Automatic certificate issuance system and automatic certificate issuance method
The system enhances security and accessibility of certificate delivery services by using personal devices for authentication and controlled kiosk printing, addressing password exposure and privacy concerns in public kiosk terminals.
Patent Information
- Application Number
- JP2023213816
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-07-01
AI Technical Summary
The security of certificate automatic delivery services using My Number Cards is compromised due to the risk of password exposure when entering the password into kiosk terminals in public locations, and some individuals resist using these services due to privacy concerns.
A system that allows users to apply for certificates using a personal device, which verifies the password and electronic certificate, and only proceeds with the delivery process after successful authentication, ensuring the certificate is printed securely at a kiosk terminal only when authorized.
Enhances security by preventing password exposure and making the service more accessible to those resistant to using kiosk terminals, allowing secure certificate delivery through personal devices.
Smart Images

Figure 2025097570000001_ABST
Abstract
Description
[Technical field]
[0001] This application relates to an automatic certificate issuing service that enables users to obtain various certificates issued by government agencies using kiosk terminals (multi-copy machines) installed in convenience stores and the like. [Background technology]
[0002] Certificate issuing services that allow users to obtain various certificates issued by government agencies using kiosk terminals have been available for some time. For example, Patent Document 1 discloses an automatic certificate issuing system (official document issuing system) that allows users to obtain various certificates issued by government services using kiosk terminals (multi-copy machines) installed in convenience stores, etc.
[0003] In an automatic certificate issuing system that uses a kiosk terminal, it is necessary to authenticate the identity of the applicant who applies for the issuance of a certificate. In the invention disclosed in Patent Document 1, the Basic Resident Register card, which is one of the personal number cards issued to individuals by government agencies, is used to authenticate the identity of the applicant. In the invention disclosed in Patent Document 1, the identity of the applicant who applies for the issuance of a certificate is authenticated by using a digital certificate read from the Basic Resident Register card. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2005-309888 A Summary of the Invention [Problem to be solved by the invention]
[0005] In Japan, the personal number cards issued to individuals by government agencies have been changed from Basic Resident Registration Cards to My Number Cards since January 2016. In response to this, existing automatic certificate issuance services using kiosk terminals are now compatible with My Number Cards.
[0006] When reading an electronic certificate (such as an electronic certificate for user authentication) from a My Number card, it is necessary to verify the password (4-digit PIN) set by the applicant at the time of issuance of the My Number card. Therefore, in a conventional certificate automatic delivery service using a kiosk terminal, the applicant has to enter the password of the My Number card into the kiosk terminal.
[0007] When applying for a certificate using a kiosk terminal installed in a location with a lot of foot traffic, such as a multi-copy machine installed in a convenience store, in a conventional certificate automatic delivery service, there is a risk that the password of the My Number card entered by the applicant into the kiosk terminal may be peeked at by others.
[0008] Therefore, the present application aims to enhance the security of a certificate automatic delivery service using an individual number card.
Means for Solving the Problem
[0009] A first invention for solving the above-described problems is a certificate automatic delivery system including an individual number card issued to an applicant, a user device having a function of communicating with the individual number card, and a certificate delivery server for delivering a certificate. The individual number card according to the first invention stores an electronic certificate with a password set therein. The user device according to the first invention performs an identity verification process for verifying the password set in the electronic certificate, and after performing a process of generating application information for a certificate when the password verification is successful, transmits the application information to the certificate delivery server, and includes a certificate application unit that executes a delivery application process of storing the reception number of the application information received from the certificate delivery server. The certificate delivery server according to the first invention, when the application information is transmitted from the user device, generates a reception number for the application information, stores at least the application information in association with the reception number, and then includes a certificate delivery unit that executes a reception process of transmitting the reception number to the user device. The certificate automatic delivery system according to the first invention is configured so that an applicant can apply for the delivery of a certificate using a user device possessed by the applicant in order to solve the problems of the present application.
[0010] The second invention is an invention in the first invention that enables a certificate applied for delivery using a user device to be printed at a kiosk terminal. The certificate automatic delivery system according to the second invention includes a kiosk terminal having a print function. When a reception number is transmitted from the kiosk terminal, the certificate delivery unit of the certificate delivery server according to the second invention executes a delivery process of transmitting certificate information corresponding to the application information associated with this reception number to the kiosk terminal. The kiosk terminal according to the second invention includes a certificate printing unit that acquires a reception number from an applicant, transmits this reception number to the certificate delivery server, and executes a printing process of printing the certificate information transmitted from the certificate delivery server.
