the second identifier can be obtained by input via an input device. In addition, for example, at least one of the first identifier and the second identifier can be converted into a code, and at least one of the first identifier and the second identifier can be obtained by reading (decoding) the code.

[0073] (Server 1 and Server 2)

[0074] Each of the first server 2 and the second server 3 can be composed of one or more server devices. Each of the first server 2 and the second server 3 can be configured to manage object information related to each object and perform authentication of each object upon request. Object information related to each object can be stored in one or more storage devices provided inside or outside the first server 2 and the second server 3.

[0075] The object information managed by the first server 2 and the second server 3 may include information specific to the respective objects. Furthermore, in this embodiment, the object information managed by the second server 3 includes information used for authentication of the second object. For example, the information used for authentication of the second object may be pre-registered at any time before the association establishment is delegated (e.g., when the second object's account is created).

[0076] The success or failure of the authentication of the second object is determined by verifying the validity of the electronic certificate of the second object received from the first terminal 4, and comparing the registered information associated with the second identifier received from the first terminal 4 with the information included in the electronic certificate of the second object. The comparison method can be appropriately selected according to the implementation method. In a simple example, the success or failure of the authentication can be determined based on whether the registered information associated with the second identifier and the information included in the electronic certificate of the second object are consistent. In another example, the success or failure of the authentication can be determined based on the degree of consistency between the registered information associated with the second identifier and the information included in the electronic certificate of the second object. The comparison can use a trained model generated by machine learning. During the comparison, the registered information corresponding to the second identifier and the information included in the electronic certificate of the second object can be compared directly, or can be compared indirectly after being converted into feature quantities, etc.

[0077] The unit of information managed by the first server 2 and the second server 3 may not be particularly limited and may be appropriately determined according to the implementation method. That is, the information managed by the first server 2 and the second server 3 may be centrally (unified) managed or decentralized (independently) managed according to each arbitrary group. In addition, the server devices constituting the first server 2 and the second server 3 may be equipped by more than one operating organization (subject). At least one of the first server 2 and the second server 3 may also be equipped by multiple operating organizations. In the case of being equipped by multiple operating organizations, the information to be managed may be shared (that is, may be centrally managed) or may be decentralized and managed for each operating organization.

[0078] (Management Server)

[0079] The management server 1 may be composed of one or more server devices. The management server 1 of the present disclosure is configured to record information related to the creation and disappearance of a correspondence between a first object and a second object as association information. The association information may be stored in one or more storage devices, at least one of which is internal or external to the management server 1.

[0080] The association establishment information recorded by the management server 1 can be used in various scenarios. In one example, the association establishment information can be used to track the utilization relationship between the first object and the second object. As a specific example, the association establishment information can be used to enable either the first object or the second object to exercise the authority to establish an association with the other object during the period in which the corresponding relationship between the first object and the second object is set. That is, the association establishment information can be used to validate the authority of either the first object or the second object to exercise the authority of the other object based on the association between the first object and the second object (described later). Figure 2 ).

[0081] (Confirmation of continued use)

[0082] Management server 1 may send a notification indicating the result of the association establishment process to at least one of first terminal 4 and second terminal 5. The path for sending the notification is not particularly limited and may be determined appropriately depending on the implementation. In one example, management server 1 may directly notify at least one of first terminal 4 and second terminal 5. In another example, management server 1 may indirectly notify at least one of first terminal 4 and second terminal 5 via an external computer such as first server 2 or second server 3.

[0083] After the management server 1 sets the correspondence between the first object and the second object, the management server 1 may further execute a process for confirming whether the correspondence continues (confirmation process). The method for confirming continued use may be appropriately selected depending on the embodiment.

[0084] In one example, when at least one of the first object and the second object is a user (for example, Figure 2 In the case of a confirmation notification, the management server 1 may directly or indirectly send a confirmation notification including an operating element to at least one of the first terminal 4 and the second terminal 5. The operating element may be, for example, a confirmation button, a reply button, a link, etc. The destination of the confirmation notification does not necessarily have to correspond to the user. Figure 2 In this case, management server 1 may send a confirmation notification to at least one of first terminal 4 and second terminal 5. The destination of the confirmation notification may be the same as or different from the destination of the notification indicating the result of the association establishment process. The confirmation notification may be configured to directly or indirectly return a response to management server 1 based on the user's operation of the operating element. Management server 1 may determine that the association relationship is maintained if a response based on the operation of the operating element is received within a predetermined period, and may determine that the association relationship is no longer maintained if no response is received.

[0085] In another example, when tracking the correspondence between a first object and a second object in the real world, the first terminal 4 and the second terminal 5 may be equipped with a positioning module, such as a GPS (Global Positioning Satellite) module or a GNSS (Global Navigation Satellite System) module. The first terminal 4 can use the positioning module to measure the current position of the first object (first terminal 4), and the second terminal 5 can use the positioning module to measure the current position of the second object (second terminal 5). The first terminal 4 and the second terminal 5 can transmit the obtained current positions of each object to the management server 1 directly or indirectly via an external computer (e.g., the first server 2 or the second server 3). The management server 1 can determine whether the correspondence relationship continues based on whether the received current positions of each object are close enough to meet a predetermined condition of the utilization relationship (e.g., the user of one of the first and second objects is riding on the other mobile object). In other words, the management server 1 can determine that the correspondence relationship continues if the current positions of each object are close enough to meet the predetermined condition, and determine that the correspondence relationship does not continue if they are not. Furthermore, when this method is employed, the management server 1 can associate the obtained current location information of each object with the association information and store it. This allows the management server 1 to track the movement history of each object along with its corresponding relationship. Furthermore, at least a portion of the above processing can be performed by a computer other than the management server 1.

[0086] If the management server 1 determines that the correspondence relationship continues, it may maintain the correspondence relationship. On the other hand, if the management server 1 determines that the correspondence relationship does not continue, it may cancel the correspondence relationship. After the correspondence relationship is set, the management server 1 may be configured to update the status of the correspondence relationship by repeating the confirmation process periodically or irregularly until the correspondence relationship is canceled.

[0087] (Remove association)

[0088] In the application example of the present embodiment, the management server 1 may be configured to terminate the correspondence relationship upon receipt of a termination request from at least one of the first terminal 4 and the second terminal 5 or upon satisfaction of a predetermined termination condition.

[0089] (I) Termination of the commission

[0090] In one example, the release request for establishing an association includes at least one of the first and second identifiers. Simply put, the first terminal 4 can send a release request including the first identifier but not the second identifier to the management server 1. Similarly, the second terminal 5 can send a release request including the second identifier but not the first identifier to the management server 1. In cases where duplicate correspondence settings are permitted (when multiple other objects are associated with the first or second object), the release request can include both the first and second identifiers. In one example, the first terminal 4 or the second terminal 5 can send a release request including both the first and second identifiers to the management server 1. In another example, the first terminal 4 can send a release request including one of the first and second identifiers, while the second terminal 5 can send a release request including the other. In yet another example, the management server 1 can assign an identifier to the established correspondence and notify at least one of the first and second terminals 4 and 5 of the assigned identifier at any time, such as when notifying the results of the association establishment process. At least one of the first terminal 4 and the second terminal 5 can specify the correspondence to be released by sending a release delegation message including the identifier to the management server 1, causing the management server 1 to release the specified correspondence. According to one example of this embodiment, the first and second identifiers can be omitted from the information included in the release delegation message. This can improve the efficiency of data communication during the release delegation.

[0091] The revocation of delegation from at least one of the first terminal 4 and the second terminal 5 can be sent directly from the terminal of the delegation source to the management server 1, or can be sent indirectly to the management server 1 via an external computer (e.g., the first server 2 or the second server 3). In addition, the revocation of delegation from at least one of the first terminal 4 and the second terminal 5 can be sent to the management server 1 via the other of the first terminal 4 and the second terminal 5.

[0092] After receiving the deregistration request, the management server 1 refers to the association establishment information and deregisters the association relationship specified by the identifier included in the deregistration request. Following this deregistration, the management server 1 may transmit a notification indicating the deregistration result to at least one of the first terminal 4 and the second terminal 5, similar to the notification during the association establishment process.

[0093] Furthermore, the delegating process may include authentication of the second party. This authentication of the second party may be the same as that used in the association establishment process described above. However, authentication of the second party is not necessarily required when delegating. In another example, omitting authentication can simplify the delegating process.

[0094] The trigger for delegating can be appropriately configured depending on the implementation. In one example, when at least one of the first and second objects is a user, a delegating message can be sent from at least one of the first and second terminals 4, 5, via a user's operation on at least one of the first and second terminals 5. In other words, the trigger for delegating can be a user operation. In another example, arbitrary information processing can be performed by at least one of the first and second terminals 4, 5, as the utilization relationship ends. This arbitrary information processing can serve as a trigger for sending a delegating message from at least one of the first and second terminals 4, 5. For example, the arbitrary information processing can be data exchanged between the first and second terminals 4, 5. The method for data exchange during delegating can be the same as the data exchange during association establishment. It is possible to appropriately distinguish between data exchange during association establishment and data exchange during delegating. For example, the first terminal 4 can be equipped with separate sensor devices at the entrance and exit, similar to bus boarding and alighting gates or railway ticket gates. In this case, the sensor devices used in the data exchange can distinguish whether the data is being exchanged during association establishment or during delegating. In addition, for example, when data exchange is performed by an application in a terminal, the application may be configured to switch between an association setting mode and a de-entrustment mode. In this case, whether the association setting mode or the de-entrustment mode is being distinguished can be determined based on the application mode.

