Processing authority transfer system and processing authority transfer method
Patent Information
- Application Number
- JP2022161248
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-10-05
- Publication Date
- 2025-07-16
- Estimated Expiration
- 2042-10-05
AI Technical Summary
Existing systems for processing authority transfer do not define conditions for approving transactions or the details of processing to be performed, leading to a risk of unintended processes being executed.
A processing authority transfer system that includes a first terminal and an execution entity, utilizing biometric information-based certificates to verify execution conditions and transfer authority only to entities that satisfy specified criteria, ensuring intended processing is executed.
Prevents the execution of unintended processes by ensuring that only authorized entities with satisfied execution conditions execute the delegated tasks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a processing authority delegation system and a processing authority delegation method. [Background technology]
[0002] Background art of this technical field includes JP 2018-14622 A (Patent Document 1) and JP 2013-123142 A (Patent Document 2).
[0003] Patent Document 1 states, "A signature verification system that verifies a signature using a computer equipped with a processor and memory, comprising: a biometric information acquisition unit that acquires a user's biometric information; a public template certificate generation unit that applies predetermined processing to the biometric information to generate a public template certificate; a key pair generation unit that generates a pair of a private key and a public key; a public key certificate generation unit that generates a public key certificate by using the biometric information as a key and assigning a biometric signature to the public key; and a verification unit that accepts a transaction including the public template certificate, the public key certificate, and a signature, verifies the authenticity of the public key certificate using the public template certificate, and further verifies the signature using the public key certificate" (see abstract).
[0004] Patent Document 2 states that "At the time of registration, a predetermined private key is embedded in the features of the user's biometric information, and a biometric certificate is issued in combination with the corresponding public key. When signing, a new pair of temporary private key and temporary public key is generated for the signature features of the user's biometric information, a signature for the message is created using the temporary private key, a commitment is created by embedding the temporary private key in the signature features, and the pair of the temporary public key, signature, and commitment is used as a biometric signature. When verifying the biometric signature, the signature is verified with the temporary public key, and a differential private key and differential public key are generated from the biometric certificate, commitment, and temporary public key to verify the correspondence" (see abstract). [Prior art documents] [Patent documents]
[0005] [Patent Document 1] JP 2018-14622 A [Patent Document 2] JP 2013-123142 A Summary of the Invention [Problem to be solved by the invention]
[0006] The technology described in Patent Document 1 approves a transaction when the transaction is successfully verified based on the results of verification of the public template certificate and the results of verification of the public key certificate, but the public template certificate and public key certificate do not define the conditions for approving a transaction or the details of the process to be executed when the transaction is approved, so there is a risk that a process not intended by the user will be executed. Furthermore, Patent Document 2 does not describe information defining the conditions or the details of the process.
[0007] Therefore, one aspect of the present invention prevents the execution subject from executing a process not intended by the delegator. [Means for solving the problem]
[0008] In order to solve the above problem, one aspect of the present invention employs the following configuration: A processing authority transfer system includes a first terminal and an execution subject of a process, the first terminal holds a first certificate indicating delegation contents indicating execution conditions and execution contents of the process, and an identifier of an execution subject to which the authority to execute the process is to be transferred, and based on biometric information of a delegator of the process, the execution subject transmits information indicating whether the execution conditions are satisfied and the identifier of the execution subject to the first terminal, the first terminal performs first certificate verification based on the delegation contents and the identifier indicated by the first certificate, and when it is determined in the first certificate verification that there is an execution subject that has transmitted information indicating that the execution conditions are satisfied based on the information received from the execution subject, it determines whether the identifier of the execution subject matches the identifier indicated by the first certificate, and transfers the authority for the process indicated by the execution contents to the execution subject based on the result of the first certificate verification. Effect of the Invention
[0009] According to one aspect of the present invention, it is possible to prevent an execution entity from executing a process that is not intended by a delegator.
[0010] Problems, configurations and effects other than those described above will become apparent from the following description of the embodiments. [Brief description of the drawings]
[0011] [Figure 1] 1 is a block diagram showing an example of a configuration of a processing authority delegation system according to a first embodiment. [Diagram 2] 11 is a flowchart showing a processing procedure for initial registration of an entrustor template certificate in the first embodiment. [Diagram 3] 11 is a flowchart showing an example of a specific procedure of an initial registration process in the first embodiment. [Figure 4A] 11 is a flowchart illustrating an example of a right transfer process in the first embodiment. [Figure 4B] 11 is a flowchart illustrating an example of a right transfer process in the first embodiment. [Diagram 5] 11 is a flowchart illustrating an example of details of a device certificate verification process according to the first embodiment. [Figure 6] 13 is a flowchart illustrating an example of details of a delegator template verification process in the first embodiment. [Figure 7A] FIG. 4 is a diagram illustrating an example of a data structure of a device certificate according to the first embodiment. [Figure 7B] 13 is a diagram illustrating an example of a data structure of an entrustor template certificate in the first embodiment. FIG. [Figure 8] 2 is a block diagram illustrating an example of a hardware configuration of an IoT terminal, a verification terminal, and a delegator template repository in the processing authority delegation system according to the first embodiment. FIG. [Figure 9] 11 is a flowchart illustrating an example of a verification process by a verification terminal in the first embodiment. [Figure 10] FIG. 2 is an explanatory diagram showing an example of an outline of the entire process performed by the processing authority transfer system according to the first embodiment; [Figure 11A] FIG. 11 is an explanatory diagram showing an example of delegation authority of a delegator in the second embodiment. [Figure 11B] FIG. 11 is an explanatory diagram showing an example of delegation authority of a delegator in the second embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Hereinafter, an embodiment of the present invention will be described with reference to the accompanying drawings. In this embodiment, the same components are generally designated by the same reference numerals, and repeated explanations are omitted. Note that this embodiment is merely an example for realizing the present invention, and does not limit the technical scope of the present invention. EXAMPLES
[0013] In this embodiment, after verifying the attributes of the delegator and the signature of the delegator's superior, and verifying whether the conditions for executing the processing are met, the delegator transfers processing authority to a device / application, and the device / application to which the processing authority has been transferred autonomously executes the processing.
[0014] The procedure will be described below with reference to the drawings.
[0015] 1 is a block diagram showing an example of the configuration of a processing authority delegation system. The processing authority delegation system includes, for example, an IoT (Internet of Things) terminal 1000 (an example of a first terminal) having functions as a signing terminal and an issuing terminal, a verification terminal 1100 (an example of a second terminal), a delegator template repository 1200, one or more devices / applications 1300, and one or more IoT terminals 1400, all of which are connected to each other via a network 100 such as the Internet.
[0016] In this figure, the IoT terminal 1000 includes a communication unit 1010, a biometric information acquisition unit 1020, a delegator template generation unit 1030, a device key pair generation unit 1040, a device certificate generation unit 1050, an execution information acquisition unit 1060, a signature generation unit 1070, a delegation information acquisition unit 1080, a key storage unit 1090, a delegator template certificate storage unit 1091, a hash value generation unit 1092, a certificate verification unit 1093, and a delegator condition storage unit 1094.
[0017] The communication unit 1010 communicates between the verification terminal 1100, the delegator template repository 1200, the device / application 1300, and the IoT terminal 1400 via the network 100.
[0018] The biometric information acquisition unit 1020 acquires biometric information such as a fingerprint, vein, and / or face image from a user via, for example, a fingerprint sensor, a vein sensor, and / or a camera, etc. Note that a fingerprint sensor, a vein sensor, or a camera of a mobile phone or a smartphone can be used as a sensor for acquiring biometric information.
[0019] The delegator template generation unit 1030 generates a delegator template as a public template by performing one-way (irreversible) conversion on the biometric information acquired by the biometric information acquisition unit 1020 in accordance with the method of Patent Document 2. Note that as the one-way conversion, a publicly known or well-known conversion process may be applied.
[0020] The device key pair generating unit 1040 generates a pair of a device private key and a device public key by using a public key cryptosystem (such as RSA or DSA (Digital Signature Algorithm)). A pair of a device private key and a device public key is generated for each device / application 1300. When a process is executed by the device / application 1300 to which processing authority has been transferred, a signature using the device private key corresponding to the device / application 1300 is added to execution information (described later). Furthermore, the signature is verified by using the device public key corresponding to the device private key.
