Information processing system and information processing method
The system converts electronic certificate serial numbers into authentication IDs using a one-way function, addressing the challenge of handling restricted card data to efficiently determine benefit recipients and prevent duplicate payments.
Patent Information
- Application Number
- JP2024007164
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-22
- Publication Date
- 2025-08-01
AI Technical Summary
Existing technologies face challenges in handling restricted information on personal identification cards, such as electronic certificate serial numbers, for targeted measures by public institutions, particularly in determining eligible individuals for benefits like cashless payments and subsidies.
An information processing system and method that converts serial numbers of electronic certificates into authentication IDs using a one-way function, allowing secure transmission and management of these IDs across systems to determine eligibility for benefits, while maintaining confidentiality and preventing duplicate payments.
Enables efficient and secure determination of benefit recipients by converting serial numbers into authentication IDs, ensuring accurate measure targeting and preventing multiple payments, while adhering to handling restrictions and maintaining identity integrity.
Smart Images

Figure 2025112739000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to data processing technologies, and particularly to information processing systems and information processing methods.
Background Art
[0002] In recent years, in various industries and business types, measures for promoting the sales of products and services have been implemented (see, for example, Patent Document 1). In addition, in each of the national and local governments, measures for providing benefits for the purpose of popularizing personal identification cards (also called "My Number Cards") and expanding the use of cashless payments have been implemented.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the measures implemented by public institutions for the target persons, the use of the information recorded on the personal identification cards held by individuals is assumed for the discrimination of the target persons and the like. On the other hand, among the information recorded on the personal identification cards, there are those whose handling is restricted, such as the serial numbers of electronic certificates for user authentication. One object of the present disclosure is to provide a technology for supporting measures applied using personal identification cards.
Means for Solving the Problems
[0005] To solve the above problems, an information processing system according to an aspect of the present disclosure includes a first acquisition unit that acquires a first serial number, which is the serial number of an electronic certificate for user authentication of an individual targeted by a public institution's measure, transmitted from the public institution's system; a conversion unit that acquires a first authentication ID obtained by converting the first serial number using a predetermined algorithm; a first transmission unit that transmits the first authentication ID of an individual targeted by a measure to be registered in a ledger system that manages the application status of the measure to the public institution's system; and a second acquisition unit that acquires a second serial number, which is the serial number of an electronic certificate for user authentication read from the personal number card of an individual applying for the measure. The conversion unit further acquires a second authentication ID obtained by converting the second serial number using the algorithm, and further includes a second transmission unit that transmits the second authentication ID of an individual applying for the measure to the ledger system.
[0006] Another aspect of the present disclosure is an information processing method. This method includes steps of: a computer acquiring a first serial number, which is the serial number of an electronic certificate for user authentication of an individual targeted by a public institution's measure, transmitted from the public institution's system; acquiring a first authentication ID obtained by converting the first serial number using a predetermined algorithm; transmitting the first authentication ID of an individual targeted by a measure to be registered in a ledger system that manages the application status of the measure to the public institution's system; acquiring a second serial number, which is the serial number of an electronic certificate for user authentication read from the personal number card of an individual applying for the measure; acquiring a second authentication ID obtained by converting the second serial number using the algorithm; and transmitting the second authentication ID of an individual applying for the measure to the ledger system.
[0007] Note that any combination of the above components, and those obtained by converting the expressions of the present disclosure among an apparatus, a computer program, a recording medium storing the computer program, etc. are also effective as aspects of the present disclosure.
Advantages of the Invention
[0008] According to the technology of the present disclosure, it is possible to support measures applied using a personal number card.
Brief Description of Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0010] Hereinafter, the present disclosure will be described with reference to the drawings based on preferred embodiments. The embodiments are illustrative rather than limiting the present disclosure, and not all features or combinations thereof described in the embodiments are necessarily essential to the present disclosure. Also, when terms such as "first" and "second" are used in this specification or claims, unless otherwise specified, these terms do not represent any order or importance, but are for distinguishing one configuration from another.