[0095] In addition, arbitrary internal processing may be performed by the first terminal 4 and the second terminal 5 in conjunction with the delegating process. In one example, if the current association establishment information is created by at least one of the first terminal 4 and the second terminal 5, the at least one terminal may update the current association establishment information to the past association establishment information in conjunction with the delegating process. The updating process may be appropriately configured depending on the implementation. For example, the updating process may delete the current association establishment information. In this case, the current association establishment information may be completely deleted or stored as a past association establishment history. Alternatively, the updating process may invalidate the current association establishment information by appending invalidation information, such as an end time or an end flag setting, to the current association establishment information. In the case where one of the first terminal 4 and the second terminal 5 transmits the delegating process, the terminal of one party may transmit a notification notifying the other party of the delegating process or the establishment of the delegating process to the terminal of the other party. If the current association establishment information was created by the terminal of the other party, the terminal of the other party may perform the aforementioned updating process based on the notification.

[0096] (II) Conditions for rescission

[0097] The release condition indicates a condition for releasing the correspondence relationship between the objects. The release condition can be appropriately defined according to the embodiment.

[0098] In one example, the termination condition can be defined as the termination of the correspondence at an arbitrarily set termination time. The termination time can be assigned, for example, by a user or by another application (such as a scheduler). In this case, the management server 1 can terminate the correspondence of the object upon the arrival of the termination time. The termination time can be set to the validity period of the association establishment information. If the termination time is set according to the validity period, the management server 1 can process the termination of the correspondence of the object upon the arrival of the termination time.

[0099] In another example, the termination condition may be defined as discontinuing the corresponding relationship based on the current location of each object failing to satisfy the prescribed conditions of the utilization relationship. Specifically, the termination condition may be defined as discontinuing the corresponding relationship based on a determination that the utilization relationship is no longer continuing during the confirmation process for continued utilization corresponding to the current location of each object.

[0100] As described above, the management server 1 can terminate the correspondence upon receipt of a cancellation request from at least one of the first terminal 4 and the second terminal 5, or upon the satisfaction of a predetermined termination condition. According to one example of this embodiment, the disappearance of the utilization relationship between the first object and the second object can be tracked. Furthermore, the association information after the correspondence is terminated can be stored as a history record.

[0101] (Simplified processing of association establishment settings)

[0102] In one example, if a usage relationship repeatedly occurs and disappears between the same combination of a first object and a second object, the management system 100 can perform authentication processing for the second object each time, repeatedly setting and canceling the corresponding relationship. However, if the frequency of repeated creation and disappearance of the usage relationship is high, performing authentication processing for the same second object each time may increase the load on the management system 100. In particular, if one of the first and second objects is a user and the other is a frequently used mobile object such as a private car, performing authentication processing for the second object each time will increase the load on the management system 100.

[0103] In view of this, in another example, the management system 100 can be configured to set a corresponding relationship for the same combination of the first and second objects by omitting the authentication process for the second object in subsequent association establishment processes. Specifically, the management system 100 can be configured to accept requests to set a corresponding relationship by omitting the authentication process for the second object for a combination of the first and second objects for which a corresponding relationship has previously been established. For ease of explanation, the process of setting a corresponding relationship by omitting the authentication process for the second object will be referred to as "simplified association establishment process," and the process of the normal route without omitting the authentication process will be referred to as "normal association establishment process."

[0104] Furthermore, the relationship between the operating organizations of management server 1, first server 2, and second server 3 can be arbitrary. In one example, the operating organization of management server 1 can overlap with the operating organization of at least one of first server 2 and second server 3. In another example, the operating organization of management server 1 can be different from the operating organizations of first server 2 and second server 3. The management system 100 of the present disclosure can be produced by connecting management server 1 to first server 2, second server 3, first terminal 4, and second terminal 5 via a network, and each of these terminals being configured to execute the aforementioned information processing in accordance with the intention of the operating organization of management server 1.

[0105] [Application Examples]

[0106] In one example, one of the first and second objects may be a user. One of the first and second terminals 4 and 5 that corresponds to the user may be a user terminal associated with the user. The other of the first and second objects may be a mobile object utilized by the user. One of the first and second terminals 4 and 5 that corresponds to the mobile object may be a loading terminal mounted on the mobile object. According to one example of this embodiment, the utilization relationship between the user and the mobile object can be tracked while ensuring security.

[0107] As long as the mobile body can be used by the user, its type is not particularly limited and can be appropriately selected according to the embodiment. In addition, the type of the mobile body can be appropriately selected. The mobile body can be, for example, a vehicle, a railway vehicle, an aircraft (aircraft, unmanned aircraft, etc.), a ship, etc. The mobile body can be at least any one of a manually controlled manned aircraft and an automatically controlled unmanned aircraft. In the case where the mobile body is a vehicle, the type of vehicle can be arbitrarily selected. The type of vehicle can be selected, for example, from two-wheeled vehicles, three-wheeled vehicles, four-wheeled vehicles, etc. Vehicles can include private cars, rental cars, shared cars, taxis, buses, etc. The vehicle can be at least any one of an autonomous driving vehicle and a manually driven vehicle. The loading terminal can be called a mobile body terminal. According to an example of this embodiment, the utilization relationship between the user and the mobile body can be tracked.

[0108] Figure 2 FIG. 1 is a diagram schematically showing an embodiment of a scenario in which the management system 100 of the present disclosure is applied. Figure 2 In the example shown, the first object is a mobile object and the second object is a user. Figure 2 In the description of the example, for convenience, it is assumed that "1" is related to the vehicle and "2" is related to the user.

[0109] When the first object is a mobile object, an example of the first terminal 4 is a mobile object terminal (onboard terminal). Examples of mobile object terminals include terminals installed inside or outside the mobile object, terminals held by people involved in the operation of the mobile object (e.g., drivers, crew members, etc.), and equipment installed on the mobile object (e.g., ticket gates, etc.). When the mobile object is a vehicle, the mobile object terminal can be referred to as an onboard terminal.

[0110] An example of the first identifier is a mobile identifier (mobile ID, car ID). The mobile identifier may be, for example, a mobile account ID, identification information unique to the target mobile object (such as a car registration number, vehicle identification number (VIN)), or identification information of a mobile terminal.

[0111] A mobile object is an example of a usable object. Figure 2 This method can be applied to any situation where the user (occupant) of a property changes dynamically. Besides mobile objects, the property can also be, for example, a leased property or accommodation facility. Leased properties can include leased offices and leased spaces.

[0112] When the second object is a user, an example of the second terminal 5 is a user terminal. A user terminal can be any computer, such as a mobile terminal (smartphone, etc.), a dedicated device (electronic key device, etc.), or another computer device. Typically, the user terminal is carried by the user who is the object of association (the second object). A user's account can be shared across multiple computers, allowing each computer sharing the account to be used as the user terminal (second terminal 5) of the same user.

[0113] An example of the second identifier is a user identifier (user ID, My ID). The user identifier may be, for example, a user account ID, a personal number, or identification information of a user terminal (eg, a MAC address, terminal identification information).

[0114] When the second object is a user, the information managed by the second server 3 includes, in addition to information inherent to the second object (e.g., the user's name, biometric information, personal number, etc.) and information used for authentication of the second object, information related to the corresponding user's authority. Information related to the user's authority can be associated with various information E10 used to exercise that authority. Various information E10 can include, for example, public personal authentication information, settlement information, and information from other service systems. Public personal authentication information can include, for example, personal numbers. Settlement information can include, for example, credit card information, online banking information, electronic settlement information, etc. Information from other service systems can include, for example, information related to electronic prescriptions (insurer number, prescription information, etc.). Various information E10 can be managed in an external system or within the management system 100. Furthermore, the second server 3 can be provided by a certification authority or a partner organization of the certification authority. Partner organizations of the certification authority can be public institutions, neutral organizations, or companies (such as vehicle manufacturers and service operators). The second server 3 can be referred to as a user ID server or a my ID server, etc.

[0115] The management system 100 may be configured to set the association between the first identifier and the second identifier upon the start of use of the mobile object and to release the association upon the end of use. Furthermore, the management system 100 may validate (activate) at least some of the rights that the mobile object corresponding to the first identifier has for exercising various information E10 associated with the user corresponding to the second identifier, based on the setting of the association between the first identifier and the second identifier. Furthermore, the management system 100 may invalidate (deactivate) the aforementioned validated rights upon the release of the association between the first identifier and the second identifier.

[0116] The start and end of use of the mobile body can be detected by any method, for example, at the time of boarding or disembarking the mobile body, or at the time of loaning or returning the mobile body. In one example, at least one of the start and end of use can be detected by executing data exchange between the first terminal 4 and the second terminal 5.

[0117] Furthermore, the application scenarios of the management system 100 disclosed herein are not limited to tracking relationships between users and mobile objects. In another example, both the first object and the second object may be robotic devices configured to operate autonomously through automatic control. Robotic devices may include autonomous vehicles, drones, and other mobile objects. In scenarios where two or more robotic devices interact autonomously, the management system 100 disclosed herein can be used to track the emergence and disappearance of relationships between the robotic devices.

[0118] As a specific example, one of the first object and the second object may be a large autonomous driving vehicle, and the other may be a small autonomous driving vehicle. The large autonomous driving vehicle may be configured to accommodate multiple small autonomous driving vehicles. The large autonomous driving vehicle may appropriately recover, transport, and release each small autonomous driving vehicle. Each small autonomous driving vehicle may be appropriately used at the release destination. In this case, the management system 100 of the present disclosure may be configured to track whether the vehicle is being transported (recovery completed) by setting and releasing the correspondence between the large autonomous driving vehicle and the small autonomous driving vehicle.

[0119] (Data exchange in application examples)

[0120] In the application example of this embodiment, data exchange between the first terminal 4 and the second terminal 5 can be performed ( Figure 2 Steps SA101 and SA102 in the process are used as a trigger to start a series of processes related to association establishment. The method of data exchange is not particularly limited and can be appropriately selected according to the embodiment.