[0021] The device certificate generation unit 1050 generates a device certificate (an example of a first certificate) as a public key certificate by adding a biometric signature using the biometric information acquired by the biometric information acquisition unit 1020 as a key to the device public key generated by the device key pair generation unit 1040.
[0022] The execution information acquisition unit 1060 acquires the execution information by inputting it from an input device, receiving it from another system, etc. The execution information indicates, for example, the execution content, which is the content of the process executed by the device / application 1300.
[0023] The delegation information acquisition unit 1080 acquires delegation information. The delegation information indicates, for example, an identifier of a delegator who transfers processing authority to the device / application 1300, attributes of the delegator, and (if necessary) information on the delegator's superior, the expiration date of the delegator template certificate, the serial number of the device / application 1300 to which the processing authority is transferred, delegation details (including, for example, the execution conditions of the process and the execution details of the process), the expiration date of the device certificate, and the like.
[0024] The key storage unit 1090 stores a device private key and a device certificate. The delegator template certificate storage unit 1091 stores a delegator template certificate (an example of a second certificate) generated by a delegator template certificate generation unit 1220 (described later) of the delegator template repository 1200.
[0025] The hash value generation unit 1092 generates a hash value by inputting the execution information acquired by the execution information acquisition unit 1060 and other information into a predetermined hash function.
[0026] The signature generation unit 1070 generates a signature value for the hash value generated by the hash value generation unit 1092 by using the device private key.
[0027] The certificate verification unit 1093 verifies the delegator template certificate generated by the delegator template certificate generation unit 1220 and the device certificate generated by the device certificate generation unit 1050 .
[0028] The delegator condition storage unit 1094 stores predetermined delegator conditions. The delegator conditions indicate, for example, attributes of a delegator who can transfer processing authority to the device / application 1300. Note that the attributes of the delegator who can transfer the processing authority indicated by the delegator conditions may be defined for each device / application 1300, may be defined for each execution content, or may be defined for each combination of the device / application 1300 and the execution content. In addition, a list of identifiers of delegators who can transfer processing authority to the device / application 1300 may be described as the delegator conditions. Note that the delegator conditions may be stored in the delegator template repository 1200 instead of or in addition to the IoT terminal 1000.
[0029] Next, the verification terminal 1100 includes a communication unit 1110 , a certificate verification unit 1120 , and a signature verification unit 1130 .
[0030] The certificate verification unit 1120 verifies the delegator template certificate generated by the delegator template certificate generation unit 1220 and the device certificate generated by the device certificate generation unit 1050, for example, after processing authority is transferred to the device / application 1300 (or after processing is executed by the device / application 1300).
[0031] The signature verification unit 1130 verifies various signatures, for example, after processing authority is transferred to the device / application 1300 (or after processing is executed by the device / application 1300).
[0032] The communication unit 1110 performs communication between the IoT terminal 1000, the delegator template repository 1200, the device / application 1300, and the IoT terminal 1400 via the network 100.
[0033] It is preferable that the verification terminal 1100 is managed by an organization different from the organization that owns the IoT terminal 1000, the device / application 1300, and the IoT terminal 1400. In other words, the verification terminal 1100 verifies various certificates and various signatures, and the legitimacy of the process (procedure) is verified by a third party that receives the process result.
[0034] Next, the delegator template repository 1200 is configured to include a communication unit 1210 , a delegator template certificate generation unit 1220 , a delegator template certificate storage unit 1230 , and a delegation information storage unit 1240 .
[0035] The delegator template certificate generation unit 1220 generates a delegator template certificate from the delegator template generated by the delegator template generation unit 1030 of the IoT terminal 1000.
[0036] The delegator template certificate storage unit 1230 stores the delegator template certificate generated by the delegator template certificate generation unit 1220 .
[0037] The delegation information storage unit 1240 stores, for example, the delegation information acquired by the delegation information acquisition unit 1080 of the IoT terminal 1000.
[0038] The communication unit 1210 performs communication between the IoT terminal 1000, the verification terminal 1100, the device / application 1300, and the IoT terminal 1400 via the network 100.
[0039] The device / application 1300 is an entity that receives the transfer of processing authority and executes processing based on the transferred processing authority. The device / application 1300 may be integrated with either the IoT terminal 1000 or the IoT terminal 1400, or the application of the device / application 1300 may be installed in either the IoT terminal 1000 or the IoT terminal 1400. In other words, either the IoT terminal 1000 or the IoT terminal 1400 itself may be an entity that receives the transfer of processing authority and executes processing based on the transferred processing authority.
[0040] Although not shown in the figure, the IoT terminal 1400 has a similar configuration to that of the IoT terminal 1000, for example.
[0041] 2 is a flowchart showing the processing steps for initial registration of an entruster template certificate. In this processing, the IoT terminal 1000 acquires biometric information from a user, and the entruster template repository 1200 generates an entruster template certificate. Each step will be described below.
[0042] The IoT terminal 1000 performs initial registration (S2010). A specific procedure for the initial registration will be described later with reference to Fig. 3. Through this procedure, a delegator template is generated.
[0043] The IoT terminal 1000 transmits the delegator template to the delegator template repository 1200 (S2020). At this time, the IoT terminal 1000 also transmits information required to generate a delegator template certificate, such as the user name, the biometric signature algorithm used to generate the delegator template, and at least a portion of the delegation information (e.g., information including an identifier of the delegator who transfers processing authority to the device / application 1300, attributes of the delegator, information about the delegator's superior, and the expiration date of the delegator template). Note that a biometric signature may be added to such information to prevent tampering.
[0044] The delegator template repository 1200 receives the delegator template (S2110) and issues a serial number for the received delegator template (S2120). The serial number is a number that is uniquely assigned to the delegator template, and is managed in the delegator template repository 1200 to prevent duplication.
[0045] The delegator template repository 1200 assigns a signature to the delegator template, generates a delegator template certificate, and registers it in the delegator template certificate storage unit 1230 (S2130). The delegator template is also assigned an identifier of the delegator, information indicating the delegator's attributes, an expiration date, and the like. The delegator template may also be assigned a signature of the delegator's superior (generated by any signature algorithm, such as a biometric signature, for example). The data structure of the delegator template certificate will be described later with reference to FIG. 7B. The delegator template repository 1200 also stores at least a portion of the delegation information received from the IoT terminal 1000 in the delegation information storage unit 1240.
[0046] In the first embodiment, it is assumed that the delegator template repository 1200 functions as a reliable third party and that no fraudulent activity will occur.
[0047] For this reason, the signature for the delegator template is generated, for example, using the private key of the certification authority stored in the delegator template repository 1200. This makes it difficult for a third party who does not have the private key of the certification authority to generate a delegator template certificate, making it possible to prevent the issuance of an unauthorized delegator template certificate and the occurrence of spoofing, etc.
[0048] The delegator template repository 1200 transmits the delegator template certificate generated in step S2130 to the IoT terminal 1000 (S2140), and the IoT terminal 1000 receives the delegator template certificate (S2030).
[0049] The IoT terminal 1000 stores the delegator template certificate received in step S2030 in the delegator template certificate storage unit 1091 (S2040). In this way, by the IoT terminal 1000 holding the delegator template certificate, as will be described later, the IoT terminal 1000 can transmit the delegator template certificate to the verification terminal 1100 after the device / application 1300 to which the processing authority has been transferred executes processing, and thus can verify the delegator template certificate even in a situation where the verification terminal 1100 cannot access the delegator template repository 1200.
[0050] This completes the initial registration of the delegator template certificate.
[0051] Next, a specific procedure of the initial registration process performed in step S2010 of FIG. 2 will be described with reference to FIG.
[0052] The biometric information acquisition unit 1020 of the IoT terminal 1000 acquires biometric information of the delegator (e.g., the administrator, owner, or user of the IoT terminal 1000) (S3010). The IoT terminal 1000 is connected to biometric sensors such as a fingerprint sensor, a vein sensor, and a camera, and the biometric information acquisition unit 1020 uses these sensors to acquire biometric information such as the delegator's fingerprint, vein, and face image.
[0053] The delegation information acquisition unit 1080 acquires delegation information via input to an input device of the IoT terminal 1000 (S3020).