[0011] Among the measures taken by local governments, there are those that determine the persons to whom benefits should be provided by the measures (hereinafter also referred to as "target persons of the measures") by obtaining the serial numbers of the electronic certificates for individual user identification used by the local government from the resident registration system or the like and registering them in a management ledger (in the embodiment, a ledger server). On the other hand, the businesses that can handle the serial numbers of the electronic certificates for individual user identification are restricted by regulations. Therefore, in the electronic application system of the embodiment, the serial numbers of the electronic certificates for individual user identification are converted into different IDs (hereinafter also referred to as "authentication IDs"), and the authentication IDs are used for determining the target persons of the measures.
[0012] The measures implemented by the local government may include child-rearing support measures and single-parent family support measures. The residents, etc. of the local government apply for the measures using their personal number cards. The benefits provided to specific target persons in the measures may include various value exchange media. In the embodiment, the local government implements a benefit payment business that provides a benefit payment as a benefit to specific individuals who meet predetermined conditions. The benefit payment as a benefit may include at least one of cash currency, points, coupons, gift certificates, and regional revitalization vouchers. For example, the points can be exchanged for payment means such as electronic money and used for shopping, etc.
[0013] FIG. 1 shows the configuration of the electronic application system 10 of the embodiment. The electronic application system 10 is an information processing system that supports the benefit payment business of a public agency (in the embodiment, a local government). In other words, the electronic application system 10 is a computer system that supports the measures of the local government to provide benefit payments to specific individuals. The electronic application system 10 includes a user terminal 12, a local government system 16, a portal server 18, a gateway server 20, and a ledger server 22. Each device constituting the electronic application system 10 is connected via a communication network 24 including a LAN, WAN, and the Internet.
[0014] The user terminal 12 is an information terminal operated by an individual who has a personal number card and applies for the measures (benefit payment) (hereinafter also referred to as "user"). The user can be said to be an individual, a national, or a resident who can be the target of benefit payment in the local government's benefit payment business. The user terminal 12 may be a PC equipped with an IC card reader, a smartphone, or a tablet terminal.
[0015] Although Figure 1 depicts one user terminal 12, in reality, there are multiple user terminals 12. At least some of the user terminals 12 have an application provided by a payment operator and an application (hereinafter also referred to as "Payment App 14") that supports cashless payment, in other words, electronic payment, installed. The Payment App 14 incorporates an SDK (Software Development Kit) that provides functions to support communication and authentication with the gateway server 20, etc.
[0016] The local government system 16 is an information processing system of a local government that conducts benefit payment operations. The local government system 16 includes an information terminal operated by the person in charge of the local government. The portal server 18 is an information processing device that provides a website (hereinafter also referred to as "My Portal") as an online window for administrative procedures.
[0017] The ledger server 22 is an information processing device having a database function for managing the application status of users for the measures of the local government's benefit payment operations and the benefit payment status for the target persons. The gateway server 20 is an information processing device that provides a gateway function to the ledger server 22. For example, the gateway server 20 provides functions such as an ID management function, a measure inquiry function, and a measure application function for users. The ID management function can also be said to be an account management function.
[0018] Each of the portal server 18, the gateway server 20, and the ledger server 22 may be composed of a single computer or a combination of multiple computers. Note that the "information processing system" referred to in the claims may refer to the entire electronic application system 10 or the gateway server 20 alone.
[0019] FIG. 2 is a block diagram showing the functional blocks of the gateway server 20 in FIG. 1. Each block shown in the block diagrams in this specification can be implemented, in terms of hardware, by elements and electronic circuits such as a computer's processor, CPU, memory, and mechanical devices, and can be implemented, in terms of software, by a computer program or the like. Here, however, functional blocks realized by their cooperation are depicted. Therefore, it is understood by those skilled in the art that these functional blocks can be realized in various forms by a combination of hardware and software.