[0121] In one example, data exchange between the first terminal 4 and the second terminal 5 can be performed through wireless or wired data communication. Wireless communication can be performed, for example, through NFC (Near Field Communication), Bluetooth (registered trademark), Wi-Fi (registered trademark), etc. Wired communication can be performed, for example, through a wired LAN (Local Area Network), USB (Universal Serial Bus), etc. Data communication can be performed directly between the first terminal 4 and the second terminal 5, or indirectly via other computers. In another example, data exchange can also be performed by methods other than data communication, such as reading a QR code.

[0122] In this embodiment, data exchange between the first terminal 4 and the second terminal is performed starting with the provision of data (provision of electronic information) from the first terminal 4 to the second terminal 5. Furthermore, in response to this, data is provided from the second terminal 5 to the first terminal 4 (provision of the electronic certificate of the second subject, the second identifier of the second subject, and the electronic signature of the second subject).

[0123] (Electronic certificate for the second object in the application example)

[0124] In the application example of this embodiment, the electronic certificate of the second object is used to verify the authenticity of the second object. Such an electronic certificate is generated by a certification authority. The certification authority is a third-party organization that performs certification-related business such as issuing electronic certificates for the second object. The certification authority generates the electronic certificate of the second object based on the issuance entrustment of the electronic certificate from the user who is the second object. Here, in the case where the second server 3 is a server device equipped by the certification authority, the user who is the second object can entrust the issuance of the electronic certificate through the second server 3. In addition, in the case where the second server 3 is a server device equipped by an organization or enterprise other than the certification authority, the user who is the second object can directly entrust the certification authority to issue the electronic certificate.

[0125] The certification authority that has accepted the issuance commission of the electronic certificate performs identity verification of the second object based on the information used to publicly authenticate the second object (such as a driver's license, a driver's experience certificate, a passport, a personal number card (my number card, various welfare handbooks with facial photos attached to government agencies, etc.). If the identity verification is successful, the certification authority creates the owner identification information of the second object. The certification authority calculates a hash value of the plain text including the owner identification information created and the public key of the second object. The generation of the owner identification information and the composition of the plain text can be changed arbitrarily. The certification authority generates the electronic signature of the certification authority by encrypting the calculated hash value using the certification authority's key. The certification authority generates an electronic certificate including information for reconstructing the plain text (in the above example, the owner identification information of the second object), the public key of the second object, and the electronic signature of the certification authority. The certification authority can register the generated electronic certificate to the repository. In addition, the key and public key of the second object can be generated by the user who is the second object, or can also be generated by the certification authority.

[0126] The electronic certificate generated by the certification authority is transferred to the user serving as the second subject and stored on the second terminal 5. Furthermore, the electronic certificate or the owner identification information included in the electronic certificate may also be transferred from the second subject to the second server 3 as information used in authenticating the second subject and stored on the second server 3. Furthermore, the information used in authenticating the second subject may include, in addition to the owner identification information, the public key of the certification authority used to create the electronic certificate for the second subject. The information used in authenticating the second subject may be stored on the second server 3 in a form associated with the second identifier when the account of the user serving as the second subject is created.

[0127] (Electronic Signature of the Second Target in the Application Example)

[0128] In the application example of this embodiment, the electronic signature of the second object is generated using predetermined information including electronic information provided from the first terminal 4 to the second terminal 5 and a second identifier. In one example, the electronic signature of the second object can be generated by encrypting the predetermined information using the second object's key generated when the second object's electronic certificate was issued. The electronic information used to generate the electronic signature of the second object can be a random number generated by the first terminal 4 or a timestamp. Furthermore, the electronic information is not limited to random numbers or timestamps and can be arbitrarily selected depending on the embodiment.

[0129] In the application examples of the present disclosure, the user's secret key and public key, which are the second object, are referred to as "Second Object Key A" and "Public Key A," respectively, and the certification authority's secret key and public key are referred to as "Second Object Key B" and "Public Key B," respectively. Furthermore, the second object's electronic signature is referred to as "Electronic Signature A," and the certification authority's electronic signature is referred to as "Electronic Signature B."

[0130] (Authentication of the second object in the application example)

[0131] In the application example of this embodiment, authentication of the second object is achieved by verifying the authenticity of the second object. Verification of the authenticity of the second object in this embodiment includes verification of the validity of the electronic certificate of the second object issued by the certification authority, verification of the validity of the second identifier of the second object, and verification of the validity of the electronic signature A of the second object.

[0132] In verifying the validity of the second subject's electronic certificate, the certification authority's electronic signature B included in the second subject's electronic certificate is first decoded using the certification authority's public key B. Furthermore, a hash value is calculated for the owner identification information included in the second subject's electronic certificate and the plaintext of the second subject's public key. Furthermore, the decoded information of the certification authority's electronic signature B is compared with the calculated hash value. If the comparison between the decoded information of the certification authority's electronic signature B and the calculated hash value is successful, the certification authority's repository is referenced to determine whether the second subject's electronic certificate has not expired. If it is determined that the electronic certificate has not expired, the validity verification of the second subject's electronic certificate is determined to be successful.

[0133] Next, the validity of the second identifier of the second object is verified using information (information used in the authentication of the second object) stored on the second server 3 in a form associated with the second identifier. In one example, the information used in the authentication of the second object may include owner identification information generated when the electronic certificate of the second object is created. In this case, the validity of the second identifier is verified by comparing the owner identification information included in the electronic certificate of the second object with the owner identification information registered on the second server 3 in a form associated with the second identifier. If the comparison between the owner identification information included in the electronic certificate of the second object and the owner identification information registered on the second server 3 in a form associated with the second identifier is successful, it is determined that the second identifier of the second object is valid.

[0134] Alternatively, the second server 3 may verify the validity of the second subject's electronic certificate and second identifier. In this case, the first terminal 4 may delegate verification of the validity of the second subject's electronic certificate and second identifier to the second server 3 by transmitting the second identifier and electronic signature B provided by the second terminal 5 to the second server 3. Alternatively, the first terminal 4 may verify the validity of the second subject's electronic certificate and second identifier. In this case, the first terminal 4 only needs to obtain the certification authority's public key B and owner identification information from the second server 3.

[0135] Next, the second subject's electronic signature A is verified using the second subject's public key A, included in the second subject's electronic certificate. To verify the second subject's electronic signature A, the second subject's public key A, included in the second subject's electronic certificate, is first used to decrypt the second subject's electronic signature A. Information about the decoded second subject's electronic signature A is then compared with prescribed information. The prescribed information used in this comparison is generated using the electronic information provided from the first terminal 4 to the second terminal 5 and the second identifier provided from the second terminal to the first terminal 4. If the comparison between the decoded second subject's electronic signature A and the prescribed information is successful, the second subject's electronic signature A is determined to be valid.

[0136] Alternatively, the first terminal 4 can verify the validity of the second subject's electronic signature A. In this case, the first terminal 4 can simply decrypt the second subject's electronic signature A using the public key A included in the electronic certificate provided by the second terminal 5, and generate the specified information using the electronic information provided to the second terminal 5 and the second identifier provided by the second terminal. Alternatively, the second server 3 can verify the validity of the second subject's electronic signature A. In this case, the first terminal 4 can simply delegate the verification of the validity of the second subject's electronic signature A to the second server 3 by transmitting the second subject's electronic certificate, the second subject's electronic signature A, and the specified information to the second server 3.

[0137] If authentication of the second object using the above method is successful, it is proven that electronic signature A was generated using key A of the second object and the electronic information provided from first terminal 4. Therefore, it can be assumed that the source of electronic signature A holds key A of the second object, and that the destination of the electronic information matches the source of electronic signature A. In other words, the matching of the source of electronic signature A with the second object, whose identity has been verified by the authenticated authority, can be guaranteed. Furthermore, the matching of the source of the electronic certificate and second identifier with the second object, which has been registered with second server 3, can also be guaranteed. Therefore, if authentication of the second object is successful, the authenticity of the second object can be considered guaranteed.

[0138] (Use of related information in application examples)

[0139] As described above, association establishment information can be used in various scenarios. In one example, association establishment information can be used to track only the generation and disappearance of the relationship between the first object and the second object. In another example, association establishment information can be used to enable either the first object or the second object to exercise at least a part of the authority to establish an association with the other object during the period in which the corresponding relationship between the first object and the second object is set. Figure 2 In the example of , the association information can be used to enable the mobile object to exercise at least a part of the authority to establish an association with the user while the association relationship between the user and the mobile object is set.

[0140] For example, the use of the mobile object to exercise at least a portion of the rights associated with the user may include, when the user's rights relate to public services, using the mobile object's first identifier to receive the provision of a public service to which the user has rights. Alternatively, the use of the mobile object to exercise at least a portion of the rights associated with the user may include, when the user's rights relate to settlement services, using the mobile object's first identifier to receive the provision of a settlement service to which the user has rights. Examples of settlement services include payment for parking fees, highway fees, drive-through fees, or public transportation fees. Furthermore, the use of the mobile object to exercise at least a portion of the rights associated with the user may include, when the user is a user of an electronic prescription service, using the mobile object's first identifier to receive the provision of an electronic prescription service to which the user has rights. Receiving the provision of an electronic prescription service may include, for example, receiving medication prescribed based on an electronic prescription.

[0141] (Data communication between devices in the application example)

[0142] The data communication between the devices (management server 1, first server 2, second server 3, first terminal 4, and second terminal 5) is not particularly limited and can be appropriately selected according to the implementation method. The network between the devices can be appropriately selected from, for example, the Internet, a wireless communication network, a mobile communication network, a telephone network, a dedicated network, a local area network, etc. Data communication between the devices can be encrypted using methods such as SSL (Secure Socket Layer) and TLS (Transport Layer Security). In one example, the first terminal 4 and the second terminal 5 can have a SIM (Subscriber Identity Module), and data communication between each of the first terminal 4 and the second terminal 5 and the management server 1 can be carried out through encrypted communication using the SIM.