[0054] The delegator template generating unit 1030 generates a delegator template as a public template by performing one-way conversion on the delegator's biometric information acquired in step S3010 (S3030). For this conversion, for example, a biometric encryption method is adopted, which corrects errors contained in the biometric information to generate unique data, and performs encryption processing using the obtained data as a key. Methods that can be used for this conversion include, for example, Fuzzy Commitment, Fuzzy Vault, and the biometric signature disclosed in Patent Document 2. The following description is based on the biometric signature disclosed in Patent Document 2.
[0055] In a biometric signature, a public template (a delegator template in this embodiment) is generated by performing a one-way conversion on biometric information. Even if a third party obtains the public template (a delegator template in this embodiment), it is very difficult to restore the biometric information, and the public template can be treated as public information, similar to a public key.
[0056] The device key pair generating unit 1040 of the IoT terminal 1000 generates a device key pair consisting of a device private key and a device public key (S3040). This device key pair is generated based on a public key cryptosystem known or well known, such as RSA cryptography, DSA cryptography, or Elgamal cryptography.
[0057] The device certificate generating unit 1050 of the IoT terminal 1000 generates a device certificate by adding a biometric signature using the biometric information of the delegator acquired in step S3010 as a key to the device public key obtained in step S3040 (S3050). Furthermore, at least a part of the delegation information (e.g., an identifier of the delegator who transfers the processing authority to the device / application 1300, a serial number of the device / application 1300 to which the processing authority is transferred, the contents of the delegated processing (the execution conditions of the processing and the execution contents of the processing), and the expiration date of the device certificate, etc.) is added to the device certificate. The data structure of the device certificate will be described later with reference to FIG. 7B.
[0058] The IoT terminal 1000 associates the device private key generated in step S3040 with the device certificate generated in step S3050 and stores them in the key storage unit 1090 (S3060).
[0059] In this manner, a device key pair and a device certificate are generated, and the initial registration process in step S2010 is completed.
[0060] 4A and 4B are flowcharts showing an example of a right transfer process. Note that this process may be executed periodically or may be started in response to an instruction from a user of the IoT terminal 1000, for example.
[0061] The execution information acquisition unit 1060 of the IoT terminal 1000 acquires execution information according to, for example, an input from an input device (S4010).
[0062] The certificate verification unit 1093 searches and acquires a device certificate corresponding to the execution information acquired in step S4010 from the key storage unit 1090 (S4020). Note that the execution information indicates, for example, the execution content of the process by the device / application 1300, and the execution content is stored as part of the delegation content in the device certificate, so in step S4020, a device certificate including the execution content indicated by the execution information acquired in step S4010 is acquired. Note that the execution information may further indicate information for searching for a device certificate (for example, an identifier of the delegator or a serial number of the device / application 1300, etc.) that is different from the execution content.
[0063] The certificate verification unit 1093 identifies an execution condition included in the delegation contents from the device certificate acquired in step S4020, and acquires information for determining whether the identified execution condition is satisfied (S4030). The execution condition is defined by, for example, internal factors such as the internal state of the device / application 1300 and processing already executed by the device / application 1300, and / or external factors such as the environment to which the device / application 1300 belongs and the state of a target to be processed by the device / application 1300. Therefore, in step S4030, for example, the certificate verification unit 1093 transmits a request for acquiring the information from a predetermined number of devices / applications 1300 (for example, all the devices / applications 1300) via the communication unit 1010, and receives a response including the information and the device / application serial number of the device / application 1300 from each of the multiple devices / applications 1300.
[0064] For example, in the device certificate, if an electricity trading system is defined as the device / application 1300, an electricity price equal to or higher than a predetermined value is defined as an execution condition, and selling electricity is defined as an execution content, the certificate verification unit 1093 acquires, for example, an electricity price from an external electricity price monitoring system, etc., as information for determining whether the execution condition is satisfied. Note that the method of acquiring the information for determining whether the execution condition is satisfied may be determined in advance for each execution condition, or may be described as a part of the delegation content included in the device certificate.
[0065] The certificate verification unit 1093 verifies the device certificate acquired in step S4020 (S4040). The device certificate includes an expiration date 7060 of the device certificate, delegation contents 7080 (including execution conditions and execution contents), and a target device / application serial number 7081, which will be described later with reference to FIG. 7A. In this procedure, the certificate verification unit 1093 verifies whether the device certificate is within the expiration date, whether the execution conditions are satisfied, whether a device / application serial number that matches the serial number of the target device / application 1300 has been acquired, and the like.
[0066] This allows the correct device / application 1300 to execute a process that is described in a valid device certificate, satisfies the execution conditions, and is in line with the execution content. As a result, it is possible to prevent execution of a process that is not intended by the delegator (e.g., the administrator or owner of the IoT terminal 1000).
[0067] In addition, a biometric signature using biometric information as a key is added to the device certificate in step S3050. In step S4040, the certificate verification unit 1093 may further execute a process of verifying the legitimacy of the biometric signature by using the delegator template certificate to check whether the biometric signature was indeed added by the principal. Through this verification, the verification terminal 1100 can verify that the user who generated the delegator template certificate is the same as the user who generated the device certificate. For example, the user who generated the delegator template certificate included in the existing transaction and the user who generated the device certificate are the delegator (for example, the owner, administrator, or user of the IoT terminal 1000). That is, in this embodiment, this verification shows that the execution of a legitimate process has been delegated by a legitimate delegator.
[0068] The certificate validator 1093 performs conditional branching based on the verification result of step S4040 (S4050), and if all the verifications performed in step S4040 are successful, the process proceeds to step S4060 and subsequent steps, and if the verifications fail, the execution condition verification result is set to failure (S4091). Details of the processes in steps S4040 and S4050 will be described later with reference to FIG. 5. After the process of step S4091 is performed, the certificate validator 1093 notifies the delegator by outputting an alert indicating that the execution condition verification result is failure to the output device of the IoT terminal 1000 (S4092), and ends the authority transfer process. In addition, when the certificate validation unit 1093 executes the processing of step S4091 (when the execution condition validation result is assigned a failure), it may record a log of the delegator template certificate validation processing and the device certificate validation processing (however, if the delegator template certificate validation processing is not executed, the log of the delegator template certificate validation processing is not recorded) and retain it in the IoT terminal 1000.
[0069] The certificate verification unit 1093 searches and obtains from the delegator template certificate storage unit 1091 the delegator template certificate (the device certificate and the delegator template certificate store the delegator's identifier) that matches the delegator indicated by the device certificate obtained in step S4020 (S4060).
[0070] The certificate validation unit 1093 verifies the delegator template certificate acquired in step S4060 (S4070). The delegator template device certificate includes the expiration date 7160 of the delegator template certificate, delegator attributes 7180, and (if necessary) the delegator's superior signature 7190, which will be described later with reference to Fig. 7B. In this procedure, the certificate validation unit 1093 verifies whether the delegator template certificate is within the expiration date, whether the delegator attributes satisfy the delegator conditions, and if the delegator attributes do not satisfy the delegator conditions, whether the signature of the delegator's superior has been affixed.
[0071] This makes it possible to verify that a delegator template that is within its validity period has been generated with proper authority (i.e., generated by a delegator with proper authority or approved by a superior with proper authority).
[0072] Furthermore, a signature value generated with the private key of the certification authority in step S2130 is added to the delegator template certificate, and in step S4070, the certificate validation unit 1093 may further execute a process of validating the signature value using the public key of the certification authority. Through this validation, the certificate validation unit 1093 can verify that the delegator template certificate has indeed been issued by the certification authority.
[0073] The certificate validation unit 1093 performs conditional branching based on the verification result of step S4070 (S4080), and if all verifications performed in step S4070 are successful, assigns "success" to the execution condition verification result (S4090) and proceeds to processing from step S4100 onward, and if the verifications fail, assigns "failure" to the execution condition verification result (S4091). Details of the processing in steps S4070 and S4080 will be described later with reference to FIG. 6.