[0011] The third invention is an invention in the second invention that enhances the security related to the printing of a certificate. In the third invention, in the delivery process, the certificate delivery unit of the certificate delivery server transmits a print confirmation request to the user device that transmitted the application information corresponding to the reception number received from the kiosk terminal, and only when print permission is indicated by the print confirmation response received from this user device, transmits the certificate information to the kiosk terminal.
[0012] The fourth invention is an invention in any one of the first to third inventions that enhances the security of personal authentication. In the fourth invention, in the personal confirmation process, when the password verification is successful, the certificate application unit of the user device executes a process of authenticating the applicant using the electronic certificate read from the personal identification number card, and only when the password verification is successful and the authentication of the applicant using the electronic certificate is successful, transmits the application information to the certificate delivery server.
[0013] The fifth invention is a method invention. The certificate automatic delivery method according to the fifth invention includes: step a in which a user device operated by an applicant who makes a delivery application for a certificate collates a password set in an electronic certificate stored in a personal identification number card; step b in which, when the password collation is successful, the user device generates application information for applying for a certificate, and then transmits the application information to a certificate delivery server that delivers the certificate; step c in which, when the certificate delivery server receives the application information from the user device, the certificate delivery server generates a reception number for the application information, stores at least the application information in association with the reception number, and then transmits the reception number to the user device; and step d in which the user device stores the reception number received from the certificate delivery server.
[0014] The sixth invention is an invention in the fifth invention that enables a certificate delivered by using a user device to be printed. The certificate automatic delivery method according to the sixth invention includes: step e in which a kiosk terminal having a print function acquires a reception number from an applicant and transmits the reception number to the certificate delivery server; step f in which, when the certificate delivery server receives the reception number from the kiosk terminal, the certificate delivery server transmits certificate information corresponding to the application information associated with the reception number to the kiosk terminal; and step g in which the kiosk terminal prints the certificate information transmitted from the certificate delivery server.
[0015] The seventh invention is an invention in the sixth invention that enhances the security related to the printing of a certificate. In the certificate automatic delivery method according to the seventh invention, in step f, the certificate delivery server transmits a print confirmation request to the user device that transmitted the application information associated with the reception number received from the kiosk terminal, and transmits the certificate information to the kiosk terminal only when print permission is indicated by a print confirmation response received from the user device.
[0016] The eighth invention is an invention that enhances the security of personal authentication in any one of the sixth invention to the seventh invention. In the certificate automatic delivery method according to the eighth invention, the personal identification number card stores the electronic certificate of the applicant who holds the personal identification number card. In the certificate automatic delivery method according to the eighth invention, in step a, when the password verification is successful, the user device executes a process of authenticating the applicant using the electronic certificate read from the personal identification number card, and only when the password verification is successful and the authentication of the applicant using the electronic certificate is successful, step b is executed.
Effect of the Invention
[0017] In the present invention, by enabling the applicant to apply for the delivery of a certificate using the user device held by the applicant, the security of the certificate automatic delivery service is enhanced. By enabling the applicant to apply for the delivery of a certificate using the user device held by the applicant, it is possible to prevent the password entered by the applicant into the personal identification number card and the coupon information printed on the personal identification number card from being peeked at.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Embodiment for Carrying out the Invention
[0019] Hereinafter, embodiments of the invention according to the present application will be described. These embodiments are for facilitating the understanding of the invention of the present application, and the invention of the present application is not limited to these embodiments. Also, unless otherwise specified, the drawings are schematic diagrams drawn for facilitating the understanding of the invention of the present application.
[0020] The invention disclosed in the present application is an invention devised for the purpose of enhancing the security of a certificate automatic delivery service that uses a personal identification number card issued by an administrative agency to an individual. Here, the certificate automatic delivery service is a service that enables various certificates (such as copies of household registers and seal registration certificates) delivered by an administrative agency to be obtained at a kiosk terminal installed in a convenience store or the like.