[0143] [Hardware Configuration Example]

[0144] (Management Server)

[0145] Figure 3 This figure schematically shows an example of the hardware configuration of the management server 1 in an application example of this embodiment. The management server 1 according to this embodiment is a computer including a control unit 11, a storage unit 12, a communication interface 13, an input device 14, an output device 15, and a drive 16 electrically connected.

[0146] The control unit 11 includes a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), etc., which are hardware processors, and is configured to execute arbitrary information processing based on programs and various data. The control unit 11 (CPU) is an example of a processor resource of the management server 1.

[0147] The storage unit 12 can be composed of, for example, a hard disk drive, a solid-state drive, or a semiconductor memory. The storage unit 12 (along with RAM and ROM) is an example of a memory resource. In this embodiment, the storage unit 12 stores various information, including a management program 81 and association establishment information D10. The management program 81 is a program that causes the management server 1 to execute information processing related to setting and canceling associations with first and second objects. The management program 81 includes a series of commands for this information processing.

[0148] The communication interface 13 is configured to perform wired or wireless communication via a network. For example, the communication interface 13 may be configured by a wired LAN (Local Area Network) module or a wireless LAN module. The management server 1 can perform data communication with other computers (the first server 2, the second server 3, the first terminal 4, and the second terminal 5) via the communication interface 13.

[0149] The input device 14 is, for example, a device for input, such as a mouse, keyboard, or operation buttons. The output device 15 is, for example, a device for output, such as a display or speaker. An operator can operate the management server 1 using the input device 14 and the output device 15. The input device 14 and the output device 15 can be integrally formed, for example, by a touch panel display. The input device 14 and the output device 15 can be connected via an external interface. The external interface can be appropriately configured to connect to an external device via a USB (Universal Serial Bus) port, a dedicated port, a wireless communication port, or the like, either wired or wirelessly.

[0150] The drive 16 is a device for reading various information such as programs stored in the storage medium 91. At least one of the management program 81 and the association establishment information D10 can be stored in the storage medium 91 instead of the storage unit 12 or in addition to the storage unit 12. The storage medium 91 is configured to store various information (stored programs, etc.) through electrical, magnetic, optical, mechanical or chemical action in a manner that allows a machine such as a computer to read the information. The management server 1 can obtain at least one of the management program 81 and the association establishment information D10 from the storage medium 91. The storage medium 91 can be a disk-type storage medium such as a CD or DVD, or a storage medium other than a disk-type storage medium such as a semiconductor memory (such as a flash memory). The type of the drive 16 can be appropriately selected according to the type of the storage medium 91. The drive 16 can be connected via an external interface.

[0151] In addition, regarding the specific hardware composition of the management server 1, the constituent elements can be appropriately omitted, replaced, and added according to the implementation method. For example, the control unit 11 may include a plurality of hardware processors. The hardware processor may be composed of a microprocessor, an FPGA (field-programmable gate array), a DSP (digital signal processor), a GPU (Graphics Processing Unit), etc. At least any one of the input device 14, the output device 15, and the driver 16 may be omitted. The association establishment information D10 may also be stored in an external computer accessible to the management server 1 (such as NAS: Network Attached Storage, etc.) instead of the storage unit 12. The management server 1 may also be composed of multiple computers. In this case, the hardware composition of each computer may be consistent or inconsistent. In addition to being an information processing device designed specifically for the service to be provided, the management server 1 may also be a general-purpose server device, a general-purpose computer, etc.

[0152] (Server 1)

[0153] Figure 4 An example of the hardware configuration of the first server 2 in an example application of this embodiment is schematically shown. The first server 2 according to this embodiment is a computer comprising a control unit 21, a storage unit 22, a communication interface 23, an input device 24, an output device 25, and a drive 26 electrically connected together. The control unit 21, storage unit 22, communication interface 23, input device 24, output device 25, drive 26, and storage medium 92 of the first server 2 can be configured similarly to the control unit 11, storage unit 12, communication interface 13, input device 14, output device 15, drive 16, and storage medium 91 of the aforementioned management server 1.

[0154] The control unit 21 (CPU) is an example of a processor resource of the first server 2, and the storage unit 22 (as well as RAM and ROM) is an example of a memory resource of the first server 2. In this embodiment, the storage unit 22 stores various information, such as a program 82 and first object information D20. The program 82 is a program for causing the first server 2 to perform information processing targeting the first object. The program 82 includes a series of commands for this information processing. At least one of the program 82 and the first object information D20 can be stored in the storage medium 92 in place of the storage unit 22 or in addition to the storage unit 22. The first server 2 can obtain at least one of the program 82 and the first object information D20 from the storage medium 92. The first server 2 can communicate data with other computers (such as the management server 1) via the communication interface 23. The first server 2 can be operated via the input device 24 and the output device 25.

[0155] In addition, regarding the specific hardware composition of the first server 2, the constituent elements can be appropriately omitted, replaced, and added according to the implementation method. For example, the control unit 21 may include multiple hardware processors. The hardware processor may be composed of a microprocessor, an FPGA, a DSP, a GPU, etc. At least any one of the input device 24, the output device 25, and the driver 26 may be omitted. The first object information D20 may be stored not in the storage unit 22 but in an external computer (such as NAS, etc.) accessible to the first server 2. The first server 2 may be composed of multiple computers. In this case, the hardware composition of each computer may be consistent or inconsistent. In addition to being an information processing device designed specifically for the service to be provided, the first server 2 may also be a general-purpose server device, a general-purpose computer, etc.

[0156] (Server 2)

[0157] Figure 5 This figure schematically illustrates an example of the hardware configuration of the second server 3 in accordance with the application example of this embodiment. The second server 3 in accordance with this embodiment is a computer comprising a control unit 31, a storage unit 32, a communication interface 33, an input device 34, an output device 35, and a drive 36 electrically connected to one another. The control unit 31, storage unit 32, communication interface 33, input device 34, output device 35, drive 36, and storage medium 93 of the second server 3 can be configured similarly to the control unit 11, storage unit 12, communication interface 13, input device 14, output device 15, drive 16, and storage medium 91 of the aforementioned management server 1.

[0158] The control unit 31 (CPU) is an example of a processor resource of the second server 3, and the storage unit 32 (as well as RAM and ROM) is an example of a memory resource of the second server 3. In this embodiment, the storage unit 32 stores various information, such as a program 83 and second object information D30. The program 83 is a program for causing the second server 3 to perform information processing targeting the second object. The program 83 includes a series of commands for this information processing. At least one of the program 83 and the second object information D30 can be stored in the storage medium 93 in place of the storage unit 32 or in addition to the storage unit 32. The second server 3 can obtain at least one of the program 83 and the second object information D30 from the storage medium 93. The second server 3 can communicate data with other computers (such as the management server 1) via the communication interface 33. The second server 3 can be operated via the input device 34 and the output device 35.

[0159] In addition, regarding the specific hardware composition of the second server 3, the constituent elements can be appropriately omitted, replaced, and added according to the implementation method. For example, the control unit 31 may include multiple hardware processors. The hardware processor may be composed of a microprocessor, an FPGA, a DSP, a GPU, etc. At least any one of the input device 34, the output device 35, and the driver 36 may be omitted. The second object information D30 may be stored not in the storage unit 32 but in an external computer (such as NAS, etc.) accessible to the second server 3. The second server 3 may be composed of multiple computers. In this case, the hardware composition of each computer may be consistent or inconsistent. In addition to being an information processing device designed specifically for the service to be provided, the second server 3 may also be a general-purpose server device, a general-purpose computer, etc.

[0160] (Terminal 1)

[0161] Figure 6 An example of the hardware configuration of the first terminal 4 in an application example of this embodiment is schematically shown. The first terminal 4 according to this embodiment is a computer comprising a control unit 41, a storage unit 42, a communication interface 43, an input device 44, an output device 45, and a drive 46 electrically connected. The control unit 41, storage unit 42, communication interface 43, input device 44, output device 45, drive 46, and storage medium 94 of the first terminal 4 can be configured similarly to the control unit 11, storage unit 12, communication interface 13, input device 14, output device 15, drive 16, and storage medium 91 of the aforementioned management server 1.

[0162] The control unit 41 (CPU) is an example of a processor resource of the first terminal 4, and the storage unit 42 (as well as RAM and ROM) is an example of a memory resource of the first terminal 4. In this embodiment, the storage unit 42 stores various information such as a program 84 and a first identifier I10. The program 84 is a program for causing the first terminal 4 to perform information processing related to association establishment. The program 84 includes a series of commands for this information processing. At least one of the program 84 and the first identifier I10 can be stored in the storage medium 94 instead of the storage unit 42 or in addition to the storage unit 42. The first terminal 4 can obtain at least one of the program 84 and the first identifier I10 from the storage medium 94. The first terminal 4 can communicate data with other computers (such as the management server 1 and the second terminal 5) via the communication interface 43. The first terminal 4 can be operated via the input device 44 and the output device 45.

[0163] In addition, regarding the specific hardware structure of the first terminal 4, the components can be appropriately omitted, replaced, and added according to the implementation method. For example, the control unit 41 may include multiple hardware processors. The hardware processor may be composed of a microprocessor, an FPGA, a DSP, a GPU, an ECU (Electronic Control Unit), etc. At least any one of the input device 44, the output device 45, and the driver 46 may be omitted. The first identifier I10 may not be stored in the storage unit 42. The first identifier I10 can be obtained every time. In order to obtain data such as identifiers and inherent information, the first terminal 4 may also have data acquisition devices such as sensors and reading devices. The communication interface 43 can be composed of multiple types of modules. For example, the communication interface 43 can have a proximity wireless communication module and a wireless communication module, and the first terminal 4 communicates data with the second terminal 5 via the proximity wireless communication module and communicates data with the management server 1 via the wireless communication module. The first terminal 4 can be composed of multiple computers. In this case, the hardware structure of each computer may be consistent or inconsistent. The first terminal 4 may be an information processing device designed specifically for the service to be provided, or may be a general-purpose computer, a terminal device for use in a mobile body, or the like.