[0074] If success is substituted for the execution condition verification result in step S4090, the certificate verification unit 1093 transfers processing authority to the target device / application 1300 and causes the target device / application 1300 to execute the processing (S4100). Specifically, in step S4100, for example, the certificate verification unit 1093 acquires the target device / application serial number and delegation contents from the device certificate acquired in step S4020, and the communication unit 1010 instructs the device / application 1300 indicated by the acquired target device / application serial number to execute processing of the execution contents indicated by the acquired delegation contents.
[0075] The hash value generation unit 1092 generates a hash value for the execution information acquired in step S4010 (S4110).
[0076] The signature generating unit 1070 obtains the device private key corresponding to the device certificate obtained in step S4020 from the key storage unit 1090, and adds a signature to the hash value generated in step S4110 with the obtained device private key (S4120). By adding a signature to the execution information with the device private key, it is possible to prevent tampering with the execution information.
[0077] The certificate validator 1093 records a log of the delegator template certificate validation process and the device certificate validation process, as well as a log (received from the device / app 1300) of the process executed by the device / app 1300 to which the processing authority was delegated in step S4100 based on the processing authority (the process indicated by the execution content included in the delegation content), and retains these in the IoT terminal 1000 (S4130). The delegator, a superior, or a stakeholder related to the process can confirm from these logs and the device certificate that the process executed by the device / app 1300 was executed based on the processing authority delegated from the legitimate delegator, and that the process executed by the device / app 1300 to which the processing authority was delegated was the process intended by the delegator.
[0078] The communication unit 1010 transmits (S4140) the delegator template certificate acquired in step S4070, the device certificate acquired in step S4020, and the execution information to which the signature has been added in step S4120 to the verification terminal 1100. Note that the verification terminal 1100 may acquire the delegator template certificate from the delegator template repository 1200 (for example, the communication unit 1010 notifies the verification terminal 1100 of the delegator template certificate serial number of the delegator template certificate acquired in step S4070, and the verification terminal 1100 requests the delegator template repository 1200 to transmit the delegator template certificate corresponding to the delegator template certificate serial number).
[0079] Note that either the device certificate validation process in steps S4040 and S4050 or the delegator template certificate validation process in steps S4070 and S4080 may be omitted.
[0080] With the above, the authority transfer process by the IoT terminal 1000 is completed.
[0081] FIG. 5 is a flowchart showing an example of details of the device certificate verification process in steps S4040 and S4050.
[0082] The certificate validation unit 1093 verifies whether the validity period 7060 of the device certificate is after the current time (S5010). The certificate validation unit 1093 performs conditional branching based on the verification result of step S5010 (S5020), and if the verification of step S5010 is successful, the unit 1093 proceeds to the process of step S5021 and thereafter, and if the verification of step S5010 is unsuccessful, the unit 1093 assigns failure to the device certificate verification result (S5030). Note that if failure is assigned to the device certificate verification result, the device certificate verification result in step S4050 is determined to be a failure.
[0083] The certificate verification unit 1093 verifies whether the execution conditions are satisfied (S5021). Specifically, for example, the certificate verification unit 1093 determines whether there is any device / application 1300 that has transmitted a response indicating that the execution conditions are satisfied, according to information included in the response (i.e., information for determining whether the execution conditions are satisfied) received from each of the devices / applications 1300 in step S4030. If the certificate verification unit 1093 determines that there is any device / application 1300 that has transmitted a response indicating that the execution conditions are satisfied, the certificate verification unit 1093 determines that the verification in step S5021 has been successful, and if it determines that there is no device / application 1300 that has transmitted a response indicating that the execution conditions are satisfied, the certificate verification unit 1093 determines that the verification in step S5021 has failed.
[0084] The certificate verification unit 1093 performs conditional branching based on the verification result of step S5021 (S5022), and if the verification of step S5022 is successful, executes processing from step S5023 onwards, and if the verification of step S5022 fails, assigns failure to the device certificate verification result (S5030).
[0085] The certificate verification unit 1093 verifies the serial number of the target device / application 1300 (S5023). Specifically, for example, the certificate verification unit 1093 determines whether any of the devices / applications 1300 that have transmitted a response indicating that the execution condition is satisfied (as described above, the response also includes the device / application serial number) have a device / application serial number that matches the target device / application serial number 7081 of the device certificate. If the certificate verification unit 1093 determines that any of the devices / applications 1300 that have transmitted a response indicating that the execution condition is satisfied have a device / application serial number that matches the target device / application serial number 7081 of the device certificate, the certificate verification unit 1093 determines that the verification in step S5023 has been successful, and if the certificate verification unit 1093 determines that no device / application has a device / application serial number that matches the target device / application serial number 7081 of the device certificate, the certificate verification unit 1093 determines that the verification in step S5023 has failed.
[0086] For example, if the certificate validation unit 1093 determines that there are multiple devices / apps 1300 that have device / app serial numbers matching the target device / app serial number 7081 of the device certificate among the devices / apps 1300 that have sent a response indicating that the execution conditions are met, then, for example, the certificate validation unit 1093 may determine that the device / app 1300 that sent the response first among the multiple devices / apps 1300 is the target device / app 1300 (candidate) to which processing authority is to be transferred.
[0087] The certificate verification unit 1093 performs conditional branching based on the verification result of step S5023 (S5024), and if the verification of step S5024 is successful, assigns "success" to the device certificate verification result (S5025), and if the verification of step S5024 is unsuccessful, assigns "failure" to the device certificate verification result (S5030). Note that if "success" is assigned to the device certificate verification result, the device certificate verification result in step S4050 is determined to be successful.
[0088] In the above example, in the process of step S5021 included in the device certificate verification process of step S4040, the certificate verification unit 1093 verifies whether the execution conditions are satisfied and then the processing authority is transferred to the target device / application 1300. However, it is also possible to have the target device / application 1300 determine whether the execution conditions are satisfied.
[0089] Specifically, for example, the process of acquiring execution information is omitted in step S4030, and the processes of steps S5021 and S5022 are omitted in the device certificate verification process in step S4040 (in this case, if the process in step S5020 is determined to be "successful," the process proceeds to the process in step S5023), and thus the determination regarding the execution condition by the certificate verification unit 1093 is omitted. Furthermore, in step S4100, the certificate verification unit 1093 acquires the target device / application serial number and the delegation content from the device certificate acquired in step S4020, and the communication unit 1010 instructs the device / application 1300 indicated by the acquired target device / application serial number to execute the process indicated by the execution content when it is determined that the execution condition indicated by the acquired delegation content is satisfied. In other words, the target device / application 1300 acquires the execution information, for example, periodically, and determines whether the execution condition is satisfied by itself, and executes the process of the execution content when it is determined that the execution condition is satisfied.
[0090] Furthermore, among the three verifications shown in FIG. 5 (verification regarding the expiration date, verification regarding the execution conditions, and verification regarding the target device / application serial number), any one or two of the verifications may be omitted.
[0091] With the above, the device certificate verification process by the certificate verification unit 1093 is completed.
[0092] FIG. 6 is a flowchart showing an example of the details of the delegator template verification process in steps S4070 and S4080.
[0093] The certificate validation unit 1093 verifies whether the validity period 7160 of the delegator template certificate is after the current time (S6010).
[0094] The certificate validation unit 1093 performs conditional branching based on the verification result of step S6010 (S6020), and if the verification is successful, proceeds to the processing of step S6030 and thereafter, and if the verification is unsuccessful, assigns failure to the delegator template certificate verification result (S6043). Note that if failure is assigned to the delegator template certificate verification result, it is determined that the delegator template certificate verification result in step S4080 is a failure.
[0095] The certificate validation unit 1093 validates the delegator attribute 7180 of the delegator template certificate (S6030). Note that the delegator attribute 7180 includes, for example, at least one of the following: the delegator's rating, the delegator's business track record (experience), and the delegator's qualifications (all of which are information indicating the delegator's capabilities).
[0096] The delegator conditions stored in advance in the delegator condition storage unit 1094 define attributes of a delegator who can transfer processing authority to the device / application 1300. If the attribute indicated by the delegator attribute 7180 is included in the attributes defined in the delegator conditions, it is determined that the verification in step S6030 is successful.
[0097] As described above, the attributes of a delegator to which the processing authority indicated by the delegator condition can be transferred may be defined for each device / application 1300, for each execution content, or for each combination of the device / application 1300 and the execution content. In this case, the certificate validator 1093 identifies the execution content indicated by the target device / application serial number 7081 or the delegation content 7080 of the device certificate, and verifies whether the delegator condition corresponding to the identified device / application 1300 or execution content is satisfied.