[0020] The gateway server 20 includes a processing unit 30, a storage unit 32, and a communication unit 34. The processing unit 30 executes various information processes. The processing unit 30 may be realized by a processor (such as a CPU) of a computer that constitutes the gateway server 20. The storage unit 32 stores data that is referred to or updated by the processing unit 30. The storage unit 32 may be realized by a storage or memory of a computer that constitutes the gateway server 20. The communication unit 34 communicates with an external device according to a predetermined communication protocol. The processing unit 30 transmits and receives data to and from the user terminal 12, the local government system 16, the portal server 18, and the ledger server 22 via the communication unit 34.
[0021] The storage unit 32 includes an ID storage unit 36. The ID storage unit 36 stores the user's ID. FIG. 3 shows the relationship between multiple types of IDs in the embodiment. The serial number is the serial number of the electronic certificate for user authentication stored in the user's personal number card. Hereinafter, when simply referred to as the serial number, it refers to the serial number of the electronic certificate for user authentication. When a user's personal number card is reissued or the like, the serial number of the user may be changed. That is, there may be multiple serial numbers as the serial number of one user. In the public personal authentication system (not shown in FIG. 1), the old and new serial numbers are managed in association with each other.
[0022] The gateway ID is a unique ID for each user. The gateway ID is different from the user's personal number and is the personal ID for policy application. For example, the gateway ID is used for benefit application and management of application status. The gateway ID is an exclusive ID assigned to only one user, and even if multiple serial numbers are issued for the user, the gateway ID remains one. That is, the relationship between the gateway ID and the serial number is one-to-N.
[0023] The authentication ID is a value obtained by converting the serial number using a predetermined algorithm. This algorithm is a predetermined one-way function in the embodiment, for example, a hash function. A one-way function is a function that is easy to calculate the function value but very difficult to calculate the inverse function. The relationship between the authentication ID and the serial number is one-to-one. When multiple serial numbers are issued for one user, an authentication ID corresponding to each of the multiple serial numbers is generated.
[0024] In the embodiment, the ID storage unit 36 stores, for each user, one gateway ID and one or more serial numbers in association with each other. On the other hand, the authentication ID is dynamically generated from the serial number each time it is required. As a modification, the storage unit 32 may further store one or more authentication IDs corresponding to one or more serial numbers. The ID storage unit 36 continues to manage the gateway ID associated with the serial number read from the user's personal number card even when the user terminates the use of the ID management service of the gateway server 20.
[0025] Returning to FIG. 2, the processing unit 30 includes an enrollment reception unit 40, a withdrawal reception unit 42, a first serial number acquisition unit 44, a conversion unit 46, a first ID transmission unit 48, a second serial number acquisition unit 50, a second ID transmission unit 52, a policy information transmission unit 54, a policy application unit 56, a history acquisition unit 58, and a gateway ID issuing unit 60.
[0026] The functions of the plurality of functional blocks included in the processing unit 30 may be implemented in a computer program. This computer program may be stored in a recording medium and may be installed in the storage of the gateway server 20 via the recording medium. Further, this computer program may be downloaded via a communication network and installed in the storage of the gateway server 20. The processor of the gateway server 20 may exhibit the functions of the plurality of functional blocks by reading this computer program into the main memory and executing it.
[0027] The membership reception unit 40 receives an application for using the ID management service provided by the gateway server 20 (which can also be said to be an application for membership) transmitted from the user terminal 12. The withdrawal reception unit 42 receives an application for terminating the use of the ID management service provided by the gateway server 20 (which can also be said to be an application for withdrawal) transmitted from the user terminal 12.