[0164] (Terminal 2)

[0165] Figure 7An example of the hardware configuration of the second terminal 5 according to this embodiment is schematically shown. The second terminal 5 according to this embodiment is a computer comprising a control unit 51, a storage unit 52, a communication interface 53, an input device 54, an output device 55, and a drive 56 electrically connected. The control unit 51, storage unit 52, communication interface 53, input device 54, output device 55, drive 56, and storage medium 95 of the second terminal 5 can be configured similarly to the control unit 11, storage unit 12, communication interface 13, input device 14, output device 15, drive 16, and storage medium 91 of the aforementioned management server 1.

[0166] The control unit 51 (CPU) is an example of a processor resource of the second terminal 5, and the storage unit 52 (as well as RAM and ROM) is an example of a memory resource of the second terminal 5. In this embodiment, the storage unit 52 stores various information, such as a program 85, the second identifier I20, the electronic certificate EC50, the secret key A, and the public key A. The program 85 is a program for causing the second terminal 5 to perform information processing related to establishing an association. The program 85 includes a series of commands for this information processing. At least one of the program 85, the second identifier I20, the electronic certificate EC50, the secret key A, and the public key A can be stored in the storage medium 95 in place of the storage unit 52 or in addition to the storage unit 52. The second terminal 5 can obtain at least one of the program 85, the second identifier I20, the electronic certificate EC50, the secret key A, and the public key A from the storage medium 95. The second terminal 5 can communicate data with other computers (such as the management server 1 and the first terminal 4) via the communication interface 53. The second terminal 5 can be operated via the input device 54 and the output device 55.

[0167] In addition, regarding the specific hardware structure of the second terminal 5, it is possible to appropriately omit, replace, and add components according to the implementation method. For example, the control unit 51 may include multiple hardware processors. The hardware processor may be composed of a microprocessor, FPGA, DSP, GPU, ECU, etc. At least one of the input device 54, the output device 55, and the driver 56 may be omitted. In addition, the second identifier I20, the electronic certificate EC50, the key A, and the public key A may not be stored in the storage unit 52. That is, the second identifier I20, the electronic certificate EC50, the key A, and the public key A can be obtained every time. In this case, the second terminal 5 may also have a sensor and a data acquisition device such as a reading device for obtaining the various data mentioned above every time. The communication interface 53 may be composed of multiple types of modules, similar to the above-mentioned first terminal 4. The second terminal 5 may be composed of multiple computers. In this case, the hardware structure of each computer may be consistent or inconsistent. The second terminal 5 may be an information processing device designed specifically for the service to be provided, or may be a general-purpose computer, a user terminal device (eg, a smartphone, a tablet PC, etc.), or the like.

[0168] [Software Configuration Example]

[0169] Figure 8 This is a diagram schematically showing an example of the software configuration of each device (the management server 1 , the first server 2 , the second server 3 , the first terminal 4 , and the second terminal 5 ) according to the present embodiment.

[0170] (Management Server)

[0171] The control unit 11 of the management server 1 expands the management program 81 stored in the storage unit 12 into the RAM and causes the CPU to execute the commands included in the management program 81. Thus, the management server 1 operates as a computer including the setting unit 111, the release unit 112, and the notification unit 113 as software modules.

[0172] The setting unit 111 is configured to execute a process for setting the correspondence between the first identifier I10 and the second identifier I20 upon receiving a request for establishing an association (a request for establishing a correspondence between the first identifier I10 and the second identifier I20) from the first terminal 4. During the process for establishing the correspondence between the first identifier I10 and the second identifier I20, the setting unit 111 generates association information D10 for establishing an association between the first identifier I10 and the second identifier I20, and stores the generated association information D10 in the storage unit 12.

[0173] Furthermore, upon receiving an association establishment request from the first terminal 4, the setting unit 111 can authenticate the first object through the first server 2. Furthermore, the setting unit 111 can set the correspondence between the first identifier I10 and the second identifier I20, conditional on successful authentication of the first object. In one example, authentication of the first object can be performed using inherent information of the first object. In this case, the association establishment request sent from the first terminal 4 to the management server 1 can include the inherent information of the first object. Furthermore, the setting unit 111 can delegate authentication of the first object to the first server 2 by sending the first identifier I10 and inherent information of the first object to the first server 2.

[0174] In one example, Figure 9 As shown, the association establishment information D10 stored in the storage unit 12 may include a first identifier I10, a second identifier I20, a setting time, and a release time, etc. The setting time indicates the time when the correspondence between the first object and the second object is set. The setting time may be composed of a timestamp. The release time indicates the time when the correspondence between the first object and the second object is released. The value of the release time may be added when the process of releasing the correspondence is executed. The method of expressing the release may not be limited to such an example. In another example, the release time may be replaced with at least one of an expiration date and a flag. The expiration date indicates the period during which the setting of the correspondence is valid. In this case, whether the setting of the correspondence is valid (i.e., whether the correspondence is set or released) is indicated by whether it is within the expiration date. The flag indicates whether the correspondence is released. The flag may be set when the process of releasing the correspondence is executed. In another example, the association establishment information D10 may include a field for at least one of an expiration date and a flag and a release time. In addition, as long as the setting of the correspondence can be indicated, the composition of the association establishment information D10 may not be limited to Figure 9 The example may be modified appropriately depending on the implementation. In another example, the association establishment information D10 may also include information indicating the type of the object (whether it is a regularly used object or a temporarily used object). Furthermore, the type of the object does not necessarily need to be identified based on individual information. For example, the type of the object may be identified based on information such as an identifier.

[0175] The release unit 112 is configured to release the corresponding relationship upon receipt of a release request from at least one of the first terminal 4 and the second terminal 5, or upon the satisfaction of a predetermined release condition. The notification unit 113 is configured to send a notification indicating the result of the process of setting the corresponding relationship to at least one of the first terminal 4 and the second terminal 5. Furthermore, the notification unit 113 is configured to send a notification indicating the result of the process of releasing the corresponding relationship to at least one of the first terminal 4 and the second terminal 5.

[0176] (Server 1)

[0177] The control unit 21 of the first server 2 executes the commands included in the program 82 through the CPU. As a result, the first server 2 operates as a computer having a registration unit 211 as a software module. The registration unit 211 performs an account creation process for the first object in response to a request for account creation for the first object. In the account creation process for the first object, the registration unit 211 generates a first identifier I10 for the first object and stores the first object information D20 including the generated first identifier I10 in the storage unit 22. In one example, as Figure 10 As shown, the first object information D20 stored in the storage unit 22 may include the first identifier I10, unique information (vehicle registration number, vehicle identification information, identification information of the first terminal 4, etc.), vehicle model, and owner.

[0178] Furthermore, the first server 2 may further include a software module for authenticating the first object based on the authentication request from the management server 1. In this case, the software module can authenticate the first object using the first object's unique information. In one example, the software module can access the first object information D20 registered in the storage unit 22 from the management server 1 using the first identifier I10 included in the authentication request as an argument, and extract the registered unique information associated with the first identifier I10. The software module can then authenticate the first object by comparing the extracted unique information with the unique information included in the authentication request from the management server 1.

[0179] (Server 2)

[0180] The control unit 31 of the second server 3 executes the instructions included in the program 83 via the CPU. As a result, the second server 3 operates as a computer including the registration unit 311 and the authentication unit 312 as software modules.

[0181] The registration unit 311 executes the account creation process for the second object according to the request for account creation for the second object. In the account creation process for the second object, the registration unit 311 generates a second identifier I20 for the second object and stores the second object information D30 including the generated second identifier I20 in the storage unit 32. In one example, Figure 11As shown, the second object information D30 stored in the storage unit 32 may include a second identifier I20, owner identification information, and permission information. Owner identification information is an example of information used for authentication of the second object. In addition to owner identification information, the information used for authentication of the second object may also include the public key B of the certification authority used to create the electronic certificate for the second object. Permission information is information related to the permissions of the corresponding user. For example, permission information may include information for coordinating with a server that performs information processing related to the user's permissions, information indicating the establishment of associations with various information E10, and the like.

[0182] The authentication unit 312 verifies the validity of the second subject's electronic certificate EC50 and the second subject's second identifier I20 based on the verification request from the first terminal 4 (a request to verify the validity of the second identifier I20 and the electronic certificate EC50). To verify the validity of the second subject's electronic certificate, the authentication unit 312 first uses the certification authority's public key B to decrypt the certification authority's electronic signature B included in the second subject's electronic certificate. Furthermore, the authentication unit 312 calculates a hash value of the owner identification information included in the second subject's electronic certificate and the plaintext of the second subject's public key. Furthermore, the authentication unit 312 compares the decoded information of the certification authority's electronic signature B with the calculated hash value. If the comparison between the decoded information of the certification authority's electronic signature B and the calculated hash value is successful, the authentication unit 312 determines whether the second subject's electronic certificate EC50 has not expired by referring to the certification authority's repository. If the electronic certificate is determined to be valid, the authentication unit 312 determines that the verification of the validity of the second subject's electronic certificate has been successful.

[0183] Furthermore, in verifying the validity of the second identifier I20, the authentication unit 312 verifies the validity of the second identifier by comparing the owner identification information included in the electronic certificate EC50 of the second object with the owner identification information included in the second object information D30 in the storage unit 32. If the comparison between the owner identification information included in the electronic certificate EC50 of the second object and the owner identification information included in the second object information D30 in the storage unit 32 is successful, the authentication unit 312 determines that the second identifier of the second object is valid.