[0098] As described above, the delegator condition may describe a list of identifiers of delegators who can transfer processing authority to the device / application 1300. In this case, the certificate validator 1093 determines that the verification in step S6030 is successful when the delegator 7070 indicated by the delegator template is included in the list.
[0099] The certificate validation unit 1093 performs conditional branching based on the verification result of step S6030 (S6040), and if the verification is successful, assigns "success" to the delegator template certificate verification result (S6050), and if the verification is unsuccessful, proceeds to processing from step S6041 onwards. Note that if "success" is assigned to the delegator template certificate verification result, it is determined that the delegator template certificate verification result in step S4080 is successful.
[0100] The certificate validation unit 1093 verifies the delegate's superior signature 7190 of the delegate template certificate (S6041).
[0101] If the certificate validating unit 1093 determines that the signature value is included in the delegator superior signature 7190 of the delegator template certificate, it determines that the verification in step S6041 is successful.
[0102] Also, for example, a list of superior identifiers may be described as the delegator condition, and the certificate validation unit 1093 may determine that the verification in step S6041 is successful if the superior ID indicated by the delegator superior signature 7190 in the delegator template is included in the list.
[0103] In addition, the certificate validation unit 1093 may perform validation of the superior's signature in accordance with the algorithm by which the signature was generated (for example, as described in the delegator superior signature 7190 of the delegator template certificate), and determine that the validation in step S6041 is successful only if the validation of the signature is successful.
[0104] The certificate validation unit 1093 performs a conditional branch based on the verification result of step S6041 (S6042), and if the verification of step S6042 is successful, assigns success to the delegator template certificate verification result (S6050), and if the verification of step S6042 fails, assigns failure to the delegator template certificate verification result (S6043).
[0105] Of the three verifications shown in FIG. 6 (verification regarding the expiration date, verification regarding the delegator attributes, and verification regarding the delegator's superior signature), any one or two of the verifications may be omitted.
[0106] With the above, the delegator template verification process by the certificate validator 1093 is completed.
[0107] 7A and 7B are diagrams showing the data structures of a device certificate and a delegator template certificate, respectively.
[0108] FIG. 7A is a diagram showing an example of the data structure of the device certificate 7000. As shown in FIG.
[0109] The device certificate 7000 is data generated in step S3040 in which a biometric signature using biometric information as a key is added to the device public key, and complies with X.509, which is the standard for public key certificates (device certificates in this embodiment) in PKI (Public Key Infrastructure). The following description will be given with reference to the drawings.
[0110] The version 7010 indicates a string indicating the version of the device certificate.
[0111] The delegator template serial number 7020 is a serial number that is uniquely assigned to the delegator template by the delegator template repository 1200 corresponding to the device certificate 7000, and is assigned so as not to be duplicated.
[0112] The device public key serial number 7030 is a unique character string that is assigned to the device public key by the device key pair generation unit 1040 of the IoT terminal 1000, and is generated so that there is no duplication among different device public keys.
[0113] The biometric signature algorithm 7040 indicates an algorithm for generating the biometric signature value 7093 .
[0114] The issuer 7050 indicates the entity that issues the delegator template certificate, that is, the certificate authority.
[0115] The expiration date 7060 indicates the date and time when the device certificate expires.
[0116] Delegator 7070 indicates the delegator (the subject of the device certificate, that is, the user who requests issuance).
[0117] The delegation contents 7080 indicate the execution conditions of the process for which the authority is transferred to the device / application 1300, the execution contents of the process, and the like.
[0118] The target device / application serial number 7081 indicates the serial number (identifier) of the device / application 1300 to which the authority is transferred. In principle, the serial number of one device / application 1300 is stored in the target device / application serial number 7081, but the serial numbers of multiple devices / applications 1300 may be stored. If the serial numbers of multiple devices / applications 1300 are stored in the target device / application serial number 7081, the processing authority is transferred to all of the multiple devices / applications 1300 when the processing authority is transferred based on the device certificate.
[0119] The device public key algorithm 7091 indicates an algorithm for generating the device public key 7092 .
[0120] Device public key 7092 indicates the device public key generated in step S3040.
[0121] The biometric signature value 7093 is a value obtained by inputting the data from the version 7010 to the device public key 7092 into a predetermined hash function (for example, SHA1, SHA256, etc.) and generating a biometric signature for the obtained hash value using the biometric information as a key.
[0122] The above is the data structure of the device certificate 7000.
[0123] Fig. 7B is a diagram showing an example of the data structure of the delegator template certificate 7100. The delegator template certificate 7100 is data generated in step S2130 of Fig. 2. The basic data structure is a delegator template 7192 to which other header information, such as information about the delegator and the delegator's superior, is added, and which is also given a signature value 7193, and complies with X.509, the standard for public key certificates (device certificates in this embodiment) in PKI (Public Key Infrastructure). Each piece of data will be explained below.
[0124] The version 7110 indicates the version of the delegator template certificate as a string.
[0125] The delegator template serial number 7120 is a character string that is uniquely assigned to the delegator template by the delegator template repository 1200 and is assigned so as not to be duplicated.
[0126] The signature algorithm 7140 indicates an algorithm for generating the signature value 7193 to be assigned to the delegator template certificate.
[0127] The issuer 7150 indicates the entity that issues the delegator template certificate, that is, the certificate authority.
[0128] The expiration date 7160 indicates the date and time of expiration of the delegator template certificate.
[0129] The delegator 7170 indicates the delegator who delegates the transfer of processing authority to the target device / application 1300 (the subject of the delegator template certificate, that is, the user who requests issuance).
[0130] The delegator attributes 7180 indicate the attributes of the delegator (for example, the delegator's rating, track record, or experience, as described above).
[0131] The signature of the delegator's superior 7190 indicates the signature of the delegator's superior.
[0132] The biometric signature algorithm 7191 indicates an algorithm for generating the delegate template certificate 7100 .
[0133] Delegator template 7192 indicates the delegator template generated in step S3030 of FIG.
[0134] The signature value 7193 is a value obtained by inputting the data from the version 7110 to the delegator template 7192 into a predetermined hash function (for example, SHA1, SHA256, etc.) and converting the obtained hash value with the private key of the certificate authority.
[0135] The data structure of the delegator template certificate 7100 has been described above.
[0136] FIG. 8 is a block diagram showing an example of the hardware configuration of an IoT terminal 1000, a verification terminal 1100, a delegator template repository 1200, and an IoT terminal 1400 in the processing authority delegation system.
[0137] The IoT terminal 1000, the verification terminal 1100, the delegator template repository 1200, and the IoT terminal 1400 are each composed of a computer including, for example, a CPU (Central Processing Unit) 10, a main memory device 20, an auxiliary memory device 30, an input device 40, an output device 50, and a communication device 60.
[0138] The CPU 10 executes programs corresponding to each of the biometric information acquisition unit 1020, the delegator template generation unit 1030, the device key pair generation unit 1040, the device certificate generation unit 1050, the execution information acquisition unit 1060, the signature generation unit 1070, the hash value generation unit 1092, the certificate verification unit 1093, the certificate verification unit 1120, the signature verification unit 1130, and the delegator template certificate generation unit 1220.
[0139] The main memory device 20 is a device equivalent to a computer memory, and stores programs corresponding to the biometric information acquisition unit 1020, the delegator template generation unit 1030, the device key pair generation unit 1040, the device certificate generation unit 1050, the execution information acquisition unit 1060, the signature generation unit 1070, the delegation information acquisition unit 1080, the hash value generation unit 1092, the certificate verification unit 1093, the certificate verification unit 1120, the signature verification unit 1130, and the delegator template certificate generation unit 1220. Each process is realized by executing these programs by the CPU 10.
[0140] The auxiliary storage device 30 is a storage device represented by a hard disk drive (HDD) or a solid state drive (SSD), and corresponds to a key storage unit 1090, a delegator template certificate storage unit 1091, a delegator condition storage unit 1094, a delegator template certificate storage unit 1230, and a delegation information storage unit 1240. Data stored in each unit is accumulated as data on the auxiliary storage device 30.