[0021] In the conventional certificate automatic delivery service, an applicant who uses the certificate automatic delivery service operates a kiosk terminal installed in a convenience store or the like to apply for the delivery of a certificate. The kiosk terminal operated by the applicant in the conventional certificate automatic delivery service is often installed in a crowded place such as a convenience store. For this reason, in the conventional certificate automatic delivery service, there is a risk that the password entered by the applicant into the kiosk terminal or the face information of the personal identification number card (for example, the personal identification number) may be peeked at. Also, some people are resistant to entering the password of the personal identification number card into a kiosk terminal installed in a convenience store or the like, and there are those who do not use the conventional certificate automatic delivery service.
[0022] In view of such problems, in the present application, it is possible to apply for the delivery of a certificate using a user device possessed by the user. If it is possible to apply for the delivery of a certificate using a user device possessed by the user, it is possible to apply for the delivery of a certificate in a place where it is not easily noticeable (for example, at home), and thus the risk of the password entered into the personal identification number card or the face information of the personal identification number card being peeked at can be eliminated. Also, those who are resistant to entering the password of the personal identification number card into a kiosk terminal can use the certificate automatic delivery service without resistance.
[0023] FIG. 1 is a system configuration diagram of a certificate automatic delivery system 1 according to the present embodiment. FIG. 2 is a block diagram of the certificate automatic delivery system 1 shown in FIG. 1.
[0024] As shown in FIG. 1, the certificate automatic delivery system 1 according to the present embodiment includes a personal number card 2 issued by an administrative agency to an individual, a user device 3 having a function of communicating with the personal number card 2, a certificate delivery server 4 for delivering a certificate, and a kiosk terminal 5 having a printing function. The user device 3, the certificate delivery server 4, and the kiosk terminal 5 are connected to a network 6.
[0025] The personal number card 2 held by the applicant 7 is a card issued by an administrative agency to a national, and is an IC card that stores at least a personal number for identifying the national. In the case of Japan, the personal number card 2 is a my number card, which is an IC card compatible with contact type and non-contact type. In the present embodiment, since it is assumed that the my number card is used as the personal number card 2, a detailed description of the hardware of the personal number card 2 will be omitted.
[0026] As shown in FIG. 2, the personal number card 2 stores basic information 24 such as address, name, date of birth, gender, and personal number, and a face photo 23 of the owner as information related to the owner of the personal number card 2. Further, as information used for the identity verification process, the personal number card 2 stores an electronic certificate 21 of the owner. An electronic certificate password 20 is set for the electronic certificate 21 by the owner. The personal number card 2 is configured to be able to read at least the electronic certificate 21 only when the verification of the electronic certificate password 20 is successful. In the case of a my number card, a signature electronic certificate and a user authentication electronic certificate are stored in the my number card. In the conventional certificate automatic delivery service, the user authentication electronic certificate is used for identity verification.
[0027] The user device 3 owned by applicant 7 is a device realized by using a computer device. For example, a smartphone, a tablet computer, or a personal computer can be used as the user device 3. As shown in FIG. 2, the user device 3 owned by applicant 7 includes, as hardware, a network interface 31, an IC card reader 35, a display 33, an input device 34, and a memory 32. Further, the user device 3 owned by applicant 7 includes, as a function realized by using a computer program that operates a processor mounted on the user device 3, a certificate application unit 30 that executes processing related to an application for issuance of a certificate.
[0028] The network interface 31 included in the user device 3 is an interface for the user device 3 to connect to the network 6. The network interface 31 plays a role of transmitting and receiving data and processing communication protocols. The network interface 31 includes an Ethernet for wired connection to the network 6, a mobile communication interface for wireless connection to the network 6, a short-range wireless communication interface, and the like. The type of the network interface 31 used by the user device 3 is determined by the type of the user device 3. For example, when a smartphone is used as the user device 3, the user device 3 includes a mobile communication interface as the network interface 31. Further, when a personal computer is used as the user device 3, the user device 3 includes an Ethernet as the network interface 31.
[0029] The IC card reader 35 is a device for communicating with the personal identification number card 2. When a my number card is used for the personal identification number card 2, the IC card reader 35 becomes a contactless IC card reader. A general smartphone incorporates a contactless IC card reader corresponding to the my number card. When a personal computer that does not incorporate a contactless IC card reader corresponding to the my number card is used as the user device 3, an IC card reader corresponding to the my number card is connected to a port (for example, a USB port) of this user device 3.