[0184] The authentication unit 312 transmits the verification result of the validity of the electronic certificate EC50 and the second identifier I20 to the first terminal 4 via the communication interface 33 .

[0185] (Terminal 1)

[0186] The control unit 41 of the first terminal 4 executes the commands included in the program 84 through the CPU. As a result, the first terminal 4 operates as a computer having a data exchange unit 411, a verification unit 412, a setting commission unit 413, and a release commission unit 414 as software modules. The data exchange unit 411 is configured to perform data exchange with the second terminal 5. In this embodiment, the data exchange unit 411 is configured to generate electronic information and provide the generated electronic information to the second terminal 5 based on the occurrence of a utilization relationship between the first object and the second object. In addition, the data exchange unit 411 is configured to receive the electronic certificate EC50, the second identifier I20, and the electronic signature A of the second object provided from the second terminal 5, and transfer the received data to the verification unit 412 described later.

[0187] The verification unit 412 is configured to verify the authenticity of the second object. In verifying the authenticity of the second object, the verification unit 412 verifies the validity of the second object's electronic certificate EC50, the validity of the second object's second identifier I20, and the validity of the second object's electronic signature A. In this embodiment, the verification unit 412 delegates the verification of the validity of the second object's electronic certificate EC50 and the verification of the validity of the second object's second identifier I20 to the second server 3. The verification unit 412 verifies the validity of the second object's electronic signature A. In verifying the validity of the second object's electronic signature A, the verification unit 412 first decrypts the second object's electronic signature A using the second object's public key A included in the second object's electronic certificate EC50. In addition, the verification unit 412 generates specified information using the electronic information provided from the first terminal 4 to the second terminal 5 and the second identifier I20 provided from the second terminal to the first terminal 4. The verification unit 412 then compares the decoded information of the second target's electronic signature A with the generated predetermined information. If the comparison between the decoded information of the second target's electronic signature A and the predetermined information is successful, the verification unit 412 determines that the second target's electronic signature A is valid.

[0188] The setting delegation unit 413 is configured to delegate the setting (association) of the correspondence between the first object and the second object to the management server 1, conditional on the successful verification of the validity of the electronic certificate EC50, the validity of the second identifier I20, and the validity of the electronic signature A. The release delegation unit 414 is configured to delegate the release of the correspondence between the first object and the second object to the management server 1.

[0189] (Terminal 2)

[0190] The control unit 51 of the second terminal 5 executes the commands included in the program 85 via the CPU. Consequently, the second terminal 5 operates as a computer having a data exchange unit 511, a signature generation unit 512, and a decommissioning unit 513 as software modules. The data exchange unit 511 is configured to exchange data with the first terminal 4. In this embodiment, the data exchange unit 511 is configured to receive electronic information provided from the first terminal 4 and transfer the received data to the signature generation unit 512, which will be described later. Furthermore, the data exchange unit 511 is configured to provide the electronic certificate EC50, the second identifier I20, and the electronic signature A generated by the signature generation unit 512, which will be described later, to the first terminal 4.

[0191] The signature generation unit 512 is configured to generate the electronic signature A of the second object when the data exchange unit 511 receives the electronic information provided from the first terminal 4 as a trigger. To generate the electronic signature A of the second object, the signature generation unit 512 first generates predetermined information including the electronic information provided from the first terminal 4 and the second identifier I20. The signature generation unit 512 then encrypts the generated predetermined information using the key A of the second object to generate the electronic signature A of the second object.

[0192] The release delegation unit 513 is configured to delegate the management server 1 to release the correspondence relationship.

[0193] Furthermore, in this embodiment, an example is described in which each software module of each device is implemented by a general-purpose CPU. However, some or all of the above software modules may be implemented by one or more dedicated processors. Each of the above modules may be implemented as a hardware module. Regarding the software configuration of each device, modules may be omitted, replaced, or added as appropriate depending on the embodiment.

[0194] [Action Example]

[0195] Figure 12 This is an example of a process procedure for association setting in the management system 100 in the application example of this embodiment. The following process procedure is an example of a management method executed by a computer.

[0196] In step S11 , the control unit 41 of the first terminal 4 operates as the data exchange unit 411 and provides electronic information to the second terminal 5 .

[0197] In step S12, the control unit 51 of the second terminal 5 operates as a signature generation unit 512, and generates an electronic signature A of the second object using the electronic information provided from the first terminal 4. In one example, the signature generation unit 512 first generates predetermined information including the electronic information provided from the first terminal 4 and the second identifier I20 stored in the storage unit 52. Next, the signature generation unit 512 generates the electronic signature A of the second object by encrypting the generated predetermined information using the key A of the second object stored in the storage unit 52.

[0198] In step S13, the control unit 51 of the second terminal 5 operates as the data exchange unit 511 and provides the generated electronic signature A of the second object, the second identifier I20 stored in the storage unit 52, and the electronic certificate EC50 stored in the storage unit 52 to the first terminal 4. In response, the control unit 41 of the first terminal 4 operates as the data exchange unit 411 and receives the electronic signature A, second identifier I20, and electronic certificate EC50 provided from the second terminal 5.

[0199] In step S14, the control unit 41 of the first terminal 4 operates as the verification unit 412, and transmits the second identifier I20 and the electronic certificate EC50 provided by the second terminal 5 to the second server 3, thereby delegating the verification of the validity of the second identifier I20 and the electronic certificate EC50 to the second server 3. The second identifier I20 and the electronic certificate EC50 are transmitted to the management server 1 via the communication interface 43.

[0200] In step S15, the verification request sent from the first terminal 4 is received by the communication interface 33 of the second server 3. In the second server 3, having received the verification request from the first terminal 4, the control unit 31 operates as the authentication unit 312, verifying the validity of the second identifier I20 and the electronic certificate EC50 received from the first terminal 4. Regarding the verification of the validity of the electronic certificate EC50, in one example, the authentication unit 312 first accesses the second object information D30 in the storage unit 32 using the second identifier I20 as an argument, and obtains the public key B of the certification authority. The authentication unit 312 uses the obtained public key B to decrypt the certification authority's electronic signature A included in the electronic certificate EC50. Furthermore, the authentication unit 312 calculates a hash value of the plaintext of the owner identification information and the second object public key A included in the electronic certificate EC50. The authentication unit 312 then compares the information containing the decrypted electronic signature B of the certification authority with the calculated hash value. If the comparison between the decoded information of the certification authority's electronic signature B and the calculated hash value is successful, the authentication unit 312 refers to the certification authority's repository to determine whether the second electronic certificate EC50 has not expired. If it is determined that the electronic certificate has not expired, the authentication unit 312 determines that the verification of the validity of the second electronic certificate has been successful.

[0201] Furthermore, to verify the validity of the second identifier I20, in one example, the authentication unit 312 first accesses the second object information D30 in the storage unit 32 using the second identifier I20 as an argument, and obtains the owner identification information corresponding to the second object. Next, the authentication unit 312 verifies the validity of the second identifier by comparing the obtained owner identification information with the owner identification information included in the electronic certificate EC50. If the comparison between the obtained owner identification information and the owner identification information included in the electronic certificate EC50 is successful, the authentication unit 312 determines that the second identifier of the second object is valid.

[0202] When the verification of the validity of the second identifier I20 and the electronic certificate EC50 is successful, the authentication unit 312 transmits the verification result (verification success) to the first terminal 4 via the communication interface 33 (step S16 ).

[0203] In step S17, the verification result transmitted from the second server 3 is received by the communication interface 43 of the first terminal 4. In the first terminal 4, having received the verification result from the second server 3, the control unit 41 operates as the verification unit 412 to verify the validity of the electronic signature A of the second subject provided by the second terminal 5. In one example, the verification unit 412 first uses the public key A of the second subject included in the electronic certificate EC50 of the second subject to decrypt the electronic signature A of the second subject. Furthermore, the verification unit 412 generates predetermined information using the electronic information provided from the first terminal 4 to the second terminal 5 and the second identifier I20 provided from the second terminal to the first terminal 4. Furthermore, the verification unit 412 compares the decoded information of the electronic signature A of the second subject with the generated predetermined information. If the comparison between the decoded information of the electronic signature A of the second subject and the predetermined information is successful, the verification unit 412 determines that the electronic signature A of the second subject is valid.

[0204] In step S18, upon successful verification of the validity of the electronic certificate EC50, the second identifier I20, and the electronic signature A, the control unit 41 of the first terminal 4 operates as the setting delegation unit 413, delegating the setting of the correspondence between the first object and the second object to the management server 1. Specifically, the setting delegation unit 413 transmits the association establishment request including the first identifier I10 and the second identifier I20 to the management server 1 via the communication interface 43.

[0205] In step S19, the association request sent from the first terminal 4 is received by the communication interface 13 of the management server 1. In response, the control unit 11 of the management server 1 operates as the setting unit 111 and executes the association process. In one example, during the association process, the setting unit 111 generates association information D10 for associating the first identifier I10 with the second identifier I20, and stores the generated association information D10 in the storage unit 12.

[0206] In this embodiment, the authenticity of the second object is verified based on the generation of a utilization relationship between the first object and the second object. Figure 12 Steps S14-S17 in the example above are performed. This ensures security. Furthermore, if the authenticity of the second object is successfully verified, a correspondence between the first identifier I10 and the second identifier I20 is established. By recording this setting, the usage relationship between the first and second objects can be tracked. Therefore, according to this embodiment, the usage relationship between the first and second objects can be tracked while ensuring security.

[0207] [Variation 1]

[0208] While the embodiments of the present disclosure have been described above using application examples, the descriptions thus far are merely illustrative of the present disclosure in all respects. Various improvements or modifications are naturally possible without departing from the scope of the present disclosure. For example, the following modifications are possible. Furthermore, the same reference numerals are used for components identical to those in the application examples above, and descriptions of points identical to those in the application examples are omitted where appropriate.