[0141] The input device 40 includes a mouse, a keyboard, etc. for receiving input from an operator, and a sensor for acquiring biometric information. The output device 50 includes a display, a printer, etc., and outputs the results of program execution and information on the main memory device 20. The communication device 60 is used when communicating with other devices, and realizes communication by the communication unit 1010, the communication unit 1110, and the communication unit 1210.
[0142] The CPU 10 operates as a functional unit that provides a specified function by executing processing in accordance with the programs of each functional unit loaded into the main memory device 20. For example, the CPU 10 functions as a delegator template generation unit 1030 by executing processing in accordance with a delegator template generation program loaded into the main memory device 20. The same applies to other programs. Furthermore, the CPU 10 also operates as a functional unit that provides each function of the multiple processes executed by each program. Computers and computer systems are devices and systems that include these functional units.
[0143] Information such as programs and tables that realize each function can be stored in a storage device such as an auxiliary storage device 30, a non-volatile semiconductor memory, a hard disk drive, or an SSD (Solid State Drive), or in a computer-readable non-transitory data storage medium such as an IC card, an SD card, or a DVD.
[0144] 9 is a flowchart showing an example of the verification process by the verification terminal 1100. In this process, the verification terminal 1100 verifies the delegator template certificate, the device certificate, and the signature added to the execution information transmitted in step S2140.
[0145] The certificate verification unit 1120 and the signature verification unit 1130 of the verification terminal 1100 execute the delegator template certificate verification process (S9010). Specifically, for example, the certificate verification unit 1120 executes the same verification as in step S4070 (note that the verification terminal 1100 acquires the delegator conditions from the IoT terminal 1000), and in addition, the signature verification unit 1130 verifies whether there is a signature of the issuer of the delegator template certificate (i.e., whether the signature is stored in the signature value 7193). In addition, since the signature value 7193 is generated by the private key of the certification authority, the signature verification unit 1130 may verify the signature value 7193 by using, for example, the public key of the certification authority.
[0146] The certificate validation unit 1120 performs conditional branching based on the verification result of step S9010 (S9020). If all verifications performed in step S9010 are successful, the process proceeds to step S9030 and subsequent steps. If the verifications fail, the process assigns failure to the verification result of the processing content (S9071).
[0147] The certificate verification unit 1120 executes a device certificate verification process (S9030). Specifically, for example, the certificate verification unit 1120 executes the same verification as in step S4040. Note that the verification in step S5021 included in the process of step S4040 requires information indicating whether the execution condition is satisfied, and the verification in step S5023 included in the process of step S4040 requires information indicating the device / application serial number of the device / application 1300 that has responded that the execution condition is satisfied. For example, in the process of step S4140, the communication unit 1010 includes these pieces of information in the execution information (to which a signature is attached) and transmits the information to the verification terminal 1100, whereby the information is disclosed to the verification terminal 1100. Also, it is not necessary for the information to be disclosed to the verification terminal 1100. In this case, in step S9030, the same verification process as in step S5021 and the same verification process as in step S5023 may be omitted.
[0148] The certificate validation unit 1120 performs conditional branching based on the verification result of step S9030 (S9040). If all verifications performed in step S9030 are successful, the process proceeds to step S9050 and subsequent steps. If the verifications fail, the process assigns failure to the verification result of the processing content (S9071).
[0149] The signature verification unit 1130 verifies the signature added to the execution information (S9050). Specifically, for example, the signature verification unit 1130 verifies whether the signature added to the execution information was generated by the device private key by using the device public key 7092 included in the device certificate.
[0150] The certificate validation unit 1120 performs a conditional branch based on the result of the validation in step S9050 (S9060), and if the validation performed in step S9050 is successful, assigns success to the processing content validation result (S9070), and if the validation fails, assigns failure to the processing content validation result (S9071).
[0151] When the certificate validating unit 1120 assigns success to the processing content verification result, it records logs of the delegator template certificate verification, the device certificate verification, and the signature verification added to the execution information by the verification terminal 1100, and holds them in the verification terminal 1100 (S9080). Note that when the certificate validating unit 1120 assigns failure to the processing content verification result, it may execute the log recording process in step S9080.
[0152] With the above, the verification process by the verification terminal 1100 is completed.
[0153] 9, the verification terminal 1100 can verify that a valid device / application 1300 performed processing according to the execution contents described in a valid device certificate, and that the processing was performed according to the execution contents based on the execution information that has been verified to satisfy the execution conditions and not have been tampered with. Furthermore, the verification terminal 1100 can verify that a delegator template that is within the validity period was generated with proper authority (i.e., generated by a delegator with proper authority, or approved by a superior with proper authority).
[0154] Fig. 10 is an explanatory diagram showing an example of an outline of the overall processing by the processing authority delegation system. As shown in Fig. 10, the processing authority delegation system may further include an audit server 1600. In the example of Fig. 10, some of the configurations included in the processing authority delegation system shown in Fig. 1 are omitted.
[0155] The IoT terminal 1000 generates a device key pair, and a delegator template and device certificate based on the biometric signature according to the process shown in Fig. 3. The IoT terminal 1000 transmits the delegator template to the delegator template repository 1200, which generates a delegator template certificate including the delegator attributes (and the delegator's superior signature, if necessary) according to the method shown in Fig. 2, and retains it itself and transmits it to the IoT terminal 1000. The IoT terminal 1000 stores the generated device certificate and the device private key included in the device key pair in its own key storage unit 1090.
[0156] The IoT terminal 1000 signs the execution information using the device private key in step S4120. The IoT terminal 1000 executes device certificate verification processing in step S4040 and delegator template certificate verification processing in step S4070, and if these verifications are successful, transfers processing authority to the target device / application 1300 in step S4100.
[0157] The device / application 1300 to which the processing authority has been transferred executes the processing indicated by the execution content. The IoT terminal 1000 stores the processing data 1510 in the log 1520 (S4130). The processing data 1510 includes data generated by the executed processing (the data is transmitted from the device / application 1300 to the IoT terminal 1000) and execution information to which a signature has been added in step S4120. The IoT terminal 1000 may also store in the log 1520 a log of the generation processing of each certificate and a log of the authority transfer processing of FIGS. 4A and 4B.
[0158] In addition, the IoT terminal 1000 may transmit the processing data 1510 to the verification terminal 1100, and the verification terminal 1100 may confirm the processing contents (S2401). The verification terminal 1100 obtains a delegator template certificate from the IoT terminal 1000 or the delegator template repository 1200, and obtains a device certificate from the IoT terminal 1000.
[0159] The verification terminal 1100 executes the delegate template certificate verification process of step S9010, the device certificate verification process of step S9030, and the signature verification process attached to the execution information of step S9050, and stores the results of these verification processes and the results of the processing content confirmation process of step S2401 in the log 1150.
[0160] The verification terminal 1100 transmits a log 1150 to the audit server 1600, and the audit server 1600 verifies the received log. Specifically, for example, the audit server 1600 verifies, based on the log 1150, when and for what processing (or when and for what processing authority to transfer) the delegator template certificate and the device certificate were used, verifies which verification terminal 1100 performed the verification process, and verifies the verification results by the verification terminal 1100. By having the audit server 1600 verify the log 1150, a user (e.g., a third party) of the audit server 1600 can manage whether the cycle of transfer of processing authority is functioning correctly.
[0161] As described above, according to the first embodiment, a delegator template certificate is generated from the user's biometric information, a pair of a device private key and a device public key is generated, a device certificate is generated by adding a biometric signature to the device public key using the user's biometric information as a key, the validity of the device certificate is verified using the delegator template certificate, and further the validity of the user's signature is verified using the device certificate.
[0162] Furthermore, a signature using the private key of the certification authority is added to the delegator template certificate, and when verifying the signature, it is possible to verify the validity using the public key of the certification authority that corresponds to the private key of the certification authority.
[0163] In addition, the delegator template certificate is provided with the attributes of the delegator and, if necessary, the signature of the delegator's superior, and in the delegator template certificate verification process, it is verified whether the attributes of the delegator satisfy the delegator conditions, or whether the signature of the delegator's superior has been provided even if the attributes of the delegator do not satisfy the delegator conditions. In this way, processing authority is transferred to device / application 1300 by a person having valid authority.