[0030] The display 33 is a device for visually displaying information and images. As the display 33 mounted on the user device 3, a light-emitting display such as an OLED (Organic Light Emitting Diode) or a liquid crystal display can be used. The input device 34 is a device for inputting information and the like into the user device 3. For the input device 34, a mouse, a keyboard, a touch screen, and the like can be used. The type of the input device 34 included in the user device 3 differs depending on the type of the user device 3. When the user device 3 is a smartphone, the user device 3 includes a touch screen combined with the display 33 as the input device 34. When the user device 3 is a personal computer, a keyboard and a mouse are used as the input device 34.
[0031] The memory 32 included in the user device 3 includes a main storage device (RAM: Random Access Memory) for storing data used by the processor for processing, and an auxiliary storage device (hard disk or SSD (Solid State Drive)) for retaining data even when the power is turned off.
[0032] The certificate application unit 30 included in the user device 3 is a function for executing processing related to an application for issuance of a certificate. A computer program for operating the processor of the user device 3 is installed in the user device 3 as the certificate application unit 30. When a smartphone or a tablet computer is used as the user device 3, an application functioning as the certificate application unit 30 is installed in the user device 3.
[0033] The certificate application unit 30 provided in the user device 3, as processing related to the application for the issuance of a certificate, performs an identity verification process for verifying the electronic certificate password 20 set in the personal identification number card 2, and when the verification of the electronic certificate password 20 is successful, transmits the application information of the certificate applied for by the applicant 7 to the certificate issuance server 4, and executes a delivery application process for storing the reception number received from the certificate issuance server 4. In addition, when the certificate application unit 30 provided in the user device 3 receives a certificate printing confirmation request from the certificate issuance server 4, it executes a printing confirmation process for transmitting the printing confirmation response obtained from the applicant 7 to the certificate issuance server 4.
[0034] The kiosk terminal 5 is a terminal realized by a computer device having a printing function. The kiosk terminal 5 includes, in addition to a self-standing small information terminal, a multi-copy machine installed in a convenience store or the like. As hardware, the kiosk terminal 5 includes a network interface 51, a printer 55, a display 53, an input device 54, and a memory 52. Further, as a function realized by using a computer program that operates a processor mounted on the kiosk terminal 5, the kiosk terminal 5 includes a certificate printing unit 50 that executes processing related to the printing of a certificate.
[0035] Since the network interface 51 provided in the kiosk terminal 5 is the same as the network interface 31 provided in the user device 3, a detailed description of the network interface 51 provided in the kiosk terminal 5 is omitted here. Since the kiosk terminal 5 is a stationary terminal, the network interface 51 provided in the kiosk terminal 5 is generally an Ethernet for wired connection to the network 6.
[0036] The printer 55 is a device that outputs digital information onto paper. The printer 55 of the kiosk terminal 5 prints the certificate information received from the certificate issuance server 4 onto paper and outputs a paper medium certificate.
[0037] Since the display 53, input device 54, and memory 52 provided in the kiosk terminal 5 are the same as those provided in the user device 3, the detailed description of these devices provided in the kiosk terminal 5 is omitted here. The kiosk terminal 5 generally includes a touch screen combined with the display 53 as the input device 54.
[0038] The certificate printing unit 50 provided in the kiosk terminal 5 is a function that executes a process of printing certificate information on paper using the printer 55. When printing the certificate information on paper, the certificate printing unit 50 provided in the kiosk terminal 5 transmits the received number obtained from the applicant 7 to the certificate delivery server 4, and executes a process of outputting the certificate information transmitted from the certificate delivery server 4 from the printer 55.
[0039] The certificate delivery server 4 is a device realized by using a commercially available server. As hardware, the certificate delivery server 4 includes a network interface 41, a memory 42, and an application information DB 43 (DB: Data Base). Further, as a function realized by using a computer program that operates a processor implemented in the certificate delivery server 4, the certificate delivery server 4 includes a certificate delivery unit 40 that executes a process of delivering a certificate.
[0040] Since the network interface 41 provided in the certificate delivery server 4 is the same as the network interface 31 provided in the user device 3, the detailed description is omitted here. Since the certificate delivery server 4 is a stationary device, the network interface 41 provided in the certificate delivery server 4 is generally an Ethernet for wired connection to the network 6.