[0028] The first serial number acquisition unit 44, as the first acquisition unit, acquires the serial number of the electronic certificate for user authentication of an individual targeted by the policy (hereinafter also referred to as the "first serial number") transmitted from the local government system 16. The individual targeted by the policy can also be said to be an individual targeted for benefit payment. The conversion unit 46 acquires an authentication ID (hereinafter also referred to as the "first authentication ID") obtained by converting the first serial number using a predetermined algorithm (a predetermined one-way function in the embodiment). The first ID transmission unit 48, as the first transmission unit, transmits the first authentication ID of the individual targeted by the policy to be registered in the ledger system to the local government system 16.
[0029] The second serial number acquisition unit 50, as the second acquisition unit, acquires the serial number of the electronic certificate for user authentication (hereinafter also referred to as the "second serial number") read from the personal number card of the user applying for the measure. The user applying for the measure can also be said to be the user who intends to receive the benefit payment. The conversion unit 46 uses the same algorithm (a predetermined one-way function in the embodiment) as when converting the first serial number to obtain an authentication ID (hereinafter also referred to as the "second authentication ID") obtained by converting the second serial number. The first authentication ID and the second authentication ID are generated by the same one-way function. Therefore, if the original serial numbers are the same, the first authentication ID and the second authentication ID will have the same value.
[0030] The second ID transmission unit 52, as the second transmission unit, transmits the second authentication ID of the user applying for the measure to the ledger server 22. The second ID transmission unit 52 of the embodiment functions as a measure inquiry unit. Specifically, the second ID transmission unit 52 transmits a measure inquiry including the second authentication ID of the user applying for the measure to the ledger server 22. The second ID transmission unit 52 receives the information of the measure associated with the second authentication ID in the ledger server 22, that is, the information of the measure targeted at the user who entered the second serial number, transmitted from the ledger server 22 in response to the measure inquiry. The measures targeted at the user who entered the second serial number include, for example, measures for which the user can receive benefit payments.
[0031] The conversion unit 46 further obtains an authentication ID (hereinafter also referred to as the "third authentication ID") obtained by converting the past serial number associated with the second serial number in a public personal authentication system (not shown) using the same algorithm as when converting the first serial number. When there is a past serial number associated with the second serial number (i.e., the current serial number), the second ID transmission unit 52 transmits both the second authentication ID and the third authentication ID to the ledger server 22. The second ID transmission unit 52 obtains, from the ledger server 22, the information of the measure associated with the second authentication ID or the third authentication ID in the ledger server 22 as the information of the measure targeted at the user who entered the second serial number.
[0032] The measure information transmission unit 54 transmits information on measures targeted at the user who input the second serial number acquired by the second ID transmission unit 52 to the user terminal 12 of the user. The measure application unit 56 receives application information for a specific measure transmitted from the user terminal 12 of the user and transmits the application information to the ledger server 22.
[0033] When the membership reception unit 40 receives an application for using the ID management service from the user terminal 12 of a certain user, the history acquisition unit 58, as the third acquisition unit, acquires from a public personal authentication system (not shown) the serial numbers of past electronic certificates for user authentication read from the personal number card of the user (hereinafter also referred to as "current serial numbers"). The user here is also referred to as an "application applicant" below.
[0034] When the gateway ID issuing unit 60 refers to the ID storage unit 36 and there is no gateway ID assigned to either the current serial number or the past serial numbers of the application applicant, the gateway ID issuing unit 60 issues a new single gateway ID to the application applicant and stores it in the ID storage unit 36. The ID storage unit 36 stores the current serial number and the past serial numbers as the ID information of the application applicant, and further stores a new single gateway ID in association with those serial numbers. When a certain user applies for a specific measure, the measure application unit 56 transmits application information including the gateway ID of the user to the ledger server 22.
[0035] The ledger server 22 stores the gateway IDs of the individuals who have applied for each measure, or in other words, stores the gateway IDs of the individuals who have received the benefits. The ledger server 22 uses the gateway IDs to identify the individuals who have applied for the measures, or in other words, to identify the individuals who have received the benefits. The ledger server 22 determines whether a user who is an applicant has applied for the measure (or in other words, whether the user has received the benefits) using the gateway ID included in the application information for the measure. The ledger server 22 executes the benefit payment process for the user on the condition that the user has not applied for the measure (or in other words, that the user has not received the benefits).