[0164] The device certificate is provided with the serial number of the device / application 1300, execution conditions, and execution details of the process to which the authority is transferred, and the device certificate verification process verifies that the process is executed by the legitimate device / application 1300 and that the execution conditions are satisfied. This not only guarantees that the process is executed by the legitimate device / application 1300, but also prevents the device / application 1300 from executing a process not intended by the delegator.
[0165] The processing authority delegation system does not need to include the delegator template repository 1200. In this case, for example, the IoT terminal 1000 executes the processing by the delegator template repository 1200 shown in this embodiment, and the IoT terminal 1000 holds the information held by the delegator template repository 1200 shown in this embodiment. In this case, the communication between the IoT terminal 1000 and the delegator template repository 1200 shown in this embodiment is omitted. EXAMPLES
[0166] In this embodiment, an example of delegation authority of a delegator in the processing authority delegation system of embodiment 1 will be described. Unless otherwise specified below, the configuration of the processing authority delegation system in this embodiment and the processing executed by the processing authority delegation system are the same as those in embodiment 1.
[0167] As described in Example 1, a delegator template certificate and a device certificate corresponding to a certain delegator are generated, and the IoT terminal 1000 performs verification of the delegator template certificate and the device certificate, thereby transferring processing authority for the execution conditions and execution contents indicated by the device certificate to the apparatus / app 1300 indicated by the device certificate.
[0168] Fig. 11A is an explanatory diagram showing an example of delegation authority of a delegator. In the example of Fig. 11A, there are three delegators (referred to as delegator α, delegator β, and delegator γ), three IoT terminals 1000 (referred to as IoT terminal 1, IoT terminal 2, and IoT terminal 3), three devices / applications 1300 (referred to as device / application a, device / application b, and device / application c), and three processes (process A executed by device / application a, process B executed by device / application b, and process C executed by device / application c).
[0169] Furthermore, device / app a is given the processing authority to execute step A by delegator α, device / app b is given the processing authority to execute step B by delegator β, and device / app c is given the processing authority to execute step C by delegator γ. That is, for example, the IoT terminal 1 generates a delegator template for delegator α and a device certificate for delegator α to transfer the processing authority for the execution of step A to device / app a, verifies the delegator template certificate corresponding to the delegator template and verifies the device certificate, and transfers the processing authority to device / app a. The same applies to the transfer of processing authority for step B and the transfer of processing authority for step C.
[0170] Furthermore, step B can be executed only after step A has been executed, and step C can be executed only after step B has been executed. Therefore, for example, if the execution conditions of the device certificate corresponding to the delegator β state that step A has been executed, and the execution conditions of the device certificate corresponding to the delegator γ state that step C has been executed, the processing will be executed in the order of step A, step B, and step C.
[0171] As shown in FIG. 11A, each of different (series of) processes such as process A, process B, and process C may be executed by a different device / application 1300, and a delegator template generation process, a device certificate generation process, and various certificate verification processes for transferring processing authority by each of the different devices / applications 1300 may be executed by a different IoT terminal 1000.
[0172] Fig. 11B is an explanatory diagram showing an example of the delegator's delegation authority. The example in Fig. 11B is different from the example in Fig. 11A in that the number of IoT terminals 1000 is one (referred to as IoT terminal 1), the number of devices / applications 1300 is six (device / application a', device / application b', and device / application c' are added), and process A, process B, and process C are also executed by device / application a', device / application b', and device / application c', respectively.
[0173] The example in FIG. 11B differs from the example in FIG. 11A in that device / app a and device / app a' are given processing authority to execute step A by delegator α, delegator β, or delegator δ (however, delegator δ requires the signature of a superior), device / app b and device / app b' are given processing authority to execute step B by delegator β, delegator γ, or delegator δ (however, delegator δ requires the signature of a superior), and device / app c and device / app c' are given processing authority to execute step C by delegator γ, delegator α, or delegator δ (however, delegator δ requires the signature of a superior).
[0174] Each of the multiple steps (execution contents) can be executed by one device / application 1300, or can be executed by any of multiple different devices / applications 1300 as in the example of Fig. 11B. Also, each of the multiple devices / applications 1300 can receive processing authority delegated from any of a single delegator, or can receive processing authority delegated from any of multiple delegators as in the example of Fig. 11B. Also, although not shown in Fig. 11B, multiple different expiration dates can be set for the device certificate even with the same delegation contents, the same device / application serial number, and the same delegator.
[0175] Therefore, the maximum number of device certificates that can be prepared for the transfer of processing authority is the number of target devices / applications x the number of delegators x the number of delegation contents x the number of validity periods.
[0176] As shown in the second embodiment, when there are multiple consecutive steps or when multiple devices / applications 1300 can execute the processing of one step, even if the delegator is different for each device / application 1300, the IoT terminal 1000 transfers the processing authority in advance, so that the processing can be executed autonomously based on the will of the delegator. EXAMPLES
[0177] In the third embodiment, a use case of the processing authority delegation system in the first embodiment will be described.
[0178] <Use case 1: Setting and processing instructions for equipment on a factory production line> In use case 1, the processing authority delegation system functions as a production management system for a manufacturing line in a factory, and the device / application 1300 is a device included in the manufacturing line in the factory. Furthermore, a worker on the manufacturing line in the factory is the delegator, and a supervisor on the manufacturing line in the factory is the superior of the delegator. In other words, a delegator template and a signature for a device certificate are generated using biometric information of the worker. Furthermore, the delegator template may include the signature of the supervisor.
[0179] The execution conditions of use case 1 include, for example, that there is free time in the operation schedule of the device, that the excess inventory of the product manufactured by the device is below a specified amount, that the materials for the item manufactured by the device are secured, that an order for the product manufactured by the device has been received, and that there is a storage location for the product manufactured by the device, etc. Furthermore, the delegator conditions of use case 1 include, for example, that the delegator is a worker authorized to operate the device, etc.
[0180] If the verifications in steps S4040 and S4080 are successful (however, verification of the execution conditions in step S5021 included in step S4080 may be performed by the device after the processing authority is transferred to the device), the processing authority is transferred to the device, and the device's autonomous setting change, start and stop of processing by the device, etc. are executed as the execution contents indicated by the execution information, and a signature is further attached to the execution information using the device private key. This allows the processing to be executed without the delegator having to present his / her biometric information each time the processing is executed.
[0181] In addition, the delegator conditions describe, for example, the correspondence between the importance of the execution contents and the qualifications and achievements of the worker. In step S6030, it is verified whether the qualifications and achievements of the worker indicated in the delegator attribute 7180 of the delegator template certificate satisfy the qualifications and achievements corresponding to the execution contents indicated in the delegator contents 7080 of the device certificate (in the delegator conditions). If it is determined that this is not satisfied, the verification of step S6041 is executed.
[0182] The IoT terminal 1000 may, for example, periodically check the expiration date 7160 of the delegator template certificate stored in the delegator template certificate storage unit 1091 and the expiration date 7060 of the device certificate stored in the key storage unit 1090, and when the time until these expiration dates falls within a predetermined time, may display a message on the output device 50 of the IoT terminal 1000 urging the user to update the certificate. This also applies to use cases described later.
[0183] Furthermore, a purchaser of a product manufactured by the machine can verify from the delegator template certificate, device certificate, and execution information (signed) that the product was manufactured by the machine executing a process delegated to the machine at the will of the worker (and supervisor).
[0184] <Use case 2: Energy trading using an autonomous trading system> In use case 2, the processing authority delegation system functions as an energy trading system, and the device / application 1300 is an energy trading terminal owned by an intermediary for energy trading. The energy consumer (buyer) and supplier (seller) are the delegators. That is, a delegator template and a signature for a device certificate are generated using biometric information of the energy consumer (buyer) and supplier (seller). The delegator template may also include the signature of a superior of the energy consumer (buyer) and supplier (seller).
[0185] Execution conditions for use case 2 on the electricity consumer (buyer) side include, for example, that the predicted power shortage is greater than or equal to a predetermined value, that the source of the electricity consumed is of a predetermined type, that the trading price of electricity is less than or equal to a predetermined value, and that the length of time for which the power shortage is predicted is greater than or equal to a predetermined value.