[0041] Since the memory 42 provided in the certificate delivery server 4 is the same as the memory 32 provided in the user device 3 and the like, the detailed description is omitted here. The certificate delivery server 4 includes an application information DB 43 that stores the application information transmitted from the user device 3 in association with the received number used for identifying the application information.
[0042] As described above, as a function realized by using a computer program that operates a processor implemented in the certificate delivery server 4, the certificate delivery server 4 includes a certificate delivery unit 40 that executes processes related to certificate delivery. When application information is transmitted from the user device 3, the certificate delivery unit 40 included in the certificate delivery server 4 generates a reception number for the application information transmitted from the user device 3, stores the application information in at least the application information DB 43 in association with the reception number, and then executes a reception process of transmitting the reception number to the user device 3. Further, when a reception number is transmitted from the kiosk terminal 5, the certificate delivery unit 40 included in the certificate delivery server 4 executes a delivery process of transmitting certificate information corresponding to the application information associated with the reception number to the kiosk terminal 5. In addition, in the delivery process, the certificate delivery unit 40 included in the certificate delivery server 4 transmits a print confirmation request to the user device 3 that transmitted the application information associated with the reception number transmitted from the kiosk terminal 5, and executes a process of transmitting the certificate information to the kiosk terminal 5 only when print permission is indicated by a print confirmation response received from the user device 3.
[0043] Hereinafter, the operation of the certificate automatic delivery system 1 according to the present embodiment will be described in more detail. FIG. 3 is a diagram for explaining the operation of the certificate automatic delivery system 1 when applying for a certificate delivery. FIG. 4 is a diagram for explaining the operation of the certificate automatic delivery system 1 when delivering a certificate. Note that the description with reference to FIGS. 3 and 4 also serves as an explanation of the certificate automatic delivery method that is the invention of the method according to the present application.
[0044] First, with reference to FIG. 3, the operation of the certificate automatic delivery system 1 when the applicant 7 applies for a certificate delivery will be described.
[0045] When the applicant 7 applies for a certificate delivery, the applicant 7 starts a computer program (application) that functions as the certificate application unit 30, and the certificate application unit 30 included in the user device 3 starts a process related to the certificate delivery application (step S1).
[0046] After the certificate application unit 30 activated on the user device 3 displays a screen on the display 33 notifying the user to set the personal number card 2 on the user device 3, it uses the IC card reader 35 to detect the personal number card 2 set on the user device 3 (step S2). When the user device 3 is a smartphone, the certificate application unit 30 detects the personal number card 2 set within the reading range of the IC card reader 35 installed in the smartphone.
[0047] When the certificate application unit 30 of the user device 3 detects the personal number card 2, it displays a password input screen on the display 33 and then uses the input device 34 to obtain the password entered by the applicant 7 (step S3). Note that before displaying the password input screen on the display 33, in the conventional certificate automatic delivery service, the applicant 7 is made to select the municipality that will issue the certificate.
[0048] Next, the certificate application unit 30 of the user device 3 sends the password obtained from the applicant 7 to the personal number card 2 and requests the personal number card 2 to verify the password entered by the applicant 7 (step S4). Specifically, the certificate application unit 30 of the user device 3 sends a command message for password verification to the personal number card 2. The personal number card 2 verifies the password sent from the user device 3 with the electronic certificate password 20 registered in the personal number card 2 (step S5) and sends a password verification result indicating whether the password sent from the user device 3 matches or does not match the electronic certificate password 20 registered in the personal number card 2 to the user device 3 (step S6).
[0049] If the password verification result sent from the personal number card 2 indicates a verification failure, the password verification will be retried or the subsequent processing will be aborted. Here, it is assumed that the password verification result sent from the personal number card 2 indicates a verification success.
[0050] When the password verification result transmitted from the personal identification number card 2 indicates successful verification, the certificate application unit 30 of the user device 3 requests the personal identification number card 2 to transmit the electronic certificate 21 (step S7). Specifically, the certificate application unit 30 of the user device 3 transmits a command message for reading the electronic certificate 21 to the personal identification number card 2. Here, since the verification of the electronic certificate password 20 has been successful, the personal identification number card 2 transmits the electronic certificate 21 stored in the personal identification number card 2 to the user device 3 (step S8). At this time, in addition to the electronic certificate 21, the certificate application unit 30 of the user device 3 can read the basic information 24 stored in the personal identification number card 2.