[0209] In one example, the management system 100 may be configured so that a proxy user of the second object (user) can exercise the authority of the second object by proxy through the use of the first object (mobile object).

[0210] Figure 13 This is a diagram schematically showing an example of a scenario in which the management system 100 according to this modification is applied. Figure 14 This is a diagram showing an example of the hardware configuration of the third terminal 6 in this modification. Figure 15 This is a diagram schematically showing an example of the software configuration of each device (the management server 1 , the first server 2 , the second server 3 , the first terminal 4 , and the second terminal 5 ) according to this modification. Figure 16 This is a diagram showing an example of the second object information D30 held by the second server 3 according to this modification. Figure 17 This is a diagram showing an example of association information D10 held by the management server 1 in this modification.

[0211] exist Figure 13 In the example, the second object grants the proxy right to the proxy user at any time before the first object and the proxy user are established. In one example, the second object applies to the second server 3 for the proxy right to the proxy user via the second terminal 5. Figure 15 As shown, the second terminal 5 of this variation operates as a computer having a proxy designation unit 514 as a software module in addition to a data exchange unit 511, a signature generation unit 512, and a delegating unit 513. Accordingly, when requesting the second server 3 to grant proxy rights to a proxy user, the control unit 51 of the second terminal 5 operates as the proxy designation unit 514. The proxy designation unit 514 transmits the second identifier I20 of the second object, the owner identification information of the second object, and the proxy identifier I30 of the proxy user to the second server 3, thereby requesting the second server 3 to grant proxy rights to the proxy user (step SB101).

[0212] The second server 3 that receives the proxy application from the second terminal 5 authenticates the second object and grants the proxy to the proxy user. Figure 15As shown, the second server 3 in this variation operates as a computer that includes a proxy authorization unit 313 as a software module in addition to a registration unit 311 and an authentication unit 312. Accordingly, upon receiving a proxy authorization application from the second terminal 5, the control unit 31 in the second server 3 operates as the proxy authorization unit 313. The proxy authorization unit 313 verifies the validity of the second identifier I20 by comparing the owner identification information of the second object included in the proxy authorization application with the owner identification information registered in the second object information D30 of the storage unit 230 (the owner identification information registered in association with the second identifier I20). If the comparison between the owner identification information of the second object included in the proxy authorization application and the owner identification information registered in the second object information D30 is successful, the proxy authorization unit 313 determines that the second identifier I20 is valid.

[0213] If it is determined that the second identifier I20 of the second object is valid, the proxy authorization unit 313 sets the correspondence between the second identifier I20 of the second object and the proxy identifier I30 of the proxy user (establishes an association). In one example, the establishment of the association can be completed by recording the proxy identifier I30 in the second object information D30 corresponding to the second object. In addition, in this modified example, Figure 16 As shown, the second object information D30 may include the second object electronic certificate EC50 and the proxy identifier I30 of the proxy user in addition to the second identifier I20, owner identification information, and authority information. Furthermore, the second object information D30 may also include the second object key A.

[0214] After establishing the correspondence (establishing the association) between the second identifier I20 of the second object and the proxy identifier I30 of the proxy user, the proxy authorization unit 313 authorizes the proxy user to authorize the second object (step SB102). In one example, the proxy authorization unit 313 authorizes the proxy user (third terminal 6) to authorize the proxy user to authorize the second object by sending the second identifier I20 of the second object, the electronic certificate EC50 of the second object, and the key A of the second object to the third terminal 6 (equivalent to the "proxy user terminal" involved in this disclosure). Alternatively, after authorizing the proxy user to authorize the second object, the electronic certificate EC50 and key A of the second object can be directly provided from the second terminal 5 to the third terminal 6.

[0215] When the proxy user (third terminal 6) is granted the proxy right for the second object, and a utilization relationship is established between the first object and the proxy user, data exchange occurs between the first terminal 4 and the third terminal 6. In one example, electronic information is first provided from the first terminal 4 to the third terminal 6 (step SA1201). Next, upon receiving the electronic information provided from the first terminal 4, the third terminal 6 generates the proxy user's electronic signature A. The generated electronic signature A, along with the second identifier I20, the electronic certificate EC50, and the proxy identifier I30, is provided from the third terminal 6 to the first terminal 4 (step S1202).

[0216] Here, as Figure 14 As shown, the third terminal 6 in this modified example is configured as a computer comprising a control unit 61, a storage unit 62, a communication interface 63, an input device 64, an output device 65, and a drive 66 electrically connected. The control unit 61, storage unit 62, communication interface 63, input device 64, output device 65, drive 66, and storage medium 96 of the third terminal 6 can be configured similarly to the control unit 51, storage unit 52, communication interface 53, input device 54, output device 55, drive 56, and storage medium 95 of the second terminal 5. The storage unit 62 of the third terminal 6 stores various information, including the program 86, the proxy identifier I30 of the proxy user, the second identifier I20 of the second object, the electronic certificate EC50 of the second object, and the key A of the second object. When the proxy right for the second object is granted to the proxy user (step SB102), the second identifier I20 of the second object, the electronic certificate EC50 of the second object, and the key A of the second object are provided from the second server 3.

[0217] like Figure 15 As shown, with Figure 14 The third terminal 6, having the hardware configuration shown, operates as a computer including a data exchange unit 611, a signature generation unit 612, and a de-delegation unit 613 as software modules. The data exchange unit 611, the signature generation unit 612, and the de-delegation unit 613 are implemented by the control unit 61 of the third terminal 6 executing instructions included in the program 86 in the storage unit 62.

[0218] In the possession Figure 15 In the third terminal 6 of the software module shown in FIG. Figure 13In step SA1201, the control unit 61 operates as the data exchange unit 611 to receive the electronic information provided by the first terminal 4. Next, the control unit 61 of the third terminal 6 operates as the signature generation unit 612 to generate the electronic signature A of the second object. The generation of the electronic signature A can be similar to the above-described application example. Specifically, the signature generation unit 612 first generates predetermined information including the electronic information provided by the first terminal 4 and the second identifier I20 stored in the storage unit 62. The signature generation unit 612 then encrypts the generated predetermined information using the key A of the second object stored in the storage unit 62 to generate the electronic signature A of the second object.

[0219] When the electronic signature A of the second object is generated, the control unit 61 of the third terminal 6 operates as a data exchange unit 611 and provides the generated electronic signature A, the second identifier I20 of the second object stored in the storage unit 62, the electronic certificate EC50 of the second object stored in the storage unit 62, and the proxy identifier I30 of the proxy user stored in the storage unit 62 to the first terminal 4. At this time, the control unit 41 of the first terminal 4 operates as a data exchange unit 411 and receives the electronic signature A, second identifier I20, electronic certificate EC50, and proxy identifier I30 provided from the third terminal 6.

[0220] In the first terminal 4 that receives the electronic signature A, the second identifier I20, the electronic certificate EC50, and the proxy identifier I30, the control unit 41 acts as the verification unit 412, and entrusts the verification of the validity of the second identifier I20, the electronic certificate EC50, and the proxy identifier I30 to the second server 3 by sending the second identifier I20, the electronic certificate EC50, and the proxy identifier I30 provided from the third terminal 6 to the second server 3 (step SA1203).

[0221] When the verification request sent from the first terminal 4 is received by the communication interface 33 of the second server 3, the control unit 31 of the second server 3 functions as the authentication unit 312 to verify the validity of the second identifier I20, electronic certificate EC50, and proxy identifier I30 received from the first terminal 4. The verification of the validity of the second identifier I20 and electronic certificate EC50 can be performed in the same manner as in the aforementioned application example. Regarding the verification of the validity of the proxy identifier I30, in one example, the authentication unit 312 first accesses the second object information D30 in the storage unit 32 using the second identifier I20 as an argument and identifies the proxy identifier registered in the second object information D30 in an associated manner with the second identifier I20. The authentication unit 312 then compares the proxy identifier registered in the second object information D30 with the proxy identifier I30 provided from the first terminal 4. When the proxy identifier registered in the second target information D30 is successfully compared with the proxy identifier I30 provided from the first terminal 4 , the authentication unit 312 determines that the proxy identifier I30 is valid.

[0222] If the verification of the validity of the second identifier I20, electronic certificate EC50, and proxy identifier I30 is successful, the authentication unit 312 transmits the verification result (verification success) to the first terminal 4 via the communication interface 33 (step SA1204). In this variation, the second server 3 performing the above-mentioned verification process corresponds to the "external server" involved in this disclosure.

[0223] When the verification result transmitted from the second server 3 is received by the communication interface of the first terminal 4, the control unit 41 of the first terminal 4 operates as the verification unit 412 to verify the validity of the electronic signature A provided by the third terminal 6 (step SA1205). The verification of the validity of the electronic signature A can be performed in the same manner as in the above-mentioned application example.

[0224] If the validity of the second identifier I20, electronic certificate EC50, and electronic signature A is successfully verified, control unit 41 of first terminal 4 operates as setting delegation unit 413 to delegate the establishment of the association between the first object and the proxy user to management server 1 (step SA1206). In one example, setting delegation unit 413 transmits an association establishment request including first identifier I10, second identifier I20, and proxy identifier I30 to management server 1 via communication interface 43.

[0225] When the association request sent from the first terminal 4 is received by the communication interface 13 of the management server 1, the control unit 11 of the management server 1 operates as the setting unit 111 and performs the association process (step SA1207). In one example, the setting unit 111 generates association information D10 for associating the first identifier I10, the second identifier I20, and the proxy identifier I30, and stores the generated association information D10 in the storage unit 12.