[0036] Even when the ID storage unit 36 receives an application to terminate the use of the ID management service from a certain user's user terminal 12, it continues to manage the gateway ID associated with the serial number read from the personal number card of the user. In other words, even when a certain user withdraws from the service, the ID storage unit 36 continues to store the user's gateway ID without deleting it.
[0037] Figure 4 is a flowchart showing the operation of the gateway server 20. Hereinafter, the operation of the electronic application system 10 will be described with reference to Figure 4. The user in the following description is an individual who operates a specific user terminal 12.
[0038] The user terminal 12 accesses the portal server 18 in response to the user's operation and displays the web page of the my portal provided by the portal server 18 on the display. The user applies for the use of the ID management service provided by the gateway server 20 from the web page of the my portal. The user terminal 12 transmits the data of the application for the use of the ID management service to the gateway server 20 in response to the user's operation.
[0039] Alternatively, the user launches the payment App on the user terminal 12 and applies for using the ID management service provided by the gateway server 20 from the screen of the payment App. The user terminal 12 transmits data for applying for using the ID management service to the gateway server 20 according to the user's operation. The data for applying for using the ID management service includes the serial number of the electronic certificate for user authentication read by the IC card reader from the user's personal identification card (hereinafter also referred to as "current serial number").
[0040] The membership reception unit 40 of the gateway server 20 receives the application for using the ID management service transmitted from the user terminal 12 (Y in S10). The history acquisition unit 58 of the gateway server 20 acquires the serial number of the electronic certificate for user authentication recorded on the personal identification card issued to the user in the past (hereinafter also referred to as "past serial number") associated with the current serial number of the user included in the application for using the ID management service from a public personal authentication system (not shown) (S12). In S12, the history acquisition unit 58 can acquire one or more past serial numbers associated with the current serial number.
[0041] The gateway ID issuing unit 60 of the gateway server 20 determines whether there is a gateway ID associated with the current serial number and at least one of the one or more past serial numbers among the plurality of gateway IDs stored in the ID storage unit 36. In other words, the gateway ID issuing unit 60 detects if a gateway ID has already been assigned to the user who has applied for using the ID management service.
[0042] If a gateway ID is not associated with either the current serial number or one or more past serial numbers (Y in S14), the gateway ID issuing unit 60 issues a unique gateway ID to the user (S16). The gateway ID issuing unit 60 associates the gateway ID issued to the user in S16 with the user's current serial number and stores it in the ID storage unit 36 (S18). If a gateway ID is associated with the current serial number and at least one of the one or more past serial numbers (N in S14), the processes of S16 and S18 are skipped.
[0043] In the embodiment, if a gateway ID is associated with a past serial number in the ID storage unit 36 but a gateway ID is not associated with the current serial number, the gateway ID issuing unit 60 associates the current serial number with the existing gateway ID and stores it in the ID storage unit 36. On the other hand, if a gateway ID is associated with the current serial number in the ID storage unit 36, the gateway ID issuing unit 60 does nothing.
[0044] If the application for use of the ID management service sent from the user terminal 12 is not accepted (N in S10), the processes of S12 to S18 are skipped.
[0045] The person in charge of the local government's subsidy program obtains the serial number of the individual to whom the subsidy is to be paid from the resident registration system. In response to the person in charge's operation, the local government system 16 transmits the serial number of the individual to whom the subsidy is to be paid to the portal server 18. The first serial acquisition unit 44 of the gateway server 20 obtains the serial number of the individual to whom the subsidy is to be paid (hereinafter also referred to as the "subject serial number") transmitted from the local government system 16 (Y of S20).