[0051] The certificate application unit 30 of the user device 3 authenticates the applicant 7 using the electronic certificate 21 read from the personal identification number card 2 (step S9). In the present embodiment, the electronic certificate 21 stored in the personal identification number card 2 includes the public key of the owner who holds the personal identification number card 2, and the personal identification number card 2 stores the secret key paired with this public key. The procedure for authenticating the applicant 7 using the electronic certificate 21 read from the personal identification number card 2 is as follows. 1) When reading the electronic certificate 21 from the personal identification number card 2, the user device 3 generates a random number and sends this random number to the personal identification number card 2. 2) The personal identification number card 2 encrypts the random number received from the user device 3 with the secret key, and transmits the encrypted text of the random number and the electronic certificate 21 to the user device 3. 3) The user device 3 decrypts the encrypted text received from the personal identification number card 2 with the public key of the electronic certificate 21, and compares the content obtained by decrypting the encrypted text with the random number generated in 1). If the content obtained by decrypting the encrypted text and the random number generated in 1) match, the user device 3 determines that the electronic certificate 21 has not been forged. 4) When it is determined that the electronic certificate 21 has not been forged, the user device 3 accesses the certification authority that issued the electronic certificate 21 read from the personal identification number card 2 to confirm the validity of the electronic certificate 21. In the case of the My Number Card, the certification authority that issued the electronic certificate 21 is the Local Public Entity Information System Agency (abbreviation: J-LIS). 5) If the electronic certificate 21 is valid, the user device 3 determines that the authentication of the applicant 7 using the electronic certificate 21 read from the personal identification number card 2 has been successful.
[0052] If the authentication of the applicant 7 using the electronic certificate 21 read from the personal identification number card 2 fails, the user device 3 aborts the subsequent processing. Here, it is assumed that the authentication of the applicant 7 using the electronic certificate 21 read from the personal identification number card 2 has been successful.
[0053] If the verification of the electronic certificate password 20 set in the personal identification number card 2 is successful and the authentication of the applicant 7 using the electronic certificate 21 read from the personal identification number card 2 is successful, the certificate application unit 30 of the user device 3 executes a process of generating application information for the certificate that the applicant 7 applies for (step S10). When generating the application information, the certificate application unit 30 of the user device 3 allows the applicant 7 to select the type of certificate (such as a copy of a family register), the type of delivery (for the applicant only, for all family members, etc.), the items to be described (such as the description of the head of the household and the relationship), and the number of copies. If personal information such as the address of the applicant 7 is required for the certificate applied for, the certificate application unit 30 of the user device 3 uses the basic information 24 read from the personal identification number card 2 for generating the application information.
[0054] Next, the certificate application unit 30 of the user device 3 acquires the contact information of the applicant 7 (step S11). The contact information of the applicant 7 is information that enables communication with the applicant 7 using the user device 3, such as the email address of the applicant 7 or the phone number of the user device 3. The contact information of the applicant 7 can be registered in advance in the certificate application unit 30 of the user device 3, or the applicant 7 may be allowed to input the contact information of the applicant 7.
[0055] Next, the certificate application section 30 of the user device 3 transmits the application information and the contact information of the applicant 7 to the certificate issuing server 4 (step S12). The certificate issuing section 40 of the certificate issuing server 4 generates a reception number corresponding to the application information transmitted from the user device 3 (step S13). Next, the certificate issuing section 40 of the certificate issuing server 4 stores the application information transmitted from the user device 3 and the contact information of the applicant 7 in the application information DB 43 in association with the reception number (step S14). Next, the certificate issuing section 40 of the certificate issuing server 4 transmits the reception number corresponding to the application information transmitted from the user device 3 to the user device 3 that transmitted the application information (step S15). The certificate application section 30 of the user device 3 saves the reception number transmitted by the certificate issuing server 4 in the memory 32 (step S16), and the procedure of FIG. 3 ends.
[0056] Steps S2 to S9 in FIG. 3 are the description of the identity verification process executed by the user device 3. Also, steps S10 to S12 in FIG. 3 and step S16 in FIG. 3 are the description of the delivery application process executed by the user device 3. Also, steps S13 to S15 in FIG. 3 are the description of the reception process executed by the certificate issuing server 4.