[0226] In one example, Figure 17 As shown, the association establishment information D10 in this variant may include the first identifier I10, the second identifier I20, the proxy identifier I30, the setting time and the release time, etc. The setting time indicates the time when the correspondence between the first object and the proxy user is set. The setting time may be composed of a timestamp. The release time indicates the time when the correspondence between the first object and the proxy user is released. The value of the release time may be added when the process of releasing the correspondence is executed. The method of expressing the release may not be limited to such an example. In another example, the release time may be replaced with at least one of the validity period and the flag. The validity period indicates the period during which the setting of the correspondence is valid. In this case, whether the setting of the correspondence is valid (that is, whether the correspondence is set or released) is indicated by whether it is within the validity period. The flag indicates whether the correspondence is released. The flag may be set when the process of releasing the correspondence is executed. In another example, the association establishment information D10 may include a field for at least one of the validity period and the flag and the release time. In addition, as long as the setting of the correspondence can be indicated, the composition of the association establishment information D10 may not be limited to Figure 17 The example may be modified appropriately depending on the implementation. In another example, the association information D10 may also include information indicating the type of the object (whether it is a regularly used object or a temporarily used object). Furthermore, the type of the object does not necessarily need to be identified based on individual information. For example, the type of the object may also be identified based on information such as an identifier.

[0227] In addition, Figure 13In step SB101, at least one of the validity period of the proxy exercise and the authority (effective authority) allowed to be exercised by the proxy can be specified together with the designation of the proxy user. Based on this, designation information can be generated to represent at least one of the specified validity period and effective authority. The designation information of at least one of the specified validity period and effective authority can be appropriately managed. In one example, the designation information can be sent from the second terminal 5 to the second server 3, and managed in the second server 3 in the form of an association with the second object information D30. When at least one of the validity period of the proxy exercise and the authority (effective authority) allowed to be exercised by the proxy is specified, the proxy authority granted to the proxy user can disappear according to the arrival of the specified effective authority. In addition, the proxy authority granted to the proxy user can disappear due to the exercise of the specified effective authority.

[0228] According to this variation, a proxy user can exercise the authority of the user (second subject) by utilizing a mobile object. This allows for greater scalability in the exercise of authority while ensuring security. For example, consider a scenario where the authority information includes information related to an electronic prescription, and the subject's authority is to receive medication prescribed in accordance with the electronic prescription. In this case, the user (second subject) grants proxy authority to a proxy user, such as a family member, so that the proxy user can receive medication prescribed to the user (second subject) by utilizing the mobile object.

[0229] [Variation 2]

[0230] In the above application example, the first object is a mobile object and the second object is a user. However, Figure 17 As shown, the first target is a user and the second target is a mobile object. In this case, the first terminal 4 can be a user terminal used by the user as the first target, and the second terminal 5 can be a loading terminal mounted on the mobile object. Furthermore, it is sufficient that the first server 2 is configured to authenticate the user as the first target, and the second server 3 is configured to authenticate the mobile object as the second target.

[0231] <Other>

[0232] The processes and means described in this disclosure can be implemented in combination as long as no technical contradiction occurs.

[0233] Furthermore, a process described as being performed by one device may be shared and executed by multiple devices. Alternatively, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration that implements each function can be flexibly changed.

[0234] The present disclosure can also be implemented by supplying a computer program that has the functions described in the above-mentioned embodiments to a computer, and having one or more processors of the computer read out the program and execute it. Such a computer program can be provided to the computer via a non-temporary computer-readable storage medium that can be connected to the system bus of the computer, or it can be provided to the computer via a network. Non-temporary computer-readable storage media include, for example, any type of disk such as a magnetic disk (floppy (registered trademark) disk, hard disk drive (HDD), etc.), an optical disk (CD-ROM, DVD disk, Blu-ray disk, etc.), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, a semiconductor drive (solid-state drive, etc.), or any type of medium suitable for storing electronic commands.

[0235] Description of reference numerals:

[0236] 1…management server; 2…first server; 3…second server; 4…first terminal; 41…control unit; 411…data exchange unit; 412…verification unit; 413…setting delegation unit; 414…delegation release unit; 42…storage unit; 43…communication interface; 44…input device; 45…output device; 46…driver; 5…second terminal; 84…program.

Claims

1. A terminal is associated with a first object that is a mobile object and a user, wherein: A control unit configured to execute the following processing: providing electronic information to another terminal associated with a second object that is the other of the mobile object and the user; acquiring, from the other terminal, an electronic signature of the second object generated using the electronic information, an electronic certificate of the second object issued by a certification authority, and an identifier of the second object; Using the public key of the certification authority to verify the validity of the obtained electronic certificate; Verifying the validity of the obtained electronic signature using the public key of the second object included in the electronic certificate; and In response to the success of the verification of the validity of the electronic certificate and the electronic signature, a request for setting the correspondence relationship between the identifier of the first object and the identifier of the second object is transmitted to a management server.

2. The terminal according to claim 1, wherein: The electronic signature of the second object is generated by encrypting predetermined information including the electronic information and the identifier of the second object using a secret key corresponding to the public key of the second object.

3. The terminal according to claim 2, wherein: The electronic information is a random number generated by the control unit. The terminal according to claim 2 , wherein: Verifying the validity of the electronic certificate includes: Decoding the electronic signature of the certification authority included in the electronic certificate using the public key of the certification authority; verifying the validity of information obtained by decoding the electronic signature of the certification authority using the identification information of the second object included in the electronic certificate and the public key of the second object; and Determine whether the electronic certificate has not expired. The terminal according to claim 2 , wherein: The first object is the moving object, The terminal associated with the first object is a loading terminal loaded on the mobile body, The second object is the user, The other terminal associated with the second object is a proxy user terminal used by a proxy user of the user. The terminal according to claim 5 , wherein: Verifying the validity of the electronic certificate includes: In addition to verifying the validity of the obtained electronic certificate using the public key of the certification authority, the validity of the proxy user's proxy authority is also verified. The terminal according to claim 6 , wherein: Verifying the validity of the proxy user's proxy rights includes: sending a verification request including the identifier of the user and the identifier of the proxy user to an external server that manages information of a proxy user to whom the user has granted proxy authority; and A verification result of the validity of the proxy authority of the proxy user is received from the external server.

8. An information processing method, wherein: The following processing is performed by a terminal associated with the first object which is one of the mobile object and the user: providing electronic information to another terminal associated with a second object that is the other of the mobile object and the user; acquiring, from the other terminal, an electronic signature of the second object generated using the electronic information, an electronic certificate of the second object issued by a certification authority, and an identifier of the second object; Using the public key of the certification authority to verify the validity of the obtained electronic certificate; Verifying the validity of the obtained electronic signature using the public key of the second object included in the electronic certificate; and In response to the success of the verification of the validity of the electronic certificate and the electronic signature, a request for setting the correspondence relationship between the identifier of the first object and the identifier of the second object is transmitted to a management server.

9. The information processing method according to claim 8, wherein: The electronic signature of the second object is generated by encrypting predetermined information including the electronic information and the identifier of the second object using a secret key corresponding to the public key of the second object.

10. The information processing method according to claim 9, wherein: The electronic information is a random number.

11. The information processing method according to claim 9, wherein: Verifying the validity of the electronic certificate includes: Decoding the electronic signature of the certification authority included in the electronic certificate using the public key of the certification authority; verifying the validity of information obtained by decoding the electronic signature of the certification authority using the identification information of the second object included in the electronic certificate and the public key of the second object; and Determine whether the electronic certificate has not expired.

12. The information processing method according to claim 9, wherein: The first object is the moving object, The terminal associated with the first object is a loading terminal loaded on the mobile body, The second object is the user, The other terminal associated with the second object is a proxy user terminal used by a proxy user of the user.

13. The information processing method according to claim 12, wherein: Verifying the validity of the electronic certificate includes: In addition to verifying the validity of the obtained electronic certificate using the public key of the certification authority, the validity of the proxy user's proxy authority is also verified.

14. The information processing method according to claim 13, wherein: Verifying the validity of the proxy user's proxy rights includes: sending a verification request including the identifier of the user and the identifier of the proxy user to an external server that manages information of a proxy user to whom the user has granted proxy authority; and A verification result of the validity of the proxy authority of the proxy user is received from the external server.

15. A program product, wherein The terminal is configured to associate a first object, which is one of a mobile object and a user, with the terminal executing the following processing: providing electronic information to another terminal associated with a second object that is the other of the mobile object and the user; acquiring, from the other terminal, an electronic signature of the second object generated using the electronic information, an electronic certificate of the second object issued by a certification authority, and an identifier of the second object; Using the public key of the certification authority to verify the validity of the obtained electronic certificate; Verifying the validity of the obtained electronic signature using the public key of the second object included in the electronic certificate; and In response to the success of the verification of the validity of the electronic certificate and the electronic signature, a request for setting the correspondence relationship between the identifier of the first object and the identifier of the second object is transmitted to a management server.

16. The program product according to claim 15, wherein The electronic signature of the second object is generated by encrypting predetermined information including the electronic information and the identifier of the second object using a secret key corresponding to the public key of the second object.

17. The program product according to claim 16, wherein The electronic information is a random number.

18. The program product according to claim 16, wherein Verifying the validity of the electronic certificate includes: Decoding the electronic signature of the certification authority included in the electronic certificate using the public key of the certification authority; verifying the validity of information obtained by decoding the electronic signature of the certification authority using the identification information of the second object included in the electronic certificate and the public key of the second object; and Determine whether the electronic certificate has not expired.

19. The program product according to claim 16, wherein The first object is the moving object, The terminal associated with the first object is a loading terminal loaded on the mobile body, The second object is the user, The other terminal associated with the second object is a proxy user terminal used by a proxy user of the user.

20. The program product according to claim 19, wherein Verifying the validity of the electronic certificate includes: In addition to verifying the validity of the obtained electronic certificate using the public key of the certification authority, the validity of the proxy user's proxy authority is also verified.

Citation Information

Patent Citations

  • Vehicle payment support device

    JP2022140747A