[0046] The conversion unit 46 of the gateway server 20 generates a converted value of the target serial number (hereinafter also referred to as "target authentication ID") using a predetermined one-way function (S22). For example, the conversion unit 46 inputs the target serial number into a predetermined one-way function and obtains the converted value output from the one-way function as the target authentication ID. The first ID transmission unit 48 of the gateway server 20 transmits the target authentication ID to the local government system 16 as the ID of the individual who is the recipient of the benefit to be registered in the ledger server 22 (S24). If the target serial number transmitted from the local government system 16 is not received (N in S20), the processes of S22 and S24 are skipped.
[0047] In practice, the local government system 16 transmits a plurality of target serial numbers to the gateway server 20. The gateway server 20 generates target authentication IDs obtained by converting each of the plurality of target serial numbers. The gateway server 20 transmits a plurality of target authentication IDs corresponding to the plurality of target serial numbers to the local government system 16. The person in charge of the local government registers a plurality of target authentication IDs regarding a plurality of target persons in the ledger server 22 for each measure. The ledger server 22 stores a plurality of target authentication IDs regarding a plurality of target persons for each of the plurality of measures in the benefit project of the local government.
[0048] FIG. 5 is also a flowchart showing the operation of the gateway server 20. This figure shows the operation of the gateway server 20 following the operation shown in FIG. 4.
[0049] The user inputs an operation to search for the measures of the subsidy program of the local government to which the user belongs on the web page of the My Portal. The user terminal 12 transmits the data of the measure inquiry to the gateway server 20 according to the user's operation. Alternatively, the user inputs an operation to search for the measures of the subsidy program of the local government to which the user belongs on the screen of the payment App. The user terminal 12 transmits the data of the measure inquiry to the gateway server 20 according to the user's operation. The data of the measure inquiry includes the serial number (current serial number) of the electronic certificate for user authentication read by the IC card reader from the user's personal number card.
[0050] The second serial number acquisition unit 50 of the gateway server 20 receives the data of the measure inquiry transmitted from the user terminal 12 (Y in S26). The second serial number acquisition unit 50 acquires the current serial number of the user included in the data of the measure inquiry. The history acquisition unit 58 of the gateway server 20 acquires one or more past serial numbers associated with the current serial number of the user from a public personal authentication system (not shown) (S28).
[0051] The conversion unit 46 of the gateway server 20 uses the same one-way function as in S22 to acquire the value obtained by converting the current serial number of the user as the application authentication ID. Also, when one or more past serial numbers are acquired, the conversion unit 46 further acquires the values obtained by converting each of the one or more past serial numbers as the application authentication ID. That is, the conversion unit 46 acquires one or more application authentication IDs related to the user based on the current and past serial numbers related to the user (S30). The second ID transmission unit 52 of the gateway server 20 transmits the data of the measure inquiry specifying one or more application authentication IDs related to the user to the ledger server 22 (S32).
[0052] The ledger server 22 identifies a measure that targets the user as a benefit recipient (hereinafter also referred to as the "applicable measure") by comparing the target authentication ID of each measure registered in advance with one or more application authentication IDs included in the data of the measure inquiry. Specifically, the ledger server 22 identifies, as the applicable measure, a measure that targets at least one of the one or more application authentication IDs included in the data of the measure inquiry from among a plurality of measures registered in advance. The ledger server 22 transmits information regarding the applicable measure to the gateway server 20. The information regarding the applicable measure may include details indicating the conditions and procedures for the payment of benefits.
[0053] The second ID transmission unit 52 of the gateway server 20 receives the information regarding the applicable measure transmitted from the ledger server 22. The measure information transmission unit 54 of the gateway server 20 transmits the information regarding the applicable measure to the user terminal 12 (S34). The user terminal 12 displays the information regarding the applicable measure on the display as the result of the inquiry of the measure targeted at the user. If the data of the measure inquiry transmitted from the user terminal 12 is not received (N in S26), the processes of S28 to S34 are skipped.
[0054] The user selects, from the measures targeted at the user displayed on the display, the measure for which the user applies for the payment of benefits. The user terminal 12 transmits data of the measure application (which can also be said to be data of the benefit application) specifying the measure selected by the user (hereinafter also referred to as the "target measure") to the gateway server 20.