[0057] Next, with reference to FIG. 4, the operation of the certificate automatic delivery system 1 when printing a certificate will be described.
[0058] When the applicant 7 uses the input device 54 of the kiosk terminal 5 to select a menu related to the delivery of a certificate from the menus displayed on the display 53 of the kiosk terminal 5, the certificate printing section 50 of the kiosk terminal 5 is activated, and the certificate printing section 50 of the kiosk terminal 5 executes the procedure related to the printing of the certificate (step S20).
[0059] First, the certificate printing unit 50 of the kiosk terminal 5 acquires a reception number from the applicant 7 who operates the kiosk terminal 5 (step S21). The method of acquiring the reception number from the applicant 7 is arbitrary. The applicant 7 may be made to input the reception number into the kiosk terminal 5. Also, in the case of a kiosk terminal 5 equipped with a barcode reader, the certificate application unit 30 of the user device 3 is provided with a function of displaying a barcode encoded with the reception number on the display 33, and the barcode displayed on the display 33 of the user device 3 may be read by the barcode reader of the kiosk terminal 5.
[0060] Upon acquiring the reception number, the certificate printing unit 50 of the kiosk terminal 5 transmits the reception number acquired from the applicant 7 to the certificate delivery server 4 and requests the certificate delivery server 4 to transmit certificate information corresponding to the reception number (step S22). The certificate delivery unit 40 of the certificate delivery server 4 acquires the certificate information corresponding to the reception number transmitted from the kiosk terminal 5 (step S23). The certificate delivery unit 40 of the certificate delivery server 4 requests the generation of a certificate from a system operated by an administrative agency (for example, a certificate delivery center) and acquires the certificate information from this system. The certificate information to be transmitted to the kiosk terminal 5 is information in a predetermined printing format (for example, PDF). In the case of a kiosk terminal 5 installed in a convenience store or the like, information for preventing forgery and alteration is added to the certificate information to be transmitted to the kiosk terminal 5.
[0061] When the certificate delivery unit 40 of the certificate delivery server 4 acquires the certificate information to be transmitted to the kiosk terminal 5, it refers to the application information DB43, identifies the contact information of the applicant 7 corresponding to the reception number transmitted from the kiosk terminal 5, and then transmits a printing confirmation request to this contact information (step S24). The printing confirmation request transmitted to the user device 3 is a message that causes the display 33 of the user device 3 to display a screen for the applicant 7 to select printable or non-printable. When a web page is used for the screen for selecting printable or non-printable, the printing confirmation request includes the address of this web page.
[0062] When the certificate application section 30 of the user device 3 receives a print confirmation request from the certificate issuing server 4, it displays on the display 33 of the user device 3 a screen for selecting printable or non-printable, and obtains a selection result of printable or non-printable from the applicant 7 (step S25). The certificate application section 30 of the user device 3 transmits a print confirmation response indicating the selection result of printable or non-printable to the certificate issuing server 4 (step S26).
[0063] When the certificate issuing section 40 of the certificate issuing server 4 is indicated as non-printable in the print confirmation response transmitted from the user device 3, the subsequent processing will be aborted. Here, it is assumed that printable is indicated in the print confirmation response transmitted from the user device 3. In this case, the certificate issuing section 40 of the certificate issuing server 4 transmits the certificate information corresponding to the reception number transmitted from the kiosk terminal 5 to the kiosk terminal 5 (step S27). The certificate printing section 50 of the kiosk terminal 5 uses the printer 55 to print the certificate information transmitted by the certificate issuing server 4 (step S28). When the printing of the certificate information is completed, the certificate issuing server 4 is notified of the completion of the output of the certificate information (step S29). Note that the kiosk terminal 5 deletes the output-completed certificate information from the memory 52.
[0064] The certificate issuing section 40 of the certificate issuing server 4 deletes the certificate information transmitted to the kiosk terminal 5 from the certificate issuing server 4 (step S30) so that the certificate information transmitted to the kiosk terminal 5 is not reused, and the procedure of FIG. 4 ends.