[0186] Furthermore, execution conditions on the electricity supplier (seller) side of use case 2 include, for example, that the predicted surplus amount of electricity is equal to or greater than a predetermined value, that the source of the supplied electricity is of a predetermined type, that the trading price of electricity is equal to or greater than a predetermined value, and that the length of time during which the surplus of electricity is predicted is equal to or greater than a predetermined value. The electricity trading system may include smart meters installed at the electricity consumer (buyer) or supplier (seller), and power generation facilities installed at the electricity supplier (seller).
[0187] If the verification in steps S4040 and S4080 is successful (however, verification of the execution conditions in step S5021 included in step S4080 may be performed by the energy trading terminal after the processing authority is transferred to the energy trading terminal), the processing authority is transferred to the energy trading terminal, and the transaction of electricity between the electricity consumer (buyer) and supplier (seller) is autonomously executed as the execution content indicated by the execution information, and further a signature is added to the execution information using the device private key. This allows the processing to be executed without the delegator having to present his / her biometric identity each time the processing is executed.
[0188] Furthermore, electricity consumers (buyers) and suppliers (sellers) can confirm that the electricity trading processing was performed by the energy trading terminal at the will of the electricity consumer (buyer) and supplier (seller) by using the delegator template certificate, device certificate, and execution information (signed).
[0189] <Use case 3: Autonomous issuance of inspection certificates> In use case 3, the processing authority delegation system functions as an inspection system that inspects products on a factory production line, and device / application 1300 is an issuing device that issues inspection certificates for products manufactured on the production line. An inspection worker on the factory production line is the delegator, and an inspection supervisor on the factory production line is the delegator's superior. In other words, a delegator template and a signature for a device certificate are generated using biometric information of the inspection worker. The delegator template may also include the signature of the inspection supervisor.
[0190] Conditions for executing use case 3 include, for example, that parts procured from a specified supplier are used in the product being inspected, that the product being inspected has been manufactured under the instructions (or delegation) of a worker who is authorized to use the issuing device, that inspection has been carried out on the product being inspected in accordance with a specified process, and that the product being inspected meets specified performance requirements.
[0191] If the verification in steps S4040 and S4080 is successful (however, verification of the execution conditions in step S5021 included in step S4080 may be performed by the issuing device after the processing authority is transferred to the issuing device), the processing authority is transferred to the issuing device, the issuing device autonomously issues an inspection certificate as the execution content indicated by the execution information, and further, a signature is added to the execution information using the device private key. This allows the processing to be executed without the delegator having to present a biometrics each time the processing is executed.
[0192] Furthermore, a purchaser of a product for which an inspection certificate has been issued by the issuing device can verify from the delegator template certificate, device certificate, and execution information (signed) that the inspection of said product was carried out by a worker (and supervisor) at his / her discretion, and that the product was manufactured by executing a process delegated to said device.
[0193] <Summary> The present invention is not limited to the above-mentioned embodiment, and various modifications are included. For example, the above-mentioned embodiment is described in detail to easily explain the present invention, and is not necessarily limited to those having all the configurations described. In addition, it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of one embodiment. In addition, the addition, deletion, or replacement of other configurations can be applied to a part of the configuration of each embodiment, either alone or in combination.
[0194] In addition, the above-mentioned configurations, functions, processing units, processing means, etc. may be realized in part or in whole by hardware, for example, by designing them as integrated circuits. In addition, the above-mentioned configurations and functions, etc. may be realized in software by a processor interpreting and executing a program that realizes each function. Information such as the program, table, file, etc. that realizes each function can be stored in a memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.
[0195] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and not all control lines and information lines in the product are necessarily shown. In reality, it can be considered that almost all components are connected to each other. [Explanation of symbols]
[0196] 10 CPU, 20 main memory device, 30 auxiliary memory device, 60 communication device, 1000 IoT terminal, 1030 delegate template generation unit, 1040 device key pair generation unit, 1050 device certificate generation unit, 1060 execution information acquisition unit, 1070 signature generation unit, 1080 delegation information acquisition unit, 1090 key storage unit, 1091 delegate template certificate storage unit, 1092 hash value generation unit, 1093 certificate verification unit, 1100 verification terminal, 1120 certificate verification unit, 1130 signature verification unit, 1200 delegate template repository, 1220 delegate template certificate generation unit, 1230 delegate template certificate storage unit, 1240 delegation information storage unit, 1300 device / application
Claims
1. A processing authority transfer system, A first terminal and a processing execution entity, the first terminal holds a first certificate indicating delegation contents indicating execution conditions and execution contents of the process and an identifier of an execution subject to which authority to execute the process is transferred and based on biometric information of a delegator of the process; The execution subject transmits information indicating whether the execution condition is satisfied and an identifier of the execution subject to the first terminal; The first terminal is performing a first certificate validation based on the delegation content and the identifier indicated by the first certificate; when it is determined in the first certificate verification that an execution subject has transmitted information indicating that the execution condition is satisfied based on the information received from the execution subject, it is determined whether an identifier of the execution subject matches an identifier indicated by the first certificate; A processing authority delegation system that delegates the authority for the processing indicated by the execution content to the execution subject based on a result of the first certificate verification.
2. 2. The processing authority transfer system according to claim 1, Further comprising a second terminal; The first terminal holds a plurality of the first certificates; each of the plurality of first certificates includes a public key associated with the first certificate; The first terminal is maintaining a private key corresponding to each of said public keys; Acquire execution information indicating the execution content; obtaining a first certificate indicating the execution content indicated by the execution information from the plurality of first certificates; performing the first certificate validation based on the obtained first certificate; If the first certificate verification is successful, a signature is added to the execution information based on a private key corresponding to a public key included in the acquired first certificate; Transmitting the execution information to which the signature has been added and the acquired first certificate to the second terminal; The second terminal verifies the signature attached to the execution information based on a public key included in a first certificate received from the first terminal.
3. 2. The processing authority transfer system according to claim 1, The first terminal is a second certificate indicating an attribute of the trustor and based on the biometric information; A delegator condition regarding attributes of a delegator who can delegate the authority to the execution entity is stored; performing a second certificate validation, including validating whether attributes indicated by the second certificate satisfy the delegator condition; A processing authority delegation system that delegates the authority to the execution entity based on results of the first certificate validation and the second certificate validation.
4. 4. The processing authority transfer system according to claim 3, The attribute indicates at least one of a rating of the delegator, a business performance of the delegator, and a qualification of the delegator.
5. 4. The processing authority transfer system according to claim 3, the second certificate includes an area for storing a signature of the superior of the delegator; The first terminal is In the second certificate verification, a processing authority delegation system that performs verification of the superior's signature in the second certificate when it is determined that the attribute indicated by the second certificate does not satisfy the delegator condition.
6. 2. The processing authority transfer system according to claim 1, A plurality of consecutive processes can be executed by a plurality of execution entities, A plurality of the delegators correspond to each of the execution entities; The first terminal is holding the first certificate corresponding to each combination of a process included in the plurality of processes, an execution subject included in the plurality of execution subjects, and a delegator included in the plurality of delegators; performing the first certificate validation based on any of the first certificates; A processing authority delegation system that transfers authority to execute a process corresponding to the first certificate to an execution entity corresponding to the first certificate based on a result of the first certificate verification.
7. A processing authority transfer method by a processing authority transfer system, comprising: The processing authority delegation system includes a first terminal and a processing execution entity, the first terminal holds a first certificate indicating delegation contents indicating execution conditions and execution contents of the process and an identifier of an execution subject to which authority to execute the process is transferred and based on biometric information of a delegator of the process; The processing authority transfer method includes: The execution subject transmits information indicating whether the execution condition is satisfied and an identifier of the execution subject to the first terminal; The first terminal performs a first certificate verification based on the delegation content and the identifier indicated by the first certificate; When the first terminal determines, in the first certificate verification, based on the information received from the execution subject, that there is an execution subject that has transmitted information indicating that the execution condition is satisfied, the first terminal determines whether an identifier of the execution subject matches an identifier indicated by the first certificate; A processing authority transfer method, in which the first terminal transfers the authority for a process indicated by the execution content to the execution subject based on a result of the first certificate verification.