[0055] The gateway server 20 receives the data of the measure application transmitted from the user terminal 12 (Y in S36). The measure application unit 56 of the gateway server 20 transmits the data of the measure application including the information of the target measure, one or more application authentication IDs regarding the user, and the gateway ID of the user associated with those application authentication IDs to the ledger server 22 (S38). If the data of the measure application transmitted from the user terminal 12 is not received (N in S36), the process of S38 is skipped.
[0056] When the gateway ID specified in the policy application is included in the gateway IDs for which the target policy has been applied, the ledger server 22 sends information (which can also be called error information) indicating that the user has already applied for the target policy to the gateway server 20. On the other hand, if the gateway ID specified in the policy application is not included in the gateway IDs for which the target policy has been applied, the ledger server 22 executes a predetermined process for providing the target policy to the user. At the same time, the ledger server 22 saves the gateway ID specified in the policy application as a gateway ID for which the target policy has been applied.
[0057] Note that the gateway server 20 may further include a settlement account information storage unit and a settlement account information update unit (not shown). The settlement account information may include the user's account in the settlement service used by the user. The settlement service may include at least one of credit card settlement, electronic money settlement, debit card settlement, and QR code settlement (where "QR code" is a registered trademark).
[0058] The settlement account information update unit may store the user's settlement account information transmitted from the user terminal 12 in the settlement account information storage unit in association with the user's gateway ID. The policy application unit 56 may send data for the policy application including the user's settlement account information stored in the settlement account information storage unit to the ledger server 22. The ledger server 22 may execute a process of paying the benefit to the user's account in the settlement service used by the user specified in the policy application. By registering their own settlement account information in the gateway server 20 in advance, the user does not need to input the settlement account information each time they apply for a policy.
[0059] Return to the description of FIG. 5. The user applies for termination of the use of the ID management service from the web page of the My Portal. The user terminal 12 transmits data for an application to terminate the use of the ID management service to the gateway server 20 according to the user's operation. The data for the application to terminate the use of the ID management service includes the current serial number read by the IC card reader from the user's personal number card.
[0060] When the membership cancellation reception unit 42 of the gateway server 20 receives an application to terminate the use of the ID management service transmitted from the user terminal 12 (Y in S40), it executes a predetermined membership cancellation process (S42). The membership cancellation process includes deleting the settlement account information of the user who has applied for termination of use from the settlement account information storage unit. On the other hand, the membership cancellation process does not include deleting the gateway ID of the user who has applied for termination of use from the ID storage unit 36. That is, the ID storage unit 36 of the gateway server 20 continues to manage the gateway ID of the user even after the user withdraws. If an application to terminate the use of the ID management service is not received (N in S40), the process of S42 is skipped.
[0061] As described above, businesses that can handle the serial numbers of personal user authentication electronic certificates are restricted. The gateway server 20 of the embodiment converts the serial number of the personal user authentication electronic certificate into a different ID called an authentication ID, and uses the authentication ID for determining the target person (for example, the recipient of benefits) in the ledger server 22. Thereby, while complying with the handling restrictions on the serial numbers of the user authentication electronic certificates, the measures of local governments that pay benefits to specific individuals can be efficiently realized. Also, by using a one-way function of irreversible logic for the conversion of the serial number, the confidentiality of the serial number can be maintained while ensuring the identity between the target authentication ID and the application authentication ID generated from the same serial number.
[0062] In addition, the gateway server 20 of the embodiment transmits both the application authentication ID obtained by converting the current serial number of the user and the application authentication ID obtained by converting the past serial number associated with the current serial number in the public personal authentication system to the ledger server 22 to inquire about the measures targeted at the user. Thereby, even in a situation where the serial number recorded on the user's personal number card can change, the measures targeted at the user can be accurately extracted.