[0065] Steps S23 to S27 in FIG. 4 and S30 in FIG. 4 are explanations of the delivery process executed by the certificate issuing server 4. Also, steps S20 to S22 in FIG. 4 and steps S28 to S29 in FIG. 4 are explanations of the printing process executed by the kiosk terminal 5.
Explanation of Signs
[0066] 1 Certificate Automatic Issuing System 2 Personal Number Card 20 Electronic Certificate Password 21 Electronic certificate 3 User device 30 Certificate application section 4 Certificate issuing server 40 Certificate issuing section 43 Application information database 5 Kiosk terminal 50 Certificate printing section
Claims
1. It includes a personal number card issued to the applicant, a user device having a function of communicating with the personal number card, and a certificate issuing server for issuing a certificate. The personal number card stores an electronic certificate with a password set. The user device performs an identity verification process for verifying the password set in the electronic certificate, and after performing a process of generating application information for the certificate when the password verification is successful, transmits the application information to the certificate issuing server, and includes a certificate application unit that executes a delivery application process of storing the acceptance number of the application information received from the certificate issuing server. When the application information is transmitted from the user device, the certificate issuing server of the certificate issuing server generates an acceptance number for the application information, stores at least the application information in association with the acceptance number, and then includes a certificate delivery unit that executes an acceptance process of transmitting the acceptance number to the user device. A certificate automatic delivery system characterized by the above.
2. It includes a kiosk terminal having a printing function. When the acceptance number is transmitted from the kiosk terminal, the certificate delivery unit of the certificate issuing server executes a delivery process of transmitting certificate information corresponding to the application information associated with this acceptance number to the kiosk terminal. The kiosk terminal includes a certificate printing unit that acquires the acceptance number from the applicant, transmits the acceptance number to the certificate issuing server, and executes a printing process of printing the certificate information transmitted from the certificate issuing server. The certificate automatic delivery system according to claim 1, characterized by the above.
3. In the delivery process, the certificate delivery unit of the certificate issuing server transmits a printing confirmation request to the user device that transmitted the application information corresponding to the acceptance number received from the kiosk terminal, and only when the printing confirmation response received from the user device indicates printability, transmits the certificate information to the kiosk terminal. The certificate automatic delivery system according to claim 2, characterized by the above.
4. In the identity verification process, when the password verification is successful, the certificate application unit of the user device executes a process of authenticating the applicant using the electronic certificate read from the personal number card, and only when the password verification is successful and the authentication of the applicant using the electronic certificate is successful, transmits the application information to the certificate issuing server. The certificate automatic delivery system according to any one of claims 1 to 3, characterized in that.
5. Step a in which a user device operated by an applicant who applies for the delivery of a certificate collates a password set in an electronic certificate stored in a personal identification number card; Step b in which, when the password collation is successful, the user device generates application information for applying for the delivery of a certificate, and then transmits the application information to a certificate delivery server that delivers the certificate after performing a process of generating the application information; Step c in which, when the application information is transmitted from the user device, the certificate delivery server generates a reception number of the application information, stores at least the application information in association with the reception number, and then transmits the reception number to the user device; Step d in which the user device stores the reception number received from the certificate delivery server; A certificate automatic delivery method, characterized by including.
6. Step e in which a kiosk terminal having a print function acquires a reception number from an applicant and transmits the reception number to the certificate delivery server; Step f in which, when the reception number is transmitted from the kiosk terminal, the certificate delivery server transmits certificate information corresponding to the application information associated with the reception number to the kiosk terminal; Step g in which the kiosk terminal prints the certificate information transmitted from the certificate delivery server; The certificate automatic delivery method according to claim 5, characterized by including.
7. In step f, the certificate delivery server transmits a print confirmation request to the user device that transmitted the application information associated with the reception number received from the kiosk terminal, and only when print permission is indicated by a print confirmation response received from the user device, transmits the certificate information to the kiosk terminal. The certificate automatic delivery method according to claim 6, characterized in that.
8. The personal identification number card stores an electronic certificate of an applicant who holds the personal identification number card. In step a, when the password collation is successful, the user device executes a process of authenticating the applicant using the electronic certificate read from the personal identification number card, and only when the password collation is successful and the authentication of the applicant using the electronic certificate is successful, executes step b. The certificate automatic delivery method according to any one of claims 5 to 7, characterized in that.
Citation Information
Patent Citations
Official document issuing system
JP2005309888A