[0063] In addition, the gateway server 20 of the embodiment manages a single gateway ID of the user in association with one or more serial numbers of the user. Even when the user terminates the use of the ID management service, the gateway server 20 continues to manage the gateway ID of the user. Thereby, even when the serial number of the user changes, it is possible to prevent the same measure payment from being paid to the user multiple times.
[0064] As described above, the present disclosure has been described based on the embodiments. It is understood by those skilled in the art that the content described in the embodiments is exemplary, and various modifications are possible for the combinations of the components and processing processes of the embodiments, and such modifications are also within the scope of the present disclosure.
[0065] Any combination of the above-described embodiments and modifications is also useful as an embodiment of the present disclosure. The new embodiment generated by the combination has the effects of the combined embodiments and modifications. It is also understood by those skilled in the art that the functions to be achieved by each constituent element described in the claims are realized by a single one of the constituent elements shown in the embodiments and modifications or by their cooperation.
Explanation of Reference Numerals
[0066] 10 Electronic application system, 12 User terminal, 20 Gateway server, 22 Ledger server, 36 ID storage unit, 44 First serial number acquisition unit, 46 Conversion unit, 48 First ID transmission unit, 50 Second serial number acquisition unit, 52 Second ID transmission unit, 58 History acquisition unit, 60 Gateway ID numbering unit.
Claims
1. A first acquisition unit that acquires a first serial number, which is the serial number of an electronic certificate for user identification of an individual targeted by the public agency's policy, transmitted from the public agency's system; A conversion unit that acquires a first authentication ID obtained by converting the first serial number using a predetermined algorithm; A first transmission unit that transmits the first authentication ID of the individual targeted by the policy to the public agency's system for registration in a ledger system that manages the application status for the policy; A second acquisition unit that acquires a second serial number, which is the serial number of an electronic certificate for user identification read from the personal number card of an individual applying for the policy; comprising: The conversion unit further acquires a second authentication ID obtained by converting the second serial number using the algorithm; The information processing system further includes a second transmission unit that transmits the second authentication ID of the individual applying for the policy to the ledger system. Information processing system.
2. The algorithm is a predetermined one-way function. The information processing system according to Claim 1.
3. The conversion unit further acquires a third authentication ID obtained by converting, using the algorithm, a past serial number associated with the second serial number in a public personal authentication system; The second transmission unit transmits both the second authentication ID and the third authentication ID to the ledger system. The information processing system according to Claim 1.
4. When receiving an application for using an ID management service from a certain individual, a third acquisition unit that acquires, from a public personal authentication system, a past serial number associated with the serial number of an electronic certificate for user identification read from the personal number card of the certain individual; A storage unit that stores a new single personal ID in association with the serial number and the past serial number when the personal ID, which is an ID different from the personal number and unique for each individual, has not been assigned to either the serial number or the past serial number; further comprising: The ledger system identifies the individuals who have applied for the policy using the personal ID; The storage unit continues to manage the personal ID associated with the serial number of the electronic certificate for user identification read from the personal number card of the certain individual even when the certain individual terminates the use of the ID management service. The information processing system according to any one of Claims 1 to 3.
5. A step of obtaining a first serial number, which is the serial number of an electronic certificate for user authentication of an individual targeted by the measure of the public institution, sent from the system of the public institution; A step of obtaining a first authentication ID obtained by converting the first serial number using a predetermined algorithm; A step of sending the first authentication ID of the individual targeted by the measure to the system of the public institution to be registered in a ledger system that manages the application status for the measure; A step of obtaining a second serial number, which is the serial number of an electronic certificate for user authentication read from the personal number card of an individual applying for the measure; A step of obtaining a second authentication ID obtained by converting the second serial number using the algorithm; A step of sending the second authentication ID of the individual applying for the measure to the ledger system; An information processing method executed by a computer.
Citation Information
Patent Citations
Sales promotion system, corporate point management server and corporate point management program
JP2011198277A